bundle.yaml 1.8 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. type: string
  561. deletionPolicy:
  562. default: Retain
  563. description: |-
  564. DeletionPolicy defines rules on how to delete the resulting Secret.
  565. Defaults to "Retain"
  566. enum:
  567. - Delete
  568. - Merge
  569. - Retain
  570. type: string
  571. immutable:
  572. description: Immutable defines if the final secret will be immutable
  573. type: boolean
  574. manifest:
  575. description: |-
  576. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  577. When specified, ExternalSecret will create the resource type defined here
  578. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  579. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  580. properties:
  581. apiVersion:
  582. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  583. minLength: 1
  584. type: string
  585. kind:
  586. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  587. minLength: 1
  588. type: string
  589. required:
  590. - apiVersion
  591. - kind
  592. type: object
  593. name:
  594. description: |-
  595. The name of the Secret resource to be managed.
  596. Defaults to the .metadata.name of the ExternalSecret resource
  597. maxLength: 253
  598. minLength: 1
  599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  600. type: string
  601. template:
  602. description: Template defines a blueprint for the created Secret resource.
  603. properties:
  604. data:
  605. additionalProperties:
  606. type: string
  607. type: object
  608. engineVersion:
  609. default: v2
  610. description: |-
  611. EngineVersion specifies the template engine version
  612. that should be used to compile/execute the
  613. template specified in .data and .templateFrom[].
  614. enum:
  615. - v2
  616. type: string
  617. mergePolicy:
  618. default: Replace
  619. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  620. enum:
  621. - Replace
  622. - Merge
  623. type: string
  624. metadata:
  625. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  626. properties:
  627. annotations:
  628. additionalProperties:
  629. type: string
  630. type: object
  631. finalizers:
  632. items:
  633. type: string
  634. type: array
  635. labels:
  636. additionalProperties:
  637. type: string
  638. type: object
  639. type: object
  640. templateFrom:
  641. items:
  642. description: |-
  643. TemplateFrom specifies a source for templates.
  644. Each item in the list can either reference a ConfigMap or a Secret resource.
  645. properties:
  646. configMap:
  647. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  648. properties:
  649. items:
  650. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  651. items:
  652. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  653. properties:
  654. key:
  655. description: A key in the ConfigMap/Secret
  656. maxLength: 253
  657. minLength: 1
  658. pattern: ^[-._a-zA-Z0-9]+$
  659. type: string
  660. templateAs:
  661. default: Values
  662. description: TemplateScope specifies how the template keys should be interpreted.
  663. enum:
  664. - Values
  665. - KeysAndValues
  666. type: string
  667. required:
  668. - key
  669. type: object
  670. type: array
  671. name:
  672. description: The name of the ConfigMap/Secret resource
  673. maxLength: 253
  674. minLength: 1
  675. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  676. type: string
  677. required:
  678. - items
  679. - name
  680. type: object
  681. literal:
  682. type: string
  683. secret:
  684. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  685. properties:
  686. items:
  687. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  688. items:
  689. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  690. properties:
  691. key:
  692. description: A key in the ConfigMap/Secret
  693. maxLength: 253
  694. minLength: 1
  695. pattern: ^[-._a-zA-Z0-9]+$
  696. type: string
  697. templateAs:
  698. default: Values
  699. description: TemplateScope specifies how the template keys should be interpreted.
  700. enum:
  701. - Values
  702. - KeysAndValues
  703. type: string
  704. required:
  705. - key
  706. type: object
  707. type: array
  708. name:
  709. description: The name of the ConfigMap/Secret resource
  710. maxLength: 253
  711. minLength: 1
  712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  713. type: string
  714. required:
  715. - items
  716. - name
  717. type: object
  718. target:
  719. default: Data
  720. description: |-
  721. Target specifies where to place the template result.
  722. For Secret resources, common values are: "Data", "Annotations", "Labels".
  723. For custom resources (when spec.target.manifest is set), this supports
  724. nested paths like "spec.database.config" or "data".
  725. type: string
  726. valuesDecodingStrategy:
  727. default: None
  728. description: Used to define a decoding Strategy for the rendered template values.
  729. enum:
  730. - Auto
  731. - Base64
  732. - Base64URL
  733. - None
  734. type: string
  735. type: object
  736. type: array
  737. type:
  738. type: string
  739. type: object
  740. type: object
  741. type: object
  742. namespaceSelector:
  743. description: |-
  744. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  745. Deprecated: Use NamespaceSelectors instead.
  746. properties:
  747. matchExpressions:
  748. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  749. items:
  750. description: |-
  751. A label selector requirement is a selector that contains values, a key, and an operator that
  752. relates the key and values.
  753. properties:
  754. key:
  755. description: key is the label key that the selector applies to.
  756. type: string
  757. operator:
  758. description: |-
  759. operator represents a key's relationship to a set of values.
  760. Valid operators are In, NotIn, Exists and DoesNotExist.
  761. type: string
  762. values:
  763. description: |-
  764. values is an array of string values. If the operator is In or NotIn,
  765. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  766. the values array must be empty. This array is replaced during a strategic
  767. merge patch.
  768. items:
  769. type: string
  770. type: array
  771. x-kubernetes-list-type: atomic
  772. required:
  773. - key
  774. - operator
  775. type: object
  776. type: array
  777. x-kubernetes-list-type: atomic
  778. matchLabels:
  779. additionalProperties:
  780. type: string
  781. description: |-
  782. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  783. map is equivalent to an element of matchExpressions, whose key field is "key", the
  784. operator is "In", and the values array contains only "value". The requirements are ANDed.
  785. type: object
  786. type: object
  787. x-kubernetes-map-type: atomic
  788. namespaceSelectors:
  789. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  790. items:
  791. description: |-
  792. A label selector is a label query over a set of resources. The result of matchLabels and
  793. matchExpressions are ANDed. An empty label selector matches all objects. A null
  794. label selector matches no objects.
  795. properties:
  796. matchExpressions:
  797. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  798. items:
  799. description: |-
  800. A label selector requirement is a selector that contains values, a key, and an operator that
  801. relates the key and values.
  802. properties:
  803. key:
  804. description: key is the label key that the selector applies to.
  805. type: string
  806. operator:
  807. description: |-
  808. operator represents a key's relationship to a set of values.
  809. Valid operators are In, NotIn, Exists and DoesNotExist.
  810. type: string
  811. values:
  812. description: |-
  813. values is an array of string values. If the operator is In or NotIn,
  814. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  815. the values array must be empty. This array is replaced during a strategic
  816. merge patch.
  817. items:
  818. type: string
  819. type: array
  820. x-kubernetes-list-type: atomic
  821. required:
  822. - key
  823. - operator
  824. type: object
  825. type: array
  826. x-kubernetes-list-type: atomic
  827. matchLabels:
  828. additionalProperties:
  829. type: string
  830. description: |-
  831. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  832. map is equivalent to an element of matchExpressions, whose key field is "key", the
  833. operator is "In", and the values array contains only "value". The requirements are ANDed.
  834. type: object
  835. type: object
  836. x-kubernetes-map-type: atomic
  837. type: array
  838. namespaces:
  839. description: |-
  840. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  841. Deprecated: Use NamespaceSelectors instead.
  842. items:
  843. maxLength: 63
  844. minLength: 1
  845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  846. type: string
  847. type: array
  848. refreshTime:
  849. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  850. type: string
  851. required:
  852. - externalSecretSpec
  853. type: object
  854. status:
  855. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  856. properties:
  857. conditions:
  858. items:
  859. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  860. properties:
  861. message:
  862. type: string
  863. status:
  864. type: string
  865. type:
  866. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  867. type: string
  868. required:
  869. - status
  870. - type
  871. type: object
  872. type: array
  873. externalSecretName:
  874. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  875. type: string
  876. failedNamespaces:
  877. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  878. items:
  879. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  880. properties:
  881. namespace:
  882. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  883. type: string
  884. reason:
  885. description: Reason is why the ExternalSecret failed to apply to the namespace
  886. type: string
  887. required:
  888. - namespace
  889. type: object
  890. type: array
  891. provisionedNamespaces:
  892. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  893. items:
  894. type: string
  895. type: array
  896. type: object
  897. type: object
  898. served: true
  899. storage: true
  900. subresources:
  901. status: {}
  902. - additionalPrinterColumns:
  903. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  904. name: Store
  905. type: string
  906. - jsonPath: .spec.refreshTime
  907. name: Refresh Interval
  908. type: string
  909. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  910. name: Ready
  911. type: string
  912. deprecated: true
  913. name: v1beta1
  914. schema:
  915. openAPIV3Schema:
  916. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  917. properties:
  918. apiVersion:
  919. description: |-
  920. APIVersion defines the versioned schema of this representation of an object.
  921. Servers should convert recognized schemas to the latest internal value, and
  922. may reject unrecognized values.
  923. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  924. type: string
  925. kind:
  926. description: |-
  927. Kind is a string value representing the REST resource this object represents.
  928. Servers may infer this from the endpoint the client submits requests to.
  929. Cannot be updated.
  930. In CamelCase.
  931. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  932. type: string
  933. metadata:
  934. type: object
  935. spec:
  936. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  937. properties:
  938. externalSecretMetadata:
  939. description: The metadata of the external secrets to be created
  940. properties:
  941. annotations:
  942. additionalProperties:
  943. type: string
  944. type: object
  945. labels:
  946. additionalProperties:
  947. type: string
  948. type: object
  949. type: object
  950. externalSecretName:
  951. description: |-
  952. The name of the external secrets to be created.
  953. Defaults to the name of the ClusterExternalSecret
  954. maxLength: 253
  955. minLength: 1
  956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  957. type: string
  958. externalSecretSpec:
  959. description: The spec for the ExternalSecrets to be created
  960. properties:
  961. data:
  962. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  963. items:
  964. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  965. properties:
  966. remoteRef:
  967. description: |-
  968. RemoteRef points to the remote secret and defines
  969. which secret (version/property/..) to fetch.
  970. properties:
  971. conversionStrategy:
  972. default: Default
  973. description: Used to define a conversion Strategy
  974. enum:
  975. - Default
  976. - Unicode
  977. type: string
  978. decodingStrategy:
  979. default: None
  980. description: Used to define a decoding Strategy
  981. enum:
  982. - Auto
  983. - Base64
  984. - Base64URL
  985. - None
  986. type: string
  987. key:
  988. description: Key is the key used in the Provider, mandatory
  989. type: string
  990. metadataPolicy:
  991. default: None
  992. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  993. enum:
  994. - None
  995. - Fetch
  996. type: string
  997. property:
  998. description: Used to select a specific property of the Provider value (if a map), if supported
  999. type: string
  1000. version:
  1001. description: Used to select a specific version of the Provider value, if supported
  1002. type: string
  1003. required:
  1004. - key
  1005. type: object
  1006. secretKey:
  1007. description: The key in the Kubernetes Secret to store the value.
  1008. maxLength: 253
  1009. minLength: 1
  1010. pattern: ^[-._a-zA-Z0-9]+$
  1011. type: string
  1012. sourceRef:
  1013. description: |-
  1014. SourceRef allows you to override the source
  1015. from which the value will be pulled.
  1016. maxProperties: 1
  1017. minProperties: 1
  1018. properties:
  1019. generatorRef:
  1020. description: |-
  1021. GeneratorRef points to a generator custom resource.
  1022. Deprecated: The generatorRef is not implemented in .data[].
  1023. this will be removed with v1.
  1024. properties:
  1025. apiVersion:
  1026. default: generators.external-secrets.io/v1alpha1
  1027. description: Specify the apiVersion of the generator resource
  1028. type: string
  1029. kind:
  1030. description: Specify the Kind of the generator resource
  1031. enum:
  1032. - ACRAccessToken
  1033. - ClusterGenerator
  1034. - ECRAuthorizationToken
  1035. - Fake
  1036. - GCRAccessToken
  1037. - GithubAccessToken
  1038. - QuayAccessToken
  1039. - Password
  1040. - SSHKey
  1041. - STSSessionToken
  1042. - UUID
  1043. - VaultDynamicSecret
  1044. - Webhook
  1045. - Grafana
  1046. type: string
  1047. name:
  1048. description: Specify the name of the generator resource
  1049. maxLength: 253
  1050. minLength: 1
  1051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1052. type: string
  1053. required:
  1054. - kind
  1055. - name
  1056. type: object
  1057. storeRef:
  1058. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1059. properties:
  1060. kind:
  1061. description: |-
  1062. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1063. Defaults to `SecretStore`
  1064. enum:
  1065. - SecretStore
  1066. - ClusterSecretStore
  1067. type: string
  1068. name:
  1069. description: Name of the SecretStore resource
  1070. maxLength: 253
  1071. minLength: 1
  1072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1073. type: string
  1074. type: object
  1075. type: object
  1076. required:
  1077. - remoteRef
  1078. - secretKey
  1079. type: object
  1080. type: array
  1081. dataFrom:
  1082. description: |-
  1083. DataFrom is used to fetch all properties from a specific Provider data
  1084. If multiple entries are specified, the Secret keys are merged in the specified order
  1085. items:
  1086. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1087. properties:
  1088. extract:
  1089. description: |-
  1090. Used to extract multiple key/value pairs from one secret
  1091. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1092. properties:
  1093. conversionStrategy:
  1094. default: Default
  1095. description: Used to define a conversion Strategy
  1096. enum:
  1097. - Default
  1098. - Unicode
  1099. type: string
  1100. decodingStrategy:
  1101. default: None
  1102. description: Used to define a decoding Strategy
  1103. enum:
  1104. - Auto
  1105. - Base64
  1106. - Base64URL
  1107. - None
  1108. type: string
  1109. key:
  1110. description: Key is the key used in the Provider, mandatory
  1111. type: string
  1112. metadataPolicy:
  1113. default: None
  1114. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1115. enum:
  1116. - None
  1117. - Fetch
  1118. type: string
  1119. property:
  1120. description: Used to select a specific property of the Provider value (if a map), if supported
  1121. type: string
  1122. version:
  1123. description: Used to select a specific version of the Provider value, if supported
  1124. type: string
  1125. required:
  1126. - key
  1127. type: object
  1128. find:
  1129. description: |-
  1130. Used to find secrets based on tags or regular expressions
  1131. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1132. properties:
  1133. conversionStrategy:
  1134. default: Default
  1135. description: Used to define a conversion Strategy
  1136. enum:
  1137. - Default
  1138. - Unicode
  1139. type: string
  1140. decodingStrategy:
  1141. default: None
  1142. description: Used to define a decoding Strategy
  1143. enum:
  1144. - Auto
  1145. - Base64
  1146. - Base64URL
  1147. - None
  1148. type: string
  1149. name:
  1150. description: Finds secrets based on the name.
  1151. properties:
  1152. regexp:
  1153. description: Finds secrets base
  1154. type: string
  1155. type: object
  1156. path:
  1157. description: A root path to start the find operations.
  1158. type: string
  1159. tags:
  1160. additionalProperties:
  1161. type: string
  1162. description: Find secrets based on tags.
  1163. type: object
  1164. type: object
  1165. rewrite:
  1166. description: |-
  1167. Used to rewrite secret Keys after getting them from the secret Provider
  1168. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1169. items:
  1170. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1171. maxProperties: 1
  1172. minProperties: 1
  1173. properties:
  1174. regexp:
  1175. description: |-
  1176. Used to rewrite with regular expressions.
  1177. The resulting key will be the output of a regexp.ReplaceAll operation.
  1178. properties:
  1179. source:
  1180. description: Used to define the regular expression of a re.Compiler.
  1181. type: string
  1182. target:
  1183. description: Used to define the target pattern of a ReplaceAll operation.
  1184. type: string
  1185. required:
  1186. - source
  1187. - target
  1188. type: object
  1189. transform:
  1190. description: |-
  1191. Used to apply string transformation on the secrets.
  1192. The resulting key will be the output of the template applied by the operation.
  1193. properties:
  1194. template:
  1195. description: |-
  1196. Used to define the template to apply on the secret name.
  1197. `.value ` will specify the secret name in the template.
  1198. type: string
  1199. required:
  1200. - template
  1201. type: object
  1202. type: object
  1203. type: array
  1204. sourceRef:
  1205. description: |-
  1206. SourceRef points to a store or generator
  1207. which contains secret values ready to use.
  1208. Use this in combination with Extract or Find pull values out of
  1209. a specific SecretStore.
  1210. When sourceRef points to a generator Extract or Find is not supported.
  1211. The generator returns a static map of values
  1212. maxProperties: 1
  1213. minProperties: 1
  1214. properties:
  1215. generatorRef:
  1216. description: GeneratorRef points to a generator custom resource.
  1217. properties:
  1218. apiVersion:
  1219. default: generators.external-secrets.io/v1alpha1
  1220. description: Specify the apiVersion of the generator resource
  1221. type: string
  1222. kind:
  1223. description: Specify the Kind of the generator resource
  1224. enum:
  1225. - ACRAccessToken
  1226. - ClusterGenerator
  1227. - ECRAuthorizationToken
  1228. - Fake
  1229. - GCRAccessToken
  1230. - GithubAccessToken
  1231. - QuayAccessToken
  1232. - Password
  1233. - SSHKey
  1234. - STSSessionToken
  1235. - UUID
  1236. - VaultDynamicSecret
  1237. - Webhook
  1238. - Grafana
  1239. type: string
  1240. name:
  1241. description: Specify the name of the generator resource
  1242. maxLength: 253
  1243. minLength: 1
  1244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1245. type: string
  1246. required:
  1247. - kind
  1248. - name
  1249. type: object
  1250. storeRef:
  1251. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1252. properties:
  1253. kind:
  1254. description: |-
  1255. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1256. Defaults to `SecretStore`
  1257. enum:
  1258. - SecretStore
  1259. - ClusterSecretStore
  1260. type: string
  1261. name:
  1262. description: Name of the SecretStore resource
  1263. maxLength: 253
  1264. minLength: 1
  1265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1266. type: string
  1267. type: object
  1268. type: object
  1269. type: object
  1270. type: array
  1271. refreshInterval:
  1272. default: 1h0m0s
  1273. description: |-
  1274. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1275. specified as Golang Duration strings.
  1276. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1277. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1278. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1279. type: string
  1280. refreshPolicy:
  1281. description: |-
  1282. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1283. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1284. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1285. No periodic updates occur if refreshInterval is 0.
  1286. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1287. enum:
  1288. - CreatedOnce
  1289. - Periodic
  1290. - OnChange
  1291. type: string
  1292. secretStoreRef:
  1293. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1294. properties:
  1295. kind:
  1296. description: |-
  1297. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1298. Defaults to `SecretStore`
  1299. enum:
  1300. - SecretStore
  1301. - ClusterSecretStore
  1302. type: string
  1303. name:
  1304. description: Name of the SecretStore resource
  1305. maxLength: 253
  1306. minLength: 1
  1307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1308. type: string
  1309. type: object
  1310. target:
  1311. default:
  1312. creationPolicy: Owner
  1313. deletionPolicy: Retain
  1314. description: |-
  1315. ExternalSecretTarget defines the Kubernetes Secret to be created
  1316. There can be only one target per ExternalSecret.
  1317. properties:
  1318. creationPolicy:
  1319. default: Owner
  1320. description: |-
  1321. CreationPolicy defines rules on how to create the resulting Secret.
  1322. Defaults to "Owner"
  1323. enum:
  1324. - Owner
  1325. - Orphan
  1326. - Merge
  1327. - None
  1328. type: string
  1329. deletionPolicy:
  1330. default: Retain
  1331. description: |-
  1332. DeletionPolicy defines rules on how to delete the resulting Secret.
  1333. Defaults to "Retain"
  1334. enum:
  1335. - Delete
  1336. - Merge
  1337. - Retain
  1338. type: string
  1339. immutable:
  1340. description: Immutable defines if the final secret will be immutable
  1341. type: boolean
  1342. name:
  1343. description: |-
  1344. The name of the Secret resource to be managed.
  1345. Defaults to the .metadata.name of the ExternalSecret resource
  1346. maxLength: 253
  1347. minLength: 1
  1348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1349. type: string
  1350. template:
  1351. description: Template defines a blueprint for the created Secret resource.
  1352. properties:
  1353. data:
  1354. additionalProperties:
  1355. type: string
  1356. type: object
  1357. engineVersion:
  1358. default: v2
  1359. description: |-
  1360. EngineVersion specifies the template engine version
  1361. that should be used to compile/execute the
  1362. template specified in .data and .templateFrom[].
  1363. enum:
  1364. - v2
  1365. type: string
  1366. mergePolicy:
  1367. default: Replace
  1368. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1369. enum:
  1370. - Replace
  1371. - Merge
  1372. type: string
  1373. metadata:
  1374. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1375. properties:
  1376. annotations:
  1377. additionalProperties:
  1378. type: string
  1379. type: object
  1380. labels:
  1381. additionalProperties:
  1382. type: string
  1383. type: object
  1384. type: object
  1385. templateFrom:
  1386. items:
  1387. description: TemplateFrom defines a source for template data.
  1388. properties:
  1389. configMap:
  1390. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1391. properties:
  1392. items:
  1393. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1394. items:
  1395. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1396. properties:
  1397. key:
  1398. description: A key in the ConfigMap/Secret
  1399. maxLength: 253
  1400. minLength: 1
  1401. pattern: ^[-._a-zA-Z0-9]+$
  1402. type: string
  1403. templateAs:
  1404. default: Values
  1405. description: TemplateScope defines the scope of the template when processing template data.
  1406. enum:
  1407. - Values
  1408. - KeysAndValues
  1409. type: string
  1410. required:
  1411. - key
  1412. type: object
  1413. type: array
  1414. name:
  1415. description: The name of the ConfigMap/Secret resource
  1416. maxLength: 253
  1417. minLength: 1
  1418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1419. type: string
  1420. required:
  1421. - items
  1422. - name
  1423. type: object
  1424. literal:
  1425. type: string
  1426. secret:
  1427. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1428. properties:
  1429. items:
  1430. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1431. items:
  1432. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1433. properties:
  1434. key:
  1435. description: A key in the ConfigMap/Secret
  1436. maxLength: 253
  1437. minLength: 1
  1438. pattern: ^[-._a-zA-Z0-9]+$
  1439. type: string
  1440. templateAs:
  1441. default: Values
  1442. description: TemplateScope defines the scope of the template when processing template data.
  1443. enum:
  1444. - Values
  1445. - KeysAndValues
  1446. type: string
  1447. required:
  1448. - key
  1449. type: object
  1450. type: array
  1451. name:
  1452. description: The name of the ConfigMap/Secret resource
  1453. maxLength: 253
  1454. minLength: 1
  1455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1456. type: string
  1457. required:
  1458. - items
  1459. - name
  1460. type: object
  1461. target:
  1462. default: Data
  1463. description: TemplateTarget defines the target field where the template result will be stored.
  1464. enum:
  1465. - Data
  1466. - Annotations
  1467. - Labels
  1468. type: string
  1469. type: object
  1470. type: array
  1471. type:
  1472. type: string
  1473. type: object
  1474. type: object
  1475. type: object
  1476. namespaceSelector:
  1477. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1478. properties:
  1479. matchExpressions:
  1480. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1481. items:
  1482. description: |-
  1483. A label selector requirement is a selector that contains values, a key, and an operator that
  1484. relates the key and values.
  1485. properties:
  1486. key:
  1487. description: key is the label key that the selector applies to.
  1488. type: string
  1489. operator:
  1490. description: |-
  1491. operator represents a key's relationship to a set of values.
  1492. Valid operators are In, NotIn, Exists and DoesNotExist.
  1493. type: string
  1494. values:
  1495. description: |-
  1496. values is an array of string values. If the operator is In or NotIn,
  1497. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1498. the values array must be empty. This array is replaced during a strategic
  1499. merge patch.
  1500. items:
  1501. type: string
  1502. type: array
  1503. x-kubernetes-list-type: atomic
  1504. required:
  1505. - key
  1506. - operator
  1507. type: object
  1508. type: array
  1509. x-kubernetes-list-type: atomic
  1510. matchLabels:
  1511. additionalProperties:
  1512. type: string
  1513. description: |-
  1514. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1515. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1516. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1517. type: object
  1518. type: object
  1519. x-kubernetes-map-type: atomic
  1520. namespaceSelectors:
  1521. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1522. items:
  1523. description: |-
  1524. A label selector is a label query over a set of resources. The result of matchLabels and
  1525. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1526. label selector matches no objects.
  1527. properties:
  1528. matchExpressions:
  1529. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1530. items:
  1531. description: |-
  1532. A label selector requirement is a selector that contains values, a key, and an operator that
  1533. relates the key and values.
  1534. properties:
  1535. key:
  1536. description: key is the label key that the selector applies to.
  1537. type: string
  1538. operator:
  1539. description: |-
  1540. operator represents a key's relationship to a set of values.
  1541. Valid operators are In, NotIn, Exists and DoesNotExist.
  1542. type: string
  1543. values:
  1544. description: |-
  1545. values is an array of string values. If the operator is In or NotIn,
  1546. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1547. the values array must be empty. This array is replaced during a strategic
  1548. merge patch.
  1549. items:
  1550. type: string
  1551. type: array
  1552. x-kubernetes-list-type: atomic
  1553. required:
  1554. - key
  1555. - operator
  1556. type: object
  1557. type: array
  1558. x-kubernetes-list-type: atomic
  1559. matchLabels:
  1560. additionalProperties:
  1561. type: string
  1562. description: |-
  1563. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1564. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1565. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1566. type: object
  1567. type: object
  1568. x-kubernetes-map-type: atomic
  1569. type: array
  1570. namespaces:
  1571. description: |-
  1572. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1573. Deprecated: Use NamespaceSelectors instead.
  1574. items:
  1575. maxLength: 63
  1576. minLength: 1
  1577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1578. type: string
  1579. type: array
  1580. refreshTime:
  1581. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1582. type: string
  1583. required:
  1584. - externalSecretSpec
  1585. type: object
  1586. status:
  1587. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1588. properties:
  1589. conditions:
  1590. items:
  1591. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1592. properties:
  1593. message:
  1594. type: string
  1595. status:
  1596. type: string
  1597. type:
  1598. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1599. type: string
  1600. required:
  1601. - status
  1602. - type
  1603. type: object
  1604. type: array
  1605. externalSecretName:
  1606. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1607. type: string
  1608. failedNamespaces:
  1609. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1610. items:
  1611. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1612. properties:
  1613. namespace:
  1614. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1615. type: string
  1616. reason:
  1617. description: Reason is why the ExternalSecret failed to apply to the namespace
  1618. type: string
  1619. required:
  1620. - namespace
  1621. type: object
  1622. type: array
  1623. provisionedNamespaces:
  1624. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1625. items:
  1626. type: string
  1627. type: array
  1628. type: object
  1629. type: object
  1630. served: false
  1631. storage: false
  1632. subresources:
  1633. status: {}
  1634. ---
  1635. apiVersion: apiextensions.k8s.io/v1
  1636. kind: CustomResourceDefinition
  1637. metadata:
  1638. annotations:
  1639. controller-gen.kubebuilder.io/version: v0.19.0
  1640. labels:
  1641. external-secrets.io/component: controller
  1642. name: clusterpushsecrets.external-secrets.io
  1643. spec:
  1644. group: external-secrets.io
  1645. names:
  1646. categories:
  1647. - external-secrets
  1648. kind: ClusterPushSecret
  1649. listKind: ClusterPushSecretList
  1650. plural: clusterpushsecrets
  1651. singular: clusterpushsecret
  1652. scope: Cluster
  1653. versions:
  1654. - additionalPrinterColumns:
  1655. - jsonPath: .metadata.creationTimestamp
  1656. name: AGE
  1657. type: date
  1658. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1659. name: Status
  1660. type: string
  1661. name: v1alpha1
  1662. schema:
  1663. openAPIV3Schema:
  1664. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1665. properties:
  1666. apiVersion:
  1667. description: |-
  1668. APIVersion defines the versioned schema of this representation of an object.
  1669. Servers should convert recognized schemas to the latest internal value, and
  1670. may reject unrecognized values.
  1671. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1672. type: string
  1673. kind:
  1674. description: |-
  1675. Kind is a string value representing the REST resource this object represents.
  1676. Servers may infer this from the endpoint the client submits requests to.
  1677. Cannot be updated.
  1678. In CamelCase.
  1679. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1680. type: string
  1681. metadata:
  1682. type: object
  1683. spec:
  1684. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1685. properties:
  1686. namespaceSelectors:
  1687. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1688. items:
  1689. description: |-
  1690. A label selector is a label query over a set of resources. The result of matchLabels and
  1691. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1692. label selector matches no objects.
  1693. properties:
  1694. matchExpressions:
  1695. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1696. items:
  1697. description: |-
  1698. A label selector requirement is a selector that contains values, a key, and an operator that
  1699. relates the key and values.
  1700. properties:
  1701. key:
  1702. description: key is the label key that the selector applies to.
  1703. type: string
  1704. operator:
  1705. description: |-
  1706. operator represents a key's relationship to a set of values.
  1707. Valid operators are In, NotIn, Exists and DoesNotExist.
  1708. type: string
  1709. values:
  1710. description: |-
  1711. values is an array of string values. If the operator is In or NotIn,
  1712. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1713. the values array must be empty. This array is replaced during a strategic
  1714. merge patch.
  1715. items:
  1716. type: string
  1717. type: array
  1718. x-kubernetes-list-type: atomic
  1719. required:
  1720. - key
  1721. - operator
  1722. type: object
  1723. type: array
  1724. x-kubernetes-list-type: atomic
  1725. matchLabels:
  1726. additionalProperties:
  1727. type: string
  1728. description: |-
  1729. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1730. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1731. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1732. type: object
  1733. type: object
  1734. x-kubernetes-map-type: atomic
  1735. type: array
  1736. pushSecretMetadata:
  1737. description: The metadata of the external secrets to be created
  1738. properties:
  1739. annotations:
  1740. additionalProperties:
  1741. type: string
  1742. type: object
  1743. labels:
  1744. additionalProperties:
  1745. type: string
  1746. type: object
  1747. type: object
  1748. pushSecretName:
  1749. description: |-
  1750. The name of the push secrets to be created.
  1751. Defaults to the name of the ClusterPushSecret
  1752. maxLength: 253
  1753. minLength: 1
  1754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1755. type: string
  1756. pushSecretSpec:
  1757. description: PushSecretSpec defines what to do with the secrets.
  1758. properties:
  1759. data:
  1760. description: Secret Data that should be pushed to providers
  1761. items:
  1762. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1763. properties:
  1764. conversionStrategy:
  1765. default: None
  1766. description: Used to define a conversion Strategy for the secret keys
  1767. enum:
  1768. - None
  1769. - ReverseUnicode
  1770. type: string
  1771. match:
  1772. description: Match a given Secret Key to be pushed to the provider.
  1773. properties:
  1774. remoteRef:
  1775. description: Remote Refs to push to providers.
  1776. properties:
  1777. property:
  1778. description: Name of the property in the resulting secret
  1779. type: string
  1780. remoteKey:
  1781. description: Name of the resulting provider secret.
  1782. type: string
  1783. required:
  1784. - remoteKey
  1785. type: object
  1786. secretKey:
  1787. description: Secret Key to be pushed
  1788. type: string
  1789. required:
  1790. - remoteRef
  1791. type: object
  1792. metadata:
  1793. description: |-
  1794. Metadata is metadata attached to the secret.
  1795. The structure of metadata is provider specific, please look it up in the provider documentation.
  1796. x-kubernetes-preserve-unknown-fields: true
  1797. required:
  1798. - match
  1799. type: object
  1800. type: array
  1801. dataTo:
  1802. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1803. items:
  1804. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1805. properties:
  1806. conversionStrategy:
  1807. default: None
  1808. description: Used to define a conversion Strategy for the secret keys
  1809. enum:
  1810. - None
  1811. - ReverseUnicode
  1812. type: string
  1813. match:
  1814. description: |-
  1815. Match pattern for selecting keys from the source Secret.
  1816. If not specified, all keys are selected.
  1817. properties:
  1818. regexp:
  1819. description: |-
  1820. Regexp matches keys by regular expression.
  1821. If not specified, all keys are matched.
  1822. type: string
  1823. type: object
  1824. metadata:
  1825. description: |-
  1826. Metadata is metadata attached to the secret.
  1827. The structure of metadata is provider specific, please look it up in the provider documentation.
  1828. x-kubernetes-preserve-unknown-fields: true
  1829. remoteKey:
  1830. description: |-
  1831. RemoteKey is the name of the single provider secret that will receive ALL
  1832. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1833. When set, per-key expansion is skipped and a single push is performed.
  1834. The provider's store prefix (if any) is still prepended to this value.
  1835. When not set, each matched key is pushed as its own individual provider secret.
  1836. type: string
  1837. rewrite:
  1838. description: |-
  1839. Rewrite operations to transform keys before pushing to the provider.
  1840. Operations are applied sequentially.
  1841. items:
  1842. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1843. properties:
  1844. regexp:
  1845. description: Used to rewrite with regular expressions.
  1846. properties:
  1847. source:
  1848. description: Used to define the regular expression of a re.Compiler.
  1849. type: string
  1850. target:
  1851. description: Used to define the target pattern of a ReplaceAll operation.
  1852. type: string
  1853. required:
  1854. - source
  1855. - target
  1856. type: object
  1857. transform:
  1858. description: Used to apply string transformation on the secrets.
  1859. properties:
  1860. template:
  1861. description: |-
  1862. Used to define the template to apply on the secret name.
  1863. `.value ` will specify the secret name in the template.
  1864. type: string
  1865. required:
  1866. - template
  1867. type: object
  1868. type: object
  1869. x-kubernetes-validations:
  1870. - message: exactly one of regexp or transform must be set
  1871. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1872. type: array
  1873. storeRef:
  1874. description: StoreRef specifies which SecretStore to push to. Required.
  1875. properties:
  1876. kind:
  1877. default: SecretStore
  1878. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1879. enum:
  1880. - SecretStore
  1881. - ClusterSecretStore
  1882. type: string
  1883. labelSelector:
  1884. description: Optionally, sync to secret stores with label selector
  1885. properties:
  1886. matchExpressions:
  1887. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1888. items:
  1889. description: |-
  1890. A label selector requirement is a selector that contains values, a key, and an operator that
  1891. relates the key and values.
  1892. properties:
  1893. key:
  1894. description: key is the label key that the selector applies to.
  1895. type: string
  1896. operator:
  1897. description: |-
  1898. operator represents a key's relationship to a set of values.
  1899. Valid operators are In, NotIn, Exists and DoesNotExist.
  1900. type: string
  1901. values:
  1902. description: |-
  1903. values is an array of string values. If the operator is In or NotIn,
  1904. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1905. the values array must be empty. This array is replaced during a strategic
  1906. merge patch.
  1907. items:
  1908. type: string
  1909. type: array
  1910. x-kubernetes-list-type: atomic
  1911. required:
  1912. - key
  1913. - operator
  1914. type: object
  1915. type: array
  1916. x-kubernetes-list-type: atomic
  1917. matchLabels:
  1918. additionalProperties:
  1919. type: string
  1920. description: |-
  1921. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1922. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1923. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1924. type: object
  1925. type: object
  1926. x-kubernetes-map-type: atomic
  1927. name:
  1928. description: Optionally, sync to the SecretStore of the given name
  1929. maxLength: 253
  1930. minLength: 1
  1931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1932. type: string
  1933. type: object
  1934. type: object
  1935. x-kubernetes-validations:
  1936. - message: storeRef must specify either name or labelSelector
  1937. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1938. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1939. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1940. type: array
  1941. deletionPolicy:
  1942. default: None
  1943. description: Deletion Policy to handle Secrets in the provider.
  1944. enum:
  1945. - Delete
  1946. - None
  1947. type: string
  1948. refreshInterval:
  1949. default: 1h0m0s
  1950. description: The Interval to which External Secrets will try to push a secret definition
  1951. type: string
  1952. secretStoreRefs:
  1953. items:
  1954. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1955. properties:
  1956. kind:
  1957. default: SecretStore
  1958. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1959. enum:
  1960. - SecretStore
  1961. - ClusterSecretStore
  1962. type: string
  1963. labelSelector:
  1964. description: Optionally, sync to secret stores with label selector
  1965. properties:
  1966. matchExpressions:
  1967. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1968. items:
  1969. description: |-
  1970. A label selector requirement is a selector that contains values, a key, and an operator that
  1971. relates the key and values.
  1972. properties:
  1973. key:
  1974. description: key is the label key that the selector applies to.
  1975. type: string
  1976. operator:
  1977. description: |-
  1978. operator represents a key's relationship to a set of values.
  1979. Valid operators are In, NotIn, Exists and DoesNotExist.
  1980. type: string
  1981. values:
  1982. description: |-
  1983. values is an array of string values. If the operator is In or NotIn,
  1984. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1985. the values array must be empty. This array is replaced during a strategic
  1986. merge patch.
  1987. items:
  1988. type: string
  1989. type: array
  1990. x-kubernetes-list-type: atomic
  1991. required:
  1992. - key
  1993. - operator
  1994. type: object
  1995. type: array
  1996. x-kubernetes-list-type: atomic
  1997. matchLabels:
  1998. additionalProperties:
  1999. type: string
  2000. description: |-
  2001. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2002. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2003. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2004. type: object
  2005. type: object
  2006. x-kubernetes-map-type: atomic
  2007. name:
  2008. description: Optionally, sync to the SecretStore of the given name
  2009. maxLength: 253
  2010. minLength: 1
  2011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2012. type: string
  2013. type: object
  2014. type: array
  2015. selector:
  2016. description: The Secret Selector (k8s source) for the Push Secret
  2017. maxProperties: 1
  2018. minProperties: 1
  2019. properties:
  2020. generatorRef:
  2021. description: Point to a generator to create a Secret.
  2022. properties:
  2023. apiVersion:
  2024. default: generators.external-secrets.io/v1alpha1
  2025. description: Specify the apiVersion of the generator resource
  2026. type: string
  2027. kind:
  2028. description: Specify the Kind of the generator resource
  2029. enum:
  2030. - ACRAccessToken
  2031. - BeyondtrustWorkloadCredentialsDynamicSecret
  2032. - ClusterGenerator
  2033. - CloudsmithAccessToken
  2034. - ECRAuthorizationToken
  2035. - Fake
  2036. - GCRAccessToken
  2037. - GithubAccessToken
  2038. - GitlabDeployToken
  2039. - QuayAccessToken
  2040. - Password
  2041. - SSHKey
  2042. - STSSessionToken
  2043. - UUID
  2044. - VaultDynamicSecret
  2045. - Webhook
  2046. - Grafana
  2047. - MFA
  2048. type: string
  2049. name:
  2050. description: Specify the name of the generator resource
  2051. maxLength: 253
  2052. minLength: 1
  2053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2054. type: string
  2055. required:
  2056. - kind
  2057. - name
  2058. type: object
  2059. secret:
  2060. description: Select a Secret to Push.
  2061. properties:
  2062. name:
  2063. description: |-
  2064. Name of the Secret.
  2065. The Secret must exist in the same namespace as the PushSecret manifest.
  2066. maxLength: 253
  2067. minLength: 1
  2068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2069. type: string
  2070. selector:
  2071. description: Selector chooses secrets using a labelSelector.
  2072. properties:
  2073. matchExpressions:
  2074. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2075. items:
  2076. description: |-
  2077. A label selector requirement is a selector that contains values, a key, and an operator that
  2078. relates the key and values.
  2079. properties:
  2080. key:
  2081. description: key is the label key that the selector applies to.
  2082. type: string
  2083. operator:
  2084. description: |-
  2085. operator represents a key's relationship to a set of values.
  2086. Valid operators are In, NotIn, Exists and DoesNotExist.
  2087. type: string
  2088. values:
  2089. description: |-
  2090. values is an array of string values. If the operator is In or NotIn,
  2091. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2092. the values array must be empty. This array is replaced during a strategic
  2093. merge patch.
  2094. items:
  2095. type: string
  2096. type: array
  2097. x-kubernetes-list-type: atomic
  2098. required:
  2099. - key
  2100. - operator
  2101. type: object
  2102. type: array
  2103. x-kubernetes-list-type: atomic
  2104. matchLabels:
  2105. additionalProperties:
  2106. type: string
  2107. description: |-
  2108. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2109. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2110. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2111. type: object
  2112. type: object
  2113. x-kubernetes-map-type: atomic
  2114. type: object
  2115. type: object
  2116. template:
  2117. description: Template defines a blueprint for the created Secret resource.
  2118. properties:
  2119. data:
  2120. additionalProperties:
  2121. type: string
  2122. type: object
  2123. engineVersion:
  2124. default: v2
  2125. description: |-
  2126. EngineVersion specifies the template engine version
  2127. that should be used to compile/execute the
  2128. template specified in .data and .templateFrom[].
  2129. enum:
  2130. - v2
  2131. type: string
  2132. mergePolicy:
  2133. default: Replace
  2134. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2135. enum:
  2136. - Replace
  2137. - Merge
  2138. type: string
  2139. metadata:
  2140. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2141. properties:
  2142. annotations:
  2143. additionalProperties:
  2144. type: string
  2145. type: object
  2146. finalizers:
  2147. items:
  2148. type: string
  2149. type: array
  2150. labels:
  2151. additionalProperties:
  2152. type: string
  2153. type: object
  2154. type: object
  2155. templateFrom:
  2156. items:
  2157. description: |-
  2158. TemplateFrom specifies a source for templates.
  2159. Each item in the list can either reference a ConfigMap or a Secret resource.
  2160. properties:
  2161. configMap:
  2162. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2163. properties:
  2164. items:
  2165. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2166. items:
  2167. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2168. properties:
  2169. key:
  2170. description: A key in the ConfigMap/Secret
  2171. maxLength: 253
  2172. minLength: 1
  2173. pattern: ^[-._a-zA-Z0-9]+$
  2174. type: string
  2175. templateAs:
  2176. default: Values
  2177. description: TemplateScope specifies how the template keys should be interpreted.
  2178. enum:
  2179. - Values
  2180. - KeysAndValues
  2181. type: string
  2182. required:
  2183. - key
  2184. type: object
  2185. type: array
  2186. name:
  2187. description: The name of the ConfigMap/Secret resource
  2188. maxLength: 253
  2189. minLength: 1
  2190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2191. type: string
  2192. required:
  2193. - items
  2194. - name
  2195. type: object
  2196. literal:
  2197. type: string
  2198. secret:
  2199. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2200. properties:
  2201. items:
  2202. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2203. items:
  2204. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2205. properties:
  2206. key:
  2207. description: A key in the ConfigMap/Secret
  2208. maxLength: 253
  2209. minLength: 1
  2210. pattern: ^[-._a-zA-Z0-9]+$
  2211. type: string
  2212. templateAs:
  2213. default: Values
  2214. description: TemplateScope specifies how the template keys should be interpreted.
  2215. enum:
  2216. - Values
  2217. - KeysAndValues
  2218. type: string
  2219. required:
  2220. - key
  2221. type: object
  2222. type: array
  2223. name:
  2224. description: The name of the ConfigMap/Secret resource
  2225. maxLength: 253
  2226. minLength: 1
  2227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2228. type: string
  2229. required:
  2230. - items
  2231. - name
  2232. type: object
  2233. target:
  2234. default: Data
  2235. description: |-
  2236. Target specifies where to place the template result.
  2237. For Secret resources, common values are: "Data", "Annotations", "Labels".
  2238. For custom resources (when spec.target.manifest is set), this supports
  2239. nested paths like "spec.database.config" or "data".
  2240. type: string
  2241. valuesDecodingStrategy:
  2242. default: None
  2243. description: Used to define a decoding Strategy for the rendered template values.
  2244. enum:
  2245. - Auto
  2246. - Base64
  2247. - Base64URL
  2248. - None
  2249. type: string
  2250. type: object
  2251. type: array
  2252. type:
  2253. type: string
  2254. type: object
  2255. updatePolicy:
  2256. default: Replace
  2257. description: UpdatePolicy to handle Secrets in the provider.
  2258. enum:
  2259. - Replace
  2260. - IfNotExists
  2261. type: string
  2262. required:
  2263. - secretStoreRefs
  2264. - selector
  2265. type: object
  2266. refreshTime:
  2267. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2268. type: string
  2269. required:
  2270. - pushSecretSpec
  2271. type: object
  2272. status:
  2273. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2274. properties:
  2275. conditions:
  2276. items:
  2277. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2278. properties:
  2279. lastTransitionTime:
  2280. format: date-time
  2281. type: string
  2282. message:
  2283. type: string
  2284. reason:
  2285. type: string
  2286. status:
  2287. type: string
  2288. type:
  2289. description: PushSecretConditionType indicates the condition of the PushSecret.
  2290. type: string
  2291. required:
  2292. - status
  2293. - type
  2294. type: object
  2295. type: array
  2296. failedNamespaces:
  2297. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2298. items:
  2299. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2300. properties:
  2301. namespace:
  2302. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2303. type: string
  2304. reason:
  2305. description: Reason is why the PushSecret failed to apply to the namespace
  2306. type: string
  2307. required:
  2308. - namespace
  2309. type: object
  2310. type: array
  2311. provisionedNamespaces:
  2312. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2313. items:
  2314. type: string
  2315. type: array
  2316. pushSecretName:
  2317. type: string
  2318. type: object
  2319. type: object
  2320. served: true
  2321. storage: true
  2322. subresources:
  2323. status: {}
  2324. ---
  2325. apiVersion: apiextensions.k8s.io/v1
  2326. kind: CustomResourceDefinition
  2327. metadata:
  2328. annotations:
  2329. controller-gen.kubebuilder.io/version: v0.19.0
  2330. labels:
  2331. external-secrets.io/component: controller
  2332. name: clustersecretstores.external-secrets.io
  2333. spec:
  2334. group: external-secrets.io
  2335. names:
  2336. categories:
  2337. - external-secrets
  2338. kind: ClusterSecretStore
  2339. listKind: ClusterSecretStoreList
  2340. plural: clustersecretstores
  2341. shortNames:
  2342. - css
  2343. singular: clustersecretstore
  2344. scope: Cluster
  2345. versions:
  2346. - additionalPrinterColumns:
  2347. - jsonPath: .metadata.creationTimestamp
  2348. name: AGE
  2349. type: date
  2350. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2351. name: Status
  2352. type: string
  2353. - jsonPath: .status.capabilities
  2354. name: Capabilities
  2355. type: string
  2356. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2357. name: Ready
  2358. type: string
  2359. name: v1
  2360. schema:
  2361. openAPIV3Schema:
  2362. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2363. properties:
  2364. apiVersion:
  2365. description: |-
  2366. APIVersion defines the versioned schema of this representation of an object.
  2367. Servers should convert recognized schemas to the latest internal value, and
  2368. may reject unrecognized values.
  2369. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2370. type: string
  2371. kind:
  2372. description: |-
  2373. Kind is a string value representing the REST resource this object represents.
  2374. Servers may infer this from the endpoint the client submits requests to.
  2375. Cannot be updated.
  2376. In CamelCase.
  2377. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2378. type: string
  2379. metadata:
  2380. type: object
  2381. spec:
  2382. description: SecretStoreSpec defines the desired state of SecretStore.
  2383. properties:
  2384. conditions:
  2385. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2386. items:
  2387. description: |-
  2388. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2389. for a ClusterSecretStore instance.
  2390. properties:
  2391. namespaceRegexes:
  2392. description: Choose namespaces by using regex matching
  2393. items:
  2394. type: string
  2395. type: array
  2396. namespaceSelector:
  2397. description: Choose namespace using a labelSelector
  2398. properties:
  2399. matchExpressions:
  2400. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2401. items:
  2402. description: |-
  2403. A label selector requirement is a selector that contains values, a key, and an operator that
  2404. relates the key and values.
  2405. properties:
  2406. key:
  2407. description: key is the label key that the selector applies to.
  2408. type: string
  2409. operator:
  2410. description: |-
  2411. operator represents a key's relationship to a set of values.
  2412. Valid operators are In, NotIn, Exists and DoesNotExist.
  2413. type: string
  2414. values:
  2415. description: |-
  2416. values is an array of string values. If the operator is In or NotIn,
  2417. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2418. the values array must be empty. This array is replaced during a strategic
  2419. merge patch.
  2420. items:
  2421. type: string
  2422. type: array
  2423. x-kubernetes-list-type: atomic
  2424. required:
  2425. - key
  2426. - operator
  2427. type: object
  2428. type: array
  2429. x-kubernetes-list-type: atomic
  2430. matchLabels:
  2431. additionalProperties:
  2432. type: string
  2433. description: |-
  2434. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2435. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2436. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2437. type: object
  2438. type: object
  2439. x-kubernetes-map-type: atomic
  2440. namespaces:
  2441. description: Choose namespaces by name
  2442. items:
  2443. maxLength: 63
  2444. minLength: 1
  2445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2446. type: string
  2447. type: array
  2448. type: object
  2449. type: array
  2450. controller:
  2451. description: |-
  2452. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2453. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2454. type: string
  2455. provider:
  2456. description: Used to configure the provider. Only one provider may be set
  2457. maxProperties: 1
  2458. minProperties: 1
  2459. properties:
  2460. akeyless:
  2461. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2462. properties:
  2463. akeylessGWApiURL:
  2464. description: Akeyless GW API Url from which the secrets to be fetched from.
  2465. type: string
  2466. authSecretRef:
  2467. description: Auth configures how the operator authenticates with Akeyless.
  2468. properties:
  2469. kubernetesAuth:
  2470. description: |-
  2471. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2472. token stored in the named Secret resource.
  2473. properties:
  2474. accessID:
  2475. description: the Akeyless Kubernetes auth-method access-id
  2476. type: string
  2477. k8sConfName:
  2478. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2479. type: string
  2480. secretRef:
  2481. description: |-
  2482. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2483. for authenticating with Akeyless. If a name is specified without a key,
  2484. `token` is the default. If one is not specified, the one bound to
  2485. the controller will be used.
  2486. properties:
  2487. key:
  2488. description: |-
  2489. A key in the referenced Secret.
  2490. Some instances of this field may be defaulted, in others it may be required.
  2491. maxLength: 253
  2492. minLength: 1
  2493. pattern: ^[-._a-zA-Z0-9]+$
  2494. type: string
  2495. name:
  2496. description: The name of the Secret resource being referred to.
  2497. maxLength: 253
  2498. minLength: 1
  2499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2500. type: string
  2501. namespace:
  2502. description: |-
  2503. The namespace of the Secret resource being referred to.
  2504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2505. maxLength: 63
  2506. minLength: 1
  2507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2508. type: string
  2509. type: object
  2510. serviceAccountRef:
  2511. description: |-
  2512. Optional service account field containing the name of a kubernetes ServiceAccount.
  2513. If the service account is specified, the service account secret token JWT will be used
  2514. for authenticating with Akeyless. If the service account selector is not supplied,
  2515. the secretRef will be used instead.
  2516. properties:
  2517. audiences:
  2518. description: |-
  2519. Audience specifies the `aud` claim for the service account token
  2520. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2521. then this audiences will be appended to the list
  2522. items:
  2523. type: string
  2524. type: array
  2525. name:
  2526. description: The name of the ServiceAccount resource being referred to.
  2527. maxLength: 253
  2528. minLength: 1
  2529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2530. type: string
  2531. namespace:
  2532. description: |-
  2533. Namespace of the resource being referred to.
  2534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2535. maxLength: 63
  2536. minLength: 1
  2537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2538. type: string
  2539. required:
  2540. - name
  2541. type: object
  2542. required:
  2543. - accessID
  2544. - k8sConfName
  2545. type: object
  2546. secretRef:
  2547. description: |-
  2548. Reference to a Secret that contains the details
  2549. to authenticate with Akeyless.
  2550. properties:
  2551. accessID:
  2552. description: The SecretAccessID is used for authentication
  2553. properties:
  2554. key:
  2555. description: |-
  2556. A key in the referenced Secret.
  2557. Some instances of this field may be defaulted, in others it may be required.
  2558. maxLength: 253
  2559. minLength: 1
  2560. pattern: ^[-._a-zA-Z0-9]+$
  2561. type: string
  2562. name:
  2563. description: The name of the Secret resource being referred to.
  2564. maxLength: 253
  2565. minLength: 1
  2566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2567. type: string
  2568. namespace:
  2569. description: |-
  2570. The namespace of the Secret resource being referred to.
  2571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2572. maxLength: 63
  2573. minLength: 1
  2574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2575. type: string
  2576. type: object
  2577. accessType:
  2578. description: |-
  2579. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2580. In some instances, `key` is a required field.
  2581. properties:
  2582. key:
  2583. description: |-
  2584. A key in the referenced Secret.
  2585. Some instances of this field may be defaulted, in others it may be required.
  2586. maxLength: 253
  2587. minLength: 1
  2588. pattern: ^[-._a-zA-Z0-9]+$
  2589. type: string
  2590. name:
  2591. description: The name of the Secret resource being referred to.
  2592. maxLength: 253
  2593. minLength: 1
  2594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2595. type: string
  2596. namespace:
  2597. description: |-
  2598. The namespace of the Secret resource being referred to.
  2599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2600. maxLength: 63
  2601. minLength: 1
  2602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2603. type: string
  2604. type: object
  2605. accessTypeParam:
  2606. description: |-
  2607. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2608. In some instances, `key` is a required field.
  2609. properties:
  2610. key:
  2611. description: |-
  2612. A key in the referenced Secret.
  2613. Some instances of this field may be defaulted, in others it may be required.
  2614. maxLength: 253
  2615. minLength: 1
  2616. pattern: ^[-._a-zA-Z0-9]+$
  2617. type: string
  2618. name:
  2619. description: The name of the Secret resource being referred to.
  2620. maxLength: 253
  2621. minLength: 1
  2622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2623. type: string
  2624. namespace:
  2625. description: |-
  2626. The namespace of the Secret resource being referred to.
  2627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2628. maxLength: 63
  2629. minLength: 1
  2630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2631. type: string
  2632. type: object
  2633. type: object
  2634. serviceAccountRef:
  2635. description: |-
  2636. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2637. authentication on AKS Workload Identity. The operator obtains a federated
  2638. identity token from this ServiceAccount via the TokenRequest API instead
  2639. of using the ESO controller pod identity. Ignored for other access types.
  2640. properties:
  2641. audiences:
  2642. description: |-
  2643. Audience specifies the `aud` claim for the service account token
  2644. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2645. then this audiences will be appended to the list
  2646. items:
  2647. type: string
  2648. type: array
  2649. name:
  2650. description: The name of the ServiceAccount resource being referred to.
  2651. maxLength: 253
  2652. minLength: 1
  2653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2654. type: string
  2655. namespace:
  2656. description: |-
  2657. Namespace of the resource being referred to.
  2658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2659. maxLength: 63
  2660. minLength: 1
  2661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2662. type: string
  2663. required:
  2664. - name
  2665. type: object
  2666. type: object
  2667. caBundle:
  2668. description: |-
  2669. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2670. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2671. are used to validate the TLS connection.
  2672. format: byte
  2673. type: string
  2674. caProvider:
  2675. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2676. properties:
  2677. key:
  2678. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2679. maxLength: 253
  2680. minLength: 1
  2681. pattern: ^[-._a-zA-Z0-9]+$
  2682. type: string
  2683. name:
  2684. description: The name of the object located at the provider type.
  2685. maxLength: 253
  2686. minLength: 1
  2687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2688. type: string
  2689. namespace:
  2690. description: |-
  2691. The namespace the Provider type is in.
  2692. Can only be defined when used in a ClusterSecretStore.
  2693. maxLength: 63
  2694. minLength: 1
  2695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2696. type: string
  2697. type:
  2698. description: The type of provider to use such as "Secret", or "ConfigMap".
  2699. enum:
  2700. - Secret
  2701. - ConfigMap
  2702. type: string
  2703. required:
  2704. - name
  2705. - type
  2706. type: object
  2707. ignoreCache:
  2708. description: |-
  2709. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2710. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2711. type: boolean
  2712. required:
  2713. - akeylessGWApiURL
  2714. - authSecretRef
  2715. type: object
  2716. aws:
  2717. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2718. properties:
  2719. additionalRoles:
  2720. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2721. items:
  2722. type: string
  2723. type: array
  2724. auth:
  2725. description: |-
  2726. Auth defines the information necessary to authenticate against AWS
  2727. if not set aws sdk will infer credentials from your environment
  2728. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2729. properties:
  2730. jwt:
  2731. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2732. properties:
  2733. serviceAccountRef:
  2734. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2735. properties:
  2736. audiences:
  2737. description: |-
  2738. Audience specifies the `aud` claim for the service account token
  2739. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2740. then this audiences will be appended to the list
  2741. items:
  2742. type: string
  2743. type: array
  2744. name:
  2745. description: The name of the ServiceAccount resource being referred to.
  2746. maxLength: 253
  2747. minLength: 1
  2748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2749. type: string
  2750. namespace:
  2751. description: |-
  2752. Namespace of the resource being referred to.
  2753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2754. maxLength: 63
  2755. minLength: 1
  2756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2757. type: string
  2758. required:
  2759. - name
  2760. type: object
  2761. type: object
  2762. secretRef:
  2763. description: |-
  2764. AWSAuthSecretRef holds secret references for AWS credentials
  2765. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2766. properties:
  2767. accessKeyIDSecretRef:
  2768. description: The AccessKeyID is used for authentication
  2769. properties:
  2770. key:
  2771. description: |-
  2772. A key in the referenced Secret.
  2773. Some instances of this field may be defaulted, in others it may be required.
  2774. maxLength: 253
  2775. minLength: 1
  2776. pattern: ^[-._a-zA-Z0-9]+$
  2777. type: string
  2778. name:
  2779. description: The name of the Secret resource being referred to.
  2780. maxLength: 253
  2781. minLength: 1
  2782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2783. type: string
  2784. namespace:
  2785. description: |-
  2786. The namespace of the Secret resource being referred to.
  2787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2788. maxLength: 63
  2789. minLength: 1
  2790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2791. type: string
  2792. type: object
  2793. secretAccessKeySecretRef:
  2794. description: The SecretAccessKey is used for authentication
  2795. properties:
  2796. key:
  2797. description: |-
  2798. A key in the referenced Secret.
  2799. Some instances of this field may be defaulted, in others it may be required.
  2800. maxLength: 253
  2801. minLength: 1
  2802. pattern: ^[-._a-zA-Z0-9]+$
  2803. type: string
  2804. name:
  2805. description: The name of the Secret resource being referred to.
  2806. maxLength: 253
  2807. minLength: 1
  2808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2809. type: string
  2810. namespace:
  2811. description: |-
  2812. The namespace of the Secret resource being referred to.
  2813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2814. maxLength: 63
  2815. minLength: 1
  2816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2817. type: string
  2818. type: object
  2819. sessionTokenSecretRef:
  2820. description: |-
  2821. The SessionToken used for authentication
  2822. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2823. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2824. properties:
  2825. key:
  2826. description: |-
  2827. A key in the referenced Secret.
  2828. Some instances of this field may be defaulted, in others it may be required.
  2829. maxLength: 253
  2830. minLength: 1
  2831. pattern: ^[-._a-zA-Z0-9]+$
  2832. type: string
  2833. name:
  2834. description: The name of the Secret resource being referred to.
  2835. maxLength: 253
  2836. minLength: 1
  2837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2838. type: string
  2839. namespace:
  2840. description: |-
  2841. The namespace of the Secret resource being referred to.
  2842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2843. maxLength: 63
  2844. minLength: 1
  2845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2846. type: string
  2847. type: object
  2848. type: object
  2849. type: object
  2850. customSessionTags:
  2851. additionalProperties:
  2852. type: string
  2853. description: |-
  2854. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2855. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2856. type: object
  2857. x-kubernetes-validations:
  2858. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2859. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2860. externalID:
  2861. description: AWS External ID set on assumed IAM roles
  2862. type: string
  2863. prefix:
  2864. description: Prefix adds a prefix to all retrieved values.
  2865. type: string
  2866. region:
  2867. description: AWS Region to be used for the provider
  2868. type: string
  2869. role:
  2870. description: Role is a Role ARN which the provider will assume
  2871. type: string
  2872. secretsManager:
  2873. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2874. properties:
  2875. forceDeleteWithoutRecovery:
  2876. description: |-
  2877. Specifies whether to delete the secret without any recovery window. You
  2878. can't use both this parameter and RecoveryWindowInDays in the same call.
  2879. If you don't use either, then by default Secrets Manager uses a 30 day
  2880. recovery window.
  2881. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2882. type: boolean
  2883. recoveryWindowInDays:
  2884. description: |-
  2885. The number of days from 7 to 30 that Secrets Manager waits before
  2886. permanently deleting the secret. You can't use both this parameter and
  2887. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2888. then by default Secrets Manager uses a 30-day recovery window.
  2889. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2890. format: int64
  2891. type: integer
  2892. type: object
  2893. service:
  2894. description: Service defines which service should be used to fetch the secrets
  2895. enum:
  2896. - SecretsManager
  2897. - ParameterStore
  2898. - CertificateManager
  2899. type: string
  2900. sessionTags:
  2901. description: AWS STS assume role session tags
  2902. items:
  2903. description: |-
  2904. Tag is a key-value pair that can be attached to an AWS resource.
  2905. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2906. properties:
  2907. key:
  2908. type: string
  2909. value:
  2910. type: string
  2911. required:
  2912. - key
  2913. - value
  2914. type: object
  2915. type: array
  2916. sessionTagsPolicy:
  2917. default: None
  2918. description: |-
  2919. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2920. None (default): no tags are added.
  2921. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2922. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2923. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2924. enum:
  2925. - None
  2926. - Simple
  2927. - Custom
  2928. type: string
  2929. transitiveTagKeys:
  2930. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2931. items:
  2932. type: string
  2933. type: array
  2934. required:
  2935. - region
  2936. - service
  2937. type: object
  2938. azurekv:
  2939. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2940. properties:
  2941. authSecretRef:
  2942. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2943. properties:
  2944. clientCertificate:
  2945. description: The Azure ClientCertificate of the service principle used for authentication.
  2946. properties:
  2947. key:
  2948. description: |-
  2949. A key in the referenced Secret.
  2950. Some instances of this field may be defaulted, in others it may be required.
  2951. maxLength: 253
  2952. minLength: 1
  2953. pattern: ^[-._a-zA-Z0-9]+$
  2954. type: string
  2955. name:
  2956. description: The name of the Secret resource being referred to.
  2957. maxLength: 253
  2958. minLength: 1
  2959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2960. type: string
  2961. namespace:
  2962. description: |-
  2963. The namespace of the Secret resource being referred to.
  2964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2965. maxLength: 63
  2966. minLength: 1
  2967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2968. type: string
  2969. type: object
  2970. clientId:
  2971. description: The Azure clientId of the service principle or managed identity used for authentication.
  2972. properties:
  2973. key:
  2974. description: |-
  2975. A key in the referenced Secret.
  2976. Some instances of this field may be defaulted, in others it may be required.
  2977. maxLength: 253
  2978. minLength: 1
  2979. pattern: ^[-._a-zA-Z0-9]+$
  2980. type: string
  2981. name:
  2982. description: The name of the Secret resource being referred to.
  2983. maxLength: 253
  2984. minLength: 1
  2985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2986. type: string
  2987. namespace:
  2988. description: |-
  2989. The namespace of the Secret resource being referred to.
  2990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2991. maxLength: 63
  2992. minLength: 1
  2993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2994. type: string
  2995. type: object
  2996. clientSecret:
  2997. description: The Azure ClientSecret of the service principle used for authentication.
  2998. properties:
  2999. key:
  3000. description: |-
  3001. A key in the referenced Secret.
  3002. Some instances of this field may be defaulted, in others it may be required.
  3003. maxLength: 253
  3004. minLength: 1
  3005. pattern: ^[-._a-zA-Z0-9]+$
  3006. type: string
  3007. name:
  3008. description: The name of the Secret resource being referred to.
  3009. maxLength: 253
  3010. minLength: 1
  3011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3012. type: string
  3013. namespace:
  3014. description: |-
  3015. The namespace of the Secret resource being referred to.
  3016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3017. maxLength: 63
  3018. minLength: 1
  3019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3020. type: string
  3021. type: object
  3022. tenantId:
  3023. description: The Azure tenantId of the managed identity used for authentication.
  3024. properties:
  3025. key:
  3026. description: |-
  3027. A key in the referenced Secret.
  3028. Some instances of this field may be defaulted, in others it may be required.
  3029. maxLength: 253
  3030. minLength: 1
  3031. pattern: ^[-._a-zA-Z0-9]+$
  3032. type: string
  3033. name:
  3034. description: The name of the Secret resource being referred to.
  3035. maxLength: 253
  3036. minLength: 1
  3037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3038. type: string
  3039. namespace:
  3040. description: |-
  3041. The namespace of the Secret resource being referred to.
  3042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3043. maxLength: 63
  3044. minLength: 1
  3045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3046. type: string
  3047. type: object
  3048. type: object
  3049. authType:
  3050. default: ServicePrincipal
  3051. description: |-
  3052. Auth type defines how to authenticate to the keyvault service.
  3053. Valid values are:
  3054. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3055. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3056. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3057. enum:
  3058. - ServicePrincipal
  3059. - ManagedIdentity
  3060. - WorkloadIdentity
  3061. type: string
  3062. customCloudConfig:
  3063. description: |-
  3064. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3065. Required when EnvironmentType is AzureStackCloud.
  3066. Optional for other environment types - useful for Azure China when using Workload Identity
  3067. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3068. standard China Cloud endpoint (login.chinacloudapi.cn).
  3069. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3070. configuration is not supported with the legacy go-autorest SDK.
  3071. properties:
  3072. activeDirectoryEndpoint:
  3073. description: |-
  3074. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3075. Required when using custom cloud configuration
  3076. type: string
  3077. keyVaultDNSSuffix:
  3078. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3079. type: string
  3080. keyVaultEndpoint:
  3081. description: KeyVaultEndpoint is the Key Vault service endpoint
  3082. type: string
  3083. resourceManagerEndpoint:
  3084. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3085. type: string
  3086. required:
  3087. - activeDirectoryEndpoint
  3088. type: object
  3089. environmentType:
  3090. default: PublicCloud
  3091. description: |-
  3092. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3093. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3094. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3095. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3096. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3097. enum:
  3098. - PublicCloud
  3099. - USGovernmentCloud
  3100. - ChinaCloud
  3101. - GermanCloud
  3102. - AzureStackCloud
  3103. type: string
  3104. identityId:
  3105. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3106. type: string
  3107. serviceAccountRef:
  3108. description: |-
  3109. ServiceAccountRef specified the service account
  3110. that should be used when authenticating with WorkloadIdentity.
  3111. properties:
  3112. audiences:
  3113. description: |-
  3114. Audience specifies the `aud` claim for the service account token
  3115. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3116. then this audiences will be appended to the list
  3117. items:
  3118. type: string
  3119. type: array
  3120. name:
  3121. description: The name of the ServiceAccount resource being referred to.
  3122. maxLength: 253
  3123. minLength: 1
  3124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3125. type: string
  3126. namespace:
  3127. description: |-
  3128. Namespace of the resource being referred to.
  3129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3130. maxLength: 63
  3131. minLength: 1
  3132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3133. type: string
  3134. required:
  3135. - name
  3136. type: object
  3137. tenantId:
  3138. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3139. type: string
  3140. useAzureSDK:
  3141. default: false
  3142. description: |-
  3143. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3144. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3145. type: boolean
  3146. vaultUrl:
  3147. description: Vault Url from which the secrets to be fetched from.
  3148. type: string
  3149. required:
  3150. - vaultUrl
  3151. type: object
  3152. barbican:
  3153. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3154. properties:
  3155. auth:
  3156. description: BarbicanAuth contains the authentication information for Barbican.
  3157. properties:
  3158. password:
  3159. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3160. properties:
  3161. secretRef:
  3162. description: |-
  3163. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3164. In some instances, `key` is a required field.
  3165. properties:
  3166. key:
  3167. description: |-
  3168. A key in the referenced Secret.
  3169. Some instances of this field may be defaulted, in others it may be required.
  3170. maxLength: 253
  3171. minLength: 1
  3172. pattern: ^[-._a-zA-Z0-9]+$
  3173. type: string
  3174. name:
  3175. description: The name of the Secret resource being referred to.
