bundle.yaml 1.9 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619326203262132622326233262432625326263262732628326293263032631326323263332634326353263632637326383263932640326413264232643326443264532646326473264832649326503265132652326533265432655326563265732658326593266032661326623266332664326653266632667326683266932670326713267232673326743267532676326773267832679326803268132682326833268432685326863268732688326893269032691326923269332694326953269632697326983269932700327013270232703327043270532706327073270832709327103271132712327133271432715327163271732718327193272032721327223272332724327253272632727327283272932730327313273232733327343273532736327373273832739327403274132742327433274432745327463274732748327493275032751327523275332754327553275632757327583275932760327613276232763327643276532766327673276832769327703277132772327733277432775327763277732778327793278032781327823278332784327853278632787327883278932790327913279232793327943279532796327973279832799328003280132802328033280432805328063280732808328093281032811328123281332814328153281632817328183281932820328213282232823328243282532826328273282832829328303283132832328333283432835328363283732838328393284032841328423284332844328453284632847328483284932850328513285232853328543285532856328573285832859328603286132862328633286432865328663286732868328693287032871328723287332874328753287632877328783287932880328813288232883328843288532886328873288832889328903289132892328933289432895328963289732898328993290032901329023290332904329053290632907329083290932910329113291232913329143291532916329173291832919329203292132922329233292432925329263292732928329293293032931329323293332934329353293632937329383293932940329413294232943329443294532946329473294832949329503295132952329533295432955329563295732958329593296032961329623296332964329653296632967329683296932970329713297232973329743297532976329773297832979329803298132982329833298432985329863298732988329893299032991329923299332994329953299632997329983299933000330013300233003330043300533006330073300833009330103301133012330133301433015330163301733018330193302033021330223302333024330253302633027330283302933030330313303233033330343303533036330373303833039330403304133042330433304433045330463304733048330493305033051330523305333054330553305633057330583305933060330613306233063330643306533066330673306833069330703307133072330733307433075330763307733078330793308033081330823308333084330853308633087330883308933090330913309233093330943309533096330973309833099331003310133102331033310433105331063310733108331093311033111331123311333114331153311633117331183311933120331213312233123
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: Selector chooses secrets using a labelSelector.
  2067. properties:
  2068. matchExpressions:
  2069. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2070. items:
  2071. description: |-
  2072. A label selector requirement is a selector that contains values, a key, and an operator that
  2073. relates the key and values.
  2074. properties:
  2075. key:
  2076. description: key is the label key that the selector applies to.
  2077. type: string
  2078. operator:
  2079. description: |-
  2080. operator represents a key's relationship to a set of values.
  2081. Valid operators are In, NotIn, Exists and DoesNotExist.
  2082. type: string
  2083. values:
  2084. description: |-
  2085. values is an array of string values. If the operator is In or NotIn,
  2086. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2087. the values array must be empty. This array is replaced during a strategic
  2088. merge patch.
  2089. items:
  2090. type: string
  2091. type: array
  2092. x-kubernetes-list-type: atomic
  2093. required:
  2094. - key
  2095. - operator
  2096. type: object
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. matchLabels:
  2100. additionalProperties:
  2101. type: string
  2102. description: |-
  2103. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2104. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2105. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2106. type: object
  2107. type: object
  2108. x-kubernetes-map-type: atomic
  2109. type: object
  2110. type: object
  2111. template:
  2112. description: Template defines a blueprint for the created Secret resource.
  2113. properties:
  2114. data:
  2115. additionalProperties:
  2116. type: string
  2117. type: object
  2118. engineVersion:
  2119. default: v2
  2120. description: |-
  2121. EngineVersion specifies the template engine version
  2122. that should be used to compile/execute the
  2123. template specified in .data and .templateFrom[].
  2124. enum:
  2125. - v2
  2126. type: string
  2127. mergePolicy:
  2128. default: Replace
  2129. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2130. enum:
  2131. - Replace
  2132. - Merge
  2133. type: string
  2134. metadata:
  2135. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2136. properties:
  2137. annotations:
  2138. additionalProperties:
  2139. type: string
  2140. type: object
  2141. finalizers:
  2142. items:
  2143. type: string
  2144. type: array
  2145. labels:
  2146. additionalProperties:
  2147. type: string
  2148. type: object
  2149. type: object
  2150. templateFrom:
  2151. items:
  2152. description: |-
  2153. TemplateFrom specifies a source for templates.
  2154. Each item in the list can either reference a ConfigMap or a Secret resource.
  2155. properties:
  2156. configMap:
  2157. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2158. properties:
  2159. items:
  2160. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2161. items:
  2162. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2163. properties:
  2164. key:
  2165. description: A key in the ConfigMap/Secret
  2166. maxLength: 253
  2167. minLength: 1
  2168. pattern: ^[-._a-zA-Z0-9]+$
  2169. type: string
  2170. templateAs:
  2171. default: Values
  2172. description: TemplateScope specifies how the template keys should be interpreted.
  2173. enum:
  2174. - Values
  2175. - KeysAndValues
  2176. type: string
  2177. required:
  2178. - key
  2179. type: object
  2180. type: array
  2181. name:
  2182. description: The name of the ConfigMap/Secret resource
  2183. maxLength: 253
  2184. minLength: 1
  2185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2186. type: string
  2187. required:
  2188. - items
  2189. - name
  2190. type: object
  2191. literal:
  2192. type: string
  2193. secret:
  2194. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2195. properties:
  2196. items:
  2197. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2198. items:
  2199. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2200. properties:
  2201. key:
  2202. description: A key in the ConfigMap/Secret
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[-._a-zA-Z0-9]+$
  2206. type: string
  2207. templateAs:
  2208. default: Values
  2209. description: TemplateScope specifies how the template keys should be interpreted.
  2210. enum:
  2211. - Values
  2212. - KeysAndValues
  2213. type: string
  2214. required:
  2215. - key
  2216. type: object
  2217. type: array
  2218. name:
  2219. description: The name of the ConfigMap/Secret resource
  2220. maxLength: 253
  2221. minLength: 1
  2222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2223. type: string
  2224. required:
  2225. - items
  2226. - name
  2227. type: object
  2228. target:
  2229. default: Data
  2230. description: |-
  2231. Target specifies where to place the template result.
  2232. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2233. any other value is rejected because it would allow writes to privileged Secret fields.
  2234. For custom resources (when spec.target.manifest is set), this supports
  2235. nested paths like "spec.database.config" or "data".
  2236. type: string
  2237. valuesDecodingStrategy:
  2238. description: |-
  2239. Used to define a decoding Strategy for the rendered template values.
  2240. Defaults to None when omitted.
  2241. enum:
  2242. - Auto
  2243. - Base64
  2244. - Base64URL
  2245. - None
  2246. type: string
  2247. type: object
  2248. type: array
  2249. type:
  2250. type: string
  2251. type: object
  2252. updatePolicy:
  2253. default: Replace
  2254. description: UpdatePolicy to handle Secrets in the provider.
  2255. enum:
  2256. - Replace
  2257. - IfNotExists
  2258. type: string
  2259. required:
  2260. - secretStoreRefs
  2261. - selector
  2262. type: object
  2263. refreshTime:
  2264. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2265. type: string
  2266. required:
  2267. - pushSecretSpec
  2268. type: object
  2269. status:
  2270. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2271. properties:
  2272. conditions:
  2273. items:
  2274. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2275. properties:
  2276. lastTransitionTime:
  2277. format: date-time
  2278. type: string
  2279. message:
  2280. type: string
  2281. reason:
  2282. type: string
  2283. status:
  2284. type: string
  2285. type:
  2286. description: PushSecretConditionType indicates the condition of the PushSecret.
  2287. type: string
  2288. required:
  2289. - status
  2290. - type
  2291. type: object
  2292. type: array
  2293. failedNamespaces:
  2294. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2295. items:
  2296. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2297. properties:
  2298. namespace:
  2299. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2300. type: string
  2301. reason:
  2302. description: Reason is why the PushSecret failed to apply to the namespace
  2303. type: string
  2304. required:
  2305. - namespace
  2306. type: object
  2307. type: array
  2308. provisionedNamespaces:
  2309. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2310. items:
  2311. type: string
  2312. type: array
  2313. pushSecretName:
  2314. type: string
  2315. type: object
  2316. type: object
  2317. served: true
  2318. storage: true
  2319. subresources:
  2320. status: {}
  2321. ---
  2322. apiVersion: apiextensions.k8s.io/v1
  2323. kind: CustomResourceDefinition
  2324. metadata:
  2325. annotations:
  2326. controller-gen.kubebuilder.io/version: v0.19.0
  2327. labels:
  2328. external-secrets.io/component: controller
  2329. name: clustersecretstores.external-secrets.io
  2330. spec:
  2331. group: external-secrets.io
  2332. names:
  2333. categories:
  2334. - external-secrets
  2335. kind: ClusterSecretStore
  2336. listKind: ClusterSecretStoreList
  2337. plural: clustersecretstores
  2338. shortNames:
  2339. - css
  2340. singular: clustersecretstore
  2341. scope: Cluster
  2342. versions:
  2343. - additionalPrinterColumns:
  2344. - jsonPath: .metadata.creationTimestamp
  2345. name: AGE
  2346. type: date
  2347. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2348. name: Status
  2349. type: string
  2350. - jsonPath: .status.capabilities
  2351. name: Capabilities
  2352. type: string
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2354. name: Ready
  2355. type: string
  2356. name: v1
  2357. schema:
  2358. openAPIV3Schema:
  2359. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2360. properties:
  2361. apiVersion:
  2362. description: |-
  2363. APIVersion defines the versioned schema of this representation of an object.
  2364. Servers should convert recognized schemas to the latest internal value, and
  2365. may reject unrecognized values.
  2366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2367. type: string
  2368. kind:
  2369. description: |-
  2370. Kind is a string value representing the REST resource this object represents.
  2371. Servers may infer this from the endpoint the client submits requests to.
  2372. Cannot be updated.
  2373. In CamelCase.
  2374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2375. type: string
  2376. metadata:
  2377. type: object
  2378. spec:
  2379. description: SecretStoreSpec defines the desired state of SecretStore.
  2380. properties:
  2381. conditions:
  2382. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2383. items:
  2384. description: |-
  2385. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2386. for a ClusterSecretStore instance.
  2387. properties:
  2388. namespaceRegexes:
  2389. description: Choose namespaces by using regex matching
  2390. items:
  2391. type: string
  2392. type: array
  2393. namespaceSelector:
  2394. description: Choose namespace using a labelSelector
  2395. properties:
  2396. matchExpressions:
  2397. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2398. items:
  2399. description: |-
  2400. A label selector requirement is a selector that contains values, a key, and an operator that
  2401. relates the key and values.
  2402. properties:
  2403. key:
  2404. description: key is the label key that the selector applies to.
  2405. type: string
  2406. operator:
  2407. description: |-
  2408. operator represents a key's relationship to a set of values.
  2409. Valid operators are In, NotIn, Exists and DoesNotExist.
  2410. type: string
  2411. values:
  2412. description: |-
  2413. values is an array of string values. If the operator is In or NotIn,
  2414. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2415. the values array must be empty. This array is replaced during a strategic
  2416. merge patch.
  2417. items:
  2418. type: string
  2419. type: array
  2420. x-kubernetes-list-type: atomic
  2421. required:
  2422. - key
  2423. - operator
  2424. type: object
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. matchLabels:
  2428. additionalProperties:
  2429. type: string
  2430. description: |-
  2431. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2432. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2433. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2434. type: object
  2435. type: object
  2436. x-kubernetes-map-type: atomic
  2437. namespaces:
  2438. description: Choose namespaces by name
  2439. items:
  2440. maxLength: 63
  2441. minLength: 1
  2442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2443. type: string
  2444. type: array
  2445. type: object
  2446. type: array
  2447. controller:
  2448. description: |-
  2449. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2450. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2451. type: string
  2452. provider:
  2453. description: Used to configure the provider. Only one provider may be set
  2454. maxProperties: 1
  2455. minProperties: 1
  2456. properties:
  2457. akeyless:
  2458. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2459. properties:
  2460. akeylessGWApiURL:
  2461. description: Akeyless GW API Url from which the secrets to be fetched from.
  2462. type: string
  2463. authSecretRef:
  2464. description: Auth configures how the operator authenticates with Akeyless.
  2465. properties:
  2466. kubernetesAuth:
  2467. description: |-
  2468. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2469. token stored in the named Secret resource.
  2470. properties:
  2471. accessID:
  2472. description: the Akeyless Kubernetes auth-method access-id
  2473. type: string
  2474. k8sConfName:
  2475. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2476. type: string
  2477. secretRef:
  2478. description: |-
  2479. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2480. for authenticating with Akeyless. If a name is specified without a key,
  2481. `token` is the default. If one is not specified, the one bound to
  2482. the controller will be used.
  2483. properties:
  2484. key:
  2485. description: |-
  2486. A key in the referenced Secret.
  2487. Some instances of this field may be defaulted, in others it may be required.
  2488. maxLength: 253
  2489. minLength: 1
  2490. pattern: ^[-._a-zA-Z0-9]+$
  2491. type: string
  2492. name:
  2493. description: The name of the Secret resource being referred to.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2497. type: string
  2498. namespace:
  2499. description: |-
  2500. The namespace of the Secret resource being referred to.
  2501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2502. maxLength: 63
  2503. minLength: 1
  2504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2505. type: string
  2506. type: object
  2507. serviceAccountRef:
  2508. description: |-
  2509. Optional service account field containing the name of a kubernetes ServiceAccount.
  2510. If the service account is specified, the service account secret token JWT will be used
  2511. for authenticating with Akeyless. If the service account selector is not supplied,
  2512. the secretRef will be used instead.
  2513. properties:
  2514. audiences:
  2515. description: |-
  2516. Audience specifies the `aud` claim for the service account token
  2517. Some providers automatically extend the audience field based on well-known annotations for workload
  2518. identity (e.g. IRSA or GCP Workload Identity)
  2519. items:
  2520. type: string
  2521. type: array
  2522. name:
  2523. description: The name of the ServiceAccount resource being referred to.
  2524. maxLength: 253
  2525. minLength: 1
  2526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2527. type: string
  2528. namespace:
  2529. description: |-
  2530. Namespace of the resource being referred to.
  2531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2532. maxLength: 63
  2533. minLength: 1
  2534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2535. type: string
  2536. required:
  2537. - name
  2538. type: object
  2539. required:
  2540. - accessID
  2541. - k8sConfName
  2542. type: object
  2543. secretRef:
  2544. description: |-
  2545. Reference to a Secret that contains the details
  2546. to authenticate with Akeyless.
  2547. properties:
  2548. accessID:
  2549. description: The SecretAccessID is used for authentication
  2550. properties:
  2551. key:
  2552. description: |-
  2553. A key in the referenced Secret.
  2554. Some instances of this field may be defaulted, in others it may be required.
  2555. maxLength: 253
  2556. minLength: 1
  2557. pattern: ^[-._a-zA-Z0-9]+$
  2558. type: string
  2559. name:
  2560. description: The name of the Secret resource being referred to.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2564. type: string
  2565. namespace:
  2566. description: |-
  2567. The namespace of the Secret resource being referred to.
  2568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2569. maxLength: 63
  2570. minLength: 1
  2571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2572. type: string
  2573. type: object
  2574. accessType:
  2575. description: |-
  2576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2577. In some instances, `key` is a required field.
  2578. properties:
  2579. key:
  2580. description: |-
  2581. A key in the referenced Secret.
  2582. Some instances of this field may be defaulted, in others it may be required.
  2583. maxLength: 253
  2584. minLength: 1
  2585. pattern: ^[-._a-zA-Z0-9]+$
  2586. type: string
  2587. name:
  2588. description: The name of the Secret resource being referred to.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2592. type: string
  2593. namespace:
  2594. description: |-
  2595. The namespace of the Secret resource being referred to.
  2596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2597. maxLength: 63
  2598. minLength: 1
  2599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2600. type: string
  2601. type: object
  2602. accessTypeParam:
  2603. description: |-
  2604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2605. In some instances, `key` is a required field.
  2606. properties:
  2607. key:
  2608. description: |-
  2609. A key in the referenced Secret.
  2610. Some instances of this field may be defaulted, in others it may be required.
  2611. maxLength: 253
  2612. minLength: 1
  2613. pattern: ^[-._a-zA-Z0-9]+$
  2614. type: string
  2615. name:
  2616. description: The name of the Secret resource being referred to.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2620. type: string
  2621. namespace:
  2622. description: |-
  2623. The namespace of the Secret resource being referred to.
  2624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2625. maxLength: 63
  2626. minLength: 1
  2627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2628. type: string
  2629. type: object
  2630. type: object
  2631. serviceAccountRef:
  2632. description: |-
  2633. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2634. authentication on AKS Workload Identity. The operator obtains a federated
  2635. identity token from this ServiceAccount via the TokenRequest API instead
  2636. of using the ESO controller pod identity. Ignored for other access types.
  2637. properties:
  2638. audiences:
  2639. description: |-
  2640. Audience specifies the `aud` claim for the service account token
  2641. Some providers automatically extend the audience field based on well-known annotations for workload
  2642. identity (e.g. IRSA or GCP Workload Identity)
  2643. items:
  2644. type: string
  2645. type: array
  2646. name:
  2647. description: The name of the ServiceAccount resource being referred to.
  2648. maxLength: 253
  2649. minLength: 1
  2650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2651. type: string
  2652. namespace:
  2653. description: |-
  2654. Namespace of the resource being referred to.
  2655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2656. maxLength: 63
  2657. minLength: 1
  2658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2659. type: string
  2660. required:
  2661. - name
  2662. type: object
  2663. type: object
  2664. caBundle:
  2665. description: |-
  2666. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2667. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2668. are used to validate the TLS connection.
  2669. format: byte
  2670. type: string
  2671. caProvider:
  2672. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2673. properties:
  2674. key:
  2675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2676. maxLength: 253
  2677. minLength: 1
  2678. pattern: ^[-._a-zA-Z0-9]+$
  2679. type: string
  2680. name:
  2681. description: The name of the object located at the provider type.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2685. type: string
  2686. namespace:
  2687. description: |-
  2688. The namespace the Provider type is in.
  2689. Can only be defined when used in a ClusterSecretStore.
  2690. maxLength: 63
  2691. minLength: 1
  2692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2693. type: string
  2694. type:
  2695. description: The type of provider to use such as "Secret", or "ConfigMap".
  2696. enum:
  2697. - Secret
  2698. - ConfigMap
  2699. type: string
  2700. required:
  2701. - name
  2702. - type
  2703. type: object
  2704. ignoreCache:
  2705. description: |-
  2706. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2707. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2708. type: boolean
  2709. required:
  2710. - akeylessGWApiURL
  2711. - authSecretRef
  2712. type: object
  2713. aws:
  2714. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2715. properties:
  2716. additionalRoles:
  2717. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2718. items:
  2719. type: string
  2720. type: array
  2721. auth:
  2722. description: |-
  2723. Auth defines the information necessary to authenticate against AWS
  2724. if not set aws sdk will infer credentials from your environment
  2725. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2726. properties:
  2727. jwt:
  2728. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2729. properties:
  2730. serviceAccountRef:
  2731. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2732. properties:
  2733. audiences:
  2734. description: |-
  2735. Audience specifies the `aud` claim for the service account token
  2736. Some providers automatically extend the audience field based on well-known annotations for workload
  2737. identity (e.g. IRSA or GCP Workload Identity)
  2738. items:
  2739. type: string
  2740. type: array
  2741. name:
  2742. description: The name of the ServiceAccount resource being referred to.
  2743. maxLength: 253
  2744. minLength: 1
  2745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2746. type: string
  2747. namespace:
  2748. description: |-
  2749. Namespace of the resource being referred to.
  2750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2751. maxLength: 63
  2752. minLength: 1
  2753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2754. type: string
  2755. required:
  2756. - name
  2757. type: object
  2758. type: object
  2759. secretRef:
  2760. description: |-
  2761. AWSAuthSecretRef holds secret references for AWS credentials
  2762. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2763. properties:
  2764. accessKeyIDSecretRef:
  2765. description: The AccessKeyID is used for authentication
  2766. properties:
  2767. key:
  2768. description: |-
  2769. A key in the referenced Secret.
  2770. Some instances of this field may be defaulted, in others it may be required.
  2771. maxLength: 253
  2772. minLength: 1
  2773. pattern: ^[-._a-zA-Z0-9]+$
  2774. type: string
  2775. name:
  2776. description: The name of the Secret resource being referred to.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2780. type: string
  2781. namespace:
  2782. description: |-
  2783. The namespace of the Secret resource being referred to.
  2784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2785. maxLength: 63
  2786. minLength: 1
  2787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2788. type: string
  2789. type: object
  2790. secretAccessKeySecretRef:
  2791. description: The SecretAccessKey is used for authentication
  2792. properties:
  2793. key:
  2794. description: |-
  2795. A key in the referenced Secret.
  2796. Some instances of this field may be defaulted, in others it may be required.
  2797. maxLength: 253
  2798. minLength: 1
  2799. pattern: ^[-._a-zA-Z0-9]+$
  2800. type: string
  2801. name:
  2802. description: The name of the Secret resource being referred to.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2806. type: string
  2807. namespace:
  2808. description: |-
  2809. The namespace of the Secret resource being referred to.
  2810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2811. maxLength: 63
  2812. minLength: 1
  2813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2814. type: string
  2815. type: object
  2816. sessionTokenSecretRef:
  2817. description: |-
  2818. The SessionToken used for authentication
  2819. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2820. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2821. properties:
  2822. key:
  2823. description: |-
  2824. A key in the referenced Secret.
  2825. Some instances of this field may be defaulted, in others it may be required.
  2826. maxLength: 253
  2827. minLength: 1
  2828. pattern: ^[-._a-zA-Z0-9]+$
  2829. type: string
  2830. name:
  2831. description: The name of the Secret resource being referred to.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2835. type: string
  2836. namespace:
  2837. description: |-
  2838. The namespace of the Secret resource being referred to.
  2839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2840. maxLength: 63
  2841. minLength: 1
  2842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2843. type: string
  2844. type: object
  2845. type: object
  2846. type: object
  2847. customSessionTags:
  2848. additionalProperties:
  2849. type: string
  2850. description: |-
  2851. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2852. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2853. type: object
  2854. x-kubernetes-validations:
  2855. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2856. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2857. externalID:
  2858. description: AWS External ID set on assumed IAM roles
  2859. type: string
  2860. prefix:
  2861. description: Prefix adds a prefix to all retrieved values.
  2862. type: string
  2863. region:
  2864. description: AWS Region to be used for the provider
  2865. type: string
  2866. role:
  2867. description: Role is a Role ARN which the provider will assume
  2868. type: string
  2869. secretsManager:
  2870. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2871. properties:
  2872. forceDeleteWithoutRecovery:
  2873. description: |-
  2874. Specifies whether to delete the secret without any recovery window. You
  2875. can't use both this parameter and RecoveryWindowInDays in the same call.
  2876. If you don't use either, then by default Secrets Manager uses a 30 day
  2877. recovery window.
  2878. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2879. type: boolean
  2880. recoveryWindowInDays:
  2881. description: |-
  2882. The number of days from 7 to 30 that Secrets Manager waits before
  2883. permanently deleting the secret. You can't use both this parameter and
  2884. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2885. then by default Secrets Manager uses a 30-day recovery window.
  2886. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2887. format: int64
  2888. type: integer
  2889. type: object
  2890. service:
  2891. description: Service defines which service should be used to fetch the secrets
  2892. enum:
  2893. - SecretsManager
  2894. - ParameterStore
  2895. - CertificateManager
  2896. type: string
  2897. sessionTags:
  2898. description: AWS STS assume role session tags
  2899. items:
  2900. description: |-
  2901. Tag is a key-value pair that can be attached to an AWS resource.
  2902. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2903. properties:
  2904. key:
  2905. type: string
  2906. value:
  2907. type: string
  2908. required:
  2909. - key
  2910. - value
  2911. type: object
  2912. type: array
  2913. sessionTagsPolicy:
  2914. default: None
  2915. description: |-
  2916. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2917. None (default): no tags are added.
  2918. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2919. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2920. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2921. enum:
  2922. - None
  2923. - Simple
  2924. - Custom
  2925. type: string
  2926. transitiveTagKeys:
  2927. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2928. items:
  2929. type: string
  2930. type: array
  2931. required:
  2932. - region
  2933. - service
  2934. type: object
  2935. azurekv:
  2936. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2937. properties:
  2938. authSecretRef:
  2939. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2940. properties:
  2941. clientCertificate:
  2942. description: The Azure ClientCertificate of the service principle used for authentication.
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. clientId:
  2968. description: The Azure clientId of the service principle or managed identity used for authentication.
  2969. properties:
  2970. key:
  2971. description: |-
  2972. A key in the referenced Secret.
  2973. Some instances of this field may be defaulted, in others it may be required.
  2974. maxLength: 253
  2975. minLength: 1
  2976. pattern: ^[-._a-zA-Z0-9]+$
  2977. type: string
  2978. name:
  2979. description: The name of the Secret resource being referred to.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2983. type: string
  2984. namespace:
  2985. description: |-
  2986. The namespace of the Secret resource being referred to.
  2987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2988. maxLength: 63
  2989. minLength: 1
  2990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2991. type: string
  2992. type: object
  2993. clientSecret:
  2994. description: The Azure ClientSecret of the service principle used for authentication.
  2995. properties:
  2996. key:
  2997. description: |-
  2998. A key in the referenced Secret.
  2999. Some instances of this field may be defaulted, in others it may be required.
  3000. maxLength: 253
  3001. minLength: 1
  3002. pattern: ^[-._a-zA-Z0-9]+$
  3003. type: string
  3004. name:
  3005. description: The name of the Secret resource being referred to.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3009. type: string
  3010. namespace:
  3011. description: |-
  3012. The namespace of the Secret resource being referred to.
  3013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3014. maxLength: 63
  3015. minLength: 1
  3016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3017. type: string
  3018. type: object
  3019. tenantId:
  3020. description: The Azure tenantId of the managed identity used for authentication.
  3021. properties:
  3022. key:
  3023. description: |-
  3024. A key in the referenced Secret.
  3025. Some instances of this field may be defaulted, in others it may be required.
  3026. maxLength: 253
  3027. minLength: 1
  3028. pattern: ^[-._a-zA-Z0-9]+$
  3029. type: string
  3030. name:
  3031. description: The name of the Secret resource being referred to.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3035. type: string
  3036. namespace:
  3037. description: |-
  3038. The namespace of the Secret resource being referred to.
  3039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3040. maxLength: 63
  3041. minLength: 1
  3042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3043. type: string
  3044. type: object
  3045. type: object
  3046. authType:
  3047. default: ServicePrincipal
  3048. description: |-
  3049. Auth type defines how to authenticate to the keyvault service.
  3050. Valid values are:
  3051. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3052. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3053. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3054. enum:
  3055. - ServicePrincipal
  3056. - ManagedIdentity
  3057. - WorkloadIdentity
  3058. type: string
  3059. customCloudConfig:
  3060. description: |-
  3061. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3062. Required when EnvironmentType is AzureStackCloud.
  3063. Optional for other environment types - useful for Azure China when using Workload Identity
  3064. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3065. standard China Cloud endpoint (login.chinacloudapi.cn).
  3066. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3067. configuration is not supported with the legacy go-autorest SDK.
  3068. properties:
  3069. activeDirectoryEndpoint:
  3070. description: |-
  3071. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3072. Required when using custom cloud configuration
  3073. type: string
  3074. keyVaultDNSSuffix:
  3075. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3076. type: string
  3077. keyVaultEndpoint:
  3078. description: KeyVaultEndpoint is the Key Vault service endpoint
  3079. type: string
  3080. resourceManagerEndpoint:
  3081. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3082. type: string
  3083. required:
  3084. - activeDirectoryEndpoint
  3085. type: object
  3086. environmentType:
  3087. default: PublicCloud
  3088. description: |-
  3089. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3090. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3091. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3092. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3093. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3094. enum:
  3095. - PublicCloud
  3096. - USGovernmentCloud
  3097. - ChinaCloud
  3098. - GermanCloud
  3099. - AzureStackCloud
  3100. type: string
  3101. identityId:
  3102. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3103. type: string
  3104. serviceAccountRef:
  3105. description: |-
  3106. ServiceAccountRef specified the service account
  3107. that should be used when authenticating with WorkloadIdentity.
  3108. properties:
  3109. audiences:
  3110. description: |-
  3111. Audience specifies the `aud` claim for the service account token
  3112. Some providers automatically extend the audience field based on well-known annotations for workload
  3113. identity (e.g. IRSA or GCP Workload Identity)
  3114. items:
  3115. type: string
  3116. type: array
  3117. name:
  3118. description: The name of the ServiceAccount resource being referred to.
  3119. maxLength: 253
  3120. minLength: 1
  3121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3122. type: string
  3123. namespace:
  3124. description: |-
  3125. Namespace of the resource being referred to.
  3126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3127. maxLength: 63
  3128. minLength: 1
  3129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3130. type: string
  3131. required:
  3132. - name
  3133. type: object
  3134. tenantId:
  3135. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3136. type: string
  3137. useAzureSDK:
  3138. default: false
  3139. description: |-
  3140. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3141. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3142. type: boolean
  3143. vaultUrl:
  3144. description: Vault Url from which the secrets to be fetched from.
  3145. type: string
  3146. required:
  3147. - vaultUrl
  3148. type: object
  3149. barbican:
  3150. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3151. properties:
  3152. auth:
  3153. description: BarbicanAuth contains the authentication information for Barbican.
  3154. properties:
  3155. applicationCredentialID:
  3156. description: ID of the application credential used for authentication.
  3157. maxProperties: 1
  3158. minProperties: 1
  3159. properties:
  3160. secretRef:
  3161. description: |-
  3162. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3163. In some instances, `key` is a required field.
  3164. properties:
  3165. key:
  3166. description: |-
  3167. A key in the referenced Secret.
  3168. Some instances of this field may be defaulted, in others it may be required.
  3169. maxLength: 253
  3170. minLength: 1
  3171. pattern: ^[-._a-zA-Z0-9]+$
  3172. type: string
  3173. name:
  3174. description: The name of the Secret resource being referred to.
  3175. maxLength: 253
  3176. minLength: 1
  3177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3178. type: string
  3179. namespace:
  3180. description: |-
  3181. The namespace of the Secret resource being referred to.
  3182. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3183. maxLength: 63
  3184. minLength: 1
  3185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3186. type: string
  3187. type: object
  3188. value:
  3189. minLength: 1
  3190. type: string
  3191. type: object
  3192. applicationCredentialSecret:
  3193. description: BarbicanProviderAppCredSecretRef defines a reference to an Application Credential Secret.
  3194. properties:
  3195. secretRef:
  3196. description: |-
  3197. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3198. In some instances, `key` is a required field.
  3199. properties:
  3200. key:
  3201. description: |-
  3202. A key in the referenced Secret.
  3203. Some instances of this field may be defaulted, in others it may be required.
  3204. maxLength: 253
  3205. minLength: 1
  3206. pattern: ^[-._a-zA-Z0-9]+$
  3207. type: string
  3208. name:
  3209. description: The name of the Secret resource being referred to.
  3210. maxLength: 253
  3211. minLength: 1
  3212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3213. type: string
  3214. namespace:
  3215. description: |-
  3216. The namespace of the Secret resource being referred to.
  3217. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3218. maxLength: 63
  3219. minLength: 1
  3220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3221. type: string
  3222. type: object
  3223. required:
  3224. - secretRef
  3225. type: object
  3226. authType:
  3227. default: password
  3228. description: |-
  3229. AuthType selects how Barbican authenticates.
  3230. - "password": use username and password.
  3231. - "applicationCredential": use application credential ID and secret.
  3232. Defaults to "password".
  3233. enum:
  3234. - password
  3235. - applicationCredential
  3236. type: string
  3237. password:
  3238. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3239. properties:
  3240. secretRef:
  3241. description: |-
  3242. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3243. In some instances, `key` is a required field.
  3244. properties:
  3245. key:
  3246. description: |-
  3247. A key in the referenced Secret.
  3248. Some instances of this field may be defaulted, in others it may be required.
  3249. maxLength: 253
  3250. minLength: 1
  3251. pattern: ^[-._a-zA-Z0-9]+$
  3252. type: string
  3253. name:
  3254. description: The name of the Secret resource being referred to.
  3255. maxLength: 253
  3256. minLength: 1
  3257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3258. type: string
  3259. namespace:
  3260. description: |-
  3261. The namespace of the Secret resource being referred to.
  3262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3263. maxLength: 63
  3264. minLength: 1
  3265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3266. type: string
  3267. type: object
  3268. required:
  3269. - secretRef
  3270. type: object
  3271. username:
  3272. description: Username / Password authentication fields.
  3273. maxProperties: 1
  3274. minProperties: 1
  3275. properties:
  3276. secretRef:
  3277. description: |-
  3278. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3279. In some instances, `key` is a required field.
  3280. properties:
  3281. key:
  3282. description: |-
  3283. A key in the referenced Secret.
  3284. Some instances of this field may be defaulted, in others it may be required.
  3285. maxLength: 253
  3286. minLength: 1
  3287. pattern: ^[-._a-zA-Z0-9]+$
  3288. type: string
  3289. name:
  3290. description: The name of the Secret resource being referred to.
  3291. maxLength: 253
  3292. minLength: 1
  3293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3294. type: string
  3295. namespace:
  3296. description: |-
  3297. The namespace of the Secret resource being referred to.
  3298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3299. maxLength: 63
  3300. minLength: 1
  3301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3302. type: string
  3303. type: object
  3304. value:
  3305. minLength: 1
  3306. type: string
  3307. type: object
  3308. type: object
  3309. x-kubernetes-validations:
  3310. - message: password auth requires both username and password
  3311. rule: (has(self.authType) && self.authType == 'applicationCredential') || (has(self.username) && has(self.password))
  3312. - message: applicationCredential auth requires both applicationCredentialID and applicationCredentialSecret
  3313. rule: self.authType != 'applicationCredential' || (has(self.applicationCredentialID) && has(self.applicationCredentialSecret))
  3314. - message: password auth should not include applicationCredential fields
  3315. rule: (has(self.authType) && self.authType == 'applicationCredential') || (!has(self.applicationCredentialID) && !has(self.applicationCredentialSecret))
  3316. - message: applicationCredential auth should not include password fields
  3317. rule: self.authType != 'applicationCredential' || (!has(self.username) && !has(self.password))
  3318. authURL:
  3319. type: string
  3320. domainName:
  3321. type: string
  3322. region:
  3323. type: string
  3324. tenantName:
  3325. type: string
  3326. required:
  3327. - auth
  3328. type: object
  3329. beyondtrust:
  3330. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3331. properties:
  3332. auth:
  3333. description: Auth configures how the operator authenticates with Beyondtrust.
  3334. properties:
  3335. apiKey:
  3336. description: APIKey If not provided then ClientID/ClientSecret become required.
  3337. properties:
  3338. secretRef:
  3339. description: SecretRef references a key in a secret that will be used as value.
  3340. properties:
  3341. key:
  3342. description: |-
  3343. A key in the referenced Secret.
  3344. Some instances of this field may be defaulted, in others it may be required.
  3345. maxLength: 253
  3346. minLength: 1
  3347. pattern: ^[-._a-zA-Z0-9]+$
  3348. type: string
  3349. name:
  3350. description: The name of the Secret resource being referred to.
  3351. maxLength: 253
  3352. minLength: 1
  3353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3354. type: string
  3355. namespace:
  3356. description: |-
  3357. The namespace of the Secret resource being referred to.
  3358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3359. maxLength: 63
  3360. minLength: 1
  3361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3362. type: string
  3363. type: object
  3364. value:
  3365. description: Value can be specified directly to set a value without using a secret.
  3366. type: string
  3367. type: object
  3368. certificate:
  3369. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3370. properties:
  3371. secretRef:
  3372. description: SecretRef references a key in a secret that will be used as value.
  3373. properties:
  3374. key:
  3375. description: |-
  3376. A key in the referenced Secret.
  3377. Some instances of this field may be defaulted, in others it may be required.
  3378. maxLength: 253
  3379. minLength: 1
  3380. pattern: ^[-._a-zA-Z0-9]+$
  3381. type: string
  3382. name:
  3383. description: The name of the Secret resource being referred to.
  3384. maxLength: 253
  3385. minLength: 1
  3386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3387. type: string
  3388. namespace:
  3389. description: |-
  3390. The namespace of the Secret resource being referred to.
  3391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3392. maxLength: 63
  3393. minLength: 1
  3394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3395. type: string
  3396. type: object
  3397. value:
  3398. description: Value can be specified directly to set a value without using a secret.
  3399. type: string
  3400. type: object
  3401. certificateKey:
  3402. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3403. properties:
  3404. secretRef:
  3405. description: SecretRef references a key in a secret that will be used as value.
  3406. properties:
  3407. key:
  3408. description: |-
  3409. A key in the referenced Secret.
  3410. Some instances of this field may be defaulted, in others it may be required.
  3411. maxLength: 253
  3412. minLength: 1
  3413. pattern: ^[-._a-zA-Z0-9]+$
  3414. type: string
  3415. name:
  3416. description: The name of the Secret resource being referred to.
  3417. maxLength: 253
  3418. minLength: 1
  3419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3420. type: string
  3421. namespace:
  3422. description: |-
  3423. The namespace of the Secret resource being referred to.
  3424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3425. maxLength: 63
  3426. minLength: 1
  3427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3428. type: string
  3429. type: object
  3430. value:
  3431. description: Value can be specified directly to set a value without using a secret.
  3432. type: string
  3433. type: object
  3434. clientId:
  3435. description: ClientID is the API OAuth Client ID.
  3436. properties:
  3437. secretRef:
  3438. description: SecretRef references a key in a secret that will be used as value.
  3439. properties:
  3440. key:
  3441. description: |-
  3442. A key in the referenced Secret.
  3443. Some instances of this field may be defaulted, in others it may be required.
  3444. maxLength: 253
  3445. minLength: 1
  3446. pattern: ^[-._a-zA-Z0-9]+$
  3447. type: string
  3448. name:
  3449. description: The name of the Secret resource being referred to.
  3450. maxLength: 253
  3451. minLength: 1
  3452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3453. type: string
  3454. namespace:
  3455. description: |-
  3456. The namespace of the Secret resource being referred to.
  3457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3458. maxLength: 63
  3459. minLength: 1
  3460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3461. type: string
  3462. type: object
  3463. value:
  3464. description: Value can be specified directly to set a value without using a secret.
  3465. type: string
  3466. type: object
  3467. clientSecret:
  3468. description: ClientSecret is the API OAuth Client Secret.
  3469. properties:
  3470. secretRef:
  3471. description: SecretRef references a key in a secret that will be used as value.
  3472. properties:
  3473. key:
  3474. description: |-
  3475. A key in the referenced Secret.
  3476. Some instances of this field may be defaulted, in others it may be required.
  3477. maxLength: 253
  3478. minLength: 1
  3479. pattern: ^[-._a-zA-Z0-9]+$
  3480. type: string
  3481. name:
  3482. description: The name of the Secret resource being referred to.
  3483. maxLength: 253
  3484. minLength: 1
  3485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3486. type: string
  3487. namespace:
  3488. description: |-
  3489. The namespace of the Secret resource being referred to.
  3490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3491. maxLength: 63
  3492. minLength: 1
  3493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3494. type: string
  3495. type: object
  3496. value:
  3497. description: Value can be specified directly to set a value without using a secret.
  3498. type: string
  3499. type: object
  3500. type: object
  3501. server:
  3502. description: Auth configures how API server works.
  3503. properties:
  3504. apiUrl:
  3505. type: string
  3506. apiVersion:
  3507. type: string
  3508. clientTimeOutSeconds:
  3509. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3510. type: integer
  3511. decrypt:
  3512. default: true
  3513. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3514. type: boolean
  3515. retrievalType:
  3516. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3517. type: string
  3518. separator:
  3519. description: A character that separates the folder names.
  3520. type: string
  3521. verifyCA:
  3522. type: boolean
  3523. required:
  3524. - apiUrl
  3525. - verifyCA
  3526. type: object
  3527. required:
  3528. - auth
  3529. - server
  3530. type: object
  3531. beyondtrustworkloadcredentials:
  3532. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3533. properties:
  3534. auth:
  3535. description: |-
  3536. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3537. Currently supports API key authentication via Kubernetes secret reference.
  3538. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3539. properties:
  3540. apikey:
  3541. description: |-
  3542. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3543. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3544. properties:
  3545. token:
  3546. description: |-
  3547. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3548. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3549. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3550. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3551. properties:
  3552. key:
  3553. description: |-
  3554. A key in the referenced Secret.
  3555. Some instances of this field may be defaulted, in others it may be required.
  3556. maxLength: 253
  3557. minLength: 1
  3558. pattern: ^[-._a-zA-Z0-9]+$
  3559. type: string
  3560. name:
  3561. description: The name of the Secret resource being referred to.
  3562. maxLength: 253
  3563. minLength: 1
  3564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3565. type: string
  3566. namespace:
  3567. description: |-
  3568. The namespace of the Secret resource being referred to.
  3569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3570. maxLength: 63
  3571. minLength: 1
  3572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3573. type: string
  3574. type: object
  3575. required:
  3576. - token
  3577. type: object
  3578. required:
  3579. - apikey
  3580. type: object
  3581. caBundle:
  3582. description: |-
  3583. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3584. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3585. If not set, the system's trusted root certificates are used.
  3586. format: byte
  3587. type: string
  3588. caProvider:
  3589. description: |-
  3590. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3591. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3592. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3593. properties:
  3594. key:
  3595. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3596. maxLength: 253
  3597. minLength: 1
  3598. pattern: ^[-._a-zA-Z0-9]+$
  3599. type: string
  3600. name:
  3601. description: The name of the object located at the provider type.
  3602. maxLength: 253
  3603. minLength: 1
  3604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3605. type: string
  3606. namespace:
  3607. description: |-
  3608. The namespace the Provider type is in.
  3609. Can only be defined when used in a ClusterSecretStore.
  3610. maxLength: 63
  3611. minLength: 1
  3612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3613. type: string
  3614. type:
  3615. description: The type of provider to use such as "Secret", or "ConfigMap".
  3616. enum:
  3617. - Secret
  3618. - ConfigMap
  3619. type: string
  3620. required:
  3621. - name
  3622. - type
  3623. type: object
  3624. folderPath:
  3625. description: |-
  3626. FolderPath specifies the default folder path for secret retrieval.
  3627. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3628. Example: "production/database" or "dev/api-keys"
  3629. Leave empty to retrieve secrets from the root folder.
  3630. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3631. type: string
  3632. server:
  3633. description: |-
  3634. Server configures the BeyondTrust Workload Credentials server connection details.
  3635. Includes the API URL and Site ID for your BeyondTrust instance.
  3636. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3637. properties:
  3638. apiUrl:
  3639. description: |-
  3640. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3641. This should be the full URL to your BeyondTrust instance.
  3642. Example: https://api.beyondtrust.io/siie
  3643. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3644. type: string
  3645. siteId:
  3646. description: |-
  3647. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3648. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3649. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3650. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3651. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3652. type: string
  3653. required:
  3654. - apiUrl
  3655. - siteId
  3656. type: object
  3657. required:
  3658. - auth
  3659. - server
  3660. type: object
  3661. bitwardensecretsmanager:
  3662. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3663. properties:
  3664. apiURL:
  3665. type: string
  3666. auth:
  3667. description: |-
  3668. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3669. Make sure that the token being used has permissions on the given secret.
  3670. properties:
  3671. secretRef:
  3672. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3673. properties:
  3674. credentials:
  3675. description: AccessToken used for the bitwarden instance.
  3676. properties:
  3677. key:
  3678. description: |-
  3679. A key in the referenced Secret.
  3680. Some instances of this field may be defaulted, in others it may be required.
  3681. maxLength: 253
  3682. minLength: 1
  3683. pattern: ^[-._a-zA-Z0-9]+$
  3684. type: string
  3685. name:
  3686. description: The name of the Secret resource being referred to.
  3687. maxLength: 253
  3688. minLength: 1
  3689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3690. type: string
  3691. namespace:
  3692. description: |-
  3693. The namespace of the Secret resource being referred to.
  3694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3695. maxLength: 63
  3696. minLength: 1
  3697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3698. type: string
  3699. type: object
  3700. required:
  3701. - credentials
  3702. type: object
  3703. required:
  3704. - secretRef
  3705. type: object
  3706. bitwardenServerSDKURL:
  3707. type: string
  3708. caBundle:
  3709. description: |-
  3710. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3711. can be performed.
  3712. type: string
  3713. caProvider:
  3714. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3715. properties:
  3716. key:
  3717. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3718. maxLength: 253
  3719. minLength: 1
  3720. pattern: ^[-._a-zA-Z0-9]+$
  3721. type: string
  3722. name:
  3723. description: The name of the object located at the provider type.
  3724. maxLength: 253
  3725. minLength: 1
  3726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3727. type: string
  3728. namespace:
  3729. description: |-
  3730. The namespace the Provider type is in.
  3731. Can only be defined when used in a ClusterSecretStore.
  3732. maxLength: 63
  3733. minLength: 1
  3734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3735. type: string
  3736. type:
  3737. description: The type of provider to use such as "Secret", or "ConfigMap".
  3738. enum:
  3739. - Secret
  3740. - ConfigMap
  3741. type: string
  3742. required:
  3743. - name
  3744. - type
  3745. type: object
  3746. identityURL:
  3747. type: string
  3748. organizationID:
  3749. description: OrganizationID determines which organization this secret store manages.
  3750. type: string
  3751. projectID:
  3752. description: ProjectID determines which project this secret store manages.
  3753. type: string
  3754. required:
  3755. - auth
  3756. - organizationID
  3757. - projectID
  3758. type: object
  3759. chef:
  3760. description: Chef configures this store to sync secrets with chef server
  3761. properties:
  3762. auth:
  3763. description: Auth defines the information necessary to authenticate against chef Server
  3764. properties:
  3765. secretRef:
  3766. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3767. properties:
  3768. privateKeySecretRef:
  3769. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3770. properties:
  3771. key:
  3772. description: |-
  3773. A key in the referenced Secret.
  3774. Some instances of this field may be defaulted, in others it may be required.
  3775. maxLength: 253
  3776. minLength: 1
  3777. pattern: ^[-._a-zA-Z0-9]+$
  3778. type: string
  3779. name:
  3780. description: The name of the Secret resource being referred to.
  3781. maxLength: 253
  3782. minLength: 1
  3783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3784. type: string
  3785. namespace:
  3786. description: |-
  3787. The namespace of the Secret resource being referred to.
  3788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3789. maxLength: 63
  3790. minLength: 1
  3791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3792. type: string
  3793. type: object
  3794. required:
  3795. - privateKeySecretRef
  3796. type: object
  3797. required:
  3798. - secretRef
  3799. type: object
  3800. serverUrl:
  3801. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3802. type: string
  3803. username:
  3804. description: UserName should be the user ID on the chef server
  3805. type: string
  3806. required:
  3807. - auth
  3808. - serverUrl
  3809. - username
  3810. type: object
  3811. cloudrusm:
  3812. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3813. properties:
  3814. auth:
  3815. description: CSMAuth contains a secretRef for credentials.
  3816. properties:
  3817. secretRef:
  3818. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3819. properties:
  3820. accessKeyIDSecretRef:
  3821. description: The AccessKeyID is used for authentication
  3822. properties:
  3823. key:
  3824. description: |-
  3825. A key in the referenced Secret.
  3826. Some instances of this field may be defaulted, in others it may be required.
  3827. maxLength: 253
  3828. minLength: 1
  3829. pattern: ^[-._a-zA-Z0-9]+$
  3830. type: string
  3831. name:
  3832. description: The name of the Secret resource being referred to.
  3833. maxLength: 253
  3834. minLength: 1
  3835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3836. type: string
  3837. namespace:
  3838. description: |-
  3839. The namespace of the Secret resource being referred to.
  3840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3841. maxLength: 63
  3842. minLength: 1
  3843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3844. type: string
  3845. type: object
  3846. accessKeySecretSecretRef:
  3847. description: The AccessKeySecret is used for authentication
  3848. properties:
  3849. key:
  3850. description: |-
  3851. A key in the referenced Secret.
  3852. Some instances of this field may be defaulted, in others it may be required.
  3853. maxLength: 253
  3854. minLength: 1
  3855. pattern: ^[-._a-zA-Z0-9]+$
  3856. type: string
  3857. name:
  3858. description: The name of the Secret resource being referred to.
  3859. maxLength: 253
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3862. type: string
  3863. namespace:
  3864. description: |-
  3865. The namespace of the Secret resource being referred to.
  3866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3867. maxLength: 63
  3868. minLength: 1
  3869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3870. type: string
  3871. type: object
  3872. required:
  3873. - accessKeyIDSecretRef
  3874. - accessKeySecretSecretRef
  3875. type: object
  3876. type: object
  3877. projectID:
  3878. description: ProjectID is the project, which the secrets are stored in.
  3879. type: string
  3880. required:
  3881. - auth
  3882. type: object
  3883. conjur:
  3884. description: Conjur configures this store to sync secrets using conjur provider
  3885. properties:
  3886. auth:
  3887. description: Defines authentication settings for connecting to Conjur.
  3888. maxProperties: 1
  3889. minProperties: 1
  3890. properties:
  3891. apikey:
  3892. description: Authenticates with Conjur using an API key.
  3893. properties:
  3894. account:
  3895. description: Account is the Conjur organization account name.
  3896. type: string
  3897. apiKeyRef:
  3898. description: |-
  3899. A reference to a specific 'key' containing the Conjur API key
  3900. within a Secret resource. In some instances, `key` is a required field.
  3901. properties:
  3902. key:
  3903. description: |-
  3904. A key in the referenced Secret.
  3905. Some instances of this field may be defaulted, in others it may be required.
  3906. maxLength: 253
  3907. minLength: 1
  3908. pattern: ^[-._a-zA-Z0-9]+$
  3909. type: string
  3910. name:
  3911. description: The name of the Secret resource being referred to.
  3912. maxLength: 253
  3913. minLength: 1
  3914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3915. type: string
  3916. namespace:
  3917. description: |-
  3918. The namespace of the Secret resource being referred to.
  3919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3920. maxLength: 63
  3921. minLength: 1
  3922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3923. type: string
  3924. type: object
  3925. userRef:
  3926. description: |-
  3927. A reference to a specific 'key' containing the Conjur username
  3928. within a Secret resource. In some instances, `key` is a required field.
  3929. properties:
  3930. key:
  3931. description: |-
  3932. A key in the referenced Secret.
  3933. Some instances of this field may be defaulted, in others it may be required.
  3934. maxLength: 253
  3935. minLength: 1
  3936. pattern: ^[-._a-zA-Z0-9]+$
  3937. type: string
  3938. name:
  3939. description: The name of the Secret resource being referred to.
  3940. maxLength: 253
  3941. minLength: 1
  3942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3943. type: string
  3944. namespace:
  3945. description: |-
  3946. The namespace of the Secret resource being referred to.
  3947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3948. maxLength: 63
  3949. minLength: 1
  3950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3951. type: string
  3952. type: object
  3953. required:
  3954. - account
  3955. - apiKeyRef
  3956. - userRef
  3957. type: object
  3958. cert:
  3959. description: Cert enables certificate-based authentication using a client certificate and key.
  3960. properties:
  3961. account:
  3962. description: Account is the Conjur organization account name.
  3963. type: string
  3964. clientCertRef:
  3965. description: |-
  3966. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3967. within a Secret resource. The certificate must be PEM-encoded.
  3968. properties:
  3969. key:
  3970. description: |-
  3971. A key in the referenced Secret.
  3972. Some instances of this field may be defaulted, in others it may be required.
  3973. maxLength: 253
  3974. minLength: 1
  3975. pattern: ^[-._a-zA-Z0-9]+$
  3976. type: string
  3977. name:
  3978. description: The name of the Secret resource being referred to.
  3979. maxLength: 253
  3980. minLength: 1
  3981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3982. type: string
  3983. namespace:
  3984. description: |-
  3985. The namespace of the Secret resource being referred to.
  3986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3987. maxLength: 63
  3988. minLength: 1
  3989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3990. type: string
  3991. type: object
  3992. clientKeyRef:
  3993. description: |-
  3994. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3995. within a Secret resource. The key must be PEM-encoded.
  3996. properties:
  3997. key:
  3998. description: |-
  3999. A key in the referenced Secret.
  4000. Some instances of this field may be defaulted, in others it may be required.
  4001. maxLength: 253
  4002. minLength: 1
  4003. pattern: ^[-._a-zA-Z0-9]+$
  4004. type: string
  4005. name:
  4006. description: The name of the Secret resource being referred to.
  4007. maxLength: 253
  4008. minLength: 1
  4009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4010. type: string
  4011. namespace:
  4012. description: |-
  4013. The namespace of the Secret resource being referred to.
  4014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4015. maxLength: 63
  4016. minLength: 1
  4017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4018. type: string
  4019. type: object
  4020. hostId:
  4021. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  4022. type: string
  4023. serviceID:
  4024. description: The conjur authn cert webservice id
  4025. type: string
  4026. required:
  4027. - account
  4028. - clientCertRef
  4029. - clientKeyRef
  4030. - serviceID
  4031. type: object
  4032. jwt:
  4033. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  4034. properties:
  4035. account:
  4036. description: Account is the Conjur organization account name.
  4037. type: string
  4038. hostId:
  4039. description: |-
  4040. Optional HostID for JWT authentication. This may be used depending
  4041. on how the Conjur JWT authenticator policy is configured.
  4042. type: string
  4043. secretRef:
  4044. description: |-
  4045. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  4046. authenticate with Conjur using the JWT authentication method.
  4047. properties:
  4048. key:
  4049. description: |-
  4050. A key in the referenced Secret.
  4051. Some instances of this field may be defaulted, in others it may be required.
  4052. maxLength: 253
  4053. minLength: 1
  4054. pattern: ^[-._a-zA-Z0-9]+$
  4055. type: string
  4056. name:
  4057. description: The name of the Secret resource being referred to.
  4058. maxLength: 253
  4059. minLength: 1
  4060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4061. type: string
  4062. namespace:
  4063. description: |-
  4064. The namespace of the Secret resource being referred to.
  4065. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4066. maxLength: 63
  4067. minLength: 1
  4068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4069. type: string
  4070. type: object
  4071. serviceAccountRef:
  4072. description: |-
  4073. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  4074. a token for with the `TokenRequest` API.
  4075. properties:
  4076. audiences:
  4077. description: |-
  4078. Audience specifies the `aud` claim for the service account token
  4079. Some providers automatically extend the audience field based on well-known annotations for workload
  4080. identity (e.g. IRSA or GCP Workload Identity)
  4081. items:
  4082. type: string
  4083. type: array
  4084. name:
  4085. description: The name of the ServiceAccount resource being referred to.
  4086. maxLength: 253
  4087. minLength: 1
  4088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4089. type: string
  4090. namespace:
  4091. description: |-
  4092. Namespace of the resource being referred to.
  4093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4094. maxLength: 63
  4095. minLength: 1
  4096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4097. type: string
  4098. required:
  4099. - name
  4100. type: object
  4101. serviceID:
  4102. description: The conjur authn jwt webservice id
  4103. type: string
  4104. required:
  4105. - account
  4106. - serviceID
  4107. type: object
  4108. type: object
  4109. caBundle:
  4110. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4111. type: string
  4112. caProvider:
  4113. description: |-
  4114. Used to provide custom certificate authority (CA) certificates
  4115. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4116. that contains a PEM-encoded certificate.
  4117. properties:
  4118. key:
  4119. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4120. maxLength: 253
  4121. minLength: 1
  4122. pattern: ^[-._a-zA-Z0-9]+$
  4123. type: string
  4124. name:
  4125. description: The name of the object located at the provider type.
  4126. maxLength: 253
  4127. minLength: 1
  4128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4129. type: string
  4130. namespace:
  4131. description: |-
  4132. The namespace the Provider type is in.
  4133. Can only be defined when used in a ClusterSecretStore.
  4134. maxLength: 63
  4135. minLength: 1
  4136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4137. type: string
  4138. type:
  4139. description: The type of provider to use such as "Secret", or "ConfigMap".
  4140. enum:
  4141. - Secret
  4142. - ConfigMap
  4143. type: string
  4144. required:
  4145. - name
  4146. - type
  4147. type: object
  4148. url:
  4149. description: URL is the endpoint of the Conjur instance.
  4150. type: string
  4151. required:
  4152. - auth
  4153. - url
  4154. type: object
  4155. crd:
  4156. description: |-
  4157. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4158. including both custom resources (CRDs) and core API resources. Resources are
  4159. selected by API group, version and kind, where group can be "" (empty string)
  4160. for core resources such as ConfigMap. Reading the core v1 Secret is
  4161. intentionally blocked — use the Kubernetes provider for that.
  4162. properties:
  4163. auth:
  4164. description: |-
  4165. Auth configures authentication to the Kubernetes API, same as the
  4166. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4167. maxProperties: 1
  4168. minProperties: 1
  4169. properties:
  4170. cert:
  4171. description: has both clientCert and clientKey as secretKeySelector
  4172. properties:
  4173. clientCert:
  4174. description: |-
  4175. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4176. In some instances, `key` is a required field.
  4177. properties:
  4178. key:
  4179. description: |-
  4180. A key in the referenced Secret.
  4181. Some instances of this field may be defaulted, in others it may be required.
  4182. maxLength: 253
  4183. minLength: 1
  4184. pattern: ^[-._a-zA-Z0-9]+$
  4185. type: string
  4186. name:
  4187. description: The name of the Secret resource being referred to.
  4188. maxLength: 253
  4189. minLength: 1
  4190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4191. type: string
  4192. namespace:
  4193. description: |-
  4194. The namespace of the Secret resource being referred to.
  4195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4196. maxLength: 63
  4197. minLength: 1
  4198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4199. type: string
  4200. type: object
  4201. clientKey:
  4202. description: |-
  4203. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4204. In some instances, `key` is a required field.
  4205. properties:
  4206. key:
  4207. description: |-
  4208. A key in the referenced Secret.
  4209. Some instances of this field may be defaulted, in others it may be required.
  4210. maxLength: 253
  4211. minLength: 1
  4212. pattern: ^[-._a-zA-Z0-9]+$
  4213. type: string
  4214. name:
  4215. description: The name of the Secret resource being referred to.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4219. type: string
  4220. namespace:
  4221. description: |-
  4222. The namespace of the Secret resource being referred to.
  4223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4224. maxLength: 63
  4225. minLength: 1
  4226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4227. type: string
  4228. type: object
  4229. required:
  4230. - clientCert
  4231. - clientKey
  4232. type: object
  4233. serviceAccount:
  4234. description: points to a service account that should be used for authentication
  4235. properties:
  4236. audiences:
  4237. description: |-
  4238. Audience specifies the `aud` claim for the service account token
  4239. Some providers automatically extend the audience field based on well-known annotations for workload
  4240. identity (e.g. IRSA or GCP Workload Identity)
  4241. items:
  4242. type: string
  4243. type: array
  4244. name:
  4245. description: The name of the ServiceAccount resource being referred to.
  4246. maxLength: 253
  4247. minLength: 1
  4248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4249. type: string
  4250. namespace:
  4251. description: |-
  4252. Namespace of the resource being referred to.
  4253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4254. maxLength: 63
  4255. minLength: 1
  4256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4257. type: string
  4258. required:
  4259. - name
  4260. type: object
  4261. token:
  4262. description: use static token to authenticate with
  4263. properties:
  4264. bearerToken:
  4265. description: |-
  4266. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4267. In some instances, `key` is a required field.
  4268. properties:
  4269. key:
  4270. description: |-
  4271. A key in the referenced Secret.
  4272. Some instances of this field may be defaulted, in others it may be required.
  4273. maxLength: 253
  4274. minLength: 1
  4275. pattern: ^[-._a-zA-Z0-9]+$
  4276. type: string
  4277. name:
  4278. description: The name of the Secret resource being referred to.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4282. type: string
  4283. namespace:
  4284. description: |-
  4285. The namespace of the Secret resource being referred to.
  4286. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4287. maxLength: 63
  4288. minLength: 1
  4289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4290. type: string
  4291. type: object
  4292. required:
  4293. - bearerToken
  4294. type: object
  4295. type: object
  4296. authRef:
  4297. description: |-
  4298. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4299. Kubernetes provider.
  4300. properties:
  4301. key:
  4302. description: |-
  4303. A key in the referenced Secret.
  4304. Some instances of this field may be defaulted, in others it may be required.
  4305. maxLength: 253
  4306. minLength: 1
  4307. pattern: ^[-._a-zA-Z0-9]+$
  4308. type: string
  4309. name:
  4310. description: The name of the Secret resource being referred to.
  4311. maxLength: 253
  4312. minLength: 1
  4313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4314. type: string
  4315. namespace:
  4316. description: |-
  4317. The namespace of the Secret resource being referred to.
  4318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4319. maxLength: 63
  4320. minLength: 1
  4321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4322. type: string
  4323. type: object
  4324. resource:
  4325. description: Resource identifies the CRD by its API group, version and kind.
  4326. properties:
  4327. group:
  4328. description: |-
  4329. Group is the API group of the resource. Use "" (empty string) for core
  4330. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4331. for a CRD. The field is required to be present in the manifest — write
  4332. `group: ""` explicitly for core resources so typos fail at admission
  4333. time rather than later at discovery.
  4334. type: string
  4335. kind:
  4336. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4337. minLength: 1
  4338. type: string
  4339. version:
  4340. description: Version is the API version of the resource (e.g. "v1alpha1").
  4341. minLength: 1
  4342. type: string
  4343. required:
  4344. - group
  4345. - kind
  4346. - version
  4347. type: object
  4348. server:
  4349. description: |-
  4350. Server configures the Kubernetes API address and TLS trust, same as the
  4351. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4352. properties:
  4353. caBundle:
  4354. description: CABundle is a base64-encoded CA certificate
  4355. format: byte
  4356. type: string
  4357. caProvider:
  4358. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4359. properties:
  4360. key:
  4361. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4362. maxLength: 253
  4363. minLength: 1
  4364. pattern: ^[-._a-zA-Z0-9]+$
  4365. type: string
  4366. name:
  4367. description: The name of the object located at the provider type.
  4368. maxLength: 253
  4369. minLength: 1
  4370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4371. type: string
  4372. namespace:
  4373. description: |-
  4374. The namespace the Provider type is in.
  4375. Can only be defined when used in a ClusterSecretStore.
  4376. maxLength: 63
  4377. minLength: 1
  4378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4379. type: string
  4380. type:
  4381. description: The type of provider to use such as "Secret", or "ConfigMap".
  4382. enum:
  4383. - Secret
  4384. - ConfigMap
  4385. type: string
  4386. required:
  4387. - name
  4388. - type
  4389. type: object
  4390. url:
  4391. default: kubernetes.default
  4392. description: configures the Kubernetes server Address.
  4393. type: string
  4394. type: object
  4395. whitelist:
  4396. description: |-
  4397. Whitelist optionally restricts which object names and requested properties
  4398. are allowed to be read.
  4399. properties:
  4400. rules:
  4401. description: |-
  4402. Rules is a list of allow rules. If rules are set, at least one rule must
  4403. match for a request to be allowed.
  4404. items:
  4405. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4406. properties:
  4407. name:
  4408. description: |-
  4409. Name is an optional regular expression matched against the bare object name.
  4410. For both SecretStore and ClusterSecretStore this is always the object name
  4411. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4412. type: string
  4413. namespace:
  4414. description: |-
  4415. Namespace is an optional regular expression matched against the namespace of
  4416. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4417. for SecretStore (where the namespace is fixed to the store namespace).
  4418. type: string
  4419. properties:
  4420. description: |-
  4421. Properties is an optional list of regular expressions matched against
  4422. requested property keys (for example: "spec.secretValue").
  4423. items:
  4424. type: string
  4425. type: array
  4426. type: object
  4427. type: array
  4428. type: object
  4429. required:
  4430. - resource
  4431. type: object
  4432. x-kubernetes-validations:
  4433. - message: one of auth or authRef is required
  4434. rule: has(self.auth) || has(self.authRef)
  4435. - message: at most one of the fields in [auth authRef] may be set
  4436. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4437. delinea:
  4438. description: |-
  4439. Delinea DevOps Secrets Vault
  4440. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4441. properties:
  4442. clientId:
  4443. description: ClientID is the non-secret part of the credential.
  4444. properties:
  4445. secretRef:
  4446. description: SecretRef references a key in a secret that will be used as value.
  4447. properties:
  4448. key:
  4449. description: |-
  4450. A key in the referenced Secret.
  4451. Some instances of this field may be defaulted, in others it may be required.
  4452. maxLength: 253
  4453. minLength: 1
  4454. pattern: ^[-._a-zA-Z0-9]+$
  4455. type: string
  4456. name:
  4457. description: The name of the Secret resource being referred to.
  4458. maxLength: 253
  4459. minLength: 1
  4460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4461. type: string
  4462. namespace:
  4463. description: |-
  4464. The namespace of the Secret resource being referred to.
  4465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4466. maxLength: 63
  4467. minLength: 1
  4468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4469. type: string
  4470. type: object
  4471. value:
  4472. description: Value can be specified directly to set a value without using a secret.
  4473. type: string
  4474. type: object
  4475. clientSecret:
  4476. description: ClientSecret is the secret part of the credential.
  4477. properties:
  4478. secretRef:
  4479. description: SecretRef references a key in a secret that will be used as value.
  4480. properties:
  4481. key:
  4482. description: |-
  4483. A key in the referenced Secret.
  4484. Some instances of this field may be defaulted, in others it may be required.
  4485. maxLength: 253
  4486. minLength: 1
  4487. pattern: ^[-._a-zA-Z0-9]+$
  4488. type: string
  4489. name:
  4490. description: The name of the Secret resource being referred to.
  4491. maxLength: 253
  4492. minLength: 1
  4493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4494. type: string
  4495. namespace:
  4496. description: |-
  4497. The namespace of the Secret resource being referred to.
  4498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4499. maxLength: 63
  4500. minLength: 1
  4501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4502. type: string
  4503. type: object
  4504. value:
  4505. description: Value can be specified directly to set a value without using a secret.
  4506. type: string
  4507. type: object
  4508. tenant:
  4509. description: Tenant is the chosen hostname / site name.
  4510. type: string
  4511. tld:
  4512. description: |-
  4513. TLD is based on the server location that was chosen during provisioning.
  4514. If unset, defaults to "com".
  4515. type: string
  4516. urlTemplate:
  4517. description: |-
  4518. URLTemplate
  4519. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4520. type: string
  4521. required:
  4522. - clientId
  4523. - clientSecret
  4524. - tenant
  4525. type: object
  4526. doppler:
  4527. description: Doppler configures this store to sync secrets using the Doppler provider
  4528. properties:
  4529. auth:
  4530. description: Auth configures how the Operator authenticates with the Doppler API
  4531. properties:
  4532. oidcConfig:
  4533. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4534. properties:
  4535. expirationSeconds:
  4536. default: 600
  4537. description: |-
  4538. ExpirationSeconds sets the ServiceAccount token validity duration.
  4539. Defaults to 10 minutes.
  4540. format: int64
  4541. type: integer
  4542. identity:
  4543. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4544. type: string
  4545. serviceAccountRef:
  4546. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4547. properties:
  4548. audiences:
  4549. description: |-
  4550. Audience specifies the `aud` claim for the service account token
  4551. Some providers automatically extend the audience field based on well-known annotations for workload
  4552. identity (e.g. IRSA or GCP Workload Identity)
  4553. items:
  4554. type: string
  4555. type: array
  4556. name:
  4557. description: The name of the ServiceAccount resource being referred to.
  4558. maxLength: 253
  4559. minLength: 1
  4560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4561. type: string
  4562. namespace:
  4563. description: |-
  4564. Namespace of the resource being referred to.
  4565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4566. maxLength: 63
  4567. minLength: 1
  4568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4569. type: string
  4570. required:
  4571. - name
  4572. type: object
  4573. required:
  4574. - identity
  4575. - serviceAccountRef
  4576. type: object
  4577. secretRef:
  4578. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4579. properties:
  4580. dopplerToken:
  4581. description: |-
  4582. The DopplerToken is used for authentication.
  4583. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4584. The Key attribute defaults to dopplerToken if not specified.
  4585. properties:
  4586. key:
  4587. description: |-
  4588. A key in the referenced Secret.
  4589. Some instances of this field may be defaulted, in others it may be required.
  4590. maxLength: 253
  4591. minLength: 1
  4592. pattern: ^[-._a-zA-Z0-9]+$
  4593. type: string
  4594. name:
  4595. description: The name of the Secret resource being referred to.
  4596. maxLength: 253
  4597. minLength: 1
  4598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4599. type: string
  4600. namespace:
  4601. description: |-
  4602. The namespace of the Secret resource being referred to.
  4603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4604. maxLength: 63
  4605. minLength: 1
  4606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4607. type: string
  4608. type: object
  4609. required:
  4610. - dopplerToken
  4611. type: object
  4612. type: object
  4613. x-kubernetes-validations:
  4614. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4615. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4616. config:
  4617. description: Doppler config (required if not using a Service Token)
  4618. type: string
  4619. format:
  4620. description: Format enables the downloading of secrets as a file (string)
  4621. enum:
  4622. - json
  4623. - dotnet-json
  4624. - env
  4625. - yaml
  4626. - docker
  4627. type: string
  4628. nameTransformer:
  4629. description: Environment variable compatible name transforms that change secret names to a different format
  4630. enum:
  4631. - upper-camel
  4632. - camel
  4633. - lower-snake
  4634. - tf-var
  4635. - dotnet-env
  4636. - lower-kebab
  4637. type: string
  4638. project:
  4639. description: Doppler project (required if not using a Service Token)
  4640. type: string
  4641. required:
  4642. - auth
  4643. type: object
  4644. dvls:
  4645. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4646. properties:
  4647. auth:
  4648. description: Auth defines the authentication method to use.
  4649. properties:
  4650. secretRef:
  4651. description: SecretRef contains the Application ID and Application Secret for authentication.
  4652. properties:
  4653. appId:
  4654. description: AppID is the reference to the secret containing the Application ID.
  4655. properties:
  4656. key:
  4657. description: |-
  4658. A key in the referenced Secret.
  4659. Some instances of this field may be defaulted, in others it may be required.
  4660. maxLength: 253
  4661. minLength: 1
  4662. pattern: ^[-._a-zA-Z0-9]+$
  4663. type: string
  4664. name:
  4665. description: The name of the Secret resource being referred to.
  4666. maxLength: 253
  4667. minLength: 1
  4668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4669. type: string
  4670. namespace:
  4671. description: |-
  4672. The namespace of the Secret resource being referred to.
  4673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4674. maxLength: 63
  4675. minLength: 1
  4676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4677. type: string
  4678. type: object
  4679. appSecret:
  4680. description: AppSecret is the reference to the secret containing the Application Secret.
  4681. properties:
  4682. key:
  4683. description: |-
  4684. A key in the referenced Secret.
  4685. Some instances of this field may be defaulted, in others it may be required.
  4686. maxLength: 253
  4687. minLength: 1
  4688. pattern: ^[-._a-zA-Z0-9]+$
  4689. type: string
  4690. name:
  4691. description: The name of the Secret resource being referred to.
  4692. maxLength: 253
  4693. minLength: 1
  4694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4695. type: string
  4696. namespace:
  4697. description: |-
  4698. The namespace of the Secret resource being referred to.
  4699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4700. maxLength: 63
  4701. minLength: 1
  4702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4703. type: string
  4704. type: object
  4705. required:
  4706. - appId
  4707. - appSecret
  4708. type: object
  4709. required:
  4710. - secretRef
  4711. type: object
  4712. insecure:
  4713. description: |-
  4714. Insecure allows connecting to DVLS over plain HTTP.
  4715. This is NOT RECOMMENDED for production use.
  4716. Set to true only if you understand the security implications.
  4717. type: boolean
  4718. serverUrl:
  4719. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4720. type: string
  4721. vault:
  4722. description: |-
  4723. Vault is the name or UUID of the vault to fetch secrets from.
  4724. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4725. type: string
  4726. required:
  4727. - auth
  4728. - serverUrl
  4729. type: object
  4730. fake:
  4731. description: Fake configures a store with static key/value pairs
  4732. properties:
  4733. data:
  4734. items:
  4735. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4736. properties:
  4737. key:
  4738. type: string
  4739. value:
  4740. type: string
  4741. version:
  4742. type: string
  4743. required:
  4744. - key
  4745. - value
  4746. type: object
  4747. type: array
  4748. validationResult:
  4749. description: ValidationResult is defined type for the number of validation results.
  4750. type: integer
  4751. required:
  4752. - data
  4753. type: object
  4754. fortanix:
  4755. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4756. properties:
  4757. apiKey:
  4758. description: APIKey is the API token to access SDKMS Applications.
  4759. properties:
  4760. secretRef:
  4761. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4762. properties:
  4763. key:
  4764. description: |-
  4765. A key in the referenced Secret.
  4766. Some instances of this field may be defaulted, in others it may be required.
  4767. maxLength: 253
  4768. minLength: 1
  4769. pattern: ^[-._a-zA-Z0-9]+$
  4770. type: string
  4771. name:
  4772. description: The name of the Secret resource being referred to.
  4773. maxLength: 253
  4774. minLength: 1
  4775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4776. type: string
  4777. namespace:
  4778. description: |-
  4779. The namespace of the Secret resource being referred to.
  4780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4781. maxLength: 63
  4782. minLength: 1
  4783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4784. type: string
  4785. type: object
  4786. type: object
  4787. apiUrl:
  4788. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4789. type: string
  4790. type: object
  4791. gcpsm:
  4792. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4793. properties:
  4794. auth:
  4795. description: Auth defines the information necessary to authenticate against GCP
  4796. properties:
  4797. secretRef:
  4798. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4799. properties:
  4800. secretAccessKeySecretRef:
  4801. description: The SecretAccessKey is used for authentication
  4802. properties:
  4803. key:
  4804. description: |-
  4805. A key in the referenced Secret.
  4806. Some instances of this field may be defaulted, in others it may be required.
  4807. maxLength: 253
  4808. minLength: 1
  4809. pattern: ^[-._a-zA-Z0-9]+$
  4810. type: string
  4811. name:
  4812. description: The name of the Secret resource being referred to.
  4813. maxLength: 253
  4814. minLength: 1
  4815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4816. type: string
  4817. namespace:
  4818. description: |-
  4819. The namespace of the Secret resource being referred to.
  4820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4821. maxLength: 63
  4822. minLength: 1
  4823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4824. type: string
  4825. type: object
  4826. type: object
  4827. workloadIdentity:
  4828. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4829. properties:
  4830. clusterLocation:
  4831. description: |-
  4832. ClusterLocation is the location of the cluster
  4833. If not specified, it fetches information from the metadata server
  4834. type: string
  4835. clusterName:
  4836. description: |-
  4837. ClusterName is the name of the cluster
  4838. If not specified, it fetches information from the metadata server
  4839. type: string
  4840. clusterProjectID:
  4841. description: |-
  4842. ClusterProjectID is the project ID of the cluster
  4843. If not specified, it fetches information from the metadata server
  4844. type: string
  4845. serviceAccountRef:
  4846. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4847. properties:
  4848. audiences:
  4849. description: |-
  4850. Audience specifies the `aud` claim for the service account token
  4851. Some providers automatically extend the audience field based on well-known annotations for workload
  4852. identity (e.g. IRSA or GCP Workload Identity)
  4853. items:
  4854. type: string
  4855. type: array
  4856. name:
  4857. description: The name of the ServiceAccount resource being referred to.
  4858. maxLength: 253
  4859. minLength: 1
  4860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4861. type: string
  4862. namespace:
  4863. description: |-
  4864. Namespace of the resource being referred to.
  4865. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4866. maxLength: 63
  4867. minLength: 1
  4868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4869. type: string
  4870. required:
  4871. - name
  4872. type: object
  4873. required:
  4874. - serviceAccountRef
  4875. type: object
  4876. workloadIdentityFederation:
  4877. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4878. properties:
  4879. audience:
  4880. description: |-
  4881. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4882. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4883. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4884. type: string
  4885. awsSecurityCredentials:
  4886. description: |-
  4887. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4888. when using the AWS metadata server is not an option.
  4889. properties:
  4890. awsCredentialsSecretRef:
  4891. description: |-
  4892. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4893. Secret should be created with below names for keys
  4894. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4895. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4896. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4897. properties:
  4898. name:
  4899. description: name of the secret.
  4900. maxLength: 253
  4901. minLength: 1
  4902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4903. type: string
  4904. namespace:
  4905. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4906. maxLength: 63
  4907. minLength: 1
  4908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4909. type: string
  4910. required:
  4911. - name
  4912. type: object
  4913. region:
  4914. description: region is for configuring the AWS region to be used.
  4915. example: ap-south-1
  4916. maxLength: 50
  4917. minLength: 1
  4918. pattern: ^[a-z0-9-]+$
  4919. type: string
  4920. required:
  4921. - awsCredentialsSecretRef
  4922. - region
  4923. type: object
  4924. credConfig:
  4925. description: |-
  4926. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4927. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4928. serviceAccountRef must be used by providing operators service account details.
  4929. properties:
  4930. key:
  4931. description: key name holding the external account credential config.
  4932. maxLength: 253
  4933. minLength: 1
  4934. pattern: ^[-._a-zA-Z0-9]+$
  4935. type: string
  4936. name:
  4937. description: name of the configmap.
  4938. maxLength: 253
  4939. minLength: 1
  4940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4941. type: string
  4942. namespace:
  4943. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4944. maxLength: 63
  4945. minLength: 1
  4946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4947. type: string
  4948. required:
  4949. - key
  4950. - name
  4951. type: object
  4952. externalTokenEndpoint:
  4953. description: |-
  4954. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4955. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4956. URL is having the expected value.
  4957. type: string
  4958. gcpServiceAccountEmail:
  4959. description: |-
  4960. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4961. after Workload Identity Federation. Use this to grant access through the service account's
  4962. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4963. service_account_impersonation_url in the external account JSON from credConfig;
  4964. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4965. on that ServiceAccount.
  4966. example: my-gsa@my-project.iam.gserviceaccount.com
  4967. minLength: 1
  4968. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4969. type: string
  4970. serviceAccountRef:
  4971. description: |-
  4972. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4973. when Kubernetes is configured as provider in workload identity pool.
  4974. properties:
  4975. audiences:
  4976. description: |-
  4977. Audience specifies the `aud` claim for the service account token
  4978. Some providers automatically extend the audience field based on well-known annotations for workload
  4979. identity (e.g. IRSA or GCP Workload Identity)
  4980. items:
  4981. type: string
  4982. type: array
  4983. name:
  4984. description: The name of the ServiceAccount resource being referred to.
  4985. maxLength: 253
  4986. minLength: 1
  4987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4988. type: string
  4989. namespace:
  4990. description: |-
  4991. Namespace of the resource being referred to.
  4992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4993. maxLength: 63
  4994. minLength: 1
  4995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4996. type: string
  4997. required:
  4998. - name
  4999. type: object
  5000. type: object
  5001. type: object
  5002. location:
  5003. description: Location optionally defines a location for a secret
  5004. type: string
  5005. projectID:
  5006. description: ProjectID project where secret is located
  5007. type: string
  5008. secretVersionSelectionPolicy:
  5009. default: LatestOrFail
  5010. description: |-
  5011. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  5012. when "latest" is disabled or destroyed.
  5013. Possible values are:
  5014. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  5015. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  5016. type: string
  5017. type: object
  5018. github:
  5019. description: |-
  5020. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  5021. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  5022. properties:
  5023. appID:
  5024. description: appID specifies the Github APP that will be used to authenticate the client
  5025. format: int64
  5026. type: integer
  5027. auth:
  5028. description: auth configures how secret-manager authenticates with a Github instance.
  5029. properties:
  5030. privateKey:
  5031. description: |-
  5032. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5033. In some instances, `key` is a required field.
  5034. properties:
  5035. key:
  5036. description: |-
  5037. A key in the referenced Secret.
  5038. Some instances of this field may be defaulted, in others it may be required.
  5039. maxLength: 253
  5040. minLength: 1
  5041. pattern: ^[-._a-zA-Z0-9]+$
  5042. type: string
  5043. name:
  5044. description: The name of the Secret resource being referred to.
  5045. maxLength: 253
  5046. minLength: 1
  5047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5048. type: string
  5049. namespace:
  5050. description: |-
  5051. The namespace of the Secret resource being referred to.
  5052. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5053. maxLength: 63
  5054. minLength: 1
  5055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5056. type: string
  5057. type: object
  5058. required:
  5059. - privateKey
  5060. type: object
  5061. environment:
  5062. description: environment will be used to fetch secrets from a particular environment within a github repository
  5063. type: string
  5064. installationID:
  5065. description: installationID specifies the Github APP installation that will be used to authenticate the client
  5066. format: int64
  5067. type: integer
  5068. orgSecretVisibility:
  5069. description: |-
  5070. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  5071. Valid values are "all" or "private".
  5072. When unset, new secrets are created with visibility "all" and existing secrets preserve
  5073. whatever visibility they already have in GitHub.
  5074. enum:
  5075. - all
  5076. - private
  5077. type: string
  5078. organization:
  5079. description: organization will be used to fetch secrets from the Github organization
  5080. type: string
  5081. repository:
  5082. description: repository will be used to fetch secrets from the Github repository within an organization
  5083. type: string
  5084. secretType:
  5085. default: Actions
  5086. description: |-
  5087. secretType specifies which GitHub secret service to use.
  5088. Defaults to Actions for backwards compatibility.
  5089. enum:
  5090. - Actions
  5091. - Dependabot
  5092. type: string
  5093. uploadURL:
  5094. description: Upload URL for enterprise instances. Default to URL.
  5095. type: string
  5096. url:
  5097. default: https://github.com/
  5098. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5099. type: string
  5100. required:
  5101. - appID
  5102. - auth
  5103. - installationID
  5104. - organization
  5105. type: object
  5106. x-kubernetes-validations:
  5107. - message: Dependabot secrets do not support environments
  5108. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  5109. gitlab:
  5110. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5111. properties:
  5112. auth:
  5113. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5114. properties:
  5115. SecretRef:
  5116. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5117. properties:
  5118. accessToken:
  5119. description: AccessToken is used for authentication.
  5120. properties:
  5121. key:
  5122. description: |-
  5123. A key in the referenced Secret.
  5124. Some instances of this field may be defaulted, in others it may be required.
  5125. maxLength: 253
  5126. minLength: 1
  5127. pattern: ^[-._a-zA-Z0-9]+$
  5128. type: string
  5129. name:
  5130. description: The name of the Secret resource being referred to.
  5131. maxLength: 253
  5132. minLength: 1
  5133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5134. type: string
  5135. namespace:
  5136. description: |-
  5137. The namespace of the Secret resource being referred to.
  5138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5139. maxLength: 63
  5140. minLength: 1
  5141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5142. type: string
  5143. type: object
  5144. type: object
  5145. required:
  5146. - SecretRef
  5147. type: object
  5148. caBundle:
  5149. description: |-
  5150. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5151. can be performed.
  5152. format: byte
  5153. type: string
  5154. caProvider:
  5155. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5156. properties:
  5157. key:
  5158. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5159. maxLength: 253
  5160. minLength: 1
  5161. pattern: ^[-._a-zA-Z0-9]+$
  5162. type: string
  5163. name:
  5164. description: The name of the object located at the provider type.
  5165. maxLength: 253
  5166. minLength: 1
  5167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5168. type: string
  5169. namespace:
  5170. description: |-
  5171. The namespace the Provider type is in.
  5172. Can only be defined when used in a ClusterSecretStore.
  5173. maxLength: 63
  5174. minLength: 1
  5175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5176. type: string
  5177. type:
  5178. description: The type of provider to use such as "Secret", or "ConfigMap".
  5179. enum:
  5180. - Secret
  5181. - ConfigMap
  5182. type: string
  5183. required:
  5184. - name
  5185. - type
  5186. type: object
  5187. environment:
  5188. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5189. type: string
  5190. groupIDs:
  5191. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5192. items:
  5193. type: string
  5194. type: array
  5195. inheritFromGroups:
  5196. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5197. type: boolean
  5198. projectID:
  5199. description: ProjectID specifies a project where secrets are located.
  5200. type: string
  5201. url:
  5202. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5203. type: string
  5204. required:
  5205. - auth
  5206. type: object
  5207. ibm:
  5208. description: IBM configures this store to sync secrets using IBM Cloud provider
  5209. properties:
  5210. auth:
  5211. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5212. maxProperties: 1
  5213. minProperties: 1
  5214. properties:
  5215. containerAuth:
  5216. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5217. properties:
  5218. iamEndpoint:
  5219. type: string
  5220. profile:
  5221. description: the IBM Trusted Profile
  5222. type: string
  5223. tokenLocation:
  5224. description: Location the token is mounted on the pod
  5225. type: string
  5226. required:
  5227. - profile
  5228. type: object
  5229. secretRef:
  5230. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5231. properties:
  5232. iamEndpoint:
  5233. description: The IAM endpoint used to obain a token
  5234. type: string
  5235. secretApiKeySecretRef:
  5236. description: The SecretAccessKey is used for authentication
  5237. properties:
  5238. key:
  5239. description: |-
  5240. A key in the referenced Secret.
  5241. Some instances of this field may be defaulted, in others it may be required.
  5242. maxLength: 253
  5243. minLength: 1
  5244. pattern: ^[-._a-zA-Z0-9]+$
  5245. type: string
  5246. name:
  5247. description: The name of the Secret resource being referred to.
  5248. maxLength: 253
  5249. minLength: 1
  5250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5251. type: string
  5252. namespace:
  5253. description: |-
  5254. The namespace of the Secret resource being referred to.
  5255. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5256. maxLength: 63
  5257. minLength: 1
  5258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5259. type: string
  5260. type: object
  5261. type: object
  5262. type: object
  5263. serviceUrl:
  5264. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5265. type: string
  5266. required:
  5267. - auth
  5268. type: object
  5269. infisical:
  5270. description: Infisical configures this store to sync secrets using the Infisical provider
  5271. properties:
  5272. auth:
  5273. description: Auth configures how the Operator authenticates with the Infisical API
  5274. properties:
  5275. awsAuthCredentials:
  5276. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5277. properties:
  5278. identityId:
  5279. description: |-
  5280. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5281. In some instances, `key` is a required field.
  5282. properties:
  5283. key:
  5284. description: |-
  5285. A key in the referenced Secret.
  5286. Some instances of this field may be defaulted, in others it may be required.
  5287. maxLength: 253
  5288. minLength: 1
  5289. pattern: ^[-._a-zA-Z0-9]+$
  5290. type: string
  5291. name:
  5292. description: The name of the Secret resource being referred to.
  5293. maxLength: 253
  5294. minLength: 1
  5295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5296. type: string
  5297. namespace:
  5298. description: |-
  5299. The namespace of the Secret resource being referred to.
  5300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5301. maxLength: 63
  5302. minLength: 1
  5303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5304. type: string
  5305. type: object
  5306. required:
  5307. - identityId
  5308. type: object
  5309. azureAuthCredentials:
  5310. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5311. properties:
  5312. identityId:
  5313. description: |-
  5314. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5315. In some instances, `key` is a required field.
  5316. properties:
  5317. key:
  5318. description: |-
  5319. A key in the referenced Secret.
  5320. Some instances of this field may be defaulted, in others it may be required.
  5321. maxLength: 253
  5322. minLength: 1
  5323. pattern: ^[-._a-zA-Z0-9]+$
  5324. type: string
  5325. name:
  5326. description: The name of the Secret resource being referred to.
  5327. maxLength: 253
  5328. minLength: 1
  5329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5330. type: string
  5331. namespace:
  5332. description: |-
  5333. The namespace of the Secret resource being referred to.
  5334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5335. maxLength: 63
  5336. minLength: 1
  5337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5338. type: string
  5339. type: object
  5340. resource:
  5341. description: |-
  5342. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5343. In some instances, `key` is a required field.
  5344. properties:
  5345. key:
  5346. description: |-
  5347. A key in the referenced Secret.
  5348. Some instances of this field may be defaulted, in others it may be required.
  5349. maxLength: 253
  5350. minLength: 1
  5351. pattern: ^[-._a-zA-Z0-9]+$
  5352. type: string
  5353. name:
  5354. description: The name of the Secret resource being referred to.
  5355. maxLength: 253
  5356. minLength: 1
  5357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5358. type: string
  5359. namespace:
  5360. description: |-
  5361. The namespace of the Secret resource being referred to.
  5362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5363. maxLength: 63
  5364. minLength: 1
  5365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5366. type: string
  5367. type: object
  5368. required:
  5369. - identityId
  5370. type: object
  5371. gcpIamAuthCredentials:
  5372. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5373. properties:
  5374. identityId:
  5375. description: |-
  5376. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5377. In some instances, `key` is a required field.
  5378. properties:
  5379. key:
  5380. description: |-
  5381. A key in the referenced Secret.
  5382. Some instances of this field may be defaulted, in others it may be required.
  5383. maxLength: 253
  5384. minLength: 1
  5385. pattern: ^[-._a-zA-Z0-9]+$
  5386. type: string
  5387. name:
  5388. description: The name of the Secret resource being referred to.
  5389. maxLength: 253
  5390. minLength: 1
  5391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5392. type: string
  5393. namespace:
  5394. description: |-
  5395. The namespace of the Secret resource being referred to.
  5396. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5397. maxLength: 63
  5398. minLength: 1
  5399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5400. type: string
  5401. type: object
  5402. serviceAccountKeyFilePath:
  5403. description: |-
  5404. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5405. In some instances, `key` is a required field.
  5406. properties:
  5407. key:
  5408. description: |-
  5409. A key in the referenced Secret.
  5410. Some instances of this field may be defaulted, in others it may be required.
  5411. maxLength: 253
  5412. minLength: 1
  5413. pattern: ^[-._a-zA-Z0-9]+$
  5414. type: string
  5415. name:
  5416. description: The name of the Secret resource being referred to.
  5417. maxLength: 253
  5418. minLength: 1
  5419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5420. type: string
  5421. namespace:
  5422. description: |-
  5423. The namespace of the Secret resource being referred to.
  5424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5425. maxLength: 63
  5426. minLength: 1
  5427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5428. type: string
  5429. type: object
  5430. required:
  5431. - identityId
  5432. - serviceAccountKeyFilePath
  5433. type: object
  5434. gcpIdTokenAuthCredentials:
  5435. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5436. properties:
  5437. identityId:
  5438. description: |-
  5439. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5440. In some instances, `key` is a required field.
  5441. properties:
  5442. key:
  5443. description: |-
  5444. A key in the referenced Secret.
  5445. Some instances of this field may be defaulted, in others it may be required.
  5446. maxLength: 253
  5447. minLength: 1
  5448. pattern: ^[-._a-zA-Z0-9]+$
  5449. type: string
  5450. name:
  5451. description: The name of the Secret resource being referred to.
  5452. maxLength: 253
  5453. minLength: 1
  5454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5455. type: string
  5456. namespace:
  5457. description: |-
  5458. The namespace of the Secret resource being referred to.
  5459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5460. maxLength: 63
  5461. minLength: 1
  5462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5463. type: string
  5464. type: object
  5465. required:
  5466. - identityId
  5467. type: object
  5468. jwtAuthCredentials:
  5469. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5470. properties:
  5471. identityId:
  5472. description: |-
  5473. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5474. In some instances, `key` is a required field.
  5475. properties:
  5476. key:
  5477. description: |-
  5478. A key in the referenced Secret.
  5479. Some instances of this field may be defaulted, in others it may be required.
  5480. maxLength: 253
  5481. minLength: 1
  5482. pattern: ^[-._a-zA-Z0-9]+$
  5483. type: string
  5484. name:
  5485. description: The name of the Secret resource being referred to.
  5486. maxLength: 253
  5487. minLength: 1
  5488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5489. type: string
  5490. namespace:
  5491. description: |-
  5492. The namespace of the Secret resource being referred to.
  5493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5494. maxLength: 63
  5495. minLength: 1
  5496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5497. type: string
  5498. type: object
  5499. jwt:
  5500. description: |-
  5501. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5502. In some instances, `key` is a required field.
  5503. properties:
  5504. key:
  5505. description: |-
  5506. A key in the referenced Secret.
  5507. Some instances of this field may be defaulted, in others it may be required.
  5508. maxLength: 253
  5509. minLength: 1
  5510. pattern: ^[-._a-zA-Z0-9]+$
  5511. type: string
  5512. name:
  5513. description: The name of the Secret resource being referred to.
  5514. maxLength: 253
  5515. minLength: 1
  5516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5517. type: string
  5518. namespace:
  5519. description: |-
  5520. The namespace of the Secret resource being referred to.
  5521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5522. maxLength: 63
  5523. minLength: 1
  5524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5525. type: string
  5526. type: object
  5527. required:
  5528. - identityId
  5529. - jwt
  5530. type: object
  5531. kubernetesAuthCredentials:
  5532. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5533. properties:
  5534. identityId:
  5535. description: |-
  5536. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5537. In some instances, `key` is a required field.
  5538. properties:
  5539. key:
  5540. description: |-
  5541. A key in the referenced Secret.
  5542. Some instances of this field may be defaulted, in others it may be required.
  5543. maxLength: 253
  5544. minLength: 1
  5545. pattern: ^[-._a-zA-Z0-9]+$
  5546. type: string
  5547. name:
  5548. description: The name of the Secret resource being referred to.
  5549. maxLength: 253
  5550. minLength: 1
  5551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5552. type: string
  5553. namespace:
  5554. description: |-
  5555. The namespace of the Secret resource being referred to.
  5556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5557. maxLength: 63
  5558. minLength: 1
  5559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5560. type: string
  5561. type: object
  5562. serviceAccountTokenPath:
  5563. description: |-
  5564. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5565. In some instances, `key` is a required field.
  5566. properties:
  5567. key:
  5568. description: |-
  5569. A key in the referenced Secret.
  5570. Some instances of this field may be defaulted, in others it may be required.
  5571. maxLength: 253
  5572. minLength: 1
  5573. pattern: ^[-._a-zA-Z0-9]+$
  5574. type: string
  5575. name:
  5576. description: The name of the Secret resource being referred to.
  5577. maxLength: 253
  5578. minLength: 1
  5579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5580. type: string
  5581. namespace:
  5582. description: |-
  5583. The namespace of the Secret resource being referred to.
  5584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5585. maxLength: 63
  5586. minLength: 1
  5587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5588. type: string
  5589. type: object
  5590. required:
  5591. - identityId
  5592. type: object
  5593. ldapAuthCredentials:
  5594. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5595. properties:
  5596. identityId:
  5597. description: |-
  5598. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5599. In some instances, `key` is a required field.
  5600. properties:
  5601. key:
  5602. description: |-
  5603. A key in the referenced Secret.
  5604. Some instances of this field may be defaulted, in others it may be required.
  5605. maxLength: 253
  5606. minLength: 1
  5607. pattern: ^[-._a-zA-Z0-9]+$
  5608. type: string
  5609. name:
  5610. description: The name of the Secret resource being referred to.
  5611. maxLength: 253
  5612. minLength: 1
  5613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5614. type: string
  5615. namespace:
  5616. description: |-
  5617. The namespace of the Secret resource being referred to.
  5618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5619. maxLength: 63
  5620. minLength: 1
  5621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5622. type: string
  5623. type: object
  5624. ldapPassword:
  5625. description: |-
  5626. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5627. In some instances, `key` is a required field.
  5628. properties:
  5629. key:
  5630. description: |-
  5631. A key in the referenced Secret.
  5632. Some instances of this field may be defaulted, in others it may be required.
  5633. maxLength: 253
  5634. minLength: 1
  5635. pattern: ^[-._a-zA-Z0-9]+$
  5636. type: string
  5637. name:
  5638. description: The name of the Secret resource being referred to.
  5639. maxLength: 253
  5640. minLength: 1
  5641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5642. type: string
  5643. namespace:
  5644. description: |-
  5645. The namespace of the Secret resource being referred to.
  5646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5647. maxLength: 63
  5648. minLength: 1
  5649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5650. type: string
  5651. type: object
  5652. ldapUsername:
  5653. description: |-
  5654. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5655. In some instances, `key` is a required field.
  5656. properties:
  5657. key:
  5658. description: |-
  5659. A key in the referenced Secret.
  5660. Some instances of this field may be defaulted, in others it may be required.
  5661. maxLength: 253
  5662. minLength: 1
  5663. pattern: ^[-._a-zA-Z0-9]+$
  5664. type: string
  5665. name:
  5666. description: The name of the Secret resource being referred to.
  5667. maxLength: 253
  5668. minLength: 1
  5669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5670. type: string
  5671. namespace:
  5672. description: |-
  5673. The namespace of the Secret resource being referred to.
  5674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5675. maxLength: 63
  5676. minLength: 1
  5677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5678. type: string
  5679. type: object
  5680. required:
  5681. - identityId
  5682. - ldapPassword
  5683. - ldapUsername
  5684. type: object
  5685. ociAuthCredentials:
  5686. description: OciAuthCredentials represents the credentials for OCI authentication.
  5687. properties:
  5688. fingerprint:
  5689. description: |-
  5690. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5691. In some instances, `key` is a required field.
  5692. properties:
  5693. key:
  5694. description: |-
  5695. A key in the referenced Secret.
  5696. Some instances of this field may be defaulted, in others it may be required.
  5697. maxLength: 253
  5698. minLength: 1
  5699. pattern: ^[-._a-zA-Z0-9]+$
  5700. type: string
  5701. name:
  5702. description: The name of the Secret resource being referred to.
  5703. maxLength: 253
  5704. minLength: 1
  5705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5706. type: string
  5707. namespace:
  5708. description: |-
  5709. The namespace of the Secret resource being referred to.
  5710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5711. maxLength: 63
  5712. minLength: 1
  5713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5714. type: string
  5715. type: object
  5716. identityId:
  5717. description: |-
  5718. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5719. In some instances, `key` is a required field.
  5720. properties:
  5721. key:
  5722. description: |-
  5723. A key in the referenced Secret.
  5724. Some instances of this field may be defaulted, in others it may be required.
  5725. maxLength: 253
  5726. minLength: 1
  5727. pattern: ^[-._a-zA-Z0-9]+$
  5728. type: string
  5729. name:
  5730. description: The name of the Secret resource being referred to.
  5731. maxLength: 253
  5732. minLength: 1
  5733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5734. type: string
  5735. namespace:
  5736. description: |-
  5737. The namespace of the Secret resource being referred to.
  5738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5739. maxLength: 63
  5740. minLength: 1
  5741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5742. type: string
  5743. type: object
  5744. privateKey:
  5745. description: |-
  5746. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5747. In some instances, `key` is a required field.
  5748. properties:
  5749. key:
  5750. description: |-
  5751. A key in the referenced Secret.
  5752. Some instances of this field may be defaulted, in others it may be required.
  5753. maxLength: 253
  5754. minLength: 1
  5755. pattern: ^[-._a-zA-Z0-9]+$
  5756. type: string
  5757. name:
  5758. description: The name of the Secret resource being referred to.
  5759. maxLength: 253
  5760. minLength: 1
  5761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5762. type: string
  5763. namespace:
  5764. description: |-
  5765. The namespace of the Secret resource being referred to.
  5766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5767. maxLength: 63
  5768. minLength: 1
  5769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5770. type: string
  5771. type: object
  5772. privateKeyPassphrase:
  5773. description: |-
  5774. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5775. In some instances, `key` is a required field.
  5776. properties:
  5777. key:
  5778. description: |-
  5779. A key in the referenced Secret.
  5780. Some instances of this field may be defaulted, in others it may be required.
  5781. maxLength: 253
  5782. minLength: 1
  5783. pattern: ^[-._a-zA-Z0-9]+$
  5784. type: string
  5785. name:
  5786. description: The name of the Secret resource being referred to.
  5787. maxLength: 253
  5788. minLength: 1
  5789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5790. type: string
  5791. namespace:
  5792. description: |-
  5793. The namespace of the Secret resource being referred to.
  5794. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5795. maxLength: 63
  5796. minLength: 1
  5797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5798. type: string
  5799. type: object
  5800. region:
  5801. description: |-
  5802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5803. In some instances, `key` is a required field.
  5804. properties:
  5805. key:
  5806. description: |-
  5807. A key in the referenced Secret.
  5808. Some instances of this field may be defaulted, in others it may be required.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[-._a-zA-Z0-9]+$
  5812. type: string
  5813. name:
  5814. description: The name of the Secret resource being referred to.
  5815. maxLength: 253
  5816. minLength: 1
  5817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5818. type: string
  5819. namespace:
  5820. description: |-
  5821. The namespace of the Secret resource being referred to.
  5822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5823. maxLength: 63
  5824. minLength: 1
  5825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5826. type: string
  5827. type: object
  5828. tenancyId:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. userId:
  5857. description: |-
  5858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5859. In some instances, `key` is a required field.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. required:
  5885. - fingerprint
  5886. - identityId
  5887. - privateKey
  5888. - region
  5889. - tenancyId
  5890. - userId
  5891. type: object
  5892. tokenAuthCredentials:
  5893. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5894. properties:
  5895. accessToken:
  5896. description: |-
  5897. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5898. In some instances, `key` is a required field.
  5899. properties:
  5900. key:
  5901. description: |-
  5902. A key in the referenced Secret.
  5903. Some instances of this field may be defaulted, in others it may be required.
  5904. maxLength: 253
  5905. minLength: 1
  5906. pattern: ^[-._a-zA-Z0-9]+$
  5907. type: string
  5908. name:
  5909. description: The name of the Secret resource being referred to.
  5910. maxLength: 253
  5911. minLength: 1
  5912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5913. type: string
  5914. namespace:
  5915. description: |-
  5916. The namespace of the Secret resource being referred to.
  5917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5918. maxLength: 63
  5919. minLength: 1
  5920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5921. type: string
  5922. type: object
  5923. required:
  5924. - accessToken
  5925. type: object
  5926. universalAuthCredentials:
  5927. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5928. properties:
  5929. clientId:
  5930. description: |-
  5931. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5932. In some instances, `key` is a required field.
  5933. properties:
  5934. key:
  5935. description: |-
  5936. A key in the referenced Secret.
  5937. Some instances of this field may be defaulted, in others it may be required.
  5938. maxLength: 253
  5939. minLength: 1
  5940. pattern: ^[-._a-zA-Z0-9]+$
  5941. type: string
  5942. name:
  5943. description: The name of the Secret resource being referred to.
  5944. maxLength: 253
  5945. minLength: 1
  5946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5947. type: string
  5948. namespace:
  5949. description: |-
  5950. The namespace of the Secret resource being referred to.
  5951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5952. maxLength: 63
  5953. minLength: 1
  5954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5955. type: string
  5956. type: object
  5957. clientSecret:
  5958. description: |-
  5959. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5960. In some instances, `key` is a required field.
  5961. properties:
  5962. key:
  5963. description: |-
  5964. A key in the referenced Secret.
  5965. Some instances of this field may be defaulted, in others it may be required.
  5966. maxLength: 253
  5967. minLength: 1
  5968. pattern: ^[-._a-zA-Z0-9]+$
  5969. type: string
  5970. name:
  5971. description: The name of the Secret resource being referred to.
  5972. maxLength: 253
  5973. minLength: 1
  5974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5975. type: string
  5976. namespace:
  5977. description: |-
  5978. The namespace of the Secret resource being referred to.
  5979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5980. maxLength: 63
  5981. minLength: 1
  5982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5983. type: string
  5984. type: object
  5985. required:
  5986. - clientId
  5987. - clientSecret
  5988. type: object
  5989. type: object
  5990. caBundle:
  5991. description: |-
  5992. CABundle is a PEM-encoded CA certificate bundle used to validate
  5993. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5994. format: byte
  5995. type: string
  5996. caProvider:
  5997. description: |-
  5998. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5999. The certificate is used to validate the Infisical server's TLS certificate.
  6000. Mutually exclusive with CABundle.
  6001. properties:
  6002. key:
  6003. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6004. maxLength: 253
  6005. minLength: 1
  6006. pattern: ^[-._a-zA-Z0-9]+$
  6007. type: string
  6008. name:
  6009. description: The name of the object located at the provider type.
  6010. maxLength: 253
  6011. minLength: 1
  6012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6013. type: string
  6014. namespace:
  6015. description: |-
  6016. The namespace the Provider type is in.
  6017. Can only be defined when used in a ClusterSecretStore.
  6018. maxLength: 63
  6019. minLength: 1
  6020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6021. type: string
  6022. type:
  6023. description: The type of provider to use such as "Secret", or "ConfigMap".
  6024. enum:
  6025. - Secret
  6026. - ConfigMap
  6027. type: string
  6028. required:
  6029. - name
  6030. - type
  6031. type: object
  6032. hostAPI:
  6033. default: https://app.infisical.com/api
  6034. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  6035. type: string
  6036. secretsScope:
  6037. description: SecretsScope defines the scope of the secrets within the workspace
  6038. properties:
  6039. environmentSlug:
  6040. description: EnvironmentSlug is the required slug identifier for the environment.