  3176. maxLength: 253
  3177. minLength: 1
  3178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3179. type: string
  3180. namespace:
  3181. description: |-
  3182. The namespace of the Secret resource being referred to.
  3183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3184. maxLength: 63
  3185. minLength: 1
  3186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3187. type: string
  3188. type: object
  3189. required:
  3190. - secretRef
  3191. type: object
  3192. username:
  3193. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3194. maxProperties: 1
  3195. minProperties: 1
  3196. properties:
  3197. secretRef:
  3198. description: |-
  3199. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3200. In some instances, `key` is a required field.
  3201. properties:
  3202. key:
  3203. description: |-
  3204. A key in the referenced Secret.
  3205. Some instances of this field may be defaulted, in others it may be required.
  3206. maxLength: 253
  3207. minLength: 1
  3208. pattern: ^[-._a-zA-Z0-9]+$
  3209. type: string
  3210. name:
  3211. description: The name of the Secret resource being referred to.
  3212. maxLength: 253
  3213. minLength: 1
  3214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3215. type: string
  3216. namespace:
  3217. description: |-
  3218. The namespace of the Secret resource being referred to.
  3219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3220. maxLength: 63
  3221. minLength: 1
  3222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3223. type: string
  3224. type: object
  3225. value:
  3226. type: string
  3227. type: object
  3228. required:
  3229. - password
  3230. - username
  3231. type: object
  3232. authURL:
  3233. type: string
  3234. domainName:
  3235. type: string
  3236. region:
  3237. type: string
  3238. tenantName:
  3239. type: string
  3240. required:
  3241. - auth
  3242. type: object
  3243. beyondtrust:
  3244. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3245. properties:
  3246. auth:
  3247. description: Auth configures how the operator authenticates with Beyondtrust.
  3248. properties:
  3249. apiKey:
  3250. description: APIKey If not provided then ClientID/ClientSecret become required.
  3251. properties:
  3252. secretRef:
  3253. description: SecretRef references a key in a secret that will be used as value.
  3254. properties:
  3255. key:
  3256. description: |-
  3257. A key in the referenced Secret.
  3258. Some instances of this field may be defaulted, in others it may be required.
  3259. maxLength: 253
  3260. minLength: 1
  3261. pattern: ^[-._a-zA-Z0-9]+$
  3262. type: string
  3263. name:
  3264. description: The name of the Secret resource being referred to.
  3265. maxLength: 253
  3266. minLength: 1
  3267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3268. type: string
  3269. namespace:
  3270. description: |-
  3271. The namespace of the Secret resource being referred to.
  3272. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3273. maxLength: 63
  3274. minLength: 1
  3275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3276. type: string
  3277. type: object
  3278. value:
  3279. description: Value can be specified directly to set a value without using a secret.
  3280. type: string
  3281. type: object
  3282. certificate:
  3283. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3284. properties:
  3285. secretRef:
  3286. description: SecretRef references a key in a secret that will be used as value.
  3287. properties:
  3288. key:
  3289. description: |-
  3290. A key in the referenced Secret.
  3291. Some instances of this field may be defaulted, in others it may be required.
  3292. maxLength: 253
  3293. minLength: 1
  3294. pattern: ^[-._a-zA-Z0-9]+$
  3295. type: string
  3296. name:
  3297. description: The name of the Secret resource being referred to.
  3298. maxLength: 253
  3299. minLength: 1
  3300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3301. type: string
  3302. namespace:
  3303. description: |-
  3304. The namespace of the Secret resource being referred to.
  3305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3306. maxLength: 63
  3307. minLength: 1
  3308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3309. type: string
  3310. type: object
  3311. value:
  3312. description: Value can be specified directly to set a value without using a secret.
  3313. type: string
  3314. type: object
  3315. certificateKey:
  3316. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3317. properties:
  3318. secretRef:
  3319. description: SecretRef references a key in a secret that will be used as value.
  3320. properties:
  3321. key:
  3322. description: |-
  3323. A key in the referenced Secret.
  3324. Some instances of this field may be defaulted, in others it may be required.
  3325. maxLength: 253
  3326. minLength: 1
  3327. pattern: ^[-._a-zA-Z0-9]+$
  3328. type: string
  3329. name:
  3330. description: The name of the Secret resource being referred to.
  3331. maxLength: 253
  3332. minLength: 1
  3333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3334. type: string
  3335. namespace:
  3336. description: |-
  3337. The namespace of the Secret resource being referred to.
  3338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3339. maxLength: 63
  3340. minLength: 1
  3341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3342. type: string
  3343. type: object
  3344. value:
  3345. description: Value can be specified directly to set a value without using a secret.
  3346. type: string
  3347. type: object
  3348. clientId:
  3349. description: ClientID is the API OAuth Client ID.
  3350. properties:
  3351. secretRef:
  3352. description: SecretRef references a key in a secret that will be used as value.
  3353. properties:
  3354. key:
  3355. description: |-
  3356. A key in the referenced Secret.
  3357. Some instances of this field may be defaulted, in others it may be required.
  3358. maxLength: 253
  3359. minLength: 1
  3360. pattern: ^[-._a-zA-Z0-9]+$
  3361. type: string
  3362. name:
  3363. description: The name of the Secret resource being referred to.
  3364. maxLength: 253
  3365. minLength: 1
  3366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3367. type: string
  3368. namespace:
  3369. description: |-
  3370. The namespace of the Secret resource being referred to.
  3371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3372. maxLength: 63
  3373. minLength: 1
  3374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3375. type: string
  3376. type: object
  3377. value:
  3378. description: Value can be specified directly to set a value without using a secret.
  3379. type: string
  3380. type: object
  3381. clientSecret:
  3382. description: ClientSecret is the API OAuth Client Secret.
  3383. properties:
  3384. secretRef:
  3385. description: SecretRef references a key in a secret that will be used as value.
  3386. properties:
  3387. key:
  3388. description: |-
  3389. A key in the referenced Secret.
  3390. Some instances of this field may be defaulted, in others it may be required.
  3391. maxLength: 253
  3392. minLength: 1
  3393. pattern: ^[-._a-zA-Z0-9]+$
  3394. type: string
  3395. name:
  3396. description: The name of the Secret resource being referred to.
  3397. maxLength: 253
  3398. minLength: 1
  3399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3400. type: string
  3401. namespace:
  3402. description: |-
  3403. The namespace of the Secret resource being referred to.
  3404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3405. maxLength: 63
  3406. minLength: 1
  3407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3408. type: string
  3409. type: object
  3410. value:
  3411. description: Value can be specified directly to set a value without using a secret.
  3412. type: string
  3413. type: object
  3414. type: object
  3415. server:
  3416. description: Auth configures how API server works.
  3417. properties:
  3418. apiUrl:
  3419. type: string
  3420. apiVersion:
  3421. type: string
  3422. clientTimeOutSeconds:
  3423. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3424. type: integer
  3425. decrypt:
  3426. default: true
  3427. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3428. type: boolean
  3429. retrievalType:
  3430. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3431. type: string
  3432. separator:
  3433. description: A character that separates the folder names.
  3434. type: string
  3435. verifyCA:
  3436. type: boolean
  3437. required:
  3438. - apiUrl
  3439. - verifyCA
  3440. type: object
  3441. required:
  3442. - auth
  3443. - server
  3444. type: object
  3445. beyondtrustworkloadcredentials:
  3446. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3447. properties:
  3448. auth:
  3449. description: |-
  3450. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3451. Currently supports API key authentication via Kubernetes secret reference.
  3452. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3453. properties:
  3454. apikey:
  3455. description: |-
  3456. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3457. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3458. properties:
  3459. token:
  3460. description: |-
  3461. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3462. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3463. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3464. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3465. properties:
  3466. key:
  3467. description: |-
  3468. A key in the referenced Secret.
  3469. Some instances of this field may be defaulted, in others it may be required.
  3470. maxLength: 253
  3471. minLength: 1
  3472. pattern: ^[-._a-zA-Z0-9]+$
  3473. type: string
  3474. name:
  3475. description: The name of the Secret resource being referred to.
  3476. maxLength: 253
  3477. minLength: 1
  3478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3479. type: string
  3480. namespace:
  3481. description: |-
  3482. The namespace of the Secret resource being referred to.
  3483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3484. maxLength: 63
  3485. minLength: 1
  3486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3487. type: string
  3488. type: object
  3489. required:
  3490. - token
  3491. type: object
  3492. required:
  3493. - apikey
  3494. type: object
  3495. caBundle:
  3496. description: |-
  3497. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3498. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3499. If not set, the system's trusted root certificates are used.
  3500. format: byte
  3501. type: string
  3502. caProvider:
  3503. description: |-
  3504. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3505. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3506. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3507. properties:
  3508. key:
  3509. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3510. maxLength: 253
  3511. minLength: 1
  3512. pattern: ^[-._a-zA-Z0-9]+$
  3513. type: string
  3514. name:
  3515. description: The name of the object located at the provider type.
  3516. maxLength: 253
  3517. minLength: 1
  3518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3519. type: string
  3520. namespace:
  3521. description: |-
  3522. The namespace the Provider type is in.
  3523. Can only be defined when used in a ClusterSecretStore.
  3524. maxLength: 63
  3525. minLength: 1
  3526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3527. type: string
  3528. type:
  3529. description: The type of provider to use such as "Secret", or "ConfigMap".
  3530. enum:
  3531. - Secret
  3532. - ConfigMap
  3533. type: string
  3534. required:
  3535. - name
  3536. - type
  3537. type: object
  3538. folderPath:
  3539. description: |-
  3540. FolderPath specifies the default folder path for secret retrieval.
  3541. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3542. Example: "production/database" or "dev/api-keys"
  3543. Leave empty to retrieve secrets from the root folder.
  3544. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3545. type: string
  3546. server:
  3547. description: |-
  3548. Server configures the BeyondTrust Workload Credentials server connection details.
  3549. Includes the API URL and Site ID for your BeyondTrust instance.
  3550. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3551. properties:
  3552. apiUrl:
  3553. description: |-
  3554. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3555. This should be the full URL to your BeyondTrust instance.
  3556. Example: https://api.beyondtrust.io/siie
  3557. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3558. type: string
  3559. siteId:
  3560. description: |-
  3561. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3562. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3563. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3564. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3565. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3566. type: string
  3567. required:
  3568. - apiUrl
  3569. - siteId
  3570. type: object
  3571. required:
  3572. - auth
  3573. - server
  3574. type: object
  3575. bitwardensecretsmanager:
  3576. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3577. properties:
  3578. apiURL:
  3579. type: string
  3580. auth:
  3581. description: |-
  3582. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3583. Make sure that the token being used has permissions on the given secret.
  3584. properties:
  3585. secretRef:
  3586. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3587. properties:
  3588. credentials:
  3589. description: AccessToken used for the bitwarden instance.
  3590. properties:
  3591. key:
  3592. description: |-
  3593. A key in the referenced Secret.
  3594. Some instances of this field may be defaulted, in others it may be required.
  3595. maxLength: 253
  3596. minLength: 1
  3597. pattern: ^[-._a-zA-Z0-9]+$
  3598. type: string
  3599. name:
  3600. description: The name of the Secret resource being referred to.
  3601. maxLength: 253
  3602. minLength: 1
  3603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3604. type: string
  3605. namespace:
  3606. description: |-
  3607. The namespace of the Secret resource being referred to.
  3608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3609. maxLength: 63
  3610. minLength: 1
  3611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3612. type: string
  3613. type: object
  3614. required:
  3615. - credentials
  3616. type: object
  3617. required:
  3618. - secretRef
  3619. type: object
  3620. bitwardenServerSDKURL:
  3621. type: string
  3622. caBundle:
  3623. description: |-
  3624. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3625. can be performed.
  3626. type: string
  3627. caProvider:
  3628. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3629. properties:
  3630. key:
  3631. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3632. maxLength: 253
  3633. minLength: 1
  3634. pattern: ^[-._a-zA-Z0-9]+$
  3635. type: string
  3636. name:
  3637. description: The name of the object located at the provider type.
  3638. maxLength: 253
  3639. minLength: 1
  3640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3641. type: string
  3642. namespace:
  3643. description: |-
  3644. The namespace the Provider type is in.
  3645. Can only be defined when used in a ClusterSecretStore.
  3646. maxLength: 63
  3647. minLength: 1
  3648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3649. type: string
  3650. type:
  3651. description: The type of provider to use such as "Secret", or "ConfigMap".
  3652. enum:
  3653. - Secret
  3654. - ConfigMap
  3655. type: string
  3656. required:
  3657. - name
  3658. - type
  3659. type: object
  3660. identityURL:
  3661. type: string
  3662. organizationID:
  3663. description: OrganizationID determines which organization this secret store manages.
  3664. type: string
  3665. projectID:
  3666. description: ProjectID determines which project this secret store manages.
  3667. type: string
  3668. required:
  3669. - auth
  3670. - organizationID
  3671. - projectID
  3672. type: object
  3673. chef:
  3674. description: Chef configures this store to sync secrets with chef server
  3675. properties:
  3676. auth:
  3677. description: Auth defines the information necessary to authenticate against chef Server
  3678. properties:
  3679. secretRef:
  3680. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3681. properties:
  3682. privateKeySecretRef:
  3683. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3684. properties:
  3685. key:
  3686. description: |-
  3687. A key in the referenced Secret.
  3688. Some instances of this field may be defaulted, in others it may be required.
  3689. maxLength: 253
  3690. minLength: 1
  3691. pattern: ^[-._a-zA-Z0-9]+$
  3692. type: string
  3693. name:
  3694. description: The name of the Secret resource being referred to.
  3695. maxLength: 253
  3696. minLength: 1
  3697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3698. type: string
  3699. namespace:
  3700. description: |-
  3701. The namespace of the Secret resource being referred to.
  3702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3703. maxLength: 63
  3704. minLength: 1
  3705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3706. type: string
  3707. type: object
  3708. required:
  3709. - privateKeySecretRef
  3710. type: object
  3711. required:
  3712. - secretRef
  3713. type: object
  3714. serverUrl:
  3715. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3716. type: string
  3717. username:
  3718. description: UserName should be the user ID on the chef server
  3719. type: string
  3720. required:
  3721. - auth
  3722. - serverUrl
  3723. - username
  3724. type: object
  3725. cloudrusm:
  3726. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3727. properties:
  3728. auth:
  3729. description: CSMAuth contains a secretRef for credentials.
  3730. properties:
  3731. secretRef:
  3732. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3733. properties:
  3734. accessKeyIDSecretRef:
  3735. description: The AccessKeyID is used for authentication
  3736. properties:
  3737. key:
  3738. description: |-
  3739. A key in the referenced Secret.
  3740. Some instances of this field may be defaulted, in others it may be required.
  3741. maxLength: 253
  3742. minLength: 1
  3743. pattern: ^[-._a-zA-Z0-9]+$
  3744. type: string
  3745. name:
  3746. description: The name of the Secret resource being referred to.
  3747. maxLength: 253
  3748. minLength: 1
  3749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3750. type: string
  3751. namespace:
  3752. description: |-
  3753. The namespace of the Secret resource being referred to.
  3754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3755. maxLength: 63
  3756. minLength: 1
  3757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3758. type: string
  3759. type: object
  3760. accessKeySecretSecretRef:
  3761. description: The AccessKeySecret is used for authentication
  3762. properties:
  3763. key:
  3764. description: |-
  3765. A key in the referenced Secret.
  3766. Some instances of this field may be defaulted, in others it may be required.
  3767. maxLength: 253
  3768. minLength: 1
  3769. pattern: ^[-._a-zA-Z0-9]+$
  3770. type: string
  3771. name:
  3772. description: The name of the Secret resource being referred to.
  3773. maxLength: 253
  3774. minLength: 1
  3775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3776. type: string
  3777. namespace:
  3778. description: |-
  3779. The namespace of the Secret resource being referred to.
  3780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3781. maxLength: 63
  3782. minLength: 1
  3783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3784. type: string
  3785. type: object
  3786. required:
  3787. - accessKeyIDSecretRef
  3788. - accessKeySecretSecretRef
  3789. type: object
  3790. type: object
  3791. projectID:
  3792. description: ProjectID is the project, which the secrets are stored in.
  3793. type: string
  3794. required:
  3795. - auth
  3796. type: object
  3797. conjur:
  3798. description: Conjur configures this store to sync secrets using conjur provider
  3799. properties:
  3800. auth:
  3801. description: Defines authentication settings for connecting to Conjur.
  3802. properties:
  3803. apikey:
  3804. description: Authenticates with Conjur using an API key.
  3805. properties:
  3806. account:
  3807. description: Account is the Conjur organization account name.
  3808. type: string
  3809. apiKeyRef:
  3810. description: |-
  3811. A reference to a specific 'key' containing the Conjur API key
  3812. within a Secret resource. In some instances, `key` is a required field.
  3813. properties:
  3814. key:
  3815. description: |-
  3816. A key in the referenced Secret.
  3817. Some instances of this field may be defaulted, in others it may be required.
  3818. maxLength: 253
  3819. minLength: 1
  3820. pattern: ^[-._a-zA-Z0-9]+$
  3821. type: string
  3822. name:
  3823. description: The name of the Secret resource being referred to.
  3824. maxLength: 253
  3825. minLength: 1
  3826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3827. type: string
  3828. namespace:
  3829. description: |-
  3830. The namespace of the Secret resource being referred to.
  3831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3832. maxLength: 63
  3833. minLength: 1
  3834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3835. type: string
  3836. type: object
  3837. userRef:
  3838. description: |-
  3839. A reference to a specific 'key' containing the Conjur username
  3840. within a Secret resource. In some instances, `key` is a required field.
  3841. properties:
  3842. key:
  3843. description: |-
  3844. A key in the referenced Secret.
  3845. Some instances of this field may be defaulted, in others it may be required.
  3846. maxLength: 253
  3847. minLength: 1
  3848. pattern: ^[-._a-zA-Z0-9]+$
  3849. type: string
  3850. name:
  3851. description: The name of the Secret resource being referred to.
  3852. maxLength: 253
  3853. minLength: 1
  3854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3855. type: string
  3856. namespace:
  3857. description: |-
  3858. The namespace of the Secret resource being referred to.
  3859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3860. maxLength: 63
  3861. minLength: 1
  3862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3863. type: string
  3864. type: object
  3865. required:
  3866. - account
  3867. - apiKeyRef
  3868. - userRef
  3869. type: object
  3870. jwt:
  3871. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3872. properties:
  3873. account:
  3874. description: Account is the Conjur organization account name.
  3875. type: string
  3876. hostId:
  3877. description: |-
  3878. Optional HostID for JWT authentication. This may be used depending
  3879. on how the Conjur JWT authenticator policy is configured.
  3880. type: string
  3881. secretRef:
  3882. description: |-
  3883. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3884. authenticate with Conjur using the JWT authentication method.
  3885. properties:
  3886. key:
  3887. description: |-
  3888. A key in the referenced Secret.
  3889. Some instances of this field may be defaulted, in others it may be required.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[-._a-zA-Z0-9]+$
  3893. type: string
  3894. name:
  3895. description: The name of the Secret resource being referred to.
  3896. maxLength: 253
  3897. minLength: 1
  3898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3899. type: string
  3900. namespace:
  3901. description: |-
  3902. The namespace of the Secret resource being referred to.
  3903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3904. maxLength: 63
  3905. minLength: 1
  3906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3907. type: string
  3908. type: object
  3909. serviceAccountRef:
  3910. description: |-
  3911. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3912. a token for with the `TokenRequest` API.
  3913. properties:
  3914. audiences:
  3915. description: |-
  3916. Audience specifies the `aud` claim for the service account token
  3917. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3918. then this audiences will be appended to the list
  3919. items:
  3920. type: string
  3921. type: array
  3922. name:
  3923. description: The name of the ServiceAccount resource being referred to.
  3924. maxLength: 253
  3925. minLength: 1
  3926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3927. type: string
  3928. namespace:
  3929. description: |-
  3930. Namespace of the resource being referred to.
  3931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3932. maxLength: 63
  3933. minLength: 1
  3934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3935. type: string
  3936. required:
  3937. - name
  3938. type: object
  3939. serviceID:
  3940. description: The conjur authn jwt webservice id
  3941. type: string
  3942. required:
  3943. - account
  3944. - serviceID
  3945. type: object
  3946. type: object
  3947. caBundle:
  3948. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  3949. type: string
  3950. caProvider:
  3951. description: |-
  3952. Used to provide custom certificate authority (CA) certificates
  3953. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  3954. that contains a PEM-encoded certificate.
  3955. properties:
  3956. key:
  3957. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3958. maxLength: 253
  3959. minLength: 1
  3960. pattern: ^[-._a-zA-Z0-9]+$
  3961. type: string
  3962. name:
  3963. description: The name of the object located at the provider type.
  3964. maxLength: 253
  3965. minLength: 1
  3966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3967. type: string
  3968. namespace:
  3969. description: |-
  3970. The namespace the Provider type is in.
  3971. Can only be defined when used in a ClusterSecretStore.
  3972. maxLength: 63
  3973. minLength: 1
  3974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3975. type: string
  3976. type:
  3977. description: The type of provider to use such as "Secret", or "ConfigMap".
  3978. enum:
  3979. - Secret
  3980. - ConfigMap
  3981. type: string
  3982. required:
  3983. - name
  3984. - type
  3985. type: object
  3986. url:
  3987. description: URL is the endpoint of the Conjur instance.
  3988. type: string
  3989. required:
  3990. - auth
  3991. - url
  3992. type: object
  3993. delinea:
  3994. description: |-
  3995. Delinea DevOps Secrets Vault
  3996. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  3997. properties:
  3998. clientId:
  3999. description: ClientID is the non-secret part of the credential.
  4000. properties:
  4001. secretRef:
  4002. description: SecretRef references a key in a secret that will be used as value.
  4003. properties:
  4004. key:
  4005. description: |-
  4006. A key in the referenced Secret.
  4007. Some instances of this field may be defaulted, in others it may be required.
  4008. maxLength: 253
  4009. minLength: 1
  4010. pattern: ^[-._a-zA-Z0-9]+$
  4011. type: string
  4012. name:
  4013. description: The name of the Secret resource being referred to.
  4014. maxLength: 253
  4015. minLength: 1
  4016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4017. type: string
  4018. namespace:
  4019. description: |-
  4020. The namespace of the Secret resource being referred to.
  4021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4022. maxLength: 63
  4023. minLength: 1
  4024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4025. type: string
  4026. type: object
  4027. value:
  4028. description: Value can be specified directly to set a value without using a secret.
  4029. type: string
  4030. type: object
  4031. clientSecret:
  4032. description: ClientSecret is the secret part of the credential.
  4033. properties:
  4034. secretRef:
  4035. description: SecretRef references a key in a secret that will be used as value.
  4036. properties:
  4037. key:
  4038. description: |-
  4039. A key in the referenced Secret.
  4040. Some instances of this field may be defaulted, in others it may be required.
  4041. maxLength: 253
  4042. minLength: 1
  4043. pattern: ^[-._a-zA-Z0-9]+$
  4044. type: string
  4045. name:
  4046. description: The name of the Secret resource being referred to.
  4047. maxLength: 253
  4048. minLength: 1
  4049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4050. type: string
  4051. namespace:
  4052. description: |-
  4053. The namespace of the Secret resource being referred to.
  4054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4055. maxLength: 63
  4056. minLength: 1
  4057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4058. type: string
  4059. type: object
  4060. value:
  4061. description: Value can be specified directly to set a value without using a secret.
  4062. type: string
  4063. type: object
  4064. tenant:
  4065. description: Tenant is the chosen hostname / site name.
  4066. type: string
  4067. tld:
  4068. description: |-
  4069. TLD is based on the server location that was chosen during provisioning.
  4070. If unset, defaults to "com".
  4071. type: string
  4072. urlTemplate:
  4073. description: |-
  4074. URLTemplate
  4075. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4076. type: string
  4077. required:
  4078. - clientId
  4079. - clientSecret
  4080. - tenant
  4081. type: object
  4082. doppler:
  4083. description: Doppler configures this store to sync secrets using the Doppler provider
  4084. properties:
  4085. auth:
  4086. description: Auth configures how the Operator authenticates with the Doppler API
  4087. properties:
  4088. oidcConfig:
  4089. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4090. properties:
  4091. expirationSeconds:
  4092. default: 600
  4093. description: |-
  4094. ExpirationSeconds sets the ServiceAccount token validity duration.
  4095. Defaults to 10 minutes.
  4096. format: int64
  4097. type: integer
  4098. identity:
  4099. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4100. type: string
  4101. serviceAccountRef:
  4102. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4103. properties:
  4104. audiences:
  4105. description: |-
  4106. Audience specifies the `aud` claim for the service account token
  4107. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4108. then this audiences will be appended to the list
  4109. items:
  4110. type: string
  4111. type: array
  4112. name:
  4113. description: The name of the ServiceAccount resource being referred to.
  4114. maxLength: 253
  4115. minLength: 1
  4116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4117. type: string
  4118. namespace:
  4119. description: |-
  4120. Namespace of the resource being referred to.
  4121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4122. maxLength: 63
  4123. minLength: 1
  4124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4125. type: string
  4126. required:
  4127. - name
  4128. type: object
  4129. required:
  4130. - identity
  4131. - serviceAccountRef
  4132. type: object
  4133. secretRef:
  4134. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4135. properties:
  4136. dopplerToken:
  4137. description: |-
  4138. The DopplerToken is used for authentication.
  4139. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4140. The Key attribute defaults to dopplerToken if not specified.
  4141. properties:
  4142. key:
  4143. description: |-
  4144. A key in the referenced Secret.
  4145. Some instances of this field may be defaulted, in others it may be required.
  4146. maxLength: 253
  4147. minLength: 1
  4148. pattern: ^[-._a-zA-Z0-9]+$
  4149. type: string
  4150. name:
  4151. description: The name of the Secret resource being referred to.
  4152. maxLength: 253
  4153. minLength: 1
  4154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4155. type: string
  4156. namespace:
  4157. description: |-
  4158. The namespace of the Secret resource being referred to.
  4159. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4160. maxLength: 63
  4161. minLength: 1
  4162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4163. type: string
  4164. type: object
  4165. required:
  4166. - dopplerToken
  4167. type: object
  4168. type: object
  4169. x-kubernetes-validations:
  4170. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4171. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4172. config:
  4173. description: Doppler config (required if not using a Service Token)
  4174. type: string
  4175. format:
  4176. description: Format enables the downloading of secrets as a file (string)
  4177. enum:
  4178. - json
  4179. - dotnet-json
  4180. - env
  4181. - yaml
  4182. - docker
  4183. type: string
  4184. nameTransformer:
  4185. description: Environment variable compatible name transforms that change secret names to a different format
  4186. enum:
  4187. - upper-camel
  4188. - camel
  4189. - lower-snake
  4190. - tf-var
  4191. - dotnet-env
  4192. - lower-kebab
  4193. type: string
  4194. project:
  4195. description: Doppler project (required if not using a Service Token)
  4196. type: string
  4197. required:
  4198. - auth
  4199. type: object
  4200. dvls:
  4201. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4202. properties:
  4203. auth:
  4204. description: Auth defines the authentication method to use.
  4205. properties:
  4206. secretRef:
  4207. description: SecretRef contains the Application ID and Application Secret for authentication.
  4208. properties:
  4209. appId:
  4210. description: AppID is the reference to the secret containing the Application ID.
  4211. properties:
  4212. key:
  4213. description: |-
  4214. A key in the referenced Secret.
  4215. Some instances of this field may be defaulted, in others it may be required.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[-._a-zA-Z0-9]+$
  4219. type: string
  4220. name:
  4221. description: The name of the Secret resource being referred to.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4225. type: string
  4226. namespace:
  4227. description: |-
  4228. The namespace of the Secret resource being referred to.
  4229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4230. maxLength: 63
  4231. minLength: 1
  4232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4233. type: string
  4234. type: object
  4235. appSecret:
  4236. description: AppSecret is the reference to the secret containing the Application Secret.
  4237. properties:
  4238. key:
  4239. description: |-
  4240. A key in the referenced Secret.
  4241. Some instances of this field may be defaulted, in others it may be required.
  4242. maxLength: 253
  4243. minLength: 1
  4244. pattern: ^[-._a-zA-Z0-9]+$
  4245. type: string
  4246. name:
  4247. description: The name of the Secret resource being referred to.
  4248. maxLength: 253
  4249. minLength: 1
  4250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4251. type: string
  4252. namespace:
  4253. description: |-
  4254. The namespace of the Secret resource being referred to.
  4255. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4256. maxLength: 63
  4257. minLength: 1
  4258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4259. type: string
  4260. type: object
  4261. required:
  4262. - appId
  4263. - appSecret
  4264. type: object
  4265. required:
  4266. - secretRef
  4267. type: object
  4268. insecure:
  4269. description: |-
  4270. Insecure allows connecting to DVLS over plain HTTP.
  4271. This is NOT RECOMMENDED for production use.
  4272. Set to true only if you understand the security implications.
  4273. type: boolean
  4274. serverUrl:
  4275. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4276. type: string
  4277. vault:
  4278. description: |-
  4279. Vault is the name or UUID of the vault to fetch secrets from.
  4280. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4281. type: string
  4282. required:
  4283. - auth
  4284. - serverUrl
  4285. type: object
  4286. fake:
  4287. description: Fake configures a store with static key/value pairs
  4288. properties:
  4289. data:
  4290. items:
  4291. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4292. properties:
  4293. key:
  4294. type: string
  4295. value:
  4296. type: string
  4297. version:
  4298. type: string
  4299. required:
  4300. - key
  4301. - value
  4302. type: object
  4303. type: array
  4304. validationResult:
  4305. description: ValidationResult is defined type for the number of validation results.
  4306. type: integer
  4307. required:
  4308. - data
  4309. type: object
  4310. fortanix:
  4311. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4312. properties:
  4313. apiKey:
  4314. description: APIKey is the API token to access SDKMS Applications.
  4315. properties:
  4316. secretRef:
  4317. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4318. properties:
  4319. key:
  4320. description: |-
  4321. A key in the referenced Secret.
  4322. Some instances of this field may be defaulted, in others it may be required.
  4323. maxLength: 253
  4324. minLength: 1
  4325. pattern: ^[-._a-zA-Z0-9]+$
  4326. type: string
  4327. name:
  4328. description: The name of the Secret resource being referred to.
  4329. maxLength: 253
  4330. minLength: 1
  4331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4332. type: string
  4333. namespace:
  4334. description: |-
  4335. The namespace of the Secret resource being referred to.
  4336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4337. maxLength: 63
  4338. minLength: 1
  4339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4340. type: string
  4341. type: object
  4342. type: object
  4343. apiUrl:
  4344. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4345. type: string
  4346. type: object
  4347. gcpsm:
  4348. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4349. properties:
  4350. auth:
  4351. description: Auth defines the information necessary to authenticate against GCP
  4352. properties:
  4353. secretRef:
  4354. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4355. properties:
  4356. secretAccessKeySecretRef:
  4357. description: The SecretAccessKey is used for authentication
  4358. properties:
  4359. key:
  4360. description: |-
  4361. A key in the referenced Secret.
  4362. Some instances of this field may be defaulted, in others it may be required.
  4363. maxLength: 253
  4364. minLength: 1
  4365. pattern: ^[-._a-zA-Z0-9]+$
  4366. type: string
  4367. name:
  4368. description: The name of the Secret resource being referred to.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4372. type: string
  4373. namespace:
  4374. description: |-
  4375. The namespace of the Secret resource being referred to.
  4376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4377. maxLength: 63
  4378. minLength: 1
  4379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4380. type: string
  4381. type: object
  4382. type: object
  4383. workloadIdentity:
  4384. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4385. properties:
  4386. clusterLocation:
  4387. description: |-
  4388. ClusterLocation is the location of the cluster
  4389. If not specified, it fetches information from the metadata server
  4390. type: string
  4391. clusterName:
  4392. description: |-
  4393. ClusterName is the name of the cluster
  4394. If not specified, it fetches information from the metadata server
  4395. type: string
  4396. clusterProjectID:
  4397. description: |-
  4398. ClusterProjectID is the project ID of the cluster
  4399. If not specified, it fetches information from the metadata server
  4400. type: string
  4401. serviceAccountRef:
  4402. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4403. properties:
  4404. audiences:
  4405. description: |-
  4406. Audience specifies the `aud` claim for the service account token
  4407. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4408. then this audiences will be appended to the list
  4409. items:
  4410. type: string
  4411. type: array
  4412. name:
  4413. description: The name of the ServiceAccount resource being referred to.
  4414. maxLength: 253
  4415. minLength: 1
  4416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4417. type: string
  4418. namespace:
  4419. description: |-
  4420. Namespace of the resource being referred to.
  4421. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4422. maxLength: 63
  4423. minLength: 1
  4424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4425. type: string
  4426. required:
  4427. - name
  4428. type: object
  4429. required:
  4430. - serviceAccountRef
  4431. type: object
  4432. workloadIdentityFederation:
  4433. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4434. properties:
  4435. audience:
  4436. description: |-
  4437. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4438. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4439. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4440. type: string
  4441. awsSecurityCredentials:
  4442. description: |-
  4443. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4444. when using the AWS metadata server is not an option.
  4445. properties:
  4446. awsCredentialsSecretRef:
  4447. description: |-
  4448. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4449. Secret should be created with below names for keys
  4450. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4451. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4452. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4453. properties:
  4454. name:
  4455. description: name of the secret.
  4456. maxLength: 253
  4457. minLength: 1
  4458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4459. type: string
  4460. namespace:
  4461. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4462. maxLength: 63
  4463. minLength: 1
  4464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4465. type: string
  4466. required:
  4467. - name
  4468. type: object
  4469. region:
  4470. description: region is for configuring the AWS region to be used.
  4471. example: ap-south-1
  4472. maxLength: 50
  4473. minLength: 1
  4474. pattern: ^[a-z0-9-]+$
  4475. type: string
  4476. required:
  4477. - awsCredentialsSecretRef
  4478. - region
  4479. type: object
  4480. credConfig:
  4481. description: |-
  4482. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4483. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4484. serviceAccountRef must be used by providing operators service account details.
  4485. properties:
  4486. key:
  4487. description: key name holding the external account credential config.
  4488. maxLength: 253
  4489. minLength: 1
  4490. pattern: ^[-._a-zA-Z0-9]+$
  4491. type: string
  4492. name:
  4493. description: name of the configmap.
  4494. maxLength: 253
  4495. minLength: 1
  4496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4497. type: string
  4498. namespace:
  4499. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4500. maxLength: 63
  4501. minLength: 1
  4502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4503. type: string
  4504. required:
  4505. - key
  4506. - name
  4507. type: object
  4508. externalTokenEndpoint:
  4509. description: |-
  4510. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4511. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4512. URL is having the expected value.
  4513. type: string
  4514. gcpServiceAccountEmail:
  4515. description: |-
  4516. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4517. after Workload Identity Federation. Use this to grant access through the service account's
  4518. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4519. service_account_impersonation_url in the external account JSON from credConfig;
  4520. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4521. on that ServiceAccount.
  4522. example: my-gsa@my-project.iam.gserviceaccount.com
  4523. minLength: 1
  4524. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4525. type: string
  4526. serviceAccountRef:
  4527. description: |-
  4528. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4529. when Kubernetes is configured as provider in workload identity pool.
  4530. properties:
  4531. audiences:
  4532. description: |-
  4533. Audience specifies the `aud` claim for the service account token
  4534. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4535. then this audiences will be appended to the list
  4536. items:
  4537. type: string
  4538. type: array
  4539. name:
  4540. description: The name of the ServiceAccount resource being referred to.
  4541. maxLength: 253
  4542. minLength: 1
  4543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4544. type: string
  4545. namespace:
  4546. description: |-
  4547. Namespace of the resource being referred to.
  4548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4549. maxLength: 63
  4550. minLength: 1
  4551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4552. type: string
  4553. required:
  4554. - name
  4555. type: object
  4556. type: object
  4557. type: object
  4558. location:
  4559. description: Location optionally defines a location for a secret
  4560. type: string
  4561. projectID:
  4562. description: ProjectID project where secret is located
  4563. type: string
  4564. secretVersionSelectionPolicy:
  4565. default: LatestOrFail
  4566. description: |-
  4567. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4568. when "latest" is disabled or destroyed.
  4569. Possible values are:
  4570. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4571. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4572. type: string
  4573. type: object
  4574. github:
  4575. description: |-
  4576. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4577. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4578. properties:
  4579. appID:
  4580. description: appID specifies the Github APP that will be used to authenticate the client
  4581. format: int64
  4582. type: integer
  4583. auth:
  4584. description: auth configures how secret-manager authenticates with a Github instance.
  4585. properties:
  4586. privateKey:
  4587. description: |-
  4588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4589. In some instances, `key` is a required field.
  4590. properties:
  4591. key:
  4592. description: |-
  4593. A key in the referenced Secret.
  4594. Some instances of this field may be defaulted, in others it may be required.
  4595. maxLength: 253
  4596. minLength: 1
  4597. pattern: ^[-._a-zA-Z0-9]+$
  4598. type: string
  4599. name:
  4600. description: The name of the Secret resource being referred to.
  4601. maxLength: 253
  4602. minLength: 1
  4603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4604. type: string
  4605. namespace:
  4606. description: |-
  4607. The namespace of the Secret resource being referred to.
  4608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4609. maxLength: 63
  4610. minLength: 1
  4611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4612. type: string
  4613. type: object
  4614. required:
  4615. - privateKey
  4616. type: object
  4617. environment:
  4618. description: environment will be used to fetch secrets from a particular environment within a github repository
  4619. type: string
  4620. installationID:
  4621. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4622. format: int64
  4623. type: integer
  4624. orgSecretVisibility:
  4625. description: |-
  4626. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4627. Valid values are "all" or "private".
  4628. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4629. whatever visibility they already have in GitHub.
  4630. enum:
  4631. - all
  4632. - private
  4633. type: string
  4634. organization:
  4635. description: organization will be used to fetch secrets from the Github organization
  4636. type: string
  4637. repository:
  4638. description: repository will be used to fetch secrets from the Github repository within an organization
  4639. type: string
  4640. uploadURL:
  4641. description: Upload URL for enterprise instances. Default to URL.
  4642. type: string
  4643. url:
  4644. default: https://github.com/
  4645. description: URL configures the Github instance URL. Defaults to https://github.com/.
  4646. type: string
  4647. required:
  4648. - appID
  4649. - auth
  4650. - installationID
  4651. - organization
  4652. type: object
  4653. gitlab:
  4654. description: GitLab configures this store to sync secrets using GitLab Variables provider
  4655. properties:
  4656. auth:
  4657. description: Auth configures how secret-manager authenticates with a GitLab instance.
  4658. properties:
  4659. SecretRef:
  4660. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  4661. properties:
  4662. accessToken:
  4663. description: AccessToken is used for authentication.
  4664. properties:
  4665. key:
  4666. description: |-
  4667. A key in the referenced Secret.
  4668. Some instances of this field may be defaulted, in others it may be required.
  4669. maxLength: 253
  4670. minLength: 1
  4671. pattern: ^[-._a-zA-Z0-9]+$
  4672. type: string
  4673. name:
  4674. description: The name of the Secret resource being referred to.
  4675. maxLength: 253
  4676. minLength: 1
  4677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4678. type: string
  4679. namespace:
  4680. description: |-
  4681. The namespace of the Secret resource being referred to.
  4682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4683. maxLength: 63
  4684. minLength: 1
  4685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4686. type: string
  4687. type: object
  4688. type: object
  4689. required:
  4690. - SecretRef
  4691. type: object
  4692. caBundle:
  4693. description: |-
  4694. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  4695. can be performed.
  4696. format: byte
  4697. type: string
  4698. caProvider:
  4699. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4700. properties:
  4701. key:
  4702. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4703. maxLength: 253
  4704. minLength: 1
  4705. pattern: ^[-._a-zA-Z0-9]+$
  4706. type: string
  4707. name:
  4708. description: The name of the object located at the provider type.
  4709. maxLength: 253
  4710. minLength: 1
  4711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4712. type: string
  4713. namespace:
  4714. description: |-
  4715. The namespace the Provider type is in.
  4716. Can only be defined when used in a ClusterSecretStore.
  4717. maxLength: 63
  4718. minLength: 1
  4719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4720. type: string
  4721. type:
  4722. description: The type of provider to use such as "Secret", or "ConfigMap".
  4723. enum:
  4724. - Secret
  4725. - ConfigMap
  4726. type: string
  4727. required:
  4728. - name
  4729. - type
  4730. type: object
  4731. environment:
  4732. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  4733. type: string
  4734. groupIDs:
  4735. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  4736. items:
  4737. type: string
  4738. type: array
  4739. inheritFromGroups:
  4740. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  4741. type: boolean
  4742. projectID:
  4743. description: ProjectID specifies a project where secrets are located.
  4744. type: string
  4745. url:
  4746. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  4747. type: string
  4748. required:
  4749. - auth
  4750. type: object
  4751. ibm:
  4752. description: IBM configures this store to sync secrets using IBM Cloud provider
  4753. properties:
  4754. auth:
  4755. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  4756. maxProperties: 1
  4757. minProperties: 1
  4758. properties:
  4759. containerAuth:
  4760. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  4761. properties:
  4762. iamEndpoint:
  4763. type: string
  4764. profile:
  4765. description: the IBM Trusted Profile
  4766. type: string
  4767. tokenLocation:
  4768. description: Location the token is mounted on the pod
  4769. type: string
  4770. required:
  4771. - profile
  4772. type: object
  4773. secretRef:
  4774. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  4775. properties:
  4776. iamEndpoint:
  4777. description: The IAM endpoint used to obain a token
  4778. type: string
  4779. secretApiKeySecretRef:
  4780. description: The SecretAccessKey is used for authentication
  4781. properties:
  4782. key:
  4783. description: |-
  4784. A key in the referenced Secret.
  4785. Some instances of this field may be defaulted, in others it may be required.
  4786. maxLength: 253
  4787. minLength: 1
  4788. pattern: ^[-._a-zA-Z0-9]+$
  4789. type: string
  4790. name:
  4791. description: The name of the Secret resource being referred to.
  4792. maxLength: 253
  4793. minLength: 1
  4794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4795. type: string
  4796. namespace:
  4797. description: |-
  4798. The namespace of the Secret resource being referred to.
  4799. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4800. maxLength: 63
  4801. minLength: 1
  4802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4803. type: string
  4804. type: object
  4805. type: object
  4806. type: object
  4807. serviceUrl:
  4808. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  4809. type: string
  4810. required:
  4811. - auth
  4812. type: object
  4813. infisical:
  4814. description: Infisical configures this store to sync secrets using the Infisical provider
  4815. properties:
  4816. auth:
  4817. description: Auth configures how the Operator authenticates with the Infisical API
  4818. properties:
  4819. awsAuthCredentials:
  4820. description: AwsAuthCredentials represents the credentials for AWS authentication.
  4821. properties:
  4822. identityId:
  4823. description: |-
  4824. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4825. In some instances, `key` is a required field.
  4826. properties:
  4827. key:
  4828. description: |-
  4829. A key in the referenced Secret.
  4830. Some instances of this field may be defaulted, in others it may be required.
  4831. maxLength: 253
  4832. minLength: 1
  4833. pattern: ^[-._a-zA-Z0-9]+$
  4834. type: string
  4835. name:
  4836. description: The name of the Secret resource being referred to.
  4837. maxLength: 253
  4838. minLength: 1
  4839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4840. type: string
  4841. namespace:
  4842. description: |-
  4843. The namespace of the Secret resource being referred to.
  4844. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4845. maxLength: 63
  4846. minLength: 1
  4847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4848. type: string
  4849. type: object
  4850. required:
  4851. - identityId
  4852. type: object
  4853. azureAuthCredentials:
  4854. description: AzureAuthCredentials represents the credentials for Azure authentication.
  4855. properties:
  4856. identityId:
  4857. description: |-
  4858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4859. In some instances, `key` is a required field.
  4860. properties:
  4861. key:
  4862. description: |-
  4863. A key in the referenced Secret.
  4864. Some instances of this field may be defaulted, in others it may be required.
  4865. maxLength: 253
  4866. minLength: 1
  4867. pattern: ^[-._a-zA-Z0-9]+$
  4868. type: string
  4869. name:
  4870. description: The name of the Secret resource being referred to.
  4871. maxLength: 253
  4872. minLength: 1
  4873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4874. type: string
  4875. namespace:
  4876. description: |-
  4877. The namespace of the Secret resource being referred to.
  4878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4879. maxLength: 63
  4880. minLength: 1
  4881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4882. type: string
  4883. type: object
  4884. resource:
  4885. description: |-
  4886. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4887. In some instances, `key` is a required field.
  4888. properties:
  4889. key:
  4890. description: |-
  4891. A key in the referenced Secret.
  4892. Some instances of this field may be defaulted, in others it may be required.
  4893. maxLength: 253
  4894. minLength: 1
  4895. pattern: ^[-._a-zA-Z0-9]+$
  4896. type: string
  4897. name:
  4898. description: The name of the Secret resource being referred to.
  4899. maxLength: 253
  4900. minLength: 1
  4901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4902. type: string
  4903. namespace:
  4904. description: |-
  4905. The namespace of the Secret resource being referred to.
  4906. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4907. maxLength: 63
  4908. minLength: 1
  4909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4910. type: string
  4911. type: object
  4912. required:
  4913. - identityId
  4914. type: object
  4915. gcpIamAuthCredentials:
  4916. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  4917. properties:
  4918. identityId:
  4919. description: |-
  4920. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4921. In some instances, `key` is a required field.
  4922. properties:
  4923. key:
  4924. description: |-
  4925. A key in the referenced Secret.
  4926. Some instances of this field may be defaulted, in others it may be required.
  4927. maxLength: 253
  4928. minLength: 1
  4929. pattern: ^[-._a-zA-Z0-9]+$
  4930. type: string
  4931. name:
  4932. description: The name of the Secret resource being referred to.
  4933. maxLength: 253
  4934. minLength: 1
  4935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4936. type: string
  4937. namespace:
  4938. description: |-
  4939. The namespace of the Secret resource being referred to.
  4940. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4941. maxLength: 63
  4942. minLength: 1
  4943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4944. type: string
  4945. type: object
  4946. serviceAccountKeyFilePath:
  4947. description: |-
  4948. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4949. In some instances, `key` is a required field.
  4950. properties:
  4951. key:
  4952. description: |-
  4953. A key in the referenced Secret.
  4954. Some instances of this field may be defaulted, in others it may be required.
  4955. maxLength: 253
  4956. minLength: 1
  4957. pattern: ^[-._a-zA-Z0-9]+$
  4958. type: string
  4959. name:
  4960. description: The name of the Secret resource being referred to.
  4961. maxLength: 253
  4962. minLength: 1
  4963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4964. type: string
  4965. namespace:
  4966. description: |-
  4967. The namespace of the Secret resource being referred to.
  4968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4969. maxLength: 63
  4970. minLength: 1
  4971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4972. type: string
  4973. type: object
  4974. required:
  4975. - identityId
  4976. - serviceAccountKeyFilePath
  4977. type: object
  4978. gcpIdTokenAuthCredentials:
  4979. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  4980. properties:
  4981. identityId:
  4982. description: |-
  4983. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4984. In some instances, `key` is a required field.
  4985. properties:
  4986. key:
  4987. description: |-
  4988. A key in the referenced Secret.
  4989. Some instances of this field may be defaulted, in others it may be required.
  4990. maxLength: 253
  4991. minLength: 1
  4992. pattern: ^[-._a-zA-Z0-9]+$
  4993. type: string
  4994. name:
  4995. description: The name of the Secret resource being referred to.
  4996. maxLength: 253
  4997. minLength: 1
  4998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4999. type: string
  5000. namespace:
  5001. description: |-
  5002. The namespace of the Secret resource being referred to.
  5003. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5004. maxLength: 63
  5005. minLength: 1
  5006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5007. type: string
  5008. type: object
  5009. required:
  5010. - identityId
  5011. type: object
  5012. jwtAuthCredentials:
  5013. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5014. properties:
  5015. identityId:
  5016. description: |-
  5017. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5018. In some instances, `key` is a required field.
  5019. properties:
  5020. key:
  5021. description: |-
  5022. A key in the referenced Secret.
  5023. Some instances of this field may be defaulted, in others it may be required.
  5024. maxLength: 253
  5025. minLength: 1
  5026. pattern: ^[-._a-zA-Z0-9]+$
  5027. type: string
  5028. name:
  5029. description: The name of the Secret resource being referred to.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5033. type: string
  5034. namespace:
  5035. description: |-
  5036. The namespace of the Secret resource being referred to.
  5037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5038. maxLength: 63
  5039. minLength: 1
  5040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5041. type: string
  5042. type: object
  5043. jwt:
  5044. description: |-
  5045. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5046. In some instances, `key` is a required field.
  5047. properties:
  5048. key:
  5049. description: |-
  5050. A key in the referenced Secret.
  5051. Some instances of this field may be defaulted, in others it may be required.
  5052. maxLength: 253
  5053. minLength: 1
  5054. pattern: ^[-._a-zA-Z0-9]+$
  5055. type: string
  5056. name:
  5057. description: The name of the Secret resource being referred to.
  5058. maxLength: 253
  5059. minLength: 1
  5060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5061. type: string
  5062. namespace:
  5063. description: |-
  5064. The namespace of the Secret resource being referred to.
  5065. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5066. maxLength: 63
  5067. minLength: 1
  5068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5069. type: string
  5070. type: object
  5071. required:
  5072. - identityId
  5073. - jwt
  5074. type: object
  5075. kubernetesAuthCredentials:
  5076. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5077. properties:
  5078. identityId:
  5079. description: |-
  5080. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5081. In some instances, `key` is a required field.
  5082. properties:
  5083. key:
  5084. description: |-
  5085. A key in the referenced Secret.
  5086. Some instances of this field may be defaulted, in others it may be required.
  5087. maxLength: 253
  5088. minLength: 1
  5089. pattern: ^[-._a-zA-Z0-9]+$
  5090. type: string
  5091. name:
  5092. description: The name of the Secret resource being referred to.
  5093. maxLength: 253
  5094. minLength: 1
  5095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5096. type: string
  5097. namespace:
  5098. description: |-
  5099. The namespace of the Secret resource being referred to.
  5100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5101. maxLength: 63
  5102. minLength: 1
  5103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5104. type: string
  5105. type: object
  5106. serviceAccountTokenPath:
  5107. description: |-
  5108. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5109. In some instances, `key` is a required field.
  5110. properties:
  5111. key:
  5112. description: |-
  5113. A key in the referenced Secret.
  5114. Some instances of this field may be defaulted, in others it may be required.
  5115. maxLength: 253
  5116. minLength: 1
  5117. pattern: ^[-._a-zA-Z0-9]+$
  5118. type: string
  5119. name:
  5120. description: The name of the Secret resource being referred to.
  5121. maxLength: 253
  5122. minLength: 1
  5123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5124. type: string
  5125. namespace:
  5126. description: |-
  5127. The namespace of the Secret resource being referred to.
  5128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5129. maxLength: 63
  5130. minLength: 1
  5131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5132. type: string
  5133. type: object
  5134. required:
  5135. - identityId
  5136. type: object
  5137. ldapAuthCredentials:
  5138. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5139. properties:
  5140. identityId:
  5141. description: |-
  5142. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5143. In some instances, `key` is a required field.
  5144. properties:
  5145. key:
  5146. description: |-
  5147. A key in the referenced Secret.
  5148. Some instances of this field may be defaulted, in others it may be required.
  5149. maxLength: 253
  5150. minLength: 1
  5151. pattern: ^[-._a-zA-Z0-9]+$
  5152. type: string
  5153. name:
  5154. description: The name of the Secret resource being referred to.
  5155. maxLength: 253
  5156. minLength: 1
  5157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5158. type: string
  5159. namespace:
  5160. description: |-
  5161. The namespace of the Secret resource being referred to.
  5162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5163. maxLength: 63
  5164. minLength: 1
  5165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5166. type: string
  5167. type: object
  5168. ldapPassword:
  5169. description: |-
  5170. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5171. In some instances, `key` is a required field.
  5172. properties:
  5173. key:
  5174. description: |-
  5175. A key in the referenced Secret.
  5176. Some instances of this field may be defaulted, in others it may be required.
  5177. maxLength: 253
  5178. minLength: 1
  5179. pattern: ^[-._a-zA-Z0-9]+$
  5180. type: string
  5181. name:
  5182. description: The name of the Secret resource being referred to.
  5183. maxLength: 253
  5184. minLength: 1
  5185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5186. type: string
  5187. namespace:
  5188. description: |-
  5189. The namespace of the Secret resource being referred to.
  5190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5191. maxLength: 63
  5192. minLength: 1
  5193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5194. type: string
  5195. type: object
  5196. ldapUsername:
  5197. description: |-
  5198. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5199. In some instances, `key` is a required field.
  5200. properties:
  5201. key:
  5202. description: |-
  5203. A key in the referenced Secret.
  5204. Some instances of this field may be defaulted, in others it may be required.
  5205. maxLength: 253
  5206. minLength: 1
  5207. pattern: ^[-._a-zA-Z0-9]+$
  5208. type: string
  5209. name:
  5210. description: The name of the Secret resource being referred to.
  5211. maxLength: 253
  5212. minLength: 1
  5213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5214. type: string
  5215. namespace:
  5216. description: |-
  5217. The namespace of the Secret resource being referred to.
  5218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5219. maxLength: 63
  5220. minLength: 1
  5221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5222. type: string
  5223. type: object
  5224. required:
  5225. - identityId
  5226. - ldapPassword
  5227. - ldapUsername
  5228. type: object
  5229. ociAuthCredentials:
  5230. description: OciAuthCredentials represents the credentials for OCI authentication.
  5231. properties:
  5232. fingerprint:
  5233. description: |-
  5234. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5235. In some instances, `key` is a required field.
  5236. properties:
  5237. key:
  5238. description: |-
  5239. A key in the referenced Secret.
  5240. Some instances of this field may be defaulted, in others it may be required.
  5241. maxLength: 253
  5242. minLength: 1
  5243. pattern: ^[-._a-zA-Z0-9]+$
  5244. type: string
  5245. name:
  5246. description: The name of the Secret resource being referred to.
  5247. maxLength: 253
  5248. minLength: 1
  5249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5250. type: string
  5251. namespace:
  5252. description: |-
  5253. The namespace of the Secret resource being referred to.
  5254. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5255. maxLength: 63
  5256. minLength: 1
  5257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5258. type: string
  5259. type: object
  5260. identityId:
  5261. description: |-
  5262. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5263. In some instances, `key` is a required field.
  5264. properties:
  5265. key:
  5266. description: |-
  5267. A key in the referenced Secret.
  5268. Some instances of this field may be defaulted, in others it may be required.
  5269. maxLength: 253
  5270. minLength: 1
  5271. pattern: ^[-._a-zA-Z0-9]+$
  5272. type: string
  5273. name:
  5274. description: The name of the Secret resource being referred to.
  5275. maxLength: 253
  5276. minLength: 1
  5277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5278. type: string
  5279. namespace:
  5280. description: |-
  5281. The namespace of the Secret resource being referred to.
  5282. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5283. maxLength: 63
  5284. minLength: 1
  5285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5286. type: string
  5287. type: object
  5288. privateKey:
  5289. description: |-
  5290. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5291. In some instances, `key` is a required field.
  5292. properties:
  5293. key:
  5294. description: |-
  5295. A key in the referenced Secret.
  5296. Some instances of this field may be defaulted, in others it may be required.
  5297. maxLength: 253
  5298. minLength: 1
  5299. pattern: ^[-._a-zA-Z0-9]+$
  5300. type: string
  5301. name:
  5302. description: The name of the Secret resource being referred to.
  5303. maxLength: 253
  5304. minLength: 1
  5305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5306. type: string
  5307. namespace:
  5308. description: |-
  5309. The namespace of the Secret resource being referred to.
  5310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5311. maxLength: 63
  5312. minLength: 1
  5313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5314. type: string
  5315. type: object
  5316. privateKeyPassphrase:
  5317. description: |-
  5318. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5319. In some instances, `key` is a required field.
  5320. properties:
  5321. key:
  5322. description: |-
  5323. A key in the referenced Secret.
  5324. Some instances of this field may be defaulted, in others it may be required.
  5325. maxLength: 253
  5326. minLength: 1
  5327. pattern: ^[-._a-zA-Z0-9]+$
  5328. type: string
  5329. name:
  5330. description: The name of the Secret resource being referred to.
  5331. maxLength: 253
  5332. minLength: 1
  5333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5334. type: string
  5335. namespace:
  5336. description: |-
  5337. The namespace of the Secret resource being referred to.
  5338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5339. maxLength: 63
  5340. minLength: 1
  5341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5342. type: string
  5343. type: object
  5344. region:
  5345. description: |-
  5346. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5347. In some instances, `key` is a required field.
  5348. properties:
  5349. key:
  5350. description: |-
  5351. A key in the referenced Secret.
  5352. Some instances of this field may be defaulted, in others it may be required.
  5353. maxLength: 253
  5354. minLength: 1
  5355. pattern: ^[-._a-zA-Z0-9]+$
  5356. type: string
  5357. name:
  5358. description: The name of the Secret resource being referred to.
  5359. maxLength: 253
  5360. minLength: 1
  5361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5362. type: string
  5363. namespace:
  5364. description: |-
  5365. The namespace of the Secret resource being referred to.
  5366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5367. maxLength: 63
  5368. minLength: 1
  5369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5370. type: string
  5371. type: object
  5372. tenancyId:
  5373. description: |-
  5374. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5375. In some instances, `key` is a required field.
  5376. properties:
  5377. key:
  5378. description: |-
  5379. A key in the referenced Secret.
  5380. Some instances of this field may be defaulted, in others it may be required.
  5381. maxLength: 253
  5382. minLength: 1
  5383. pattern: ^[-._a-zA-Z0-9]+$
  5384. type: string
  5385. name:
  5386. description: The name of the Secret resource being referred to.
  5387. maxLength: 253
  5388. minLength: 1
  5389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5390. type: string
  5391. namespace:
  5392. description: |-
  5393. The namespace of the Secret resource being referred to.
  5394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5395. maxLength: 63
  5396. minLength: 1
  5397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5398. type: string
  5399. type: object
  5400. userId:
  5401. description: |-
  5402. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5403. In some instances, `key` is a required field.
  5404. properties:
  5405. key:
  5406. description: |-
  5407. A key in the referenced Secret.
  5408. Some instances of this field may be defaulted, in others it may be required.
  5409. maxLength: 253
  5410. minLength: 1
  5411. pattern: ^[-._a-zA-Z0-9]+$
  5412. type: string
  5413. name:
  5414. description: The name of the Secret resource being referred to.
  5415. maxLength: 253
  5416. minLength: 1
  5417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5418. type: string
  5419. namespace:
  5420. description: |-
  5421. The namespace of the Secret resource being referred to.
  5422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5423. maxLength: 63
  5424. minLength: 1
  5425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5426. type: string
  5427. type: object
  5428. required:
  5429. - fingerprint
  5430. - identityId
  5431. - privateKey
  5432. - region
  5433. - tenancyId
  5434. - userId
  5435. type: object
  5436. tokenAuthCredentials:
  5437. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5438. properties:
  5439. accessToken:
  5440. description: |-
  5441. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5442. In some instances, `key` is a required field.
  5443. properties:
  5444. key:
  5445. description: |-
  5446. A key in the referenced Secret.
  5447. Some instances of this field may be defaulted, in others it may be required.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[-._a-zA-Z0-9]+$
  5451. type: string
  5452. name:
  5453. description: The name of the Secret resource being referred to.
  5454. maxLength: 253
  5455. minLength: 1
  5456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5457. type: string
  5458. namespace:
  5459. description: |-
  5460. The namespace of the Secret resource being referred to.
  5461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5462. maxLength: 63
  5463. minLength: 1
  5464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5465. type: string
  5466. type: object
  5467. required:
  5468. - accessToken
  5469. type: object
  5470. universalAuthCredentials:
  5471. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5472. properties:
  5473. clientId:
  5474. description: |-
  5475. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5476. In some instances, `key` is a required field.
  5477. properties:
  5478. key:
  5479. description: |-
  5480. A key in the referenced Secret.
  5481. Some instances of this field may be defaulted, in others it may be required.
  5482. maxLength: 253
  5483. minLength: 1
  5484. pattern: ^[-._a-zA-Z0-9]+$
  5485. type: string
  5486. name:
  5487. description: The name of the Secret resource being referred to.
  5488. maxLength: 253
  5489. minLength: 1
  5490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5491. type: string
  5492. namespace:
  5493. description: |-
  5494. The namespace of the Secret resource being referred to.
  5495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5496. maxLength: 63
  5497. minLength: 1
  5498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5499. type: string
  5500. type: object
  5501. clientSecret:
  5502. description: |-
  5503. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5504. In some instances, `key` is a required field.
  5505. properties:
  5506. key:
  5507. description: |-
  5508. A key in the referenced Secret.
  5509. Some instances of this field may be defaulted, in others it may be required.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[-._a-zA-Z0-9]+$
  5513. type: string
  5514. name:
  5515. description: The name of the Secret resource being referred to.
  5516. maxLength: 253
  5517. minLength: 1
  5518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5519. type: string
  5520. namespace:
  5521. description: |-
  5522. The namespace of the Secret resource being referred to.
  5523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5524. maxLength: 63
  5525. minLength: 1
  5526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5527. type: string
  5528. type: object
  5529. required:
  5530. - clientId
  5531. - clientSecret
  5532. type: object
  5533. type: object
  5534. caBundle:
  5535. description: |-
  5536. CABundle is a PEM-encoded CA certificate bundle used to validate
  5537. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5538. format: byte
  5539. type: string
  5540. caProvider:
  5541. description: |-
  5542. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5543. The certificate is used to validate the Infisical server's TLS certificate.
  5544. Mutually exclusive with CABundle.
  5545. properties:
  5546. key:
  5547. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5548. maxLength: 253
  5549. minLength: 1
  5550. pattern: ^[-._a-zA-Z0-9]+$
  5551. type: string
  5552. name:
  5553. description: The name of the object located at the provider type.
  5554. maxLength: 253
  5555. minLength: 1
  5556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5557. type: string
  5558. namespace:
  5559. description: |-
  5560. The namespace the Provider type is in.
  5561. Can only be defined when used in a ClusterSecretStore.
  5562. maxLength: 63
  5563. minLength: 1
  5564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5565. type: string
  5566. type:
  5567. description: The type of provider to use such as "Secret", or "ConfigMap".
  5568. enum:
  5569. - Secret
  5570. - ConfigMap
  5571. type: string
  5572. required:
  5573. - name
  5574. - type
  5575. type: object
  5576. hostAPI:
  5577. default: https://app.infisical.com/api
  5578. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5579. type: string
  5580. secretsScope:
  5581. description: SecretsScope defines the scope of the secrets within the workspace
  5582. properties:
  5583. environmentSlug:
  5584. description: EnvironmentSlug is the required slug identifier for the environment.
  5585. type: string
  5586. expandSecretReferences:
  5587. default: true
  5588. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5589. type: boolean
  5590. organizationSlug:
  5591. description: |-
  5592. OrganizationSlug is the optional slug that identifies the organization that will be used
  5593. during authentication. Useful for sub-organization setups
  5594. type: string
  5595. projectSlug:
  5596. description: ProjectSlug is the required slug identifier for the project.
  5597. type: string
  5598. recursive:
  5599. default: false
  5600. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5601. type: boolean
  5602. secretsPath:
  5603. default: /
  5604. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5605. type: string
  5606. required:
  5607. - environmentSlug
  5608. - projectSlug
  5609. type: object
  5610. required:
  5611. - auth
  5612. - secretsScope
  5613. type: object
  5614. keepersecurity:
  5615. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5616. properties:
  5617. authRef:
  5618. description: |-
  5619. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5620. In some instances, `key` is a required field.
  5621. properties:
  5622. key:
  5623. description: |-
  5624. A key in the referenced Secret.
  5625. Some instances of this field may be defaulted, in others it may be required.
  5626. maxLength: 253
  5627. minLength: 1
  5628. pattern: ^[-._a-zA-Z0-9]+$
  5629. type: string
  5630. name:
  5631. description: The name of the Secret resource being referred to.
  5632. maxLength: 253
  5633. minLength: 1
  5634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5635. type: string
  5636. namespace:
  5637. description: |-
  5638. The namespace of the Secret resource being referred to.
  5639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5640. maxLength: 63
  5641. minLength: 1
  5642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5643. type: string
  5644. type: object
  5645. folderID:
  5646. type: string
  5647. getByTitleFallback:
  5648. type: boolean
  5649. required:
  5650. - authRef
  5651. - folderID
  5652. type: object
  5653. kubernetes:
  5654. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  5655. properties:
  5656. auth:
  5657. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  5658. maxProperties: 1
  5659. minProperties: 1
  5660. properties:
  5661. cert:
  5662. description: has both clientCert and clientKey as secretKeySelector
  5663. properties:
  5664. clientCert:
  5665. description: |-
  5666. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5667. In some instances, `key` is a required field.
  5668. properties:
  5669. key:
  5670. description: |-
  5671. A key in the referenced Secret.
  5672. Some instances of this field may be defaulted, in others it may be required.
  5673. maxLength: 253
  5674. minLength: 1
  5675. pattern: ^[-._a-zA-Z0-9]+$
  5676. type: string
  5677. name:
  5678. description: The name of the Secret resource being referred to.
  5679. maxLength: 253
  5680. minLength: 1
  5681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5682. type: string
  5683. namespace:
  5684. description: |-
  5685. The namespace of the Secret resource being referred to.
  5686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5687. maxLength: 63
  5688. minLength: 1
  5689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5690. type: string
  5691. type: object
  5692. clientKey:
  5693. description: |-
  5694. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5695. In some instances, `key` is a required field.
  5696. properties:
  5697. key:
  5698. description: |-
  5699. A key in the referenced Secret.
  5700. Some instances of this field may be defaulted, in others it may be required.
  5701. maxLength: 253
  5702. minLength: 1
  5703. pattern: ^[-._a-zA-Z0-9]+$
  5704. type: string
  5705. name:
  5706. description: The name of the Secret resource being referred to.
  5707. maxLength: 253
  5708. minLength: 1
  5709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5710. type: string
  5711. namespace:
  5712. description: |-
  5713. The namespace of the Secret resource being referred to.
  5714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5715. maxLength: 63
  5716. minLength: 1
  5717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5718. type: string
  5719. type: object
  5720. type: object
  5721. serviceAccount:
  5722. description: points to a service account that should be used for authentication
  5723. properties:
  5724. audiences:
  5725. description: |-
  5726. Audience specifies the `aud` claim for the service account token
  5727. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  5728. then this audiences will be appended to the list
  5729. items:
  5730. type: string
  5731. type: array
  5732. name:
  5733. description: The name of the ServiceAccount resource being referred to.
  5734. maxLength: 253
  5735. minLength: 1
  5736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5737. type: string
  5738. namespace:
  5739. description: |-
  5740. Namespace of the resource being referred to.
  5741. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5742. maxLength: 63
  5743. minLength: 1
  5744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5745. type: string
  5746. required:
  5747. - name
  5748. type: object
  5749. token:
  5750. description: use static token to authenticate with
  5751. properties:
  5752. bearerToken:
  5753. description: |-
  5754. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5755. In some instances, `key` is a required field.
  5756. properties:
  5757. key:
  5758. description: |-
  5759. A key in the referenced Secret.
  5760. Some instances of this field may be defaulted, in others it may be required.
  5761. maxLength: 253
  5762. minLength: 1
  5763. pattern: ^[-._a-zA-Z0-9]+$
  5764. type: string
  5765. name:
  5766. description: The name of the Secret resource being referred to.
  5767. maxLength: 253
  5768. minLength: 1
  5769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5770. type: string
  5771. namespace:
  5772. description: |-
  5773. The namespace of the Secret resource being referred to.
  5774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5775. maxLength: 63
  5776. minLength: 1
  5777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5778. type: string
  5779. type: object
  5780. type: object
  5781. type: object
  5782. authRef:
  5783. description: A reference to a secret that contains the auth information.