  6041. type: string
  6042. expandSecretReferences:
  6043. default: true
  6044. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  6045. type: boolean
  6046. organizationSlug:
  6047. description: |-
  6048. OrganizationSlug is the optional slug that identifies the organization that will be used
  6049. during authentication. Useful for sub-organization setups
  6050. type: string
  6051. projectSlug:
  6052. description: ProjectSlug is the required slug identifier for the project.
  6053. type: string
  6054. recursive:
  6055. default: false
  6056. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  6057. type: boolean
  6058. secretsPath:
  6059. default: /
  6060. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  6061. type: string
  6062. required:
  6063. - environmentSlug
  6064. - projectSlug
  6065. type: object
  6066. required:
  6067. - auth
  6068. - secretsScope
  6069. type: object
  6070. keepersecurity:
  6071. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  6072. properties:
  6073. authRef:
  6074. description: |-
  6075. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6076. In some instances, `key` is a required field.
  6077. properties:
  6078. key:
  6079. description: |-
  6080. A key in the referenced Secret.
  6081. Some instances of this field may be defaulted, in others it may be required.
  6082. maxLength: 253
  6083. minLength: 1
  6084. pattern: ^[-._a-zA-Z0-9]+$
  6085. type: string
  6086. name:
  6087. description: The name of the Secret resource being referred to.
  6088. maxLength: 253
  6089. minLength: 1
  6090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6091. type: string
  6092. namespace:
  6093. description: |-
  6094. The namespace of the Secret resource being referred to.
  6095. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6096. maxLength: 63
  6097. minLength: 1
  6098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6099. type: string
  6100. type: object
  6101. folderID:
  6102. type: string
  6103. getByTitleFallback:
  6104. type: boolean
  6105. required:
  6106. - authRef
  6107. - folderID
  6108. type: object
  6109. kubernetes:
  6110. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6111. properties:
  6112. auth:
  6113. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6114. maxProperties: 1
  6115. minProperties: 1
  6116. properties:
  6117. cert:
  6118. description: has both clientCert and clientKey as secretKeySelector
  6119. properties:
  6120. clientCert:
  6121. description: |-
  6122. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6123. In some instances, `key` is a required field.
  6124. properties:
  6125. key:
  6126. description: |-
  6127. A key in the referenced Secret.
  6128. Some instances of this field may be defaulted, in others it may be required.
  6129. maxLength: 253
  6130. minLength: 1
  6131. pattern: ^[-._a-zA-Z0-9]+$
  6132. type: string
  6133. name:
  6134. description: The name of the Secret resource being referred to.
  6135. maxLength: 253
  6136. minLength: 1
  6137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6138. type: string
  6139. namespace:
  6140. description: |-
  6141. The namespace of the Secret resource being referred to.
  6142. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6143. maxLength: 63
  6144. minLength: 1
  6145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6146. type: string
  6147. type: object
  6148. clientKey:
  6149. description: |-
  6150. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6151. In some instances, `key` is a required field.
  6152. properties:
  6153. key:
  6154. description: |-
  6155. A key in the referenced Secret.
  6156. Some instances of this field may be defaulted, in others it may be required.
  6157. maxLength: 253
  6158. minLength: 1
  6159. pattern: ^[-._a-zA-Z0-9]+$
  6160. type: string
  6161. name:
  6162. description: The name of the Secret resource being referred to.
  6163. maxLength: 253
  6164. minLength: 1
  6165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6166. type: string
  6167. namespace:
  6168. description: |-
  6169. The namespace of the Secret resource being referred to.
  6170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6171. maxLength: 63
  6172. minLength: 1
  6173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6174. type: string
  6175. type: object
  6176. required:
  6177. - clientCert
  6178. - clientKey
  6179. type: object
  6180. serviceAccount:
  6181. description: points to a service account that should be used for authentication
  6182. properties:
  6183. audiences:
  6184. description: |-
  6185. Audience specifies the `aud` claim for the service account token
  6186. Some providers automatically extend the audience field based on well-known annotations for workload
  6187. identity (e.g. IRSA or GCP Workload Identity)
  6188. items:
  6189. type: string
  6190. type: array
  6191. name:
  6192. description: The name of the ServiceAccount resource being referred to.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6196. type: string
  6197. namespace:
  6198. description: |-
  6199. Namespace of the resource being referred to.
  6200. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6201. maxLength: 63
  6202. minLength: 1
  6203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6204. type: string
  6205. required:
  6206. - name
  6207. type: object
  6208. token:
  6209. description: use static token to authenticate with
  6210. properties:
  6211. bearerToken:
  6212. description: |-
  6213. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6214. In some instances, `key` is a required field.
  6215. properties:
  6216. key:
  6217. description: |-
  6218. A key in the referenced Secret.
  6219. Some instances of this field may be defaulted, in others it may be required.
  6220. maxLength: 253
  6221. minLength: 1
  6222. pattern: ^[-._a-zA-Z0-9]+$
  6223. type: string
  6224. name:
  6225. description: The name of the Secret resource being referred to.
  6226. maxLength: 253
  6227. minLength: 1
  6228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6229. type: string
  6230. namespace:
  6231. description: |-
  6232. The namespace of the Secret resource being referred to.
  6233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6234. maxLength: 63
  6235. minLength: 1
  6236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6237. type: string
  6238. type: object
  6239. required:
  6240. - bearerToken
  6241. type: object
  6242. type: object
  6243. authRef:
  6244. description: A reference to a secret that contains the auth information.
  6245. properties:
  6246. key:
  6247. description: |-
  6248. A key in the referenced Secret.
  6249. Some instances of this field may be defaulted, in others it may be required.
  6250. maxLength: 253
  6251. minLength: 1
  6252. pattern: ^[-._a-zA-Z0-9]+$
  6253. type: string
  6254. name:
  6255. description: The name of the Secret resource being referred to.
  6256. maxLength: 253
  6257. minLength: 1
  6258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6259. type: string
  6260. namespace:
  6261. description: |-
  6262. The namespace of the Secret resource being referred to.
  6263. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6264. maxLength: 63
  6265. minLength: 1
  6266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6267. type: string
  6268. type: object
  6269. remoteNamespace:
  6270. default: default
  6271. description: Remote namespace to fetch the secrets from
  6272. maxLength: 63
  6273. minLength: 1
  6274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6275. type: string
  6276. server:
  6277. description: configures the Kubernetes server Address.
  6278. properties:
  6279. caBundle:
  6280. description: CABundle is a base64-encoded CA certificate
  6281. format: byte
  6282. type: string
  6283. caProvider:
  6284. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6285. properties:
  6286. key:
  6287. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6288. maxLength: 253
  6289. minLength: 1
  6290. pattern: ^[-._a-zA-Z0-9]+$
  6291. type: string
  6292. name:
  6293. description: The name of the object located at the provider type.
  6294. maxLength: 253
  6295. minLength: 1
  6296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6297. type: string
  6298. namespace:
  6299. description: |-
  6300. The namespace the Provider type is in.
  6301. Can only be defined when used in a ClusterSecretStore.
  6302. maxLength: 63
  6303. minLength: 1
  6304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6305. type: string
  6306. type:
  6307. description: The type of provider to use such as "Secret", or "ConfigMap".
  6308. enum:
  6309. - Secret
  6310. - ConfigMap
  6311. type: string
  6312. required:
  6313. - name
  6314. - type
  6315. type: object
  6316. url:
  6317. default: kubernetes.default
  6318. description: configures the Kubernetes server Address.
  6319. type: string
  6320. type: object
  6321. type: object
  6322. nebiusmysterybox:
  6323. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6324. properties:
  6325. apiDomain:
  6326. description: NebiusMysterybox API endpoint
  6327. type: string
  6328. auth:
  6329. description: Auth defines parameters to authenticate in MysteryBox
  6330. properties:
  6331. serviceAccountCredsSecretRef:
  6332. description: |-
  6333. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6334. document with service account credentials used to get an IAM token.
  6335. Expected JSON structure:
  6336. {
  6337. "subject-credentials": {
  6338. "alg": "RS256",
  6339. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6340. "kid": "<public-key-id>",
  6341. "iss": "<issuer-service-account-id>",
  6342. "sub": "<subject-service-account-id>"
  6343. }
  6344. }
  6345. properties:
  6346. key:
  6347. description: |-
  6348. A key in the referenced Secret.
  6349. Some instances of this field may be defaulted, in others it may be required.
  6350. maxLength: 253
  6351. minLength: 1
  6352. pattern: ^[-._a-zA-Z0-9]+$
  6353. type: string
  6354. name:
  6355. description: The name of the Secret resource being referred to.
  6356. maxLength: 253
  6357. minLength: 1
  6358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6359. type: string
  6360. namespace:
  6361. description: |-
  6362. The namespace of the Secret resource being referred to.
  6363. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6364. maxLength: 63
  6365. minLength: 1
  6366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6367. type: string
  6368. type: object
  6369. tokenSecretRef:
  6370. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6371. properties:
  6372. key:
  6373. description: |-
  6374. A key in the referenced Secret.
  6375. Some instances of this field may be defaulted, in others it may be required.
  6376. maxLength: 253
  6377. minLength: 1
  6378. pattern: ^[-._a-zA-Z0-9]+$
  6379. type: string
  6380. name:
  6381. description: The name of the Secret resource being referred to.
  6382. maxLength: 253
  6383. minLength: 1
  6384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6385. type: string
  6386. namespace:
  6387. description: |-
  6388. The namespace of the Secret resource being referred to.
  6389. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6390. maxLength: 63
  6391. minLength: 1
  6392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6393. type: string
  6394. type: object
  6395. workloadIdentity:
  6396. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  6397. properties:
  6398. iamServiceAccountID:
  6399. description: |-
  6400. IAMServiceAccountID is the Nebius IAM service account identifier that the
  6401. federated Kubernetes service account should impersonate during token exchange.
  6402. example: serviceaccount-e00example
  6403. minLength: 1
  6404. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  6405. type: string
  6406. serviceAccountRef:
  6407. description: |-
  6408. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  6409. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  6410. Nebius IAM token using workload federation.
  6411. properties:
  6412. audiences:
  6413. description: |-
  6414. Audience specifies the `aud` claim for the service account token
  6415. Some providers automatically extend the audience field based on well-known annotations for workload
  6416. identity (e.g. IRSA or GCP Workload Identity)
  6417. items:
  6418. type: string
  6419. type: array
  6420. name:
  6421. description: The name of the ServiceAccount resource being referred to.
  6422. maxLength: 253
  6423. minLength: 1
  6424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6425. type: string
  6426. namespace:
  6427. description: |-
  6428. Namespace of the resource being referred to.
  6429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6430. maxLength: 63
  6431. minLength: 1
  6432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6433. type: string
  6434. required:
  6435. - name
  6436. type: object
  6437. required:
  6438. - iamServiceAccountID
  6439. - serviceAccountRef
  6440. type: object
  6441. type: object
  6442. x-kubernetes-validations:
  6443. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  6444. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  6445. caProvider:
  6446. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6447. properties:
  6448. certSecretRef:
  6449. description: |-
  6450. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6451. In some instances, `key` is a required field.
  6452. properties:
  6453. key:
  6454. description: |-
  6455. A key in the referenced Secret.
  6456. Some instances of this field may be defaulted, in others it may be required.
  6457. maxLength: 253
  6458. minLength: 1
  6459. pattern: ^[-._a-zA-Z0-9]+$
  6460. type: string
  6461. name:
  6462. description: The name of the Secret resource being referred to.
  6463. maxLength: 253
  6464. minLength: 1
  6465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6466. type: string
  6467. namespace:
  6468. description: |-
  6469. The namespace of the Secret resource being referred to.
  6470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6471. maxLength: 63
  6472. minLength: 1
  6473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6474. type: string
  6475. type: object
  6476. type: object
  6477. required:
  6478. - apiDomain
  6479. - auth
  6480. type: object
  6481. ngrok:
  6482. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6483. properties:
  6484. apiUrl:
  6485. default: https://api.ngrok.com
  6486. description: APIURL is the URL of the ngrok API.
  6487. type: string
  6488. auth:
  6489. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6490. maxProperties: 1
  6491. minProperties: 1
  6492. properties:
  6493. apiKey:
  6494. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6495. properties:
  6496. secretRef:
  6497. description: SecretRef is a reference to a secret containing the ngrok API key.
  6498. properties:
  6499. key:
  6500. description: |-
  6501. A key in the referenced Secret.
  6502. Some instances of this field may be defaulted, in others it may be required.
  6503. maxLength: 253
  6504. minLength: 1
  6505. pattern: ^[-._a-zA-Z0-9]+$
  6506. type: string
  6507. name:
  6508. description: The name of the Secret resource being referred to.
  6509. maxLength: 253
  6510. minLength: 1
  6511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6512. type: string
  6513. namespace:
  6514. description: |-
  6515. The namespace of the Secret resource being referred to.
  6516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6517. maxLength: 63
  6518. minLength: 1
  6519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6520. type: string
  6521. type: object
  6522. type: object
  6523. type: object
  6524. vault:
  6525. description: Vault configures the ngrok vault to sync secrets with.
  6526. properties:
  6527. name:
  6528. description: Name is the name of the ngrok vault to sync secrets with.
  6529. type: string
  6530. required:
  6531. - name
  6532. type: object
  6533. required:
  6534. - auth
  6535. - vault
  6536. type: object
  6537. onboardbase:
  6538. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6539. properties:
  6540. apiHost:
  6541. default: https://public.onboardbase.com/api/v1/
  6542. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6543. type: string
  6544. auth:
  6545. description: Auth configures how the Operator authenticates with the Onboardbase API
  6546. properties:
  6547. apiKeyRef:
  6548. description: |-
  6549. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6550. It is used to recognize and authorize access to a project and environment within onboardbase
  6551. properties:
  6552. key:
  6553. description: |-
  6554. A key in the referenced Secret.
  6555. Some instances of this field may be defaulted, in others it may be required.
  6556. maxLength: 253
  6557. minLength: 1
  6558. pattern: ^[-._a-zA-Z0-9]+$
  6559. type: string
  6560. name:
  6561. description: The name of the Secret resource being referred to.
  6562. maxLength: 253
  6563. minLength: 1
  6564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6565. type: string
  6566. namespace:
  6567. description: |-
  6568. The namespace of the Secret resource being referred to.
  6569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6570. maxLength: 63
  6571. minLength: 1
  6572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6573. type: string
  6574. type: object
  6575. passcodeRef:
  6576. description: OnboardbasePasscode is the passcode attached to the API Key
  6577. properties:
  6578. key:
  6579. description: |-
  6580. A key in the referenced Secret.
  6581. Some instances of this field may be defaulted, in others it may be required.
  6582. maxLength: 253
  6583. minLength: 1
  6584. pattern: ^[-._a-zA-Z0-9]+$
  6585. type: string
  6586. name:
  6587. description: The name of the Secret resource being referred to.
  6588. maxLength: 253
  6589. minLength: 1
  6590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6591. type: string
  6592. namespace:
  6593. description: |-
  6594. The namespace of the Secret resource being referred to.
  6595. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6596. maxLength: 63
  6597. minLength: 1
  6598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6599. type: string
  6600. type: object
  6601. required:
  6602. - apiKeyRef
  6603. - passcodeRef
  6604. type: object
  6605. environment:
  6606. default: development
  6607. description: Environment is the name of an environmnent within a project to pull the secrets from
  6608. type: string
  6609. project:
  6610. default: development
  6611. description: Project is an onboardbase project that the secrets should be pulled from
  6612. type: string
  6613. required:
  6614. - apiHost
  6615. - auth
  6616. - environment
  6617. - project
  6618. type: object
  6619. onepassword:
  6620. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6621. properties:
  6622. auth:
  6623. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6624. properties:
  6625. secretRef:
  6626. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6627. properties:
  6628. connectTokenSecretRef:
  6629. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6630. properties:
  6631. key:
  6632. description: |-
  6633. A key in the referenced Secret.
  6634. Some instances of this field may be defaulted, in others it may be required.
  6635. maxLength: 253
  6636. minLength: 1
  6637. pattern: ^[-._a-zA-Z0-9]+$
  6638. type: string
  6639. name:
  6640. description: The name of the Secret resource being referred to.
  6641. maxLength: 253
  6642. minLength: 1
  6643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6644. type: string
  6645. namespace:
  6646. description: |-
  6647. The namespace of the Secret resource being referred to.
  6648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6649. maxLength: 63
  6650. minLength: 1
  6651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6652. type: string
  6653. type: object
  6654. required:
  6655. - connectTokenSecretRef
  6656. type: object
  6657. required:
  6658. - secretRef
  6659. type: object
  6660. connectHost:
  6661. description: ConnectHost defines the OnePassword Connect Server to connect to
  6662. type: string
  6663. vaults:
  6664. additionalProperties:
  6665. type: integer
  6666. description: Vaults defines which OnePassword vaults to search in which order
  6667. type: object
  6668. required:
  6669. - auth
  6670. - connectHost
  6671. - vaults
  6672. type: object
  6673. onepasswordSDK:
  6674. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6675. properties:
  6676. auth:
  6677. description: Auth defines the information necessary to authenticate against OnePassword API.
  6678. properties:
  6679. serviceAccountSecretRef:
  6680. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6681. properties:
  6682. key:
  6683. description: |-
  6684. A key in the referenced Secret.
  6685. Some instances of this field may be defaulted, in others it may be required.
  6686. maxLength: 253
  6687. minLength: 1
  6688. pattern: ^[-._a-zA-Z0-9]+$
  6689. type: string
  6690. name:
  6691. description: The name of the Secret resource being referred to.
  6692. maxLength: 253
  6693. minLength: 1
  6694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6695. type: string
  6696. namespace:
  6697. description: |-
  6698. The namespace of the Secret resource being referred to.
  6699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6700. maxLength: 63
  6701. minLength: 1
  6702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6703. type: string
  6704. type: object
  6705. required:
  6706. - serviceAccountSecretRef
  6707. type: object
  6708. cache:
  6709. description: |-
  6710. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6711. When enabled, secrets are cached with the specified TTL.
  6712. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6713. If omitted, caching is disabled (default).
  6714. cache: {} is a valid option to set.
  6715. properties:
  6716. maxSize:
  6717. default: 100
  6718. description: |-
  6719. MaxSize is the maximum number of secrets to cache.
  6720. When the cache is full, least-recently-used entries are evicted.
  6721. minimum: 1
  6722. type: integer
  6723. ttl:
  6724. default: 5m
  6725. description: |-
  6726. TTL is the time-to-live for cached secrets.
  6727. Format: duration string (e.g., "5m", "1h", "30s")
  6728. type: string
  6729. type: object
  6730. environment:
  6731. description: |-
  6732. Environment defines the 1Password Environment ID to read variables from.
  6733. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6734. Mutually exclusive with Vault.
  6735. type: string
  6736. integrationInfo:
  6737. description: |-
  6738. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6739. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6740. properties:
  6741. name:
  6742. default: 1Password SDK
  6743. description: Name defaults to "1Password SDK".
  6744. type: string
  6745. version:
  6746. default: v1.0.0
  6747. description: Version defaults to "v1.0.0".
  6748. type: string
  6749. type: object
  6750. vault:
  6751. description: |-
  6752. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6753. Mutually exclusive with Environment.
  6754. type: string
  6755. required:
  6756. - auth
  6757. type: object
  6758. x-kubernetes-validations:
  6759. - message: at most one of the fields in [vault environment] may be set
  6760. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6761. openBao:
  6762. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6763. properties:
  6764. auth:
  6765. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6766. properties:
  6767. appRole:
  6768. description: |-
  6769. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6770. with the role and secret stored in a Kubernetes Secret resource.
  6771. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6772. properties:
  6773. path:
  6774. default: approle
  6775. description: |-
  6776. Path where the App Role authentication backend is mounted
  6777. in OpenBao, e.g: "approle"
  6778. type: string
  6779. roleId:
  6780. description: |-
  6781. RoleID configured in the App Role authentication backend when setting
  6782. up the authentication backend in OpenBao.
  6783. minLength: 1
  6784. type: string
  6785. roleRef:
  6786. description: |-
  6787. Reference to a key in a Secret that contains the App Role ID used
  6788. to authenticate with OpenBao.
  6789. The `key` field must be specified and denotes which entry within the Secret
  6790. resource is used as the app role id.
  6791. properties:
  6792. key:
  6793. description: |-
  6794. A key in the referenced Secret.
  6795. Some instances of this field may be defaulted, in others it may be required.
  6796. maxLength: 253
  6797. minLength: 1
  6798. pattern: ^[-._a-zA-Z0-9]+$
  6799. type: string
  6800. name:
  6801. description: The name of the Secret resource being referred to.
  6802. maxLength: 253
  6803. minLength: 1
  6804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6805. type: string
  6806. namespace:
  6807. description: |-
  6808. The namespace of the Secret resource being referred to.
  6809. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6810. maxLength: 63
  6811. minLength: 1
  6812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6813. type: string
  6814. type: object
  6815. secretRef:
  6816. description: |-
  6817. Reference to a key in a Secret that contains the App Role secret used
  6818. to authenticate with OpenBao.
  6819. The `key` field must be specified and denotes which entry within the Secret
  6820. resource is used as the app role secret.
  6821. properties:
  6822. key:
  6823. description: |-
  6824. A key in the referenced Secret.
  6825. Some instances of this field may be defaulted, in others it may be required.
  6826. maxLength: 253
  6827. minLength: 1
  6828. pattern: ^[-._a-zA-Z0-9]+$
  6829. type: string
  6830. name:
  6831. description: The name of the Secret resource being referred to.
  6832. maxLength: 253
  6833. minLength: 1
  6834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6835. type: string
  6836. namespace:
  6837. description: |-
  6838. The namespace of the Secret resource being referred to.
  6839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6840. maxLength: 63
  6841. minLength: 1
  6842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6843. type: string
  6844. type: object
  6845. required:
  6846. - path
  6847. - secretRef
  6848. type: object
  6849. x-kubernetes-validations:
  6850. - message: exactly one of the fields in [roleId roleRef] must be set
  6851. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6852. kubernetes:
  6853. description: |-
  6854. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  6855. token to the [Kubernetes auth mechanism].
  6856. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  6857. properties:
  6858. path:
  6859. default: kubernetes
  6860. description: |-
  6861. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  6862. "kubernetes"
  6863. type: string
  6864. role:
  6865. description: |-
  6866. A required field containing the OpenBao Role to assume. A Role binds a
  6867. Kubernetes ServiceAccount with a set of OpenBao policies.
  6868. minLength: 1
  6869. type: string
  6870. secretRef:
  6871. description: |-
  6872. Optional secret field containing a Kubernetes ServiceAccount JWT used
  6873. for authenticating with OpenBao. If a name is specified without a key,
  6874. `token` is the default.
  6875. properties:
  6876. key:
  6877. description: |-
  6878. A key in the referenced Secret.
  6879. Some instances of this field may be defaulted, in others it may be required.
  6880. maxLength: 253
  6881. minLength: 1
  6882. pattern: ^[-._a-zA-Z0-9]+$
  6883. type: string
  6884. name:
  6885. description: The name of the Secret resource being referred to.
  6886. maxLength: 253
  6887. minLength: 1
  6888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6889. type: string
  6890. namespace:
  6891. description: |-
  6892. The namespace of the Secret resource being referred to.
  6893. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6894. maxLength: 63
  6895. minLength: 1
  6896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6897. type: string
  6898. type: object
  6899. serviceAccountRef:
  6900. description: |-
  6901. Optional service account field containing the name of a Kubernetes ServiceAccount.
  6902. If the service account is specified, a token will be requested from the Kubernetes
  6903. TokenRequest API for authenticating with OpenBao.
  6904. Any configured audiences will be passed to the TokenRequest as-is.
  6905. properties:
  6906. audiences:
  6907. description: |-
  6908. Audience specifies the `aud` claim for the service account token
  6909. Some providers automatically extend the audience field based on well-known annotations for workload
  6910. identity (e.g. IRSA or GCP Workload Identity)
  6911. items:
  6912. type: string
  6913. type: array
  6914. name:
  6915. description: The name of the ServiceAccount resource being referred to.
  6916. maxLength: 253
  6917. minLength: 1
  6918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6919. type: string
  6920. namespace:
  6921. description: |-
  6922. Namespace of the resource being referred to.
  6923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6924. maxLength: 63
  6925. minLength: 1
  6926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6927. type: string
  6928. required:
  6929. - name
  6930. type: object
  6931. required:
  6932. - path
  6933. - role
  6934. type: object
  6935. x-kubernetes-validations:
  6936. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  6937. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  6938. namespace:
  6939. description: |-
  6940. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6941. than the namespace your secret is in. Namespaces is a set of features
  6942. within OpenBao that allows OpenBao environments to support secure
  6943. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6944. if set, or empty otherwise
  6945. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6946. type: string
  6947. tokenSecretRef:
  6948. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6949. properties:
  6950. key:
  6951. description: |-
  6952. A key in the referenced Secret.
  6953. Some instances of this field may be defaulted, in others it may be required.
  6954. maxLength: 253
  6955. minLength: 1
  6956. pattern: ^[-._a-zA-Z0-9]+$
  6957. type: string
  6958. name:
  6959. description: The name of the Secret resource being referred to.
  6960. maxLength: 253
  6961. minLength: 1
  6962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6963. type: string
  6964. namespace:
  6965. description: |-
  6966. The namespace of the Secret resource being referred to.
  6967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6968. maxLength: 63
  6969. minLength: 1
  6970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6971. type: string
  6972. type: object
  6973. userPass:
  6974. description: UserPass authenticates with OpenBao by passing a username/password pair
  6975. properties:
  6976. path:
  6977. default: userpass
  6978. description: |-
  6979. Path where the UserPassword authentication backend is mounted
  6980. in OpenBao, e.g: "userpass"
  6981. type: string
  6982. secretRef:
  6983. description: |-
  6984. SecretRef to a key in a Secret resource containing password for the user
  6985. used to authenticate with OpenBao using the [UserPass authentication
  6986. method]
  6987. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6988. properties:
  6989. key:
  6990. description: |-
  6991. A key in the referenced Secret.
  6992. Some instances of this field may be defaulted, in others it may be required.
  6993. maxLength: 253
  6994. minLength: 1
  6995. pattern: ^[-._a-zA-Z0-9]+$
  6996. type: string
  6997. name:
  6998. description: The name of the Secret resource being referred to.
  6999. maxLength: 253
  7000. minLength: 1
  7001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7002. type: string
  7003. namespace:
  7004. description: |-
  7005. The namespace of the Secret resource being referred to.
  7006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7007. maxLength: 63
  7008. minLength: 1
  7009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7010. type: string
  7011. type: object
  7012. username:
  7013. description: |-
  7014. Username is a username used to authenticate using the [UserPass
  7015. authentication method]
  7016. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  7017. type: string
  7018. required:
  7019. - path
  7020. - username
  7021. type: object
  7022. type: object
  7023. x-kubernetes-validations:
  7024. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  7025. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  7026. caBundle:
  7027. description: |-
  7028. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  7029. this and `caProvider` are not set the system root certificates are used
  7030. to validate the TLS connection.
  7031. format: byte
  7032. type: string
  7033. caProvider:
  7034. description: |-
  7035. The provider for the CA bundle to use to validate OpenBao server
  7036. certificate. If this and `caBundle` are not set the system root
  7037. certificates are used to validate the TLS connection.
  7038. properties:
  7039. key:
  7040. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7041. maxLength: 253
  7042. minLength: 1
  7043. pattern: ^[-._a-zA-Z0-9]+$
  7044. type: string
  7045. name:
  7046. description: The name of the object located at the provider type.
  7047. maxLength: 253
  7048. minLength: 1
  7049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7050. type: string
  7051. namespace:
  7052. description: |-
  7053. The namespace the Provider type is in.
  7054. Can only be defined when used in a ClusterSecretStore.
  7055. maxLength: 63
  7056. minLength: 1
  7057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7058. type: string
  7059. type:
  7060. description: The type of provider to use such as "Secret", or "ConfigMap".
  7061. enum:
  7062. - Secret
  7063. - ConfigMap
  7064. type: string
  7065. required:
  7066. - name
  7067. - type
  7068. type: object
  7069. namespace:
  7070. description: |-
  7071. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  7072. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  7073. e.g: "ns1".
  7074. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  7075. type: string
  7076. path:
  7077. description: |-
  7078. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  7079. "secret". The v2 KV secret engine version specific "/data" path suffix
  7080. for fetching secrets from OpenBao is optional and will be appended
  7081. if not present in specified path.
  7082. type: string
  7083. server:
  7084. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  7085. type: string
  7086. version:
  7087. default: v2
  7088. description: |-
  7089. Version is the OpenBao KV secret engine version. This can be either "v1" or
  7090. "v2". Version defaults to "v2".
  7091. enum:
  7092. - v1
  7093. - v2
  7094. type: string
  7095. required:
  7096. - server
  7097. type: object
  7098. x-kubernetes-validations:
  7099. - message: at most one of the fields in [caBundle caProvider] may be set
  7100. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  7101. oracle:
  7102. description: Oracle configures this store to sync secrets using Oracle Vault provider
  7103. properties:
  7104. auth:
  7105. description: |-
  7106. Auth configures how secret-manager authenticates with the Oracle Vault.
  7107. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  7108. properties:
  7109. secretRef:
  7110. description: SecretRef to pass through sensitive information.
  7111. properties:
  7112. fingerprint:
  7113. description: Fingerprint is the fingerprint of the API private key.
  7114. properties:
  7115. key:
  7116. description: |-
  7117. A key in the referenced Secret.
  7118. Some instances of this field may be defaulted, in others it may be required.
  7119. maxLength: 253
  7120. minLength: 1
  7121. pattern: ^[-._a-zA-Z0-9]+$
  7122. type: string
  7123. name:
  7124. description: The name of the Secret resource being referred to.
  7125. maxLength: 253
  7126. minLength: 1
  7127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7128. type: string
  7129. namespace:
  7130. description: |-
  7131. The namespace of the Secret resource being referred to.
  7132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7133. maxLength: 63
  7134. minLength: 1
  7135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7136. type: string
  7137. type: object
  7138. privatekey:
  7139. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  7140. properties:
  7141. key:
  7142. description: |-
  7143. A key in the referenced Secret.
  7144. Some instances of this field may be defaulted, in others it may be required.
  7145. maxLength: 253
  7146. minLength: 1
  7147. pattern: ^[-._a-zA-Z0-9]+$
  7148. type: string
  7149. name:
  7150. description: The name of the Secret resource being referred to.
  7151. maxLength: 253
  7152. minLength: 1
  7153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7154. type: string
  7155. namespace:
  7156. description: |-
  7157. The namespace of the Secret resource being referred to.
  7158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7159. maxLength: 63
  7160. minLength: 1
  7161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7162. type: string
  7163. type: object
  7164. required:
  7165. - fingerprint
  7166. - privatekey
  7167. type: object
  7168. tenancy:
  7169. description: Tenancy is the tenancy OCID where user is located.
  7170. type: string
  7171. user:
  7172. description: User is an access OCID specific to the account.
  7173. type: string
  7174. required:
  7175. - secretRef
  7176. - tenancy
  7177. - user
  7178. type: object
  7179. compartment:
  7180. description: |-
  7181. Compartment is the vault compartment OCID.
  7182. Required for PushSecret
  7183. type: string
  7184. encryptionKey:
  7185. description: |-
  7186. EncryptionKey is the OCID of the encryption key within the vault.
  7187. Required for PushSecret
  7188. type: string
  7189. principalType:
  7190. description: |-
  7191. The type of principal to use for authentication. If left blank, the Auth struct will
  7192. determine the principal type. This optional field must be specified if using
  7193. workload identity.
  7194. enum:
  7195. - ""
  7196. - UserPrincipal
  7197. - InstancePrincipal
  7198. - Workload
  7199. type: string
  7200. region:
  7201. description: Region is the region where vault is located.
  7202. type: string
  7203. serviceAccountRef:
  7204. description: |-
  7205. ServiceAccountRef specified the service account
  7206. that should be used when authenticating with WorkloadIdentity.
  7207. properties:
  7208. audiences:
  7209. description: |-
  7210. Audience specifies the `aud` claim for the service account token
  7211. Some providers automatically extend the audience field based on well-known annotations for workload
  7212. identity (e.g. IRSA or GCP Workload Identity)
  7213. items:
  7214. type: string
  7215. type: array
  7216. name:
  7217. description: The name of the ServiceAccount resource being referred to.
  7218. maxLength: 253
  7219. minLength: 1
  7220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7221. type: string
  7222. namespace:
  7223. description: |-
  7224. Namespace of the resource being referred to.
  7225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7226. maxLength: 63
  7227. minLength: 1
  7228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7229. type: string
  7230. required:
  7231. - name
  7232. type: object
  7233. vault:
  7234. description: Vault is the vault's OCID of the specific vault where secret is located.
  7235. type: string
  7236. required:
  7237. - region
  7238. - vault
  7239. type: object
  7240. ovh:
  7241. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7242. properties:
  7243. auth:
  7244. description: Authentication method (mtls or token).
  7245. properties:
  7246. mtls:
  7247. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7248. properties:
  7249. caBundle:
  7250. format: byte
  7251. type: string
  7252. caProvider:
  7253. description: |-
  7254. CAProvider provides a custom certificate authority for accessing the provider's store.
  7255. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7256. properties:
  7257. key:
  7258. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7259. maxLength: 253
  7260. minLength: 1
  7261. pattern: ^[-._a-zA-Z0-9]+$
  7262. type: string
  7263. name:
  7264. description: The name of the object located at the provider type.
  7265. maxLength: 253
  7266. minLength: 1
  7267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7268. type: string
  7269. namespace:
  7270. description: |-
  7271. The namespace the Provider type is in.
  7272. Can only be defined when used in a ClusterSecretStore.
  7273. maxLength: 63
  7274. minLength: 1
  7275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7276. type: string
  7277. type:
  7278. description: The type of provider to use such as "Secret", or "ConfigMap".
  7279. enum:
  7280. - Secret
  7281. - ConfigMap
  7282. type: string
  7283. required:
  7284. - name
  7285. - type
  7286. type: object
  7287. certSecretRef:
  7288. description: |-
  7289. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7290. In some instances, `key` is a required field.
  7291. properties:
  7292. key:
  7293. description: |-
  7294. A key in the referenced Secret.
  7295. Some instances of this field may be defaulted, in others it may be required.
  7296. maxLength: 253
  7297. minLength: 1
  7298. pattern: ^[-._a-zA-Z0-9]+$
  7299. type: string
  7300. name:
  7301. description: The name of the Secret resource being referred to.
  7302. maxLength: 253
  7303. minLength: 1
  7304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7305. type: string
  7306. namespace:
  7307. description: |-
  7308. The namespace of the Secret resource being referred to.
  7309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7310. maxLength: 63
  7311. minLength: 1
  7312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7313. type: string
  7314. type: object
  7315. keySecretRef:
  7316. description: |-
  7317. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7318. In some instances, `key` is a required field.
  7319. properties:
  7320. key:
  7321. description: |-
  7322. A key in the referenced Secret.
  7323. Some instances of this field may be defaulted, in others it may be required.
  7324. maxLength: 253
  7325. minLength: 1
  7326. pattern: ^[-._a-zA-Z0-9]+$
  7327. type: string
  7328. name:
  7329. description: The name of the Secret resource being referred to.
  7330. maxLength: 253
  7331. minLength: 1
  7332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7333. type: string
  7334. namespace:
  7335. description: |-
  7336. The namespace of the Secret resource being referred to.
  7337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7338. maxLength: 63
  7339. minLength: 1
  7340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7341. type: string
  7342. type: object
  7343. required:
  7344. - certSecretRef
  7345. - keySecretRef
  7346. type: object
  7347. token:
  7348. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7349. properties:
  7350. tokenSecretRef:
  7351. description: |-
  7352. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7353. In some instances, `key` is a required field.
  7354. properties:
  7355. key:
  7356. description: |-
  7357. A key in the referenced Secret.
  7358. Some instances of this field may be defaulted, in others it may be required.
  7359. maxLength: 253
  7360. minLength: 1
  7361. pattern: ^[-._a-zA-Z0-9]+$
  7362. type: string
  7363. name:
  7364. description: The name of the Secret resource being referred to.
  7365. maxLength: 253
  7366. minLength: 1
  7367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7368. type: string
  7369. namespace:
  7370. description: |-
  7371. The namespace of the Secret resource being referred to.
  7372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7373. maxLength: 63
  7374. minLength: 1
  7375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7376. type: string
  7377. type: object
  7378. required:
  7379. - tokenSecretRef
  7380. type: object
  7381. type: object
  7382. casRequired:
  7383. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7384. type: boolean
  7385. okmsTimeout:
  7386. default: 30
  7387. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7388. format: int32
  7389. minimum: 1
  7390. type: integer
  7391. okmsid:
  7392. description: specifies the OKMS ID.
  7393. type: string
  7394. server:
  7395. description: specifies the OKMS server endpoint.
  7396. type: string
  7397. required:
  7398. - auth
  7399. - okmsid
  7400. - server
  7401. type: object
  7402. passbolt:
  7403. description: |-
  7404. PassboltProvider provides access to Passbolt secrets manager.
  7405. See: https://www.passbolt.com.
  7406. properties:
  7407. auth:
  7408. description: Auth defines the information necessary to authenticate against Passbolt Server
  7409. properties:
  7410. passwordSecretRef:
  7411. description: |-
  7412. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7413. In some instances, `key` is a required field.
  7414. properties:
  7415. key:
  7416. description: |-
  7417. A key in the referenced Secret.
  7418. Some instances of this field may be defaulted, in others it may be required.
  7419. maxLength: 253
  7420. minLength: 1
  7421. pattern: ^[-._a-zA-Z0-9]+$
  7422. type: string
  7423. name:
  7424. description: The name of the Secret resource being referred to.
  7425. maxLength: 253
  7426. minLength: 1
  7427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7428. type: string
  7429. namespace:
  7430. description: |-
  7431. The namespace of the Secret resource being referred to.
  7432. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7433. maxLength: 63
  7434. minLength: 1
  7435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7436. type: string
  7437. type: object
  7438. privateKeySecretRef:
  7439. description: |-
  7440. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7441. In some instances, `key` is a required field.
  7442. properties:
  7443. key:
  7444. description: |-
  7445. A key in the referenced Secret.
  7446. Some instances of this field may be defaulted, in others it may be required.
  7447. maxLength: 253
  7448. minLength: 1
  7449. pattern: ^[-._a-zA-Z0-9]+$
  7450. type: string
  7451. name:
  7452. description: The name of the Secret resource being referred to.
  7453. maxLength: 253
  7454. minLength: 1
  7455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7456. type: string
  7457. namespace:
  7458. description: |-
  7459. The namespace of the Secret resource being referred to.
  7460. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7461. maxLength: 63
  7462. minLength: 1
  7463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7464. type: string
  7465. type: object
  7466. required:
  7467. - passwordSecretRef
  7468. - privateKeySecretRef
  7469. type: object
  7470. caBundle:
  7471. description: |-
  7472. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7473. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7474. are used to validate the TLS connection.
  7475. format: byte
  7476. type: string
  7477. caProvider:
  7478. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7479. properties:
  7480. key:
  7481. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7482. maxLength: 253
  7483. minLength: 1
  7484. pattern: ^[-._a-zA-Z0-9]+$
  7485. type: string
  7486. name:
  7487. description: The name of the object located at the provider type.
  7488. maxLength: 253
  7489. minLength: 1
  7490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7491. type: string
  7492. namespace:
  7493. description: |-
  7494. The namespace the Provider type is in.
  7495. Can only be defined when used in a ClusterSecretStore.
  7496. maxLength: 63
  7497. minLength: 1
  7498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7499. type: string
  7500. type:
  7501. description: The type of provider to use such as "Secret", or "ConfigMap".
  7502. enum:
  7503. - Secret
  7504. - ConfigMap
  7505. type: string
  7506. required:
  7507. - name
  7508. - type
  7509. type: object
  7510. host:
  7511. description: Host defines the Passbolt Server to connect to
  7512. type: string
  7513. required:
  7514. - auth
  7515. - host
  7516. type: object
  7517. passworddepot:
  7518. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7519. properties:
  7520. auth:
  7521. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7522. properties:
  7523. secretRef:
  7524. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7525. properties:
  7526. credentials:
  7527. description: Username / Password is used for authentication.
  7528. properties:
  7529. key:
  7530. description: |-
  7531. A key in the referenced Secret.
  7532. Some instances of this field may be defaulted, in others it may be required.
  7533. maxLength: 253
  7534. minLength: 1
  7535. pattern: ^[-._a-zA-Z0-9]+$
  7536. type: string
  7537. name:
  7538. description: The name of the Secret resource being referred to.
  7539. maxLength: 253
  7540. minLength: 1
  7541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7542. type: string
  7543. namespace:
  7544. description: |-
  7545. The namespace of the Secret resource being referred to.
  7546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7547. maxLength: 63
  7548. minLength: 1
  7549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7550. type: string
  7551. type: object
  7552. type: object
  7553. required:
  7554. - secretRef
  7555. type: object
  7556. database:
  7557. description: Database to use as source
  7558. type: string
  7559. host:
  7560. description: URL configures the Password Depot instance URL.
  7561. type: string
  7562. required:
  7563. - auth
  7564. - database
  7565. - host
  7566. type: object
  7567. previder:
  7568. description: Previder configures this store to sync secrets using the Previder provider
  7569. properties:
  7570. auth:
  7571. description: PreviderAuth contains a secretRef for credentials.
  7572. properties:
  7573. secretRef:
  7574. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7575. properties:
  7576. accessToken:
  7577. description: The AccessToken is used for authentication
  7578. properties:
  7579. key:
  7580. description: |-
  7581. A key in the referenced Secret.
  7582. Some instances of this field may be defaulted, in others it may be required.
  7583. maxLength: 253
  7584. minLength: 1
  7585. pattern: ^[-._a-zA-Z0-9]+$
  7586. type: string
  7587. name:
  7588. description: The name of the Secret resource being referred to.
  7589. maxLength: 253
  7590. minLength: 1
  7591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7592. type: string
  7593. namespace:
  7594. description: |-
  7595. The namespace of the Secret resource being referred to.
  7596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7597. maxLength: 63
  7598. minLength: 1
  7599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7600. type: string
  7601. type: object
  7602. required:
  7603. - accessToken
  7604. type: object
  7605. type: object
  7606. baseUri:
  7607. type: string
  7608. required:
  7609. - auth
  7610. type: object
  7611. pulumi:
  7612. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7613. properties:
  7614. accessToken:
  7615. description: |-
  7616. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7617. Deprecated: Use auth.accessToken instead.
  7618. properties:
  7619. secretRef:
  7620. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7621. properties:
  7622. key:
  7623. description: |-
  7624. A key in the referenced Secret.
  7625. Some instances of this field may be defaulted, in others it may be required.
  7626. maxLength: 253
  7627. minLength: 1
  7628. pattern: ^[-._a-zA-Z0-9]+$
  7629. type: string
  7630. name:
  7631. description: The name of the Secret resource being referred to.
  7632. maxLength: 253
  7633. minLength: 1
  7634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7635. type: string
  7636. namespace:
  7637. description: |-
  7638. The namespace of the Secret resource being referred to.
  7639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7640. maxLength: 63
  7641. minLength: 1
  7642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7643. type: string
  7644. type: object
  7645. type: object
  7646. apiUrl:
  7647. default: https://api.pulumi.com/api/esc
  7648. description: APIURL is the URL of the Pulumi API.
  7649. type: string
  7650. auth:
  7651. description: |-
  7652. Auth configures how the Operator authenticates with the Pulumi API.
  7653. Either auth or the deprecated accessToken field must be specified.
  7654. properties:
  7655. accessToken:
  7656. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7657. properties:
  7658. secretRef:
  7659. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7660. properties:
  7661. key:
  7662. description: |-
  7663. A key in the referenced Secret.
  7664. Some instances of this field may be defaulted, in others it may be required.
  7665. maxLength: 253
  7666. minLength: 1
  7667. pattern: ^[-._a-zA-Z0-9]+$
  7668. type: string
  7669. name:
  7670. description: The name of the Secret resource being referred to.
  7671. maxLength: 253
  7672. minLength: 1
  7673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7674. type: string
  7675. namespace:
  7676. description: |-
  7677. The namespace of the Secret resource being referred to.
  7678. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7679. maxLength: 63
  7680. minLength: 1
  7681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7682. type: string
  7683. type: object
  7684. type: object
  7685. oidcConfig:
  7686. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7687. properties:
  7688. expirationSeconds:
  7689. default: 600
  7690. description: |-
  7691. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7692. Defaults to 10 minutes.
  7693. format: int64
  7694. minimum: 600
  7695. type: integer
  7696. organization:
  7697. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7698. type: string
  7699. serviceAccountRef:
  7700. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7701. properties:
  7702. audiences:
  7703. description: |-
  7704. Audience specifies the `aud` claim for the service account token
  7705. Some providers automatically extend the audience field based on well-known annotations for workload
  7706. identity (e.g. IRSA or GCP Workload Identity)
  7707. items:
  7708. type: string
  7709. type: array
  7710. name:
  7711. description: The name of the ServiceAccount resource being referred to.
  7712. maxLength: 253
  7713. minLength: 1
  7714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7715. type: string
  7716. namespace:
  7717. description: |-
  7718. Namespace of the resource being referred to.
  7719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7720. maxLength: 63
  7721. minLength: 1
  7722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7723. type: string
  7724. required:
  7725. - name
  7726. type: object
  7727. required:
  7728. - organization
  7729. - serviceAccountRef
  7730. type: object
  7731. type: object
  7732. x-kubernetes-validations:
  7733. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7734. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7735. environment:
  7736. description: |-
  7737. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7738. dynamically retrieved values from supported providers including all major clouds,
  7739. and other Pulumi ESC environments.
  7740. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7741. type: string
  7742. organization:
  7743. description: |-
  7744. Organization are a space to collaborate on shared projects and stacks.
  7745. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7746. type: string
  7747. project:
  7748. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7749. type: string
  7750. required:
  7751. - environment
  7752. - organization
  7753. - project
  7754. type: object
  7755. x-kubernetes-validations:
  7756. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7757. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7758. scaleway:
  7759. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7760. properties:
  7761. accessKey:
  7762. description: AccessKey is the non-secret part of the api key.
  7763. properties:
  7764. secretRef:
  7765. description: SecretRef references a key in a secret that will be used as value.
  7766. properties:
  7767. key:
  7768. description: |-
  7769. A key in the referenced Secret.
  7770. Some instances of this field may be defaulted, in others it may be required.
  7771. maxLength: 253
  7772. minLength: 1
  7773. pattern: ^[-._a-zA-Z0-9]+$
  7774. type: string
  7775. name:
  7776. description: The name of the Secret resource being referred to.
  7777. maxLength: 253
  7778. minLength: 1
  7779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7780. type: string
  7781. namespace:
  7782. description: |-
  7783. The namespace of the Secret resource being referred to.
  7784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7785. maxLength: 63
  7786. minLength: 1
  7787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7788. type: string
  7789. type: object
  7790. value:
  7791. description: Value can be specified directly to set a value without using a secret.
  7792. type: string
  7793. type: object
  7794. apiUrl:
  7795. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7796. type: string
  7797. projectId:
  7798. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7799. type: string
  7800. region:
  7801. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7802. type: string
  7803. secretKey:
  7804. description: SecretKey is the non-secret part of the api key.
  7805. properties:
  7806. secretRef:
  7807. description: SecretRef references a key in a secret that will be used as value.
  7808. properties:
  7809. key:
  7810. description: |-
  7811. A key in the referenced Secret.
  7812. Some instances of this field may be defaulted, in others it may be required.
  7813. maxLength: 253
  7814. minLength: 1
  7815. pattern: ^[-._a-zA-Z0-9]+$
  7816. type: string
  7817. name:
  7818. description: The name of the Secret resource being referred to.
  7819. maxLength: 253
  7820. minLength: 1
  7821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7822. type: string
  7823. namespace:
  7824. description: |-
  7825. The namespace of the Secret resource being referred to.
  7826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7827. maxLength: 63
  7828. minLength: 1
  7829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7830. type: string
  7831. type: object
  7832. value:
  7833. description: Value can be specified directly to set a value without using a secret.
  7834. type: string
  7835. type: object
  7836. required:
  7837. - accessKey
  7838. - projectId
  7839. - region
  7840. - secretKey
  7841. type: object
  7842. secretserver:
  7843. description: |-
  7844. SecretServer configures this store to sync secrets using SecretServer provider
  7845. https://docs.delinea.com/online-help/secret-server/start.htm
  7846. properties:
  7847. caBundle:
  7848. description: |-
  7849. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7850. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7851. are used to validate the TLS connection.
  7852. format: byte
  7853. type: string
  7854. caProvider:
  7855. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7856. properties:
  7857. key:
  7858. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7859. maxLength: 253
  7860. minLength: 1
  7861. pattern: ^[-._a-zA-Z0-9]+$
  7862. type: string
  7863. name:
  7864. description: The name of the object located at the provider type.
  7865. maxLength: 253
  7866. minLength: 1
  7867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7868. type: string
  7869. namespace:
  7870. description: |-
  7871. The namespace the Provider type is in.
  7872. Can only be defined when used in a ClusterSecretStore.
  7873. maxLength: 63
  7874. minLength: 1
  7875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7876. type: string
  7877. type:
  7878. description: The type of provider to use such as "Secret", or "ConfigMap".
  7879. enum:
  7880. - Secret
  7881. - ConfigMap
  7882. type: string
  7883. required:
  7884. - name
  7885. - type
  7886. type: object
  7887. disableSiteIDValidation:
  7888. description: |-
  7889. DisableSiteIDValidation permits a missing site ID for new secrets.
  7890. The provider sends 0 if no site ID is set.
  7891. type: boolean
  7892. domain:
  7893. description: Domain is the secret server domain.
  7894. type: string
  7895. password:
  7896. description: |-
  7897. Password is the secret server account password.
  7898. Required unless Token is set.
  7899. properties:
  7900. secretRef:
  7901. description: SecretRef references a key in a secret that will be used as value.
  7902. properties:
  7903. key:
  7904. description: |-
  7905. A key in the referenced Secret.
  7906. Some instances of this field may be defaulted, in others it may be required.
  7907. maxLength: 253
  7908. minLength: 1
  7909. pattern: ^[-._a-zA-Z0-9]+$
  7910. type: string
  7911. name:
  7912. description: The name of the Secret resource being referred to.
  7913. maxLength: 253
  7914. minLength: 1
  7915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7916. type: string
  7917. namespace:
  7918. description: |-
  7919. The namespace of the Secret resource being referred to.
  7920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7921. maxLength: 63
  7922. minLength: 1
  7923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7924. type: string
  7925. type: object
  7926. value:
  7927. description: Value can be specified directly to set a value without using a secret.
  7928. minLength: 1
  7929. type: string
  7930. type: object
  7931. x-kubernetes-validations:
  7932. - message: exactly one of value or secretRef must be set
  7933. rule: has(self.value) != has(self.secretRef)
  7934. serverURL:
  7935. description: |-
  7936. ServerURL
  7937. URL to your secret server installation
  7938. type: string
  7939. siteId:
  7940. description: |-
  7941. SiteID is the ID of the Secret Server site for new secrets.
  7942. PushSecret metadata can override this value for one secret.
  7943. The provider uses 1 if this field is not set.
  7944. minimum: 1
  7945. type: integer
  7946. token:
  7947. description: |-
  7948. Token is an access token used to authenticate to the secret server,
  7949. as an alternative to Username and Password. When set, Username and
  7950. Password are not required and are ignored.
  7951. properties:
  7952. secretRef:
  7953. description: SecretRef references a key in a secret that will be used as value.
  7954. properties:
  7955. key:
  7956. description: |-
  7957. A key in the referenced Secret.
  7958. Some instances of this field may be defaulted, in others it may be required.
  7959. maxLength: 253
  7960. minLength: 1
  7961. pattern: ^[-._a-zA-Z0-9]+$
  7962. type: string
  7963. name:
  7964. description: The name of the Secret resource being referred to.
  7965. maxLength: 253
  7966. minLength: 1
  7967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7968. type: string
  7969. namespace:
  7970. description: |-
  7971. The namespace of the Secret resource being referred to.
  7972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7973. maxLength: 63
  7974. minLength: 1
  7975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7976. type: string
  7977. type: object
  7978. value:
  7979. description: Value can be specified directly to set a value without using a secret.
  7980. minLength: 1
  7981. type: string
  7982. type: object
  7983. x-kubernetes-validations:
  7984. - message: exactly one of value or secretRef must be set
  7985. rule: has(self.value) != has(self.secretRef)
  7986. username:
  7987. description: |-
  7988. Username is the secret server account username.
  7989. Required unless Token is set.
  7990. properties:
  7991. secretRef:
  7992. description: SecretRef references a key in a secret that will be used as value.
  7993. properties:
  7994. key:
  7995. description: |-
  7996. A key in the referenced Secret.
  7997. Some instances of this field may be defaulted, in others it may be required.
  7998. maxLength: 253
  7999. minLength: 1
  8000. pattern: ^[-._a-zA-Z0-9]+$
  8001. type: string
  8002. name:
  8003. description: The name of the Secret resource being referred to.
  8004. maxLength: 253
  8005. minLength: 1
  8006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8007. type: string
  8008. namespace:
  8009. description: |-
  8010. The namespace of the Secret resource being referred to.
  8011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8012. maxLength: 63
  8013. minLength: 1
  8014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8015. type: string
  8016. type: object
  8017. value:
  8018. description: Value can be specified directly to set a value without using a secret.
  8019. minLength: 1
  8020. type: string
  8021. type: object
  8022. x-kubernetes-validations:
  8023. - message: exactly one of value or secretRef must be set
  8024. rule: has(self.value) != has(self.secretRef)
  8025. required:
  8026. - serverURL
  8027. type: object
  8028. x-kubernetes-validations:
  8029. - message: either token, or both username and password, must be set
  8030. rule: has(self.token) || (has(self.username) && has(self.password))
  8031. senhasegura:
  8032. description: Senhasegura configures this store to sync secrets using senhasegura provider
  8033. properties:
  8034. auth:
  8035. description: Auth defines parameters to authenticate in senhasegura
  8036. properties:
  8037. clientId:
  8038. type: string
  8039. clientSecretSecretRef:
  8040. description: |-
  8041. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8042. In some instances, `key` is a required field.
  8043. properties:
  8044. key:
  8045. description: |-
  8046. A key in the referenced Secret.
  8047. Some instances of this field may be defaulted, in others it may be required.
  8048. maxLength: 253
  8049. minLength: 1
  8050. pattern: ^[-._a-zA-Z0-9]+$
  8051. type: string
  8052. name:
  8053. description: The name of the Secret resource being referred to.
  8054. maxLength: 253
  8055. minLength: 1
  8056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8057. type: string
  8058. namespace:
  8059. description: |-
  8060. The namespace of the Secret resource being referred to.
  8061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8062. maxLength: 63
  8063. minLength: 1
  8064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8065. type: string
  8066. type: object
  8067. required:
  8068. - clientId
  8069. - clientSecretSecretRef
  8070. type: object
  8071. ignoreSslCertificate:
  8072. default: false
  8073. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  8074. type: boolean
  8075. module:
  8076. description: Module defines which senhasegura module should be used to get secrets
  8077. type: string
  8078. url:
  8079. description: URL of senhasegura
  8080. type: string
  8081. required:
  8082. - auth
  8083. - module
  8084. - url
  8085. type: object
  8086. vault:
  8087. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  8088. properties:
  8089. auth:
  8090. description: Auth configures how secret-manager authenticates with the Vault server.
  8091. properties:
  8092. appRole:
  8093. description: |-
  8094. AppRole authenticates with Vault using the App Role auth mechanism,
  8095. with the role and secret stored in a Kubernetes Secret resource.
  8096. properties:
  8097. path:
  8098. default: approle
  8099. description: |-
  8100. Path where the App Role authentication backend is mounted
  8101. in Vault, e.g: "approle"
  8102. type: string
  8103. roleId:
  8104. description: |-
  8105. RoleID configured in the App Role authentication backend when setting
  8106. up the authentication backend in Vault.
  8107. type: string
  8108. roleRef:
  8109. description: |-
  8110. Reference to a key in a Secret that contains the App Role ID used
  8111. to authenticate with Vault.
  8112. The `key` field must be specified and denotes which entry within the Secret
  8113. resource is used as the app role id.
  8114. properties:
  8115. key:
  8116. description: |-
  8117. A key in the referenced Secret.
  8118. Some instances of this field may be defaulted, in others it may be required.
  8119. maxLength: 253
  8120. minLength: 1
  8121. pattern: ^[-._a-zA-Z0-9]+$
  8122. type: string
  8123. name:
  8124. description: The name of the Secret resource being referred to.
  8125. maxLength: 253
  8126. minLength: 1
  8127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8128. type: string
  8129. namespace:
  8130. description: |-
  8131. The namespace of the Secret resource being referred to.
  8132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8133. maxLength: 63
  8134. minLength: 1
  8135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8136. type: string
  8137. type: object
  8138. secretRef:
  8139. description: |-
  8140. Reference to a key in a Secret that contains the App Role secret used
  8141. to authenticate with Vault.
  8142. The `key` field must be specified and denotes which entry within the Secret
  8143. resource is used as the app role secret.
  8144. properties:
  8145. key:
  8146. description: |-
  8147. A key in the referenced Secret.
  8148. Some instances of this field may be defaulted, in others it may be required.
  8149. maxLength: 253
  8150. minLength: 1
  8151. pattern: ^[-._a-zA-Z0-9]+$
  8152. type: string
  8153. name:
  8154. description: The name of the Secret resource being referred to.
  8155. maxLength: 253
  8156. minLength: 1
  8157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8158. type: string
  8159. namespace:
  8160. description: |-
  8161. The namespace of the Secret resource being referred to.
  8162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8163. maxLength: 63
  8164. minLength: 1
  8165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8166. type: string
  8167. type: object
  8168. required:
  8169. - path
  8170. - secretRef
  8171. type: object
  8172. cert:
  8173. description: |-
  8174. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  8175. Cert authentication method
  8176. properties:
  8177. clientCert:
  8178. description: |-
  8179. ClientCert is a certificate to authenticate using the Cert Vault
  8180. authentication method
  8181. properties:
  8182. key:
  8183. description: |-
  8184. A key in the referenced Secret.
  8185. Some instances of this field may be defaulted, in others it may be required.
  8186. maxLength: 253
  8187. minLength: 1
  8188. pattern: ^[-._a-zA-Z0-9]+$
  8189. type: string
  8190. name:
  8191. description: The name of the Secret resource being referred to.
  8192. maxLength: 253
  8193. minLength: 1
  8194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8195. type: string
  8196. namespace:
  8197. description: |-
  8198. The namespace of the Secret resource being referred to.
  8199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8200. maxLength: 63
  8201. minLength: 1
  8202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8203. type: string
  8204. type: object
  8205. path:
  8206. default: cert
  8207. description: |-
  8208. Path where the Certificate authentication backend is mounted
  8209. in Vault, e.g: "cert"
  8210. type: string
  8211. secretRef:
  8212. description: |-
  8213. SecretRef to a key in a Secret resource containing client private key to
  8214. authenticate with Vault using the Cert authentication method
  8215. properties:
  8216. key:
  8217. description: |-
  8218. A key in the referenced Secret.
  8219. Some instances of this field may be defaulted, in others it may be required.
  8220. maxLength: 253
  8221. minLength: 1
  8222. pattern: ^[-._a-zA-Z0-9]+$
  8223. type: string
  8224. name:
  8225. description: The name of the Secret resource being referred to.
  8226. maxLength: 253
  8227. minLength: 1
  8228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8229. type: string
  8230. namespace:
  8231. description: |-
  8232. The namespace of the Secret resource being referred to.
  8233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8234. maxLength: 63
  8235. minLength: 1
  8236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8237. type: string
  8238. type: object
  8239. vaultRole:
  8240. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8241. type: string
  8242. type: object
  8243. gcp:
  8244. description: |-
  8245. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8246. GCP authentication method
  8247. properties:
  8248. location:
  8249. description: Location optionally defines a location/region for the secret
  8250. type: string
  8251. path:
  8252. default: gcp
  8253. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8254. type: string
  8255. projectID:
  8256. description: Project ID of the Google Cloud Platform project
  8257. type: string
  8258. role:
  8259. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8260. type: string
  8261. secretRef:
  8262. description: Specify credentials in a Secret object
  8263. properties:
  8264. secretAccessKeySecretRef:
  8265. description: The SecretAccessKey is used for authentication
  8266. properties:
  8267. key:
  8268. description: |-
  8269. A key in the referenced Secret.
  8270. Some instances of this field may be defaulted, in others it may be required.
  8271. maxLength: 253
  8272. minLength: 1
  8273. pattern: ^[-._a-zA-Z0-9]+$
  8274. type: string
  8275. name:
  8276. description: The name of the Secret resource being referred to.
  8277. maxLength: 253
  8278. minLength: 1
  8279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8280. type: string
  8281. namespace:
  8282. description: |-
  8283. The namespace of the Secret resource being referred to.
  8284. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8285. maxLength: 63
  8286. minLength: 1
  8287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8288. type: string
  8289. type: object
  8290. type: object
  8291. serviceAccountRef:
  8292. description: ServiceAccountRef to a service account for impersonation
  8293. properties:
  8294. audiences:
  8295. description: |-
  8296. Audience specifies the `aud` claim for the service account token
  8297. Some providers automatically extend the audience field based on well-known annotations for workload
  8298. identity (e.g. IRSA or GCP Workload Identity)
  8299. items:
  8300. type: string
  8301. type: array
  8302. name:
  8303. description: The name of the ServiceAccount resource being referred to.
  8304. maxLength: 253
  8305. minLength: 1
  8306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8307. type: string
  8308. namespace:
  8309. description: |-
  8310. Namespace of the resource being referred to.
  8311. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8312. maxLength: 63
  8313. minLength: 1
  8314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8315. type: string
  8316. required:
  8317. - name
  8318. type: object
  8319. workloadIdentity:
  8320. description: Specify a service account with Workload Identity
  8321. properties:
  8322. clusterLocation:
  8323. description: |-
  8324. ClusterLocation is the location of the cluster
  8325. If not specified, it fetches information from the metadata server
  8326. type: string
  8327. clusterName:
  8328. description: |-
  8329. ClusterName is the name of the cluster
  8330. If not specified, it fetches information from the metadata server
  8331. type: string
  8332. clusterProjectID:
  8333. description: |-
  8334. ClusterProjectID is the project ID of the cluster
  8335. If not specified, it fetches information from the metadata server
  8336. type: string
  8337. serviceAccountRef:
  8338. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8339. properties:
  8340. audiences:
  8341. description: |-
  8342. Audience specifies the `aud` claim for the service account token
  8343. Some providers automatically extend the audience field based on well-known annotations for workload
  8344. identity (e.g. IRSA or GCP Workload Identity)
  8345. items:
  8346. type: string
  8347. type: array
  8348. name:
  8349. description: The name of the ServiceAccount resource being referred to.
  8350. maxLength: 253
  8351. minLength: 1
  8352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8353. type: string
  8354. namespace:
  8355. description: |-
  8356. Namespace of the resource being referred to.
  8357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8358. maxLength: 63
  8359. minLength: 1
  8360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8361. type: string
  8362. required:
  8363. - name
  8364. type: object
  8365. required:
  8366. - serviceAccountRef
  8367. type: object
  8368. required:
  8369. - role
  8370. type: object
  8371. iam:
  8372. description: |-
  8373. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8374. AWS IAM authentication method
  8375. properties:
  8376. externalID:
  8377. description: AWS External ID set on assumed IAM roles
  8378. type: string
  8379. jwt:
  8380. description: Specify a service account with IRSA enabled
  8381. properties:
  8382. serviceAccountRef:
  8383. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8384. properties:
  8385. audiences:
  8386. description: |-
  8387. Audience specifies the `aud` claim for the service account token
  8388. Some providers automatically extend the audience field based on well-known annotations for workload
  8389. identity (e.g. IRSA or GCP Workload Identity)
  8390. items:
  8391. type: string
  8392. type: array
  8393. name:
  8394. description: The name of the ServiceAccount resource being referred to.
  8395. maxLength: 253
  8396. minLength: 1
  8397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8398. type: string
  8399. namespace:
  8400. description: |-
  8401. Namespace of the resource being referred to.
  8402. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8403. maxLength: 63
  8404. minLength: 1
  8405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8406. type: string
  8407. required:
  8408. - name
  8409. type: object
  8410. type: object
  8411. path:
  8412. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8413. type: string
  8414. region:
  8415. description: AWS region
  8416. type: string
  8417. role:
  8418. description: This is the AWS role to be assumed before talking to vault
  8419. type: string
  8420. secretRef:
  8421. description: Specify credentials in a Secret object
  8422. properties:
  8423. accessKeyIDSecretRef:
  8424. description: The AccessKeyID is used for authentication
  8425. properties:
  8426. key:
  8427. description: |-
  8428. A key in the referenced Secret.
  8429. Some instances of this field may be defaulted, in others it may be required.
  8430. maxLength: 253
  8431. minLength: 1
  8432. pattern: ^[-._a-zA-Z0-9]+$
  8433. type: string
  8434. name:
  8435. description: The name of the Secret resource being referred to.
  8436. maxLength: 253
  8437. minLength: 1
  8438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8439. type: string
  8440. namespace:
  8441. description: |-
  8442. The namespace of the Secret resource being referred to.
  8443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8444. maxLength: 63
  8445. minLength: 1
  8446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8447. type: string
  8448. type: object
  8449. secretAccessKeySecretRef:
  8450. description: The SecretAccessKey is used for authentication
  8451. properties:
  8452. key:
  8453. description: |-
  8454. A key in the referenced Secret.
  8455. Some instances of this field may be defaulted, in others it may be required.
  8456. maxLength: 253
  8457. minLength: 1
  8458. pattern: ^[-._a-zA-Z0-9]+$
  8459. type: string
  8460. name:
  8461. description: The name of the Secret resource being referred to.
  8462. maxLength: 253
  8463. minLength: 1
  8464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8465. type: string
  8466. namespace:
  8467. description: |-
  8468. The namespace of the Secret resource being referred to.
  8469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8470. maxLength: 63
  8471. minLength: 1
  8472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8473. type: string
  8474. type: object
  8475. sessionTokenSecretRef:
  8476. description: |-
  8477. The SessionToken used for authentication
  8478. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8479. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8480. properties:
  8481. key:
  8482. description: |-
  8483. A key in the referenced Secret.
  8484. Some instances of this field may be defaulted, in others it may be required.
  8485. maxLength: 253
  8486. minLength: 1
  8487. pattern: ^[-._a-zA-Z0-9]+$
  8488. type: string
  8489. name:
  8490. description: The name of the Secret resource being referred to.
  8491. maxLength: 253
  8492. minLength: 1
  8493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8494. type: string
  8495. namespace:
  8496. description: |-
  8497. The namespace of the Secret resource being referred to.
  8498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8499. maxLength: 63
  8500. minLength: 1
  8501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8502. type: string
  8503. type: object
  8504. type: object
  8505. vaultAwsIamServerID:
  8506. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8507. type: string
  8508. vaultRole:
  8509. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8510. type: string
  8511. required:
  8512. - vaultRole
  8513. type: object
  8514. jwt:
  8515. description: |-
  8516. Jwt authenticates with Vault by passing role and JWT token using the
  8517. JWT/OIDC authentication method
  8518. properties:
  8519. kubernetesServiceAccountToken:
  8520. description: |-
  8521. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8522. a token for with the `TokenRequest` API.
  8523. properties:
  8524. audiences:
  8525. description: |-
  8526. Optional audiences field that will be used to request a temporary Kubernetes service
  8527. account token for the service account referenced by `serviceAccountRef`.
  8528. Defaults to a single audience `vault` it not specified.
  8529. Deprecated: use serviceAccountRef.Audiences instead
  8530. items:
  8531. type: string
  8532. type: array
  8533. expirationSeconds:
  8534. description: |-
  8535. Optional expiration time in seconds that will be used to request a temporary
  8536. Kubernetes service account token for the service account referenced by
  8537. `serviceAccountRef`.
  8538. Deprecated: this will be removed in the future.
  8539. Defaults to 10 minutes.
  8540. format: int64
  8541. type: integer
  8542. serviceAccountRef:
  8543. description: Service account field containing the name of a kubernetes ServiceAccount.
  8544. properties:
  8545. audiences:
  8546. description: |-
  8547. Audience specifies the `aud` claim for the service account token
  8548. Some providers automatically extend the audience field based on well-known annotations for workload
  8549. identity (e.g. IRSA or GCP Workload Identity)
  8550. items:
  8551. type: string
  8552. type: array
  8553. name:
  8554. description: The name of the ServiceAccount resource being referred to.
  8555. maxLength: 253
  8556. minLength: 1
  8557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8558. type: string
  8559. namespace:
  8560. description: |-
  8561. Namespace of the resource being referred to.
  8562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8563. maxLength: 63
  8564. minLength: 1
  8565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8566. type: string
  8567. required:
  8568. - name
  8569. type: object
  8570. required:
  8571. - serviceAccountRef
  8572. type: object
  8573. path:
  8574. default: jwt
  8575. description: |-
  8576. Path where the JWT authentication backend is mounted
  8577. in Vault, e.g: "jwt"
  8578. type: string
  8579. role:
  8580. description: |-
  8581. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8582. authentication method
  8583. type: string
  8584. secretRef:
  8585. description: |-
  8586. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8587. authenticate with Vault using the JWT/OIDC authentication method.
  8588. properties:
  8589. key:
  8590. description: |-
  8591. A key in the referenced Secret.
  8592. Some instances of this field may be defaulted, in others it may be required.
  8593. maxLength: 253
  8594. minLength: 1
  8595. pattern: ^[-._a-zA-Z0-9]+$
  8596. type: string
  8597. name:
  8598. description: The name of the Secret resource being referred to.
  8599. maxLength: 253
  8600. minLength: 1
  8601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8602. type: string
  8603. namespace:
  8604. description: |-
  8605. The namespace of the Secret resource being referred to.
  8606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8607. maxLength: 63
  8608. minLength: 1
  8609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8610. type: string
  8611. type: object
  8612. required:
  8613. - path
  8614. type: object
  8615. kubernetes:
  8616. description: |-
  8617. Kubernetes authenticates with Vault by passing the ServiceAccount
  8618. token stored in the named Secret resource to the Vault server.
  8619. properties:
  8620. mountPath:
  8621. default: kubernetes
  8622. description: |-
  8623. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8624. "kubernetes"
  8625. type: string
  8626. role:
  8627. description: |-
  8628. A required field containing the Vault Role to assume. A Role binds a
  8629. Kubernetes ServiceAccount with a set of Vault policies.
  8630. type: string
  8631. secretRef:
  8632. description: |-
  8633. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8634. for authenticating with Vault. If a name is specified without a key,
  8635. `token` is the default. If one is not specified, the one bound to
  8636. the controller will be used.
  8637. properties:
  8638. key:
  8639. description: |-
  8640. A key in the referenced Secret.
  8641. Some instances of this field may be defaulted, in others it may be required.
  8642. maxLength: 253
  8643. minLength: 1
  8644. pattern: ^[-._a-zA-Z0-9]+$
  8645. type: string
  8646. name:
  8647. description: The name of the Secret resource being referred to.
  8648. maxLength: 253
  8649. minLength: 1
  8650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8651. type: string
  8652. namespace:
  8653. description: |-
  8654. The namespace of the Secret resource being referred to.
  8655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8656. maxLength: 63
  8657. minLength: 1
  8658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8659. type: string
  8660. type: object
  8661. serviceAccountRef:
  8662. description: |-
  8663. Optional service account field containing the name of a kubernetes ServiceAccount.
  8664. If the service account is specified, the service account secret token JWT will be used
  8665. for authenticating with Vault. If the service account selector is not supplied,
  8666. the secretRef will be used instead.
  8667. properties:
  8668. audiences:
  8669. description: |-
  8670. Audience specifies the `aud` claim for the service account token
  8671. Some providers automatically extend the audience field based on well-known annotations for workload
  8672. identity (e.g. IRSA or GCP Workload Identity)
  8673. items:
  8674. type: string
  8675. type: array
  8676. name:
  8677. description: The name of the ServiceAccount resource being referred to.
  8678. maxLength: 253
  8679. minLength: 1
  8680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8681. type: string
  8682. namespace:
  8683. description: |-
  8684. Namespace of the resource being referred to.
  8685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8686. maxLength: 63
  8687. minLength: 1
  8688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8689. type: string
  8690. required:
  8691. - name
  8692. type: object
  8693. required:
  8694. - mountPath
  8695. - role
  8696. type: object
  8697. ldap:
  8698. description: |-
  8699. Ldap authenticates with Vault by passing username/password pair using
  8700. the LDAP authentication method
  8701. properties:
  8702. path:
  8703. default: ldap
  8704. description: |-
  8705. Path where the LDAP authentication backend is mounted
  8706. in Vault, e.g: "ldap"
  8707. type: string
  8708. secretRef:
  8709. description: |-
  8710. SecretRef to a key in a Secret resource containing password for the LDAP
  8711. user used to authenticate with Vault using the LDAP authentication
  8712. method
  8713. properties:
  8714. key:
  8715. description: |-
  8716. A key in the referenced Secret.
  8717. Some instances of this field may be defaulted, in others it may be required.
  8718. maxLength: 253
  8719. minLength: 1
  8720. pattern: ^[-._a-zA-Z0-9]+$
  8721. type: string
  8722. name:
  8723. description: The name of the Secret resource being referred to.
  8724. maxLength: 253
  8725. minLength: 1
  8726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8727. type: string
  8728. namespace:
  8729. description: |-
  8730. The namespace of the Secret resource being referred to.
  8731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8732. maxLength: 63
  8733. minLength: 1
  8734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8735. type: string
  8736. type: object
  8737. username:
  8738. description: |-
  8739. Username is an LDAP username used to authenticate using the LDAP Vault
  8740. authentication method
  8741. type: string
  8742. required:
  8743. - path
  8744. - username
  8745. type: object
  8746. namespace:
  8747. description: |-
  8748. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8749. Namespaces is a set of features within Vault Enterprise that allows
  8750. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8751. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8752. This will default to Vault.Namespace field if set, or empty otherwise
  8753. type: string
  8754. tokenSecretRef:
  8755. description: TokenSecretRef authenticates with Vault by presenting a token.
  8756. properties:
  8757. key:
  8758. description: |-
  8759. A key in the referenced Secret.
  8760. Some instances of this field may be defaulted, in others it may be required.
  8761. maxLength: 253
  8762. minLength: 1
  8763. pattern: ^[-._a-zA-Z0-9]+$
  8764. type: string
  8765. name:
  8766. description: The name of the Secret resource being referred to.
  8767. maxLength: 253
  8768. minLength: 1
  8769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8770. type: string
  8771. namespace:
  8772. description: |-
  8773. The namespace of the Secret resource being referred to.
  8774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8775. maxLength: 63
  8776. minLength: 1
  8777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8778. type: string
  8779. type: object
  8780. userPass:
  8781. description: UserPass authenticates with Vault by passing username/password pair
  8782. properties:
  8783. path:
  8784. default: userpass
  8785. description: |-
  8786. Path where the UserPassword authentication backend is mounted
  8787. in Vault, e.g: "userpass"
  8788. type: string
  8789. secretRef:
  8790. description: |-
  8791. SecretRef to a key in a Secret resource containing password for the
  8792. user used to authenticate with Vault using the UserPass authentication
  8793. method
  8794. properties:
  8795. key:
  8796. description: |-
  8797. A key in the referenced Secret.
  8798. Some instances of this field may be defaulted, in others it may be required.
  8799. maxLength: 253
  8800. minLength: 1
  8801. pattern: ^[-._a-zA-Z0-9]+$
  8802. type: string
  8803. name:
  8804. description: The name of the Secret resource being referred to.
  8805. maxLength: 253
  8806. minLength: 1
  8807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8808. type: string
  8809. namespace:
  8810. description: |-
  8811. The namespace of the Secret resource being referred to.
  8812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8813. maxLength: 63
  8814. minLength: 1
  8815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8816. type: string
  8817. type: object
  8818. username:
  8819. description: |-
  8820. Username is a username used to authenticate using the UserPass Vault
  8821. authentication method
  8822. type: string
  8823. required:
  8824. - path
  8825. - username
  8826. type: object
  8827. type: object
  8828. caBundle:
  8829. description: |-
  8830. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8831. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8832. plain HTTP protocol connection. If not set the system root certificates
  8833. are used to validate the TLS connection.
  8834. format: byte
  8835. type: string
  8836. caProvider:
  8837. description: The provider for the CA bundle to use to validate Vault server certificate.
  8838. properties:
  8839. key:
  8840. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8841. maxLength: 253
  8842. minLength: 1
  8843. pattern: ^[-._a-zA-Z0-9]+$
  8844. type: string
  8845. name:
  8846. description: The name of the object located at the provider type.
  8847. maxLength: 253
  8848. minLength: 1
  8849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8850. type: string
  8851. namespace:
  8852. description: |-
  8853. The namespace the Provider type is in.
  8854. Can only be defined when used in a ClusterSecretStore.
  8855. maxLength: 63
  8856. minLength: 1
  8857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8858. type: string
  8859. type:
  8860. description: The type of provider to use such as "Secret", or "ConfigMap".
  8861. enum:
  8862. - Secret
  8863. - ConfigMap
  8864. type: string
  8865. required:
  8866. - name
  8867. - type
  8868. type: object
  8869. checkAndSet:
  8870. description: |-
  8871. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8872. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8873. the current version of the secret to prevent unintentional overwrites.
  8874. properties:
  8875. required:
  8876. description: |-
  8877. Required when true, all write operations must include a check-and-set parameter.
  8878. This helps prevent unintentional overwrites of secrets.
  8879. type: boolean
  8880. type: object
  8881. forwardInconsistent:
  8882. description: |-
  8883. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8884. leader instead of simply retrying within a loop. This can increase performance if
  8885. the option is enabled serverside.
  8886. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8887. type: boolean
  8888. headers:
  8889. additionalProperties:
  8890. type: string
  8891. description: Headers to be added in Vault request
  8892. type: object
  8893. namespace:
  8894. description: |-
  8895. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8896. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8897. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8898. type: string
  8899. path:
  8900. description: |-
  8901. Path is the mount path of the Vault KV backend endpoint, e.g:
  8902. "secret". The v2 KV secret engine version specific "/data" path suffix
  8903. for fetching secrets from Vault is optional and will be appended
  8904. if not present in specified path.
  8905. type: string
  8906. readYourWrites:
  8907. description: |-
  8908. ReadYourWrites ensures isolated read-after-write semantics by
  8909. providing discovered cluster replication states in each request.
  8910. More information about eventual consistency in Vault can be found here
  8911. https://www.vaultproject.io/docs/enterprise/consistency
  8912. type: boolean
  8913. server:
  8914. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8915. type: string
  8916. tls:
  8917. description: |-
  8918. The configuration used for client side related TLS communication, when the Vault server
  8919. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8920. This parameter is ignored for plain HTTP protocol connection.
  8921. It's worth noting this configuration is different from the "TLS certificates auth method",
  8922. which is available under the `auth.cert` section.
  8923. properties:
  8924. certSecretRef:
  8925. description: |-
  8926. CertSecretRef is a certificate added to the transport layer
  8927. when communicating with the Vault server.
  8928. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8929. properties:
  8930. key:
  8931. description: |-
  8932. A key in the referenced Secret.
  8933. Some instances of this field may be defaulted, in others it may be required.
  8934. maxLength: 253
  8935. minLength: 1
  8936. pattern: ^[-._a-zA-Z0-9]+$
  8937. type: string
  8938. name:
  8939. description: The name of the Secret resource being referred to.
  8940. maxLength: 253
  8941. minLength: 1
  8942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8943. type: string
  8944. namespace:
  8945. description: |-
  8946. The namespace of the Secret resource being referred to.
  8947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8948. maxLength: 63
  8949. minLength: 1
  8950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8951. type: string
  8952. type: object
  8953. keySecretRef:
  8954. description: |-
  8955. KeySecretRef to a key in a Secret resource containing client private key
  8956. added to the transport layer when communicating with the Vault server.
  8957. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8958. properties:
  8959. key:
  8960. description: |-
  8961. A key in the referenced Secret.
  8962. Some instances of this field may be defaulted, in others it may be required.
  8963. maxLength: 253
  8964. minLength: 1
  8965. pattern: ^[-._a-zA-Z0-9]+$
  8966. type: string
  8967. name:
  8968. description: The name of the Secret resource being referred to.
  8969. maxLength: 253
  8970. minLength: 1
  8971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8972. type: string
  8973. namespace:
  8974. description: |-
  8975. The namespace of the Secret resource being referred to.
  8976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8977. maxLength: 63
  8978. minLength: 1
  8979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8980. type: string
  8981. type: object
  8982. type: object
  8983. version:
  8984. default: v2
  8985. description: |-
  8986. Version is the Vault KV secret engine version. This can be either "v1" or
  8987. "v2". Version defaults to "v2".
  8988. enum:
  8989. - v1
  8990. - v2
  8991. type: string
  8992. required:
  8993. - server
  8994. type: object
  8995. volcengine:
  8996. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8997. properties:
  8998. auth:
  8999. description: |-
  9000. Auth defines the authentication method to use.
  9001. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  9002. properties:
  9003. secretRef:
  9004. description: |-
  9005. SecretRef defines the static credentials to use for authentication.
  9006. If not set, IRSA is used.
  9007. properties:
  9008. accessKeyID:
  9009. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  9010. properties:
  9011. key:
  9012. description: |-
  9013. A key in the referenced Secret.
  9014. Some instances of this field may be defaulted, in others it may be required.
  9015. maxLength: 253
  9016. minLength: 1
  9017. pattern: ^[-._a-zA-Z0-9]+$
  9018. type: string
  9019. name:
  9020. description: The name of the Secret resource being referred to.
  9021. maxLength: 253
  9022. minLength: 1
  9023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9024. type: string
  9025. namespace:
  9026. description: |-
  9027. The namespace of the Secret resource being referred to.
  9028. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9029. maxLength: 63
  9030. minLength: 1
  9031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9032. type: string
  9033. type: object
  9034. secretAccessKey:
  9035. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  9036. properties:
  9037. key:
  9038. description: |-
  9039. A key in the referenced Secret.
  9040. Some instances of this field may be defaulted, in others it may be required.
  9041. maxLength: 253
  9042. minLength: 1
  9043. pattern: ^[-._a-zA-Z0-9]+$
  9044. type: string
  9045. name:
  9046. description: The name of the Secret resource being referred to.
  9047. maxLength: 253
  9048. minLength: 1
  9049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9050. type: string
  9051. namespace:
  9052. description: |-
  9053. The namespace of the Secret resource being referred to.
  9054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9055. maxLength: 63
  9056. minLength: 1
  9057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9058. type: string
  9059. type: object
  9060. token:
  9061. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  9062. properties:
  9063. key:
  9064. description: |-
  9065. A key in the referenced Secret.
  9066. Some instances of this field may be defaulted, in others it may be required.
  9067. maxLength: 253
  9068. minLength: 1
  9069. pattern: ^[-._a-zA-Z0-9]+$
  9070. type: string
  9071. name:
  9072. description: The name of the Secret resource being referred to.
  9073. maxLength: 253
  9074. minLength: 1
  9075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9076. type: string
  9077. namespace:
  9078. description: |-
  9079. The namespace of the Secret resource being referred to.
  9080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9081. maxLength: 63
  9082. minLength: 1
  9083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9084. type: string
  9085. type: object
  9086. required:
  9087. - accessKeyID
  9088. - secretAccessKey
  9089. type: object
  9090. type: object
  9091. region:
  9092. description: Region specifies the Volcengine region to connect to.
  9093. type: string
  9094. required:
  9095. - region
  9096. type: object
  9097. webhook:
  9098. description: Webhook configures this store to sync secrets using a generic templated webhook
  9099. properties:
  9100. auth:
  9101. description: Auth specifies a authorization protocol. Only one protocol may be set.
  9102. maxProperties: 1
  9103. minProperties: 1
  9104. properties:
  9105. ntlm:
  9106. description: NTLMProtocol configures the store to use NTLM for auth
  9107. properties:
  9108. passwordSecret:
  9109. description: |-
  9110. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9111. In some instances, `key` is a required field.
  9112. properties:
  9113. key:
  9114. description: |-
  9115. A key in the referenced Secret.
  9116. Some instances of this field may be defaulted, in others it may be required.
  9117. maxLength: 253
  9118. minLength: 1
  9119. pattern: ^[-._a-zA-Z0-9]+$
  9120. type: string
  9121. name:
  9122. description: The name of the Secret resource being referred to.
  9123. maxLength: 253
  9124. minLength: 1
  9125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9126. type: string
  9127. namespace:
  9128. description: |-
  9129. The namespace of the Secret resource being referred to.
  9130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9131. maxLength: 63
  9132. minLength: 1
  9133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9134. type: string
  9135. type: object
  9136. usernameSecret:
  9137. description: |-
  9138. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9139. In some instances, `key` is a required field.
  9140. properties:
  9141. key:
  9142. description: |-
  9143. A key in the referenced Secret.
  9144. Some instances of this field may be defaulted, in others it may be required.
  9145. maxLength: 253
  9146. minLength: 1
  9147. pattern: ^[-._a-zA-Z0-9]+$
  9148. type: string
  9149. name:
  9150. description: The name of the Secret resource being referred to.
  9151. maxLength: 253
  9152. minLength: 1
  9153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9154. type: string
  9155. namespace:
  9156. description: |-
  9157. The namespace of the Secret resource being referred to.
  9158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9159. maxLength: 63
  9160. minLength: 1
  9161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9162. type: string
  9163. type: object
  9164. required:
  9165. - passwordSecret
  9166. - usernameSecret
  9167. type: object
  9168. type: object
  9169. body:
  9170. description: Body
  9171. type: string
  9172. caBundle:
  9173. description: |-
  9174. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9175. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9176. plain HTTP protocol connection. If not set the system root certificates
  9177. are used to validate the TLS connection.
  9178. format: byte
  9179. type: string
  9180. caProvider:
  9181. description: The provider for the CA bundle to use to validate webhook server certificate.
  9182. properties:
  9183. key:
  9184. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9185. maxLength: 253
  9186. minLength: 1
  9187. pattern: ^[-._a-zA-Z0-9]+$
  9188. type: string
  9189. name:
  9190. description: The name of the object located at the provider type.
  9191. maxLength: 253
  9192. minLength: 1
  9193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9194. type: string
  9195. namespace:
  9196. description: The namespace the Provider type is in.
  9197. maxLength: 63
  9198. minLength: 1
  9199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9200. type: string
  9201. type:
  9202. description: The type of provider to use such as "Secret", or "ConfigMap".
  9203. enum:
  9204. - Secret
  9205. - ConfigMap
  9206. type: string
  9207. required:
  9208. - name
  9209. - type
  9210. type: object
  9211. headers:
  9212. additionalProperties:
  9213. type: string
  9214. description: Headers
  9215. type: object
  9216. method:
  9217. description: Webhook Method
  9218. type: string
  9219. result:
  9220. description: Result formatting
  9221. properties:
  9222. jsonPath:
  9223. description: Json path of return value
  9224. type: string
  9225. type: object
  9226. secrets:
  9227. description: |-
  9228. Secrets to fill in templates
  9229. These secrets will be passed to the templating function as key value pairs under the given name
  9230. items:
  9231. description: WebhookSecret defines a secret that will be passed to the webhook request.
  9232. properties:
  9233. name:
  9234. description: Name of this secret in templates
  9235. type: string
  9236. secretRef:
  9237. description: Secret ref to fill in credentials
  9238. properties:
  9239. key:
  9240. description: |-
  9241. A key in the referenced Secret.
  9242. Some instances of this field may be defaulted, in others it may be required.
  9243. maxLength: 253
  9244. minLength: 1
  9245. pattern: ^[-._a-zA-Z0-9]+$
  9246. type: string
  9247. name:
  9248. description: The name of the Secret resource being referred to.
  9249. maxLength: 253
  9250. minLength: 1
  9251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9252. type: string
  9253. namespace:
  9254. description: |-
  9255. The namespace of the Secret resource being referred to.
  9256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9257. maxLength: 63
  9258. minLength: 1
  9259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9260. type: string
  9261. type: object
  9262. required:
  9263. - name
  9264. - secretRef
  9265. type: object
  9266. type: array
  9267. timeout:
  9268. description: Timeout
  9269. type: string
  9270. url:
  9271. description: Webhook url to call
  9272. type: string
  9273. required:
  9274. - url
  9275. type: object
  9276. yandexcertificatemanager:
  9277. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9278. properties:
  9279. apiEndpoint:
  9280. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9281. type: string
  9282. auth:
  9283. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9284. properties:
  9285. authorizedKeySecretRef:
  9286. description: The authorized key used for authentication
  9287. properties:
  9288. key:
  9289. description: |-
  9290. A key in the referenced Secret.
  9291. Some instances of this field may be defaulted, in others it may be required.
  9292. maxLength: 253
  9293. minLength: 1
  9294. pattern: ^[-._a-zA-Z0-9]+$
  9295. type: string
  9296. name:
  9297. description: The name of the Secret resource being referred to.
  9298. maxLength: 253
  9299. minLength: 1
  9300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9301. type: string
  9302. namespace:
  9303. description: |-
  9304. The namespace of the Secret resource being referred to.
  9305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9306. maxLength: 63
  9307. minLength: 1
  9308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9309. type: string
  9310. type: object
  9311. type: object
  9312. caProvider:
  9313. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9314. properties:
  9315. certSecretRef:
  9316. description: |-
  9317. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9318. In some instances, `key` is a required field.
  9319. properties:
  9320. key:
  9321. description: |-
  9322. A key in the referenced Secret.
  9323. Some instances of this field may be defaulted, in others it may be required.
  9324. maxLength: 253
  9325. minLength: 1
  9326. pattern: ^[-._a-zA-Z0-9]+$
  9327. type: string
  9328. name:
  9329. description: The name of the Secret resource being referred to.
  9330. maxLength: 253
  9331. minLength: 1
  9332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9333. type: string
  9334. namespace:
  9335. description: |-
  9336. The namespace of the Secret resource being referred to.
  9337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9338. maxLength: 63
  9339. minLength: 1
  9340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9341. type: string
  9342. type: object
  9343. type: object
  9344. fetching:
  9345. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9346. maxProperties: 1
  9347. minProperties: 1
  9348. properties:
  9349. byID:
  9350. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9351. type: object
  9352. byName:
  9353. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9354. properties:
  9355. folderID:
  9356. description: The folder to fetch secrets from
  9357. type: string
  9358. required:
  9359. - folderID
  9360. type: object
  9361. type: object
  9362. required:
  9363. - auth
  9364. type: object
  9365. yandexlockbox:
  9366. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9367. properties:
  9368. apiEndpoint:
  9369. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9370. type: string
  9371. auth:
  9372. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9373. properties:
  9374. authorizedKeySecretRef:
  9375. description: The authorized key used for authentication
  9376. properties:
  9377. key:
  9378. description: |-
  9379. A key in the referenced Secret.
  9380. Some instances of this field may be defaulted, in others it may be required.
  9381. maxLength: 253
  9382. minLength: 1
  9383. pattern: ^[-._a-zA-Z0-9]+$
  9384. type: string
  9385. name:
  9386. description: The name of the Secret resource being referred to.
  9387. maxLength: 253
  9388. minLength: 1
  9389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9390. type: string
  9391. namespace:
  9392. description: |-
  9393. The namespace of the Secret resource being referred to.
  9394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9395. maxLength: 63
  9396. minLength: 1
  9397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9398. type: string
  9399. type: object
  9400. type: object
  9401. caProvider:
  9402. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9403. properties:
  9404. certSecretRef:
  9405. description: |-
  9406. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9407. In some instances, `key` is a required field.
  9408. properties:
  9409. key:
  9410. description: |-
  9411. A key in the referenced Secret.
  9412. Some instances of this field may be defaulted, in others it may be required.
  9413. maxLength: 253
  9414. minLength: 1
  9415. pattern: ^[-._a-zA-Z0-9]+$
  9416. type: string
  9417. name:
  9418. description: The name of the Secret resource being referred to.
  9419. maxLength: 253
  9420. minLength: 1
  9421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9422. type: string
  9423. namespace:
  9424. description: |-
  9425. The namespace of the Secret resource being referred to.
  9426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9427. maxLength: 63
  9428. minLength: 1
  9429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9430. type: string
  9431. type: object
  9432. type: object
  9433. fetching:
  9434. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9435. maxProperties: 1
  9436. minProperties: 1
  9437. properties:
  9438. byID:
  9439. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9440. type: object
  9441. byName:
  9442. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9443. properties:
  9444. folderID:
  9445. description: The folder to fetch secrets from
  9446. type: string
  9447. required:
  9448. - folderID
  9449. type: object
  9450. type: object
  9451. required:
  9452. - auth
  9453. type: object
  9454. type: object
  9455. refreshInterval:
  9456. anyOf:
  9457. - type: integer
  9458. - type: string
  9459. description: |-
  9460. Used to configure store refresh interval. Accepts either an integer number
  9461. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9462. 0 will default to the controller config.
  9463. x-kubernetes-int-or-string: true
  9464. retrySettings:
  9465. description: Used to configure HTTP retries on failures.
  9466. properties:
  9467. maxRetries:
  9468. format: int32
  9469. type: integer
  9470. retryInterval:
  9471. type: string
  9472. type: object
  9473. required:
  9474. - provider
  9475. type: object
  9476. status:
  9477. description: SecretStoreStatus defines the observed state of the SecretStore.
  9478. properties:
  9479. capabilities:
  9480. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9481. type: string
  9482. conditions:
  9483. items:
  9484. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9485. properties:
  9486. lastTransitionTime:
  9487. format: date-time
  9488. type: string
  9489. message:
  9490. type: string
  9491. reason:
  9492. type: string
  9493. status:
  9494. type: string
  9495. type:
  9496. description: SecretStoreConditionType represents the condition of the SecretStore.
  9497. type: string
  9498. required:
  9499. - status
  9500. - type
  9501. type: object
  9502. type: array
  9503. type: object
  9504. type: object
  9505. served: true
  9506. storage: true
  9507. subresources:
  9508. status: {}
  9509. - additionalPrinterColumns:
  9510. - jsonPath: .metadata.creationTimestamp
  9511. name: AGE
  9512. type: date
  9513. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9514. name: Status
  9515. type: string
  9516. - jsonPath: .status.capabilities
  9517. name: Capabilities
  9518. type: string
  9519. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9520. name: Ready
  9521. type: string
  9522. deprecated: true
  9523. name: v1beta1
  9524. schema:
  9525. openAPIV3Schema:
  9526. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9527. properties:
  9528. apiVersion:
  9529. description: |-
  9530. APIVersion defines the versioned schema of this representation of an object.
  9531. Servers should convert recognized schemas to the latest internal value, and
  9532. may reject unrecognized values.
  9533. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9534. type: string
  9535. kind:
  9536. description: |-
  9537. Kind is a string value representing the REST resource this object represents.
  9538. Servers may infer this from the endpoint the client submits requests to.
  9539. Cannot be updated.
  9540. In CamelCase.
  9541. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9542. type: string
  9543. metadata:
  9544. type: object
  9545. spec:
  9546. description: SecretStoreSpec defines the desired state of SecretStore.
  9547. properties:
  9548. conditions:
  9549. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9550. items:
  9551. description: |-
  9552. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9553. for a ClusterSecretStore instance.
  9554. properties:
  9555. namespaceRegexes:
  9556. description: Choose namespaces by using regex matching
  9557. items:
  9558. type: string
  9559. type: array
  9560. namespaceSelector:
  9561. description: Choose namespace using a labelSelector
  9562. properties:
  9563. matchExpressions:
  9564. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9565. items:
  9566. description: |-
  9567. A label selector requirement is a selector that contains values, a key, and an operator that
  9568. relates the key and values.
  9569. properties:
  9570. key:
  9571. description: key is the label key that the selector applies to.
  9572. type: string
  9573. operator:
  9574. description: |-
  9575. operator represents a key's relationship to a set of values.
  9576. Valid operators are In, NotIn, Exists and DoesNotExist.
  9577. type: string
  9578. values:
  9579. description: |-
  9580. values is an array of string values. If the operator is In or NotIn,
  9581. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9582. the values array must be empty. This array is replaced during a strategic
  9583. merge patch.
  9584. items:
  9585. type: string
  9586. type: array
  9587. x-kubernetes-list-type: atomic
  9588. required:
  9589. - key
  9590. - operator
  9591. type: object
  9592. type: array
  9593. x-kubernetes-list-type: atomic
  9594. matchLabels:
  9595. additionalProperties:
  9596. type: string
  9597. description: |-
  9598. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9599. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9600. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9601. type: object
  9602. type: object
  9603. x-kubernetes-map-type: atomic
  9604. namespaces:
  9605. description: Choose namespaces by name
  9606. items:
  9607. maxLength: 63
  9608. minLength: 1
  9609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9610. type: string
  9611. type: array
  9612. type: object
  9613. type: array
  9614. controller:
  9615. description: |-
  9616. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9617. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9618. type: string
  9619. provider:
  9620. description: Used to configure the provider. Only one provider may be set
  9621. maxProperties: 1
  9622. minProperties: 1
  9623. properties:
  9624. akeyless:
  9625. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9626. properties:
  9627. akeylessGWApiURL:
  9628. description: Akeyless GW API Url from which the secrets to be fetched from.
  9629. type: string
  9630. authSecretRef:
  9631. description: Auth configures how the operator authenticates with Akeyless.
  9632. properties:
  9633. kubernetesAuth:
  9634. description: |-
  9635. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9636. token stored in the named Secret resource.
  9637. properties:
  9638. accessID:
  9639. description: the Akeyless Kubernetes auth-method access-id
  9640. type: string
  9641. k8sConfName:
  9642. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9643. type: string
  9644. secretRef:
  9645. description: |-
  9646. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9647. for authenticating with Akeyless. If a name is specified without a key,
  9648. `token` is the default. If one is not specified, the one bound to
  9649. the controller will be used.
  9650. properties:
  9651. key:
  9652. description: |-
  9653. A key in the referenced Secret.
  9654. Some instances of this field may be defaulted, in others it may be required.
  9655. maxLength: 253
  9656. minLength: 1
  9657. pattern: ^[-._a-zA-Z0-9]+$
  9658. type: string
  9659. name:
  9660. description: The name of the Secret resource being referred to.
  9661. maxLength: 253
  9662. minLength: 1
  9663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9664. type: string
  9665. namespace:
  9666. description: |-
  9667. The namespace of the Secret resource being referred to.
  9668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9669. maxLength: 63
  9670. minLength: 1
  9671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9672. type: string
  9673. type: object
  9674. serviceAccountRef:
  9675. description: |-
  9676. Optional service account field containing the name of a kubernetes ServiceAccount.
  9677. If the service account is specified, the service account secret token JWT will be used
  9678. for authenticating with Akeyless. If the service account selector is not supplied,
  9679. the secretRef will be used instead.
  9680. properties:
  9681. audiences:
  9682. description: |-
  9683. Audience specifies the `aud` claim for the service account token
  9684. Some providers automatically extend the audience field based on well-known annotations for workload
  9685. identity (e.g. IRSA or GCP Workload Identity)
  9686. items:
  9687. type: string
  9688. type: array
  9689. name:
  9690. description: The name of the ServiceAccount resource being referred to.
  9691. maxLength: 253
  9692. minLength: 1
  9693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9694. type: string
  9695. namespace:
  9696. description: |-
  9697. Namespace of the resource being referred to.
  9698. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9699. maxLength: 63
  9700. minLength: 1
  9701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9702. type: string
  9703. required:
  9704. - name
  9705. type: object
  9706. required:
  9707. - accessID
  9708. - k8sConfName
  9709. type: object
  9710. secretRef:
  9711. description: |-
  9712. Reference to a Secret that contains the details
  9713. to authenticate with Akeyless.
  9714. properties:
  9715. accessID:
  9716. description: The SecretAccessID is used for authentication
  9717. properties:
  9718. key:
  9719. description: |-
  9720. A key in the referenced Secret.
  9721. Some instances of this field may be defaulted, in others it may be required.
  9722. maxLength: 253
  9723. minLength: 1
  9724. pattern: ^[-._a-zA-Z0-9]+$
  9725. type: string
  9726. name:
  9727. description: The name of the Secret resource being referred to.
  9728. maxLength: 253
  9729. minLength: 1
  9730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9731. type: string
  9732. namespace:
  9733. description: |-
  9734. The namespace of the Secret resource being referred to.
  9735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9736. maxLength: 63
  9737. minLength: 1
  9738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9739. type: string
  9740. type: object
  9741. accessType:
  9742. description: |-
  9743. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9744. In some instances, `key` is a required field.
  9745. properties:
  9746. key:
  9747. description: |-
  9748. A key in the referenced Secret.
  9749. Some instances of this field may be defaulted, in others it may be required.
  9750. maxLength: 253
  9751. minLength: 1
  9752. pattern: ^[-._a-zA-Z0-9]+$
  9753. type: string
  9754. name:
  9755. description: The name of the Secret resource being referred to.
  9756. maxLength: 253
  9757. minLength: 1
  9758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9759. type: string
  9760. namespace:
  9761. description: |-
  9762. The namespace of the Secret resource being referred to.
  9763. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9764. maxLength: 63
  9765. minLength: 1
  9766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9767. type: string
  9768. type: object
  9769. accessTypeParam:
  9770. description: |-
  9771. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9772. In some instances, `key` is a required field.
  9773. properties:
  9774. key:
  9775. description: |-
  9776. A key in the referenced Secret.
  9777. Some instances of this field may be defaulted, in others it may be required.
  9778. maxLength: 253
  9779. minLength: 1
  9780. pattern: ^[-._a-zA-Z0-9]+$
  9781. type: string
  9782. name:
  9783. description: The name of the Secret resource being referred to.
  9784. maxLength: 253
  9785. minLength: 1
  9786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9787. type: string
  9788. namespace:
  9789. description: |-
  9790. The namespace of the Secret resource being referred to.
  9791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9792. maxLength: 63
  9793. minLength: 1
  9794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9795. type: string
  9796. type: object
  9797. type: object
  9798. type: object
  9799. caBundle:
  9800. description: |-
  9801. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9802. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9803. are used to validate the TLS connection.
  9804. format: byte
  9805. type: string
  9806. caProvider:
  9807. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9808. properties:
  9809. key:
  9810. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9811. maxLength: 253
  9812. minLength: 1
  9813. pattern: ^[-._a-zA-Z0-9]+$
  9814. type: string
  9815. name:
  9816. description: The name of the object located at the provider type.
  9817. maxLength: 253
  9818. minLength: 1
  9819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9820. type: string
  9821. namespace:
  9822. description: |-
  9823. The namespace the Provider type is in.
  9824. Can only be defined when used in a ClusterSecretStore.
  9825. maxLength: 63
  9826. minLength: 1
  9827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9828. type: string
  9829. type:
  9830. description: The type of provider to use such as "Secret", or "ConfigMap".
  9831. enum:
  9832. - Secret
  9833. - ConfigMap
  9834. type: string
  9835. required:
  9836. - name
  9837. - type
  9838. type: object
  9839. required:
  9840. - akeylessGWApiURL
  9841. - authSecretRef
  9842. type: object
  9843. alibaba:
  9844. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9845. properties:
  9846. auth:
  9847. description: AlibabaAuth contains a secretRef for credentials.
  9848. properties:
  9849. rrsa:
  9850. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9851. properties:
  9852. oidcProviderArn:
  9853. type: string
  9854. oidcTokenFilePath:
  9855. type: string
  9856. roleArn:
  9857. type: string
  9858. sessionName:
  9859. type: string
  9860. required:
  9861. - oidcProviderArn
  9862. - oidcTokenFilePath
  9863. - roleArn
  9864. - sessionName
  9865. type: object
  9866. secretRef:
  9867. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9868. properties:
  9869. accessKeyIDSecretRef:
  9870. description: The AccessKeyID is used for authentication
  9871. properties:
  9872. key:
  9873. description: |-
  9874. A key in the referenced Secret.
  9875. Some instances of this field may be defaulted, in others it may be required.
  9876. maxLength: 253
  9877. minLength: 1
  9878. pattern: ^[-._a-zA-Z0-9]+$
  9879. type: string
  9880. name:
  9881. description: The name of the Secret resource being referred to.
  9882. maxLength: 253
  9883. minLength: 1
  9884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9885. type: string
  9886. namespace:
  9887. description: |-
  9888. The namespace of the Secret resource being referred to.
  9889. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9890. maxLength: 63
  9891. minLength: 1
  9892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9893. type: string
  9894. type: object
  9895. accessKeySecretSecretRef:
  9896. description: The AccessKeySecret is used for authentication
  9897. properties:
  9898. key:
  9899. description: |-
  9900. A key in the referenced Secret.
  9901. Some instances of this field may be defaulted, in others it may be required.
  9902. maxLength: 253
  9903. minLength: 1
  9904. pattern: ^[-._a-zA-Z0-9]+$
  9905. type: string
  9906. name:
  9907. description: The name of the Secret resource being referred to.
  9908. maxLength: 253
  9909. minLength: 1
  9910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9911. type: string
  9912. namespace:
  9913. description: |-
  9914. The namespace of the Secret resource being referred to.
  9915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9916. maxLength: 63
  9917. minLength: 1
  9918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9919. type: string
  9920. type: object
  9921. required:
  9922. - accessKeyIDSecretRef
  9923. - accessKeySecretSecretRef
  9924. type: object
  9925. type: object
  9926. regionID:
  9927. description: Alibaba Region to be used for the provider
  9928. type: string
  9929. required:
  9930. - auth
  9931. - regionID
  9932. type: object
  9933. aws:
  9934. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9935. properties:
  9936. additionalRoles:
  9937. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9938. items:
  9939. type: string
  9940. type: array
  9941. auth:
  9942. description: |-
  9943. Auth defines the information necessary to authenticate against AWS
  9944. if not set aws sdk will infer credentials from your environment
  9945. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9946. properties:
  9947. jwt:
  9948. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9949. properties:
  9950. serviceAccountRef:
  9951. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9952. properties:
  9953. audiences:
  9954. description: |-
  9955. Audience specifies the `aud` claim for the service account token
  9956. Some providers automatically extend the audience field based on well-known annotations for workload
  9957. identity (e.g. IRSA or GCP Workload Identity)
  9958. items:
  9959. type: string
  9960. type: array
  9961. name:
  9962. description: The name of the ServiceAccount resource being referred to.
  9963. maxLength: 253
  9964. minLength: 1
  9965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9966. type: string
  9967. namespace:
  9968. description: |-
  9969. Namespace of the resource being referred to.
  9970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9971. maxLength: 63
  9972. minLength: 1
  9973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9974. type: string
  9975. required:
  9976. - name
  9977. type: object
  9978. type: object
  9979. secretRef:
  9980. description: |-
  9981. AWSAuthSecretRef holds secret references for AWS credentials
  9982. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9983. properties:
  9984. accessKeyIDSecretRef:
  9985. description: The AccessKeyID is used for authentication
  9986. properties:
  9987. key:
  9988. description: |-
  9989. A key in the referenced Secret.
  9990. Some instances of this field may be defaulted, in others it may be required.
  9991. maxLength: 253
  9992. minLength: 1
  9993. pattern: ^[-._a-zA-Z0-9]+$
  9994. type: string
  9995. name:
  9996. description: The name of the Secret resource being referred to.
  9997. maxLength: 253
  9998. minLength: 1
  9999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10000. type: string
  10001. namespace:
  10002. description: |-
  10003. The namespace of the Secret resource being referred to.
  10004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10005. maxLength: 63
  10006. minLength: 1
  10007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10008. type: string
  10009. type: object
  10010. secretAccessKeySecretRef:
  10011. description: The SecretAccessKey is used for authentication
  10012. properties:
  10013. key:
  10014. description: |-
  10015. A key in the referenced Secret.
  10016. Some instances of this field may be defaulted, in others it may be required.
  10017. maxLength: 253
  10018. minLength: 1
  10019. pattern: ^[-._a-zA-Z0-9]+$
  10020. type: string
  10021. name:
  10022. description: The name of the Secret resource being referred to.
  10023. maxLength: 253
  10024. minLength: 1
  10025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10026. type: string
  10027. namespace:
  10028. description: |-
  10029. The namespace of the Secret resource being referred to.
  10030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10031. maxLength: 63
  10032. minLength: 1
  10033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10034. type: string
  10035. type: object
  10036. sessionTokenSecretRef:
  10037. description: |-
  10038. The SessionToken used for authentication
  10039. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  10040. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  10041. properties:
  10042. key:
  10043. description: |-
  10044. A key in the referenced Secret.
  10045. Some instances of this field may be defaulted, in others it may be required.
  10046. maxLength: 253
  10047. minLength: 1
  10048. pattern: ^[-._a-zA-Z0-9]+$
  10049. type: string
  10050. name:
  10051. description: The name of the Secret resource being referred to.
  10052. maxLength: 253
  10053. minLength: 1
  10054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10055. type: string
  10056. namespace:
  10057. description: |-
  10058. The namespace of the Secret resource being referred to.
  10059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10060. maxLength: 63
  10061. minLength: 1
  10062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10063. type: string
  10064. type: object
  10065. type: object
  10066. type: object
  10067. externalID:
  10068. description: AWS External ID set on assumed IAM roles
  10069. type: string
  10070. prefix:
  10071. description: Prefix adds a prefix to all retrieved values.
  10072. type: string
  10073. region:
  10074. description: AWS Region to be used for the provider
  10075. type: string
  10076. role:
  10077. description: Role is a Role ARN which the provider will assume
  10078. type: string
  10079. secretsManager:
  10080. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  10081. properties:
  10082. forceDeleteWithoutRecovery:
  10083. description: |-
  10084. Specifies whether to delete the secret without any recovery window. You
  10085. can't use both this parameter and RecoveryWindowInDays in the same call.
  10086. If you don't use either, then by default Secrets Manager uses a 30 day
  10087. recovery window.
  10088. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  10089. type: boolean
  10090. recoveryWindowInDays:
  10091. description: |-
  10092. The number of days from 7 to 30 that Secrets Manager waits before
  10093. permanently deleting the secret. You can't use both this parameter and
  10094. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  10095. then by default Secrets Manager uses a 30 day recovery window.
  10096. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  10097. format: int64
  10098. type: integer
  10099. type: object
  10100. service:
  10101. description: Service defines which service should be used to fetch the secrets
  10102. enum:
  10103. - SecretsManager
  10104. - ParameterStore
  10105. type: string
  10106. sessionTags:
  10107. description: AWS STS assume role session tags
  10108. items:
  10109. description: Tag defines a tag key and value for AWS resources.
  10110. properties:
  10111. key:
  10112. type: string
  10113. value:
  10114. type: string
  10115. required:
  10116. - key
  10117. - value
  10118. type: object
  10119. type: array
  10120. transitiveTagKeys:
  10121. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  10122. items:
  10123. type: string
  10124. type: array
  10125. required:
  10126. - region
  10127. - service
  10128. type: object
  10129. azurekv:
  10130. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  10131. properties:
  10132. authSecretRef:
  10133. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10134. properties:
  10135. clientCertificate:
  10136. description: The Azure ClientCertificate of the service principle used for authentication.
  10137. properties:
  10138. key:
  10139. description: |-
  10140. A key in the referenced Secret.
  10141. Some instances of this field may be defaulted, in others it may be required.
  10142. maxLength: 253
  10143. minLength: 1
  10144. pattern: ^[-._a-zA-Z0-9]+$
  10145. type: string
  10146. name:
  10147. description: The name of the Secret resource being referred to.
  10148. maxLength: 253
  10149. minLength: 1
  10150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10151. type: string
  10152. namespace:
  10153. description: |-
  10154. The namespace of the Secret resource being referred to.
  10155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10156. maxLength: 63
  10157. minLength: 1
  10158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10159. type: string
  10160. type: object
  10161. clientId:
  10162. description: The Azure clientId of the service principle or managed identity used for authentication.
  10163. properties:
  10164. key:
  10165. description: |-
  10166. A key in the referenced Secret.
  10167. Some instances of this field may be defaulted, in others it may be required.
  10168. maxLength: 253
  10169. minLength: 1
  10170. pattern: ^[-._a-zA-Z0-9]+$
  10171. type: string
  10172. name:
  10173. description: The name of the Secret resource being referred to.
  10174. maxLength: 253
  10175. minLength: 1
  10176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10177. type: string
  10178. namespace:
  10179. description: |-
  10180. The namespace of the Secret resource being referred to.
  10181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10182. maxLength: 63
  10183. minLength: 1
  10184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10185. type: string
  10186. type: object
  10187. clientSecret:
  10188. description: The Azure ClientSecret of the service principle used for authentication.
  10189. properties:
  10190. key:
  10191. description: |-
  10192. A key in the referenced Secret.
  10193. Some instances of this field may be defaulted, in others it may be required.
  10194. maxLength: 253
  10195. minLength: 1
  10196. pattern: ^[-._a-zA-Z0-9]+$
  10197. type: string
  10198. name:
  10199. description: The name of the Secret resource being referred to.
  10200. maxLength: 253
  10201. minLength: 1
  10202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10203. type: string
  10204. namespace:
  10205. description: |-
  10206. The namespace of the Secret resource being referred to.
  10207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10208. maxLength: 63
  10209. minLength: 1
  10210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10211. type: string
  10212. type: object
  10213. tenantId:
  10214. description: The Azure tenantId of the managed identity used for authentication.
  10215. properties:
  10216. key:
  10217. description: |-
  10218. A key in the referenced Secret.
  10219. Some instances of this field may be defaulted, in others it may be required.
  10220. maxLength: 253
  10221. minLength: 1
  10222. pattern: ^[-._a-zA-Z0-9]+$
  10223. type: string
  10224. name:
  10225. description: The name of the Secret resource being referred to.
  10226. maxLength: 253
  10227. minLength: 1
  10228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10229. type: string
  10230. namespace:
  10231. description: |-
  10232. The namespace of the Secret resource being referred to.
  10233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10234. maxLength: 63
  10235. minLength: 1
  10236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10237. type: string
  10238. type: object
  10239. type: object
  10240. authType:
  10241. default: ServicePrincipal
  10242. description: |-
  10243. Auth type defines how to authenticate to the keyvault service.
  10244. Valid values are:
  10245. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10246. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10247. enum:
  10248. - ServicePrincipal
  10249. - ManagedIdentity
  10250. - WorkloadIdentity
  10251. type: string
  10252. environmentType:
  10253. default: PublicCloud
  10254. description: |-
  10255. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10256. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10257. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10258. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10259. enum:
  10260. - PublicCloud
  10261. - USGovernmentCloud
  10262. - ChinaCloud
  10263. - GermanCloud
  10264. type: string
  10265. identityId:
  10266. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10267. type: string
  10268. serviceAccountRef:
  10269. description: |-
  10270. ServiceAccountRef specified the service account
  10271. that should be used when authenticating with WorkloadIdentity.
  10272. properties:
  10273. audiences:
  10274. description: |-
  10275. Audience specifies the `aud` claim for the service account token
  10276. Some providers automatically extend the audience field based on well-known annotations for workload
  10277. identity (e.g. IRSA or GCP Workload Identity)
  10278. items:
  10279. type: string
  10280. type: array
  10281. name:
  10282. description: The name of the ServiceAccount resource being referred to.
  10283. maxLength: 253
  10284. minLength: 1
  10285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10286. type: string
  10287. namespace:
  10288. description: |-
  10289. Namespace of the resource being referred to.
  10290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10291. maxLength: 63
  10292. minLength: 1
  10293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10294. type: string
  10295. required:
  10296. - name
  10297. type: object
  10298. tenantId:
  10299. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10300. type: string
  10301. vaultUrl:
  10302. description: Vault Url from which the secrets to be fetched from.
  10303. type: string
  10304. required:
  10305. - vaultUrl
  10306. type: object
  10307. beyondtrust:
  10308. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10309. properties:
  10310. auth:
  10311. description: Auth configures how the operator authenticates with Beyondtrust.
  10312. properties:
  10313. apiKey:
  10314. description: APIKey If not provided then ClientID/ClientSecret become required.
  10315. properties:
  10316. secretRef:
  10317. description: SecretRef references a key in a secret that will be used as value.
  10318. properties:
  10319. key:
  10320. description: |-
  10321. A key in the referenced Secret.
  10322. Some instances of this field may be defaulted, in others it may be required.
  10323. maxLength: 253
  10324. minLength: 1
  10325. pattern: ^[-._a-zA-Z0-9]+$
  10326. type: string
  10327. name:
  10328. description: The name of the Secret resource being referred to.
  10329. maxLength: 253
  10330. minLength: 1
  10331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10332. type: string
  10333. namespace:
  10334. description: |-
  10335. The namespace of the Secret resource being referred to.
  10336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10337. maxLength: 63
  10338. minLength: 1
  10339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10340. type: string
  10341. type: object
  10342. value:
  10343. description: Value can be specified directly to set a value without using a secret.
  10344. type: string
  10345. type: object
  10346. certificate:
  10347. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10348. properties:
  10349. secretRef:
  10350. description: SecretRef references a key in a secret that will be used as value.
  10351. properties:
  10352. key:
  10353. description: |-
  10354. A key in the referenced Secret.
  10355. Some instances of this field may be defaulted, in others it may be required.
  10356. maxLength: 253
  10357. minLength: 1
  10358. pattern: ^[-._a-zA-Z0-9]+$
  10359. type: string
  10360. name:
  10361. description: The name of the Secret resource being referred to.
  10362. maxLength: 253
  10363. minLength: 1
  10364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10365. type: string
  10366. namespace:
  10367. description: |-
  10368. The namespace of the Secret resource being referred to.
  10369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10370. maxLength: 63
  10371. minLength: 1
  10372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10373. type: string
  10374. type: object
  10375. value:
  10376. description: Value can be specified directly to set a value without using a secret.
  10377. type: string
  10378. type: object
  10379. certificateKey:
  10380. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10381. properties:
  10382. secretRef:
  10383. description: SecretRef references a key in a secret that will be used as value.
  10384. properties:
  10385. key:
  10386. description: |-
  10387. A key in the referenced Secret.
  10388. Some instances of this field may be defaulted, in others it may be required.
  10389. maxLength: 253
  10390. minLength: 1
  10391. pattern: ^[-._a-zA-Z0-9]+$
  10392. type: string
  10393. name:
  10394. description: The name of the Secret resource being referred to.
  10395. maxLength: 253
  10396. minLength: 1
  10397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10398. type: string
  10399. namespace:
  10400. description: |-
  10401. The namespace of the Secret resource being referred to.
  10402. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10403. maxLength: 63
  10404. minLength: 1
  10405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10406. type: string
  10407. type: object
  10408. value:
  10409. description: Value can be specified directly to set a value without using a secret.
  10410. type: string
  10411. type: object
  10412. clientId:
  10413. description: ClientID is the API OAuth Client ID.
  10414. properties:
  10415. secretRef:
  10416. description: SecretRef references a key in a secret that will be used as value.
  10417. properties:
  10418. key:
  10419. description: |-
  10420. A key in the referenced Secret.
  10421. Some instances of this field may be defaulted, in others it may be required.
  10422. maxLength: 253
  10423. minLength: 1
  10424. pattern: ^[-._a-zA-Z0-9]+$
  10425. type: string
  10426. name:
  10427. description: The name of the Secret resource being referred to.
  10428. maxLength: 253
  10429. minLength: 1
  10430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10431. type: string
  10432. namespace:
  10433. description: |-
  10434. The namespace of the Secret resource being referred to.
  10435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10436. maxLength: 63
  10437. minLength: 1
  10438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10439. type: string
  10440. type: object
  10441. value:
  10442. description: Value can be specified directly to set a value without using a secret.
  10443. type: string
  10444. type: object
  10445. clientSecret:
  10446. description: ClientSecret is the API OAuth Client Secret.
  10447. properties:
  10448. secretRef:
  10449. description: SecretRef references a key in a secret that will be used as value.
  10450. properties:
  10451. key:
  10452. description: |-
  10453. A key in the referenced Secret.
  10454. Some instances of this field may be defaulted, in others it may be required.
  10455. maxLength: 253
  10456. minLength: 1
  10457. pattern: ^[-._a-zA-Z0-9]+$
  10458. type: string
  10459. name:
  10460. description: The name of the Secret resource being referred to.
  10461. maxLength: 253
  10462. minLength: 1
  10463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10464. type: string
  10465. namespace:
  10466. description: |-
  10467. The namespace of the Secret resource being referred to.
  10468. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10469. maxLength: 63
  10470. minLength: 1
  10471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10472. type: string
  10473. type: object
  10474. value:
  10475. description: Value can be specified directly to set a value without using a secret.
  10476. type: string
  10477. type: object
  10478. type: object
  10479. server:
  10480. description: Auth configures how API server works.
  10481. properties:
  10482. apiUrl:
  10483. type: string
  10484. apiVersion:
  10485. type: string
  10486. clientTimeOutSeconds:
  10487. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10488. type: integer
  10489. decrypt:
  10490. default: true
  10491. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10492. type: boolean
  10493. retrievalType:
  10494. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10495. type: string
  10496. separator:
  10497. description: A character that separates the folder names.
  10498. type: string
  10499. verifyCA:
  10500. type: boolean
  10501. required:
  10502. - apiUrl
  10503. - verifyCA
  10504. type: object
  10505. required:
  10506. - auth
  10507. - server
  10508. type: object
  10509. bitwardensecretsmanager:
  10510. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10511. properties:
  10512. apiURL:
  10513. type: string
  10514. auth:
  10515. description: |-
  10516. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10517. Make sure that the token being used has permissions on the given secret.
  10518. properties:
  10519. secretRef:
  10520. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10521. properties:
  10522. credentials:
  10523. description: AccessToken used for the bitwarden instance.
  10524. properties:
  10525. key:
  10526. description: |-
  10527. A key in the referenced Secret.
  10528. Some instances of this field may be defaulted, in others it may be required.
  10529. maxLength: 253
  10530. minLength: 1
  10531. pattern: ^[-._a-zA-Z0-9]+$
  10532. type: string
  10533. name:
  10534. description: The name of the Secret resource being referred to.
  10535. maxLength: 253
  10536. minLength: 1
  10537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10538. type: string
  10539. namespace:
  10540. description: |-
  10541. The namespace of the Secret resource being referred to.
  10542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10543. maxLength: 63
  10544. minLength: 1
  10545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10546. type: string
  10547. type: object
  10548. required:
  10549. - credentials
  10550. type: object
  10551. required:
  10552. - secretRef
  10553. type: object
  10554. bitwardenServerSDKURL:
  10555. type: string
  10556. caBundle:
  10557. description: |-
  10558. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10559. can be performed.
  10560. type: string
  10561. caProvider:
  10562. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10563. properties:
  10564. key:
  10565. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10566. maxLength: 253
  10567. minLength: 1
  10568. pattern: ^[-._a-zA-Z0-9]+$
  10569. type: string
  10570. name:
  10571. description: The name of the object located at the provider type.
  10572. maxLength: 253
  10573. minLength: 1
  10574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10575. type: string
  10576. namespace:
  10577. description: |-
  10578. The namespace the Provider type is in.
  10579. Can only be defined when used in a ClusterSecretStore.
  10580. maxLength: 63
  10581. minLength: 1
  10582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10583. type: string
  10584. type:
  10585. description: The type of provider to use such as "Secret", or "ConfigMap".
  10586. enum:
  10587. - Secret
  10588. - ConfigMap
  10589. type: string
  10590. required:
  10591. - name
  10592. - type
  10593. type: object
  10594. identityURL:
  10595. type: string
  10596. organizationID:
  10597. description: OrganizationID determines which organization this secret store manages.
  10598. type: string
  10599. projectID:
  10600. description: ProjectID determines which project this secret store manages.
  10601. type: string
  10602. required:
  10603. - auth
  10604. - organizationID
  10605. - projectID
  10606. type: object
  10607. chef:
  10608. description: Chef configures this store to sync secrets with chef server
  10609. properties:
  10610. auth:
  10611. description: Auth defines the information necessary to authenticate against chef Server
  10612. properties:
  10613. secretRef:
  10614. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10615. properties:
  10616. privateKeySecretRef:
  10617. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10618. properties:
  10619. key:
  10620. description: |-
  10621. A key in the referenced Secret.
  10622. Some instances of this field may be defaulted, in others it may be required.
  10623. maxLength: 253
  10624. minLength: 1
  10625. pattern: ^[-._a-zA-Z0-9]+$
  10626. type: string
  10627. name:
  10628. description: The name of the Secret resource being referred to.
  10629. maxLength: 253
  10630. minLength: 1
  10631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10632. type: string
  10633. namespace:
  10634. description: |-
  10635. The namespace of the Secret resource being referred to.
  10636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10637. maxLength: 63
  10638. minLength: 1
  10639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10640. type: string
  10641. type: object
  10642. required:
  10643. - privateKeySecretRef
  10644. type: object
  10645. required:
  10646. - secretRef
  10647. type: object
  10648. serverUrl:
  10649. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10650. type: string
  10651. username:
  10652. description: UserName should be the user ID on the chef server
  10653. type: string
  10654. required:
  10655. - auth
  10656. - serverUrl
  10657. - username
  10658. type: object
  10659. cloudrusm:
  10660. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10661. properties:
  10662. auth:
  10663. description: CSMAuth contains a secretRef for credentials.
  10664. properties:
  10665. secretRef:
  10666. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10667. properties:
  10668. accessKeyIDSecretRef:
  10669. description: The AccessKeyID is used for authentication
  10670. properties:
  10671. key:
  10672. description: |-
  10673. A key in the referenced Secret.
  10674. Some instances of this field may be defaulted, in others it may be required.
  10675. maxLength: 253
  10676. minLength: 1
  10677. pattern: ^[-._a-zA-Z0-9]+$
  10678. type: string
  10679. name:
  10680. description: The name of the Secret resource being referred to.
  10681. maxLength: 253
  10682. minLength: 1
  10683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10684. type: string
  10685. namespace:
  10686. description: |-
  10687. The namespace of the Secret resource being referred to.
  10688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10689. maxLength: 63
  10690. minLength: 1
  10691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10692. type: string
  10693. type: object
  10694. accessKeySecretSecretRef:
  10695. description: The AccessKeySecret is used for authentication
  10696. properties:
  10697. key:
  10698. description: |-
  10699. A key in the referenced Secret.
  10700. Some instances of this field may be defaulted, in others it may be required.
  10701. maxLength: 253
  10702. minLength: 1
  10703. pattern: ^[-._a-zA-Z0-9]+$
  10704. type: string
  10705. name:
  10706. description: The name of the Secret resource being referred to.
  10707. maxLength: 253
  10708. minLength: 1
  10709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10710. type: string
  10711. namespace:
  10712. description: |-
  10713. The namespace of the Secret resource being referred to.
  10714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10715. maxLength: 63
  10716. minLength: 1
  10717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10718. type: string
  10719. type: object
  10720. required:
  10721. - accessKeyIDSecretRef
  10722. - accessKeySecretSecretRef
  10723. type: object
  10724. type: object
  10725. projectID:
  10726. description: ProjectID is the project, which the secrets are stored in.
  10727. type: string
  10728. required:
  10729. - auth
  10730. type: object
  10731. conjur:
  10732. description: Conjur configures this store to sync secrets using conjur provider
  10733. properties:
  10734. auth:
  10735. description: Defines authentication settings for connecting to Conjur.
  10736. properties:
  10737. apikey:
  10738. description: Authenticates with Conjur using an API key.
  10739. properties:
  10740. account:
  10741. description: Account is the Conjur organization account name.
  10742. type: string
  10743. apiKeyRef:
  10744. description: |-
  10745. A reference to a specific 'key' containing the Conjur API key
  10746. within a Secret resource. In some instances, `key` is a required field.
  10747. properties:
  10748. key:
  10749. description: |-
  10750. A key in the referenced Secret.
  10751. Some instances of this field may be defaulted, in others it may be required.
  10752. maxLength: 253
  10753. minLength: 1
  10754. pattern: ^[-._a-zA-Z0-9]+$
  10755. type: string
  10756. name:
  10757. description: The name of the Secret resource being referred to.
  10758. maxLength: 253
  10759. minLength: 1
  10760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10761. type: string
  10762. namespace:
  10763. description: |-
  10764. The namespace of the Secret resource being referred to.
  10765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10766. maxLength: 63
  10767. minLength: 1
  10768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10769. type: string
  10770. type: object
  10771. userRef:
  10772. description: |-
  10773. A reference to a specific 'key' containing the Conjur username
  10774. within a Secret resource. In some instances, `key` is a required field.
  10775. properties:
  10776. key:
  10777. description: |-
  10778. A key in the referenced Secret.
  10779. Some instances of this field may be defaulted, in others it may be required.
  10780. maxLength: 253
  10781. minLength: 1
  10782. pattern: ^[-._a-zA-Z0-9]+$
  10783. type: string
  10784. name:
  10785. description: The name of the Secret resource being referred to.
  10786. maxLength: 253
  10787. minLength: 1
  10788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10789. type: string
  10790. namespace:
  10791. description: |-
  10792. The namespace of the Secret resource being referred to.
  10793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10794. maxLength: 63
  10795. minLength: 1
  10796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10797. type: string
  10798. type: object
  10799. required:
  10800. - account
  10801. - apiKeyRef
  10802. - userRef
  10803. type: object
  10804. jwt:
  10805. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10806. properties:
  10807. account:
  10808. description: Account is the Conjur organization account name.
  10809. type: string
  10810. hostId:
  10811. description: |-
  10812. Optional HostID for JWT authentication. This may be used depending
  10813. on how the Conjur JWT authenticator policy is configured.
  10814. type: string
  10815. secretRef:
  10816. description: |-
  10817. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10818. authenticate with Conjur using the JWT authentication method.
  10819. properties:
  10820. key:
  10821. description: |-
  10822. A key in the referenced Secret.
  10823. Some instances of this field may be defaulted, in others it may be required.
  10824. maxLength: 253
  10825. minLength: 1
  10826. pattern: ^[-._a-zA-Z0-9]+$
  10827. type: string
  10828. name:
  10829. description: The name of the Secret resource being referred to.
  10830. maxLength: 253
  10831. minLength: 1
  10832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10833. type: string
  10834. namespace:
  10835. description: |-
  10836. The namespace of the Secret resource being referred to.
  10837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10838. maxLength: 63
  10839. minLength: 1
  10840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10841. type: string
  10842. type: object
  10843. serviceAccountRef:
  10844. description: |-
  10845. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10846. a token for with the `TokenRequest` API.
  10847. properties:
  10848. audiences:
  10849. description: |-
  10850. Audience specifies the `aud` claim for the service account token
  10851. Some providers automatically extend the audience field based on well-known annotations for workload
  10852. identity (e.g. IRSA or GCP Workload Identity)
  10853. items:
  10854. type: string
  10855. type: array
  10856. name:
  10857. description: The name of the ServiceAccount resource being referred to.
  10858. maxLength: 253
  10859. minLength: 1
  10860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10861. type: string
  10862. namespace:
  10863. description: |-
  10864. Namespace of the resource being referred to.
  10865. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10866. maxLength: 63
  10867. minLength: 1
  10868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10869. type: string
  10870. required:
  10871. - name
  10872. type: object
  10873. serviceID:
  10874. description: The conjur authn jwt webservice id
  10875. type: string
  10876. required:
  10877. - account
  10878. - serviceID
  10879. type: object
  10880. type: object
  10881. caBundle:
  10882. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10883. type: string
  10884. caProvider:
  10885. description: |-
  10886. Used to provide custom certificate authority (CA) certificates
  10887. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10888. that contains a PEM-encoded certificate.
  10889. properties:
  10890. key:
  10891. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10892. maxLength: 253
  10893. minLength: 1
  10894. pattern: ^[-._a-zA-Z0-9]+$
  10895. type: string
  10896. name:
  10897. description: The name of the object located at the provider type.
  10898. maxLength: 253
  10899. minLength: 1
  10900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10901. type: string
  10902. namespace:
  10903. description: |-
  10904. The namespace the Provider type is in.
  10905. Can only be defined when used in a ClusterSecretStore.
  10906. maxLength: 63
  10907. minLength: 1
  10908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10909. type: string
  10910. type:
  10911. description: The type of provider to use such as "Secret", or "ConfigMap".
  10912. enum:
  10913. - Secret
  10914. - ConfigMap
  10915. type: string
  10916. required:
  10917. - name
  10918. - type
  10919. type: object
  10920. url:
  10921. description: URL is the endpoint of the Conjur instance.
  10922. type: string
  10923. required:
  10924. - auth
  10925. - url
  10926. type: object
  10927. delinea:
  10928. description: |-
  10929. Delinea DevOps Secrets Vault
  10930. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10931. properties:
  10932. clientId:
  10933. description: ClientID is the non-secret part of the credential.
  10934. properties:
  10935. secretRef:
  10936. description: SecretRef references a key in a secret that will be used as value.
  10937. properties:
  10938. key:
  10939. description: |-
  10940. A key in the referenced Secret.
  10941. Some instances of this field may be defaulted, in others it may be required.
  10942. maxLength: 253
  10943. minLength: 1
  10944. pattern: ^[-._a-zA-Z0-9]+$
  10945. type: string
  10946. name:
  10947. description: The name of the Secret resource being referred to.
  10948. maxLength: 253
  10949. minLength: 1
  10950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10951. type: string
  10952. namespace:
  10953. description: |-
  10954. The namespace of the Secret resource being referred to.
  10955. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10956. maxLength: 63
  10957. minLength: 1
  10958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10959. type: string
  10960. type: object
  10961. value:
  10962. description: Value can be specified directly to set a value without using a secret.
  10963. type: string
  10964. type: object
  10965. clientSecret:
  10966. description: ClientSecret is the secret part of the credential.
  10967. properties:
  10968. secretRef:
  10969. description: SecretRef references a key in a secret that will be used as value.
  10970. properties:
  10971. key:
  10972. description: |-
  10973. A key in the referenced Secret.
  10974. Some instances of this field may be defaulted, in others it may be required.
  10975. maxLength: 253
  10976. minLength: 1
  10977. pattern: ^[-._a-zA-Z0-9]+$
  10978. type: string
  10979. name:
  10980. description: The name of the Secret resource being referred to.
  10981. maxLength: 253
  10982. minLength: 1
  10983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10984. type: string
  10985. namespace:
  10986. description: |-
  10987. The namespace of the Secret resource being referred to.
  10988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10989. maxLength: 63
  10990. minLength: 1
  10991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10992. type: string
  10993. type: object
  10994. value:
  10995. description: Value can be specified directly to set a value without using a secret.
  10996. type: string
  10997. type: object
  10998. tenant:
  10999. description: Tenant is the chosen hostname / site name.
  11000. type: string
  11001. tld:
  11002. description: |-
  11003. TLD is based on the server location that was chosen during provisioning.
  11004. If unset, defaults to "com".
  11005. type: string
  11006. urlTemplate:
  11007. description: |-
  11008. URLTemplate
  11009. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  11010. type: string
  11011. required:
  11012. - clientId
  11013. - clientSecret
  11014. - tenant
  11015. type: object
  11016. device42:
  11017. description: Device42 configures this store to sync secrets using the Device42 provider
  11018. properties:
  11019. auth:
  11020. description: Auth configures how secret-manager authenticates with a Device42 instance.
  11021. properties:
  11022. secretRef:
  11023. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  11024. properties:
  11025. credentials:
  11026. description: Username / Password is used for authentication.
  11027. properties:
  11028. key:
  11029. description: |-
  11030. A key in the referenced Secret.
  11031. Some instances of this field may be defaulted, in others it may be required.
  11032. maxLength: 253
  11033. minLength: 1
  11034. pattern: ^[-._a-zA-Z0-9]+$
  11035. type: string
  11036. name:
  11037. description: The name of the Secret resource being referred to.
  11038. maxLength: 253
  11039. minLength: 1
  11040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11041. type: string
  11042. namespace:
  11043. description: |-
  11044. The namespace of the Secret resource being referred to.
  11045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11046. maxLength: 63
  11047. minLength: 1
  11048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11049. type: string
  11050. type: object
  11051. type: object
  11052. required:
  11053. - secretRef
  11054. type: object
  11055. host:
  11056. description: URL configures the Device42 instance URL.
  11057. type: string
  11058. required:
  11059. - auth
  11060. - host
  11061. type: object
  11062. doppler:
  11063. description: Doppler configures this store to sync secrets using the Doppler provider
  11064. properties:
  11065. auth:
  11066. description: Auth configures how the Operator authenticates with the Doppler API
  11067. properties:
  11068. secretRef:
  11069. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  11070. properties:
  11071. dopplerToken:
  11072. description: |-
  11073. The DopplerToken is used for authentication.
  11074. See https://docs.doppler.com/reference/api#authentication for auth token types.
  11075. The Key attribute defaults to dopplerToken if not specified.
  11076. properties:
  11077. key:
  11078. description: |-
  11079. A key in the referenced Secret.
  11080. Some instances of this field may be defaulted, in others it may be required.
  11081. maxLength: 253
  11082. minLength: 1
  11083. pattern: ^[-._a-zA-Z0-9]+$
  11084. type: string
  11085. name:
  11086. description: The name of the Secret resource being referred to.
  11087. maxLength: 253
  11088. minLength: 1
  11089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11090. type: string
  11091. namespace:
  11092. description: |-
  11093. The namespace of the Secret resource being referred to.
  11094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11095. maxLength: 63
  11096. minLength: 1
  11097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11098. type: string
  11099. type: object
  11100. required:
  11101. - dopplerToken
  11102. type: object
  11103. required:
  11104. - secretRef
  11105. type: object
  11106. config:
  11107. description: Doppler config (required if not using a Service Token)
  11108. type: string
  11109. format:
  11110. description: Format enables the downloading of secrets as a file (string)
  11111. enum:
  11112. - json
  11113. - dotnet-json
  11114. - env
  11115. - yaml
  11116. - docker
  11117. type: string
  11118. nameTransformer:
  11119. description: Environment variable compatible name transforms that change secret names to a different format
  11120. enum:
  11121. - upper-camel
  11122. - camel
  11123. - lower-snake
  11124. - tf-var
  11125. - dotnet-env
  11126. - lower-kebab
  11127. type: string
  11128. project:
  11129. description: Doppler project (required if not using a Service Token)
  11130. type: string
  11131. required:
  11132. - auth
  11133. type: object
  11134. fake:
  11135. description: Fake configures a store with static key/value pairs
  11136. properties:
  11137. data:
  11138. items:
  11139. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  11140. properties:
  11141. key:
  11142. type: string
  11143. value:
  11144. type: string
  11145. version:
  11146. type: string
  11147. required:
  11148. - key
  11149. - value
  11150. type: object
  11151. type: array
  11152. required:
  11153. - data
  11154. type: object
  11155. fortanix:
  11156. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11157. properties:
  11158. apiKey:
  11159. description: APIKey is the API token to access SDKMS Applications.
  11160. properties:
  11161. secretRef:
  11162. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11163. properties:
  11164. key:
  11165. description: |-
  11166. A key in the referenced Secret.
  11167. Some instances of this field may be defaulted, in others it may be required.
  11168. maxLength: 253
  11169. minLength: 1
  11170. pattern: ^[-._a-zA-Z0-9]+$
  11171. type: string
  11172. name:
  11173. description: The name of the Secret resource being referred to.
  11174. maxLength: 253
  11175. minLength: 1
  11176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11177. type: string
  11178. namespace:
  11179. description: |-
  11180. The namespace of the Secret resource being referred to.
  11181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11182. maxLength: 63
  11183. minLength: 1
  11184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11185. type: string
  11186. type: object
  11187. type: object
  11188. apiUrl:
  11189. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11190. type: string
  11191. type: object
  11192. gcpsm:
  11193. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11194. properties:
  11195. auth:
  11196. description: Auth defines the information necessary to authenticate against GCP
  11197. properties:
  11198. secretRef:
  11199. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  11200. properties:
  11201. secretAccessKeySecretRef:
  11202. description: The SecretAccessKey is used for authentication
  11203. properties:
  11204. key:
  11205. description: |-
  11206. A key in the referenced Secret.
  11207. Some instances of this field may be defaulted, in others it may be required.
  11208. maxLength: 253
  11209. minLength: 1
  11210. pattern: ^[-._a-zA-Z0-9]+$
  11211. type: string
  11212. name:
  11213. description: The name of the Secret resource being referred to.
  11214. maxLength: 253
  11215. minLength: 1
  11216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11217. type: string
  11218. namespace:
  11219. description: |-
  11220. The namespace of the Secret resource being referred to.
  11221. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11222. maxLength: 63
  11223. minLength: 1
  11224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11225. type: string
  11226. type: object
  11227. type: object
  11228. workloadIdentity:
  11229. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  11230. properties:
  11231. clusterLocation:
  11232. description: |-
  11233. ClusterLocation is the location of the cluster
  11234. If not specified, it fetches information from the metadata server
  11235. type: string
  11236. clusterName:
  11237. description: |-
  11238. ClusterName is the name of the cluster
  11239. If not specified, it fetches information from the metadata server
  11240. type: string
  11241. clusterProjectID:
  11242. description: |-
  11243. ClusterProjectID is the project ID of the cluster
  11244. If not specified, it fetches information from the metadata server
  11245. type: string
  11246. serviceAccountRef:
  11247. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11248. properties:
  11249. audiences:
  11250. description: |-
  11251. Audience specifies the `aud` claim for the service account token
  11252. Some providers automatically extend the audience field based on well-known annotations for workload
  11253. identity (e.g. IRSA or GCP Workload Identity)
  11254. items:
  11255. type: string
  11256. type: array
  11257. name:
  11258. description: The name of the ServiceAccount resource being referred to.
  11259. maxLength: 253
  11260. minLength: 1
  11261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11262. type: string
  11263. namespace:
  11264. description: |-
  11265. Namespace of the resource being referred to.
  11266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11267. maxLength: 63
  11268. minLength: 1
  11269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11270. type: string
  11271. required:
  11272. - name
  11273. type: object
  11274. required:
  11275. - serviceAccountRef
  11276. type: object
  11277. type: object
  11278. location:
  11279. description: Location optionally defines a location for a secret
  11280. type: string
  11281. projectID:
  11282. description: ProjectID project where secret is located
  11283. type: string
  11284. type: object
  11285. github:
  11286. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11287. properties:
  11288. appID:
  11289. description: appID specifies the Github APP that will be used to authenticate the client
  11290. format: int64
  11291. type: integer
  11292. auth:
  11293. description: auth configures how secret-manager authenticates with a Github instance.
  11294. properties:
  11295. privateKey:
  11296. description: |-
  11297. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11298. In some instances, `key` is a required field.
  11299. properties:
  11300. key:
  11301. description: |-
  11302. A key in the referenced Secret.
  11303. Some instances of this field may be defaulted, in others it may be required.
  11304. maxLength: 253
  11305. minLength: 1
  11306. pattern: ^[-._a-zA-Z0-9]+$
  11307. type: string
  11308. name:
  11309. description: The name of the Secret resource being referred to.
  11310. maxLength: 253
  11311. minLength: 1
  11312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11313. type: string
  11314. namespace:
  11315. description: |-
  11316. The namespace of the Secret resource being referred to.
  11317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11318. maxLength: 63
  11319. minLength: 1
  11320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11321. type: string
  11322. type: object
  11323. required:
  11324. - privateKey
  11325. type: object
  11326. environment:
  11327. description: environment will be used to fetch secrets from a particular environment within a github repository
  11328. type: string
  11329. installationID:
  11330. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11331. format: int64
  11332. type: integer
  11333. organization:
  11334. description: organization will be used to fetch secrets from the Github organization
  11335. type: string
  11336. repository:
  11337. description: repository will be used to fetch secrets from the Github repository within an organization
  11338. type: string
  11339. uploadURL:
  11340. description: Upload URL for enterprise instances. Default to URL.
  11341. type: string
  11342. url:
  11343. default: https://github.com/
  11344. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11345. type: string
  11346. required:
  11347. - appID
  11348. - auth
  11349. - installationID
  11350. - organization
  11351. type: object
  11352. gitlab:
  11353. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11354. properties:
  11355. auth:
  11356. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11357. properties:
  11358. SecretRef:
  11359. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11360. properties:
  11361. accessToken:
  11362. description: AccessToken is used for authentication.
  11363. properties:
  11364. key:
  11365. description: |-
  11366. A key in the referenced Secret.
  11367. Some instances of this field may be defaulted, in others it may be required.
  11368. maxLength: 253
  11369. minLength: 1
  11370. pattern: ^[-._a-zA-Z0-9]+$
  11371. type: string
  11372. name:
  11373. description: The name of the Secret resource being referred to.
  11374. maxLength: 253
  11375. minLength: 1
  11376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11377. type: string
  11378. namespace:
  11379. description: |-
  11380. The namespace of the Secret resource being referred to.
  11381. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11382. maxLength: 63
  11383. minLength: 1
  11384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11385. type: string
  11386. type: object
  11387. type: object
  11388. required:
  11389. - SecretRef
  11390. type: object
  11391. caBundle:
  11392. description: |-
  11393. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11394. can be performed.
  11395. format: byte
  11396. type: string
  11397. caProvider:
  11398. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11399. properties:
  11400. key:
  11401. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11402. maxLength: 253
  11403. minLength: 1
  11404. pattern: ^[-._a-zA-Z0-9]+$
  11405. type: string
  11406. name:
  11407. description: The name of the object located at the provider type.
  11408. maxLength: 253
  11409. minLength: 1
  11410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11411. type: string
  11412. namespace:
  11413. description: |-
  11414. The namespace the Provider type is in.
  11415. Can only be defined when used in a ClusterSecretStore.
  11416. maxLength: 63
  11417. minLength: 1
  11418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11419. type: string
  11420. type:
  11421. description: The type of provider to use such as "Secret", or "ConfigMap".
  11422. enum:
  11423. - Secret
  11424. - ConfigMap
  11425. type: string
  11426. required:
  11427. - name
  11428. - type
  11429. type: object
  11430. environment:
  11431. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11432. type: string
  11433. groupIDs:
  11434. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11435. items:
  11436. type: string
  11437. type: array
  11438. inheritFromGroups:
  11439. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11440. type: boolean
  11441. projectID:
  11442. description: ProjectID specifies a project where secrets are located.
  11443. type: string
  11444. url:
  11445. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11446. type: string
  11447. required:
  11448. - auth
  11449. type: object
  11450. ibm:
  11451. description: IBM configures this store to sync secrets using IBM Cloud provider
  11452. properties:
  11453. auth:
  11454. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11455. maxProperties: 1
  11456. minProperties: 1
  11457. properties:
  11458. containerAuth:
  11459. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11460. properties:
  11461. iamEndpoint:
  11462. type: string
  11463. profile:
  11464. description: the IBM Trusted Profile
  11465. type: string
  11466. tokenLocation:
  11467. description: Location the token is mounted on the pod
  11468. type: string
  11469. required:
  11470. - profile
  11471. type: object
  11472. secretRef:
  11473. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11474. properties:
  11475. secretApiKeySecretRef:
  11476. description: The SecretAccessKey is used for authentication
  11477. properties:
  11478. key:
  11479. description: |-
  11480. A key in the referenced Secret.
  11481. Some instances of this field may be defaulted, in others it may be required.
  11482. maxLength: 253
  11483. minLength: 1
  11484. pattern: ^[-._a-zA-Z0-9]+$
  11485. type: string
  11486. name:
  11487. description: The name of the Secret resource being referred to.
  11488. maxLength: 253
  11489. minLength: 1
  11490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11491. type: string
  11492. namespace:
  11493. description: |-
  11494. The namespace of the Secret resource being referred to.
  11495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11496. maxLength: 63
  11497. minLength: 1
  11498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11499. type: string
  11500. type: object
  11501. type: object
  11502. type: object
  11503. serviceUrl:
  11504. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11505. type: string
  11506. required:
  11507. - auth
  11508. type: object
  11509. infisical:
  11510. description: Infisical configures this store to sync secrets using the Infisical provider
  11511. properties:
  11512. auth:
  11513. description: Auth configures how the Operator authenticates with the Infisical API
  11514. properties:
  11515. universalAuthCredentials:
  11516. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11517. properties:
  11518. clientId:
  11519. description: |-
  11520. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11521. In some instances, `key` is a required field.
  11522. properties:
  11523. key:
  11524. description: |-
  11525. A key in the referenced Secret.
  11526. Some instances of this field may be defaulted, in others it may be required.
  11527. maxLength: 253
  11528. minLength: 1
  11529. pattern: ^[-._a-zA-Z0-9]+$
  11530. type: string
  11531. name:
  11532. description: The name of the Secret resource being referred to.
  11533. maxLength: 253
  11534. minLength: 1
  11535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11536. type: string
  11537. namespace:
  11538. description: |-
  11539. The namespace of the Secret resource being referred to.
  11540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11541. maxLength: 63
  11542. minLength: 1
  11543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11544. type: string
  11545. type: object
  11546. clientSecret:
  11547. description: |-
  11548. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11549. In some instances, `key` is a required field.
  11550. properties:
  11551. key:
  11552. description: |-
  11553. A key in the referenced Secret.
  11554. Some instances of this field may be defaulted, in others it may be required.
  11555. maxLength: 253
  11556. minLength: 1
  11557. pattern: ^[-._a-zA-Z0-9]+$
  11558. type: string
  11559. name:
  11560. description: The name of the Secret resource being referred to.
  11561. maxLength: 253
  11562. minLength: 1
  11563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11564. type: string
  11565. namespace:
  11566. description: |-
  11567. The namespace of the Secret resource being referred to.
  11568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11569. maxLength: 63
  11570. minLength: 1
  11571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11572. type: string
  11573. type: object
  11574. required:
  11575. - clientId
  11576. - clientSecret
  11577. type: object
  11578. type: object
  11579. hostAPI:
  11580. default: https://app.infisical.com/api
  11581. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11582. type: string
  11583. secretsScope:
  11584. description: SecretsScope defines the scope of the secrets within the workspace
  11585. properties:
  11586. environmentSlug:
  11587. description: EnvironmentSlug is the required slug identifier for the environment.
  11588. type: string
  11589. expandSecretReferences:
  11590. default: true
  11591. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11592. type: boolean
  11593. projectSlug:
  11594. description: ProjectSlug is the required slug identifier for the project.
  11595. type: string
  11596. recursive:
  11597. default: false
  11598. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11599. type: boolean
  11600. secretsPath:
  11601. default: /
  11602. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11603. type: string
  11604. required:
  11605. - environmentSlug
  11606. - projectSlug
  11607. type: object
  11608. required:
  11609. - auth
  11610. - secretsScope
  11611. type: object
  11612. keepersecurity:
  11613. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11614. properties:
  11615. authRef:
  11616. description: |-
  11617. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11618. In some instances, `key` is a required field.
  11619. properties:
  11620. key:
  11621. description: |-
  11622. A key in the referenced Secret.
  11623. Some instances of this field may be defaulted, in others it may be required.
  11624. maxLength: 253
  11625. minLength: 1
  11626. pattern: ^[-._a-zA-Z0-9]+$
  11627. type: string
  11628. name:
  11629. description: The name of the Secret resource being referred to.
  11630. maxLength: 253
  11631. minLength: 1
  11632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11633. type: string
  11634. namespace:
  11635. description: |-
  11636. The namespace of the Secret resource being referred to.
  11637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11638. maxLength: 63
  11639. minLength: 1
  11640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11641. type: string
  11642. type: object
  11643. folderID:
  11644. type: string
  11645. required:
  11646. - authRef
  11647. - folderID
  11648. type: object
  11649. kubernetes:
  11650. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11651. properties:
  11652. auth:
  11653. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11654. maxProperties: 1
  11655. minProperties: 1
  11656. properties:
  11657. cert:
  11658. description: has both clientCert and clientKey as secretKeySelector
  11659. properties:
  11660. clientCert:
  11661. description: |-
  11662. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11663. In some instances, `key` is a required field.
  11664. properties:
  11665. key:
  11666. description: |-
  11667. A key in the referenced Secret.
  11668. Some instances of this field may be defaulted, in others it may be required.
  11669. maxLength: 253
  11670. minLength: 1
  11671. pattern: ^[-._a-zA-Z0-9]+$
  11672. type: string
  11673. name:
  11674. description: The name of the Secret resource being referred to.
  11675. maxLength: 253
  11676. minLength: 1
  11677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11678. type: string
  11679. namespace:
  11680. description: |-
  11681. The namespace of the Secret resource being referred to.
  11682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11683. maxLength: 63
  11684. minLength: 1
  11685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11686. type: string
  11687. type: object
  11688. clientKey:
  11689. description: |-
  11690. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11691. In some instances, `key` is a required field.
  11692. properties:
  11693. key:
  11694. description: |-
  11695. A key in the referenced Secret.
  11696. Some instances of this field may be defaulted, in others it may be required.
  11697. maxLength: 253
  11698. minLength: 1
  11699. pattern: ^[-._a-zA-Z0-9]+$
  11700. type: string
  11701. name:
  11702. description: The name of the Secret resource being referred to.
  11703. maxLength: 253
  11704. minLength: 1
  11705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11706. type: string
  11707. namespace:
  11708. description: |-
  11709. The namespace of the Secret resource being referred to.
  11710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11711. maxLength: 63
  11712. minLength: 1
  11713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11714. type: string
  11715. type: object
  11716. type: object
  11717. serviceAccount:
  11718. description: points to a service account that should be used for authentication
  11719. properties:
  11720. audiences:
  11721. description: |-
  11722. Audience specifies the `aud` claim for the service account token
  11723. Some providers automatically extend the audience field based on well-known annotations for workload
  11724. identity (e.g. IRSA or GCP Workload Identity)
  11725. items:
  11726. type: string
  11727. type: array
  11728. name:
  11729. description: The name of the ServiceAccount resource being referred to.
  11730. maxLength: 253
  11731. minLength: 1
  11732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11733. type: string
  11734. namespace:
  11735. description: |-
  11736. Namespace of the resource being referred to.
  11737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11738. maxLength: 63
  11739. minLength: 1
  11740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11741. type: string
  11742. required:
  11743. - name
  11744. type: object
  11745. token:
  11746. description: use static token to authenticate with
  11747. properties:
  11748. bearerToken:
  11749. description: |-
  11750. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11751. In some instances, `key` is a required field.
  11752. properties:
  11753. key:
  11754. description: |-
  11755. A key in the referenced Secret.
  11756. Some instances of this field may be defaulted, in others it may be required.
  11757. maxLength: 253
  11758. minLength: 1
  11759. pattern: ^[-._a-zA-Z0-9]+$
  11760. type: string
  11761. name:
  11762. description: The name of the Secret resource being referred to.
  11763. maxLength: 253
  11764. minLength: 1
  11765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11766. type: string
  11767. namespace:
  11768. description: |-
  11769. The namespace of the Secret resource being referred to.
  11770. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11771. maxLength: 63
  11772. minLength: 1
  11773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11774. type: string
  11775. type: object
  11776. type: object
  11777. type: object
  11778. authRef:
  11779. description: A reference to a secret that contains the auth information.
  11780. properties:
  11781. key:
  11782. description: |-
  11783. A key in the referenced Secret.
  11784. Some instances of this field may be defaulted, in others it may be required.
  11785. maxLength: 253
  11786. minLength: 1
  11787. pattern: ^[-._a-zA-Z0-9]+$
  11788. type: string
  11789. name:
  11790. description: The name of the Secret resource being referred to.
  11791. maxLength: 253
  11792. minLength: 1
  11793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11794. type: string
  11795. namespace:
  11796. description: |-
  11797. The namespace of the Secret resource being referred to.
  11798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11799. maxLength: 63
  11800. minLength: 1
  11801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11802. type: string
  11803. type: object
  11804. remoteNamespace:
  11805. default: default
  11806. description: Remote namespace to fetch the secrets from
  11807. maxLength: 63
  11808. minLength: 1
  11809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11810. type: string
  11811. server:
  11812. description: configures the Kubernetes server Address.
  11813. properties:
  11814. caBundle:
  11815. description: CABundle is a base64-encoded CA certificate
  11816. format: byte
  11817. type: string
  11818. caProvider:
  11819. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11820. properties:
  11821. key:
  11822. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11823. maxLength: 253
  11824. minLength: 1
  11825. pattern: ^[-._a-zA-Z0-9]+$
  11826. type: string
  11827. name:
  11828. description: The name of the object located at the provider type.
  11829. maxLength: 253
  11830. minLength: 1
  11831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11832. type: string
  11833. namespace:
  11834. description: |-
  11835. The namespace the Provider type is in.
  11836. Can only be defined when used in a ClusterSecretStore.
  11837. maxLength: 63
  11838. minLength: 1
  11839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11840. type: string
  11841. type:
  11842. description: The type of provider to use such as "Secret", or "ConfigMap".
  11843. enum:
  11844. - Secret
  11845. - ConfigMap
  11846. type: string
  11847. required:
  11848. - name
  11849. - type
  11850. type: object
  11851. url:
  11852. default: kubernetes.default
  11853. description: configures the Kubernetes server Address.
  11854. type: string
  11855. type: object
  11856. type: object
  11857. onboardbase:
  11858. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11859. properties:
  11860. apiHost:
  11861. default: https://public.onboardbase.com/api/v1/
  11862. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11863. type: string
  11864. auth:
  11865. description: Auth configures how the Operator authenticates with the Onboardbase API
  11866. properties:
  11867. apiKeyRef:
  11868. description: |-
  11869. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11870. It is used to recognize and authorize access to a project and environment within onboardbase
  11871. properties:
  11872. key:
  11873. description: |-
  11874. A key in the referenced Secret.
  11875. Some instances of this field may be defaulted, in others it may be required.
  11876. maxLength: 253
  11877. minLength: 1
  11878. pattern: ^[-._a-zA-Z0-9]+$
  11879. type: string
  11880. name:
  11881. description: The name of the Secret resource being referred to.
  11882. maxLength: 253
  11883. minLength: 1
  11884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11885. type: string
  11886. namespace:
  11887. description: |-
  11888. The namespace of the Secret resource being referred to.
  11889. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11890. maxLength: 63
  11891. minLength: 1
  11892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11893. type: string
  11894. type: object
  11895. passcodeRef:
  11896. description: OnboardbasePasscode is the passcode attached to the API Key
  11897. properties:
  11898. key:
  11899. description: |-
  11900. A key in the referenced Secret.
  11901. Some instances of this field may be defaulted, in others it may be required.
  11902. maxLength: 253
  11903. minLength: 1
  11904. pattern: ^[-._a-zA-Z0-9]+$
  11905. type: string
  11906. name:
  11907. description: The name of the Secret resource being referred to.
  11908. maxLength: 253
  11909. minLength: 1
  11910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11911. type: string
  11912. namespace:
  11913. description: |-
  11914. The namespace of the Secret resource being referred to.
  11915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11916. maxLength: 63
  11917. minLength: 1
  11918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11919. type: string
  11920. type: object
  11921. required:
  11922. - apiKeyRef
  11923. - passcodeRef
  11924. type: object
  11925. environment:
  11926. default: development
  11927. description: Environment is the name of an environmnent within a project to pull the secrets from
  11928. type: string
  11929. project:
  11930. default: development
  11931. description: Project is an onboardbase project that the secrets should be pulled from
  11932. type: string
  11933. required:
  11934. - apiHost
  11935. - auth
  11936. - environment
  11937. - project
  11938. type: object
  11939. onepassword:
  11940. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11941. properties:
  11942. auth:
  11943. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11944. properties:
  11945. secretRef:
  11946. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11947. properties:
  11948. connectTokenSecretRef:
  11949. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11950. properties:
  11951. key:
  11952. description: |-
  11953. A key in the referenced Secret.
  11954. Some instances of this field may be defaulted, in others it may be required.
  11955. maxLength: 253
  11956. minLength: 1
  11957. pattern: ^[-._a-zA-Z0-9]+$
  11958. type: string
  11959. name:
  11960. description: The name of the Secret resource being referred to.
  11961. maxLength: 253
  11962. minLength: 1
  11963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11964. type: string
  11965. namespace:
  11966. description: |-
  11967. The namespace of the Secret resource being referred to.
  11968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11969. maxLength: 63
  11970. minLength: 1
  11971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11972. type: string
  11973. type: object
  11974. required:
  11975. - connectTokenSecretRef
  11976. type: object
  11977. required:
  11978. - secretRef
  11979. type: object
  11980. connectHost:
  11981. description: ConnectHost defines the OnePassword Connect Server to connect to
  11982. type: string
  11983. vaults:
  11984. additionalProperties:
  11985. type: integer
  11986. description: Vaults defines which OnePassword vaults to search in which order
  11987. type: object
  11988. required:
  11989. - auth
  11990. - connectHost
  11991. - vaults
  11992. type: object
  11993. oracle:
  11994. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11995. properties:
  11996. auth:
  11997. description: |-
  11998. Auth configures how secret-manager authenticates with the Oracle Vault.
  11999. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  12000. properties:
  12001. secretRef:
  12002. description: SecretRef to pass through sensitive information.
  12003. properties:
  12004. fingerprint:
  12005. description: Fingerprint is the fingerprint of the API private key.
  12006. properties:
  12007. key:
  12008. description: |-
  12009. A key in the referenced Secret.
  12010. Some instances of this field may be defaulted, in others it may be required.
  12011. maxLength: 253
  12012. minLength: 1
  12013. pattern: ^[-._a-zA-Z0-9]+$
  12014. type: string
  12015. name:
  12016. description: The name of the Secret resource being referred to.
  12017. maxLength: 253
  12018. minLength: 1
  12019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12020. type: string
  12021. namespace:
  12022. description: |-
  12023. The namespace of the Secret resource being referred to.
  12024. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12025. maxLength: 63
  12026. minLength: 1
  12027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12028. type: string
  12029. type: object
  12030. privatekey:
  12031. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  12032. properties:
  12033. key:
  12034. description: |-
  12035. A key in the referenced Secret.
  12036. Some instances of this field may be defaulted, in others it may be required.
  12037. maxLength: 253
  12038. minLength: 1
  12039. pattern: ^[-._a-zA-Z0-9]+$
  12040. type: string
  12041. name:
  12042. description: The name of the Secret resource being referred to.
  12043. maxLength: 253
  12044. minLength: 1
  12045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12046. type: string
  12047. namespace:
  12048. description: |-
  12049. The namespace of the Secret resource being referred to.
  12050. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12051. maxLength: 63
  12052. minLength: 1
  12053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12054. type: string
  12055. type: object
  12056. required:
  12057. - fingerprint
  12058. - privatekey
  12059. type: object
  12060. tenancy:
  12061. description: Tenancy is the tenancy OCID where user is located.
  12062. type: string
  12063. user:
  12064. description: User is an access OCID specific to the account.
  12065. type: string
  12066. required:
  12067. - secretRef
  12068. - tenancy
  12069. - user
  12070. type: object
  12071. compartment:
  12072. description: |-
  12073. Compartment is the vault compartment OCID.
  12074. Required for PushSecret
  12075. type: string
  12076. encryptionKey:
  12077. description: |-
  12078. EncryptionKey is the OCID of the encryption key within the vault.
  12079. Required for PushSecret
  12080. type: string
  12081. principalType:
  12082. description: |-
  12083. The type of principal to use for authentication. If left blank, the Auth struct will
  12084. determine the principal type. This optional field must be specified if using
  12085. workload identity.
  12086. enum:
  12087. - ""
  12088. - UserPrincipal
  12089. - InstancePrincipal
  12090. - Workload
  12091. type: string
  12092. region:
  12093. description: Region is the region where vault is located.
  12094. type: string
  12095. serviceAccountRef:
  12096. description: |-
  12097. ServiceAccountRef specified the service account
  12098. that should be used when authenticating with WorkloadIdentity.
  12099. properties:
  12100. audiences:
  12101. description: |-
  12102. Audience specifies the `aud` claim for the service account token
  12103. Some providers automatically extend the audience field based on well-known annotations for workload
  12104. identity (e.g. IRSA or GCP Workload Identity)
  12105. items:
  12106. type: string
  12107. type: array
  12108. name:
  12109. description: The name of the ServiceAccount resource being referred to.
  12110. maxLength: 253
  12111. minLength: 1
  12112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12113. type: string
  12114. namespace:
  12115. description: |-
  12116. Namespace of the resource being referred to.
  12117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12118. maxLength: 63
  12119. minLength: 1
  12120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12121. type: string
  12122. required:
  12123. - name
  12124. type: object
  12125. vault:
  12126. description: Vault is the vault's OCID of the specific vault where secret is located.
  12127. type: string
  12128. required:
  12129. - region
  12130. - vault
  12131. type: object
  12132. passbolt:
  12133. description: PassboltProvider defines configuration for the Passbolt provider.
  12134. properties:
  12135. auth:
  12136. description: Auth defines the information necessary to authenticate against Passbolt Server
  12137. properties:
  12138. passwordSecretRef:
  12139. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  12140. properties:
  12141. key:
  12142. description: |-
  12143. A key in the referenced Secret.
  12144. Some instances of this field may be defaulted, in others it may be required.
  12145. maxLength: 253
  12146. minLength: 1
  12147. pattern: ^[-._a-zA-Z0-9]+$
  12148. type: string
  12149. name:
  12150. description: The name of the Secret resource being referred to.
  12151. maxLength: 253
  12152. minLength: 1
  12153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12154. type: string
  12155. namespace:
  12156. description: |-
  12157. The namespace of the Secret resource being referred to.
  12158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12159. maxLength: 63
  12160. minLength: 1
  12161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12162. type: string
  12163. type: object
  12164. privateKeySecretRef:
  12165. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  12166. properties:
  12167. key:
  12168. description: |-
  12169. A key in the referenced Secret.
  12170. Some instances of this field may be defaulted, in others it may be required.
  12171. maxLength: 253
  12172. minLength: 1
  12173. pattern: ^[-._a-zA-Z0-9]+$
  12174. type: string
  12175. name:
  12176. description: The name of the Secret resource being referred to.
  12177. maxLength: 253
  12178. minLength: 1
  12179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12180. type: string
  12181. namespace:
  12182. description: |-
  12183. The namespace of the Secret resource being referred to.
  12184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12185. maxLength: 63
  12186. minLength: 1
  12187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12188. type: string
  12189. type: object
  12190. required:
  12191. - passwordSecretRef
  12192. - privateKeySecretRef
  12193. type: object
  12194. host:
  12195. description: Host defines the Passbolt Server to connect to
  12196. type: string
  12197. required:
  12198. - auth
  12199. - host
  12200. type: object
  12201. passworddepot:
  12202. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  12203. properties:
  12204. auth:
  12205. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12206. properties:
  12207. secretRef:
  12208. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  12209. properties:
  12210. credentials:
  12211. description: Username / Password is used for authentication.
  12212. properties:
  12213. key:
  12214. description: |-
  12215. A key in the referenced Secret.
  12216. Some instances of this field may be defaulted, in others it may be required.
  12217. maxLength: 253
  12218. minLength: 1
  12219. pattern: ^[-._a-zA-Z0-9]+$
  12220. type: string
  12221. name:
  12222. description: The name of the Secret resource being referred to.
  12223. maxLength: 253
  12224. minLength: 1
  12225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12226. type: string
  12227. namespace:
  12228. description: |-
  12229. The namespace of the Secret resource being referred to.
  12230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12231. maxLength: 63
  12232. minLength: 1
  12233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12234. type: string
  12235. type: object
  12236. type: object
  12237. required:
  12238. - secretRef
  12239. type: object
  12240. database:
  12241. description: Database to use as source
  12242. type: string
  12243. host:
  12244. description: URL configures the Password Depot instance URL.
  12245. type: string
  12246. required:
  12247. - auth
  12248. - database
  12249. - host
  12250. type: object
  12251. previder:
  12252. description: Previder configures this store to sync secrets using the Previder provider
  12253. properties:
  12254. auth:
  12255. description: PreviderAuth contains a secretRef for credentials.
  12256. properties:
  12257. secretRef:
  12258. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12259. properties:
  12260. accessToken:
  12261. description: The AccessToken is used for authentication
  12262. properties:
  12263. key:
  12264. description: |-
  12265. A key in the referenced Secret.
  12266. Some instances of this field may be defaulted, in others it may be required.
  12267. maxLength: 253
  12268. minLength: 1
  12269. pattern: ^[-._a-zA-Z0-9]+$
  12270. type: string
  12271. name:
  12272. description: The name of the Secret resource being referred to.
  12273. maxLength: 253
  12274. minLength: 1
  12275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12276. type: string
  12277. namespace:
  12278. description: |-
  12279. The namespace of the Secret resource being referred to.
  12280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12281. maxLength: 63
  12282. minLength: 1
  12283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12284. type: string
  12285. type: object
  12286. required:
  12287. - accessToken
  12288. type: object
  12289. type: object
  12290. baseUri:
  12291. type: string
  12292. required:
  12293. - auth
  12294. type: object
  12295. pulumi:
  12296. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12297. properties:
  12298. accessToken:
  12299. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12300. properties:
  12301. secretRef:
  12302. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12303. properties:
  12304. key:
  12305. description: |-
  12306. A key in the referenced Secret.
  12307. Some instances of this field may be defaulted, in others it may be required.
  12308. maxLength: 253
  12309. minLength: 1
  12310. pattern: ^[-._a-zA-Z0-9]+$
  12311. type: string
  12312. name:
  12313. description: The name of the Secret resource being referred to.
  12314. maxLength: 253
  12315. minLength: 1
  12316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12317. type: string
  12318. namespace:
  12319. description: |-
  12320. The namespace of the Secret resource being referred to.
  12321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12322. maxLength: 63
  12323. minLength: 1
  12324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12325. type: string
  12326. type: object
  12327. type: object
  12328. apiUrl:
  12329. default: https://api.pulumi.com/api/esc
  12330. description: APIURL is the URL of the Pulumi API.
  12331. type: string
  12332. environment:
  12333. description: |-
  12334. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12335. dynamically retrieved values from supported providers including all major clouds,
  12336. and other Pulumi ESC environments.
  12337. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12338. type: string
  12339. organization:
  12340. description: |-
  12341. Organization are a space to collaborate on shared projects and stacks.
  12342. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12343. type: string
  12344. project:
  12345. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12346. type: string
  12347. required:
  12348. - accessToken
  12349. - environment
  12350. - organization
  12351. - project
  12352. type: object
  12353. scaleway:
  12354. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12355. properties:
  12356. accessKey:
  12357. description: AccessKey is the non-secret part of the api key.
  12358. properties:
  12359. secretRef:
  12360. description: SecretRef references a key in a secret that will be used as value.
  12361. properties:
  12362. key:
  12363. description: |-
  12364. A key in the referenced Secret.
  12365. Some instances of this field may be defaulted, in others it may be required.
  12366. maxLength: 253
  12367. minLength: 1
  12368. pattern: ^[-._a-zA-Z0-9]+$
  12369. type: string
  12370. name:
  12371. description: The name of the Secret resource being referred to.
  12372. maxLength: 253
  12373. minLength: 1
  12374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12375. type: string
  12376. namespace:
  12377. description: |-
  12378. The namespace of the Secret resource being referred to.
  12379. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12380. maxLength: 63
  12381. minLength: 1
  12382. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12383. type: string
  12384. type: object
  12385. value:
  12386. description: Value can be specified directly to set a value without using a secret.
  12387. type: string
  12388. type: object
  12389. apiUrl:
  12390. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12391. type: string
  12392. projectId:
  12393. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12394. type: string
  12395. region:
  12396. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12397. type: string
  12398. secretKey:
  12399. description: SecretKey is the non-secret part of the api key.
  12400. properties:
  12401. secretRef:
  12402. description: SecretRef references a key in a secret that will be used as value.
  12403. properties:
  12404. key:
  12405. description: |-
  12406. A key in the referenced Secret.
  12407. Some instances of this field may be defaulted, in others it may be required.
  12408. maxLength: 253
  12409. minLength: 1
  12410. pattern: ^[-._a-zA-Z0-9]+$
  12411. type: string
  12412. name:
  12413. description: The name of the Secret resource being referred to.
  12414. maxLength: 253
  12415. minLength: 1
  12416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12417. type: string
  12418. namespace:
  12419. description: |-
  12420. The namespace of the Secret resource being referred to.
  12421. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12422. maxLength: 63
  12423. minLength: 1
  12424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12425. type: string
  12426. type: object
  12427. value:
  12428. description: Value can be specified directly to set a value without using a secret.
  12429. type: string
  12430. type: object
  12431. required:
  12432. - accessKey
  12433. - projectId
  12434. - region
  12435. - secretKey
  12436. type: object
  12437. secretserver:
  12438. description: |-
  12439. SecretServer configures this store to sync secrets using SecretServer provider
  12440. https://docs.delinea.com/online-help/secret-server/start.htm
  12441. properties:
  12442. password:
  12443. description: Password is the secret server account password.
  12444. properties:
  12445. secretRef:
  12446. description: SecretRef references a key in a secret that will be used as value.
  12447. properties:
  12448. key:
  12449. description: |-
  12450. A key in the referenced Secret.
  12451. Some instances of this field may be defaulted, in others it may be required.
  12452. maxLength: 253
  12453. minLength: 1
  12454. pattern: ^[-._a-zA-Z0-9]+$
  12455. type: string
  12456. name:
  12457. description: The name of the Secret resource being referred to.
  12458. maxLength: 253
  12459. minLength: 1
  12460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12461. type: string
  12462. namespace:
  12463. description: |-
  12464. The namespace of the Secret resource being referred to.
  12465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12466. maxLength: 63
  12467. minLength: 1
  12468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12469. type: string
  12470. type: object
  12471. value:
  12472. description: Value can be specified directly to set a value without using a secret.
  12473. type: string
  12474. type: object
  12475. serverURL:
  12476. description: |-
  12477. ServerURL
  12478. URL to your secret server installation
  12479. type: string
  12480. username:
  12481. description: Username is the secret server account username.
  12482. properties:
  12483. secretRef:
  12484. description: SecretRef references a key in a secret that will be used as value.
  12485. properties:
  12486. key:
  12487. description: |-
  12488. A key in the referenced Secret.
  12489. Some instances of this field may be defaulted, in others it may be required.
  12490. maxLength: 253
  12491. minLength: 1
  12492. pattern: ^[-._a-zA-Z0-9]+$
  12493. type: string
  12494. name:
  12495. description: The name of the Secret resource being referred to.
  12496. maxLength: 253
  12497. minLength: 1
  12498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12499. type: string
  12500. namespace:
  12501. description: |-
  12502. The namespace of the Secret resource being referred to.
  12503. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12504. maxLength: 63
  12505. minLength: 1
  12506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12507. type: string
  12508. type: object
  12509. value:
  12510. description: Value can be specified directly to set a value without using a secret.
  12511. type: string
  12512. type: object
  12513. required:
  12514. - password
  12515. - serverURL
  12516. - username
  12517. type: object
  12518. senhasegura:
  12519. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12520. properties:
  12521. auth:
  12522. description: Auth defines parameters to authenticate in senhasegura
  12523. properties:
  12524. clientId:
  12525. type: string
  12526. clientSecretSecretRef:
  12527. description: |-
  12528. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12529. In some instances, `key` is a required field.
  12530. properties:
  12531. key:
  12532. description: |-
  12533. A key in the referenced Secret.
  12534. Some instances of this field may be defaulted, in others it may be required.
  12535. maxLength: 253
  12536. minLength: 1
  12537. pattern: ^[-._a-zA-Z0-9]+$
  12538. type: string
  12539. name:
  12540. description: The name of the Secret resource being referred to.
  12541. maxLength: 253
  12542. minLength: 1
  12543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12544. type: string
  12545. namespace:
  12546. description: |-
  12547. The namespace of the Secret resource being referred to.
  12548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12549. maxLength: 63
  12550. minLength: 1
  12551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12552. type: string
  12553. type: object
  12554. required:
  12555. - clientId
  12556. - clientSecretSecretRef
  12557. type: object
  12558. ignoreSslCertificate:
  12559. default: false
  12560. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12561. type: boolean
  12562. module:
  12563. description: Module defines which senhasegura module should be used to get secrets
  12564. type: string
  12565. url:
  12566. description: URL of senhasegura
  12567. type: string
  12568. required:
  12569. - auth
  12570. - module
  12571. - url
  12572. type: object
  12573. vault:
  12574. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12575. properties:
  12576. auth:
  12577. description: Auth configures how secret-manager authenticates with the Vault server.
  12578. properties:
  12579. appRole:
  12580. description: |-
  12581. AppRole authenticates with Vault using the App Role auth mechanism,
  12582. with the role and secret stored in a Kubernetes Secret resource.
  12583. properties:
  12584. path:
  12585. default: approle
  12586. description: |-
  12587. Path where the App Role authentication backend is mounted
  12588. in Vault, e.g: "approle"
  12589. type: string
  12590. roleId:
  12591. description: |-
  12592. RoleID configured in the App Role authentication backend when setting
  12593. up the authentication backend in Vault.
  12594. type: string
  12595. roleRef:
  12596. description: |-
  12597. Reference to a key in a Secret that contains the App Role ID used
  12598. to authenticate with Vault.
  12599. The `key` field must be specified and denotes which entry within the Secret
  12600. resource is used as the app role id.
  12601. properties:
  12602. key:
  12603. description: |-
  12604. A key in the referenced Secret.
  12605. Some instances of this field may be defaulted, in others it may be required.
  12606. maxLength: 253
  12607. minLength: 1
  12608. pattern: ^[-._a-zA-Z0-9]+$
  12609. type: string
  12610. name:
  12611. description: The name of the Secret resource being referred to.
  12612. maxLength: 253
  12613. minLength: 1
  12614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12615. type: string
  12616. namespace:
  12617. description: |-
  12618. The namespace of the Secret resource being referred to.
  12619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12620. maxLength: 63
  12621. minLength: 1
  12622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12623. type: string
  12624. type: object
  12625. secretRef:
  12626. description: |-
  12627. Reference to a key in a Secret that contains the App Role secret used
  12628. to authenticate with Vault.
  12629. The `key` field must be specified and denotes which entry within the Secret
  12630. resource is used as the app role secret.
  12631. properties:
  12632. key:
  12633. description: |-
  12634. A key in the referenced Secret.
  12635. Some instances of this field may be defaulted, in others it may be required.
  12636. maxLength: 253
  12637. minLength: 1
  12638. pattern: ^[-._a-zA-Z0-9]+$
  12639. type: string
  12640. name:
  12641. description: The name of the Secret resource being referred to.
  12642. maxLength: 253
  12643. minLength: 1
  12644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12645. type: string
  12646. namespace:
  12647. description: |-
  12648. The namespace of the Secret resource being referred to.
  12649. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12650. maxLength: 63
  12651. minLength: 1
  12652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12653. type: string
  12654. type: object
  12655. required:
  12656. - path
  12657. - secretRef
  12658. type: object
  12659. cert:
  12660. description: |-
  12661. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12662. Cert authentication method
  12663. properties:
  12664. clientCert:
  12665. description: |-
  12666. ClientCert is a certificate to authenticate using the Cert Vault
  12667. authentication method
  12668. properties:
  12669. key:
  12670. description: |-
  12671. A key in the referenced Secret.
  12672. Some instances of this field may be defaulted, in others it may be required.
  12673. maxLength: 253
  12674. minLength: 1
  12675. pattern: ^[-._a-zA-Z0-9]+$
  12676. type: string
  12677. name:
  12678. description: The name of the Secret resource being referred to.
  12679. maxLength: 253
  12680. minLength: 1
  12681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12682. type: string
  12683. namespace:
  12684. description: |-
  12685. The namespace of the Secret resource being referred to.
  12686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12687. maxLength: 63
  12688. minLength: 1
  12689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12690. type: string
  12691. type: object
  12692. secretRef:
  12693. description: |-
  12694. SecretRef to a key in a Secret resource containing client private key to
  12695. authenticate with Vault using the Cert authentication method
  12696. properties:
  12697. key:
  12698. description: |-
  12699. A key in the referenced Secret.
  12700. Some instances of this field may be defaulted, in others it may be required.
  12701. maxLength: 253
  12702. minLength: 1
  12703. pattern: ^[-._a-zA-Z0-9]+$
  12704. type: string
  12705. name:
  12706. description: The name of the Secret resource being referred to.
  12707. maxLength: 253
  12708. minLength: 1
  12709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12710. type: string
  12711. namespace:
  12712. description: |-
  12713. The namespace of the Secret resource being referred to.
  12714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12715. maxLength: 63
  12716. minLength: 1
  12717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12718. type: string
  12719. type: object
  12720. type: object
  12721. iam:
  12722. description: |-
  12723. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12724. AWS IAM authentication method
  12725. properties:
  12726. externalID:
  12727. description: AWS External ID set on assumed IAM roles
  12728. type: string
  12729. jwt:
  12730. description: Specify a service account with IRSA enabled
  12731. properties:
  12732. serviceAccountRef:
  12733. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12734. properties:
  12735. audiences:
  12736. description: |-
  12737. Audience specifies the `aud` claim for the service account token
  12738. Some providers automatically extend the audience field based on well-known annotations for workload
  12739. identity (e.g. IRSA or GCP Workload Identity)
  12740. items:
  12741. type: string
  12742. type: array
  12743. name:
  12744. description: The name of the ServiceAccount resource being referred to.
  12745. maxLength: 253
  12746. minLength: 1
  12747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12748. type: string
  12749. namespace:
  12750. description: |-
  12751. Namespace of the resource being referred to.
  12752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12753. maxLength: 63
  12754. minLength: 1
  12755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12756. type: string
  12757. required:
  12758. - name
  12759. type: object
  12760. type: object
  12761. path:
  12762. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12763. type: string
  12764. region:
  12765. description: AWS region
  12766. type: string
  12767. role:
  12768. description: This is the AWS role to be assumed before talking to vault
  12769. type: string
  12770. secretRef:
  12771. description: Specify credentials in a Secret object
  12772. properties:
  12773. accessKeyIDSecretRef:
  12774. description: The AccessKeyID is used for authentication
  12775. properties:
  12776. key:
  12777. description: |-
  12778. A key in the referenced Secret.
  12779. Some instances of this field may be defaulted, in others it may be required.
  12780. maxLength: 253
  12781. minLength: 1
  12782. pattern: ^[-._a-zA-Z0-9]+$
  12783. type: string
  12784. name:
  12785. description: The name of the Secret resource being referred to.
  12786. maxLength: 253
  12787. minLength: 1
  12788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12789. type: string
  12790. namespace:
  12791. description: |-
  12792. The namespace of the Secret resource being referred to.
  12793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12794. maxLength: 63
  12795. minLength: 1
  12796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12797. type: string
  12798. type: object
  12799. secretAccessKeySecretRef:
  12800. description: The SecretAccessKey is used for authentication
  12801. properties:
  12802. key:
  12803. description: |-
  12804. A key in the referenced Secret.
  12805. Some instances of this field may be defaulted, in others it may be required.
  12806. maxLength: 253
  12807. minLength: 1
  12808. pattern: ^[-._a-zA-Z0-9]+$
  12809. type: string
  12810. name:
  12811. description: The name of the Secret resource being referred to.
  12812. maxLength: 253
  12813. minLength: 1
  12814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12815. type: string
  12816. namespace:
  12817. description: |-
  12818. The namespace of the Secret resource being referred to.
  12819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12820. maxLength: 63
  12821. minLength: 1
  12822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12823. type: string
  12824. type: object
  12825. sessionTokenSecretRef:
  12826. description: |-
  12827. The SessionToken used for authentication
  12828. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12829. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12830. properties:
  12831. key:
  12832. description: |-
  12833. A key in the referenced Secret.
  12834. Some instances of this field may be defaulted, in others it may be required.
  12835. maxLength: 253
  12836. minLength: 1
  12837. pattern: ^[-._a-zA-Z0-9]+$
  12838. type: string
  12839. name:
  12840. description: The name of the Secret resource being referred to.
  12841. maxLength: 253
  12842. minLength: 1
  12843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12844. type: string
  12845. namespace:
  12846. description: |-
  12847. The namespace of the Secret resource being referred to.
  12848. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12849. maxLength: 63
  12850. minLength: 1
  12851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12852. type: string
  12853. type: object
  12854. type: object
  12855. vaultAwsIamServerID:
  12856. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12857. type: string
  12858. vaultRole:
  12859. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12860. type: string
  12861. required:
  12862. - vaultRole
  12863. type: object
  12864. jwt:
  12865. description: |-
  12866. Jwt authenticates with Vault by passing role and JWT token using the
  12867. JWT/OIDC authentication method
  12868. properties:
  12869. kubernetesServiceAccountToken:
  12870. description: |-
  12871. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12872. a token for with the `TokenRequest` API.
  12873. properties:
  12874. audiences:
  12875. description: |-
  12876. Optional audiences field that will be used to request a temporary Kubernetes service
  12877. account token for the service account referenced by `serviceAccountRef`.
  12878. Defaults to a single audience `vault` it not specified.
  12879. Deprecated: use serviceAccountRef.Audiences instead
  12880. items:
  12881. type: string
  12882. type: array
  12883. expirationSeconds:
  12884. description: |-
  12885. Optional expiration time in seconds that will be used to request a temporary
  12886. Kubernetes service account token for the service account referenced by
  12887. `serviceAccountRef`.
  12888. Deprecated: this will be removed in the future.
  12889. Defaults to 10 minutes.
  12890. format: int64
  12891. type: integer
  12892. serviceAccountRef:
  12893. description: Service account field containing the name of a kubernetes ServiceAccount.
  12894. properties:
  12895. audiences:
  12896. description: |-
  12897. Audience specifies the `aud` claim for the service account token
  12898. Some providers automatically extend the audience field based on well-known annotations for workload
  12899. identity (e.g. IRSA or GCP Workload Identity)
  12900. items:
  12901. type: string
  12902. type: array
  12903. name:
  12904. description: The name of the ServiceAccount resource being referred to.
  12905. maxLength: 253
  12906. minLength: 1
  12907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12908. type: string
  12909. namespace:
  12910. description: |-
  12911. Namespace of the resource being referred to.
  12912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12913. maxLength: 63
  12914. minLength: 1
  12915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12916. type: string
  12917. required:
  12918. - name
  12919. type: object
  12920. required:
  12921. - serviceAccountRef
  12922. type: object
  12923. path:
  12924. default: jwt
  12925. description: |-
  12926. Path where the JWT authentication backend is mounted
  12927. in Vault, e.g: "jwt"
  12928. type: string
  12929. role:
  12930. description: |-
  12931. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12932. authentication method
  12933. type: string
  12934. secretRef:
  12935. description: |-
  12936. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12937. authenticate with Vault using the JWT/OIDC authentication method.
  12938. properties:
  12939. key:
  12940. description: |-
  12941. A key in the referenced Secret.
  12942. Some instances of this field may be defaulted, in others it may be required.
  12943. maxLength: 253
  12944. minLength: 1
  12945. pattern: ^[-._a-zA-Z0-9]+$
  12946. type: string
  12947. name:
  12948. description: The name of the Secret resource being referred to.
  12949. maxLength: 253
  12950. minLength: 1
  12951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12952. type: string
  12953. namespace:
  12954. description: |-
  12955. The namespace of the Secret resource being referred to.
  12956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12957. maxLength: 63
  12958. minLength: 1
  12959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12960. type: string
  12961. type: object
  12962. required:
  12963. - path
  12964. type: object
  12965. kubernetes:
  12966. description: |-
  12967. Kubernetes authenticates with Vault by passing the ServiceAccount
  12968. token stored in the named Secret resource to the Vault server.
  12969. properties:
  12970. mountPath:
  12971. default: kubernetes
  12972. description: |-
  12973. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12974. "kubernetes"
  12975. type: string
  12976. role:
  12977. description: |-
  12978. A required field containing the Vault Role to assume. A Role binds a
  12979. Kubernetes ServiceAccount with a set of Vault policies.
  12980. type: string
  12981. secretRef:
  12982. description: |-
  12983. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12984. for authenticating with Vault. If a name is specified without a key,
  12985. `token` is the default. If one is not specified, the one bound to
  12986. the controller will be used.
  12987. properties:
  12988. key:
  12989. description: |-
  12990. A key in the referenced Secret.
  12991. Some instances of this field may be defaulted, in others it may be required.
  12992. maxLength: 253
  12993. minLength: 1
  12994. pattern: ^[-._a-zA-Z0-9]+$
  12995. type: string
  12996. name:
  12997. description: The name of the Secret resource being referred to.
  12998. maxLength: 253
  12999. minLength: 1
  13000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13001. type: string
  13002. namespace:
  13003. description: |-
  13004. The namespace of the Secret resource being referred to.
  13005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13006. maxLength: 63
  13007. minLength: 1
  13008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13009. type: string
  13010. type: object
  13011. serviceAccountRef:
  13012. description: |-
  13013. Optional service account field containing the name of a kubernetes ServiceAccount.
  13014. If the service account is specified, the service account secret token JWT will be used
  13015. for authenticating with Vault. If the service account selector is not supplied,
  13016. the secretRef will be used instead.
  13017. properties:
  13018. audiences:
  13019. description: |-
  13020. Audience specifies the `aud` claim for the service account token
  13021. Some providers automatically extend the audience field based on well-known annotations for workload
  13022. identity (e.g. IRSA or GCP Workload Identity)
  13023. items:
  13024. type: string
  13025. type: array
  13026. name:
  13027. description: The name of the ServiceAccount resource being referred to.
  13028. maxLength: 253
  13029. minLength: 1
  13030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13031. type: string
  13032. namespace:
  13033. description: |-
  13034. Namespace of the resource being referred to.
  13035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13036. maxLength: 63
  13037. minLength: 1
  13038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13039. type: string
  13040. required:
  13041. - name
  13042. type: object
  13043. required:
  13044. - mountPath
  13045. - role
  13046. type: object
  13047. ldap:
  13048. description: |-
  13049. Ldap authenticates with Vault by passing username/password pair using
  13050. the LDAP authentication method
  13051. properties:
  13052. path:
  13053. default: ldap
  13054. description: |-
  13055. Path where the LDAP authentication backend is mounted
  13056. in Vault, e.g: "ldap"
  13057. type: string
  13058. secretRef:
  13059. description: |-
  13060. SecretRef to a key in a Secret resource containing password for the LDAP
  13061. user used to authenticate with Vault using the LDAP authentication
  13062. method
  13063. properties:
  13064. key:
  13065. description: |-
  13066. A key in the referenced Secret.
  13067. Some instances of this field may be defaulted, in others it may be required.
  13068. maxLength: 253
  13069. minLength: 1
  13070. pattern: ^[-._a-zA-Z0-9]+$
  13071. type: string
  13072. name:
  13073. description: The name of the Secret resource being referred to.
  13074. maxLength: 253
  13075. minLength: 1
  13076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13077. type: string
  13078. namespace:
  13079. description: |-
  13080. The namespace of the Secret resource being referred to.
  13081. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13082. maxLength: 63
  13083. minLength: 1
  13084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13085. type: string
  13086. type: object
  13087. username:
  13088. description: |-
  13089. Username is an LDAP username used to authenticate using the LDAP Vault
  13090. authentication method
  13091. type: string
  13092. required:
  13093. - path
  13094. - username
  13095. type: object
  13096. namespace:
  13097. description: |-
  13098. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  13099. Namespaces is a set of features within Vault Enterprise that allows
  13100. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13101. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13102. This will default to Vault.Namespace field if set, or empty otherwise
  13103. type: string
  13104. tokenSecretRef:
  13105. description: TokenSecretRef authenticates with Vault by presenting a token.
  13106. properties:
  13107. key:
  13108. description: |-
  13109. A key in the referenced Secret.
  13110. Some instances of this field may be defaulted, in others it may be required.
  13111. maxLength: 253
  13112. minLength: 1
  13113. pattern: ^[-._a-zA-Z0-9]+$
  13114. type: string
  13115. name:
  13116. description: The name of the Secret resource being referred to.
  13117. maxLength: 253
  13118. minLength: 1
  13119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13120. type: string
  13121. namespace:
  13122. description: |-
  13123. The namespace of the Secret resource being referred to.
  13124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13125. maxLength: 63
  13126. minLength: 1
  13127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13128. type: string
  13129. type: object
  13130. userPass:
  13131. description: UserPass authenticates with Vault by passing username/password pair
  13132. properties:
  13133. path:
  13134. default: userpass
  13135. description: |-
  13136. Path where the UserPassword authentication backend is mounted
  13137. in Vault, e.g: "userpass"
  13138. type: string
  13139. secretRef:
  13140. description: |-
  13141. SecretRef to a key in a Secret resource containing password for the
  13142. user used to authenticate with Vault using the UserPass authentication
  13143. method
  13144. properties:
  13145. key:
  13146. description: |-
  13147. A key in the referenced Secret.
  13148. Some instances of this field may be defaulted, in others it may be required.
  13149. maxLength: 253
  13150. minLength: 1
  13151. pattern: ^[-._a-zA-Z0-9]+$
  13152. type: string
  13153. name:
  13154. description: The name of the Secret resource being referred to.
  13155. maxLength: 253
  13156. minLength: 1
  13157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13158. type: string
  13159. namespace:
  13160. description: |-
  13161. The namespace of the Secret resource being referred to.
  13162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13163. maxLength: 63
  13164. minLength: 1
  13165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13166. type: string
  13167. type: object
  13168. username:
  13169. description: |-
  13170. Username is a username used to authenticate using the UserPass Vault
  13171. authentication method
  13172. type: string
  13173. required:
  13174. - path
  13175. - username
  13176. type: object
  13177. type: object
  13178. caBundle:
  13179. description: |-
  13180. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13181. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13182. plain HTTP protocol connection. If not set the system root certificates
  13183. are used to validate the TLS connection.
  13184. format: byte
  13185. type: string
  13186. caProvider:
  13187. description: The provider for the CA bundle to use to validate Vault server certificate.
  13188. properties:
  13189. key:
  13190. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13191. maxLength: 253
  13192. minLength: 1
  13193. pattern: ^[-._a-zA-Z0-9]+$
  13194. type: string
  13195. name:
  13196. description: The name of the object located at the provider type.
  13197. maxLength: 253
  13198. minLength: 1
  13199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13200. type: string
  13201. namespace:
  13202. description: |-
  13203. The namespace the Provider type is in.
  13204. Can only be defined when used in a ClusterSecretStore.
  13205. maxLength: 63
  13206. minLength: 1
  13207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13208. type: string
  13209. type:
  13210. description: The type of provider to use such as "Secret", or "ConfigMap".
  13211. enum:
  13212. - Secret
  13213. - ConfigMap
  13214. type: string
  13215. required:
  13216. - name
  13217. - type
  13218. type: object
  13219. forwardInconsistent:
  13220. description: |-
  13221. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13222. leader instead of simply retrying within a loop. This can increase performance if
  13223. the option is enabled serverside.
  13224. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13225. type: boolean
  13226. headers:
  13227. additionalProperties:
  13228. type: string
  13229. description: Headers to be added in Vault request
  13230. type: object
  13231. namespace:
  13232. description: |-
  13233. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13234. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13235. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13236. type: string
  13237. path:
  13238. description: |-
  13239. Path is the mount path of the Vault KV backend endpoint, e.g:
  13240. "secret". The v2 KV secret engine version specific "/data" path suffix
  13241. for fetching secrets from Vault is optional and will be appended
  13242. if not present in specified path.
  13243. type: string
  13244. readYourWrites:
  13245. description: |-
  13246. ReadYourWrites ensures isolated read-after-write semantics by
  13247. providing discovered cluster replication states in each request.
  13248. More information about eventual consistency in Vault can be found here
  13249. https://www.vaultproject.io/docs/enterprise/consistency
  13250. type: boolean
  13251. server:
  13252. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13253. type: string
  13254. tls:
  13255. description: |-
  13256. The configuration used for client side related TLS communication, when the Vault server
  13257. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13258. This parameter is ignored for plain HTTP protocol connection.
  13259. It's worth noting this configuration is different from the "TLS certificates auth method",
  13260. which is available under the `auth.cert` section.
  13261. properties:
  13262. certSecretRef:
  13263. description: |-
  13264. CertSecretRef is a certificate added to the transport layer
  13265. when communicating with the Vault server.
  13266. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13267. properties:
  13268. key:
  13269. description: |-
  13270. A key in the referenced Secret.
  13271. Some instances of this field may be defaulted, in others it may be required.
  13272. maxLength: 253
  13273. minLength: 1
  13274. pattern: ^[-._a-zA-Z0-9]+$
  13275. type: string
  13276. name:
  13277. description: The name of the Secret resource being referred to.
  13278. maxLength: 253
  13279. minLength: 1
  13280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13281. type: string
  13282. namespace:
  13283. description: |-
  13284. The namespace of the Secret resource being referred to.
  13285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13286. maxLength: 63
  13287. minLength: 1
  13288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13289. type: string
  13290. type: object
  13291. keySecretRef:
  13292. description: |-
  13293. KeySecretRef to a key in a Secret resource containing client private key
  13294. added to the transport layer when communicating with the Vault server.
  13295. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13296. properties:
  13297. key:
  13298. description: |-
  13299. A key in the referenced Secret.
  13300. Some instances of this field may be defaulted, in others it may be required.
  13301. maxLength: 253
  13302. minLength: 1
  13303. pattern: ^[-._a-zA-Z0-9]+$
  13304. type: string
  13305. name:
  13306. description: The name of the Secret resource being referred to.
  13307. maxLength: 253
  13308. minLength: 1
  13309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13310. type: string
  13311. namespace:
  13312. description: |-
  13313. The namespace of the Secret resource being referred to.
  13314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13315. maxLength: 63
  13316. minLength: 1
  13317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13318. type: string
  13319. type: object
  13320. type: object
  13321. version:
  13322. default: v2
  13323. description: |-
  13324. Version is the Vault KV secret engine version. This can be either "v1" or
  13325. "v2". Version defaults to "v2".
  13326. enum:
  13327. - v1
  13328. - v2
  13329. type: string
  13330. required:
  13331. - server
  13332. type: object
  13333. webhook:
  13334. description: Webhook configures this store to sync secrets using a generic templated webhook
  13335. properties:
  13336. auth:
  13337. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13338. maxProperties: 1
  13339. minProperties: 1
  13340. properties:
  13341. ntlm:
  13342. description: NTLMProtocol configures the store to use NTLM for auth
  13343. properties:
  13344. passwordSecret:
  13345. description: |-
  13346. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13347. In some instances, `key` is a required field.
  13348. properties:
  13349. key:
  13350. description: |-
  13351. A key in the referenced Secret.
  13352. Some instances of this field may be defaulted, in others it may be required.
  13353. maxLength: 253
  13354. minLength: 1
  13355. pattern: ^[-._a-zA-Z0-9]+$
  13356. type: string
  13357. name:
  13358. description: The name of the Secret resource being referred to.
  13359. maxLength: 253
  13360. minLength: 1
  13361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13362. type: string
  13363. namespace:
  13364. description: |-
  13365. The namespace of the Secret resource being referred to.
  13366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13367. maxLength: 63
  13368. minLength: 1
  13369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13370. type: string
  13371. type: object
  13372. usernameSecret:
  13373. description: |-
  13374. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13375. In some instances, `key` is a required field.
  13376. properties:
  13377. key:
  13378. description: |-
  13379. A key in the referenced Secret.
  13380. Some instances of this field may be defaulted, in others it may be required.
  13381. maxLength: 253
  13382. minLength: 1
  13383. pattern: ^[-._a-zA-Z0-9]+$
  13384. type: string
  13385. name:
  13386. description: The name of the Secret resource being referred to.
  13387. maxLength: 253
  13388. minLength: 1
  13389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13390. type: string
  13391. namespace:
  13392. description: |-
  13393. The namespace of the Secret resource being referred to.
  13394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13395. maxLength: 63
  13396. minLength: 1
  13397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13398. type: string
  13399. type: object
  13400. required:
  13401. - passwordSecret
  13402. - usernameSecret
  13403. type: object
  13404. type: object
  13405. body:
  13406. description: Body
  13407. type: string
  13408. caBundle:
  13409. description: |-
  13410. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13411. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13412. plain HTTP protocol connection. If not set the system root certificates
  13413. are used to validate the TLS connection.
  13414. format: byte
  13415. type: string
  13416. caProvider:
  13417. description: The provider for the CA bundle to use to validate webhook server certificate.
  13418. properties:
  13419. key:
  13420. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13421. maxLength: 253
  13422. minLength: 1
  13423. pattern: ^[-._a-zA-Z0-9]+$
  13424. type: string
  13425. name:
  13426. description: The name of the object located at the provider type.
  13427. maxLength: 253
  13428. minLength: 1
  13429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13430. type: string
  13431. namespace:
  13432. description: The namespace the Provider type is in.
  13433. maxLength: 63
  13434. minLength: 1
  13435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13436. type: string
  13437. type:
  13438. description: The type of provider to use such as "Secret", or "ConfigMap".
  13439. enum:
  13440. - Secret
  13441. - ConfigMap
  13442. type: string
  13443. required:
  13444. - name
  13445. - type
  13446. type: object
  13447. headers:
  13448. additionalProperties:
  13449. type: string
  13450. description: Headers
  13451. type: object
  13452. method:
  13453. description: Webhook Method
  13454. type: string
  13455. result:
  13456. description: Result formatting
  13457. properties:
  13458. jsonPath:
  13459. description: Json path of return value
  13460. type: string
  13461. type: object
  13462. secrets:
  13463. description: |-
  13464. Secrets to fill in templates
  13465. These secrets will be passed to the templating function as key value pairs under the given name
  13466. items:
  13467. description: WebhookSecret defines a secret to be used in webhook templates.
  13468. properties:
  13469. name:
  13470. description: Name of this secret in templates
  13471. type: string
  13472. secretRef:
  13473. description: Secret ref to fill in credentials
  13474. properties:
  13475. key:
  13476. description: |-
  13477. A key in the referenced Secret.
  13478. Some instances of this field may be defaulted, in others it may be required.
  13479. maxLength: 253
  13480. minLength: 1
  13481. pattern: ^[-._a-zA-Z0-9]+$
  13482. type: string
  13483. name:
  13484. description: The name of the Secret resource being referred to.
  13485. maxLength: 253
  13486. minLength: 1
  13487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13488. type: string
  13489. namespace:
  13490. description: |-
  13491. The namespace of the Secret resource being referred to.
  13492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13493. maxLength: 63
  13494. minLength: 1
  13495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13496. type: string
  13497. type: object
  13498. required:
  13499. - name
  13500. - secretRef
  13501. type: object
  13502. type: array
  13503. timeout:
  13504. description: Timeout
  13505. type: string
  13506. url:
  13507. description: Webhook url to call
  13508. type: string
  13509. required:
  13510. - result
  13511. - url
  13512. type: object
  13513. yandexcertificatemanager:
  13514. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13515. properties:
  13516. apiEndpoint:
  13517. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13518. type: string
  13519. auth:
  13520. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13521. properties:
  13522. authorizedKeySecretRef:
  13523. description: The authorized key used for authentication
  13524. properties:
  13525. key:
  13526. description: |-
  13527. A key in the referenced Secret.
  13528. Some instances of this field may be defaulted, in others it may be required.
  13529. maxLength: 253
  13530. minLength: 1
  13531. pattern: ^[-._a-zA-Z0-9]+$
  13532. type: string
  13533. name:
  13534. description: The name of the Secret resource being referred to.
  13535. maxLength: 253
  13536. minLength: 1
  13537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13538. type: string
  13539. namespace:
  13540. description: |-
  13541. The namespace of the Secret resource being referred to.
  13542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13543. maxLength: 63
  13544. minLength: 1
  13545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13546. type: string
  13547. type: object
  13548. type: object
  13549. caProvider:
  13550. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13551. properties:
  13552. certSecretRef:
  13553. description: |-
  13554. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13555. In some instances, `key` is a required field.
  13556. properties:
  13557. key:
  13558. description: |-
  13559. A key in the referenced Secret.
  13560. Some instances of this field may be defaulted, in others it may be required.
  13561. maxLength: 253
  13562. minLength: 1
  13563. pattern: ^[-._a-zA-Z0-9]+$
  13564. type: string
  13565. name:
  13566. description: The name of the Secret resource being referred to.
  13567. maxLength: 253
  13568. minLength: 1
  13569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13570. type: string
  13571. namespace:
  13572. description: |-
  13573. The namespace of the Secret resource being referred to.
  13574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13575. maxLength: 63
  13576. minLength: 1
  13577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13578. type: string
  13579. type: object
  13580. type: object
  13581. required:
  13582. - auth
  13583. type: object
  13584. yandexlockbox:
  13585. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13586. properties:
  13587. apiEndpoint:
  13588. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13589. type: string
  13590. auth:
  13591. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13592. properties:
  13593. authorizedKeySecretRef:
  13594. description: The authorized key used for authentication
  13595. properties:
  13596. key:
  13597. description: |-
  13598. A key in the referenced Secret.
  13599. Some instances of this field may be defaulted, in others it may be required.
  13600. maxLength: 253
  13601. minLength: 1
  13602. pattern: ^[-._a-zA-Z0-9]+$
  13603. type: string
  13604. name:
  13605. description: The name of the Secret resource being referred to.
  13606. maxLength: 253
  13607. minLength: 1
  13608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13609. type: string
  13610. namespace:
  13611. description: |-
  13612. The namespace of the Secret resource being referred to.
  13613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13614. maxLength: 63
  13615. minLength: 1
  13616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13617. type: string
  13618. type: object
  13619. type: object
  13620. caProvider:
  13621. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13622. properties:
  13623. certSecretRef:
  13624. description: |-
  13625. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13626. In some instances, `key` is a required field.
  13627. properties:
  13628. key:
  13629. description: |-
  13630. A key in the referenced Secret.
  13631. Some instances of this field may be defaulted, in others it may be required.
  13632. maxLength: 253
  13633. minLength: 1
  13634. pattern: ^[-._a-zA-Z0-9]+$
  13635. type: string
  13636. name:
  13637. description: The name of the Secret resource being referred to.
  13638. maxLength: 253
  13639. minLength: 1
  13640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13641. type: string
  13642. namespace:
  13643. description: |-
  13644. The namespace of the Secret resource being referred to.
  13645. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13646. maxLength: 63
  13647. minLength: 1
  13648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13649. type: string
  13650. type: object
  13651. type: object
  13652. required:
  13653. - auth
  13654. type: object
  13655. type: object
  13656. refreshInterval:
  13657. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13658. type: integer
  13659. retrySettings:
  13660. description: Used to configure HTTP retries on failures.
  13661. properties:
  13662. maxRetries:
  13663. description: MaxRetries is the maximum number of retry attempts.
  13664. format: int32
  13665. type: integer
  13666. retryInterval:
  13667. description: RetryInterval is the interval between retry attempts.
  13668. type: string
  13669. type: object
  13670. required:
  13671. - provider
  13672. type: object
  13673. status:
  13674. description: SecretStoreStatus defines the observed state of the SecretStore.
  13675. properties:
  13676. capabilities:
  13677. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13678. type: string
  13679. conditions:
  13680. items:
  13681. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13682. properties:
  13683. lastTransitionTime:
  13684. format: date-time
  13685. type: string
  13686. message:
  13687. type: string
  13688. reason:
  13689. type: string
  13690. status:
  13691. type: string
  13692. type:
  13693. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13694. type: string
  13695. required:
  13696. - status
  13697. - type
  13698. type: object
  13699. type: array
  13700. type: object
  13701. type: object
  13702. served: false
  13703. storage: false
  13704. subresources:
  13705. status: {}
  13706. ---
  13707. apiVersion: apiextensions.k8s.io/v1
  13708. kind: CustomResourceDefinition
  13709. metadata:
  13710. annotations:
  13711. controller-gen.kubebuilder.io/version: v0.19.0
  13712. labels:
  13713. external-secrets.io/component: controller
  13714. name: externalsecrets.external-secrets.io
  13715. spec:
  13716. group: external-secrets.io
  13717. names:
  13718. categories:
  13719. - external-secrets
  13720. kind: ExternalSecret
  13721. listKind: ExternalSecretList
  13722. plural: externalsecrets
  13723. shortNames:
  13724. - es
  13725. singular: externalsecret
  13726. scope: Namespaced
  13727. versions:
  13728. - additionalPrinterColumns:
  13729. - jsonPath: .spec.secretStoreRef.kind
  13730. name: StoreType
  13731. type: string
  13732. - jsonPath: .spec.secretStoreRef.name
  13733. name: Store
  13734. type: string
  13735. - jsonPath: .spec.refreshInterval
  13736. name: Refresh Interval
  13737. type: string
  13738. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13739. name: Status
  13740. type: string
  13741. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13742. name: Ready
  13743. type: string
  13744. - jsonPath: .status.refreshTime
  13745. name: Last Sync
  13746. type: date
  13747. name: v1
  13748. schema:
  13749. openAPIV3Schema:
  13750. description: |-
  13751. ExternalSecret is the Schema for the external-secrets API.
  13752. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13753. properties:
  13754. apiVersion:
  13755. description: |-
  13756. APIVersion defines the versioned schema of this representation of an object.
  13757. Servers should convert recognized schemas to the latest internal value, and
  13758. may reject unrecognized values.
  13759. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13760. type: string
  13761. kind:
  13762. description: |-
  13763. Kind is a string value representing the REST resource this object represents.
  13764. Servers may infer this from the endpoint the client submits requests to.
  13765. Cannot be updated.
  13766. In CamelCase.
  13767. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13768. type: string
  13769. metadata:
  13770. type: object
  13771. spec:
  13772. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13773. properties:
  13774. data:
  13775. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13776. items:
  13777. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13778. properties:
  13779. remoteRef:
  13780. description: |-
  13781. RemoteRef points to the remote secret and defines
  13782. which secret (version/property/..) to fetch.
  13783. properties:
  13784. conversionStrategy:
  13785. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13786. enum:
  13787. - Default
  13788. - Unicode
  13789. type: string
  13790. decodingStrategy:
  13791. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13792. enum:
  13793. - Auto
  13794. - Base64
  13795. - Base64URL
  13796. - None
  13797. type: string
  13798. key:
  13799. description: Key is the key used in the Provider, mandatory
  13800. type: string
  13801. metadataPolicy:
  13802. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13803. enum:
  13804. - None
  13805. - Fetch
  13806. type: string
  13807. nullBytePolicy:
  13808. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13809. enum:
  13810. - Ignore
  13811. - Fail
  13812. type: string
  13813. property:
  13814. description: Used to select a specific property of the Provider value (if a map), if supported
  13815. type: string
  13816. version:
  13817. description: Used to select a specific version of the Provider value, if supported
  13818. type: string
  13819. required:
  13820. - key
  13821. type: object
  13822. secretKey:
  13823. description: The key in the Kubernetes Secret to store the value.