  5784. properties:
  5785. key:
  5786. description: |-
  5787. A key in the referenced Secret.
  5788. Some instances of this field may be defaulted, in others it may be required.
  5789. maxLength: 253
  5790. minLength: 1
  5791. pattern: ^[-._a-zA-Z0-9]+$
  5792. type: string
  5793. name:
  5794. description: The name of the Secret resource being referred to.
  5795. maxLength: 253
  5796. minLength: 1
  5797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5798. type: string
  5799. namespace:
  5800. description: |-
  5801. The namespace of the Secret resource being referred to.
  5802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5803. maxLength: 63
  5804. minLength: 1
  5805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5806. type: string
  5807. type: object
  5808. remoteNamespace:
  5809. default: default
  5810. description: Remote namespace to fetch the secrets from
  5811. maxLength: 63
  5812. minLength: 1
  5813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5814. type: string
  5815. server:
  5816. description: configures the Kubernetes server Address.
  5817. properties:
  5818. caBundle:
  5819. description: CABundle is a base64-encoded CA certificate
  5820. format: byte
  5821. type: string
  5822. caProvider:
  5823. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  5824. properties:
  5825. key:
  5826. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5827. maxLength: 253
  5828. minLength: 1
  5829. pattern: ^[-._a-zA-Z0-9]+$
  5830. type: string
  5831. name:
  5832. description: The name of the object located at the provider type.
  5833. maxLength: 253
  5834. minLength: 1
  5835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5836. type: string
  5837. namespace:
  5838. description: |-
  5839. The namespace the Provider type is in.
  5840. Can only be defined when used in a ClusterSecretStore.
  5841. maxLength: 63
  5842. minLength: 1
  5843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5844. type: string
  5845. type:
  5846. description: The type of provider to use such as "Secret", or "ConfigMap".
  5847. enum:
  5848. - Secret
  5849. - ConfigMap
  5850. type: string
  5851. required:
  5852. - name
  5853. - type
  5854. type: object
  5855. url:
  5856. default: kubernetes.default
  5857. description: configures the Kubernetes server Address.
  5858. type: string
  5859. type: object
  5860. type: object
  5861. nebiusmysterybox:
  5862. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  5863. properties:
  5864. apiDomain:
  5865. description: NebiusMysterybox API endpoint
  5866. type: string
  5867. auth:
  5868. description: Auth defines parameters to authenticate in MysteryBox
  5869. properties:
  5870. serviceAccountCredsSecretRef:
  5871. description: |-
  5872. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  5873. document with service account credentials used to get an IAM token.
  5874. Expected JSON structure:
  5875. {
  5876. "subject-credentials": {
  5877. "alg": "RS256",
  5878. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  5879. "kid": "<public-key-id>",
  5880. "iss": "<issuer-service-account-id>",
  5881. "sub": "<subject-service-account-id>"
  5882. }
  5883. }
  5884. properties:
  5885. key:
  5886. description: |-
  5887. A key in the referenced Secret.
  5888. Some instances of this field may be defaulted, in others it may be required.
  5889. maxLength: 253
  5890. minLength: 1
  5891. pattern: ^[-._a-zA-Z0-9]+$
  5892. type: string
  5893. name:
  5894. description: The name of the Secret resource being referred to.
  5895. maxLength: 253
  5896. minLength: 1
  5897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5898. type: string
  5899. namespace:
  5900. description: |-
  5901. The namespace of the Secret resource being referred to.
  5902. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5903. maxLength: 63
  5904. minLength: 1
  5905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5906. type: string
  5907. type: object
  5908. tokenSecretRef:
  5909. description: Token authenticates with Nebius Mysterybox by presenting a token.
  5910. properties:
  5911. key:
  5912. description: |-
  5913. A key in the referenced Secret.
  5914. Some instances of this field may be defaulted, in others it may be required.
  5915. maxLength: 253
  5916. minLength: 1
  5917. pattern: ^[-._a-zA-Z0-9]+$
  5918. type: string
  5919. name:
  5920. description: The name of the Secret resource being referred to.
  5921. maxLength: 253
  5922. minLength: 1
  5923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5924. type: string
  5925. namespace:
  5926. description: |-
  5927. The namespace of the Secret resource being referred to.
  5928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5929. maxLength: 63
  5930. minLength: 1
  5931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5932. type: string
  5933. type: object
  5934. type: object
  5935. x-kubernetes-validations:
  5936. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  5937. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  5938. caProvider:
  5939. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  5940. properties:
  5941. certSecretRef:
  5942. description: |-
  5943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5944. In some instances, `key` is a required field.
  5945. properties:
  5946. key:
  5947. description: |-
  5948. A key in the referenced Secret.
  5949. Some instances of this field may be defaulted, in others it may be required.
  5950. maxLength: 253
  5951. minLength: 1
  5952. pattern: ^[-._a-zA-Z0-9]+$
  5953. type: string
  5954. name:
  5955. description: The name of the Secret resource being referred to.
  5956. maxLength: 253
  5957. minLength: 1
  5958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5959. type: string
  5960. namespace:
  5961. description: |-
  5962. The namespace of the Secret resource being referred to.
  5963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5964. maxLength: 63
  5965. minLength: 1
  5966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5967. type: string
  5968. type: object
  5969. type: object
  5970. required:
  5971. - apiDomain
  5972. - auth
  5973. type: object
  5974. ngrok:
  5975. description: Ngrok configures this store to sync secrets using the ngrok provider.
  5976. properties:
  5977. apiUrl:
  5978. default: https://api.ngrok.com
  5979. description: APIURL is the URL of the ngrok API.
  5980. type: string
  5981. auth:
  5982. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  5983. maxProperties: 1
  5984. minProperties: 1
  5985. properties:
  5986. apiKey:
  5987. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  5988. properties:
  5989. secretRef:
  5990. description: SecretRef is a reference to a secret containing the ngrok API key.
  5991. properties:
  5992. key:
  5993. description: |-
  5994. A key in the referenced Secret.
  5995. Some instances of this field may be defaulted, in others it may be required.
  5996. maxLength: 253
  5997. minLength: 1
  5998. pattern: ^[-._a-zA-Z0-9]+$
  5999. type: string
  6000. name:
  6001. description: The name of the Secret resource being referred to.
  6002. maxLength: 253
  6003. minLength: 1
  6004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6005. type: string
  6006. namespace:
  6007. description: |-
  6008. The namespace of the Secret resource being referred to.
  6009. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6010. maxLength: 63
  6011. minLength: 1
  6012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6013. type: string
  6014. type: object
  6015. type: object
  6016. type: object
  6017. vault:
  6018. description: Vault configures the ngrok vault to sync secrets with.
  6019. properties:
  6020. name:
  6021. description: Name is the name of the ngrok vault to sync secrets with.
  6022. type: string
  6023. required:
  6024. - name
  6025. type: object
  6026. required:
  6027. - auth
  6028. - vault
  6029. type: object
  6030. onboardbase:
  6031. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6032. properties:
  6033. apiHost:
  6034. default: https://public.onboardbase.com/api/v1/
  6035. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6036. type: string
  6037. auth:
  6038. description: Auth configures how the Operator authenticates with the Onboardbase API
  6039. properties:
  6040. apiKeyRef:
  6041. description: |-
  6042. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6043. It is used to recognize and authorize access to a project and environment within onboardbase
  6044. properties:
  6045. key:
  6046. description: |-
  6047. A key in the referenced Secret.
  6048. Some instances of this field may be defaulted, in others it may be required.
  6049. maxLength: 253
  6050. minLength: 1
  6051. pattern: ^[-._a-zA-Z0-9]+$
  6052. type: string
  6053. name:
  6054. description: The name of the Secret resource being referred to.
  6055. maxLength: 253
  6056. minLength: 1
  6057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6058. type: string
  6059. namespace:
  6060. description: |-
  6061. The namespace of the Secret resource being referred to.
  6062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6063. maxLength: 63
  6064. minLength: 1
  6065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6066. type: string
  6067. type: object
  6068. passcodeRef:
  6069. description: OnboardbasePasscode is the passcode attached to the API Key
  6070. properties:
  6071. key:
  6072. description: |-
  6073. A key in the referenced Secret.
  6074. Some instances of this field may be defaulted, in others it may be required.
  6075. maxLength: 253
  6076. minLength: 1
  6077. pattern: ^[-._a-zA-Z0-9]+$
  6078. type: string
  6079. name:
  6080. description: The name of the Secret resource being referred to.
  6081. maxLength: 253
  6082. minLength: 1
  6083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6084. type: string
  6085. namespace:
  6086. description: |-
  6087. The namespace of the Secret resource being referred to.
  6088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6089. maxLength: 63
  6090. minLength: 1
  6091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6092. type: string
  6093. type: object
  6094. required:
  6095. - apiKeyRef
  6096. - passcodeRef
  6097. type: object
  6098. environment:
  6099. default: development
  6100. description: Environment is the name of an environmnent within a project to pull the secrets from
  6101. type: string
  6102. project:
  6103. default: development
  6104. description: Project is an onboardbase project that the secrets should be pulled from
  6105. type: string
  6106. required:
  6107. - apiHost
  6108. - auth
  6109. - environment
  6110. - project
  6111. type: object
  6112. onepassword:
  6113. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6114. properties:
  6115. auth:
  6116. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6117. properties:
  6118. secretRef:
  6119. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6120. properties:
  6121. connectTokenSecretRef:
  6122. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6123. properties:
  6124. key:
  6125. description: |-
  6126. A key in the referenced Secret.
  6127. Some instances of this field may be defaulted, in others it may be required.
  6128. maxLength: 253
  6129. minLength: 1
  6130. pattern: ^[-._a-zA-Z0-9]+$
  6131. type: string
  6132. name:
  6133. description: The name of the Secret resource being referred to.
  6134. maxLength: 253
  6135. minLength: 1
  6136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6137. type: string
  6138. namespace:
  6139. description: |-
  6140. The namespace of the Secret resource being referred to.
  6141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6142. maxLength: 63
  6143. minLength: 1
  6144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6145. type: string
  6146. type: object
  6147. required:
  6148. - connectTokenSecretRef
  6149. type: object
  6150. required:
  6151. - secretRef
  6152. type: object
  6153. connectHost:
  6154. description: ConnectHost defines the OnePassword Connect Server to connect to
  6155. type: string
  6156. vaults:
  6157. additionalProperties:
  6158. type: integer
  6159. description: Vaults defines which OnePassword vaults to search in which order
  6160. type: object
  6161. required:
  6162. - auth
  6163. - connectHost
  6164. - vaults
  6165. type: object
  6166. onepasswordSDK:
  6167. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6168. properties:
  6169. auth:
  6170. description: Auth defines the information necessary to authenticate against OnePassword API.
  6171. properties:
  6172. serviceAccountSecretRef:
  6173. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6174. properties:
  6175. key:
  6176. description: |-
  6177. A key in the referenced Secret.
  6178. Some instances of this field may be defaulted, in others it may be required.
  6179. maxLength: 253
  6180. minLength: 1
  6181. pattern: ^[-._a-zA-Z0-9]+$
  6182. type: string
  6183. name:
  6184. description: The name of the Secret resource being referred to.
  6185. maxLength: 253
  6186. minLength: 1
  6187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6188. type: string
  6189. namespace:
  6190. description: |-
  6191. The namespace of the Secret resource being referred to.
  6192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6193. maxLength: 63
  6194. minLength: 1
  6195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6196. type: string
  6197. type: object
  6198. required:
  6199. - serviceAccountSecretRef
  6200. type: object
  6201. cache:
  6202. description: |-
  6203. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6204. When enabled, secrets are cached with the specified TTL.
  6205. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6206. If omitted, caching is disabled (default).
  6207. cache: {} is a valid option to set.
  6208. properties:
  6209. maxSize:
  6210. default: 100
  6211. description: |-
  6212. MaxSize is the maximum number of secrets to cache.
  6213. When the cache is full, least-recently-used entries are evicted.
  6214. minimum: 1
  6215. type: integer
  6216. ttl:
  6217. default: 5m
  6218. description: |-
  6219. TTL is the time-to-live for cached secrets.
  6220. Format: duration string (e.g., "5m", "1h", "30s")
  6221. type: string
  6222. type: object
  6223. integrationInfo:
  6224. description: |-
  6225. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6226. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6227. properties:
  6228. name:
  6229. default: 1Password SDK
  6230. description: Name defaults to "1Password SDK".
  6231. type: string
  6232. version:
  6233. default: v1.0.0
  6234. description: Version defaults to "v1.0.0".
  6235. type: string
  6236. type: object
  6237. vault:
  6238. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6239. type: string
  6240. required:
  6241. - auth
  6242. - vault
  6243. type: object
  6244. openBao:
  6245. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6246. properties:
  6247. auth:
  6248. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6249. properties:
  6250. appRole:
  6251. description: |-
  6252. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6253. with the role and secret stored in a Kubernetes Secret resource.
  6254. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6255. properties:
  6256. path:
  6257. default: approle
  6258. description: |-
  6259. Path where the App Role authentication backend is mounted
  6260. in OpenBao, e.g: "approle"
  6261. type: string
  6262. roleId:
  6263. description: |-
  6264. RoleID configured in the App Role authentication backend when setting
  6265. up the authentication backend in OpenBao.
  6266. minLength: 1
  6267. type: string
  6268. roleRef:
  6269. description: |-
  6270. Reference to a key in a Secret that contains the App Role ID used
  6271. to authenticate with OpenBao.
  6272. The `key` field must be specified and denotes which entry within the Secret
  6273. resource is used as the app role id.
  6274. properties:
  6275. key:
  6276. description: |-
  6277. A key in the referenced Secret.
  6278. Some instances of this field may be defaulted, in others it may be required.
  6279. maxLength: 253
  6280. minLength: 1
  6281. pattern: ^[-._a-zA-Z0-9]+$
  6282. type: string
  6283. name:
  6284. description: The name of the Secret resource being referred to.
  6285. maxLength: 253
  6286. minLength: 1
  6287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6288. type: string
  6289. namespace:
  6290. description: |-
  6291. The namespace of the Secret resource being referred to.
  6292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6293. maxLength: 63
  6294. minLength: 1
  6295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6296. type: string
  6297. type: object
  6298. secretRef:
  6299. description: |-
  6300. Reference to a key in a Secret that contains the App Role secret used
  6301. to authenticate with OpenBao.
  6302. The `key` field must be specified and denotes which entry within the Secret
  6303. resource is used as the app role secret.
  6304. properties:
  6305. key:
  6306. description: |-
  6307. A key in the referenced Secret.
  6308. Some instances of this field may be defaulted, in others it may be required.
  6309. maxLength: 253
  6310. minLength: 1
  6311. pattern: ^[-._a-zA-Z0-9]+$
  6312. type: string
  6313. name:
  6314. description: The name of the Secret resource being referred to.
  6315. maxLength: 253
  6316. minLength: 1
  6317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6318. type: string
  6319. namespace:
  6320. description: |-
  6321. The namespace of the Secret resource being referred to.
  6322. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6323. maxLength: 63
  6324. minLength: 1
  6325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6326. type: string
  6327. type: object
  6328. required:
  6329. - path
  6330. - secretRef
  6331. type: object
  6332. x-kubernetes-validations:
  6333. - message: exactly one of the fields in [roleId roleRef] must be set
  6334. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6335. namespace:
  6336. description: |-
  6337. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6338. than the namespace your secret is in. Namespaces is a set of features
  6339. within OpenBao that allows OpenBao environments to support secure
  6340. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6341. if set, or empty otherwise
  6342. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6343. type: string
  6344. tokenSecretRef:
  6345. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6346. properties:
  6347. key:
  6348. description: |-
  6349. A key in the referenced Secret.
  6350. Some instances of this field may be defaulted, in others it may be required.
  6351. maxLength: 253
  6352. minLength: 1
  6353. pattern: ^[-._a-zA-Z0-9]+$
  6354. type: string
  6355. name:
  6356. description: The name of the Secret resource being referred to.
  6357. maxLength: 253
  6358. minLength: 1
  6359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6360. type: string
  6361. namespace:
  6362. description: |-
  6363. The namespace of the Secret resource being referred to.
  6364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6365. maxLength: 63
  6366. minLength: 1
  6367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6368. type: string
  6369. type: object
  6370. userPass:
  6371. description: UserPass authenticates with OpenBao by passing a username/password pair
  6372. properties:
  6373. path:
  6374. default: userpass
  6375. description: |-
  6376. Path where the UserPassword authentication backend is mounted
  6377. in OpenBao, e.g: "userpass"
  6378. type: string
  6379. secretRef:
  6380. description: |-
  6381. SecretRef to a key in a Secret resource containing password for the user
  6382. used to authenticate with OpenBao using the [UserPass authentication
  6383. method]
  6384. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6385. properties:
  6386. key:
  6387. description: |-
  6388. A key in the referenced Secret.
  6389. Some instances of this field may be defaulted, in others it may be required.
  6390. maxLength: 253
  6391. minLength: 1
  6392. pattern: ^[-._a-zA-Z0-9]+$
  6393. type: string
  6394. name:
  6395. description: The name of the Secret resource being referred to.
  6396. maxLength: 253
  6397. minLength: 1
  6398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6399. type: string
  6400. namespace:
  6401. description: |-
  6402. The namespace of the Secret resource being referred to.
  6403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6404. maxLength: 63
  6405. minLength: 1
  6406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6407. type: string
  6408. type: object
  6409. username:
  6410. description: |-
  6411. Username is a username used to authenticate using the [UserPass
  6412. authentication method]
  6413. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6414. type: string
  6415. required:
  6416. - path
  6417. - username
  6418. type: object
  6419. type: object
  6420. x-kubernetes-validations:
  6421. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6422. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6423. caBundle:
  6424. description: |-
  6425. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6426. this and `caProvider` are not set the system root certificates are used
  6427. to validate the TLS connection.
  6428. format: byte
  6429. type: string
  6430. caProvider:
  6431. description: |-
  6432. The provider for the CA bundle to use to validate OpenBao server
  6433. certificate. If this and `caBundle` are not set the system root
  6434. certificates are used to validate the TLS connection.
  6435. properties:
  6436. key:
  6437. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6438. maxLength: 253
  6439. minLength: 1
  6440. pattern: ^[-._a-zA-Z0-9]+$
  6441. type: string
  6442. name:
  6443. description: The name of the object located at the provider type.
  6444. maxLength: 253
  6445. minLength: 1
  6446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6447. type: string
  6448. namespace:
  6449. description: |-
  6450. The namespace the Provider type is in.
  6451. Can only be defined when used in a ClusterSecretStore.
  6452. maxLength: 63
  6453. minLength: 1
  6454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6455. type: string
  6456. type:
  6457. description: The type of provider to use such as "Secret", or "ConfigMap".
  6458. enum:
  6459. - Secret
  6460. - ConfigMap
  6461. type: string
  6462. required:
  6463. - name
  6464. - type
  6465. type: object
  6466. namespace:
  6467. description: |-
  6468. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6469. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6470. e.g: "ns1".
  6471. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6472. type: string
  6473. path:
  6474. description: |-
  6475. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6476. "secret". The v2 KV secret engine version specific "/data" path suffix
  6477. for fetching secrets from OpenBao is optional and will be appended
  6478. if not present in specified path.
  6479. type: string
  6480. server:
  6481. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6482. type: string
  6483. version:
  6484. default: v2
  6485. description: |-
  6486. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6487. "v2". Version defaults to "v2".
  6488. enum:
  6489. - v1
  6490. - v2
  6491. type: string
  6492. required:
  6493. - server
  6494. type: object
  6495. x-kubernetes-validations:
  6496. - message: at most one of the fields in [caBundle caProvider] may be set
  6497. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6498. oracle:
  6499. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6500. properties:
  6501. auth:
  6502. description: |-
  6503. Auth configures how secret-manager authenticates with the Oracle Vault.
  6504. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6505. properties:
  6506. secretRef:
  6507. description: SecretRef to pass through sensitive information.
  6508. properties:
  6509. fingerprint:
  6510. description: Fingerprint is the fingerprint of the API private key.
  6511. properties:
  6512. key:
  6513. description: |-
  6514. A key in the referenced Secret.
  6515. Some instances of this field may be defaulted, in others it may be required.
  6516. maxLength: 253
  6517. minLength: 1
  6518. pattern: ^[-._a-zA-Z0-9]+$
  6519. type: string
  6520. name:
  6521. description: The name of the Secret resource being referred to.
  6522. maxLength: 253
  6523. minLength: 1
  6524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6525. type: string
  6526. namespace:
  6527. description: |-
  6528. The namespace of the Secret resource being referred to.
  6529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6530. maxLength: 63
  6531. minLength: 1
  6532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6533. type: string
  6534. type: object
  6535. privatekey:
  6536. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6537. properties:
  6538. key:
  6539. description: |-
  6540. A key in the referenced Secret.
  6541. Some instances of this field may be defaulted, in others it may be required.
  6542. maxLength: 253
  6543. minLength: 1
  6544. pattern: ^[-._a-zA-Z0-9]+$
  6545. type: string
  6546. name:
  6547. description: The name of the Secret resource being referred to.
  6548. maxLength: 253
  6549. minLength: 1
  6550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6551. type: string
  6552. namespace:
  6553. description: |-
  6554. The namespace of the Secret resource being referred to.
  6555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6556. maxLength: 63
  6557. minLength: 1
  6558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6559. type: string
  6560. type: object
  6561. required:
  6562. - fingerprint
  6563. - privatekey
  6564. type: object
  6565. tenancy:
  6566. description: Tenancy is the tenancy OCID where user is located.
  6567. type: string
  6568. user:
  6569. description: User is an access OCID specific to the account.
  6570. type: string
  6571. required:
  6572. - secretRef
  6573. - tenancy
  6574. - user
  6575. type: object
  6576. compartment:
  6577. description: |-
  6578. Compartment is the vault compartment OCID.
  6579. Required for PushSecret
  6580. type: string
  6581. encryptionKey:
  6582. description: |-
  6583. EncryptionKey is the OCID of the encryption key within the vault.
  6584. Required for PushSecret
  6585. type: string
  6586. principalType:
  6587. description: |-
  6588. The type of principal to use for authentication. If left blank, the Auth struct will
  6589. determine the principal type. This optional field must be specified if using
  6590. workload identity.
  6591. enum:
  6592. - ""
  6593. - UserPrincipal
  6594. - InstancePrincipal
  6595. - Workload
  6596. type: string
  6597. region:
  6598. description: Region is the region where vault is located.
  6599. type: string
  6600. serviceAccountRef:
  6601. description: |-
  6602. ServiceAccountRef specified the service account
  6603. that should be used when authenticating with WorkloadIdentity.
  6604. properties:
  6605. audiences:
  6606. description: |-
  6607. Audience specifies the `aud` claim for the service account token
  6608. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6609. then this audiences will be appended to the list
  6610. items:
  6611. type: string
  6612. type: array
  6613. name:
  6614. description: The name of the ServiceAccount resource being referred to.
  6615. maxLength: 253
  6616. minLength: 1
  6617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6618. type: string
  6619. namespace:
  6620. description: |-
  6621. Namespace of the resource being referred to.
  6622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6623. maxLength: 63
  6624. minLength: 1
  6625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6626. type: string
  6627. required:
  6628. - name
  6629. type: object
  6630. vault:
  6631. description: Vault is the vault's OCID of the specific vault where secret is located.
  6632. type: string
  6633. required:
  6634. - region
  6635. - vault
  6636. type: object
  6637. ovh:
  6638. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  6639. properties:
  6640. auth:
  6641. description: Authentication method (mtls or token).
  6642. properties:
  6643. mtls:
  6644. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  6645. properties:
  6646. caBundle:
  6647. format: byte
  6648. type: string
  6649. caProvider:
  6650. description: |-
  6651. CAProvider provides a custom certificate authority for accessing the provider's store.
  6652. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  6653. properties:
  6654. key:
  6655. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6656. maxLength: 253
  6657. minLength: 1
  6658. pattern: ^[-._a-zA-Z0-9]+$
  6659. type: string
  6660. name:
  6661. description: The name of the object located at the provider type.
  6662. maxLength: 253
  6663. minLength: 1
  6664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6665. type: string
  6666. namespace:
  6667. description: |-
  6668. The namespace the Provider type is in.
  6669. Can only be defined when used in a ClusterSecretStore.
  6670. maxLength: 63
  6671. minLength: 1
  6672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6673. type: string
  6674. type:
  6675. description: The type of provider to use such as "Secret", or "ConfigMap".
  6676. enum:
  6677. - Secret
  6678. - ConfigMap
  6679. type: string
  6680. required:
  6681. - name
  6682. - type
  6683. type: object
  6684. certSecretRef:
  6685. description: |-
  6686. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6687. In some instances, `key` is a required field.
  6688. properties:
  6689. key:
  6690. description: |-
  6691. A key in the referenced Secret.
  6692. Some instances of this field may be defaulted, in others it may be required.
  6693. maxLength: 253
  6694. minLength: 1
  6695. pattern: ^[-._a-zA-Z0-9]+$
  6696. type: string
  6697. name:
  6698. description: The name of the Secret resource being referred to.
  6699. maxLength: 253
  6700. minLength: 1
  6701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6702. type: string
  6703. namespace:
  6704. description: |-
  6705. The namespace of the Secret resource being referred to.
  6706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6707. maxLength: 63
  6708. minLength: 1
  6709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6710. type: string
  6711. type: object
  6712. keySecretRef:
  6713. description: |-
  6714. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6715. In some instances, `key` is a required field.
  6716. properties:
  6717. key:
  6718. description: |-
  6719. A key in the referenced Secret.
  6720. Some instances of this field may be defaulted, in others it may be required.
  6721. maxLength: 253
  6722. minLength: 1
  6723. pattern: ^[-._a-zA-Z0-9]+$
  6724. type: string
  6725. name:
  6726. description: The name of the Secret resource being referred to.
  6727. maxLength: 253
  6728. minLength: 1
  6729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6730. type: string
  6731. namespace:
  6732. description: |-
  6733. The namespace of the Secret resource being referred to.
  6734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6735. maxLength: 63
  6736. minLength: 1
  6737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6738. type: string
  6739. type: object
  6740. required:
  6741. - certSecretRef
  6742. - keySecretRef
  6743. type: object
  6744. token:
  6745. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  6746. properties:
  6747. tokenSecretRef:
  6748. description: |-
  6749. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6750. In some instances, `key` is a required field.
  6751. properties:
  6752. key:
  6753. description: |-
  6754. A key in the referenced Secret.
  6755. Some instances of this field may be defaulted, in others it may be required.
  6756. maxLength: 253
  6757. minLength: 1
  6758. pattern: ^[-._a-zA-Z0-9]+$
  6759. type: string
  6760. name:
  6761. description: The name of the Secret resource being referred to.
  6762. maxLength: 253
  6763. minLength: 1
  6764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6765. type: string
  6766. namespace:
  6767. description: |-
  6768. The namespace of the Secret resource being referred to.
  6769. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6770. maxLength: 63
  6771. minLength: 1
  6772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6773. type: string
  6774. type: object
  6775. required:
  6776. - tokenSecretRef
  6777. type: object
  6778. type: object
  6779. casRequired:
  6780. description: 'Enables or disables check-and-set (CAS) (default: false).'
  6781. type: boolean
  6782. okmsTimeout:
  6783. default: 30
  6784. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  6785. format: int32
  6786. minimum: 1
  6787. type: integer
  6788. okmsid:
  6789. description: specifies the OKMS ID.
  6790. type: string
  6791. server:
  6792. description: specifies the OKMS server endpoint.
  6793. type: string
  6794. required:
  6795. - auth
  6796. - okmsid
  6797. - server
  6798. type: object
  6799. passbolt:
  6800. description: |-
  6801. PassboltProvider provides access to Passbolt secrets manager.
  6802. See: https://www.passbolt.com.
  6803. properties:
  6804. auth:
  6805. description: Auth defines the information necessary to authenticate against Passbolt Server
  6806. properties:
  6807. passwordSecretRef:
  6808. description: |-
  6809. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6810. In some instances, `key` is a required field.
  6811. properties:
  6812. key:
  6813. description: |-
  6814. A key in the referenced Secret.
  6815. Some instances of this field may be defaulted, in others it may be required.
  6816. maxLength: 253
  6817. minLength: 1
  6818. pattern: ^[-._a-zA-Z0-9]+$
  6819. type: string
  6820. name:
  6821. description: The name of the Secret resource being referred to.
  6822. maxLength: 253
  6823. minLength: 1
  6824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6825. type: string
  6826. namespace:
  6827. description: |-
  6828. The namespace of the Secret resource being referred to.
  6829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6830. maxLength: 63
  6831. minLength: 1
  6832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6833. type: string
  6834. type: object
  6835. privateKeySecretRef:
  6836. description: |-
  6837. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6838. In some instances, `key` is a required field.
  6839. properties:
  6840. key:
  6841. description: |-
  6842. A key in the referenced Secret.
  6843. Some instances of this field may be defaulted, in others it may be required.
  6844. maxLength: 253
  6845. minLength: 1
  6846. pattern: ^[-._a-zA-Z0-9]+$
  6847. type: string
  6848. name:
  6849. description: The name of the Secret resource being referred to.
  6850. maxLength: 253
  6851. minLength: 1
  6852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6853. type: string
  6854. namespace:
  6855. description: |-
  6856. The namespace of the Secret resource being referred to.
  6857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6858. maxLength: 63
  6859. minLength: 1
  6860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6861. type: string
  6862. type: object
  6863. required:
  6864. - passwordSecretRef
  6865. - privateKeySecretRef
  6866. type: object
  6867. caBundle:
  6868. description: |-
  6869. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  6870. if the Host URL is using HTTPS protocol. If not set the system root certificates
  6871. are used to validate the TLS connection.
  6872. format: byte
  6873. type: string
  6874. caProvider:
  6875. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  6876. properties:
  6877. key:
  6878. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6879. maxLength: 253
  6880. minLength: 1
  6881. pattern: ^[-._a-zA-Z0-9]+$
  6882. type: string
  6883. name:
  6884. description: The name of the object located at the provider type.
  6885. maxLength: 253
  6886. minLength: 1
  6887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6888. type: string
  6889. namespace:
  6890. description: |-
  6891. The namespace the Provider type is in.
  6892. Can only be defined when used in a ClusterSecretStore.
  6893. maxLength: 63
  6894. minLength: 1
  6895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6896. type: string
  6897. type:
  6898. description: The type of provider to use such as "Secret", or "ConfigMap".
  6899. enum:
  6900. - Secret
  6901. - ConfigMap
  6902. type: string
  6903. required:
  6904. - name
  6905. - type
  6906. type: object
  6907. host:
  6908. description: Host defines the Passbolt Server to connect to
  6909. type: string
  6910. required:
  6911. - auth
  6912. - host
  6913. type: object
  6914. passworddepot:
  6915. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  6916. properties:
  6917. auth:
  6918. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  6919. properties:
  6920. secretRef:
  6921. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  6922. properties:
  6923. credentials:
  6924. description: Username / Password is used for authentication.
  6925. properties:
  6926. key:
  6927. description: |-
  6928. A key in the referenced Secret.
  6929. Some instances of this field may be defaulted, in others it may be required.
  6930. maxLength: 253
  6931. minLength: 1
  6932. pattern: ^[-._a-zA-Z0-9]+$
  6933. type: string
  6934. name:
  6935. description: The name of the Secret resource being referred to.
  6936. maxLength: 253
  6937. minLength: 1
  6938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6939. type: string
  6940. namespace:
  6941. description: |-
  6942. The namespace of the Secret resource being referred to.
  6943. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6944. maxLength: 63
  6945. minLength: 1
  6946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6947. type: string
  6948. type: object
  6949. type: object
  6950. required:
  6951. - secretRef
  6952. type: object
  6953. database:
  6954. description: Database to use as source
  6955. type: string
  6956. host:
  6957. description: URL configures the Password Depot instance URL.
  6958. type: string
  6959. required:
  6960. - auth
  6961. - database
  6962. - host
  6963. type: object
  6964. previder:
  6965. description: Previder configures this store to sync secrets using the Previder provider
  6966. properties:
  6967. auth:
  6968. description: PreviderAuth contains a secretRef for credentials.
  6969. properties:
  6970. secretRef:
  6971. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  6972. properties:
  6973. accessToken:
  6974. description: The AccessToken is used for authentication
  6975. properties:
  6976. key:
  6977. description: |-
  6978. A key in the referenced Secret.
  6979. Some instances of this field may be defaulted, in others it may be required.
  6980. maxLength: 253
  6981. minLength: 1
  6982. pattern: ^[-._a-zA-Z0-9]+$
  6983. type: string
  6984. name:
  6985. description: The name of the Secret resource being referred to.
  6986. maxLength: 253
  6987. minLength: 1
  6988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6989. type: string
  6990. namespace:
  6991. description: |-
  6992. The namespace of the Secret resource being referred to.
  6993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6994. maxLength: 63
  6995. minLength: 1
  6996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6997. type: string
  6998. type: object
  6999. required:
  7000. - accessToken
  7001. type: object
  7002. type: object
  7003. baseUri:
  7004. type: string
  7005. required:
  7006. - auth
  7007. type: object
  7008. pulumi:
  7009. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7010. properties:
  7011. accessToken:
  7012. description: |-
  7013. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7014. Deprecated: Use auth.accessToken instead.
  7015. properties:
  7016. secretRef:
  7017. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7018. properties:
  7019. key:
  7020. description: |-
  7021. A key in the referenced Secret.
  7022. Some instances of this field may be defaulted, in others it may be required.
  7023. maxLength: 253
  7024. minLength: 1
  7025. pattern: ^[-._a-zA-Z0-9]+$
  7026. type: string
  7027. name:
  7028. description: The name of the Secret resource being referred to.
  7029. maxLength: 253
  7030. minLength: 1
  7031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7032. type: string
  7033. namespace:
  7034. description: |-
  7035. The namespace of the Secret resource being referred to.
  7036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7037. maxLength: 63
  7038. minLength: 1
  7039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7040. type: string
  7041. type: object
  7042. type: object
  7043. apiUrl:
  7044. default: https://api.pulumi.com/api/esc
  7045. description: APIURL is the URL of the Pulumi API.
  7046. type: string
  7047. auth:
  7048. description: |-
  7049. Auth configures how the Operator authenticates with the Pulumi API.
  7050. Either auth or the deprecated accessToken field must be specified.
  7051. properties:
  7052. accessToken:
  7053. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7054. properties:
  7055. secretRef:
  7056. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7057. properties:
  7058. key:
  7059. description: |-
  7060. A key in the referenced Secret.
  7061. Some instances of this field may be defaulted, in others it may be required.
  7062. maxLength: 253
  7063. minLength: 1
  7064. pattern: ^[-._a-zA-Z0-9]+$
  7065. type: string
  7066. name:
  7067. description: The name of the Secret resource being referred to.
  7068. maxLength: 253
  7069. minLength: 1
  7070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7071. type: string
  7072. namespace:
  7073. description: |-
  7074. The namespace of the Secret resource being referred to.
  7075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7076. maxLength: 63
  7077. minLength: 1
  7078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7079. type: string
  7080. type: object
  7081. type: object
  7082. oidcConfig:
  7083. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7084. properties:
  7085. expirationSeconds:
  7086. default: 600
  7087. description: |-
  7088. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7089. Defaults to 10 minutes.
  7090. format: int64
  7091. minimum: 600
  7092. type: integer
  7093. organization:
  7094. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7095. type: string
  7096. serviceAccountRef:
  7097. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7098. properties:
  7099. audiences:
  7100. description: |-
  7101. Audience specifies the `aud` claim for the service account token
  7102. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7103. then this audiences will be appended to the list
  7104. items:
  7105. type: string
  7106. type: array
  7107. name:
  7108. description: The name of the ServiceAccount resource being referred to.
  7109. maxLength: 253
  7110. minLength: 1
  7111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7112. type: string
  7113. namespace:
  7114. description: |-
  7115. Namespace of the resource being referred to.
  7116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7117. maxLength: 63
  7118. minLength: 1
  7119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7120. type: string
  7121. required:
  7122. - name
  7123. type: object
  7124. required:
  7125. - organization
  7126. - serviceAccountRef
  7127. type: object
  7128. type: object
  7129. x-kubernetes-validations:
  7130. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7131. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7132. environment:
  7133. description: |-
  7134. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7135. dynamically retrieved values from supported providers including all major clouds,
  7136. and other Pulumi ESC environments.
  7137. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7138. type: string
  7139. organization:
  7140. description: |-
  7141. Organization are a space to collaborate on shared projects and stacks.
  7142. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7143. type: string
  7144. project:
  7145. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7146. type: string
  7147. required:
  7148. - environment
  7149. - organization
  7150. - project
  7151. type: object
  7152. x-kubernetes-validations:
  7153. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7154. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7155. scaleway:
  7156. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7157. properties:
  7158. accessKey:
  7159. description: AccessKey is the non-secret part of the api key.
  7160. properties:
  7161. secretRef:
  7162. description: SecretRef references a key in a secret that will be used as value.
  7163. properties:
  7164. key:
  7165. description: |-
  7166. A key in the referenced Secret.
  7167. Some instances of this field may be defaulted, in others it may be required.
  7168. maxLength: 253
  7169. minLength: 1
  7170. pattern: ^[-._a-zA-Z0-9]+$
  7171. type: string
  7172. name:
  7173. description: The name of the Secret resource being referred to.
  7174. maxLength: 253
  7175. minLength: 1
  7176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7177. type: string
  7178. namespace:
  7179. description: |-
  7180. The namespace of the Secret resource being referred to.
  7181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7182. maxLength: 63
  7183. minLength: 1
  7184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7185. type: string
  7186. type: object
  7187. value:
  7188. description: Value can be specified directly to set a value without using a secret.
  7189. type: string
  7190. type: object
  7191. apiUrl:
  7192. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7193. type: string
  7194. projectId:
  7195. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7196. type: string
  7197. region:
  7198. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7199. type: string
  7200. secretKey:
  7201. description: SecretKey is the non-secret part of the api key.
  7202. properties:
  7203. secretRef:
  7204. description: SecretRef references a key in a secret that will be used as value.
  7205. properties:
  7206. key:
  7207. description: |-
  7208. A key in the referenced Secret.
  7209. Some instances of this field may be defaulted, in others it may be required.
  7210. maxLength: 253
  7211. minLength: 1
  7212. pattern: ^[-._a-zA-Z0-9]+$
  7213. type: string
  7214. name:
  7215. description: The name of the Secret resource being referred to.
  7216. maxLength: 253
  7217. minLength: 1
  7218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7219. type: string
  7220. namespace:
  7221. description: |-
  7222. The namespace of the Secret resource being referred to.
  7223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7224. maxLength: 63
  7225. minLength: 1
  7226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7227. type: string
  7228. type: object
  7229. value:
  7230. description: Value can be specified directly to set a value without using a secret.
  7231. type: string
  7232. type: object
  7233. required:
  7234. - accessKey
  7235. - projectId
  7236. - region
  7237. - secretKey
  7238. type: object
  7239. secretserver:
  7240. description: |-
  7241. SecretServer configures this store to sync secrets using SecretServer provider
  7242. https://docs.delinea.com/online-help/secret-server/start.htm
  7243. properties:
  7244. caBundle:
  7245. description: |-
  7246. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7247. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7248. are used to validate the TLS connection.
  7249. format: byte
  7250. type: string
  7251. caProvider:
  7252. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7253. properties:
  7254. key:
  7255. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7256. maxLength: 253
  7257. minLength: 1
  7258. pattern: ^[-._a-zA-Z0-9]+$
  7259. type: string
  7260. name:
  7261. description: The name of the object located at the provider type.
  7262. maxLength: 253
  7263. minLength: 1
  7264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7265. type: string
  7266. namespace:
  7267. description: |-
  7268. The namespace the Provider type is in.
  7269. Can only be defined when used in a ClusterSecretStore.
  7270. maxLength: 63
  7271. minLength: 1
  7272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7273. type: string
  7274. type:
  7275. description: The type of provider to use such as "Secret", or "ConfigMap".
  7276. enum:
  7277. - Secret
  7278. - ConfigMap
  7279. type: string
  7280. required:
  7281. - name
  7282. - type
  7283. type: object
  7284. domain:
  7285. description: Domain is the secret server domain.
  7286. type: string
  7287. password:
  7288. description: Password is the secret server account password.
  7289. properties:
  7290. secretRef:
  7291. description: SecretRef references a key in a secret that will be used as value.
  7292. properties:
  7293. key:
  7294. description: |-
  7295. A key in the referenced Secret.
  7296. Some instances of this field may be defaulted, in others it may be required.
  7297. maxLength: 253
  7298. minLength: 1
  7299. pattern: ^[-._a-zA-Z0-9]+$
  7300. type: string
  7301. name:
  7302. description: The name of the Secret resource being referred to.
  7303. maxLength: 253
  7304. minLength: 1
  7305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7306. type: string
  7307. namespace:
  7308. description: |-
  7309. The namespace of the Secret resource being referred to.
  7310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7311. maxLength: 63
  7312. minLength: 1
  7313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7314. type: string
  7315. type: object
  7316. value:
  7317. description: Value can be specified directly to set a value without using a secret.
  7318. type: string
  7319. type: object
  7320. serverURL:
  7321. description: |-
  7322. ServerURL
  7323. URL to your secret server installation
  7324. type: string
  7325. username:
  7326. description: Username is the secret server account username.
  7327. properties:
  7328. secretRef:
  7329. description: SecretRef references a key in a secret that will be used as value.
  7330. properties:
  7331. key:
  7332. description: |-
  7333. A key in the referenced Secret.
  7334. Some instances of this field may be defaulted, in others it may be required.
  7335. maxLength: 253
  7336. minLength: 1
  7337. pattern: ^[-._a-zA-Z0-9]+$
  7338. type: string
  7339. name:
  7340. description: The name of the Secret resource being referred to.
  7341. maxLength: 253
  7342. minLength: 1
  7343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7344. type: string
  7345. namespace:
  7346. description: |-
  7347. The namespace of the Secret resource being referred to.
  7348. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7349. maxLength: 63
  7350. minLength: 1
  7351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7352. type: string
  7353. type: object
  7354. value:
  7355. description: Value can be specified directly to set a value without using a secret.
  7356. type: string
  7357. type: object
  7358. required:
  7359. - password
  7360. - serverURL
  7361. - username
  7362. type: object
  7363. senhasegura:
  7364. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7365. properties:
  7366. auth:
  7367. description: Auth defines parameters to authenticate in senhasegura
  7368. properties:
  7369. clientId:
  7370. type: string
  7371. clientSecretSecretRef:
  7372. description: |-
  7373. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7374. In some instances, `key` is a required field.
  7375. properties:
  7376. key:
  7377. description: |-
  7378. A key in the referenced Secret.
  7379. Some instances of this field may be defaulted, in others it may be required.
  7380. maxLength: 253
  7381. minLength: 1
  7382. pattern: ^[-._a-zA-Z0-9]+$
  7383. type: string
  7384. name:
  7385. description: The name of the Secret resource being referred to.
  7386. maxLength: 253
  7387. minLength: 1
  7388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7389. type: string
  7390. namespace:
  7391. description: |-
  7392. The namespace of the Secret resource being referred to.
  7393. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7394. maxLength: 63
  7395. minLength: 1
  7396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7397. type: string
  7398. type: object
  7399. required:
  7400. - clientId
  7401. - clientSecretSecretRef
  7402. type: object
  7403. ignoreSslCertificate:
  7404. default: false
  7405. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7406. type: boolean
  7407. module:
  7408. description: Module defines which senhasegura module should be used to get secrets
  7409. type: string
  7410. url:
  7411. description: URL of senhasegura
  7412. type: string
  7413. required:
  7414. - auth
  7415. - module
  7416. - url
  7417. type: object
  7418. vault:
  7419. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7420. properties:
  7421. auth:
  7422. description: Auth configures how secret-manager authenticates with the Vault server.
  7423. properties:
  7424. appRole:
  7425. description: |-
  7426. AppRole authenticates with Vault using the App Role auth mechanism,
  7427. with the role and secret stored in a Kubernetes Secret resource.
  7428. properties:
  7429. path:
  7430. default: approle
  7431. description: |-
  7432. Path where the App Role authentication backend is mounted
  7433. in Vault, e.g: "approle"
  7434. type: string
  7435. roleId:
  7436. description: |-
  7437. RoleID configured in the App Role authentication backend when setting
  7438. up the authentication backend in Vault.
  7439. type: string
  7440. roleRef:
  7441. description: |-
  7442. Reference to a key in a Secret that contains the App Role ID used
  7443. to authenticate with Vault.
  7444. The `key` field must be specified and denotes which entry within the Secret
  7445. resource is used as the app role id.
  7446. properties:
  7447. key:
  7448. description: |-
  7449. A key in the referenced Secret.
  7450. Some instances of this field may be defaulted, in others it may be required.
  7451. maxLength: 253
  7452. minLength: 1
  7453. pattern: ^[-._a-zA-Z0-9]+$
  7454. type: string
  7455. name:
  7456. description: The name of the Secret resource being referred to.
  7457. maxLength: 253
  7458. minLength: 1
  7459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7460. type: string
  7461. namespace:
  7462. description: |-
  7463. The namespace of the Secret resource being referred to.
  7464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7465. maxLength: 63
  7466. minLength: 1
  7467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7468. type: string
  7469. type: object
  7470. secretRef:
  7471. description: |-
  7472. Reference to a key in a Secret that contains the App Role secret used
  7473. to authenticate with Vault.
  7474. The `key` field must be specified and denotes which entry within the Secret
  7475. resource is used as the app role secret.
  7476. properties:
  7477. key:
  7478. description: |-
  7479. A key in the referenced Secret.
  7480. Some instances of this field may be defaulted, in others it may be required.
  7481. maxLength: 253
  7482. minLength: 1
  7483. pattern: ^[-._a-zA-Z0-9]+$
  7484. type: string
  7485. name:
  7486. description: The name of the Secret resource being referred to.
  7487. maxLength: 253
  7488. minLength: 1
  7489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7490. type: string
  7491. namespace:
  7492. description: |-
  7493. The namespace of the Secret resource being referred to.
  7494. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7495. maxLength: 63
  7496. minLength: 1
  7497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7498. type: string
  7499. type: object
  7500. required:
  7501. - path
  7502. - secretRef
  7503. type: object
  7504. cert:
  7505. description: |-
  7506. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7507. Cert authentication method
  7508. properties:
  7509. clientCert:
  7510. description: |-
  7511. ClientCert is a certificate to authenticate using the Cert Vault
  7512. authentication method
  7513. properties:
  7514. key:
  7515. description: |-
  7516. A key in the referenced Secret.
  7517. Some instances of this field may be defaulted, in others it may be required.
  7518. maxLength: 253
  7519. minLength: 1
  7520. pattern: ^[-._a-zA-Z0-9]+$
  7521. type: string
  7522. name:
  7523. description: The name of the Secret resource being referred to.
  7524. maxLength: 253
  7525. minLength: 1
  7526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7527. type: string
  7528. namespace:
  7529. description: |-
  7530. The namespace of the Secret resource being referred to.
  7531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7532. maxLength: 63
  7533. minLength: 1
  7534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7535. type: string
  7536. type: object
  7537. path:
  7538. default: cert
  7539. description: |-
  7540. Path where the Certificate authentication backend is mounted
  7541. in Vault, e.g: "cert"
  7542. type: string
  7543. secretRef:
  7544. description: |-
  7545. SecretRef to a key in a Secret resource containing client private key to
  7546. authenticate with Vault using the Cert authentication method
  7547. properties:
  7548. key:
  7549. description: |-
  7550. A key in the referenced Secret.
  7551. Some instances of this field may be defaulted, in others it may be required.
  7552. maxLength: 253
  7553. minLength: 1
  7554. pattern: ^[-._a-zA-Z0-9]+$
  7555. type: string
  7556. name:
  7557. description: The name of the Secret resource being referred to.
  7558. maxLength: 253
  7559. minLength: 1
  7560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7561. type: string
  7562. namespace:
  7563. description: |-
  7564. The namespace of the Secret resource being referred to.
  7565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7566. maxLength: 63
  7567. minLength: 1
  7568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7569. type: string
  7570. type: object
  7571. vaultRole:
  7572. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7573. type: string
  7574. type: object
  7575. gcp:
  7576. description: |-
  7577. Gcp authenticates with Vault using Google Cloud Platform authentication method
  7578. GCP authentication method
  7579. properties:
  7580. location:
  7581. description: Location optionally defines a location/region for the secret
  7582. type: string
  7583. path:
  7584. default: gcp
  7585. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  7586. type: string
  7587. projectID:
  7588. description: Project ID of the Google Cloud Platform project
  7589. type: string
  7590. role:
  7591. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  7592. type: string
  7593. secretRef:
  7594. description: Specify credentials in a Secret object
  7595. properties:
  7596. secretAccessKeySecretRef:
  7597. description: The SecretAccessKey is used for authentication
  7598. properties:
  7599. key:
  7600. description: |-
  7601. A key in the referenced Secret.
  7602. Some instances of this field may be defaulted, in others it may be required.
  7603. maxLength: 253
  7604. minLength: 1
  7605. pattern: ^[-._a-zA-Z0-9]+$
  7606. type: string
  7607. name:
  7608. description: The name of the Secret resource being referred to.
  7609. maxLength: 253
  7610. minLength: 1
  7611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7612. type: string
  7613. namespace:
  7614. description: |-
  7615. The namespace of the Secret resource being referred to.
  7616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7617. maxLength: 63
  7618. minLength: 1
  7619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7620. type: string
  7621. type: object
  7622. type: object
  7623. serviceAccountRef:
  7624. description: ServiceAccountRef to a service account for impersonation
  7625. properties:
  7626. audiences:
  7627. description: |-
  7628. Audience specifies the `aud` claim for the service account token
  7629. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7630. then this audiences will be appended to the list
  7631. items:
  7632. type: string
  7633. type: array
  7634. name:
  7635. description: The name of the ServiceAccount resource being referred to.
  7636. maxLength: 253
  7637. minLength: 1
  7638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7639. type: string
  7640. namespace:
  7641. description: |-
  7642. Namespace of the resource being referred to.
  7643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7644. maxLength: 63
  7645. minLength: 1
  7646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7647. type: string
  7648. required:
  7649. - name
  7650. type: object
  7651. workloadIdentity:
  7652. description: Specify a service account with Workload Identity
  7653. properties:
  7654. clusterLocation:
  7655. description: |-
  7656. ClusterLocation is the location of the cluster
  7657. If not specified, it fetches information from the metadata server
  7658. type: string
  7659. clusterName:
  7660. description: |-
  7661. ClusterName is the name of the cluster
  7662. If not specified, it fetches information from the metadata server
  7663. type: string
  7664. clusterProjectID:
  7665. description: |-
  7666. ClusterProjectID is the project ID of the cluster
  7667. If not specified, it fetches information from the metadata server
  7668. type: string
  7669. serviceAccountRef:
  7670. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  7671. properties:
  7672. audiences:
  7673. description: |-
  7674. Audience specifies the `aud` claim for the service account token
  7675. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7676. then this audiences will be appended to the list
  7677. items:
  7678. type: string
  7679. type: array
  7680. name:
  7681. description: The name of the ServiceAccount resource being referred to.
  7682. maxLength: 253
  7683. minLength: 1
  7684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7685. type: string
  7686. namespace:
  7687. description: |-
  7688. Namespace of the resource being referred to.
  7689. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7690. maxLength: 63
  7691. minLength: 1
  7692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7693. type: string
  7694. required:
  7695. - name
  7696. type: object
  7697. required:
  7698. - serviceAccountRef
  7699. type: object
  7700. required:
  7701. - role
  7702. type: object
  7703. iam:
  7704. description: |-
  7705. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  7706. AWS IAM authentication method
  7707. properties:
  7708. externalID:
  7709. description: AWS External ID set on assumed IAM roles
  7710. type: string
  7711. jwt:
  7712. description: Specify a service account with IRSA enabled
  7713. properties:
  7714. serviceAccountRef:
  7715. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  7716. properties:
  7717. audiences:
  7718. description: |-
  7719. Audience specifies the `aud` claim for the service account token
  7720. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7721. then this audiences will be appended to the list
  7722. items:
  7723. type: string
  7724. type: array
  7725. name:
  7726. description: The name of the ServiceAccount resource being referred to.
  7727. maxLength: 253
  7728. minLength: 1
  7729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7730. type: string
  7731. namespace:
  7732. description: |-
  7733. Namespace of the resource being referred to.
  7734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7735. maxLength: 63
  7736. minLength: 1
  7737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7738. type: string
  7739. required:
  7740. - name
  7741. type: object
  7742. type: object
  7743. path:
  7744. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  7745. type: string
  7746. region:
  7747. description: AWS region
  7748. type: string
  7749. role:
  7750. description: This is the AWS role to be assumed before talking to vault
  7751. type: string
  7752. secretRef:
  7753. description: Specify credentials in a Secret object
  7754. properties:
  7755. accessKeyIDSecretRef:
  7756. description: The AccessKeyID is used for authentication
  7757. properties:
  7758. key:
  7759. description: |-
  7760. A key in the referenced Secret.
  7761. Some instances of this field may be defaulted, in others it may be required.
  7762. maxLength: 253
  7763. minLength: 1
  7764. pattern: ^[-._a-zA-Z0-9]+$
  7765. type: string
  7766. name:
  7767. description: The name of the Secret resource being referred to.
  7768. maxLength: 253
  7769. minLength: 1
  7770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7771. type: string
  7772. namespace:
  7773. description: |-
  7774. The namespace of the Secret resource being referred to.
  7775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7776. maxLength: 63
  7777. minLength: 1
  7778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7779. type: string
  7780. type: object
  7781. secretAccessKeySecretRef:
  7782. description: The SecretAccessKey is used for authentication
  7783. properties:
  7784. key:
  7785. description: |-
  7786. A key in the referenced Secret.
  7787. Some instances of this field may be defaulted, in others it may be required.
  7788. maxLength: 253
  7789. minLength: 1
  7790. pattern: ^[-._a-zA-Z0-9]+$
  7791. type: string
  7792. name:
  7793. description: The name of the Secret resource being referred to.
  7794. maxLength: 253
  7795. minLength: 1
  7796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7797. type: string
  7798. namespace:
  7799. description: |-
  7800. The namespace of the Secret resource being referred to.
  7801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7802. maxLength: 63
  7803. minLength: 1
  7804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7805. type: string
  7806. type: object
  7807. sessionTokenSecretRef:
  7808. description: |-
  7809. The SessionToken used for authentication
  7810. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  7811. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  7812. properties:
  7813. key:
  7814. description: |-
  7815. A key in the referenced Secret.
  7816. Some instances of this field may be defaulted, in others it may be required.
  7817. maxLength: 253
  7818. minLength: 1
  7819. pattern: ^[-._a-zA-Z0-9]+$
  7820. type: string
  7821. name:
  7822. description: The name of the Secret resource being referred to.
  7823. maxLength: 253
  7824. minLength: 1
  7825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7826. type: string
  7827. namespace:
  7828. description: |-
  7829. The namespace of the Secret resource being referred to.
  7830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7831. maxLength: 63
  7832. minLength: 1
  7833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7834. type: string
  7835. type: object
  7836. type: object
  7837. vaultAwsIamServerID:
  7838. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  7839. type: string
  7840. vaultRole:
  7841. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  7842. type: string
  7843. required:
  7844. - vaultRole
  7845. type: object
  7846. jwt:
  7847. description: |-
  7848. Jwt authenticates with Vault by passing role and JWT token using the
  7849. JWT/OIDC authentication method
  7850. properties:
  7851. kubernetesServiceAccountToken:
  7852. description: |-
  7853. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  7854. a token for with the `TokenRequest` API.
  7855. properties:
  7856. audiences:
  7857. description: |-
  7858. Optional audiences field that will be used to request a temporary Kubernetes service
  7859. account token for the service account referenced by `serviceAccountRef`.
  7860. Defaults to a single audience `vault` it not specified.
  7861. Deprecated: use serviceAccountRef.Audiences instead
  7862. items:
  7863. type: string
  7864. type: array
  7865. expirationSeconds:
  7866. description: |-
  7867. Optional expiration time in seconds that will be used to request a temporary
  7868. Kubernetes service account token for the service account referenced by
  7869. `serviceAccountRef`.
  7870. Deprecated: this will be removed in the future.
  7871. Defaults to 10 minutes.
  7872. format: int64
  7873. type: integer
  7874. serviceAccountRef:
  7875. description: Service account field containing the name of a kubernetes ServiceAccount.
  7876. properties:
  7877. audiences:
  7878. description: |-
  7879. Audience specifies the `aud` claim for the service account token
  7880. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7881. then this audiences will be appended to the list
  7882. items:
  7883. type: string
  7884. type: array
  7885. name:
  7886. description: The name of the ServiceAccount resource being referred to.
  7887. maxLength: 253
  7888. minLength: 1
  7889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7890. type: string
  7891. namespace:
  7892. description: |-
  7893. Namespace of the resource being referred to.
  7894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7895. maxLength: 63
  7896. minLength: 1
  7897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7898. type: string
  7899. required:
  7900. - name
  7901. type: object
  7902. required:
  7903. - serviceAccountRef
  7904. type: object
  7905. path:
  7906. default: jwt
  7907. description: |-
  7908. Path where the JWT authentication backend is mounted
  7909. in Vault, e.g: "jwt"
  7910. type: string
  7911. role:
  7912. description: |-
  7913. Role is a JWT role to authenticate using the JWT/OIDC Vault
  7914. authentication method
  7915. type: string
  7916. secretRef:
  7917. description: |-
  7918. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  7919. authenticate with Vault using the JWT/OIDC authentication method.
  7920. properties:
  7921. key:
  7922. description: |-
  7923. A key in the referenced Secret.
  7924. Some instances of this field may be defaulted, in others it may be required.
  7925. maxLength: 253
  7926. minLength: 1
  7927. pattern: ^[-._a-zA-Z0-9]+$
  7928. type: string
  7929. name:
  7930. description: The name of the Secret resource being referred to.
  7931. maxLength: 253
  7932. minLength: 1
  7933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7934. type: string
  7935. namespace:
  7936. description: |-
  7937. The namespace of the Secret resource being referred to.
  7938. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7939. maxLength: 63
  7940. minLength: 1
  7941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7942. type: string
  7943. type: object
  7944. required:
  7945. - path
  7946. type: object
  7947. kubernetes:
  7948. description: |-
  7949. Kubernetes authenticates with Vault by passing the ServiceAccount
  7950. token stored in the named Secret resource to the Vault server.
  7951. properties:
  7952. mountPath:
  7953. default: kubernetes
  7954. description: |-
  7955. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  7956. "kubernetes"
  7957. type: string
  7958. role:
  7959. description: |-
  7960. A required field containing the Vault Role to assume. A Role binds a
  7961. Kubernetes ServiceAccount with a set of Vault policies.
  7962. type: string
  7963. secretRef:
  7964. description: |-
  7965. Optional secret field containing a Kubernetes ServiceAccount JWT used
  7966. for authenticating with Vault. If a name is specified without a key,
  7967. `token` is the default. If one is not specified, the one bound to
  7968. the controller will be used.
  7969. properties:
  7970. key:
  7971. description: |-
  7972. A key in the referenced Secret.
  7973. Some instances of this field may be defaulted, in others it may be required.
  7974. maxLength: 253
  7975. minLength: 1
  7976. pattern: ^[-._a-zA-Z0-9]+$
  7977. type: string
  7978. name:
  7979. description: The name of the Secret resource being referred to.
  7980. maxLength: 253
  7981. minLength: 1
  7982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7983. type: string
  7984. namespace:
  7985. description: |-
  7986. The namespace of the Secret resource being referred to.
  7987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7988. maxLength: 63
  7989. minLength: 1
  7990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7991. type: string
  7992. type: object
  7993. serviceAccountRef:
  7994. description: |-
  7995. Optional service account field containing the name of a kubernetes ServiceAccount.
  7996. If the service account is specified, the service account secret token JWT will be used
  7997. for authenticating with Vault. If the service account selector is not supplied,
  7998. the secretRef will be used instead.
  7999. properties:
  8000. audiences:
  8001. description: |-
  8002. Audience specifies the `aud` claim for the service account token
  8003. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8004. then this audiences will be appended to the list
  8005. items:
  8006. type: string
  8007. type: array
  8008. name:
  8009. description: The name of the ServiceAccount resource being referred to.
  8010. maxLength: 253
  8011. minLength: 1
  8012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8013. type: string
  8014. namespace:
  8015. description: |-
  8016. Namespace of the resource being referred to.
  8017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8018. maxLength: 63
  8019. minLength: 1
  8020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8021. type: string
  8022. required:
  8023. - name
  8024. type: object
  8025. required:
  8026. - mountPath
  8027. - role
  8028. type: object
  8029. ldap:
  8030. description: |-
  8031. Ldap authenticates with Vault by passing username/password pair using
  8032. the LDAP authentication method
  8033. properties:
  8034. path:
  8035. default: ldap
  8036. description: |-
  8037. Path where the LDAP authentication backend is mounted
  8038. in Vault, e.g: "ldap"
  8039. type: string
  8040. secretRef:
  8041. description: |-
  8042. SecretRef to a key in a Secret resource containing password for the LDAP
  8043. user used to authenticate with Vault using the LDAP authentication
  8044. method
  8045. properties:
  8046. key:
  8047. description: |-
  8048. A key in the referenced Secret.
  8049. Some instances of this field may be defaulted, in others it may be required.
  8050. maxLength: 253
  8051. minLength: 1
  8052. pattern: ^[-._a-zA-Z0-9]+$
  8053. type: string
  8054. name:
  8055. description: The name of the Secret resource being referred to.
  8056. maxLength: 253
  8057. minLength: 1
  8058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8059. type: string
  8060. namespace:
  8061. description: |-
  8062. The namespace of the Secret resource being referred to.
  8063. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8064. maxLength: 63
  8065. minLength: 1
  8066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8067. type: string
  8068. type: object
  8069. username:
  8070. description: |-
  8071. Username is an LDAP username used to authenticate using the LDAP Vault
  8072. authentication method
  8073. type: string
  8074. required:
  8075. - path
  8076. - username
  8077. type: object
  8078. namespace:
  8079. description: |-
  8080. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8081. Namespaces is a set of features within Vault Enterprise that allows
  8082. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8083. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8084. This will default to Vault.Namespace field if set, or empty otherwise
  8085. type: string
  8086. tokenSecretRef:
  8087. description: TokenSecretRef authenticates with Vault by presenting a token.
  8088. properties:
  8089. key:
  8090. description: |-
  8091. A key in the referenced Secret.
  8092. Some instances of this field may be defaulted, in others it may be required.
  8093. maxLength: 253
  8094. minLength: 1
  8095. pattern: ^[-._a-zA-Z0-9]+$
  8096. type: string
  8097. name:
  8098. description: The name of the Secret resource being referred to.
  8099. maxLength: 253
  8100. minLength: 1
  8101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8102. type: string
  8103. namespace:
  8104. description: |-
  8105. The namespace of the Secret resource being referred to.
  8106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8107. maxLength: 63
  8108. minLength: 1
  8109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8110. type: string
  8111. type: object
  8112. userPass:
  8113. description: UserPass authenticates with Vault by passing username/password pair
  8114. properties:
  8115. path:
  8116. default: userpass
  8117. description: |-
  8118. Path where the UserPassword authentication backend is mounted
  8119. in Vault, e.g: "userpass"
  8120. type: string
  8121. secretRef:
  8122. description: |-
  8123. SecretRef to a key in a Secret resource containing password for the
  8124. user used to authenticate with Vault using the UserPass authentication
  8125. method
  8126. properties:
  8127. key:
  8128. description: |-
  8129. A key in the referenced Secret.
  8130. Some instances of this field may be defaulted, in others it may be required.
  8131. maxLength: 253
  8132. minLength: 1
  8133. pattern: ^[-._a-zA-Z0-9]+$
  8134. type: string
  8135. name:
  8136. description: The name of the Secret resource being referred to.
  8137. maxLength: 253
  8138. minLength: 1
  8139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8140. type: string
  8141. namespace:
  8142. description: |-
  8143. The namespace of the Secret resource being referred to.
  8144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8145. maxLength: 63
  8146. minLength: 1
  8147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8148. type: string
  8149. type: object
  8150. username:
  8151. description: |-
  8152. Username is a username used to authenticate using the UserPass Vault
  8153. authentication method
  8154. type: string
  8155. required:
  8156. - path
  8157. - username
  8158. type: object
  8159. type: object
  8160. caBundle:
  8161. description: |-
  8162. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8163. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8164. plain HTTP protocol connection. If not set the system root certificates
  8165. are used to validate the TLS connection.
  8166. format: byte
  8167. type: string
  8168. caProvider:
  8169. description: The provider for the CA bundle to use to validate Vault server certificate.
  8170. properties:
  8171. key:
  8172. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8173. maxLength: 253
  8174. minLength: 1
  8175. pattern: ^[-._a-zA-Z0-9]+$
  8176. type: string
  8177. name:
  8178. description: The name of the object located at the provider type.
  8179. maxLength: 253
  8180. minLength: 1
  8181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8182. type: string
  8183. namespace:
  8184. description: |-
  8185. The namespace the Provider type is in.
  8186. Can only be defined when used in a ClusterSecretStore.
  8187. maxLength: 63
  8188. minLength: 1
  8189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8190. type: string
  8191. type:
  8192. description: The type of provider to use such as "Secret", or "ConfigMap".
  8193. enum:
  8194. - Secret
  8195. - ConfigMap
  8196. type: string
  8197. required:
  8198. - name
  8199. - type
  8200. type: object
  8201. checkAndSet:
  8202. description: |-
  8203. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8204. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8205. the current version of the secret to prevent unintentional overwrites.
  8206. properties:
  8207. required:
  8208. description: |-
  8209. Required when true, all write operations must include a check-and-set parameter.
  8210. This helps prevent unintentional overwrites of secrets.
  8211. type: boolean
  8212. type: object
  8213. forwardInconsistent:
  8214. description: |-
  8215. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8216. leader instead of simply retrying within a loop. This can increase performance if
  8217. the option is enabled serverside.
  8218. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8219. type: boolean
  8220. headers:
  8221. additionalProperties:
  8222. type: string
  8223. description: Headers to be added in Vault request
  8224. type: object
  8225. namespace:
  8226. description: |-
  8227. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8228. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8229. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8230. type: string
  8231. path:
  8232. description: |-
  8233. Path is the mount path of the Vault KV backend endpoint, e.g:
  8234. "secret". The v2 KV secret engine version specific "/data" path suffix
  8235. for fetching secrets from Vault is optional and will be appended
  8236. if not present in specified path.
  8237. type: string
  8238. readYourWrites:
  8239. description: |-
  8240. ReadYourWrites ensures isolated read-after-write semantics by
  8241. providing discovered cluster replication states in each request.
  8242. More information about eventual consistency in Vault can be found here
  8243. https://www.vaultproject.io/docs/enterprise/consistency
  8244. type: boolean
  8245. server:
  8246. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8247. type: string
  8248. tls:
  8249. description: |-
  8250. The configuration used for client side related TLS communication, when the Vault server
  8251. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8252. This parameter is ignored for plain HTTP protocol connection.
  8253. It's worth noting this configuration is different from the "TLS certificates auth method",
  8254. which is available under the `auth.cert` section.
  8255. properties:
  8256. certSecretRef:
  8257. description: |-
  8258. CertSecretRef is a certificate added to the transport layer
  8259. when communicating with the Vault server.
  8260. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8261. properties:
  8262. key:
  8263. description: |-
  8264. A key in the referenced Secret.
  8265. Some instances of this field may be defaulted, in others it may be required.
  8266. maxLength: 253
  8267. minLength: 1
  8268. pattern: ^[-._a-zA-Z0-9]+$
  8269. type: string
  8270. name:
  8271. description: The name of the Secret resource being referred to.
  8272. maxLength: 253
  8273. minLength: 1
  8274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8275. type: string
  8276. namespace:
  8277. description: |-
  8278. The namespace of the Secret resource being referred to.
  8279. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8280. maxLength: 63
  8281. minLength: 1
  8282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8283. type: string
  8284. type: object
  8285. keySecretRef:
  8286. description: |-
  8287. KeySecretRef to a key in a Secret resource containing client private key
  8288. added to the transport layer when communicating with the Vault server.