  13824. maxLength: 253
  13825. minLength: 1
  13826. pattern: ^[-._a-zA-Z0-9]+$
  13827. type: string
  13828. sourceRef:
  13829. description: |-
  13830. SourceRef allows you to override the source
  13831. from which the value will be pulled.
  13832. maxProperties: 1
  13833. minProperties: 1
  13834. properties:
  13835. generatorRef:
  13836. description: |-
  13837. GeneratorRef points to a generator custom resource.
  13838. Deprecated: The generatorRef is not implemented in .data[].
  13839. this will be removed with v1.
  13840. properties:
  13841. apiVersion:
  13842. default: generators.external-secrets.io/v1alpha1
  13843. description: Specify the apiVersion of the generator resource
  13844. type: string
  13845. kind:
  13846. description: Specify the Kind of the generator resource
  13847. enum:
  13848. - ACRAccessToken
  13849. - BeyondtrustWorkloadCredentialsDynamicSecret
  13850. - ClusterGenerator
  13851. - CloudsmithAccessToken
  13852. - ECRAuthorizationToken
  13853. - Fake
  13854. - GCRAccessToken
  13855. - GithubAccessToken
  13856. - GitlabDeployToken
  13857. - QuayAccessToken
  13858. - Password
  13859. - SSHKey
  13860. - STSSessionToken
  13861. - UUID
  13862. - VaultDynamicSecret
  13863. - Webhook
  13864. - Grafana
  13865. - MFA
  13866. type: string
  13867. name:
  13868. description: Specify the name of the generator resource
  13869. maxLength: 253
  13870. minLength: 1
  13871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13872. type: string
  13873. required:
  13874. - kind
  13875. - name
  13876. type: object
  13877. storeRef:
  13878. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13879. properties:
  13880. kind:
  13881. description: |-
  13882. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13883. Defaults to `SecretStore`
  13884. enum:
  13885. - SecretStore
  13886. - ClusterSecretStore
  13887. type: string
  13888. name:
  13889. description: Name of the SecretStore resource
  13890. maxLength: 253
  13891. minLength: 1
  13892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13893. type: string
  13894. type: object
  13895. type: object
  13896. required:
  13897. - remoteRef
  13898. - secretKey
  13899. type: object
  13900. type: array
  13901. dataFrom:
  13902. description: |-
  13903. DataFrom is used to fetch all properties from a specific Provider data
  13904. If multiple entries are specified, the Secret keys are merged in the specified order
  13905. items:
  13906. description: |-
  13907. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13908. when using DataFrom to fetch multiple values from a Provider.
  13909. properties:
  13910. extract:
  13911. description: |-
  13912. Used to extract multiple key/value pairs from one secret
  13913. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13914. properties:
  13915. conversionStrategy:
  13916. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13917. enum:
  13918. - Default
  13919. - Unicode
  13920. type: string
  13921. decodingStrategy:
  13922. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13923. enum:
  13924. - Auto
  13925. - Base64
  13926. - Base64URL
  13927. - None
  13928. type: string
  13929. key:
  13930. description: Key is the key used in the Provider, mandatory
  13931. type: string
  13932. metadataPolicy:
  13933. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13934. enum:
  13935. - None
  13936. - Fetch
  13937. type: string
  13938. nullBytePolicy:
  13939. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13940. enum:
  13941. - Ignore
  13942. - Fail
  13943. type: string
  13944. property:
  13945. description: Used to select a specific property of the Provider value (if a map), if supported
  13946. type: string
  13947. version:
  13948. description: Used to select a specific version of the Provider value, if supported
  13949. type: string
  13950. required:
  13951. - key
  13952. type: object
  13953. find:
  13954. description: |-
  13955. Used to find secrets based on tags or regular expressions
  13956. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13957. properties:
  13958. conversionStrategy:
  13959. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13960. enum:
  13961. - Default
  13962. - Unicode
  13963. type: string
  13964. decodingStrategy:
  13965. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13966. enum:
  13967. - Auto
  13968. - Base64
  13969. - Base64URL
  13970. - None
  13971. type: string
  13972. name:
  13973. description: Finds secrets based on the name.
  13974. properties:
  13975. regexp:
  13976. description: Finds secrets base
  13977. type: string
  13978. type: object
  13979. nullBytePolicy:
  13980. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13981. enum:
  13982. - Ignore
  13983. - Fail
  13984. type: string
  13985. path:
  13986. description: A root path to start the find operations.
  13987. type: string
  13988. tags:
  13989. additionalProperties:
  13990. type: string
  13991. description: Find secrets based on tags.
  13992. type: object
  13993. type: object
  13994. rewrite:
  13995. description: |-
  13996. Used to rewrite secret Keys after getting them from the secret Provider
  13997. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13998. items:
  13999. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  14000. maxProperties: 1
  14001. minProperties: 1
  14002. properties:
  14003. merge:
  14004. description: |-
  14005. Used to merge key/values in one single Secret
  14006. The resulting key will contain all values from the specified secrets
  14007. properties:
  14008. conflictPolicy:
  14009. default: Error
  14010. description: Used to define the policy to use in conflict resolution.
  14011. enum:
  14012. - Ignore
  14013. - Error
  14014. type: string
  14015. into:
  14016. default: ""
  14017. description: |-
  14018. Used to define the target key of the merge operation.
  14019. Required if strategy is JSON. Ignored otherwise.
  14020. type: string
  14021. priority:
  14022. description: Used to define key priority in conflict resolution.
  14023. items:
  14024. type: string
  14025. type: array
  14026. priorityPolicy:
  14027. default: Strict
  14028. description: Used to define the policy when a key in the priority list does not exist in the input.
  14029. enum:
  14030. - IgnoreNotFound
  14031. - Strict
  14032. type: string
  14033. strategy:
  14034. default: Extract
  14035. description: Used to define the strategy to use in the merge operation.
  14036. enum:
  14037. - Extract
  14038. - JSON
  14039. type: string
  14040. type: object
  14041. regexp:
  14042. description: |-
  14043. Used to rewrite with regular expressions.
  14044. The resulting key will be the output of a regexp.ReplaceAll operation.
  14045. properties:
  14046. source:
  14047. description: Used to define the regular expression of a re.Compiler.
  14048. type: string
  14049. target:
  14050. description: Used to define the target pattern of a ReplaceAll operation.
  14051. type: string
  14052. required:
  14053. - source
  14054. - target
  14055. type: object
  14056. transform:
  14057. description: |-
  14058. Used to apply string transformation on the secrets.
  14059. The resulting key will be the output of the template applied by the operation.
  14060. properties:
  14061. template:
  14062. description: |-
  14063. Used to define the template to apply on the secret name.
  14064. `.value ` will specify the secret name in the template.
  14065. type: string
  14066. required:
  14067. - template
  14068. type: object
  14069. type: object
  14070. type: array
  14071. sourceRef:
  14072. description: |-
  14073. SourceRef points to a store or generator
  14074. which contains secret values ready to use.
  14075. Use this in combination with Extract or Find pull values out of
  14076. a specific SecretStore.
  14077. When sourceRef points to a generator Extract or Find is not supported.
  14078. The generator returns a static map of values
  14079. maxProperties: 1
  14080. minProperties: 1
  14081. properties:
  14082. generatorRef:
  14083. description: GeneratorRef points to a generator custom resource.
  14084. properties:
  14085. apiVersion:
  14086. default: generators.external-secrets.io/v1alpha1
  14087. description: Specify the apiVersion of the generator resource
  14088. type: string
  14089. kind:
  14090. description: Specify the Kind of the generator resource
  14091. enum:
  14092. - ACRAccessToken
  14093. - BeyondtrustWorkloadCredentialsDynamicSecret
  14094. - ClusterGenerator
  14095. - CloudsmithAccessToken
  14096. - ECRAuthorizationToken
  14097. - Fake
  14098. - GCRAccessToken
  14099. - GithubAccessToken
  14100. - GitlabDeployToken
  14101. - QuayAccessToken
  14102. - Password
  14103. - SSHKey
  14104. - STSSessionToken
  14105. - UUID
  14106. - VaultDynamicSecret
  14107. - Webhook
  14108. - Grafana
  14109. - MFA
  14110. type: string
  14111. name:
  14112. description: Specify the name of the generator resource
  14113. maxLength: 253
  14114. minLength: 1
  14115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14116. type: string
  14117. required:
  14118. - kind
  14119. - name
  14120. type: object
  14121. storeRef:
  14122. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14123. properties:
  14124. kind:
  14125. description: |-
  14126. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14127. Defaults to `SecretStore`
  14128. enum:
  14129. - SecretStore
  14130. - ClusterSecretStore
  14131. type: string
  14132. name:
  14133. description: Name of the SecretStore resource
  14134. maxLength: 253
  14135. minLength: 1
  14136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14137. type: string
  14138. type: object
  14139. type: object
  14140. type: object
  14141. type: array
  14142. refreshInterval:
  14143. default: 1h0m0s
  14144. description: |-
  14145. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14146. specified as Golang Duration strings.
  14147. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14148. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14149. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14150. type: string
  14151. refreshPolicy:
  14152. description: |-
  14153. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14154. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14155. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14156. No periodic updates occur if refreshInterval is 0.
  14157. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14158. enum:
  14159. - CreatedOnce
  14160. - Periodic
  14161. - OnChange
  14162. type: string
  14163. secretStoreRef:
  14164. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14165. properties:
  14166. kind:
  14167. description: |-
  14168. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14169. Defaults to `SecretStore`
  14170. enum:
  14171. - SecretStore
  14172. - ClusterSecretStore
  14173. type: string
  14174. name:
  14175. description: Name of the SecretStore resource
  14176. maxLength: 253
  14177. minLength: 1
  14178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14179. type: string
  14180. type: object
  14181. syncWindows:
  14182. description: |-
  14183. SyncWindows optionally restricts when periodic refreshes may occur.
  14184. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  14185. properties:
  14186. kind:
  14187. description: |-
  14188. Kind applies to every window in the list.
  14189. "allow" -- syncs are permitted only while at least one window is active;
  14190. all other times are blocked.
  14191. "deny" -- syncs are blocked while any window is active;
  14192. all other times are permitted.
  14193. enum:
  14194. - allow
  14195. - deny
  14196. type: string
  14197. windows:
  14198. description: Windows is the list of schedule+duration pairs.
  14199. items:
  14200. description: |-
  14201. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  14202. within a SyncWindows block.
  14203. properties:
  14204. duration:
  14205. description: |-
  14206. Duration specifies how long the window stays open after each Schedule
  14207. firing. Example: "8h".
  14208. type: string
  14209. schedule:
  14210. description: |-
  14211. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  14212. named shorthand such as @daily or @every 1h. It marks the start time of
  14213. each window occurrence.
  14214. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  14215. minLength: 1
  14216. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  14217. type: string
  14218. required:
  14219. - duration
  14220. - schedule
  14221. type: object
  14222. minItems: 1
  14223. type: array
  14224. required:
  14225. - kind
  14226. - windows
  14227. type: object
  14228. target:
  14229. default:
  14230. creationPolicy: Owner
  14231. deletionPolicy: Retain
  14232. description: |-
  14233. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14234. there can be only one target per ExternalSecret.
  14235. properties:
  14236. creationPolicy:
  14237. default: Owner
  14238. description: |-
  14239. CreationPolicy defines rules on how to create the resulting Secret.
  14240. Defaults to "Owner"
  14241. enum:
  14242. - Owner
  14243. - Orphan
  14244. - Merge
  14245. - None
  14246. - CreateOrMerge
  14247. type: string
  14248. deletionPolicy:
  14249. default: Retain
  14250. description: |-
  14251. DeletionPolicy defines rules on how to delete the resulting Secret.
  14252. Defaults to "Retain"
  14253. enum:
  14254. - Delete
  14255. - Merge
  14256. - Retain
  14257. type: string
  14258. immutable:
  14259. description: Immutable defines if the final secret will be immutable
  14260. type: boolean
  14261. manifest:
  14262. description: |-
  14263. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14264. When specified, ExternalSecret will create the resource type defined here
  14265. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14266. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14267. properties:
  14268. apiVersion:
  14269. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14270. minLength: 1
  14271. type: string
  14272. kind:
  14273. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14274. minLength: 1
  14275. type: string
  14276. required:
  14277. - apiVersion
  14278. - kind
  14279. type: object
  14280. name:
  14281. description: |-
  14282. The name of the Secret resource to be managed.
  14283. Defaults to the .metadata.name of the ExternalSecret resource
  14284. maxLength: 253
  14285. minLength: 1
  14286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14287. type: string
  14288. template:
  14289. description: Template defines a blueprint for the created Secret resource.
  14290. properties:
  14291. data:
  14292. additionalProperties:
  14293. type: string
  14294. type: object
  14295. engineVersion:
  14296. default: v2
  14297. description: |-
  14298. EngineVersion specifies the template engine version
  14299. that should be used to compile/execute the
  14300. template specified in .data and .templateFrom[].
  14301. enum:
  14302. - v2
  14303. type: string
  14304. mergePolicy:
  14305. default: Replace
  14306. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14307. enum:
  14308. - Replace
  14309. - Merge
  14310. type: string
  14311. metadata:
  14312. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14313. properties:
  14314. annotations:
  14315. additionalProperties:
  14316. type: string
  14317. type: object
  14318. finalizers:
  14319. items:
  14320. type: string
  14321. type: array
  14322. labels:
  14323. additionalProperties:
  14324. type: string
  14325. type: object
  14326. type: object
  14327. templateFrom:
  14328. items:
  14329. description: |-
  14330. TemplateFrom specifies a source for templates.
  14331. Each item in the list can either reference a ConfigMap or a Secret resource.
  14332. properties:
  14333. configMap:
  14334. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14335. properties:
  14336. items:
  14337. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14338. items:
  14339. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14340. properties:
  14341. key:
  14342. description: A key in the ConfigMap/Secret
  14343. maxLength: 253
  14344. minLength: 1
  14345. pattern: ^[-._a-zA-Z0-9]+$
  14346. type: string
  14347. templateAs:
  14348. default: Values
  14349. description: TemplateScope specifies how the template keys should be interpreted.
  14350. enum:
  14351. - Values
  14352. - KeysAndValues
  14353. type: string
  14354. required:
  14355. - key
  14356. type: object
  14357. type: array
  14358. name:
  14359. description: The name of the ConfigMap/Secret resource
  14360. maxLength: 253
  14361. minLength: 1
  14362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14363. type: string
  14364. required:
  14365. - items
  14366. - name
  14367. type: object
  14368. literal:
  14369. type: string
  14370. secret:
  14371. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14372. properties:
  14373. items:
  14374. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14375. items:
  14376. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14377. properties:
  14378. key:
  14379. description: A key in the ConfigMap/Secret
  14380. maxLength: 253
  14381. minLength: 1
  14382. pattern: ^[-._a-zA-Z0-9]+$
  14383. type: string
  14384. templateAs:
  14385. default: Values
  14386. description: TemplateScope specifies how the template keys should be interpreted.
  14387. enum:
  14388. - Values
  14389. - KeysAndValues
  14390. type: string
  14391. required:
  14392. - key
  14393. type: object
  14394. type: array
  14395. name:
  14396. description: The name of the ConfigMap/Secret resource
  14397. maxLength: 253
  14398. minLength: 1
  14399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14400. type: string
  14401. required:
  14402. - items
  14403. - name
  14404. type: object
  14405. target:
  14406. default: Data
  14407. description: |-
  14408. Target specifies where to place the template result.
  14409. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14410. any other value is rejected because it would allow writes to privileged Secret fields.
  14411. For custom resources (when spec.target.manifest is set), this supports
  14412. nested paths like "spec.database.config" or "data".
  14413. type: string
  14414. valuesDecodingStrategy:
  14415. description: |-
  14416. Used to define a decoding Strategy for the rendered template values.
  14417. Defaults to None when omitted.
  14418. enum:
  14419. - Auto
  14420. - Base64
  14421. - Base64URL
  14422. - None
  14423. type: string
  14424. type: object
  14425. type: array
  14426. type:
  14427. type: string
  14428. type: object
  14429. type: object
  14430. type: object
  14431. status:
  14432. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14433. properties:
  14434. binding:
  14435. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14436. properties:
  14437. name:
  14438. default: ""
  14439. description: |-
  14440. Name of the referent.
  14441. This field is effectively required, but due to backwards compatibility is
  14442. allowed to be empty. Instances of this type with an empty value here are
  14443. almost certainly wrong.
  14444. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14445. type: string
  14446. type: object
  14447. x-kubernetes-map-type: atomic
  14448. conditions:
  14449. items:
  14450. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14451. properties:
  14452. lastTransitionTime:
  14453. format: date-time
  14454. type: string
  14455. message:
  14456. type: string
  14457. reason:
  14458. type: string
  14459. status:
  14460. type: string
  14461. type:
  14462. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14463. enum:
  14464. - Ready
  14465. - Deleted
  14466. type: string
  14467. required:
  14468. - status
  14469. - type
  14470. type: object
  14471. type: array
  14472. refreshTime:
  14473. description: |-
  14474. refreshTime is the time and date the external secret was fetched and
  14475. the target secret updated
  14476. format: date-time
  14477. nullable: true
  14478. type: string
  14479. syncedResourceVersion:
  14480. description: SyncedResourceVersion keeps track of the last synced version
  14481. type: string
  14482. type: object
  14483. type: object
  14484. selectableFields:
  14485. - jsonPath: .spec.secretStoreRef.name
  14486. - jsonPath: .spec.secretStoreRef.kind
  14487. - jsonPath: .spec.target.name
  14488. - jsonPath: .spec.refreshInterval
  14489. served: true
  14490. storage: true
  14491. subresources:
  14492. status: {}
  14493. - additionalPrinterColumns:
  14494. - jsonPath: .spec.secretStoreRef.kind
  14495. name: StoreType
  14496. type: string
  14497. - jsonPath: .spec.secretStoreRef.name
  14498. name: Store
  14499. type: string
  14500. - jsonPath: .spec.refreshInterval
  14501. name: Refresh Interval
  14502. type: string
  14503. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14504. name: Status
  14505. type: string
  14506. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14507. name: Ready
  14508. type: string
  14509. - jsonPath: .status.refreshTime
  14510. name: Last Sync
  14511. type: date
  14512. deprecated: true
  14513. name: v1beta1
  14514. schema:
  14515. openAPIV3Schema:
  14516. description: ExternalSecret is the schema for the external-secrets API.
  14517. properties:
  14518. apiVersion:
  14519. description: |-
  14520. APIVersion defines the versioned schema of this representation of an object.
  14521. Servers should convert recognized schemas to the latest internal value, and
  14522. may reject unrecognized values.
  14523. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14524. type: string
  14525. kind:
  14526. description: |-
  14527. Kind is a string value representing the REST resource this object represents.
  14528. Servers may infer this from the endpoint the client submits requests to.
  14529. Cannot be updated.
  14530. In CamelCase.
  14531. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14532. type: string
  14533. metadata:
  14534. type: object
  14535. spec:
  14536. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14537. properties:
  14538. data:
  14539. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14540. items:
  14541. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14542. properties:
  14543. remoteRef:
  14544. description: |-
  14545. RemoteRef points to the remote secret and defines
  14546. which secret (version/property/..) to fetch.
  14547. properties:
  14548. conversionStrategy:
  14549. default: Default
  14550. description: Used to define a conversion Strategy
  14551. enum:
  14552. - Default
  14553. - Unicode
  14554. type: string
  14555. decodingStrategy:
  14556. default: None
  14557. description: Used to define a decoding Strategy
  14558. enum:
  14559. - Auto
  14560. - Base64
  14561. - Base64URL
  14562. - None
  14563. type: string
  14564. key:
  14565. description: Key is the key used in the Provider, mandatory
  14566. type: string
  14567. metadataPolicy:
  14568. default: None
  14569. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14570. enum:
  14571. - None
  14572. - Fetch
  14573. type: string
  14574. property:
  14575. description: Used to select a specific property of the Provider value (if a map), if supported
  14576. type: string
  14577. version:
  14578. description: Used to select a specific version of the Provider value, if supported
  14579. type: string
  14580. required:
  14581. - key
  14582. type: object
  14583. secretKey:
  14584. description: The key in the Kubernetes Secret to store the value.
  14585. maxLength: 253
  14586. minLength: 1
  14587. pattern: ^[-._a-zA-Z0-9]+$
  14588. type: string
  14589. sourceRef:
  14590. description: |-
  14591. SourceRef allows you to override the source
  14592. from which the value will be pulled.
  14593. maxProperties: 1
  14594. minProperties: 1
  14595. properties:
  14596. generatorRef:
  14597. description: |-
  14598. GeneratorRef points to a generator custom resource.
  14599. Deprecated: The generatorRef is not implemented in .data[].
  14600. this will be removed with v1.
  14601. properties:
  14602. apiVersion:
  14603. default: generators.external-secrets.io/v1alpha1
  14604. description: Specify the apiVersion of the generator resource
  14605. type: string
  14606. kind:
  14607. description: Specify the Kind of the generator resource
  14608. enum:
  14609. - ACRAccessToken
  14610. - ClusterGenerator
  14611. - ECRAuthorizationToken
  14612. - Fake
  14613. - GCRAccessToken
  14614. - GithubAccessToken
  14615. - QuayAccessToken
  14616. - Password
  14617. - SSHKey
  14618. - STSSessionToken
  14619. - UUID
  14620. - VaultDynamicSecret
  14621. - Webhook
  14622. - Grafana
  14623. type: string
  14624. name:
  14625. description: Specify the name of the generator resource
  14626. maxLength: 253
  14627. minLength: 1
  14628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14629. type: string
  14630. required:
  14631. - kind
  14632. - name
  14633. type: object
  14634. storeRef:
  14635. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14636. properties:
  14637. kind:
  14638. description: |-
  14639. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14640. Defaults to `SecretStore`
  14641. enum:
  14642. - SecretStore
  14643. - ClusterSecretStore
  14644. type: string
  14645. name:
  14646. description: Name of the SecretStore resource
  14647. maxLength: 253
  14648. minLength: 1
  14649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14650. type: string
  14651. type: object
  14652. type: object
  14653. required:
  14654. - remoteRef
  14655. - secretKey
  14656. type: object
  14657. type: array
  14658. dataFrom:
  14659. description: |-
  14660. DataFrom is used to fetch all properties from a specific Provider data
  14661. If multiple entries are specified, the Secret keys are merged in the specified order
  14662. items:
  14663. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14664. properties:
  14665. extract:
  14666. description: |-
  14667. Used to extract multiple key/value pairs from one secret
  14668. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14669. properties:
  14670. conversionStrategy:
  14671. default: Default
  14672. description: Used to define a conversion Strategy
  14673. enum:
  14674. - Default
  14675. - Unicode
  14676. type: string
  14677. decodingStrategy:
  14678. default: None
  14679. description: Used to define a decoding Strategy
  14680. enum:
  14681. - Auto
  14682. - Base64
  14683. - Base64URL
  14684. - None
  14685. type: string
  14686. key:
  14687. description: Key is the key used in the Provider, mandatory
  14688. type: string
  14689. metadataPolicy:
  14690. default: None
  14691. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14692. enum:
  14693. - None
  14694. - Fetch
  14695. type: string
  14696. property:
  14697. description: Used to select a specific property of the Provider value (if a map), if supported
  14698. type: string
  14699. version:
  14700. description: Used to select a specific version of the Provider value, if supported
  14701. type: string
  14702. required:
  14703. - key
  14704. type: object
  14705. find:
  14706. description: |-
  14707. Used to find secrets based on tags or regular expressions
  14708. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14709. properties:
  14710. conversionStrategy:
  14711. default: Default
  14712. description: Used to define a conversion Strategy
  14713. enum:
  14714. - Default
  14715. - Unicode
  14716. type: string
  14717. decodingStrategy:
  14718. default: None
  14719. description: Used to define a decoding Strategy
  14720. enum:
  14721. - Auto
  14722. - Base64
  14723. - Base64URL
  14724. - None
  14725. type: string
  14726. name:
  14727. description: Finds secrets based on the name.
  14728. properties:
  14729. regexp:
  14730. description: Finds secrets base
  14731. type: string
  14732. type: object
  14733. path:
  14734. description: A root path to start the find operations.
  14735. type: string
  14736. tags:
  14737. additionalProperties:
  14738. type: string
  14739. description: Find secrets based on tags.
  14740. type: object
  14741. type: object
  14742. rewrite:
  14743. description: |-
  14744. Used to rewrite secret Keys after getting them from the secret Provider
  14745. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14746. items:
  14747. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14748. maxProperties: 1
  14749. minProperties: 1
  14750. properties:
  14751. regexp:
  14752. description: |-
  14753. Used to rewrite with regular expressions.
  14754. The resulting key will be the output of a regexp.ReplaceAll operation.
  14755. properties:
  14756. source:
  14757. description: Used to define the regular expression of a re.Compiler.
  14758. type: string
  14759. target:
  14760. description: Used to define the target pattern of a ReplaceAll operation.
  14761. type: string
  14762. required:
  14763. - source
  14764. - target
  14765. type: object
  14766. transform:
  14767. description: |-
  14768. Used to apply string transformation on the secrets.
  14769. The resulting key will be the output of the template applied by the operation.
  14770. properties:
  14771. template:
  14772. description: |-
  14773. Used to define the template to apply on the secret name.
  14774. `.value ` will specify the secret name in the template.
  14775. type: string
  14776. required:
  14777. - template
  14778. type: object
  14779. type: object
  14780. type: array
  14781. sourceRef:
  14782. description: |-
  14783. SourceRef points to a store or generator
  14784. which contains secret values ready to use.
  14785. Use this in combination with Extract or Find pull values out of
  14786. a specific SecretStore.
  14787. When sourceRef points to a generator Extract or Find is not supported.
  14788. The generator returns a static map of values
  14789. maxProperties: 1
  14790. minProperties: 1
  14791. properties:
  14792. generatorRef:
  14793. description: GeneratorRef points to a generator custom resource.
  14794. properties:
  14795. apiVersion:
  14796. default: generators.external-secrets.io/v1alpha1
  14797. description: Specify the apiVersion of the generator resource
  14798. type: string
  14799. kind:
  14800. description: Specify the Kind of the generator resource
  14801. enum:
  14802. - ACRAccessToken
  14803. - ClusterGenerator
  14804. - ECRAuthorizationToken
  14805. - Fake
  14806. - GCRAccessToken
  14807. - GithubAccessToken
  14808. - QuayAccessToken
  14809. - Password
  14810. - SSHKey
  14811. - STSSessionToken
  14812. - UUID
  14813. - VaultDynamicSecret
  14814. - Webhook
  14815. - Grafana
  14816. type: string
  14817. name:
  14818. description: Specify the name of the generator resource
  14819. maxLength: 253
  14820. minLength: 1
  14821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14822. type: string
  14823. required:
  14824. - kind
  14825. - name
  14826. type: object
  14827. storeRef:
  14828. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14829. properties:
  14830. kind:
  14831. description: |-
  14832. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14833. Defaults to `SecretStore`
  14834. enum:
  14835. - SecretStore
  14836. - ClusterSecretStore
  14837. type: string
  14838. name:
  14839. description: Name of the SecretStore resource
  14840. maxLength: 253
  14841. minLength: 1
  14842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14843. type: string
  14844. type: object
  14845. type: object
  14846. type: object
  14847. type: array
  14848. refreshInterval:
  14849. default: 1h0m0s
  14850. description: |-
  14851. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14852. specified as Golang Duration strings.
  14853. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14854. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14855. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14856. type: string
  14857. refreshPolicy:
  14858. description: |-
  14859. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14860. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14861. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14862. No periodic updates occur if refreshInterval is 0.
  14863. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14864. enum:
  14865. - CreatedOnce
  14866. - Periodic
  14867. - OnChange
  14868. type: string
  14869. secretStoreRef:
  14870. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14871. properties:
  14872. kind:
  14873. description: |-
  14874. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14875. Defaults to `SecretStore`
  14876. enum:
  14877. - SecretStore
  14878. - ClusterSecretStore
  14879. type: string
  14880. name:
  14881. description: Name of the SecretStore resource
  14882. maxLength: 253
  14883. minLength: 1
  14884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14885. type: string
  14886. type: object
  14887. target:
  14888. default:
  14889. creationPolicy: Owner
  14890. deletionPolicy: Retain
  14891. description: |-
  14892. ExternalSecretTarget defines the Kubernetes Secret to be created
  14893. There can be only one target per ExternalSecret.
  14894. properties:
  14895. creationPolicy:
  14896. default: Owner
  14897. description: |-
  14898. CreationPolicy defines rules on how to create the resulting Secret.
  14899. Defaults to "Owner"
  14900. enum:
  14901. - Owner
  14902. - Orphan
  14903. - Merge
  14904. - None
  14905. type: string
  14906. deletionPolicy:
  14907. default: Retain
  14908. description: |-
  14909. DeletionPolicy defines rules on how to delete the resulting Secret.
  14910. Defaults to "Retain"
  14911. enum:
  14912. - Delete
  14913. - Merge
  14914. - Retain
  14915. type: string
  14916. immutable:
  14917. description: Immutable defines if the final secret will be immutable
  14918. type: boolean
  14919. name:
  14920. description: |-
  14921. The name of the Secret resource to be managed.
  14922. Defaults to the .metadata.name of the ExternalSecret resource
  14923. maxLength: 253
  14924. minLength: 1
  14925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14926. type: string
  14927. template:
  14928. description: Template defines a blueprint for the created Secret resource.
  14929. properties:
  14930. data:
  14931. additionalProperties:
  14932. type: string
  14933. type: object
  14934. engineVersion:
  14935. default: v2
  14936. description: |-
  14937. EngineVersion specifies the template engine version
  14938. that should be used to compile/execute the
  14939. template specified in .data and .templateFrom[].
  14940. enum:
  14941. - v2
  14942. type: string
  14943. mergePolicy:
  14944. default: Replace
  14945. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14946. enum:
  14947. - Replace
  14948. - Merge
  14949. type: string
  14950. metadata:
  14951. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14952. properties:
  14953. annotations:
  14954. additionalProperties:
  14955. type: string
  14956. type: object
  14957. labels:
  14958. additionalProperties:
  14959. type: string
  14960. type: object
  14961. type: object
  14962. templateFrom:
  14963. items:
  14964. description: TemplateFrom defines a source for template data.
  14965. properties:
  14966. configMap:
  14967. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14968. properties:
  14969. items:
  14970. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14971. items:
  14972. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14973. properties:
  14974. key:
  14975. description: A key in the ConfigMap/Secret
  14976. maxLength: 253
  14977. minLength: 1
  14978. pattern: ^[-._a-zA-Z0-9]+$
  14979. type: string
  14980. templateAs:
  14981. default: Values
  14982. description: TemplateScope defines the scope of the template when processing template data.
  14983. enum:
  14984. - Values
  14985. - KeysAndValues
  14986. type: string
  14987. required:
  14988. - key
  14989. type: object
  14990. type: array
  14991. name:
  14992. description: The name of the ConfigMap/Secret resource
  14993. maxLength: 253
  14994. minLength: 1
  14995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14996. type: string
  14997. required:
  14998. - items
  14999. - name
  15000. type: object
  15001. literal:
  15002. type: string
  15003. secret:
  15004. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  15005. properties:
  15006. items:
  15007. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15008. items:
  15009. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  15010. properties:
  15011. key:
  15012. description: A key in the ConfigMap/Secret
  15013. maxLength: 253
  15014. minLength: 1
  15015. pattern: ^[-._a-zA-Z0-9]+$
  15016. type: string
  15017. templateAs:
  15018. default: Values
  15019. description: TemplateScope defines the scope of the template when processing template data.
  15020. enum:
  15021. - Values
  15022. - KeysAndValues
  15023. type: string
  15024. required:
  15025. - key
  15026. type: object
  15027. type: array
  15028. name:
  15029. description: The name of the ConfigMap/Secret resource
  15030. maxLength: 253
  15031. minLength: 1
  15032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15033. type: string
  15034. required:
  15035. - items
  15036. - name
  15037. type: object
  15038. target:
  15039. default: Data
  15040. description: TemplateTarget defines the target field where the template result will be stored.
  15041. enum:
  15042. - Data
  15043. - Annotations
  15044. - Labels
  15045. type: string
  15046. type: object
  15047. type: array
  15048. type:
  15049. type: string
  15050. type: object
  15051. type: object
  15052. type: object
  15053. status:
  15054. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  15055. properties:
  15056. binding:
  15057. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  15058. properties:
  15059. name:
  15060. default: ""
  15061. description: |-
  15062. Name of the referent.
  15063. This field is effectively required, but due to backwards compatibility is
  15064. allowed to be empty. Instances of this type with an empty value here are
  15065. almost certainly wrong.
  15066. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  15067. type: string
  15068. type: object
  15069. x-kubernetes-map-type: atomic
  15070. conditions:
  15071. items:
  15072. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  15073. properties:
  15074. lastTransitionTime:
  15075. format: date-time
  15076. type: string
  15077. message:
  15078. type: string
  15079. reason:
  15080. type: string
  15081. status:
  15082. type: string
  15083. type:
  15084. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  15085. type: string
  15086. required:
  15087. - status
  15088. - type
  15089. type: object
  15090. type: array
  15091. refreshTime:
  15092. description: |-
  15093. refreshTime is the time and date the external secret was fetched and
  15094. the target secret updated
  15095. format: date-time
  15096. nullable: true
  15097. type: string
  15098. syncedResourceVersion:
  15099. description: SyncedResourceVersion keeps track of the last synced version
  15100. type: string
  15101. type: object
  15102. type: object
  15103. served: false
  15104. storage: false
  15105. subresources:
  15106. status: {}
  15107. ---
  15108. apiVersion: apiextensions.k8s.io/v1
  15109. kind: CustomResourceDefinition
  15110. metadata:
  15111. annotations:
  15112. controller-gen.kubebuilder.io/version: v0.19.0
  15113. labels:
  15114. external-secrets.io/component: controller
  15115. name: pushsecrets.external-secrets.io
  15116. spec:
  15117. group: external-secrets.io
  15118. names:
  15119. categories:
  15120. - external-secrets
  15121. kind: PushSecret
  15122. listKind: PushSecretList
  15123. plural: pushsecrets
  15124. shortNames:
  15125. - ps
  15126. singular: pushsecret
  15127. scope: Namespaced
  15128. versions:
  15129. - additionalPrinterColumns:
  15130. - jsonPath: .metadata.creationTimestamp
  15131. name: AGE
  15132. type: date
  15133. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15134. name: Status
  15135. type: string
  15136. - jsonPath: .status.refreshTime
  15137. name: Last Sync
  15138. type: date
  15139. name: v1alpha1
  15140. schema:
  15141. openAPIV3Schema:
  15142. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  15143. properties:
  15144. apiVersion:
  15145. description: |-
  15146. APIVersion defines the versioned schema of this representation of an object.
  15147. Servers should convert recognized schemas to the latest internal value, and
  15148. may reject unrecognized values.
  15149. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15150. type: string
  15151. kind:
  15152. description: |-
  15153. Kind is a string value representing the REST resource this object represents.
  15154. Servers may infer this from the endpoint the client submits requests to.
  15155. Cannot be updated.
  15156. In CamelCase.
  15157. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15158. type: string
  15159. metadata:
  15160. type: object
  15161. spec:
  15162. description: PushSecretSpec configures the behavior of the PushSecret.
  15163. properties:
  15164. data:
  15165. description: Secret Data that should be pushed to providers
  15166. items:
  15167. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15168. properties:
  15169. conversionStrategy:
  15170. default: None
  15171. description: Used to define a conversion Strategy for the secret keys
  15172. enum:
  15173. - None
  15174. - ReverseUnicode
  15175. type: string
  15176. match:
  15177. description: Match a given Secret Key to be pushed to the provider.
  15178. properties:
  15179. remoteRef:
  15180. description: Remote Refs to push to providers.
  15181. properties:
  15182. property:
  15183. description: Name of the property in the resulting secret
  15184. type: string
  15185. remoteKey:
  15186. description: Name of the resulting provider secret.
  15187. type: string
  15188. required:
  15189. - remoteKey
  15190. type: object
  15191. secretKey:
  15192. description: Secret Key to be pushed
  15193. type: string
  15194. required:
  15195. - remoteRef
  15196. type: object
  15197. metadata:
  15198. description: |-
  15199. Metadata is metadata attached to the secret.
  15200. The structure of metadata is provider specific, please look it up in the provider documentation.
  15201. x-kubernetes-preserve-unknown-fields: true
  15202. required:
  15203. - match
  15204. type: object
  15205. type: array
  15206. dataTo:
  15207. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  15208. items:
  15209. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  15210. properties:
  15211. conversionStrategy:
  15212. default: None
  15213. description: Used to define a conversion Strategy for the secret keys
  15214. enum:
  15215. - None
  15216. - ReverseUnicode
  15217. type: string
  15218. match:
  15219. description: |-
  15220. Match pattern for selecting keys from the source Secret.
  15221. If not specified, all keys are selected.
  15222. properties:
  15223. regexp:
  15224. description: |-
  15225. Regexp matches keys by regular expression.
  15226. If not specified, all keys are matched.
  15227. type: string
  15228. type: object
  15229. metadata:
  15230. description: |-
  15231. Metadata is metadata attached to the secret.
  15232. The structure of metadata is provider specific, please look it up in the provider documentation.
  15233. x-kubernetes-preserve-unknown-fields: true
  15234. remoteKey:
  15235. description: |-
  15236. RemoteKey is the name of the single provider secret that will receive ALL
  15237. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15238. When set, per-key expansion is skipped and a single push is performed.
  15239. The provider's store prefix (if any) is still prepended to this value.
  15240. When not set, each matched key is pushed as its own individual provider secret.
  15241. type: string
  15242. rewrite:
  15243. description: |-
  15244. Rewrite operations to transform keys before pushing to the provider.
  15245. Operations are applied sequentially.
  15246. items:
  15247. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15248. properties:
  15249. regexp:
  15250. description: Used to rewrite with regular expressions.
  15251. properties:
  15252. source:
  15253. description: Used to define the regular expression of a re.Compiler.
  15254. type: string
  15255. target:
  15256. description: Used to define the target pattern of a ReplaceAll operation.
  15257. type: string
  15258. required:
  15259. - source
  15260. - target
  15261. type: object
  15262. transform:
  15263. description: Used to apply string transformation on the secrets.
  15264. properties:
  15265. template:
  15266. description: |-
  15267. Used to define the template to apply on the secret name.
  15268. `.value ` will specify the secret name in the template.
  15269. type: string
  15270. required:
  15271. - template
  15272. type: object
  15273. type: object
  15274. x-kubernetes-validations:
  15275. - message: exactly one of regexp or transform must be set
  15276. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15277. type: array
  15278. storeRef:
  15279. description: StoreRef specifies which SecretStore to push to. Required.
  15280. properties:
  15281. kind:
  15282. default: SecretStore
  15283. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15284. enum:
  15285. - SecretStore
  15286. - ClusterSecretStore
  15287. type: string
  15288. labelSelector:
  15289. description: Optionally, sync to secret stores with label selector
  15290. properties:
  15291. matchExpressions:
  15292. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15293. items:
  15294. description: |-
  15295. A label selector requirement is a selector that contains values, a key, and an operator that
  15296. relates the key and values.
  15297. properties:
  15298. key:
  15299. description: key is the label key that the selector applies to.
  15300. type: string
  15301. operator:
  15302. description: |-
  15303. operator represents a key's relationship to a set of values.
  15304. Valid operators are In, NotIn, Exists and DoesNotExist.
  15305. type: string
  15306. values:
  15307. description: |-
  15308. values is an array of string values. If the operator is In or NotIn,
  15309. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15310. the values array must be empty. This array is replaced during a strategic
  15311. merge patch.
  15312. items:
  15313. type: string
  15314. type: array
  15315. x-kubernetes-list-type: atomic
  15316. required:
  15317. - key
  15318. - operator
  15319. type: object
  15320. type: array
  15321. x-kubernetes-list-type: atomic
  15322. matchLabels:
  15323. additionalProperties:
  15324. type: string
  15325. description: |-
  15326. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15327. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15328. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15329. type: object
  15330. type: object
  15331. x-kubernetes-map-type: atomic
  15332. name:
  15333. description: Optionally, sync to the SecretStore of the given name
  15334. maxLength: 253
  15335. minLength: 1
  15336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15337. type: string
  15338. type: object
  15339. type: object
  15340. x-kubernetes-validations:
  15341. - message: storeRef must specify either name or labelSelector
  15342. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15343. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15344. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15345. type: array
  15346. deletionPolicy:
  15347. default: None
  15348. description: Deletion Policy to handle Secrets in the provider.
  15349. enum:
  15350. - Delete
  15351. - None
  15352. type: string
  15353. refreshInterval:
  15354. default: 1h0m0s
  15355. description: The Interval to which External Secrets will try to push a secret definition
  15356. type: string
  15357. secretStoreRefs:
  15358. items:
  15359. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15360. properties:
  15361. kind:
  15362. default: SecretStore
  15363. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15364. enum:
  15365. - SecretStore
  15366. - ClusterSecretStore
  15367. type: string
  15368. labelSelector:
  15369. description: Optionally, sync to secret stores with label selector
  15370. properties:
  15371. matchExpressions:
  15372. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15373. items:
  15374. description: |-
  15375. A label selector requirement is a selector that contains values, a key, and an operator that
  15376. relates the key and values.
  15377. properties:
  15378. key:
  15379. description: key is the label key that the selector applies to.
  15380. type: string
  15381. operator:
  15382. description: |-
  15383. operator represents a key's relationship to a set of values.
  15384. Valid operators are In, NotIn, Exists and DoesNotExist.
  15385. type: string
  15386. values:
  15387. description: |-
  15388. values is an array of string values. If the operator is In or NotIn,
  15389. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15390. the values array must be empty. This array is replaced during a strategic
  15391. merge patch.
  15392. items:
  15393. type: string
  15394. type: array
  15395. x-kubernetes-list-type: atomic
  15396. required:
  15397. - key
  15398. - operator
  15399. type: object
  15400. type: array
  15401. x-kubernetes-list-type: atomic
  15402. matchLabels:
  15403. additionalProperties:
  15404. type: string
  15405. description: |-
  15406. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15407. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15408. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15409. type: object
  15410. type: object
  15411. x-kubernetes-map-type: atomic
  15412. name:
  15413. description: Optionally, sync to the SecretStore of the given name
  15414. maxLength: 253
  15415. minLength: 1
  15416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15417. type: string
  15418. type: object
  15419. type: array
  15420. selector:
  15421. description: The Secret Selector (k8s source) for the Push Secret
  15422. maxProperties: 1
  15423. minProperties: 1
  15424. properties:
  15425. generatorRef:
  15426. description: Point to a generator to create a Secret.
  15427. properties:
  15428. apiVersion:
  15429. default: generators.external-secrets.io/v1alpha1
  15430. description: Specify the apiVersion of the generator resource
  15431. type: string
  15432. kind:
  15433. description: Specify the Kind of the generator resource
  15434. enum:
  15435. - ACRAccessToken
  15436. - BeyondtrustWorkloadCredentialsDynamicSecret
  15437. - ClusterGenerator
  15438. - CloudsmithAccessToken
  15439. - ECRAuthorizationToken
  15440. - Fake
  15441. - GCRAccessToken
  15442. - GithubAccessToken
  15443. - GitlabDeployToken
  15444. - QuayAccessToken
  15445. - Password
  15446. - SSHKey
  15447. - STSSessionToken
  15448. - UUID
  15449. - VaultDynamicSecret
  15450. - Webhook
  15451. - Grafana
  15452. - MFA
  15453. type: string
  15454. name:
  15455. description: Specify the name of the generator resource
  15456. maxLength: 253
  15457. minLength: 1
  15458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15459. type: string
  15460. required:
  15461. - kind
  15462. - name
  15463. type: object
  15464. secret:
  15465. description: Select a Secret to Push.
  15466. properties:
  15467. name:
  15468. description: |-
  15469. Name of the Secret.
  15470. The Secret must exist in the same namespace as the PushSecret manifest.
  15471. maxLength: 253
  15472. minLength: 1
  15473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15474. type: string
  15475. selector:
  15476. description: Selector chooses secrets using a labelSelector.
  15477. properties:
  15478. matchExpressions:
  15479. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15480. items:
  15481. description: |-
  15482. A label selector requirement is a selector that contains values, a key, and an operator that
  15483. relates the key and values.
  15484. properties:
  15485. key:
  15486. description: key is the label key that the selector applies to.
  15487. type: string
  15488. operator:
  15489. description: |-
  15490. operator represents a key's relationship to a set of values.
  15491. Valid operators are In, NotIn, Exists and DoesNotExist.
  15492. type: string
  15493. values:
  15494. description: |-
  15495. values is an array of string values. If the operator is In or NotIn,
  15496. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15497. the values array must be empty. This array is replaced during a strategic
  15498. merge patch.
  15499. items:
  15500. type: string
  15501. type: array
  15502. x-kubernetes-list-type: atomic
  15503. required:
  15504. - key
  15505. - operator
  15506. type: object
  15507. type: array
  15508. x-kubernetes-list-type: atomic
  15509. matchLabels:
  15510. additionalProperties:
  15511. type: string
  15512. description: |-
  15513. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15514. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15515. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15516. type: object
  15517. type: object
  15518. x-kubernetes-map-type: atomic
  15519. type: object
  15520. type: object
  15521. template:
  15522. description: Template defines a blueprint for the created Secret resource.
  15523. properties:
  15524. data:
  15525. additionalProperties:
  15526. type: string
  15527. type: object
  15528. engineVersion:
  15529. default: v2
  15530. description: |-
  15531. EngineVersion specifies the template engine version
  15532. that should be used to compile/execute the
  15533. template specified in .data and .templateFrom[].
  15534. enum:
  15535. - v2
  15536. type: string
  15537. mergePolicy:
  15538. default: Replace
  15539. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15540. enum:
  15541. - Replace
  15542. - Merge
  15543. type: string
  15544. metadata:
  15545. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15546. properties:
  15547. annotations:
  15548. additionalProperties:
  15549. type: string
  15550. type: object
  15551. finalizers:
  15552. items:
  15553. type: string
  15554. type: array
  15555. labels:
  15556. additionalProperties:
  15557. type: string
  15558. type: object
  15559. type: object
  15560. templateFrom:
  15561. items:
  15562. description: |-
  15563. TemplateFrom specifies a source for templates.
  15564. Each item in the list can either reference a ConfigMap or a Secret resource.
  15565. properties:
  15566. configMap:
  15567. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15568. properties:
  15569. items:
  15570. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15571. items:
  15572. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15573. properties:
  15574. key:
  15575. description: A key in the ConfigMap/Secret
  15576. maxLength: 253
  15577. minLength: 1
  15578. pattern: ^[-._a-zA-Z0-9]+$
  15579. type: string
  15580. templateAs:
  15581. default: Values
  15582. description: TemplateScope specifies how the template keys should be interpreted.
  15583. enum:
  15584. - Values
  15585. - KeysAndValues
  15586. type: string
  15587. required:
  15588. - key
  15589. type: object
  15590. type: array
  15591. name:
  15592. description: The name of the ConfigMap/Secret resource
  15593. maxLength: 253
  15594. minLength: 1
  15595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15596. type: string
  15597. required:
  15598. - items
  15599. - name
  15600. type: object
  15601. literal:
  15602. type: string
  15603. secret:
  15604. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15605. properties:
  15606. items:
  15607. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15608. items:
  15609. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15610. properties:
  15611. key:
  15612. description: A key in the ConfigMap/Secret
  15613. maxLength: 253
  15614. minLength: 1
  15615. pattern: ^[-._a-zA-Z0-9]+$
  15616. type: string
  15617. templateAs:
  15618. default: Values
  15619. description: TemplateScope specifies how the template keys should be interpreted.
  15620. enum:
  15621. - Values
  15622. - KeysAndValues
  15623. type: string
  15624. required:
  15625. - key
  15626. type: object
  15627. type: array
  15628. name:
  15629. description: The name of the ConfigMap/Secret resource
  15630. maxLength: 253
  15631. minLength: 1
  15632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15633. type: string
  15634. required:
  15635. - items
  15636. - name
  15637. type: object
  15638. target:
  15639. default: Data
  15640. description: |-
  15641. Target specifies where to place the template result.
  15642. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15643. any other value is rejected because it would allow writes to privileged Secret fields.
  15644. For custom resources (when spec.target.manifest is set), this supports
  15645. nested paths like "spec.database.config" or "data".
  15646. type: string
  15647. valuesDecodingStrategy:
  15648. description: |-
  15649. Used to define a decoding Strategy for the rendered template values.
  15650. Defaults to None when omitted.
  15651. enum:
  15652. - Auto
  15653. - Base64
  15654. - Base64URL
  15655. - None
  15656. type: string
  15657. type: object
  15658. type: array
  15659. type:
  15660. type: string
  15661. type: object
  15662. updatePolicy:
  15663. default: Replace
  15664. description: UpdatePolicy to handle Secrets in the provider.
  15665. enum:
  15666. - Replace
  15667. - IfNotExists
  15668. type: string
  15669. required:
  15670. - secretStoreRefs
  15671. - selector
  15672. type: object
  15673. status:
  15674. description: PushSecretStatus indicates the history of the status of PushSecret.
  15675. properties:
  15676. conditions:
  15677. items:
  15678. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15679. properties:
  15680. lastTransitionTime:
  15681. format: date-time
  15682. type: string
  15683. message:
  15684. type: string
  15685. reason:
  15686. type: string
  15687. status:
  15688. type: string
  15689. type:
  15690. description: PushSecretConditionType indicates the condition of the PushSecret.
  15691. type: string
  15692. required:
  15693. - status
  15694. - type
  15695. type: object
  15696. type: array
  15697. refreshTime:
  15698. description: |-
  15699. refreshTime is the time and date the external secret was fetched and
  15700. the target secret updated
  15701. format: date-time
  15702. nullable: true
  15703. type: string
  15704. syncedPushSecrets:
  15705. additionalProperties:
  15706. additionalProperties:
  15707. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15708. properties:
  15709. conversionStrategy:
  15710. default: None
  15711. description: Used to define a conversion Strategy for the secret keys
  15712. enum:
  15713. - None
  15714. - ReverseUnicode
  15715. type: string
  15716. match:
  15717. description: Match a given Secret Key to be pushed to the provider.
  15718. properties:
  15719. remoteRef:
  15720. description: Remote Refs to push to providers.
  15721. properties:
  15722. property:
  15723. description: Name of the property in the resulting secret
  15724. type: string
  15725. remoteKey:
  15726. description: Name of the resulting provider secret.
  15727. type: string
  15728. required:
  15729. - remoteKey
  15730. type: object
  15731. secretKey:
  15732. description: Secret Key to be pushed
  15733. type: string
  15734. required:
  15735. - remoteRef
  15736. type: object
  15737. metadata:
  15738. description: |-
  15739. Metadata is metadata attached to the secret.
  15740. The structure of metadata is provider specific, please look it up in the provider documentation.
  15741. x-kubernetes-preserve-unknown-fields: true
  15742. required:
  15743. - match
  15744. type: object
  15745. type: object
  15746. description: |-
  15747. Synced PushSecrets, including secrets that already exist in provider.
  15748. Matches secret stores to PushSecretData that was stored to that secret store.
  15749. type: object
  15750. syncedResourceVersion:
  15751. description: SyncedResourceVersion keeps track of the last synced version.
  15752. type: string
  15753. type: object
  15754. type: object
  15755. served: true
  15756. storage: true
  15757. subresources:
  15758. status: {}
  15759. ---
  15760. apiVersion: apiextensions.k8s.io/v1
  15761. kind: CustomResourceDefinition
  15762. metadata:
  15763. annotations:
  15764. controller-gen.kubebuilder.io/version: v0.19.0
  15765. labels:
  15766. external-secrets.io/component: controller
  15767. name: secretstores.external-secrets.io
  15768. spec:
  15769. group: external-secrets.io
  15770. names:
  15771. categories:
  15772. - external-secrets
  15773. kind: SecretStore
  15774. listKind: SecretStoreList
  15775. plural: secretstores
  15776. shortNames:
  15777. - ss
  15778. singular: secretstore
  15779. scope: Namespaced
  15780. versions:
  15781. - additionalPrinterColumns:
  15782. - jsonPath: .metadata.creationTimestamp
  15783. name: AGE
  15784. type: date
  15785. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15786. name: Status
  15787. type: string
  15788. - jsonPath: .status.capabilities
  15789. name: Capabilities
  15790. type: string
  15791. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15792. name: Ready
  15793. type: string
  15794. name: v1
  15795. schema:
  15796. openAPIV3Schema:
  15797. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15798. properties:
  15799. apiVersion:
  15800. description: |-
  15801. APIVersion defines the versioned schema of this representation of an object.
  15802. Servers should convert recognized schemas to the latest internal value, and
  15803. may reject unrecognized values.
  15804. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15805. type: string
  15806. kind:
  15807. description: |-
  15808. Kind is a string value representing the REST resource this object represents.
  15809. Servers may infer this from the endpoint the client submits requests to.
  15810. Cannot be updated.
  15811. In CamelCase.
  15812. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15813. type: string
  15814. metadata:
  15815. type: object
  15816. spec:
  15817. description: SecretStoreSpec defines the desired state of SecretStore.
  15818. properties:
  15819. conditions:
  15820. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15821. items:
  15822. description: |-
  15823. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15824. for a ClusterSecretStore instance.
  15825. properties:
  15826. namespaceRegexes:
  15827. description: Choose namespaces by using regex matching
  15828. items:
  15829. type: string
  15830. type: array
  15831. namespaceSelector:
  15832. description: Choose namespace using a labelSelector
  15833. properties:
  15834. matchExpressions:
  15835. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15836. items:
  15837. description: |-
  15838. A label selector requirement is a selector that contains values, a key, and an operator that
  15839. relates the key and values.
  15840. properties:
  15841. key:
  15842. description: key is the label key that the selector applies to.
  15843. type: string
  15844. operator:
  15845. description: |-
  15846. operator represents a key's relationship to a set of values.
  15847. Valid operators are In, NotIn, Exists and DoesNotExist.
  15848. type: string
  15849. values:
  15850. description: |-
  15851. values is an array of string values. If the operator is In or NotIn,
  15852. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15853. the values array must be empty. This array is replaced during a strategic
  15854. merge patch.
  15855. items:
  15856. type: string
  15857. type: array
  15858. x-kubernetes-list-type: atomic
  15859. required:
  15860. - key
  15861. - operator
  15862. type: object
  15863. type: array
  15864. x-kubernetes-list-type: atomic
  15865. matchLabels:
  15866. additionalProperties:
  15867. type: string
  15868. description: |-
  15869. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15870. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15871. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15872. type: object
  15873. type: object
  15874. x-kubernetes-map-type: atomic
  15875. namespaces:
  15876. description: Choose namespaces by name
  15877. items:
  15878. maxLength: 63
  15879. minLength: 1
  15880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15881. type: string
  15882. type: array
  15883. type: object
  15884. type: array
  15885. controller:
  15886. description: |-
  15887. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15888. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15889. type: string
  15890. provider:
  15891. description: Used to configure the provider. Only one provider may be set
  15892. maxProperties: 1
  15893. minProperties: 1
  15894. properties:
  15895. akeyless:
  15896. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15897. properties:
  15898. akeylessGWApiURL:
  15899. description: Akeyless GW API Url from which the secrets to be fetched from.
  15900. type: string
  15901. authSecretRef:
  15902. description: Auth configures how the operator authenticates with Akeyless.
  15903. properties:
  15904. kubernetesAuth:
  15905. description: |-
  15906. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15907. token stored in the named Secret resource.
  15908. properties:
  15909. accessID:
  15910. description: the Akeyless Kubernetes auth-method access-id
  15911. type: string
  15912. k8sConfName:
  15913. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15914. type: string
  15915. secretRef:
  15916. description: |-
  15917. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15918. for authenticating with Akeyless. If a name is specified without a key,
  15919. `token` is the default. If one is not specified, the one bound to
  15920. the controller will be used.
  15921. properties:
  15922. key:
  15923. description: |-
  15924. A key in the referenced Secret.
  15925. Some instances of this field may be defaulted, in others it may be required.
  15926. maxLength: 253
  15927. minLength: 1
  15928. pattern: ^[-._a-zA-Z0-9]+$
  15929. type: string
  15930. name:
  15931. description: The name of the Secret resource being referred to.
  15932. maxLength: 253
  15933. minLength: 1
  15934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15935. type: string
  15936. namespace:
  15937. description: |-
  15938. The namespace of the Secret resource being referred to.
  15939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15940. maxLength: 63
  15941. minLength: 1
  15942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15943. type: string
  15944. type: object
  15945. serviceAccountRef:
  15946. description: |-
  15947. Optional service account field containing the name of a kubernetes ServiceAccount.
  15948. If the service account is specified, the service account secret token JWT will be used
  15949. for authenticating with Akeyless. If the service account selector is not supplied,
  15950. the secretRef will be used instead.
  15951. properties:
  15952. audiences:
  15953. description: |-
  15954. Audience specifies the `aud` claim for the service account token
  15955. Some providers automatically extend the audience field based on well-known annotations for workload
  15956. identity (e.g. IRSA or GCP Workload Identity)
  15957. items:
  15958. type: string
  15959. type: array
  15960. name:
  15961. description: The name of the ServiceAccount resource being referred to.
  15962. maxLength: 253
  15963. minLength: 1
  15964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15965. type: string
  15966. namespace:
  15967. description: |-
  15968. Namespace of the resource being referred to.
  15969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15970. maxLength: 63
  15971. minLength: 1
  15972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15973. type: string
  15974. required:
  15975. - name
  15976. type: object
  15977. required:
  15978. - accessID
  15979. - k8sConfName
  15980. type: object
  15981. secretRef:
  15982. description: |-
  15983. Reference to a Secret that contains the details
  15984. to authenticate with Akeyless.
  15985. properties:
  15986. accessID:
  15987. description: The SecretAccessID is used for authentication
  15988. properties:
  15989. key:
  15990. description: |-
  15991. A key in the referenced Secret.
  15992. Some instances of this field may be defaulted, in others it may be required.
  15993. maxLength: 253
  15994. minLength: 1
  15995. pattern: ^[-._a-zA-Z0-9]+$
  15996. type: string
  15997. name:
  15998. description: The name of the Secret resource being referred to.
  15999. maxLength: 253
  16000. minLength: 1
  16001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16002. type: string
  16003. namespace:
  16004. description: |-
  16005. The namespace of the Secret resource being referred to.
  16006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16007. maxLength: 63
  16008. minLength: 1
  16009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16010. type: string
  16011. type: object
  16012. accessType:
  16013. description: |-
  16014. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16015. In some instances, `key` is a required field.
  16016. properties:
  16017. key:
  16018. description: |-
  16019. A key in the referenced Secret.
  16020. Some instances of this field may be defaulted, in others it may be required.
  16021. maxLength: 253
  16022. minLength: 1
  16023. pattern: ^[-._a-zA-Z0-9]+$
  16024. type: string
  16025. name:
  16026. description: The name of the Secret resource being referred to.
  16027. maxLength: 253
  16028. minLength: 1
  16029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16030. type: string
  16031. namespace:
  16032. description: |-
  16033. The namespace of the Secret resource being referred to.
  16034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16035. maxLength: 63
  16036. minLength: 1
  16037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16038. type: string
  16039. type: object
  16040. accessTypeParam:
  16041. description: |-
  16042. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16043. In some instances, `key` is a required field.
  16044. properties:
  16045. key:
  16046. description: |-
  16047. A key in the referenced Secret.
  16048. Some instances of this field may be defaulted, in others it may be required.
  16049. maxLength: 253
  16050. minLength: 1
  16051. pattern: ^[-._a-zA-Z0-9]+$
  16052. type: string
  16053. name:
  16054. description: The name of the Secret resource being referred to.
  16055. maxLength: 253
  16056. minLength: 1
  16057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16058. type: string
  16059. namespace:
  16060. description: |-
  16061. The namespace of the Secret resource being referred to.
  16062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16063. maxLength: 63
  16064. minLength: 1
  16065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16066. type: string
  16067. type: object
  16068. type: object
  16069. serviceAccountRef:
  16070. description: |-
  16071. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  16072. authentication on AKS Workload Identity. The operator obtains a federated
  16073. identity token from this ServiceAccount via the TokenRequest API instead
  16074. of using the ESO controller pod identity. Ignored for other access types.
  16075. properties:
  16076. audiences:
  16077. description: |-
  16078. Audience specifies the `aud` claim for the service account token
  16079. Some providers automatically extend the audience field based on well-known annotations for workload
  16080. identity (e.g. IRSA or GCP Workload Identity)
  16081. items:
  16082. type: string
  16083. type: array
  16084. name:
  16085. description: The name of the ServiceAccount resource being referred to.
  16086. maxLength: 253
  16087. minLength: 1
  16088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16089. type: string
  16090. namespace:
  16091. description: |-
  16092. Namespace of the resource being referred to.
  16093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16094. maxLength: 63
  16095. minLength: 1
  16096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16097. type: string
  16098. required:
  16099. - name
  16100. type: object
  16101. type: object
  16102. caBundle:
  16103. description: |-
  16104. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  16105. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  16106. are used to validate the TLS connection.
  16107. format: byte
  16108. type: string
  16109. caProvider:
  16110. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  16111. properties:
  16112. key:
  16113. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16114. maxLength: 253
  16115. minLength: 1
  16116. pattern: ^[-._a-zA-Z0-9]+$
  16117. type: string
  16118. name:
  16119. description: The name of the object located at the provider type.
  16120. maxLength: 253
  16121. minLength: 1
  16122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16123. type: string
  16124. namespace:
  16125. description: |-
  16126. The namespace the Provider type is in.
  16127. Can only be defined when used in a ClusterSecretStore.
  16128. maxLength: 63
  16129. minLength: 1
  16130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16131. type: string
  16132. type:
  16133. description: The type of provider to use such as "Secret", or "ConfigMap".
  16134. enum:
  16135. - Secret
  16136. - ConfigMap
  16137. type: string
  16138. required:
  16139. - name
  16140. - type
  16141. type: object
  16142. ignoreCache:
  16143. description: |-
  16144. IgnoreCache bypasses the Gateway cache for secret reads when true.
  16145. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  16146. type: boolean
  16147. required:
  16148. - akeylessGWApiURL
  16149. - authSecretRef
  16150. type: object
  16151. aws:
  16152. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  16153. properties:
  16154. additionalRoles:
  16155. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  16156. items:
  16157. type: string
  16158. type: array
  16159. auth:
  16160. description: |-
  16161. Auth defines the information necessary to authenticate against AWS
  16162. if not set aws sdk will infer credentials from your environment
  16163. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  16164. properties:
  16165. jwt:
  16166. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  16167. properties:
  16168. serviceAccountRef:
  16169. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  16170. properties:
  16171. audiences:
  16172. description: |-
  16173. Audience specifies the `aud` claim for the service account token
  16174. Some providers automatically extend the audience field based on well-known annotations for workload
  16175. identity (e.g. IRSA or GCP Workload Identity)
  16176. items:
  16177. type: string
  16178. type: array
  16179. name:
  16180. description: The name of the ServiceAccount resource being referred to.
  16181. maxLength: 253
  16182. minLength: 1
  16183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16184. type: string
  16185. namespace:
  16186. description: |-
  16187. Namespace of the resource being referred to.
  16188. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16189. maxLength: 63
  16190. minLength: 1
  16191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16192. type: string
  16193. required:
  16194. - name
  16195. type: object
  16196. type: object
  16197. secretRef:
  16198. description: |-
  16199. AWSAuthSecretRef holds secret references for AWS credentials
  16200. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16201. properties:
  16202. accessKeyIDSecretRef:
  16203. description: The AccessKeyID is used for authentication
  16204. properties:
  16205. key:
  16206. description: |-
  16207. A key in the referenced Secret.
  16208. Some instances of this field may be defaulted, in others it may be required.
  16209. maxLength: 253
  16210. minLength: 1
  16211. pattern: ^[-._a-zA-Z0-9]+$
  16212. type: string
  16213. name:
  16214. description: The name of the Secret resource being referred to.
  16215. maxLength: 253
  16216. minLength: 1
  16217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16218. type: string
  16219. namespace:
  16220. description: |-
  16221. The namespace of the Secret resource being referred to.
  16222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16223. maxLength: 63
  16224. minLength: 1
  16225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16226. type: string
  16227. type: object
  16228. secretAccessKeySecretRef:
  16229. description: The SecretAccessKey is used for authentication
  16230. properties:
  16231. key:
  16232. description: |-
  16233. A key in the referenced Secret.
  16234. Some instances of this field may be defaulted, in others it may be required.
  16235. maxLength: 253
  16236. minLength: 1
  16237. pattern: ^[-._a-zA-Z0-9]+$
  16238. type: string
  16239. name:
  16240. description: The name of the Secret resource being referred to.
  16241. maxLength: 253
  16242. minLength: 1
  16243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16244. type: string
  16245. namespace:
  16246. description: |-
  16247. The namespace of the Secret resource being referred to.
  16248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16249. maxLength: 63
  16250. minLength: 1
  16251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16252. type: string
  16253. type: object
  16254. sessionTokenSecretRef:
  16255. description: |-
  16256. The SessionToken used for authentication
  16257. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16258. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16259. properties:
  16260. key:
  16261. description: |-
  16262. A key in the referenced Secret.
  16263. Some instances of this field may be defaulted, in others it may be required.
  16264. maxLength: 253
  16265. minLength: 1
  16266. pattern: ^[-._a-zA-Z0-9]+$
  16267. type: string
  16268. name:
  16269. description: The name of the Secret resource being referred to.
  16270. maxLength: 253
  16271. minLength: 1
  16272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16273. type: string
  16274. namespace:
  16275. description: |-
  16276. The namespace of the Secret resource being referred to.
  16277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16278. maxLength: 63
  16279. minLength: 1
  16280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16281. type: string
  16282. type: object
  16283. type: object
  16284. type: object
  16285. customSessionTags:
  16286. additionalProperties:
  16287. type: string
  16288. description: |-
  16289. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16290. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16291. type: object
  16292. x-kubernetes-validations:
  16293. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16294. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16295. externalID:
  16296. description: AWS External ID set on assumed IAM roles
  16297. type: string
  16298. prefix:
  16299. description: Prefix adds a prefix to all retrieved values.
  16300. type: string
  16301. region:
  16302. description: AWS Region to be used for the provider
  16303. type: string
  16304. role:
  16305. description: Role is a Role ARN which the provider will assume
  16306. type: string
  16307. secretsManager:
  16308. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16309. properties:
  16310. forceDeleteWithoutRecovery:
  16311. description: |-
  16312. Specifies whether to delete the secret without any recovery window. You
  16313. can't use both this parameter and RecoveryWindowInDays in the same call.
  16314. If you don't use either, then by default Secrets Manager uses a 30 day
  16315. recovery window.
  16316. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16317. type: boolean
  16318. recoveryWindowInDays:
  16319. description: |-
  16320. The number of days from 7 to 30 that Secrets Manager waits before
  16321. permanently deleting the secret. You can't use both this parameter and
  16322. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16323. then by default Secrets Manager uses a 30-day recovery window.
  16324. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16325. format: int64
  16326. type: integer
  16327. type: object
  16328. service:
  16329. description: Service defines which service should be used to fetch the secrets
  16330. enum:
  16331. - SecretsManager
  16332. - ParameterStore
  16333. - CertificateManager
  16334. type: string
  16335. sessionTags:
  16336. description: AWS STS assume role session tags
  16337. items:
  16338. description: |-
  16339. Tag is a key-value pair that can be attached to an AWS resource.
  16340. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16341. properties:
  16342. key:
  16343. type: string
  16344. value:
  16345. type: string
  16346. required:
  16347. - key
  16348. - value
  16349. type: object
  16350. type: array
  16351. sessionTagsPolicy:
  16352. default: None
  16353. description: |-
  16354. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16355. None (default): no tags are added.
  16356. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16357. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16358. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16359. enum:
  16360. - None
  16361. - Simple
  16362. - Custom
  16363. type: string
  16364. transitiveTagKeys:
  16365. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16366. items:
  16367. type: string
  16368. type: array
  16369. required:
  16370. - region
  16371. - service
  16372. type: object
  16373. azurekv:
  16374. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16375. properties:
  16376. authSecretRef:
  16377. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16378. properties:
  16379. clientCertificate:
  16380. description: The Azure ClientCertificate of the service principle used for authentication.
  16381. properties:
  16382. key:
  16383. description: |-
  16384. A key in the referenced Secret.
  16385. Some instances of this field may be defaulted, in others it may be required.
  16386. maxLength: 253
  16387. minLength: 1
  16388. pattern: ^[-._a-zA-Z0-9]+$
  16389. type: string
  16390. name:
  16391. description: The name of the Secret resource being referred to.
  16392. maxLength: 253
  16393. minLength: 1
  16394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16395. type: string
  16396. namespace:
  16397. description: |-
  16398. The namespace of the Secret resource being referred to.
  16399. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16400. maxLength: 63
  16401. minLength: 1
  16402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16403. type: string
  16404. type: object
  16405. clientId:
  16406. description: The Azure clientId of the service principle or managed identity used for authentication.
  16407. properties:
  16408. key:
  16409. description: |-
  16410. A key in the referenced Secret.
  16411. Some instances of this field may be defaulted, in others it may be required.
  16412. maxLength: 253
  16413. minLength: 1
  16414. pattern: ^[-._a-zA-Z0-9]+$
  16415. type: string
  16416. name:
  16417. description: The name of the Secret resource being referred to.
  16418. maxLength: 253
  16419. minLength: 1
  16420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16421. type: string
  16422. namespace:
  16423. description: |-
  16424. The namespace of the Secret resource being referred to.
  16425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16426. maxLength: 63
  16427. minLength: 1
  16428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16429. type: string
  16430. type: object
  16431. clientSecret:
  16432. description: The Azure ClientSecret of the service principle used for authentication.
  16433. properties:
  16434. key:
  16435. description: |-
  16436. A key in the referenced Secret.
  16437. Some instances of this field may be defaulted, in others it may be required.
  16438. maxLength: 253
  16439. minLength: 1
  16440. pattern: ^[-._a-zA-Z0-9]+$
  16441. type: string
  16442. name:
  16443. description: The name of the Secret resource being referred to.
  16444. maxLength: 253
  16445. minLength: 1
  16446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16447. type: string
  16448. namespace:
  16449. description: |-
  16450. The namespace of the Secret resource being referred to.
  16451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16452. maxLength: 63
  16453. minLength: 1
  16454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16455. type: string
  16456. type: object
  16457. tenantId:
  16458. description: The Azure tenantId of the managed identity used for authentication.
  16459. properties:
  16460. key:
  16461. description: |-
  16462. A key in the referenced Secret.
  16463. Some instances of this field may be defaulted, in others it may be required.
  16464. maxLength: 253
  16465. minLength: 1
  16466. pattern: ^[-._a-zA-Z0-9]+$
  16467. type: string
  16468. name:
  16469. description: The name of the Secret resource being referred to.
  16470. maxLength: 253
  16471. minLength: 1
  16472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16473. type: string
  16474. namespace:
  16475. description: |-
  16476. The namespace of the Secret resource being referred to.
  16477. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16478. maxLength: 63
  16479. minLength: 1
  16480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16481. type: string
  16482. type: object
  16483. type: object
  16484. authType:
  16485. default: ServicePrincipal
  16486. description: |-
  16487. Auth type defines how to authenticate to the keyvault service.
  16488. Valid values are:
  16489. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16490. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16491. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16492. enum:
  16493. - ServicePrincipal
  16494. - ManagedIdentity
  16495. - WorkloadIdentity
  16496. type: string
  16497. customCloudConfig:
  16498. description: |-
  16499. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16500. Required when EnvironmentType is AzureStackCloud.
  16501. Optional for other environment types - useful for Azure China when using Workload Identity
  16502. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16503. standard China Cloud endpoint (login.chinacloudapi.cn).
  16504. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16505. configuration is not supported with the legacy go-autorest SDK.
  16506. properties:
  16507. activeDirectoryEndpoint:
  16508. description: |-
  16509. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16510. Required when using custom cloud configuration
  16511. type: string
  16512. keyVaultDNSSuffix:
  16513. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16514. type: string
  16515. keyVaultEndpoint:
  16516. description: KeyVaultEndpoint is the Key Vault service endpoint
  16517. type: string
  16518. resourceManagerEndpoint:
  16519. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16520. type: string
  16521. required:
  16522. - activeDirectoryEndpoint
  16523. type: object
  16524. environmentType:
  16525. default: PublicCloud
  16526. description: |-
  16527. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16528. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16529. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16530. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16531. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16532. enum:
  16533. - PublicCloud
  16534. - USGovernmentCloud
  16535. - ChinaCloud
  16536. - GermanCloud
  16537. - AzureStackCloud
  16538. type: string
  16539. identityId:
  16540. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16541. type: string
  16542. serviceAccountRef:
  16543. description: |-
  16544. ServiceAccountRef specified the service account
  16545. that should be used when authenticating with WorkloadIdentity.
  16546. properties:
  16547. audiences:
  16548. description: |-
  16549. Audience specifies the `aud` claim for the service account token
  16550. Some providers automatically extend the audience field based on well-known annotations for workload
  16551. identity (e.g. IRSA or GCP Workload Identity)
  16552. items:
  16553. type: string
  16554. type: array
  16555. name:
  16556. description: The name of the ServiceAccount resource being referred to.
  16557. maxLength: 253
  16558. minLength: 1
  16559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16560. type: string
  16561. namespace:
  16562. description: |-
  16563. Namespace of the resource being referred to.
  16564. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16565. maxLength: 63
  16566. minLength: 1
  16567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16568. type: string
  16569. required:
  16570. - name
  16571. type: object
  16572. tenantId:
  16573. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16574. type: string
  16575. useAzureSDK:
  16576. default: false
  16577. description: |-
  16578. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16579. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16580. type: boolean
  16581. vaultUrl:
  16582. description: Vault Url from which the secrets to be fetched from.
  16583. type: string
  16584. required:
  16585. - vaultUrl
  16586. type: object
  16587. barbican:
  16588. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16589. properties:
  16590. auth:
  16591. description: BarbicanAuth contains the authentication information for Barbican.
  16592. properties:
  16593. applicationCredentialID:
  16594. description: ID of the application credential used for authentication.
  16595. maxProperties: 1
  16596. minProperties: 1
  16597. properties:
  16598. secretRef:
  16599. description: |-
  16600. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16601. In some instances, `key` is a required field.
  16602. properties:
  16603. key:
  16604. description: |-
  16605. A key in the referenced Secret.
  16606. Some instances of this field may be defaulted, in others it may be required.
  16607. maxLength: 253
  16608. minLength: 1
  16609. pattern: ^[-._a-zA-Z0-9]+$
  16610. type: string
  16611. name:
  16612. description: The name of the Secret resource being referred to.
  16613. maxLength: 253
  16614. minLength: 1
  16615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16616. type: string
  16617. namespace:
  16618. description: |-
  16619. The namespace of the Secret resource being referred to.
  16620. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16621. maxLength: 63
  16622. minLength: 1
  16623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16624. type: string
  16625. type: object
  16626. value:
  16627. minLength: 1
  16628. type: string
  16629. type: object
  16630. applicationCredentialSecret:
  16631. description: BarbicanProviderAppCredSecretRef defines a reference to an Application Credential Secret.
  16632. properties:
  16633. secretRef:
  16634. description: |-
  16635. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16636. In some instances, `key` is a required field.
  16637. properties:
  16638. key:
  16639. description: |-
  16640. A key in the referenced Secret.
  16641. Some instances of this field may be defaulted, in others it may be required.
  16642. maxLength: 253
  16643. minLength: 1
  16644. pattern: ^[-._a-zA-Z0-9]+$
  16645. type: string
  16646. name:
  16647. description: The name of the Secret resource being referred to.
  16648. maxLength: 253
  16649. minLength: 1
  16650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16651. type: string
  16652. namespace:
  16653. description: |-
  16654. The namespace of the Secret resource being referred to.
  16655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16656. maxLength: 63
  16657. minLength: 1
  16658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16659. type: string
  16660. type: object
  16661. required:
  16662. - secretRef
  16663. type: object
  16664. authType:
  16665. default: password
  16666. description: |-
  16667. AuthType selects how Barbican authenticates.
  16668. - "password": use username and password.
  16669. - "applicationCredential": use application credential ID and secret.
  16670. Defaults to "password".
  16671. enum:
  16672. - password
  16673. - applicationCredential
  16674. type: string
  16675. password:
  16676. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16677. properties:
  16678. secretRef:
  16679. description: |-
  16680. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16681. In some instances, `key` is a required field.
  16682. properties:
  16683. key:
  16684. description: |-
  16685. A key in the referenced Secret.
  16686. Some instances of this field may be defaulted, in others it may be required.
  16687. maxLength: 253
  16688. minLength: 1
  16689. pattern: ^[-._a-zA-Z0-9]+$
  16690. type: string
  16691. name:
  16692. description: The name of the Secret resource being referred to.
  16693. maxLength: 253
  16694. minLength: 1
  16695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16696. type: string
  16697. namespace:
  16698. description: |-
  16699. The namespace of the Secret resource being referred to.
  16700. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16701. maxLength: 63
  16702. minLength: 1
  16703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16704. type: string
  16705. type: object
  16706. required:
  16707. - secretRef
  16708. type: object
  16709. username:
  16710. description: Username / Password authentication fields.
  16711. maxProperties: 1
  16712. minProperties: 1
  16713. properties:
  16714. secretRef:
  16715. description: |-
  16716. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16717. In some instances, `key` is a required field.
  16718. properties:
  16719. key:
  16720. description: |-
  16721. A key in the referenced Secret.
  16722. Some instances of this field may be defaulted, in others it may be required.
  16723. maxLength: 253
  16724. minLength: 1
  16725. pattern: ^[-._a-zA-Z0-9]+$
  16726. type: string
  16727. name:
  16728. description: The name of the Secret resource being referred to.
  16729. maxLength: 253
  16730. minLength: 1
  16731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16732. type: string
  16733. namespace:
  16734. description: |-
  16735. The namespace of the Secret resource being referred to.
  16736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16737. maxLength: 63
  16738. minLength: 1
  16739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16740. type: string
  16741. type: object
  16742. value:
  16743. minLength: 1
  16744. type: string
  16745. type: object
  16746. type: object
  16747. x-kubernetes-validations:
  16748. - message: password auth requires both username and password
  16749. rule: (has(self.authType) && self.authType == 'applicationCredential') || (has(self.username) && has(self.password))
  16750. - message: applicationCredential auth requires both applicationCredentialID and applicationCredentialSecret
  16751. rule: self.authType != 'applicationCredential' || (has(self.applicationCredentialID) && has(self.applicationCredentialSecret))
  16752. - message: password auth should not include applicationCredential fields
  16753. rule: (has(self.authType) && self.authType == 'applicationCredential') || (!has(self.applicationCredentialID) && !has(self.applicationCredentialSecret))
  16754. - message: applicationCredential auth should not include password fields
  16755. rule: self.authType != 'applicationCredential' || (!has(self.username) && !has(self.password))
  16756. authURL:
  16757. type: string
  16758. domainName:
  16759. type: string
  16760. region:
  16761. type: string
  16762. tenantName:
  16763. type: string
  16764. required:
  16765. - auth
  16766. type: object
  16767. beyondtrust:
  16768. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16769. properties:
  16770. auth:
  16771. description: Auth configures how the operator authenticates with Beyondtrust.
  16772. properties:
  16773. apiKey:
  16774. description: APIKey If not provided then ClientID/ClientSecret become required.
  16775. properties:
  16776. secretRef:
  16777. description: SecretRef references a key in a secret that will be used as value.
  16778. properties:
  16779. key:
  16780. description: |-
  16781. A key in the referenced Secret.
  16782. Some instances of this field may be defaulted, in others it may be required.
  16783. maxLength: 253
  16784. minLength: 1
  16785. pattern: ^[-._a-zA-Z0-9]+$
  16786. type: string
  16787. name:
  16788. description: The name of the Secret resource being referred to.
  16789. maxLength: 253
  16790. minLength: 1
  16791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16792. type: string
  16793. namespace:
  16794. description: |-
  16795. The namespace of the Secret resource being referred to.
  16796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16797. maxLength: 63
  16798. minLength: 1
  16799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16800. type: string
  16801. type: object
  16802. value:
  16803. description: Value can be specified directly to set a value without using a secret.
  16804. type: string
  16805. type: object
  16806. certificate:
  16807. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16808. properties:
  16809. secretRef:
  16810. description: SecretRef references a key in a secret that will be used as value.
  16811. properties:
  16812. key:
  16813. description: |-
  16814. A key in the referenced Secret.
  16815. Some instances of this field may be defaulted, in others it may be required.
  16816. maxLength: 253
  16817. minLength: 1
  16818. pattern: ^[-._a-zA-Z0-9]+$
  16819. type: string
  16820. name:
  16821. description: The name of the Secret resource being referred to.
  16822. maxLength: 253
  16823. minLength: 1
  16824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16825. type: string
  16826. namespace:
  16827. description: |-
  16828. The namespace of the Secret resource being referred to.
  16829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16830. maxLength: 63
  16831. minLength: 1
  16832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16833. type: string
  16834. type: object
  16835. value:
  16836. description: Value can be specified directly to set a value without using a secret.
  16837. type: string
  16838. type: object
  16839. certificateKey:
  16840. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16841. properties:
  16842. secretRef:
  16843. description: SecretRef references a key in a secret that will be used as value.
  16844. properties:
  16845. key:
  16846. description: |-
  16847. A key in the referenced Secret.
  16848. Some instances of this field may be defaulted, in others it may be required.
  16849. maxLength: 253
  16850. minLength: 1
  16851. pattern: ^[-._a-zA-Z0-9]+$
  16852. type: string
  16853. name:
  16854. description: The name of the Secret resource being referred to.
  16855. maxLength: 253
  16856. minLength: 1
  16857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16858. type: string
  16859. namespace:
  16860. description: |-
  16861. The namespace of the Secret resource being referred to.
  16862. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16863. maxLength: 63
  16864. minLength: 1
  16865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16866. type: string
  16867. type: object
  16868. value:
  16869. description: Value can be specified directly to set a value without using a secret.
  16870. type: string
  16871. type: object
  16872. clientId:
  16873. description: ClientID is the API OAuth Client ID.
  16874. properties:
  16875. secretRef:
  16876. description: SecretRef references a key in a secret that will be used as value.
  16877. properties:
  16878. key:
  16879. description: |-
  16880. A key in the referenced Secret.
  16881. Some instances of this field may be defaulted, in others it may be required.
  16882. maxLength: 253
  16883. minLength: 1
  16884. pattern: ^[-._a-zA-Z0-9]+$
  16885. type: string
  16886. name:
  16887. description: The name of the Secret resource being referred to.
  16888. maxLength: 253
  16889. minLength: 1
  16890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16891. type: string
  16892. namespace:
  16893. description: |-
  16894. The namespace of the Secret resource being referred to.
  16895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16896. maxLength: 63
  16897. minLength: 1
  16898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16899. type: string
  16900. type: object
  16901. value:
  16902. description: Value can be specified directly to set a value without using a secret.
  16903. type: string
  16904. type: object
  16905. clientSecret:
  16906. description: ClientSecret is the API OAuth Client Secret.
  16907. properties:
  16908. secretRef:
  16909. description: SecretRef references a key in a secret that will be used as value.
  16910. properties:
  16911. key:
  16912. description: |-
  16913. A key in the referenced Secret.
  16914. Some instances of this field may be defaulted, in others it may be required.
  16915. maxLength: 253
  16916. minLength: 1
  16917. pattern: ^[-._a-zA-Z0-9]+$
  16918. type: string
  16919. name:
  16920. description: The name of the Secret resource being referred to.
  16921. maxLength: 253
  16922. minLength: 1
  16923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16924. type: string
  16925. namespace:
  16926. description: |-
  16927. The namespace of the Secret resource being referred to.
  16928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16929. maxLength: 63
  16930. minLength: 1
  16931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16932. type: string
  16933. type: object
  16934. value:
  16935. description: Value can be specified directly to set a value without using a secret.
  16936. type: string
  16937. type: object
  16938. type: object
  16939. server:
  16940. description: Auth configures how API server works.
  16941. properties:
  16942. apiUrl:
  16943. type: string
  16944. apiVersion:
  16945. type: string
  16946. clientTimeOutSeconds:
  16947. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16948. type: integer
  16949. decrypt:
  16950. default: true
  16951. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16952. type: boolean
  16953. retrievalType:
  16954. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16955. type: string
  16956. separator:
  16957. description: A character that separates the folder names.
  16958. type: string
  16959. verifyCA:
  16960. type: boolean
  16961. required:
  16962. - apiUrl
  16963. - verifyCA
  16964. type: object
  16965. required:
  16966. - auth
  16967. - server
  16968. type: object
  16969. beyondtrustworkloadcredentials:
  16970. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16971. properties:
  16972. auth:
  16973. description: |-
  16974. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16975. Currently supports API key authentication via Kubernetes secret reference.
  16976. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16977. properties:
  16978. apikey:
  16979. description: |-
  16980. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16981. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16982. properties:
  16983. token:
  16984. description: |-
  16985. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16986. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16987. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16988. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16989. properties:
  16990. key:
  16991. description: |-
  16992. A key in the referenced Secret.
  16993. Some instances of this field may be defaulted, in others it may be required.
  16994. maxLength: 253
  16995. minLength: 1
  16996. pattern: ^[-._a-zA-Z0-9]+$
  16997. type: string
  16998. name:
  16999. description: The name of the Secret resource being referred to.
  17000. maxLength: 253
  17001. minLength: 1
  17002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17003. type: string
  17004. namespace:
  17005. description: |-
  17006. The namespace of the Secret resource being referred to.
  17007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17008. maxLength: 63
  17009. minLength: 1
  17010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17011. type: string
  17012. type: object
  17013. required:
  17014. - token
  17015. type: object
  17016. required:
  17017. - apikey
  17018. type: object
  17019. caBundle:
  17020. description: |-
  17021. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  17022. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  17023. If not set, the system's trusted root certificates are used.
  17024. format: byte
  17025. type: string
  17026. caProvider:
  17027. description: |-
  17028. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  17029. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  17030. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  17031. properties:
  17032. key:
  17033. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17034. maxLength: 253
  17035. minLength: 1
  17036. pattern: ^[-._a-zA-Z0-9]+$
  17037. type: string
  17038. name:
  17039. description: The name of the object located at the provider type.
  17040. maxLength: 253
  17041. minLength: 1
  17042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17043. type: string
  17044. namespace:
  17045. description: |-
  17046. The namespace the Provider type is in.
  17047. Can only be defined when used in a ClusterSecretStore.
  17048. maxLength: 63
  17049. minLength: 1
  17050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17051. type: string
  17052. type:
  17053. description: The type of provider to use such as "Secret", or "ConfigMap".
  17054. enum:
  17055. - Secret
  17056. - ConfigMap
  17057. type: string
  17058. required:
  17059. - name
  17060. - type
  17061. type: object
  17062. folderPath:
  17063. description: |-
  17064. FolderPath specifies the default folder path for secret retrieval.
  17065. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  17066. Example: "production/database" or "dev/api-keys"
  17067. Leave empty to retrieve secrets from the root folder.
  17068. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  17069. type: string
  17070. server:
  17071. description: |-
  17072. Server configures the BeyondTrust Workload Credentials server connection details.
  17073. Includes the API URL and Site ID for your BeyondTrust instance.
  17074. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  17075. properties:
  17076. apiUrl:
  17077. description: |-
  17078. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  17079. This should be the full URL to your BeyondTrust instance.
  17080. Example: https://api.beyondtrust.io/siie
  17081. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  17082. type: string
  17083. siteId:
  17084. description: |-
  17085. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  17086. This identifier is unique to your BeyondTrust Workload Credentials instance.
  17087. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  17088. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  17089. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  17090. type: string
  17091. required:
  17092. - apiUrl
  17093. - siteId
  17094. type: object
  17095. required:
  17096. - auth
  17097. - server
  17098. type: object
  17099. bitwardensecretsmanager:
  17100. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  17101. properties:
  17102. apiURL:
  17103. type: string
  17104. auth:
  17105. description: |-
  17106. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  17107. Make sure that the token being used has permissions on the given secret.
  17108. properties:
  17109. secretRef:
  17110. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  17111. properties:
  17112. credentials:
  17113. description: AccessToken used for the bitwarden instance.
  17114. properties:
  17115. key:
  17116. description: |-
  17117. A key in the referenced Secret.
  17118. Some instances of this field may be defaulted, in others it may be required.
  17119. maxLength: 253
  17120. minLength: 1
  17121. pattern: ^[-._a-zA-Z0-9]+$
  17122. type: string
  17123. name:
  17124. description: The name of the Secret resource being referred to.
  17125. maxLength: 253
  17126. minLength: 1
  17127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17128. type: string
  17129. namespace:
  17130. description: |-
  17131. The namespace of the Secret resource being referred to.
  17132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17133. maxLength: 63
  17134. minLength: 1
  17135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17136. type: string
  17137. type: object
  17138. required:
  17139. - credentials
  17140. type: object
  17141. required:
  17142. - secretRef
  17143. type: object
  17144. bitwardenServerSDKURL:
  17145. type: string
  17146. caBundle:
  17147. description: |-
  17148. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  17149. can be performed.
  17150. type: string
  17151. caProvider:
  17152. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17153. properties:
  17154. key:
  17155. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17156. maxLength: 253
  17157. minLength: 1
  17158. pattern: ^[-._a-zA-Z0-9]+$
  17159. type: string
  17160. name:
  17161. description: The name of the object located at the provider type.
  17162. maxLength: 253
  17163. minLength: 1
  17164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17165. type: string
  17166. namespace:
  17167. description: |-
  17168. The namespace the Provider type is in.
  17169. Can only be defined when used in a ClusterSecretStore.
  17170. maxLength: 63
  17171. minLength: 1
  17172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17173. type: string
  17174. type:
  17175. description: The type of provider to use such as "Secret", or "ConfigMap".
  17176. enum:
  17177. - Secret
  17178. - ConfigMap
  17179. type: string
  17180. required:
  17181. - name
  17182. - type
  17183. type: object
  17184. identityURL:
  17185. type: string
  17186. organizationID:
  17187. description: OrganizationID determines which organization this secret store manages.
  17188. type: string
  17189. projectID:
  17190. description: ProjectID determines which project this secret store manages.
  17191. type: string
  17192. required:
  17193. - auth
  17194. - organizationID
  17195. - projectID
  17196. type: object
  17197. chef:
  17198. description: Chef configures this store to sync secrets with chef server
  17199. properties:
  17200. auth:
  17201. description: Auth defines the information necessary to authenticate against chef Server
  17202. properties:
  17203. secretRef:
  17204. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  17205. properties:
  17206. privateKeySecretRef:
  17207. description: SecretKey is the Signing Key in PEM format, used for authentication.
  17208. properties:
  17209. key:
  17210. description: |-
  17211. A key in the referenced Secret.
  17212. Some instances of this field may be defaulted, in others it may be required.
  17213. maxLength: 253
  17214. minLength: 1
  17215. pattern: ^[-._a-zA-Z0-9]+$
  17216. type: string
  17217. name:
  17218. description: The name of the Secret resource being referred to.
  17219. maxLength: 253
  17220. minLength: 1
  17221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17222. type: string
  17223. namespace:
  17224. description: |-
  17225. The namespace of the Secret resource being referred to.
  17226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17227. maxLength: 63
  17228. minLength: 1
  17229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17230. type: string
  17231. type: object
  17232. required:
  17233. - privateKeySecretRef
  17234. type: object
  17235. required:
  17236. - secretRef
  17237. type: object
  17238. serverUrl:
  17239. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  17240. type: string
  17241. username:
  17242. description: UserName should be the user ID on the chef server
  17243. type: string
  17244. required:
  17245. - auth
  17246. - serverUrl
  17247. - username
  17248. type: object
  17249. cloudrusm:
  17250. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  17251. properties:
  17252. auth:
  17253. description: CSMAuth contains a secretRef for credentials.
  17254. properties:
  17255. secretRef:
  17256. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  17257. properties:
  17258. accessKeyIDSecretRef:
  17259. description: The AccessKeyID is used for authentication
  17260. properties:
  17261. key:
  17262. description: |-
  17263. A key in the referenced Secret.
  17264. Some instances of this field may be defaulted, in others it may be required.
  17265. maxLength: 253
  17266. minLength: 1
  17267. pattern: ^[-._a-zA-Z0-9]+$
  17268. type: string
  17269. name:
  17270. description: The name of the Secret resource being referred to.
  17271. maxLength: 253
  17272. minLength: 1
  17273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17274. type: string
  17275. namespace:
  17276. description: |-
  17277. The namespace of the Secret resource being referred to.
  17278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17279. maxLength: 63
  17280. minLength: 1
  17281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17282. type: string
  17283. type: object
  17284. accessKeySecretSecretRef:
  17285. description: The AccessKeySecret is used for authentication
  17286. properties:
  17287. key:
  17288. description: |-
  17289. A key in the referenced Secret.
  17290. Some instances of this field may be defaulted, in others it may be required.
  17291. maxLength: 253
  17292. minLength: 1
  17293. pattern: ^[-._a-zA-Z0-9]+$
  17294. type: string
  17295. name:
  17296. description: The name of the Secret resource being referred to.
  17297. maxLength: 253
  17298. minLength: 1
  17299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17300. type: string
  17301. namespace:
  17302. description: |-
  17303. The namespace of the Secret resource being referred to.
  17304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17305. maxLength: 63
  17306. minLength: 1
  17307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17308. type: string
  17309. type: object
  17310. required:
  17311. - accessKeyIDSecretRef
  17312. - accessKeySecretSecretRef
  17313. type: object
  17314. type: object
  17315. projectID:
  17316. description: ProjectID is the project, which the secrets are stored in.
  17317. type: string
  17318. required:
  17319. - auth
  17320. type: object
  17321. conjur:
  17322. description: Conjur configures this store to sync secrets using conjur provider
  17323. properties:
  17324. auth:
  17325. description: Defines authentication settings for connecting to Conjur.
  17326. maxProperties: 1
  17327. minProperties: 1
  17328. properties:
  17329. apikey:
  17330. description: Authenticates with Conjur using an API key.
  17331. properties:
  17332. account:
  17333. description: Account is the Conjur organization account name.
  17334. type: string
  17335. apiKeyRef:
  17336. description: |-
  17337. A reference to a specific 'key' containing the Conjur API key
  17338. within a Secret resource. In some instances, `key` is a required field.
  17339. properties:
  17340. key:
  17341. description: |-
  17342. A key in the referenced Secret.
  17343. Some instances of this field may be defaulted, in others it may be required.
  17344. maxLength: 253
  17345. minLength: 1
  17346. pattern: ^[-._a-zA-Z0-9]+$
  17347. type: string
  17348. name:
  17349. description: The name of the Secret resource being referred to.
  17350. maxLength: 253
  17351. minLength: 1
  17352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17353. type: string
  17354. namespace:
  17355. description: |-
  17356. The namespace of the Secret resource being referred to.
  17357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17358. maxLength: 63
  17359. minLength: 1
  17360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17361. type: string
  17362. type: object
  17363. userRef:
  17364. description: |-
  17365. A reference to a specific 'key' containing the Conjur username
  17366. within a Secret resource. In some instances, `key` is a required field.
  17367. properties:
  17368. key:
  17369. description: |-
  17370. A key in the referenced Secret.
  17371. Some instances of this field may be defaulted, in others it may be required.
  17372. maxLength: 253
  17373. minLength: 1
  17374. pattern: ^[-._a-zA-Z0-9]+$
  17375. type: string
  17376. name:
  17377. description: The name of the Secret resource being referred to.
  17378. maxLength: 253
  17379. minLength: 1
  17380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17381. type: string
  17382. namespace:
  17383. description: |-
  17384. The namespace of the Secret resource being referred to.
  17385. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17386. maxLength: 63
  17387. minLength: 1
  17388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17389. type: string
  17390. type: object
  17391. required:
  17392. - account
  17393. - apiKeyRef
  17394. - userRef
  17395. type: object
  17396. cert:
  17397. description: Cert enables certificate-based authentication using a client certificate and key.
  17398. properties:
  17399. account:
  17400. description: Account is the Conjur organization account name.
  17401. type: string
  17402. clientCertRef:
  17403. description: |-
  17404. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17405. within a Secret resource. The certificate must be PEM-encoded.
  17406. properties:
  17407. key:
  17408. description: |-
  17409. A key in the referenced Secret.
  17410. Some instances of this field may be defaulted, in others it may be required.
  17411. maxLength: 253
  17412. minLength: 1
  17413. pattern: ^[-._a-zA-Z0-9]+$
  17414. type: string
  17415. name:
  17416. description: The name of the Secret resource being referred to.
  17417. maxLength: 253
  17418. minLength: 1
  17419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17420. type: string
  17421. namespace:
  17422. description: |-
  17423. The namespace of the Secret resource being referred to.
  17424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17425. maxLength: 63
  17426. minLength: 1
  17427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17428. type: string
  17429. type: object
  17430. clientKeyRef:
  17431. description: |-
  17432. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17433. within a Secret resource. The key must be PEM-encoded.
  17434. properties:
  17435. key:
  17436. description: |-
  17437. A key in the referenced Secret.
  17438. Some instances of this field may be defaulted, in others it may be required.
  17439. maxLength: 253
  17440. minLength: 1
  17441. pattern: ^[-._a-zA-Z0-9]+$
  17442. type: string
  17443. name:
  17444. description: The name of the Secret resource being referred to.
  17445. maxLength: 253
  17446. minLength: 1
  17447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17448. type: string
  17449. namespace:
  17450. description: |-
  17451. The namespace of the Secret resource being referred to.
  17452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17453. maxLength: 63
  17454. minLength: 1
  17455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17456. type: string
  17457. type: object
  17458. hostId:
  17459. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17460. type: string
  17461. serviceID:
  17462. description: The conjur authn cert webservice id
  17463. type: string
  17464. required:
  17465. - account
  17466. - clientCertRef
  17467. - clientKeyRef
  17468. - serviceID
  17469. type: object
  17470. jwt:
  17471. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17472. properties:
  17473. account:
  17474. description: Account is the Conjur organization account name.
  17475. type: string
  17476. hostId:
  17477. description: |-
  17478. Optional HostID for JWT authentication. This may be used depending
  17479. on how the Conjur JWT authenticator policy is configured.
  17480. type: string
  17481. secretRef:
  17482. description: |-
  17483. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17484. authenticate with Conjur using the JWT authentication method.
  17485. properties:
  17486. key:
  17487. description: |-
  17488. A key in the referenced Secret.
  17489. Some instances of this field may be defaulted, in others it may be required.
  17490. maxLength: 253
  17491. minLength: 1
  17492. pattern: ^[-._a-zA-Z0-9]+$
  17493. type: string
  17494. name:
  17495. description: The name of the Secret resource being referred to.
  17496. maxLength: 253
  17497. minLength: 1
  17498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17499. type: string
  17500. namespace:
  17501. description: |-
  17502. The namespace of the Secret resource being referred to.
  17503. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17504. maxLength: 63
  17505. minLength: 1
  17506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17507. type: string
  17508. type: object
  17509. serviceAccountRef:
  17510. description: |-
  17511. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17512. a token for with the `TokenRequest` API.
  17513. properties:
  17514. audiences:
  17515. description: |-
  17516. Audience specifies the `aud` claim for the service account token
  17517. Some providers automatically extend the audience field based on well-known annotations for workload
  17518. identity (e.g. IRSA or GCP Workload Identity)
  17519. items:
  17520. type: string
  17521. type: array
  17522. name:
  17523. description: The name of the ServiceAccount resource being referred to.
  17524. maxLength: 253
  17525. minLength: 1
  17526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17527. type: string
  17528. namespace:
  17529. description: |-
  17530. Namespace of the resource being referred to.
  17531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17532. maxLength: 63
  17533. minLength: 1
  17534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17535. type: string
  17536. required:
  17537. - name
  17538. type: object
  17539. serviceID:
  17540. description: The conjur authn jwt webservice id
  17541. type: string
  17542. required:
  17543. - account
  17544. - serviceID
  17545. type: object
  17546. type: object
  17547. caBundle:
  17548. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17549. type: string
  17550. caProvider:
  17551. description: |-
  17552. Used to provide custom certificate authority (CA) certificates
  17553. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17554. that contains a PEM-encoded certificate.
  17555. properties:
  17556. key:
  17557. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17558. maxLength: 253
  17559. minLength: 1
  17560. pattern: ^[-._a-zA-Z0-9]+$
  17561. type: string
  17562. name:
  17563. description: The name of the object located at the provider type.
  17564. maxLength: 253
  17565. minLength: 1
  17566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17567. type: string
  17568. namespace:
  17569. description: |-
  17570. The namespace the Provider type is in.
  17571. Can only be defined when used in a ClusterSecretStore.
  17572. maxLength: 63
  17573. minLength: 1
  17574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17575. type: string
  17576. type:
  17577. description: The type of provider to use such as "Secret", or "ConfigMap".
  17578. enum:
  17579. - Secret
  17580. - ConfigMap
  17581. type: string
  17582. required:
  17583. - name
  17584. - type
  17585. type: object
  17586. url:
  17587. description: URL is the endpoint of the Conjur instance.
  17588. type: string
  17589. required:
  17590. - auth
  17591. - url
  17592. type: object
  17593. crd:
  17594. description: |-
  17595. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17596. including both custom resources (CRDs) and core API resources. Resources are
  17597. selected by API group, version and kind, where group can be "" (empty string)
  17598. for core resources such as ConfigMap. Reading the core v1 Secret is
  17599. intentionally blocked — use the Kubernetes provider for that.
  17600. properties:
  17601. auth:
  17602. description: |-
  17603. Auth configures authentication to the Kubernetes API, same as the
  17604. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17605. maxProperties: 1
  17606. minProperties: 1
  17607. properties:
  17608. cert:
  17609. description: has both clientCert and clientKey as secretKeySelector
  17610. properties:
  17611. clientCert:
  17612. description: |-
  17613. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17614. In some instances, `key` is a required field.
  17615. properties:
  17616. key:
  17617. description: |-
  17618. A key in the referenced Secret.
  17619. Some instances of this field may be defaulted, in others it may be required.
  17620. maxLength: 253
  17621. minLength: 1
  17622. pattern: ^[-._a-zA-Z0-9]+$
  17623. type: string
  17624. name:
  17625. description: The name of the Secret resource being referred to.
  17626. maxLength: 253
  17627. minLength: 1
  17628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17629. type: string
  17630. namespace:
  17631. description: |-
  17632. The namespace of the Secret resource being referred to.
  17633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17634. maxLength: 63
  17635. minLength: 1
  17636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17637. type: string
  17638. type: object
  17639. clientKey:
  17640. description: |-
  17641. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17642. In some instances, `key` is a required field.
  17643. properties:
  17644. key:
  17645. description: |-
  17646. A key in the referenced Secret.
  17647. Some instances of this field may be defaulted, in others it may be required.
  17648. maxLength: 253
  17649. minLength: 1
  17650. pattern: ^[-._a-zA-Z0-9]+$
  17651. type: string
  17652. name:
  17653. description: The name of the Secret resource being referred to.
  17654. maxLength: 253
  17655. minLength: 1
  17656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17657. type: string
  17658. namespace:
  17659. description: |-
  17660. The namespace of the Secret resource being referred to.
  17661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17662. maxLength: 63
  17663. minLength: 1
  17664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17665. type: string
  17666. type: object
  17667. required:
  17668. - clientCert
  17669. - clientKey
  17670. type: object
  17671. serviceAccount:
  17672. description: points to a service account that should be used for authentication
  17673. properties:
  17674. audiences:
  17675. description: |-
  17676. Audience specifies the `aud` claim for the service account token
  17677. Some providers automatically extend the audience field based on well-known annotations for workload
  17678. identity (e.g. IRSA or GCP Workload Identity)
  17679. items:
  17680. type: string
  17681. type: array
  17682. name:
  17683. description: The name of the ServiceAccount resource being referred to.
  17684. maxLength: 253
  17685. minLength: 1
  17686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17687. type: string
  17688. namespace:
  17689. description: |-
  17690. Namespace of the resource being referred to.
  17691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17692. maxLength: 63
  17693. minLength: 1
  17694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17695. type: string
  17696. required:
  17697. - name
  17698. type: object
  17699. token:
  17700. description: use static token to authenticate with
  17701. properties:
  17702. bearerToken:
  17703. description: |-
  17704. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17705. In some instances, `key` is a required field.
  17706. properties:
  17707. key:
  17708. description: |-
  17709. A key in the referenced Secret.
  17710. Some instances of this field may be defaulted, in others it may be required.
  17711. maxLength: 253
  17712. minLength: 1
  17713. pattern: ^[-._a-zA-Z0-9]+$
  17714. type: string
  17715. name:
  17716. description: The name of the Secret resource being referred to.
  17717. maxLength: 253
  17718. minLength: 1
  17719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17720. type: string
  17721. namespace:
  17722. description: |-
  17723. The namespace of the Secret resource being referred to.
  17724. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17725. maxLength: 63
  17726. minLength: 1
  17727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17728. type: string
  17729. type: object
  17730. required:
  17731. - bearerToken
  17732. type: object
  17733. type: object
  17734. authRef:
  17735. description: |-
  17736. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17737. Kubernetes provider.
  17738. properties:
  17739. key:
  17740. description: |-
  17741. A key in the referenced Secret.
  17742. Some instances of this field may be defaulted, in others it may be required.
  17743. maxLength: 253
  17744. minLength: 1
  17745. pattern: ^[-._a-zA-Z0-9]+$
  17746. type: string
  17747. name:
  17748. description: The name of the Secret resource being referred to.
  17749. maxLength: 253
  17750. minLength: 1
  17751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17752. type: string
  17753. namespace:
  17754. description: |-
  17755. The namespace of the Secret resource being referred to.
  17756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17757. maxLength: 63
  17758. minLength: 1
  17759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17760. type: string
  17761. type: object
  17762. resource:
  17763. description: Resource identifies the CRD by its API group, version and kind.
  17764. properties:
  17765. group:
  17766. description: |-
  17767. Group is the API group of the resource. Use "" (empty string) for core
  17768. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17769. for a CRD. The field is required to be present in the manifest — write
  17770. `group: ""` explicitly for core resources so typos fail at admission
  17771. time rather than later at discovery.
  17772. type: string
  17773. kind:
  17774. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17775. minLength: 1
  17776. type: string
  17777. version:
  17778. description: Version is the API version of the resource (e.g. "v1alpha1").
  17779. minLength: 1
  17780. type: string
  17781. required:
  17782. - group
  17783. - kind
  17784. - version
  17785. type: object
  17786. server:
  17787. description: |-
  17788. Server configures the Kubernetes API address and TLS trust, same as the
  17789. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17790. properties:
  17791. caBundle:
  17792. description: CABundle is a base64-encoded CA certificate
  17793. format: byte
  17794. type: string
  17795. caProvider:
  17796. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17797. properties:
  17798. key:
  17799. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17800. maxLength: 253
  17801. minLength: 1
  17802. pattern: ^[-._a-zA-Z0-9]+$
  17803. type: string
  17804. name:
  17805. description: The name of the object located at the provider type.
  17806. maxLength: 253
  17807. minLength: 1
  17808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17809. type: string
  17810. namespace:
  17811. description: |-
  17812. The namespace the Provider type is in.
  17813. Can only be defined when used in a ClusterSecretStore.
  17814. maxLength: 63
  17815. minLength: 1
  17816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17817. type: string
  17818. type:
  17819. description: The type of provider to use such as "Secret", or "ConfigMap".
  17820. enum:
  17821. - Secret
  17822. - ConfigMap
  17823. type: string
  17824. required:
  17825. - name
  17826. - type
  17827. type: object
  17828. url:
  17829. default: kubernetes.default
  17830. description: configures the Kubernetes server Address.
  17831. type: string
  17832. type: object
  17833. whitelist:
  17834. description: |-
  17835. Whitelist optionally restricts which object names and requested properties
  17836. are allowed to be read.
  17837. properties:
  17838. rules:
  17839. description: |-
  17840. Rules is a list of allow rules. If rules are set, at least one rule must
  17841. match for a request to be allowed.
  17842. items:
  17843. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17844. properties:
  17845. name:
  17846. description: |-
  17847. Name is an optional regular expression matched against the bare object name.
  17848. For both SecretStore and ClusterSecretStore this is always the object name
  17849. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17850. type: string
  17851. namespace:
  17852. description: |-
  17853. Namespace is an optional regular expression matched against the namespace of
  17854. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17855. for SecretStore (where the namespace is fixed to the store namespace).
  17856. type: string
  17857. properties:
  17858. description: |-
  17859. Properties is an optional list of regular expressions matched against
  17860. requested property keys (for example: "spec.secretValue").
  17861. items:
  17862. type: string
  17863. type: array
  17864. type: object
  17865. type: array
  17866. type: object
  17867. required:
  17868. - resource
  17869. type: object
  17870. x-kubernetes-validations:
  17871. - message: one of auth or authRef is required
  17872. rule: has(self.auth) || has(self.authRef)
  17873. - message: at most one of the fields in [auth authRef] may be set
  17874. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17875. delinea:
  17876. description: |-
  17877. Delinea DevOps Secrets Vault
  17878. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17879. properties:
  17880. clientId:
  17881. description: ClientID is the non-secret part of the credential.
  17882. properties:
  17883. secretRef:
  17884. description: SecretRef references a key in a secret that will be used as value.
  17885. properties:
  17886. key:
  17887. description: |-
  17888. A key in the referenced Secret.
  17889. Some instances of this field may be defaulted, in others it may be required.
  17890. maxLength: 253
  17891. minLength: 1
  17892. pattern: ^[-._a-zA-Z0-9]+$
  17893. type: string
  17894. name:
  17895. description: The name of the Secret resource being referred to.
  17896. maxLength: 253
  17897. minLength: 1
  17898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17899. type: string
  17900. namespace:
  17901. description: |-
  17902. The namespace of the Secret resource being referred to.
  17903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17904. maxLength: 63
  17905. minLength: 1
  17906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17907. type: string
  17908. type: object
  17909. value:
  17910. description: Value can be specified directly to set a value without using a secret.
  17911. type: string
  17912. type: object
  17913. clientSecret:
  17914. description: ClientSecret is the secret part of the credential.
  17915. properties:
  17916. secretRef:
  17917. description: SecretRef references a key in a secret that will be used as value.
  17918. properties:
  17919. key:
  17920. description: |-
  17921. A key in the referenced Secret.
  17922. Some instances of this field may be defaulted, in others it may be required.
  17923. maxLength: 253
  17924. minLength: 1
  17925. pattern: ^[-._a-zA-Z0-9]+$
  17926. type: string
  17927. name:
  17928. description: The name of the Secret resource being referred to.
  17929. maxLength: 253
  17930. minLength: 1
  17931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17932. type: string
  17933. namespace:
  17934. description: |-
  17935. The namespace of the Secret resource being referred to.
  17936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17937. maxLength: 63
  17938. minLength: 1
  17939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17940. type: string
  17941. type: object
  17942. value:
  17943. description: Value can be specified directly to set a value without using a secret.
  17944. type: string
  17945. type: object
  17946. tenant:
  17947. description: Tenant is the chosen hostname / site name.
  17948. type: string
  17949. tld:
  17950. description: |-
  17951. TLD is based on the server location that was chosen during provisioning.
  17952. If unset, defaults to "com".
  17953. type: string
  17954. urlTemplate:
  17955. description: |-
  17956. URLTemplate
  17957. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17958. type: string
  17959. required:
  17960. - clientId
  17961. - clientSecret
  17962. - tenant
  17963. type: object
  17964. doppler:
  17965. description: Doppler configures this store to sync secrets using the Doppler provider
  17966. properties:
  17967. auth:
  17968. description: Auth configures how the Operator authenticates with the Doppler API
  17969. properties:
  17970. oidcConfig:
  17971. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17972. properties:
  17973. expirationSeconds:
  17974. default: 600
  17975. description: |-
  17976. ExpirationSeconds sets the ServiceAccount token validity duration.
  17977. Defaults to 10 minutes.
  17978. format: int64
  17979. type: integer
  17980. identity:
  17981. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17982. type: string
  17983. serviceAccountRef:
  17984. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17985. properties:
  17986. audiences:
  17987. description: |-
  17988. Audience specifies the `aud` claim for the service account token
  17989. Some providers automatically extend the audience field based on well-known annotations for workload
  17990. identity (e.g. IRSA or GCP Workload Identity)
  17991. items:
  17992. type: string
  17993. type: array
  17994. name:
  17995. description: The name of the ServiceAccount resource being referred to.
  17996. maxLength: 253
  17997. minLength: 1
  17998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17999. type: string
  18000. namespace:
  18001. description: |-
  18002. Namespace of the resource being referred to.
  18003. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18004. maxLength: 63
  18005. minLength: 1
  18006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18007. type: string
  18008. required:
  18009. - name
  18010. type: object
  18011. required:
  18012. - identity
  18013. - serviceAccountRef
  18014. type: object
  18015. secretRef:
  18016. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  18017. properties:
  18018. dopplerToken:
  18019. description: |-
  18020. The DopplerToken is used for authentication.
  18021. See https://docs.doppler.com/reference/api#authentication for auth token types.
  18022. The Key attribute defaults to dopplerToken if not specified.
  18023. properties:
  18024. key:
  18025. description: |-
  18026. A key in the referenced Secret.
  18027. Some instances of this field may be defaulted, in others it may be required.
  18028. maxLength: 253
  18029. minLength: 1
  18030. pattern: ^[-._a-zA-Z0-9]+$
  18031. type: string
  18032. name:
  18033. description: The name of the Secret resource being referred to.
  18034. maxLength: 253
  18035. minLength: 1
  18036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18037. type: string
  18038. namespace:
  18039. description: |-
  18040. The namespace of the Secret resource being referred to.
  18041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18042. maxLength: 63
  18043. minLength: 1
  18044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18045. type: string
  18046. type: object
  18047. required:
  18048. - dopplerToken
  18049. type: object
  18050. type: object
  18051. x-kubernetes-validations:
  18052. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  18053. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  18054. config:
  18055. description: Doppler config (required if not using a Service Token)
  18056. type: string
  18057. format:
  18058. description: Format enables the downloading of secrets as a file (string)
  18059. enum:
  18060. - json
  18061. - dotnet-json
  18062. - env
  18063. - yaml
  18064. - docker
  18065. type: string
  18066. nameTransformer:
  18067. description: Environment variable compatible name transforms that change secret names to a different format
  18068. enum:
  18069. - upper-camel
  18070. - camel
  18071. - lower-snake
  18072. - tf-var
  18073. - dotnet-env
  18074. - lower-kebab
  18075. type: string
  18076. project:
  18077. description: Doppler project (required if not using a Service Token)
  18078. type: string
  18079. required:
  18080. - auth
  18081. type: object
  18082. dvls:
  18083. description: DVLS configures this store to sync secrets using Devolutions Server provider
  18084. properties:
  18085. auth:
  18086. description: Auth defines the authentication method to use.
  18087. properties:
  18088. secretRef:
  18089. description: SecretRef contains the Application ID and Application Secret for authentication.
  18090. properties:
  18091. appId:
  18092. description: AppID is the reference to the secret containing the Application ID.
  18093. properties:
  18094. key:
  18095. description: |-
  18096. A key in the referenced Secret.
  18097. Some instances of this field may be defaulted, in others it may be required.
  18098. maxLength: 253
  18099. minLength: 1
  18100. pattern: ^[-._a-zA-Z0-9]+$
  18101. type: string
  18102. name:
  18103. description: The name of the Secret resource being referred to.
  18104. maxLength: 253
  18105. minLength: 1
  18106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18107. type: string
  18108. namespace:
  18109. description: |-
  18110. The namespace of the Secret resource being referred to.
  18111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18112. maxLength: 63
  18113. minLength: 1
  18114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18115. type: string
  18116. type: object
  18117. appSecret:
  18118. description: AppSecret is the reference to the secret containing the Application Secret.
  18119. properties:
  18120. key:
  18121. description: |-
  18122. A key in the referenced Secret.
  18123. Some instances of this field may be defaulted, in others it may be required.
  18124. maxLength: 253
  18125. minLength: 1
  18126. pattern: ^[-._a-zA-Z0-9]+$
  18127. type: string
  18128. name:
  18129. description: The name of the Secret resource being referred to.
  18130. maxLength: 253
  18131. minLength: 1
  18132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18133. type: string
  18134. namespace:
  18135. description: |-
  18136. The namespace of the Secret resource being referred to.
  18137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18138. maxLength: 63
  18139. minLength: 1
  18140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18141. type: string
  18142. type: object
  18143. required:
  18144. - appId
  18145. - appSecret
  18146. type: object
  18147. required:
  18148. - secretRef
  18149. type: object
  18150. insecure:
  18151. description: |-
  18152. Insecure allows connecting to DVLS over plain HTTP.
  18153. This is NOT RECOMMENDED for production use.
  18154. Set to true only if you understand the security implications.
  18155. type: boolean
  18156. serverUrl:
  18157. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  18158. type: string
  18159. vault:
  18160. description: |-
  18161. Vault is the name or UUID of the vault to fetch secrets from.
  18162. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  18163. type: string
  18164. required:
  18165. - auth
  18166. - serverUrl
  18167. type: object
  18168. fake:
  18169. description: Fake configures a store with static key/value pairs
  18170. properties:
  18171. data:
  18172. items:
  18173. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  18174. properties:
  18175. key:
  18176. type: string
  18177. value:
  18178. type: string
  18179. version:
  18180. type: string
  18181. required:
  18182. - key
  18183. - value
  18184. type: object
  18185. type: array
  18186. validationResult:
  18187. description: ValidationResult is defined type for the number of validation results.
  18188. type: integer
  18189. required:
  18190. - data
  18191. type: object
  18192. fortanix:
  18193. description: Fortanix configures this store to sync secrets using the Fortanix provider
  18194. properties:
  18195. apiKey:
  18196. description: APIKey is the API token to access SDKMS Applications.
  18197. properties:
  18198. secretRef:
  18199. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  18200. properties:
  18201. key:
  18202. description: |-
  18203. A key in the referenced Secret.
  18204. Some instances of this field may be defaulted, in others it may be required.
  18205. maxLength: 253
  18206. minLength: 1
  18207. pattern: ^[-._a-zA-Z0-9]+$
  18208. type: string
  18209. name:
  18210. description: The name of the Secret resource being referred to.
  18211. maxLength: 253
  18212. minLength: 1
  18213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18214. type: string
  18215. namespace:
  18216. description: |-
  18217. The namespace of the Secret resource being referred to.
  18218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18219. maxLength: 63
  18220. minLength: 1
  18221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18222. type: string
  18223. type: object
  18224. type: object
  18225. apiUrl:
  18226. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  18227. type: string
  18228. type: object
  18229. gcpsm:
  18230. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  18231. properties:
  18232. auth:
  18233. description: Auth defines the information necessary to authenticate against GCP
  18234. properties:
  18235. secretRef:
  18236. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  18237. properties:
  18238. secretAccessKeySecretRef:
  18239. description: The SecretAccessKey is used for authentication
  18240. properties:
  18241. key:
  18242. description: |-
  18243. A key in the referenced Secret.
  18244. Some instances of this field may be defaulted, in others it may be required.
  18245. maxLength: 253
  18246. minLength: 1
  18247. pattern: ^[-._a-zA-Z0-9]+$
  18248. type: string
  18249. name:
  18250. description: The name of the Secret resource being referred to.
  18251. maxLength: 253
  18252. minLength: 1
  18253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18254. type: string
  18255. namespace:
  18256. description: |-
  18257. The namespace of the Secret resource being referred to.
  18258. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18259. maxLength: 63
  18260. minLength: 1
  18261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18262. type: string
  18263. type: object
  18264. type: object
  18265. workloadIdentity:
  18266. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  18267. properties:
  18268. clusterLocation:
  18269. description: |-
  18270. ClusterLocation is the location of the cluster
  18271. If not specified, it fetches information from the metadata server
  18272. type: string
  18273. clusterName:
  18274. description: |-
  18275. ClusterName is the name of the cluster
  18276. If not specified, it fetches information from the metadata server
  18277. type: string
  18278. clusterProjectID:
  18279. description: |-
  18280. ClusterProjectID is the project ID of the cluster
  18281. If not specified, it fetches information from the metadata server
  18282. type: string
  18283. serviceAccountRef:
  18284. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  18285. properties:
  18286. audiences:
  18287. description: |-
  18288. Audience specifies the `aud` claim for the service account token
  18289. Some providers automatically extend the audience field based on well-known annotations for workload
  18290. identity (e.g. IRSA or GCP Workload Identity)
  18291. items:
  18292. type: string
  18293. type: array
  18294. name:
  18295. description: The name of the ServiceAccount resource being referred to.
  18296. maxLength: 253
  18297. minLength: 1
  18298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18299. type: string
  18300. namespace:
  18301. description: |-
  18302. Namespace of the resource being referred to.
  18303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18304. maxLength: 63
  18305. minLength: 1
  18306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18307. type: string
  18308. required:
  18309. - name
  18310. type: object
  18311. required:
  18312. - serviceAccountRef
  18313. type: object
  18314. workloadIdentityFederation:
  18315. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  18316. properties:
  18317. audience:
  18318. description: |-
  18319. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  18320. If specified, Audience found in the external account credential config will be overridden with the configured value.
  18321. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18322. type: string
  18323. awsSecurityCredentials:
  18324. description: |-
  18325. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18326. when using the AWS metadata server is not an option.
  18327. properties:
  18328. awsCredentialsSecretRef:
  18329. description: |-
  18330. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18331. Secret should be created with below names for keys
  18332. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18333. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18334. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18335. properties:
  18336. name:
  18337. description: name of the secret.
  18338. maxLength: 253
  18339. minLength: 1
  18340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18341. type: string
  18342. namespace:
  18343. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18344. maxLength: 63
  18345. minLength: 1
  18346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18347. type: string
  18348. required:
  18349. - name
  18350. type: object
  18351. region:
  18352. description: region is for configuring the AWS region to be used.
  18353. example: ap-south-1
  18354. maxLength: 50
  18355. minLength: 1
  18356. pattern: ^[a-z0-9-]+$
  18357. type: string
  18358. required:
  18359. - awsCredentialsSecretRef
  18360. - region
  18361. type: object
  18362. credConfig:
  18363. description: |-
  18364. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18365. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18366. serviceAccountRef must be used by providing operators service account details.
  18367. properties:
  18368. key:
  18369. description: key name holding the external account credential config.
  18370. maxLength: 253
  18371. minLength: 1
  18372. pattern: ^[-._a-zA-Z0-9]+$
  18373. type: string
  18374. name:
  18375. description: name of the configmap.
  18376. maxLength: 253
  18377. minLength: 1
  18378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18379. type: string
  18380. namespace:
  18381. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18382. maxLength: 63
  18383. minLength: 1
  18384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18385. type: string
  18386. required:
  18387. - key
  18388. - name
  18389. type: object
  18390. externalTokenEndpoint:
  18391. description: |-
  18392. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18393. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18394. URL is having the expected value.
  18395. type: string
  18396. gcpServiceAccountEmail:
  18397. description: |-
  18398. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18399. after Workload Identity Federation. Use this to grant access through the service account's
  18400. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18401. service_account_impersonation_url in the external account JSON from credConfig;
  18402. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18403. on that ServiceAccount.
  18404. example: my-gsa@my-project.iam.gserviceaccount.com
  18405. minLength: 1
  18406. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18407. type: string
  18408. serviceAccountRef:
  18409. description: |-
  18410. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18411. when Kubernetes is configured as provider in workload identity pool.
  18412. properties:
  18413. audiences:
  18414. description: |-
  18415. Audience specifies the `aud` claim for the service account token
  18416. Some providers automatically extend the audience field based on well-known annotations for workload
  18417. identity (e.g. IRSA or GCP Workload Identity)
  18418. items:
  18419. type: string
  18420. type: array
  18421. name:
  18422. description: The name of the ServiceAccount resource being referred to.
  18423. maxLength: 253
  18424. minLength: 1
  18425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18426. type: string
  18427. namespace:
  18428. description: |-
  18429. Namespace of the resource being referred to.
  18430. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18431. maxLength: 63
  18432. minLength: 1
  18433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18434. type: string
  18435. required:
  18436. - name
  18437. type: object
  18438. type: object
  18439. type: object
  18440. location:
  18441. description: Location optionally defines a location for a secret
  18442. type: string
  18443. projectID:
  18444. description: ProjectID project where secret is located
  18445. type: string
  18446. secretVersionSelectionPolicy:
  18447. default: LatestOrFail
  18448. description: |-
  18449. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18450. when "latest" is disabled or destroyed.
  18451. Possible values are:
  18452. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18453. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18454. type: string
  18455. type: object
  18456. github:
  18457. description: |-
  18458. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  18459. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18460. properties:
  18461. appID:
  18462. description: appID specifies the Github APP that will be used to authenticate the client
  18463. format: int64
  18464. type: integer
  18465. auth:
  18466. description: auth configures how secret-manager authenticates with a Github instance.
  18467. properties:
  18468. privateKey:
  18469. description: |-
  18470. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18471. In some instances, `key` is a required field.
  18472. properties:
  18473. key:
  18474. description: |-
  18475. A key in the referenced Secret.
  18476. Some instances of this field may be defaulted, in others it may be required.
  18477. maxLength: 253
  18478. minLength: 1
  18479. pattern: ^[-._a-zA-Z0-9]+$
  18480. type: string
  18481. name:
  18482. description: The name of the Secret resource being referred to.
  18483. maxLength: 253
  18484. minLength: 1
  18485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18486. type: string
  18487. namespace:
  18488. description: |-
  18489. The namespace of the Secret resource being referred to.
  18490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18491. maxLength: 63
  18492. minLength: 1
  18493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18494. type: string
  18495. type: object
  18496. required:
  18497. - privateKey
  18498. type: object
  18499. environment:
  18500. description: environment will be used to fetch secrets from a particular environment within a github repository
  18501. type: string
  18502. installationID:
  18503. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18504. format: int64
  18505. type: integer
  18506. orgSecretVisibility:
  18507. description: |-
  18508. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18509. Valid values are "all" or "private".
  18510. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18511. whatever visibility they already have in GitHub.
  18512. enum:
  18513. - all
  18514. - private
  18515. type: string
  18516. organization:
  18517. description: organization will be used to fetch secrets from the Github organization
  18518. type: string
  18519. repository:
  18520. description: repository will be used to fetch secrets from the Github repository within an organization
  18521. type: string
  18522. secretType:
  18523. default: Actions
  18524. description: |-
  18525. secretType specifies which GitHub secret service to use.
  18526. Defaults to Actions for backwards compatibility.
  18527. enum:
  18528. - Actions
  18529. - Dependabot
  18530. type: string
  18531. uploadURL:
  18532. description: Upload URL for enterprise instances. Default to URL.
  18533. type: string
  18534. url:
  18535. default: https://github.com/
  18536. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18537. type: string
  18538. required:
  18539. - appID
  18540. - auth
  18541. - installationID
  18542. - organization
  18543. type: object
  18544. x-kubernetes-validations:
  18545. - message: Dependabot secrets do not support environments
  18546. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  18547. gitlab:
  18548. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18549. properties:
  18550. auth:
  18551. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18552. properties:
  18553. SecretRef:
  18554. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18555. properties:
  18556. accessToken:
  18557. description: AccessToken is used for authentication.
  18558. properties:
  18559. key:
  18560. description: |-
  18561. A key in the referenced Secret.
  18562. Some instances of this field may be defaulted, in others it may be required.
  18563. maxLength: 253
  18564. minLength: 1
  18565. pattern: ^[-._a-zA-Z0-9]+$
  18566. type: string
  18567. name:
  18568. description: The name of the Secret resource being referred to.
  18569. maxLength: 253
  18570. minLength: 1
  18571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18572. type: string
  18573. namespace:
  18574. description: |-
  18575. The namespace of the Secret resource being referred to.
  18576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18577. maxLength: 63
  18578. minLength: 1
  18579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18580. type: string
  18581. type: object
  18582. type: object
  18583. required:
  18584. - SecretRef
  18585. type: object
  18586. caBundle:
  18587. description: |-
  18588. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18589. can be performed.
  18590. format: byte
  18591. type: string
  18592. caProvider:
  18593. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18594. properties:
  18595. key:
  18596. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18597. maxLength: 253
  18598. minLength: 1
  18599. pattern: ^[-._a-zA-Z0-9]+$
  18600. type: string
  18601. name:
  18602. description: The name of the object located at the provider type.
  18603. maxLength: 253
  18604. minLength: 1
  18605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18606. type: string
  18607. namespace:
  18608. description: |-
  18609. The namespace the Provider type is in.
  18610. Can only be defined when used in a ClusterSecretStore.
  18611. maxLength: 63
  18612. minLength: 1
  18613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18614. type: string
  18615. type:
  18616. description: The type of provider to use such as "Secret", or "ConfigMap".
  18617. enum:
  18618. - Secret
  18619. - ConfigMap
  18620. type: string
  18621. required:
  18622. - name
  18623. - type
  18624. type: object
  18625. environment:
  18626. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18627. type: string
  18628. groupIDs:
  18629. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18630. items:
  18631. type: string
  18632. type: array
  18633. inheritFromGroups:
  18634. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18635. type: boolean
  18636. projectID:
  18637. description: ProjectID specifies a project where secrets are located.
  18638. type: string
  18639. url:
  18640. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18641. type: string
  18642. required:
  18643. - auth
  18644. type: object
  18645. ibm:
  18646. description: IBM configures this store to sync secrets using IBM Cloud provider
  18647. properties:
  18648. auth:
  18649. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18650. maxProperties: 1
  18651. minProperties: 1
  18652. properties:
  18653. containerAuth:
  18654. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18655. properties:
  18656. iamEndpoint:
  18657. type: string
  18658. profile:
  18659. description: the IBM Trusted Profile
  18660. type: string
  18661. tokenLocation:
  18662. description: Location the token is mounted on the pod
  18663. type: string
  18664. required:
  18665. - profile
  18666. type: object
  18667. secretRef:
  18668. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18669. properties:
  18670. iamEndpoint:
  18671. description: The IAM endpoint used to obain a token
  18672. type: string
  18673. secretApiKeySecretRef:
  18674. description: The SecretAccessKey is used for authentication
  18675. properties:
  18676. key:
  18677. description: |-
  18678. A key in the referenced Secret.
  18679. Some instances of this field may be defaulted, in others it may be required.
  18680. maxLength: 253
  18681. minLength: 1
  18682. pattern: ^[-._a-zA-Z0-9]+$
  18683. type: string
  18684. name:
  18685. description: The name of the Secret resource being referred to.
  18686. maxLength: 253
  18687. minLength: 1
  18688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18689. type: string
  18690. namespace:
  18691. description: |-
  18692. The namespace of the Secret resource being referred to.
  18693. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18694. maxLength: 63
  18695. minLength: 1
  18696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18697. type: string
  18698. type: object
  18699. type: object
  18700. type: object
  18701. serviceUrl:
  18702. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18703. type: string
  18704. required:
  18705. - auth
  18706. type: object
  18707. infisical:
  18708. description: Infisical configures this store to sync secrets using the Infisical provider
  18709. properties:
  18710. auth:
  18711. description: Auth configures how the Operator authenticates with the Infisical API
  18712. properties:
  18713. awsAuthCredentials:
  18714. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18715. properties:
  18716. identityId:
  18717. description: |-
  18718. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18719. In some instances, `key` is a required field.
  18720. properties:
  18721. key:
  18722. description: |-
  18723. A key in the referenced Secret.
  18724. Some instances of this field may be defaulted, in others it may be required.
  18725. maxLength: 253
  18726. minLength: 1
  18727. pattern: ^[-._a-zA-Z0-9]+$
  18728. type: string
  18729. name:
  18730. description: The name of the Secret resource being referred to.
  18731. maxLength: 253
  18732. minLength: 1
  18733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18734. type: string
  18735. namespace:
  18736. description: |-
  18737. The namespace of the Secret resource being referred to.
  18738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18739. maxLength: 63
  18740. minLength: 1
  18741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18742. type: string
  18743. type: object
  18744. required:
  18745. - identityId
  18746. type: object
  18747. azureAuthCredentials:
  18748. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18749. properties:
  18750. identityId:
  18751. description: |-
  18752. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18753. In some instances, `key` is a required field.
  18754. properties:
  18755. key:
  18756. description: |-
  18757. A key in the referenced Secret.
  18758. Some instances of this field may be defaulted, in others it may be required.
  18759. maxLength: 253
  18760. minLength: 1
  18761. pattern: ^[-._a-zA-Z0-9]+$
  18762. type: string
  18763. name:
  18764. description: The name of the Secret resource being referred to.
  18765. maxLength: 253
  18766. minLength: 1
  18767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18768. type: string
  18769. namespace:
  18770. description: |-
  18771. The namespace of the Secret resource being referred to.
  18772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18773. maxLength: 63
  18774. minLength: 1
  18775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18776. type: string
  18777. type: object
  18778. resource:
  18779. description: |-
  18780. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18781. In some instances, `key` is a required field.
  18782. properties:
  18783. key:
  18784. description: |-
  18785. A key in the referenced Secret.
  18786. Some instances of this field may be defaulted, in others it may be required.
  18787. maxLength: 253
  18788. minLength: 1
  18789. pattern: ^[-._a-zA-Z0-9]+$
  18790. type: string
  18791. name:
  18792. description: The name of the Secret resource being referred to.
  18793. maxLength: 253
  18794. minLength: 1
  18795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18796. type: string
  18797. namespace:
  18798. description: |-
  18799. The namespace of the Secret resource being referred to.
  18800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18801. maxLength: 63
  18802. minLength: 1
  18803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18804. type: string
  18805. type: object
  18806. required:
  18807. - identityId
  18808. type: object
  18809. gcpIamAuthCredentials:
  18810. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18811. properties:
  18812. identityId:
  18813. description: |-
  18814. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18815. In some instances, `key` is a required field.
  18816. properties:
  18817. key:
  18818. description: |-
  18819. A key in the referenced Secret.
  18820. Some instances of this field may be defaulted, in others it may be required.
  18821. maxLength: 253
  18822. minLength: 1
  18823. pattern: ^[-._a-zA-Z0-9]+$
  18824. type: string
  18825. name:
  18826. description: The name of the Secret resource being referred to.
  18827. maxLength: 253
  18828. minLength: 1
  18829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18830. type: string
  18831. namespace:
  18832. description: |-
  18833. The namespace of the Secret resource being referred to.
  18834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18835. maxLength: 63
  18836. minLength: 1
  18837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18838. type: string
  18839. type: object
  18840. serviceAccountKeyFilePath:
  18841. description: |-
  18842. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18843. In some instances, `key` is a required field.
  18844. properties:
  18845. key:
  18846. description: |-
  18847. A key in the referenced Secret.
  18848. Some instances of this field may be defaulted, in others it may be required.
  18849. maxLength: 253
  18850. minLength: 1
  18851. pattern: ^[-._a-zA-Z0-9]+$
  18852. type: string
  18853. name:
  18854. description: The name of the Secret resource being referred to.
  18855. maxLength: 253
  18856. minLength: 1
  18857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18858. type: string
  18859. namespace:
  18860. description: |-
  18861. The namespace of the Secret resource being referred to.
  18862. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18863. maxLength: 63
  18864. minLength: 1
  18865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18866. type: string
  18867. type: object
  18868. required:
  18869. - identityId
  18870. - serviceAccountKeyFilePath
  18871. type: object
  18872. gcpIdTokenAuthCredentials:
  18873. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18874. properties:
  18875. identityId:
  18876. description: |-
  18877. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18878. In some instances, `key` is a required field.
  18879. properties:
  18880. key:
  18881. description: |-
  18882. A key in the referenced Secret.
  18883. Some instances of this field may be defaulted, in others it may be required.
  18884. maxLength: 253
  18885. minLength: 1
  18886. pattern: ^[-._a-zA-Z0-9]+$
  18887. type: string
  18888. name:
  18889. description: The name of the Secret resource being referred to.
  18890. maxLength: 253
  18891. minLength: 1
  18892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18893. type: string
  18894. namespace:
  18895. description: |-
  18896. The namespace of the Secret resource being referred to.
  18897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18898. maxLength: 63
  18899. minLength: 1
  18900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18901. type: string
  18902. type: object
  18903. required:
  18904. - identityId
  18905. type: object
  18906. jwtAuthCredentials:
  18907. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18908. properties:
  18909. identityId:
  18910. description: |-
  18911. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18912. In some instances, `key` is a required field.
  18913. properties:
  18914. key:
  18915. description: |-
  18916. A key in the referenced Secret.
  18917. Some instances of this field may be defaulted, in others it may be required.
  18918. maxLength: 253
  18919. minLength: 1
  18920. pattern: ^[-._a-zA-Z0-9]+$
  18921. type: string
  18922. name:
  18923. description: The name of the Secret resource being referred to.
  18924. maxLength: 253
  18925. minLength: 1
  18926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18927. type: string
  18928. namespace:
  18929. description: |-
  18930. The namespace of the Secret resource being referred to.
  18931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18932. maxLength: 63
  18933. minLength: 1
  18934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18935. type: string
  18936. type: object
  18937. jwt:
  18938. description: |-
  18939. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18940. In some instances, `key` is a required field.
  18941. properties:
  18942. key:
  18943. description: |-
  18944. A key in the referenced Secret.
  18945. Some instances of this field may be defaulted, in others it may be required.
  18946. maxLength: 253
  18947. minLength: 1
  18948. pattern: ^[-._a-zA-Z0-9]+$
  18949. type: string
  18950. name:
  18951. description: The name of the Secret resource being referred to.
  18952. maxLength: 253
  18953. minLength: 1
  18954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18955. type: string
  18956. namespace:
  18957. description: |-
  18958. The namespace of the Secret resource being referred to.
  18959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18960. maxLength: 63
  18961. minLength: 1
  18962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18963. type: string
  18964. type: object
  18965. required:
  18966. - identityId
  18967. - jwt
  18968. type: object
  18969. kubernetesAuthCredentials:
  18970. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18971. properties:
  18972. identityId:
  18973. description: |-
  18974. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18975. In some instances, `key` is a required field.
  18976. properties:
  18977. key:
  18978. description: |-
  18979. A key in the referenced Secret.
  18980. Some instances of this field may be defaulted, in others it may be required.
  18981. maxLength: 253
  18982. minLength: 1
  18983. pattern: ^[-._a-zA-Z0-9]+$
  18984. type: string
  18985. name:
  18986. description: The name of the Secret resource being referred to.
  18987. maxLength: 253
  18988. minLength: 1
  18989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18990. type: string
  18991. namespace:
  18992. description: |-
  18993. The namespace of the Secret resource being referred to.
  18994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18995. maxLength: 63
  18996. minLength: 1
  18997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18998. type: string
  18999. type: object
  19000. serviceAccountTokenPath:
  19001. description: |-
  19002. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19003. In some instances, `key` is a required field.
  19004. properties:
  19005. key:
  19006. description: |-
  19007. A key in the referenced Secret.
  19008. Some instances of this field may be defaulted, in others it may be required.
  19009. maxLength: 253
  19010. minLength: 1
  19011. pattern: ^[-._a-zA-Z0-9]+$
  19012. type: string
  19013. name:
  19014. description: The name of the Secret resource being referred to.
  19015. maxLength: 253
  19016. minLength: 1
  19017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19018. type: string
  19019. namespace:
  19020. description: |-
  19021. The namespace of the Secret resource being referred to.
  19022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19023. maxLength: 63
  19024. minLength: 1
  19025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19026. type: string
  19027. type: object
  19028. required:
  19029. - identityId
  19030. type: object
  19031. ldapAuthCredentials:
  19032. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  19033. properties:
  19034. identityId:
  19035. description: |-
  19036. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19037. In some instances, `key` is a required field.
  19038. properties:
  19039. key:
  19040. description: |-
  19041. A key in the referenced Secret.
  19042. Some instances of this field may be defaulted, in others it may be required.
  19043. maxLength: 253
  19044. minLength: 1
  19045. pattern: ^[-._a-zA-Z0-9]+$
  19046. type: string
  19047. name:
  19048. description: The name of the Secret resource being referred to.
  19049. maxLength: 253
  19050. minLength: 1
  19051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19052. type: string
  19053. namespace:
  19054. description: |-
  19055. The namespace of the Secret resource being referred to.
  19056. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19057. maxLength: 63
  19058. minLength: 1
  19059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19060. type: string
  19061. type: object
  19062. ldapPassword:
  19063. description: |-
  19064. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19065. In some instances, `key` is a required field.
  19066. properties:
  19067. key:
  19068. description: |-
  19069. A key in the referenced Secret.
  19070. Some instances of this field may be defaulted, in others it may be required.
  19071. maxLength: 253
  19072. minLength: 1
  19073. pattern: ^[-._a-zA-Z0-9]+$
  19074. type: string
  19075. name:
  19076. description: The name of the Secret resource being referred to.
  19077. maxLength: 253
  19078. minLength: 1
  19079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19080. type: string
  19081. namespace:
  19082. description: |-
  19083. The namespace of the Secret resource being referred to.
  19084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19085. maxLength: 63
  19086. minLength: 1
  19087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19088. type: string
  19089. type: object
  19090. ldapUsername:
  19091. description: |-
  19092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19093. In some instances, `key` is a required field.
  19094. properties:
  19095. key:
  19096. description: |-
  19097. A key in the referenced Secret.
  19098. Some instances of this field may be defaulted, in others it may be required.
  19099. maxLength: 253
  19100. minLength: 1
  19101. pattern: ^[-._a-zA-Z0-9]+$
  19102. type: string
  19103. name:
  19104. description: The name of the Secret resource being referred to.
  19105. maxLength: 253
  19106. minLength: 1
  19107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19108. type: string
  19109. namespace:
  19110. description: |-
  19111. The namespace of the Secret resource being referred to.
  19112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19113. maxLength: 63
  19114. minLength: 1
  19115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19116. type: string
  19117. type: object
  19118. required:
  19119. - identityId
  19120. - ldapPassword
  19121. - ldapUsername
  19122. type: object
  19123. ociAuthCredentials:
  19124. description: OciAuthCredentials represents the credentials for OCI authentication.
  19125. properties:
  19126. fingerprint:
  19127. description: |-
  19128. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19129. In some instances, `key` is a required field.
  19130. properties:
  19131. key:
  19132. description: |-
  19133. A key in the referenced Secret.
  19134. Some instances of this field may be defaulted, in others it may be required.
  19135. maxLength: 253
  19136. minLength: 1
  19137. pattern: ^[-._a-zA-Z0-9]+$
  19138. type: string
  19139. name:
  19140. description: The name of the Secret resource being referred to.
  19141. maxLength: 253
  19142. minLength: 1
  19143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19144. type: string
  19145. namespace:
  19146. description: |-
  19147. The namespace of the Secret resource being referred to.
  19148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19149. maxLength: 63
  19150. minLength: 1
  19151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19152. type: string
  19153. type: object
  19154. identityId:
  19155. description: |-
  19156. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19157. In some instances, `key` is a required field.
  19158. properties:
  19159. key:
  19160. description: |-
  19161. A key in the referenced Secret.
  19162. Some instances of this field may be defaulted, in others it may be required.
  19163. maxLength: 253
  19164. minLength: 1
  19165. pattern: ^[-._a-zA-Z0-9]+$
  19166. type: string
  19167. name:
  19168. description: The name of the Secret resource being referred to.
  19169. maxLength: 253
  19170. minLength: 1
  19171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19172. type: string
  19173. namespace:
  19174. description: |-
  19175. The namespace of the Secret resource being referred to.
  19176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19177. maxLength: 63
  19178. minLength: 1
  19179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19180. type: string
  19181. type: object
  19182. privateKey:
  19183. description: |-
  19184. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19185. In some instances, `key` is a required field.
  19186. properties:
  19187. key:
  19188. description: |-
  19189. A key in the referenced Secret.
  19190. Some instances of this field may be defaulted, in others it may be required.
  19191. maxLength: 253
  19192. minLength: 1
  19193. pattern: ^[-._a-zA-Z0-9]+$
  19194. type: string
  19195. name:
  19196. description: The name of the Secret resource being referred to.
  19197. maxLength: 253
  19198. minLength: 1
  19199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19200. type: string
  19201. namespace:
  19202. description: |-
  19203. The namespace of the Secret resource being referred to.
  19204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19205. maxLength: 63
  19206. minLength: 1
  19207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19208. type: string
  19209. type: object
  19210. privateKeyPassphrase:
  19211. description: |-
  19212. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19213. In some instances, `key` is a required field.
  19214. properties:
  19215. key:
  19216. description: |-
  19217. A key in the referenced Secret.
  19218. Some instances of this field may be defaulted, in others it may be required.
  19219. maxLength: 253
  19220. minLength: 1
  19221. pattern: ^[-._a-zA-Z0-9]+$
  19222. type: string
  19223. name:
  19224. description: The name of the Secret resource being referred to.
  19225. maxLength: 253
  19226. minLength: 1
  19227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19228. type: string
  19229. namespace:
  19230. description: |-
  19231. The namespace of the Secret resource being referred to.
  19232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19233. maxLength: 63
  19234. minLength: 1
  19235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19236. type: string
  19237. type: object
  19238. region:
  19239. description: |-
  19240. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19241. In some instances, `key` is a required field.
  19242. properties:
  19243. key:
  19244. description: |-
  19245. A key in the referenced Secret.
  19246. Some instances of this field may be defaulted, in others it may be required.
  19247. maxLength: 253
  19248. minLength: 1
  19249. pattern: ^[-._a-zA-Z0-9]+$
  19250. type: string
  19251. name:
  19252. description: The name of the Secret resource being referred to.
  19253. maxLength: 253
  19254. minLength: 1
  19255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19256. type: string
  19257. namespace:
  19258. description: |-
  19259. The namespace of the Secret resource being referred to.
  19260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19261. maxLength: 63
  19262. minLength: 1
  19263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19264. type: string
  19265. type: object
  19266. tenancyId:
  19267. description: |-
  19268. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19269. In some instances, `key` is a required field.
  19270. properties:
  19271. key:
  19272. description: |-
  19273. A key in the referenced Secret.
  19274. Some instances of this field may be defaulted, in others it may be required.
  19275. maxLength: 253
  19276. minLength: 1
  19277. pattern: ^[-._a-zA-Z0-9]+$
  19278. type: string
  19279. name:
  19280. description: The name of the Secret resource being referred to.
  19281. maxLength: 253
  19282. minLength: 1
  19283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19284. type: string
  19285. namespace:
  19286. description: |-
  19287. The namespace of the Secret resource being referred to.
  19288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19289. maxLength: 63
  19290. minLength: 1
  19291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19292. type: string
  19293. type: object
  19294. userId:
  19295. description: |-
  19296. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19297. In some instances, `key` is a required field.
  19298. properties:
  19299. key:
  19300. description: |-
  19301. A key in the referenced Secret.
  19302. Some instances of this field may be defaulted, in others it may be required.
  19303. maxLength: 253
  19304. minLength: 1
  19305. pattern: ^[-._a-zA-Z0-9]+$
  19306. type: string
  19307. name:
  19308. description: The name of the Secret resource being referred to.
  19309. maxLength: 253
  19310. minLength: 1
  19311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19312. type: string
  19313. namespace:
  19314. description: |-
  19315. The namespace of the Secret resource being referred to.
  19316. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19317. maxLength: 63
  19318. minLength: 1
  19319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19320. type: string
  19321. type: object
  19322. required:
  19323. - fingerprint
  19324. - identityId
  19325. - privateKey
  19326. - region
  19327. - tenancyId
  19328. - userId
  19329. type: object
  19330. tokenAuthCredentials:
  19331. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  19332. properties:
  19333. accessToken:
  19334. description: |-
  19335. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19336. In some instances, `key` is a required field.
  19337. properties:
  19338. key:
  19339. description: |-
  19340. A key in the referenced Secret.
  19341. Some instances of this field may be defaulted, in others it may be required.
  19342. maxLength: 253
  19343. minLength: 1
  19344. pattern: ^[-._a-zA-Z0-9]+$
  19345. type: string
  19346. name:
  19347. description: The name of the Secret resource being referred to.
  19348. maxLength: 253
  19349. minLength: 1
  19350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19351. type: string
  19352. namespace:
  19353. description: |-
  19354. The namespace of the Secret resource being referred to.
  19355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19356. maxLength: 63
  19357. minLength: 1
  19358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19359. type: string
  19360. type: object
  19361. required:
  19362. - accessToken
  19363. type: object
  19364. universalAuthCredentials:
  19365. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19366. properties:
  19367. clientId:
  19368. description: |-
  19369. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19370. In some instances, `key` is a required field.
  19371. properties:
  19372. key:
  19373. description: |-
  19374. A key in the referenced Secret.
  19375. Some instances of this field may be defaulted, in others it may be required.
  19376. maxLength: 253
  19377. minLength: 1
  19378. pattern: ^[-._a-zA-Z0-9]+$
  19379. type: string
  19380. name:
  19381. description: The name of the Secret resource being referred to.
  19382. maxLength: 253
  19383. minLength: 1
  19384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19385. type: string
  19386. namespace:
  19387. description: |-
  19388. The namespace of the Secret resource being referred to.
  19389. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19390. maxLength: 63
  19391. minLength: 1
  19392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19393. type: string
  19394. type: object
  19395. clientSecret:
  19396. description: |-
  19397. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19398. In some instances, `key` is a required field.
  19399. properties:
  19400. key:
  19401. description: |-
  19402. A key in the referenced Secret.
  19403. Some instances of this field may be defaulted, in others it may be required.
  19404. maxLength: 253
  19405. minLength: 1
  19406. pattern: ^[-._a-zA-Z0-9]+$
  19407. type: string
  19408. name:
  19409. description: The name of the Secret resource being referred to.
  19410. maxLength: 253
  19411. minLength: 1
  19412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19413. type: string
  19414. namespace:
  19415. description: |-
  19416. The namespace of the Secret resource being referred to.
  19417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19418. maxLength: 63
  19419. minLength: 1
  19420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19421. type: string
  19422. type: object
  19423. required:
  19424. - clientId
  19425. - clientSecret
  19426. type: object
  19427. type: object
  19428. caBundle:
  19429. description: |-
  19430. CABundle is a PEM-encoded CA certificate bundle used to validate
  19431. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19432. format: byte
  19433. type: string
  19434. caProvider:
  19435. description: |-
  19436. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19437. The certificate is used to validate the Infisical server's TLS certificate.
  19438. Mutually exclusive with CABundle.
  19439. properties:
  19440. key:
  19441. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19442. maxLength: 253
  19443. minLength: 1
  19444. pattern: ^[-._a-zA-Z0-9]+$
  19445. type: string
  19446. name:
  19447. description: The name of the object located at the provider type.
  19448. maxLength: 253
  19449. minLength: 1
  19450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19451. type: string
  19452. namespace:
  19453. description: |-
  19454. The namespace the Provider type is in.
  19455. Can only be defined when used in a ClusterSecretStore.
  19456. maxLength: 63
  19457. minLength: 1
  19458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19459. type: string
  19460. type:
  19461. description: The type of provider to use such as "Secret", or "ConfigMap".
  19462. enum:
  19463. - Secret
  19464. - ConfigMap
  19465. type: string
  19466. required:
  19467. - name
  19468. - type
  19469. type: object
  19470. hostAPI:
  19471. default: https://app.infisical.com/api
  19472. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19473. type: string
  19474. secretsScope:
  19475. description: SecretsScope defines the scope of the secrets within the workspace
  19476. properties:
  19477. environmentSlug:
  19478. description: EnvironmentSlug is the required slug identifier for the environment.
  19479. type: string
  19480. expandSecretReferences:
  19481. default: true
  19482. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19483. type: boolean
  19484. organizationSlug:
  19485. description: |-
  19486. OrganizationSlug is the optional slug that identifies the organization that will be used
  19487. during authentication. Useful for sub-organization setups
  19488. type: string
  19489. projectSlug:
  19490. description: ProjectSlug is the required slug identifier for the project.
  19491. type: string
  19492. recursive:
  19493. default: false
  19494. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19495. type: boolean
  19496. secretsPath:
  19497. default: /
  19498. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19499. type: string
  19500. required:
  19501. - environmentSlug
  19502. - projectSlug
  19503. type: object
  19504. required:
  19505. - auth
  19506. - secretsScope
  19507. type: object
  19508. keepersecurity:
  19509. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19510. properties:
  19511. authRef:
  19512. description: |-
  19513. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19514. In some instances, `key` is a required field.
  19515. properties:
  19516. key:
  19517. description: |-
  19518. A key in the referenced Secret.
  19519. Some instances of this field may be defaulted, in others it may be required.
  19520. maxLength: 253
  19521. minLength: 1
  19522. pattern: ^[-._a-zA-Z0-9]+$
  19523. type: string
  19524. name:
  19525. description: The name of the Secret resource being referred to.
  19526. maxLength: 253
  19527. minLength: 1
  19528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19529. type: string
  19530. namespace:
  19531. description: |-
  19532. The namespace of the Secret resource being referred to.
  19533. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19534. maxLength: 63
  19535. minLength: 1
  19536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19537. type: string
  19538. type: object
  19539. folderID:
  19540. type: string
  19541. getByTitleFallback:
  19542. type: boolean
  19543. required:
  19544. - authRef
  19545. - folderID
  19546. type: object
  19547. kubernetes:
  19548. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19549. properties:
  19550. auth:
  19551. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19552. maxProperties: 1
  19553. minProperties: 1
  19554. properties:
  19555. cert:
  19556. description: has both clientCert and clientKey as secretKeySelector
  19557. properties:
  19558. clientCert:
  19559. description: |-
  19560. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19561. In some instances, `key` is a required field.
  19562. properties:
  19563. key:
  19564. description: |-
  19565. A key in the referenced Secret.
  19566. Some instances of this field may be defaulted, in others it may be required.
  19567. maxLength: 253
  19568. minLength: 1
  19569. pattern: ^[-._a-zA-Z0-9]+$
  19570. type: string
  19571. name:
  19572. description: The name of the Secret resource being referred to.
  19573. maxLength: 253
  19574. minLength: 1
  19575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19576. type: string
  19577. namespace:
  19578. description: |-
  19579. The namespace of the Secret resource being referred to.
  19580. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19581. maxLength: 63
  19582. minLength: 1
  19583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19584. type: string
  19585. type: object
  19586. clientKey:
  19587. description: |-
  19588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19589. In some instances, `key` is a required field.
  19590. properties:
  19591. key:
  19592. description: |-
  19593. A key in the referenced Secret.
  19594. Some instances of this field may be defaulted, in others it may be required.
  19595. maxLength: 253
  19596. minLength: 1
  19597. pattern: ^[-._a-zA-Z0-9]+$
  19598. type: string
  19599. name:
  19600. description: The name of the Secret resource being referred to.
  19601. maxLength: 253
  19602. minLength: 1
  19603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19604. type: string
  19605. namespace:
  19606. description: |-
  19607. The namespace of the Secret resource being referred to.
  19608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19609. maxLength: 63
  19610. minLength: 1
  19611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19612. type: string
  19613. type: object
  19614. required:
  19615. - clientCert
  19616. - clientKey
  19617. type: object
  19618. serviceAccount:
  19619. description: points to a service account that should be used for authentication
  19620. properties:
  19621. audiences:
  19622. description: |-
  19623. Audience specifies the `aud` claim for the service account token
  19624. Some providers automatically extend the audience field based on well-known annotations for workload
  19625. identity (e.g. IRSA or GCP Workload Identity)
  19626. items:
  19627. type: string
  19628. type: array
  19629. name:
  19630. description: The name of the ServiceAccount resource being referred to.
  19631. maxLength: 253
  19632. minLength: 1
  19633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19634. type: string
  19635. namespace:
  19636. description: |-
  19637. Namespace of the resource being referred to.
  19638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19639. maxLength: 63
  19640. minLength: 1
  19641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19642. type: string
  19643. required:
  19644. - name
  19645. type: object
  19646. token:
  19647. description: use static token to authenticate with
  19648. properties:
  19649. bearerToken:
  19650. description: |-
  19651. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19652. In some instances, `key` is a required field.
  19653. properties:
  19654. key:
  19655. description: |-
  19656. A key in the referenced Secret.
  19657. Some instances of this field may be defaulted, in others it may be required.
  19658. maxLength: 253
  19659. minLength: 1
  19660. pattern: ^[-._a-zA-Z0-9]+$
  19661. type: string
  19662. name:
  19663. description: The name of the Secret resource being referred to.
  19664. maxLength: 253
  19665. minLength: 1
  19666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19667. type: string
  19668. namespace:
  19669. description: |-
  19670. The namespace of the Secret resource being referred to.
  19671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19672. maxLength: 63
  19673. minLength: 1
  19674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19675. type: string
  19676. type: object
  19677. required:
  19678. - bearerToken
  19679. type: object
  19680. type: object
  19681. authRef:
  19682. description: A reference to a secret that contains the auth information.
  19683. properties:
  19684. key:
  19685. description: |-
  19686. A key in the referenced Secret.
  19687. Some instances of this field may be defaulted, in others it may be required.
  19688. maxLength: 253
  19689. minLength: 1
  19690. pattern: ^[-._a-zA-Z0-9]+$
  19691. type: string
  19692. name:
  19693. description: The name of the Secret resource being referred to.
  19694. maxLength: 253
  19695. minLength: 1
  19696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19697. type: string
  19698. namespace:
  19699. description: |-
  19700. The namespace of the Secret resource being referred to.
  19701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19702. maxLength: 63
  19703. minLength: 1
  19704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19705. type: string
  19706. type: object
  19707. remoteNamespace:
  19708. default: default
  19709. description: Remote namespace to fetch the secrets from
  19710. maxLength: 63
  19711. minLength: 1
  19712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19713. type: string
  19714. server:
  19715. description: configures the Kubernetes server Address.
  19716. properties:
  19717. caBundle:
  19718. description: CABundle is a base64-encoded CA certificate
  19719. format: byte
  19720. type: string
  19721. caProvider:
  19722. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19723. properties:
  19724. key:
  19725. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19726. maxLength: 253
  19727. minLength: 1
  19728. pattern: ^[-._a-zA-Z0-9]+$
  19729. type: string
  19730. name:
  19731. description: The name of the object located at the provider type.
  19732. maxLength: 253
  19733. minLength: 1
  19734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19735. type: string
  19736. namespace:
  19737. description: |-
  19738. The namespace the Provider type is in.
  19739. Can only be defined when used in a ClusterSecretStore.
  19740. maxLength: 63
  19741. minLength: 1
  19742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19743. type: string
  19744. type:
  19745. description: The type of provider to use such as "Secret", or "ConfigMap".
  19746. enum:
  19747. - Secret
  19748. - ConfigMap
  19749. type: string
  19750. required:
  19751. - name
  19752. - type
  19753. type: object
  19754. url:
  19755. default: kubernetes.default
  19756. description: configures the Kubernetes server Address.
  19757. type: string
  19758. type: object
  19759. type: object
  19760. nebiusmysterybox:
  19761. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19762. properties:
  19763. apiDomain:
  19764. description: NebiusMysterybox API endpoint
  19765. type: string
  19766. auth:
  19767. description: Auth defines parameters to authenticate in MysteryBox
  19768. properties:
  19769. serviceAccountCredsSecretRef:
  19770. description: |-
  19771. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19772. document with service account credentials used to get an IAM token.
  19773. Expected JSON structure:
  19774. {
  19775. "subject-credentials": {
  19776. "alg": "RS256",
  19777. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19778. "kid": "<public-key-id>",
  19779. "iss": "<issuer-service-account-id>",
  19780. "sub": "<subject-service-account-id>"
  19781. }
  19782. }
  19783. properties:
  19784. key:
  19785. description: |-
  19786. A key in the referenced Secret.
  19787. Some instances of this field may be defaulted, in others it may be required.
  19788. maxLength: 253
  19789. minLength: 1
  19790. pattern: ^[-._a-zA-Z0-9]+$
  19791. type: string
  19792. name:
  19793. description: The name of the Secret resource being referred to.
  19794. maxLength: 253
  19795. minLength: 1
  19796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19797. type: string
  19798. namespace:
  19799. description: |-
  19800. The namespace of the Secret resource being referred to.
  19801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19802. maxLength: 63
  19803. minLength: 1
  19804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19805. type: string
  19806. type: object
  19807. tokenSecretRef:
  19808. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19809. properties:
  19810. key:
  19811. description: |-
  19812. A key in the referenced Secret.
  19813. Some instances of this field may be defaulted, in others it may be required.
  19814. maxLength: 253
  19815. minLength: 1
  19816. pattern: ^[-._a-zA-Z0-9]+$
  19817. type: string
  19818. name:
  19819. description: The name of the Secret resource being referred to.
  19820. maxLength: 253
  19821. minLength: 1
  19822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19823. type: string
  19824. namespace:
  19825. description: |-
  19826. The namespace of the Secret resource being referred to.
  19827. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19828. maxLength: 63
  19829. minLength: 1
  19830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19831. type: string
  19832. type: object
  19833. workloadIdentity:
  19834. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  19835. properties:
  19836. iamServiceAccountID:
  19837. description: |-
  19838. IAMServiceAccountID is the Nebius IAM service account identifier that the
  19839. federated Kubernetes service account should impersonate during token exchange.
  19840. example: serviceaccount-e00example
  19841. minLength: 1
  19842. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  19843. type: string
  19844. serviceAccountRef:
  19845. description: |-
  19846. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  19847. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  19848. Nebius IAM token using workload federation.
  19849. properties:
  19850. audiences:
  19851. description: |-
  19852. Audience specifies the `aud` claim for the service account token
  19853. Some providers automatically extend the audience field based on well-known annotations for workload
  19854. identity (e.g. IRSA or GCP Workload Identity)
  19855. items:
  19856. type: string
  19857. type: array
  19858. name:
  19859. description: The name of the ServiceAccount resource being referred to.
  19860. maxLength: 253
  19861. minLength: 1
  19862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19863. type: string
  19864. namespace:
  19865. description: |-
  19866. Namespace of the resource being referred to.
  19867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19868. maxLength: 63
  19869. minLength: 1
  19870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19871. type: string
  19872. required:
  19873. - name
  19874. type: object
  19875. required:
  19876. - iamServiceAccountID
  19877. - serviceAccountRef
  19878. type: object
  19879. type: object
  19880. x-kubernetes-validations:
  19881. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  19882. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  19883. caProvider:
  19884. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19885. properties:
  19886. certSecretRef:
  19887. description: |-
  19888. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19889. In some instances, `key` is a required field.
  19890. properties:
  19891. key:
  19892. description: |-
  19893. A key in the referenced Secret.
  19894. Some instances of this field may be defaulted, in others it may be required.
  19895. maxLength: 253
  19896. minLength: 1
  19897. pattern: ^[-._a-zA-Z0-9]+$
  19898. type: string
  19899. name:
  19900. description: The name of the Secret resource being referred to.
  19901. maxLength: 253
  19902. minLength: 1
  19903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19904. type: string
  19905. namespace:
  19906. description: |-
  19907. The namespace of the Secret resource being referred to.
  19908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19909. maxLength: 63
  19910. minLength: 1
  19911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19912. type: string
  19913. type: object
  19914. type: object
  19915. required:
  19916. - apiDomain
  19917. - auth
  19918. type: object
  19919. ngrok:
  19920. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19921. properties:
  19922. apiUrl:
  19923. default: https://api.ngrok.com
  19924. description: APIURL is the URL of the ngrok API.
  19925. type: string
  19926. auth:
  19927. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19928. maxProperties: 1
  19929. minProperties: 1
  19930. properties:
  19931. apiKey:
  19932. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19933. properties:
  19934. secretRef:
  19935. description: SecretRef is a reference to a secret containing the ngrok API key.
  19936. properties:
  19937. key:
  19938. description: |-
  19939. A key in the referenced Secret.
  19940. Some instances of this field may be defaulted, in others it may be required.
  19941. maxLength: 253
  19942. minLength: 1
  19943. pattern: ^[-._a-zA-Z0-9]+$
  19944. type: string
  19945. name:
  19946. description: The name of the Secret resource being referred to.
  19947. maxLength: 253
  19948. minLength: 1
  19949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19950. type: string
  19951. namespace:
  19952. description: |-
  19953. The namespace of the Secret resource being referred to.
  19954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19955. maxLength: 63
  19956. minLength: 1
  19957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19958. type: string
  19959. type: object
  19960. type: object
  19961. type: object
  19962. vault:
  19963. description: Vault configures the ngrok vault to sync secrets with.
  19964. properties:
  19965. name:
  19966. description: Name is the name of the ngrok vault to sync secrets with.
  19967. type: string
  19968. required:
  19969. - name
  19970. type: object
  19971. required:
  19972. - auth
  19973. - vault
  19974. type: object
  19975. onboardbase:
  19976. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19977. properties:
  19978. apiHost:
  19979. default: https://public.onboardbase.com/api/v1/
  19980. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19981. type: string
  19982. auth:
  19983. description: Auth configures how the Operator authenticates with the Onboardbase API
  19984. properties:
  19985. apiKeyRef:
  19986. description: |-
  19987. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19988. It is used to recognize and authorize access to a project and environment within onboardbase
  19989. properties:
  19990. key:
  19991. description: |-
  19992. A key in the referenced Secret.
  19993. Some instances of this field may be defaulted, in others it may be required.
  19994. maxLength: 253
  19995. minLength: 1
  19996. pattern: ^[-._a-zA-Z0-9]+$
  19997. type: string
  19998. name:
  19999. description: The name of the Secret resource being referred to.
  20000. maxLength: 253
  20001. minLength: 1
  20002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20003. type: string
  20004. namespace:
  20005. description: |-
  20006. The namespace of the Secret resource being referred to.
  20007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20008. maxLength: 63
  20009. minLength: 1
  20010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20011. type: string
  20012. type: object
  20013. passcodeRef:
  20014. description: OnboardbasePasscode is the passcode attached to the API Key
  20015. properties:
  20016. key:
  20017. description: |-
  20018. A key in the referenced Secret.
  20019. Some instances of this field may be defaulted, in others it may be required.
  20020. maxLength: 253
  20021. minLength: 1
  20022. pattern: ^[-._a-zA-Z0-9]+$
  20023. type: string
  20024. name:
  20025. description: The name of the Secret resource being referred to.
  20026. maxLength: 253
  20027. minLength: 1
  20028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20029. type: string
  20030. namespace:
  20031. description: |-
  20032. The namespace of the Secret resource being referred to.
  20033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20034. maxLength: 63
  20035. minLength: 1
  20036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20037. type: string
  20038. type: object
  20039. required:
  20040. - apiKeyRef
  20041. - passcodeRef
  20042. type: object
  20043. environment:
  20044. default: development
  20045. description: Environment is the name of an environmnent within a project to pull the secrets from
  20046. type: string
  20047. project:
  20048. default: development
  20049. description: Project is an onboardbase project that the secrets should be pulled from
  20050. type: string
  20051. required:
  20052. - apiHost
  20053. - auth
  20054. - environment
  20055. - project
  20056. type: object
  20057. onepassword:
  20058. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  20059. properties:
  20060. auth:
  20061. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  20062. properties:
  20063. secretRef:
  20064. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  20065. properties:
  20066. connectTokenSecretRef:
  20067. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  20068. properties:
  20069. key:
  20070. description: |-
  20071. A key in the referenced Secret.
  20072. Some instances of this field may be defaulted, in others it may be required.
  20073. maxLength: 253
  20074. minLength: 1
  20075. pattern: ^[-._a-zA-Z0-9]+$
  20076. type: string
  20077. name:
  20078. description: The name of the Secret resource being referred to.
  20079. maxLength: 253
  20080. minLength: 1
  20081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20082. type: string
  20083. namespace:
  20084. description: |-
  20085. The namespace of the Secret resource being referred to.
  20086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20087. maxLength: 63
  20088. minLength: 1
  20089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20090. type: string
  20091. type: object
  20092. required:
  20093. - connectTokenSecretRef
  20094. type: object
  20095. required:
  20096. - secretRef
  20097. type: object
  20098. connectHost:
  20099. description: ConnectHost defines the OnePassword Connect Server to connect to
  20100. type: string
  20101. vaults:
  20102. additionalProperties:
  20103. type: integer
  20104. description: Vaults defines which OnePassword vaults to search in which order
  20105. type: object
  20106. required:
  20107. - auth
  20108. - connectHost
  20109. - vaults
  20110. type: object
  20111. onepasswordSDK:
  20112. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  20113. properties:
  20114. auth:
  20115. description: Auth defines the information necessary to authenticate against OnePassword API.
  20116. properties:
  20117. serviceAccountSecretRef:
  20118. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  20119. properties:
  20120. key:
  20121. description: |-
  20122. A key in the referenced Secret.
  20123. Some instances of this field may be defaulted, in others it may be required.
  20124. maxLength: 253
  20125. minLength: 1
  20126. pattern: ^[-._a-zA-Z0-9]+$
  20127. type: string
  20128. name:
  20129. description: The name of the Secret resource being referred to.
  20130. maxLength: 253
  20131. minLength: 1
  20132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20133. type: string
  20134. namespace:
  20135. description: |-
  20136. The namespace of the Secret resource being referred to.
  20137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20138. maxLength: 63
  20139. minLength: 1
  20140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20141. type: string
  20142. type: object
  20143. required:
  20144. - serviceAccountSecretRef
  20145. type: object
  20146. cache:
  20147. description: |-
  20148. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  20149. When enabled, secrets are cached with the specified TTL.
  20150. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  20151. If omitted, caching is disabled (default).
  20152. cache: {} is a valid option to set.
  20153. properties:
  20154. maxSize:
  20155. default: 100
  20156. description: |-
  20157. MaxSize is the maximum number of secrets to cache.
  20158. When the cache is full, least-recently-used entries are evicted.
  20159. minimum: 1
  20160. type: integer
  20161. ttl:
  20162. default: 5m
  20163. description: |-
  20164. TTL is the time-to-live for cached secrets.
  20165. Format: duration string (e.g., "5m", "1h", "30s")
  20166. type: string
  20167. type: object
  20168. environment:
  20169. description: |-
  20170. Environment defines the 1Password Environment ID to read variables from.
  20171. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  20172. Mutually exclusive with Vault.
  20173. type: string
  20174. integrationInfo:
  20175. description: |-
  20176. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  20177. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  20178. properties:
  20179. name:
  20180. default: 1Password SDK
  20181. description: Name defaults to "1Password SDK".
  20182. type: string
  20183. version:
  20184. default: v1.0.0
  20185. description: Version defaults to "v1.0.0".
  20186. type: string
  20187. type: object
  20188. vault:
  20189. description: |-
  20190. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  20191. Mutually exclusive with Environment.
  20192. type: string
  20193. required:
  20194. - auth
  20195. type: object
  20196. x-kubernetes-validations:
  20197. - message: at most one of the fields in [vault environment] may be set
  20198. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  20199. openBao:
  20200. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  20201. properties:
  20202. auth:
  20203. description: Auth configures how secret-manager authenticates with the OpenBao server.
  20204. properties:
  20205. appRole:
  20206. description: |-
  20207. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  20208. with the role and secret stored in a Kubernetes Secret resource.
  20209. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  20210. properties:
  20211. path:
  20212. default: approle
  20213. description: |-
  20214. Path where the App Role authentication backend is mounted
  20215. in OpenBao, e.g: "approle"
  20216. type: string
  20217. roleId:
  20218. description: |-
  20219. RoleID configured in the App Role authentication backend when setting
  20220. up the authentication backend in OpenBao.
  20221. minLength: 1
  20222. type: string
  20223. roleRef:
  20224. description: |-
  20225. Reference to a key in a Secret that contains the App Role ID used
  20226. to authenticate with OpenBao.
  20227. The `key` field must be specified and denotes which entry within the Secret
  20228. resource is used as the app role id.
  20229. properties:
  20230. key:
  20231. description: |-
  20232. A key in the referenced Secret.
  20233. Some instances of this field may be defaulted, in others it may be required.
  20234. maxLength: 253
  20235. minLength: 1
  20236. pattern: ^[-._a-zA-Z0-9]+$
  20237. type: string
  20238. name:
  20239. description: The name of the Secret resource being referred to.
  20240. maxLength: 253
  20241. minLength: 1
  20242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20243. type: string
  20244. namespace:
  20245. description: |-
  20246. The namespace of the Secret resource being referred to.
  20247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20248. maxLength: 63
  20249. minLength: 1
  20250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20251. type: string
  20252. type: object
  20253. secretRef:
  20254. description: |-
  20255. Reference to a key in a Secret that contains the App Role secret used
  20256. to authenticate with OpenBao.
  20257. The `key` field must be specified and denotes which entry within the Secret
  20258. resource is used as the app role secret.
  20259. properties:
  20260. key:
  20261. description: |-
  20262. A key in the referenced Secret.
  20263. Some instances of this field may be defaulted, in others it may be required.
  20264. maxLength: 253
  20265. minLength: 1
  20266. pattern: ^[-._a-zA-Z0-9]+$
  20267. type: string
  20268. name:
  20269. description: The name of the Secret resource being referred to.
  20270. maxLength: 253
  20271. minLength: 1
  20272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20273. type: string
  20274. namespace:
  20275. description: |-
  20276. The namespace of the Secret resource being referred to.
  20277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20278. maxLength: 63
  20279. minLength: 1
  20280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20281. type: string
  20282. type: object
  20283. required:
  20284. - path
  20285. - secretRef
  20286. type: object
  20287. x-kubernetes-validations:
  20288. - message: exactly one of the fields in [roleId roleRef] must be set
  20289. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  20290. kubernetes:
  20291. description: |-
  20292. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  20293. token to the [Kubernetes auth mechanism].
  20294. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  20295. properties:
  20296. path:
  20297. default: kubernetes
  20298. description: |-
  20299. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  20300. "kubernetes"
  20301. type: string
  20302. role:
  20303. description: |-
  20304. A required field containing the OpenBao Role to assume. A Role binds a
  20305. Kubernetes ServiceAccount with a set of OpenBao policies.
  20306. minLength: 1
  20307. type: string
  20308. secretRef:
  20309. description: |-
  20310. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20311. for authenticating with OpenBao. If a name is specified without a key,
  20312. `token` is the default.
  20313. properties:
  20314. key:
  20315. description: |-
  20316. A key in the referenced Secret.
  20317. Some instances of this field may be defaulted, in others it may be required.
  20318. maxLength: 253
  20319. minLength: 1
  20320. pattern: ^[-._a-zA-Z0-9]+$
  20321. type: string
  20322. name:
  20323. description: The name of the Secret resource being referred to.
  20324. maxLength: 253
  20325. minLength: 1
  20326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20327. type: string
  20328. namespace:
  20329. description: |-
  20330. The namespace of the Secret resource being referred to.
  20331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20332. maxLength: 63
  20333. minLength: 1
  20334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20335. type: string
  20336. type: object
  20337. serviceAccountRef:
  20338. description: |-
  20339. Optional service account field containing the name of a Kubernetes ServiceAccount.
  20340. If the service account is specified, a token will be requested from the Kubernetes
  20341. TokenRequest API for authenticating with OpenBao.
  20342. Any configured audiences will be passed to the TokenRequest as-is.
  20343. properties:
  20344. audiences:
  20345. description: |-
  20346. Audience specifies the `aud` claim for the service account token
  20347. Some providers automatically extend the audience field based on well-known annotations for workload
  20348. identity (e.g. IRSA or GCP Workload Identity)
  20349. items:
  20350. type: string
  20351. type: array
  20352. name:
  20353. description: The name of the ServiceAccount resource being referred to.
  20354. maxLength: 253
  20355. minLength: 1
  20356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20357. type: string
  20358. namespace:
  20359. description: |-
  20360. Namespace of the resource being referred to.
  20361. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20362. maxLength: 63
  20363. minLength: 1
  20364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20365. type: string
  20366. required:
  20367. - name
  20368. type: object
  20369. required:
  20370. - path
  20371. - role
  20372. type: object
  20373. x-kubernetes-validations:
  20374. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  20375. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  20376. namespace:
  20377. description: |-
  20378. Name of the [OpenBao Namespace] to authenticate to. This can be different
  20379. than the namespace your secret is in. Namespaces is a set of features
  20380. within OpenBao that allows OpenBao environments to support secure
  20381. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  20382. if set, or empty otherwise
  20383. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20384. type: string
  20385. tokenSecretRef:
  20386. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  20387. properties:
  20388. key:
  20389. description: |-
  20390. A key in the referenced Secret.
  20391. Some instances of this field may be defaulted, in others it may be required.
  20392. maxLength: 253
  20393. minLength: 1
  20394. pattern: ^[-._a-zA-Z0-9]+$
  20395. type: string
  20396. name:
  20397. description: The name of the Secret resource being referred to.
  20398. maxLength: 253
  20399. minLength: 1
  20400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20401. type: string
  20402. namespace:
  20403. description: |-
  20404. The namespace of the Secret resource being referred to.
  20405. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20406. maxLength: 63
  20407. minLength: 1
  20408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20409. type: string
  20410. type: object
  20411. userPass:
  20412. description: UserPass authenticates with OpenBao by passing a username/password pair
  20413. properties:
  20414. path:
  20415. default: userpass
  20416. description: |-
  20417. Path where the UserPassword authentication backend is mounted
  20418. in OpenBao, e.g: "userpass"
  20419. type: string
  20420. secretRef:
  20421. description: |-
  20422. SecretRef to a key in a Secret resource containing password for the user
  20423. used to authenticate with OpenBao using the [UserPass authentication
  20424. method]
  20425. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20426. properties:
  20427. key:
  20428. description: |-
  20429. A key in the referenced Secret.
  20430. Some instances of this field may be defaulted, in others it may be required.
  20431. maxLength: 253
  20432. minLength: 1
  20433. pattern: ^[-._a-zA-Z0-9]+$
  20434. type: string
  20435. name:
  20436. description: The name of the Secret resource being referred to.
  20437. maxLength: 253
  20438. minLength: 1
  20439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20440. type: string
  20441. namespace:
  20442. description: |-
  20443. The namespace of the Secret resource being referred to.
  20444. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20445. maxLength: 63
  20446. minLength: 1
  20447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20448. type: string
  20449. type: object
  20450. username:
  20451. description: |-
  20452. Username is a username used to authenticate using the [UserPass
  20453. authentication method]
  20454. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20455. type: string
  20456. required:
  20457. - path
  20458. - username
  20459. type: object
  20460. type: object
  20461. x-kubernetes-validations:
  20462. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  20463. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  20464. caBundle:
  20465. description: |-
  20466. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20467. this and `caProvider` are not set the system root certificates are used
  20468. to validate the TLS connection.
  20469. format: byte
  20470. type: string
  20471. caProvider:
  20472. description: |-
  20473. The provider for the CA bundle to use to validate OpenBao server
  20474. certificate. If this and `caBundle` are not set the system root
  20475. certificates are used to validate the TLS connection.
  20476. properties:
  20477. key:
  20478. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20479. maxLength: 253
  20480. minLength: 1
  20481. pattern: ^[-._a-zA-Z0-9]+$
  20482. type: string
  20483. name:
  20484. description: The name of the object located at the provider type.
  20485. maxLength: 253
  20486. minLength: 1
  20487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20488. type: string
  20489. namespace:
  20490. description: |-
  20491. The namespace the Provider type is in.
  20492. Can only be defined when used in a ClusterSecretStore.
  20493. maxLength: 63
  20494. minLength: 1
  20495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20496. type: string
  20497. type:
  20498. description: The type of provider to use such as "Secret", or "ConfigMap".
  20499. enum:
  20500. - Secret
  20501. - ConfigMap
  20502. type: string
  20503. required:
  20504. - name
  20505. - type
  20506. type: object
  20507. namespace:
  20508. description: |-
  20509. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20510. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20511. e.g: "ns1".
  20512. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20513. type: string
  20514. path:
  20515. description: |-
  20516. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20517. "secret". The v2 KV secret engine version specific "/data" path suffix
  20518. for fetching secrets from OpenBao is optional and will be appended
  20519. if not present in specified path.
  20520. type: string
  20521. server:
  20522. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20523. type: string
  20524. version:
  20525. default: v2
  20526. description: |-
  20527. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20528. "v2". Version defaults to "v2".
  20529. enum:
  20530. - v1
  20531. - v2
  20532. type: string
  20533. required:
  20534. - server
  20535. type: object
  20536. x-kubernetes-validations:
  20537. - message: at most one of the fields in [caBundle caProvider] may be set
  20538. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20539. oracle:
  20540. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20541. properties:
  20542. auth:
  20543. description: |-
  20544. Auth configures how secret-manager authenticates with the Oracle Vault.
  20545. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20546. properties:
  20547. secretRef:
  20548. description: SecretRef to pass through sensitive information.
  20549. properties:
  20550. fingerprint:
  20551. description: Fingerprint is the fingerprint of the API private key.
  20552. properties:
  20553. key:
  20554. description: |-
  20555. A key in the referenced Secret.
  20556. Some instances of this field may be defaulted, in others it may be required.
  20557. maxLength: 253
  20558. minLength: 1
  20559. pattern: ^[-._a-zA-Z0-9]+$
  20560. type: string
  20561. name:
  20562. description: The name of the Secret resource being referred to.
  20563. maxLength: 253
  20564. minLength: 1
  20565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20566. type: string
  20567. namespace:
  20568. description: |-
  20569. The namespace of the Secret resource being referred to.
  20570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20571. maxLength: 63
  20572. minLength: 1
  20573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20574. type: string
  20575. type: object
  20576. privatekey:
  20577. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20578. properties:
  20579. key:
  20580. description: |-
  20581. A key in the referenced Secret.
  20582. Some instances of this field may be defaulted, in others it may be required.
  20583. maxLength: 253
  20584. minLength: 1
  20585. pattern: ^[-._a-zA-Z0-9]+$
  20586. type: string
  20587. name:
  20588. description: The name of the Secret resource being referred to.
  20589. maxLength: 253
  20590. minLength: 1
  20591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20592. type: string
  20593. namespace:
  20594. description: |-
  20595. The namespace of the Secret resource being referred to.
  20596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20597. maxLength: 63
  20598. minLength: 1
  20599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20600. type: string
  20601. type: object
  20602. required:
  20603. - fingerprint
  20604. - privatekey
  20605. type: object
  20606. tenancy:
  20607. description: Tenancy is the tenancy OCID where user is located.
  20608. type: string
  20609. user:
  20610. description: User is an access OCID specific to the account.
  20611. type: string
  20612. required:
  20613. - secretRef
  20614. - tenancy
  20615. - user
  20616. type: object
  20617. compartment:
  20618. description: |-
  20619. Compartment is the vault compartment OCID.
  20620. Required for PushSecret
  20621. type: string
  20622. encryptionKey:
  20623. description: |-
  20624. EncryptionKey is the OCID of the encryption key within the vault.
  20625. Required for PushSecret
  20626. type: string
  20627. principalType:
  20628. description: |-
  20629. The type of principal to use for authentication. If left blank, the Auth struct will
  20630. determine the principal type. This optional field must be specified if using
  20631. workload identity.
  20632. enum:
  20633. - ""
  20634. - UserPrincipal
  20635. - InstancePrincipal
  20636. - Workload
  20637. type: string
  20638. region:
  20639. description: Region is the region where vault is located.
  20640. type: string
  20641. serviceAccountRef:
  20642. description: |-
  20643. ServiceAccountRef specified the service account
  20644. that should be used when authenticating with WorkloadIdentity.
  20645. properties:
  20646. audiences:
  20647. description: |-
  20648. Audience specifies the `aud` claim for the service account token
  20649. Some providers automatically extend the audience field based on well-known annotations for workload
  20650. identity (e.g. IRSA or GCP Workload Identity)
  20651. items:
  20652. type: string
  20653. type: array
  20654. name:
  20655. description: The name of the ServiceAccount resource being referred to.
  20656. maxLength: 253
  20657. minLength: 1
  20658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20659. type: string
  20660. namespace:
  20661. description: |-
  20662. Namespace of the resource being referred to.
  20663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20664. maxLength: 63
  20665. minLength: 1
  20666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20667. type: string
  20668. required:
  20669. - name
  20670. type: object
  20671. vault:
  20672. description: Vault is the vault's OCID of the specific vault where secret is located.
  20673. type: string
  20674. required:
  20675. - region
  20676. - vault
  20677. type: object
  20678. ovh:
  20679. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20680. properties:
  20681. auth:
  20682. description: Authentication method (mtls or token).
  20683. properties:
  20684. mtls:
  20685. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20686. properties:
  20687. caBundle:
  20688. format: byte
  20689. type: string
  20690. caProvider:
  20691. description: |-
  20692. CAProvider provides a custom certificate authority for accessing the provider's store.
  20693. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20694. properties:
  20695. key:
  20696. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20697. maxLength: 253
  20698. minLength: 1
  20699. pattern: ^[-._a-zA-Z0-9]+$
  20700. type: string
  20701. name:
  20702. description: The name of the object located at the provider type.
  20703. maxLength: 253
  20704. minLength: 1
  20705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20706. type: string
  20707. namespace:
  20708. description: |-
  20709. The namespace the Provider type is in.
  20710. Can only be defined when used in a ClusterSecretStore.
  20711. maxLength: 63
  20712. minLength: 1
  20713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20714. type: string
  20715. type:
  20716. description: The type of provider to use such as "Secret", or "ConfigMap".
  20717. enum:
  20718. - Secret
  20719. - ConfigMap
  20720. type: string
  20721. required:
  20722. - name
  20723. - type
  20724. type: object
  20725. certSecretRef:
  20726. description: |-
  20727. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20728. In some instances, `key` is a required field.
  20729. properties:
  20730. key:
  20731. description: |-
  20732. A key in the referenced Secret.
  20733. Some instances of this field may be defaulted, in others it may be required.
  20734. maxLength: 253
  20735. minLength: 1
  20736. pattern: ^[-._a-zA-Z0-9]+$
  20737. type: string
  20738. name:
  20739. description: The name of the Secret resource being referred to.
  20740. maxLength: 253
  20741. minLength: 1
  20742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20743. type: string
  20744. namespace:
  20745. description: |-
  20746. The namespace of the Secret resource being referred to.
  20747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20748. maxLength: 63
  20749. minLength: 1
  20750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20751. type: string
  20752. type: object
  20753. keySecretRef:
  20754. description: |-
  20755. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20756. In some instances, `key` is a required field.
  20757. properties:
  20758. key:
  20759. description: |-
  20760. A key in the referenced Secret.
  20761. Some instances of this field may be defaulted, in others it may be required.
  20762. maxLength: 253
  20763. minLength: 1
  20764. pattern: ^[-._a-zA-Z0-9]+$
  20765. type: string
  20766. name:
  20767. description: The name of the Secret resource being referred to.
  20768. maxLength: 253
  20769. minLength: 1
  20770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20771. type: string
  20772. namespace:
  20773. description: |-
  20774. The namespace of the Secret resource being referred to.
  20775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20776. maxLength: 63
  20777. minLength: 1
  20778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20779. type: string
  20780. type: object
  20781. required:
  20782. - certSecretRef
  20783. - keySecretRef
  20784. type: object
  20785. token:
  20786. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20787. properties:
  20788. tokenSecretRef:
  20789. description: |-
  20790. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20791. In some instances, `key` is a required field.
  20792. properties:
  20793. key:
  20794. description: |-
  20795. A key in the referenced Secret.
  20796. Some instances of this field may be defaulted, in others it may be required.
  20797. maxLength: 253
  20798. minLength: 1
  20799. pattern: ^[-._a-zA-Z0-9]+$
  20800. type: string
  20801. name:
  20802. description: The name of the Secret resource being referred to.
  20803. maxLength: 253
  20804. minLength: 1
  20805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20806. type: string
  20807. namespace:
  20808. description: |-
  20809. The namespace of the Secret resource being referred to.
  20810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20811. maxLength: 63
  20812. minLength: 1
  20813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20814. type: string
  20815. type: object
  20816. required:
  20817. - tokenSecretRef
  20818. type: object
  20819. type: object
  20820. casRequired:
  20821. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20822. type: boolean
  20823. okmsTimeout:
  20824. default: 30
  20825. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20826. format: int32
  20827. minimum: 1
  20828. type: integer
  20829. okmsid:
  20830. description: specifies the OKMS ID.
  20831. type: string
  20832. server:
  20833. description: specifies the OKMS server endpoint.
  20834. type: string
  20835. required:
  20836. - auth
  20837. - okmsid
  20838. - server
  20839. type: object
  20840. passbolt:
  20841. description: |-
  20842. PassboltProvider provides access to Passbolt secrets manager.
  20843. See: https://www.passbolt.com.
  20844. properties:
  20845. auth:
  20846. description: Auth defines the information necessary to authenticate against Passbolt Server
  20847. properties:
  20848. passwordSecretRef:
  20849. description: |-
  20850. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20851. In some instances, `key` is a required field.
  20852. properties:
  20853. key:
  20854. description: |-
  20855. A key in the referenced Secret.
  20856. Some instances of this field may be defaulted, in others it may be required.
  20857. maxLength: 253
  20858. minLength: 1
  20859. pattern: ^[-._a-zA-Z0-9]+$
  20860. type: string
  20861. name:
  20862. description: The name of the Secret resource being referred to.
  20863. maxLength: 253
  20864. minLength: 1
  20865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20866. type: string
  20867. namespace:
  20868. description: |-
  20869. The namespace of the Secret resource being referred to.
  20870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20871. maxLength: 63
  20872. minLength: 1
  20873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20874. type: string
  20875. type: object
  20876. privateKeySecretRef:
  20877. description: |-
  20878. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20879. In some instances, `key` is a required field.
  20880. properties:
  20881. key:
  20882. description: |-
  20883. A key in the referenced Secret.
  20884. Some instances of this field may be defaulted, in others it may be required.
  20885. maxLength: 253
  20886. minLength: 1
  20887. pattern: ^[-._a-zA-Z0-9]+$
  20888. type: string
  20889. name:
  20890. description: The name of the Secret resource being referred to.
  20891. maxLength: 253
  20892. minLength: 1
  20893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20894. type: string
  20895. namespace:
  20896. description: |-
  20897. The namespace of the Secret resource being referred to.
  20898. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20899. maxLength: 63
  20900. minLength: 1
  20901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20902. type: string
  20903. type: object
  20904. required:
  20905. - passwordSecretRef
  20906. - privateKeySecretRef
  20907. type: object
  20908. caBundle:
  20909. description: |-
  20910. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20911. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20912. are used to validate the TLS connection.
  20913. format: byte
  20914. type: string
  20915. caProvider:
  20916. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20917. properties:
  20918. key:
  20919. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20920. maxLength: 253
  20921. minLength: 1
  20922. pattern: ^[-._a-zA-Z0-9]+$
  20923. type: string
  20924. name:
  20925. description: The name of the object located at the provider type.
  20926. maxLength: 253
  20927. minLength: 1
  20928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20929. type: string
  20930. namespace:
  20931. description: |-
  20932. The namespace the Provider type is in.
  20933. Can only be defined when used in a ClusterSecretStore.
  20934. maxLength: 63
  20935. minLength: 1
  20936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20937. type: string
  20938. type:
  20939. description: The type of provider to use such as "Secret", or "ConfigMap".
  20940. enum:
  20941. - Secret
  20942. - ConfigMap
  20943. type: string
  20944. required:
  20945. - name
  20946. - type
  20947. type: object
  20948. host:
  20949. description: Host defines the Passbolt Server to connect to
  20950. type: string
  20951. required:
  20952. - auth
  20953. - host
  20954. type: object
  20955. passworddepot:
  20956. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20957. properties:
  20958. auth:
  20959. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20960. properties:
  20961. secretRef:
  20962. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20963. properties:
  20964. credentials:
  20965. description: Username / Password is used for authentication.
  20966. properties:
  20967. key:
  20968. description: |-
  20969. A key in the referenced Secret.
  20970. Some instances of this field may be defaulted, in others it may be required.
  20971. maxLength: 253
  20972. minLength: 1
  20973. pattern: ^[-._a-zA-Z0-9]+$
  20974. type: string
  20975. name:
  20976. description: The name of the Secret resource being referred to.
  20977. maxLength: 253
  20978. minLength: 1
  20979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20980. type: string
  20981. namespace:
  20982. description: |-
  20983. The namespace of the Secret resource being referred to.
  20984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20985. maxLength: 63
  20986. minLength: 1
  20987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20988. type: string
  20989. type: object
  20990. type: object
  20991. required:
  20992. - secretRef
  20993. type: object
  20994. database:
  20995. description: Database to use as source
  20996. type: string
  20997. host:
  20998. description: URL configures the Password Depot instance URL.
  20999. type: string
  21000. required:
  21001. - auth
  21002. - database
  21003. - host
  21004. type: object
  21005. previder:
  21006. description: Previder configures this store to sync secrets using the Previder provider
  21007. properties:
  21008. auth:
  21009. description: PreviderAuth contains a secretRef for credentials.
  21010. properties:
  21011. secretRef:
  21012. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  21013. properties:
  21014. accessToken:
  21015. description: The AccessToken is used for authentication
  21016. properties:
  21017. key:
  21018. description: |-
  21019. A key in the referenced Secret.
  21020. Some instances of this field may be defaulted, in others it may be required.
  21021. maxLength: 253
  21022. minLength: 1
  21023. pattern: ^[-._a-zA-Z0-9]+$
  21024. type: string
  21025. name:
  21026. description: The name of the Secret resource being referred to.
  21027. maxLength: 253
  21028. minLength: 1
  21029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21030. type: string
  21031. namespace:
  21032. description: |-
  21033. The namespace of the Secret resource being referred to.
  21034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21035. maxLength: 63
  21036. minLength: 1
  21037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21038. type: string
  21039. type: object
  21040. required:
  21041. - accessToken
  21042. type: object
  21043. type: object
  21044. baseUri:
  21045. type: string
  21046. required:
  21047. - auth
  21048. type: object
  21049. pulumi:
  21050. description: Pulumi configures this store to sync secrets using the Pulumi provider
  21051. properties:
  21052. accessToken:
  21053. description: |-
  21054. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  21055. Deprecated: Use auth.accessToken instead.
  21056. properties:
  21057. secretRef:
  21058. description: SecretRef is a reference to a secret containing the Pulumi API token.
  21059. properties:
  21060. key:
  21061. description: |-
  21062. A key in the referenced Secret.
  21063. Some instances of this field may be defaulted, in others it may be required.
  21064. maxLength: 253
  21065. minLength: 1
  21066. pattern: ^[-._a-zA-Z0-9]+$
  21067. type: string
  21068. name:
  21069. description: The name of the Secret resource being referred to.
  21070. maxLength: 253
  21071. minLength: 1
  21072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21073. type: string
  21074. namespace:
  21075. description: |-
  21076. The namespace of the Secret resource being referred to.
  21077. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21078. maxLength: 63
  21079. minLength: 1
  21080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21081. type: string
  21082. type: object
  21083. type: object
  21084. apiUrl:
  21085. default: https://api.pulumi.com/api/esc
  21086. description: APIURL is the URL of the Pulumi API.
  21087. type: string
  21088. auth:
  21089. description: |-
  21090. Auth configures how the Operator authenticates with the Pulumi API.
  21091. Either auth or the deprecated accessToken field must be specified.
  21092. properties:
  21093. accessToken:
  21094. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  21095. properties:
  21096. secretRef:
  21097. description: SecretRef is a reference to a secret containing the Pulumi API token.
  21098. properties:
  21099. key:
  21100. description: |-
  21101. A key in the referenced Secret.
  21102. Some instances of this field may be defaulted, in others it may be required.
  21103. maxLength: 253
  21104. minLength: 1
  21105. pattern: ^[-._a-zA-Z0-9]+$
  21106. type: string
  21107. name:
  21108. description: The name of the Secret resource being referred to.
  21109. maxLength: 253
  21110. minLength: 1
  21111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21112. type: string
  21113. namespace:
  21114. description: |-
  21115. The namespace of the Secret resource being referred to.
  21116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21117. maxLength: 63
  21118. minLength: 1
  21119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21120. type: string
  21121. type: object
  21122. type: object
  21123. oidcConfig:
  21124. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  21125. properties:
  21126. expirationSeconds:
  21127. default: 600
  21128. description: |-
  21129. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  21130. Defaults to 10 minutes.
  21131. format: int64
  21132. minimum: 600
  21133. type: integer
  21134. organization:
  21135. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  21136. type: string
  21137. serviceAccountRef:
  21138. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  21139. properties:
  21140. audiences:
  21141. description: |-
  21142. Audience specifies the `aud` claim for the service account token
  21143. Some providers automatically extend the audience field based on well-known annotations for workload
  21144. identity (e.g. IRSA or GCP Workload Identity)
  21145. items:
  21146. type: string
  21147. type: array
  21148. name:
  21149. description: The name of the ServiceAccount resource being referred to.
  21150. maxLength: 253
  21151. minLength: 1
  21152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21153. type: string
  21154. namespace:
  21155. description: |-
  21156. Namespace of the resource being referred to.
  21157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21158. maxLength: 63
  21159. minLength: 1
  21160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21161. type: string
  21162. required:
  21163. - name
  21164. type: object
  21165. required:
  21166. - organization
  21167. - serviceAccountRef
  21168. type: object
  21169. type: object
  21170. x-kubernetes-validations:
  21171. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  21172. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  21173. environment:
  21174. description: |-
  21175. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  21176. dynamically retrieved values from supported providers including all major clouds,
  21177. and other Pulumi ESC environments.
  21178. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  21179. type: string
  21180. organization:
  21181. description: |-
  21182. Organization are a space to collaborate on shared projects and stacks.
  21183. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  21184. type: string
  21185. project:
  21186. description: Project is the name of the Pulumi ESC project the environment belongs to.
  21187. type: string
  21188. required:
  21189. - environment
  21190. - organization
  21191. - project
  21192. type: object
  21193. x-kubernetes-validations:
  21194. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  21195. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  21196. scaleway:
  21197. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  21198. properties:
  21199. accessKey:
  21200. description: AccessKey is the non-secret part of the api key.
  21201. properties:
  21202. secretRef:
  21203. description: SecretRef references a key in a secret that will be used as value.
  21204. properties:
  21205. key:
  21206. description: |-
  21207. A key in the referenced Secret.
  21208. Some instances of this field may be defaulted, in others it may be required.
  21209. maxLength: 253
  21210. minLength: 1
  21211. pattern: ^[-._a-zA-Z0-9]+$
  21212. type: string
  21213. name:
  21214. description: The name of the Secret resource being referred to.
  21215. maxLength: 253
  21216. minLength: 1
  21217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21218. type: string
  21219. namespace:
  21220. description: |-
  21221. The namespace of the Secret resource being referred to.
  21222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21223. maxLength: 63
  21224. minLength: 1
  21225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21226. type: string
  21227. type: object
  21228. value:
  21229. description: Value can be specified directly to set a value without using a secret.
  21230. type: string
  21231. type: object
  21232. apiUrl:
  21233. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  21234. type: string
  21235. projectId:
  21236. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  21237. type: string
  21238. region:
  21239. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  21240. type: string
  21241. secretKey:
  21242. description: SecretKey is the non-secret part of the api key.
  21243. properties:
  21244. secretRef:
  21245. description: SecretRef references a key in a secret that will be used as value.
  21246. properties:
  21247. key:
  21248. description: |-
  21249. A key in the referenced Secret.
  21250. Some instances of this field may be defaulted, in others it may be required.
  21251. maxLength: 253
  21252. minLength: 1
  21253. pattern: ^[-._a-zA-Z0-9]+$
  21254. type: string
  21255. name:
  21256. description: The name of the Secret resource being referred to.
  21257. maxLength: 253
  21258. minLength: 1
  21259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21260. type: string
  21261. namespace:
  21262. description: |-
  21263. The namespace of the Secret resource being referred to.
  21264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21265. maxLength: 63
  21266. minLength: 1
  21267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21268. type: string
  21269. type: object
  21270. value:
  21271. description: Value can be specified directly to set a value without using a secret.
  21272. type: string
  21273. type: object
  21274. required:
  21275. - accessKey
  21276. - projectId
  21277. - region
  21278. - secretKey
  21279. type: object
  21280. secretserver:
  21281. description: |-
  21282. SecretServer configures this store to sync secrets using SecretServer provider
  21283. https://docs.delinea.com/online-help/secret-server/start.htm
  21284. properties:
  21285. caBundle:
  21286. description: |-
  21287. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  21288. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  21289. are used to validate the TLS connection.
  21290. format: byte
  21291. type: string
  21292. caProvider:
  21293. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  21294. properties:
  21295. key:
  21296. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21297. maxLength: 253
  21298. minLength: 1
  21299. pattern: ^[-._a-zA-Z0-9]+$
  21300. type: string
  21301. name:
  21302. description: The name of the object located at the provider type.
  21303. maxLength: 253
  21304. minLength: 1
  21305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21306. type: string
  21307. namespace:
  21308. description: |-
  21309. The namespace the Provider type is in.
  21310. Can only be defined when used in a ClusterSecretStore.
  21311. maxLength: 63
  21312. minLength: 1
  21313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21314. type: string
  21315. type:
  21316. description: The type of provider to use such as "Secret", or "ConfigMap".
  21317. enum:
  21318. - Secret
  21319. - ConfigMap
  21320. type: string
  21321. required:
  21322. - name
  21323. - type
  21324. type: object
  21325. disableSiteIDValidation:
  21326. description: |-
  21327. DisableSiteIDValidation permits a missing site ID for new secrets.
  21328. The provider sends 0 if no site ID is set.
  21329. type: boolean
  21330. domain:
  21331. description: Domain is the secret server domain.
  21332. type: string
  21333. password:
  21334. description: |-
  21335. Password is the secret server account password.
  21336. Required unless Token is set.
  21337. properties:
  21338. secretRef:
  21339. description: SecretRef references a key in a secret that will be used as value.
  21340. properties:
  21341. key:
  21342. description: |-
  21343. A key in the referenced Secret.
  21344. Some instances of this field may be defaulted, in others it may be required.
  21345. maxLength: 253
  21346. minLength: 1
  21347. pattern: ^[-._a-zA-Z0-9]+$
  21348. type: string
  21349. name:
  21350. description: The name of the Secret resource being referred to.
  21351. maxLength: 253
  21352. minLength: 1
  21353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21354. type: string
  21355. namespace:
  21356. description: |-
  21357. The namespace of the Secret resource being referred to.
  21358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21359. maxLength: 63
  21360. minLength: 1
  21361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21362. type: string
  21363. type: object
  21364. value:
  21365. description: Value can be specified directly to set a value without using a secret.
  21366. minLength: 1
  21367. type: string
  21368. type: object
  21369. x-kubernetes-validations:
  21370. - message: exactly one of value or secretRef must be set
  21371. rule: has(self.value) != has(self.secretRef)
  21372. serverURL:
  21373. description: |-
  21374. ServerURL
  21375. URL to your secret server installation
  21376. type: string
  21377. siteId:
  21378. description: |-
  21379. SiteID is the ID of the Secret Server site for new secrets.
  21380. PushSecret metadata can override this value for one secret.
  21381. The provider uses 1 if this field is not set.
  21382. minimum: 1
  21383. type: integer
  21384. token:
  21385. description: |-
  21386. Token is an access token used to authenticate to the secret server,
  21387. as an alternative to Username and Password. When set, Username and
  21388. Password are not required and are ignored.
  21389. properties:
  21390. secretRef:
  21391. description: SecretRef references a key in a secret that will be used as value.
  21392. properties:
  21393. key:
  21394. description: |-
  21395. A key in the referenced Secret.
  21396. Some instances of this field may be defaulted, in others it may be required.
  21397. maxLength: 253
  21398. minLength: 1
  21399. pattern: ^[-._a-zA-Z0-9]+$
  21400. type: string
  21401. name:
  21402. description: The name of the Secret resource being referred to.
  21403. maxLength: 253
  21404. minLength: 1
  21405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21406. type: string
  21407. namespace:
  21408. description: |-
  21409. The namespace of the Secret resource being referred to.
  21410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21411. maxLength: 63
  21412. minLength: 1
  21413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21414. type: string
  21415. type: object
  21416. value:
  21417. description: Value can be specified directly to set a value without using a secret.
  21418. minLength: 1
  21419. type: string
  21420. type: object
  21421. x-kubernetes-validations:
  21422. - message: exactly one of value or secretRef must be set
  21423. rule: has(self.value) != has(self.secretRef)
  21424. username:
  21425. description: |-
  21426. Username is the secret server account username.
  21427. Required unless Token is set.
  21428. properties:
  21429. secretRef:
  21430. description: SecretRef references a key in a secret that will be used as value.
  21431. properties:
  21432. key:
  21433. description: |-
  21434. A key in the referenced Secret.
  21435. Some instances of this field may be defaulted, in others it may be required.
  21436. maxLength: 253
  21437. minLength: 1
  21438. pattern: ^[-._a-zA-Z0-9]+$
  21439. type: string
  21440. name:
  21441. description: The name of the Secret resource being referred to.
  21442. maxLength: 253
  21443. minLength: 1
  21444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21445. type: string
  21446. namespace:
  21447. description: |-
  21448. The namespace of the Secret resource being referred to.
  21449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21450. maxLength: 63
  21451. minLength: 1
  21452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21453. type: string
  21454. type: object
  21455. value:
  21456. description: Value can be specified directly to set a value without using a secret.
  21457. minLength: 1
  21458. type: string
  21459. type: object
  21460. x-kubernetes-validations:
  21461. - message: exactly one of value or secretRef must be set
  21462. rule: has(self.value) != has(self.secretRef)
  21463. required:
  21464. - serverURL
  21465. type: object
  21466. x-kubernetes-validations:
  21467. - message: either token, or both username and password, must be set
  21468. rule: has(self.token) || (has(self.username) && has(self.password))
  21469. senhasegura:
  21470. description: Senhasegura configures this store to sync secrets using senhasegura provider
  21471. properties:
  21472. auth:
  21473. description: Auth defines parameters to authenticate in senhasegura
  21474. properties:
  21475. clientId:
  21476. type: string
  21477. clientSecretSecretRef:
  21478. description: |-
  21479. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21480. In some instances, `key` is a required field.
  21481. properties:
  21482. key:
  21483. description: |-
  21484. A key in the referenced Secret.
  21485. Some instances of this field may be defaulted, in others it may be required.
  21486. maxLength: 253
  21487. minLength: 1
  21488. pattern: ^[-._a-zA-Z0-9]+$
  21489. type: string
  21490. name:
  21491. description: The name of the Secret resource being referred to.
  21492. maxLength: 253
  21493. minLength: 1
  21494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21495. type: string
  21496. namespace:
  21497. description: |-
  21498. The namespace of the Secret resource being referred to.
  21499. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21500. maxLength: 63
  21501. minLength: 1
  21502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21503. type: string
  21504. type: object
  21505. required:
  21506. - clientId
  21507. - clientSecretSecretRef
  21508. type: object
  21509. ignoreSslCertificate:
  21510. default: false
  21511. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21512. type: boolean
  21513. module:
  21514. description: Module defines which senhasegura module should be used to get secrets
  21515. type: string
  21516. url:
  21517. description: URL of senhasegura
  21518. type: string
  21519. required:
  21520. - auth
  21521. - module
  21522. - url
  21523. type: object
  21524. vault:
  21525. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21526. properties:
  21527. auth:
  21528. description: Auth configures how secret-manager authenticates with the Vault server.
  21529. properties:
  21530. appRole:
  21531. description: |-
  21532. AppRole authenticates with Vault using the App Role auth mechanism,
  21533. with the role and secret stored in a Kubernetes Secret resource.
  21534. properties:
  21535. path:
  21536. default: approle
  21537. description: |-
  21538. Path where the App Role authentication backend is mounted
  21539. in Vault, e.g: "approle"
  21540. type: string
  21541. roleId:
  21542. description: |-
  21543. RoleID configured in the App Role authentication backend when setting
  21544. up the authentication backend in Vault.
  21545. type: string
  21546. roleRef:
  21547. description: |-
  21548. Reference to a key in a Secret that contains the App Role ID used
  21549. to authenticate with Vault.
  21550. The `key` field must be specified and denotes which entry within the Secret
  21551. resource is used as the app role id.
  21552. properties:
  21553. key:
  21554. description: |-
  21555. A key in the referenced Secret.
  21556. Some instances of this field may be defaulted, in others it may be required.
  21557. maxLength: 253
  21558. minLength: 1
  21559. pattern: ^[-._a-zA-Z0-9]+$
  21560. type: string
  21561. name:
  21562. description: The name of the Secret resource being referred to.
  21563. maxLength: 253
  21564. minLength: 1
  21565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21566. type: string
  21567. namespace:
  21568. description: |-
  21569. The namespace of the Secret resource being referred to.
  21570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21571. maxLength: 63
  21572. minLength: 1
  21573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21574. type: string
  21575. type: object
  21576. secretRef:
  21577. description: |-
  21578. Reference to a key in a Secret that contains the App Role secret used
  21579. to authenticate with Vault.
  21580. The `key` field must be specified and denotes which entry within the Secret
  21581. resource is used as the app role secret.
  21582. properties:
  21583. key:
  21584. description: |-
  21585. A key in the referenced Secret.
  21586. Some instances of this field may be defaulted, in others it may be required.
  21587. maxLength: 253
  21588. minLength: 1
  21589. pattern: ^[-._a-zA-Z0-9]+$
  21590. type: string
  21591. name:
  21592. description: The name of the Secret resource being referred to.
  21593. maxLength: 253
  21594. minLength: 1
  21595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21596. type: string
  21597. namespace:
  21598. description: |-
  21599. The namespace of the Secret resource being referred to.
  21600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21601. maxLength: 63
  21602. minLength: 1
  21603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21604. type: string
  21605. type: object
  21606. required:
  21607. - path
  21608. - secretRef
  21609. type: object
  21610. cert:
  21611. description: |-
  21612. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21613. Cert authentication method
  21614. properties:
  21615. clientCert:
  21616. description: |-
  21617. ClientCert is a certificate to authenticate using the Cert Vault
  21618. authentication method
  21619. properties:
  21620. key:
  21621. description: |-
  21622. A key in the referenced Secret.
  21623. Some instances of this field may be defaulted, in others it may be required.
  21624. maxLength: 253
  21625. minLength: 1
  21626. pattern: ^[-._a-zA-Z0-9]+$
  21627. type: string
  21628. name:
  21629. description: The name of the Secret resource being referred to.