  8289. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8290. properties:
  8291. key:
  8292. description: |-
  8293. A key in the referenced Secret.
  8294. Some instances of this field may be defaulted, in others it may be required.
  8295. maxLength: 253
  8296. minLength: 1
  8297. pattern: ^[-._a-zA-Z0-9]+$
  8298. type: string
  8299. name:
  8300. description: The name of the Secret resource being referred to.
  8301. maxLength: 253
  8302. minLength: 1
  8303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8304. type: string
  8305. namespace:
  8306. description: |-
  8307. The namespace of the Secret resource being referred to.
  8308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8309. maxLength: 63
  8310. minLength: 1
  8311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8312. type: string
  8313. type: object
  8314. type: object
  8315. version:
  8316. default: v2
  8317. description: |-
  8318. Version is the Vault KV secret engine version. This can be either "v1" or
  8319. "v2". Version defaults to "v2".
  8320. enum:
  8321. - v1
  8322. - v2
  8323. type: string
  8324. required:
  8325. - server
  8326. type: object
  8327. volcengine:
  8328. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8329. properties:
  8330. auth:
  8331. description: |-
  8332. Auth defines the authentication method to use.
  8333. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8334. properties:
  8335. secretRef:
  8336. description: |-
  8337. SecretRef defines the static credentials to use for authentication.
  8338. If not set, IRSA is used.
  8339. properties:
  8340. accessKeyID:
  8341. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8342. properties:
  8343. key:
  8344. description: |-
  8345. A key in the referenced Secret.
  8346. Some instances of this field may be defaulted, in others it may be required.
  8347. maxLength: 253
  8348. minLength: 1
  8349. pattern: ^[-._a-zA-Z0-9]+$
  8350. type: string
  8351. name:
  8352. description: The name of the Secret resource being referred to.
  8353. maxLength: 253
  8354. minLength: 1
  8355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8356. type: string
  8357. namespace:
  8358. description: |-
  8359. The namespace of the Secret resource being referred to.
  8360. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8361. maxLength: 63
  8362. minLength: 1
  8363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8364. type: string
  8365. type: object
  8366. secretAccessKey:
  8367. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8368. properties:
  8369. key:
  8370. description: |-
  8371. A key in the referenced Secret.
  8372. Some instances of this field may be defaulted, in others it may be required.
  8373. maxLength: 253
  8374. minLength: 1
  8375. pattern: ^[-._a-zA-Z0-9]+$
  8376. type: string
  8377. name:
  8378. description: The name of the Secret resource being referred to.
  8379. maxLength: 253
  8380. minLength: 1
  8381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8382. type: string
  8383. namespace:
  8384. description: |-
  8385. The namespace of the Secret resource being referred to.
  8386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8387. maxLength: 63
  8388. minLength: 1
  8389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8390. type: string
  8391. type: object
  8392. token:
  8393. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8394. properties:
  8395. key:
  8396. description: |-
  8397. A key in the referenced Secret.
  8398. Some instances of this field may be defaulted, in others it may be required.
  8399. maxLength: 253
  8400. minLength: 1
  8401. pattern: ^[-._a-zA-Z0-9]+$
  8402. type: string
  8403. name:
  8404. description: The name of the Secret resource being referred to.
  8405. maxLength: 253
  8406. minLength: 1
  8407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8408. type: string
  8409. namespace:
  8410. description: |-
  8411. The namespace of the Secret resource being referred to.
  8412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8413. maxLength: 63
  8414. minLength: 1
  8415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8416. type: string
  8417. type: object
  8418. required:
  8419. - accessKeyID
  8420. - secretAccessKey
  8421. type: object
  8422. type: object
  8423. region:
  8424. description: Region specifies the Volcengine region to connect to.
  8425. type: string
  8426. required:
  8427. - region
  8428. type: object
  8429. webhook:
  8430. description: Webhook configures this store to sync secrets using a generic templated webhook
  8431. properties:
  8432. auth:
  8433. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8434. maxProperties: 1
  8435. minProperties: 1
  8436. properties:
  8437. ntlm:
  8438. description: NTLMProtocol configures the store to use NTLM for auth
  8439. properties:
  8440. passwordSecret:
  8441. description: |-
  8442. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8443. In some instances, `key` is a required field.
  8444. properties:
  8445. key:
  8446. description: |-
  8447. A key in the referenced Secret.
  8448. Some instances of this field may be defaulted, in others it may be required.
  8449. maxLength: 253
  8450. minLength: 1
  8451. pattern: ^[-._a-zA-Z0-9]+$
  8452. type: string
  8453. name:
  8454. description: The name of the Secret resource being referred to.
  8455. maxLength: 253
  8456. minLength: 1
  8457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8458. type: string
  8459. namespace:
  8460. description: |-
  8461. The namespace of the Secret resource being referred to.
  8462. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8463. maxLength: 63
  8464. minLength: 1
  8465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8466. type: string
  8467. type: object
  8468. usernameSecret:
  8469. description: |-
  8470. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8471. In some instances, `key` is a required field.
  8472. properties:
  8473. key:
  8474. description: |-
  8475. A key in the referenced Secret.
  8476. Some instances of this field may be defaulted, in others it may be required.
  8477. maxLength: 253
  8478. minLength: 1
  8479. pattern: ^[-._a-zA-Z0-9]+$
  8480. type: string
  8481. name:
  8482. description: The name of the Secret resource being referred to.
  8483. maxLength: 253
  8484. minLength: 1
  8485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8486. type: string
  8487. namespace:
  8488. description: |-
  8489. The namespace of the Secret resource being referred to.
  8490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8491. maxLength: 63
  8492. minLength: 1
  8493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8494. type: string
  8495. type: object
  8496. required:
  8497. - passwordSecret
  8498. - usernameSecret
  8499. type: object
  8500. type: object
  8501. body:
  8502. description: Body
  8503. type: string
  8504. caBundle:
  8505. description: |-
  8506. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8507. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8508. plain HTTP protocol connection. If not set the system root certificates
  8509. are used to validate the TLS connection.
  8510. format: byte
  8511. type: string
  8512. caProvider:
  8513. description: The provider for the CA bundle to use to validate webhook server certificate.
  8514. properties:
  8515. key:
  8516. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8517. maxLength: 253
  8518. minLength: 1
  8519. pattern: ^[-._a-zA-Z0-9]+$
  8520. type: string
  8521. name:
  8522. description: The name of the object located at the provider type.
  8523. maxLength: 253
  8524. minLength: 1
  8525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8526. type: string
  8527. namespace:
  8528. description: The namespace the Provider type is in.
  8529. maxLength: 63
  8530. minLength: 1
  8531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8532. type: string
  8533. type:
  8534. description: The type of provider to use such as "Secret", or "ConfigMap".
  8535. enum:
  8536. - Secret
  8537. - ConfigMap
  8538. type: string
  8539. required:
  8540. - name
  8541. - type
  8542. type: object
  8543. headers:
  8544. additionalProperties:
  8545. type: string
  8546. description: Headers
  8547. type: object
  8548. method:
  8549. description: Webhook Method
  8550. type: string
  8551. result:
  8552. description: Result formatting
  8553. properties:
  8554. jsonPath:
  8555. description: Json path of return value
  8556. type: string
  8557. type: object
  8558. secrets:
  8559. description: |-
  8560. Secrets to fill in templates
  8561. These secrets will be passed to the templating function as key value pairs under the given name
  8562. items:
  8563. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8564. properties:
  8565. name:
  8566. description: Name of this secret in templates
  8567. type: string
  8568. secretRef:
  8569. description: Secret ref to fill in credentials
  8570. properties:
  8571. key:
  8572. description: |-
  8573. A key in the referenced Secret.
  8574. Some instances of this field may be defaulted, in others it may be required.
  8575. maxLength: 253
  8576. minLength: 1
  8577. pattern: ^[-._a-zA-Z0-9]+$
  8578. type: string
  8579. name:
  8580. description: The name of the Secret resource being referred to.
  8581. maxLength: 253
  8582. minLength: 1
  8583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8584. type: string
  8585. namespace:
  8586. description: |-
  8587. The namespace of the Secret resource being referred to.
  8588. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8589. maxLength: 63
  8590. minLength: 1
  8591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8592. type: string
  8593. type: object
  8594. required:
  8595. - name
  8596. - secretRef
  8597. type: object
  8598. type: array
  8599. timeout:
  8600. description: Timeout
  8601. type: string
  8602. url:
  8603. description: Webhook url to call
  8604. type: string
  8605. required:
  8606. - url
  8607. type: object
  8608. yandexcertificatemanager:
  8609. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  8610. properties:
  8611. apiEndpoint:
  8612. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  8613. type: string
  8614. auth:
  8615. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  8616. properties:
  8617. authorizedKeySecretRef:
  8618. description: The authorized key used for authentication
  8619. properties:
  8620. key:
  8621. description: |-
  8622. A key in the referenced Secret.
  8623. Some instances of this field may be defaulted, in others it may be required.
  8624. maxLength: 253
  8625. minLength: 1
  8626. pattern: ^[-._a-zA-Z0-9]+$
  8627. type: string
  8628. name:
  8629. description: The name of the Secret resource being referred to.
  8630. maxLength: 253
  8631. minLength: 1
  8632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8633. type: string
  8634. namespace:
  8635. description: |-
  8636. The namespace of the Secret resource being referred to.
  8637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8638. maxLength: 63
  8639. minLength: 1
  8640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8641. type: string
  8642. type: object
  8643. type: object
  8644. caProvider:
  8645. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  8646. properties:
  8647. certSecretRef:
  8648. description: |-
  8649. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8650. In some instances, `key` is a required field.
  8651. properties:
  8652. key:
  8653. description: |-
  8654. A key in the referenced Secret.
  8655. Some instances of this field may be defaulted, in others it may be required.
  8656. maxLength: 253
  8657. minLength: 1
  8658. pattern: ^[-._a-zA-Z0-9]+$
  8659. type: string
  8660. name:
  8661. description: The name of the Secret resource being referred to.
  8662. maxLength: 253
  8663. minLength: 1
  8664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8665. type: string
  8666. namespace:
  8667. description: |-
  8668. The namespace of the Secret resource being referred to.
  8669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8670. maxLength: 63
  8671. minLength: 1
  8672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8673. type: string
  8674. type: object
  8675. type: object
  8676. fetching:
  8677. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  8678. maxProperties: 1
  8679. minProperties: 1
  8680. properties:
  8681. byID:
  8682. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  8683. type: object
  8684. byName:
  8685. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  8686. properties:
  8687. folderID:
  8688. description: The folder to fetch secrets from
  8689. type: string
  8690. required:
  8691. - folderID
  8692. type: object
  8693. type: object
  8694. required:
  8695. - auth
  8696. type: object
  8697. yandexlockbox:
  8698. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  8699. properties:
  8700. apiEndpoint:
  8701. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  8702. type: string
  8703. auth:
  8704. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  8705. properties:
  8706. authorizedKeySecretRef:
  8707. description: The authorized key used for authentication
  8708. properties:
  8709. key:
  8710. description: |-
  8711. A key in the referenced Secret.
  8712. Some instances of this field may be defaulted, in others it may be required.
  8713. maxLength: 253
  8714. minLength: 1
  8715. pattern: ^[-._a-zA-Z0-9]+$
  8716. type: string
  8717. name:
  8718. description: The name of the Secret resource being referred to.
  8719. maxLength: 253
  8720. minLength: 1
  8721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8722. type: string
  8723. namespace:
  8724. description: |-
  8725. The namespace of the Secret resource being referred to.
  8726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8727. maxLength: 63
  8728. minLength: 1
  8729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8730. type: string
  8731. type: object
  8732. type: object
  8733. caProvider:
  8734. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  8735. properties:
  8736. certSecretRef:
  8737. description: |-
  8738. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8739. In some instances, `key` is a required field.
  8740. properties:
  8741. key:
  8742. description: |-
  8743. A key in the referenced Secret.
  8744. Some instances of this field may be defaulted, in others it may be required.
  8745. maxLength: 253
  8746. minLength: 1
  8747. pattern: ^[-._a-zA-Z0-9]+$
  8748. type: string
  8749. name:
  8750. description: The name of the Secret resource being referred to.
  8751. maxLength: 253
  8752. minLength: 1
  8753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8754. type: string
  8755. namespace:
  8756. description: |-
  8757. The namespace of the Secret resource being referred to.
  8758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8759. maxLength: 63
  8760. minLength: 1
  8761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8762. type: string
  8763. type: object
  8764. type: object
  8765. fetching:
  8766. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  8767. maxProperties: 1
  8768. minProperties: 1
  8769. properties:
  8770. byID:
  8771. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  8772. type: object
  8773. byName:
  8774. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  8775. properties:
  8776. folderID:
  8777. description: The folder to fetch secrets from
  8778. type: string
  8779. required:
  8780. - folderID
  8781. type: object
  8782. type: object
  8783. required:
  8784. - auth
  8785. type: object
  8786. type: object
  8787. refreshInterval:
  8788. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  8789. type: integer
  8790. retrySettings:
  8791. description: Used to configure HTTP retries on failures.
  8792. properties:
  8793. maxRetries:
  8794. format: int32
  8795. type: integer
  8796. retryInterval:
  8797. type: string
  8798. type: object
  8799. required:
  8800. - provider
  8801. type: object
  8802. status:
  8803. description: SecretStoreStatus defines the observed state of the SecretStore.
  8804. properties:
  8805. capabilities:
  8806. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  8807. type: string
  8808. conditions:
  8809. items:
  8810. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  8811. properties:
  8812. lastTransitionTime:
  8813. format: date-time
  8814. type: string
  8815. message:
  8816. type: string
  8817. reason:
  8818. type: string
  8819. status:
  8820. type: string
  8821. type:
  8822. description: SecretStoreConditionType represents the condition of the SecretStore.
  8823. type: string
  8824. required:
  8825. - status
  8826. - type
  8827. type: object
  8828. type: array
  8829. type: object
  8830. type: object
  8831. served: true
  8832. storage: true
  8833. subresources:
  8834. status: {}
  8835. - additionalPrinterColumns:
  8836. - jsonPath: .metadata.creationTimestamp
  8837. name: AGE
  8838. type: date
  8839. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  8840. name: Status
  8841. type: string
  8842. - jsonPath: .status.capabilities
  8843. name: Capabilities
  8844. type: string
  8845. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  8846. name: Ready
  8847. type: string
  8848. deprecated: true
  8849. name: v1beta1
  8850. schema:
  8851. openAPIV3Schema:
  8852. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  8853. properties:
  8854. apiVersion:
  8855. description: |-
  8856. APIVersion defines the versioned schema of this representation of an object.
  8857. Servers should convert recognized schemas to the latest internal value, and
  8858. may reject unrecognized values.
  8859. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  8860. type: string
  8861. kind:
  8862. description: |-
  8863. Kind is a string value representing the REST resource this object represents.
  8864. Servers may infer this from the endpoint the client submits requests to.
  8865. Cannot be updated.
  8866. In CamelCase.
  8867. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  8868. type: string
  8869. metadata:
  8870. type: object
  8871. spec:
  8872. description: SecretStoreSpec defines the desired state of SecretStore.
  8873. properties:
  8874. conditions:
  8875. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  8876. items:
  8877. description: |-
  8878. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  8879. for a ClusterSecretStore instance.
  8880. properties:
  8881. namespaceRegexes:
  8882. description: Choose namespaces by using regex matching
  8883. items:
  8884. type: string
  8885. type: array
  8886. namespaceSelector:
  8887. description: Choose namespace using a labelSelector
  8888. properties:
  8889. matchExpressions:
  8890. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  8891. items:
  8892. description: |-
  8893. A label selector requirement is a selector that contains values, a key, and an operator that
  8894. relates the key and values.
  8895. properties:
  8896. key:
  8897. description: key is the label key that the selector applies to.
  8898. type: string
  8899. operator:
  8900. description: |-
  8901. operator represents a key's relationship to a set of values.
  8902. Valid operators are In, NotIn, Exists and DoesNotExist.
  8903. type: string
  8904. values:
  8905. description: |-
  8906. values is an array of string values. If the operator is In or NotIn,
  8907. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  8908. the values array must be empty. This array is replaced during a strategic
  8909. merge patch.
  8910. items:
  8911. type: string
  8912. type: array
  8913. x-kubernetes-list-type: atomic
  8914. required:
  8915. - key
  8916. - operator
  8917. type: object
  8918. type: array
  8919. x-kubernetes-list-type: atomic
  8920. matchLabels:
  8921. additionalProperties:
  8922. type: string
  8923. description: |-
  8924. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  8925. map is equivalent to an element of matchExpressions, whose key field is "key", the
  8926. operator is "In", and the values array contains only "value". The requirements are ANDed.
  8927. type: object
  8928. type: object
  8929. x-kubernetes-map-type: atomic
  8930. namespaces:
  8931. description: Choose namespaces by name
  8932. items:
  8933. maxLength: 63
  8934. minLength: 1
  8935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8936. type: string
  8937. type: array
  8938. type: object
  8939. type: array
  8940. controller:
  8941. description: |-
  8942. Used to select the correct ESO controller (think: ingress.ingressClassName)
  8943. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  8944. type: string
  8945. provider:
  8946. description: Used to configure the provider. Only one provider may be set
  8947. maxProperties: 1
  8948. minProperties: 1
  8949. properties:
  8950. akeyless:
  8951. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  8952. properties:
  8953. akeylessGWApiURL:
  8954. description: Akeyless GW API Url from which the secrets to be fetched from.
  8955. type: string
  8956. authSecretRef:
  8957. description: Auth configures how the operator authenticates with Akeyless.
  8958. properties:
  8959. kubernetesAuth:
  8960. description: |-
  8961. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  8962. token stored in the named Secret resource.
  8963. properties:
  8964. accessID:
  8965. description: the Akeyless Kubernetes auth-method access-id
  8966. type: string
  8967. k8sConfName:
  8968. description: Kubernetes-auth configuration name in Akeyless-Gateway
  8969. type: string
  8970. secretRef:
  8971. description: |-
  8972. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8973. for authenticating with Akeyless. If a name is specified without a key,
  8974. `token` is the default. If one is not specified, the one bound to
  8975. the controller will be used.
  8976. properties:
  8977. key:
  8978. description: |-
  8979. A key in the referenced Secret.
  8980. Some instances of this field may be defaulted, in others it may be required.
  8981. maxLength: 253
  8982. minLength: 1
  8983. pattern: ^[-._a-zA-Z0-9]+$
  8984. type: string
  8985. name:
  8986. description: The name of the Secret resource being referred to.
  8987. maxLength: 253
  8988. minLength: 1
  8989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8990. type: string
  8991. namespace:
  8992. description: |-
  8993. The namespace of the Secret resource being referred to.
  8994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8995. maxLength: 63
  8996. minLength: 1
  8997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8998. type: string
  8999. type: object
  9000. serviceAccountRef:
  9001. description: |-
  9002. Optional service account field containing the name of a kubernetes ServiceAccount.
  9003. If the service account is specified, the service account secret token JWT will be used
  9004. for authenticating with Akeyless. If the service account selector is not supplied,
  9005. the secretRef will be used instead.
  9006. properties:
  9007. audiences:
  9008. description: |-
  9009. Audience specifies the `aud` claim for the service account token
  9010. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9011. then this audiences will be appended to the list
  9012. items:
  9013. type: string
  9014. type: array
  9015. name:
  9016. description: The name of the ServiceAccount resource being referred to.
  9017. maxLength: 253
  9018. minLength: 1
  9019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9020. type: string
  9021. namespace:
  9022. description: |-
  9023. Namespace of the resource being referred to.
  9024. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9025. maxLength: 63
  9026. minLength: 1
  9027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9028. type: string
  9029. required:
  9030. - name
  9031. type: object
  9032. required:
  9033. - accessID
  9034. - k8sConfName
  9035. type: object
  9036. secretRef:
  9037. description: |-
  9038. Reference to a Secret that contains the details
  9039. to authenticate with Akeyless.
  9040. properties:
  9041. accessID:
  9042. description: The SecretAccessID is used for authentication
  9043. properties:
  9044. key:
  9045. description: |-
  9046. A key in the referenced Secret.
  9047. Some instances of this field may be defaulted, in others it may be required.
  9048. maxLength: 253
  9049. minLength: 1
  9050. pattern: ^[-._a-zA-Z0-9]+$
  9051. type: string
  9052. name:
  9053. description: The name of the Secret resource being referred to.
  9054. maxLength: 253
  9055. minLength: 1
  9056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9057. type: string
  9058. namespace:
  9059. description: |-
  9060. The namespace of the Secret resource being referred to.
  9061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9062. maxLength: 63
  9063. minLength: 1
  9064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9065. type: string
  9066. type: object
  9067. accessType:
  9068. description: |-
  9069. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9070. In some instances, `key` is a required field.
  9071. properties:
  9072. key:
  9073. description: |-
  9074. A key in the referenced Secret.
  9075. Some instances of this field may be defaulted, in others it may be required.
  9076. maxLength: 253
  9077. minLength: 1
  9078. pattern: ^[-._a-zA-Z0-9]+$
  9079. type: string
  9080. name:
  9081. description: The name of the Secret resource being referred to.
  9082. maxLength: 253
  9083. minLength: 1
  9084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9085. type: string
  9086. namespace:
  9087. description: |-
  9088. The namespace of the Secret resource being referred to.
  9089. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9090. maxLength: 63
  9091. minLength: 1
  9092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9093. type: string
  9094. type: object
  9095. accessTypeParam:
  9096. description: |-
  9097. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9098. In some instances, `key` is a required field.
  9099. properties:
  9100. key:
  9101. description: |-
  9102. A key in the referenced Secret.
  9103. Some instances of this field may be defaulted, in others it may be required.
  9104. maxLength: 253
  9105. minLength: 1
  9106. pattern: ^[-._a-zA-Z0-9]+$
  9107. type: string
  9108. name:
  9109. description: The name of the Secret resource being referred to.
  9110. maxLength: 253
  9111. minLength: 1
  9112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9113. type: string
  9114. namespace:
  9115. description: |-
  9116. The namespace of the Secret resource being referred to.
  9117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9118. maxLength: 63
  9119. minLength: 1
  9120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9121. type: string
  9122. type: object
  9123. type: object
  9124. type: object
  9125. caBundle:
  9126. description: |-
  9127. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9128. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9129. are used to validate the TLS connection.
  9130. format: byte
  9131. type: string
  9132. caProvider:
  9133. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9134. properties:
  9135. key:
  9136. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9137. maxLength: 253
  9138. minLength: 1
  9139. pattern: ^[-._a-zA-Z0-9]+$
  9140. type: string
  9141. name:
  9142. description: The name of the object located at the provider type.
  9143. maxLength: 253
  9144. minLength: 1
  9145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9146. type: string
  9147. namespace:
  9148. description: |-
  9149. The namespace the Provider type is in.
  9150. Can only be defined when used in a ClusterSecretStore.
  9151. maxLength: 63
  9152. minLength: 1
  9153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9154. type: string
  9155. type:
  9156. description: The type of provider to use such as "Secret", or "ConfigMap".
  9157. enum:
  9158. - Secret
  9159. - ConfigMap
  9160. type: string
  9161. required:
  9162. - name
  9163. - type
  9164. type: object
  9165. required:
  9166. - akeylessGWApiURL
  9167. - authSecretRef
  9168. type: object
  9169. alibaba:
  9170. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9171. properties:
  9172. auth:
  9173. description: AlibabaAuth contains a secretRef for credentials.
  9174. properties:
  9175. rrsa:
  9176. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9177. properties:
  9178. oidcProviderArn:
  9179. type: string
  9180. oidcTokenFilePath:
  9181. type: string
  9182. roleArn:
  9183. type: string
  9184. sessionName:
  9185. type: string
  9186. required:
  9187. - oidcProviderArn
  9188. - oidcTokenFilePath
  9189. - roleArn
  9190. - sessionName
  9191. type: object
  9192. secretRef:
  9193. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9194. properties:
  9195. accessKeyIDSecretRef:
  9196. description: The AccessKeyID is used for authentication
  9197. properties:
  9198. key:
  9199. description: |-
  9200. A key in the referenced Secret.
  9201. Some instances of this field may be defaulted, in others it may be required.
  9202. maxLength: 253
  9203. minLength: 1
  9204. pattern: ^[-._a-zA-Z0-9]+$
  9205. type: string
  9206. name:
  9207. description: The name of the Secret resource being referred to.
  9208. maxLength: 253
  9209. minLength: 1
  9210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9211. type: string
  9212. namespace:
  9213. description: |-
  9214. The namespace of the Secret resource being referred to.
  9215. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9216. maxLength: 63
  9217. minLength: 1
  9218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9219. type: string
  9220. type: object
  9221. accessKeySecretSecretRef:
  9222. description: The AccessKeySecret is used for authentication
  9223. properties:
  9224. key:
  9225. description: |-
  9226. A key in the referenced Secret.
  9227. Some instances of this field may be defaulted, in others it may be required.
  9228. maxLength: 253
  9229. minLength: 1
  9230. pattern: ^[-._a-zA-Z0-9]+$
  9231. type: string
  9232. name:
  9233. description: The name of the Secret resource being referred to.
  9234. maxLength: 253
  9235. minLength: 1
  9236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9237. type: string
  9238. namespace:
  9239. description: |-
  9240. The namespace of the Secret resource being referred to.
  9241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9242. maxLength: 63
  9243. minLength: 1
  9244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9245. type: string
  9246. type: object
  9247. required:
  9248. - accessKeyIDSecretRef
  9249. - accessKeySecretSecretRef
  9250. type: object
  9251. type: object
  9252. regionID:
  9253. description: Alibaba Region to be used for the provider
  9254. type: string
  9255. required:
  9256. - auth
  9257. - regionID
  9258. type: object
  9259. aws:
  9260. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9261. properties:
  9262. additionalRoles:
  9263. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9264. items:
  9265. type: string
  9266. type: array
  9267. auth:
  9268. description: |-
  9269. Auth defines the information necessary to authenticate against AWS
  9270. if not set aws sdk will infer credentials from your environment
  9271. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9272. properties:
  9273. jwt:
  9274. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9275. properties:
  9276. serviceAccountRef:
  9277. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9278. properties:
  9279. audiences:
  9280. description: |-
  9281. Audience specifies the `aud` claim for the service account token
  9282. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9283. then this audiences will be appended to the list
  9284. items:
  9285. type: string
  9286. type: array
  9287. name:
  9288. description: The name of the ServiceAccount resource being referred to.
  9289. maxLength: 253
  9290. minLength: 1
  9291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9292. type: string
  9293. namespace:
  9294. description: |-
  9295. Namespace of the resource being referred to.
  9296. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9297. maxLength: 63
  9298. minLength: 1
  9299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9300. type: string
  9301. required:
  9302. - name
  9303. type: object
  9304. type: object
  9305. secretRef:
  9306. description: |-
  9307. AWSAuthSecretRef holds secret references for AWS credentials
  9308. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9309. properties:
  9310. accessKeyIDSecretRef:
  9311. description: The AccessKeyID is used for authentication
  9312. properties:
  9313. key:
  9314. description: |-
  9315. A key in the referenced Secret.
  9316. Some instances of this field may be defaulted, in others it may be required.
  9317. maxLength: 253
  9318. minLength: 1
  9319. pattern: ^[-._a-zA-Z0-9]+$
  9320. type: string
  9321. name:
  9322. description: The name of the Secret resource being referred to.
  9323. maxLength: 253
  9324. minLength: 1
  9325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9326. type: string
  9327. namespace:
  9328. description: |-
  9329. The namespace of the Secret resource being referred to.
  9330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9331. maxLength: 63
  9332. minLength: 1
  9333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9334. type: string
  9335. type: object
  9336. secretAccessKeySecretRef:
  9337. description: The SecretAccessKey is used for authentication
  9338. properties:
  9339. key:
  9340. description: |-
  9341. A key in the referenced Secret.
  9342. Some instances of this field may be defaulted, in others it may be required.
  9343. maxLength: 253
  9344. minLength: 1
  9345. pattern: ^[-._a-zA-Z0-9]+$
  9346. type: string
  9347. name:
  9348. description: The name of the Secret resource being referred to.
  9349. maxLength: 253
  9350. minLength: 1
  9351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9352. type: string
  9353. namespace:
  9354. description: |-
  9355. The namespace of the Secret resource being referred to.
  9356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9357. maxLength: 63
  9358. minLength: 1
  9359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9360. type: string
  9361. type: object
  9362. sessionTokenSecretRef:
  9363. description: |-
  9364. The SessionToken used for authentication
  9365. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9366. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9367. properties:
  9368. key:
  9369. description: |-
  9370. A key in the referenced Secret.
  9371. Some instances of this field may be defaulted, in others it may be required.
  9372. maxLength: 253
  9373. minLength: 1
  9374. pattern: ^[-._a-zA-Z0-9]+$
  9375. type: string
  9376. name:
  9377. description: The name of the Secret resource being referred to.
  9378. maxLength: 253
  9379. minLength: 1
  9380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9381. type: string
  9382. namespace:
  9383. description: |-
  9384. The namespace of the Secret resource being referred to.
  9385. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9386. maxLength: 63
  9387. minLength: 1
  9388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9389. type: string
  9390. type: object
  9391. type: object
  9392. type: object
  9393. externalID:
  9394. description: AWS External ID set on assumed IAM roles
  9395. type: string
  9396. prefix:
  9397. description: Prefix adds a prefix to all retrieved values.
  9398. type: string
  9399. region:
  9400. description: AWS Region to be used for the provider
  9401. type: string
  9402. role:
  9403. description: Role is a Role ARN which the provider will assume
  9404. type: string
  9405. secretsManager:
  9406. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9407. properties:
  9408. forceDeleteWithoutRecovery:
  9409. description: |-
  9410. Specifies whether to delete the secret without any recovery window. You
  9411. can't use both this parameter and RecoveryWindowInDays in the same call.
  9412. If you don't use either, then by default Secrets Manager uses a 30 day
  9413. recovery window.
  9414. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9415. type: boolean
  9416. recoveryWindowInDays:
  9417. description: |-
  9418. The number of days from 7 to 30 that Secrets Manager waits before
  9419. permanently deleting the secret. You can't use both this parameter and
  9420. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9421. then by default Secrets Manager uses a 30 day recovery window.
  9422. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9423. format: int64
  9424. type: integer
  9425. type: object
  9426. service:
  9427. description: Service defines which service should be used to fetch the secrets
  9428. enum:
  9429. - SecretsManager
  9430. - ParameterStore
  9431. type: string
  9432. sessionTags:
  9433. description: AWS STS assume role session tags
  9434. items:
  9435. description: Tag defines a tag key and value for AWS resources.
  9436. properties:
  9437. key:
  9438. type: string
  9439. value:
  9440. type: string
  9441. required:
  9442. - key
  9443. - value
  9444. type: object
  9445. type: array
  9446. transitiveTagKeys:
  9447. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9448. items:
  9449. type: string
  9450. type: array
  9451. required:
  9452. - region
  9453. - service
  9454. type: object
  9455. azurekv:
  9456. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9457. properties:
  9458. authSecretRef:
  9459. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9460. properties:
  9461. clientCertificate:
  9462. description: The Azure ClientCertificate of the service principle used for authentication.
  9463. properties:
  9464. key:
  9465. description: |-
  9466. A key in the referenced Secret.
  9467. Some instances of this field may be defaulted, in others it may be required.
  9468. maxLength: 253
  9469. minLength: 1
  9470. pattern: ^[-._a-zA-Z0-9]+$
  9471. type: string
  9472. name:
  9473. description: The name of the Secret resource being referred to.
  9474. maxLength: 253
  9475. minLength: 1
  9476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9477. type: string
  9478. namespace:
  9479. description: |-
  9480. The namespace of the Secret resource being referred to.
  9481. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9482. maxLength: 63
  9483. minLength: 1
  9484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9485. type: string
  9486. type: object
  9487. clientId:
  9488. description: The Azure clientId of the service principle or managed identity used for authentication.
  9489. properties:
  9490. key:
  9491. description: |-
  9492. A key in the referenced Secret.
  9493. Some instances of this field may be defaulted, in others it may be required.
  9494. maxLength: 253
  9495. minLength: 1
  9496. pattern: ^[-._a-zA-Z0-9]+$
  9497. type: string
  9498. name:
  9499. description: The name of the Secret resource being referred to.
  9500. maxLength: 253
  9501. minLength: 1
  9502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9503. type: string
  9504. namespace:
  9505. description: |-
  9506. The namespace of the Secret resource being referred to.
  9507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9508. maxLength: 63
  9509. minLength: 1
  9510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9511. type: string
  9512. type: object
  9513. clientSecret:
  9514. description: The Azure ClientSecret of the service principle used for authentication.
  9515. properties:
  9516. key:
  9517. description: |-
  9518. A key in the referenced Secret.
  9519. Some instances of this field may be defaulted, in others it may be required.
  9520. maxLength: 253
  9521. minLength: 1
  9522. pattern: ^[-._a-zA-Z0-9]+$
  9523. type: string
  9524. name:
  9525. description: The name of the Secret resource being referred to.
  9526. maxLength: 253
  9527. minLength: 1
  9528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9529. type: string
  9530. namespace:
  9531. description: |-
  9532. The namespace of the Secret resource being referred to.
  9533. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9534. maxLength: 63
  9535. minLength: 1
  9536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9537. type: string
  9538. type: object
  9539. tenantId:
  9540. description: The Azure tenantId of the managed identity used for authentication.
  9541. properties:
  9542. key:
  9543. description: |-
  9544. A key in the referenced Secret.
  9545. Some instances of this field may be defaulted, in others it may be required.
  9546. maxLength: 253
  9547. minLength: 1
  9548. pattern: ^[-._a-zA-Z0-9]+$
  9549. type: string
  9550. name:
  9551. description: The name of the Secret resource being referred to.
  9552. maxLength: 253
  9553. minLength: 1
  9554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9555. type: string
  9556. namespace:
  9557. description: |-
  9558. The namespace of the Secret resource being referred to.
  9559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9560. maxLength: 63
  9561. minLength: 1
  9562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9563. type: string
  9564. type: object
  9565. type: object
  9566. authType:
  9567. default: ServicePrincipal
  9568. description: |-
  9569. Auth type defines how to authenticate to the keyvault service.
  9570. Valid values are:
  9571. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  9572. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  9573. enum:
  9574. - ServicePrincipal
  9575. - ManagedIdentity
  9576. - WorkloadIdentity
  9577. type: string
  9578. environmentType:
  9579. default: PublicCloud
  9580. description: |-
  9581. EnvironmentType specifies the Azure cloud environment endpoints to use for
  9582. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  9583. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  9584. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  9585. enum:
  9586. - PublicCloud
  9587. - USGovernmentCloud
  9588. - ChinaCloud
  9589. - GermanCloud
  9590. type: string
  9591. identityId:
  9592. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  9593. type: string
  9594. serviceAccountRef:
  9595. description: |-
  9596. ServiceAccountRef specified the service account
  9597. that should be used when authenticating with WorkloadIdentity.
  9598. properties:
  9599. audiences:
  9600. description: |-
  9601. Audience specifies the `aud` claim for the service account token
  9602. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9603. then this audiences will be appended to the list
  9604. items:
  9605. type: string
  9606. type: array
  9607. name:
  9608. description: The name of the ServiceAccount resource being referred to.
  9609. maxLength: 253
  9610. minLength: 1
  9611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9612. type: string
  9613. namespace:
  9614. description: |-
  9615. Namespace of the resource being referred to.
  9616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9617. maxLength: 63
  9618. minLength: 1
  9619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9620. type: string
  9621. required:
  9622. - name
  9623. type: object
  9624. tenantId:
  9625. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9626. type: string
  9627. vaultUrl:
  9628. description: Vault Url from which the secrets to be fetched from.
  9629. type: string
  9630. required:
  9631. - vaultUrl
  9632. type: object
  9633. beyondtrust:
  9634. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  9635. properties:
  9636. auth:
  9637. description: Auth configures how the operator authenticates with Beyondtrust.
  9638. properties:
  9639. apiKey:
  9640. description: APIKey If not provided then ClientID/ClientSecret become required.
  9641. properties:
  9642. secretRef:
  9643. description: SecretRef references a key in a secret that will be used as value.
  9644. properties:
  9645. key:
  9646. description: |-
  9647. A key in the referenced Secret.
  9648. Some instances of this field may be defaulted, in others it may be required.
  9649. maxLength: 253
  9650. minLength: 1
  9651. pattern: ^[-._a-zA-Z0-9]+$
  9652. type: string
  9653. name:
  9654. description: The name of the Secret resource being referred to.
  9655. maxLength: 253
  9656. minLength: 1
  9657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9658. type: string
  9659. namespace:
  9660. description: |-
  9661. The namespace of the Secret resource being referred to.
  9662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9663. maxLength: 63
  9664. minLength: 1
  9665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9666. type: string
  9667. type: object
  9668. value:
  9669. description: Value can be specified directly to set a value without using a secret.
  9670. type: string
  9671. type: object
  9672. certificate:
  9673. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  9674. properties:
  9675. secretRef:
  9676. description: SecretRef references a key in a secret that will be used as value.
  9677. properties:
  9678. key:
  9679. description: |-
  9680. A key in the referenced Secret.
  9681. Some instances of this field may be defaulted, in others it may be required.
  9682. maxLength: 253
  9683. minLength: 1
  9684. pattern: ^[-._a-zA-Z0-9]+$
  9685. type: string
  9686. name:
  9687. description: The name of the Secret resource being referred to.
  9688. maxLength: 253
  9689. minLength: 1
  9690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9691. type: string
  9692. namespace:
  9693. description: |-
  9694. The namespace of the Secret resource being referred to.
  9695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9696. maxLength: 63
  9697. minLength: 1
  9698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9699. type: string
  9700. type: object
  9701. value:
  9702. description: Value can be specified directly to set a value without using a secret.
  9703. type: string
  9704. type: object
  9705. certificateKey:
  9706. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  9707. properties:
  9708. secretRef:
  9709. description: SecretRef references a key in a secret that will be used as value.
  9710. properties:
  9711. key:
  9712. description: |-
  9713. A key in the referenced Secret.
  9714. Some instances of this field may be defaulted, in others it may be required.
  9715. maxLength: 253
  9716. minLength: 1
  9717. pattern: ^[-._a-zA-Z0-9]+$
  9718. type: string
  9719. name:
  9720. description: The name of the Secret resource being referred to.
  9721. maxLength: 253
  9722. minLength: 1
  9723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9724. type: string
  9725. namespace:
  9726. description: |-
  9727. The namespace of the Secret resource being referred to.
  9728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9729. maxLength: 63
  9730. minLength: 1
  9731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9732. type: string
  9733. type: object
  9734. value:
  9735. description: Value can be specified directly to set a value without using a secret.
  9736. type: string
  9737. type: object
  9738. clientId:
  9739. description: ClientID is the API OAuth Client ID.
  9740. properties:
  9741. secretRef:
  9742. description: SecretRef references a key in a secret that will be used as value.
  9743. properties:
  9744. key:
  9745. description: |-
  9746. A key in the referenced Secret.
  9747. Some instances of this field may be defaulted, in others it may be required.
  9748. maxLength: 253
  9749. minLength: 1
  9750. pattern: ^[-._a-zA-Z0-9]+$
  9751. type: string
  9752. name:
  9753. description: The name of the Secret resource being referred to.
  9754. maxLength: 253
  9755. minLength: 1
  9756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9757. type: string
  9758. namespace:
  9759. description: |-
  9760. The namespace of the Secret resource being referred to.
  9761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9762. maxLength: 63
  9763. minLength: 1
  9764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9765. type: string
  9766. type: object
  9767. value:
  9768. description: Value can be specified directly to set a value without using a secret.
  9769. type: string
  9770. type: object
  9771. clientSecret:
  9772. description: ClientSecret is the API OAuth Client Secret.
  9773. properties:
  9774. secretRef:
  9775. description: SecretRef references a key in a secret that will be used as value.
  9776. properties:
  9777. key:
  9778. description: |-
  9779. A key in the referenced Secret.
  9780. Some instances of this field may be defaulted, in others it may be required.
  9781. maxLength: 253
  9782. minLength: 1
  9783. pattern: ^[-._a-zA-Z0-9]+$
  9784. type: string
  9785. name:
  9786. description: The name of the Secret resource being referred to.
  9787. maxLength: 253
  9788. minLength: 1
  9789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9790. type: string
  9791. namespace:
  9792. description: |-
  9793. The namespace of the Secret resource being referred to.
  9794. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9795. maxLength: 63
  9796. minLength: 1
  9797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9798. type: string
  9799. type: object
  9800. value:
  9801. description: Value can be specified directly to set a value without using a secret.
  9802. type: string
  9803. type: object
  9804. type: object
  9805. server:
  9806. description: Auth configures how API server works.
  9807. properties:
  9808. apiUrl:
  9809. type: string
  9810. apiVersion:
  9811. type: string
  9812. clientTimeOutSeconds:
  9813. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  9814. type: integer
  9815. decrypt:
  9816. default: true
  9817. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  9818. type: boolean
  9819. retrievalType:
  9820. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  9821. type: string
  9822. separator:
  9823. description: A character that separates the folder names.
  9824. type: string
  9825. verifyCA:
  9826. type: boolean
  9827. required:
  9828. - apiUrl
  9829. - verifyCA
  9830. type: object
  9831. required:
  9832. - auth
  9833. - server
  9834. type: object
  9835. bitwardensecretsmanager:
  9836. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  9837. properties:
  9838. apiURL:
  9839. type: string
  9840. auth:
  9841. description: |-
  9842. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  9843. Make sure that the token being used has permissions on the given secret.
  9844. properties:
  9845. secretRef:
  9846. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  9847. properties:
  9848. credentials:
  9849. description: AccessToken used for the bitwarden instance.
  9850. properties:
  9851. key:
  9852. description: |-
  9853. A key in the referenced Secret.
  9854. Some instances of this field may be defaulted, in others it may be required.
  9855. maxLength: 253
  9856. minLength: 1
  9857. pattern: ^[-._a-zA-Z0-9]+$
  9858. type: string
  9859. name:
  9860. description: The name of the Secret resource being referred to.
  9861. maxLength: 253
  9862. minLength: 1
  9863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9864. type: string
  9865. namespace:
  9866. description: |-
  9867. The namespace of the Secret resource being referred to.
  9868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9869. maxLength: 63
  9870. minLength: 1
  9871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9872. type: string
  9873. type: object
  9874. required:
  9875. - credentials
  9876. type: object
  9877. required:
  9878. - secretRef
  9879. type: object
  9880. bitwardenServerSDKURL:
  9881. type: string
  9882. caBundle:
  9883. description: |-
  9884. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  9885. can be performed.
  9886. type: string
  9887. caProvider:
  9888. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  9889. properties:
  9890. key:
  9891. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9892. maxLength: 253
  9893. minLength: 1
  9894. pattern: ^[-._a-zA-Z0-9]+$
  9895. type: string
  9896. name:
  9897. description: The name of the object located at the provider type.
  9898. maxLength: 253
  9899. minLength: 1
  9900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9901. type: string
  9902. namespace:
  9903. description: |-
  9904. The namespace the Provider type is in.
  9905. Can only be defined when used in a ClusterSecretStore.
  9906. maxLength: 63
  9907. minLength: 1
  9908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9909. type: string
  9910. type:
  9911. description: The type of provider to use such as "Secret", or "ConfigMap".
  9912. enum:
  9913. - Secret
  9914. - ConfigMap
  9915. type: string
  9916. required:
  9917. - name
  9918. - type
  9919. type: object
  9920. identityURL:
  9921. type: string
  9922. organizationID:
  9923. description: OrganizationID determines which organization this secret store manages.
  9924. type: string
  9925. projectID:
  9926. description: ProjectID determines which project this secret store manages.
  9927. type: string
  9928. required:
  9929. - auth
  9930. - organizationID
  9931. - projectID
  9932. type: object
  9933. chef:
  9934. description: Chef configures this store to sync secrets with chef server
  9935. properties:
  9936. auth:
  9937. description: Auth defines the information necessary to authenticate against chef Server
  9938. properties:
  9939. secretRef:
  9940. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  9941. properties:
  9942. privateKeySecretRef:
  9943. description: SecretKey is the Signing Key in PEM format, used for authentication.
  9944. properties:
  9945. key:
  9946. description: |-
  9947. A key in the referenced Secret.
  9948. Some instances of this field may be defaulted, in others it may be required.
  9949. maxLength: 253
  9950. minLength: 1
  9951. pattern: ^[-._a-zA-Z0-9]+$
  9952. type: string
  9953. name:
  9954. description: The name of the Secret resource being referred to.
  9955. maxLength: 253
  9956. minLength: 1
  9957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9958. type: string
  9959. namespace:
  9960. description: |-
  9961. The namespace of the Secret resource being referred to.
  9962. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9963. maxLength: 63
  9964. minLength: 1
  9965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9966. type: string
  9967. type: object
  9968. required:
  9969. - privateKeySecretRef
  9970. type: object
  9971. required:
  9972. - secretRef
  9973. type: object
  9974. serverUrl:
  9975. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  9976. type: string
  9977. username:
  9978. description: UserName should be the user ID on the chef server
  9979. type: string
  9980. required:
  9981. - auth
  9982. - serverUrl
  9983. - username
  9984. type: object
  9985. cloudrusm:
  9986. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  9987. properties:
  9988. auth:
  9989. description: CSMAuth contains a secretRef for credentials.
  9990. properties:
  9991. secretRef:
  9992. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  9993. properties:
  9994. accessKeyIDSecretRef:
  9995. description: The AccessKeyID is used for authentication
  9996. properties:
  9997. key:
  9998. description: |-
  9999. A key in the referenced Secret.
  10000. Some instances of this field may be defaulted, in others it may be required.
  10001. maxLength: 253
  10002. minLength: 1
  10003. pattern: ^[-._a-zA-Z0-9]+$
  10004. type: string
  10005. name:
  10006. description: The name of the Secret resource being referred to.
  10007. maxLength: 253
  10008. minLength: 1
  10009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10010. type: string
  10011. namespace:
  10012. description: |-
  10013. The namespace of the Secret resource being referred to.
  10014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10015. maxLength: 63
  10016. minLength: 1
  10017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10018. type: string
  10019. type: object
  10020. accessKeySecretSecretRef:
  10021. description: The AccessKeySecret is used for authentication
  10022. properties:
  10023. key:
  10024. description: |-
  10025. A key in the referenced Secret.
  10026. Some instances of this field may be defaulted, in others it may be required.
  10027. maxLength: 253
  10028. minLength: 1
  10029. pattern: ^[-._a-zA-Z0-9]+$
  10030. type: string
  10031. name:
  10032. description: The name of the Secret resource being referred to.
  10033. maxLength: 253
  10034. minLength: 1
  10035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10036. type: string
  10037. namespace:
  10038. description: |-
  10039. The namespace of the Secret resource being referred to.
  10040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10041. maxLength: 63
  10042. minLength: 1
  10043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10044. type: string
  10045. type: object
  10046. required:
  10047. - accessKeyIDSecretRef
  10048. - accessKeySecretSecretRef
  10049. type: object
  10050. type: object
  10051. projectID:
  10052. description: ProjectID is the project, which the secrets are stored in.
  10053. type: string
  10054. required:
  10055. - auth
  10056. type: object
  10057. conjur:
  10058. description: Conjur configures this store to sync secrets using conjur provider
  10059. properties:
  10060. auth:
  10061. description: Defines authentication settings for connecting to Conjur.
  10062. properties:
  10063. apikey:
  10064. description: Authenticates with Conjur using an API key.
  10065. properties:
  10066. account:
  10067. description: Account is the Conjur organization account name.
  10068. type: string
  10069. apiKeyRef:
  10070. description: |-
  10071. A reference to a specific 'key' containing the Conjur API key
  10072. within a Secret resource. In some instances, `key` is a required field.
  10073. properties:
  10074. key:
  10075. description: |-
  10076. A key in the referenced Secret.
  10077. Some instances of this field may be defaulted, in others it may be required.
  10078. maxLength: 253
  10079. minLength: 1
  10080. pattern: ^[-._a-zA-Z0-9]+$
  10081. type: string
  10082. name:
  10083. description: The name of the Secret resource being referred to.
  10084. maxLength: 253
  10085. minLength: 1
  10086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10087. type: string
  10088. namespace:
  10089. description: |-
  10090. The namespace of the Secret resource being referred to.
  10091. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10092. maxLength: 63
  10093. minLength: 1
  10094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10095. type: string
  10096. type: object
  10097. userRef:
  10098. description: |-
  10099. A reference to a specific 'key' containing the Conjur username
  10100. within a Secret resource. In some instances, `key` is a required field.
  10101. properties:
  10102. key:
  10103. description: |-
  10104. A key in the referenced Secret.
  10105. Some instances of this field may be defaulted, in others it may be required.
  10106. maxLength: 253
  10107. minLength: 1
  10108. pattern: ^[-._a-zA-Z0-9]+$
  10109. type: string
  10110. name:
  10111. description: The name of the Secret resource being referred to.
  10112. maxLength: 253
  10113. minLength: 1
  10114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10115. type: string
  10116. namespace:
  10117. description: |-
  10118. The namespace of the Secret resource being referred to.
  10119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10120. maxLength: 63
  10121. minLength: 1
  10122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10123. type: string
  10124. type: object
  10125. required:
  10126. - account
  10127. - apiKeyRef
  10128. - userRef
  10129. type: object
  10130. jwt:
  10131. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10132. properties:
  10133. account:
  10134. description: Account is the Conjur organization account name.
  10135. type: string
  10136. hostId:
  10137. description: |-
  10138. Optional HostID for JWT authentication. This may be used depending
  10139. on how the Conjur JWT authenticator policy is configured.
  10140. type: string
  10141. secretRef:
  10142. description: |-
  10143. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10144. authenticate with Conjur using the JWT authentication method.
  10145. properties:
  10146. key:
  10147. description: |-
  10148. A key in the referenced Secret.
  10149. Some instances of this field may be defaulted, in others it may be required.
  10150. maxLength: 253
  10151. minLength: 1
  10152. pattern: ^[-._a-zA-Z0-9]+$
  10153. type: string
  10154. name:
  10155. description: The name of the Secret resource being referred to.
  10156. maxLength: 253
  10157. minLength: 1
  10158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10159. type: string
  10160. namespace:
  10161. description: |-
  10162. The namespace of the Secret resource being referred to.
  10163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10164. maxLength: 63
  10165. minLength: 1
  10166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10167. type: string
  10168. type: object
  10169. serviceAccountRef:
  10170. description: |-
  10171. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10172. a token for with the `TokenRequest` API.
  10173. properties:
  10174. audiences:
  10175. description: |-
  10176. Audience specifies the `aud` claim for the service account token
  10177. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10178. then this audiences will be appended to the list
  10179. items:
  10180. type: string
  10181. type: array
  10182. name:
  10183. description: The name of the ServiceAccount resource being referred to.
  10184. maxLength: 253
  10185. minLength: 1
  10186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10187. type: string
  10188. namespace:
  10189. description: |-
  10190. Namespace of the resource being referred to.
  10191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10192. maxLength: 63
  10193. minLength: 1
  10194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10195. type: string
  10196. required:
  10197. - name
  10198. type: object
  10199. serviceID:
  10200. description: The conjur authn jwt webservice id
  10201. type: string
  10202. required:
  10203. - account
  10204. - serviceID
  10205. type: object
  10206. type: object
  10207. caBundle:
  10208. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10209. type: string
  10210. caProvider:
  10211. description: |-
  10212. Used to provide custom certificate authority (CA) certificates
  10213. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10214. that contains a PEM-encoded certificate.
  10215. properties:
  10216. key:
  10217. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10218. maxLength: 253
  10219. minLength: 1
  10220. pattern: ^[-._a-zA-Z0-9]+$
  10221. type: string
  10222. name:
  10223. description: The name of the object located at the provider type.
  10224. maxLength: 253
  10225. minLength: 1
  10226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10227. type: string
  10228. namespace:
  10229. description: |-
  10230. The namespace the Provider type is in.
  10231. Can only be defined when used in a ClusterSecretStore.
  10232. maxLength: 63
  10233. minLength: 1
  10234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10235. type: string
  10236. type:
  10237. description: The type of provider to use such as "Secret", or "ConfigMap".
  10238. enum:
  10239. - Secret
  10240. - ConfigMap
  10241. type: string
  10242. required:
  10243. - name
  10244. - type
  10245. type: object
  10246. url:
  10247. description: URL is the endpoint of the Conjur instance.
  10248. type: string
  10249. required:
  10250. - auth
  10251. - url
  10252. type: object
  10253. delinea:
  10254. description: |-
  10255. Delinea DevOps Secrets Vault
  10256. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10257. properties:
  10258. clientId:
  10259. description: ClientID is the non-secret part of the credential.
  10260. properties:
  10261. secretRef:
  10262. description: SecretRef references a key in a secret that will be used as value.
  10263. properties:
  10264. key:
  10265. description: |-
  10266. A key in the referenced Secret.
  10267. Some instances of this field may be defaulted, in others it may be required.
  10268. maxLength: 253
  10269. minLength: 1
  10270. pattern: ^[-._a-zA-Z0-9]+$
  10271. type: string
  10272. name:
  10273. description: The name of the Secret resource being referred to.
  10274. maxLength: 253
  10275. minLength: 1
  10276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10277. type: string
  10278. namespace:
  10279. description: |-
  10280. The namespace of the Secret resource being referred to.
  10281. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10282. maxLength: 63
  10283. minLength: 1
  10284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10285. type: string
  10286. type: object
  10287. value:
  10288. description: Value can be specified directly to set a value without using a secret.
  10289. type: string
  10290. type: object
  10291. clientSecret:
  10292. description: ClientSecret is the secret part of the credential.
  10293. properties:
  10294. secretRef:
  10295. description: SecretRef references a key in a secret that will be used as value.
  10296. properties:
  10297. key:
  10298. description: |-
  10299. A key in the referenced Secret.
  10300. Some instances of this field may be defaulted, in others it may be required.
  10301. maxLength: 253
  10302. minLength: 1
  10303. pattern: ^[-._a-zA-Z0-9]+$
  10304. type: string
  10305. name:
  10306. description: The name of the Secret resource being referred to.
  10307. maxLength: 253
  10308. minLength: 1
  10309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10310. type: string
  10311. namespace:
  10312. description: |-
  10313. The namespace of the Secret resource being referred to.
  10314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10315. maxLength: 63
  10316. minLength: 1
  10317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10318. type: string
  10319. type: object
  10320. value:
  10321. description: Value can be specified directly to set a value without using a secret.
  10322. type: string
  10323. type: object
  10324. tenant:
  10325. description: Tenant is the chosen hostname / site name.
  10326. type: string
  10327. tld:
  10328. description: |-
  10329. TLD is based on the server location that was chosen during provisioning.
  10330. If unset, defaults to "com".
  10331. type: string
  10332. urlTemplate:
  10333. description: |-
  10334. URLTemplate
  10335. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10336. type: string
  10337. required:
  10338. - clientId
  10339. - clientSecret
  10340. - tenant
  10341. type: object
  10342. device42:
  10343. description: Device42 configures this store to sync secrets using the Device42 provider
  10344. properties:
  10345. auth:
  10346. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10347. properties:
  10348. secretRef:
  10349. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10350. properties:
  10351. credentials:
  10352. description: Username / Password is used for authentication.
  10353. properties:
  10354. key:
  10355. description: |-
  10356. A key in the referenced Secret.
  10357. Some instances of this field may be defaulted, in others it may be required.
  10358. maxLength: 253
  10359. minLength: 1
  10360. pattern: ^[-._a-zA-Z0-9]+$
  10361. type: string
  10362. name:
  10363. description: The name of the Secret resource being referred to.
  10364. maxLength: 253
  10365. minLength: 1
  10366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10367. type: string
  10368. namespace:
  10369. description: |-
  10370. The namespace of the Secret resource being referred to.
  10371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10372. maxLength: 63
  10373. minLength: 1
  10374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10375. type: string
  10376. type: object
  10377. type: object
  10378. required:
  10379. - secretRef
  10380. type: object
  10381. host:
  10382. description: URL configures the Device42 instance URL.
  10383. type: string
  10384. required:
  10385. - auth
  10386. - host
  10387. type: object
  10388. doppler:
  10389. description: Doppler configures this store to sync secrets using the Doppler provider
  10390. properties:
  10391. auth:
  10392. description: Auth configures how the Operator authenticates with the Doppler API
  10393. properties:
  10394. secretRef:
  10395. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10396. properties:
  10397. dopplerToken:
  10398. description: |-
  10399. The DopplerToken is used for authentication.
  10400. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10401. The Key attribute defaults to dopplerToken if not specified.
  10402. properties:
  10403. key:
  10404. description: |-
  10405. A key in the referenced Secret.
  10406. Some instances of this field may be defaulted, in others it may be required.
  10407. maxLength: 253
  10408. minLength: 1
  10409. pattern: ^[-._a-zA-Z0-9]+$
  10410. type: string
  10411. name:
  10412. description: The name of the Secret resource being referred to.
  10413. maxLength: 253
  10414. minLength: 1
  10415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10416. type: string
  10417. namespace:
  10418. description: |-
  10419. The namespace of the Secret resource being referred to.
  10420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10421. maxLength: 63
  10422. minLength: 1
  10423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10424. type: string
  10425. type: object
  10426. required:
  10427. - dopplerToken
  10428. type: object
  10429. required:
  10430. - secretRef
  10431. type: object
  10432. config:
  10433. description: Doppler config (required if not using a Service Token)
  10434. type: string
  10435. format:
  10436. description: Format enables the downloading of secrets as a file (string)
  10437. enum:
  10438. - json
  10439. - dotnet-json
  10440. - env
  10441. - yaml
  10442. - docker
  10443. type: string
  10444. nameTransformer:
  10445. description: Environment variable compatible name transforms that change secret names to a different format
  10446. enum:
  10447. - upper-camel
  10448. - camel
  10449. - lower-snake
  10450. - tf-var
  10451. - dotnet-env
  10452. - lower-kebab
  10453. type: string
  10454. project:
  10455. description: Doppler project (required if not using a Service Token)
  10456. type: string
  10457. required:
  10458. - auth
  10459. type: object
  10460. fake:
  10461. description: Fake configures a store with static key/value pairs
  10462. properties:
  10463. data:
  10464. items:
  10465. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10466. properties:
  10467. key:
  10468. type: string
  10469. value:
  10470. type: string
  10471. version:
  10472. type: string
  10473. required:
  10474. - key
  10475. - value
  10476. type: object
  10477. type: array
  10478. required:
  10479. - data
  10480. type: object
  10481. fortanix:
  10482. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10483. properties:
  10484. apiKey:
  10485. description: APIKey is the API token to access SDKMS Applications.
  10486. properties:
  10487. secretRef:
  10488. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10489. properties:
  10490. key:
  10491. description: |-
  10492. A key in the referenced Secret.
  10493. Some instances of this field may be defaulted, in others it may be required.
  10494. maxLength: 253
  10495. minLength: 1
  10496. pattern: ^[-._a-zA-Z0-9]+$
  10497. type: string
  10498. name:
  10499. description: The name of the Secret resource being referred to.
  10500. maxLength: 253
  10501. minLength: 1
  10502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10503. type: string
  10504. namespace:
  10505. description: |-
  10506. The namespace of the Secret resource being referred to.
  10507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10508. maxLength: 63
  10509. minLength: 1
  10510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10511. type: string
  10512. type: object
  10513. type: object
  10514. apiUrl:
  10515. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10516. type: string
  10517. type: object
  10518. gcpsm:
  10519. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10520. properties:
  10521. auth:
  10522. description: Auth defines the information necessary to authenticate against GCP
  10523. properties:
  10524. secretRef:
  10525. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10526. properties:
  10527. secretAccessKeySecretRef:
  10528. description: The SecretAccessKey is used for authentication
  10529. properties:
  10530. key:
  10531. description: |-
  10532. A key in the referenced Secret.
  10533. Some instances of this field may be defaulted, in others it may be required.
  10534. maxLength: 253
  10535. minLength: 1
  10536. pattern: ^[-._a-zA-Z0-9]+$
  10537. type: string
  10538. name:
  10539. description: The name of the Secret resource being referred to.
  10540. maxLength: 253
  10541. minLength: 1
  10542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10543. type: string
  10544. namespace:
  10545. description: |-
  10546. The namespace of the Secret resource being referred to.
  10547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10548. maxLength: 63
  10549. minLength: 1
  10550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10551. type: string
  10552. type: object
  10553. type: object
  10554. workloadIdentity:
  10555. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10556. properties:
  10557. clusterLocation:
  10558. description: |-
  10559. ClusterLocation is the location of the cluster
  10560. If not specified, it fetches information from the metadata server
  10561. type: string
  10562. clusterName:
  10563. description: |-
  10564. ClusterName is the name of the cluster
  10565. If not specified, it fetches information from the metadata server
  10566. type: string
  10567. clusterProjectID:
  10568. description: |-
  10569. ClusterProjectID is the project ID of the cluster
  10570. If not specified, it fetches information from the metadata server
  10571. type: string
  10572. serviceAccountRef:
  10573. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  10574. properties:
  10575. audiences:
  10576. description: |-
  10577. Audience specifies the `aud` claim for the service account token
  10578. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10579. then this audiences will be appended to the list
  10580. items:
  10581. type: string
  10582. type: array
  10583. name:
  10584. description: The name of the ServiceAccount resource being referred to.
  10585. maxLength: 253
  10586. minLength: 1
  10587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10588. type: string
  10589. namespace:
  10590. description: |-
  10591. Namespace of the resource being referred to.
  10592. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10593. maxLength: 63
  10594. minLength: 1
  10595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10596. type: string
  10597. required:
  10598. - name
  10599. type: object
  10600. required:
  10601. - serviceAccountRef
  10602. type: object
  10603. type: object
  10604. location:
  10605. description: Location optionally defines a location for a secret
  10606. type: string
  10607. projectID:
  10608. description: ProjectID project where secret is located
  10609. type: string
  10610. type: object
  10611. github:
  10612. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  10613. properties:
  10614. appID:
  10615. description: appID specifies the Github APP that will be used to authenticate the client
  10616. format: int64
  10617. type: integer
  10618. auth:
  10619. description: auth configures how secret-manager authenticates with a Github instance.
  10620. properties:
  10621. privateKey:
  10622. description: |-
  10623. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10624. In some instances, `key` is a required field.
  10625. properties:
  10626. key:
  10627. description: |-
  10628. A key in the referenced Secret.
  10629. Some instances of this field may be defaulted, in others it may be required.
  10630. maxLength: 253
  10631. minLength: 1
  10632. pattern: ^[-._a-zA-Z0-9]+$
  10633. type: string
  10634. name:
  10635. description: The name of the Secret resource being referred to.
  10636. maxLength: 253
  10637. minLength: 1
  10638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10639. type: string
  10640. namespace:
  10641. description: |-
  10642. The namespace of the Secret resource being referred to.
  10643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10644. maxLength: 63
  10645. minLength: 1
  10646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10647. type: string
  10648. type: object
  10649. required:
  10650. - privateKey
  10651. type: object
  10652. environment:
  10653. description: environment will be used to fetch secrets from a particular environment within a github repository
  10654. type: string
  10655. installationID:
  10656. description: installationID specifies the Github APP installation that will be used to authenticate the client
  10657. format: int64
  10658. type: integer
  10659. organization:
  10660. description: organization will be used to fetch secrets from the Github organization
  10661. type: string
  10662. repository:
  10663. description: repository will be used to fetch secrets from the Github repository within an organization
  10664. type: string
  10665. uploadURL:
  10666. description: Upload URL for enterprise instances. Default to URL.
  10667. type: string
  10668. url:
  10669. default: https://github.com/
  10670. description: URL configures the Github instance URL. Defaults to https://github.com/.
  10671. type: string
  10672. required:
  10673. - appID
  10674. - auth
  10675. - installationID
  10676. - organization
  10677. type: object
  10678. gitlab:
  10679. description: GitLab configures this store to sync secrets using GitLab Variables provider
  10680. properties:
  10681. auth:
  10682. description: Auth configures how secret-manager authenticates with a GitLab instance.
  10683. properties:
  10684. SecretRef:
  10685. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  10686. properties:
  10687. accessToken:
  10688. description: AccessToken is used for authentication.
  10689. properties:
  10690. key:
  10691. description: |-
  10692. A key in the referenced Secret.
  10693. Some instances of this field may be defaulted, in others it may be required.
  10694. maxLength: 253
  10695. minLength: 1
  10696. pattern: ^[-._a-zA-Z0-9]+$
  10697. type: string
  10698. name:
  10699. description: The name of the Secret resource being referred to.
  10700. maxLength: 253
  10701. minLength: 1
  10702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10703. type: string
  10704. namespace:
  10705. description: |-
  10706. The namespace of the Secret resource being referred to.
  10707. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10708. maxLength: 63
  10709. minLength: 1
  10710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10711. type: string
  10712. type: object
  10713. type: object
  10714. required:
  10715. - SecretRef
  10716. type: object
  10717. caBundle:
  10718. description: |-
  10719. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10720. can be performed.
  10721. format: byte
  10722. type: string
  10723. caProvider:
  10724. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10725. properties:
  10726. key:
  10727. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10728. maxLength: 253
  10729. minLength: 1
  10730. pattern: ^[-._a-zA-Z0-9]+$
  10731. type: string
  10732. name:
  10733. description: The name of the object located at the provider type.
  10734. maxLength: 253
  10735. minLength: 1
  10736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10737. type: string
  10738. namespace:
  10739. description: |-
  10740. The namespace the Provider type is in.
  10741. Can only be defined when used in a ClusterSecretStore.
  10742. maxLength: 63
  10743. minLength: 1
  10744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10745. type: string
  10746. type:
  10747. description: The type of provider to use such as "Secret", or "ConfigMap".
  10748. enum:
  10749. - Secret
  10750. - ConfigMap
  10751. type: string
  10752. required:
  10753. - name
  10754. - type
  10755. type: object
  10756. environment:
  10757. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  10758. type: string
  10759. groupIDs:
  10760. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  10761. items:
  10762. type: string
  10763. type: array
  10764. inheritFromGroups:
  10765. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  10766. type: boolean
  10767. projectID:
  10768. description: ProjectID specifies a project where secrets are located.
  10769. type: string
  10770. url:
  10771. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  10772. type: string
  10773. required:
  10774. - auth
  10775. type: object
  10776. ibm:
  10777. description: IBM configures this store to sync secrets using IBM Cloud provider
  10778. properties:
  10779. auth:
  10780. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  10781. maxProperties: 1
  10782. minProperties: 1
  10783. properties:
  10784. containerAuth:
  10785. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  10786. properties:
  10787. iamEndpoint:
  10788. type: string
  10789. profile:
  10790. description: the IBM Trusted Profile
  10791. type: string
  10792. tokenLocation:
  10793. description: Location the token is mounted on the pod
  10794. type: string
  10795. required:
  10796. - profile
  10797. type: object
  10798. secretRef:
  10799. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  10800. properties:
  10801. secretApiKeySecretRef:
  10802. description: The SecretAccessKey is used for authentication
  10803. properties:
  10804. key:
  10805. description: |-
  10806. A key in the referenced Secret.
  10807. Some instances of this field may be defaulted, in others it may be required.
  10808. maxLength: 253
  10809. minLength: 1
  10810. pattern: ^[-._a-zA-Z0-9]+$
  10811. type: string
  10812. name:
  10813. description: The name of the Secret resource being referred to.
  10814. maxLength: 253
  10815. minLength: 1
  10816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10817. type: string
  10818. namespace:
  10819. description: |-
  10820. The namespace of the Secret resource being referred to.
  10821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10822. maxLength: 63
  10823. minLength: 1
  10824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10825. type: string
  10826. type: object
  10827. type: object
  10828. type: object
  10829. serviceUrl:
  10830. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  10831. type: string
  10832. required:
  10833. - auth
  10834. type: object
  10835. infisical:
  10836. description: Infisical configures this store to sync secrets using the Infisical provider
  10837. properties:
  10838. auth:
  10839. description: Auth configures how the Operator authenticates with the Infisical API
  10840. properties:
  10841. universalAuthCredentials:
  10842. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  10843. properties:
  10844. clientId:
  10845. description: |-
  10846. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10847. In some instances, `key` is a required field.