  21630. maxLength: 253
  21631. minLength: 1
  21632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21633. type: string
  21634. namespace:
  21635. description: |-
  21636. The namespace of the Secret resource being referred to.
  21637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21638. maxLength: 63
  21639. minLength: 1
  21640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21641. type: string
  21642. type: object
  21643. path:
  21644. default: cert
  21645. description: |-
  21646. Path where the Certificate authentication backend is mounted
  21647. in Vault, e.g: "cert"
  21648. type: string
  21649. secretRef:
  21650. description: |-
  21651. SecretRef to a key in a Secret resource containing client private key to
  21652. authenticate with Vault using the Cert authentication method
  21653. properties:
  21654. key:
  21655. description: |-
  21656. A key in the referenced Secret.
  21657. Some instances of this field may be defaulted, in others it may be required.
  21658. maxLength: 253
  21659. minLength: 1
  21660. pattern: ^[-._a-zA-Z0-9]+$
  21661. type: string
  21662. name:
  21663. description: The name of the Secret resource being referred to.
  21664. maxLength: 253
  21665. minLength: 1
  21666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21667. type: string
  21668. namespace:
  21669. description: |-
  21670. The namespace of the Secret resource being referred to.
  21671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21672. maxLength: 63
  21673. minLength: 1
  21674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21675. type: string
  21676. type: object
  21677. vaultRole:
  21678. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21679. type: string
  21680. type: object
  21681. gcp:
  21682. description: |-
  21683. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21684. GCP authentication method
  21685. properties:
  21686. location:
  21687. description: Location optionally defines a location/region for the secret
  21688. type: string
  21689. path:
  21690. default: gcp
  21691. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21692. type: string
  21693. projectID:
  21694. description: Project ID of the Google Cloud Platform project
  21695. type: string
  21696. role:
  21697. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21698. type: string
  21699. secretRef:
  21700. description: Specify credentials in a Secret object
  21701. properties:
  21702. secretAccessKeySecretRef:
  21703. description: The SecretAccessKey is used for authentication
  21704. properties:
  21705. key:
  21706. description: |-
  21707. A key in the referenced Secret.
  21708. Some instances of this field may be defaulted, in others it may be required.
  21709. maxLength: 253
  21710. minLength: 1
  21711. pattern: ^[-._a-zA-Z0-9]+$
  21712. type: string
  21713. name:
  21714. description: The name of the Secret resource being referred to.
  21715. maxLength: 253
  21716. minLength: 1
  21717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21718. type: string
  21719. namespace:
  21720. description: |-
  21721. The namespace of the Secret resource being referred to.
  21722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21723. maxLength: 63
  21724. minLength: 1
  21725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21726. type: string
  21727. type: object
  21728. type: object
  21729. serviceAccountRef:
  21730. description: ServiceAccountRef to a service account for impersonation
  21731. properties:
  21732. audiences:
  21733. description: |-
  21734. Audience specifies the `aud` claim for the service account token
  21735. Some providers automatically extend the audience field based on well-known annotations for workload
  21736. identity (e.g. IRSA or GCP Workload Identity)
  21737. items:
  21738. type: string
  21739. type: array
  21740. name:
  21741. description: The name of the ServiceAccount resource being referred to.
  21742. maxLength: 253
  21743. minLength: 1
  21744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21745. type: string
  21746. namespace:
  21747. description: |-
  21748. Namespace of the resource being referred to.
  21749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21750. maxLength: 63
  21751. minLength: 1
  21752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21753. type: string
  21754. required:
  21755. - name
  21756. type: object
  21757. workloadIdentity:
  21758. description: Specify a service account with Workload Identity
  21759. properties:
  21760. clusterLocation:
  21761. description: |-
  21762. ClusterLocation is the location of the cluster
  21763. If not specified, it fetches information from the metadata server
  21764. type: string
  21765. clusterName:
  21766. description: |-
  21767. ClusterName is the name of the cluster
  21768. If not specified, it fetches information from the metadata server
  21769. type: string
  21770. clusterProjectID:
  21771. description: |-
  21772. ClusterProjectID is the project ID of the cluster
  21773. If not specified, it fetches information from the metadata server
  21774. type: string
  21775. serviceAccountRef:
  21776. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21777. properties:
  21778. audiences:
  21779. description: |-
  21780. Audience specifies the `aud` claim for the service account token
  21781. Some providers automatically extend the audience field based on well-known annotations for workload
  21782. identity (e.g. IRSA or GCP Workload Identity)
  21783. items:
  21784. type: string
  21785. type: array
  21786. name:
  21787. description: The name of the ServiceAccount resource being referred to.
  21788. maxLength: 253
  21789. minLength: 1
  21790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21791. type: string
  21792. namespace:
  21793. description: |-
  21794. Namespace of the resource being referred to.
  21795. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21796. maxLength: 63
  21797. minLength: 1
  21798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21799. type: string
  21800. required:
  21801. - name
  21802. type: object
  21803. required:
  21804. - serviceAccountRef
  21805. type: object
  21806. required:
  21807. - role
  21808. type: object
  21809. iam:
  21810. description: |-
  21811. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21812. AWS IAM authentication method
  21813. properties:
  21814. externalID:
  21815. description: AWS External ID set on assumed IAM roles
  21816. type: string
  21817. jwt:
  21818. description: Specify a service account with IRSA enabled
  21819. properties:
  21820. serviceAccountRef:
  21821. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21822. properties:
  21823. audiences:
  21824. description: |-
  21825. Audience specifies the `aud` claim for the service account token
  21826. Some providers automatically extend the audience field based on well-known annotations for workload
  21827. identity (e.g. IRSA or GCP Workload Identity)
  21828. items:
  21829. type: string
  21830. type: array
  21831. name:
  21832. description: The name of the ServiceAccount resource being referred to.
  21833. maxLength: 253
  21834. minLength: 1
  21835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21836. type: string
  21837. namespace:
  21838. description: |-
  21839. Namespace of the resource being referred to.
  21840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21841. maxLength: 63
  21842. minLength: 1
  21843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21844. type: string
  21845. required:
  21846. - name
  21847. type: object
  21848. type: object
  21849. path:
  21850. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21851. type: string
  21852. region:
  21853. description: AWS region
  21854. type: string
  21855. role:
  21856. description: This is the AWS role to be assumed before talking to vault
  21857. type: string
  21858. secretRef:
  21859. description: Specify credentials in a Secret object
  21860. properties:
  21861. accessKeyIDSecretRef:
  21862. description: The AccessKeyID is used for authentication
  21863. properties:
  21864. key:
  21865. description: |-
  21866. A key in the referenced Secret.
  21867. Some instances of this field may be defaulted, in others it may be required.
  21868. maxLength: 253
  21869. minLength: 1
  21870. pattern: ^[-._a-zA-Z0-9]+$
  21871. type: string
  21872. name:
  21873. description: The name of the Secret resource being referred to.
  21874. maxLength: 253
  21875. minLength: 1
  21876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21877. type: string
  21878. namespace:
  21879. description: |-
  21880. The namespace of the Secret resource being referred to.
  21881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21882. maxLength: 63
  21883. minLength: 1
  21884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21885. type: string
  21886. type: object
  21887. secretAccessKeySecretRef:
  21888. description: The SecretAccessKey is used for authentication
  21889. properties:
  21890. key:
  21891. description: |-
  21892. A key in the referenced Secret.
  21893. Some instances of this field may be defaulted, in others it may be required.
  21894. maxLength: 253
  21895. minLength: 1
  21896. pattern: ^[-._a-zA-Z0-9]+$
  21897. type: string
  21898. name:
  21899. description: The name of the Secret resource being referred to.
  21900. maxLength: 253
  21901. minLength: 1
  21902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21903. type: string
  21904. namespace:
  21905. description: |-
  21906. The namespace of the Secret resource being referred to.
  21907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21908. maxLength: 63
  21909. minLength: 1
  21910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21911. type: string
  21912. type: object
  21913. sessionTokenSecretRef:
  21914. description: |-
  21915. The SessionToken used for authentication
  21916. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21917. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21918. properties:
  21919. key:
  21920. description: |-
  21921. A key in the referenced Secret.
  21922. Some instances of this field may be defaulted, in others it may be required.
  21923. maxLength: 253
  21924. minLength: 1
  21925. pattern: ^[-._a-zA-Z0-9]+$
  21926. type: string
  21927. name:
  21928. description: The name of the Secret resource being referred to.
  21929. maxLength: 253
  21930. minLength: 1
  21931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21932. type: string
  21933. namespace:
  21934. description: |-
  21935. The namespace of the Secret resource being referred to.
  21936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21937. maxLength: 63
  21938. minLength: 1
  21939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21940. type: string
  21941. type: object
  21942. type: object
  21943. vaultAwsIamServerID:
  21944. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21945. type: string
  21946. vaultRole:
  21947. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21948. type: string
  21949. required:
  21950. - vaultRole
  21951. type: object
  21952. jwt:
  21953. description: |-
  21954. Jwt authenticates with Vault by passing role and JWT token using the
  21955. JWT/OIDC authentication method
  21956. properties:
  21957. kubernetesServiceAccountToken:
  21958. description: |-
  21959. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21960. a token for with the `TokenRequest` API.
  21961. properties:
  21962. audiences:
  21963. description: |-
  21964. Optional audiences field that will be used to request a temporary Kubernetes service
  21965. account token for the service account referenced by `serviceAccountRef`.
  21966. Defaults to a single audience `vault` it not specified.
  21967. Deprecated: use serviceAccountRef.Audiences instead
  21968. items:
  21969. type: string
  21970. type: array
  21971. expirationSeconds:
  21972. description: |-
  21973. Optional expiration time in seconds that will be used to request a temporary
  21974. Kubernetes service account token for the service account referenced by
  21975. `serviceAccountRef`.
  21976. Deprecated: this will be removed in the future.
  21977. Defaults to 10 minutes.
  21978. format: int64
  21979. type: integer
  21980. serviceAccountRef:
  21981. description: Service account field containing the name of a kubernetes ServiceAccount.
  21982. properties:
  21983. audiences:
  21984. description: |-
  21985. Audience specifies the `aud` claim for the service account token
  21986. Some providers automatically extend the audience field based on well-known annotations for workload
  21987. identity (e.g. IRSA or GCP Workload Identity)
  21988. items:
  21989. type: string
  21990. type: array
  21991. name:
  21992. description: The name of the ServiceAccount resource being referred to.
  21993. maxLength: 253
  21994. minLength: 1
  21995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21996. type: string
  21997. namespace:
  21998. description: |-
  21999. Namespace of the resource being referred to.
  22000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22001. maxLength: 63
  22002. minLength: 1
  22003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22004. type: string
  22005. required:
  22006. - name
  22007. type: object
  22008. required:
  22009. - serviceAccountRef
  22010. type: object
  22011. path:
  22012. default: jwt
  22013. description: |-
  22014. Path where the JWT authentication backend is mounted
  22015. in Vault, e.g: "jwt"
  22016. type: string
  22017. role:
  22018. description: |-
  22019. Role is a JWT role to authenticate using the JWT/OIDC Vault
  22020. authentication method
  22021. type: string
  22022. secretRef:
  22023. description: |-
  22024. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  22025. authenticate with Vault using the JWT/OIDC authentication method.
  22026. properties:
  22027. key:
  22028. description: |-
  22029. A key in the referenced Secret.
  22030. Some instances of this field may be defaulted, in others it may be required.
  22031. maxLength: 253
  22032. minLength: 1
  22033. pattern: ^[-._a-zA-Z0-9]+$
  22034. type: string
  22035. name:
  22036. description: The name of the Secret resource being referred to.
  22037. maxLength: 253
  22038. minLength: 1
  22039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22040. type: string
  22041. namespace:
  22042. description: |-
  22043. The namespace of the Secret resource being referred to.
  22044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22045. maxLength: 63
  22046. minLength: 1
  22047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22048. type: string
  22049. type: object
  22050. required:
  22051. - path
  22052. type: object
  22053. kubernetes:
  22054. description: |-
  22055. Kubernetes authenticates with Vault by passing the ServiceAccount
  22056. token stored in the named Secret resource to the Vault server.
  22057. properties:
  22058. mountPath:
  22059. default: kubernetes
  22060. description: |-
  22061. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  22062. "kubernetes"
  22063. type: string
  22064. role:
  22065. description: |-
  22066. A required field containing the Vault Role to assume. A Role binds a
  22067. Kubernetes ServiceAccount with a set of Vault policies.
  22068. type: string
  22069. secretRef:
  22070. description: |-
  22071. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22072. for authenticating with Vault. If a name is specified without a key,
  22073. `token` is the default. If one is not specified, the one bound to
  22074. the controller will be used.
  22075. properties:
  22076. key:
  22077. description: |-
  22078. A key in the referenced Secret.
  22079. Some instances of this field may be defaulted, in others it may be required.
  22080. maxLength: 253
  22081. minLength: 1
  22082. pattern: ^[-._a-zA-Z0-9]+$
  22083. type: string
  22084. name:
  22085. description: The name of the Secret resource being referred to.
  22086. maxLength: 253
  22087. minLength: 1
  22088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22089. type: string
  22090. namespace:
  22091. description: |-
  22092. The namespace of the Secret resource being referred to.
  22093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22094. maxLength: 63
  22095. minLength: 1
  22096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22097. type: string
  22098. type: object
  22099. serviceAccountRef:
  22100. description: |-
  22101. Optional service account field containing the name of a kubernetes ServiceAccount.
  22102. If the service account is specified, the service account secret token JWT will be used
  22103. for authenticating with Vault. If the service account selector is not supplied,
  22104. the secretRef will be used instead.
  22105. properties:
  22106. audiences:
  22107. description: |-
  22108. Audience specifies the `aud` claim for the service account token
  22109. Some providers automatically extend the audience field based on well-known annotations for workload
  22110. identity (e.g. IRSA or GCP Workload Identity)
  22111. items:
  22112. type: string
  22113. type: array
  22114. name:
  22115. description: The name of the ServiceAccount resource being referred to.
  22116. maxLength: 253
  22117. minLength: 1
  22118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22119. type: string
  22120. namespace:
  22121. description: |-
  22122. Namespace of the resource being referred to.
  22123. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22124. maxLength: 63
  22125. minLength: 1
  22126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22127. type: string
  22128. required:
  22129. - name
  22130. type: object
  22131. required:
  22132. - mountPath
  22133. - role
  22134. type: object
  22135. ldap:
  22136. description: |-
  22137. Ldap authenticates with Vault by passing username/password pair using
  22138. the LDAP authentication method
  22139. properties:
  22140. path:
  22141. default: ldap
  22142. description: |-
  22143. Path where the LDAP authentication backend is mounted
  22144. in Vault, e.g: "ldap"
  22145. type: string
  22146. secretRef:
  22147. description: |-
  22148. SecretRef to a key in a Secret resource containing password for the LDAP
  22149. user used to authenticate with Vault using the LDAP authentication
  22150. method
  22151. properties:
  22152. key:
  22153. description: |-
  22154. A key in the referenced Secret.
  22155. Some instances of this field may be defaulted, in others it may be required.
  22156. maxLength: 253
  22157. minLength: 1
  22158. pattern: ^[-._a-zA-Z0-9]+$
  22159. type: string
  22160. name:
  22161. description: The name of the Secret resource being referred to.
  22162. maxLength: 253
  22163. minLength: 1
  22164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22165. type: string
  22166. namespace:
  22167. description: |-
  22168. The namespace of the Secret resource being referred to.
  22169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22170. maxLength: 63
  22171. minLength: 1
  22172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22173. type: string
  22174. type: object
  22175. username:
  22176. description: |-
  22177. Username is an LDAP username used to authenticate using the LDAP Vault
  22178. authentication method
  22179. type: string
  22180. required:
  22181. - path
  22182. - username
  22183. type: object
  22184. namespace:
  22185. description: |-
  22186. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  22187. Namespaces is a set of features within Vault Enterprise that allows
  22188. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22189. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22190. This will default to Vault.Namespace field if set, or empty otherwise
  22191. type: string
  22192. tokenSecretRef:
  22193. description: TokenSecretRef authenticates with Vault by presenting a token.
  22194. properties:
  22195. key:
  22196. description: |-
  22197. A key in the referenced Secret.
  22198. Some instances of this field may be defaulted, in others it may be required.
  22199. maxLength: 253
  22200. minLength: 1
  22201. pattern: ^[-._a-zA-Z0-9]+$
  22202. type: string
  22203. name:
  22204. description: The name of the Secret resource being referred to.
  22205. maxLength: 253
  22206. minLength: 1
  22207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22208. type: string
  22209. namespace:
  22210. description: |-
  22211. The namespace of the Secret resource being referred to.
  22212. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22213. maxLength: 63
  22214. minLength: 1
  22215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22216. type: string
  22217. type: object
  22218. userPass:
  22219. description: UserPass authenticates with Vault by passing username/password pair
  22220. properties:
  22221. path:
  22222. default: userpass
  22223. description: |-
  22224. Path where the UserPassword authentication backend is mounted
  22225. in Vault, e.g: "userpass"
  22226. type: string
  22227. secretRef:
  22228. description: |-
  22229. SecretRef to a key in a Secret resource containing password for the
  22230. user used to authenticate with Vault using the UserPass authentication
  22231. method
  22232. properties:
  22233. key:
  22234. description: |-
  22235. A key in the referenced Secret.
  22236. Some instances of this field may be defaulted, in others it may be required.
  22237. maxLength: 253
  22238. minLength: 1
  22239. pattern: ^[-._a-zA-Z0-9]+$
  22240. type: string
  22241. name:
  22242. description: The name of the Secret resource being referred to.
  22243. maxLength: 253
  22244. minLength: 1
  22245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22246. type: string
  22247. namespace:
  22248. description: |-
  22249. The namespace of the Secret resource being referred to.
  22250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22251. maxLength: 63
  22252. minLength: 1
  22253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22254. type: string
  22255. type: object
  22256. username:
  22257. description: |-
  22258. Username is a username used to authenticate using the UserPass Vault
  22259. authentication method
  22260. type: string
  22261. required:
  22262. - path
  22263. - username
  22264. type: object
  22265. type: object
  22266. caBundle:
  22267. description: |-
  22268. PEM encoded CA bundle used to validate Vault server certificate. Only used
  22269. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22270. plain HTTP protocol connection. If not set the system root certificates
  22271. are used to validate the TLS connection.
  22272. format: byte
  22273. type: string
  22274. caProvider:
  22275. description: The provider for the CA bundle to use to validate Vault server certificate.
  22276. properties:
  22277. key:
  22278. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22279. maxLength: 253
  22280. minLength: 1
  22281. pattern: ^[-._a-zA-Z0-9]+$
  22282. type: string
  22283. name:
  22284. description: The name of the object located at the provider type.
  22285. maxLength: 253
  22286. minLength: 1
  22287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22288. type: string
  22289. namespace:
  22290. description: |-
  22291. The namespace the Provider type is in.
  22292. Can only be defined when used in a ClusterSecretStore.
  22293. maxLength: 63
  22294. minLength: 1
  22295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22296. type: string
  22297. type:
  22298. description: The type of provider to use such as "Secret", or "ConfigMap".
  22299. enum:
  22300. - Secret
  22301. - ConfigMap
  22302. type: string
  22303. required:
  22304. - name
  22305. - type
  22306. type: object
  22307. checkAndSet:
  22308. description: |-
  22309. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  22310. Only applies to Vault KV v2 stores. When enabled, write operations must include
  22311. the current version of the secret to prevent unintentional overwrites.
  22312. properties:
  22313. required:
  22314. description: |-
  22315. Required when true, all write operations must include a check-and-set parameter.
  22316. This helps prevent unintentional overwrites of secrets.
  22317. type: boolean
  22318. type: object
  22319. forwardInconsistent:
  22320. description: |-
  22321. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  22322. leader instead of simply retrying within a loop. This can increase performance if
  22323. the option is enabled serverside.
  22324. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  22325. type: boolean
  22326. headers:
  22327. additionalProperties:
  22328. type: string
  22329. description: Headers to be added in Vault request
  22330. type: object
  22331. namespace:
  22332. description: |-
  22333. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  22334. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22335. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22336. type: string
  22337. path:
  22338. description: |-
  22339. Path is the mount path of the Vault KV backend endpoint, e.g:
  22340. "secret". The v2 KV secret engine version specific "/data" path suffix
  22341. for fetching secrets from Vault is optional and will be appended
  22342. if not present in specified path.
  22343. type: string
  22344. readYourWrites:
  22345. description: |-
  22346. ReadYourWrites ensures isolated read-after-write semantics by
  22347. providing discovered cluster replication states in each request.
  22348. More information about eventual consistency in Vault can be found here
  22349. https://www.vaultproject.io/docs/enterprise/consistency
  22350. type: boolean
  22351. server:
  22352. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  22353. type: string
  22354. tls:
  22355. description: |-
  22356. The configuration used for client side related TLS communication, when the Vault server
  22357. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  22358. This parameter is ignored for plain HTTP protocol connection.
  22359. It's worth noting this configuration is different from the "TLS certificates auth method",
  22360. which is available under the `auth.cert` section.
  22361. properties:
  22362. certSecretRef:
  22363. description: |-
  22364. CertSecretRef is a certificate added to the transport layer
  22365. when communicating with the Vault server.
  22366. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  22367. properties:
  22368. key:
  22369. description: |-
  22370. A key in the referenced Secret.
  22371. Some instances of this field may be defaulted, in others it may be required.
  22372. maxLength: 253
  22373. minLength: 1
  22374. pattern: ^[-._a-zA-Z0-9]+$
  22375. type: string
  22376. name:
  22377. description: The name of the Secret resource being referred to.
  22378. maxLength: 253
  22379. minLength: 1
  22380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22381. type: string
  22382. namespace:
  22383. description: |-
  22384. The namespace of the Secret resource being referred to.
  22385. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22386. maxLength: 63
  22387. minLength: 1
  22388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22389. type: string
  22390. type: object
  22391. keySecretRef:
  22392. description: |-
  22393. KeySecretRef to a key in a Secret resource containing client private key
  22394. added to the transport layer when communicating with the Vault server.
  22395. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  22396. properties:
  22397. key:
  22398. description: |-
  22399. A key in the referenced Secret.
  22400. Some instances of this field may be defaulted, in others it may be required.
  22401. maxLength: 253
  22402. minLength: 1
  22403. pattern: ^[-._a-zA-Z0-9]+$
  22404. type: string
  22405. name:
  22406. description: The name of the Secret resource being referred to.
  22407. maxLength: 253
  22408. minLength: 1
  22409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22410. type: string
  22411. namespace:
  22412. description: |-
  22413. The namespace of the Secret resource being referred to.
  22414. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22415. maxLength: 63
  22416. minLength: 1
  22417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22418. type: string
  22419. type: object
  22420. type: object
  22421. version:
  22422. default: v2
  22423. description: |-
  22424. Version is the Vault KV secret engine version. This can be either "v1" or
  22425. "v2". Version defaults to "v2".
  22426. enum:
  22427. - v1
  22428. - v2
  22429. type: string
  22430. required:
  22431. - server
  22432. type: object
  22433. volcengine:
  22434. description: Volcengine configures this store to sync secrets using the Volcengine provider
  22435. properties:
  22436. auth:
  22437. description: |-
  22438. Auth defines the authentication method to use.
  22439. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  22440. properties:
  22441. secretRef:
  22442. description: |-
  22443. SecretRef defines the static credentials to use for authentication.
  22444. If not set, IRSA is used.
  22445. properties:
  22446. accessKeyID:
  22447. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  22448. properties:
  22449. key:
  22450. description: |-
  22451. A key in the referenced Secret.
  22452. Some instances of this field may be defaulted, in others it may be required.
  22453. maxLength: 253
  22454. minLength: 1
  22455. pattern: ^[-._a-zA-Z0-9]+$
  22456. type: string
  22457. name:
  22458. description: The name of the Secret resource being referred to.
  22459. maxLength: 253
  22460. minLength: 1
  22461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22462. type: string
  22463. namespace:
  22464. description: |-
  22465. The namespace of the Secret resource being referred to.
  22466. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22467. maxLength: 63
  22468. minLength: 1
  22469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22470. type: string
  22471. type: object
  22472. secretAccessKey:
  22473. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  22474. properties:
  22475. key:
  22476. description: |-
  22477. A key in the referenced Secret.
  22478. Some instances of this field may be defaulted, in others it may be required.
  22479. maxLength: 253
  22480. minLength: 1
  22481. pattern: ^[-._a-zA-Z0-9]+$
  22482. type: string
  22483. name:
  22484. description: The name of the Secret resource being referred to.
  22485. maxLength: 253
  22486. minLength: 1
  22487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22488. type: string
  22489. namespace:
  22490. description: |-
  22491. The namespace of the Secret resource being referred to.
  22492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22493. maxLength: 63
  22494. minLength: 1
  22495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22496. type: string
  22497. type: object
  22498. token:
  22499. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22500. properties:
  22501. key:
  22502. description: |-
  22503. A key in the referenced Secret.
  22504. Some instances of this field may be defaulted, in others it may be required.
  22505. maxLength: 253
  22506. minLength: 1
  22507. pattern: ^[-._a-zA-Z0-9]+$
  22508. type: string
  22509. name:
  22510. description: The name of the Secret resource being referred to.
  22511. maxLength: 253
  22512. minLength: 1
  22513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22514. type: string
  22515. namespace:
  22516. description: |-
  22517. The namespace of the Secret resource being referred to.
  22518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22519. maxLength: 63
  22520. minLength: 1
  22521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22522. type: string
  22523. type: object
  22524. required:
  22525. - accessKeyID
  22526. - secretAccessKey
  22527. type: object
  22528. type: object
  22529. region:
  22530. description: Region specifies the Volcengine region to connect to.
  22531. type: string
  22532. required:
  22533. - region
  22534. type: object
  22535. webhook:
  22536. description: Webhook configures this store to sync secrets using a generic templated webhook
  22537. properties:
  22538. auth:
  22539. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22540. maxProperties: 1
  22541. minProperties: 1
  22542. properties:
  22543. ntlm:
  22544. description: NTLMProtocol configures the store to use NTLM for auth
  22545. properties:
  22546. passwordSecret:
  22547. description: |-
  22548. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22549. In some instances, `key` is a required field.
  22550. properties:
  22551. key:
  22552. description: |-
  22553. A key in the referenced Secret.
  22554. Some instances of this field may be defaulted, in others it may be required.
  22555. maxLength: 253
  22556. minLength: 1
  22557. pattern: ^[-._a-zA-Z0-9]+$
  22558. type: string
  22559. name:
  22560. description: The name of the Secret resource being referred to.
  22561. maxLength: 253
  22562. minLength: 1
  22563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22564. type: string
  22565. namespace:
  22566. description: |-
  22567. The namespace of the Secret resource being referred to.
  22568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22569. maxLength: 63
  22570. minLength: 1
  22571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22572. type: string
  22573. type: object
  22574. usernameSecret:
  22575. description: |-
  22576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22577. In some instances, `key` is a required field.
  22578. properties:
  22579. key:
  22580. description: |-
  22581. A key in the referenced Secret.
  22582. Some instances of this field may be defaulted, in others it may be required.
  22583. maxLength: 253
  22584. minLength: 1
  22585. pattern: ^[-._a-zA-Z0-9]+$
  22586. type: string
  22587. name:
  22588. description: The name of the Secret resource being referred to.
  22589. maxLength: 253
  22590. minLength: 1
  22591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22592. type: string
  22593. namespace:
  22594. description: |-
  22595. The namespace of the Secret resource being referred to.
  22596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22597. maxLength: 63
  22598. minLength: 1
  22599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22600. type: string
  22601. type: object
  22602. required:
  22603. - passwordSecret
  22604. - usernameSecret
  22605. type: object
  22606. type: object
  22607. body:
  22608. description: Body
  22609. type: string
  22610. caBundle:
  22611. description: |-
  22612. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22613. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22614. plain HTTP protocol connection. If not set the system root certificates
  22615. are used to validate the TLS connection.
  22616. format: byte
  22617. type: string
  22618. caProvider:
  22619. description: The provider for the CA bundle to use to validate webhook server certificate.
  22620. properties:
  22621. key:
  22622. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22623. maxLength: 253
  22624. minLength: 1
  22625. pattern: ^[-._a-zA-Z0-9]+$
  22626. type: string
  22627. name:
  22628. description: The name of the object located at the provider type.
  22629. maxLength: 253
  22630. minLength: 1
  22631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22632. type: string
  22633. namespace:
  22634. description: The namespace the Provider type is in.
  22635. maxLength: 63
  22636. minLength: 1
  22637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22638. type: string
  22639. type:
  22640. description: The type of provider to use such as "Secret", or "ConfigMap".
  22641. enum:
  22642. - Secret
  22643. - ConfigMap
  22644. type: string
  22645. required:
  22646. - name
  22647. - type
  22648. type: object
  22649. headers:
  22650. additionalProperties:
  22651. type: string
  22652. description: Headers
  22653. type: object
  22654. method:
  22655. description: Webhook Method
  22656. type: string
  22657. result:
  22658. description: Result formatting
  22659. properties:
  22660. jsonPath:
  22661. description: Json path of return value
  22662. type: string
  22663. type: object
  22664. secrets:
  22665. description: |-
  22666. Secrets to fill in templates
  22667. These secrets will be passed to the templating function as key value pairs under the given name
  22668. items:
  22669. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22670. properties:
  22671. name:
  22672. description: Name of this secret in templates
  22673. type: string
  22674. secretRef:
  22675. description: Secret ref to fill in credentials
  22676. properties:
  22677. key:
  22678. description: |-
  22679. A key in the referenced Secret.
  22680. Some instances of this field may be defaulted, in others it may be required.
  22681. maxLength: 253
  22682. minLength: 1
  22683. pattern: ^[-._a-zA-Z0-9]+$
  22684. type: string
  22685. name:
  22686. description: The name of the Secret resource being referred to.
  22687. maxLength: 253
  22688. minLength: 1
  22689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22690. type: string
  22691. namespace:
  22692. description: |-
  22693. The namespace of the Secret resource being referred to.
  22694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22695. maxLength: 63
  22696. minLength: 1
  22697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22698. type: string
  22699. type: object
  22700. required:
  22701. - name
  22702. - secretRef
  22703. type: object
  22704. type: array
  22705. timeout:
  22706. description: Timeout
  22707. type: string
  22708. url:
  22709. description: Webhook url to call
  22710. type: string
  22711. required:
  22712. - url
  22713. type: object
  22714. yandexcertificatemanager:
  22715. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22716. properties:
  22717. apiEndpoint:
  22718. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22719. type: string
  22720. auth:
  22721. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22722. properties:
  22723. authorizedKeySecretRef:
  22724. description: The authorized key used for authentication
  22725. properties:
  22726. key:
  22727. description: |-
  22728. A key in the referenced Secret.
  22729. Some instances of this field may be defaulted, in others it may be required.
  22730. maxLength: 253
  22731. minLength: 1
  22732. pattern: ^[-._a-zA-Z0-9]+$
  22733. type: string
  22734. name:
  22735. description: The name of the Secret resource being referred to.
  22736. maxLength: 253
  22737. minLength: 1
  22738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22739. type: string
  22740. namespace:
  22741. description: |-
  22742. The namespace of the Secret resource being referred to.
  22743. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22744. maxLength: 63
  22745. minLength: 1
  22746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22747. type: string
  22748. type: object
  22749. type: object
  22750. caProvider:
  22751. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22752. properties:
  22753. certSecretRef:
  22754. description: |-
  22755. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22756. In some instances, `key` is a required field.
  22757. properties:
  22758. key:
  22759. description: |-
  22760. A key in the referenced Secret.
  22761. Some instances of this field may be defaulted, in others it may be required.
  22762. maxLength: 253
  22763. minLength: 1
  22764. pattern: ^[-._a-zA-Z0-9]+$
  22765. type: string
  22766. name:
  22767. description: The name of the Secret resource being referred to.
  22768. maxLength: 253
  22769. minLength: 1
  22770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22771. type: string
  22772. namespace:
  22773. description: |-
  22774. The namespace of the Secret resource being referred to.
  22775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22776. maxLength: 63
  22777. minLength: 1
  22778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22779. type: string
  22780. type: object
  22781. type: object
  22782. fetching:
  22783. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22784. maxProperties: 1
  22785. minProperties: 1
  22786. properties:
  22787. byID:
  22788. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22789. type: object
  22790. byName:
  22791. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22792. properties:
  22793. folderID:
  22794. description: The folder to fetch secrets from
  22795. type: string
  22796. required:
  22797. - folderID
  22798. type: object
  22799. type: object
  22800. required:
  22801. - auth
  22802. type: object
  22803. yandexlockbox:
  22804. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22805. properties:
  22806. apiEndpoint:
  22807. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22808. type: string
  22809. auth:
  22810. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22811. properties:
  22812. authorizedKeySecretRef:
  22813. description: The authorized key used for authentication
  22814. properties:
  22815. key:
  22816. description: |-
  22817. A key in the referenced Secret.
  22818. Some instances of this field may be defaulted, in others it may be required.
  22819. maxLength: 253
  22820. minLength: 1
  22821. pattern: ^[-._a-zA-Z0-9]+$
  22822. type: string
  22823. name:
  22824. description: The name of the Secret resource being referred to.
  22825. maxLength: 253
  22826. minLength: 1
  22827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22828. type: string
  22829. namespace:
  22830. description: |-
  22831. The namespace of the Secret resource being referred to.
  22832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22833. maxLength: 63
  22834. minLength: 1
  22835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22836. type: string
  22837. type: object
  22838. type: object
  22839. caProvider:
  22840. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22841. properties:
  22842. certSecretRef:
  22843. description: |-
  22844. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22845. In some instances, `key` is a required field.
  22846. properties:
  22847. key:
  22848. description: |-
  22849. A key in the referenced Secret.
  22850. Some instances of this field may be defaulted, in others it may be required.
  22851. maxLength: 253
  22852. minLength: 1
  22853. pattern: ^[-._a-zA-Z0-9]+$
  22854. type: string
  22855. name:
  22856. description: The name of the Secret resource being referred to.
  22857. maxLength: 253
  22858. minLength: 1
  22859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22860. type: string
  22861. namespace:
  22862. description: |-
  22863. The namespace of the Secret resource being referred to.
  22864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22865. maxLength: 63
  22866. minLength: 1
  22867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22868. type: string
  22869. type: object
  22870. type: object
  22871. fetching:
  22872. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22873. maxProperties: 1
  22874. minProperties: 1
  22875. properties:
  22876. byID:
  22877. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22878. type: object
  22879. byName:
  22880. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22881. properties:
  22882. folderID:
  22883. description: The folder to fetch secrets from
  22884. type: string
  22885. required:
  22886. - folderID
  22887. type: object
  22888. type: object
  22889. required:
  22890. - auth
  22891. type: object
  22892. type: object
  22893. refreshInterval:
  22894. anyOf:
  22895. - type: integer
  22896. - type: string
  22897. description: |-
  22898. Used to configure store refresh interval. Accepts either an integer number
  22899. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22900. 0 will default to the controller config.
  22901. x-kubernetes-int-or-string: true
  22902. retrySettings:
  22903. description: Used to configure HTTP retries on failures.
  22904. properties:
  22905. maxRetries:
  22906. format: int32
  22907. type: integer
  22908. retryInterval:
  22909. type: string
  22910. type: object
  22911. required:
  22912. - provider
  22913. type: object
  22914. status:
  22915. description: SecretStoreStatus defines the observed state of the SecretStore.
  22916. properties:
  22917. capabilities:
  22918. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22919. type: string
  22920. conditions:
  22921. items:
  22922. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22923. properties:
  22924. lastTransitionTime:
  22925. format: date-time
  22926. type: string
  22927. message:
  22928. type: string
  22929. reason:
  22930. type: string
  22931. status:
  22932. type: string
  22933. type:
  22934. description: SecretStoreConditionType represents the condition of the SecretStore.
  22935. type: string
  22936. required:
  22937. - status
  22938. - type
  22939. type: object
  22940. type: array
  22941. type: object
  22942. type: object
  22943. served: true
  22944. storage: true
  22945. subresources:
  22946. status: {}
  22947. - additionalPrinterColumns:
  22948. - jsonPath: .metadata.creationTimestamp
  22949. name: AGE
  22950. type: date
  22951. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22952. name: Status
  22953. type: string
  22954. - jsonPath: .status.capabilities
  22955. name: Capabilities
  22956. type: string
  22957. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22958. name: Ready
  22959. type: string
  22960. deprecated: true
  22961. name: v1beta1
  22962. schema:
  22963. openAPIV3Schema:
  22964. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22965. properties:
  22966. apiVersion:
  22967. description: |-
  22968. APIVersion defines the versioned schema of this representation of an object.
  22969. Servers should convert recognized schemas to the latest internal value, and
  22970. may reject unrecognized values.
  22971. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22972. type: string
  22973. kind:
  22974. description: |-
  22975. Kind is a string value representing the REST resource this object represents.
  22976. Servers may infer this from the endpoint the client submits requests to.
  22977. Cannot be updated.
  22978. In CamelCase.
  22979. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22980. type: string
  22981. metadata:
  22982. type: object
  22983. spec:
  22984. description: SecretStoreSpec defines the desired state of SecretStore.
  22985. properties:
  22986. conditions:
  22987. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22988. items:
  22989. description: |-
  22990. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22991. for a ClusterSecretStore instance.
  22992. properties:
  22993. namespaceRegexes:
  22994. description: Choose namespaces by using regex matching
  22995. items:
  22996. type: string
  22997. type: array
  22998. namespaceSelector:
  22999. description: Choose namespace using a labelSelector
  23000. properties:
  23001. matchExpressions:
  23002. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  23003. items:
  23004. description: |-
  23005. A label selector requirement is a selector that contains values, a key, and an operator that
  23006. relates the key and values.
  23007. properties:
  23008. key:
  23009. description: key is the label key that the selector applies to.
  23010. type: string
  23011. operator:
  23012. description: |-
  23013. operator represents a key's relationship to a set of values.
  23014. Valid operators are In, NotIn, Exists and DoesNotExist.
  23015. type: string
  23016. values:
  23017. description: |-
  23018. values is an array of string values. If the operator is In or NotIn,
  23019. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  23020. the values array must be empty. This array is replaced during a strategic
  23021. merge patch.
  23022. items:
  23023. type: string
  23024. type: array
  23025. x-kubernetes-list-type: atomic
  23026. required:
  23027. - key
  23028. - operator
  23029. type: object
  23030. type: array
  23031. x-kubernetes-list-type: atomic
  23032. matchLabels:
  23033. additionalProperties:
  23034. type: string
  23035. description: |-
  23036. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  23037. map is equivalent to an element of matchExpressions, whose key field is "key", the
  23038. operator is "In", and the values array contains only "value". The requirements are ANDed.
  23039. type: object
  23040. type: object
  23041. x-kubernetes-map-type: atomic
  23042. namespaces:
  23043. description: Choose namespaces by name
  23044. items:
  23045. maxLength: 63
  23046. minLength: 1
  23047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23048. type: string
  23049. type: array
  23050. type: object
  23051. type: array
  23052. controller:
  23053. description: |-
  23054. Used to select the correct ESO controller (think: ingress.ingressClassName)
  23055. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  23056. type: string
  23057. provider:
  23058. description: Used to configure the provider. Only one provider may be set
  23059. maxProperties: 1
  23060. minProperties: 1
  23061. properties:
  23062. akeyless:
  23063. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  23064. properties:
  23065. akeylessGWApiURL:
  23066. description: Akeyless GW API Url from which the secrets to be fetched from.
  23067. type: string
  23068. authSecretRef:
  23069. description: Auth configures how the operator authenticates with Akeyless.
  23070. properties:
  23071. kubernetesAuth:
  23072. description: |-
  23073. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  23074. token stored in the named Secret resource.
  23075. properties:
  23076. accessID:
  23077. description: the Akeyless Kubernetes auth-method access-id
  23078. type: string
  23079. k8sConfName:
  23080. description: Kubernetes-auth configuration name in Akeyless-Gateway
  23081. type: string
  23082. secretRef:
  23083. description: |-
  23084. Optional secret field containing a Kubernetes ServiceAccount JWT used
  23085. for authenticating with Akeyless. If a name is specified without a key,
  23086. `token` is the default. If one is not specified, the one bound to
  23087. the controller will be used.
  23088. properties:
  23089. key:
  23090. description: |-
  23091. A key in the referenced Secret.
  23092. Some instances of this field may be defaulted, in others it may be required.
  23093. maxLength: 253
  23094. minLength: 1
  23095. pattern: ^[-._a-zA-Z0-9]+$
  23096. type: string
  23097. name:
  23098. description: The name of the Secret resource being referred to.
  23099. maxLength: 253
  23100. minLength: 1
  23101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23102. type: string
  23103. namespace:
  23104. description: |-
  23105. The namespace of the Secret resource being referred to.
  23106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23107. maxLength: 63
  23108. minLength: 1
  23109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23110. type: string
  23111. type: object
  23112. serviceAccountRef:
  23113. description: |-
  23114. Optional service account field containing the name of a kubernetes ServiceAccount.
  23115. If the service account is specified, the service account secret token JWT will be used
  23116. for authenticating with Akeyless. If the service account selector is not supplied,
  23117. the secretRef will be used instead.
  23118. properties:
  23119. audiences:
  23120. description: |-
  23121. Audience specifies the `aud` claim for the service account token
  23122. Some providers automatically extend the audience field based on well-known annotations for workload
  23123. identity (e.g. IRSA or GCP Workload Identity)
  23124. items:
  23125. type: string
  23126. type: array
  23127. name:
  23128. description: The name of the ServiceAccount resource being referred to.
  23129. maxLength: 253
  23130. minLength: 1
  23131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23132. type: string
  23133. namespace:
  23134. description: |-
  23135. Namespace of the resource being referred to.
  23136. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23137. maxLength: 63
  23138. minLength: 1
  23139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23140. type: string
  23141. required:
  23142. - name
  23143. type: object
  23144. required:
  23145. - accessID
  23146. - k8sConfName
  23147. type: object
  23148. secretRef:
  23149. description: |-
  23150. Reference to a Secret that contains the details
  23151. to authenticate with Akeyless.
  23152. properties:
  23153. accessID:
  23154. description: The SecretAccessID is used for authentication
  23155. properties:
  23156. key:
  23157. description: |-
  23158. A key in the referenced Secret.
  23159. Some instances of this field may be defaulted, in others it may be required.
  23160. maxLength: 253
  23161. minLength: 1
  23162. pattern: ^[-._a-zA-Z0-9]+$
  23163. type: string
  23164. name:
  23165. description: The name of the Secret resource being referred to.
  23166. maxLength: 253
  23167. minLength: 1
  23168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23169. type: string
  23170. namespace:
  23171. description: |-
  23172. The namespace of the Secret resource being referred to.
  23173. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23174. maxLength: 63
  23175. minLength: 1
  23176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23177. type: string
  23178. type: object
  23179. accessType:
  23180. description: |-
  23181. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23182. In some instances, `key` is a required field.
  23183. properties:
  23184. key:
  23185. description: |-
  23186. A key in the referenced Secret.
  23187. Some instances of this field may be defaulted, in others it may be required.
  23188. maxLength: 253
  23189. minLength: 1
  23190. pattern: ^[-._a-zA-Z0-9]+$
  23191. type: string
  23192. name:
  23193. description: The name of the Secret resource being referred to.
  23194. maxLength: 253
  23195. minLength: 1
  23196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23197. type: string
  23198. namespace:
  23199. description: |-
  23200. The namespace of the Secret resource being referred to.
  23201. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23202. maxLength: 63
  23203. minLength: 1
  23204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23205. type: string
  23206. type: object
  23207. accessTypeParam:
  23208. description: |-
  23209. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23210. In some instances, `key` is a required field.
  23211. properties:
  23212. key:
  23213. description: |-
  23214. A key in the referenced Secret.
  23215. Some instances of this field may be defaulted, in others it may be required.
  23216. maxLength: 253
  23217. minLength: 1
  23218. pattern: ^[-._a-zA-Z0-9]+$
  23219. type: string
  23220. name:
  23221. description: The name of the Secret resource being referred to.
  23222. maxLength: 253
  23223. minLength: 1
  23224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23225. type: string
  23226. namespace:
  23227. description: |-
  23228. The namespace of the Secret resource being referred to.
  23229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23230. maxLength: 63
  23231. minLength: 1
  23232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23233. type: string
  23234. type: object
  23235. type: object
  23236. type: object
  23237. caBundle:
  23238. description: |-
  23239. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  23240. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  23241. are used to validate the TLS connection.
  23242. format: byte
  23243. type: string
  23244. caProvider:
  23245. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  23246. properties:
  23247. key:
  23248. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23249. maxLength: 253
  23250. minLength: 1
  23251. pattern: ^[-._a-zA-Z0-9]+$
  23252. type: string
  23253. name:
  23254. description: The name of the object located at the provider type.
  23255. maxLength: 253
  23256. minLength: 1
  23257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23258. type: string
  23259. namespace:
  23260. description: |-
  23261. The namespace the Provider type is in.
  23262. Can only be defined when used in a ClusterSecretStore.
  23263. maxLength: 63
  23264. minLength: 1
  23265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23266. type: string
  23267. type:
  23268. description: The type of provider to use such as "Secret", or "ConfigMap".
  23269. enum:
  23270. - Secret
  23271. - ConfigMap
  23272. type: string
  23273. required:
  23274. - name
  23275. - type
  23276. type: object
  23277. required:
  23278. - akeylessGWApiURL
  23279. - authSecretRef
  23280. type: object
  23281. alibaba:
  23282. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  23283. properties:
  23284. auth:
  23285. description: AlibabaAuth contains a secretRef for credentials.
  23286. properties:
  23287. rrsa:
  23288. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  23289. properties:
  23290. oidcProviderArn:
  23291. type: string
  23292. oidcTokenFilePath:
  23293. type: string
  23294. roleArn:
  23295. type: string
  23296. sessionName:
  23297. type: string
  23298. required:
  23299. - oidcProviderArn
  23300. - oidcTokenFilePath
  23301. - roleArn
  23302. - sessionName
  23303. type: object
  23304. secretRef:
  23305. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  23306. properties:
  23307. accessKeyIDSecretRef:
  23308. description: The AccessKeyID is used for authentication
  23309. properties:
  23310. key:
  23311. description: |-
  23312. A key in the referenced Secret.
  23313. Some instances of this field may be defaulted, in others it may be required.
  23314. maxLength: 253
  23315. minLength: 1
  23316. pattern: ^[-._a-zA-Z0-9]+$
  23317. type: string
  23318. name:
  23319. description: The name of the Secret resource being referred to.
  23320. maxLength: 253
  23321. minLength: 1
  23322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23323. type: string
  23324. namespace:
  23325. description: |-
  23326. The namespace of the Secret resource being referred to.
  23327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23328. maxLength: 63
  23329. minLength: 1
  23330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23331. type: string
  23332. type: object
  23333. accessKeySecretSecretRef:
  23334. description: The AccessKeySecret is used for authentication
  23335. properties:
  23336. key:
  23337. description: |-
  23338. A key in the referenced Secret.
  23339. Some instances of this field may be defaulted, in others it may be required.
  23340. maxLength: 253
  23341. minLength: 1
  23342. pattern: ^[-._a-zA-Z0-9]+$
  23343. type: string
  23344. name:
  23345. description: The name of the Secret resource being referred to.
  23346. maxLength: 253
  23347. minLength: 1
  23348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23349. type: string
  23350. namespace:
  23351. description: |-
  23352. The namespace of the Secret resource being referred to.
  23353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23354. maxLength: 63
  23355. minLength: 1
  23356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23357. type: string
  23358. type: object
  23359. required:
  23360. - accessKeyIDSecretRef
  23361. - accessKeySecretSecretRef
  23362. type: object
  23363. type: object
  23364. regionID:
  23365. description: Alibaba Region to be used for the provider
  23366. type: string
  23367. required:
  23368. - auth
  23369. - regionID
  23370. type: object
  23371. aws:
  23372. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  23373. properties:
  23374. additionalRoles:
  23375. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  23376. items:
  23377. type: string
  23378. type: array
  23379. auth:
  23380. description: |-
  23381. Auth defines the information necessary to authenticate against AWS
  23382. if not set aws sdk will infer credentials from your environment
  23383. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  23384. properties:
  23385. jwt:
  23386. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  23387. properties:
  23388. serviceAccountRef:
  23389. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23390. properties:
  23391. audiences:
  23392. description: |-
  23393. Audience specifies the `aud` claim for the service account token
  23394. Some providers automatically extend the audience field based on well-known annotations for workload
  23395. identity (e.g. IRSA or GCP Workload Identity)
  23396. items:
  23397. type: string
  23398. type: array
  23399. name:
  23400. description: The name of the ServiceAccount resource being referred to.
  23401. maxLength: 253
  23402. minLength: 1
  23403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23404. type: string
  23405. namespace:
  23406. description: |-
  23407. Namespace of the resource being referred to.
  23408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23409. maxLength: 63
  23410. minLength: 1
  23411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23412. type: string
  23413. required:
  23414. - name
  23415. type: object
  23416. type: object
  23417. secretRef:
  23418. description: |-
  23419. AWSAuthSecretRef holds secret references for AWS credentials
  23420. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  23421. properties:
  23422. accessKeyIDSecretRef:
  23423. description: The AccessKeyID is used for authentication
  23424. properties:
  23425. key:
  23426. description: |-
  23427. A key in the referenced Secret.
  23428. Some instances of this field may be defaulted, in others it may be required.
  23429. maxLength: 253
  23430. minLength: 1
  23431. pattern: ^[-._a-zA-Z0-9]+$
  23432. type: string
  23433. name:
  23434. description: The name of the Secret resource being referred to.
  23435. maxLength: 253
  23436. minLength: 1
  23437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23438. type: string
  23439. namespace:
  23440. description: |-
  23441. The namespace of the Secret resource being referred to.
  23442. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23443. maxLength: 63
  23444. minLength: 1
  23445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23446. type: string
  23447. type: object
  23448. secretAccessKeySecretRef:
  23449. description: The SecretAccessKey is used for authentication
  23450. properties:
  23451. key:
  23452. description: |-
  23453. A key in the referenced Secret.
  23454. Some instances of this field may be defaulted, in others it may be required.
  23455. maxLength: 253
  23456. minLength: 1
  23457. pattern: ^[-._a-zA-Z0-9]+$
  23458. type: string
  23459. name:
  23460. description: The name of the Secret resource being referred to.
  23461. maxLength: 253
  23462. minLength: 1
  23463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23464. type: string
  23465. namespace:
  23466. description: |-
  23467. The namespace of the Secret resource being referred to.
  23468. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23469. maxLength: 63
  23470. minLength: 1
  23471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23472. type: string
  23473. type: object
  23474. sessionTokenSecretRef:
  23475. description: |-
  23476. The SessionToken used for authentication
  23477. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23478. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23479. properties:
  23480. key:
  23481. description: |-
  23482. A key in the referenced Secret.
  23483. Some instances of this field may be defaulted, in others it may be required.
  23484. maxLength: 253
  23485. minLength: 1
  23486. pattern: ^[-._a-zA-Z0-9]+$
  23487. type: string
  23488. name:
  23489. description: The name of the Secret resource being referred to.
  23490. maxLength: 253
  23491. minLength: 1
  23492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23493. type: string
  23494. namespace:
  23495. description: |-
  23496. The namespace of the Secret resource being referred to.
  23497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23498. maxLength: 63
  23499. minLength: 1
  23500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23501. type: string
  23502. type: object
  23503. type: object
  23504. type: object
  23505. externalID:
  23506. description: AWS External ID set on assumed IAM roles
  23507. type: string
  23508. prefix:
  23509. description: Prefix adds a prefix to all retrieved values.
  23510. type: string
  23511. region:
  23512. description: AWS Region to be used for the provider
  23513. type: string
  23514. role:
  23515. description: Role is a Role ARN which the provider will assume
  23516. type: string
  23517. secretsManager:
  23518. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23519. properties:
  23520. forceDeleteWithoutRecovery:
  23521. description: |-
  23522. Specifies whether to delete the secret without any recovery window. You
  23523. can't use both this parameter and RecoveryWindowInDays in the same call.
  23524. If you don't use either, then by default Secrets Manager uses a 30 day
  23525. recovery window.
  23526. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23527. type: boolean
  23528. recoveryWindowInDays:
  23529. description: |-
  23530. The number of days from 7 to 30 that Secrets Manager waits before
  23531. permanently deleting the secret. You can't use both this parameter and
  23532. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23533. then by default Secrets Manager uses a 30 day recovery window.
  23534. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23535. format: int64
  23536. type: integer
  23537. type: object
  23538. service:
  23539. description: Service defines which service should be used to fetch the secrets
  23540. enum:
  23541. - SecretsManager
  23542. - ParameterStore
  23543. type: string
  23544. sessionTags:
  23545. description: AWS STS assume role session tags
  23546. items:
  23547. description: Tag defines a tag key and value for AWS resources.
  23548. properties:
  23549. key:
  23550. type: string
  23551. value:
  23552. type: string
  23553. required:
  23554. - key
  23555. - value
  23556. type: object
  23557. type: array
  23558. transitiveTagKeys:
  23559. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23560. items:
  23561. type: string
  23562. type: array
  23563. required:
  23564. - region
  23565. - service
  23566. type: object
  23567. azurekv:
  23568. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23569. properties:
  23570. authSecretRef:
  23571. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23572. properties:
  23573. clientCertificate:
  23574. description: The Azure ClientCertificate of the service principle used for authentication.
  23575. properties:
  23576. key:
  23577. description: |-
  23578. A key in the referenced Secret.
  23579. Some instances of this field may be defaulted, in others it may be required.
  23580. maxLength: 253
  23581. minLength: 1
  23582. pattern: ^[-._a-zA-Z0-9]+$
  23583. type: string
  23584. name:
  23585. description: The name of the Secret resource being referred to.
  23586. maxLength: 253
  23587. minLength: 1
  23588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23589. type: string
  23590. namespace:
  23591. description: |-
  23592. The namespace of the Secret resource being referred to.
  23593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23594. maxLength: 63
  23595. minLength: 1
  23596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23597. type: string
  23598. type: object
  23599. clientId:
  23600. description: The Azure clientId of the service principle or managed identity used for authentication.
  23601. properties:
  23602. key:
  23603. description: |-
  23604. A key in the referenced Secret.
  23605. Some instances of this field may be defaulted, in others it may be required.
  23606. maxLength: 253
  23607. minLength: 1
  23608. pattern: ^[-._a-zA-Z0-9]+$
  23609. type: string
  23610. name:
  23611. description: The name of the Secret resource being referred to.
  23612. maxLength: 253
  23613. minLength: 1
  23614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23615. type: string
  23616. namespace:
  23617. description: |-
  23618. The namespace of the Secret resource being referred to.
  23619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23620. maxLength: 63
  23621. minLength: 1
  23622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23623. type: string
  23624. type: object
  23625. clientSecret:
  23626. description: The Azure ClientSecret of the service principle used for authentication.
  23627. properties:
  23628. key:
  23629. description: |-
  23630. A key in the referenced Secret.
  23631. Some instances of this field may be defaulted, in others it may be required.
  23632. maxLength: 253
  23633. minLength: 1
  23634. pattern: ^[-._a-zA-Z0-9]+$
  23635. type: string
  23636. name:
  23637. description: The name of the Secret resource being referred to.
  23638. maxLength: 253
  23639. minLength: 1
  23640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23641. type: string
  23642. namespace:
  23643. description: |-
  23644. The namespace of the Secret resource being referred to.
  23645. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23646. maxLength: 63
  23647. minLength: 1
  23648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23649. type: string
  23650. type: object
  23651. tenantId:
  23652. description: The Azure tenantId of the managed identity used for authentication.
  23653. properties:
  23654. key:
  23655. description: |-
  23656. A key in the referenced Secret.
  23657. Some instances of this field may be defaulted, in others it may be required.
  23658. maxLength: 253
  23659. minLength: 1
  23660. pattern: ^[-._a-zA-Z0-9]+$
  23661. type: string
  23662. name:
  23663. description: The name of the Secret resource being referred to.
  23664. maxLength: 253
  23665. minLength: 1
  23666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23667. type: string
  23668. namespace:
  23669. description: |-
  23670. The namespace of the Secret resource being referred to.
  23671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23672. maxLength: 63
  23673. minLength: 1
  23674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23675. type: string
  23676. type: object
  23677. type: object
  23678. authType:
  23679. default: ServicePrincipal
  23680. description: |-
  23681. Auth type defines how to authenticate to the keyvault service.
  23682. Valid values are:
  23683. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23684. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23685. enum:
  23686. - ServicePrincipal
  23687. - ManagedIdentity
  23688. - WorkloadIdentity
  23689. type: string
  23690. environmentType:
  23691. default: PublicCloud
  23692. description: |-
  23693. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23694. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23695. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23696. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23697. enum:
  23698. - PublicCloud
  23699. - USGovernmentCloud
  23700. - ChinaCloud
  23701. - GermanCloud
  23702. type: string
  23703. identityId:
  23704. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23705. type: string
  23706. serviceAccountRef:
  23707. description: |-
  23708. ServiceAccountRef specified the service account
  23709. that should be used when authenticating with WorkloadIdentity.
  23710. properties:
  23711. audiences:
  23712. description: |-
  23713. Audience specifies the `aud` claim for the service account token
  23714. Some providers automatically extend the audience field based on well-known annotations for workload
  23715. identity (e.g. IRSA or GCP Workload Identity)
  23716. items:
  23717. type: string
  23718. type: array
  23719. name:
  23720. description: The name of the ServiceAccount resource being referred to.
  23721. maxLength: 253
  23722. minLength: 1
  23723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23724. type: string
  23725. namespace:
  23726. description: |-
  23727. Namespace of the resource being referred to.
  23728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23729. maxLength: 63
  23730. minLength: 1
  23731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23732. type: string
  23733. required:
  23734. - name
  23735. type: object
  23736. tenantId:
  23737. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23738. type: string
  23739. vaultUrl:
  23740. description: Vault Url from which the secrets to be fetched from.
  23741. type: string
  23742. required:
  23743. - vaultUrl
  23744. type: object
  23745. beyondtrust:
  23746. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23747. properties:
  23748. auth:
  23749. description: Auth configures how the operator authenticates with Beyondtrust.
  23750. properties:
  23751. apiKey:
  23752. description: APIKey If not provided then ClientID/ClientSecret become required.
  23753. properties:
  23754. secretRef:
  23755. description: SecretRef references a key in a secret that will be used as value.
  23756. properties:
  23757. key:
  23758. description: |-
  23759. A key in the referenced Secret.
  23760. Some instances of this field may be defaulted, in others it may be required.
  23761. maxLength: 253
  23762. minLength: 1
  23763. pattern: ^[-._a-zA-Z0-9]+$
  23764. type: string
  23765. name:
  23766. description: The name of the Secret resource being referred to.
  23767. maxLength: 253
  23768. minLength: 1
  23769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23770. type: string
  23771. namespace:
  23772. description: |-
  23773. The namespace of the Secret resource being referred to.
  23774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23775. maxLength: 63
  23776. minLength: 1
  23777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23778. type: string
  23779. type: object
  23780. value:
  23781. description: Value can be specified directly to set a value without using a secret.
  23782. type: string
  23783. type: object
  23784. certificate:
  23785. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23786. properties:
  23787. secretRef:
  23788. description: SecretRef references a key in a secret that will be used as value.
  23789. properties:
  23790. key:
  23791. description: |-
  23792. A key in the referenced Secret.
  23793. Some instances of this field may be defaulted, in others it may be required.
  23794. maxLength: 253
  23795. minLength: 1
  23796. pattern: ^[-._a-zA-Z0-9]+$
  23797. type: string
  23798. name:
  23799. description: The name of the Secret resource being referred to.
  23800. maxLength: 253
  23801. minLength: 1
  23802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23803. type: string
  23804. namespace:
  23805. description: |-
  23806. The namespace of the Secret resource being referred to.
  23807. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23808. maxLength: 63
  23809. minLength: 1
  23810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23811. type: string
  23812. type: object
  23813. value:
  23814. description: Value can be specified directly to set a value without using a secret.
  23815. type: string
  23816. type: object
  23817. certificateKey:
  23818. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23819. properties:
  23820. secretRef:
  23821. description: SecretRef references a key in a secret that will be used as value.
  23822. properties:
  23823. key:
  23824. description: |-
  23825. A key in the referenced Secret.
  23826. Some instances of this field may be defaulted, in others it may be required.
  23827. maxLength: 253
  23828. minLength: 1
  23829. pattern: ^[-._a-zA-Z0-9]+$
  23830. type: string
  23831. name:
  23832. description: The name of the Secret resource being referred to.
  23833. maxLength: 253
  23834. minLength: 1
  23835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23836. type: string
  23837. namespace:
  23838. description: |-
  23839. The namespace of the Secret resource being referred to.
  23840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23841. maxLength: 63
  23842. minLength: 1
  23843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23844. type: string
  23845. type: object
  23846. value:
  23847. description: Value can be specified directly to set a value without using a secret.
  23848. type: string
  23849. type: object
  23850. clientId:
  23851. description: ClientID is the API OAuth Client ID.
  23852. properties:
  23853. secretRef:
  23854. description: SecretRef references a key in a secret that will be used as value.
  23855. properties:
  23856. key:
  23857. description: |-
  23858. A key in the referenced Secret.
  23859. Some instances of this field may be defaulted, in others it may be required.
  23860. maxLength: 253
  23861. minLength: 1
  23862. pattern: ^[-._a-zA-Z0-9]+$
  23863. type: string
  23864. name:
  23865. description: The name of the Secret resource being referred to.
  23866. maxLength: 253
  23867. minLength: 1
  23868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23869. type: string
  23870. namespace:
  23871. description: |-
  23872. The namespace of the Secret resource being referred to.
  23873. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23874. maxLength: 63
  23875. minLength: 1
  23876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23877. type: string
  23878. type: object
  23879. value:
  23880. description: Value can be specified directly to set a value without using a secret.
  23881. type: string
  23882. type: object
  23883. clientSecret:
  23884. description: ClientSecret is the API OAuth Client Secret.
  23885. properties:
  23886. secretRef:
  23887. description: SecretRef references a key in a secret that will be used as value.
  23888. properties:
  23889. key:
  23890. description: |-
  23891. A key in the referenced Secret.
  23892. Some instances of this field may be defaulted, in others it may be required.
  23893. maxLength: 253
  23894. minLength: 1
  23895. pattern: ^[-._a-zA-Z0-9]+$
  23896. type: string
  23897. name:
  23898. description: The name of the Secret resource being referred to.
  23899. maxLength: 253
  23900. minLength: 1
  23901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23902. type: string
  23903. namespace:
  23904. description: |-
  23905. The namespace of the Secret resource being referred to.
  23906. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23907. maxLength: 63
  23908. minLength: 1
  23909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23910. type: string
  23911. type: object
  23912. value:
  23913. description: Value can be specified directly to set a value without using a secret.
  23914. type: string
  23915. type: object
  23916. type: object
  23917. server:
  23918. description: Auth configures how API server works.
  23919. properties:
  23920. apiUrl:
  23921. type: string
  23922. apiVersion:
  23923. type: string
  23924. clientTimeOutSeconds:
  23925. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23926. type: integer
  23927. decrypt:
  23928. default: true
  23929. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23930. type: boolean
  23931. retrievalType:
  23932. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23933. type: string
  23934. separator:
  23935. description: A character that separates the folder names.
  23936. type: string
  23937. verifyCA:
  23938. type: boolean
  23939. required:
  23940. - apiUrl
  23941. - verifyCA
  23942. type: object
  23943. required:
  23944. - auth
  23945. - server
  23946. type: object
  23947. bitwardensecretsmanager:
  23948. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23949. properties:
  23950. apiURL:
  23951. type: string
  23952. auth:
  23953. description: |-
  23954. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23955. Make sure that the token being used has permissions on the given secret.
  23956. properties:
  23957. secretRef:
  23958. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23959. properties:
  23960. credentials:
  23961. description: AccessToken used for the bitwarden instance.
  23962. properties:
  23963. key:
  23964. description: |-
  23965. A key in the referenced Secret.
  23966. Some instances of this field may be defaulted, in others it may be required.
  23967. maxLength: 253
  23968. minLength: 1
  23969. pattern: ^[-._a-zA-Z0-9]+$
  23970. type: string
  23971. name:
  23972. description: The name of the Secret resource being referred to.
  23973. maxLength: 253
  23974. minLength: 1
  23975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23976. type: string
  23977. namespace:
  23978. description: |-
  23979. The namespace of the Secret resource being referred to.
  23980. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23981. maxLength: 63
  23982. minLength: 1
  23983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23984. type: string
  23985. type: object
  23986. required:
  23987. - credentials
  23988. type: object
  23989. required:
  23990. - secretRef
  23991. type: object
  23992. bitwardenServerSDKURL:
  23993. type: string
  23994. caBundle:
  23995. description: |-
  23996. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23997. can be performed.
  23998. type: string
  23999. caProvider:
  24000. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24001. properties:
  24002. key:
  24003. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24004. maxLength: 253
  24005. minLength: 1
  24006. pattern: ^[-._a-zA-Z0-9]+$
  24007. type: string
  24008. name:
  24009. description: The name of the object located at the provider type.
  24010. maxLength: 253
  24011. minLength: 1
  24012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24013. type: string
  24014. namespace:
  24015. description: |-
  24016. The namespace the Provider type is in.
  24017. Can only be defined when used in a ClusterSecretStore.
  24018. maxLength: 63
  24019. minLength: 1
  24020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24021. type: string
  24022. type:
  24023. description: The type of provider to use such as "Secret", or "ConfigMap".
  24024. enum:
  24025. - Secret
  24026. - ConfigMap
  24027. type: string
  24028. required:
  24029. - name
  24030. - type
  24031. type: object
  24032. identityURL:
  24033. type: string
  24034. organizationID:
  24035. description: OrganizationID determines which organization this secret store manages.
  24036. type: string
  24037. projectID:
  24038. description: ProjectID determines which project this secret store manages.
  24039. type: string
  24040. required:
  24041. - auth
  24042. - organizationID
  24043. - projectID
  24044. type: object
  24045. chef:
  24046. description: Chef configures this store to sync secrets with chef server
  24047. properties:
  24048. auth:
  24049. description: Auth defines the information necessary to authenticate against chef Server
  24050. properties:
  24051. secretRef:
  24052. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  24053. properties:
  24054. privateKeySecretRef:
  24055. description: SecretKey is the Signing Key in PEM format, used for authentication.
  24056. properties:
  24057. key:
  24058. description: |-
  24059. A key in the referenced Secret.
  24060. Some instances of this field may be defaulted, in others it may be required.
  24061. maxLength: 253
  24062. minLength: 1
  24063. pattern: ^[-._a-zA-Z0-9]+$
  24064. type: string
  24065. name:
  24066. description: The name of the Secret resource being referred to.
  24067. maxLength: 253
  24068. minLength: 1
  24069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24070. type: string
  24071. namespace:
  24072. description: |-
  24073. The namespace of the Secret resource being referred to.
  24074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24075. maxLength: 63
  24076. minLength: 1
  24077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24078. type: string
  24079. type: object
  24080. required:
  24081. - privateKeySecretRef
  24082. type: object
  24083. required:
  24084. - secretRef
  24085. type: object
  24086. serverUrl:
  24087. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  24088. type: string
  24089. username:
  24090. description: UserName should be the user ID on the chef server
  24091. type: string
  24092. required:
  24093. - auth
  24094. - serverUrl
  24095. - username
  24096. type: object
  24097. cloudrusm:
  24098. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  24099. properties:
  24100. auth:
  24101. description: CSMAuth contains a secretRef for credentials.
  24102. properties:
  24103. secretRef:
  24104. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  24105. properties:
  24106. accessKeyIDSecretRef:
  24107. description: The AccessKeyID is used for authentication
  24108. properties:
  24109. key:
  24110. description: |-
  24111. A key in the referenced Secret.
  24112. Some instances of this field may be defaulted, in others it may be required.
  24113. maxLength: 253
  24114. minLength: 1
  24115. pattern: ^[-._a-zA-Z0-9]+$
  24116. type: string
  24117. name:
  24118. description: The name of the Secret resource being referred to.
  24119. maxLength: 253
  24120. minLength: 1
  24121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24122. type: string
  24123. namespace:
  24124. description: |-
  24125. The namespace of the Secret resource being referred to.
  24126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24127. maxLength: 63
  24128. minLength: 1
  24129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24130. type: string
  24131. type: object
  24132. accessKeySecretSecretRef:
  24133. description: The AccessKeySecret is used for authentication
  24134. properties:
  24135. key:
  24136. description: |-
  24137. A key in the referenced Secret.
  24138. Some instances of this field may be defaulted, in others it may be required.
  24139. maxLength: 253
  24140. minLength: 1
  24141. pattern: ^[-._a-zA-Z0-9]+$
  24142. type: string
  24143. name:
  24144. description: The name of the Secret resource being referred to.
  24145. maxLength: 253
  24146. minLength: 1
  24147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24148. type: string
  24149. namespace:
  24150. description: |-
  24151. The namespace of the Secret resource being referred to.
  24152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24153. maxLength: 63
  24154. minLength: 1
  24155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24156. type: string
  24157. type: object
  24158. required:
  24159. - accessKeyIDSecretRef
  24160. - accessKeySecretSecretRef
  24161. type: object
  24162. type: object
  24163. projectID:
  24164. description: ProjectID is the project, which the secrets are stored in.
  24165. type: string
  24166. required:
  24167. - auth
  24168. type: object
  24169. conjur:
  24170. description: Conjur configures this store to sync secrets using conjur provider
  24171. properties:
  24172. auth:
  24173. description: Defines authentication settings for connecting to Conjur.
  24174. properties:
  24175. apikey:
  24176. description: Authenticates with Conjur using an API key.
  24177. properties:
  24178. account:
  24179. description: Account is the Conjur organization account name.
  24180. type: string
  24181. apiKeyRef:
  24182. description: |-
  24183. A reference to a specific 'key' containing the Conjur API key
  24184. within a Secret resource. In some instances, `key` is a required field.
  24185. properties:
  24186. key:
  24187. description: |-
  24188. A key in the referenced Secret.
  24189. Some instances of this field may be defaulted, in others it may be required.
  24190. maxLength: 253
  24191. minLength: 1
  24192. pattern: ^[-._a-zA-Z0-9]+$
  24193. type: string
  24194. name:
  24195. description: The name of the Secret resource being referred to.
  24196. maxLength: 253
  24197. minLength: 1
  24198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24199. type: string
  24200. namespace:
  24201. description: |-
  24202. The namespace of the Secret resource being referred to.
  24203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24204. maxLength: 63
  24205. minLength: 1
  24206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24207. type: string
  24208. type: object
  24209. userRef:
  24210. description: |-
  24211. A reference to a specific 'key' containing the Conjur username
  24212. within a Secret resource. In some instances, `key` is a required field.
  24213. properties:
  24214. key:
  24215. description: |-
  24216. A key in the referenced Secret.
  24217. Some instances of this field may be defaulted, in others it may be required.
  24218. maxLength: 253
  24219. minLength: 1
  24220. pattern: ^[-._a-zA-Z0-9]+$
  24221. type: string
  24222. name:
  24223. description: The name of the Secret resource being referred to.
  24224. maxLength: 253
  24225. minLength: 1
  24226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24227. type: string
  24228. namespace:
  24229. description: |-
  24230. The namespace of the Secret resource being referred to.
  24231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24232. maxLength: 63
  24233. minLength: 1
  24234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24235. type: string
  24236. type: object
  24237. required:
  24238. - account
  24239. - apiKeyRef
  24240. - userRef
  24241. type: object
  24242. jwt:
  24243. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  24244. properties:
  24245. account:
  24246. description: Account is the Conjur organization account name.
  24247. type: string
  24248. hostId:
  24249. description: |-
  24250. Optional HostID for JWT authentication. This may be used depending
  24251. on how the Conjur JWT authenticator policy is configured.
  24252. type: string
  24253. secretRef:
  24254. description: |-
  24255. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  24256. authenticate with Conjur using the JWT authentication method.
  24257. properties:
  24258. key:
  24259. description: |-
  24260. A key in the referenced Secret.
  24261. Some instances of this field may be defaulted, in others it may be required.
  24262. maxLength: 253
  24263. minLength: 1
  24264. pattern: ^[-._a-zA-Z0-9]+$
  24265. type: string
  24266. name:
  24267. description: The name of the Secret resource being referred to.
  24268. maxLength: 253
  24269. minLength: 1
  24270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24271. type: string
  24272. namespace:
  24273. description: |-
  24274. The namespace of the Secret resource being referred to.
  24275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24276. maxLength: 63
  24277. minLength: 1
  24278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24279. type: string
  24280. type: object
  24281. serviceAccountRef:
  24282. description: |-
  24283. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  24284. a token for with the `TokenRequest` API.
  24285. properties:
  24286. audiences:
  24287. description: |-
  24288. Audience specifies the `aud` claim for the service account token
  24289. Some providers automatically extend the audience field based on well-known annotations for workload
  24290. identity (e.g. IRSA or GCP Workload Identity)
  24291. items:
  24292. type: string
  24293. type: array
  24294. name:
  24295. description: The name of the ServiceAccount resource being referred to.
  24296. maxLength: 253
  24297. minLength: 1
  24298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24299. type: string
  24300. namespace:
  24301. description: |-
  24302. Namespace of the resource being referred to.
  24303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24304. maxLength: 63
  24305. minLength: 1
  24306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24307. type: string
  24308. required:
  24309. - name
  24310. type: object
  24311. serviceID:
  24312. description: The conjur authn jwt webservice id
  24313. type: string
  24314. required:
  24315. - account
  24316. - serviceID
  24317. type: object
  24318. type: object
  24319. caBundle:
  24320. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  24321. type: string
  24322. caProvider:
  24323. description: |-
  24324. Used to provide custom certificate authority (CA) certificates
  24325. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  24326. that contains a PEM-encoded certificate.
  24327. properties:
  24328. key:
  24329. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24330. maxLength: 253
  24331. minLength: 1
  24332. pattern: ^[-._a-zA-Z0-9]+$
  24333. type: string
  24334. name:
  24335. description: The name of the object located at the provider type.
  24336. maxLength: 253
  24337. minLength: 1
  24338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24339. type: string
  24340. namespace:
  24341. description: |-
  24342. The namespace the Provider type is in.
  24343. Can only be defined when used in a ClusterSecretStore.
  24344. maxLength: 63
  24345. minLength: 1
  24346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24347. type: string
  24348. type:
  24349. description: The type of provider to use such as "Secret", or "ConfigMap".
  24350. enum:
  24351. - Secret
  24352. - ConfigMap
  24353. type: string
  24354. required:
  24355. - name
  24356. - type
  24357. type: object
  24358. url:
  24359. description: URL is the endpoint of the Conjur instance.
  24360. type: string
  24361. required:
  24362. - auth
  24363. - url
  24364. type: object
  24365. delinea:
  24366. description: |-
  24367. Delinea DevOps Secrets Vault
  24368. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  24369. properties:
  24370. clientId:
  24371. description: ClientID is the non-secret part of the credential.
  24372. properties:
  24373. secretRef:
  24374. description: SecretRef references a key in a secret that will be used as value.
  24375. properties:
  24376. key:
  24377. description: |-
  24378. A key in the referenced Secret.
  24379. Some instances of this field may be defaulted, in others it may be required.
  24380. maxLength: 253
  24381. minLength: 1
  24382. pattern: ^[-._a-zA-Z0-9]+$
  24383. type: string
  24384. name:
  24385. description: The name of the Secret resource being referred to.
  24386. maxLength: 253
  24387. minLength: 1
  24388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24389. type: string
  24390. namespace:
  24391. description: |-
  24392. The namespace of the Secret resource being referred to.
  24393. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24394. maxLength: 63
  24395. minLength: 1
  24396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24397. type: string
  24398. type: object
  24399. value:
  24400. description: Value can be specified directly to set a value without using a secret.
  24401. type: string
  24402. type: object
  24403. clientSecret:
  24404. description: ClientSecret is the secret part of the credential.
  24405. properties:
  24406. secretRef:
  24407. description: SecretRef references a key in a secret that will be used as value.
  24408. properties:
  24409. key:
  24410. description: |-
  24411. A key in the referenced Secret.
  24412. Some instances of this field may be defaulted, in others it may be required.
  24413. maxLength: 253
  24414. minLength: 1
  24415. pattern: ^[-._a-zA-Z0-9]+$
  24416. type: string
  24417. name:
  24418. description: The name of the Secret resource being referred to.
  24419. maxLength: 253
  24420. minLength: 1
  24421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24422. type: string
  24423. namespace:
  24424. description: |-
  24425. The namespace of the Secret resource being referred to.
  24426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24427. maxLength: 63
  24428. minLength: 1
  24429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24430. type: string
  24431. type: object
  24432. value:
  24433. description: Value can be specified directly to set a value without using a secret.
  24434. type: string
  24435. type: object
  24436. tenant:
  24437. description: Tenant is the chosen hostname / site name.
  24438. type: string
  24439. tld:
  24440. description: |-
  24441. TLD is based on the server location that was chosen during provisioning.
  24442. If unset, defaults to "com".
  24443. type: string
  24444. urlTemplate:
  24445. description: |-
  24446. URLTemplate
  24447. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  24448. type: string
  24449. required:
  24450. - clientId
  24451. - clientSecret
  24452. - tenant
  24453. type: object
  24454. device42:
  24455. description: Device42 configures this store to sync secrets using the Device42 provider
  24456. properties:
  24457. auth:
  24458. description: Auth configures how secret-manager authenticates with a Device42 instance.
  24459. properties:
  24460. secretRef:
  24461. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  24462. properties:
  24463. credentials:
  24464. description: Username / Password is used for authentication.
  24465. properties:
  24466. key:
  24467. description: |-
  24468. A key in the referenced Secret.
  24469. Some instances of this field may be defaulted, in others it may be required.
  24470. maxLength: 253
  24471. minLength: 1
  24472. pattern: ^[-._a-zA-Z0-9]+$
  24473. type: string
  24474. name:
  24475. description: The name of the Secret resource being referred to.
  24476. maxLength: 253
  24477. minLength: 1
  24478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24479. type: string
  24480. namespace:
  24481. description: |-
  24482. The namespace of the Secret resource being referred to.
  24483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24484. maxLength: 63
  24485. minLength: 1
  24486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24487. type: string
  24488. type: object
  24489. type: object
  24490. required:
  24491. - secretRef
  24492. type: object
  24493. host:
  24494. description: URL configures the Device42 instance URL.
  24495. type: string
  24496. required:
  24497. - auth
  24498. - host
  24499. type: object
  24500. doppler:
  24501. description: Doppler configures this store to sync secrets using the Doppler provider
  24502. properties:
  24503. auth:
  24504. description: Auth configures how the Operator authenticates with the Doppler API
  24505. properties:
  24506. secretRef:
  24507. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24508. properties:
  24509. dopplerToken:
  24510. description: |-
  24511. The DopplerToken is used for authentication.
  24512. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24513. The Key attribute defaults to dopplerToken if not specified.
  24514. properties:
  24515. key:
  24516. description: |-
  24517. A key in the referenced Secret.
  24518. Some instances of this field may be defaulted, in others it may be required.
  24519. maxLength: 253
  24520. minLength: 1
  24521. pattern: ^[-._a-zA-Z0-9]+$
  24522. type: string
  24523. name:
  24524. description: The name of the Secret resource being referred to.
  24525. maxLength: 253
  24526. minLength: 1
  24527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24528. type: string
  24529. namespace:
  24530. description: |-
  24531. The namespace of the Secret resource being referred to.
  24532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24533. maxLength: 63
  24534. minLength: 1
  24535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24536. type: string
  24537. type: object
  24538. required:
  24539. - dopplerToken
  24540. type: object
  24541. required:
  24542. - secretRef
  24543. type: object
  24544. config:
  24545. description: Doppler config (required if not using a Service Token)
  24546. type: string
  24547. format:
  24548. description: Format enables the downloading of secrets as a file (string)
  24549. enum:
  24550. - json
  24551. - dotnet-json
  24552. - env
  24553. - yaml
  24554. - docker
  24555. type: string
  24556. nameTransformer:
  24557. description: Environment variable compatible name transforms that change secret names to a different format
  24558. enum:
  24559. - upper-camel
  24560. - camel
  24561. - lower-snake
  24562. - tf-var
  24563. - dotnet-env
  24564. - lower-kebab
  24565. type: string
  24566. project:
  24567. description: Doppler project (required if not using a Service Token)
  24568. type: string
  24569. required:
  24570. - auth
  24571. type: object
  24572. fake:
  24573. description: Fake configures a store with static key/value pairs
  24574. properties:
  24575. data:
  24576. items:
  24577. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24578. properties:
  24579. key:
  24580. type: string
  24581. value:
  24582. type: string
  24583. version:
  24584. type: string
  24585. required:
  24586. - key
  24587. - value
  24588. type: object
  24589. type: array
  24590. required:
  24591. - data
  24592. type: object
  24593. fortanix:
  24594. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24595. properties:
  24596. apiKey:
  24597. description: APIKey is the API token to access SDKMS Applications.
  24598. properties:
  24599. secretRef:
  24600. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24601. properties:
  24602. key:
  24603. description: |-
  24604. A key in the referenced Secret.
  24605. Some instances of this field may be defaulted, in others it may be required.
  24606. maxLength: 253
  24607. minLength: 1
  24608. pattern: ^[-._a-zA-Z0-9]+$
  24609. type: string
  24610. name:
  24611. description: The name of the Secret resource being referred to.
  24612. maxLength: 253
  24613. minLength: 1
  24614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24615. type: string
  24616. namespace:
  24617. description: |-
  24618. The namespace of the Secret resource being referred to.
  24619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24620. maxLength: 63
  24621. minLength: 1
  24622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24623. type: string
  24624. type: object
  24625. type: object
  24626. apiUrl:
  24627. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24628. type: string
  24629. type: object
  24630. gcpsm:
  24631. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24632. properties:
  24633. auth:
  24634. description: Auth defines the information necessary to authenticate against GCP
  24635. properties:
  24636. secretRef:
  24637. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24638. properties:
  24639. secretAccessKeySecretRef:
  24640. description: The SecretAccessKey is used for authentication
  24641. properties:
  24642. key:
  24643. description: |-
  24644. A key in the referenced Secret.
  24645. Some instances of this field may be defaulted, in others it may be required.
  24646. maxLength: 253
  24647. minLength: 1
  24648. pattern: ^[-._a-zA-Z0-9]+$
  24649. type: string
  24650. name:
  24651. description: The name of the Secret resource being referred to.
  24652. maxLength: 253
  24653. minLength: 1
  24654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24655. type: string
  24656. namespace:
  24657. description: |-
  24658. The namespace of the Secret resource being referred to.
  24659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24660. maxLength: 63
  24661. minLength: 1
  24662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24663. type: string
  24664. type: object
  24665. type: object
  24666. workloadIdentity:
  24667. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24668. properties:
  24669. clusterLocation:
  24670. description: |-
  24671. ClusterLocation is the location of the cluster
  24672. If not specified, it fetches information from the metadata server
  24673. type: string
  24674. clusterName:
  24675. description: |-
  24676. ClusterName is the name of the cluster
  24677. If not specified, it fetches information from the metadata server
  24678. type: string
  24679. clusterProjectID:
  24680. description: |-
  24681. ClusterProjectID is the project ID of the cluster
  24682. If not specified, it fetches information from the metadata server
  24683. type: string
  24684. serviceAccountRef:
  24685. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24686. properties:
  24687. audiences:
  24688. description: |-
  24689. Audience specifies the `aud` claim for the service account token
  24690. Some providers automatically extend the audience field based on well-known annotations for workload
  24691. identity (e.g. IRSA or GCP Workload Identity)
  24692. items:
  24693. type: string
  24694. type: array
  24695. name:
  24696. description: The name of the ServiceAccount resource being referred to.
  24697. maxLength: 253
  24698. minLength: 1
  24699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24700. type: string
  24701. namespace:
  24702. description: |-
  24703. Namespace of the resource being referred to.
  24704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24705. maxLength: 63
  24706. minLength: 1
  24707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24708. type: string
  24709. required:
  24710. - name
  24711. type: object
  24712. required:
  24713. - serviceAccountRef
  24714. type: object
  24715. type: object
  24716. location:
  24717. description: Location optionally defines a location for a secret
  24718. type: string
  24719. projectID:
  24720. description: ProjectID project where secret is located
  24721. type: string
  24722. type: object
  24723. github:
  24724. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24725. properties:
  24726. appID:
  24727. description: appID specifies the Github APP that will be used to authenticate the client
  24728. format: int64
  24729. type: integer
  24730. auth:
  24731. description: auth configures how secret-manager authenticates with a Github instance.
  24732. properties:
  24733. privateKey:
  24734. description: |-
  24735. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24736. In some instances, `key` is a required field.
  24737. properties:
  24738. key:
  24739. description: |-
  24740. A key in the referenced Secret.
  24741. Some instances of this field may be defaulted, in others it may be required.
  24742. maxLength: 253
  24743. minLength: 1
  24744. pattern: ^[-._a-zA-Z0-9]+$
  24745. type: string
  24746. name:
  24747. description: The name of the Secret resource being referred to.
  24748. maxLength: 253
  24749. minLength: 1
  24750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24751. type: string
  24752. namespace:
  24753. description: |-
  24754. The namespace of the Secret resource being referred to.
  24755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24756. maxLength: 63
  24757. minLength: 1
  24758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24759. type: string
  24760. type: object
  24761. required:
  24762. - privateKey
  24763. type: object
  24764. environment:
  24765. description: environment will be used to fetch secrets from a particular environment within a github repository
  24766. type: string
  24767. installationID:
  24768. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24769. format: int64
  24770. type: integer
  24771. organization:
  24772. description: organization will be used to fetch secrets from the Github organization
  24773. type: string
  24774. repository:
  24775. description: repository will be used to fetch secrets from the Github repository within an organization
  24776. type: string
  24777. uploadURL:
  24778. description: Upload URL for enterprise instances. Default to URL.
  24779. type: string
  24780. url:
  24781. default: https://github.com/
  24782. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24783. type: string
  24784. required:
  24785. - appID
  24786. - auth
  24787. - installationID
  24788. - organization
  24789. type: object
  24790. gitlab:
  24791. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24792. properties:
  24793. auth:
  24794. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24795. properties:
  24796. SecretRef:
  24797. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24798. properties:
  24799. accessToken:
  24800. description: AccessToken is used for authentication.
  24801. properties:
  24802. key:
  24803. description: |-
  24804. A key in the referenced Secret.
  24805. Some instances of this field may be defaulted, in others it may be required.
  24806. maxLength: 253
  24807. minLength: 1
  24808. pattern: ^[-._a-zA-Z0-9]+$
  24809. type: string
  24810. name:
  24811. description: The name of the Secret resource being referred to.
  24812. maxLength: 253
  24813. minLength: 1
  24814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24815. type: string
  24816. namespace:
  24817. description: |-
  24818. The namespace of the Secret resource being referred to.
  24819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24820. maxLength: 63
  24821. minLength: 1
  24822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24823. type: string
  24824. type: object
  24825. type: object
  24826. required:
  24827. - SecretRef
  24828. type: object
  24829. caBundle:
  24830. description: |-
  24831. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24832. can be performed.
  24833. format: byte
  24834. type: string
  24835. caProvider:
  24836. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24837. properties:
  24838. key:
  24839. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24840. maxLength: 253
  24841. minLength: 1
  24842. pattern: ^[-._a-zA-Z0-9]+$
  24843. type: string
  24844. name:
  24845. description: The name of the object located at the provider type.
  24846. maxLength: 253
  24847. minLength: 1
  24848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24849. type: string
  24850. namespace:
  24851. description: |-
  24852. The namespace the Provider type is in.
  24853. Can only be defined when used in a ClusterSecretStore.
  24854. maxLength: 63
  24855. minLength: 1
  24856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24857. type: string
  24858. type:
  24859. description: The type of provider to use such as "Secret", or "ConfigMap".
  24860. enum:
  24861. - Secret
  24862. - ConfigMap
  24863. type: string
  24864. required:
  24865. - name
  24866. - type
  24867. type: object
  24868. environment:
  24869. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24870. type: string
  24871. groupIDs:
  24872. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24873. items:
  24874. type: string
  24875. type: array
  24876. inheritFromGroups:
  24877. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24878. type: boolean
  24879. projectID:
  24880. description: ProjectID specifies a project where secrets are located.
  24881. type: string
  24882. url:
  24883. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24884. type: string
  24885. required:
  24886. - auth
  24887. type: object
  24888. ibm:
  24889. description: IBM configures this store to sync secrets using IBM Cloud provider
  24890. properties:
  24891. auth:
  24892. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24893. maxProperties: 1
  24894. minProperties: 1
  24895. properties:
  24896. containerAuth:
  24897. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24898. properties:
  24899. iamEndpoint:
  24900. type: string
  24901. profile:
  24902. description: the IBM Trusted Profile
  24903. type: string
  24904. tokenLocation:
  24905. description: Location the token is mounted on the pod
  24906. type: string
  24907. required:
  24908. - profile
  24909. type: object
  24910. secretRef:
  24911. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24912. properties:
  24913. secretApiKeySecretRef:
  24914. description: The SecretAccessKey is used for authentication
  24915. properties:
  24916. key:
  24917. description: |-
  24918. A key in the referenced Secret.
  24919. Some instances of this field may be defaulted, in others it may be required.
  24920. maxLength: 253
  24921. minLength: 1
  24922. pattern: ^[-._a-zA-Z0-9]+$
  24923. type: string
  24924. name:
  24925. description: The name of the Secret resource being referred to.
  24926. maxLength: 253
  24927. minLength: 1
  24928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24929. type: string
  24930. namespace:
  24931. description: |-
  24932. The namespace of the Secret resource being referred to.
  24933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24934. maxLength: 63
  24935. minLength: 1
  24936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24937. type: string
  24938. type: object
  24939. type: object
  24940. type: object
  24941. serviceUrl:
  24942. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24943. type: string
  24944. required:
  24945. - auth
  24946. type: object
  24947. infisical:
  24948. description: Infisical configures this store to sync secrets using the Infisical provider
  24949. properties:
  24950. auth:
  24951. description: Auth configures how the Operator authenticates with the Infisical API
  24952. properties:
  24953. universalAuthCredentials:
  24954. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24955. properties:
  24956. clientId:
  24957. description: |-
  24958. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24959. In some instances, `key` is a required field.
  24960. properties:
  24961. key:
  24962. description: |-
  24963. A key in the referenced Secret.
  24964. Some instances of this field may be defaulted, in others it may be required.
  24965. maxLength: 253
  24966. minLength: 1
  24967. pattern: ^[-._a-zA-Z0-9]+$
  24968. type: string
  24969. name:
  24970. description: The name of the Secret resource being referred to.
  24971. maxLength: 253
  24972. minLength: 1
  24973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24974. type: string
  24975. namespace:
  24976. description: |-
  24977. The namespace of the Secret resource being referred to.
  24978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24979. maxLength: 63
  24980. minLength: 1
  24981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24982. type: string
  24983. type: object
  24984. clientSecret:
  24985. description: |-
  24986. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24987. In some instances, `key` is a required field.
  24988. properties:
  24989. key:
  24990. description: |-
  24991. A key in the referenced Secret.
  24992. Some instances of this field may be defaulted, in others it may be required.
  24993. maxLength: 253
  24994. minLength: 1
  24995. pattern: ^[-._a-zA-Z0-9]+$
  24996. type: string
  24997. name:
  24998. description: The name of the Secret resource being referred to.
  24999. maxLength: 253
  25000. minLength: 1
  25001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25002. type: string
  25003. namespace:
  25004. description: |-
  25005. The namespace of the Secret resource being referred to.
  25006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25007. maxLength: 63
  25008. minLength: 1
  25009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25010. type: string
  25011. type: object
  25012. required:
  25013. - clientId
  25014. - clientSecret
  25015. type: object
  25016. type: object
  25017. hostAPI:
  25018. default: https://app.infisical.com/api
  25019. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  25020. type: string
  25021. secretsScope:
  25022. description: SecretsScope defines the scope of the secrets within the workspace
  25023. properties:
  25024. environmentSlug:
  25025. description: EnvironmentSlug is the required slug identifier for the environment.
  25026. type: string
  25027. expandSecretReferences:
  25028. default: true
  25029. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  25030. type: boolean
  25031. projectSlug:
  25032. description: ProjectSlug is the required slug identifier for the project.
  25033. type: string
  25034. recursive:
  25035. default: false
  25036. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  25037. type: boolean
  25038. secretsPath:
  25039. default: /
  25040. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  25041. type: string
  25042. required:
  25043. - environmentSlug
  25044. - projectSlug
  25045. type: object
  25046. required:
  25047. - auth
  25048. - secretsScope
  25049. type: object
  25050. keepersecurity:
  25051. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  25052. properties:
  25053. authRef:
  25054. description: |-
  25055. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25056. In some instances, `key` is a required field.
  25057. properties:
  25058. key:
  25059. description: |-
  25060. A key in the referenced Secret.
  25061. Some instances of this field may be defaulted, in others it may be required.
  25062. maxLength: 253
  25063. minLength: 1
  25064. pattern: ^[-._a-zA-Z0-9]+$
  25065. type: string
  25066. name:
  25067. description: The name of the Secret resource being referred to.
  25068. maxLength: 253
  25069. minLength: 1
  25070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25071. type: string
  25072. namespace:
  25073. description: |-
  25074. The namespace of the Secret resource being referred to.
  25075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25076. maxLength: 63
  25077. minLength: 1
  25078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25079. type: string
  25080. type: object
  25081. folderID:
  25082. type: string
  25083. required:
  25084. - authRef
  25085. - folderID
  25086. type: object
  25087. kubernetes:
  25088. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  25089. properties:
  25090. auth:
  25091. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  25092. maxProperties: 1
  25093. minProperties: 1
  25094. properties:
  25095. cert:
  25096. description: has both clientCert and clientKey as secretKeySelector
  25097. properties:
  25098. clientCert:
  25099. description: |-
  25100. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25101. In some instances, `key` is a required field.
  25102. properties:
  25103. key:
  25104. description: |-
  25105. A key in the referenced Secret.
  25106. Some instances of this field may be defaulted, in others it may be required.
  25107. maxLength: 253
  25108. minLength: 1
  25109. pattern: ^[-._a-zA-Z0-9]+$
  25110. type: string
  25111. name:
  25112. description: The name of the Secret resource being referred to.
  25113. maxLength: 253
  25114. minLength: 1
  25115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25116. type: string
  25117. namespace:
  25118. description: |-
  25119. The namespace of the Secret resource being referred to.
  25120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25121. maxLength: 63
  25122. minLength: 1
  25123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25124. type: string
  25125. type: object
  25126. clientKey:
  25127. description: |-
  25128. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25129. In some instances, `key` is a required field.
  25130. properties:
  25131. key:
  25132. description: |-
  25133. A key in the referenced Secret.
  25134. Some instances of this field may be defaulted, in others it may be required.
  25135. maxLength: 253
  25136. minLength: 1
  25137. pattern: ^[-._a-zA-Z0-9]+$
  25138. type: string
  25139. name:
  25140. description: The name of the Secret resource being referred to.
  25141. maxLength: 253
  25142. minLength: 1
  25143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25144. type: string
  25145. namespace:
  25146. description: |-
  25147. The namespace of the Secret resource being referred to.
  25148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25149. maxLength: 63
  25150. minLength: 1
  25151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25152. type: string
  25153. type: object
  25154. type: object
  25155. serviceAccount:
  25156. description: points to a service account that should be used for authentication
  25157. properties:
  25158. audiences:
  25159. description: |-
  25160. Audience specifies the `aud` claim for the service account token
  25161. Some providers automatically extend the audience field based on well-known annotations for workload
  25162. identity (e.g. IRSA or GCP Workload Identity)
  25163. items:
  25164. type: string
  25165. type: array
  25166. name:
  25167. description: The name of the ServiceAccount resource being referred to.
  25168. maxLength: 253
  25169. minLength: 1
  25170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25171. type: string
  25172. namespace:
  25173. description: |-
  25174. Namespace of the resource being referred to.
  25175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25176. maxLength: 63
  25177. minLength: 1
  25178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25179. type: string
  25180. required:
  25181. - name
  25182. type: object
  25183. token:
  25184. description: use static token to authenticate with
  25185. properties:
  25186. bearerToken:
  25187. description: |-
  25188. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25189. In some instances, `key` is a required field.
  25190. properties:
  25191. key:
  25192. description: |-
  25193. A key in the referenced Secret.
  25194. Some instances of this field may be defaulted, in others it may be required.
  25195. maxLength: 253
  25196. minLength: 1
  25197. pattern: ^[-._a-zA-Z0-9]+$
  25198. type: string
  25199. name:
  25200. description: The name of the Secret resource being referred to.
  25201. maxLength: 253
  25202. minLength: 1
  25203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25204. type: string
  25205. namespace:
  25206. description: |-
  25207. The namespace of the Secret resource being referred to.
  25208. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25209. maxLength: 63
  25210. minLength: 1
  25211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25212. type: string
  25213. type: object
  25214. type: object
  25215. type: object
  25216. authRef:
  25217. description: A reference to a secret that contains the auth information.
  25218. properties:
  25219. key:
  25220. description: |-
  25221. A key in the referenced Secret.
  25222. Some instances of this field may be defaulted, in others it may be required.
  25223. maxLength: 253
  25224. minLength: 1
  25225. pattern: ^[-._a-zA-Z0-9]+$
  25226. type: string
  25227. name:
  25228. description: The name of the Secret resource being referred to.
  25229. maxLength: 253
  25230. minLength: 1
  25231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25232. type: string
  25233. namespace:
  25234. description: |-
  25235. The namespace of the Secret resource being referred to.
  25236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25237. maxLength: 63
  25238. minLength: 1
  25239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25240. type: string
  25241. type: object
  25242. remoteNamespace:
  25243. default: default
  25244. description: Remote namespace to fetch the secrets from
  25245. maxLength: 63
  25246. minLength: 1
  25247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25248. type: string
  25249. server:
  25250. description: configures the Kubernetes server Address.
  25251. properties:
  25252. caBundle:
  25253. description: CABundle is a base64-encoded CA certificate
  25254. format: byte
  25255. type: string
  25256. caProvider:
  25257. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  25258. properties:
  25259. key:
  25260. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25261. maxLength: 253
  25262. minLength: 1
  25263. pattern: ^[-._a-zA-Z0-9]+$
  25264. type: string
  25265. name:
  25266. description: The name of the object located at the provider type.
  25267. maxLength: 253
  25268. minLength: 1
  25269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25270. type: string
  25271. namespace:
  25272. description: |-
  25273. The namespace the Provider type is in.
  25274. Can only be defined when used in a ClusterSecretStore.
  25275. maxLength: 63
  25276. minLength: 1
  25277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25278. type: string
  25279. type:
  25280. description: The type of provider to use such as "Secret", or "ConfigMap".
  25281. enum:
  25282. - Secret
  25283. - ConfigMap
  25284. type: string
  25285. required:
  25286. - name
  25287. - type
  25288. type: object
  25289. url:
  25290. default: kubernetes.default
  25291. description: configures the Kubernetes server Address.
  25292. type: string
  25293. type: object
  25294. type: object
  25295. onboardbase:
  25296. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  25297. properties:
  25298. apiHost:
  25299. default: https://public.onboardbase.com/api/v1/
  25300. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  25301. type: string
  25302. auth:
  25303. description: Auth configures how the Operator authenticates with the Onboardbase API
  25304. properties:
  25305. apiKeyRef:
  25306. description: |-
  25307. OnboardbaseAPIKey is the APIKey generated by an admin account.
  25308. It is used to recognize and authorize access to a project and environment within onboardbase
  25309. properties:
  25310. key:
  25311. description: |-
  25312. A key in the referenced Secret.
  25313. Some instances of this field may be defaulted, in others it may be required.
  25314. maxLength: 253
  25315. minLength: 1
  25316. pattern: ^[-._a-zA-Z0-9]+$
  25317. type: string
  25318. name:
  25319. description: The name of the Secret resource being referred to.
  25320. maxLength: 253
  25321. minLength: 1
  25322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25323. type: string
  25324. namespace:
  25325. description: |-
  25326. The namespace of the Secret resource being referred to.
  25327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25328. maxLength: 63
  25329. minLength: 1
  25330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25331. type: string
  25332. type: object
  25333. passcodeRef:
  25334. description: OnboardbasePasscode is the passcode attached to the API Key
  25335. properties:
  25336. key:
  25337. description: |-
  25338. A key in the referenced Secret.
  25339. Some instances of this field may be defaulted, in others it may be required.
  25340. maxLength: 253
  25341. minLength: 1
  25342. pattern: ^[-._a-zA-Z0-9]+$
  25343. type: string
  25344. name:
  25345. description: The name of the Secret resource being referred to.
  25346. maxLength: 253
  25347. minLength: 1
  25348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25349. type: string
  25350. namespace:
  25351. description: |-
  25352. The namespace of the Secret resource being referred to.
  25353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25354. maxLength: 63
  25355. minLength: 1
  25356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25357. type: string
  25358. type: object
  25359. required:
  25360. - apiKeyRef
  25361. - passcodeRef
  25362. type: object
  25363. environment:
  25364. default: development
  25365. description: Environment is the name of an environmnent within a project to pull the secrets from
  25366. type: string
  25367. project:
  25368. default: development
  25369. description: Project is an onboardbase project that the secrets should be pulled from
  25370. type: string
  25371. required:
  25372. - apiHost
  25373. - auth
  25374. - environment
  25375. - project
  25376. type: object
  25377. onepassword:
  25378. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  25379. properties:
  25380. auth:
  25381. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  25382. properties:
  25383. secretRef:
  25384. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  25385. properties:
  25386. connectTokenSecretRef:
  25387. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  25388. properties:
  25389. key:
  25390. description: |-
  25391. A key in the referenced Secret.
  25392. Some instances of this field may be defaulted, in others it may be required.
  25393. maxLength: 253
  25394. minLength: 1
  25395. pattern: ^[-._a-zA-Z0-9]+$
  25396. type: string
  25397. name:
  25398. description: The name of the Secret resource being referred to.
  25399. maxLength: 253
  25400. minLength: 1
  25401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25402. type: string
  25403. namespace:
  25404. description: |-
  25405. The namespace of the Secret resource being referred to.
  25406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25407. maxLength: 63
  25408. minLength: 1
  25409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25410. type: string
  25411. type: object
  25412. required:
  25413. - connectTokenSecretRef
  25414. type: object
  25415. required:
  25416. - secretRef
  25417. type: object
  25418. connectHost:
  25419. description: ConnectHost defines the OnePassword Connect Server to connect to
  25420. type: string
  25421. vaults:
  25422. additionalProperties:
  25423. type: integer
  25424. description: Vaults defines which OnePassword vaults to search in which order
  25425. type: object
  25426. required:
  25427. - auth
  25428. - connectHost
  25429. - vaults
  25430. type: object
  25431. oracle:
  25432. description: Oracle configures this store to sync secrets using Oracle Vault provider
  25433. properties:
  25434. auth:
  25435. description: |-
  25436. Auth configures how secret-manager authenticates with the Oracle Vault.
  25437. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  25438. properties:
  25439. secretRef:
  25440. description: SecretRef to pass through sensitive information.
  25441. properties:
  25442. fingerprint:
  25443. description: Fingerprint is the fingerprint of the API private key.
  25444. properties:
  25445. key:
  25446. description: |-
  25447. A key in the referenced Secret.
  25448. Some instances of this field may be defaulted, in others it may be required.
  25449. maxLength: 253
  25450. minLength: 1
  25451. pattern: ^[-._a-zA-Z0-9]+$
  25452. type: string
  25453. name:
  25454. description: The name of the Secret resource being referred to.
  25455. maxLength: 253
  25456. minLength: 1
  25457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25458. type: string
  25459. namespace:
  25460. description: |-
  25461. The namespace of the Secret resource being referred to.
  25462. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25463. maxLength: 63
  25464. minLength: 1
  25465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25466. type: string
  25467. type: object
  25468. privatekey:
  25469. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  25470. properties:
  25471. key:
  25472. description: |-
  25473. A key in the referenced Secret.
  25474. Some instances of this field may be defaulted, in others it may be required.
  25475. maxLength: 253
  25476. minLength: 1
  25477. pattern: ^[-._a-zA-Z0-9]+$
  25478. type: string
  25479. name:
  25480. description: The name of the Secret resource being referred to.
  25481. maxLength: 253
  25482. minLength: 1
  25483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25484. type: string
  25485. namespace:
  25486. description: |-
  25487. The namespace of the Secret resource being referred to.
  25488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25489. maxLength: 63
  25490. minLength: 1
  25491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25492. type: string
  25493. type: object
  25494. required:
  25495. - fingerprint
  25496. - privatekey
  25497. type: object
  25498. tenancy:
  25499. description: Tenancy is the tenancy OCID where user is located.
  25500. type: string
  25501. user:
  25502. description: User is an access OCID specific to the account.
  25503. type: string
  25504. required:
  25505. - secretRef
  25506. - tenancy
  25507. - user
  25508. type: object
  25509. compartment:
  25510. description: |-
  25511. Compartment is the vault compartment OCID.
  25512. Required for PushSecret
  25513. type: string
  25514. encryptionKey:
  25515. description: |-
  25516. EncryptionKey is the OCID of the encryption key within the vault.
  25517. Required for PushSecret
  25518. type: string
  25519. principalType:
  25520. description: |-
  25521. The type of principal to use for authentication. If left blank, the Auth struct will
  25522. determine the principal type. This optional field must be specified if using
  25523. workload identity.
  25524. enum:
  25525. - ""
  25526. - UserPrincipal
  25527. - InstancePrincipal
  25528. - Workload
  25529. type: string
  25530. region:
  25531. description: Region is the region where vault is located.
  25532. type: string
  25533. serviceAccountRef:
  25534. description: |-
  25535. ServiceAccountRef specified the service account
  25536. that should be used when authenticating with WorkloadIdentity.
  25537. properties:
  25538. audiences:
  25539. description: |-
  25540. Audience specifies the `aud` claim for the service account token
  25541. Some providers automatically extend the audience field based on well-known annotations for workload
  25542. identity (e.g. IRSA or GCP Workload Identity)
  25543. items:
  25544. type: string
  25545. type: array
  25546. name:
  25547. description: The name of the ServiceAccount resource being referred to.
  25548. maxLength: 253
  25549. minLength: 1
  25550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25551. type: string
  25552. namespace:
  25553. description: |-
  25554. Namespace of the resource being referred to.
  25555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25556. maxLength: 63
  25557. minLength: 1
  25558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25559. type: string
  25560. required:
  25561. - name
  25562. type: object
  25563. vault:
  25564. description: Vault is the vault's OCID of the specific vault where secret is located.
  25565. type: string
  25566. required:
  25567. - region
  25568. - vault
  25569. type: object
  25570. passbolt:
  25571. description: PassboltProvider defines configuration for the Passbolt provider.
  25572. properties:
  25573. auth:
  25574. description: Auth defines the information necessary to authenticate against Passbolt Server
  25575. properties:
  25576. passwordSecretRef:
  25577. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25578. properties:
  25579. key:
  25580. description: |-
  25581. A key in the referenced Secret.
  25582. Some instances of this field may be defaulted, in others it may be required.
  25583. maxLength: 253
  25584. minLength: 1
  25585. pattern: ^[-._a-zA-Z0-9]+$
  25586. type: string
  25587. name:
  25588. description: The name of the Secret resource being referred to.
  25589. maxLength: 253
  25590. minLength: 1
  25591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25592. type: string
  25593. namespace:
  25594. description: |-
  25595. The namespace of the Secret resource being referred to.
  25596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25597. maxLength: 63
  25598. minLength: 1
  25599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25600. type: string
  25601. type: object
  25602. privateKeySecretRef:
  25603. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25604. properties:
  25605. key:
  25606. description: |-
  25607. A key in the referenced Secret.
  25608. Some instances of this field may be defaulted, in others it may be required.
  25609. maxLength: 253
  25610. minLength: 1
  25611. pattern: ^[-._a-zA-Z0-9]+$
  25612. type: string
  25613. name:
  25614. description: The name of the Secret resource being referred to.
  25615. maxLength: 253
  25616. minLength: 1
  25617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25618. type: string
  25619. namespace:
  25620. description: |-
  25621. The namespace of the Secret resource being referred to.
  25622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25623. maxLength: 63
  25624. minLength: 1
  25625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25626. type: string
  25627. type: object
  25628. required:
  25629. - passwordSecretRef
  25630. - privateKeySecretRef
  25631. type: object
  25632. host:
  25633. description: Host defines the Passbolt Server to connect to
  25634. type: string
  25635. required:
  25636. - auth
  25637. - host
  25638. type: object
  25639. passworddepot:
  25640. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25641. properties:
  25642. auth:
  25643. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25644. properties:
  25645. secretRef:
  25646. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25647. properties:
  25648. credentials:
  25649. description: Username / Password is used for authentication.
  25650. properties:
  25651. key:
  25652. description: |-
  25653. A key in the referenced Secret.
  25654. Some instances of this field may be defaulted, in others it may be required.
  25655. maxLength: 253
  25656. minLength: 1
  25657. pattern: ^[-._a-zA-Z0-9]+$
  25658. type: string
  25659. name:
  25660. description: The name of the Secret resource being referred to.
  25661. maxLength: 253
  25662. minLength: 1
  25663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25664. type: string
  25665. namespace:
  25666. description: |-
  25667. The namespace of the Secret resource being referred to.
  25668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25669. maxLength: 63
  25670. minLength: 1
  25671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25672. type: string
  25673. type: object
  25674. type: object
  25675. required:
  25676. - secretRef
  25677. type: object
  25678. database:
  25679. description: Database to use as source
  25680. type: string
  25681. host:
  25682. description: URL configures the Password Depot instance URL.
  25683. type: string
  25684. required:
  25685. - auth
  25686. - database
  25687. - host
  25688. type: object
  25689. previder:
  25690. description: Previder configures this store to sync secrets using the Previder provider
  25691. properties:
  25692. auth:
  25693. description: PreviderAuth contains a secretRef for credentials.
  25694. properties:
  25695. secretRef:
  25696. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25697. properties:
  25698. accessToken:
  25699. description: The AccessToken is used for authentication
  25700. properties:
  25701. key:
  25702. description: |-
  25703. A key in the referenced Secret.
  25704. Some instances of this field may be defaulted, in others it may be required.
  25705. maxLength: 253
  25706. minLength: 1
  25707. pattern: ^[-._a-zA-Z0-9]+$
  25708. type: string
  25709. name:
  25710. description: The name of the Secret resource being referred to.
  25711. maxLength: 253
  25712. minLength: 1
  25713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25714. type: string
  25715. namespace:
  25716. description: |-
  25717. The namespace of the Secret resource being referred to.
  25718. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25719. maxLength: 63
  25720. minLength: 1
  25721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25722. type: string
  25723. type: object
  25724. required:
  25725. - accessToken
  25726. type: object
  25727. type: object
  25728. baseUri:
  25729. type: string
  25730. required:
  25731. - auth
  25732. type: object
  25733. pulumi:
  25734. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25735. properties:
  25736. accessToken:
  25737. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25738. properties:
  25739. secretRef:
  25740. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25741. properties:
  25742. key:
  25743. description: |-
  25744. A key in the referenced Secret.
  25745. Some instances of this field may be defaulted, in others it may be required.
  25746. maxLength: 253
  25747. minLength: 1
  25748. pattern: ^[-._a-zA-Z0-9]+$
  25749. type: string
  25750. name:
  25751. description: The name of the Secret resource being referred to.
  25752. maxLength: 253
  25753. minLength: 1
  25754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25755. type: string
  25756. namespace:
  25757. description: |-
  25758. The namespace of the Secret resource being referred to.
  25759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25760. maxLength: 63
  25761. minLength: 1
  25762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25763. type: string
  25764. type: object
  25765. type: object
  25766. apiUrl:
  25767. default: https://api.pulumi.com/api/esc
  25768. description: APIURL is the URL of the Pulumi API.
  25769. type: string
  25770. environment:
  25771. description: |-
  25772. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25773. dynamically retrieved values from supported providers including all major clouds,
  25774. and other Pulumi ESC environments.
  25775. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25776. type: string
  25777. organization:
  25778. description: |-
  25779. Organization are a space to collaborate on shared projects and stacks.
  25780. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25781. type: string
  25782. project:
  25783. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25784. type: string
  25785. required:
  25786. - accessToken
  25787. - environment
  25788. - organization
  25789. - project
  25790. type: object
  25791. scaleway:
  25792. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25793. properties:
  25794. accessKey:
  25795. description: AccessKey is the non-secret part of the api key.
  25796. properties:
  25797. secretRef:
  25798. description: SecretRef references a key in a secret that will be used as value.
  25799. properties:
  25800. key:
  25801. description: |-
  25802. A key in the referenced Secret.
  25803. Some instances of this field may be defaulted, in others it may be required.
  25804. maxLength: 253
  25805. minLength: 1
  25806. pattern: ^[-._a-zA-Z0-9]+$
  25807. type: string
  25808. name:
  25809. description: The name of the Secret resource being referred to.
  25810. maxLength: 253
  25811. minLength: 1
  25812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25813. type: string
  25814. namespace:
  25815. description: |-
  25816. The namespace of the Secret resource being referred to.
  25817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25818. maxLength: 63
  25819. minLength: 1
  25820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25821. type: string
  25822. type: object
  25823. value:
  25824. description: Value can be specified directly to set a value without using a secret.
  25825. type: string
  25826. type: object
  25827. apiUrl:
  25828. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25829. type: string
  25830. projectId:
  25831. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25832. type: string
  25833. region:
  25834. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25835. type: string
  25836. secretKey:
  25837. description: SecretKey is the non-secret part of the api key.
  25838. properties:
  25839. secretRef:
  25840. description: SecretRef references a key in a secret that will be used as value.
  25841. properties:
  25842. key:
  25843. description: |-
  25844. A key in the referenced Secret.
  25845. Some instances of this field may be defaulted, in others it may be required.
  25846. maxLength: 253
  25847. minLength: 1
  25848. pattern: ^[-._a-zA-Z0-9]+$
  25849. type: string
  25850. name:
  25851. description: The name of the Secret resource being referred to.
  25852. maxLength: 253
  25853. minLength: 1
  25854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25855. type: string
  25856. namespace:
  25857. description: |-
  25858. The namespace of the Secret resource being referred to.
  25859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25860. maxLength: 63
  25861. minLength: 1
  25862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25863. type: string
  25864. type: object
  25865. value:
  25866. description: Value can be specified directly to set a value without using a secret.
  25867. type: string
  25868. type: object
  25869. required:
  25870. - accessKey
  25871. - projectId
  25872. - region
  25873. - secretKey
  25874. type: object
  25875. secretserver:
  25876. description: |-
  25877. SecretServer configures this store to sync secrets using SecretServer provider
  25878. https://docs.delinea.com/online-help/secret-server/start.htm
  25879. properties:
  25880. password:
  25881. description: Password is the secret server account password.
  25882. properties:
  25883. secretRef:
  25884. description: SecretRef references a key in a secret that will be used as value.
  25885. properties:
  25886. key:
  25887. description: |-
  25888. A key in the referenced Secret.
  25889. Some instances of this field may be defaulted, in others it may be required.
  25890. maxLength: 253
  25891. minLength: 1
  25892. pattern: ^[-._a-zA-Z0-9]+$
  25893. type: string
  25894. name:
  25895. description: The name of the Secret resource being referred to.
  25896. maxLength: 253
  25897. minLength: 1
  25898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25899. type: string
  25900. namespace:
  25901. description: |-
  25902. The namespace of the Secret resource being referred to.
  25903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25904. maxLength: 63
  25905. minLength: 1
  25906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25907. type: string
  25908. type: object
  25909. value:
  25910. description: Value can be specified directly to set a value without using a secret.
  25911. type: string
  25912. type: object
  25913. serverURL:
  25914. description: |-
  25915. ServerURL
  25916. URL to your secret server installation
  25917. type: string
  25918. username:
  25919. description: Username is the secret server account username.
  25920. properties:
  25921. secretRef:
  25922. description: SecretRef references a key in a secret that will be used as value.
  25923. properties:
  25924. key:
  25925. description: |-
  25926. A key in the referenced Secret.
  25927. Some instances of this field may be defaulted, in others it may be required.
  25928. maxLength: 253
  25929. minLength: 1
  25930. pattern: ^[-._a-zA-Z0-9]+$
  25931. type: string
  25932. name:
  25933. description: The name of the Secret resource being referred to.
  25934. maxLength: 253
  25935. minLength: 1
  25936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25937. type: string
  25938. namespace:
  25939. description: |-
  25940. The namespace of the Secret resource being referred to.
  25941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25942. maxLength: 63
  25943. minLength: 1
  25944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25945. type: string
  25946. type: object
  25947. value:
  25948. description: Value can be specified directly to set a value without using a secret.
  25949. type: string
  25950. type: object
  25951. required:
  25952. - password
  25953. - serverURL
  25954. - username
  25955. type: object
  25956. senhasegura:
  25957. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25958. properties:
  25959. auth:
  25960. description: Auth defines parameters to authenticate in senhasegura
  25961. properties:
  25962. clientId:
  25963. type: string
  25964. clientSecretSecretRef:
  25965. description: |-
  25966. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25967. In some instances, `key` is a required field.
  25968. properties:
  25969. key:
  25970. description: |-
  25971. A key in the referenced Secret.
  25972. Some instances of this field may be defaulted, in others it may be required.
  25973. maxLength: 253
  25974. minLength: 1
  25975. pattern: ^[-._a-zA-Z0-9]+$
  25976. type: string
  25977. name:
  25978. description: The name of the Secret resource being referred to.
  25979. maxLength: 253
  25980. minLength: 1
  25981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25982. type: string
  25983. namespace:
  25984. description: |-
  25985. The namespace of the Secret resource being referred to.
  25986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25987. maxLength: 63
  25988. minLength: 1
  25989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25990. type: string
  25991. type: object
  25992. required:
  25993. - clientId
  25994. - clientSecretSecretRef
  25995. type: object
  25996. ignoreSslCertificate:
  25997. default: false
  25998. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25999. type: boolean
  26000. module:
  26001. description: Module defines which senhasegura module should be used to get secrets
  26002. type: string
  26003. url:
  26004. description: URL of senhasegura
  26005. type: string
  26006. required:
  26007. - auth
  26008. - module
  26009. - url
  26010. type: object
  26011. vault:
  26012. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  26013. properties:
  26014. auth:
  26015. description: Auth configures how secret-manager authenticates with the Vault server.
  26016. properties:
  26017. appRole:
  26018. description: |-
  26019. AppRole authenticates with Vault using the App Role auth mechanism,
  26020. with the role and secret stored in a Kubernetes Secret resource.
  26021. properties:
  26022. path:
  26023. default: approle
  26024. description: |-
  26025. Path where the App Role authentication backend is mounted
  26026. in Vault, e.g: "approle"
  26027. type: string
  26028. roleId:
  26029. description: |-
  26030. RoleID configured in the App Role authentication backend when setting
  26031. up the authentication backend in Vault.
  26032. type: string
  26033. roleRef:
  26034. description: |-
  26035. Reference to a key in a Secret that contains the App Role ID used
  26036. to authenticate with Vault.
  26037. The `key` field must be specified and denotes which entry within the Secret
  26038. resource is used as the app role id.
  26039. properties:
  26040. key:
  26041. description: |-
  26042. A key in the referenced Secret.
  26043. Some instances of this field may be defaulted, in others it may be required.
  26044. maxLength: 253
  26045. minLength: 1
  26046. pattern: ^[-._a-zA-Z0-9]+$
  26047. type: string
  26048. name:
  26049. description: The name of the Secret resource being referred to.
  26050. maxLength: 253
  26051. minLength: 1
  26052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26053. type: string
  26054. namespace:
  26055. description: |-
  26056. The namespace of the Secret resource being referred to.
  26057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26058. maxLength: 63
  26059. minLength: 1
  26060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26061. type: string
  26062. type: object
  26063. secretRef:
  26064. description: |-
  26065. Reference to a key in a Secret that contains the App Role secret used
  26066. to authenticate with Vault.
  26067. The `key` field must be specified and denotes which entry within the Secret
  26068. resource is used as the app role secret.
  26069. properties:
  26070. key:
  26071. description: |-
  26072. A key in the referenced Secret.
  26073. Some instances of this field may be defaulted, in others it may be required.
  26074. maxLength: 253
  26075. minLength: 1
  26076. pattern: ^[-._a-zA-Z0-9]+$
  26077. type: string
  26078. name:
  26079. description: The name of the Secret resource being referred to.
  26080. maxLength: 253
  26081. minLength: 1
  26082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26083. type: string
  26084. namespace:
  26085. description: |-
  26086. The namespace of the Secret resource being referred to.
  26087. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26088. maxLength: 63
  26089. minLength: 1
  26090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26091. type: string
  26092. type: object
  26093. required:
  26094. - path
  26095. - secretRef
  26096. type: object
  26097. cert:
  26098. description: |-
  26099. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  26100. Cert authentication method
  26101. properties:
  26102. clientCert:
  26103. description: |-
  26104. ClientCert is a certificate to authenticate using the Cert Vault
  26105. authentication method
  26106. properties:
  26107. key:
  26108. description: |-
  26109. A key in the referenced Secret.
  26110. Some instances of this field may be defaulted, in others it may be required.
  26111. maxLength: 253
  26112. minLength: 1
  26113. pattern: ^[-._a-zA-Z0-9]+$
  26114. type: string
  26115. name:
  26116. description: The name of the Secret resource being referred to.
  26117. maxLength: 253
  26118. minLength: 1
  26119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26120. type: string
  26121. namespace:
  26122. description: |-
  26123. The namespace of the Secret resource being referred to.
  26124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26125. maxLength: 63
  26126. minLength: 1
  26127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26128. type: string
  26129. type: object
  26130. secretRef:
  26131. description: |-
  26132. SecretRef to a key in a Secret resource containing client private key to
  26133. authenticate with Vault using the Cert authentication method
  26134. properties:
  26135. key:
  26136. description: |-
  26137. A key in the referenced Secret.
  26138. Some instances of this field may be defaulted, in others it may be required.
  26139. maxLength: 253
  26140. minLength: 1
  26141. pattern: ^[-._a-zA-Z0-9]+$
  26142. type: string
  26143. name:
  26144. description: The name of the Secret resource being referred to.
  26145. maxLength: 253
  26146. minLength: 1
  26147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26148. type: string
  26149. namespace:
  26150. description: |-
  26151. The namespace of the Secret resource being referred to.
  26152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26153. maxLength: 63
  26154. minLength: 1
  26155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26156. type: string
  26157. type: object
  26158. type: object
  26159. iam:
  26160. description: |-
  26161. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  26162. AWS IAM authentication method
  26163. properties:
  26164. externalID:
  26165. description: AWS External ID set on assumed IAM roles
  26166. type: string
  26167. jwt:
  26168. description: Specify a service account with IRSA enabled
  26169. properties:
  26170. serviceAccountRef:
  26171. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26172. properties:
  26173. audiences:
  26174. description: |-
  26175. Audience specifies the `aud` claim for the service account token
  26176. Some providers automatically extend the audience field based on well-known annotations for workload
  26177. identity (e.g. IRSA or GCP Workload Identity)
  26178. items:
  26179. type: string
  26180. type: array
  26181. name:
  26182. description: The name of the ServiceAccount resource being referred to.
  26183. maxLength: 253
  26184. minLength: 1
  26185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26186. type: string
  26187. namespace:
  26188. description: |-
  26189. Namespace of the resource being referred to.
  26190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26191. maxLength: 63
  26192. minLength: 1
  26193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26194. type: string
  26195. required:
  26196. - name
  26197. type: object
  26198. type: object
  26199. path:
  26200. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  26201. type: string
  26202. region:
  26203. description: AWS region
  26204. type: string
  26205. role:
  26206. description: This is the AWS role to be assumed before talking to vault
  26207. type: string
  26208. secretRef:
  26209. description: Specify credentials in a Secret object
  26210. properties:
  26211. accessKeyIDSecretRef:
  26212. description: The AccessKeyID is used for authentication
  26213. properties:
  26214. key:
  26215. description: |-
  26216. A key in the referenced Secret.
  26217. Some instances of this field may be defaulted, in others it may be required.
  26218. maxLength: 253
  26219. minLength: 1
  26220. pattern: ^[-._a-zA-Z0-9]+$
  26221. type: string
  26222. name:
  26223. description: The name of the Secret resource being referred to.
  26224. maxLength: 253
  26225. minLength: 1
  26226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26227. type: string
  26228. namespace:
  26229. description: |-
  26230. The namespace of the Secret resource being referred to.
  26231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26232. maxLength: 63
  26233. minLength: 1
  26234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26235. type: string
  26236. type: object
  26237. secretAccessKeySecretRef:
  26238. description: The SecretAccessKey is used for authentication
  26239. properties:
  26240. key:
  26241. description: |-
  26242. A key in the referenced Secret.
  26243. Some instances of this field may be defaulted, in others it may be required.
  26244. maxLength: 253
  26245. minLength: 1
  26246. pattern: ^[-._a-zA-Z0-9]+$
  26247. type: string
  26248. name:
  26249. description: The name of the Secret resource being referred to.
  26250. maxLength: 253
  26251. minLength: 1
  26252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26253. type: string
  26254. namespace:
  26255. description: |-
  26256. The namespace of the Secret resource being referred to.
  26257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26258. maxLength: 63
  26259. minLength: 1
  26260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26261. type: string
  26262. type: object
  26263. sessionTokenSecretRef:
  26264. description: |-
  26265. The SessionToken used for authentication
  26266. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26267. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26268. properties:
  26269. key:
  26270. description: |-
  26271. A key in the referenced Secret.
  26272. Some instances of this field may be defaulted, in others it may be required.
  26273. maxLength: 253
  26274. minLength: 1
  26275. pattern: ^[-._a-zA-Z0-9]+$
  26276. type: string
  26277. name:
  26278. description: The name of the Secret resource being referred to.
  26279. maxLength: 253
  26280. minLength: 1
  26281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26282. type: string
  26283. namespace:
  26284. description: |-
  26285. The namespace of the Secret resource being referred to.
  26286. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26287. maxLength: 63
  26288. minLength: 1
  26289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26290. type: string
  26291. type: object
  26292. type: object
  26293. vaultAwsIamServerID:
  26294. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  26295. type: string
  26296. vaultRole:
  26297. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  26298. type: string
  26299. required:
  26300. - vaultRole
  26301. type: object
  26302. jwt:
  26303. description: |-
  26304. Jwt authenticates with Vault by passing role and JWT token using the
  26305. JWT/OIDC authentication method
  26306. properties:
  26307. kubernetesServiceAccountToken:
  26308. description: |-
  26309. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  26310. a token for with the `TokenRequest` API.
  26311. properties:
  26312. audiences:
  26313. description: |-
  26314. Optional audiences field that will be used to request a temporary Kubernetes service
  26315. account token for the service account referenced by `serviceAccountRef`.
  26316. Defaults to a single audience `vault` it not specified.
  26317. Deprecated: use serviceAccountRef.Audiences instead
  26318. items:
  26319. type: string
  26320. type: array
  26321. expirationSeconds:
  26322. description: |-
  26323. Optional expiration time in seconds that will be used to request a temporary
  26324. Kubernetes service account token for the service account referenced by
  26325. `serviceAccountRef`.
  26326. Deprecated: this will be removed in the future.
  26327. Defaults to 10 minutes.
  26328. format: int64
  26329. type: integer
  26330. serviceAccountRef:
  26331. description: Service account field containing the name of a kubernetes ServiceAccount.
  26332. properties:
  26333. audiences:
  26334. description: |-
  26335. Audience specifies the `aud` claim for the service account token
  26336. Some providers automatically extend the audience field based on well-known annotations for workload
  26337. identity (e.g. IRSA or GCP Workload Identity)
  26338. items:
  26339. type: string
  26340. type: array
  26341. name:
  26342. description: The name of the ServiceAccount resource being referred to.
  26343. maxLength: 253
  26344. minLength: 1
  26345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26346. type: string
  26347. namespace:
  26348. description: |-
  26349. Namespace of the resource being referred to.
  26350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26351. maxLength: 63
  26352. minLength: 1
  26353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26354. type: string
  26355. required:
  26356. - name
  26357. type: object
  26358. required:
  26359. - serviceAccountRef
  26360. type: object
  26361. path:
  26362. default: jwt
  26363. description: |-
  26364. Path where the JWT authentication backend is mounted
  26365. in Vault, e.g: "jwt"
  26366. type: string
  26367. role:
  26368. description: |-
  26369. Role is a JWT role to authenticate using the JWT/OIDC Vault
  26370. authentication method
  26371. type: string
  26372. secretRef:
  26373. description: |-
  26374. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  26375. authenticate with Vault using the JWT/OIDC authentication method.
  26376. properties:
  26377. key:
  26378. description: |-
  26379. A key in the referenced Secret.
  26380. Some instances of this field may be defaulted, in others it may be required.
  26381. maxLength: 253
  26382. minLength: 1
  26383. pattern: ^[-._a-zA-Z0-9]+$
  26384. type: string
  26385. name:
  26386. description: The name of the Secret resource being referred to.
  26387. maxLength: 253
  26388. minLength: 1
  26389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26390. type: string
  26391. namespace:
  26392. description: |-
  26393. The namespace of the Secret resource being referred to.
  26394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26395. maxLength: 63
  26396. minLength: 1
  26397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26398. type: string
  26399. type: object
  26400. required:
  26401. - path
  26402. type: object
  26403. kubernetes:
  26404. description: |-
  26405. Kubernetes authenticates with Vault by passing the ServiceAccount
  26406. token stored in the named Secret resource to the Vault server.
  26407. properties:
  26408. mountPath:
  26409. default: kubernetes
  26410. description: |-
  26411. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  26412. "kubernetes"
  26413. type: string
  26414. role:
  26415. description: |-
  26416. A required field containing the Vault Role to assume. A Role binds a
  26417. Kubernetes ServiceAccount with a set of Vault policies.
  26418. type: string
  26419. secretRef:
  26420. description: |-
  26421. Optional secret field containing a Kubernetes ServiceAccount JWT used
  26422. for authenticating with Vault. If a name is specified without a key,
  26423. `token` is the default. If one is not specified, the one bound to
  26424. the controller will be used.
  26425. properties:
  26426. key:
  26427. description: |-
  26428. A key in the referenced Secret.
  26429. Some instances of this field may be defaulted, in others it may be required.
  26430. maxLength: 253
  26431. minLength: 1
  26432. pattern: ^[-._a-zA-Z0-9]+$
  26433. type: string
  26434. name:
  26435. description: The name of the Secret resource being referred to.
  26436. maxLength: 253
  26437. minLength: 1
  26438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26439. type: string
  26440. namespace:
  26441. description: |-
  26442. The namespace of the Secret resource being referred to.
  26443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26444. maxLength: 63
  26445. minLength: 1
  26446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26447. type: string
  26448. type: object
  26449. serviceAccountRef:
  26450. description: |-
  26451. Optional service account field containing the name of a kubernetes ServiceAccount.
  26452. If the service account is specified, the service account secret token JWT will be used
  26453. for authenticating with Vault. If the service account selector is not supplied,
  26454. the secretRef will be used instead.
  26455. properties:
  26456. audiences:
  26457. description: |-
  26458. Audience specifies the `aud` claim for the service account token
  26459. Some providers automatically extend the audience field based on well-known annotations for workload
  26460. identity (e.g. IRSA or GCP Workload Identity)
  26461. items:
  26462. type: string
  26463. type: array
  26464. name:
  26465. description: The name of the ServiceAccount resource being referred to.
  26466. maxLength: 253
  26467. minLength: 1
  26468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26469. type: string
  26470. namespace:
  26471. description: |-
  26472. Namespace of the resource being referred to.
  26473. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26474. maxLength: 63
  26475. minLength: 1
  26476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26477. type: string
  26478. required:
  26479. - name
  26480. type: object
  26481. required:
  26482. - mountPath
  26483. - role
  26484. type: object
  26485. ldap:
  26486. description: |-
  26487. Ldap authenticates with Vault by passing username/password pair using
  26488. the LDAP authentication method
  26489. properties:
  26490. path:
  26491. default: ldap
  26492. description: |-
  26493. Path where the LDAP authentication backend is mounted
  26494. in Vault, e.g: "ldap"
  26495. type: string
  26496. secretRef:
  26497. description: |-
  26498. SecretRef to a key in a Secret resource containing password for the LDAP
  26499. user used to authenticate with Vault using the LDAP authentication
  26500. method
  26501. properties:
  26502. key:
  26503. description: |-
  26504. A key in the referenced Secret.
  26505. Some instances of this field may be defaulted, in others it may be required.
  26506. maxLength: 253
  26507. minLength: 1
  26508. pattern: ^[-._a-zA-Z0-9]+$
  26509. type: string
  26510. name:
  26511. description: The name of the Secret resource being referred to.
  26512. maxLength: 253
  26513. minLength: 1
  26514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26515. type: string
  26516. namespace:
  26517. description: |-
  26518. The namespace of the Secret resource being referred to.
  26519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26520. maxLength: 63
  26521. minLength: 1
  26522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26523. type: string
  26524. type: object
  26525. username:
  26526. description: |-
  26527. Username is an LDAP username used to authenticate using the LDAP Vault
  26528. authentication method
  26529. type: string
  26530. required:
  26531. - path
  26532. - username
  26533. type: object
  26534. namespace:
  26535. description: |-
  26536. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26537. Namespaces is a set of features within Vault Enterprise that allows
  26538. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26539. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26540. This will default to Vault.Namespace field if set, or empty otherwise
  26541. type: string
  26542. tokenSecretRef:
  26543. description: TokenSecretRef authenticates with Vault by presenting a token.
  26544. properties:
  26545. key:
  26546. description: |-
  26547. A key in the referenced Secret.
  26548. Some instances of this field may be defaulted, in others it may be required.
  26549. maxLength: 253
  26550. minLength: 1
  26551. pattern: ^[-._a-zA-Z0-9]+$
  26552. type: string
  26553. name:
  26554. description: The name of the Secret resource being referred to.
  26555. maxLength: 253
  26556. minLength: 1
  26557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26558. type: string
  26559. namespace:
  26560. description: |-
  26561. The namespace of the Secret resource being referred to.
  26562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26563. maxLength: 63
  26564. minLength: 1
  26565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26566. type: string
  26567. type: object
  26568. userPass:
  26569. description: UserPass authenticates with Vault by passing username/password pair
  26570. properties:
  26571. path:
  26572. default: userpass
  26573. description: |-
  26574. Path where the UserPassword authentication backend is mounted
  26575. in Vault, e.g: "userpass"
  26576. type: string
  26577. secretRef:
  26578. description: |-
  26579. SecretRef to a key in a Secret resource containing password for the
  26580. user used to authenticate with Vault using the UserPass authentication
  26581. method
  26582. properties:
  26583. key:
  26584. description: |-
  26585. A key in the referenced Secret.
  26586. Some instances of this field may be defaulted, in others it may be required.
  26587. maxLength: 253
  26588. minLength: 1
  26589. pattern: ^[-._a-zA-Z0-9]+$
  26590. type: string
  26591. name:
  26592. description: The name of the Secret resource being referred to.
  26593. maxLength: 253
  26594. minLength: 1
  26595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26596. type: string
  26597. namespace:
  26598. description: |-
  26599. The namespace of the Secret resource being referred to.
  26600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26601. maxLength: 63
  26602. minLength: 1
  26603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26604. type: string
  26605. type: object
  26606. username:
  26607. description: |-
  26608. Username is a username used to authenticate using the UserPass Vault
  26609. authentication method
  26610. type: string
  26611. required:
  26612. - path
  26613. - username
  26614. type: object
  26615. type: object
  26616. caBundle:
  26617. description: |-
  26618. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26619. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26620. plain HTTP protocol connection. If not set the system root certificates
  26621. are used to validate the TLS connection.
  26622. format: byte
  26623. type: string
  26624. caProvider:
  26625. description: The provider for the CA bundle to use to validate Vault server certificate.
  26626. properties:
  26627. key:
  26628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26629. maxLength: 253
  26630. minLength: 1
  26631. pattern: ^[-._a-zA-Z0-9]+$
  26632. type: string
  26633. name:
  26634. description: The name of the object located at the provider type.
  26635. maxLength: 253
  26636. minLength: 1
  26637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26638. type: string
  26639. namespace:
  26640. description: |-
  26641. The namespace the Provider type is in.
  26642. Can only be defined when used in a ClusterSecretStore.
  26643. maxLength: 63
  26644. minLength: 1
  26645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26646. type: string
  26647. type:
  26648. description: The type of provider to use such as "Secret", or "ConfigMap".
  26649. enum:
  26650. - Secret
  26651. - ConfigMap
  26652. type: string
  26653. required:
  26654. - name
  26655. - type
  26656. type: object
  26657. forwardInconsistent:
  26658. description: |-
  26659. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26660. leader instead of simply retrying within a loop. This can increase performance if
  26661. the option is enabled serverside.
  26662. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26663. type: boolean
  26664. headers:
  26665. additionalProperties:
  26666. type: string
  26667. description: Headers to be added in Vault request
  26668. type: object
  26669. namespace:
  26670. description: |-
  26671. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26672. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26673. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26674. type: string
  26675. path:
  26676. description: |-
  26677. Path is the mount path of the Vault KV backend endpoint, e.g:
  26678. "secret". The v2 KV secret engine version specific "/data" path suffix
  26679. for fetching secrets from Vault is optional and will be appended
  26680. if not present in specified path.
  26681. type: string
  26682. readYourWrites:
  26683. description: |-
  26684. ReadYourWrites ensures isolated read-after-write semantics by
  26685. providing discovered cluster replication states in each request.
  26686. More information about eventual consistency in Vault can be found here
  26687. https://www.vaultproject.io/docs/enterprise/consistency
  26688. type: boolean
  26689. server:
  26690. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26691. type: string
  26692. tls:
  26693. description: |-
  26694. The configuration used for client side related TLS communication, when the Vault server
  26695. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26696. This parameter is ignored for plain HTTP protocol connection.
  26697. It's worth noting this configuration is different from the "TLS certificates auth method",
  26698. which is available under the `auth.cert` section.
  26699. properties:
  26700. certSecretRef:
  26701. description: |-
  26702. CertSecretRef is a certificate added to the transport layer
  26703. when communicating with the Vault server.
  26704. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26705. properties:
  26706. key:
  26707. description: |-
  26708. A key in the referenced Secret.
  26709. Some instances of this field may be defaulted, in others it may be required.
  26710. maxLength: 253
  26711. minLength: 1
  26712. pattern: ^[-._a-zA-Z0-9]+$
  26713. type: string
  26714. name:
  26715. description: The name of the Secret resource being referred to.
  26716. maxLength: 253
  26717. minLength: 1
  26718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26719. type: string
  26720. namespace:
  26721. description: |-
  26722. The namespace of the Secret resource being referred to.
  26723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26724. maxLength: 63
  26725. minLength: 1
  26726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26727. type: string
  26728. type: object
  26729. keySecretRef:
  26730. description: |-
  26731. KeySecretRef to a key in a Secret resource containing client private key
  26732. added to the transport layer when communicating with the Vault server.
  26733. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26734. properties:
  26735. key:
  26736. description: |-
  26737. A key in the referenced Secret.
  26738. Some instances of this field may be defaulted, in others it may be required.
  26739. maxLength: 253
  26740. minLength: 1
  26741. pattern: ^[-._a-zA-Z0-9]+$
  26742. type: string
  26743. name:
  26744. description: The name of the Secret resource being referred to.
  26745. maxLength: 253
  26746. minLength: 1
  26747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26748. type: string
  26749. namespace:
  26750. description: |-
  26751. The namespace of the Secret resource being referred to.
  26752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26753. maxLength: 63
  26754. minLength: 1
  26755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26756. type: string
  26757. type: object
  26758. type: object
  26759. version:
  26760. default: v2
  26761. description: |-
  26762. Version is the Vault KV secret engine version. This can be either "v1" or
  26763. "v2". Version defaults to "v2".
  26764. enum:
  26765. - v1
  26766. - v2
  26767. type: string
  26768. required:
  26769. - server
  26770. type: object
  26771. webhook:
  26772. description: Webhook configures this store to sync secrets using a generic templated webhook
  26773. properties:
  26774. auth:
  26775. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26776. maxProperties: 1
  26777. minProperties: 1
  26778. properties:
  26779. ntlm:
  26780. description: NTLMProtocol configures the store to use NTLM for auth
  26781. properties:
  26782. passwordSecret:
  26783. description: |-
  26784. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26785. In some instances, `key` is a required field.
  26786. properties:
  26787. key:
  26788. description: |-
  26789. A key in the referenced Secret.
  26790. Some instances of this field may be defaulted, in others it may be required.
  26791. maxLength: 253
  26792. minLength: 1
  26793. pattern: ^[-._a-zA-Z0-9]+$
  26794. type: string
  26795. name:
  26796. description: The name of the Secret resource being referred to.
  26797. maxLength: 253
  26798. minLength: 1
  26799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26800. type: string
  26801. namespace:
  26802. description: |-
  26803. The namespace of the Secret resource being referred to.
  26804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26805. maxLength: 63
  26806. minLength: 1
  26807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26808. type: string
  26809. type: object
  26810. usernameSecret:
  26811. description: |-
  26812. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26813. In some instances, `key` is a required field.
  26814. properties:
  26815. key:
  26816. description: |-
  26817. A key in the referenced Secret.
  26818. Some instances of this field may be defaulted, in others it may be required.
  26819. maxLength: 253
  26820. minLength: 1
  26821. pattern: ^[-._a-zA-Z0-9]+$
  26822. type: string
  26823. name:
  26824. description: The name of the Secret resource being referred to.
  26825. maxLength: 253
  26826. minLength: 1
  26827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26828. type: string
  26829. namespace:
  26830. description: |-
  26831. The namespace of the Secret resource being referred to.
  26832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26833. maxLength: 63
  26834. minLength: 1
  26835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26836. type: string
  26837. type: object
  26838. required:
  26839. - passwordSecret
  26840. - usernameSecret
  26841. type: object
  26842. type: object
  26843. body:
  26844. description: Body
  26845. type: string
  26846. caBundle:
  26847. description: |-
  26848. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26849. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26850. plain HTTP protocol connection. If not set the system root certificates
  26851. are used to validate the TLS connection.
  26852. format: byte
  26853. type: string
  26854. caProvider:
  26855. description: The provider for the CA bundle to use to validate webhook server certificate.
  26856. properties:
  26857. key:
  26858. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26859. maxLength: 253
  26860. minLength: 1
  26861. pattern: ^[-._a-zA-Z0-9]+$
  26862. type: string
  26863. name:
  26864. description: The name of the object located at the provider type.
  26865. maxLength: 253
  26866. minLength: 1
  26867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26868. type: string
  26869. namespace:
  26870. description: The namespace the Provider type is in.
  26871. maxLength: 63
  26872. minLength: 1
  26873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26874. type: string
  26875. type:
  26876. description: The type of provider to use such as "Secret", or "ConfigMap".
  26877. enum:
  26878. - Secret
  26879. - ConfigMap
  26880. type: string
  26881. required:
  26882. - name
  26883. - type
  26884. type: object
  26885. headers:
  26886. additionalProperties:
  26887. type: string
  26888. description: Headers
  26889. type: object
  26890. method:
  26891. description: Webhook Method
  26892. type: string
  26893. result:
  26894. description: Result formatting
  26895. properties:
  26896. jsonPath:
  26897. description: Json path of return value
  26898. type: string
  26899. type: object
  26900. secrets:
  26901. description: |-
  26902. Secrets to fill in templates
  26903. These secrets will be passed to the templating function as key value pairs under the given name
  26904. items:
  26905. description: WebhookSecret defines a secret to be used in webhook templates.
  26906. properties:
  26907. name:
  26908. description: Name of this secret in templates
  26909. type: string
  26910. secretRef:
  26911. description: Secret ref to fill in credentials
  26912. properties:
  26913. key:
  26914. description: |-
  26915. A key in the referenced Secret.
  26916. Some instances of this field may be defaulted, in others it may be required.
  26917. maxLength: 253
  26918. minLength: 1
  26919. pattern: ^[-._a-zA-Z0-9]+$
  26920. type: string
  26921. name:
  26922. description: The name of the Secret resource being referred to.
  26923. maxLength: 253
  26924. minLength: 1
  26925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26926. type: string
  26927. namespace:
  26928. description: |-
  26929. The namespace of the Secret resource being referred to.
  26930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26931. maxLength: 63
  26932. minLength: 1
  26933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26934. type: string
  26935. type: object
  26936. required:
  26937. - name
  26938. - secretRef
  26939. type: object
  26940. type: array
  26941. timeout:
  26942. description: Timeout
  26943. type: string
  26944. url:
  26945. description: Webhook url to call
  26946. type: string
  26947. required:
  26948. - result
  26949. - url
  26950. type: object
  26951. yandexcertificatemanager:
  26952. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26953. properties:
  26954. apiEndpoint:
  26955. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26956. type: string
  26957. auth:
  26958. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26959. properties:
  26960. authorizedKeySecretRef:
  26961. description: The authorized key used for authentication
  26962. properties:
  26963. key:
  26964. description: |-
  26965. A key in the referenced Secret.
  26966. Some instances of this field may be defaulted, in others it may be required.
  26967. maxLength: 253
  26968. minLength: 1
  26969. pattern: ^[-._a-zA-Z0-9]+$
  26970. type: string
  26971. name:
  26972. description: The name of the Secret resource being referred to.
  26973. maxLength: 253
  26974. minLength: 1
  26975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26976. type: string
  26977. namespace:
  26978. description: |-
  26979. The namespace of the Secret resource being referred to.
  26980. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26981. maxLength: 63
  26982. minLength: 1
  26983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26984. type: string
  26985. type: object
  26986. type: object
  26987. caProvider:
  26988. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26989. properties:
  26990. certSecretRef:
  26991. description: |-
  26992. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26993. In some instances, `key` is a required field.
  26994. properties:
  26995. key:
  26996. description: |-
  26997. A key in the referenced Secret.
  26998. Some instances of this field may be defaulted, in others it may be required.
  26999. maxLength: 253
  27000. minLength: 1
  27001. pattern: ^[-._a-zA-Z0-9]+$
  27002. type: string
  27003. name:
  27004. description: The name of the Secret resource being referred to.
  27005. maxLength: 253
  27006. minLength: 1
  27007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27008. type: string
  27009. namespace:
  27010. description: |-
  27011. The namespace of the Secret resource being referred to.
  27012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27013. maxLength: 63
  27014. minLength: 1
  27015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27016. type: string
  27017. type: object
  27018. type: object
  27019. required:
  27020. - auth
  27021. type: object
  27022. yandexlockbox:
  27023. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  27024. properties:
  27025. apiEndpoint:
  27026. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  27027. type: string
  27028. auth:
  27029. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  27030. properties:
  27031. authorizedKeySecretRef:
  27032. description: The authorized key used for authentication
  27033. properties:
  27034. key:
  27035. description: |-
  27036. A key in the referenced Secret.
  27037. Some instances of this field may be defaulted, in others it may be required.
  27038. maxLength: 253
  27039. minLength: 1
  27040. pattern: ^[-._a-zA-Z0-9]+$
  27041. type: string
  27042. name:
  27043. description: The name of the Secret resource being referred to.
  27044. maxLength: 253
  27045. minLength: 1
  27046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27047. type: string
  27048. namespace:
  27049. description: |-
  27050. The namespace of the Secret resource being referred to.
  27051. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27052. maxLength: 63
  27053. minLength: 1
  27054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27055. type: string
  27056. type: object
  27057. type: object
  27058. caProvider:
  27059. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  27060. properties:
  27061. certSecretRef:
  27062. description: |-
  27063. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27064. In some instances, `key` is a required field.
  27065. properties:
  27066. key:
  27067. description: |-
  27068. A key in the referenced Secret.
  27069. Some instances of this field may be defaulted, in others it may be required.
  27070. maxLength: 253
  27071. minLength: 1
  27072. pattern: ^[-._a-zA-Z0-9]+$
  27073. type: string
  27074. name:
  27075. description: The name of the Secret resource being referred to.
  27076. maxLength: 253
  27077. minLength: 1
  27078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27079. type: string
  27080. namespace:
  27081. description: |-
  27082. The namespace of the Secret resource being referred to.
  27083. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27084. maxLength: 63
  27085. minLength: 1
  27086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27087. type: string
  27088. type: object
  27089. type: object
  27090. required:
  27091. - auth
  27092. type: object
  27093. type: object
  27094. refreshInterval:
  27095. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  27096. type: integer
  27097. retrySettings:
  27098. description: Used to configure HTTP retries on failures.
  27099. properties:
  27100. maxRetries:
  27101. description: MaxRetries is the maximum number of retry attempts.
  27102. format: int32
  27103. type: integer
  27104. retryInterval:
  27105. description: RetryInterval is the interval between retry attempts.
  27106. type: string
  27107. type: object
  27108. required:
  27109. - provider
  27110. type: object
  27111. status:
  27112. description: SecretStoreStatus defines the observed state of the SecretStore.
  27113. properties:
  27114. capabilities:
  27115. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  27116. type: string
  27117. conditions:
  27118. items:
  27119. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  27120. properties:
  27121. lastTransitionTime:
  27122. format: date-time
  27123. type: string
  27124. message:
  27125. type: string
  27126. reason:
  27127. type: string
  27128. status:
  27129. type: string
  27130. type:
  27131. description: SecretStoreConditionType represents the condition type of the SecretStore.
  27132. type: string
  27133. required:
  27134. - status
  27135. - type
  27136. type: object
  27137. type: array
  27138. type: object
  27139. type: object
  27140. served: false
  27141. storage: false
  27142. subresources:
  27143. status: {}
  27144. ---
  27145. apiVersion: apiextensions.k8s.io/v1
  27146. kind: CustomResourceDefinition
  27147. metadata:
  27148. annotations:
  27149. controller-gen.kubebuilder.io/version: v0.19.0
  27150. labels:
  27151. external-secrets.io/component: controller
  27152. name: acraccesstokens.generators.external-secrets.io
  27153. spec:
  27154. group: generators.external-secrets.io
  27155. names:
  27156. categories:
  27157. - external-secrets
  27158. - external-secrets-generators
  27159. kind: ACRAccessToken
  27160. listKind: ACRAccessTokenList
  27161. plural: acraccesstokens
  27162. singular: acraccesstoken
  27163. scope: Namespaced
  27164. versions:
  27165. - name: v1alpha1
  27166. schema:
  27167. openAPIV3Schema:
  27168. description: |-
  27169. ACRAccessToken returns an Azure Container Registry token
  27170. that can be used for pushing/pulling images.
  27171. Note: by default it will return an ACR Refresh Token with full access
  27172. (depending on the identity).
  27173. This can be scoped down to the repository level using .spec.scope.
  27174. In case scope is defined it will return an ACR Access Token.
  27175. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  27176. properties:
  27177. apiVersion:
  27178. description: |-
  27179. APIVersion defines the versioned schema of this representation of an object.
  27180. Servers should convert recognized schemas to the latest internal value, and
  27181. may reject unrecognized values.
  27182. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27183. type: string
  27184. kind:
  27185. description: |-
  27186. Kind is a string value representing the REST resource this object represents.
  27187. Servers may infer this from the endpoint the client submits requests to.
  27188. Cannot be updated.
  27189. In CamelCase.
  27190. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27191. type: string
  27192. metadata:
  27193. type: object
  27194. spec:
  27195. description: |-
  27196. ACRAccessTokenSpec defines how to generate the access token
  27197. e.g. how to authenticate and which registry to use.
  27198. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27199. properties:
  27200. auth:
  27201. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27202. properties:
  27203. managedIdentity:
  27204. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27205. properties:
  27206. identityId:
  27207. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27208. type: string
  27209. type: object
  27210. servicePrincipal:
  27211. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27212. properties:
  27213. secretRef:
  27214. description: |-
  27215. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27216. It uses static credentials stored in a Kind=Secret.
  27217. properties:
  27218. clientId:
  27219. description: The Azure clientId of the service principle used for authentication.
  27220. properties:
  27221. key:
  27222. description: |-
  27223. A key in the referenced Secret.
  27224. Some instances of this field may be defaulted, in others it may be required.
  27225. maxLength: 253
  27226. minLength: 1
  27227. pattern: ^[-._a-zA-Z0-9]+$
  27228. type: string
  27229. name:
  27230. description: The name of the Secret resource being referred to.
  27231. maxLength: 253
  27232. minLength: 1
  27233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27234. type: string
  27235. namespace:
  27236. description: |-
  27237. The namespace of the Secret resource being referred to.
  27238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27239. maxLength: 63
  27240. minLength: 1
  27241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27242. type: string
  27243. type: object
  27244. clientSecret:
  27245. description: The Azure ClientSecret of the service principle used for authentication.
  27246. properties:
  27247. key:
  27248. description: |-
  27249. A key in the referenced Secret.
  27250. Some instances of this field may be defaulted, in others it may be required.
  27251. maxLength: 253
  27252. minLength: 1
  27253. pattern: ^[-._a-zA-Z0-9]+$
  27254. type: string
  27255. name:
  27256. description: The name of the Secret resource being referred to.
  27257. maxLength: 253
  27258. minLength: 1
  27259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27260. type: string
  27261. namespace:
  27262. description: |-
  27263. The namespace of the Secret resource being referred to.
  27264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27265. maxLength: 63
  27266. minLength: 1
  27267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27268. type: string
  27269. type: object
  27270. type: object
  27271. required:
  27272. - secretRef
  27273. type: object
  27274. workloadIdentity:
  27275. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27276. properties:
  27277. serviceAccountRef:
  27278. description: |-
  27279. ServiceAccountRef specified the service account
  27280. that should be used when authenticating with WorkloadIdentity.
  27281. properties:
  27282. audiences:
  27283. description: |-
  27284. Audience specifies the `aud` claim for the service account token
  27285. Some providers automatically extend the audience field based on well-known annotations for workload
  27286. identity (e.g. IRSA or GCP Workload Identity)
  27287. items:
  27288. type: string
  27289. type: array
  27290. name:
  27291. description: The name of the ServiceAccount resource being referred to.
  27292. maxLength: 253
  27293. minLength: 1
  27294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27295. type: string
  27296. namespace:
  27297. description: |-
  27298. Namespace of the resource being referred to.
  27299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27300. maxLength: 63
  27301. minLength: 1
  27302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27303. type: string
  27304. required:
  27305. - name
  27306. type: object
  27307. type: object
  27308. type: object
  27309. environmentType:
  27310. default: PublicCloud
  27311. description: |-
  27312. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27313. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27314. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27315. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27316. enum:
  27317. - PublicCloud
  27318. - USGovernmentCloud
  27319. - ChinaCloud
  27320. - GermanCloud
  27321. - AzureStackCloud
  27322. type: string
  27323. registry:
  27324. description: |-
  27325. the domain name of the ACR registry
  27326. e.g. foobarexample.azurecr.io
  27327. type: string
  27328. scope:
  27329. description: |-
  27330. Define the scope for the access token, e.g. pull/push access for a repository.
  27331. if not provided it will return a refresh token that has full scope.
  27332. Note: you need to pin it down to the repository level, there is no wildcard available.
  27333. examples:
  27334. repository:my-repository:pull,push
  27335. repository:my-repository:pull
  27336. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27337. type: string
  27338. tenantId:
  27339. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27340. type: string
  27341. required:
  27342. - auth
  27343. - registry
  27344. type: object
  27345. type: object
  27346. served: true
  27347. storage: true
  27348. subresources:
  27349. status: {}
  27350. ---
  27351. apiVersion: apiextensions.k8s.io/v1
  27352. kind: CustomResourceDefinition
  27353. metadata:
  27354. annotations:
  27355. controller-gen.kubebuilder.io/version: v0.19.0
  27356. labels:
  27357. external-secrets.io/component: controller
  27358. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  27359. spec:
  27360. group: generators.external-secrets.io
  27361. names:
  27362. categories:
  27363. - external-secrets
  27364. - external-secrets-generators
  27365. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  27366. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  27367. plural: beyondtrustworkloadcredentialsdynamicsecrets
  27368. singular: beyondtrustworkloadcredentialsdynamicsecret
  27369. scope: Namespaced
  27370. versions:
  27371. - name: v1alpha1
  27372. schema:
  27373. openAPIV3Schema:
  27374. description: |-
  27375. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  27376. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  27377. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  27378. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  27379. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27380. properties:
  27381. apiVersion:
  27382. description: |-
  27383. APIVersion defines the versioned schema of this representation of an object.
  27384. Servers should convert recognized schemas to the latest internal value, and
  27385. may reject unrecognized values.
  27386. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27387. type: string
  27388. kind:
  27389. description: |-
  27390. Kind is a string value representing the REST resource this object represents.
  27391. Servers may infer this from the endpoint the client submits requests to.
  27392. Cannot be updated.
  27393. In CamelCase.
  27394. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27395. type: string
  27396. metadata:
  27397. type: object
  27398. spec:
  27399. description: |-
  27400. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27401. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27402. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27403. properties:
  27404. controller:
  27405. description: |-
  27406. Controller selects the controller that should handle this generator.
  27407. Leave empty to use the default controller.
  27408. type: string
  27409. provider:
  27410. description: |-
  27411. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27412. server connection details, and the folder path to the dynamic secret definition.
  27413. The folderPath should point to a dynamic secret definition that has been created in
  27414. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27415. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27416. properties:
  27417. auth:
  27418. description: |-
  27419. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27420. Currently supports API key authentication via Kubernetes secret reference.
  27421. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27422. properties:
  27423. apikey:
  27424. description: |-
  27425. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27426. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27427. properties:
  27428. token:
  27429. description: |-
  27430. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27431. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27432. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27433. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27434. properties:
  27435. key:
  27436. description: |-
  27437. A key in the referenced Secret.
  27438. Some instances of this field may be defaulted, in others it may be required.
  27439. maxLength: 253
  27440. minLength: 1
  27441. pattern: ^[-._a-zA-Z0-9]+$
  27442. type: string
  27443. name:
  27444. description: The name of the Secret resource being referred to.
  27445. maxLength: 253
  27446. minLength: 1
  27447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27448. type: string
  27449. namespace:
  27450. description: |-
  27451. The namespace of the Secret resource being referred to.
  27452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27453. maxLength: 63
  27454. minLength: 1
  27455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27456. type: string
  27457. type: object
  27458. required:
  27459. - token
  27460. type: object
  27461. required:
  27462. - apikey
  27463. type: object
  27464. caBundle:
  27465. description: |-
  27466. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27467. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27468. If not set, the system's trusted root certificates are used.
  27469. format: byte
  27470. type: string
  27471. caProvider:
  27472. description: |-
  27473. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27474. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27475. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27476. properties:
  27477. key:
  27478. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27479. maxLength: 253
  27480. minLength: 1
  27481. pattern: ^[-._a-zA-Z0-9]+$
  27482. type: string
  27483. name:
  27484. description: The name of the object located at the provider type.
  27485. maxLength: 253
  27486. minLength: 1
  27487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27488. type: string
  27489. namespace:
  27490. description: |-
  27491. The namespace the Provider type is in.
  27492. Can only be defined when used in a ClusterSecretStore.
  27493. maxLength: 63
  27494. minLength: 1
  27495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27496. type: string
  27497. type:
  27498. description: The type of provider to use such as "Secret", or "ConfigMap".
  27499. enum:
  27500. - Secret
  27501. - ConfigMap
  27502. type: string
  27503. required:
  27504. - name
  27505. - type
  27506. type: object
  27507. folderPath:
  27508. description: |-
  27509. FolderPath specifies the default folder path for secret retrieval.
  27510. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27511. Example: "production/database" or "dev/api-keys"
  27512. Leave empty to retrieve secrets from the root folder.
  27513. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27514. type: string
  27515. server:
  27516. description: |-
  27517. Server configures the BeyondTrust Workload Credentials server connection details.
  27518. Includes the API URL and Site ID for your BeyondTrust instance.
  27519. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27520. properties:
  27521. apiUrl:
  27522. description: |-
  27523. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27524. This should be the full URL to your BeyondTrust instance.
  27525. Example: https://api.beyondtrust.io/siie
  27526. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27527. type: string
  27528. siteId:
  27529. description: |-
  27530. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27531. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27532. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27533. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27534. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27535. type: string
  27536. required:
  27537. - apiUrl
  27538. - siteId
  27539. type: object
  27540. required:
  27541. - auth
  27542. - server
  27543. type: object
  27544. retrySettings:
  27545. description: |-
  27546. RetrySettings configures exponential backoff for failed API requests.
  27547. If not specified, uses the default retry settings.
  27548. properties:
  27549. maxRetries:
  27550. format: int32
  27551. type: integer
  27552. retryInterval:
  27553. type: string
  27554. type: object
  27555. required:
  27556. - provider
  27557. type: object
  27558. type: object
  27559. served: true
  27560. storage: true
  27561. subresources:
  27562. status: {}
  27563. ---
  27564. apiVersion: apiextensions.k8s.io/v1
  27565. kind: CustomResourceDefinition
  27566. metadata:
  27567. annotations:
  27568. controller-gen.kubebuilder.io/version: v0.19.0
  27569. labels:
  27570. external-secrets.io/component: controller
  27571. name: cloudsmithaccesstokens.generators.external-secrets.io
  27572. spec:
  27573. group: generators.external-secrets.io
  27574. names:
  27575. categories:
  27576. - external-secrets
  27577. - external-secrets-generators
  27578. kind: CloudsmithAccessToken
  27579. listKind: CloudsmithAccessTokenList
  27580. plural: cloudsmithaccesstokens
  27581. singular: cloudsmithaccesstoken
  27582. scope: Namespaced
  27583. versions:
  27584. - name: v1alpha1
  27585. schema:
  27586. openAPIV3Schema:
  27587. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27588. properties:
  27589. apiVersion:
  27590. description: |-
  27591. APIVersion defines the versioned schema of this representation of an object.
  27592. Servers should convert recognized schemas to the latest internal value, and
  27593. may reject unrecognized values.
  27594. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27595. type: string
  27596. kind:
  27597. description: |-
  27598. Kind is a string value representing the REST resource this object represents.
  27599. Servers may infer this from the endpoint the client submits requests to.
  27600. Cannot be updated.
  27601. In CamelCase.
  27602. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27603. type: string
  27604. metadata:
  27605. type: object
  27606. spec:
  27607. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27608. properties:
  27609. apiUrl:
  27610. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27611. type: string
  27612. orgSlug:
  27613. description: OrgSlug is the organization slug in Cloudsmith
  27614. type: string
  27615. serviceAccountRef:
  27616. description: Name of the service account you are federating with
  27617. properties:
  27618. audiences:
  27619. description: |-
  27620. Audience specifies the `aud` claim for the service account token
  27621. Some providers automatically extend the audience field based on well-known annotations for workload
  27622. identity (e.g. IRSA or GCP Workload Identity)
  27623. items:
  27624. type: string
  27625. type: array
  27626. name:
  27627. description: The name of the ServiceAccount resource being referred to.
  27628. maxLength: 253
  27629. minLength: 1
  27630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27631. type: string
  27632. namespace:
  27633. description: |-
  27634. Namespace of the resource being referred to.
  27635. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27636. maxLength: 63
  27637. minLength: 1
  27638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27639. type: string
  27640. required:
  27641. - name
  27642. type: object
  27643. serviceSlug:
  27644. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27645. type: string
  27646. required:
  27647. - orgSlug
  27648. - serviceAccountRef
  27649. - serviceSlug
  27650. type: object
  27651. type: object
  27652. served: true
  27653. storage: true
  27654. subresources:
  27655. status: {}
  27656. ---
  27657. apiVersion: apiextensions.k8s.io/v1
  27658. kind: CustomResourceDefinition
  27659. metadata:
  27660. annotations:
  27661. controller-gen.kubebuilder.io/version: v0.19.0
  27662. labels:
  27663. external-secrets.io/component: controller
  27664. name: clustergenerators.generators.external-secrets.io
  27665. spec:
  27666. group: generators.external-secrets.io
  27667. names:
  27668. categories:
  27669. - external-secrets
  27670. - external-secrets-generators
  27671. kind: ClusterGenerator
  27672. listKind: ClusterGeneratorList
  27673. plural: clustergenerators
  27674. singular: clustergenerator
  27675. scope: Cluster
  27676. versions:
  27677. - name: v1alpha1
  27678. schema:
  27679. openAPIV3Schema:
  27680. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27681. properties:
  27682. apiVersion:
  27683. description: |-
  27684. APIVersion defines the versioned schema of this representation of an object.
  27685. Servers should convert recognized schemas to the latest internal value, and
  27686. may reject unrecognized values.
  27687. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27688. type: string
  27689. kind:
  27690. description: |-
  27691. Kind is a string value representing the REST resource this object represents.
  27692. Servers may infer this from the endpoint the client submits requests to.
  27693. Cannot be updated.
  27694. In CamelCase.
  27695. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27696. type: string
  27697. metadata:
  27698. type: object
  27699. spec:
  27700. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27701. properties:
  27702. generator:
  27703. description: Generator the spec for this generator, must match the kind.
  27704. maxProperties: 1
  27705. minProperties: 1
  27706. properties:
  27707. acrAccessTokenSpec:
  27708. description: |-
  27709. ACRAccessTokenSpec defines how to generate the access token
  27710. e.g. how to authenticate and which registry to use.
  27711. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27712. properties:
  27713. auth:
  27714. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27715. properties:
  27716. managedIdentity:
  27717. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27718. properties:
  27719. identityId:
  27720. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27721. type: string
  27722. type: object
  27723. servicePrincipal:
  27724. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27725. properties:
  27726. secretRef:
  27727. description: |-
  27728. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27729. It uses static credentials stored in a Kind=Secret.
  27730. properties:
  27731. clientId:
  27732. description: The Azure clientId of the service principle used for authentication.
  27733. properties:
  27734. key:
  27735. description: |-
  27736. A key in the referenced Secret.
  27737. Some instances of this field may be defaulted, in others it may be required.
  27738. maxLength: 253
  27739. minLength: 1
  27740. pattern: ^[-._a-zA-Z0-9]+$
  27741. type: string
  27742. name:
  27743. description: The name of the Secret resource being referred to.
  27744. maxLength: 253
  27745. minLength: 1
  27746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27747. type: string
  27748. namespace:
  27749. description: |-
  27750. The namespace of the Secret resource being referred to.
  27751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27752. maxLength: 63
  27753. minLength: 1
  27754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27755. type: string
  27756. type: object
  27757. clientSecret:
  27758. description: The Azure ClientSecret of the service principle used for authentication.
  27759. properties:
  27760. key:
  27761. description: |-
  27762. A key in the referenced Secret.
  27763. Some instances of this field may be defaulted, in others it may be required.
  27764. maxLength: 253
  27765. minLength: 1
  27766. pattern: ^[-._a-zA-Z0-9]+$
  27767. type: string
  27768. name:
  27769. description: The name of the Secret resource being referred to.
  27770. maxLength: 253
  27771. minLength: 1
  27772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27773. type: string
  27774. namespace:
  27775. description: |-
  27776. The namespace of the Secret resource being referred to.
  27777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27778. maxLength: 63
  27779. minLength: 1
  27780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27781. type: string
  27782. type: object
  27783. type: object
  27784. required:
  27785. - secretRef
  27786. type: object
  27787. workloadIdentity:
  27788. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27789. properties:
  27790. serviceAccountRef:
  27791. description: |-
  27792. ServiceAccountRef specified the service account
  27793. that should be used when authenticating with WorkloadIdentity.
  27794. properties:
  27795. audiences:
  27796. description: |-
  27797. Audience specifies the `aud` claim for the service account token
  27798. Some providers automatically extend the audience field based on well-known annotations for workload
  27799. identity (e.g. IRSA or GCP Workload Identity)
  27800. items:
  27801. type: string
  27802. type: array
  27803. name:
  27804. description: The name of the ServiceAccount resource being referred to.
  27805. maxLength: 253
  27806. minLength: 1
  27807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27808. type: string
  27809. namespace:
  27810. description: |-
  27811. Namespace of the resource being referred to.
  27812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27813. maxLength: 63
  27814. minLength: 1
  27815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27816. type: string
  27817. required:
  27818. - name
  27819. type: object
  27820. type: object
  27821. type: object
  27822. environmentType:
  27823. default: PublicCloud
  27824. description: |-
  27825. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27826. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27827. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27828. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27829. enum:
  27830. - PublicCloud
  27831. - USGovernmentCloud
  27832. - ChinaCloud
  27833. - GermanCloud
  27834. - AzureStackCloud
  27835. type: string
  27836. registry:
  27837. description: |-
  27838. the domain name of the ACR registry
  27839. e.g. foobarexample.azurecr.io
  27840. type: string
  27841. scope:
  27842. description: |-
  27843. Define the scope for the access token, e.g. pull/push access for a repository.
  27844. if not provided it will return a refresh token that has full scope.
  27845. Note: you need to pin it down to the repository level, there is no wildcard available.
  27846. examples:
  27847. repository:my-repository:pull,push
  27848. repository:my-repository:pull
  27849. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27850. type: string
  27851. tenantId:
  27852. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27853. type: string
  27854. required:
  27855. - auth
  27856. - registry
  27857. type: object
  27858. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27859. description: |-
  27860. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27861. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27862. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27863. properties:
  27864. controller:
  27865. description: |-
  27866. Controller selects the controller that should handle this generator.
  27867. Leave empty to use the default controller.
  27868. type: string
  27869. provider:
  27870. description: |-
  27871. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27872. server connection details, and the folder path to the dynamic secret definition.
  27873. The folderPath should point to a dynamic secret definition that has been created in
  27874. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27875. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27876. properties:
  27877. auth:
  27878. description: |-
  27879. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27880. Currently supports API key authentication via Kubernetes secret reference.
  27881. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27882. properties:
  27883. apikey:
  27884. description: |-
  27885. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27886. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27887. properties:
  27888. token:
  27889. description: |-
  27890. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27891. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27892. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27893. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27894. properties:
  27895. key:
  27896. description: |-
  27897. A key in the referenced Secret.
  27898. Some instances of this field may be defaulted, in others it may be required.
  27899. maxLength: 253
  27900. minLength: 1
  27901. pattern: ^[-._a-zA-Z0-9]+$
  27902. type: string
  27903. name:
  27904. description: The name of the Secret resource being referred to.
  27905. maxLength: 253
  27906. minLength: 1
  27907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27908. type: string
  27909. namespace:
  27910. description: |-
  27911. The namespace of the Secret resource being referred to.
  27912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27913. maxLength: 63
  27914. minLength: 1
  27915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27916. type: string
  27917. type: object
  27918. required:
  27919. - token
  27920. type: object
  27921. required:
  27922. - apikey
  27923. type: object
  27924. caBundle:
  27925. description: |-
  27926. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27927. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27928. If not set, the system's trusted root certificates are used.
  27929. format: byte
  27930. type: string
  27931. caProvider:
  27932. description: |-
  27933. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27934. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27935. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27936. properties:
  27937. key:
  27938. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27939. maxLength: 253
  27940. minLength: 1
  27941. pattern: ^[-._a-zA-Z0-9]+$
  27942. type: string
  27943. name:
  27944. description: The name of the object located at the provider type.
  27945. maxLength: 253
  27946. minLength: 1
  27947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27948. type: string
  27949. namespace:
  27950. description: |-
  27951. The namespace the Provider type is in.
  27952. Can only be defined when used in a ClusterSecretStore.
  27953. maxLength: 63
  27954. minLength: 1
  27955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27956. type: string
  27957. type:
  27958. description: The type of provider to use such as "Secret", or "ConfigMap".
  27959. enum:
  27960. - Secret
  27961. - ConfigMap
  27962. type: string
  27963. required:
  27964. - name
  27965. - type
  27966. type: object
  27967. folderPath:
  27968. description: |-
  27969. FolderPath specifies the default folder path for secret retrieval.
  27970. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27971. Example: "production/database" or "dev/api-keys"
  27972. Leave empty to retrieve secrets from the root folder.
  27973. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27974. type: string
  27975. server:
  27976. description: |-
  27977. Server configures the BeyondTrust Workload Credentials server connection details.
  27978. Includes the API URL and Site ID for your BeyondTrust instance.
  27979. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27980. properties:
  27981. apiUrl:
  27982. description: |-
  27983. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27984. This should be the full URL to your BeyondTrust instance.
  27985. Example: https://api.beyondtrust.io/siie
  27986. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27987. type: string
  27988. siteId:
  27989. description: |-
  27990. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27991. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27992. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27993. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27994. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27995. type: string
  27996. required:
  27997. - apiUrl
  27998. - siteId
  27999. type: object
  28000. required:
  28001. - auth
  28002. - server
  28003. type: object
  28004. retrySettings:
  28005. description: |-
  28006. RetrySettings configures exponential backoff for failed API requests.
  28007. If not specified, uses the default retry settings.
  28008. properties:
  28009. maxRetries:
  28010. format: int32
  28011. type: integer
  28012. retryInterval:
  28013. type: string
  28014. type: object
  28015. required:
  28016. - provider
  28017. type: object
  28018. cloudsmithAccessTokenSpec:
  28019. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  28020. properties:
  28021. apiUrl:
  28022. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  28023. type: string
  28024. orgSlug:
  28025. description: OrgSlug is the organization slug in Cloudsmith
  28026. type: string
  28027. serviceAccountRef:
  28028. description: Name of the service account you are federating with
  28029. properties:
  28030. audiences:
  28031. description: |-
  28032. Audience specifies the `aud` claim for the service account token
  28033. Some providers automatically extend the audience field based on well-known annotations for workload
  28034. identity (e.g. IRSA or GCP Workload Identity)
  28035. items:
  28036. type: string
  28037. type: array
  28038. name:
  28039. description: The name of the ServiceAccount resource being referred to.
  28040. maxLength: 253
  28041. minLength: 1
  28042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28043. type: string
  28044. namespace:
  28045. description: |-
  28046. Namespace of the resource being referred to.
  28047. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28048. maxLength: 63
  28049. minLength: 1
  28050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28051. type: string
  28052. required:
  28053. - name
  28054. type: object
  28055. serviceSlug:
  28056. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  28057. type: string
  28058. required:
  28059. - orgSlug
  28060. - serviceAccountRef
  28061. - serviceSlug
  28062. type: object
  28063. ecrAuthorizationTokenSpec:
  28064. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  28065. properties:
  28066. auth:
  28067. description: Auth defines how to authenticate with AWS
  28068. properties:
  28069. jwt:
  28070. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28071. properties:
  28072. serviceAccountRef:
  28073. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28074. properties:
  28075. audiences:
  28076. description: |-
  28077. Audience specifies the `aud` claim for the service account token
  28078. Some providers automatically extend the audience field based on well-known annotations for workload
  28079. identity (e.g. IRSA or GCP Workload Identity)
  28080. items:
  28081. type: string
  28082. type: array
  28083. name:
  28084. description: The name of the ServiceAccount resource being referred to.
  28085. maxLength: 253
  28086. minLength: 1
  28087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28088. type: string
  28089. namespace:
  28090. description: |-
  28091. Namespace of the resource being referred to.
  28092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28093. maxLength: 63
  28094. minLength: 1
  28095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28096. type: string
  28097. required:
  28098. - name
  28099. type: object
  28100. type: object
  28101. secretRef:
  28102. description: |-
  28103. AWSAuthSecretRef holds secret references for AWS credentials
  28104. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28105. properties:
  28106. accessKeyIDSecretRef:
  28107. description: The AccessKeyID is used for authentication
  28108. properties:
  28109. key:
  28110. description: |-
  28111. A key in the referenced Secret.
  28112. Some instances of this field may be defaulted, in others it may be required.
  28113. maxLength: 253
  28114. minLength: 1
  28115. pattern: ^[-._a-zA-Z0-9]+$
  28116. type: string
  28117. name:
  28118. description: The name of the Secret resource being referred to.
  28119. maxLength: 253
  28120. minLength: 1
  28121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28122. type: string
  28123. namespace:
  28124. description: |-
  28125. The namespace of the Secret resource being referred to.
  28126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28127. maxLength: 63
  28128. minLength: 1
  28129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28130. type: string
  28131. type: object
  28132. secretAccessKeySecretRef:
  28133. description: The SecretAccessKey is used for authentication
  28134. properties:
  28135. key:
  28136. description: |-
  28137. A key in the referenced Secret.
  28138. Some instances of this field may be defaulted, in others it may be required.
  28139. maxLength: 253
  28140. minLength: 1
  28141. pattern: ^[-._a-zA-Z0-9]+$
  28142. type: string
  28143. name:
  28144. description: The name of the Secret resource being referred to.
  28145. maxLength: 253
  28146. minLength: 1
  28147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28148. type: string
  28149. namespace:
  28150. description: |-
  28151. The namespace of the Secret resource being referred to.
  28152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28153. maxLength: 63
  28154. minLength: 1
  28155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28156. type: string
  28157. type: object
  28158. sessionTokenSecretRef:
  28159. description: |-
  28160. The SessionToken used for authentication
  28161. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28162. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28163. properties:
  28164. key:
  28165. description: |-
  28166. A key in the referenced Secret.
  28167. Some instances of this field may be defaulted, in others it may be required.
  28168. maxLength: 253
  28169. minLength: 1
  28170. pattern: ^[-._a-zA-Z0-9]+$
  28171. type: string
  28172. name:
  28173. description: The name of the Secret resource being referred to.
  28174. maxLength: 253
  28175. minLength: 1
  28176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28177. type: string
  28178. namespace:
  28179. description: |-
  28180. The namespace of the Secret resource being referred to.
  28181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28182. maxLength: 63
  28183. minLength: 1
  28184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28185. type: string
  28186. type: object
  28187. type: object
  28188. type: object
  28189. region:
  28190. description: Region specifies the region to operate in.
  28191. type: string
  28192. role:
  28193. description: |-
  28194. You can assume a role before making calls to the
  28195. desired AWS service.
  28196. type: string
  28197. scope:
  28198. description: |-
  28199. Scope specifies the ECR service scope.
  28200. Valid options are private and public.
  28201. type: string
  28202. required:
  28203. - region
  28204. type: object
  28205. fakeSpec:
  28206. description: FakeSpec contains the static data.
  28207. properties:
  28208. controller:
  28209. description: |-
  28210. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28211. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28212. type: string
  28213. data:
  28214. additionalProperties:
  28215. type: string
  28216. description: |-
  28217. Data defines the static data returned
  28218. by this generator.
  28219. type: object
  28220. type: object
  28221. gcrAccessTokenSpec:
  28222. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  28223. properties:
  28224. auth:
  28225. description: Auth defines the means for authenticating with GCP
  28226. properties:
  28227. secretRef:
  28228. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  28229. properties:
  28230. secretAccessKeySecretRef:
  28231. description: The SecretAccessKey is used for authentication
  28232. properties:
  28233. key:
  28234. description: |-
  28235. A key in the referenced Secret.
  28236. Some instances of this field may be defaulted, in others it may be required.
  28237. maxLength: 253
  28238. minLength: 1
  28239. pattern: ^[-._a-zA-Z0-9]+$
  28240. type: string
  28241. name:
  28242. description: The name of the Secret resource being referred to.
  28243. maxLength: 253
  28244. minLength: 1
  28245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28246. type: string
  28247. namespace:
  28248. description: |-
  28249. The namespace of the Secret resource being referred to.
  28250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28251. maxLength: 63
  28252. minLength: 1
  28253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28254. type: string
  28255. type: object
  28256. type: object
  28257. workloadIdentity:
  28258. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  28259. properties:
  28260. clusterLocation:
  28261. type: string
  28262. clusterName:
  28263. type: string
  28264. clusterProjectID:
  28265. type: string
  28266. serviceAccountRef:
  28267. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28268. properties:
  28269. audiences:
  28270. description: |-
  28271. Audience specifies the `aud` claim for the service account token
  28272. Some providers automatically extend the audience field based on well-known annotations for workload
  28273. identity (e.g. IRSA or GCP Workload Identity)
  28274. items:
  28275. type: string
  28276. type: array
  28277. name:
  28278. description: The name of the ServiceAccount resource being referred to.
  28279. maxLength: 253
  28280. minLength: 1
  28281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28282. type: string
  28283. namespace:
  28284. description: |-
  28285. Namespace of the resource being referred to.
  28286. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28287. maxLength: 63
  28288. minLength: 1
  28289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28290. type: string
  28291. required:
  28292. - name
  28293. type: object
  28294. required:
  28295. - clusterLocation
  28296. - clusterName
  28297. - serviceAccountRef
  28298. type: object
  28299. workloadIdentityFederation:
  28300. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  28301. properties:
  28302. audience:
  28303. description: |-
  28304. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  28305. If specified, Audience found in the external account credential config will be overridden with the configured value.
  28306. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  28307. type: string
  28308. awsSecurityCredentials:
  28309. description: |-
  28310. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  28311. when using the AWS metadata server is not an option.
  28312. properties:
  28313. awsCredentialsSecretRef:
  28314. description: |-
  28315. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  28316. Secret should be created with below names for keys
  28317. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  28318. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  28319. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  28320. properties:
  28321. name:
  28322. description: name of the secret.
  28323. maxLength: 253
  28324. minLength: 1
  28325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28326. type: string
  28327. namespace:
  28328. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  28329. maxLength: 63
  28330. minLength: 1
  28331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28332. type: string
  28333. required:
  28334. - name
  28335. type: object
  28336. region:
  28337. description: region is for configuring the AWS region to be used.
  28338. example: ap-south-1
  28339. maxLength: 50
  28340. minLength: 1
  28341. pattern: ^[a-z0-9-]+$
  28342. type: string
  28343. required:
  28344. - awsCredentialsSecretRef
  28345. - region
  28346. type: object
  28347. credConfig:
  28348. description: |-
  28349. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  28350. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  28351. serviceAccountRef must be used by providing operators service account details.
  28352. properties:
  28353. key:
  28354. description: key name holding the external account credential config.
  28355. maxLength: 253
  28356. minLength: 1
  28357. pattern: ^[-._a-zA-Z0-9]+$
  28358. type: string
  28359. name:
  28360. description: name of the configmap.
  28361. maxLength: 253
  28362. minLength: 1
  28363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28364. type: string
  28365. namespace:
  28366. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  28367. maxLength: 63
  28368. minLength: 1
  28369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28370. type: string
  28371. required:
  28372. - key
  28373. - name
  28374. type: object
  28375. externalTokenEndpoint:
  28376. description: |-
  28377. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  28378. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  28379. URL is having the expected value.
  28380. type: string
  28381. gcpServiceAccountEmail:
  28382. description: |-
  28383. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  28384. after Workload Identity Federation. Use this to grant access through the service account's
  28385. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  28386. service_account_impersonation_url in the external account JSON from credConfig;
  28387. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  28388. on that ServiceAccount.
  28389. example: my-gsa@my-project.iam.gserviceaccount.com
  28390. minLength: 1
  28391. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  28392. type: string
  28393. serviceAccountRef:
  28394. description: |-
  28395. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  28396. when Kubernetes is configured as provider in workload identity pool.
  28397. properties:
  28398. audiences:
  28399. description: |-
  28400. Audience specifies the `aud` claim for the service account token
  28401. Some providers automatically extend the audience field based on well-known annotations for workload
  28402. identity (e.g. IRSA or GCP Workload Identity)
  28403. items:
  28404. type: string
  28405. type: array
  28406. name:
  28407. description: The name of the ServiceAccount resource being referred to.
  28408. maxLength: 253
  28409. minLength: 1
  28410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28411. type: string
  28412. namespace:
  28413. description: |-
  28414. Namespace of the resource being referred to.
  28415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28416. maxLength: 63
  28417. minLength: 1
  28418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28419. type: string
  28420. required:
  28421. - name
  28422. type: object
  28423. type: object
  28424. type: object
  28425. projectID:
  28426. description: ProjectID defines which project to use to authenticate with
  28427. type: string
  28428. required:
  28429. - auth
  28430. - projectID
  28431. type: object
  28432. githubAccessTokenSpec:
  28433. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  28434. properties:
  28435. appID:
  28436. type: string
  28437. auth:
  28438. description: Auth configures how ESO authenticates with a Github instance.
  28439. properties:
  28440. privateKey:
  28441. description: GithubSecretRef references a secret containing GitHub credentials.
  28442. properties:
  28443. secretRef:
  28444. description: |-
  28445. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28446. In some instances, `key` is a required field.
  28447. properties:
  28448. key:
  28449. description: |-
  28450. A key in the referenced Secret.
  28451. Some instances of this field may be defaulted, in others it may be required.
  28452. maxLength: 253
  28453. minLength: 1
  28454. pattern: ^[-._a-zA-Z0-9]+$
  28455. type: string
  28456. name:
  28457. description: The name of the Secret resource being referred to.
  28458. maxLength: 253
  28459. minLength: 1
  28460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28461. type: string
  28462. namespace:
  28463. description: |-
  28464. The namespace of the Secret resource being referred to.
  28465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28466. maxLength: 63
  28467. minLength: 1
  28468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28469. type: string
  28470. type: object
  28471. required:
  28472. - secretRef
  28473. type: object
  28474. required:
  28475. - privateKey
  28476. type: object
  28477. installID:
  28478. type: string
  28479. permissions:
  28480. additionalProperties:
  28481. type: string
  28482. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28483. type: object
  28484. repositories:
  28485. description: |-
  28486. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28487. is installed to.
  28488. items:
  28489. type: string
  28490. type: array
  28491. url:
  28492. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28493. type: string
  28494. required:
  28495. - appID
  28496. - auth
  28497. - installID
  28498. type: object
  28499. gitlabDeployTokenSpec:
  28500. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28501. properties:
  28502. auth:
  28503. description: Auth configures how ESO authenticates with the GitLab API.
  28504. properties:
  28505. token:
  28506. description: |-
  28507. Token references a secret containing a GitLab access token (personal, group, or
  28508. project) with the api scope and at least the Maintainer role on the target.
  28509. properties:
  28510. secretRef:
  28511. description: |-
  28512. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28513. In some instances, `key` is a required field.
  28514. properties:
  28515. key:
  28516. description: |-
  28517. A key in the referenced Secret.
  28518. Some instances of this field may be defaulted, in others it may be required.
  28519. maxLength: 253
  28520. minLength: 1
  28521. pattern: ^[-._a-zA-Z0-9]+$
  28522. type: string
  28523. name:
  28524. description: The name of the Secret resource being referred to.
  28525. maxLength: 253
  28526. minLength: 1
  28527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28528. type: string
  28529. namespace:
  28530. description: |-
  28531. The namespace of the Secret resource being referred to.
  28532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28533. maxLength: 63
  28534. minLength: 1
  28535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28536. type: string
  28537. type: object
  28538. required:
  28539. - secretRef
  28540. type: object
  28541. required:
  28542. - token
  28543. type: object
  28544. expiresAt:
  28545. description: |-
  28546. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28547. not expire on the GitLab side and is revoked only when the generator state is
  28548. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28549. format: date-time
  28550. type: string
  28551. groupID:
  28552. description: |-
  28553. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28554. create the deploy token in. The generator URL-escapes paths before calling the
  28555. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28556. minLength: 1
  28557. type: string
  28558. name:
  28559. description: Name of the deploy token.
  28560. minLength: 1
  28561. type: string
  28562. projectID:
  28563. description: |-
  28564. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28565. project to create the deploy token in. The generator URL-escapes paths before
  28566. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28567. minLength: 1
  28568. type: string
  28569. scopes:
  28570. description: Scopes granted to the deploy token. At least one scope is required.
  28571. items:
  28572. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28573. enum:
  28574. - read_repository
  28575. - read_registry
  28576. - write_registry
  28577. - read_package_registry
  28578. - write_package_registry
  28579. - read_virtual_registry
  28580. - write_virtual_registry
  28581. type: string
  28582. minItems: 1
  28583. type: array
  28584. url:
  28585. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28586. type: string
  28587. username:
  28588. description: |-
  28589. Username is an optional username for the deploy token. GitLab defaults it to
  28590. gitlab+deploy-token-{n} when omitted.
  28591. type: string
  28592. required:
  28593. - auth
  28594. - name
  28595. - scopes
  28596. type: object
  28597. x-kubernetes-validations:
  28598. - message: exactly one of projectID or groupID must be set
  28599. rule: has(self.projectID) != has(self.groupID)
  28600. grafanaSpec:
  28601. description: GrafanaSpec controls the behavior of the grafana generator.
  28602. properties:
  28603. auth:
  28604. description: |-
  28605. Auth is the authentication configuration to authenticate
  28606. against the Grafana instance.
  28607. properties:
  28608. basic:
  28609. description: |-
  28610. Basic auth credentials used to authenticate against the Grafana instance.
  28611. Note: you need a token which has elevated permissions to create service accounts.
  28612. See here for the documentation on basic roles offered by Grafana:
  28613. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28614. properties:
  28615. password:
  28616. description: A basic auth password used to authenticate against the Grafana instance.
  28617. properties:
  28618. key:
  28619. description: The key where the token is found.
  28620. maxLength: 253
  28621. minLength: 1
  28622. pattern: ^[-._a-zA-Z0-9]+$
  28623. type: string
  28624. name:
  28625. description: The name of the Secret resource being referred to.
  28626. maxLength: 253
  28627. minLength: 1
  28628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28629. type: string
  28630. type: object
  28631. username:
  28632. description: A basic auth username used to authenticate against the Grafana instance.
  28633. type: string
  28634. required:
  28635. - password
  28636. - username
  28637. type: object
  28638. token:
  28639. description: |-
  28640. A service account token used to authenticate against the Grafana instance.
  28641. Note: you need a token which has elevated permissions to create service accounts.
  28642. See here for the documentation on basic roles offered by Grafana:
  28643. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28644. properties:
  28645. key:
  28646. description: The key where the token is found.
  28647. maxLength: 253
  28648. minLength: 1
  28649. pattern: ^[-._a-zA-Z0-9]+$
  28650. type: string
  28651. name:
  28652. description: The name of the Secret resource being referred to.
  28653. maxLength: 253
  28654. minLength: 1
  28655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28656. type: string
  28657. type: object
  28658. type: object
  28659. serviceAccount:
  28660. description: |-
  28661. ServiceAccount is the configuration for the service account that
  28662. is supposed to be generated by the generator.
  28663. properties:
  28664. name:
  28665. description: Name is the name of the service account that will be created by ESO.
  28666. type: string
  28667. role:
  28668. description: |-
  28669. Role is the role of the service account.
  28670. See here for the documentation on basic roles offered by Grafana:
  28671. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28672. type: string
  28673. secondsToLive:
  28674. description: |-
  28675. SecondsToLive is the number of seconds before the generated service account token will expire.
  28676. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28677. format: int64
  28678. minimum: 1
  28679. type: integer
  28680. required:
  28681. - name
  28682. - role
  28683. type: object
  28684. url:
  28685. description: URL is the URL of the Grafana instance.
  28686. type: string
  28687. required:
  28688. - auth
  28689. - serviceAccount
  28690. - url
  28691. type: object
  28692. mfaSpec:
  28693. description: MFASpec controls the behavior of the mfa generator.
  28694. properties:
  28695. algorithm:
  28696. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28697. type: string
  28698. length:
  28699. description: Length defines the token length. Defaults to 6 characters.
  28700. type: integer
  28701. secret:
  28702. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28703. properties:
  28704. key:
  28705. description: |-
  28706. A key in the referenced Secret.
  28707. Some instances of this field may be defaulted, in others it may be required.
  28708. maxLength: 253
  28709. minLength: 1
  28710. pattern: ^[-._a-zA-Z0-9]+$
  28711. type: string
  28712. name:
  28713. description: The name of the Secret resource being referred to.
  28714. maxLength: 253
  28715. minLength: 1
  28716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28717. type: string
  28718. namespace:
  28719. description: |-
  28720. The namespace of the Secret resource being referred to.
  28721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28722. maxLength: 63
  28723. minLength: 1
  28724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28725. type: string
  28726. type: object
  28727. timePeriod:
  28728. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28729. type: integer
  28730. when:
  28731. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28732. format: date-time
  28733. type: string
  28734. required:
  28735. - secret
  28736. type: object
  28737. passwordSpec:
  28738. description: PasswordSpec controls the behavior of the password generator.
  28739. properties:
  28740. allowRepeat:
  28741. default: false
  28742. description: set AllowRepeat to true to allow repeating characters.
  28743. type: boolean
  28744. digits:
  28745. description: |-
  28746. Digits specifies the number of digits in the generated
  28747. password. If omitted it defaults to 25% of the length of the password
  28748. type: integer
  28749. encoding:
  28750. default: raw
  28751. description: |-
  28752. Encoding specifies the encoding of the generated password.
  28753. Valid values are:
  28754. - "raw" (default): no encoding
  28755. - "base64": standard base64 encoding
  28756. - "base64url": base64url encoding
  28757. - "base32": base32 encoding
  28758. - "hex": hexadecimal encoding
  28759. enum:
  28760. - base64
  28761. - base64url
  28762. - base32
  28763. - hex
  28764. - raw
  28765. type: string
  28766. length:
  28767. default: 24
  28768. description: |-
  28769. Length of the password to be generated.
  28770. Defaults to 24
  28771. type: integer
  28772. noUpper:
  28773. default: false
  28774. description: Set NoUpper to disable uppercase characters
  28775. type: boolean
  28776. secretKeys:
  28777. description: |-
  28778. SecretKeys defines the keys that will be populated with generated passwords.
  28779. Defaults to "password" when not set.
  28780. items:
  28781. type: string
  28782. minItems: 1
  28783. type: array
  28784. symbolCharacters:
  28785. description: |-
  28786. SymbolCharacters specifies the special characters that should be used
  28787. in the generated password.
  28788. type: string
  28789. symbols:
  28790. description: |-
  28791. Symbols specifies the number of symbol characters in the generated
  28792. password. If omitted it defaults to 25% of the length of the password
  28793. type: integer
  28794. required:
  28795. - allowRepeat
  28796. - length
  28797. - noUpper
  28798. type: object
  28799. quayAccessTokenSpec:
  28800. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28801. properties:
  28802. robotAccount:
  28803. description: Name of the robot account you are federating with
  28804. type: string
  28805. serviceAccountRef:
  28806. description: Name of the service account you are federating with
  28807. properties:
  28808. audiences:
  28809. description: |-
  28810. Audience specifies the `aud` claim for the service account token
  28811. Some providers automatically extend the audience field based on well-known annotations for workload
  28812. identity (e.g. IRSA or GCP Workload Identity)
  28813. items:
  28814. type: string
  28815. type: array
  28816. name:
  28817. description: The name of the ServiceAccount resource being referred to.
  28818. maxLength: 253
  28819. minLength: 1
  28820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28821. type: string
  28822. namespace:
  28823. description: |-
  28824. Namespace of the resource being referred to.
  28825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28826. maxLength: 63
  28827. minLength: 1
  28828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28829. type: string
  28830. required:
  28831. - name
  28832. type: object
  28833. url:
  28834. description: URL configures the Quay instance URL. Defaults to quay.io.
  28835. type: string
  28836. required:
  28837. - robotAccount
  28838. - serviceAccountRef
  28839. type: object
  28840. sshKeySpec:
  28841. description: SSHKeySpec controls the behavior of the ssh key generator.
  28842. properties:
  28843. comment:
  28844. description: Comment specifies an optional comment for the SSH key
  28845. type: string
  28846. keySize:
  28847. description: |-
  28848. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28849. For RSA keys: 2048, 3072, 4096
  28850. For ECDSA keys: 256, 384, 521
  28851. Ignored for ed25519 keys
  28852. maximum: 8192
  28853. minimum: 256
  28854. type: integer
  28855. keyType:
  28856. default: rsa
  28857. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28858. enum:
  28859. - rsa
  28860. - ecdsa
  28861. - ed25519
  28862. type: string
  28863. type: object
  28864. stsSessionTokenSpec:
  28865. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28866. properties:
  28867. auth:
  28868. description: Auth defines how to authenticate with AWS
  28869. properties:
  28870. jwt:
  28871. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28872. properties:
  28873. serviceAccountRef:
  28874. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28875. properties:
  28876. audiences:
  28877. description: |-
  28878. Audience specifies the `aud` claim for the service account token
  28879. Some providers automatically extend the audience field based on well-known annotations for workload
  28880. identity (e.g. IRSA or GCP Workload Identity)
  28881. items:
  28882. type: string
  28883. type: array
  28884. name:
  28885. description: The name of the ServiceAccount resource being referred to.
  28886. maxLength: 253
  28887. minLength: 1
  28888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28889. type: string
  28890. namespace:
  28891. description: |-
  28892. Namespace of the resource being referred to.
  28893. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28894. maxLength: 63
  28895. minLength: 1
  28896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28897. type: string
  28898. required:
  28899. - name
  28900. type: object
  28901. type: object
  28902. secretRef:
  28903. description: |-
  28904. AWSAuthSecretRef holds secret references for AWS credentials
  28905. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28906. properties:
  28907. accessKeyIDSecretRef:
  28908. description: The AccessKeyID is used for authentication
  28909. properties:
  28910. key:
  28911. description: |-
  28912. A key in the referenced Secret.
  28913. Some instances of this field may be defaulted, in others it may be required.
  28914. maxLength: 253
  28915. minLength: 1
  28916. pattern: ^[-._a-zA-Z0-9]+$
  28917. type: string
  28918. name:
  28919. description: The name of the Secret resource being referred to.
  28920. maxLength: 253
  28921. minLength: 1
  28922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28923. type: string
  28924. namespace:
  28925. description: |-
  28926. The namespace of the Secret resource being referred to.
  28927. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28928. maxLength: 63
  28929. minLength: 1
  28930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28931. type: string
  28932. type: object
  28933. secretAccessKeySecretRef:
  28934. description: The SecretAccessKey is used for authentication
  28935. properties:
  28936. key:
  28937. description: |-
  28938. A key in the referenced Secret.
  28939. Some instances of this field may be defaulted, in others it may be required.
  28940. maxLength: 253
  28941. minLength: 1
  28942. pattern: ^[-._a-zA-Z0-9]+$
  28943. type: string
  28944. name:
  28945. description: The name of the Secret resource being referred to.
  28946. maxLength: 253
  28947. minLength: 1
  28948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28949. type: string
  28950. namespace:
  28951. description: |-
  28952. The namespace of the Secret resource being referred to.
  28953. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28954. maxLength: 63
  28955. minLength: 1
  28956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28957. type: string
  28958. type: object
  28959. sessionTokenSecretRef:
  28960. description: |-
  28961. The SessionToken used for authentication
  28962. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28963. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28964. properties:
  28965. key:
  28966. description: |-
  28967. A key in the referenced Secret.
  28968. Some instances of this field may be defaulted, in others it may be required.
  28969. maxLength: 253
  28970. minLength: 1
  28971. pattern: ^[-._a-zA-Z0-9]+$
  28972. type: string
  28973. name:
  28974. description: The name of the Secret resource being referred to.
  28975. maxLength: 253
  28976. minLength: 1
  28977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28978. type: string
  28979. namespace:
  28980. description: |-
  28981. The namespace of the Secret resource being referred to.
  28982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28983. maxLength: 63
  28984. minLength: 1
  28985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28986. type: string
  28987. type: object
  28988. type: object
  28989. type: object
  28990. region:
  28991. description: Region specifies the region to operate in.
  28992. type: string
  28993. requestParameters:
  28994. description: RequestParameters contains parameters that can be passed to the STS service.
  28995. properties:
  28996. serialNumber:
  28997. description: |-
  28998. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28999. the GetSessionToken call.
  29000. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  29001. (such as arn:aws:iam::123456789012:mfa/user)
  29002. type: string
  29003. sessionDuration:
  29004. format: int32
  29005. type: integer
  29006. tokenCode:
  29007. description: TokenCode is the value provided by the MFA device, if MFA is required.
  29008. type: string
  29009. type: object
  29010. role:
  29011. description: |-
  29012. You can assume a role before making calls to the
  29013. desired AWS service.
  29014. type: string
  29015. required:
  29016. - region
  29017. type: object
  29018. uuidSpec:
  29019. description: UUIDSpec controls the behavior of the uuid generator.
  29020. type: object
  29021. vaultDynamicSecretSpec:
  29022. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  29023. properties:
  29024. allowEmptyResponse:
  29025. default: false
  29026. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  29027. type: boolean
  29028. controller:
  29029. description: |-
  29030. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29031. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29032. type: string
  29033. getParameters:
  29034. additionalProperties:
  29035. items:
  29036. type: string
  29037. type: array
  29038. description: |-
  29039. GetParameters are query-string parameters passed to Vault on GET calls.
  29040. Each key may map to multiple values, matching HTTP query-string semantics.
  29041. Ignored for non-GET methods; use Parameters for write bodies.
  29042. type: object
  29043. method:
  29044. description: Vault API method to use (GET/POST/other)
  29045. type: string
  29046. parameters:
  29047. description: Parameters to pass to Vault write (for non-GET methods)
  29048. x-kubernetes-preserve-unknown-fields: true
  29049. path:
  29050. description: Vault path to obtain the dynamic secret from
  29051. type: string
  29052. provider:
  29053. description: Vault provider common spec
  29054. properties:
  29055. auth:
  29056. description: Auth configures how secret-manager authenticates with the Vault server.
  29057. properties:
  29058. appRole:
  29059. description: |-
  29060. AppRole authenticates with Vault using the App Role auth mechanism,
  29061. with the role and secret stored in a Kubernetes Secret resource.
  29062. properties:
  29063. path:
  29064. default: approle
  29065. description: |-
  29066. Path where the App Role authentication backend is mounted
  29067. in Vault, e.g: "approle"
  29068. type: string
  29069. roleId:
  29070. description: |-
  29071. RoleID configured in the App Role authentication backend when setting
  29072. up the authentication backend in Vault.
  29073. type: string
  29074. roleRef:
  29075. description: |-
  29076. Reference to a key in a Secret that contains the App Role ID used
  29077. to authenticate with Vault.
  29078. The `key` field must be specified and denotes which entry within the Secret
  29079. resource is used as the app role id.
  29080. properties:
  29081. key:
  29082. description: |-
  29083. A key in the referenced Secret.
  29084. Some instances of this field may be defaulted, in others it may be required.
  29085. maxLength: 253
  29086. minLength: 1
  29087. pattern: ^[-._a-zA-Z0-9]+$
  29088. type: string
  29089. name:
  29090. description: The name of the Secret resource being referred to.
  29091. maxLength: 253
  29092. minLength: 1
  29093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29094. type: string
  29095. namespace:
  29096. description: |-
  29097. The namespace of the Secret resource being referred to.
  29098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29099. maxLength: 63
  29100. minLength: 1
  29101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29102. type: string
  29103. type: object
  29104. secretRef:
  29105. description: |-
  29106. Reference to a key in a Secret that contains the App Role secret used
  29107. to authenticate with Vault.
  29108. The `key` field must be specified and denotes which entry within the Secret
  29109. resource is used as the app role secret.
  29110. properties:
  29111. key:
  29112. description: |-
  29113. A key in the referenced Secret.
  29114. Some instances of this field may be defaulted, in others it may be required.
  29115. maxLength: 253
  29116. minLength: 1
  29117. pattern: ^[-._a-zA-Z0-9]+$
  29118. type: string
  29119. name:
  29120. description: The name of the Secret resource being referred to.
  29121. maxLength: 253
  29122. minLength: 1
  29123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29124. type: string
  29125. namespace:
  29126. description: |-
  29127. The namespace of the Secret resource being referred to.
  29128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29129. maxLength: 63
  29130. minLength: 1
  29131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29132. type: string
  29133. type: object
  29134. required:
  29135. - path
  29136. - secretRef
  29137. type: object
  29138. cert:
  29139. description: |-
  29140. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  29141. Cert authentication method
  29142. properties:
  29143. clientCert:
  29144. description: |-
  29145. ClientCert is a certificate to authenticate using the Cert Vault
  29146. authentication method
  29147. properties:
  29148. key:
  29149. description: |-
  29150. A key in the referenced Secret.
  29151. Some instances of this field may be defaulted, in others it may be required.
  29152. maxLength: 253
  29153. minLength: 1
  29154. pattern: ^[-._a-zA-Z0-9]+$
  29155. type: string
  29156. name:
  29157. description: The name of the Secret resource being referred to.
  29158. maxLength: 253
  29159. minLength: 1
  29160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29161. type: string
  29162. namespace:
  29163. description: |-
  29164. The namespace of the Secret resource being referred to.
  29165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29166. maxLength: 63
  29167. minLength: 1
  29168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29169. type: string
  29170. type: object
  29171. path:
  29172. default: cert
  29173. description: |-
  29174. Path where the Certificate authentication backend is mounted
  29175. in Vault, e.g: "cert"
  29176. type: string
  29177. secretRef:
  29178. description: |-
  29179. SecretRef to a key in a Secret resource containing client private key to
  29180. authenticate with Vault using the Cert authentication method
  29181. properties:
  29182. key:
  29183. description: |-
  29184. A key in the referenced Secret.
  29185. Some instances of this field may be defaulted, in others it may be required.
  29186. maxLength: 253
  29187. minLength: 1
  29188. pattern: ^[-._a-zA-Z0-9]+$
  29189. type: string
  29190. name:
  29191. description: The name of the Secret resource being referred to.
  29192. maxLength: 253
  29193. minLength: 1
  29194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29195. type: string
  29196. namespace:
  29197. description: |-
  29198. The namespace of the Secret resource being referred to.
  29199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29200. maxLength: 63
  29201. minLength: 1
  29202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29203. type: string
  29204. type: object
  29205. vaultRole:
  29206. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  29207. type: string
  29208. type: object
  29209. gcp:
  29210. description: |-
  29211. Gcp authenticates with Vault using Google Cloud Platform authentication method
  29212. GCP authentication method
  29213. properties:
  29214. location:
  29215. description: Location optionally defines a location/region for the secret
  29216. type: string
  29217. path:
  29218. default: gcp
  29219. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  29220. type: string
  29221. projectID:
  29222. description: Project ID of the Google Cloud Platform project
  29223. type: string
  29224. role:
  29225. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  29226. type: string
  29227. secretRef:
  29228. description: Specify credentials in a Secret object
  29229. properties:
  29230. secretAccessKeySecretRef:
  29231. description: The SecretAccessKey is used for authentication
  29232. properties:
  29233. key:
  29234. description: |-
  29235. A key in the referenced Secret.
  29236. Some instances of this field may be defaulted, in others it may be required.
  29237. maxLength: 253
  29238. minLength: 1
  29239. pattern: ^[-._a-zA-Z0-9]+$
  29240. type: string
  29241. name:
  29242. description: The name of the Secret resource being referred to.
  29243. maxLength: 253
  29244. minLength: 1
  29245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29246. type: string
  29247. namespace:
  29248. description: |-
  29249. The namespace of the Secret resource being referred to.
  29250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29251. maxLength: 63
  29252. minLength: 1
  29253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29254. type: string
  29255. type: object
  29256. type: object
  29257. serviceAccountRef:
  29258. description: ServiceAccountRef to a service account for impersonation
  29259. properties:
  29260. audiences:
  29261. description: |-
  29262. Audience specifies the `aud` claim for the service account token
  29263. Some providers automatically extend the audience field based on well-known annotations for workload
  29264. identity (e.g. IRSA or GCP Workload Identity)
  29265. items:
  29266. type: string
  29267. type: array
  29268. name:
  29269. description: The name of the ServiceAccount resource being referred to.
  29270. maxLength: 253
  29271. minLength: 1
  29272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29273. type: string
  29274. namespace:
  29275. description: |-
  29276. Namespace of the resource being referred to.
  29277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29278. maxLength: 63
  29279. minLength: 1
  29280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29281. type: string
  29282. required:
  29283. - name
  29284. type: object
  29285. workloadIdentity:
  29286. description: Specify a service account with Workload Identity
  29287. properties:
  29288. clusterLocation:
  29289. description: |-
  29290. ClusterLocation is the location of the cluster
  29291. If not specified, it fetches information from the metadata server
  29292. type: string
  29293. clusterName:
  29294. description: |-
  29295. ClusterName is the name of the cluster
  29296. If not specified, it fetches information from the metadata server
  29297. type: string
  29298. clusterProjectID:
  29299. description: |-
  29300. ClusterProjectID is the project ID of the cluster
  29301. If not specified, it fetches information from the metadata server
  29302. type: string
  29303. serviceAccountRef:
  29304. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29305. properties:
  29306. audiences:
  29307. description: |-
  29308. Audience specifies the `aud` claim for the service account token
  29309. Some providers automatically extend the audience field based on well-known annotations for workload
  29310. identity (e.g. IRSA or GCP Workload Identity)
  29311. items:
  29312. type: string
  29313. type: array
  29314. name:
  29315. description: The name of the ServiceAccount resource being referred to.
  29316. maxLength: 253
  29317. minLength: 1
  29318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29319. type: string
  29320. namespace:
  29321. description: |-
  29322. Namespace of the resource being referred to.
  29323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29324. maxLength: 63
  29325. minLength: 1
  29326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29327. type: string
  29328. required:
  29329. - name
  29330. type: object
  29331. required:
  29332. - serviceAccountRef
  29333. type: object
  29334. required:
  29335. - role
  29336. type: object
  29337. iam:
  29338. description: |-
  29339. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  29340. AWS IAM authentication method
  29341. properties:
  29342. externalID:
  29343. description: AWS External ID set on assumed IAM roles
  29344. type: string
  29345. jwt:
  29346. description: Specify a service account with IRSA enabled
  29347. properties:
  29348. serviceAccountRef:
  29349. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29350. properties:
  29351. audiences:
  29352. description: |-
  29353. Audience specifies the `aud` claim for the service account token
  29354. Some providers automatically extend the audience field based on well-known annotations for workload
  29355. identity (e.g. IRSA or GCP Workload Identity)
  29356. items:
  29357. type: string
  29358. type: array
  29359. name:
  29360. description: The name of the ServiceAccount resource being referred to.