  10848. properties:
  10849. key:
  10850. description: |-
  10851. A key in the referenced Secret.
  10852. Some instances of this field may be defaulted, in others it may be required.
  10853. maxLength: 253
  10854. minLength: 1
  10855. pattern: ^[-._a-zA-Z0-9]+$
  10856. type: string
  10857. name:
  10858. description: The name of the Secret resource being referred to.
  10859. maxLength: 253
  10860. minLength: 1
  10861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10862. type: string
  10863. namespace:
  10864. description: |-
  10865. The namespace of the Secret resource being referred to.
  10866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10867. maxLength: 63
  10868. minLength: 1
  10869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10870. type: string
  10871. type: object
  10872. clientSecret:
  10873. description: |-
  10874. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10875. In some instances, `key` is a required field.
  10876. properties:
  10877. key:
  10878. description: |-
  10879. A key in the referenced Secret.
  10880. Some instances of this field may be defaulted, in others it may be required.
  10881. maxLength: 253
  10882. minLength: 1
  10883. pattern: ^[-._a-zA-Z0-9]+$
  10884. type: string
  10885. name:
  10886. description: The name of the Secret resource being referred to.
  10887. maxLength: 253
  10888. minLength: 1
  10889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10890. type: string
  10891. namespace:
  10892. description: |-
  10893. The namespace of the Secret resource being referred to.
  10894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10895. maxLength: 63
  10896. minLength: 1
  10897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10898. type: string
  10899. type: object
  10900. required:
  10901. - clientId
  10902. - clientSecret
  10903. type: object
  10904. type: object
  10905. hostAPI:
  10906. default: https://app.infisical.com/api
  10907. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  10908. type: string
  10909. secretsScope:
  10910. description: SecretsScope defines the scope of the secrets within the workspace
  10911. properties:
  10912. environmentSlug:
  10913. description: EnvironmentSlug is the required slug identifier for the environment.
  10914. type: string
  10915. expandSecretReferences:
  10916. default: true
  10917. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  10918. type: boolean
  10919. projectSlug:
  10920. description: ProjectSlug is the required slug identifier for the project.
  10921. type: string
  10922. recursive:
  10923. default: false
  10924. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  10925. type: boolean
  10926. secretsPath:
  10927. default: /
  10928. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  10929. type: string
  10930. required:
  10931. - environmentSlug
  10932. - projectSlug
  10933. type: object
  10934. required:
  10935. - auth
  10936. - secretsScope
  10937. type: object
  10938. keepersecurity:
  10939. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  10940. properties:
  10941. authRef:
  10942. description: |-
  10943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10944. In some instances, `key` is a required field.
  10945. properties:
  10946. key:
  10947. description: |-
  10948. A key in the referenced Secret.
  10949. Some instances of this field may be defaulted, in others it may be required.
  10950. maxLength: 253
  10951. minLength: 1
  10952. pattern: ^[-._a-zA-Z0-9]+$
  10953. type: string
  10954. name:
  10955. description: The name of the Secret resource being referred to.
  10956. maxLength: 253
  10957. minLength: 1
  10958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10959. type: string
  10960. namespace:
  10961. description: |-
  10962. The namespace of the Secret resource being referred to.
  10963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10964. maxLength: 63
  10965. minLength: 1
  10966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10967. type: string
  10968. type: object
  10969. folderID:
  10970. type: string
  10971. required:
  10972. - authRef
  10973. - folderID
  10974. type: object
  10975. kubernetes:
  10976. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  10977. properties:
  10978. auth:
  10979. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  10980. maxProperties: 1
  10981. minProperties: 1
  10982. properties:
  10983. cert:
  10984. description: has both clientCert and clientKey as secretKeySelector
  10985. properties:
  10986. clientCert:
  10987. description: |-
  10988. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10989. In some instances, `key` is a required field.
  10990. properties:
  10991. key:
  10992. description: |-
  10993. A key in the referenced Secret.
  10994. Some instances of this field may be defaulted, in others it may be required.
  10995. maxLength: 253
  10996. minLength: 1
  10997. pattern: ^[-._a-zA-Z0-9]+$
  10998. type: string
  10999. name:
  11000. description: The name of the Secret resource being referred to.
  11001. maxLength: 253
  11002. minLength: 1
  11003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11004. type: string
  11005. namespace:
  11006. description: |-
  11007. The namespace of the Secret resource being referred to.
  11008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11009. maxLength: 63
  11010. minLength: 1
  11011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11012. type: string
  11013. type: object
  11014. clientKey:
  11015. description: |-
  11016. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11017. In some instances, `key` is a required field.
  11018. properties:
  11019. key:
  11020. description: |-
  11021. A key in the referenced Secret.
  11022. Some instances of this field may be defaulted, in others it may be required.
  11023. maxLength: 253
  11024. minLength: 1
  11025. pattern: ^[-._a-zA-Z0-9]+$
  11026. type: string
  11027. name:
  11028. description: The name of the Secret resource being referred to.
  11029. maxLength: 253
  11030. minLength: 1
  11031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11032. type: string
  11033. namespace:
  11034. description: |-
  11035. The namespace of the Secret resource being referred to.
  11036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11037. maxLength: 63
  11038. minLength: 1
  11039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11040. type: string
  11041. type: object
  11042. type: object
  11043. serviceAccount:
  11044. description: points to a service account that should be used for authentication
  11045. properties:
  11046. audiences:
  11047. description: |-
  11048. Audience specifies the `aud` claim for the service account token
  11049. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11050. then this audiences will be appended to the list
  11051. items:
  11052. type: string
  11053. type: array
  11054. name:
  11055. description: The name of the ServiceAccount resource being referred to.
  11056. maxLength: 253
  11057. minLength: 1
  11058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11059. type: string
  11060. namespace:
  11061. description: |-
  11062. Namespace of the resource being referred to.
  11063. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11064. maxLength: 63
  11065. minLength: 1
  11066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11067. type: string
  11068. required:
  11069. - name
  11070. type: object
  11071. token:
  11072. description: use static token to authenticate with
  11073. properties:
  11074. bearerToken:
  11075. description: |-
  11076. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11077. In some instances, `key` is a required field.
  11078. properties:
  11079. key:
  11080. description: |-
  11081. A key in the referenced Secret.
  11082. Some instances of this field may be defaulted, in others it may be required.
  11083. maxLength: 253
  11084. minLength: 1
  11085. pattern: ^[-._a-zA-Z0-9]+$
  11086. type: string
  11087. name:
  11088. description: The name of the Secret resource being referred to.
  11089. maxLength: 253
  11090. minLength: 1
  11091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11092. type: string
  11093. namespace:
  11094. description: |-
  11095. The namespace of the Secret resource being referred to.
  11096. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11097. maxLength: 63
  11098. minLength: 1
  11099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11100. type: string
  11101. type: object
  11102. type: object
  11103. type: object
  11104. authRef:
  11105. description: A reference to a secret that contains the auth information.
  11106. properties:
  11107. key:
  11108. description: |-
  11109. A key in the referenced Secret.
  11110. Some instances of this field may be defaulted, in others it may be required.
  11111. maxLength: 253
  11112. minLength: 1
  11113. pattern: ^[-._a-zA-Z0-9]+$
  11114. type: string
  11115. name:
  11116. description: The name of the Secret resource being referred to.
  11117. maxLength: 253
  11118. minLength: 1
  11119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11120. type: string
  11121. namespace:
  11122. description: |-
  11123. The namespace of the Secret resource being referred to.
  11124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11125. maxLength: 63
  11126. minLength: 1
  11127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11128. type: string
  11129. type: object
  11130. remoteNamespace:
  11131. default: default
  11132. description: Remote namespace to fetch the secrets from
  11133. maxLength: 63
  11134. minLength: 1
  11135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11136. type: string
  11137. server:
  11138. description: configures the Kubernetes server Address.
  11139. properties:
  11140. caBundle:
  11141. description: CABundle is a base64-encoded CA certificate
  11142. format: byte
  11143. type: string
  11144. caProvider:
  11145. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11146. properties:
  11147. key:
  11148. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11149. maxLength: 253
  11150. minLength: 1
  11151. pattern: ^[-._a-zA-Z0-9]+$
  11152. type: string
  11153. name:
  11154. description: The name of the object located at the provider type.
  11155. maxLength: 253
  11156. minLength: 1
  11157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11158. type: string
  11159. namespace:
  11160. description: |-
  11161. The namespace the Provider type is in.
  11162. Can only be defined when used in a ClusterSecretStore.
  11163. maxLength: 63
  11164. minLength: 1
  11165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11166. type: string
  11167. type:
  11168. description: The type of provider to use such as "Secret", or "ConfigMap".
  11169. enum:
  11170. - Secret
  11171. - ConfigMap
  11172. type: string
  11173. required:
  11174. - name
  11175. - type
  11176. type: object
  11177. url:
  11178. default: kubernetes.default
  11179. description: configures the Kubernetes server Address.
  11180. type: string
  11181. type: object
  11182. type: object
  11183. onboardbase:
  11184. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11185. properties:
  11186. apiHost:
  11187. default: https://public.onboardbase.com/api/v1/
  11188. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11189. type: string
  11190. auth:
  11191. description: Auth configures how the Operator authenticates with the Onboardbase API
  11192. properties:
  11193. apiKeyRef:
  11194. description: |-
  11195. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11196. It is used to recognize and authorize access to a project and environment within onboardbase
  11197. properties:
  11198. key:
  11199. description: |-
  11200. A key in the referenced Secret.
  11201. Some instances of this field may be defaulted, in others it may be required.
  11202. maxLength: 253
  11203. minLength: 1
  11204. pattern: ^[-._a-zA-Z0-9]+$
  11205. type: string
  11206. name:
  11207. description: The name of the Secret resource being referred to.
  11208. maxLength: 253
  11209. minLength: 1
  11210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11211. type: string
  11212. namespace:
  11213. description: |-
  11214. The namespace of the Secret resource being referred to.
  11215. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11216. maxLength: 63
  11217. minLength: 1
  11218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11219. type: string
  11220. type: object
  11221. passcodeRef:
  11222. description: OnboardbasePasscode is the passcode attached to the API Key
  11223. properties:
  11224. key:
  11225. description: |-
  11226. A key in the referenced Secret.
  11227. Some instances of this field may be defaulted, in others it may be required.
  11228. maxLength: 253
  11229. minLength: 1
  11230. pattern: ^[-._a-zA-Z0-9]+$
  11231. type: string
  11232. name:
  11233. description: The name of the Secret resource being referred to.
  11234. maxLength: 253
  11235. minLength: 1
  11236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11237. type: string
  11238. namespace:
  11239. description: |-
  11240. The namespace of the Secret resource being referred to.
  11241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11242. maxLength: 63
  11243. minLength: 1
  11244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11245. type: string
  11246. type: object
  11247. required:
  11248. - apiKeyRef
  11249. - passcodeRef
  11250. type: object
  11251. environment:
  11252. default: development
  11253. description: Environment is the name of an environmnent within a project to pull the secrets from
  11254. type: string
  11255. project:
  11256. default: development
  11257. description: Project is an onboardbase project that the secrets should be pulled from
  11258. type: string
  11259. required:
  11260. - apiHost
  11261. - auth
  11262. - environment
  11263. - project
  11264. type: object
  11265. onepassword:
  11266. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11267. properties:
  11268. auth:
  11269. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11270. properties:
  11271. secretRef:
  11272. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11273. properties:
  11274. connectTokenSecretRef:
  11275. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11276. properties:
  11277. key:
  11278. description: |-
  11279. A key in the referenced Secret.
  11280. Some instances of this field may be defaulted, in others it may be required.
  11281. maxLength: 253
  11282. minLength: 1
  11283. pattern: ^[-._a-zA-Z0-9]+$
  11284. type: string
  11285. name:
  11286. description: The name of the Secret resource being referred to.
  11287. maxLength: 253
  11288. minLength: 1
  11289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11290. type: string
  11291. namespace:
  11292. description: |-
  11293. The namespace of the Secret resource being referred to.
  11294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11295. maxLength: 63
  11296. minLength: 1
  11297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11298. type: string
  11299. type: object
  11300. required:
  11301. - connectTokenSecretRef
  11302. type: object
  11303. required:
  11304. - secretRef
  11305. type: object
  11306. connectHost:
  11307. description: ConnectHost defines the OnePassword Connect Server to connect to
  11308. type: string
  11309. vaults:
  11310. additionalProperties:
  11311. type: integer
  11312. description: Vaults defines which OnePassword vaults to search in which order
  11313. type: object
  11314. required:
  11315. - auth
  11316. - connectHost
  11317. - vaults
  11318. type: object
  11319. oracle:
  11320. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11321. properties:
  11322. auth:
  11323. description: |-
  11324. Auth configures how secret-manager authenticates with the Oracle Vault.
  11325. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11326. properties:
  11327. secretRef:
  11328. description: SecretRef to pass through sensitive information.
  11329. properties:
  11330. fingerprint:
  11331. description: Fingerprint is the fingerprint of the API private key.
  11332. properties:
  11333. key:
  11334. description: |-
  11335. A key in the referenced Secret.
  11336. Some instances of this field may be defaulted, in others it may be required.
  11337. maxLength: 253
  11338. minLength: 1
  11339. pattern: ^[-._a-zA-Z0-9]+$
  11340. type: string
  11341. name:
  11342. description: The name of the Secret resource being referred to.
  11343. maxLength: 253
  11344. minLength: 1
  11345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11346. type: string
  11347. namespace:
  11348. description: |-
  11349. The namespace of the Secret resource being referred to.
  11350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11351. maxLength: 63
  11352. minLength: 1
  11353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11354. type: string
  11355. type: object
  11356. privatekey:
  11357. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11358. properties:
  11359. key:
  11360. description: |-
  11361. A key in the referenced Secret.
  11362. Some instances of this field may be defaulted, in others it may be required.
  11363. maxLength: 253
  11364. minLength: 1
  11365. pattern: ^[-._a-zA-Z0-9]+$
  11366. type: string
  11367. name:
  11368. description: The name of the Secret resource being referred to.
  11369. maxLength: 253
  11370. minLength: 1
  11371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11372. type: string
  11373. namespace:
  11374. description: |-
  11375. The namespace of the Secret resource being referred to.
  11376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11377. maxLength: 63
  11378. minLength: 1
  11379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11380. type: string
  11381. type: object
  11382. required:
  11383. - fingerprint
  11384. - privatekey
  11385. type: object
  11386. tenancy:
  11387. description: Tenancy is the tenancy OCID where user is located.
  11388. type: string
  11389. user:
  11390. description: User is an access OCID specific to the account.
  11391. type: string
  11392. required:
  11393. - secretRef
  11394. - tenancy
  11395. - user
  11396. type: object
  11397. compartment:
  11398. description: |-
  11399. Compartment is the vault compartment OCID.
  11400. Required for PushSecret
  11401. type: string
  11402. encryptionKey:
  11403. description: |-
  11404. EncryptionKey is the OCID of the encryption key within the vault.
  11405. Required for PushSecret
  11406. type: string
  11407. principalType:
  11408. description: |-
  11409. The type of principal to use for authentication. If left blank, the Auth struct will
  11410. determine the principal type. This optional field must be specified if using
  11411. workload identity.
  11412. enum:
  11413. - ""
  11414. - UserPrincipal
  11415. - InstancePrincipal
  11416. - Workload
  11417. type: string
  11418. region:
  11419. description: Region is the region where vault is located.
  11420. type: string
  11421. serviceAccountRef:
  11422. description: |-
  11423. ServiceAccountRef specified the service account
  11424. that should be used when authenticating with WorkloadIdentity.
  11425. properties:
  11426. audiences:
  11427. description: |-
  11428. Audience specifies the `aud` claim for the service account token
  11429. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11430. then this audiences will be appended to the list
  11431. items:
  11432. type: string
  11433. type: array
  11434. name:
  11435. description: The name of the ServiceAccount resource being referred to.
  11436. maxLength: 253
  11437. minLength: 1
  11438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11439. type: string
  11440. namespace:
  11441. description: |-
  11442. Namespace of the resource being referred to.
  11443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11444. maxLength: 63
  11445. minLength: 1
  11446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11447. type: string
  11448. required:
  11449. - name
  11450. type: object
  11451. vault:
  11452. description: Vault is the vault's OCID of the specific vault where secret is located.
  11453. type: string
  11454. required:
  11455. - region
  11456. - vault
  11457. type: object
  11458. passbolt:
  11459. description: PassboltProvider defines configuration for the Passbolt provider.
  11460. properties:
  11461. auth:
  11462. description: Auth defines the information necessary to authenticate against Passbolt Server
  11463. properties:
  11464. passwordSecretRef:
  11465. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11466. properties:
  11467. key:
  11468. description: |-
  11469. A key in the referenced Secret.
  11470. Some instances of this field may be defaulted, in others it may be required.
  11471. maxLength: 253
  11472. minLength: 1
  11473. pattern: ^[-._a-zA-Z0-9]+$
  11474. type: string
  11475. name:
  11476. description: The name of the Secret resource being referred to.
  11477. maxLength: 253
  11478. minLength: 1
  11479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11480. type: string
  11481. namespace:
  11482. description: |-
  11483. The namespace of the Secret resource being referred to.
  11484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11485. maxLength: 63
  11486. minLength: 1
  11487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11488. type: string
  11489. type: object
  11490. privateKeySecretRef:
  11491. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11492. properties:
  11493. key:
  11494. description: |-
  11495. A key in the referenced Secret.
  11496. Some instances of this field may be defaulted, in others it may be required.
  11497. maxLength: 253
  11498. minLength: 1
  11499. pattern: ^[-._a-zA-Z0-9]+$
  11500. type: string
  11501. name:
  11502. description: The name of the Secret resource being referred to.
  11503. maxLength: 253
  11504. minLength: 1
  11505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11506. type: string
  11507. namespace:
  11508. description: |-
  11509. The namespace of the Secret resource being referred to.
  11510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11511. maxLength: 63
  11512. minLength: 1
  11513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11514. type: string
  11515. type: object
  11516. required:
  11517. - passwordSecretRef
  11518. - privateKeySecretRef
  11519. type: object
  11520. host:
  11521. description: Host defines the Passbolt Server to connect to
  11522. type: string
  11523. required:
  11524. - auth
  11525. - host
  11526. type: object
  11527. passworddepot:
  11528. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11529. properties:
  11530. auth:
  11531. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11532. properties:
  11533. secretRef:
  11534. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11535. properties:
  11536. credentials:
  11537. description: Username / Password is used for authentication.
  11538. properties:
  11539. key:
  11540. description: |-
  11541. A key in the referenced Secret.
  11542. Some instances of this field may be defaulted, in others it may be required.
  11543. maxLength: 253
  11544. minLength: 1
  11545. pattern: ^[-._a-zA-Z0-9]+$
  11546. type: string
  11547. name:
  11548. description: The name of the Secret resource being referred to.
  11549. maxLength: 253
  11550. minLength: 1
  11551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11552. type: string
  11553. namespace:
  11554. description: |-
  11555. The namespace of the Secret resource being referred to.
  11556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11557. maxLength: 63
  11558. minLength: 1
  11559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11560. type: string
  11561. type: object
  11562. type: object
  11563. required:
  11564. - secretRef
  11565. type: object
  11566. database:
  11567. description: Database to use as source
  11568. type: string
  11569. host:
  11570. description: URL configures the Password Depot instance URL.
  11571. type: string
  11572. required:
  11573. - auth
  11574. - database
  11575. - host
  11576. type: object
  11577. previder:
  11578. description: Previder configures this store to sync secrets using the Previder provider
  11579. properties:
  11580. auth:
  11581. description: PreviderAuth contains a secretRef for credentials.
  11582. properties:
  11583. secretRef:
  11584. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  11585. properties:
  11586. accessToken:
  11587. description: The AccessToken is used for authentication
  11588. properties:
  11589. key:
  11590. description: |-
  11591. A key in the referenced Secret.
  11592. Some instances of this field may be defaulted, in others it may be required.
  11593. maxLength: 253
  11594. minLength: 1
  11595. pattern: ^[-._a-zA-Z0-9]+$
  11596. type: string
  11597. name:
  11598. description: The name of the Secret resource being referred to.
  11599. maxLength: 253
  11600. minLength: 1
  11601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11602. type: string
  11603. namespace:
  11604. description: |-
  11605. The namespace of the Secret resource being referred to.
  11606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11607. maxLength: 63
  11608. minLength: 1
  11609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11610. type: string
  11611. type: object
  11612. required:
  11613. - accessToken
  11614. type: object
  11615. type: object
  11616. baseUri:
  11617. type: string
  11618. required:
  11619. - auth
  11620. type: object
  11621. pulumi:
  11622. description: Pulumi configures this store to sync secrets using the Pulumi provider
  11623. properties:
  11624. accessToken:
  11625. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  11626. properties:
  11627. secretRef:
  11628. description: SecretRef is a reference to a secret containing the Pulumi API token.
  11629. properties:
  11630. key:
  11631. description: |-
  11632. A key in the referenced Secret.
  11633. Some instances of this field may be defaulted, in others it may be required.
  11634. maxLength: 253
  11635. minLength: 1
  11636. pattern: ^[-._a-zA-Z0-9]+$
  11637. type: string
  11638. name:
  11639. description: The name of the Secret resource being referred to.
  11640. maxLength: 253
  11641. minLength: 1
  11642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11643. type: string
  11644. namespace:
  11645. description: |-
  11646. The namespace of the Secret resource being referred to.
  11647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11648. maxLength: 63
  11649. minLength: 1
  11650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11651. type: string
  11652. type: object
  11653. type: object
  11654. apiUrl:
  11655. default: https://api.pulumi.com/api/esc
  11656. description: APIURL is the URL of the Pulumi API.
  11657. type: string
  11658. environment:
  11659. description: |-
  11660. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  11661. dynamically retrieved values from supported providers including all major clouds,
  11662. and other Pulumi ESC environments.
  11663. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  11664. type: string
  11665. organization:
  11666. description: |-
  11667. Organization are a space to collaborate on shared projects and stacks.
  11668. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  11669. type: string
  11670. project:
  11671. description: Project is the name of the Pulumi ESC project the environment belongs to.
  11672. type: string
  11673. required:
  11674. - accessToken
  11675. - environment
  11676. - organization
  11677. - project
  11678. type: object
  11679. scaleway:
  11680. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  11681. properties:
  11682. accessKey:
  11683. description: AccessKey is the non-secret part of the api key.
  11684. properties:
  11685. secretRef:
  11686. description: SecretRef references a key in a secret that will be used as value.
  11687. properties:
  11688. key:
  11689. description: |-
  11690. A key in the referenced Secret.
  11691. Some instances of this field may be defaulted, in others it may be required.
  11692. maxLength: 253
  11693. minLength: 1
  11694. pattern: ^[-._a-zA-Z0-9]+$
  11695. type: string
  11696. name:
  11697. description: The name of the Secret resource being referred to.
  11698. maxLength: 253
  11699. minLength: 1
  11700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11701. type: string
  11702. namespace:
  11703. description: |-
  11704. The namespace of the Secret resource being referred to.
  11705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11706. maxLength: 63
  11707. minLength: 1
  11708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11709. type: string
  11710. type: object
  11711. value:
  11712. description: Value can be specified directly to set a value without using a secret.
  11713. type: string
  11714. type: object
  11715. apiUrl:
  11716. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  11717. type: string
  11718. projectId:
  11719. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  11720. type: string
  11721. region:
  11722. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  11723. type: string
  11724. secretKey:
  11725. description: SecretKey is the non-secret part of the api key.
  11726. properties:
  11727. secretRef:
  11728. description: SecretRef references a key in a secret that will be used as value.
  11729. properties:
  11730. key:
  11731. description: |-
  11732. A key in the referenced Secret.
  11733. Some instances of this field may be defaulted, in others it may be required.
  11734. maxLength: 253
  11735. minLength: 1
  11736. pattern: ^[-._a-zA-Z0-9]+$
  11737. type: string
  11738. name:
  11739. description: The name of the Secret resource being referred to.
  11740. maxLength: 253
  11741. minLength: 1
  11742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11743. type: string
  11744. namespace:
  11745. description: |-
  11746. The namespace of the Secret resource being referred to.
  11747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11748. maxLength: 63
  11749. minLength: 1
  11750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11751. type: string
  11752. type: object
  11753. value:
  11754. description: Value can be specified directly to set a value without using a secret.
  11755. type: string
  11756. type: object
  11757. required:
  11758. - accessKey
  11759. - projectId
  11760. - region
  11761. - secretKey
  11762. type: object
  11763. secretserver:
  11764. description: |-
  11765. SecretServer configures this store to sync secrets using SecretServer provider
  11766. https://docs.delinea.com/online-help/secret-server/start.htm
  11767. properties:
  11768. password:
  11769. description: Password is the secret server account password.
  11770. properties:
  11771. secretRef:
  11772. description: SecretRef references a key in a secret that will be used as value.
  11773. properties:
  11774. key:
  11775. description: |-
  11776. A key in the referenced Secret.
  11777. Some instances of this field may be defaulted, in others it may be required.
  11778. maxLength: 253
  11779. minLength: 1
  11780. pattern: ^[-._a-zA-Z0-9]+$
  11781. type: string
  11782. name:
  11783. description: The name of the Secret resource being referred to.
  11784. maxLength: 253
  11785. minLength: 1
  11786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11787. type: string
  11788. namespace:
  11789. description: |-
  11790. The namespace of the Secret resource being referred to.
  11791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11792. maxLength: 63
  11793. minLength: 1
  11794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11795. type: string
  11796. type: object
  11797. value:
  11798. description: Value can be specified directly to set a value without using a secret.
  11799. type: string
  11800. type: object
  11801. serverURL:
  11802. description: |-
  11803. ServerURL
  11804. URL to your secret server installation
  11805. type: string
  11806. username:
  11807. description: Username is the secret server account username.
  11808. properties:
  11809. secretRef:
  11810. description: SecretRef references a key in a secret that will be used as value.
  11811. properties:
  11812. key:
  11813. description: |-
  11814. A key in the referenced Secret.
  11815. Some instances of this field may be defaulted, in others it may be required.
  11816. maxLength: 253
  11817. minLength: 1
  11818. pattern: ^[-._a-zA-Z0-9]+$
  11819. type: string
  11820. name:
  11821. description: The name of the Secret resource being referred to.
  11822. maxLength: 253
  11823. minLength: 1
  11824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11825. type: string
  11826. namespace:
  11827. description: |-
  11828. The namespace of the Secret resource being referred to.
  11829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11830. maxLength: 63
  11831. minLength: 1
  11832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11833. type: string
  11834. type: object
  11835. value:
  11836. description: Value can be specified directly to set a value without using a secret.
  11837. type: string
  11838. type: object
  11839. required:
  11840. - password
  11841. - serverURL
  11842. - username
  11843. type: object
  11844. senhasegura:
  11845. description: Senhasegura configures this store to sync secrets using senhasegura provider
  11846. properties:
  11847. auth:
  11848. description: Auth defines parameters to authenticate in senhasegura
  11849. properties:
  11850. clientId:
  11851. type: string
  11852. clientSecretSecretRef:
  11853. description: |-
  11854. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11855. In some instances, `key` is a required field.
  11856. properties:
  11857. key:
  11858. description: |-
  11859. A key in the referenced Secret.
  11860. Some instances of this field may be defaulted, in others it may be required.
  11861. maxLength: 253
  11862. minLength: 1
  11863. pattern: ^[-._a-zA-Z0-9]+$
  11864. type: string
  11865. name:
  11866. description: The name of the Secret resource being referred to.
  11867. maxLength: 253
  11868. minLength: 1
  11869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11870. type: string
  11871. namespace:
  11872. description: |-
  11873. The namespace of the Secret resource being referred to.
  11874. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11875. maxLength: 63
  11876. minLength: 1
  11877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11878. type: string
  11879. type: object
  11880. required:
  11881. - clientId
  11882. - clientSecretSecretRef
  11883. type: object
  11884. ignoreSslCertificate:
  11885. default: false
  11886. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  11887. type: boolean
  11888. module:
  11889. description: Module defines which senhasegura module should be used to get secrets
  11890. type: string
  11891. url:
  11892. description: URL of senhasegura
  11893. type: string
  11894. required:
  11895. - auth
  11896. - module
  11897. - url
  11898. type: object
  11899. vault:
  11900. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  11901. properties:
  11902. auth:
  11903. description: Auth configures how secret-manager authenticates with the Vault server.
  11904. properties:
  11905. appRole:
  11906. description: |-
  11907. AppRole authenticates with Vault using the App Role auth mechanism,
  11908. with the role and secret stored in a Kubernetes Secret resource.
  11909. properties:
  11910. path:
  11911. default: approle
  11912. description: |-
  11913. Path where the App Role authentication backend is mounted
  11914. in Vault, e.g: "approle"
  11915. type: string
  11916. roleId:
  11917. description: |-
  11918. RoleID configured in the App Role authentication backend when setting
  11919. up the authentication backend in Vault.
  11920. type: string
  11921. roleRef:
  11922. description: |-
  11923. Reference to a key in a Secret that contains the App Role ID used
  11924. to authenticate with Vault.
  11925. The `key` field must be specified and denotes which entry within the Secret
  11926. resource is used as the app role id.
  11927. properties:
  11928. key:
  11929. description: |-
  11930. A key in the referenced Secret.
  11931. Some instances of this field may be defaulted, in others it may be required.
  11932. maxLength: 253
  11933. minLength: 1
  11934. pattern: ^[-._a-zA-Z0-9]+$
  11935. type: string
  11936. name:
  11937. description: The name of the Secret resource being referred to.
  11938. maxLength: 253
  11939. minLength: 1
  11940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11941. type: string
  11942. namespace:
  11943. description: |-
  11944. The namespace of the Secret resource being referred to.
  11945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11946. maxLength: 63
  11947. minLength: 1
  11948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11949. type: string
  11950. type: object
  11951. secretRef:
  11952. description: |-
  11953. Reference to a key in a Secret that contains the App Role secret used
  11954. to authenticate with Vault.
  11955. The `key` field must be specified and denotes which entry within the Secret
  11956. resource is used as the app role secret.
  11957. properties:
  11958. key:
  11959. description: |-
  11960. A key in the referenced Secret.
  11961. Some instances of this field may be defaulted, in others it may be required.
  11962. maxLength: 253
  11963. minLength: 1
  11964. pattern: ^[-._a-zA-Z0-9]+$
  11965. type: string
  11966. name:
  11967. description: The name of the Secret resource being referred to.
  11968. maxLength: 253
  11969. minLength: 1
  11970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11971. type: string
  11972. namespace:
  11973. description: |-
  11974. The namespace of the Secret resource being referred to.
  11975. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11976. maxLength: 63
  11977. minLength: 1
  11978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11979. type: string
  11980. type: object
  11981. required:
  11982. - path
  11983. - secretRef
  11984. type: object
  11985. cert:
  11986. description: |-
  11987. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  11988. Cert authentication method
  11989. properties:
  11990. clientCert:
  11991. description: |-
  11992. ClientCert is a certificate to authenticate using the Cert Vault
  11993. authentication method
  11994. properties:
  11995. key:
  11996. description: |-
  11997. A key in the referenced Secret.
  11998. Some instances of this field may be defaulted, in others it may be required.
  11999. maxLength: 253
  12000. minLength: 1
  12001. pattern: ^[-._a-zA-Z0-9]+$
  12002. type: string
  12003. name:
  12004. description: The name of the Secret resource being referred to.
  12005. maxLength: 253
  12006. minLength: 1
  12007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12008. type: string
  12009. namespace:
  12010. description: |-
  12011. The namespace of the Secret resource being referred to.
  12012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12013. maxLength: 63
  12014. minLength: 1
  12015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12016. type: string
  12017. type: object
  12018. secretRef:
  12019. description: |-
  12020. SecretRef to a key in a Secret resource containing client private key to
  12021. authenticate with Vault using the Cert authentication method
  12022. properties:
  12023. key:
  12024. description: |-
  12025. A key in the referenced Secret.
  12026. Some instances of this field may be defaulted, in others it may be required.
  12027. maxLength: 253
  12028. minLength: 1
  12029. pattern: ^[-._a-zA-Z0-9]+$
  12030. type: string
  12031. name:
  12032. description: The name of the Secret resource being referred to.
  12033. maxLength: 253
  12034. minLength: 1
  12035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12036. type: string
  12037. namespace:
  12038. description: |-
  12039. The namespace of the Secret resource being referred to.
  12040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12041. maxLength: 63
  12042. minLength: 1
  12043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12044. type: string
  12045. type: object
  12046. type: object
  12047. iam:
  12048. description: |-
  12049. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12050. AWS IAM authentication method
  12051. properties:
  12052. externalID:
  12053. description: AWS External ID set on assumed IAM roles
  12054. type: string
  12055. jwt:
  12056. description: Specify a service account with IRSA enabled
  12057. properties:
  12058. serviceAccountRef:
  12059. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12060. properties:
  12061. audiences:
  12062. description: |-
  12063. Audience specifies the `aud` claim for the service account token
  12064. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12065. then this audiences will be appended to the list
  12066. items:
  12067. type: string
  12068. type: array
  12069. name:
  12070. description: The name of the ServiceAccount resource being referred to.
  12071. maxLength: 253
  12072. minLength: 1
  12073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12074. type: string
  12075. namespace:
  12076. description: |-
  12077. Namespace of the resource being referred to.
  12078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12079. maxLength: 63
  12080. minLength: 1
  12081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12082. type: string
  12083. required:
  12084. - name
  12085. type: object
  12086. type: object
  12087. path:
  12088. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12089. type: string
  12090. region:
  12091. description: AWS region
  12092. type: string
  12093. role:
  12094. description: This is the AWS role to be assumed before talking to vault
  12095. type: string
  12096. secretRef:
  12097. description: Specify credentials in a Secret object
  12098. properties:
  12099. accessKeyIDSecretRef:
  12100. description: The AccessKeyID is used for authentication
  12101. properties:
  12102. key:
  12103. description: |-
  12104. A key in the referenced Secret.
  12105. Some instances of this field may be defaulted, in others it may be required.
  12106. maxLength: 253
  12107. minLength: 1
  12108. pattern: ^[-._a-zA-Z0-9]+$
  12109. type: string
  12110. name:
  12111. description: The name of the Secret resource being referred to.
  12112. maxLength: 253
  12113. minLength: 1
  12114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12115. type: string
  12116. namespace:
  12117. description: |-
  12118. The namespace of the Secret resource being referred to.
  12119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12120. maxLength: 63
  12121. minLength: 1
  12122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12123. type: string
  12124. type: object
  12125. secretAccessKeySecretRef:
  12126. description: The SecretAccessKey is used for authentication
  12127. properties:
  12128. key:
  12129. description: |-
  12130. A key in the referenced Secret.
  12131. Some instances of this field may be defaulted, in others it may be required.
  12132. maxLength: 253
  12133. minLength: 1
  12134. pattern: ^[-._a-zA-Z0-9]+$
  12135. type: string
  12136. name:
  12137. description: The name of the Secret resource being referred to.
  12138. maxLength: 253
  12139. minLength: 1
  12140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12141. type: string
  12142. namespace:
  12143. description: |-
  12144. The namespace of the Secret resource being referred to.
  12145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12146. maxLength: 63
  12147. minLength: 1
  12148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12149. type: string
  12150. type: object
  12151. sessionTokenSecretRef:
  12152. description: |-
  12153. The SessionToken used for authentication
  12154. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12155. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12156. properties:
  12157. key:
  12158. description: |-
  12159. A key in the referenced Secret.
  12160. Some instances of this field may be defaulted, in others it may be required.
  12161. maxLength: 253
  12162. minLength: 1
  12163. pattern: ^[-._a-zA-Z0-9]+$
  12164. type: string
  12165. name:
  12166. description: The name of the Secret resource being referred to.
  12167. maxLength: 253
  12168. minLength: 1
  12169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12170. type: string
  12171. namespace:
  12172. description: |-
  12173. The namespace of the Secret resource being referred to.
  12174. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12175. maxLength: 63
  12176. minLength: 1
  12177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12178. type: string
  12179. type: object
  12180. type: object
  12181. vaultAwsIamServerID:
  12182. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12183. type: string
  12184. vaultRole:
  12185. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12186. type: string
  12187. required:
  12188. - vaultRole
  12189. type: object
  12190. jwt:
  12191. description: |-
  12192. Jwt authenticates with Vault by passing role and JWT token using the
  12193. JWT/OIDC authentication method
  12194. properties:
  12195. kubernetesServiceAccountToken:
  12196. description: |-
  12197. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12198. a token for with the `TokenRequest` API.
  12199. properties:
  12200. audiences:
  12201. description: |-
  12202. Optional audiences field that will be used to request a temporary Kubernetes service
  12203. account token for the service account referenced by `serviceAccountRef`.
  12204. Defaults to a single audience `vault` it not specified.
  12205. Deprecated: use serviceAccountRef.Audiences instead
  12206. items:
  12207. type: string
  12208. type: array
  12209. expirationSeconds:
  12210. description: |-
  12211. Optional expiration time in seconds that will be used to request a temporary
  12212. Kubernetes service account token for the service account referenced by
  12213. `serviceAccountRef`.
  12214. Deprecated: this will be removed in the future.
  12215. Defaults to 10 minutes.
  12216. format: int64
  12217. type: integer
  12218. serviceAccountRef:
  12219. description: Service account field containing the name of a kubernetes ServiceAccount.
  12220. properties:
  12221. audiences:
  12222. description: |-
  12223. Audience specifies the `aud` claim for the service account token
  12224. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12225. then this audiences will be appended to the list
  12226. items:
  12227. type: string
  12228. type: array
  12229. name:
  12230. description: The name of the ServiceAccount resource being referred to.
  12231. maxLength: 253
  12232. minLength: 1
  12233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12234. type: string
  12235. namespace:
  12236. description: |-
  12237. Namespace of the resource being referred to.
  12238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12239. maxLength: 63
  12240. minLength: 1
  12241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12242. type: string
  12243. required:
  12244. - name
  12245. type: object
  12246. required:
  12247. - serviceAccountRef
  12248. type: object
  12249. path:
  12250. default: jwt
  12251. description: |-
  12252. Path where the JWT authentication backend is mounted
  12253. in Vault, e.g: "jwt"
  12254. type: string
  12255. role:
  12256. description: |-
  12257. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12258. authentication method
  12259. type: string
  12260. secretRef:
  12261. description: |-
  12262. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12263. authenticate with Vault using the JWT/OIDC authentication method.
  12264. properties:
  12265. key:
  12266. description: |-
  12267. A key in the referenced Secret.
  12268. Some instances of this field may be defaulted, in others it may be required.
  12269. maxLength: 253
  12270. minLength: 1
  12271. pattern: ^[-._a-zA-Z0-9]+$
  12272. type: string
  12273. name:
  12274. description: The name of the Secret resource being referred to.
  12275. maxLength: 253
  12276. minLength: 1
  12277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12278. type: string
  12279. namespace:
  12280. description: |-
  12281. The namespace of the Secret resource being referred to.
  12282. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12283. maxLength: 63
  12284. minLength: 1
  12285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12286. type: string
  12287. type: object
  12288. required:
  12289. - path
  12290. type: object
  12291. kubernetes:
  12292. description: |-
  12293. Kubernetes authenticates with Vault by passing the ServiceAccount
  12294. token stored in the named Secret resource to the Vault server.
  12295. properties:
  12296. mountPath:
  12297. default: kubernetes
  12298. description: |-
  12299. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12300. "kubernetes"
  12301. type: string
  12302. role:
  12303. description: |-
  12304. A required field containing the Vault Role to assume. A Role binds a
  12305. Kubernetes ServiceAccount with a set of Vault policies.
  12306. type: string
  12307. secretRef:
  12308. description: |-
  12309. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12310. for authenticating with Vault. If a name is specified without a key,
  12311. `token` is the default. If one is not specified, the one bound to
  12312. the controller will be used.
  12313. properties:
  12314. key:
  12315. description: |-
  12316. A key in the referenced Secret.
  12317. Some instances of this field may be defaulted, in others it may be required.
  12318. maxLength: 253
  12319. minLength: 1
  12320. pattern: ^[-._a-zA-Z0-9]+$
  12321. type: string
  12322. name:
  12323. description: The name of the Secret resource being referred to.
  12324. maxLength: 253
  12325. minLength: 1
  12326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12327. type: string
  12328. namespace:
  12329. description: |-
  12330. The namespace of the Secret resource being referred to.
  12331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12332. maxLength: 63
  12333. minLength: 1
  12334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12335. type: string
  12336. type: object
  12337. serviceAccountRef:
  12338. description: |-
  12339. Optional service account field containing the name of a kubernetes ServiceAccount.
  12340. If the service account is specified, the service account secret token JWT will be used
  12341. for authenticating with Vault. If the service account selector is not supplied,
  12342. the secretRef will be used instead.
  12343. properties:
  12344. audiences:
  12345. description: |-
  12346. Audience specifies the `aud` claim for the service account token
  12347. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12348. then this audiences will be appended to the list
  12349. items:
  12350. type: string
  12351. type: array
  12352. name:
  12353. description: The name of the ServiceAccount resource being referred to.
  12354. maxLength: 253
  12355. minLength: 1
  12356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12357. type: string
  12358. namespace:
  12359. description: |-
  12360. Namespace of the resource being referred to.
  12361. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12362. maxLength: 63
  12363. minLength: 1
  12364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12365. type: string
  12366. required:
  12367. - name
  12368. type: object
  12369. required:
  12370. - mountPath
  12371. - role
  12372. type: object
  12373. ldap:
  12374. description: |-
  12375. Ldap authenticates with Vault by passing username/password pair using
  12376. the LDAP authentication method
  12377. properties:
  12378. path:
  12379. default: ldap
  12380. description: |-
  12381. Path where the LDAP authentication backend is mounted
  12382. in Vault, e.g: "ldap"
  12383. type: string
  12384. secretRef:
  12385. description: |-
  12386. SecretRef to a key in a Secret resource containing password for the LDAP
  12387. user used to authenticate with Vault using the LDAP authentication
  12388. method
  12389. properties:
  12390. key:
  12391. description: |-
  12392. A key in the referenced Secret.
  12393. Some instances of this field may be defaulted, in others it may be required.
  12394. maxLength: 253
  12395. minLength: 1
  12396. pattern: ^[-._a-zA-Z0-9]+$
  12397. type: string
  12398. name:
  12399. description: The name of the Secret resource being referred to.
  12400. maxLength: 253
  12401. minLength: 1
  12402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12403. type: string
  12404. namespace:
  12405. description: |-
  12406. The namespace of the Secret resource being referred to.
  12407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12408. maxLength: 63
  12409. minLength: 1
  12410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12411. type: string
  12412. type: object
  12413. username:
  12414. description: |-
  12415. Username is an LDAP username used to authenticate using the LDAP Vault
  12416. authentication method
  12417. type: string
  12418. required:
  12419. - path
  12420. - username
  12421. type: object
  12422. namespace:
  12423. description: |-
  12424. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12425. Namespaces is a set of features within Vault Enterprise that allows
  12426. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12427. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12428. This will default to Vault.Namespace field if set, or empty otherwise
  12429. type: string
  12430. tokenSecretRef:
  12431. description: TokenSecretRef authenticates with Vault by presenting a token.
  12432. properties:
  12433. key:
  12434. description: |-
  12435. A key in the referenced Secret.
  12436. Some instances of this field may be defaulted, in others it may be required.
  12437. maxLength: 253
  12438. minLength: 1
  12439. pattern: ^[-._a-zA-Z0-9]+$
  12440. type: string
  12441. name:
  12442. description: The name of the Secret resource being referred to.
  12443. maxLength: 253
  12444. minLength: 1
  12445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12446. type: string
  12447. namespace:
  12448. description: |-
  12449. The namespace of the Secret resource being referred to.
  12450. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12451. maxLength: 63
  12452. minLength: 1
  12453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12454. type: string
  12455. type: object
  12456. userPass:
  12457. description: UserPass authenticates with Vault by passing username/password pair
  12458. properties:
  12459. path:
  12460. default: userpass
  12461. description: |-
  12462. Path where the UserPassword authentication backend is mounted
  12463. in Vault, e.g: "userpass"
  12464. type: string
  12465. secretRef:
  12466. description: |-
  12467. SecretRef to a key in a Secret resource containing password for the
  12468. user used to authenticate with Vault using the UserPass authentication
  12469. method
  12470. properties:
  12471. key:
  12472. description: |-
  12473. A key in the referenced Secret.
  12474. Some instances of this field may be defaulted, in others it may be required.
  12475. maxLength: 253
  12476. minLength: 1
  12477. pattern: ^[-._a-zA-Z0-9]+$
  12478. type: string
  12479. name:
  12480. description: The name of the Secret resource being referred to.
  12481. maxLength: 253
  12482. minLength: 1
  12483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12484. type: string
  12485. namespace:
  12486. description: |-
  12487. The namespace of the Secret resource being referred to.
  12488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12489. maxLength: 63
  12490. minLength: 1
  12491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12492. type: string
  12493. type: object
  12494. username:
  12495. description: |-
  12496. Username is a username used to authenticate using the UserPass Vault
  12497. authentication method
  12498. type: string
  12499. required:
  12500. - path
  12501. - username
  12502. type: object
  12503. type: object
  12504. caBundle:
  12505. description: |-
  12506. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12507. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12508. plain HTTP protocol connection. If not set the system root certificates
  12509. are used to validate the TLS connection.
  12510. format: byte
  12511. type: string
  12512. caProvider:
  12513. description: The provider for the CA bundle to use to validate Vault server certificate.
  12514. properties:
  12515. key:
  12516. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12517. maxLength: 253
  12518. minLength: 1
  12519. pattern: ^[-._a-zA-Z0-9]+$
  12520. type: string
  12521. name:
  12522. description: The name of the object located at the provider type.
  12523. maxLength: 253
  12524. minLength: 1
  12525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12526. type: string
  12527. namespace:
  12528. description: |-
  12529. The namespace the Provider type is in.
  12530. Can only be defined when used in a ClusterSecretStore.
  12531. maxLength: 63
  12532. minLength: 1
  12533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12534. type: string
  12535. type:
  12536. description: The type of provider to use such as "Secret", or "ConfigMap".
  12537. enum:
  12538. - Secret
  12539. - ConfigMap
  12540. type: string
  12541. required:
  12542. - name
  12543. - type
  12544. type: object
  12545. forwardInconsistent:
  12546. description: |-
  12547. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12548. leader instead of simply retrying within a loop. This can increase performance if
  12549. the option is enabled serverside.
  12550. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12551. type: boolean
  12552. headers:
  12553. additionalProperties:
  12554. type: string
  12555. description: Headers to be added in Vault request
  12556. type: object
  12557. namespace:
  12558. description: |-
  12559. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12560. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12561. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12562. type: string
  12563. path:
  12564. description: |-
  12565. Path is the mount path of the Vault KV backend endpoint, e.g:
  12566. "secret". The v2 KV secret engine version specific "/data" path suffix
  12567. for fetching secrets from Vault is optional and will be appended
  12568. if not present in specified path.
  12569. type: string
  12570. readYourWrites:
  12571. description: |-
  12572. ReadYourWrites ensures isolated read-after-write semantics by
  12573. providing discovered cluster replication states in each request.
  12574. More information about eventual consistency in Vault can be found here
  12575. https://www.vaultproject.io/docs/enterprise/consistency
  12576. type: boolean
  12577. server:
  12578. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  12579. type: string
  12580. tls:
  12581. description: |-
  12582. The configuration used for client side related TLS communication, when the Vault server
  12583. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  12584. This parameter is ignored for plain HTTP protocol connection.
  12585. It's worth noting this configuration is different from the "TLS certificates auth method",
  12586. which is available under the `auth.cert` section.
  12587. properties:
  12588. certSecretRef:
  12589. description: |-
  12590. CertSecretRef is a certificate added to the transport layer
  12591. when communicating with the Vault server.
  12592. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  12593. properties:
  12594. key:
  12595. description: |-
  12596. A key in the referenced Secret.
  12597. Some instances of this field may be defaulted, in others it may be required.
  12598. maxLength: 253
  12599. minLength: 1
  12600. pattern: ^[-._a-zA-Z0-9]+$
  12601. type: string
  12602. name:
  12603. description: The name of the Secret resource being referred to.
  12604. maxLength: 253
  12605. minLength: 1
  12606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12607. type: string
  12608. namespace:
  12609. description: |-
  12610. The namespace of the Secret resource being referred to.
  12611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12612. maxLength: 63
  12613. minLength: 1
  12614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12615. type: string
  12616. type: object
  12617. keySecretRef:
  12618. description: |-
  12619. KeySecretRef to a key in a Secret resource containing client private key
  12620. added to the transport layer when communicating with the Vault server.
  12621. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  12622. properties:
  12623. key:
  12624. description: |-
  12625. A key in the referenced Secret.
  12626. Some instances of this field may be defaulted, in others it may be required.
  12627. maxLength: 253
  12628. minLength: 1
  12629. pattern: ^[-._a-zA-Z0-9]+$
  12630. type: string
  12631. name:
  12632. description: The name of the Secret resource being referred to.
  12633. maxLength: 253
  12634. minLength: 1
  12635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12636. type: string
  12637. namespace:
  12638. description: |-
  12639. The namespace of the Secret resource being referred to.
  12640. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12641. maxLength: 63
  12642. minLength: 1
  12643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12644. type: string
  12645. type: object
  12646. type: object
  12647. version:
  12648. default: v2
  12649. description: |-
  12650. Version is the Vault KV secret engine version. This can be either "v1" or
  12651. "v2". Version defaults to "v2".
  12652. enum:
  12653. - v1
  12654. - v2
  12655. type: string
  12656. required:
  12657. - server
  12658. type: object
  12659. webhook:
  12660. description: Webhook configures this store to sync secrets using a generic templated webhook
  12661. properties:
  12662. auth:
  12663. description: Auth specifies a authorization protocol. Only one protocol may be set.
  12664. maxProperties: 1
  12665. minProperties: 1
  12666. properties:
  12667. ntlm:
  12668. description: NTLMProtocol configures the store to use NTLM for auth
  12669. properties:
  12670. passwordSecret:
  12671. description: |-
  12672. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12673. In some instances, `key` is a required field.
  12674. properties:
  12675. key:
  12676. description: |-
  12677. A key in the referenced Secret.
  12678. Some instances of this field may be defaulted, in others it may be required.
  12679. maxLength: 253
  12680. minLength: 1
  12681. pattern: ^[-._a-zA-Z0-9]+$
  12682. type: string
  12683. name:
  12684. description: The name of the Secret resource being referred to.
  12685. maxLength: 253
  12686. minLength: 1
  12687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12688. type: string
  12689. namespace:
  12690. description: |-
  12691. The namespace of the Secret resource being referred to.
  12692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12693. maxLength: 63
  12694. minLength: 1
  12695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12696. type: string
  12697. type: object
  12698. usernameSecret:
  12699. description: |-
  12700. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12701. In some instances, `key` is a required field.
  12702. properties:
  12703. key:
  12704. description: |-
  12705. A key in the referenced Secret.
  12706. Some instances of this field may be defaulted, in others it may be required.
  12707. maxLength: 253
  12708. minLength: 1
  12709. pattern: ^[-._a-zA-Z0-9]+$
  12710. type: string
  12711. name:
  12712. description: The name of the Secret resource being referred to.
  12713. maxLength: 253
  12714. minLength: 1
  12715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12716. type: string
  12717. namespace:
  12718. description: |-
  12719. The namespace of the Secret resource being referred to.
  12720. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12721. maxLength: 63
  12722. minLength: 1
  12723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12724. type: string
  12725. type: object
  12726. required:
  12727. - passwordSecret
  12728. - usernameSecret
  12729. type: object
  12730. type: object
  12731. body:
  12732. description: Body
  12733. type: string
  12734. caBundle:
  12735. description: |-
  12736. PEM encoded CA bundle used to validate webhook server certificate. Only used
  12737. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12738. plain HTTP protocol connection. If not set the system root certificates
  12739. are used to validate the TLS connection.
  12740. format: byte
  12741. type: string
  12742. caProvider:
  12743. description: The provider for the CA bundle to use to validate webhook server certificate.
  12744. properties:
  12745. key:
  12746. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12747. maxLength: 253
  12748. minLength: 1
  12749. pattern: ^[-._a-zA-Z0-9]+$
  12750. type: string
  12751. name:
  12752. description: The name of the object located at the provider type.
  12753. maxLength: 253
  12754. minLength: 1
  12755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12756. type: string
  12757. namespace:
  12758. description: The namespace the Provider type is in.
  12759. maxLength: 63
  12760. minLength: 1
  12761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12762. type: string
  12763. type:
  12764. description: The type of provider to use such as "Secret", or "ConfigMap".
  12765. enum:
  12766. - Secret
  12767. - ConfigMap
  12768. type: string
  12769. required:
  12770. - name
  12771. - type
  12772. type: object
  12773. headers:
  12774. additionalProperties:
  12775. type: string
  12776. description: Headers
  12777. type: object
  12778. method:
  12779. description: Webhook Method
  12780. type: string
  12781. result:
  12782. description: Result formatting
  12783. properties:
  12784. jsonPath:
  12785. description: Json path of return value
  12786. type: string
  12787. type: object
  12788. secrets:
  12789. description: |-
  12790. Secrets to fill in templates
  12791. These secrets will be passed to the templating function as key value pairs under the given name
  12792. items:
  12793. description: WebhookSecret defines a secret to be used in webhook templates.
  12794. properties:
  12795. name:
  12796. description: Name of this secret in templates
  12797. type: string
  12798. secretRef:
  12799. description: Secret ref to fill in credentials
  12800. properties:
  12801. key:
  12802. description: |-
  12803. A key in the referenced Secret.
  12804. Some instances of this field may be defaulted, in others it may be required.
  12805. maxLength: 253
  12806. minLength: 1
  12807. pattern: ^[-._a-zA-Z0-9]+$
  12808. type: string
  12809. name:
  12810. description: The name of the Secret resource being referred to.
  12811. maxLength: 253
  12812. minLength: 1
  12813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12814. type: string
  12815. namespace:
  12816. description: |-
  12817. The namespace of the Secret resource being referred to.
  12818. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12819. maxLength: 63
  12820. minLength: 1
  12821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12822. type: string
  12823. type: object
  12824. required:
  12825. - name
  12826. - secretRef
  12827. type: object
  12828. type: array
  12829. timeout:
  12830. description: Timeout
  12831. type: string
  12832. url:
  12833. description: Webhook url to call
  12834. type: string
  12835. required:
  12836. - result
  12837. - url
  12838. type: object
  12839. yandexcertificatemanager:
  12840. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  12841. properties:
  12842. apiEndpoint:
  12843. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  12844. type: string
  12845. auth:
  12846. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  12847. properties:
  12848. authorizedKeySecretRef:
  12849. description: The authorized key used for authentication
  12850. properties:
  12851. key:
  12852. description: |-
  12853. A key in the referenced Secret.
  12854. Some instances of this field may be defaulted, in others it may be required.
  12855. maxLength: 253
  12856. minLength: 1
  12857. pattern: ^[-._a-zA-Z0-9]+$
  12858. type: string
  12859. name:
  12860. description: The name of the Secret resource being referred to.
  12861. maxLength: 253
  12862. minLength: 1
  12863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12864. type: string
  12865. namespace:
  12866. description: |-
  12867. The namespace of the Secret resource being referred to.
  12868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12869. maxLength: 63
  12870. minLength: 1
  12871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12872. type: string
  12873. type: object
  12874. type: object
  12875. caProvider:
  12876. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  12877. properties:
  12878. certSecretRef:
  12879. description: |-
  12880. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12881. In some instances, `key` is a required field.
  12882. properties:
  12883. key:
  12884. description: |-
  12885. A key in the referenced Secret.
  12886. Some instances of this field may be defaulted, in others it may be required.
  12887. maxLength: 253
  12888. minLength: 1
  12889. pattern: ^[-._a-zA-Z0-9]+$
  12890. type: string
  12891. name:
  12892. description: The name of the Secret resource being referred to.
  12893. maxLength: 253
  12894. minLength: 1
  12895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12896. type: string
  12897. namespace:
  12898. description: |-
  12899. The namespace of the Secret resource being referred to.
  12900. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12901. maxLength: 63
  12902. minLength: 1
  12903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12904. type: string
  12905. type: object
  12906. type: object
  12907. required:
  12908. - auth
  12909. type: object
  12910. yandexlockbox:
  12911. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  12912. properties:
  12913. apiEndpoint:
  12914. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  12915. type: string
  12916. auth:
  12917. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  12918. properties:
  12919. authorizedKeySecretRef:
  12920. description: The authorized key used for authentication
  12921. properties:
  12922. key:
  12923. description: |-
  12924. A key in the referenced Secret.
  12925. Some instances of this field may be defaulted, in others it may be required.
  12926. maxLength: 253
  12927. minLength: 1
  12928. pattern: ^[-._a-zA-Z0-9]+$
  12929. type: string
  12930. name:
  12931. description: The name of the Secret resource being referred to.
  12932. maxLength: 253
  12933. minLength: 1
  12934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12935. type: string
  12936. namespace:
  12937. description: |-
  12938. The namespace of the Secret resource being referred to.
  12939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12940. maxLength: 63
  12941. minLength: 1
  12942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12943. type: string
  12944. type: object
  12945. type: object
  12946. caProvider:
  12947. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  12948. properties:
  12949. certSecretRef:
  12950. description: |-
  12951. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12952. In some instances, `key` is a required field.
  12953. properties:
  12954. key:
  12955. description: |-
  12956. A key in the referenced Secret.
  12957. Some instances of this field may be defaulted, in others it may be required.
  12958. maxLength: 253
  12959. minLength: 1
  12960. pattern: ^[-._a-zA-Z0-9]+$
  12961. type: string
  12962. name:
  12963. description: The name of the Secret resource being referred to.
  12964. maxLength: 253
  12965. minLength: 1
  12966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12967. type: string
  12968. namespace:
  12969. description: |-
  12970. The namespace of the Secret resource being referred to.
  12971. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12972. maxLength: 63
  12973. minLength: 1
  12974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12975. type: string
  12976. type: object
  12977. type: object
  12978. required:
  12979. - auth
  12980. type: object
  12981. type: object
  12982. refreshInterval:
  12983. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  12984. type: integer
  12985. retrySettings:
  12986. description: Used to configure HTTP retries on failures.
  12987. properties:
  12988. maxRetries:
  12989. description: MaxRetries is the maximum number of retry attempts.
  12990. format: int32
  12991. type: integer
  12992. retryInterval:
  12993. description: RetryInterval is the interval between retry attempts.
  12994. type: string
  12995. type: object
  12996. required:
  12997. - provider
  12998. type: object
  12999. status:
  13000. description: SecretStoreStatus defines the observed state of the SecretStore.
  13001. properties:
  13002. capabilities:
  13003. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13004. type: string
  13005. conditions:
  13006. items:
  13007. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13008. properties:
  13009. lastTransitionTime:
  13010. format: date-time
  13011. type: string
  13012. message:
  13013. type: string
  13014. reason:
  13015. type: string
  13016. status:
  13017. type: string
  13018. type:
  13019. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13020. type: string
  13021. required:
  13022. - status
  13023. - type
  13024. type: object
  13025. type: array
  13026. type: object
  13027. type: object
  13028. served: false
  13029. storage: false
  13030. subresources:
  13031. status: {}
  13032. ---
  13033. apiVersion: apiextensions.k8s.io/v1
  13034. kind: CustomResourceDefinition
  13035. metadata:
  13036. annotations:
  13037. controller-gen.kubebuilder.io/version: v0.19.0
  13038. labels:
  13039. external-secrets.io/component: controller
  13040. name: externalsecrets.external-secrets.io
  13041. spec:
  13042. group: external-secrets.io
  13043. names:
  13044. categories:
  13045. - external-secrets
  13046. kind: ExternalSecret
  13047. listKind: ExternalSecretList
  13048. plural: externalsecrets
  13049. shortNames:
  13050. - es
  13051. singular: externalsecret
  13052. scope: Namespaced
  13053. versions:
  13054. - additionalPrinterColumns:
  13055. - jsonPath: .spec.secretStoreRef.kind
  13056. name: StoreType
  13057. type: string
  13058. - jsonPath: .spec.secretStoreRef.name
  13059. name: Store
  13060. type: string
  13061. - jsonPath: .spec.refreshInterval
  13062. name: Refresh Interval
  13063. type: string
  13064. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13065. name: Status
  13066. type: string
  13067. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13068. name: Ready
  13069. type: string
  13070. - jsonPath: .status.refreshTime
  13071. name: Last Sync
  13072. type: date
  13073. name: v1
  13074. schema:
  13075. openAPIV3Schema:
  13076. description: |-
  13077. ExternalSecret is the Schema for the external-secrets API.
  13078. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13079. properties:
  13080. apiVersion:
  13081. description: |-
  13082. APIVersion defines the versioned schema of this representation of an object.
  13083. Servers should convert recognized schemas to the latest internal value, and
  13084. may reject unrecognized values.
  13085. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13086. type: string
  13087. kind:
  13088. description: |-
  13089. Kind is a string value representing the REST resource this object represents.
  13090. Servers may infer this from the endpoint the client submits requests to.
  13091. Cannot be updated.
  13092. In CamelCase.
  13093. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13094. type: string
  13095. metadata:
  13096. type: object
  13097. spec:
  13098. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13099. properties:
  13100. data:
  13101. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13102. items:
  13103. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13104. properties:
  13105. remoteRef:
  13106. description: |-
  13107. RemoteRef points to the remote secret and defines
  13108. which secret (version/property/..) to fetch.
  13109. properties:
  13110. conversionStrategy:
  13111. default: Default
  13112. description: Used to define a conversion Strategy
  13113. enum:
  13114. - Default
  13115. - Unicode
  13116. type: string
  13117. decodingStrategy:
  13118. default: None
  13119. description: Used to define a decoding Strategy
  13120. enum:
  13121. - Auto
  13122. - Base64
  13123. - Base64URL
  13124. - None
  13125. type: string
  13126. key:
  13127. description: Key is the key used in the Provider, mandatory
  13128. type: string
  13129. metadataPolicy:
  13130. default: None
  13131. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13132. enum:
  13133. - None
  13134. - Fetch
  13135. type: string
  13136. nullBytePolicy:
  13137. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13138. enum:
  13139. - Ignore
  13140. - Fail
  13141. type: string
  13142. property:
  13143. description: Used to select a specific property of the Provider value (if a map), if supported
  13144. type: string
  13145. version:
  13146. description: Used to select a specific version of the Provider value, if supported
  13147. type: string
  13148. required:
  13149. - key
  13150. type: object
  13151. secretKey:
  13152. description: The key in the Kubernetes Secret to store the value.
  13153. maxLength: 253
  13154. minLength: 1
  13155. pattern: ^[-._a-zA-Z0-9]+$
  13156. type: string
  13157. sourceRef:
  13158. description: |-
  13159. SourceRef allows you to override the source
  13160. from which the value will be pulled.
  13161. maxProperties: 1
  13162. minProperties: 1
  13163. properties:
  13164. generatorRef:
  13165. description: |-
  13166. GeneratorRef points to a generator custom resource.
  13167. Deprecated: The generatorRef is not implemented in .data[].
  13168. this will be removed with v1.
  13169. properties:
  13170. apiVersion:
  13171. default: generators.external-secrets.io/v1alpha1
  13172. description: Specify the apiVersion of the generator resource
  13173. type: string
  13174. kind:
  13175. description: Specify the Kind of the generator resource
  13176. enum:
  13177. - ACRAccessToken
  13178. - BeyondtrustWorkloadCredentialsDynamicSecret
  13179. - ClusterGenerator
  13180. - CloudsmithAccessToken
  13181. - ECRAuthorizationToken
  13182. - Fake
  13183. - GCRAccessToken
  13184. - GithubAccessToken
  13185. - GitlabDeployToken
  13186. - QuayAccessToken
  13187. - Password
  13188. - SSHKey
  13189. - STSSessionToken
  13190. - UUID
  13191. - VaultDynamicSecret
  13192. - Webhook
  13193. - Grafana
  13194. - MFA
  13195. type: string
  13196. name:
  13197. description: Specify the name of the generator resource
  13198. maxLength: 253
  13199. minLength: 1
  13200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13201. type: string
  13202. required:
  13203. - kind
  13204. - name
  13205. type: object
  13206. storeRef:
  13207. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13208. properties:
  13209. kind:
  13210. description: |-
  13211. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13212. Defaults to `SecretStore`
  13213. enum:
  13214. - SecretStore
  13215. - ClusterSecretStore
  13216. type: string
  13217. name:
  13218. description: Name of the SecretStore resource
  13219. maxLength: 253
  13220. minLength: 1
  13221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13222. type: string
  13223. type: object
  13224. type: object
  13225. required:
  13226. - remoteRef
  13227. - secretKey
  13228. type: object
  13229. type: array
  13230. dataFrom:
  13231. description: |-
  13232. DataFrom is used to fetch all properties from a specific Provider data
  13233. If multiple entries are specified, the Secret keys are merged in the specified order
  13234. items:
  13235. description: |-
  13236. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13237. when using DataFrom to fetch multiple values from a Provider.
  13238. properties:
  13239. extract:
  13240. description: |-
  13241. Used to extract multiple key/value pairs from one secret
  13242. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13243. properties:
  13244. conversionStrategy:
  13245. default: Default
  13246. description: Used to define a conversion Strategy
  13247. enum:
  13248. - Default
  13249. - Unicode
  13250. type: string
  13251. decodingStrategy:
  13252. default: None
  13253. description: Used to define a decoding Strategy
  13254. enum:
  13255. - Auto
  13256. - Base64
  13257. - Base64URL
  13258. - None
  13259. type: string
  13260. key:
  13261. description: Key is the key used in the Provider, mandatory
  13262. type: string
  13263. metadataPolicy:
  13264. default: None
  13265. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13266. enum:
  13267. - None
  13268. - Fetch
  13269. type: string
  13270. nullBytePolicy:
  13271. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13272. enum:
  13273. - Ignore
  13274. - Fail
  13275. type: string
  13276. property:
  13277. description: Used to select a specific property of the Provider value (if a map), if supported
  13278. type: string
  13279. version:
  13280. description: Used to select a specific version of the Provider value, if supported
  13281. type: string
  13282. required:
  13283. - key
  13284. type: object
  13285. find:
  13286. description: |-
  13287. Used to find secrets based on tags or regular expressions
  13288. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13289. properties:
  13290. conversionStrategy:
  13291. default: Default
  13292. description: Used to define a conversion Strategy
  13293. enum:
  13294. - Default
  13295. - Unicode
  13296. type: string
  13297. decodingStrategy:
  13298. default: None
  13299. description: Used to define a decoding Strategy
  13300. enum:
  13301. - Auto
  13302. - Base64
  13303. - Base64URL
  13304. - None
  13305. type: string
  13306. name:
  13307. description: Finds secrets based on the name.
  13308. properties:
  13309. regexp:
  13310. description: Finds secrets base
  13311. type: string
  13312. type: object
  13313. nullBytePolicy:
  13314. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13315. enum:
  13316. - Ignore
  13317. - Fail
  13318. type: string
  13319. path:
  13320. description: A root path to start the find operations.
  13321. type: string
  13322. tags:
  13323. additionalProperties:
  13324. type: string
  13325. description: Find secrets based on tags.
  13326. type: object
  13327. type: object
  13328. rewrite:
  13329. description: |-
  13330. Used to rewrite secret Keys after getting them from the secret Provider
  13331. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13332. items:
  13333. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13334. maxProperties: 1
  13335. minProperties: 1
  13336. properties:
  13337. merge:
  13338. description: |-
  13339. Used to merge key/values in one single Secret
  13340. The resulting key will contain all values from the specified secrets
  13341. properties:
  13342. conflictPolicy:
  13343. default: Error
  13344. description: Used to define the policy to use in conflict resolution.
  13345. enum:
  13346. - Ignore
  13347. - Error
  13348. type: string
  13349. into:
  13350. default: ""
  13351. description: |-
  13352. Used to define the target key of the merge operation.
  13353. Required if strategy is JSON. Ignored otherwise.
  13354. type: string
  13355. priority:
  13356. description: Used to define key priority in conflict resolution.
  13357. items:
  13358. type: string
  13359. type: array
  13360. priorityPolicy:
  13361. default: Strict
  13362. description: Used to define the policy when a key in the priority list does not exist in the input.
  13363. enum:
  13364. - IgnoreNotFound
  13365. - Strict
  13366. type: string
  13367. strategy:
  13368. default: Extract
  13369. description: Used to define the strategy to use in the merge operation.
  13370. enum:
  13371. - Extract
  13372. - JSON
  13373. type: string
  13374. type: object
  13375. regexp:
  13376. description: |-
  13377. Used to rewrite with regular expressions.
  13378. The resulting key will be the output of a regexp.ReplaceAll operation.
  13379. properties:
  13380. source:
  13381. description: Used to define the regular expression of a re.Compiler.
  13382. type: string
  13383. target:
  13384. description: Used to define the target pattern of a ReplaceAll operation.
  13385. type: string
  13386. required:
  13387. - source
  13388. - target
  13389. type: object
  13390. transform:
  13391. description: |-
  13392. Used to apply string transformation on the secrets.
  13393. The resulting key will be the output of the template applied by the operation.
  13394. properties:
  13395. template:
  13396. description: |-
  13397. Used to define the template to apply on the secret name.
  13398. `.value ` will specify the secret name in the template.
  13399. type: string
  13400. required:
  13401. - template
  13402. type: object
  13403. type: object
  13404. type: array
  13405. sourceRef:
  13406. description: |-
  13407. SourceRef points to a store or generator
  13408. which contains secret values ready to use.
  13409. Use this in combination with Extract or Find pull values out of
  13410. a specific SecretStore.
  13411. When sourceRef points to a generator Extract or Find is not supported.
  13412. The generator returns a static map of values
  13413. maxProperties: 1
  13414. minProperties: 1
  13415. properties:
  13416. generatorRef:
  13417. description: GeneratorRef points to a generator custom resource.
  13418. properties:
  13419. apiVersion:
  13420. default: generators.external-secrets.io/v1alpha1
  13421. description: Specify the apiVersion of the generator resource
  13422. type: string
  13423. kind:
  13424. description: Specify the Kind of the generator resource
  13425. enum:
  13426. - ACRAccessToken
  13427. - BeyondtrustWorkloadCredentialsDynamicSecret
  13428. - ClusterGenerator
  13429. - CloudsmithAccessToken
  13430. - ECRAuthorizationToken
  13431. - Fake
  13432. - GCRAccessToken
  13433. - GithubAccessToken
  13434. - GitlabDeployToken
  13435. - QuayAccessToken
  13436. - Password
  13437. - SSHKey
  13438. - STSSessionToken
  13439. - UUID
  13440. - VaultDynamicSecret
  13441. - Webhook
  13442. - Grafana
  13443. - MFA
  13444. type: string
  13445. name:
  13446. description: Specify the name of the generator resource
  13447. maxLength: 253
  13448. minLength: 1
  13449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13450. type: string
  13451. required:
  13452. - kind
  13453. - name
  13454. type: object
  13455. storeRef:
  13456. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13457. properties:
  13458. kind:
  13459. description: |-
  13460. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13461. Defaults to `SecretStore`
  13462. enum:
  13463. - SecretStore
  13464. - ClusterSecretStore
  13465. type: string
  13466. name:
  13467. description: Name of the SecretStore resource
  13468. maxLength: 253
  13469. minLength: 1
  13470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13471. type: string
  13472. type: object
  13473. type: object
  13474. type: object
  13475. type: array
  13476. refreshInterval:
  13477. default: 1h0m0s
  13478. description: |-
  13479. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13480. specified as Golang Duration strings.
  13481. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13482. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13483. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13484. type: string
  13485. refreshPolicy:
  13486. description: |-
  13487. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13488. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13489. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13490. No periodic updates occur if refreshInterval is 0.
  13491. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13492. enum:
  13493. - CreatedOnce
  13494. - Periodic
  13495. - OnChange
  13496. type: string
  13497. secretStoreRef:
  13498. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13499. properties:
  13500. kind:
  13501. description: |-
  13502. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13503. Defaults to `SecretStore`
  13504. enum:
  13505. - SecretStore
  13506. - ClusterSecretStore
  13507. type: string
  13508. name:
  13509. description: Name of the SecretStore resource
  13510. maxLength: 253
  13511. minLength: 1
  13512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13513. type: string
  13514. type: object
  13515. syncWindows:
  13516. description: |-
  13517. SyncWindows optionally restricts when periodic refreshes may occur.
  13518. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13519. properties:
  13520. kind:
  13521. description: |-
  13522. Kind applies to every window in the list.
  13523. "allow" -- syncs are permitted only while at least one window is active;
  13524. all other times are blocked.
  13525. "deny" -- syncs are blocked while any window is active;
  13526. all other times are permitted.
  13527. enum:
  13528. - allow
  13529. - deny
  13530. type: string
  13531. windows:
  13532. description: Windows is the list of schedule+duration pairs.
  13533. items:
  13534. description: |-
  13535. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13536. within a SyncWindows block.
  13537. properties:
  13538. duration:
  13539. description: |-
  13540. Duration specifies how long the window stays open after each Schedule
  13541. firing. Example: "8h".
  13542. type: string
  13543. schedule:
  13544. description: |-
  13545. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13546. named shorthand such as @daily or @every 1h. It marks the start time of
  13547. each window occurrence.
  13548. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13549. minLength: 1
  13550. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13551. type: string
  13552. required:
  13553. - duration
  13554. - schedule
  13555. type: object
  13556. minItems: 1
  13557. type: array
  13558. required:
  13559. - kind
  13560. - windows
  13561. type: object
  13562. target:
  13563. default:
  13564. creationPolicy: Owner
  13565. deletionPolicy: Retain
  13566. description: |-
  13567. ExternalSecretTarget defines the Kubernetes Secret to be created,
  13568. there can be only one target per ExternalSecret.
  13569. properties:
  13570. creationPolicy:
  13571. default: Owner
  13572. description: |-
  13573. CreationPolicy defines rules on how to create the resulting Secret.
  13574. Defaults to "Owner"
  13575. enum:
  13576. - Owner
  13577. - Orphan
  13578. - Merge
  13579. - None
  13580. type: string
  13581. deletionPolicy:
  13582. default: Retain
  13583. description: |-
  13584. DeletionPolicy defines rules on how to delete the resulting Secret.
  13585. Defaults to "Retain"
  13586. enum:
  13587. - Delete
  13588. - Merge
  13589. - Retain
  13590. type: string
  13591. immutable:
  13592. description: Immutable defines if the final secret will be immutable
  13593. type: boolean
  13594. manifest:
  13595. description: |-
  13596. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  13597. When specified, ExternalSecret will create the resource type defined here
  13598. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  13599. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  13600. properties:
  13601. apiVersion:
  13602. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  13603. minLength: 1
  13604. type: string
  13605. kind:
  13606. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  13607. minLength: 1
  13608. type: string
  13609. required:
  13610. - apiVersion
  13611. - kind
  13612. type: object
  13613. name:
  13614. description: |-
  13615. The name of the Secret resource to be managed.
  13616. Defaults to the .metadata.name of the ExternalSecret resource
  13617. maxLength: 253
  13618. minLength: 1
  13619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13620. type: string
  13621. template:
  13622. description: Template defines a blueprint for the created Secret resource.
  13623. properties:
  13624. data:
  13625. additionalProperties:
  13626. type: string
  13627. type: object
  13628. engineVersion:
  13629. default: v2
  13630. description: |-
  13631. EngineVersion specifies the template engine version
  13632. that should be used to compile/execute the
  13633. template specified in .data and .templateFrom[].
  13634. enum:
  13635. - v2
  13636. type: string
  13637. mergePolicy:
  13638. default: Replace
  13639. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  13640. enum:
  13641. - Replace
  13642. - Merge
  13643. type: string
  13644. metadata:
  13645. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  13646. properties:
  13647. annotations:
  13648. additionalProperties:
  13649. type: string
  13650. type: object
  13651. finalizers:
  13652. items:
  13653. type: string
  13654. type: array
  13655. labels:
  13656. additionalProperties:
  13657. type: string
  13658. type: object
  13659. type: object
  13660. templateFrom:
  13661. items:
  13662. description: |-
  13663. TemplateFrom specifies a source for templates.
  13664. Each item in the list can either reference a ConfigMap or a Secret resource.
  13665. properties:
  13666. configMap:
  13667. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  13668. properties:
  13669. items:
  13670. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  13671. items:
  13672. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  13673. properties:
  13674. key:
  13675. description: A key in the ConfigMap/Secret
  13676. maxLength: 253
  13677. minLength: 1
  13678. pattern: ^[-._a-zA-Z0-9]+$
  13679. type: string
  13680. templateAs:
  13681. default: Values
  13682. description: TemplateScope specifies how the template keys should be interpreted.
  13683. enum:
  13684. - Values
  13685. - KeysAndValues
  13686. type: string
  13687. required:
  13688. - key
  13689. type: object
  13690. type: array
  13691. name:
  13692. description: The name of the ConfigMap/Secret resource
  13693. maxLength: 253
  13694. minLength: 1
  13695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13696. type: string
  13697. required:
  13698. - items
  13699. - name
  13700. type: object
  13701. literal:
  13702. type: string
  13703. secret:
  13704. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  13705. properties:
  13706. items:
  13707. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  13708. items:
  13709. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  13710. properties:
  13711. key:
  13712. description: A key in the ConfigMap/Secret
  13713. maxLength: 253
  13714. minLength: 1
  13715. pattern: ^[-._a-zA-Z0-9]+$
  13716. type: string
  13717. templateAs:
  13718. default: Values
  13719. description: TemplateScope specifies how the template keys should be interpreted.
  13720. enum:
  13721. - Values
  13722. - KeysAndValues
  13723. type: string
  13724. required:
  13725. - key
  13726. type: object
  13727. type: array
  13728. name:
  13729. description: The name of the ConfigMap/Secret resource
  13730. maxLength: 253
  13731. minLength: 1
  13732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13733. type: string
  13734. required:
  13735. - items
  13736. - name
  13737. type: object
  13738. target:
  13739. default: Data
  13740. description: |-
  13741. Target specifies where to place the template result.
  13742. For Secret resources, common values are: "Data", "Annotations", "Labels".
  13743. For custom resources (when spec.target.manifest is set), this supports
  13744. nested paths like "spec.database.config" or "data".
  13745. type: string
  13746. valuesDecodingStrategy:
  13747. default: None
  13748. description: Used to define a decoding Strategy for the rendered template values.
  13749. enum:
  13750. - Auto
  13751. - Base64
  13752. - Base64URL
  13753. - None
  13754. type: string
  13755. type: object
  13756. type: array
  13757. type:
  13758. type: string
  13759. type: object
  13760. type: object
  13761. type: object
  13762. status:
  13763. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  13764. properties:
  13765. binding:
  13766. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  13767. properties:
  13768. name:
  13769. default: ""
  13770. description: |-
  13771. Name of the referent.
  13772. This field is effectively required, but due to backwards compatibility is
  13773. allowed to be empty. Instances of this type with an empty value here are
  13774. almost certainly wrong.
  13775. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  13776. type: string
  13777. type: object
  13778. x-kubernetes-map-type: atomic
  13779. conditions:
  13780. items:
  13781. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  13782. properties:
  13783. lastTransitionTime:
  13784. format: date-time
  13785. type: string
  13786. message:
  13787. type: string
  13788. reason:
  13789. type: string
  13790. status:
  13791. type: string
  13792. type:
  13793. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  13794. enum:
  13795. - Ready
  13796. - Deleted
  13797. type: string
  13798. required:
  13799. - status
  13800. - type
  13801. type: object
  13802. type: array
  13803. refreshTime:
  13804. description: |-
  13805. refreshTime is the time and date the external secret was fetched and
  13806. the target secret updated
  13807. format: date-time
  13808. nullable: true
  13809. type: string
  13810. syncedResourceVersion:
  13811. description: SyncedResourceVersion keeps track of the last synced version
  13812. type: string
  13813. type: object
  13814. type: object
  13815. selectableFields:
  13816. - jsonPath: .spec.secretStoreRef.name
  13817. - jsonPath: .spec.secretStoreRef.kind
  13818. - jsonPath: .spec.target.name
  13819. - jsonPath: .spec.refreshInterval
  13820. served: true
  13821. storage: true
  13822. subresources:
  13823. status: {}
  13824. - additionalPrinterColumns:
  13825. - jsonPath: .spec.secretStoreRef.kind
  13826. name: StoreType
  13827. type: string
  13828. - jsonPath: .spec.secretStoreRef.name
  13829. name: Store
  13830. type: string
  13831. - jsonPath: .spec.refreshInterval
  13832. name: Refresh Interval
  13833. type: string
  13834. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13835. name: Status
  13836. type: string
  13837. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13838. name: Ready
  13839. type: string
  13840. - jsonPath: .status.refreshTime
  13841. name: Last Sync
  13842. type: date
  13843. deprecated: true
  13844. name: v1beta1
  13845. schema:
  13846. openAPIV3Schema:
  13847. description: ExternalSecret is the schema for the external-secrets API.
  13848. properties:
  13849. apiVersion:
  13850. description: |-
  13851. APIVersion defines the versioned schema of this representation of an object.
  13852. Servers should convert recognized schemas to the latest internal value, and
  13853. may reject unrecognized values.
  13854. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13855. type: string
  13856. kind:
  13857. description: |-
  13858. Kind is a string value representing the REST resource this object represents.
  13859. Servers may infer this from the endpoint the client submits requests to.
  13860. Cannot be updated.
  13861. In CamelCase.
  13862. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13863. type: string
  13864. metadata:
  13865. type: object
  13866. spec:
  13867. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13868. properties:
  13869. data:
  13870. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13871. items:
  13872. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13873. properties:
  13874. remoteRef:
  13875. description: |-
  13876. RemoteRef points to the remote secret and defines
  13877. which secret (version/property/..) to fetch.
  13878. properties:
  13879. conversionStrategy:
  13880. default: Default
  13881. description: Used to define a conversion Strategy
  13882. enum:
  13883. - Default
  13884. - Unicode
  13885. type: string
  13886. decodingStrategy:
  13887. default: None
  13888. description: Used to define a decoding Strategy
  13889. enum:
  13890. - Auto
  13891. - Base64
  13892. - Base64URL
  13893. - None
  13894. type: string
  13895. key:
  13896. description: Key is the key used in the Provider, mandatory
  13897. type: string
  13898. metadataPolicy:
  13899. default: None
  13900. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13901. enum:
  13902. - None
  13903. - Fetch
  13904. type: string
  13905. property:
  13906. description: Used to select a specific property of the Provider value (if a map), if supported
  13907. type: string
  13908. version:
  13909. description: Used to select a specific version of the Provider value, if supported
  13910. type: string
  13911. required:
  13912. - key
  13913. type: object
  13914. secretKey:
  13915. description: The key in the Kubernetes Secret to store the value.
  13916. maxLength: 253
  13917. minLength: 1
  13918. pattern: ^[-._a-zA-Z0-9]+$
  13919. type: string
  13920. sourceRef:
  13921. description: |-
  13922. SourceRef allows you to override the source
  13923. from which the value will be pulled.
  13924. maxProperties: 1
  13925. minProperties: 1
  13926. properties:
  13927. generatorRef:
  13928. description: |-
  13929. GeneratorRef points to a generator custom resource.
  13930. Deprecated: The generatorRef is not implemented in .data[].
  13931. this will be removed with v1.
  13932. properties:
  13933. apiVersion:
  13934. default: generators.external-secrets.io/v1alpha1
  13935. description: Specify the apiVersion of the generator resource
  13936. type: string
  13937. kind:
  13938. description: Specify the Kind of the generator resource
  13939. enum:
  13940. - ACRAccessToken
  13941. - ClusterGenerator
  13942. - ECRAuthorizationToken
  13943. - Fake
  13944. - GCRAccessToken
  13945. - GithubAccessToken
  13946. - QuayAccessToken
  13947. - Password
  13948. - SSHKey
  13949. - STSSessionToken
  13950. - UUID
  13951. - VaultDynamicSecret
  13952. - Webhook
  13953. - Grafana
  13954. type: string
  13955. name:
  13956. description: Specify the name of the generator resource
  13957. maxLength: 253
  13958. minLength: 1
  13959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13960. type: string
  13961. required:
  13962. - kind
  13963. - name
  13964. type: object
  13965. storeRef:
  13966. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13967. properties:
  13968. kind:
  13969. description: |-
  13970. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13971. Defaults to `SecretStore`
  13972. enum:
  13973. - SecretStore
  13974. - ClusterSecretStore
  13975. type: string
  13976. name:
  13977. description: Name of the SecretStore resource
  13978. maxLength: 253
  13979. minLength: 1
  13980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13981. type: string
  13982. type: object
  13983. type: object
  13984. required:
  13985. - remoteRef
  13986. - secretKey
  13987. type: object
  13988. type: array
  13989. dataFrom:
  13990. description: |-
  13991. DataFrom is used to fetch all properties from a specific Provider data
  13992. If multiple entries are specified, the Secret keys are merged in the specified order
  13993. items:
  13994. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  13995. properties:
  13996. extract:
  13997. description: |-
  13998. Used to extract multiple key/value pairs from one secret
  13999. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14000. properties:
  14001. conversionStrategy:
  14002. default: Default
  14003. description: Used to define a conversion Strategy
  14004. enum:
  14005. - Default
  14006. - Unicode
  14007. type: string
  14008. decodingStrategy:
  14009. default: None
  14010. description: Used to define a decoding Strategy
  14011. enum:
  14012. - Auto
  14013. - Base64
  14014. - Base64URL
  14015. - None
  14016. type: string
  14017. key:
  14018. description: Key is the key used in the Provider, mandatory
  14019. type: string
  14020. metadataPolicy:
  14021. default: None
  14022. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14023. enum:
  14024. - None
  14025. - Fetch
  14026. type: string
  14027. property:
  14028. description: Used to select a specific property of the Provider value (if a map), if supported
  14029. type: string
  14030. version:
  14031. description: Used to select a specific version of the Provider value, if supported
  14032. type: string
  14033. required:
  14034. - key
  14035. type: object
  14036. find:
  14037. description: |-
  14038. Used to find secrets based on tags or regular expressions
  14039. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14040. properties:
  14041. conversionStrategy:
  14042. default: Default
  14043. description: Used to define a conversion Strategy
  14044. enum:
  14045. - Default
  14046. - Unicode
  14047. type: string
  14048. decodingStrategy:
  14049. default: None
  14050. description: Used to define a decoding Strategy
  14051. enum:
  14052. - Auto
  14053. - Base64
  14054. - Base64URL
  14055. - None
  14056. type: string
  14057. name:
  14058. description: Finds secrets based on the name.
  14059. properties:
  14060. regexp:
  14061. description: Finds secrets base
  14062. type: string
  14063. type: object
  14064. path:
  14065. description: A root path to start the find operations.
  14066. type: string
  14067. tags:
  14068. additionalProperties:
  14069. type: string
  14070. description: Find secrets based on tags.
  14071. type: object
  14072. type: object
  14073. rewrite:
  14074. description: |-
  14075. Used to rewrite secret Keys after getting them from the secret Provider
  14076. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14077. items:
  14078. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14079. maxProperties: 1
  14080. minProperties: 1
  14081. properties:
  14082. regexp:
  14083. description: |-
  14084. Used to rewrite with regular expressions.
  14085. The resulting key will be the output of a regexp.ReplaceAll operation.
  14086. properties:
  14087. source:
  14088. description: Used to define the regular expression of a re.Compiler.
  14089. type: string
  14090. target:
  14091. description: Used to define the target pattern of a ReplaceAll operation.
  14092. type: string
  14093. required:
  14094. - source
  14095. - target
  14096. type: object
  14097. transform:
  14098. description: |-
  14099. Used to apply string transformation on the secrets.
  14100. The resulting key will be the output of the template applied by the operation.
  14101. properties:
  14102. template:
  14103. description: |-
  14104. Used to define the template to apply on the secret name.
  14105. `.value ` will specify the secret name in the template.
  14106. type: string
  14107. required:
  14108. - template
  14109. type: object
  14110. type: object
  14111. type: array
  14112. sourceRef:
  14113. description: |-
  14114. SourceRef points to a store or generator
  14115. which contains secret values ready to use.
  14116. Use this in combination with Extract or Find pull values out of
  14117. a specific SecretStore.
  14118. When sourceRef points to a generator Extract or Find is not supported.
  14119. The generator returns a static map of values
  14120. maxProperties: 1
  14121. minProperties: 1
  14122. properties:
  14123. generatorRef:
  14124. description: GeneratorRef points to a generator custom resource.
  14125. properties:
  14126. apiVersion:
  14127. default: generators.external-secrets.io/v1alpha1
  14128. description: Specify the apiVersion of the generator resource
  14129. type: string
  14130. kind:
  14131. description: Specify the Kind of the generator resource
  14132. enum:
  14133. - ACRAccessToken
  14134. - ClusterGenerator
  14135. - ECRAuthorizationToken
  14136. - Fake
  14137. - GCRAccessToken
  14138. - GithubAccessToken
  14139. - QuayAccessToken
  14140. - Password
  14141. - SSHKey
  14142. - STSSessionToken
  14143. - UUID
  14144. - VaultDynamicSecret
  14145. - Webhook
  14146. - Grafana
  14147. type: string
  14148. name:
  14149. description: Specify the name of the generator resource
  14150. maxLength: 253
  14151. minLength: 1
  14152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14153. type: string
  14154. required:
  14155. - kind
  14156. - name
  14157. type: object
  14158. storeRef:
  14159. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14160. properties:
  14161. kind:
  14162. description: |-
  14163. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14164. Defaults to `SecretStore`
  14165. enum:
  14166. - SecretStore
  14167. - ClusterSecretStore
  14168. type: string
  14169. name:
  14170. description: Name of the SecretStore resource
  14171. maxLength: 253
  14172. minLength: 1
  14173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14174. type: string
  14175. type: object
  14176. type: object
  14177. type: object
  14178. type: array
  14179. refreshInterval:
  14180. default: 1h0m0s
  14181. description: |-
  14182. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14183. specified as Golang Duration strings.
  14184. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14185. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14186. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14187. type: string
  14188. refreshPolicy:
  14189. description: |-
  14190. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14191. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14192. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14193. No periodic updates occur if refreshInterval is 0.
  14194. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14195. enum:
  14196. - CreatedOnce
  14197. - Periodic
  14198. - OnChange
  14199. type: string
  14200. secretStoreRef:
  14201. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14202. properties:
  14203. kind:
  14204. description: |-
  14205. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14206. Defaults to `SecretStore`
  14207. enum:
  14208. - SecretStore
  14209. - ClusterSecretStore
  14210. type: string
  14211. name:
  14212. description: Name of the SecretStore resource
  14213. maxLength: 253
  14214. minLength: 1
  14215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14216. type: string
  14217. type: object
  14218. target:
  14219. default:
  14220. creationPolicy: Owner
  14221. deletionPolicy: Retain
  14222. description: |-
  14223. ExternalSecretTarget defines the Kubernetes Secret to be created
  14224. There can be only one target per ExternalSecret.
  14225. properties:
  14226. creationPolicy:
  14227. default: Owner
  14228. description: |-
  14229. CreationPolicy defines rules on how to create the resulting Secret.
  14230. Defaults to "Owner"
  14231. enum:
  14232. - Owner
  14233. - Orphan
  14234. - Merge
  14235. - None
  14236. type: string
  14237. deletionPolicy:
  14238. default: Retain
  14239. description: |-
  14240. DeletionPolicy defines rules on how to delete the resulting Secret.
  14241. Defaults to "Retain"
  14242. enum:
  14243. - Delete
  14244. - Merge
  14245. - Retain
  14246. type: string
  14247. immutable:
  14248. description: Immutable defines if the final secret will be immutable
  14249. type: boolean
  14250. name:
  14251. description: |-
  14252. The name of the Secret resource to be managed.
  14253. Defaults to the .metadata.name of the ExternalSecret resource
  14254. maxLength: 253
  14255. minLength: 1
  14256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14257. type: string
  14258. template:
  14259. description: Template defines a blueprint for the created Secret resource.
  14260. properties:
  14261. data:
  14262. additionalProperties:
  14263. type: string
  14264. type: object
  14265. engineVersion:
  14266. default: v2
  14267. description: |-
  14268. EngineVersion specifies the template engine version
  14269. that should be used to compile/execute the
  14270. template specified in .data and .templateFrom[].
  14271. enum:
  14272. - v2
  14273. type: string
  14274. mergePolicy:
  14275. default: Replace
  14276. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14277. enum:
  14278. - Replace
  14279. - Merge
  14280. type: string
  14281. metadata:
  14282. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14283. properties:
  14284. annotations:
  14285. additionalProperties:
  14286. type: string
  14287. type: object
  14288. labels:
  14289. additionalProperties:
  14290. type: string
  14291. type: object
  14292. type: object
  14293. templateFrom:
  14294. items:
  14295. description: TemplateFrom defines a source for template data.
  14296. properties:
  14297. configMap:
  14298. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14299. properties:
  14300. items:
  14301. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14302. items:
  14303. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14304. properties:
  14305. key:
  14306. description: A key in the ConfigMap/Secret
  14307. maxLength: 253
  14308. minLength: 1
  14309. pattern: ^[-._a-zA-Z0-9]+$
  14310. type: string
  14311. templateAs:
  14312. default: Values
  14313. description: TemplateScope defines the scope of the template when processing template data.
  14314. enum:
  14315. - Values
  14316. - KeysAndValues
  14317. type: string
  14318. required:
  14319. - key
  14320. type: object
  14321. type: array
  14322. name:
  14323. description: The name of the ConfigMap/Secret resource
  14324. maxLength: 253
  14325. minLength: 1
  14326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14327. type: string
  14328. required:
  14329. - items
  14330. - name
  14331. type: object
  14332. literal:
  14333. type: string
  14334. secret:
  14335. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14336. properties:
  14337. items:
  14338. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14339. items:
  14340. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14341. properties:
  14342. key:
  14343. description: A key in the ConfigMap/Secret
  14344. maxLength: 253
  14345. minLength: 1
  14346. pattern: ^[-._a-zA-Z0-9]+$
  14347. type: string
  14348. templateAs:
  14349. default: Values
  14350. description: TemplateScope defines the scope of the template when processing template data.
  14351. enum:
  14352. - Values
  14353. - KeysAndValues
  14354. type: string
  14355. required:
  14356. - key
  14357. type: object
  14358. type: array
  14359. name:
  14360. description: The name of the ConfigMap/Secret resource
  14361. maxLength: 253
  14362. minLength: 1
  14363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14364. type: string
  14365. required:
  14366. - items
  14367. - name
  14368. type: object
  14369. target:
  14370. default: Data
  14371. description: TemplateTarget defines the target field where the template result will be stored.
  14372. enum:
  14373. - Data
  14374. - Annotations
  14375. - Labels
  14376. type: string
  14377. type: object
  14378. type: array
  14379. type:
  14380. type: string
  14381. type: object
  14382. type: object
  14383. type: object
  14384. status:
  14385. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14386. properties:
  14387. binding:
  14388. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14389. properties:
  14390. name:
  14391. default: ""
  14392. description: |-
  14393. Name of the referent.
  14394. This field is effectively required, but due to backwards compatibility is
  14395. allowed to be empty. Instances of this type with an empty value here are
  14396. almost certainly wrong.
  14397. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14398. type: string
  14399. type: object
  14400. x-kubernetes-map-type: atomic
  14401. conditions:
  14402. items:
  14403. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14404. properties:
  14405. lastTransitionTime:
  14406. format: date-time
  14407. type: string
  14408. message:
  14409. type: string
  14410. reason:
  14411. type: string
  14412. status:
  14413. type: string
  14414. type:
  14415. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14416. type: string
  14417. required:
  14418. - status
  14419. - type
  14420. type: object
  14421. type: array
  14422. refreshTime:
  14423. description: |-
  14424. refreshTime is the time and date the external secret was fetched and
  14425. the target secret updated
  14426. format: date-time
  14427. nullable: true
  14428. type: string
  14429. syncedResourceVersion:
  14430. description: SyncedResourceVersion keeps track of the last synced version
  14431. type: string
  14432. type: object
  14433. type: object
  14434. served: false
  14435. storage: false
  14436. subresources:
  14437. status: {}
  14438. ---
  14439. apiVersion: apiextensions.k8s.io/v1
  14440. kind: CustomResourceDefinition
  14441. metadata:
  14442. annotations:
  14443. controller-gen.kubebuilder.io/version: v0.19.0
  14444. labels:
  14445. external-secrets.io/component: controller
  14446. name: pushsecrets.external-secrets.io
  14447. spec:
  14448. group: external-secrets.io
  14449. names:
  14450. categories:
  14451. - external-secrets
  14452. kind: PushSecret
  14453. listKind: PushSecretList
  14454. plural: pushsecrets
  14455. shortNames:
  14456. - ps
  14457. singular: pushsecret
  14458. scope: Namespaced
  14459. versions:
  14460. - additionalPrinterColumns:
  14461. - jsonPath: .metadata.creationTimestamp
  14462. name: AGE
  14463. type: date
  14464. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14465. name: Status
  14466. type: string
  14467. - jsonPath: .status.refreshTime
  14468. name: Last Sync
  14469. type: date
  14470. name: v1alpha1
  14471. schema:
  14472. openAPIV3Schema:
  14473. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14474. properties:
  14475. apiVersion:
  14476. description: |-
  14477. APIVersion defines the versioned schema of this representation of an object.
  14478. Servers should convert recognized schemas to the latest internal value, and
  14479. may reject unrecognized values.
  14480. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14481. type: string
  14482. kind:
  14483. description: |-
  14484. Kind is a string value representing the REST resource this object represents.
  14485. Servers may infer this from the endpoint the client submits requests to.
  14486. Cannot be updated.
  14487. In CamelCase.
  14488. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14489. type: string
  14490. metadata:
  14491. type: object
  14492. spec:
  14493. description: PushSecretSpec configures the behavior of the PushSecret.
  14494. properties:
  14495. data:
  14496. description: Secret Data that should be pushed to providers
  14497. items:
  14498. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14499. properties:
  14500. conversionStrategy:
  14501. default: None
  14502. description: Used to define a conversion Strategy for the secret keys
  14503. enum:
  14504. - None
  14505. - ReverseUnicode
  14506. type: string
  14507. match:
  14508. description: Match a given Secret Key to be pushed to the provider.
  14509. properties:
  14510. remoteRef:
  14511. description: Remote Refs to push to providers.
  14512. properties:
  14513. property:
  14514. description: Name of the property in the resulting secret
  14515. type: string
  14516. remoteKey:
  14517. description: Name of the resulting provider secret.
  14518. type: string
  14519. required:
  14520. - remoteKey
  14521. type: object
  14522. secretKey:
  14523. description: Secret Key to be pushed
  14524. type: string
  14525. required:
  14526. - remoteRef
  14527. type: object
  14528. metadata:
  14529. description: |-
  14530. Metadata is metadata attached to the secret.
  14531. The structure of metadata is provider specific, please look it up in the provider documentation.
  14532. x-kubernetes-preserve-unknown-fields: true
  14533. required:
  14534. - match
  14535. type: object
  14536. type: array
  14537. dataTo:
  14538. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14539. items:
  14540. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14541. properties:
  14542. conversionStrategy:
  14543. default: None
  14544. description: Used to define a conversion Strategy for the secret keys
  14545. enum:
  14546. - None
  14547. - ReverseUnicode
  14548. type: string
  14549. match:
  14550. description: |-
  14551. Match pattern for selecting keys from the source Secret.
  14552. If not specified, all keys are selected.
  14553. properties:
  14554. regexp:
  14555. description: |-
  14556. Regexp matches keys by regular expression.
  14557. If not specified, all keys are matched.
  14558. type: string
  14559. type: object
  14560. metadata:
  14561. description: |-
  14562. Metadata is metadata attached to the secret.
  14563. The structure of metadata is provider specific, please look it up in the provider documentation.
  14564. x-kubernetes-preserve-unknown-fields: true
  14565. remoteKey:
  14566. description: |-
  14567. RemoteKey is the name of the single provider secret that will receive ALL
  14568. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  14569. When set, per-key expansion is skipped and a single push is performed.
  14570. The provider's store prefix (if any) is still prepended to this value.
  14571. When not set, each matched key is pushed as its own individual provider secret.
  14572. type: string
  14573. rewrite:
  14574. description: |-
  14575. Rewrite operations to transform keys before pushing to the provider.
  14576. Operations are applied sequentially.
  14577. items:
  14578. description: PushSecretRewrite defines how to transform secret keys before pushing.
  14579. properties:
  14580. regexp:
  14581. description: Used to rewrite with regular expressions.
  14582. properties:
  14583. source:
  14584. description: Used to define the regular expression of a re.Compiler.
  14585. type: string
  14586. target:
  14587. description: Used to define the target pattern of a ReplaceAll operation.
  14588. type: string
  14589. required:
  14590. - source
  14591. - target
  14592. type: object
  14593. transform:
  14594. description: Used to apply string transformation on the secrets.
  14595. properties:
  14596. template:
  14597. description: |-
  14598. Used to define the template to apply on the secret name.
  14599. `.value ` will specify the secret name in the template.
  14600. type: string
  14601. required:
  14602. - template
  14603. type: object
  14604. type: object
  14605. x-kubernetes-validations:
  14606. - message: exactly one of regexp or transform must be set
  14607. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  14608. type: array
  14609. storeRef:
  14610. description: StoreRef specifies which SecretStore to push to. Required.
  14611. properties:
  14612. kind:
  14613. default: SecretStore
  14614. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14615. enum:
  14616. - SecretStore
  14617. - ClusterSecretStore
  14618. type: string
  14619. labelSelector:
  14620. description: Optionally, sync to secret stores with label selector
  14621. properties:
  14622. matchExpressions:
  14623. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14624. items:
  14625. description: |-
  14626. A label selector requirement is a selector that contains values, a key, and an operator that
  14627. relates the key and values.
  14628. properties:
  14629. key:
  14630. description: key is the label key that the selector applies to.
  14631. type: string
  14632. operator:
  14633. description: |-
  14634. operator represents a key's relationship to a set of values.
  14635. Valid operators are In, NotIn, Exists and DoesNotExist.
  14636. type: string
  14637. values:
  14638. description: |-
  14639. values is an array of string values. If the operator is In or NotIn,
  14640. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14641. the values array must be empty. This array is replaced during a strategic
  14642. merge patch.
  14643. items:
  14644. type: string
  14645. type: array
  14646. x-kubernetes-list-type: atomic
  14647. required:
  14648. - key
  14649. - operator
  14650. type: object
  14651. type: array
  14652. x-kubernetes-list-type: atomic
  14653. matchLabels:
  14654. additionalProperties:
  14655. type: string
  14656. description: |-
  14657. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14658. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14659. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14660. type: object
  14661. type: object
  14662. x-kubernetes-map-type: atomic
  14663. name:
  14664. description: Optionally, sync to the SecretStore of the given name
  14665. maxLength: 253
  14666. minLength: 1
  14667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14668. type: string
  14669. type: object
  14670. type: object
  14671. x-kubernetes-validations:
  14672. - message: storeRef must specify either name or labelSelector
  14673. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  14674. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  14675. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  14676. type: array
  14677. deletionPolicy:
  14678. default: None
  14679. description: Deletion Policy to handle Secrets in the provider.
  14680. enum:
  14681. - Delete
  14682. - None
  14683. type: string
  14684. refreshInterval:
  14685. default: 1h0m0s
  14686. description: The Interval to which External Secrets will try to push a secret definition
  14687. type: string
  14688. secretStoreRefs:
  14689. items:
  14690. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  14691. properties:
  14692. kind:
  14693. default: SecretStore
  14694. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14695. enum:
  14696. - SecretStore
  14697. - ClusterSecretStore
  14698. type: string
  14699. labelSelector:
  14700. description: Optionally, sync to secret stores with label selector
  14701. properties:
  14702. matchExpressions:
  14703. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14704. items:
  14705. description: |-
  14706. A label selector requirement is a selector that contains values, a key, and an operator that
  14707. relates the key and values.
  14708. properties:
  14709. key:
  14710. description: key is the label key that the selector applies to.
  14711. type: string
  14712. operator:
  14713. description: |-
  14714. operator represents a key's relationship to a set of values.
  14715. Valid operators are In, NotIn, Exists and DoesNotExist.
  14716. type: string
  14717. values:
  14718. description: |-
  14719. values is an array of string values. If the operator is In or NotIn,
  14720. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14721. the values array must be empty. This array is replaced during a strategic
  14722. merge patch.
  14723. items:
  14724. type: string
  14725. type: array
  14726. x-kubernetes-list-type: atomic
  14727. required:
  14728. - key
  14729. - operator
  14730. type: object
  14731. type: array
  14732. x-kubernetes-list-type: atomic
  14733. matchLabels:
  14734. additionalProperties:
  14735. type: string
  14736. description: |-
  14737. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14738. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14739. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14740. type: object
  14741. type: object
  14742. x-kubernetes-map-type: atomic
  14743. name:
  14744. description: Optionally, sync to the SecretStore of the given name
  14745. maxLength: 253
  14746. minLength: 1
  14747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14748. type: string
  14749. type: object
  14750. type: array
  14751. selector:
  14752. description: The Secret Selector (k8s source) for the Push Secret
  14753. maxProperties: 1
  14754. minProperties: 1
  14755. properties:
  14756. generatorRef:
  14757. description: Point to a generator to create a Secret.
  14758. properties:
  14759. apiVersion:
  14760. default: generators.external-secrets.io/v1alpha1
  14761. description: Specify the apiVersion of the generator resource
  14762. type: string
  14763. kind:
  14764. description: Specify the Kind of the generator resource
  14765. enum:
  14766. - ACRAccessToken
  14767. - BeyondtrustWorkloadCredentialsDynamicSecret
  14768. - ClusterGenerator
  14769. - CloudsmithAccessToken
  14770. - ECRAuthorizationToken
  14771. - Fake
  14772. - GCRAccessToken
  14773. - GithubAccessToken
  14774. - GitlabDeployToken
  14775. - QuayAccessToken
  14776. - Password
  14777. - SSHKey
  14778. - STSSessionToken
  14779. - UUID
  14780. - VaultDynamicSecret
  14781. - Webhook
  14782. - Grafana
  14783. - MFA
  14784. type: string
  14785. name:
  14786. description: Specify the name of the generator resource
  14787. maxLength: 253
  14788. minLength: 1
  14789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14790. type: string
  14791. required:
  14792. - kind
  14793. - name
  14794. type: object
  14795. secret:
  14796. description: Select a Secret to Push.
  14797. properties:
  14798. name:
  14799. description: |-
  14800. Name of the Secret.
  14801. The Secret must exist in the same namespace as the PushSecret manifest.
  14802. maxLength: 253
  14803. minLength: 1
  14804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14805. type: string
  14806. selector:
  14807. description: Selector chooses secrets using a labelSelector.
  14808. properties:
  14809. matchExpressions:
  14810. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14811. items:
  14812. description: |-
  14813. A label selector requirement is a selector that contains values, a key, and an operator that
  14814. relates the key and values.
  14815. properties:
  14816. key:
  14817. description: key is the label key that the selector applies to.
  14818. type: string
  14819. operator:
  14820. description: |-
  14821. operator represents a key's relationship to a set of values.
  14822. Valid operators are In, NotIn, Exists and DoesNotExist.
  14823. type: string
  14824. values:
  14825. description: |-
  14826. values is an array of string values. If the operator is In or NotIn,
  14827. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14828. the values array must be empty. This array is replaced during a strategic
  14829. merge patch.
  14830. items:
  14831. type: string
  14832. type: array
  14833. x-kubernetes-list-type: atomic
  14834. required:
  14835. - key
  14836. - operator
  14837. type: object
  14838. type: array
  14839. x-kubernetes-list-type: atomic
  14840. matchLabels:
  14841. additionalProperties:
  14842. type: string
  14843. description: |-
  14844. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14845. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14846. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14847. type: object
  14848. type: object
  14849. x-kubernetes-map-type: atomic
  14850. type: object
  14851. type: object
  14852. template:
  14853. description: Template defines a blueprint for the created Secret resource.
  14854. properties:
  14855. data:
  14856. additionalProperties:
  14857. type: string
  14858. type: object
  14859. engineVersion:
  14860. default: v2
  14861. description: |-
  14862. EngineVersion specifies the template engine version
  14863. that should be used to compile/execute the
  14864. template specified in .data and .templateFrom[].
  14865. enum:
  14866. - v2
  14867. type: string
  14868. mergePolicy:
  14869. default: Replace
  14870. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14871. enum:
  14872. - Replace
  14873. - Merge
  14874. type: string
  14875. metadata:
  14876. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14877. properties:
  14878. annotations:
  14879. additionalProperties:
  14880. type: string
  14881. type: object
  14882. finalizers:
  14883. items:
  14884. type: string
  14885. type: array
  14886. labels:
  14887. additionalProperties:
  14888. type: string
  14889. type: object
  14890. type: object
  14891. templateFrom:
  14892. items:
  14893. description: |-
  14894. TemplateFrom specifies a source for templates.
  14895. Each item in the list can either reference a ConfigMap or a Secret resource.
  14896. properties:
  14897. configMap:
  14898. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14899. properties:
  14900. items:
  14901. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14902. items:
  14903. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14904. properties:
  14905. key:
  14906. description: A key in the ConfigMap/Secret
  14907. maxLength: 253
  14908. minLength: 1
  14909. pattern: ^[-._a-zA-Z0-9]+$
  14910. type: string
  14911. templateAs:
  14912. default: Values
  14913. description: TemplateScope specifies how the template keys should be interpreted.
  14914. enum:
  14915. - Values
  14916. - KeysAndValues
  14917. type: string
  14918. required:
  14919. - key
  14920. type: object
  14921. type: array
  14922. name:
  14923. description: The name of the ConfigMap/Secret resource
  14924. maxLength: 253
  14925. minLength: 1
  14926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14927. type: string
  14928. required:
  14929. - items
  14930. - name
  14931. type: object
  14932. literal:
  14933. type: string
  14934. secret:
  14935. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14936. properties:
  14937. items:
  14938. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14939. items:
  14940. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14941. properties:
  14942. key:
  14943. description: A key in the ConfigMap/Secret
  14944. maxLength: 253
  14945. minLength: 1
  14946. pattern: ^[-._a-zA-Z0-9]+$
  14947. type: string
  14948. templateAs:
  14949. default: Values
  14950. description: TemplateScope specifies how the template keys should be interpreted.
  14951. enum:
  14952. - Values
  14953. - KeysAndValues
  14954. type: string
  14955. required:
  14956. - key
  14957. type: object
  14958. type: array
  14959. name:
  14960. description: The name of the ConfigMap/Secret resource
  14961. maxLength: 253
  14962. minLength: 1
  14963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14964. type: string
  14965. required:
  14966. - items
  14967. - name
  14968. type: object
  14969. target:
  14970. default: Data
  14971. description: |-
  14972. Target specifies where to place the template result.
  14973. For Secret resources, common values are: "Data", "Annotations", "Labels".
  14974. For custom resources (when spec.target.manifest is set), this supports
  14975. nested paths like "spec.database.config" or "data".
  14976. type: string
  14977. valuesDecodingStrategy:
  14978. default: None
  14979. description: Used to define a decoding Strategy for the rendered template values.
  14980. enum:
  14981. - Auto
  14982. - Base64
  14983. - Base64URL
  14984. - None
  14985. type: string
  14986. type: object
  14987. type: array
  14988. type:
  14989. type: string
  14990. type: object
  14991. updatePolicy:
  14992. default: Replace
  14993. description: UpdatePolicy to handle Secrets in the provider.
  14994. enum:
  14995. - Replace
  14996. - IfNotExists
  14997. type: string
  14998. required:
  14999. - secretStoreRefs
  15000. - selector
  15001. type: object
  15002. status:
  15003. description: PushSecretStatus indicates the history of the status of PushSecret.
  15004. properties:
  15005. conditions:
  15006. items:
  15007. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15008. properties:
  15009. lastTransitionTime:
  15010. format: date-time
  15011. type: string
  15012. message:
  15013. type: string
  15014. reason:
  15015. type: string
  15016. status:
  15017. type: string
  15018. type:
  15019. description: PushSecretConditionType indicates the condition of the PushSecret.
  15020. type: string
  15021. required:
  15022. - status
  15023. - type
  15024. type: object
  15025. type: array
  15026. refreshTime:
  15027. description: |-
  15028. refreshTime is the time and date the external secret was fetched and
  15029. the target secret updated
  15030. format: date-time
  15031. nullable: true
  15032. type: string
  15033. syncedPushSecrets:
  15034. additionalProperties:
  15035. additionalProperties:
  15036. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15037. properties:
  15038. conversionStrategy:
  15039. default: None
  15040. description: Used to define a conversion Strategy for the secret keys
  15041. enum:
  15042. - None
  15043. - ReverseUnicode
  15044. type: string
  15045. match:
  15046. description: Match a given Secret Key to be pushed to the provider.
  15047. properties:
  15048. remoteRef:
  15049. description: Remote Refs to push to providers.
  15050. properties:
  15051. property:
  15052. description: Name of the property in the resulting secret
  15053. type: string
  15054. remoteKey:
  15055. description: Name of the resulting provider secret.
  15056. type: string
  15057. required:
  15058. - remoteKey
  15059. type: object
  15060. secretKey:
  15061. description: Secret Key to be pushed
  15062. type: string
  15063. required:
  15064. - remoteRef
  15065. type: object
  15066. metadata:
  15067. description: |-
  15068. Metadata is metadata attached to the secret.
  15069. The structure of metadata is provider specific, please look it up in the provider documentation.
  15070. x-kubernetes-preserve-unknown-fields: true
  15071. required:
  15072. - match
  15073. type: object
  15074. type: object
  15075. description: |-
  15076. Synced PushSecrets, including secrets that already exist in provider.
  15077. Matches secret stores to PushSecretData that was stored to that secret store.
  15078. type: object
  15079. syncedResourceVersion:
  15080. description: SyncedResourceVersion keeps track of the last synced version.
  15081. type: string
  15082. type: object
  15083. type: object
  15084. served: true
  15085. storage: true
  15086. subresources:
  15087. status: {}
  15088. ---
  15089. apiVersion: apiextensions.k8s.io/v1
  15090. kind: CustomResourceDefinition
  15091. metadata:
  15092. annotations:
  15093. controller-gen.kubebuilder.io/version: v0.19.0
  15094. labels:
  15095. external-secrets.io/component: controller
  15096. name: secretstores.external-secrets.io
  15097. spec:
  15098. group: external-secrets.io
  15099. names:
  15100. categories:
  15101. - external-secrets
  15102. kind: SecretStore
  15103. listKind: SecretStoreList
  15104. plural: secretstores
  15105. shortNames:
  15106. - ss
  15107. singular: secretstore
  15108. scope: Namespaced
  15109. versions:
  15110. - additionalPrinterColumns:
  15111. - jsonPath: .metadata.creationTimestamp
  15112. name: AGE
  15113. type: date
  15114. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15115. name: Status
  15116. type: string
  15117. - jsonPath: .status.capabilities
  15118. name: Capabilities
  15119. type: string
  15120. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15121. name: Ready
  15122. type: string
  15123. name: v1
  15124. schema:
  15125. openAPIV3Schema:
  15126. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15127. properties:
  15128. apiVersion:
  15129. description: |-
  15130. APIVersion defines the versioned schema of this representation of an object.
  15131. Servers should convert recognized schemas to the latest internal value, and
  15132. may reject unrecognized values.
  15133. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15134. type: string
  15135. kind:
  15136. description: |-
  15137. Kind is a string value representing the REST resource this object represents.
  15138. Servers may infer this from the endpoint the client submits requests to.
  15139. Cannot be updated.
  15140. In CamelCase.
  15141. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15142. type: string
  15143. metadata:
  15144. type: object
  15145. spec:
  15146. description: SecretStoreSpec defines the desired state of SecretStore.
  15147. properties:
  15148. conditions:
  15149. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15150. items:
  15151. description: |-
  15152. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15153. for a ClusterSecretStore instance.
  15154. properties:
  15155. namespaceRegexes:
  15156. description: Choose namespaces by using regex matching
  15157. items:
  15158. type: string
  15159. type: array
  15160. namespaceSelector:
  15161. description: Choose namespace using a labelSelector
  15162. properties:
  15163. matchExpressions:
  15164. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15165. items:
  15166. description: |-
  15167. A label selector requirement is a selector that contains values, a key, and an operator that
  15168. relates the key and values.
  15169. properties:
  15170. key:
  15171. description: key is the label key that the selector applies to.
  15172. type: string
  15173. operator:
  15174. description: |-
  15175. operator represents a key's relationship to a set of values.
  15176. Valid operators are In, NotIn, Exists and DoesNotExist.
  15177. type: string
  15178. values:
  15179. description: |-
  15180. values is an array of string values. If the operator is In or NotIn,
  15181. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15182. the values array must be empty. This array is replaced during a strategic
  15183. merge patch.
  15184. items:
  15185. type: string
  15186. type: array
  15187. x-kubernetes-list-type: atomic
  15188. required:
  15189. - key
  15190. - operator
  15191. type: object
  15192. type: array
  15193. x-kubernetes-list-type: atomic
  15194. matchLabels:
  15195. additionalProperties:
  15196. type: string
  15197. description: |-
  15198. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15199. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15200. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15201. type: object
  15202. type: object
  15203. x-kubernetes-map-type: atomic
  15204. namespaces:
  15205. description: Choose namespaces by name
  15206. items:
  15207. maxLength: 63
  15208. minLength: 1
  15209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15210. type: string
  15211. type: array
  15212. type: object
  15213. type: array
  15214. controller:
  15215. description: |-
  15216. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15217. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15218. type: string
  15219. provider:
  15220. description: Used to configure the provider. Only one provider may be set
  15221. maxProperties: 1
  15222. minProperties: 1
  15223. properties:
  15224. akeyless:
  15225. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15226. properties:
  15227. akeylessGWApiURL:
  15228. description: Akeyless GW API Url from which the secrets to be fetched from.
  15229. type: string
  15230. authSecretRef:
  15231. description: Auth configures how the operator authenticates with Akeyless.
  15232. properties:
  15233. kubernetesAuth:
  15234. description: |-
  15235. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15236. token stored in the named Secret resource.
  15237. properties:
  15238. accessID:
  15239. description: the Akeyless Kubernetes auth-method access-id
  15240. type: string
  15241. k8sConfName:
  15242. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15243. type: string
  15244. secretRef:
  15245. description: |-
  15246. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15247. for authenticating with Akeyless. If a name is specified without a key,
  15248. `token` is the default. If one is not specified, the one bound to
  15249. the controller will be used.
  15250. properties:
  15251. key:
  15252. description: |-
  15253. A key in the referenced Secret.
  15254. Some instances of this field may be defaulted, in others it may be required.
  15255. maxLength: 253
  15256. minLength: 1
  15257. pattern: ^[-._a-zA-Z0-9]+$
  15258. type: string
  15259. name:
  15260. description: The name of the Secret resource being referred to.
  15261. maxLength: 253
  15262. minLength: 1
  15263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15264. type: string
  15265. namespace:
  15266. description: |-
  15267. The namespace of the Secret resource being referred to.
  15268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15269. maxLength: 63
  15270. minLength: 1
  15271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15272. type: string
  15273. type: object
  15274. serviceAccountRef:
  15275. description: |-
  15276. Optional service account field containing the name of a kubernetes ServiceAccount.
  15277. If the service account is specified, the service account secret token JWT will be used
  15278. for authenticating with Akeyless. If the service account selector is not supplied,
  15279. the secretRef will be used instead.
  15280. properties:
  15281. audiences:
  15282. description: |-
  15283. Audience specifies the `aud` claim for the service account token
  15284. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15285. then this audiences will be appended to the list
  15286. items:
  15287. type: string
  15288. type: array
  15289. name:
  15290. description: The name of the ServiceAccount resource being referred to.
  15291. maxLength: 253
  15292. minLength: 1
  15293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15294. type: string
  15295. namespace:
  15296. description: |-
  15297. Namespace of the resource being referred to.
  15298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15299. maxLength: 63
  15300. minLength: 1
  15301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15302. type: string
  15303. required:
  15304. - name
  15305. type: object
  15306. required:
  15307. - accessID
  15308. - k8sConfName
  15309. type: object
  15310. secretRef:
  15311. description: |-
  15312. Reference to a Secret that contains the details
  15313. to authenticate with Akeyless.
  15314. properties:
  15315. accessID:
  15316. description: The SecretAccessID is used for authentication
  15317. properties:
  15318. key:
  15319. description: |-
  15320. A key in the referenced Secret.
  15321. Some instances of this field may be defaulted, in others it may be required.
  15322. maxLength: 253
  15323. minLength: 1
  15324. pattern: ^[-._a-zA-Z0-9]+$
  15325. type: string
  15326. name:
  15327. description: The name of the Secret resource being referred to.
  15328. maxLength: 253
  15329. minLength: 1
  15330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15331. type: string
  15332. namespace:
  15333. description: |-
  15334. The namespace of the Secret resource being referred to.
  15335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15336. maxLength: 63
  15337. minLength: 1
  15338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15339. type: string
  15340. type: object
  15341. accessType:
  15342. description: |-
  15343. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15344. In some instances, `key` is a required field.
  15345. properties:
  15346. key:
  15347. description: |-
  15348. A key in the referenced Secret.
  15349. Some instances of this field may be defaulted, in others it may be required.
  15350. maxLength: 253
  15351. minLength: 1
  15352. pattern: ^[-._a-zA-Z0-9]+$
  15353. type: string
  15354. name:
  15355. description: The name of the Secret resource being referred to.
  15356. maxLength: 253
  15357. minLength: 1
  15358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15359. type: string
  15360. namespace:
  15361. description: |-
  15362. The namespace of the Secret resource being referred to.
  15363. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15364. maxLength: 63
  15365. minLength: 1
  15366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15367. type: string
  15368. type: object
  15369. accessTypeParam:
  15370. description: |-
  15371. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15372. In some instances, `key` is a required field.
  15373. properties:
  15374. key:
  15375. description: |-
  15376. A key in the referenced Secret.
  15377. Some instances of this field may be defaulted, in others it may be required.
  15378. maxLength: 253
  15379. minLength: 1
  15380. pattern: ^[-._a-zA-Z0-9]+$
  15381. type: string
  15382. name:
  15383. description: The name of the Secret resource being referred to.
  15384. maxLength: 253
  15385. minLength: 1
  15386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15387. type: string
  15388. namespace:
  15389. description: |-
  15390. The namespace of the Secret resource being referred to.
  15391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15392. maxLength: 63
  15393. minLength: 1
  15394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15395. type: string
  15396. type: object
  15397. type: object
  15398. serviceAccountRef:
  15399. description: |-
  15400. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15401. authentication on AKS Workload Identity. The operator obtains a federated
  15402. identity token from this ServiceAccount via the TokenRequest API instead
  15403. of using the ESO controller pod identity. Ignored for other access types.
  15404. properties:
  15405. audiences:
  15406. description: |-
  15407. Audience specifies the `aud` claim for the service account token
  15408. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15409. then this audiences will be appended to the list
  15410. items:
  15411. type: string
  15412. type: array
  15413. name:
  15414. description: The name of the ServiceAccount resource being referred to.
  15415. maxLength: 253
  15416. minLength: 1
  15417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15418. type: string
  15419. namespace:
  15420. description: |-
  15421. Namespace of the resource being referred to.
  15422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15423. maxLength: 63
  15424. minLength: 1
  15425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15426. type: string
  15427. required:
  15428. - name
  15429. type: object
  15430. type: object
  15431. caBundle:
  15432. description: |-
  15433. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15434. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15435. are used to validate the TLS connection.
  15436. format: byte
  15437. type: string
  15438. caProvider:
  15439. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15440. properties:
  15441. key:
  15442. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15443. maxLength: 253
  15444. minLength: 1
  15445. pattern: ^[-._a-zA-Z0-9]+$
  15446. type: string
  15447. name:
  15448. description: The name of the object located at the provider type.
  15449. maxLength: 253
  15450. minLength: 1
  15451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15452. type: string
  15453. namespace:
  15454. description: |-
  15455. The namespace the Provider type is in.
  15456. Can only be defined when used in a ClusterSecretStore.
  15457. maxLength: 63
  15458. minLength: 1
  15459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15460. type: string
  15461. type:
  15462. description: The type of provider to use such as "Secret", or "ConfigMap".
  15463. enum:
  15464. - Secret
  15465. - ConfigMap
  15466. type: string
  15467. required:
  15468. - name
  15469. - type
  15470. type: object
  15471. ignoreCache:
  15472. description: |-
  15473. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15474. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15475. type: boolean
  15476. required:
  15477. - akeylessGWApiURL
  15478. - authSecretRef
  15479. type: object
  15480. aws:
  15481. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15482. properties:
  15483. additionalRoles:
  15484. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15485. items:
  15486. type: string
  15487. type: array
  15488. auth:
  15489. description: |-
  15490. Auth defines the information necessary to authenticate against AWS
  15491. if not set aws sdk will infer credentials from your environment
  15492. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15493. properties:
  15494. jwt:
  15495. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15496. properties:
  15497. serviceAccountRef:
  15498. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15499. properties:
  15500. audiences:
  15501. description: |-
  15502. Audience specifies the `aud` claim for the service account token
  15503. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15504. then this audiences will be appended to the list
  15505. items:
  15506. type: string
  15507. type: array
  15508. name:
  15509. description: The name of the ServiceAccount resource being referred to.
  15510. maxLength: 253
  15511. minLength: 1
  15512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15513. type: string
  15514. namespace:
  15515. description: |-
  15516. Namespace of the resource being referred to.
  15517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15518. maxLength: 63
  15519. minLength: 1
  15520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15521. type: string
  15522. required:
  15523. - name
  15524. type: object
  15525. type: object
  15526. secretRef:
  15527. description: |-
  15528. AWSAuthSecretRef holds secret references for AWS credentials
  15529. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15530. properties:
  15531. accessKeyIDSecretRef:
  15532. description: The AccessKeyID is used for authentication
  15533. properties:
  15534. key:
  15535. description: |-
  15536. A key in the referenced Secret.
  15537. Some instances of this field may be defaulted, in others it may be required.
  15538. maxLength: 253
  15539. minLength: 1
  15540. pattern: ^[-._a-zA-Z0-9]+$
  15541. type: string
  15542. name:
  15543. description: The name of the Secret resource being referred to.
  15544. maxLength: 253
  15545. minLength: 1
  15546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15547. type: string
  15548. namespace:
  15549. description: |-
  15550. The namespace of the Secret resource being referred to.
  15551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15552. maxLength: 63
  15553. minLength: 1
  15554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15555. type: string
  15556. type: object
  15557. secretAccessKeySecretRef:
  15558. description: The SecretAccessKey is used for authentication
  15559. properties:
  15560. key:
  15561. description: |-
  15562. A key in the referenced Secret.
  15563. Some instances of this field may be defaulted, in others it may be required.
  15564. maxLength: 253
  15565. minLength: 1
  15566. pattern: ^[-._a-zA-Z0-9]+$
  15567. type: string
  15568. name:
  15569. description: The name of the Secret resource being referred to.
  15570. maxLength: 253
  15571. minLength: 1
  15572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15573. type: string
  15574. namespace:
  15575. description: |-
  15576. The namespace of the Secret resource being referred to.
  15577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15578. maxLength: 63
  15579. minLength: 1
  15580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15581. type: string
  15582. type: object
  15583. sessionTokenSecretRef:
  15584. description: |-
  15585. The SessionToken used for authentication
  15586. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  15587. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  15588. properties:
  15589. key:
  15590. description: |-
  15591. A key in the referenced Secret.
  15592. Some instances of this field may be defaulted, in others it may be required.
  15593. maxLength: 253
  15594. minLength: 1
  15595. pattern: ^[-._a-zA-Z0-9]+$
  15596. type: string
  15597. name:
  15598. description: The name of the Secret resource being referred to.
  15599. maxLength: 253
  15600. minLength: 1
  15601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15602. type: string
  15603. namespace:
  15604. description: |-
  15605. The namespace of the Secret resource being referred to.
  15606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15607. maxLength: 63
  15608. minLength: 1
  15609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15610. type: string
  15611. type: object
  15612. type: object
  15613. type: object
  15614. customSessionTags:
  15615. additionalProperties:
  15616. type: string
  15617. description: |-
  15618. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  15619. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  15620. type: object
  15621. x-kubernetes-validations:
  15622. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  15623. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  15624. externalID:
  15625. description: AWS External ID set on assumed IAM roles
  15626. type: string
  15627. prefix:
  15628. description: Prefix adds a prefix to all retrieved values.
  15629. type: string
  15630. region:
  15631. description: AWS Region to be used for the provider
  15632. type: string
  15633. role:
  15634. description: Role is a Role ARN which the provider will assume
  15635. type: string
  15636. secretsManager:
  15637. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  15638. properties:
  15639. forceDeleteWithoutRecovery:
  15640. description: |-
  15641. Specifies whether to delete the secret without any recovery window. You
  15642. can't use both this parameter and RecoveryWindowInDays in the same call.
  15643. If you don't use either, then by default Secrets Manager uses a 30 day
  15644. recovery window.
  15645. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  15646. type: boolean
  15647. recoveryWindowInDays:
  15648. description: |-
  15649. The number of days from 7 to 30 that Secrets Manager waits before
  15650. permanently deleting the secret. You can't use both this parameter and
  15651. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  15652. then by default Secrets Manager uses a 30-day recovery window.
  15653. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  15654. format: int64
  15655. type: integer
  15656. type: object
  15657. service:
  15658. description: Service defines which service should be used to fetch the secrets
  15659. enum:
  15660. - SecretsManager
  15661. - ParameterStore
  15662. - CertificateManager
  15663. type: string
  15664. sessionTags:
  15665. description: AWS STS assume role session tags
  15666. items:
  15667. description: |-
  15668. Tag is a key-value pair that can be attached to an AWS resource.
  15669. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  15670. properties:
  15671. key:
  15672. type: string
  15673. value:
  15674. type: string
  15675. required:
  15676. - key
  15677. - value
  15678. type: object
  15679. type: array
  15680. sessionTagsPolicy:
  15681. default: None
  15682. description: |-
  15683. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  15684. None (default): no tags are added.
  15685. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  15686. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  15687. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  15688. enum:
  15689. - None
  15690. - Simple
  15691. - Custom
  15692. type: string
  15693. transitiveTagKeys:
  15694. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  15695. items:
  15696. type: string
  15697. type: array
  15698. required:
  15699. - region
  15700. - service
  15701. type: object
  15702. azurekv:
  15703. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  15704. properties:
  15705. authSecretRef:
  15706. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  15707. properties:
  15708. clientCertificate:
  15709. description: The Azure ClientCertificate of the service principle used for authentication.
  15710. properties:
  15711. key:
  15712. description: |-
  15713. A key in the referenced Secret.
  15714. Some instances of this field may be defaulted, in others it may be required.
  15715. maxLength: 253
  15716. minLength: 1
  15717. pattern: ^[-._a-zA-Z0-9]+$
  15718. type: string
  15719. name:
  15720. description: The name of the Secret resource being referred to.
  15721. maxLength: 253
  15722. minLength: 1
  15723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15724. type: string
  15725. namespace:
  15726. description: |-
  15727. The namespace of the Secret resource being referred to.
  15728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15729. maxLength: 63
  15730. minLength: 1
  15731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15732. type: string
  15733. type: object
  15734. clientId:
  15735. description: The Azure clientId of the service principle or managed identity used for authentication.
  15736. properties:
  15737. key:
  15738. description: |-
  15739. A key in the referenced Secret.
  15740. Some instances of this field may be defaulted, in others it may be required.
  15741. maxLength: 253
  15742. minLength: 1
  15743. pattern: ^[-._a-zA-Z0-9]+$
  15744. type: string
  15745. name:
  15746. description: The name of the Secret resource being referred to.
  15747. maxLength: 253
  15748. minLength: 1
  15749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15750. type: string
  15751. namespace:
  15752. description: |-
  15753. The namespace of the Secret resource being referred to.
  15754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15755. maxLength: 63
  15756. minLength: 1
  15757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15758. type: string
  15759. type: object
  15760. clientSecret:
  15761. description: The Azure ClientSecret of the service principle used for authentication.
  15762. properties:
  15763. key:
  15764. description: |-
  15765. A key in the referenced Secret.
  15766. Some instances of this field may be defaulted, in others it may be required.
  15767. maxLength: 253
  15768. minLength: 1
  15769. pattern: ^[-._a-zA-Z0-9]+$
  15770. type: string
  15771. name:
  15772. description: The name of the Secret resource being referred to.
  15773. maxLength: 253
  15774. minLength: 1
  15775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15776. type: string
  15777. namespace:
  15778. description: |-
  15779. The namespace of the Secret resource being referred to.
  15780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15781. maxLength: 63
  15782. minLength: 1
  15783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15784. type: string
  15785. type: object
  15786. tenantId:
  15787. description: The Azure tenantId of the managed identity used for authentication.
  15788. properties:
  15789. key:
  15790. description: |-
  15791. A key in the referenced Secret.
  15792. Some instances of this field may be defaulted, in others it may be required.
  15793. maxLength: 253
  15794. minLength: 1
  15795. pattern: ^[-._a-zA-Z0-9]+$
  15796. type: string
  15797. name:
  15798. description: The name of the Secret resource being referred to.
  15799. maxLength: 253
  15800. minLength: 1
  15801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15802. type: string
  15803. namespace:
  15804. description: |-
  15805. The namespace of the Secret resource being referred to.
  15806. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15807. maxLength: 63
  15808. minLength: 1
  15809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15810. type: string
  15811. type: object
  15812. type: object
  15813. authType:
  15814. default: ServicePrincipal
  15815. description: |-
  15816. Auth type defines how to authenticate to the keyvault service.
  15817. Valid values are:
  15818. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  15819. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  15820. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  15821. enum:
  15822. - ServicePrincipal
  15823. - ManagedIdentity
  15824. - WorkloadIdentity
  15825. type: string
  15826. customCloudConfig:
  15827. description: |-
  15828. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  15829. Required when EnvironmentType is AzureStackCloud.
  15830. Optional for other environment types - useful for Azure China when using Workload Identity
  15831. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  15832. standard China Cloud endpoint (login.chinacloudapi.cn).
  15833. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  15834. configuration is not supported with the legacy go-autorest SDK.
  15835. properties:
  15836. activeDirectoryEndpoint:
  15837. description: |-
  15838. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  15839. Required when using custom cloud configuration
  15840. type: string
  15841. keyVaultDNSSuffix:
  15842. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  15843. type: string
  15844. keyVaultEndpoint:
  15845. description: KeyVaultEndpoint is the Key Vault service endpoint
  15846. type: string
  15847. resourceManagerEndpoint:
  15848. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  15849. type: string
  15850. required:
  15851. - activeDirectoryEndpoint
  15852. type: object
  15853. environmentType:
  15854. default: PublicCloud
  15855. description: |-
  15856. EnvironmentType specifies the Azure cloud environment endpoints to use for
  15857. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  15858. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  15859. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  15860. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  15861. enum:
  15862. - PublicCloud
  15863. - USGovernmentCloud
  15864. - ChinaCloud
  15865. - GermanCloud
  15866. - AzureStackCloud
  15867. type: string
  15868. identityId:
  15869. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  15870. type: string
  15871. serviceAccountRef:
  15872. description: |-
  15873. ServiceAccountRef specified the service account
  15874. that should be used when authenticating with WorkloadIdentity.
  15875. properties:
  15876. audiences:
  15877. description: |-
  15878. Audience specifies the `aud` claim for the service account token
  15879. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15880. then this audiences will be appended to the list
  15881. items:
  15882. type: string
  15883. type: array
  15884. name:
  15885. description: The name of the ServiceAccount resource being referred to.