  29361. maxLength: 253
  29362. minLength: 1
  29363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29364. type: string
  29365. namespace:
  29366. description: |-
  29367. Namespace of the resource being referred to.
  29368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29369. maxLength: 63
  29370. minLength: 1
  29371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29372. type: string
  29373. required:
  29374. - name
  29375. type: object
  29376. type: object
  29377. path:
  29378. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  29379. type: string
  29380. region:
  29381. description: AWS region
  29382. type: string
  29383. role:
  29384. description: This is the AWS role to be assumed before talking to vault
  29385. type: string
  29386. secretRef:
  29387. description: Specify credentials in a Secret object
  29388. properties:
  29389. accessKeyIDSecretRef:
  29390. description: The AccessKeyID is used for authentication
  29391. properties:
  29392. key:
  29393. description: |-
  29394. A key in the referenced Secret.
  29395. Some instances of this field may be defaulted, in others it may be required.
  29396. maxLength: 253
  29397. minLength: 1
  29398. pattern: ^[-._a-zA-Z0-9]+$
  29399. type: string
  29400. name:
  29401. description: The name of the Secret resource being referred to.
  29402. maxLength: 253
  29403. minLength: 1
  29404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29405. type: string
  29406. namespace:
  29407. description: |-
  29408. The namespace of the Secret resource being referred to.
  29409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29410. maxLength: 63
  29411. minLength: 1
  29412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29413. type: string
  29414. type: object
  29415. secretAccessKeySecretRef:
  29416. description: The SecretAccessKey is used for authentication
  29417. properties:
  29418. key:
  29419. description: |-
  29420. A key in the referenced Secret.
  29421. Some instances of this field may be defaulted, in others it may be required.
  29422. maxLength: 253
  29423. minLength: 1
  29424. pattern: ^[-._a-zA-Z0-9]+$
  29425. type: string
  29426. name:
  29427. description: The name of the Secret resource being referred to.
  29428. maxLength: 253
  29429. minLength: 1
  29430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29431. type: string
  29432. namespace:
  29433. description: |-
  29434. The namespace of the Secret resource being referred to.
  29435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29436. maxLength: 63
  29437. minLength: 1
  29438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29439. type: string
  29440. type: object
  29441. sessionTokenSecretRef:
  29442. description: |-
  29443. The SessionToken used for authentication
  29444. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29445. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29446. properties:
  29447. key:
  29448. description: |-
  29449. A key in the referenced Secret.
  29450. Some instances of this field may be defaulted, in others it may be required.
  29451. maxLength: 253
  29452. minLength: 1
  29453. pattern: ^[-._a-zA-Z0-9]+$
  29454. type: string
  29455. name:
  29456. description: The name of the Secret resource being referred to.
  29457. maxLength: 253
  29458. minLength: 1
  29459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29460. type: string
  29461. namespace:
  29462. description: |-
  29463. The namespace of the Secret resource being referred to.
  29464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29465. maxLength: 63
  29466. minLength: 1
  29467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29468. type: string
  29469. type: object
  29470. type: object
  29471. vaultAwsIamServerID:
  29472. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  29473. type: string
  29474. vaultRole:
  29475. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  29476. type: string
  29477. required:
  29478. - vaultRole
  29479. type: object
  29480. jwt:
  29481. description: |-
  29482. Jwt authenticates with Vault by passing role and JWT token using the
  29483. JWT/OIDC authentication method
  29484. properties:
  29485. kubernetesServiceAccountToken:
  29486. description: |-
  29487. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29488. a token for with the `TokenRequest` API.
  29489. properties:
  29490. audiences:
  29491. description: |-
  29492. Optional audiences field that will be used to request a temporary Kubernetes service
  29493. account token for the service account referenced by `serviceAccountRef`.
  29494. Defaults to a single audience `vault` it not specified.
  29495. Deprecated: use serviceAccountRef.Audiences instead
  29496. items:
  29497. type: string
  29498. type: array
  29499. expirationSeconds:
  29500. description: |-
  29501. Optional expiration time in seconds that will be used to request a temporary
  29502. Kubernetes service account token for the service account referenced by
  29503. `serviceAccountRef`.
  29504. Deprecated: this will be removed in the future.
  29505. Defaults to 10 minutes.
  29506. format: int64
  29507. type: integer
  29508. serviceAccountRef:
  29509. description: Service account field containing the name of a kubernetes ServiceAccount.
  29510. properties:
  29511. audiences:
  29512. description: |-
  29513. Audience specifies the `aud` claim for the service account token
  29514. Some providers automatically extend the audience field based on well-known annotations for workload
  29515. identity (e.g. IRSA or GCP Workload Identity)
  29516. items:
  29517. type: string
  29518. type: array
  29519. name:
  29520. description: The name of the ServiceAccount resource being referred to.
  29521. maxLength: 253
  29522. minLength: 1
  29523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29524. type: string
  29525. namespace:
  29526. description: |-
  29527. Namespace of the resource being referred to.
  29528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29529. maxLength: 63
  29530. minLength: 1
  29531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29532. type: string
  29533. required:
  29534. - name
  29535. type: object
  29536. required:
  29537. - serviceAccountRef
  29538. type: object
  29539. path:
  29540. default: jwt
  29541. description: |-
  29542. Path where the JWT authentication backend is mounted
  29543. in Vault, e.g: "jwt"
  29544. type: string
  29545. role:
  29546. description: |-
  29547. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29548. authentication method
  29549. type: string
  29550. secretRef:
  29551. description: |-
  29552. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29553. authenticate with Vault using the JWT/OIDC authentication method.
  29554. properties:
  29555. key:
  29556. description: |-
  29557. A key in the referenced Secret.
  29558. Some instances of this field may be defaulted, in others it may be required.
  29559. maxLength: 253
  29560. minLength: 1
  29561. pattern: ^[-._a-zA-Z0-9]+$
  29562. type: string
  29563. name:
  29564. description: The name of the Secret resource being referred to.
  29565. maxLength: 253
  29566. minLength: 1
  29567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29568. type: string
  29569. namespace:
  29570. description: |-
  29571. The namespace of the Secret resource being referred to.
  29572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29573. maxLength: 63
  29574. minLength: 1
  29575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29576. type: string
  29577. type: object
  29578. required:
  29579. - path
  29580. type: object
  29581. kubernetes:
  29582. description: |-
  29583. Kubernetes authenticates with Vault by passing the ServiceAccount
  29584. token stored in the named Secret resource to the Vault server.
  29585. properties:
  29586. mountPath:
  29587. default: kubernetes
  29588. description: |-
  29589. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29590. "kubernetes"
  29591. type: string
  29592. role:
  29593. description: |-
  29594. A required field containing the Vault Role to assume. A Role binds a
  29595. Kubernetes ServiceAccount with a set of Vault policies.
  29596. type: string
  29597. secretRef:
  29598. description: |-
  29599. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29600. for authenticating with Vault. If a name is specified without a key,
  29601. `token` is the default. If one is not specified, the one bound to
  29602. the controller will be used.
  29603. properties:
  29604. key:
  29605. description: |-
  29606. A key in the referenced Secret.
  29607. Some instances of this field may be defaulted, in others it may be required.
  29608. maxLength: 253
  29609. minLength: 1
  29610. pattern: ^[-._a-zA-Z0-9]+$
  29611. type: string
  29612. name:
  29613. description: The name of the Secret resource being referred to.
  29614. maxLength: 253
  29615. minLength: 1
  29616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29617. type: string
  29618. namespace:
  29619. description: |-
  29620. The namespace of the Secret resource being referred to.
  29621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29622. maxLength: 63
  29623. minLength: 1
  29624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29625. type: string
  29626. type: object
  29627. serviceAccountRef:
  29628. description: |-
  29629. Optional service account field containing the name of a kubernetes ServiceAccount.
  29630. If the service account is specified, the service account secret token JWT will be used
  29631. for authenticating with Vault. If the service account selector is not supplied,
  29632. the secretRef will be used instead.
  29633. properties:
  29634. audiences:
  29635. description: |-
  29636. Audience specifies the `aud` claim for the service account token
  29637. Some providers automatically extend the audience field based on well-known annotations for workload
  29638. identity (e.g. IRSA or GCP Workload Identity)
  29639. items:
  29640. type: string
  29641. type: array
  29642. name:
  29643. description: The name of the ServiceAccount resource being referred to.
  29644. maxLength: 253
  29645. minLength: 1
  29646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29647. type: string
  29648. namespace:
  29649. description: |-
  29650. Namespace of the resource being referred to.
  29651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29652. maxLength: 63
  29653. minLength: 1
  29654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29655. type: string
  29656. required:
  29657. - name
  29658. type: object
  29659. required:
  29660. - mountPath
  29661. - role
  29662. type: object
  29663. ldap:
  29664. description: |-
  29665. Ldap authenticates with Vault by passing username/password pair using
  29666. the LDAP authentication method
  29667. properties:
  29668. path:
  29669. default: ldap
  29670. description: |-
  29671. Path where the LDAP authentication backend is mounted
  29672. in Vault, e.g: "ldap"
  29673. type: string
  29674. secretRef:
  29675. description: |-
  29676. SecretRef to a key in a Secret resource containing password for the LDAP
  29677. user used to authenticate with Vault using the LDAP authentication
  29678. method
  29679. properties:
  29680. key:
  29681. description: |-
  29682. A key in the referenced Secret.
  29683. Some instances of this field may be defaulted, in others it may be required.
  29684. maxLength: 253
  29685. minLength: 1
  29686. pattern: ^[-._a-zA-Z0-9]+$
  29687. type: string
  29688. name:
  29689. description: The name of the Secret resource being referred to.
  29690. maxLength: 253
  29691. minLength: 1
  29692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29693. type: string
  29694. namespace:
  29695. description: |-
  29696. The namespace of the Secret resource being referred to.
  29697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29698. maxLength: 63
  29699. minLength: 1
  29700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29701. type: string
  29702. type: object
  29703. username:
  29704. description: |-
  29705. Username is an LDAP username used to authenticate using the LDAP Vault
  29706. authentication method
  29707. type: string
  29708. required:
  29709. - path
  29710. - username
  29711. type: object
  29712. namespace:
  29713. description: |-
  29714. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29715. Namespaces is a set of features within Vault Enterprise that allows
  29716. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29717. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29718. This will default to Vault.Namespace field if set, or empty otherwise
  29719. type: string
  29720. tokenSecretRef:
  29721. description: TokenSecretRef authenticates with Vault by presenting a token.
  29722. properties:
  29723. key:
  29724. description: |-
  29725. A key in the referenced Secret.
  29726. Some instances of this field may be defaulted, in others it may be required.
  29727. maxLength: 253
  29728. minLength: 1
  29729. pattern: ^[-._a-zA-Z0-9]+$
  29730. type: string
  29731. name:
  29732. description: The name of the Secret resource being referred to.
  29733. maxLength: 253
  29734. minLength: 1
  29735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29736. type: string
  29737. namespace:
  29738. description: |-
  29739. The namespace of the Secret resource being referred to.
  29740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29741. maxLength: 63
  29742. minLength: 1
  29743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29744. type: string
  29745. type: object
  29746. userPass:
  29747. description: UserPass authenticates with Vault by passing username/password pair
  29748. properties:
  29749. path:
  29750. default: userpass
  29751. description: |-
  29752. Path where the UserPassword authentication backend is mounted
  29753. in Vault, e.g: "userpass"
  29754. type: string
  29755. secretRef:
  29756. description: |-
  29757. SecretRef to a key in a Secret resource containing password for the
  29758. user used to authenticate with Vault using the UserPass authentication
  29759. method
  29760. properties:
  29761. key:
  29762. description: |-
  29763. A key in the referenced Secret.
  29764. Some instances of this field may be defaulted, in others it may be required.
  29765. maxLength: 253
  29766. minLength: 1
  29767. pattern: ^[-._a-zA-Z0-9]+$
  29768. type: string
  29769. name:
  29770. description: The name of the Secret resource being referred to.
  29771. maxLength: 253
  29772. minLength: 1
  29773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29774. type: string
  29775. namespace:
  29776. description: |-
  29777. The namespace of the Secret resource being referred to.
  29778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29779. maxLength: 63
  29780. minLength: 1
  29781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29782. type: string
  29783. type: object
  29784. username:
  29785. description: |-
  29786. Username is a username used to authenticate using the UserPass Vault
  29787. authentication method
  29788. type: string
  29789. required:
  29790. - path
  29791. - username
  29792. type: object
  29793. type: object
  29794. caBundle:
  29795. description: |-
  29796. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29797. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29798. plain HTTP protocol connection. If not set the system root certificates
  29799. are used to validate the TLS connection.
  29800. format: byte
  29801. type: string
  29802. caProvider:
  29803. description: The provider for the CA bundle to use to validate Vault server certificate.
  29804. properties:
  29805. key:
  29806. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29807. maxLength: 253
  29808. minLength: 1
  29809. pattern: ^[-._a-zA-Z0-9]+$
  29810. type: string
  29811. name:
  29812. description: The name of the object located at the provider type.
  29813. maxLength: 253
  29814. minLength: 1
  29815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29816. type: string
  29817. namespace:
  29818. description: |-
  29819. The namespace the Provider type is in.
  29820. Can only be defined when used in a ClusterSecretStore.
  29821. maxLength: 63
  29822. minLength: 1
  29823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29824. type: string
  29825. type:
  29826. description: The type of provider to use such as "Secret", or "ConfigMap".
  29827. enum:
  29828. - Secret
  29829. - ConfigMap
  29830. type: string
  29831. required:
  29832. - name
  29833. - type
  29834. type: object
  29835. checkAndSet:
  29836. description: |-
  29837. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29838. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29839. the current version of the secret to prevent unintentional overwrites.
  29840. properties:
  29841. required:
  29842. description: |-
  29843. Required when true, all write operations must include a check-and-set parameter.
  29844. This helps prevent unintentional overwrites of secrets.
  29845. type: boolean
  29846. type: object
  29847. forwardInconsistent:
  29848. description: |-
  29849. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29850. leader instead of simply retrying within a loop. This can increase performance if
  29851. the option is enabled serverside.
  29852. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29853. type: boolean
  29854. headers:
  29855. additionalProperties:
  29856. type: string
  29857. description: Headers to be added in Vault request
  29858. type: object
  29859. namespace:
  29860. description: |-
  29861. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29862. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29863. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29864. type: string
  29865. path:
  29866. description: |-
  29867. Path is the mount path of the Vault KV backend endpoint, e.g:
  29868. "secret". The v2 KV secret engine version specific "/data" path suffix
  29869. for fetching secrets from Vault is optional and will be appended
  29870. if not present in specified path.
  29871. type: string
  29872. readYourWrites:
  29873. description: |-
  29874. ReadYourWrites ensures isolated read-after-write semantics by
  29875. providing discovered cluster replication states in each request.
  29876. More information about eventual consistency in Vault can be found here
  29877. https://www.vaultproject.io/docs/enterprise/consistency
  29878. type: boolean
  29879. server:
  29880. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29881. type: string
  29882. tls:
  29883. description: |-
  29884. The configuration used for client side related TLS communication, when the Vault server
  29885. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29886. This parameter is ignored for plain HTTP protocol connection.
  29887. It's worth noting this configuration is different from the "TLS certificates auth method",
  29888. which is available under the `auth.cert` section.
  29889. properties:
  29890. certSecretRef:
  29891. description: |-
  29892. CertSecretRef is a certificate added to the transport layer
  29893. when communicating with the Vault server.
  29894. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29895. properties:
  29896. key:
  29897. description: |-
  29898. A key in the referenced Secret.
  29899. Some instances of this field may be defaulted, in others it may be required.
  29900. maxLength: 253
  29901. minLength: 1
  29902. pattern: ^[-._a-zA-Z0-9]+$
  29903. type: string
  29904. name:
  29905. description: The name of the Secret resource being referred to.
  29906. maxLength: 253
  29907. minLength: 1
  29908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29909. type: string
  29910. namespace:
  29911. description: |-
  29912. The namespace of the Secret resource being referred to.
  29913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29914. maxLength: 63
  29915. minLength: 1
  29916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29917. type: string
  29918. type: object
  29919. keySecretRef:
  29920. description: |-
  29921. KeySecretRef to a key in a Secret resource containing client private key
  29922. added to the transport layer when communicating with the Vault server.
  29923. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29924. properties:
  29925. key:
  29926. description: |-
  29927. A key in the referenced Secret.
  29928. Some instances of this field may be defaulted, in others it may be required.
  29929. maxLength: 253
  29930. minLength: 1
  29931. pattern: ^[-._a-zA-Z0-9]+$
  29932. type: string
  29933. name:
  29934. description: The name of the Secret resource being referred to.
  29935. maxLength: 253
  29936. minLength: 1
  29937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29938. type: string
  29939. namespace:
  29940. description: |-
  29941. The namespace of the Secret resource being referred to.
  29942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29943. maxLength: 63
  29944. minLength: 1
  29945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29946. type: string
  29947. type: object
  29948. type: object
  29949. version:
  29950. default: v2
  29951. description: |-
  29952. Version is the Vault KV secret engine version. This can be either "v1" or
  29953. "v2". Version defaults to "v2".
  29954. enum:
  29955. - v1
  29956. - v2
  29957. type: string
  29958. required:
  29959. - server
  29960. type: object
  29961. resultType:
  29962. default: Data
  29963. description: |-
  29964. Result type defines which data is returned from the generator.
  29965. By default, it is the "data" section of the Vault API response.
  29966. When using e.g. /auth/token/create the "data" section is empty but
  29967. the "auth" section contains the generated token.
  29968. Please refer to the vault docs regarding the result data structure.
  29969. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29970. enum:
  29971. - Data
  29972. - Auth
  29973. - Raw
  29974. type: string
  29975. retrySettings:
  29976. description: Used to configure http retries if failed
  29977. properties:
  29978. maxRetries:
  29979. format: int32
  29980. type: integer
  29981. retryInterval:
  29982. type: string
  29983. type: object
  29984. required:
  29985. - path
  29986. - provider
  29987. type: object
  29988. webhookSpec:
  29989. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29990. properties:
  29991. auth:
  29992. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29993. maxProperties: 1
  29994. minProperties: 1
  29995. properties:
  29996. ntlm:
  29997. description: NTLMProtocol configures the store to use NTLM for auth
  29998. properties:
  29999. passwordSecret:
  30000. description: |-
  30001. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30002. In some instances, `key` is a required field.
  30003. properties:
  30004. key:
  30005. description: |-
  30006. A key in the referenced Secret.
  30007. Some instances of this field may be defaulted, in others it may be required.
  30008. maxLength: 253
  30009. minLength: 1
  30010. pattern: ^[-._a-zA-Z0-9]+$
  30011. type: string
  30012. name:
  30013. description: The name of the Secret resource being referred to.
  30014. maxLength: 253
  30015. minLength: 1
  30016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30017. type: string
  30018. namespace:
  30019. description: |-
  30020. The namespace of the Secret resource being referred to.
  30021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30022. maxLength: 63
  30023. minLength: 1
  30024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30025. type: string
  30026. type: object
  30027. usernameSecret:
  30028. description: |-
  30029. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30030. In some instances, `key` is a required field.
  30031. properties:
  30032. key:
  30033. description: |-
  30034. A key in the referenced Secret.
  30035. Some instances of this field may be defaulted, in others it may be required.
  30036. maxLength: 253
  30037. minLength: 1
  30038. pattern: ^[-._a-zA-Z0-9]+$
  30039. type: string
  30040. name:
  30041. description: The name of the Secret resource being referred to.
  30042. maxLength: 253
  30043. minLength: 1
  30044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30045. type: string
  30046. namespace:
  30047. description: |-
  30048. The namespace of the Secret resource being referred to.
  30049. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30050. maxLength: 63
  30051. minLength: 1
  30052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30053. type: string
  30054. type: object
  30055. required:
  30056. - passwordSecret
  30057. - usernameSecret
  30058. type: object
  30059. type: object
  30060. body:
  30061. description: Body
  30062. type: string
  30063. caBundle:
  30064. description: |-
  30065. PEM encoded CA bundle used to validate webhook server certificate. Only used
  30066. if the Server URL is using HTTPS protocol. This parameter is ignored for
  30067. plain HTTP protocol connection. If not set the system root certificates
  30068. are used to validate the TLS connection.
  30069. format: byte
  30070. type: string
  30071. caProvider:
  30072. description: The provider for the CA bundle to use to validate webhook server certificate.
  30073. properties:
  30074. key:
  30075. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  30076. maxLength: 253
  30077. minLength: 1
  30078. pattern: ^[-._a-zA-Z0-9]+$
  30079. type: string
  30080. name:
  30081. description: The name of the object located at the provider type.
  30082. maxLength: 253
  30083. minLength: 1
  30084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30085. type: string
  30086. namespace:
  30087. description: The namespace the Provider type is in.
  30088. maxLength: 63
  30089. minLength: 1
  30090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30091. type: string
  30092. type:
  30093. description: The type of provider to use such as "Secret", or "ConfigMap".
  30094. enum:
  30095. - Secret
  30096. - ConfigMap
  30097. type: string
  30098. required:
  30099. - name
  30100. - type
  30101. type: object
  30102. headers:
  30103. additionalProperties:
  30104. type: string
  30105. description: Headers
  30106. type: object
  30107. method:
  30108. description: Webhook Method
  30109. type: string
  30110. result:
  30111. description: Result formatting
  30112. properties:
  30113. jsonPath:
  30114. description: Json path of return value
  30115. type: string
  30116. type: object
  30117. secrets:
  30118. description: |-
  30119. Secrets to fill in templates
  30120. These secrets will be passed to the templating function as key value pairs under the given name
  30121. items:
  30122. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  30123. properties:
  30124. name:
  30125. description: Name of this secret in templates
  30126. type: string
  30127. secretRef:
  30128. description: Secret ref to fill in credentials
  30129. properties:
  30130. key:
  30131. description: The key where the token is found.
  30132. maxLength: 253
  30133. minLength: 1
  30134. pattern: ^[-._a-zA-Z0-9]+$
  30135. type: string
  30136. name:
  30137. description: The name of the Secret resource being referred to.
  30138. maxLength: 253
  30139. minLength: 1
  30140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30141. type: string
  30142. type: object
  30143. required:
  30144. - name
  30145. - secretRef
  30146. type: object
  30147. type: array
  30148. timeout:
  30149. description: Timeout
  30150. type: string
  30151. url:
  30152. description: Webhook url to call
  30153. type: string
  30154. required:
  30155. - result
  30156. - url
  30157. type: object
  30158. type: object
  30159. kind:
  30160. description: Kind the kind of this generator.
  30161. enum:
  30162. - ACRAccessToken
  30163. - BeyondtrustWorkloadCredentialsDynamicSecret
  30164. - CloudsmithAccessToken
  30165. - ECRAuthorizationToken
  30166. - Fake
  30167. - GCRAccessToken
  30168. - GithubAccessToken
  30169. - GitlabDeployToken
  30170. - QuayAccessToken
  30171. - Password
  30172. - SSHKey
  30173. - STSSessionToken
  30174. - UUID
  30175. - VaultDynamicSecret
  30176. - Webhook
  30177. - Grafana
  30178. - MFA
  30179. type: string
  30180. required:
  30181. - generator
  30182. - kind
  30183. type: object
  30184. type: object
  30185. served: true
  30186. storage: true
  30187. subresources:
  30188. status: {}
  30189. ---
  30190. apiVersion: apiextensions.k8s.io/v1
  30191. kind: CustomResourceDefinition
  30192. metadata:
  30193. annotations:
  30194. controller-gen.kubebuilder.io/version: v0.19.0
  30195. labels:
  30196. external-secrets.io/component: controller
  30197. name: ecrauthorizationtokens.generators.external-secrets.io
  30198. spec:
  30199. group: generators.external-secrets.io
  30200. names:
  30201. categories:
  30202. - external-secrets
  30203. - external-secrets-generators
  30204. kind: ECRAuthorizationToken
  30205. listKind: ECRAuthorizationTokenList
  30206. plural: ecrauthorizationtokens
  30207. singular: ecrauthorizationtoken
  30208. scope: Namespaced
  30209. versions:
  30210. - name: v1alpha1
  30211. schema:
  30212. openAPIV3Schema:
  30213. description: |-
  30214. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  30215. The authorization token is valid for 12 hours.
  30216. The authorizationToken returned is a base64 encoded string that can be decoded
  30217. and used in a docker login command to authenticate to a registry.
  30218. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  30219. properties:
  30220. apiVersion:
  30221. description: |-
  30222. APIVersion defines the versioned schema of this representation of an object.
  30223. Servers should convert recognized schemas to the latest internal value, and
  30224. may reject unrecognized values.
  30225. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30226. type: string
  30227. kind:
  30228. description: |-
  30229. Kind is a string value representing the REST resource this object represents.
  30230. Servers may infer this from the endpoint the client submits requests to.
  30231. Cannot be updated.
  30232. In CamelCase.
  30233. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30234. type: string
  30235. metadata:
  30236. type: object
  30237. spec:
  30238. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  30239. properties:
  30240. auth:
  30241. description: Auth defines how to authenticate with AWS
  30242. properties:
  30243. jwt:
  30244. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30245. properties:
  30246. serviceAccountRef:
  30247. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30248. properties:
  30249. audiences:
  30250. description: |-
  30251. Audience specifies the `aud` claim for the service account token
  30252. Some providers automatically extend the audience field based on well-known annotations for workload
  30253. identity (e.g. IRSA or GCP Workload Identity)
  30254. items:
  30255. type: string
  30256. type: array
  30257. name:
  30258. description: The name of the ServiceAccount resource being referred to.
  30259. maxLength: 253
  30260. minLength: 1
  30261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30262. type: string
  30263. namespace:
  30264. description: |-
  30265. Namespace of the resource being referred to.
  30266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30267. maxLength: 63
  30268. minLength: 1
  30269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30270. type: string
  30271. required:
  30272. - name
  30273. type: object
  30274. type: object
  30275. secretRef:
  30276. description: |-
  30277. AWSAuthSecretRef holds secret references for AWS credentials
  30278. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30279. properties:
  30280. accessKeyIDSecretRef:
  30281. description: The AccessKeyID is used for authentication
  30282. properties:
  30283. key:
  30284. description: |-
  30285. A key in the referenced Secret.
  30286. Some instances of this field may be defaulted, in others it may be required.
  30287. maxLength: 253
  30288. minLength: 1
  30289. pattern: ^[-._a-zA-Z0-9]+$
  30290. type: string
  30291. name:
  30292. description: The name of the Secret resource being referred to.
  30293. maxLength: 253
  30294. minLength: 1
  30295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30296. type: string
  30297. namespace:
  30298. description: |-
  30299. The namespace of the Secret resource being referred to.
  30300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30301. maxLength: 63
  30302. minLength: 1
  30303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30304. type: string
  30305. type: object
  30306. secretAccessKeySecretRef:
  30307. description: The SecretAccessKey is used for authentication
  30308. properties:
  30309. key:
  30310. description: |-
  30311. A key in the referenced Secret.
  30312. Some instances of this field may be defaulted, in others it may be required.
  30313. maxLength: 253
  30314. minLength: 1
  30315. pattern: ^[-._a-zA-Z0-9]+$
  30316. type: string
  30317. name:
  30318. description: The name of the Secret resource being referred to.
  30319. maxLength: 253
  30320. minLength: 1
  30321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30322. type: string
  30323. namespace:
  30324. description: |-
  30325. The namespace of the Secret resource being referred to.
  30326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30327. maxLength: 63
  30328. minLength: 1
  30329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30330. type: string
  30331. type: object
  30332. sessionTokenSecretRef:
  30333. description: |-
  30334. The SessionToken used for authentication
  30335. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30336. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30337. properties:
  30338. key:
  30339. description: |-
  30340. A key in the referenced Secret.
  30341. Some instances of this field may be defaulted, in others it may be required.
  30342. maxLength: 253
  30343. minLength: 1
  30344. pattern: ^[-._a-zA-Z0-9]+$
  30345. type: string
  30346. name:
  30347. description: The name of the Secret resource being referred to.
  30348. maxLength: 253
  30349. minLength: 1
  30350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30351. type: string
  30352. namespace:
  30353. description: |-
  30354. The namespace of the Secret resource being referred to.
  30355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30356. maxLength: 63
  30357. minLength: 1
  30358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30359. type: string
  30360. type: object
  30361. type: object
  30362. type: object
  30363. region:
  30364. description: Region specifies the region to operate in.
  30365. type: string
  30366. role:
  30367. description: |-
  30368. You can assume a role before making calls to the
  30369. desired AWS service.
  30370. type: string
  30371. scope:
  30372. description: |-
  30373. Scope specifies the ECR service scope.
  30374. Valid options are private and public.
  30375. type: string
  30376. required:
  30377. - region
  30378. type: object
  30379. type: object
  30380. served: true
  30381. storage: true
  30382. subresources:
  30383. status: {}
  30384. ---
  30385. apiVersion: apiextensions.k8s.io/v1
  30386. kind: CustomResourceDefinition
  30387. metadata:
  30388. annotations:
  30389. controller-gen.kubebuilder.io/version: v0.19.0
  30390. labels:
  30391. external-secrets.io/component: controller
  30392. name: fakes.generators.external-secrets.io
  30393. spec:
  30394. group: generators.external-secrets.io
  30395. names:
  30396. categories:
  30397. - external-secrets
  30398. - external-secrets-generators
  30399. kind: Fake
  30400. listKind: FakeList
  30401. plural: fakes
  30402. singular: fake
  30403. scope: Namespaced
  30404. versions:
  30405. - name: v1alpha1
  30406. schema:
  30407. openAPIV3Schema:
  30408. description: |-
  30409. Fake generator is used for testing. It lets you define
  30410. a static set of credentials that is always returned.
  30411. properties:
  30412. apiVersion:
  30413. description: |-
  30414. APIVersion defines the versioned schema of this representation of an object.
  30415. Servers should convert recognized schemas to the latest internal value, and
  30416. may reject unrecognized values.
  30417. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30418. type: string
  30419. kind:
  30420. description: |-
  30421. Kind is a string value representing the REST resource this object represents.
  30422. Servers may infer this from the endpoint the client submits requests to.
  30423. Cannot be updated.
  30424. In CamelCase.
  30425. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30426. type: string
  30427. metadata:
  30428. type: object
  30429. spec:
  30430. description: FakeSpec contains the static data.
  30431. properties:
  30432. controller:
  30433. description: |-
  30434. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30435. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30436. type: string
  30437. data:
  30438. additionalProperties:
  30439. type: string
  30440. description: |-
  30441. Data defines the static data returned
  30442. by this generator.
  30443. type: object
  30444. type: object
  30445. type: object
  30446. served: true
  30447. storage: true
  30448. subresources:
  30449. status: {}
  30450. ---
  30451. apiVersion: apiextensions.k8s.io/v1
  30452. kind: CustomResourceDefinition
  30453. metadata:
  30454. annotations:
  30455. controller-gen.kubebuilder.io/version: v0.19.0
  30456. labels:
  30457. external-secrets.io/component: controller
  30458. name: gcraccesstokens.generators.external-secrets.io
  30459. spec:
  30460. group: generators.external-secrets.io
  30461. names:
  30462. categories:
  30463. - external-secrets
  30464. - external-secrets-generators
  30465. kind: GCRAccessToken
  30466. listKind: GCRAccessTokenList
  30467. plural: gcraccesstokens
  30468. singular: gcraccesstoken
  30469. scope: Namespaced
  30470. versions:
  30471. - name: v1alpha1
  30472. schema:
  30473. openAPIV3Schema:
  30474. description: |-
  30475. GCRAccessToken generates an GCP access token
  30476. that can be used to authenticate with GCR.
  30477. properties:
  30478. apiVersion:
  30479. description: |-
  30480. APIVersion defines the versioned schema of this representation of an object.
  30481. Servers should convert recognized schemas to the latest internal value, and
  30482. may reject unrecognized values.
  30483. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30484. type: string
  30485. kind:
  30486. description: |-
  30487. Kind is a string value representing the REST resource this object represents.
  30488. Servers may infer this from the endpoint the client submits requests to.
  30489. Cannot be updated.
  30490. In CamelCase.
  30491. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30492. type: string
  30493. metadata:
  30494. type: object
  30495. spec:
  30496. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30497. properties:
  30498. auth:
  30499. description: Auth defines the means for authenticating with GCP
  30500. properties:
  30501. secretRef:
  30502. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30503. properties:
  30504. secretAccessKeySecretRef:
  30505. description: The SecretAccessKey is used for authentication
  30506. properties:
  30507. key:
  30508. description: |-
  30509. A key in the referenced Secret.
  30510. Some instances of this field may be defaulted, in others it may be required.
  30511. maxLength: 253
  30512. minLength: 1
  30513. pattern: ^[-._a-zA-Z0-9]+$
  30514. type: string
  30515. name:
  30516. description: The name of the Secret resource being referred to.
  30517. maxLength: 253
  30518. minLength: 1
  30519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30520. type: string
  30521. namespace:
  30522. description: |-
  30523. The namespace of the Secret resource being referred to.
  30524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30525. maxLength: 63
  30526. minLength: 1
  30527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30528. type: string
  30529. type: object
  30530. type: object
  30531. workloadIdentity:
  30532. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30533. properties:
  30534. clusterLocation:
  30535. type: string
  30536. clusterName:
  30537. type: string
  30538. clusterProjectID:
  30539. type: string
  30540. serviceAccountRef:
  30541. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30542. properties:
  30543. audiences:
  30544. description: |-
  30545. Audience specifies the `aud` claim for the service account token
  30546. Some providers automatically extend the audience field based on well-known annotations for workload
  30547. identity (e.g. IRSA or GCP Workload Identity)
  30548. items:
  30549. type: string
  30550. type: array
  30551. name:
  30552. description: The name of the ServiceAccount resource being referred to.
  30553. maxLength: 253
  30554. minLength: 1
  30555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30556. type: string
  30557. namespace:
  30558. description: |-
  30559. Namespace of the resource being referred to.
  30560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30561. maxLength: 63
  30562. minLength: 1
  30563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30564. type: string
  30565. required:
  30566. - name
  30567. type: object
  30568. required:
  30569. - clusterLocation
  30570. - clusterName
  30571. - serviceAccountRef
  30572. type: object
  30573. workloadIdentityFederation:
  30574. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30575. properties:
  30576. audience:
  30577. description: |-
  30578. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30579. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30580. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30581. type: string
  30582. awsSecurityCredentials:
  30583. description: |-
  30584. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30585. when using the AWS metadata server is not an option.
  30586. properties:
  30587. awsCredentialsSecretRef:
  30588. description: |-
  30589. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30590. Secret should be created with below names for keys
  30591. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30592. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30593. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30594. properties:
  30595. name:
  30596. description: name of the secret.
  30597. maxLength: 253
  30598. minLength: 1
  30599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30600. type: string
  30601. namespace:
  30602. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30603. maxLength: 63
  30604. minLength: 1
  30605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30606. type: string
  30607. required:
  30608. - name
  30609. type: object
  30610. region:
  30611. description: region is for configuring the AWS region to be used.
  30612. example: ap-south-1
  30613. maxLength: 50
  30614. minLength: 1
  30615. pattern: ^[a-z0-9-]+$
  30616. type: string
  30617. required:
  30618. - awsCredentialsSecretRef
  30619. - region
  30620. type: object
  30621. credConfig:
  30622. description: |-
  30623. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30624. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30625. serviceAccountRef must be used by providing operators service account details.
  30626. properties:
  30627. key:
  30628. description: key name holding the external account credential config.
  30629. maxLength: 253
  30630. minLength: 1
  30631. pattern: ^[-._a-zA-Z0-9]+$
  30632. type: string
  30633. name:
  30634. description: name of the configmap.
  30635. maxLength: 253
  30636. minLength: 1
  30637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30638. type: string
  30639. namespace:
  30640. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30641. maxLength: 63
  30642. minLength: 1
  30643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30644. type: string
  30645. required:
  30646. - key
  30647. - name
  30648. type: object
  30649. externalTokenEndpoint:
  30650. description: |-
  30651. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30652. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30653. URL is having the expected value.
  30654. type: string
  30655. gcpServiceAccountEmail:
  30656. description: |-
  30657. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30658. after Workload Identity Federation. Use this to grant access through the service account's
  30659. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30660. service_account_impersonation_url in the external account JSON from credConfig;
  30661. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30662. on that ServiceAccount.
  30663. example: my-gsa@my-project.iam.gserviceaccount.com
  30664. minLength: 1
  30665. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30666. type: string
  30667. serviceAccountRef:
  30668. description: |-
  30669. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30670. when Kubernetes is configured as provider in workload identity pool.
  30671. properties:
  30672. audiences:
  30673. description: |-
  30674. Audience specifies the `aud` claim for the service account token
  30675. Some providers automatically extend the audience field based on well-known annotations for workload
  30676. identity (e.g. IRSA or GCP Workload Identity)
  30677. items:
  30678. type: string
  30679. type: array
  30680. name:
  30681. description: The name of the ServiceAccount resource being referred to.
  30682. maxLength: 253
  30683. minLength: 1
  30684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30685. type: string
  30686. namespace:
  30687. description: |-
  30688. Namespace of the resource being referred to.
  30689. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30690. maxLength: 63
  30691. minLength: 1
  30692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30693. type: string
  30694. required:
  30695. - name
  30696. type: object
  30697. type: object
  30698. type: object
  30699. projectID:
  30700. description: ProjectID defines which project to use to authenticate with
  30701. type: string
  30702. required:
  30703. - auth
  30704. - projectID
  30705. type: object
  30706. type: object
  30707. served: true
  30708. storage: true
  30709. subresources:
  30710. status: {}
  30711. ---
  30712. apiVersion: apiextensions.k8s.io/v1
  30713. kind: CustomResourceDefinition
  30714. metadata:
  30715. annotations:
  30716. controller-gen.kubebuilder.io/version: v0.19.0
  30717. labels:
  30718. external-secrets.io/component: controller
  30719. name: generatorstates.generators.external-secrets.io
  30720. spec:
  30721. group: generators.external-secrets.io
  30722. names:
  30723. categories:
  30724. - external-secrets
  30725. - external-secrets-generators
  30726. kind: GeneratorState
  30727. listKind: GeneratorStateList
  30728. plural: generatorstates
  30729. shortNames:
  30730. - gs
  30731. singular: generatorstate
  30732. scope: Namespaced
  30733. versions:
  30734. - additionalPrinterColumns:
  30735. - jsonPath: .spec.garbageCollectionDeadline
  30736. name: GC Deadline
  30737. type: string
  30738. - jsonPath: .metadata.creationTimestamp
  30739. name: Age
  30740. type: date
  30741. name: v1alpha1
  30742. schema:
  30743. openAPIV3Schema:
  30744. description: GeneratorState represents the state created and managed by a generator resource.
  30745. properties:
  30746. apiVersion:
  30747. description: |-
  30748. APIVersion defines the versioned schema of this representation of an object.
  30749. Servers should convert recognized schemas to the latest internal value, and
  30750. may reject unrecognized values.
  30751. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30752. type: string
  30753. kind:
  30754. description: |-
  30755. Kind is a string value representing the REST resource this object represents.
  30756. Servers may infer this from the endpoint the client submits requests to.
  30757. Cannot be updated.
  30758. In CamelCase.
  30759. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30760. type: string
  30761. metadata:
  30762. type: object
  30763. spec:
  30764. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30765. properties:
  30766. garbageCollectionDeadline:
  30767. description: |-
  30768. GarbageCollectionDeadline is the time after which the generator state
  30769. will be deleted.
  30770. It is set by the controller which creates the generator state and
  30771. can be set configured by the user.
  30772. If the garbage collection deadline is not set the generator state will not be deleted.
  30773. format: date-time
  30774. type: string
  30775. resource:
  30776. description: |-
  30777. Resource is the generator manifest that produced the state.
  30778. It is a snapshot of the generator manifest at the time the state was produced.
  30779. This manifest will be used to delete the resource. Any configuration that is referenced
  30780. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30781. be blocked by a finalizer.
  30782. x-kubernetes-preserve-unknown-fields: true
  30783. state:
  30784. description: State is the state that was produced by the generator implementation.
  30785. x-kubernetes-preserve-unknown-fields: true
  30786. required:
  30787. - resource
  30788. - state
  30789. type: object
  30790. status:
  30791. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30792. properties:
  30793. conditions:
  30794. items:
  30795. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30796. properties:
  30797. lastTransitionTime:
  30798. format: date-time
  30799. type: string
  30800. message:
  30801. type: string
  30802. reason:
  30803. type: string
  30804. status:
  30805. type: string
  30806. type:
  30807. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30808. type: string
  30809. required:
  30810. - status
  30811. - type
  30812. type: object
  30813. type: array
  30814. type: object
  30815. type: object
  30816. served: true
  30817. storage: true
  30818. subresources: {}
  30819. ---
  30820. apiVersion: apiextensions.k8s.io/v1
  30821. kind: CustomResourceDefinition
  30822. metadata:
  30823. annotations:
  30824. controller-gen.kubebuilder.io/version: v0.19.0
  30825. labels:
  30826. external-secrets.io/component: controller
  30827. name: githubaccesstokens.generators.external-secrets.io
  30828. spec:
  30829. group: generators.external-secrets.io
  30830. names:
  30831. categories:
  30832. - external-secrets
  30833. - external-secrets-generators
  30834. kind: GithubAccessToken
  30835. listKind: GithubAccessTokenList
  30836. plural: githubaccesstokens
  30837. singular: githubaccesstoken
  30838. scope: Namespaced
  30839. versions:
  30840. - name: v1alpha1
  30841. schema:
  30842. openAPIV3Schema:
  30843. description: GithubAccessToken generates ghs_ accessToken
  30844. properties:
  30845. apiVersion:
  30846. description: |-
  30847. APIVersion defines the versioned schema of this representation of an object.
  30848. Servers should convert recognized schemas to the latest internal value, and
  30849. may reject unrecognized values.
  30850. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30851. type: string
  30852. kind:
  30853. description: |-
  30854. Kind is a string value representing the REST resource this object represents.
  30855. Servers may infer this from the endpoint the client submits requests to.
  30856. Cannot be updated.
  30857. In CamelCase.
  30858. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30859. type: string
  30860. metadata:
  30861. type: object
  30862. spec:
  30863. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30864. properties:
  30865. appID:
  30866. type: string
  30867. auth:
  30868. description: Auth configures how ESO authenticates with a Github instance.
  30869. properties:
  30870. privateKey:
  30871. description: GithubSecretRef references a secret containing GitHub credentials.
  30872. properties:
  30873. secretRef:
  30874. description: |-
  30875. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30876. In some instances, `key` is a required field.
  30877. properties:
  30878. key:
  30879. description: |-
  30880. A key in the referenced Secret.
  30881. Some instances of this field may be defaulted, in others it may be required.
  30882. maxLength: 253
  30883. minLength: 1
  30884. pattern: ^[-._a-zA-Z0-9]+$
  30885. type: string
  30886. name:
  30887. description: The name of the Secret resource being referred to.
  30888. maxLength: 253
  30889. minLength: 1
  30890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30891. type: string
  30892. namespace:
  30893. description: |-
  30894. The namespace of the Secret resource being referred to.
  30895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30896. maxLength: 63
  30897. minLength: 1
  30898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30899. type: string
  30900. type: object
  30901. required:
  30902. - secretRef
  30903. type: object
  30904. required:
  30905. - privateKey
  30906. type: object
  30907. installID:
  30908. type: string
  30909. permissions:
  30910. additionalProperties:
  30911. type: string
  30912. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30913. type: object
  30914. repositories:
  30915. description: |-
  30916. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30917. is installed to.
  30918. items:
  30919. type: string
  30920. type: array
  30921. url:
  30922. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30923. type: string
  30924. required:
  30925. - appID
  30926. - auth
  30927. - installID
  30928. type: object
  30929. type: object
  30930. served: true
  30931. storage: true
  30932. subresources:
  30933. status: {}
  30934. ---
  30935. apiVersion: apiextensions.k8s.io/v1
  30936. kind: CustomResourceDefinition
  30937. metadata:
  30938. annotations:
  30939. controller-gen.kubebuilder.io/version: v0.19.0
  30940. labels:
  30941. external-secrets.io/component: controller
  30942. name: gitlabdeploytokens.generators.external-secrets.io
  30943. spec:
  30944. group: generators.external-secrets.io
  30945. names:
  30946. categories:
  30947. - external-secrets
  30948. - external-secrets-generators
  30949. kind: GitlabDeployToken
  30950. listKind: GitlabDeployTokenList
  30951. plural: gitlabdeploytokens
  30952. singular: gitlabdeploytoken
  30953. scope: Namespaced
  30954. versions:
  30955. - name: v1alpha1
  30956. schema:
  30957. openAPIV3Schema:
  30958. description: GitlabDeployToken generates a GitLab deploy token.
  30959. properties:
  30960. apiVersion:
  30961. description: |-
  30962. APIVersion defines the versioned schema of this representation of an object.
  30963. Servers should convert recognized schemas to the latest internal value, and
  30964. may reject unrecognized values.
  30965. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30966. type: string
  30967. kind:
  30968. description: |-
  30969. Kind is a string value representing the REST resource this object represents.
  30970. Servers may infer this from the endpoint the client submits requests to.
  30971. Cannot be updated.
  30972. In CamelCase.
  30973. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30974. type: string
  30975. metadata:
  30976. type: object
  30977. spec:
  30978. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30979. properties:
  30980. auth:
  30981. description: Auth configures how ESO authenticates with the GitLab API.
  30982. properties:
  30983. token:
  30984. description: |-
  30985. Token references a secret containing a GitLab access token (personal, group, or
  30986. project) with the api scope and at least the Maintainer role on the target.
  30987. properties:
  30988. secretRef:
  30989. description: |-
  30990. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30991. In some instances, `key` is a required field.
  30992. properties:
  30993. key:
  30994. description: |-
  30995. A key in the referenced Secret.
  30996. Some instances of this field may be defaulted, in others it may be required.
  30997. maxLength: 253
  30998. minLength: 1
  30999. pattern: ^[-._a-zA-Z0-9]+$
  31000. type: string
  31001. name:
  31002. description: The name of the Secret resource being referred to.
  31003. maxLength: 253
  31004. minLength: 1
  31005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31006. type: string
  31007. namespace:
  31008. description: |-
  31009. The namespace of the Secret resource being referred to.
  31010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31011. maxLength: 63
  31012. minLength: 1
  31013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31014. type: string
  31015. type: object
  31016. required:
  31017. - secretRef
  31018. type: object
  31019. required:
  31020. - token
  31021. type: object
  31022. expiresAt:
  31023. description: |-
  31024. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  31025. not expire on the GitLab side and is revoked only when the generator state is
  31026. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  31027. format: date-time
  31028. type: string
  31029. groupID:
  31030. description: |-
  31031. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  31032. create the deploy token in. The generator URL-escapes paths before calling the
  31033. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  31034. minLength: 1
  31035. type: string
  31036. name:
  31037. description: Name of the deploy token.
  31038. minLength: 1
  31039. type: string
  31040. projectID:
  31041. description: |-
  31042. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  31043. project to create the deploy token in. The generator URL-escapes paths before
  31044. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  31045. minLength: 1
  31046. type: string
  31047. scopes:
  31048. description: Scopes granted to the deploy token. At least one scope is required.
  31049. items:
  31050. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  31051. enum:
  31052. - read_repository
  31053. - read_registry
  31054. - write_registry
  31055. - read_package_registry
  31056. - write_package_registry
  31057. - read_virtual_registry
  31058. - write_virtual_registry
  31059. type: string
  31060. minItems: 1
  31061. type: array
  31062. url:
  31063. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  31064. type: string
  31065. username:
  31066. description: |-
  31067. Username is an optional username for the deploy token. GitLab defaults it to
  31068. gitlab+deploy-token-{n} when omitted.
  31069. type: string
  31070. required:
  31071. - auth
  31072. - name
  31073. - scopes
  31074. type: object
  31075. x-kubernetes-validations:
  31076. - message: exactly one of projectID or groupID must be set
  31077. rule: has(self.projectID) != has(self.groupID)
  31078. type: object
  31079. served: true
  31080. storage: true
  31081. subresources:
  31082. status: {}
  31083. ---
  31084. apiVersion: apiextensions.k8s.io/v1
  31085. kind: CustomResourceDefinition
  31086. metadata:
  31087. annotations:
  31088. controller-gen.kubebuilder.io/version: v0.19.0
  31089. labels:
  31090. external-secrets.io/component: controller
  31091. name: grafanas.generators.external-secrets.io
  31092. spec:
  31093. group: generators.external-secrets.io
  31094. names:
  31095. categories:
  31096. - external-secrets
  31097. - external-secrets-generators
  31098. kind: Grafana
  31099. listKind: GrafanaList
  31100. plural: grafanas
  31101. singular: grafana
  31102. scope: Namespaced
  31103. versions:
  31104. - name: v1alpha1
  31105. schema:
  31106. openAPIV3Schema:
  31107. description: Grafana represents a generator for Grafana service account tokens.
  31108. properties:
  31109. apiVersion:
  31110. description: |-
  31111. APIVersion defines the versioned schema of this representation of an object.
  31112. Servers should convert recognized schemas to the latest internal value, and
  31113. may reject unrecognized values.
  31114. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31115. type: string
  31116. kind:
  31117. description: |-
  31118. Kind is a string value representing the REST resource this object represents.
  31119. Servers may infer this from the endpoint the client submits requests to.
  31120. Cannot be updated.
  31121. In CamelCase.
  31122. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31123. type: string
  31124. metadata:
  31125. type: object
  31126. spec:
  31127. description: GrafanaSpec controls the behavior of the grafana generator.
  31128. properties:
  31129. auth:
  31130. description: |-
  31131. Auth is the authentication configuration to authenticate
  31132. against the Grafana instance.
  31133. properties:
  31134. basic:
  31135. description: |-
  31136. Basic auth credentials used to authenticate against the Grafana instance.
  31137. Note: you need a token which has elevated permissions to create service accounts.
  31138. See here for the documentation on basic roles offered by Grafana:
  31139. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31140. properties:
  31141. password:
  31142. description: A basic auth password used to authenticate against the Grafana instance.
  31143. properties:
  31144. key:
  31145. description: The key where the token is found.
  31146. maxLength: 253
  31147. minLength: 1
  31148. pattern: ^[-._a-zA-Z0-9]+$
  31149. type: string
  31150. name:
  31151. description: The name of the Secret resource being referred to.
  31152. maxLength: 253
  31153. minLength: 1
  31154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31155. type: string
  31156. type: object
  31157. username:
  31158. description: A basic auth username used to authenticate against the Grafana instance.
  31159. type: string
  31160. required:
  31161. - password
  31162. - username
  31163. type: object
  31164. token:
  31165. description: |-
  31166. A service account token used to authenticate against the Grafana instance.
  31167. Note: you need a token which has elevated permissions to create service accounts.
  31168. See here for the documentation on basic roles offered by Grafana:
  31169. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31170. properties:
  31171. key:
  31172. description: The key where the token is found.
  31173. maxLength: 253
  31174. minLength: 1
  31175. pattern: ^[-._a-zA-Z0-9]+$
  31176. type: string
  31177. name:
  31178. description: The name of the Secret resource being referred to.
  31179. maxLength: 253
  31180. minLength: 1
  31181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31182. type: string
  31183. type: object
  31184. type: object
  31185. serviceAccount:
  31186. description: |-
  31187. ServiceAccount is the configuration for the service account that
  31188. is supposed to be generated by the generator.
  31189. properties:
  31190. name:
  31191. description: Name is the name of the service account that will be created by ESO.
  31192. type: string
  31193. role:
  31194. description: |-
  31195. Role is the role of the service account.
  31196. See here for the documentation on basic roles offered by Grafana:
  31197. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31198. type: string
  31199. secondsToLive:
  31200. description: |-
  31201. SecondsToLive is the number of seconds before the generated service account token will expire.
  31202. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  31203. format: int64
  31204. minimum: 1
  31205. type: integer
  31206. required:
  31207. - name
  31208. - role
  31209. type: object
  31210. url:
  31211. description: URL is the URL of the Grafana instance.
  31212. type: string
  31213. required:
  31214. - auth
  31215. - serviceAccount
  31216. - url
  31217. type: object
  31218. type: object
  31219. served: true
  31220. storage: true
  31221. subresources:
  31222. status: {}
  31223. ---
  31224. apiVersion: apiextensions.k8s.io/v1
  31225. kind: CustomResourceDefinition
  31226. metadata:
  31227. annotations:
  31228. controller-gen.kubebuilder.io/version: v0.19.0
  31229. labels:
  31230. external-secrets.io/component: controller
  31231. name: mfas.generators.external-secrets.io
  31232. spec:
  31233. group: generators.external-secrets.io
  31234. names:
  31235. categories:
  31236. - external-secrets
  31237. - external-secrets-generators
  31238. kind: MFA
  31239. listKind: MFAList
  31240. plural: mfas
  31241. singular: mfa
  31242. scope: Namespaced
  31243. versions:
  31244. - name: v1alpha1
  31245. schema:
  31246. openAPIV3Schema:
  31247. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  31248. properties:
  31249. apiVersion:
  31250. description: |-
  31251. APIVersion defines the versioned schema of this representation of an object.
  31252. Servers should convert recognized schemas to the latest internal value, and
  31253. may reject unrecognized values.
  31254. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31255. type: string
  31256. kind:
  31257. description: |-
  31258. Kind is a string value representing the REST resource this object represents.
  31259. Servers may infer this from the endpoint the client submits requests to.
  31260. Cannot be updated.
  31261. In CamelCase.
  31262. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31263. type: string
  31264. metadata:
  31265. type: object
  31266. spec:
  31267. description: MFASpec controls the behavior of the mfa generator.
  31268. properties:
  31269. algorithm:
  31270. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  31271. type: string
  31272. length:
  31273. description: Length defines the token length. Defaults to 6 characters.
  31274. type: integer
  31275. secret:
  31276. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  31277. properties:
  31278. key:
  31279. description: |-
  31280. A key in the referenced Secret.
  31281. Some instances of this field may be defaulted, in others it may be required.
  31282. maxLength: 253
  31283. minLength: 1
  31284. pattern: ^[-._a-zA-Z0-9]+$
  31285. type: string
  31286. name:
  31287. description: The name of the Secret resource being referred to.
  31288. maxLength: 253
  31289. minLength: 1
  31290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31291. type: string
  31292. namespace:
  31293. description: |-
  31294. The namespace of the Secret resource being referred to.
  31295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31296. maxLength: 63
  31297. minLength: 1
  31298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31299. type: string
  31300. type: object
  31301. timePeriod:
  31302. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  31303. type: integer
  31304. when:
  31305. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  31306. format: date-time
  31307. type: string
  31308. required:
  31309. - secret
  31310. type: object
  31311. type: object
  31312. served: true
  31313. storage: true
  31314. subresources:
  31315. status: {}
  31316. ---
  31317. apiVersion: apiextensions.k8s.io/v1
  31318. kind: CustomResourceDefinition
  31319. metadata:
  31320. annotations:
  31321. controller-gen.kubebuilder.io/version: v0.19.0
  31322. labels:
  31323. external-secrets.io/component: controller
  31324. name: passwords.generators.external-secrets.io
  31325. spec:
  31326. group: generators.external-secrets.io
  31327. names:
  31328. categories:
  31329. - external-secrets
  31330. - external-secrets-generators
  31331. kind: Password
  31332. listKind: PasswordList
  31333. plural: passwords
  31334. singular: password
  31335. scope: Namespaced
  31336. versions:
  31337. - name: v1alpha1
  31338. schema:
  31339. openAPIV3Schema:
  31340. description: |-
  31341. Password generates a random password based on the
  31342. configuration parameters in spec.
  31343. You can specify the length, characterset and other attributes.
  31344. properties:
  31345. apiVersion:
  31346. description: |-
  31347. APIVersion defines the versioned schema of this representation of an object.
  31348. Servers should convert recognized schemas to the latest internal value, and
  31349. may reject unrecognized values.
  31350. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31351. type: string
  31352. kind:
  31353. description: |-
  31354. Kind is a string value representing the REST resource this object represents.
  31355. Servers may infer this from the endpoint the client submits requests to.
  31356. Cannot be updated.
  31357. In CamelCase.
  31358. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31359. type: string
  31360. metadata:
  31361. type: object
  31362. spec:
  31363. description: PasswordSpec controls the behavior of the password generator.
  31364. properties:
  31365. allowRepeat:
  31366. default: false
  31367. description: set AllowRepeat to true to allow repeating characters.
  31368. type: boolean
  31369. digits:
  31370. description: |-
  31371. Digits specifies the number of digits in the generated
  31372. password. If omitted it defaults to 25% of the length of the password
  31373. type: integer
  31374. encoding:
  31375. default: raw
  31376. description: |-
  31377. Encoding specifies the encoding of the generated password.
  31378. Valid values are:
  31379. - "raw" (default): no encoding
  31380. - "base64": standard base64 encoding
  31381. - "base64url": base64url encoding
  31382. - "base32": base32 encoding
  31383. - "hex": hexadecimal encoding
  31384. enum:
  31385. - base64
  31386. - base64url
  31387. - base32
  31388. - hex
  31389. - raw
  31390. type: string
  31391. length:
  31392. default: 24
  31393. description: |-
  31394. Length of the password to be generated.
  31395. Defaults to 24
  31396. type: integer
  31397. noUpper:
  31398. default: false
  31399. description: Set NoUpper to disable uppercase characters
  31400. type: boolean
  31401. secretKeys:
  31402. description: |-
  31403. SecretKeys defines the keys that will be populated with generated passwords.
  31404. Defaults to "password" when not set.
  31405. items:
  31406. type: string
  31407. minItems: 1
  31408. type: array
  31409. symbolCharacters:
  31410. description: |-
  31411. SymbolCharacters specifies the special characters that should be used
  31412. in the generated password.
  31413. type: string
  31414. symbols:
  31415. description: |-
  31416. Symbols specifies the number of symbol characters in the generated
  31417. password. If omitted it defaults to 25% of the length of the password
  31418. type: integer
  31419. required:
  31420. - allowRepeat
  31421. - length
  31422. - noUpper
  31423. type: object
  31424. type: object
  31425. served: true
  31426. storage: true
  31427. subresources:
  31428. status: {}
  31429. ---
  31430. apiVersion: apiextensions.k8s.io/v1
  31431. kind: CustomResourceDefinition
  31432. metadata:
  31433. annotations:
  31434. controller-gen.kubebuilder.io/version: v0.19.0
  31435. labels:
  31436. external-secrets.io/component: controller
  31437. name: quayaccesstokens.generators.external-secrets.io
  31438. spec:
  31439. group: generators.external-secrets.io
  31440. names:
  31441. categories:
  31442. - external-secrets
  31443. - external-secrets-generators
  31444. kind: QuayAccessToken
  31445. listKind: QuayAccessTokenList
  31446. plural: quayaccesstokens
  31447. singular: quayaccesstoken
  31448. scope: Namespaced
  31449. versions:
  31450. - name: v1alpha1
  31451. schema:
  31452. openAPIV3Schema:
  31453. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  31454. properties:
  31455. apiVersion:
  31456. description: |-
  31457. APIVersion defines the versioned schema of this representation of an object.
  31458. Servers should convert recognized schemas to the latest internal value, and
  31459. may reject unrecognized values.
  31460. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31461. type: string
  31462. kind:
  31463. description: |-
  31464. Kind is a string value representing the REST resource this object represents.
  31465. Servers may infer this from the endpoint the client submits requests to.
  31466. Cannot be updated.
  31467. In CamelCase.
  31468. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31469. type: string
  31470. metadata:
  31471. type: object
  31472. spec:
  31473. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  31474. properties:
  31475. robotAccount:
  31476. description: Name of the robot account you are federating with
  31477. type: string
  31478. serviceAccountRef:
  31479. description: Name of the service account you are federating with
  31480. properties:
  31481. audiences:
  31482. description: |-
  31483. Audience specifies the `aud` claim for the service account token
  31484. Some providers automatically extend the audience field based on well-known annotations for workload
  31485. identity (e.g. IRSA or GCP Workload Identity)
  31486. items:
  31487. type: string
  31488. type: array
  31489. name:
  31490. description: The name of the ServiceAccount resource being referred to.
  31491. maxLength: 253
  31492. minLength: 1
  31493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31494. type: string
  31495. namespace:
  31496. description: |-
  31497. Namespace of the resource being referred to.
  31498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31499. maxLength: 63
  31500. minLength: 1
  31501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31502. type: string
  31503. required:
  31504. - name
  31505. type: object
  31506. url:
  31507. description: URL configures the Quay instance URL. Defaults to quay.io.
  31508. type: string
  31509. required:
  31510. - robotAccount
  31511. - serviceAccountRef
  31512. type: object
  31513. type: object
  31514. served: true
  31515. storage: true
  31516. subresources:
  31517. status: {}
  31518. ---
  31519. apiVersion: apiextensions.k8s.io/v1
  31520. kind: CustomResourceDefinition
  31521. metadata:
  31522. annotations:
  31523. controller-gen.kubebuilder.io/version: v0.19.0
  31524. labels:
  31525. external-secrets.io/component: controller
  31526. name: sshkeys.generators.external-secrets.io
  31527. spec:
  31528. group: generators.external-secrets.io
  31529. names:
  31530. categories:
  31531. - external-secrets
  31532. - external-secrets-generators
  31533. kind: SSHKey
  31534. listKind: SSHKeyList
  31535. plural: sshkeys
  31536. singular: sshkey
  31537. scope: Namespaced
  31538. versions:
  31539. - name: v1alpha1
  31540. schema:
  31541. openAPIV3Schema:
  31542. description: SSHKey generates SSH key pairs.
  31543. properties:
  31544. apiVersion:
  31545. description: |-
  31546. APIVersion defines the versioned schema of this representation of an object.
  31547. Servers should convert recognized schemas to the latest internal value, and
  31548. may reject unrecognized values.
  31549. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31550. type: string
  31551. kind:
  31552. description: |-
  31553. Kind is a string value representing the REST resource this object represents.
  31554. Servers may infer this from the endpoint the client submits requests to.
  31555. Cannot be updated.
  31556. In CamelCase.
  31557. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31558. type: string
  31559. metadata:
  31560. type: object
  31561. spec:
  31562. description: SSHKeySpec controls the behavior of the ssh key generator.
  31563. properties:
  31564. comment:
  31565. description: Comment specifies an optional comment for the SSH key
  31566. type: string
  31567. keySize:
  31568. description: |-
  31569. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31570. For RSA keys: 2048, 3072, 4096
  31571. For ECDSA keys: 256, 384, 521
  31572. Ignored for ed25519 keys
  31573. maximum: 8192
  31574. minimum: 256
  31575. type: integer
  31576. keyType:
  31577. default: rsa
  31578. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31579. enum:
  31580. - rsa
  31581. - ecdsa
  31582. - ed25519
  31583. type: string
  31584. type: object
  31585. type: object
  31586. served: true
  31587. storage: true
  31588. subresources:
  31589. status: {}
  31590. ---
  31591. apiVersion: apiextensions.k8s.io/v1
  31592. kind: CustomResourceDefinition
  31593. metadata:
  31594. annotations:
  31595. controller-gen.kubebuilder.io/version: v0.19.0
  31596. labels:
  31597. external-secrets.io/component: controller
  31598. name: stssessiontokens.generators.external-secrets.io
  31599. spec:
  31600. group: generators.external-secrets.io
  31601. names:
  31602. categories:
  31603. - external-secrets
  31604. - external-secrets-generators
  31605. kind: STSSessionToken
  31606. listKind: STSSessionTokenList
  31607. plural: stssessiontokens
  31608. singular: stssessiontoken
  31609. scope: Namespaced
  31610. versions:
  31611. - name: v1alpha1
  31612. schema:
  31613. openAPIV3Schema:
  31614. description: |-
  31615. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31616. The authorization token is valid for 12 hours.
  31617. The authorizationToken returned is a base64 encoded string that can be decoded.
  31618. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31619. properties:
  31620. apiVersion:
  31621. description: |-
  31622. APIVersion defines the versioned schema of this representation of an object.
  31623. Servers should convert recognized schemas to the latest internal value, and
  31624. may reject unrecognized values.
  31625. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31626. type: string
  31627. kind:
  31628. description: |-
  31629. Kind is a string value representing the REST resource this object represents.
  31630. Servers may infer this from the endpoint the client submits requests to.
  31631. Cannot be updated.
  31632. In CamelCase.
  31633. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31634. type: string
  31635. metadata:
  31636. type: object
  31637. spec:
  31638. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31639. properties:
  31640. auth:
  31641. description: Auth defines how to authenticate with AWS
  31642. properties:
  31643. jwt:
  31644. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31645. properties:
  31646. serviceAccountRef:
  31647. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31648. properties:
  31649. audiences:
  31650. description: |-
  31651. Audience specifies the `aud` claim for the service account token
  31652. Some providers automatically extend the audience field based on well-known annotations for workload
  31653. identity (e.g. IRSA or GCP Workload Identity)
  31654. items:
  31655. type: string
  31656. type: array
  31657. name:
  31658. description: The name of the ServiceAccount resource being referred to.
  31659. maxLength: 253
  31660. minLength: 1
  31661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31662. type: string
  31663. namespace:
  31664. description: |-
  31665. Namespace of the resource being referred to.
  31666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31667. maxLength: 63
  31668. minLength: 1
  31669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31670. type: string
  31671. required:
  31672. - name
  31673. type: object
  31674. type: object
  31675. secretRef:
  31676. description: |-
  31677. AWSAuthSecretRef holds secret references for AWS credentials
  31678. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31679. properties:
  31680. accessKeyIDSecretRef:
  31681. description: The AccessKeyID is used for authentication
  31682. properties:
  31683. key:
  31684. description: |-
  31685. A key in the referenced Secret.
  31686. Some instances of this field may be defaulted, in others it may be required.
  31687. maxLength: 253
  31688. minLength: 1
  31689. pattern: ^[-._a-zA-Z0-9]+$
  31690. type: string
  31691. name:
  31692. description: The name of the Secret resource being referred to.
  31693. maxLength: 253
  31694. minLength: 1
  31695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31696. type: string
  31697. namespace:
  31698. description: |-
  31699. The namespace of the Secret resource being referred to.
  31700. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31701. maxLength: 63
  31702. minLength: 1
  31703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31704. type: string
  31705. type: object
  31706. secretAccessKeySecretRef:
  31707. description: The SecretAccessKey is used for authentication
  31708. properties:
  31709. key:
  31710. description: |-
  31711. A key in the referenced Secret.
  31712. Some instances of this field may be defaulted, in others it may be required.
  31713. maxLength: 253
  31714. minLength: 1
  31715. pattern: ^[-._a-zA-Z0-9]+$
  31716. type: string
  31717. name:
  31718. description: The name of the Secret resource being referred to.
  31719. maxLength: 253
  31720. minLength: 1
  31721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31722. type: string
  31723. namespace:
  31724. description: |-
  31725. The namespace of the Secret resource being referred to.
  31726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31727. maxLength: 63
  31728. minLength: 1
  31729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31730. type: string
  31731. type: object
  31732. sessionTokenSecretRef:
  31733. description: |-
  31734. The SessionToken used for authentication
  31735. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31736. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31737. properties:
  31738. key:
  31739. description: |-
  31740. A key in the referenced Secret.
  31741. Some instances of this field may be defaulted, in others it may be required.
  31742. maxLength: 253
  31743. minLength: 1
  31744. pattern: ^[-._a-zA-Z0-9]+$
  31745. type: string
  31746. name:
  31747. description: The name of the Secret resource being referred to.
  31748. maxLength: 253
  31749. minLength: 1
  31750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31751. type: string
  31752. namespace:
  31753. description: |-
  31754. The namespace of the Secret resource being referred to.
  31755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31756. maxLength: 63
  31757. minLength: 1
  31758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31759. type: string
  31760. type: object
  31761. type: object
  31762. type: object
  31763. region:
  31764. description: Region specifies the region to operate in.
  31765. type: string
  31766. requestParameters:
  31767. description: RequestParameters contains parameters that can be passed to the STS service.
  31768. properties:
  31769. serialNumber:
  31770. description: |-
  31771. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31772. the GetSessionToken call.
  31773. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31774. (such as arn:aws:iam::123456789012:mfa/user)
  31775. type: string
  31776. sessionDuration:
  31777. format: int32
  31778. type: integer
  31779. tokenCode:
  31780. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31781. type: string
  31782. type: object
  31783. role:
  31784. description: |-
  31785. You can assume a role before making calls to the
  31786. desired AWS service.
  31787. type: string
  31788. required:
  31789. - region
  31790. type: object
  31791. type: object
  31792. served: true
  31793. storage: true
  31794. subresources:
  31795. status: {}
  31796. ---
  31797. apiVersion: apiextensions.k8s.io/v1
  31798. kind: CustomResourceDefinition
  31799. metadata:
  31800. annotations:
  31801. controller-gen.kubebuilder.io/version: v0.19.0
  31802. labels:
  31803. external-secrets.io/component: controller
  31804. name: uuids.generators.external-secrets.io
  31805. spec:
  31806. group: generators.external-secrets.io
  31807. names:
  31808. categories:
  31809. - external-secrets
  31810. - external-secrets-generators
  31811. kind: UUID
  31812. listKind: UUIDList
  31813. plural: uuids
  31814. singular: uuid
  31815. scope: Namespaced
  31816. versions:
  31817. - name: v1alpha1
  31818. schema:
  31819. openAPIV3Schema:
  31820. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31821. properties:
  31822. apiVersion:
  31823. description: |-
  31824. APIVersion defines the versioned schema of this representation of an object.
  31825. Servers should convert recognized schemas to the latest internal value, and
  31826. may reject unrecognized values.
  31827. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31828. type: string
  31829. kind:
  31830. description: |-
  31831. Kind is a string value representing the REST resource this object represents.
  31832. Servers may infer this from the endpoint the client submits requests to.
  31833. Cannot be updated.
  31834. In CamelCase.
  31835. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31836. type: string
  31837. metadata:
  31838. type: object
  31839. spec:
  31840. description: UUIDSpec controls the behavior of the uuid generator.
  31841. type: object
  31842. type: object
  31843. served: true
  31844. storage: true
  31845. subresources:
  31846. status: {}
  31847. ---
  31848. apiVersion: apiextensions.k8s.io/v1
  31849. kind: CustomResourceDefinition
  31850. metadata:
  31851. annotations:
  31852. controller-gen.kubebuilder.io/version: v0.19.0
  31853. labels:
  31854. external-secrets.io/component: controller
  31855. name: vaultdynamicsecrets.generators.external-secrets.io
  31856. spec:
  31857. group: generators.external-secrets.io
  31858. names:
  31859. categories:
  31860. - external-secrets
  31861. - external-secrets-generators
  31862. kind: VaultDynamicSecret
  31863. listKind: VaultDynamicSecretList
  31864. plural: vaultdynamicsecrets
  31865. singular: vaultdynamicsecret
  31866. scope: Namespaced
  31867. versions:
  31868. - name: v1alpha1
  31869. schema:
  31870. openAPIV3Schema:
  31871. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31872. properties:
  31873. apiVersion:
  31874. description: |-
  31875. APIVersion defines the versioned schema of this representation of an object.
  31876. Servers should convert recognized schemas to the latest internal value, and
  31877. may reject unrecognized values.
  31878. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31879. type: string
  31880. kind:
  31881. description: |-
  31882. Kind is a string value representing the REST resource this object represents.
  31883. Servers may infer this from the endpoint the client submits requests to.
  31884. Cannot be updated.
  31885. In CamelCase.
  31886. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31887. type: string
  31888. metadata:
  31889. type: object
  31890. spec:
  31891. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31892. properties:
  31893. allowEmptyResponse:
  31894. default: false
  31895. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31896. type: boolean
  31897. controller:
  31898. description: |-
  31899. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31900. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31901. type: string
  31902. getParameters:
  31903. additionalProperties:
  31904. items:
  31905. type: string
  31906. type: array
  31907. description: |-
  31908. GetParameters are query-string parameters passed to Vault on GET calls.
  31909. Each key may map to multiple values, matching HTTP query-string semantics.
  31910. Ignored for non-GET methods; use Parameters for write bodies.
  31911. type: object
  31912. method:
  31913. description: Vault API method to use (GET/POST/other)
  31914. type: string
  31915. parameters:
  31916. description: Parameters to pass to Vault write (for non-GET methods)
  31917. x-kubernetes-preserve-unknown-fields: true
  31918. path:
  31919. description: Vault path to obtain the dynamic secret from
  31920. type: string
  31921. provider:
  31922. description: Vault provider common spec
  31923. properties:
  31924. auth:
  31925. description: Auth configures how secret-manager authenticates with the Vault server.
  31926. properties:
  31927. appRole:
  31928. description: |-
  31929. AppRole authenticates with Vault using the App Role auth mechanism,
  31930. with the role and secret stored in a Kubernetes Secret resource.
  31931. properties:
  31932. path:
  31933. default: approle
  31934. description: |-
  31935. Path where the App Role authentication backend is mounted
  31936. in Vault, e.g: "approle"
  31937. type: string
  31938. roleId:
  31939. description: |-
  31940. RoleID configured in the App Role authentication backend when setting
  31941. up the authentication backend in Vault.
  31942. type: string
  31943. roleRef:
  31944. description: |-
  31945. Reference to a key in a Secret that contains the App Role ID used
  31946. to authenticate with Vault.
  31947. The `key` field must be specified and denotes which entry within the Secret
  31948. resource is used as the app role id.
  31949. properties:
  31950. key:
  31951. description: |-
  31952. A key in the referenced Secret.
  31953. Some instances of this field may be defaulted, in others it may be required.
  31954. maxLength: 253
  31955. minLength: 1
  31956. pattern: ^[-._a-zA-Z0-9]+$
  31957. type: string
  31958. name:
  31959. description: The name of the Secret resource being referred to.
  31960. maxLength: 253
  31961. minLength: 1
  31962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31963. type: string
  31964. namespace:
  31965. description: |-
  31966. The namespace of the Secret resource being referred to.
  31967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31968. maxLength: 63
  31969. minLength: 1
  31970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31971. type: string
  31972. type: object
  31973. secretRef:
  31974. description: |-
  31975. Reference to a key in a Secret that contains the App Role secret used
  31976. to authenticate with Vault.
  31977. The `key` field must be specified and denotes which entry within the Secret
  31978. resource is used as the app role secret.
  31979. properties:
  31980. key:
  31981. description: |-
  31982. A key in the referenced Secret.
  31983. Some instances of this field may be defaulted, in others it may be required.
  31984. maxLength: 253
  31985. minLength: 1
  31986. pattern: ^[-._a-zA-Z0-9]+$
  31987. type: string
  31988. name:
  31989. description: The name of the Secret resource being referred to.
  31990. maxLength: 253
  31991. minLength: 1
  31992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31993. type: string
  31994. namespace:
  31995. description: |-
  31996. The namespace of the Secret resource being referred to.
  31997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31998. maxLength: 63
  31999. minLength: 1
  32000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32001. type: string
  32002. type: object
  32003. required:
  32004. - path
  32005. - secretRef
  32006. type: object
  32007. cert:
  32008. description: |-
  32009. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  32010. Cert authentication method
  32011. properties:
  32012. clientCert:
  32013. description: |-
  32014. ClientCert is a certificate to authenticate using the Cert Vault
  32015. authentication method
  32016. properties:
  32017. key:
  32018. description: |-
  32019. A key in the referenced Secret.
  32020. Some instances of this field may be defaulted, in others it may be required.
  32021. maxLength: 253
  32022. minLength: 1
  32023. pattern: ^[-._a-zA-Z0-9]+$
  32024. type: string
  32025. name:
  32026. description: The name of the Secret resource being referred to.
  32027. maxLength: 253
  32028. minLength: 1
  32029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32030. type: string
  32031. namespace:
  32032. description: |-
  32033. The namespace of the Secret resource being referred to.
  32034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32035. maxLength: 63
  32036. minLength: 1
  32037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32038. type: string
  32039. type: object
  32040. path:
  32041. default: cert
  32042. description: |-
  32043. Path where the Certificate authentication backend is mounted
  32044. in Vault, e.g: "cert"
  32045. type: string
  32046. secretRef:
  32047. description: |-
  32048. SecretRef to a key in a Secret resource containing client private key to
  32049. authenticate with Vault using the Cert authentication method
  32050. properties:
  32051. key:
  32052. description: |-
  32053. A key in the referenced Secret.
  32054. Some instances of this field may be defaulted, in others it may be required.
  32055. maxLength: 253
  32056. minLength: 1
  32057. pattern: ^[-._a-zA-Z0-9]+$
  32058. type: string
  32059. name:
  32060. description: The name of the Secret resource being referred to.
  32061. maxLength: 253
  32062. minLength: 1
  32063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32064. type: string
  32065. namespace:
  32066. description: |-
  32067. The namespace of the Secret resource being referred to.
  32068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32069. maxLength: 63
  32070. minLength: 1
  32071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32072. type: string
  32073. type: object
  32074. vaultRole:
  32075. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  32076. type: string
  32077. type: object
  32078. gcp:
  32079. description: |-
  32080. Gcp authenticates with Vault using Google Cloud Platform authentication method
  32081. GCP authentication method
  32082. properties:
  32083. location:
  32084. description: Location optionally defines a location/region for the secret
  32085. type: string
  32086. path:
  32087. default: gcp
  32088. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  32089. type: string
  32090. projectID:
  32091. description: Project ID of the Google Cloud Platform project
  32092. type: string
  32093. role:
  32094. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  32095. type: string
  32096. secretRef:
  32097. description: Specify credentials in a Secret object
  32098. properties:
  32099. secretAccessKeySecretRef:
  32100. description: The SecretAccessKey is used for authentication
  32101. properties:
  32102. key:
  32103. description: |-
  32104. A key in the referenced Secret.
  32105. Some instances of this field may be defaulted, in others it may be required.
  32106. maxLength: 253
  32107. minLength: 1
  32108. pattern: ^[-._a-zA-Z0-9]+$
  32109. type: string
  32110. name:
  32111. description: The name of the Secret resource being referred to.
  32112. maxLength: 253
  32113. minLength: 1
  32114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32115. type: string
  32116. namespace:
  32117. description: |-
  32118. The namespace of the Secret resource being referred to.
  32119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32120. maxLength: 63
  32121. minLength: 1
  32122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32123. type: string
  32124. type: object
  32125. type: object
  32126. serviceAccountRef:
  32127. description: ServiceAccountRef to a service account for impersonation
  32128. properties:
  32129. audiences:
  32130. description: |-
  32131. Audience specifies the `aud` claim for the service account token
  32132. Some providers automatically extend the audience field based on well-known annotations for workload
  32133. identity (e.g. IRSA or GCP Workload Identity)
  32134. items:
  32135. type: string
  32136. type: array
  32137. name:
  32138. description: The name of the ServiceAccount resource being referred to.
  32139. maxLength: 253
  32140. minLength: 1
  32141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32142. type: string
  32143. namespace:
  32144. description: |-
  32145. Namespace of the resource being referred to.
  32146. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32147. maxLength: 63
  32148. minLength: 1
  32149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32150. type: string
  32151. required:
  32152. - name
  32153. type: object
  32154. workloadIdentity:
  32155. description: Specify a service account with Workload Identity
  32156. properties:
  32157. clusterLocation:
  32158. description: |-
  32159. ClusterLocation is the location of the cluster
  32160. If not specified, it fetches information from the metadata server
  32161. type: string
  32162. clusterName:
  32163. description: |-
  32164. ClusterName is the name of the cluster
  32165. If not specified, it fetches information from the metadata server
  32166. type: string
  32167. clusterProjectID:
  32168. description: |-
  32169. ClusterProjectID is the project ID of the cluster
  32170. If not specified, it fetches information from the metadata server
  32171. type: string
  32172. serviceAccountRef:
  32173. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32174. properties:
  32175. audiences:
  32176. description: |-
  32177. Audience specifies the `aud` claim for the service account token
  32178. Some providers automatically extend the audience field based on well-known annotations for workload
  32179. identity (e.g. IRSA or GCP Workload Identity)
  32180. items:
  32181. type: string
  32182. type: array
  32183. name:
  32184. description: The name of the ServiceAccount resource being referred to.
  32185. maxLength: 253
  32186. minLength: 1
  32187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32188. type: string
  32189. namespace:
  32190. description: |-
  32191. Namespace of the resource being referred to.
  32192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32193. maxLength: 63
  32194. minLength: 1
  32195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32196. type: string
  32197. required:
  32198. - name
  32199. type: object
  32200. required:
  32201. - serviceAccountRef
  32202. type: object
  32203. required:
  32204. - role
  32205. type: object
  32206. iam:
  32207. description: |-
  32208. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  32209. AWS IAM authentication method
  32210. properties:
  32211. externalID:
  32212. description: AWS External ID set on assumed IAM roles
  32213. type: string
  32214. jwt:
  32215. description: Specify a service account with IRSA enabled
  32216. properties:
  32217. serviceAccountRef:
  32218. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32219. properties:
  32220. audiences:
  32221. description: |-
  32222. Audience specifies the `aud` claim for the service account token
  32223. Some providers automatically extend the audience field based on well-known annotations for workload
  32224. identity (e.g. IRSA or GCP Workload Identity)
  32225. items:
  32226. type: string
  32227. type: array
  32228. name:
  32229. description: The name of the ServiceAccount resource being referred to.
  32230. maxLength: 253
  32231. minLength: 1
  32232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32233. type: string
  32234. namespace:
  32235. description: |-
  32236. Namespace of the resource being referred to.
  32237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32238. maxLength: 63
  32239. minLength: 1
  32240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32241. type: string
  32242. required:
  32243. - name
  32244. type: object
  32245. type: object
  32246. path:
  32247. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  32248. type: string
  32249. region:
  32250. description: AWS region
  32251. type: string
  32252. role:
  32253. description: This is the AWS role to be assumed before talking to vault
  32254. type: string
  32255. secretRef:
  32256. description: Specify credentials in a Secret object
  32257. properties:
  32258. accessKeyIDSecretRef:
  32259. description: The AccessKeyID is used for authentication
  32260. properties:
  32261. key:
  32262. description: |-
  32263. A key in the referenced Secret.
  32264. Some instances of this field may be defaulted, in others it may be required.
  32265. maxLength: 253
  32266. minLength: 1
  32267. pattern: ^[-._a-zA-Z0-9]+$
  32268. type: string
  32269. name:
  32270. description: The name of the Secret resource being referred to.
  32271. maxLength: 253
  32272. minLength: 1
  32273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32274. type: string
  32275. namespace:
  32276. description: |-
  32277. The namespace of the Secret resource being referred to.
  32278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32279. maxLength: 63
  32280. minLength: 1
  32281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32282. type: string
  32283. type: object
  32284. secretAccessKeySecretRef:
  32285. description: The SecretAccessKey is used for authentication
  32286. properties:
  32287. key:
  32288. description: |-
  32289. A key in the referenced Secret.
  32290. Some instances of this field may be defaulted, in others it may be required.
  32291. maxLength: 253
  32292. minLength: 1
  32293. pattern: ^[-._a-zA-Z0-9]+$
  32294. type: string
  32295. name:
  32296. description: The name of the Secret resource being referred to.
  32297. maxLength: 253
  32298. minLength: 1
  32299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32300. type: string
  32301. namespace:
  32302. description: |-
  32303. The namespace of the Secret resource being referred to.
  32304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32305. maxLength: 63
  32306. minLength: 1
  32307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32308. type: string
  32309. type: object
  32310. sessionTokenSecretRef:
  32311. description: |-
  32312. The SessionToken used for authentication
  32313. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  32314. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  32315. properties:
  32316. key:
  32317. description: |-
  32318. A key in the referenced Secret.
  32319. Some instances of this field may be defaulted, in others it may be required.
  32320. maxLength: 253
  32321. minLength: 1
  32322. pattern: ^[-._a-zA-Z0-9]+$
  32323. type: string
  32324. name:
  32325. description: The name of the Secret resource being referred to.
  32326. maxLength: 253
  32327. minLength: 1
  32328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32329. type: string
  32330. namespace:
  32331. description: |-
  32332. The namespace of the Secret resource being referred to.
  32333. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32334. maxLength: 63
  32335. minLength: 1
  32336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32337. type: string
  32338. type: object
  32339. type: object
  32340. vaultAwsIamServerID:
  32341. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  32342. type: string
  32343. vaultRole:
  32344. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  32345. type: string
  32346. required:
  32347. - vaultRole
  32348. type: object
  32349. jwt:
  32350. description: |-
  32351. Jwt authenticates with Vault by passing role and JWT token using the
  32352. JWT/OIDC authentication method
  32353. properties:
  32354. kubernetesServiceAccountToken:
  32355. description: |-
  32356. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  32357. a token for with the `TokenRequest` API.
  32358. properties:
  32359. audiences:
  32360. description: |-
  32361. Optional audiences field that will be used to request a temporary Kubernetes service
  32362. account token for the service account referenced by `serviceAccountRef`.
  32363. Defaults to a single audience `vault` it not specified.
  32364. Deprecated: use serviceAccountRef.Audiences instead
  32365. items:
  32366. type: string
  32367. type: array
  32368. expirationSeconds:
  32369. description: |-
  32370. Optional expiration time in seconds that will be used to request a temporary
  32371. Kubernetes service account token for the service account referenced by
  32372. `serviceAccountRef`.
  32373. Deprecated: this will be removed in the future.
  32374. Defaults to 10 minutes.
  32375. format: int64
  32376. type: integer
  32377. serviceAccountRef:
  32378. description: Service account field containing the name of a kubernetes ServiceAccount.
  32379. properties:
  32380. audiences:
  32381. description: |-
  32382. Audience specifies the `aud` claim for the service account token
  32383. Some providers automatically extend the audience field based on well-known annotations for workload
  32384. identity (e.g. IRSA or GCP Workload Identity)
  32385. items:
  32386. type: string
  32387. type: array
  32388. name:
  32389. description: The name of the ServiceAccount resource being referred to.
  32390. maxLength: 253
  32391. minLength: 1
  32392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32393. type: string
  32394. namespace:
  32395. description: |-
  32396. Namespace of the resource being referred to.
  32397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32398. maxLength: 63
  32399. minLength: 1
  32400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32401. type: string
  32402. required:
  32403. - name
  32404. type: object
  32405. required:
  32406. - serviceAccountRef
  32407. type: object
  32408. path:
  32409. default: jwt
  32410. description: |-
  32411. Path where the JWT authentication backend is mounted
  32412. in Vault, e.g: "jwt"
  32413. type: string
  32414. role:
  32415. description: |-
  32416. Role is a JWT role to authenticate using the JWT/OIDC Vault
  32417. authentication method
  32418. type: string
  32419. secretRef:
  32420. description: |-
  32421. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  32422. authenticate with Vault using the JWT/OIDC authentication method.
  32423. properties:
  32424. key:
  32425. description: |-
  32426. A key in the referenced Secret.
  32427. Some instances of this field may be defaulted, in others it may be required.
  32428. maxLength: 253
  32429. minLength: 1
  32430. pattern: ^[-._a-zA-Z0-9]+$
  32431. type: string
  32432. name:
  32433. description: The name of the Secret resource being referred to.
  32434. maxLength: 253
  32435. minLength: 1
  32436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32437. type: string
  32438. namespace:
  32439. description: |-
  32440. The namespace of the Secret resource being referred to.
  32441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32442. maxLength: 63
  32443. minLength: 1
  32444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32445. type: string
  32446. type: object
  32447. required:
  32448. - path
  32449. type: object
  32450. kubernetes:
  32451. description: |-
  32452. Kubernetes authenticates with Vault by passing the ServiceAccount
  32453. token stored in the named Secret resource to the Vault server.
  32454. properties:
  32455. mountPath:
  32456. default: kubernetes
  32457. description: |-
  32458. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  32459. "kubernetes"
  32460. type: string
  32461. role:
  32462. description: |-
  32463. A required field containing the Vault Role to assume. A Role binds a
  32464. Kubernetes ServiceAccount with a set of Vault policies.
  32465. type: string
  32466. secretRef:
  32467. description: |-
  32468. Optional secret field containing a Kubernetes ServiceAccount JWT used
  32469. for authenticating with Vault. If a name is specified without a key,
  32470. `token` is the default. If one is not specified, the one bound to
  32471. the controller will be used.
  32472. properties:
  32473. key:
  32474. description: |-
  32475. A key in the referenced Secret.
  32476. Some instances of this field may be defaulted, in others it may be required.
  32477. maxLength: 253
  32478. minLength: 1
  32479. pattern: ^[-._a-zA-Z0-9]+$
  32480. type: string
  32481. name:
  32482. description: The name of the Secret resource being referred to.
  32483. maxLength: 253
  32484. minLength: 1
  32485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32486. type: string
  32487. namespace:
  32488. description: |-
  32489. The namespace of the Secret resource being referred to.
  32490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32491. maxLength: 63
  32492. minLength: 1
  32493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32494. type: string
  32495. type: object
  32496. serviceAccountRef:
  32497. description: |-
  32498. Optional service account field containing the name of a kubernetes ServiceAccount.
  32499. If the service account is specified, the service account secret token JWT will be used
  32500. for authenticating with Vault. If the service account selector is not supplied,
  32501. the secretRef will be used instead.
  32502. properties:
  32503. audiences:
  32504. description: |-
  32505. Audience specifies the `aud` claim for the service account token
  32506. Some providers automatically extend the audience field based on well-known annotations for workload
  32507. identity (e.g. IRSA or GCP Workload Identity)
  32508. items:
  32509. type: string
  32510. type: array
  32511. name:
  32512. description: The name of the ServiceAccount resource being referred to.
  32513. maxLength: 253
  32514. minLength: 1
  32515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32516. type: string
  32517. namespace:
  32518. description: |-
  32519. Namespace of the resource being referred to.
  32520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32521. maxLength: 63
  32522. minLength: 1
  32523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32524. type: string
  32525. required:
  32526. - name
  32527. type: object
  32528. required:
  32529. - mountPath
  32530. - role
  32531. type: object
  32532. ldap:
  32533. description: |-
  32534. Ldap authenticates with Vault by passing username/password pair using
  32535. the LDAP authentication method
  32536. properties:
  32537. path:
  32538. default: ldap
  32539. description: |-
  32540. Path where the LDAP authentication backend is mounted
  32541. in Vault, e.g: "ldap"
  32542. type: string
  32543. secretRef:
  32544. description: |-
  32545. SecretRef to a key in a Secret resource containing password for the LDAP
  32546. user used to authenticate with Vault using the LDAP authentication
  32547. method
  32548. properties:
  32549. key:
  32550. description: |-
  32551. A key in the referenced Secret.
  32552. Some instances of this field may be defaulted, in others it may be required.
  32553. maxLength: 253
  32554. minLength: 1
  32555. pattern: ^[-._a-zA-Z0-9]+$
  32556. type: string
  32557. name:
  32558. description: The name of the Secret resource being referred to.
  32559. maxLength: 253
  32560. minLength: 1
  32561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32562. type: string
  32563. namespace:
  32564. description: |-
  32565. The namespace of the Secret resource being referred to.
  32566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32567. maxLength: 63
  32568. minLength: 1
  32569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32570. type: string
  32571. type: object
  32572. username:
  32573. description: |-
  32574. Username is an LDAP username used to authenticate using the LDAP Vault
  32575. authentication method
  32576. type: string
  32577. required:
  32578. - path
  32579. - username
  32580. type: object
  32581. namespace:
  32582. description: |-
  32583. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32584. Namespaces is a set of features within Vault Enterprise that allows
  32585. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32586. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32587. This will default to Vault.Namespace field if set, or empty otherwise
  32588. type: string
  32589. tokenSecretRef:
  32590. description: TokenSecretRef authenticates with Vault by presenting a token.
  32591. properties:
  32592. key:
  32593. description: |-
  32594. A key in the referenced Secret.
  32595. Some instances of this field may be defaulted, in others it may be required.
  32596. maxLength: 253
  32597. minLength: 1
  32598. pattern: ^[-._a-zA-Z0-9]+$
  32599. type: string
  32600. name:
  32601. description: The name of the Secret resource being referred to.
  32602. maxLength: 253
  32603. minLength: 1
  32604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32605. type: string
  32606. namespace:
  32607. description: |-
  32608. The namespace of the Secret resource being referred to.
  32609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32610. maxLength: 63
  32611. minLength: 1
  32612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32613. type: string
  32614. type: object
  32615. userPass:
  32616. description: UserPass authenticates with Vault by passing username/password pair
  32617. properties:
  32618. path:
  32619. default: userpass
  32620. description: |-
  32621. Path where the UserPassword authentication backend is mounted
  32622. in Vault, e.g: "userpass"
  32623. type: string
  32624. secretRef:
  32625. description: |-
  32626. SecretRef to a key in a Secret resource containing password for the
  32627. user used to authenticate with Vault using the UserPass authentication
  32628. method
  32629. properties:
  32630. key:
  32631. description: |-
  32632. A key in the referenced Secret.
  32633. Some instances of this field may be defaulted, in others it may be required.
  32634. maxLength: 253
  32635. minLength: 1
  32636. pattern: ^[-._a-zA-Z0-9]+$
  32637. type: string
  32638. name:
  32639. description: The name of the Secret resource being referred to.
  32640. maxLength: 253
  32641. minLength: 1
  32642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32643. type: string
  32644. namespace:
  32645. description: |-
  32646. The namespace of the Secret resource being referred to.
  32647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32648. maxLength: 63
  32649. minLength: 1
  32650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32651. type: string
  32652. type: object
  32653. username:
  32654. description: |-
  32655. Username is a username used to authenticate using the UserPass Vault
  32656. authentication method
  32657. type: string
  32658. required:
  32659. - path
  32660. - username
  32661. type: object
  32662. type: object
  32663. caBundle:
  32664. description: |-
  32665. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32666. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32667. plain HTTP protocol connection. If not set the system root certificates
  32668. are used to validate the TLS connection.
  32669. format: byte
  32670. type: string
  32671. caProvider:
  32672. description: The provider for the CA bundle to use to validate Vault server certificate.
  32673. properties:
  32674. key:
  32675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32676. maxLength: 253
  32677. minLength: 1
  32678. pattern: ^[-._a-zA-Z0-9]+$
  32679. type: string
  32680. name:
  32681. description: The name of the object located at the provider type.
  32682. maxLength: 253
  32683. minLength: 1
  32684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32685. type: string
  32686. namespace:
  32687. description: |-
  32688. The namespace the Provider type is in.
  32689. Can only be defined when used in a ClusterSecretStore.
  32690. maxLength: 63
  32691. minLength: 1
  32692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32693. type: string
  32694. type:
  32695. description: The type of provider to use such as "Secret", or "ConfigMap".
  32696. enum:
  32697. - Secret
  32698. - ConfigMap
  32699. type: string
  32700. required:
  32701. - name
  32702. - type
  32703. type: object
  32704. checkAndSet:
  32705. description: |-
  32706. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32707. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32708. the current version of the secret to prevent unintentional overwrites.
  32709. properties:
  32710. required:
  32711. description: |-
  32712. Required when true, all write operations must include a check-and-set parameter.
  32713. This helps prevent unintentional overwrites of secrets.
  32714. type: boolean
  32715. type: object
  32716. forwardInconsistent:
  32717. description: |-
  32718. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32719. leader instead of simply retrying within a loop. This can increase performance if
  32720. the option is enabled serverside.
  32721. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32722. type: boolean
  32723. headers:
  32724. additionalProperties:
  32725. type: string
  32726. description: Headers to be added in Vault request
  32727. type: object
  32728. namespace:
  32729. description: |-
  32730. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32731. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32732. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32733. type: string
  32734. path:
  32735. description: |-
  32736. Path is the mount path of the Vault KV backend endpoint, e.g:
  32737. "secret". The v2 KV secret engine version specific "/data" path suffix
  32738. for fetching secrets from Vault is optional and will be appended
  32739. if not present in specified path.
  32740. type: string
  32741. readYourWrites:
  32742. description: |-
  32743. ReadYourWrites ensures isolated read-after-write semantics by
  32744. providing discovered cluster replication states in each request.
  32745. More information about eventual consistency in Vault can be found here
  32746. https://www.vaultproject.io/docs/enterprise/consistency
  32747. type: boolean
  32748. server:
  32749. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32750. type: string
  32751. tls:
  32752. description: |-
  32753. The configuration used for client side related TLS communication, when the Vault server
  32754. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32755. This parameter is ignored for plain HTTP protocol connection.
  32756. It's worth noting this configuration is different from the "TLS certificates auth method",
  32757. which is available under the `auth.cert` section.
  32758. properties:
  32759. certSecretRef:
  32760. description: |-
  32761. CertSecretRef is a certificate added to the transport layer
  32762. when communicating with the Vault server.
  32763. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32764. properties:
  32765. key:
  32766. description: |-
  32767. A key in the referenced Secret.
  32768. Some instances of this field may be defaulted, in others it may be required.
  32769. maxLength: 253
  32770. minLength: 1
  32771. pattern: ^[-._a-zA-Z0-9]+$
  32772. type: string
  32773. name:
  32774. description: The name of the Secret resource being referred to.
  32775. maxLength: 253
  32776. minLength: 1
  32777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32778. type: string
  32779. namespace:
  32780. description: |-
  32781. The namespace of the Secret resource being referred to.
  32782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32783. maxLength: 63
  32784. minLength: 1
  32785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32786. type: string
  32787. type: object
  32788. keySecretRef:
  32789. description: |-
  32790. KeySecretRef to a key in a Secret resource containing client private key
  32791. added to the transport layer when communicating with the Vault server.
  32792. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32793. properties:
  32794. key:
  32795. description: |-
  32796. A key in the referenced Secret.
  32797. Some instances of this field may be defaulted, in others it may be required.
  32798. maxLength: 253
  32799. minLength: 1
  32800. pattern: ^[-._a-zA-Z0-9]+$
  32801. type: string
  32802. name:
  32803. description: The name of the Secret resource being referred to.
  32804. maxLength: 253
  32805. minLength: 1
  32806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32807. type: string
  32808. namespace:
  32809. description: |-
  32810. The namespace of the Secret resource being referred to.
  32811. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32812. maxLength: 63
  32813. minLength: 1
  32814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32815. type: string
  32816. type: object
  32817. type: object
  32818. version:
  32819. default: v2
  32820. description: |-
  32821. Version is the Vault KV secret engine version. This can be either "v1" or
  32822. "v2". Version defaults to "v2".
  32823. enum:
  32824. - v1
  32825. - v2
  32826. type: string
  32827. required:
  32828. - server
  32829. type: object
  32830. resultType:
  32831. default: Data
  32832. description: |-
  32833. Result type defines which data is returned from the generator.
  32834. By default, it is the "data" section of the Vault API response.
  32835. When using e.g. /auth/token/create the "data" section is empty but
  32836. the "auth" section contains the generated token.
  32837. Please refer to the vault docs regarding the result data structure.
  32838. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32839. enum:
  32840. - Data
  32841. - Auth
  32842. - Raw
  32843. type: string
  32844. retrySettings:
  32845. description: Used to configure http retries if failed
  32846. properties:
  32847. maxRetries:
  32848. format: int32
  32849. type: integer
  32850. retryInterval:
  32851. type: string
  32852. type: object
  32853. required:
  32854. - path
  32855. - provider
  32856. type: object
  32857. type: object
  32858. served: true
  32859. storage: true
  32860. subresources:
  32861. status: {}
  32862. ---
  32863. apiVersion: apiextensions.k8s.io/v1
  32864. kind: CustomResourceDefinition
  32865. metadata:
  32866. annotations:
  32867. controller-gen.kubebuilder.io/version: v0.19.0
  32868. labels:
  32869. external-secrets.io/component: controller
  32870. name: webhooks.generators.external-secrets.io
  32871. spec:
  32872. group: generators.external-secrets.io
  32873. names:
  32874. categories:
  32875. - external-secrets
  32876. - external-secrets-generators
  32877. kind: Webhook
  32878. listKind: WebhookList
  32879. plural: webhooks
  32880. singular: webhook
  32881. scope: Namespaced
  32882. versions:
  32883. - name: v1alpha1
  32884. schema:
  32885. openAPIV3Schema:
  32886. description: |-
  32887. Webhook connects to a third party API server to handle the secrets generation
  32888. configuration parameters in spec.
  32889. You can specify the server, the token, and additional body parameters.
  32890. See documentation for the full API specification for requests and responses.
  32891. properties:
  32892. apiVersion:
  32893. description: |-
  32894. APIVersion defines the versioned schema of this representation of an object.
  32895. Servers should convert recognized schemas to the latest internal value, and
  32896. may reject unrecognized values.
  32897. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32898. type: string
  32899. kind:
  32900. description: |-
  32901. Kind is a string value representing the REST resource this object represents.
  32902. Servers may infer this from the endpoint the client submits requests to.
  32903. Cannot be updated.
  32904. In CamelCase.
  32905. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32906. type: string
  32907. metadata:
  32908. type: object
  32909. spec:
  32910. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32911. properties:
  32912. auth:
  32913. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32914. maxProperties: 1
  32915. minProperties: 1
  32916. properties:
  32917. ntlm:
  32918. description: NTLMProtocol configures the store to use NTLM for auth
  32919. properties:
  32920. passwordSecret:
  32921. description: |-
  32922. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32923. In some instances, `key` is a required field.
  32924. properties:
  32925. key:
  32926. description: |-
  32927. A key in the referenced Secret.
  32928. Some instances of this field may be defaulted, in others it may be required.
  32929. maxLength: 253
  32930. minLength: 1
  32931. pattern: ^[-._a-zA-Z0-9]+$
  32932. type: string
  32933. name:
  32934. description: The name of the Secret resource being referred to.
  32935. maxLength: 253
  32936. minLength: 1
  32937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32938. type: string
  32939. namespace:
  32940. description: |-
  32941. The namespace of the Secret resource being referred to.
  32942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32943. maxLength: 63
  32944. minLength: 1
  32945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32946. type: string
  32947. type: object
  32948. usernameSecret:
  32949. description: |-
  32950. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32951. In some instances, `key` is a required field.
  32952. properties:
  32953. key:
  32954. description: |-
  32955. A key in the referenced Secret.
  32956. Some instances of this field may be defaulted, in others it may be required.
  32957. maxLength: 253
  32958. minLength: 1
  32959. pattern: ^[-._a-zA-Z0-9]+$
  32960. type: string
  32961. name:
  32962. description: The name of the Secret resource being referred to.
  32963. maxLength: 253
  32964. minLength: 1
  32965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32966. type: string
  32967. namespace:
  32968. description: |-
  32969. The namespace of the Secret resource being referred to.
  32970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32971. maxLength: 63
  32972. minLength: 1
  32973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32974. type: string
  32975. type: object
  32976. required:
  32977. - passwordSecret
  32978. - usernameSecret
  32979. type: object
  32980. type: object
  32981. body:
  32982. description: Body
  32983. type: string
  32984. caBundle:
  32985. description: |-
  32986. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32987. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32988. plain HTTP protocol connection. If not set the system root certificates
  32989. are used to validate the TLS connection.
  32990. format: byte
  32991. type: string
  32992. caProvider:
  32993. description: The provider for the CA bundle to use to validate webhook server certificate.
  32994. properties:
  32995. key:
  32996. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32997. maxLength: 253
  32998. minLength: 1
  32999. pattern: ^[-._a-zA-Z0-9]+$
  33000. type: string
  33001. name:
  33002. description: The name of the object located at the provider type.
  33003. maxLength: 253
  33004. minLength: 1
  33005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  33006. type: string
  33007. namespace:
  33008. description: The namespace the Provider type is in.
  33009. maxLength: 63
  33010. minLength: 1
  33011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  33012. type: string
  33013. type:
  33014. description: The type of provider to use such as "Secret", or "ConfigMap".
  33015. enum:
  33016. - Secret
  33017. - ConfigMap
  33018. type: string
  33019. required:
  33020. - name
  33021. - type
  33022. type: object
  33023. headers:
  33024. additionalProperties:
  33025. type: string
  33026. description: Headers
  33027. type: object
  33028. method:
  33029. description: Webhook Method
  33030. type: string
  33031. result:
  33032. description: Result formatting
  33033. properties:
  33034. jsonPath:
  33035. description: Json path of return value
  33036. type: string
  33037. type: object
  33038. secrets:
  33039. description: |-
  33040. Secrets to fill in templates
  33041. These secrets will be passed to the templating function as key value pairs under the given name
  33042. items:
  33043. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  33044. properties:
  33045. name:
  33046. description: Name of this secret in templates
  33047. type: string
  33048. secretRef:
  33049. description: Secret ref to fill in credentials
  33050. properties:
  33051. key:
  33052. description: The key where the token is found.
  33053. maxLength: 253
  33054. minLength: 1
  33055. pattern: ^[-._a-zA-Z0-9]+$
  33056. type: string
  33057. name:
  33058. description: The name of the Secret resource being referred to.
  33059. maxLength: 253
  33060. minLength: 1
  33061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  33062. type: string
  33063. type: object
  33064. required:
  33065. - name
  33066. - secretRef
  33067. type: object
  33068. type: array
  33069. timeout:
  33070. description: Timeout
  33071. type: string
  33072. url:
  33073. description: Webhook url to call
  33074. type: string
  33075. required:
  33076. - result
  33077. - url
  33078. type: object
  33079. type: object
  33080. served: true
  33081. storage: true
  33082. subresources:
  33083. status: {}