  15886. maxLength: 253
  15887. minLength: 1
  15888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15889. type: string
  15890. namespace:
  15891. description: |-
  15892. Namespace of the resource being referred to.
  15893. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15894. maxLength: 63
  15895. minLength: 1
  15896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15897. type: string
  15898. required:
  15899. - name
  15900. type: object
  15901. tenantId:
  15902. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  15903. type: string
  15904. useAzureSDK:
  15905. default: false
  15906. description: |-
  15907. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  15908. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  15909. type: boolean
  15910. vaultUrl:
  15911. description: Vault Url from which the secrets to be fetched from.
  15912. type: string
  15913. required:
  15914. - vaultUrl
  15915. type: object
  15916. barbican:
  15917. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  15918. properties:
  15919. auth:
  15920. description: BarbicanAuth contains the authentication information for Barbican.
  15921. properties:
  15922. password:
  15923. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  15924. properties:
  15925. secretRef:
  15926. description: |-
  15927. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15928. In some instances, `key` is a required field.
  15929. properties:
  15930. key:
  15931. description: |-
  15932. A key in the referenced Secret.
  15933. Some instances of this field may be defaulted, in others it may be required.
  15934. maxLength: 253
  15935. minLength: 1
  15936. pattern: ^[-._a-zA-Z0-9]+$
  15937. type: string
  15938. name:
  15939. description: The name of the Secret resource being referred to.
  15940. maxLength: 253
  15941. minLength: 1
  15942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15943. type: string
  15944. namespace:
  15945. description: |-
  15946. The namespace of the Secret resource being referred to.
  15947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15948. maxLength: 63
  15949. minLength: 1
  15950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15951. type: string
  15952. type: object
  15953. required:
  15954. - secretRef
  15955. type: object
  15956. username:
  15957. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  15958. maxProperties: 1
  15959. minProperties: 1
  15960. properties:
  15961. secretRef:
  15962. description: |-
  15963. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15964. In some instances, `key` is a required field.
  15965. properties:
  15966. key:
  15967. description: |-
  15968. A key in the referenced Secret.
  15969. Some instances of this field may be defaulted, in others it may be required.
  15970. maxLength: 253
  15971. minLength: 1
  15972. pattern: ^[-._a-zA-Z0-9]+$
  15973. type: string
  15974. name:
  15975. description: The name of the Secret resource being referred to.
  15976. maxLength: 253
  15977. minLength: 1
  15978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15979. type: string
  15980. namespace:
  15981. description: |-
  15982. The namespace of the Secret resource being referred to.
  15983. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15984. maxLength: 63
  15985. minLength: 1
  15986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15987. type: string
  15988. type: object
  15989. value:
  15990. type: string
  15991. type: object
  15992. required:
  15993. - password
  15994. - username
  15995. type: object
  15996. authURL:
  15997. type: string
  15998. domainName:
  15999. type: string
  16000. region:
  16001. type: string
  16002. tenantName:
  16003. type: string
  16004. required:
  16005. - auth
  16006. type: object
  16007. beyondtrust:
  16008. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16009. properties:
  16010. auth:
  16011. description: Auth configures how the operator authenticates with Beyondtrust.
  16012. properties:
  16013. apiKey:
  16014. description: APIKey If not provided then ClientID/ClientSecret become required.
  16015. properties:
  16016. secretRef:
  16017. description: SecretRef references a key in a secret that will be used as value.
  16018. properties:
  16019. key:
  16020. description: |-
  16021. A key in the referenced Secret.
  16022. Some instances of this field may be defaulted, in others it may be required.
  16023. maxLength: 253
  16024. minLength: 1
  16025. pattern: ^[-._a-zA-Z0-9]+$
  16026. type: string
  16027. name:
  16028. description: The name of the Secret resource being referred to.
  16029. maxLength: 253
  16030. minLength: 1
  16031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16032. type: string
  16033. namespace:
  16034. description: |-
  16035. The namespace of the Secret resource being referred to.
  16036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16037. maxLength: 63
  16038. minLength: 1
  16039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16040. type: string
  16041. type: object
  16042. value:
  16043. description: Value can be specified directly to set a value without using a secret.
  16044. type: string
  16045. type: object
  16046. certificate:
  16047. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16048. properties:
  16049. secretRef:
  16050. description: SecretRef references a key in a secret that will be used as value.
  16051. properties:
  16052. key:
  16053. description: |-
  16054. A key in the referenced Secret.
  16055. Some instances of this field may be defaulted, in others it may be required.
  16056. maxLength: 253
  16057. minLength: 1
  16058. pattern: ^[-._a-zA-Z0-9]+$
  16059. type: string
  16060. name:
  16061. description: The name of the Secret resource being referred to.
  16062. maxLength: 253
  16063. minLength: 1
  16064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16065. type: string
  16066. namespace:
  16067. description: |-
  16068. The namespace of the Secret resource being referred to.
  16069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16070. maxLength: 63
  16071. minLength: 1
  16072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16073. type: string
  16074. type: object
  16075. value:
  16076. description: Value can be specified directly to set a value without using a secret.
  16077. type: string
  16078. type: object
  16079. certificateKey:
  16080. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16081. properties:
  16082. secretRef:
  16083. description: SecretRef references a key in a secret that will be used as value.
  16084. properties:
  16085. key:
  16086. description: |-
  16087. A key in the referenced Secret.
  16088. Some instances of this field may be defaulted, in others it may be required.
  16089. maxLength: 253
  16090. minLength: 1
  16091. pattern: ^[-._a-zA-Z0-9]+$
  16092. type: string
  16093. name:
  16094. description: The name of the Secret resource being referred to.
  16095. maxLength: 253
  16096. minLength: 1
  16097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16098. type: string
  16099. namespace:
  16100. description: |-
  16101. The namespace of the Secret resource being referred to.
  16102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16103. maxLength: 63
  16104. minLength: 1
  16105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16106. type: string
  16107. type: object
  16108. value:
  16109. description: Value can be specified directly to set a value without using a secret.
  16110. type: string
  16111. type: object
  16112. clientId:
  16113. description: ClientID is the API OAuth Client ID.
  16114. properties:
  16115. secretRef:
  16116. description: SecretRef references a key in a secret that will be used as value.
  16117. properties:
  16118. key:
  16119. description: |-
  16120. A key in the referenced Secret.
  16121. Some instances of this field may be defaulted, in others it may be required.
  16122. maxLength: 253
  16123. minLength: 1
  16124. pattern: ^[-._a-zA-Z0-9]+$
  16125. type: string
  16126. name:
  16127. description: The name of the Secret resource being referred to.
  16128. maxLength: 253
  16129. minLength: 1
  16130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16131. type: string
  16132. namespace:
  16133. description: |-
  16134. The namespace of the Secret resource being referred to.
  16135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16136. maxLength: 63
  16137. minLength: 1
  16138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16139. type: string
  16140. type: object
  16141. value:
  16142. description: Value can be specified directly to set a value without using a secret.
  16143. type: string
  16144. type: object
  16145. clientSecret:
  16146. description: ClientSecret is the API OAuth Client Secret.
  16147. properties:
  16148. secretRef:
  16149. description: SecretRef references a key in a secret that will be used as value.
  16150. properties:
  16151. key:
  16152. description: |-
  16153. A key in the referenced Secret.
  16154. Some instances of this field may be defaulted, in others it may be required.
  16155. maxLength: 253
  16156. minLength: 1
  16157. pattern: ^[-._a-zA-Z0-9]+$
  16158. type: string
  16159. name:
  16160. description: The name of the Secret resource being referred to.
  16161. maxLength: 253
  16162. minLength: 1
  16163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16164. type: string
  16165. namespace:
  16166. description: |-
  16167. The namespace of the Secret resource being referred to.
  16168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16169. maxLength: 63
  16170. minLength: 1
  16171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16172. type: string
  16173. type: object
  16174. value:
  16175. description: Value can be specified directly to set a value without using a secret.
  16176. type: string
  16177. type: object
  16178. type: object
  16179. server:
  16180. description: Auth configures how API server works.
  16181. properties:
  16182. apiUrl:
  16183. type: string
  16184. apiVersion:
  16185. type: string
  16186. clientTimeOutSeconds:
  16187. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16188. type: integer
  16189. decrypt:
  16190. default: true
  16191. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16192. type: boolean
  16193. retrievalType:
  16194. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16195. type: string
  16196. separator:
  16197. description: A character that separates the folder names.
  16198. type: string
  16199. verifyCA:
  16200. type: boolean
  16201. required:
  16202. - apiUrl
  16203. - verifyCA
  16204. type: object
  16205. required:
  16206. - auth
  16207. - server
  16208. type: object
  16209. beyondtrustworkloadcredentials:
  16210. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16211. properties:
  16212. auth:
  16213. description: |-
  16214. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16215. Currently supports API key authentication via Kubernetes secret reference.
  16216. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16217. properties:
  16218. apikey:
  16219. description: |-
  16220. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16221. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16222. properties:
  16223. token:
  16224. description: |-
  16225. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16226. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16227. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16228. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16229. properties:
  16230. key:
  16231. description: |-
  16232. A key in the referenced Secret.
  16233. Some instances of this field may be defaulted, in others it may be required.
  16234. maxLength: 253
  16235. minLength: 1
  16236. pattern: ^[-._a-zA-Z0-9]+$
  16237. type: string
  16238. name:
  16239. description: The name of the Secret resource being referred to.
  16240. maxLength: 253
  16241. minLength: 1
  16242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16243. type: string
  16244. namespace:
  16245. description: |-
  16246. The namespace of the Secret resource being referred to.
  16247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16248. maxLength: 63
  16249. minLength: 1
  16250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16251. type: string
  16252. type: object
  16253. required:
  16254. - token
  16255. type: object
  16256. required:
  16257. - apikey
  16258. type: object
  16259. caBundle:
  16260. description: |-
  16261. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16262. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16263. If not set, the system's trusted root certificates are used.
  16264. format: byte
  16265. type: string
  16266. caProvider:
  16267. description: |-
  16268. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16269. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16270. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16271. properties:
  16272. key:
  16273. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16274. maxLength: 253
  16275. minLength: 1
  16276. pattern: ^[-._a-zA-Z0-9]+$
  16277. type: string
  16278. name:
  16279. description: The name of the object located at the provider type.
  16280. maxLength: 253
  16281. minLength: 1
  16282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16283. type: string
  16284. namespace:
  16285. description: |-
  16286. The namespace the Provider type is in.
  16287. Can only be defined when used in a ClusterSecretStore.
  16288. maxLength: 63
  16289. minLength: 1
  16290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16291. type: string
  16292. type:
  16293. description: The type of provider to use such as "Secret", or "ConfigMap".
  16294. enum:
  16295. - Secret
  16296. - ConfigMap
  16297. type: string
  16298. required:
  16299. - name
  16300. - type
  16301. type: object
  16302. folderPath:
  16303. description: |-
  16304. FolderPath specifies the default folder path for secret retrieval.
  16305. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16306. Example: "production/database" or "dev/api-keys"
  16307. Leave empty to retrieve secrets from the root folder.
  16308. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16309. type: string
  16310. server:
  16311. description: |-
  16312. Server configures the BeyondTrust Workload Credentials server connection details.
  16313. Includes the API URL and Site ID for your BeyondTrust instance.
  16314. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16315. properties:
  16316. apiUrl:
  16317. description: |-
  16318. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16319. This should be the full URL to your BeyondTrust instance.
  16320. Example: https://api.beyondtrust.io/siie
  16321. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16322. type: string
  16323. siteId:
  16324. description: |-
  16325. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16326. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16327. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16328. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16329. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16330. type: string
  16331. required:
  16332. - apiUrl
  16333. - siteId
  16334. type: object
  16335. required:
  16336. - auth
  16337. - server
  16338. type: object
  16339. bitwardensecretsmanager:
  16340. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16341. properties:
  16342. apiURL:
  16343. type: string
  16344. auth:
  16345. description: |-
  16346. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16347. Make sure that the token being used has permissions on the given secret.
  16348. properties:
  16349. secretRef:
  16350. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16351. properties:
  16352. credentials:
  16353. description: AccessToken used for the bitwarden instance.
  16354. properties:
  16355. key:
  16356. description: |-
  16357. A key in the referenced Secret.
  16358. Some instances of this field may be defaulted, in others it may be required.
  16359. maxLength: 253
  16360. minLength: 1
  16361. pattern: ^[-._a-zA-Z0-9]+$
  16362. type: string
  16363. name:
  16364. description: The name of the Secret resource being referred to.
  16365. maxLength: 253
  16366. minLength: 1
  16367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16368. type: string
  16369. namespace:
  16370. description: |-
  16371. The namespace of the Secret resource being referred to.
  16372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16373. maxLength: 63
  16374. minLength: 1
  16375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16376. type: string
  16377. type: object
  16378. required:
  16379. - credentials
  16380. type: object
  16381. required:
  16382. - secretRef
  16383. type: object
  16384. bitwardenServerSDKURL:
  16385. type: string
  16386. caBundle:
  16387. description: |-
  16388. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16389. can be performed.
  16390. type: string
  16391. caProvider:
  16392. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16393. properties:
  16394. key:
  16395. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16396. maxLength: 253
  16397. minLength: 1
  16398. pattern: ^[-._a-zA-Z0-9]+$
  16399. type: string
  16400. name:
  16401. description: The name of the object located at the provider type.
  16402. maxLength: 253
  16403. minLength: 1
  16404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16405. type: string
  16406. namespace:
  16407. description: |-
  16408. The namespace the Provider type is in.
  16409. Can only be defined when used in a ClusterSecretStore.
  16410. maxLength: 63
  16411. minLength: 1
  16412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16413. type: string
  16414. type:
  16415. description: The type of provider to use such as "Secret", or "ConfigMap".
  16416. enum:
  16417. - Secret
  16418. - ConfigMap
  16419. type: string
  16420. required:
  16421. - name
  16422. - type
  16423. type: object
  16424. identityURL:
  16425. type: string
  16426. organizationID:
  16427. description: OrganizationID determines which organization this secret store manages.
  16428. type: string
  16429. projectID:
  16430. description: ProjectID determines which project this secret store manages.
  16431. type: string
  16432. required:
  16433. - auth
  16434. - organizationID
  16435. - projectID
  16436. type: object
  16437. chef:
  16438. description: Chef configures this store to sync secrets with chef server
  16439. properties:
  16440. auth:
  16441. description: Auth defines the information necessary to authenticate against chef Server
  16442. properties:
  16443. secretRef:
  16444. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16445. properties:
  16446. privateKeySecretRef:
  16447. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16448. properties:
  16449. key:
  16450. description: |-
  16451. A key in the referenced Secret.
  16452. Some instances of this field may be defaulted, in others it may be required.
  16453. maxLength: 253
  16454. minLength: 1
  16455. pattern: ^[-._a-zA-Z0-9]+$
  16456. type: string
  16457. name:
  16458. description: The name of the Secret resource being referred to.
  16459. maxLength: 253
  16460. minLength: 1
  16461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16462. type: string
  16463. namespace:
  16464. description: |-
  16465. The namespace of the Secret resource being referred to.
  16466. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16467. maxLength: 63
  16468. minLength: 1
  16469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16470. type: string
  16471. type: object
  16472. required:
  16473. - privateKeySecretRef
  16474. type: object
  16475. required:
  16476. - secretRef
  16477. type: object
  16478. serverUrl:
  16479. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16480. type: string
  16481. username:
  16482. description: UserName should be the user ID on the chef server
  16483. type: string
  16484. required:
  16485. - auth
  16486. - serverUrl
  16487. - username
  16488. type: object
  16489. cloudrusm:
  16490. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16491. properties:
  16492. auth:
  16493. description: CSMAuth contains a secretRef for credentials.
  16494. properties:
  16495. secretRef:
  16496. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16497. properties:
  16498. accessKeyIDSecretRef:
  16499. description: The AccessKeyID is used for authentication
  16500. properties:
  16501. key:
  16502. description: |-
  16503. A key in the referenced Secret.
  16504. Some instances of this field may be defaulted, in others it may be required.
  16505. maxLength: 253
  16506. minLength: 1
  16507. pattern: ^[-._a-zA-Z0-9]+$
  16508. type: string
  16509. name:
  16510. description: The name of the Secret resource being referred to.
  16511. maxLength: 253
  16512. minLength: 1
  16513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16514. type: string
  16515. namespace:
  16516. description: |-
  16517. The namespace of the Secret resource being referred to.
  16518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16519. maxLength: 63
  16520. minLength: 1
  16521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16522. type: string
  16523. type: object
  16524. accessKeySecretSecretRef:
  16525. description: The AccessKeySecret is used for authentication
  16526. properties:
  16527. key:
  16528. description: |-
  16529. A key in the referenced Secret.
  16530. Some instances of this field may be defaulted, in others it may be required.
  16531. maxLength: 253
  16532. minLength: 1
  16533. pattern: ^[-._a-zA-Z0-9]+$
  16534. type: string
  16535. name:
  16536. description: The name of the Secret resource being referred to.
  16537. maxLength: 253
  16538. minLength: 1
  16539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16540. type: string
  16541. namespace:
  16542. description: |-
  16543. The namespace of the Secret resource being referred to.
  16544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16545. maxLength: 63
  16546. minLength: 1
  16547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16548. type: string
  16549. type: object
  16550. required:
  16551. - accessKeyIDSecretRef
  16552. - accessKeySecretSecretRef
  16553. type: object
  16554. type: object
  16555. projectID:
  16556. description: ProjectID is the project, which the secrets are stored in.
  16557. type: string
  16558. required:
  16559. - auth
  16560. type: object
  16561. conjur:
  16562. description: Conjur configures this store to sync secrets using conjur provider
  16563. properties:
  16564. auth:
  16565. description: Defines authentication settings for connecting to Conjur.
  16566. properties:
  16567. apikey:
  16568. description: Authenticates with Conjur using an API key.
  16569. properties:
  16570. account:
  16571. description: Account is the Conjur organization account name.
  16572. type: string
  16573. apiKeyRef:
  16574. description: |-
  16575. A reference to a specific 'key' containing the Conjur API key
  16576. within a Secret resource. In some instances, `key` is a required field.
  16577. properties:
  16578. key:
  16579. description: |-
  16580. A key in the referenced Secret.
  16581. Some instances of this field may be defaulted, in others it may be required.
  16582. maxLength: 253
  16583. minLength: 1
  16584. pattern: ^[-._a-zA-Z0-9]+$
  16585. type: string
  16586. name:
  16587. description: The name of the Secret resource being referred to.
  16588. maxLength: 253
  16589. minLength: 1
  16590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16591. type: string
  16592. namespace:
  16593. description: |-
  16594. The namespace of the Secret resource being referred to.
  16595. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16596. maxLength: 63
  16597. minLength: 1
  16598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16599. type: string
  16600. type: object
  16601. userRef:
  16602. description: |-
  16603. A reference to a specific 'key' containing the Conjur username
  16604. within a Secret resource. In some instances, `key` is a required field.
  16605. properties:
  16606. key:
  16607. description: |-
  16608. A key in the referenced Secret.
  16609. Some instances of this field may be defaulted, in others it may be required.
  16610. maxLength: 253
  16611. minLength: 1
  16612. pattern: ^[-._a-zA-Z0-9]+$
  16613. type: string
  16614. name:
  16615. description: The name of the Secret resource being referred to.
  16616. maxLength: 253
  16617. minLength: 1
  16618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16619. type: string
  16620. namespace:
  16621. description: |-
  16622. The namespace of the Secret resource being referred to.
  16623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16624. maxLength: 63
  16625. minLength: 1
  16626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16627. type: string
  16628. type: object
  16629. required:
  16630. - account
  16631. - apiKeyRef
  16632. - userRef
  16633. type: object
  16634. jwt:
  16635. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  16636. properties:
  16637. account:
  16638. description: Account is the Conjur organization account name.
  16639. type: string
  16640. hostId:
  16641. description: |-
  16642. Optional HostID for JWT authentication. This may be used depending
  16643. on how the Conjur JWT authenticator policy is configured.
  16644. type: string
  16645. secretRef:
  16646. description: |-
  16647. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  16648. authenticate with Conjur using the JWT authentication method.
  16649. properties:
  16650. key:
  16651. description: |-
  16652. A key in the referenced Secret.
  16653. Some instances of this field may be defaulted, in others it may be required.
  16654. maxLength: 253
  16655. minLength: 1
  16656. pattern: ^[-._a-zA-Z0-9]+$
  16657. type: string
  16658. name:
  16659. description: The name of the Secret resource being referred to.
  16660. maxLength: 253
  16661. minLength: 1
  16662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16663. type: string
  16664. namespace:
  16665. description: |-
  16666. The namespace of the Secret resource being referred to.
  16667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16668. maxLength: 63
  16669. minLength: 1
  16670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16671. type: string
  16672. type: object
  16673. serviceAccountRef:
  16674. description: |-
  16675. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  16676. a token for with the `TokenRequest` API.
  16677. properties:
  16678. audiences:
  16679. description: |-
  16680. Audience specifies the `aud` claim for the service account token
  16681. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16682. then this audiences will be appended to the list
  16683. items:
  16684. type: string
  16685. type: array
  16686. name:
  16687. description: The name of the ServiceAccount resource being referred to.
  16688. maxLength: 253
  16689. minLength: 1
  16690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16691. type: string
  16692. namespace:
  16693. description: |-
  16694. Namespace of the resource being referred to.
  16695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16696. maxLength: 63
  16697. minLength: 1
  16698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16699. type: string
  16700. required:
  16701. - name
  16702. type: object
  16703. serviceID:
  16704. description: The conjur authn jwt webservice id
  16705. type: string
  16706. required:
  16707. - account
  16708. - serviceID
  16709. type: object
  16710. type: object
  16711. caBundle:
  16712. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  16713. type: string
  16714. caProvider:
  16715. description: |-
  16716. Used to provide custom certificate authority (CA) certificates
  16717. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  16718. that contains a PEM-encoded certificate.
  16719. properties:
  16720. key:
  16721. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16722. maxLength: 253
  16723. minLength: 1
  16724. pattern: ^[-._a-zA-Z0-9]+$
  16725. type: string
  16726. name:
  16727. description: The name of the object located at the provider type.
  16728. maxLength: 253
  16729. minLength: 1
  16730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16731. type: string
  16732. namespace:
  16733. description: |-
  16734. The namespace the Provider type is in.
  16735. Can only be defined when used in a ClusterSecretStore.
  16736. maxLength: 63
  16737. minLength: 1
  16738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16739. type: string
  16740. type:
  16741. description: The type of provider to use such as "Secret", or "ConfigMap".
  16742. enum:
  16743. - Secret
  16744. - ConfigMap
  16745. type: string
  16746. required:
  16747. - name
  16748. - type
  16749. type: object
  16750. url:
  16751. description: URL is the endpoint of the Conjur instance.
  16752. type: string
  16753. required:
  16754. - auth
  16755. - url
  16756. type: object
  16757. delinea:
  16758. description: |-
  16759. Delinea DevOps Secrets Vault
  16760. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  16761. properties:
  16762. clientId:
  16763. description: ClientID is the non-secret part of the credential.
  16764. properties:
  16765. secretRef:
  16766. description: SecretRef references a key in a secret that will be used as value.
  16767. properties:
  16768. key:
  16769. description: |-
  16770. A key in the referenced Secret.
  16771. Some instances of this field may be defaulted, in others it may be required.
  16772. maxLength: 253
  16773. minLength: 1
  16774. pattern: ^[-._a-zA-Z0-9]+$
  16775. type: string
  16776. name:
  16777. description: The name of the Secret resource being referred to.
  16778. maxLength: 253
  16779. minLength: 1
  16780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16781. type: string
  16782. namespace:
  16783. description: |-
  16784. The namespace of the Secret resource being referred to.
  16785. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16786. maxLength: 63
  16787. minLength: 1
  16788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16789. type: string
  16790. type: object
  16791. value:
  16792. description: Value can be specified directly to set a value without using a secret.
  16793. type: string
  16794. type: object
  16795. clientSecret:
  16796. description: ClientSecret is the secret part of the credential.
  16797. properties:
  16798. secretRef:
  16799. description: SecretRef references a key in a secret that will be used as value.
  16800. properties:
  16801. key:
  16802. description: |-
  16803. A key in the referenced Secret.
  16804. Some instances of this field may be defaulted, in others it may be required.
  16805. maxLength: 253
  16806. minLength: 1
  16807. pattern: ^[-._a-zA-Z0-9]+$
  16808. type: string
  16809. name:
  16810. description: The name of the Secret resource being referred to.
  16811. maxLength: 253
  16812. minLength: 1
  16813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16814. type: string
  16815. namespace:
  16816. description: |-
  16817. The namespace of the Secret resource being referred to.
  16818. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16819. maxLength: 63
  16820. minLength: 1
  16821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16822. type: string
  16823. type: object
  16824. value:
  16825. description: Value can be specified directly to set a value without using a secret.
  16826. type: string
  16827. type: object
  16828. tenant:
  16829. description: Tenant is the chosen hostname / site name.
  16830. type: string
  16831. tld:
  16832. description: |-
  16833. TLD is based on the server location that was chosen during provisioning.
  16834. If unset, defaults to "com".
  16835. type: string
  16836. urlTemplate:
  16837. description: |-
  16838. URLTemplate
  16839. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  16840. type: string
  16841. required:
  16842. - clientId
  16843. - clientSecret
  16844. - tenant
  16845. type: object
  16846. doppler:
  16847. description: Doppler configures this store to sync secrets using the Doppler provider
  16848. properties:
  16849. auth:
  16850. description: Auth configures how the Operator authenticates with the Doppler API
  16851. properties:
  16852. oidcConfig:
  16853. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  16854. properties:
  16855. expirationSeconds:
  16856. default: 600
  16857. description: |-
  16858. ExpirationSeconds sets the ServiceAccount token validity duration.
  16859. Defaults to 10 minutes.
  16860. format: int64
  16861. type: integer
  16862. identity:
  16863. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  16864. type: string
  16865. serviceAccountRef:
  16866. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  16867. properties:
  16868. audiences:
  16869. description: |-
  16870. Audience specifies the `aud` claim for the service account token
  16871. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16872. then this audiences will be appended to the list
  16873. items:
  16874. type: string
  16875. type: array
  16876. name:
  16877. description: The name of the ServiceAccount resource being referred to.
  16878. maxLength: 253
  16879. minLength: 1
  16880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16881. type: string
  16882. namespace:
  16883. description: |-
  16884. Namespace of the resource being referred to.
  16885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16886. maxLength: 63
  16887. minLength: 1
  16888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16889. type: string
  16890. required:
  16891. - name
  16892. type: object
  16893. required:
  16894. - identity
  16895. - serviceAccountRef
  16896. type: object
  16897. secretRef:
  16898. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  16899. properties:
  16900. dopplerToken:
  16901. description: |-
  16902. The DopplerToken is used for authentication.
  16903. See https://docs.doppler.com/reference/api#authentication for auth token types.
  16904. The Key attribute defaults to dopplerToken if not specified.
  16905. properties:
  16906. key:
  16907. description: |-
  16908. A key in the referenced Secret.
  16909. Some instances of this field may be defaulted, in others it may be required.
  16910. maxLength: 253
  16911. minLength: 1
  16912. pattern: ^[-._a-zA-Z0-9]+$
  16913. type: string
  16914. name:
  16915. description: The name of the Secret resource being referred to.
  16916. maxLength: 253
  16917. minLength: 1
  16918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16919. type: string
  16920. namespace:
  16921. description: |-
  16922. The namespace of the Secret resource being referred to.
  16923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16924. maxLength: 63
  16925. minLength: 1
  16926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16927. type: string
  16928. type: object
  16929. required:
  16930. - dopplerToken
  16931. type: object
  16932. type: object
  16933. x-kubernetes-validations:
  16934. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  16935. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  16936. config:
  16937. description: Doppler config (required if not using a Service Token)
  16938. type: string
  16939. format:
  16940. description: Format enables the downloading of secrets as a file (string)
  16941. enum:
  16942. - json
  16943. - dotnet-json
  16944. - env
  16945. - yaml
  16946. - docker
  16947. type: string
  16948. nameTransformer:
  16949. description: Environment variable compatible name transforms that change secret names to a different format
  16950. enum:
  16951. - upper-camel
  16952. - camel
  16953. - lower-snake
  16954. - tf-var
  16955. - dotnet-env
  16956. - lower-kebab
  16957. type: string
  16958. project:
  16959. description: Doppler project (required if not using a Service Token)
  16960. type: string
  16961. required:
  16962. - auth
  16963. type: object
  16964. dvls:
  16965. description: DVLS configures this store to sync secrets using Devolutions Server provider
  16966. properties:
  16967. auth:
  16968. description: Auth defines the authentication method to use.
  16969. properties:
  16970. secretRef:
  16971. description: SecretRef contains the Application ID and Application Secret for authentication.
  16972. properties:
  16973. appId:
  16974. description: AppID is the reference to the secret containing the Application ID.
  16975. properties:
  16976. key:
  16977. description: |-
  16978. A key in the referenced Secret.
  16979. Some instances of this field may be defaulted, in others it may be required.
  16980. maxLength: 253
  16981. minLength: 1
  16982. pattern: ^[-._a-zA-Z0-9]+$
  16983. type: string
  16984. name:
  16985. description: The name of the Secret resource being referred to.
  16986. maxLength: 253
  16987. minLength: 1
  16988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16989. type: string
  16990. namespace:
  16991. description: |-
  16992. The namespace of the Secret resource being referred to.
  16993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16994. maxLength: 63
  16995. minLength: 1
  16996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16997. type: string
  16998. type: object
  16999. appSecret:
  17000. description: AppSecret is the reference to the secret containing the Application Secret.
  17001. properties:
  17002. key:
  17003. description: |-
  17004. A key in the referenced Secret.
  17005. Some instances of this field may be defaulted, in others it may be required.
  17006. maxLength: 253
  17007. minLength: 1
  17008. pattern: ^[-._a-zA-Z0-9]+$
  17009. type: string
  17010. name:
  17011. description: The name of the Secret resource being referred to.
  17012. maxLength: 253
  17013. minLength: 1
  17014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17015. type: string
  17016. namespace:
  17017. description: |-
  17018. The namespace of the Secret resource being referred to.
  17019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17020. maxLength: 63
  17021. minLength: 1
  17022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17023. type: string
  17024. type: object
  17025. required:
  17026. - appId
  17027. - appSecret
  17028. type: object
  17029. required:
  17030. - secretRef
  17031. type: object
  17032. insecure:
  17033. description: |-
  17034. Insecure allows connecting to DVLS over plain HTTP.
  17035. This is NOT RECOMMENDED for production use.
  17036. Set to true only if you understand the security implications.
  17037. type: boolean
  17038. serverUrl:
  17039. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17040. type: string
  17041. vault:
  17042. description: |-
  17043. Vault is the name or UUID of the vault to fetch secrets from.
  17044. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17045. type: string
  17046. required:
  17047. - auth
  17048. - serverUrl
  17049. type: object
  17050. fake:
  17051. description: Fake configures a store with static key/value pairs
  17052. properties:
  17053. data:
  17054. items:
  17055. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17056. properties:
  17057. key:
  17058. type: string
  17059. value:
  17060. type: string
  17061. version:
  17062. type: string
  17063. required:
  17064. - key
  17065. - value
  17066. type: object
  17067. type: array
  17068. validationResult:
  17069. description: ValidationResult is defined type for the number of validation results.
  17070. type: integer
  17071. required:
  17072. - data
  17073. type: object
  17074. fortanix:
  17075. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17076. properties:
  17077. apiKey:
  17078. description: APIKey is the API token to access SDKMS Applications.
  17079. properties:
  17080. secretRef:
  17081. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17082. properties:
  17083. key:
  17084. description: |-
  17085. A key in the referenced Secret.
  17086. Some instances of this field may be defaulted, in others it may be required.
  17087. maxLength: 253
  17088. minLength: 1
  17089. pattern: ^[-._a-zA-Z0-9]+$
  17090. type: string
  17091. name:
  17092. description: The name of the Secret resource being referred to.
  17093. maxLength: 253
  17094. minLength: 1
  17095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17096. type: string
  17097. namespace:
  17098. description: |-
  17099. The namespace of the Secret resource being referred to.
  17100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17101. maxLength: 63
  17102. minLength: 1
  17103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17104. type: string
  17105. type: object
  17106. type: object
  17107. apiUrl:
  17108. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17109. type: string
  17110. type: object
  17111. gcpsm:
  17112. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17113. properties:
  17114. auth:
  17115. description: Auth defines the information necessary to authenticate against GCP
  17116. properties:
  17117. secretRef:
  17118. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17119. properties:
  17120. secretAccessKeySecretRef:
  17121. description: The SecretAccessKey is used for authentication
  17122. properties:
  17123. key:
  17124. description: |-
  17125. A key in the referenced Secret.
  17126. Some instances of this field may be defaulted, in others it may be required.
  17127. maxLength: 253
  17128. minLength: 1
  17129. pattern: ^[-._a-zA-Z0-9]+$
  17130. type: string
  17131. name:
  17132. description: The name of the Secret resource being referred to.
  17133. maxLength: 253
  17134. minLength: 1
  17135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17136. type: string
  17137. namespace:
  17138. description: |-
  17139. The namespace of the Secret resource being referred to.
  17140. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17141. maxLength: 63
  17142. minLength: 1
  17143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17144. type: string
  17145. type: object
  17146. type: object
  17147. workloadIdentity:
  17148. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17149. properties:
  17150. clusterLocation:
  17151. description: |-
  17152. ClusterLocation is the location of the cluster
  17153. If not specified, it fetches information from the metadata server
  17154. type: string
  17155. clusterName:
  17156. description: |-
  17157. ClusterName is the name of the cluster
  17158. If not specified, it fetches information from the metadata server
  17159. type: string
  17160. clusterProjectID:
  17161. description: |-
  17162. ClusterProjectID is the project ID of the cluster
  17163. If not specified, it fetches information from the metadata server
  17164. type: string
  17165. serviceAccountRef:
  17166. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17167. properties:
  17168. audiences:
  17169. description: |-
  17170. Audience specifies the `aud` claim for the service account token
  17171. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17172. then this audiences will be appended to the list
  17173. items:
  17174. type: string
  17175. type: array
  17176. name:
  17177. description: The name of the ServiceAccount resource being referred to.
  17178. maxLength: 253
  17179. minLength: 1
  17180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17181. type: string
  17182. namespace:
  17183. description: |-
  17184. Namespace of the resource being referred to.
  17185. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17186. maxLength: 63
  17187. minLength: 1
  17188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17189. type: string
  17190. required:
  17191. - name
  17192. type: object
  17193. required:
  17194. - serviceAccountRef
  17195. type: object
  17196. workloadIdentityFederation:
  17197. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17198. properties:
  17199. audience:
  17200. description: |-
  17201. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17202. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17203. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17204. type: string
  17205. awsSecurityCredentials:
  17206. description: |-
  17207. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  17208. when using the AWS metadata server is not an option.
  17209. properties:
  17210. awsCredentialsSecretRef:
  17211. description: |-
  17212. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  17213. Secret should be created with below names for keys
  17214. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  17215. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  17216. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  17217. properties:
  17218. name:
  17219. description: name of the secret.
  17220. maxLength: 253
  17221. minLength: 1
  17222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17223. type: string
  17224. namespace:
  17225. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  17226. maxLength: 63
  17227. minLength: 1
  17228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17229. type: string
  17230. required:
  17231. - name
  17232. type: object
  17233. region:
  17234. description: region is for configuring the AWS region to be used.
  17235. example: ap-south-1
  17236. maxLength: 50
  17237. minLength: 1
  17238. pattern: ^[a-z0-9-]+$
  17239. type: string
  17240. required:
  17241. - awsCredentialsSecretRef
  17242. - region
  17243. type: object
  17244. credConfig:
  17245. description: |-
  17246. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  17247. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  17248. serviceAccountRef must be used by providing operators service account details.
  17249. properties:
  17250. key:
  17251. description: key name holding the external account credential config.
  17252. maxLength: 253
  17253. minLength: 1
  17254. pattern: ^[-._a-zA-Z0-9]+$
  17255. type: string
  17256. name:
  17257. description: name of the configmap.
  17258. maxLength: 253
  17259. minLength: 1
  17260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17261. type: string
  17262. namespace:
  17263. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  17264. maxLength: 63
  17265. minLength: 1
  17266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17267. type: string
  17268. required:
  17269. - key
  17270. - name
  17271. type: object
  17272. externalTokenEndpoint:
  17273. description: |-
  17274. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  17275. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  17276. URL is having the expected value.
  17277. type: string
  17278. gcpServiceAccountEmail:
  17279. description: |-
  17280. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  17281. after Workload Identity Federation. Use this to grant access through the service account's
  17282. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  17283. service_account_impersonation_url in the external account JSON from credConfig;
  17284. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  17285. on that ServiceAccount.
  17286. example: my-gsa@my-project.iam.gserviceaccount.com
  17287. minLength: 1
  17288. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  17289. type: string
  17290. serviceAccountRef:
  17291. description: |-
  17292. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  17293. when Kubernetes is configured as provider in workload identity pool.
  17294. properties:
  17295. audiences:
  17296. description: |-
  17297. Audience specifies the `aud` claim for the service account token
  17298. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17299. then this audiences will be appended to the list
  17300. items:
  17301. type: string
  17302. type: array
  17303. name:
  17304. description: The name of the ServiceAccount resource being referred to.
  17305. maxLength: 253
  17306. minLength: 1
  17307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17308. type: string
  17309. namespace:
  17310. description: |-
  17311. Namespace of the resource being referred to.
  17312. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17313. maxLength: 63
  17314. minLength: 1
  17315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17316. type: string
  17317. required:
  17318. - name
  17319. type: object
  17320. type: object
  17321. type: object
  17322. location:
  17323. description: Location optionally defines a location for a secret
  17324. type: string
  17325. projectID:
  17326. description: ProjectID project where secret is located
  17327. type: string
  17328. secretVersionSelectionPolicy:
  17329. default: LatestOrFail
  17330. description: |-
  17331. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  17332. when "latest" is disabled or destroyed.
  17333. Possible values are:
  17334. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  17335. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  17336. type: string
  17337. type: object
  17338. github:
  17339. description: |-
  17340. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  17341. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  17342. properties:
  17343. appID:
  17344. description: appID specifies the Github APP that will be used to authenticate the client
  17345. format: int64
  17346. type: integer
  17347. auth:
  17348. description: auth configures how secret-manager authenticates with a Github instance.
  17349. properties:
  17350. privateKey:
  17351. description: |-
  17352. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17353. In some instances, `key` is a required field.
  17354. properties:
  17355. key:
  17356. description: |-
  17357. A key in the referenced Secret.
  17358. Some instances of this field may be defaulted, in others it may be required.
  17359. maxLength: 253
  17360. minLength: 1
  17361. pattern: ^[-._a-zA-Z0-9]+$
  17362. type: string
  17363. name:
  17364. description: The name of the Secret resource being referred to.
  17365. maxLength: 253
  17366. minLength: 1
  17367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17368. type: string
  17369. namespace:
  17370. description: |-
  17371. The namespace of the Secret resource being referred to.
  17372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17373. maxLength: 63
  17374. minLength: 1
  17375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17376. type: string
  17377. type: object
  17378. required:
  17379. - privateKey
  17380. type: object
  17381. environment:
  17382. description: environment will be used to fetch secrets from a particular environment within a github repository
  17383. type: string
  17384. installationID:
  17385. description: installationID specifies the Github APP installation that will be used to authenticate the client
  17386. format: int64
  17387. type: integer
  17388. orgSecretVisibility:
  17389. description: |-
  17390. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  17391. Valid values are "all" or "private".
  17392. When unset, new secrets are created with visibility "all" and existing secrets preserve
  17393. whatever visibility they already have in GitHub.
  17394. enum:
  17395. - all
  17396. - private
  17397. type: string
  17398. organization:
  17399. description: organization will be used to fetch secrets from the Github organization
  17400. type: string
  17401. repository:
  17402. description: repository will be used to fetch secrets from the Github repository within an organization
  17403. type: string
  17404. uploadURL:
  17405. description: Upload URL for enterprise instances. Default to URL.
  17406. type: string
  17407. url:
  17408. default: https://github.com/
  17409. description: URL configures the Github instance URL. Defaults to https://github.com/.
  17410. type: string
  17411. required:
  17412. - appID
  17413. - auth
  17414. - installationID
  17415. - organization
  17416. type: object
  17417. gitlab:
  17418. description: GitLab configures this store to sync secrets using GitLab Variables provider
  17419. properties:
  17420. auth:
  17421. description: Auth configures how secret-manager authenticates with a GitLab instance.
  17422. properties:
  17423. SecretRef:
  17424. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  17425. properties:
  17426. accessToken:
  17427. description: AccessToken is used for authentication.
  17428. properties:
  17429. key:
  17430. description: |-
  17431. A key in the referenced Secret.
  17432. Some instances of this field may be defaulted, in others it may be required.
  17433. maxLength: 253
  17434. minLength: 1
  17435. pattern: ^[-._a-zA-Z0-9]+$
  17436. type: string
  17437. name:
  17438. description: The name of the Secret resource being referred to.
  17439. maxLength: 253
  17440. minLength: 1
  17441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17442. type: string
  17443. namespace:
  17444. description: |-
  17445. The namespace of the Secret resource being referred to.
  17446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17447. maxLength: 63
  17448. minLength: 1
  17449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17450. type: string
  17451. type: object
  17452. type: object
  17453. required:
  17454. - SecretRef
  17455. type: object
  17456. caBundle:
  17457. description: |-
  17458. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  17459. can be performed.
  17460. format: byte
  17461. type: string
  17462. caProvider:
  17463. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17464. properties:
  17465. key:
  17466. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17467. maxLength: 253
  17468. minLength: 1
  17469. pattern: ^[-._a-zA-Z0-9]+$
  17470. type: string
  17471. name:
  17472. description: The name of the object located at the provider type.
  17473. maxLength: 253
  17474. minLength: 1
  17475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17476. type: string
  17477. namespace:
  17478. description: |-
  17479. The namespace the Provider type is in.
  17480. Can only be defined when used in a ClusterSecretStore.
  17481. maxLength: 63
  17482. minLength: 1
  17483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17484. type: string
  17485. type:
  17486. description: The type of provider to use such as "Secret", or "ConfigMap".
  17487. enum:
  17488. - Secret
  17489. - ConfigMap
  17490. type: string
  17491. required:
  17492. - name
  17493. - type
  17494. type: object
  17495. environment:
  17496. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  17497. type: string
  17498. groupIDs:
  17499. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  17500. items:
  17501. type: string
  17502. type: array
  17503. inheritFromGroups:
  17504. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  17505. type: boolean
  17506. projectID:
  17507. description: ProjectID specifies a project where secrets are located.
  17508. type: string
  17509. url:
  17510. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  17511. type: string
  17512. required:
  17513. - auth
  17514. type: object
  17515. ibm:
  17516. description: IBM configures this store to sync secrets using IBM Cloud provider
  17517. properties:
  17518. auth:
  17519. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  17520. maxProperties: 1
  17521. minProperties: 1
  17522. properties:
  17523. containerAuth:
  17524. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  17525. properties:
  17526. iamEndpoint:
  17527. type: string
  17528. profile:
  17529. description: the IBM Trusted Profile
  17530. type: string
  17531. tokenLocation:
  17532. description: Location the token is mounted on the pod
  17533. type: string
  17534. required:
  17535. - profile
  17536. type: object
  17537. secretRef:
  17538. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  17539. properties:
  17540. iamEndpoint:
  17541. description: The IAM endpoint used to obain a token
  17542. type: string
  17543. secretApiKeySecretRef:
  17544. description: The SecretAccessKey is used for authentication
  17545. properties:
  17546. key:
  17547. description: |-
  17548. A key in the referenced Secret.
  17549. Some instances of this field may be defaulted, in others it may be required.
  17550. maxLength: 253
  17551. minLength: 1
  17552. pattern: ^[-._a-zA-Z0-9]+$
  17553. type: string
  17554. name:
  17555. description: The name of the Secret resource being referred to.
  17556. maxLength: 253
  17557. minLength: 1
  17558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17559. type: string
  17560. namespace:
  17561. description: |-
  17562. The namespace of the Secret resource being referred to.
  17563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17564. maxLength: 63
  17565. minLength: 1
  17566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17567. type: string
  17568. type: object
  17569. type: object
  17570. type: object
  17571. serviceUrl:
  17572. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  17573. type: string
  17574. required:
  17575. - auth
  17576. type: object
  17577. infisical:
  17578. description: Infisical configures this store to sync secrets using the Infisical provider
  17579. properties:
  17580. auth:
  17581. description: Auth configures how the Operator authenticates with the Infisical API
  17582. properties:
  17583. awsAuthCredentials:
  17584. description: AwsAuthCredentials represents the credentials for AWS authentication.
  17585. properties:
  17586. identityId:
  17587. description: |-
  17588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17589. In some instances, `key` is a required field.
  17590. properties:
  17591. key:
  17592. description: |-
  17593. A key in the referenced Secret.
  17594. Some instances of this field may be defaulted, in others it may be required.
  17595. maxLength: 253
  17596. minLength: 1
  17597. pattern: ^[-._a-zA-Z0-9]+$
  17598. type: string
  17599. name:
  17600. description: The name of the Secret resource being referred to.
  17601. maxLength: 253
  17602. minLength: 1
  17603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17604. type: string
  17605. namespace:
  17606. description: |-
  17607. The namespace of the Secret resource being referred to.
  17608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17609. maxLength: 63
  17610. minLength: 1
  17611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17612. type: string
  17613. type: object
  17614. required:
  17615. - identityId
  17616. type: object
  17617. azureAuthCredentials:
  17618. description: AzureAuthCredentials represents the credentials for Azure authentication.
  17619. properties:
  17620. identityId:
  17621. description: |-
  17622. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17623. In some instances, `key` is a required field.
  17624. properties:
  17625. key:
  17626. description: |-
  17627. A key in the referenced Secret.
  17628. Some instances of this field may be defaulted, in others it may be required.
  17629. maxLength: 253
  17630. minLength: 1
  17631. pattern: ^[-._a-zA-Z0-9]+$
  17632. type: string
  17633. name:
  17634. description: The name of the Secret resource being referred to.
  17635. maxLength: 253
  17636. minLength: 1
  17637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17638. type: string
  17639. namespace:
  17640. description: |-
  17641. The namespace of the Secret resource being referred to.
  17642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17643. maxLength: 63
  17644. minLength: 1
  17645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17646. type: string
  17647. type: object
  17648. resource:
  17649. description: |-
  17650. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17651. In some instances, `key` is a required field.
  17652. properties:
  17653. key:
  17654. description: |-
  17655. A key in the referenced Secret.
  17656. Some instances of this field may be defaulted, in others it may be required.
  17657. maxLength: 253
  17658. minLength: 1
  17659. pattern: ^[-._a-zA-Z0-9]+$
  17660. type: string
  17661. name:
  17662. description: The name of the Secret resource being referred to.
  17663. maxLength: 253
  17664. minLength: 1
  17665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17666. type: string
  17667. namespace:
  17668. description: |-
  17669. The namespace of the Secret resource being referred to.
  17670. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17671. maxLength: 63
  17672. minLength: 1
  17673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17674. type: string
  17675. type: object
  17676. required:
  17677. - identityId
  17678. type: object
  17679. gcpIamAuthCredentials:
  17680. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  17681. properties:
  17682. identityId:
  17683. description: |-
  17684. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17685. In some instances, `key` is a required field.
  17686. properties:
  17687. key:
  17688. description: |-
  17689. A key in the referenced Secret.
  17690. Some instances of this field may be defaulted, in others it may be required.
  17691. maxLength: 253
  17692. minLength: 1
  17693. pattern: ^[-._a-zA-Z0-9]+$
  17694. type: string
  17695. name:
  17696. description: The name of the Secret resource being referred to.
  17697. maxLength: 253
  17698. minLength: 1
  17699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17700. type: string
  17701. namespace:
  17702. description: |-
  17703. The namespace of the Secret resource being referred to.
  17704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17705. maxLength: 63
  17706. minLength: 1
  17707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17708. type: string
  17709. type: object
  17710. serviceAccountKeyFilePath:
  17711. description: |-
  17712. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17713. In some instances, `key` is a required field.
  17714. properties:
  17715. key:
  17716. description: |-
  17717. A key in the referenced Secret.
  17718. Some instances of this field may be defaulted, in others it may be required.
  17719. maxLength: 253
  17720. minLength: 1
  17721. pattern: ^[-._a-zA-Z0-9]+$
  17722. type: string
  17723. name:
  17724. description: The name of the Secret resource being referred to.
  17725. maxLength: 253
  17726. minLength: 1
  17727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17728. type: string
  17729. namespace:
  17730. description: |-
  17731. The namespace of the Secret resource being referred to.
  17732. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17733. maxLength: 63
  17734. minLength: 1
  17735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17736. type: string
  17737. type: object
  17738. required:
  17739. - identityId
  17740. - serviceAccountKeyFilePath
  17741. type: object
  17742. gcpIdTokenAuthCredentials:
  17743. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  17744. properties:
  17745. identityId:
  17746. description: |-
  17747. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17748. In some instances, `key` is a required field.
  17749. properties:
  17750. key:
  17751. description: |-
  17752. A key in the referenced Secret.
  17753. Some instances of this field may be defaulted, in others it may be required.
  17754. maxLength: 253
  17755. minLength: 1
  17756. pattern: ^[-._a-zA-Z0-9]+$
  17757. type: string
  17758. name:
  17759. description: The name of the Secret resource being referred to.
  17760. maxLength: 253
  17761. minLength: 1
  17762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17763. type: string
  17764. namespace:
  17765. description: |-
  17766. The namespace of the Secret resource being referred to.
  17767. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17768. maxLength: 63
  17769. minLength: 1
  17770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17771. type: string
  17772. type: object
  17773. required:
  17774. - identityId
  17775. type: object
  17776. jwtAuthCredentials:
  17777. description: JwtAuthCredentials represents the credentials for JWT authentication.
  17778. properties:
  17779. identityId:
  17780. description: |-
  17781. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17782. In some instances, `key` is a required field.
  17783. properties:
  17784. key:
  17785. description: |-
  17786. A key in the referenced Secret.
  17787. Some instances of this field may be defaulted, in others it may be required.
  17788. maxLength: 253
  17789. minLength: 1
  17790. pattern: ^[-._a-zA-Z0-9]+$
  17791. type: string
  17792. name:
  17793. description: The name of the Secret resource being referred to.
  17794. maxLength: 253
  17795. minLength: 1
  17796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17797. type: string
  17798. namespace:
  17799. description: |-
  17800. The namespace of the Secret resource being referred to.
  17801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17802. maxLength: 63
  17803. minLength: 1
  17804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17805. type: string
  17806. type: object
  17807. jwt:
  17808. description: |-
  17809. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17810. In some instances, `key` is a required field.
  17811. properties:
  17812. key:
  17813. description: |-
  17814. A key in the referenced Secret.
  17815. Some instances of this field may be defaulted, in others it may be required.
  17816. maxLength: 253
  17817. minLength: 1
  17818. pattern: ^[-._a-zA-Z0-9]+$
  17819. type: string
  17820. name:
  17821. description: The name of the Secret resource being referred to.
  17822. maxLength: 253
  17823. minLength: 1
  17824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17825. type: string
  17826. namespace:
  17827. description: |-
  17828. The namespace of the Secret resource being referred to.
  17829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17830. maxLength: 63
  17831. minLength: 1
  17832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17833. type: string
  17834. type: object
  17835. required:
  17836. - identityId
  17837. - jwt
  17838. type: object
  17839. kubernetesAuthCredentials:
  17840. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  17841. properties:
  17842. identityId:
  17843. description: |-
  17844. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17845. In some instances, `key` is a required field.
  17846. properties:
  17847. key:
  17848. description: |-
  17849. A key in the referenced Secret.
  17850. Some instances of this field may be defaulted, in others it may be required.
  17851. maxLength: 253
  17852. minLength: 1
  17853. pattern: ^[-._a-zA-Z0-9]+$
  17854. type: string
  17855. name:
  17856. description: The name of the Secret resource being referred to.
  17857. maxLength: 253
  17858. minLength: 1
  17859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17860. type: string
  17861. namespace:
  17862. description: |-
  17863. The namespace of the Secret resource being referred to.
  17864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17865. maxLength: 63
  17866. minLength: 1
  17867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17868. type: string
  17869. type: object
  17870. serviceAccountTokenPath:
  17871. description: |-
  17872. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17873. In some instances, `key` is a required field.
  17874. properties:
  17875. key:
  17876. description: |-
  17877. A key in the referenced Secret.
  17878. Some instances of this field may be defaulted, in others it may be required.
  17879. maxLength: 253
  17880. minLength: 1
  17881. pattern: ^[-._a-zA-Z0-9]+$
  17882. type: string
  17883. name:
  17884. description: The name of the Secret resource being referred to.
  17885. maxLength: 253
  17886. minLength: 1
  17887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17888. type: string
  17889. namespace:
  17890. description: |-
  17891. The namespace of the Secret resource being referred to.
  17892. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17893. maxLength: 63
  17894. minLength: 1
  17895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17896. type: string
  17897. type: object
  17898. required:
  17899. - identityId
  17900. type: object
  17901. ldapAuthCredentials:
  17902. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  17903. properties:
  17904. identityId:
  17905. description: |-
  17906. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17907. In some instances, `key` is a required field.
  17908. properties:
  17909. key:
  17910. description: |-
  17911. A key in the referenced Secret.
  17912. Some instances of this field may be defaulted, in others it may be required.
  17913. maxLength: 253
  17914. minLength: 1
  17915. pattern: ^[-._a-zA-Z0-9]+$
  17916. type: string
  17917. name:
  17918. description: The name of the Secret resource being referred to.
  17919. maxLength: 253
  17920. minLength: 1
  17921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17922. type: string
  17923. namespace:
  17924. description: |-
  17925. The namespace of the Secret resource being referred to.
  17926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17927. maxLength: 63
  17928. minLength: 1
  17929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17930. type: string
  17931. type: object
  17932. ldapPassword:
  17933. description: |-
  17934. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17935. In some instances, `key` is a required field.
  17936. properties:
  17937. key:
  17938. description: |-
  17939. A key in the referenced Secret.
  17940. Some instances of this field may be defaulted, in others it may be required.
  17941. maxLength: 253
  17942. minLength: 1
  17943. pattern: ^[-._a-zA-Z0-9]+$
  17944. type: string
  17945. name:
  17946. description: The name of the Secret resource being referred to.
  17947. maxLength: 253
  17948. minLength: 1
  17949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17950. type: string
  17951. namespace:
  17952. description: |-
  17953. The namespace of the Secret resource being referred to.
  17954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17955. maxLength: 63
  17956. minLength: 1
  17957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17958. type: string
  17959. type: object
  17960. ldapUsername:
  17961. description: |-
  17962. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17963. In some instances, `key` is a required field.
  17964. properties:
  17965. key:
  17966. description: |-
  17967. A key in the referenced Secret.
  17968. Some instances of this field may be defaulted, in others it may be required.
  17969. maxLength: 253
  17970. minLength: 1
  17971. pattern: ^[-._a-zA-Z0-9]+$
  17972. type: string
  17973. name:
  17974. description: The name of the Secret resource being referred to.
  17975. maxLength: 253
  17976. minLength: 1
  17977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17978. type: string
  17979. namespace:
  17980. description: |-
  17981. The namespace of the Secret resource being referred to.
  17982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17983. maxLength: 63
  17984. minLength: 1
  17985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17986. type: string
  17987. type: object
  17988. required:
  17989. - identityId
  17990. - ldapPassword
  17991. - ldapUsername
  17992. type: object
  17993. ociAuthCredentials:
  17994. description: OciAuthCredentials represents the credentials for OCI authentication.
  17995. properties:
  17996. fingerprint:
  17997. description: |-
  17998. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17999. In some instances, `key` is a required field.
  18000. properties:
  18001. key:
  18002. description: |-
  18003. A key in the referenced Secret.
  18004. Some instances of this field may be defaulted, in others it may be required.
  18005. maxLength: 253
  18006. minLength: 1
  18007. pattern: ^[-._a-zA-Z0-9]+$
  18008. type: string
  18009. name:
  18010. description: The name of the Secret resource being referred to.
  18011. maxLength: 253
  18012. minLength: 1
  18013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18014. type: string
  18015. namespace:
  18016. description: |-
  18017. The namespace of the Secret resource being referred to.
  18018. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18019. maxLength: 63
  18020. minLength: 1
  18021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18022. type: string
  18023. type: object
  18024. identityId:
  18025. description: |-
  18026. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18027. In some instances, `key` is a required field.
  18028. properties:
  18029. key:
  18030. description: |-
  18031. A key in the referenced Secret.
  18032. Some instances of this field may be defaulted, in others it may be required.
  18033. maxLength: 253
  18034. minLength: 1
  18035. pattern: ^[-._a-zA-Z0-9]+$
  18036. type: string
  18037. name:
  18038. description: The name of the Secret resource being referred to.
  18039. maxLength: 253
  18040. minLength: 1
  18041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18042. type: string
  18043. namespace:
  18044. description: |-
  18045. The namespace of the Secret resource being referred to.
  18046. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18047. maxLength: 63
  18048. minLength: 1
  18049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18050. type: string
  18051. type: object
  18052. privateKey:
  18053. description: |-
  18054. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18055. In some instances, `key` is a required field.
  18056. properties:
  18057. key:
  18058. description: |-
  18059. A key in the referenced Secret.
  18060. Some instances of this field may be defaulted, in others it may be required.
  18061. maxLength: 253
  18062. minLength: 1
  18063. pattern: ^[-._a-zA-Z0-9]+$
  18064. type: string
  18065. name:
  18066. description: The name of the Secret resource being referred to.
  18067. maxLength: 253
  18068. minLength: 1
  18069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18070. type: string
  18071. namespace:
  18072. description: |-
  18073. The namespace of the Secret resource being referred to.
  18074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18075. maxLength: 63
  18076. minLength: 1
  18077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18078. type: string
  18079. type: object
  18080. privateKeyPassphrase:
  18081. description: |-
  18082. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18083. In some instances, `key` is a required field.
  18084. properties:
  18085. key:
  18086. description: |-
  18087. A key in the referenced Secret.
  18088. Some instances of this field may be defaulted, in others it may be required.
  18089. maxLength: 253
  18090. minLength: 1
  18091. pattern: ^[-._a-zA-Z0-9]+$
  18092. type: string
  18093. name:
  18094. description: The name of the Secret resource being referred to.
  18095. maxLength: 253
  18096. minLength: 1
  18097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18098. type: string
  18099. namespace:
  18100. description: |-
  18101. The namespace of the Secret resource being referred to.
  18102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18103. maxLength: 63
  18104. minLength: 1
  18105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18106. type: string
  18107. type: object
  18108. region:
  18109. description: |-
  18110. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18111. In some instances, `key` is a required field.
  18112. properties:
  18113. key:
  18114. description: |-
  18115. A key in the referenced Secret.
  18116. Some instances of this field may be defaulted, in others it may be required.
  18117. maxLength: 253
  18118. minLength: 1
  18119. pattern: ^[-._a-zA-Z0-9]+$
  18120. type: string
  18121. name:
  18122. description: The name of the Secret resource being referred to.
  18123. maxLength: 253
  18124. minLength: 1
  18125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18126. type: string
  18127. namespace:
  18128. description: |-
  18129. The namespace of the Secret resource being referred to.
  18130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18131. maxLength: 63
  18132. minLength: 1
  18133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18134. type: string
  18135. type: object
  18136. tenancyId:
  18137. description: |-
  18138. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18139. In some instances, `key` is a required field.
  18140. properties:
  18141. key:
  18142. description: |-
  18143. A key in the referenced Secret.
  18144. Some instances of this field may be defaulted, in others it may be required.
  18145. maxLength: 253
  18146. minLength: 1
  18147. pattern: ^[-._a-zA-Z0-9]+$
  18148. type: string
  18149. name:
  18150. description: The name of the Secret resource being referred to.
  18151. maxLength: 253
  18152. minLength: 1
  18153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18154. type: string
  18155. namespace:
  18156. description: |-
  18157. The namespace of the Secret resource being referred to.
  18158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18159. maxLength: 63
  18160. minLength: 1
  18161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18162. type: string
  18163. type: object
  18164. userId:
  18165. description: |-
  18166. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18167. In some instances, `key` is a required field.
  18168. properties:
  18169. key:
  18170. description: |-
  18171. A key in the referenced Secret.
  18172. Some instances of this field may be defaulted, in others it may be required.
  18173. maxLength: 253
  18174. minLength: 1
  18175. pattern: ^[-._a-zA-Z0-9]+$
  18176. type: string
  18177. name:
  18178. description: The name of the Secret resource being referred to.
  18179. maxLength: 253
  18180. minLength: 1
  18181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18182. type: string
  18183. namespace:
  18184. description: |-
  18185. The namespace of the Secret resource being referred to.
  18186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18187. maxLength: 63
  18188. minLength: 1
  18189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18190. type: string
  18191. type: object
  18192. required:
  18193. - fingerprint
  18194. - identityId
  18195. - privateKey
  18196. - region
  18197. - tenancyId
  18198. - userId
  18199. type: object
  18200. tokenAuthCredentials:
  18201. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18202. properties:
  18203. accessToken:
  18204. description: |-
  18205. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18206. In some instances, `key` is a required field.
  18207. properties:
  18208. key:
  18209. description: |-
  18210. A key in the referenced Secret.
  18211. Some instances of this field may be defaulted, in others it may be required.
  18212. maxLength: 253
  18213. minLength: 1
  18214. pattern: ^[-._a-zA-Z0-9]+$
  18215. type: string
  18216. name:
  18217. description: The name of the Secret resource being referred to.
  18218. maxLength: 253
  18219. minLength: 1
  18220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18221. type: string
  18222. namespace:
  18223. description: |-
  18224. The namespace of the Secret resource being referred to.
  18225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18226. maxLength: 63
  18227. minLength: 1
  18228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18229. type: string
  18230. type: object
  18231. required:
  18232. - accessToken
  18233. type: object
  18234. universalAuthCredentials:
  18235. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  18236. properties:
  18237. clientId:
  18238. description: |-
  18239. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18240. In some instances, `key` is a required field.
  18241. properties:
  18242. key:
  18243. description: |-
  18244. A key in the referenced Secret.
  18245. Some instances of this field may be defaulted, in others it may be required.
  18246. maxLength: 253
  18247. minLength: 1
  18248. pattern: ^[-._a-zA-Z0-9]+$
  18249. type: string
  18250. name:
  18251. description: The name of the Secret resource being referred to.
  18252. maxLength: 253
  18253. minLength: 1
  18254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18255. type: string
  18256. namespace:
  18257. description: |-
  18258. The namespace of the Secret resource being referred to.
  18259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18260. maxLength: 63
  18261. minLength: 1
  18262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18263. type: string
  18264. type: object
  18265. clientSecret:
  18266. description: |-
  18267. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18268. In some instances, `key` is a required field.
  18269. properties:
  18270. key:
  18271. description: |-
  18272. A key in the referenced Secret.
  18273. Some instances of this field may be defaulted, in others it may be required.
  18274. maxLength: 253
  18275. minLength: 1
  18276. pattern: ^[-._a-zA-Z0-9]+$
  18277. type: string
  18278. name:
  18279. description: The name of the Secret resource being referred to.
  18280. maxLength: 253
  18281. minLength: 1
  18282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18283. type: string
  18284. namespace:
  18285. description: |-
  18286. The namespace of the Secret resource being referred to.
  18287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18288. maxLength: 63
  18289. minLength: 1
  18290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18291. type: string
  18292. type: object
  18293. required:
  18294. - clientId
  18295. - clientSecret
  18296. type: object
  18297. type: object
  18298. caBundle:
  18299. description: |-
  18300. CABundle is a PEM-encoded CA certificate bundle used to validate
  18301. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  18302. format: byte
  18303. type: string
  18304. caProvider:
  18305. description: |-
  18306. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  18307. The certificate is used to validate the Infisical server's TLS certificate.
  18308. Mutually exclusive with CABundle.
  18309. properties:
  18310. key:
  18311. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18312. maxLength: 253
  18313. minLength: 1
  18314. pattern: ^[-._a-zA-Z0-9]+$
  18315. type: string
  18316. name:
  18317. description: The name of the object located at the provider type.
  18318. maxLength: 253
  18319. minLength: 1
  18320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18321. type: string
  18322. namespace:
  18323. description: |-
  18324. The namespace the Provider type is in.
  18325. Can only be defined when used in a ClusterSecretStore.
  18326. maxLength: 63
  18327. minLength: 1
  18328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18329. type: string
  18330. type:
  18331. description: The type of provider to use such as "Secret", or "ConfigMap".
  18332. enum:
  18333. - Secret
  18334. - ConfigMap
  18335. type: string
  18336. required:
  18337. - name
  18338. - type
  18339. type: object
  18340. hostAPI:
  18341. default: https://app.infisical.com/api
  18342. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  18343. type: string
  18344. secretsScope:
  18345. description: SecretsScope defines the scope of the secrets within the workspace
  18346. properties:
  18347. environmentSlug:
  18348. description: EnvironmentSlug is the required slug identifier for the environment.
  18349. type: string
  18350. expandSecretReferences:
  18351. default: true
  18352. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  18353. type: boolean
  18354. organizationSlug:
  18355. description: |-
  18356. OrganizationSlug is the optional slug that identifies the organization that will be used
  18357. during authentication. Useful for sub-organization setups
  18358. type: string
  18359. projectSlug:
  18360. description: ProjectSlug is the required slug identifier for the project.
  18361. type: string
  18362. recursive:
  18363. default: false
  18364. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  18365. type: boolean
  18366. secretsPath:
  18367. default: /
  18368. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  18369. type: string
  18370. required:
  18371. - environmentSlug
  18372. - projectSlug
  18373. type: object
  18374. required:
  18375. - auth
  18376. - secretsScope
  18377. type: object
  18378. keepersecurity:
  18379. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  18380. properties:
  18381. authRef:
  18382. description: |-
  18383. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18384. In some instances, `key` is a required field.
  18385. properties:
  18386. key:
  18387. description: |-
  18388. A key in the referenced Secret.
  18389. Some instances of this field may be defaulted, in others it may be required.
  18390. maxLength: 253
  18391. minLength: 1
  18392. pattern: ^[-._a-zA-Z0-9]+$
  18393. type: string
  18394. name:
  18395. description: The name of the Secret resource being referred to.
  18396. maxLength: 253
  18397. minLength: 1
  18398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18399. type: string
  18400. namespace:
  18401. description: |-
  18402. The namespace of the Secret resource being referred to.
  18403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18404. maxLength: 63
  18405. minLength: 1
  18406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18407. type: string
  18408. type: object
  18409. folderID:
  18410. type: string
  18411. getByTitleFallback:
  18412. type: boolean
  18413. required:
  18414. - authRef
  18415. - folderID
  18416. type: object
  18417. kubernetes:
  18418. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  18419. properties:
  18420. auth:
  18421. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  18422. maxProperties: 1
  18423. minProperties: 1
  18424. properties:
  18425. cert:
  18426. description: has both clientCert and clientKey as secretKeySelector
  18427. properties:
  18428. clientCert:
  18429. description: |-
  18430. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18431. In some instances, `key` is a required field.
  18432. properties:
  18433. key:
  18434. description: |-
  18435. A key in the referenced Secret.
  18436. Some instances of this field may be defaulted, in others it may be required.
  18437. maxLength: 253
  18438. minLength: 1
  18439. pattern: ^[-._a-zA-Z0-9]+$
  18440. type: string
  18441. name:
  18442. description: The name of the Secret resource being referred to.
  18443. maxLength: 253
  18444. minLength: 1
  18445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18446. type: string
  18447. namespace:
  18448. description: |-
  18449. The namespace of the Secret resource being referred to.
  18450. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18451. maxLength: 63
  18452. minLength: 1
  18453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18454. type: string
  18455. type: object
  18456. clientKey:
  18457. description: |-
  18458. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18459. In some instances, `key` is a required field.
  18460. properties:
  18461. key:
  18462. description: |-
  18463. A key in the referenced Secret.
  18464. Some instances of this field may be defaulted, in others it may be required.
  18465. maxLength: 253
  18466. minLength: 1
  18467. pattern: ^[-._a-zA-Z0-9]+$
  18468. type: string
  18469. name:
  18470. description: The name of the Secret resource being referred to.
  18471. maxLength: 253
  18472. minLength: 1
  18473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18474. type: string
  18475. namespace:
  18476. description: |-
  18477. The namespace of the Secret resource being referred to.
  18478. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18479. maxLength: 63
  18480. minLength: 1
  18481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18482. type: string
  18483. type: object
  18484. type: object
  18485. serviceAccount:
  18486. description: points to a service account that should be used for authentication
  18487. properties:
  18488. audiences:
  18489. description: |-
  18490. Audience specifies the `aud` claim for the service account token
  18491. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18492. then this audiences will be appended to the list
  18493. items:
  18494. type: string
  18495. type: array
  18496. name:
  18497. description: The name of the ServiceAccount resource being referred to.
  18498. maxLength: 253
  18499. minLength: 1
  18500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18501. type: string
  18502. namespace:
  18503. description: |-
  18504. Namespace of the resource being referred to.
  18505. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18506. maxLength: 63
  18507. minLength: 1
  18508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18509. type: string
  18510. required:
  18511. - name
  18512. type: object
  18513. token:
  18514. description: use static token to authenticate with
  18515. properties:
  18516. bearerToken:
  18517. description: |-
  18518. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18519. In some instances, `key` is a required field.
  18520. properties:
  18521. key:
  18522. description: |-
  18523. A key in the referenced Secret.
  18524. Some instances of this field may be defaulted, in others it may be required.
  18525. maxLength: 253
  18526. minLength: 1
  18527. pattern: ^[-._a-zA-Z0-9]+$
  18528. type: string
  18529. name:
  18530. description: The name of the Secret resource being referred to.
  18531. maxLength: 253
  18532. minLength: 1
  18533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18534. type: string
  18535. namespace:
  18536. description: |-
  18537. The namespace of the Secret resource being referred to.
  18538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18539. maxLength: 63
  18540. minLength: 1
  18541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18542. type: string
  18543. type: object
  18544. type: object
  18545. type: object
  18546. authRef:
  18547. description: A reference to a secret that contains the auth information.
  18548. properties:
  18549. key:
  18550. description: |-
  18551. A key in the referenced Secret.
  18552. Some instances of this field may be defaulted, in others it may be required.
  18553. maxLength: 253
  18554. minLength: 1
  18555. pattern: ^[-._a-zA-Z0-9]+$
  18556. type: string
  18557. name:
  18558. description: The name of the Secret resource being referred to.
  18559. maxLength: 253
  18560. minLength: 1
  18561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18562. type: string
  18563. namespace:
  18564. description: |-
  18565. The namespace of the Secret resource being referred to.
  18566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18567. maxLength: 63
  18568. minLength: 1
  18569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18570. type: string
  18571. type: object
  18572. remoteNamespace:
  18573. default: default
  18574. description: Remote namespace to fetch the secrets from
  18575. maxLength: 63
  18576. minLength: 1
  18577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18578. type: string
  18579. server:
  18580. description: configures the Kubernetes server Address.
  18581. properties:
  18582. caBundle:
  18583. description: CABundle is a base64-encoded CA certificate
  18584. format: byte
  18585. type: string
  18586. caProvider:
  18587. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  18588. properties:
  18589. key:
  18590. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18591. maxLength: 253
  18592. minLength: 1
  18593. pattern: ^[-._a-zA-Z0-9]+$
  18594. type: string
  18595. name:
  18596. description: The name of the object located at the provider type.
  18597. maxLength: 253
  18598. minLength: 1
  18599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18600. type: string
  18601. namespace:
  18602. description: |-
  18603. The namespace the Provider type is in.
  18604. Can only be defined when used in a ClusterSecretStore.
  18605. maxLength: 63
  18606. minLength: 1
  18607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18608. type: string
  18609. type:
  18610. description: The type of provider to use such as "Secret", or "ConfigMap".
  18611. enum:
  18612. - Secret
  18613. - ConfigMap
  18614. type: string
  18615. required:
  18616. - name
  18617. - type
  18618. type: object
  18619. url:
  18620. default: kubernetes.default
  18621. description: configures the Kubernetes server Address.
  18622. type: string
  18623. type: object
  18624. type: object
  18625. nebiusmysterybox:
  18626. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  18627. properties:
  18628. apiDomain:
  18629. description: NebiusMysterybox API endpoint
  18630. type: string
  18631. auth:
  18632. description: Auth defines parameters to authenticate in MysteryBox
  18633. properties:
  18634. serviceAccountCredsSecretRef:
  18635. description: |-
  18636. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  18637. document with service account credentials used to get an IAM token.
  18638. Expected JSON structure:
  18639. {
  18640. "subject-credentials": {
  18641. "alg": "RS256",
  18642. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  18643. "kid": "<public-key-id>",
  18644. "iss": "<issuer-service-account-id>",
  18645. "sub": "<subject-service-account-id>"
  18646. }
  18647. }
  18648. properties:
  18649. key:
  18650. description: |-
  18651. A key in the referenced Secret.
  18652. Some instances of this field may be defaulted, in others it may be required.
  18653. maxLength: 253
  18654. minLength: 1
  18655. pattern: ^[-._a-zA-Z0-9]+$
  18656. type: string
  18657. name:
  18658. description: The name of the Secret resource being referred to.
  18659. maxLength: 253
  18660. minLength: 1
  18661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18662. type: string
  18663. namespace:
  18664. description: |-
  18665. The namespace of the Secret resource being referred to.
  18666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18667. maxLength: 63
  18668. minLength: 1
  18669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18670. type: string
  18671. type: object
  18672. tokenSecretRef:
  18673. description: Token authenticates with Nebius Mysterybox by presenting a token.
  18674. properties:
  18675. key:
  18676. description: |-
  18677. A key in the referenced Secret.
  18678. Some instances of this field may be defaulted, in others it may be required.
  18679. maxLength: 253
  18680. minLength: 1
  18681. pattern: ^[-._a-zA-Z0-9]+$
  18682. type: string
  18683. name:
  18684. description: The name of the Secret resource being referred to.
  18685. maxLength: 253
  18686. minLength: 1
  18687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18688. type: string
  18689. namespace:
  18690. description: |-
  18691. The namespace of the Secret resource being referred to.
  18692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18693. maxLength: 63
  18694. minLength: 1
  18695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18696. type: string
  18697. type: object
  18698. type: object
  18699. x-kubernetes-validations:
  18700. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  18701. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  18702. caProvider:
  18703. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  18704. properties:
  18705. certSecretRef:
  18706. description: |-
  18707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18708. In some instances, `key` is a required field.
  18709. properties:
  18710. key:
  18711. description: |-
  18712. A key in the referenced Secret.
  18713. Some instances of this field may be defaulted, in others it may be required.
  18714. maxLength: 253
  18715. minLength: 1
  18716. pattern: ^[-._a-zA-Z0-9]+$
  18717. type: string
  18718. name:
  18719. description: The name of the Secret resource being referred to.
  18720. maxLength: 253
  18721. minLength: 1
  18722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18723. type: string
  18724. namespace:
  18725. description: |-
  18726. The namespace of the Secret resource being referred to.
  18727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18728. maxLength: 63
  18729. minLength: 1
  18730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18731. type: string
  18732. type: object
  18733. type: object
  18734. required:
  18735. - apiDomain
  18736. - auth
  18737. type: object
  18738. ngrok:
  18739. description: Ngrok configures this store to sync secrets using the ngrok provider.
  18740. properties:
  18741. apiUrl:
  18742. default: https://api.ngrok.com
  18743. description: APIURL is the URL of the ngrok API.
  18744. type: string
  18745. auth:
  18746. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  18747. maxProperties: 1
  18748. minProperties: 1
  18749. properties:
  18750. apiKey:
  18751. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  18752. properties:
  18753. secretRef:
  18754. description: SecretRef is a reference to a secret containing the ngrok API key.
  18755. properties:
  18756. key:
  18757. description: |-
  18758. A key in the referenced Secret.
  18759. Some instances of this field may be defaulted, in others it may be required.
  18760. maxLength: 253
  18761. minLength: 1
  18762. pattern: ^[-._a-zA-Z0-9]+$
  18763. type: string
  18764. name:
  18765. description: The name of the Secret resource being referred to.
  18766. maxLength: 253
  18767. minLength: 1
  18768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18769. type: string
  18770. namespace:
  18771. description: |-
  18772. The namespace of the Secret resource being referred to.
  18773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18774. maxLength: 63
  18775. minLength: 1
  18776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18777. type: string
  18778. type: object
  18779. type: object
  18780. type: object
  18781. vault:
  18782. description: Vault configures the ngrok vault to sync secrets with.
  18783. properties:
  18784. name:
  18785. description: Name is the name of the ngrok vault to sync secrets with.
  18786. type: string
  18787. required:
  18788. - name
  18789. type: object
  18790. required:
  18791. - auth
  18792. - vault
  18793. type: object
  18794. onboardbase:
  18795. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  18796. properties:
  18797. apiHost:
  18798. default: https://public.onboardbase.com/api/v1/
  18799. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  18800. type: string
  18801. auth:
  18802. description: Auth configures how the Operator authenticates with the Onboardbase API
  18803. properties:
  18804. apiKeyRef:
  18805. description: |-
  18806. OnboardbaseAPIKey is the APIKey generated by an admin account.
  18807. It is used to recognize and authorize access to a project and environment within onboardbase
  18808. properties:
  18809. key:
  18810. description: |-
  18811. A key in the referenced Secret.
  18812. Some instances of this field may be defaulted, in others it may be required.
  18813. maxLength: 253
  18814. minLength: 1
  18815. pattern: ^[-._a-zA-Z0-9]+$
  18816. type: string
  18817. name:
  18818. description: The name of the Secret resource being referred to.
  18819. maxLength: 253
  18820. minLength: 1
  18821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18822. type: string
  18823. namespace:
  18824. description: |-
  18825. The namespace of the Secret resource being referred to.
  18826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18827. maxLength: 63
  18828. minLength: 1
  18829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18830. type: string
  18831. type: object
  18832. passcodeRef:
  18833. description: OnboardbasePasscode is the passcode attached to the API Key
  18834. properties:
  18835. key:
  18836. description: |-
  18837. A key in the referenced Secret.
  18838. Some instances of this field may be defaulted, in others it may be required.
  18839. maxLength: 253
  18840. minLength: 1
  18841. pattern: ^[-._a-zA-Z0-9]+$
  18842. type: string
  18843. name:
  18844. description: The name of the Secret resource being referred to.
  18845. maxLength: 253
  18846. minLength: 1
  18847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18848. type: string
  18849. namespace:
  18850. description: |-
  18851. The namespace of the Secret resource being referred to.
  18852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18853. maxLength: 63
  18854. minLength: 1
  18855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18856. type: string
  18857. type: object
  18858. required:
  18859. - apiKeyRef
  18860. - passcodeRef
  18861. type: object
  18862. environment:
  18863. default: development
  18864. description: Environment is the name of an environmnent within a project to pull the secrets from
  18865. type: string
  18866. project:
  18867. default: development
  18868. description: Project is an onboardbase project that the secrets should be pulled from
  18869. type: string
  18870. required:
  18871. - apiHost
  18872. - auth
  18873. - environment
  18874. - project
  18875. type: object
  18876. onepassword:
  18877. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  18878. properties:
  18879. auth:
  18880. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  18881. properties:
  18882. secretRef:
  18883. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  18884. properties:
  18885. connectTokenSecretRef:
  18886. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  18887. properties:
  18888. key:
  18889. description: |-
  18890. A key in the referenced Secret.
  18891. Some instances of this field may be defaulted, in others it may be required.
  18892. maxLength: 253
  18893. minLength: 1
  18894. pattern: ^[-._a-zA-Z0-9]+$
  18895. type: string
  18896. name:
  18897. description: The name of the Secret resource being referred to.
  18898. maxLength: 253
  18899. minLength: 1
  18900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18901. type: string
  18902. namespace:
  18903. description: |-
  18904. The namespace of the Secret resource being referred to.
  18905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18906. maxLength: 63
  18907. minLength: 1
  18908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18909. type: string
  18910. type: object
  18911. required:
  18912. - connectTokenSecretRef
  18913. type: object
  18914. required:
  18915. - secretRef
  18916. type: object
  18917. connectHost:
  18918. description: ConnectHost defines the OnePassword Connect Server to connect to
  18919. type: string
  18920. vaults:
  18921. additionalProperties:
  18922. type: integer
  18923. description: Vaults defines which OnePassword vaults to search in which order
  18924. type: object
  18925. required:
  18926. - auth
  18927. - connectHost
  18928. - vaults
  18929. type: object
  18930. onepasswordSDK:
  18931. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  18932. properties:
  18933. auth:
  18934. description: Auth defines the information necessary to authenticate against OnePassword API.
  18935. properties:
  18936. serviceAccountSecretRef:
  18937. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  18938. properties:
  18939. key:
  18940. description: |-
  18941. A key in the referenced Secret.
  18942. Some instances of this field may be defaulted, in others it may be required.
  18943. maxLength: 253
  18944. minLength: 1
  18945. pattern: ^[-._a-zA-Z0-9]+$
  18946. type: string
  18947. name:
  18948. description: The name of the Secret resource being referred to.
  18949. maxLength: 253
  18950. minLength: 1
  18951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18952. type: string
  18953. namespace:
  18954. description: |-
  18955. The namespace of the Secret resource being referred to.
  18956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18957. maxLength: 63
  18958. minLength: 1
  18959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18960. type: string
  18961. type: object
  18962. required:
  18963. - serviceAccountSecretRef
  18964. type: object
  18965. cache:
  18966. description: |-
  18967. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  18968. When enabled, secrets are cached with the specified TTL.
  18969. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  18970. If omitted, caching is disabled (default).
  18971. cache: {} is a valid option to set.
  18972. properties:
  18973. maxSize:
  18974. default: 100
  18975. description: |-
  18976. MaxSize is the maximum number of secrets to cache.
  18977. When the cache is full, least-recently-used entries are evicted.
  18978. minimum: 1
  18979. type: integer
  18980. ttl:
  18981. default: 5m
  18982. description: |-
  18983. TTL is the time-to-live for cached secrets.
  18984. Format: duration string (e.g., "5m", "1h", "30s")
  18985. type: string
  18986. type: object
  18987. integrationInfo:
  18988. description: |-
  18989. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  18990. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  18991. properties:
  18992. name:
  18993. default: 1Password SDK
  18994. description: Name defaults to "1Password SDK".
  18995. type: string
  18996. version:
  18997. default: v1.0.0
  18998. description: Version defaults to "v1.0.0".
  18999. type: string
  19000. type: object
  19001. vault:
  19002. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19003. type: string
  19004. required:
  19005. - auth
  19006. - vault
  19007. type: object
  19008. openBao:
  19009. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19010. properties:
  19011. auth:
  19012. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19013. properties:
  19014. appRole:
  19015. description: |-
  19016. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19017. with the role and secret stored in a Kubernetes Secret resource.
  19018. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19019. properties:
  19020. path:
  19021. default: approle
  19022. description: |-
  19023. Path where the App Role authentication backend is mounted
  19024. in OpenBao, e.g: "approle"
  19025. type: string
  19026. roleId:
  19027. description: |-
  19028. RoleID configured in the App Role authentication backend when setting
  19029. up the authentication backend in OpenBao.
  19030. minLength: 1
  19031. type: string
  19032. roleRef:
  19033. description: |-
  19034. Reference to a key in a Secret that contains the App Role ID used
  19035. to authenticate with OpenBao.
  19036. The `key` field must be specified and denotes which entry within the Secret
  19037. resource is used as the app role id.
  19038. properties:
  19039. key:
  19040. description: |-
  19041. A key in the referenced Secret.
  19042. Some instances of this field may be defaulted, in others it may be required.
  19043. maxLength: 253
  19044. minLength: 1
  19045. pattern: ^[-._a-zA-Z0-9]+$
  19046. type: string
  19047. name:
  19048. description: The name of the Secret resource being referred to.
  19049. maxLength: 253
  19050. minLength: 1
  19051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19052. type: string
  19053. namespace:
  19054. description: |-
  19055. The namespace of the Secret resource being referred to.
  19056. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19057. maxLength: 63
  19058. minLength: 1
  19059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19060. type: string
  19061. type: object
  19062. secretRef:
  19063. description: |-
  19064. Reference to a key in a Secret that contains the App Role secret used
  19065. to authenticate with OpenBao.
  19066. The `key` field must be specified and denotes which entry within the Secret
  19067. resource is used as the app role secret.
  19068. properties:
  19069. key:
  19070. description: |-
  19071. A key in the referenced Secret.
  19072. Some instances of this field may be defaulted, in others it may be required.
  19073. maxLength: 253
  19074. minLength: 1
  19075. pattern: ^[-._a-zA-Z0-9]+$
  19076. type: string
  19077. name:
  19078. description: The name of the Secret resource being referred to.
  19079. maxLength: 253
  19080. minLength: 1
  19081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19082. type: string
  19083. namespace:
  19084. description: |-
  19085. The namespace of the Secret resource being referred to.
  19086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19087. maxLength: 63
  19088. minLength: 1
  19089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19090. type: string
  19091. type: object
  19092. required:
  19093. - path
  19094. - secretRef
  19095. type: object
  19096. x-kubernetes-validations:
  19097. - message: exactly one of the fields in [roleId roleRef] must be set
  19098. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19099. namespace:
  19100. description: |-
  19101. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19102. than the namespace your secret is in. Namespaces is a set of features
  19103. within OpenBao that allows OpenBao environments to support secure
  19104. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19105. if set, or empty otherwise
  19106. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19107. type: string
  19108. tokenSecretRef:
  19109. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19110. properties:
  19111. key:
  19112. description: |-
  19113. A key in the referenced Secret.
  19114. Some instances of this field may be defaulted, in others it may be required.
  19115. maxLength: 253
  19116. minLength: 1
  19117. pattern: ^[-._a-zA-Z0-9]+$
  19118. type: string
  19119. name:
  19120. description: The name of the Secret resource being referred to.
  19121. maxLength: 253
  19122. minLength: 1
  19123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19124. type: string
  19125. namespace:
  19126. description: |-
  19127. The namespace of the Secret resource being referred to.
  19128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19129. maxLength: 63
  19130. minLength: 1
  19131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19132. type: string
  19133. type: object
  19134. userPass:
  19135. description: UserPass authenticates with OpenBao by passing a username/password pair
  19136. properties:
  19137. path:
  19138. default: userpass
  19139. description: |-
  19140. Path where the UserPassword authentication backend is mounted
  19141. in OpenBao, e.g: "userpass"
  19142. type: string
  19143. secretRef:
  19144. description: |-
  19145. SecretRef to a key in a Secret resource containing password for the user
  19146. used to authenticate with OpenBao using the [UserPass authentication
  19147. method]
  19148. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19149. properties:
  19150. key:
  19151. description: |-
  19152. A key in the referenced Secret.
  19153. Some instances of this field may be defaulted, in others it may be required.
  19154. maxLength: 253
  19155. minLength: 1
  19156. pattern: ^[-._a-zA-Z0-9]+$
  19157. type: string
  19158. name:
  19159. description: The name of the Secret resource being referred to.
  19160. maxLength: 253
  19161. minLength: 1
  19162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19163. type: string
  19164. namespace:
  19165. description: |-
  19166. The namespace of the Secret resource being referred to.
  19167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19168. maxLength: 63
  19169. minLength: 1
  19170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19171. type: string
  19172. type: object
  19173. username:
  19174. description: |-
  19175. Username is a username used to authenticate using the [UserPass
  19176. authentication method]
  19177. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19178. type: string
  19179. required:
  19180. - path
  19181. - username
  19182. type: object
  19183. type: object
  19184. x-kubernetes-validations:
  19185. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19186. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19187. caBundle:
  19188. description: |-
  19189. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19190. this and `caProvider` are not set the system root certificates are used
  19191. to validate the TLS connection.
  19192. format: byte
  19193. type: string
  19194. caProvider:
  19195. description: |-
  19196. The provider for the CA bundle to use to validate OpenBao server
  19197. certificate. If this and `caBundle` are not set the system root
  19198. certificates are used to validate the TLS connection.
  19199. properties:
  19200. key:
  19201. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19202. maxLength: 253
  19203. minLength: 1
  19204. pattern: ^[-._a-zA-Z0-9]+$
  19205. type: string
  19206. name:
  19207. description: The name of the object located at the provider type.
  19208. maxLength: 253
  19209. minLength: 1
  19210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19211. type: string
  19212. namespace:
  19213. description: |-
  19214. The namespace the Provider type is in.
  19215. Can only be defined when used in a ClusterSecretStore.
  19216. maxLength: 63
  19217. minLength: 1
  19218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19219. type: string
  19220. type:
  19221. description: The type of provider to use such as "Secret", or "ConfigMap".
  19222. enum:
  19223. - Secret
  19224. - ConfigMap
  19225. type: string
  19226. required:
  19227. - name
  19228. - type
  19229. type: object
  19230. namespace:
  19231. description: |-
  19232. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  19233. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  19234. e.g: "ns1".
  19235. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19236. type: string
  19237. path:
  19238. description: |-
  19239. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  19240. "secret". The v2 KV secret engine version specific "/data" path suffix
  19241. for fetching secrets from OpenBao is optional and will be appended
  19242. if not present in specified path.
  19243. type: string
  19244. server:
  19245. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  19246. type: string
  19247. version:
  19248. default: v2
  19249. description: |-
  19250. Version is the OpenBao KV secret engine version. This can be either "v1" or
  19251. "v2". Version defaults to "v2".
  19252. enum:
  19253. - v1
  19254. - v2
  19255. type: string
  19256. required:
  19257. - server
  19258. type: object
  19259. x-kubernetes-validations:
  19260. - message: at most one of the fields in [caBundle caProvider] may be set
  19261. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  19262. oracle:
  19263. description: Oracle configures this store to sync secrets using Oracle Vault provider
  19264. properties:
  19265. auth:
  19266. description: |-
  19267. Auth configures how secret-manager authenticates with the Oracle Vault.
  19268. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  19269. properties:
  19270. secretRef:
  19271. description: SecretRef to pass through sensitive information.
  19272. properties:
  19273. fingerprint:
  19274. description: Fingerprint is the fingerprint of the API private key.
  19275. properties:
  19276. key:
  19277. description: |-
  19278. A key in the referenced Secret.
  19279. Some instances of this field may be defaulted, in others it may be required.
  19280. maxLength: 253
  19281. minLength: 1
  19282. pattern: ^[-._a-zA-Z0-9]+$
  19283. type: string
  19284. name:
  19285. description: The name of the Secret resource being referred to.
  19286. maxLength: 253
  19287. minLength: 1
  19288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19289. type: string
  19290. namespace:
  19291. description: |-
  19292. The namespace of the Secret resource being referred to.
  19293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19294. maxLength: 63
  19295. minLength: 1
  19296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19297. type: string
  19298. type: object
  19299. privatekey:
  19300. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  19301. properties:
  19302. key:
  19303. description: |-
  19304. A key in the referenced Secret.
  19305. Some instances of this field may be defaulted, in others it may be required.
  19306. maxLength: 253
  19307. minLength: 1
  19308. pattern: ^[-._a-zA-Z0-9]+$
  19309. type: string
  19310. name:
  19311. description: The name of the Secret resource being referred to.
  19312. maxLength: 253
  19313. minLength: 1
  19314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19315. type: string
  19316. namespace:
  19317. description: |-
  19318. The namespace of the Secret resource being referred to.
  19319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19320. maxLength: 63
  19321. minLength: 1
  19322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19323. type: string
  19324. type: object
  19325. required:
  19326. - fingerprint
  19327. - privatekey
  19328. type: object
  19329. tenancy:
  19330. description: Tenancy is the tenancy OCID where user is located.
  19331. type: string
  19332. user:
  19333. description: User is an access OCID specific to the account.
  19334. type: string
  19335. required:
  19336. - secretRef
  19337. - tenancy
  19338. - user
  19339. type: object
  19340. compartment:
  19341. description: |-
  19342. Compartment is the vault compartment OCID.
  19343. Required for PushSecret
  19344. type: string
  19345. encryptionKey:
  19346. description: |-
  19347. EncryptionKey is the OCID of the encryption key within the vault.
  19348. Required for PushSecret
  19349. type: string
  19350. principalType:
  19351. description: |-
  19352. The type of principal to use for authentication. If left blank, the Auth struct will
  19353. determine the principal type. This optional field must be specified if using
  19354. workload identity.
  19355. enum:
  19356. - ""
  19357. - UserPrincipal
  19358. - InstancePrincipal
  19359. - Workload
  19360. type: string
  19361. region:
  19362. description: Region is the region where vault is located.
  19363. type: string
  19364. serviceAccountRef:
  19365. description: |-
  19366. ServiceAccountRef specified the service account
  19367. that should be used when authenticating with WorkloadIdentity.
  19368. properties:
  19369. audiences:
  19370. description: |-
  19371. Audience specifies the `aud` claim for the service account token
  19372. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19373. then this audiences will be appended to the list
  19374. items:
  19375. type: string
  19376. type: array
  19377. name:
  19378. description: The name of the ServiceAccount resource being referred to.
  19379. maxLength: 253
  19380. minLength: 1
  19381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19382. type: string
  19383. namespace:
  19384. description: |-
  19385. Namespace of the resource being referred to.
  19386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19387. maxLength: 63
  19388. minLength: 1
  19389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19390. type: string
  19391. required:
  19392. - name
  19393. type: object
  19394. vault:
  19395. description: Vault is the vault's OCID of the specific vault where secret is located.
  19396. type: string
  19397. required:
  19398. - region
  19399. - vault
  19400. type: object
  19401. ovh:
  19402. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  19403. properties:
  19404. auth:
  19405. description: Authentication method (mtls or token).
  19406. properties:
  19407. mtls:
  19408. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  19409. properties:
  19410. caBundle:
  19411. format: byte
  19412. type: string
  19413. caProvider:
  19414. description: |-
  19415. CAProvider provides a custom certificate authority for accessing the provider's store.
  19416. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  19417. properties:
  19418. key:
  19419. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19420. maxLength: 253
  19421. minLength: 1
  19422. pattern: ^[-._a-zA-Z0-9]+$
  19423. type: string
  19424. name:
  19425. description: The name of the object located at the provider type.
  19426. maxLength: 253
  19427. minLength: 1
  19428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19429. type: string
  19430. namespace:
  19431. description: |-
  19432. The namespace the Provider type is in.
  19433. Can only be defined when used in a ClusterSecretStore.
  19434. maxLength: 63
  19435. minLength: 1
  19436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19437. type: string
  19438. type:
  19439. description: The type of provider to use such as "Secret", or "ConfigMap".
  19440. enum:
  19441. - Secret
  19442. - ConfigMap
  19443. type: string
  19444. required:
  19445. - name
  19446. - type
  19447. type: object
  19448. certSecretRef:
  19449. description: |-
  19450. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19451. In some instances, `key` is a required field.
  19452. properties:
  19453. key:
  19454. description: |-
  19455. A key in the referenced Secret.
  19456. Some instances of this field may be defaulted, in others it may be required.
  19457. maxLength: 253
  19458. minLength: 1
  19459. pattern: ^[-._a-zA-Z0-9]+$
  19460. type: string
  19461. name:
  19462. description: The name of the Secret resource being referred to.
  19463. maxLength: 253
  19464. minLength: 1
  19465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19466. type: string
  19467. namespace:
  19468. description: |-
  19469. The namespace of the Secret resource being referred to.
  19470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19471. maxLength: 63
  19472. minLength: 1
  19473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19474. type: string
  19475. type: object
  19476. keySecretRef:
  19477. description: |-
  19478. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19479. In some instances, `key` is a required field.
  19480. properties:
  19481. key:
  19482. description: |-
  19483. A key in the referenced Secret.
  19484. Some instances of this field may be defaulted, in others it may be required.
  19485. maxLength: 253
  19486. minLength: 1
  19487. pattern: ^[-._a-zA-Z0-9]+$
  19488. type: string
  19489. name:
  19490. description: The name of the Secret resource being referred to.
  19491. maxLength: 253
  19492. minLength: 1
  19493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19494. type: string
  19495. namespace:
  19496. description: |-
  19497. The namespace of the Secret resource being referred to.
  19498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19499. maxLength: 63
  19500. minLength: 1
  19501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19502. type: string
  19503. type: object
  19504. required:
  19505. - certSecretRef
  19506. - keySecretRef
  19507. type: object
  19508. token:
  19509. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  19510. properties:
  19511. tokenSecretRef:
  19512. description: |-
  19513. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19514. In some instances, `key` is a required field.
  19515. properties:
  19516. key:
  19517. description: |-
  19518. A key in the referenced Secret.
  19519. Some instances of this field may be defaulted, in others it may be required.
  19520. maxLength: 253
  19521. minLength: 1
  19522. pattern: ^[-._a-zA-Z0-9]+$
  19523. type: string
  19524. name:
  19525. description: The name of the Secret resource being referred to.
  19526. maxLength: 253
  19527. minLength: 1
  19528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19529. type: string
  19530. namespace:
  19531. description: |-
  19532. The namespace of the Secret resource being referred to.
  19533. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19534. maxLength: 63
  19535. minLength: 1
  19536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19537. type: string
  19538. type: object
  19539. required:
  19540. - tokenSecretRef
  19541. type: object
  19542. type: object
  19543. casRequired:
  19544. description: 'Enables or disables check-and-set (CAS) (default: false).'
  19545. type: boolean
  19546. okmsTimeout:
  19547. default: 30
  19548. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  19549. format: int32
  19550. minimum: 1
  19551. type: integer
  19552. okmsid:
  19553. description: specifies the OKMS ID.
  19554. type: string
  19555. server:
  19556. description: specifies the OKMS server endpoint.
  19557. type: string
  19558. required:
  19559. - auth
  19560. - okmsid
  19561. - server
  19562. type: object
  19563. passbolt:
  19564. description: |-
  19565. PassboltProvider provides access to Passbolt secrets manager.
  19566. See: https://www.passbolt.com.
  19567. properties:
  19568. auth:
  19569. description: Auth defines the information necessary to authenticate against Passbolt Server
  19570. properties:
  19571. passwordSecretRef:
  19572. description: |-
  19573. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19574. In some instances, `key` is a required field.
  19575. properties:
  19576. key:
  19577. description: |-
  19578. A key in the referenced Secret.
  19579. Some instances of this field may be defaulted, in others it may be required.
  19580. maxLength: 253
  19581. minLength: 1
  19582. pattern: ^[-._a-zA-Z0-9]+$
  19583. type: string
  19584. name:
  19585. description: The name of the Secret resource being referred to.
  19586. maxLength: 253
  19587. minLength: 1
  19588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19589. type: string
  19590. namespace:
  19591. description: |-
  19592. The namespace of the Secret resource being referred to.
  19593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19594. maxLength: 63
  19595. minLength: 1
  19596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19597. type: string
  19598. type: object
  19599. privateKeySecretRef:
  19600. description: |-
  19601. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19602. In some instances, `key` is a required field.
  19603. properties:
  19604. key:
  19605. description: |-
  19606. A key in the referenced Secret.
  19607. Some instances of this field may be defaulted, in others it may be required.
  19608. maxLength: 253
  19609. minLength: 1
  19610. pattern: ^[-._a-zA-Z0-9]+$
  19611. type: string
  19612. name:
  19613. description: The name of the Secret resource being referred to.
  19614. maxLength: 253
  19615. minLength: 1
  19616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19617. type: string
  19618. namespace:
  19619. description: |-
  19620. The namespace of the Secret resource being referred to.
  19621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19622. maxLength: 63
  19623. minLength: 1
  19624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19625. type: string
  19626. type: object
  19627. required:
  19628. - passwordSecretRef
  19629. - privateKeySecretRef
  19630. type: object
  19631. caBundle:
  19632. description: |-
  19633. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  19634. if the Host URL is using HTTPS protocol. If not set the system root certificates
  19635. are used to validate the TLS connection.
  19636. format: byte
  19637. type: string
  19638. caProvider:
  19639. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  19640. properties:
  19641. key:
  19642. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19643. maxLength: 253
  19644. minLength: 1
  19645. pattern: ^[-._a-zA-Z0-9]+$
  19646. type: string
  19647. name:
  19648. description: The name of the object located at the provider type.
  19649. maxLength: 253
  19650. minLength: 1
  19651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19652. type: string
  19653. namespace:
  19654. description: |-
  19655. The namespace the Provider type is in.
  19656. Can only be defined when used in a ClusterSecretStore.
  19657. maxLength: 63
  19658. minLength: 1
  19659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19660. type: string
  19661. type:
  19662. description: The type of provider to use such as "Secret", or "ConfigMap".
  19663. enum:
  19664. - Secret
  19665. - ConfigMap
  19666. type: string
  19667. required:
  19668. - name
  19669. - type
  19670. type: object
  19671. host:
  19672. description: Host defines the Passbolt Server to connect to
  19673. type: string
  19674. required:
  19675. - auth
  19676. - host
  19677. type: object
  19678. passworddepot:
  19679. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  19680. properties:
  19681. auth:
  19682. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  19683. properties:
  19684. secretRef:
  19685. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  19686. properties:
  19687. credentials:
  19688. description: Username / Password is used for authentication.
  19689. properties:
  19690. key:
  19691. description: |-
  19692. A key in the referenced Secret.
  19693. Some instances of this field may be defaulted, in others it may be required.
  19694. maxLength: 253
  19695. minLength: 1
  19696. pattern: ^[-._a-zA-Z0-9]+$
  19697. type: string
  19698. name:
  19699. description: The name of the Secret resource being referred to.
  19700. maxLength: 253
  19701. minLength: 1
  19702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19703. type: string
  19704. namespace:
  19705. description: |-
  19706. The namespace of the Secret resource being referred to.
  19707. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19708. maxLength: 63
  19709. minLength: 1
  19710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19711. type: string
  19712. type: object
  19713. type: object
  19714. required:
  19715. - secretRef
  19716. type: object
  19717. database:
  19718. description: Database to use as source
  19719. type: string
  19720. host:
  19721. description: URL configures the Password Depot instance URL.
  19722. type: string
  19723. required:
  19724. - auth
  19725. - database
  19726. - host
  19727. type: object
  19728. previder:
  19729. description: Previder configures this store to sync secrets using the Previder provider
  19730. properties:
  19731. auth:
  19732. description: PreviderAuth contains a secretRef for credentials.
  19733. properties:
  19734. secretRef:
  19735. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  19736. properties:
  19737. accessToken:
  19738. description: The AccessToken is used for authentication
  19739. properties:
  19740. key:
  19741. description: |-
  19742. A key in the referenced Secret.
  19743. Some instances of this field may be defaulted, in others it may be required.
  19744. maxLength: 253
  19745. minLength: 1
  19746. pattern: ^[-._a-zA-Z0-9]+$
  19747. type: string
  19748. name:
  19749. description: The name of the Secret resource being referred to.
  19750. maxLength: 253
  19751. minLength: 1
  19752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19753. type: string
  19754. namespace:
  19755. description: |-
  19756. The namespace of the Secret resource being referred to.
  19757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19758. maxLength: 63
  19759. minLength: 1
  19760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19761. type: string
  19762. type: object
  19763. required:
  19764. - accessToken
  19765. type: object
  19766. type: object
  19767. baseUri:
  19768. type: string
  19769. required:
  19770. - auth
  19771. type: object
  19772. pulumi:
  19773. description: Pulumi configures this store to sync secrets using the Pulumi provider
  19774. properties:
  19775. accessToken:
  19776. description: |-
  19777. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  19778. Deprecated: Use auth.accessToken instead.
  19779. properties:
  19780. secretRef:
  19781. description: SecretRef is a reference to a secret containing the Pulumi API token.
  19782. properties:
  19783. key:
  19784. description: |-
  19785. A key in the referenced Secret.
  19786. Some instances of this field may be defaulted, in others it may be required.
  19787. maxLength: 253
  19788. minLength: 1
  19789. pattern: ^[-._a-zA-Z0-9]+$
  19790. type: string
  19791. name:
  19792. description: The name of the Secret resource being referred to.
  19793. maxLength: 253
  19794. minLength: 1
  19795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19796. type: string
  19797. namespace:
  19798. description: |-
  19799. The namespace of the Secret resource being referred to.
  19800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19801. maxLength: 63
  19802. minLength: 1
  19803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19804. type: string
  19805. type: object
  19806. type: object
  19807. apiUrl:
  19808. default: https://api.pulumi.com/api/esc
  19809. description: APIURL is the URL of the Pulumi API.
  19810. type: string
  19811. auth:
  19812. description: |-
  19813. Auth configures how the Operator authenticates with the Pulumi API.
  19814. Either auth or the deprecated accessToken field must be specified.
  19815. properties:
  19816. accessToken:
  19817. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  19818. properties:
  19819. secretRef:
  19820. description: SecretRef is a reference to a secret containing the Pulumi API token.
  19821. properties:
  19822. key:
  19823. description: |-
  19824. A key in the referenced Secret.
  19825. Some instances of this field may be defaulted, in others it may be required.
  19826. maxLength: 253
  19827. minLength: 1
  19828. pattern: ^[-._a-zA-Z0-9]+$
  19829. type: string
  19830. name:
  19831. description: The name of the Secret resource being referred to.
  19832. maxLength: 253
  19833. minLength: 1
  19834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19835. type: string
  19836. namespace:
  19837. description: |-
  19838. The namespace of the Secret resource being referred to.
  19839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19840. maxLength: 63
  19841. minLength: 1
  19842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19843. type: string
  19844. type: object
  19845. type: object
  19846. oidcConfig:
  19847. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  19848. properties:
  19849. expirationSeconds:
  19850. default: 600
  19851. description: |-
  19852. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  19853. Defaults to 10 minutes.
  19854. format: int64
  19855. minimum: 600
  19856. type: integer
  19857. organization:
  19858. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  19859. type: string
  19860. serviceAccountRef:
  19861. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  19862. properties:
  19863. audiences:
  19864. description: |-
  19865. Audience specifies the `aud` claim for the service account token
  19866. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19867. then this audiences will be appended to the list
  19868. items:
  19869. type: string
  19870. type: array
  19871. name:
  19872. description: The name of the ServiceAccount resource being referred to.
  19873. maxLength: 253
  19874. minLength: 1
  19875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19876. type: string
  19877. namespace:
  19878. description: |-
  19879. Namespace of the resource being referred to.
  19880. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19881. maxLength: 63
  19882. minLength: 1
  19883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19884. type: string
  19885. required:
  19886. - name
  19887. type: object
  19888. required:
  19889. - organization
  19890. - serviceAccountRef
  19891. type: object
  19892. type: object
  19893. x-kubernetes-validations:
  19894. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  19895. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  19896. environment:
  19897. description: |-
  19898. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  19899. dynamically retrieved values from supported providers including all major clouds,
  19900. and other Pulumi ESC environments.
  19901. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  19902. type: string
  19903. organization:
  19904. description: |-
  19905. Organization are a space to collaborate on shared projects and stacks.
  19906. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  19907. type: string
  19908. project:
  19909. description: Project is the name of the Pulumi ESC project the environment belongs to.
  19910. type: string
  19911. required:
  19912. - environment
  19913. - organization
  19914. - project
  19915. type: object
  19916. x-kubernetes-validations:
  19917. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  19918. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  19919. scaleway:
  19920. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  19921. properties:
  19922. accessKey:
  19923. description: AccessKey is the non-secret part of the api key.
  19924. properties:
  19925. secretRef:
  19926. description: SecretRef references a key in a secret that will be used as value.
  19927. properties:
  19928. key:
  19929. description: |-
  19930. A key in the referenced Secret.
  19931. Some instances of this field may be defaulted, in others it may be required.
  19932. maxLength: 253
  19933. minLength: 1
  19934. pattern: ^[-._a-zA-Z0-9]+$
  19935. type: string
  19936. name:
  19937. description: The name of the Secret resource being referred to.
  19938. maxLength: 253
  19939. minLength: 1
  19940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19941. type: string
  19942. namespace:
  19943. description: |-
  19944. The namespace of the Secret resource being referred to.
  19945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19946. maxLength: 63
  19947. minLength: 1
  19948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19949. type: string
  19950. type: object
  19951. value:
  19952. description: Value can be specified directly to set a value without using a secret.
  19953. type: string
  19954. type: object
  19955. apiUrl:
  19956. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  19957. type: string
  19958. projectId:
  19959. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  19960. type: string
  19961. region:
  19962. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  19963. type: string
  19964. secretKey:
  19965. description: SecretKey is the non-secret part of the api key.
  19966. properties:
  19967. secretRef:
  19968. description: SecretRef references a key in a secret that will be used as value.
  19969. properties:
  19970. key:
  19971. description: |-
  19972. A key in the referenced Secret.
  19973. Some instances of this field may be defaulted, in others it may be required.
  19974. maxLength: 253
  19975. minLength: 1
  19976. pattern: ^[-._a-zA-Z0-9]+$
  19977. type: string
  19978. name:
  19979. description: The name of the Secret resource being referred to.
  19980. maxLength: 253
  19981. minLength: 1
  19982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19983. type: string
  19984. namespace:
  19985. description: |-
  19986. The namespace of the Secret resource being referred to.
  19987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19988. maxLength: 63
  19989. minLength: 1
  19990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19991. type: string
  19992. type: object
  19993. value:
  19994. description: Value can be specified directly to set a value without using a secret.
  19995. type: string
  19996. type: object
  19997. required:
  19998. - accessKey
  19999. - projectId
  20000. - region
  20001. - secretKey
  20002. type: object
  20003. secretserver:
  20004. description: |-
  20005. SecretServer configures this store to sync secrets using SecretServer provider
  20006. https://docs.delinea.com/online-help/secret-server/start.htm
  20007. properties:
  20008. caBundle:
  20009. description: |-
  20010. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20011. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20012. are used to validate the TLS connection.
  20013. format: byte
  20014. type: string
  20015. caProvider:
  20016. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20017. properties:
  20018. key:
  20019. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20020. maxLength: 253
  20021. minLength: 1
  20022. pattern: ^[-._a-zA-Z0-9]+$
  20023. type: string
  20024. name:
  20025. description: The name of the object located at the provider type.
  20026. maxLength: 253
  20027. minLength: 1
  20028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20029. type: string
  20030. namespace:
  20031. description: |-
  20032. The namespace the Provider type is in.
  20033. Can only be defined when used in a ClusterSecretStore.
  20034. maxLength: 63
  20035. minLength: 1
  20036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20037. type: string
  20038. type:
  20039. description: The type of provider to use such as "Secret", or "ConfigMap".
  20040. enum:
  20041. - Secret
  20042. - ConfigMap
  20043. type: string
  20044. required:
  20045. - name
  20046. - type
  20047. type: object
  20048. domain:
  20049. description: Domain is the secret server domain.
  20050. type: string
  20051. password:
  20052. description: Password is the secret server account password.
  20053. properties:
  20054. secretRef:
  20055. description: SecretRef references a key in a secret that will be used as value.
  20056. properties:
  20057. key:
  20058. description: |-
  20059. A key in the referenced Secret.
  20060. Some instances of this field may be defaulted, in others it may be required.
  20061. maxLength: 253
  20062. minLength: 1
  20063. pattern: ^[-._a-zA-Z0-9]+$
  20064. type: string
  20065. name:
  20066. description: The name of the Secret resource being referred to.
  20067. maxLength: 253
  20068. minLength: 1
  20069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20070. type: string
  20071. namespace:
  20072. description: |-
  20073. The namespace of the Secret resource being referred to.
  20074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20075. maxLength: 63
  20076. minLength: 1
  20077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20078. type: string
  20079. type: object
  20080. value:
  20081. description: Value can be specified directly to set a value without using a secret.
  20082. type: string
  20083. type: object
  20084. serverURL:
  20085. description: |-
  20086. ServerURL
  20087. URL to your secret server installation
  20088. type: string
  20089. username:
  20090. description: Username is the secret server account username.
  20091. properties:
  20092. secretRef:
  20093. description: SecretRef references a key in a secret that will be used as value.
  20094. properties:
  20095. key:
  20096. description: |-
  20097. A key in the referenced Secret.
  20098. Some instances of this field may be defaulted, in others it may be required.
  20099. maxLength: 253
  20100. minLength: 1
  20101. pattern: ^[-._a-zA-Z0-9]+$
  20102. type: string
  20103. name:
  20104. description: The name of the Secret resource being referred to.
  20105. maxLength: 253
  20106. minLength: 1
  20107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20108. type: string
  20109. namespace:
  20110. description: |-
  20111. The namespace of the Secret resource being referred to.
  20112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20113. maxLength: 63
  20114. minLength: 1
  20115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20116. type: string
  20117. type: object
  20118. value:
  20119. description: Value can be specified directly to set a value without using a secret.
  20120. type: string
  20121. type: object
  20122. required:
  20123. - password
  20124. - serverURL
  20125. - username
  20126. type: object
  20127. senhasegura:
  20128. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20129. properties:
  20130. auth:
  20131. description: Auth defines parameters to authenticate in senhasegura
  20132. properties:
  20133. clientId:
  20134. type: string
  20135. clientSecretSecretRef:
  20136. description: |-
  20137. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20138. In some instances, `key` is a required field.
  20139. properties:
  20140. key:
  20141. description: |-
  20142. A key in the referenced Secret.
  20143. Some instances of this field may be defaulted, in others it may be required.
  20144. maxLength: 253
  20145. minLength: 1
  20146. pattern: ^[-._a-zA-Z0-9]+$
  20147. type: string
  20148. name:
  20149. description: The name of the Secret resource being referred to.
  20150. maxLength: 253
  20151. minLength: 1
  20152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20153. type: string
  20154. namespace:
  20155. description: |-
  20156. The namespace of the Secret resource being referred to.
  20157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20158. maxLength: 63
  20159. minLength: 1
  20160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20161. type: string
  20162. type: object
  20163. required:
  20164. - clientId
  20165. - clientSecretSecretRef
  20166. type: object
  20167. ignoreSslCertificate:
  20168. default: false
  20169. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  20170. type: boolean
  20171. module:
  20172. description: Module defines which senhasegura module should be used to get secrets
  20173. type: string
  20174. url:
  20175. description: URL of senhasegura
  20176. type: string
  20177. required:
  20178. - auth
  20179. - module
  20180. - url
  20181. type: object
  20182. vault:
  20183. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  20184. properties:
  20185. auth:
  20186. description: Auth configures how secret-manager authenticates with the Vault server.
  20187. properties:
  20188. appRole:
  20189. description: |-
  20190. AppRole authenticates with Vault using the App Role auth mechanism,
  20191. with the role and secret stored in a Kubernetes Secret resource.
  20192. properties:
  20193. path:
  20194. default: approle
  20195. description: |-
  20196. Path where the App Role authentication backend is mounted
  20197. in Vault, e.g: "approle"
  20198. type: string
  20199. roleId:
  20200. description: |-
  20201. RoleID configured in the App Role authentication backend when setting
  20202. up the authentication backend in Vault.
  20203. type: string
  20204. roleRef:
  20205. description: |-
  20206. Reference to a key in a Secret that contains the App Role ID used
  20207. to authenticate with Vault.
  20208. The `key` field must be specified and denotes which entry within the Secret
  20209. resource is used as the app role id.
  20210. properties:
  20211. key:
  20212. description: |-
  20213. A key in the referenced Secret.
  20214. Some instances of this field may be defaulted, in others it may be required.
  20215. maxLength: 253
  20216. minLength: 1
  20217. pattern: ^[-._a-zA-Z0-9]+$
  20218. type: string
  20219. name:
  20220. description: The name of the Secret resource being referred to.
  20221. maxLength: 253
  20222. minLength: 1
  20223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20224. type: string
  20225. namespace:
  20226. description: |-
  20227. The namespace of the Secret resource being referred to.
  20228. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20229. maxLength: 63
  20230. minLength: 1
  20231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20232. type: string
  20233. type: object
  20234. secretRef:
  20235. description: |-
  20236. Reference to a key in a Secret that contains the App Role secret used
  20237. to authenticate with Vault.
  20238. The `key` field must be specified and denotes which entry within the Secret
  20239. resource is used as the app role secret.
  20240. properties:
  20241. key:
  20242. description: |-
  20243. A key in the referenced Secret.
  20244. Some instances of this field may be defaulted, in others it may be required.
  20245. maxLength: 253
  20246. minLength: 1
  20247. pattern: ^[-._a-zA-Z0-9]+$
  20248. type: string
  20249. name:
  20250. description: The name of the Secret resource being referred to.
  20251. maxLength: 253
  20252. minLength: 1
  20253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20254. type: string
  20255. namespace:
  20256. description: |-
  20257. The namespace of the Secret resource being referred to.
  20258. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20259. maxLength: 63
  20260. minLength: 1
  20261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20262. type: string
  20263. type: object
  20264. required:
  20265. - path
  20266. - secretRef
  20267. type: object
  20268. cert:
  20269. description: |-
  20270. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  20271. Cert authentication method
  20272. properties:
  20273. clientCert:
  20274. description: |-
  20275. ClientCert is a certificate to authenticate using the Cert Vault
  20276. authentication method
  20277. properties:
  20278. key:
  20279. description: |-
  20280. A key in the referenced Secret.
  20281. Some instances of this field may be defaulted, in others it may be required.
  20282. maxLength: 253
  20283. minLength: 1
  20284. pattern: ^[-._a-zA-Z0-9]+$
  20285. type: string
  20286. name:
  20287. description: The name of the Secret resource being referred to.
  20288. maxLength: 253
  20289. minLength: 1
  20290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20291. type: string
  20292. namespace:
  20293. description: |-
  20294. The namespace of the Secret resource being referred to.
  20295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20296. maxLength: 63
  20297. minLength: 1
  20298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20299. type: string
  20300. type: object
  20301. path:
  20302. default: cert
  20303. description: |-
  20304. Path where the Certificate authentication backend is mounted
  20305. in Vault, e.g: "cert"
  20306. type: string
  20307. secretRef:
  20308. description: |-
  20309. SecretRef to a key in a Secret resource containing client private key to
  20310. authenticate with Vault using the Cert authentication method
  20311. properties:
  20312. key:
  20313. description: |-
  20314. A key in the referenced Secret.
  20315. Some instances of this field may be defaulted, in others it may be required.
  20316. maxLength: 253
  20317. minLength: 1
  20318. pattern: ^[-._a-zA-Z0-9]+$
  20319. type: string
  20320. name:
  20321. description: The name of the Secret resource being referred to.
  20322. maxLength: 253
  20323. minLength: 1
  20324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20325. type: string
  20326. namespace:
  20327. description: |-
  20328. The namespace of the Secret resource being referred to.
  20329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20330. maxLength: 63
  20331. minLength: 1
  20332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20333. type: string
  20334. type: object
  20335. vaultRole:
  20336. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  20337. type: string
  20338. type: object
  20339. gcp:
  20340. description: |-
  20341. Gcp authenticates with Vault using Google Cloud Platform authentication method
  20342. GCP authentication method
  20343. properties:
  20344. location:
  20345. description: Location optionally defines a location/region for the secret
  20346. type: string
  20347. path:
  20348. default: gcp
  20349. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  20350. type: string
  20351. projectID:
  20352. description: Project ID of the Google Cloud Platform project
  20353. type: string
  20354. role:
  20355. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  20356. type: string
  20357. secretRef:
  20358. description: Specify credentials in a Secret object
  20359. properties:
  20360. secretAccessKeySecretRef:
  20361. description: The SecretAccessKey is used for authentication
  20362. properties:
  20363. key:
  20364. description: |-
  20365. A key in the referenced Secret.
  20366. Some instances of this field may be defaulted, in others it may be required.
  20367. maxLength: 253
  20368. minLength: 1
  20369. pattern: ^[-._a-zA-Z0-9]+$
  20370. type: string
  20371. name:
  20372. description: The name of the Secret resource being referred to.
  20373. maxLength: 253
  20374. minLength: 1
  20375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20376. type: string
  20377. namespace:
  20378. description: |-
  20379. The namespace of the Secret resource being referred to.
  20380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20381. maxLength: 63
  20382. minLength: 1
  20383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20384. type: string
  20385. type: object
  20386. type: object
  20387. serviceAccountRef:
  20388. description: ServiceAccountRef to a service account for impersonation
  20389. properties:
  20390. audiences:
  20391. description: |-
  20392. Audience specifies the `aud` claim for the service account token
  20393. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20394. then this audiences will be appended to the list
  20395. items:
  20396. type: string
  20397. type: array
  20398. name:
  20399. description: The name of the ServiceAccount resource being referred to.
  20400. maxLength: 253
  20401. minLength: 1
  20402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20403. type: string
  20404. namespace:
  20405. description: |-
  20406. Namespace of the resource being referred to.
  20407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20408. maxLength: 63
  20409. minLength: 1
  20410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20411. type: string
  20412. required:
  20413. - name
  20414. type: object
  20415. workloadIdentity:
  20416. description: Specify a service account with Workload Identity
  20417. properties:
  20418. clusterLocation:
  20419. description: |-
  20420. ClusterLocation is the location of the cluster
  20421. If not specified, it fetches information from the metadata server
  20422. type: string
  20423. clusterName:
  20424. description: |-
  20425. ClusterName is the name of the cluster
  20426. If not specified, it fetches information from the metadata server
  20427. type: string
  20428. clusterProjectID:
  20429. description: |-
  20430. ClusterProjectID is the project ID of the cluster
  20431. If not specified, it fetches information from the metadata server
  20432. type: string
  20433. serviceAccountRef:
  20434. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  20435. properties:
  20436. audiences:
  20437. description: |-
  20438. Audience specifies the `aud` claim for the service account token
  20439. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20440. then this audiences will be appended to the list
  20441. items:
  20442. type: string
  20443. type: array
  20444. name:
  20445. description: The name of the ServiceAccount resource being referred to.
  20446. maxLength: 253
  20447. minLength: 1
  20448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20449. type: string
  20450. namespace:
  20451. description: |-
  20452. Namespace of the resource being referred to.
  20453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20454. maxLength: 63
  20455. minLength: 1
  20456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20457. type: string
  20458. required:
  20459. - name
  20460. type: object
  20461. required:
  20462. - serviceAccountRef
  20463. type: object
  20464. required:
  20465. - role
  20466. type: object
  20467. iam:
  20468. description: |-
  20469. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  20470. AWS IAM authentication method
  20471. properties:
  20472. externalID:
  20473. description: AWS External ID set on assumed IAM roles
  20474. type: string
  20475. jwt:
  20476. description: Specify a service account with IRSA enabled
  20477. properties:
  20478. serviceAccountRef:
  20479. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  20480. properties:
  20481. audiences:
  20482. description: |-
  20483. Audience specifies the `aud` claim for the service account token
  20484. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20485. then this audiences will be appended to the list
  20486. items:
  20487. type: string
  20488. type: array
  20489. name:
  20490. description: The name of the ServiceAccount resource being referred to.
  20491. maxLength: 253
  20492. minLength: 1
  20493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20494. type: string
  20495. namespace:
  20496. description: |-
  20497. Namespace of the resource being referred to.
  20498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20499. maxLength: 63
  20500. minLength: 1
  20501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20502. type: string
  20503. required:
  20504. - name
  20505. type: object
  20506. type: object
  20507. path:
  20508. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  20509. type: string
  20510. region:
  20511. description: AWS region
  20512. type: string
  20513. role:
  20514. description: This is the AWS role to be assumed before talking to vault
  20515. type: string
  20516. secretRef:
  20517. description: Specify credentials in a Secret object
  20518. properties:
  20519. accessKeyIDSecretRef:
  20520. description: The AccessKeyID is used for authentication
  20521. properties:
  20522. key:
  20523. description: |-
  20524. A key in the referenced Secret.
  20525. Some instances of this field may be defaulted, in others it may be required.
  20526. maxLength: 253
  20527. minLength: 1
  20528. pattern: ^[-._a-zA-Z0-9]+$
  20529. type: string
  20530. name:
  20531. description: The name of the Secret resource being referred to.
  20532. maxLength: 253
  20533. minLength: 1
  20534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20535. type: string
  20536. namespace:
  20537. description: |-
  20538. The namespace of the Secret resource being referred to.
  20539. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20540. maxLength: 63
  20541. minLength: 1
  20542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20543. type: string
  20544. type: object
  20545. secretAccessKeySecretRef:
  20546. description: The SecretAccessKey is used for authentication
  20547. properties:
  20548. key:
  20549. description: |-
  20550. A key in the referenced Secret.
  20551. Some instances of this field may be defaulted, in others it may be required.
  20552. maxLength: 253
  20553. minLength: 1
  20554. pattern: ^[-._a-zA-Z0-9]+$
  20555. type: string
  20556. name:
  20557. description: The name of the Secret resource being referred to.
  20558. maxLength: 253
  20559. minLength: 1
  20560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20561. type: string
  20562. namespace:
  20563. description: |-
  20564. The namespace of the Secret resource being referred to.
  20565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20566. maxLength: 63
  20567. minLength: 1
  20568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20569. type: string
  20570. type: object
  20571. sessionTokenSecretRef:
  20572. description: |-
  20573. The SessionToken used for authentication
  20574. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  20575. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  20576. properties:
  20577. key:
  20578. description: |-
  20579. A key in the referenced Secret.
  20580. Some instances of this field may be defaulted, in others it may be required.
  20581. maxLength: 253
  20582. minLength: 1
  20583. pattern: ^[-._a-zA-Z0-9]+$
  20584. type: string
  20585. name:
  20586. description: The name of the Secret resource being referred to.
  20587. maxLength: 253
  20588. minLength: 1
  20589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20590. type: string
  20591. namespace:
  20592. description: |-
  20593. The namespace of the Secret resource being referred to.
  20594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20595. maxLength: 63
  20596. minLength: 1
  20597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20598. type: string
  20599. type: object
  20600. type: object
  20601. vaultAwsIamServerID:
  20602. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  20603. type: string
  20604. vaultRole:
  20605. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  20606. type: string
  20607. required:
  20608. - vaultRole
  20609. type: object
  20610. jwt:
  20611. description: |-
  20612. Jwt authenticates with Vault by passing role and JWT token using the
  20613. JWT/OIDC authentication method
  20614. properties:
  20615. kubernetesServiceAccountToken:
  20616. description: |-
  20617. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  20618. a token for with the `TokenRequest` API.
  20619. properties:
  20620. audiences:
  20621. description: |-
  20622. Optional audiences field that will be used to request a temporary Kubernetes service
  20623. account token for the service account referenced by `serviceAccountRef`.
  20624. Defaults to a single audience `vault` it not specified.
  20625. Deprecated: use serviceAccountRef.Audiences instead
  20626. items:
  20627. type: string
  20628. type: array
  20629. expirationSeconds:
  20630. description: |-
  20631. Optional expiration time in seconds that will be used to request a temporary
  20632. Kubernetes service account token for the service account referenced by
  20633. `serviceAccountRef`.
  20634. Deprecated: this will be removed in the future.
  20635. Defaults to 10 minutes.
  20636. format: int64
  20637. type: integer
  20638. serviceAccountRef:
  20639. description: Service account field containing the name of a kubernetes ServiceAccount.
  20640. properties:
  20641. audiences:
  20642. description: |-
  20643. Audience specifies the `aud` claim for the service account token
  20644. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20645. then this audiences will be appended to the list
  20646. items:
  20647. type: string
  20648. type: array
  20649. name:
  20650. description: The name of the ServiceAccount resource being referred to.
  20651. maxLength: 253
  20652. minLength: 1
  20653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20654. type: string
  20655. namespace:
  20656. description: |-
  20657. Namespace of the resource being referred to.
  20658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20659. maxLength: 63
  20660. minLength: 1
  20661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20662. type: string
  20663. required:
  20664. - name
  20665. type: object
  20666. required:
  20667. - serviceAccountRef
  20668. type: object
  20669. path:
  20670. default: jwt
  20671. description: |-
  20672. Path where the JWT authentication backend is mounted
  20673. in Vault, e.g: "jwt"
  20674. type: string
  20675. role:
  20676. description: |-
  20677. Role is a JWT role to authenticate using the JWT/OIDC Vault
  20678. authentication method
  20679. type: string
  20680. secretRef:
  20681. description: |-
  20682. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  20683. authenticate with Vault using the JWT/OIDC authentication method.
  20684. properties:
  20685. key:
  20686. description: |-
  20687. A key in the referenced Secret.
  20688. Some instances of this field may be defaulted, in others it may be required.
  20689. maxLength: 253
  20690. minLength: 1
  20691. pattern: ^[-._a-zA-Z0-9]+$
  20692. type: string
  20693. name:
  20694. description: The name of the Secret resource being referred to.
  20695. maxLength: 253
  20696. minLength: 1
  20697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20698. type: string
  20699. namespace:
  20700. description: |-
  20701. The namespace of the Secret resource being referred to.
  20702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20703. maxLength: 63
  20704. minLength: 1
  20705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20706. type: string
  20707. type: object
  20708. required:
  20709. - path
  20710. type: object
  20711. kubernetes:
  20712. description: |-
  20713. Kubernetes authenticates with Vault by passing the ServiceAccount
  20714. token stored in the named Secret resource to the Vault server.
  20715. properties:
  20716. mountPath:
  20717. default: kubernetes
  20718. description: |-
  20719. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  20720. "kubernetes"
  20721. type: string
  20722. role:
  20723. description: |-
  20724. A required field containing the Vault Role to assume. A Role binds a
  20725. Kubernetes ServiceAccount with a set of Vault policies.
  20726. type: string
  20727. secretRef:
  20728. description: |-
  20729. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20730. for authenticating with Vault. If a name is specified without a key,
  20731. `token` is the default. If one is not specified, the one bound to
  20732. the controller will be used.
  20733. properties:
  20734. key:
  20735. description: |-
  20736. A key in the referenced Secret.
  20737. Some instances of this field may be defaulted, in others it may be required.
  20738. maxLength: 253
  20739. minLength: 1
  20740. pattern: ^[-._a-zA-Z0-9]+$
  20741. type: string
  20742. name:
  20743. description: The name of the Secret resource being referred to.
  20744. maxLength: 253
  20745. minLength: 1
  20746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20747. type: string
  20748. namespace:
  20749. description: |-
  20750. The namespace of the Secret resource being referred to.
  20751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20752. maxLength: 63
  20753. minLength: 1
  20754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20755. type: string
  20756. type: object
  20757. serviceAccountRef:
  20758. description: |-
  20759. Optional service account field containing the name of a kubernetes ServiceAccount.
  20760. If the service account is specified, the service account secret token JWT will be used
  20761. for authenticating with Vault. If the service account selector is not supplied,
  20762. the secretRef will be used instead.
  20763. properties:
  20764. audiences:
  20765. description: |-
  20766. Audience specifies the `aud` claim for the service account token
  20767. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20768. then this audiences will be appended to the list
  20769. items:
  20770. type: string
  20771. type: array
  20772. name:
  20773. description: The name of the ServiceAccount resource being referred to.
  20774. maxLength: 253
  20775. minLength: 1
  20776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20777. type: string
  20778. namespace:
  20779. description: |-
  20780. Namespace of the resource being referred to.
  20781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20782. maxLength: 63
  20783. minLength: 1
  20784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20785. type: string
  20786. required:
  20787. - name
  20788. type: object
  20789. required:
  20790. - mountPath
  20791. - role
  20792. type: object
  20793. ldap:
  20794. description: |-
  20795. Ldap authenticates with Vault by passing username/password pair using
  20796. the LDAP authentication method
  20797. properties:
  20798. path:
  20799. default: ldap
  20800. description: |-
  20801. Path where the LDAP authentication backend is mounted
  20802. in Vault, e.g: "ldap"
  20803. type: string
  20804. secretRef:
  20805. description: |-
  20806. SecretRef to a key in a Secret resource containing password for the LDAP
  20807. user used to authenticate with Vault using the LDAP authentication
  20808. method
  20809. properties:
  20810. key:
  20811. description: |-
  20812. A key in the referenced Secret.
  20813. Some instances of this field may be defaulted, in others it may be required.
  20814. maxLength: 253
  20815. minLength: 1
  20816. pattern: ^[-._a-zA-Z0-9]+$
  20817. type: string
  20818. name:
  20819. description: The name of the Secret resource being referred to.
  20820. maxLength: 253
  20821. minLength: 1
  20822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20823. type: string
  20824. namespace:
  20825. description: |-
  20826. The namespace of the Secret resource being referred to.
  20827. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20828. maxLength: 63
  20829. minLength: 1
  20830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20831. type: string
  20832. type: object
  20833. username:
  20834. description: |-
  20835. Username is an LDAP username used to authenticate using the LDAP Vault
  20836. authentication method
  20837. type: string
  20838. required:
  20839. - path
  20840. - username
  20841. type: object
  20842. namespace:
  20843. description: |-
  20844. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  20845. Namespaces is a set of features within Vault Enterprise that allows
  20846. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  20847. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  20848. This will default to Vault.Namespace field if set, or empty otherwise
  20849. type: string
  20850. tokenSecretRef:
  20851. description: TokenSecretRef authenticates with Vault by presenting a token.
  20852. properties:
  20853. key:
  20854. description: |-
  20855. A key in the referenced Secret.
  20856. Some instances of this field may be defaulted, in others it may be required.
  20857. maxLength: 253
  20858. minLength: 1
  20859. pattern: ^[-._a-zA-Z0-9]+$
  20860. type: string
  20861. name:
  20862. description: The name of the Secret resource being referred to.
  20863. maxLength: 253
  20864. minLength: 1
  20865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20866. type: string
  20867. namespace:
  20868. description: |-
  20869. The namespace of the Secret resource being referred to.
  20870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20871. maxLength: 63
  20872. minLength: 1
  20873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20874. type: string
  20875. type: object
  20876. userPass:
  20877. description: UserPass authenticates with Vault by passing username/password pair
  20878. properties:
  20879. path:
  20880. default: userpass
  20881. description: |-
  20882. Path where the UserPassword authentication backend is mounted
  20883. in Vault, e.g: "userpass"
  20884. type: string
  20885. secretRef:
  20886. description: |-
  20887. SecretRef to a key in a Secret resource containing password for the
  20888. user used to authenticate with Vault using the UserPass authentication
  20889. method
  20890. properties:
  20891. key:
  20892. description: |-
  20893. A key in the referenced Secret.
  20894. Some instances of this field may be defaulted, in others it may be required.
  20895. maxLength: 253
  20896. minLength: 1
  20897. pattern: ^[-._a-zA-Z0-9]+$
  20898. type: string
  20899. name:
  20900. description: The name of the Secret resource being referred to.
  20901. maxLength: 253
  20902. minLength: 1
  20903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20904. type: string
  20905. namespace:
  20906. description: |-
  20907. The namespace of the Secret resource being referred to.
  20908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20909. maxLength: 63
  20910. minLength: 1
  20911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20912. type: string
  20913. type: object
  20914. username:
  20915. description: |-
  20916. Username is a username used to authenticate using the UserPass Vault
  20917. authentication method
  20918. type: string
  20919. required:
  20920. - path
  20921. - username
  20922. type: object
  20923. type: object
  20924. caBundle:
  20925. description: |-
  20926. PEM encoded CA bundle used to validate Vault server certificate. Only used
  20927. if the Server URL is using HTTPS protocol. This parameter is ignored for
  20928. plain HTTP protocol connection. If not set the system root certificates
  20929. are used to validate the TLS connection.
  20930. format: byte
  20931. type: string
  20932. caProvider:
  20933. description: The provider for the CA bundle to use to validate Vault server certificate.
  20934. properties:
  20935. key:
  20936. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20937. maxLength: 253
  20938. minLength: 1
  20939. pattern: ^[-._a-zA-Z0-9]+$
  20940. type: string
  20941. name:
  20942. description: The name of the object located at the provider type.
  20943. maxLength: 253
  20944. minLength: 1
  20945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20946. type: string
  20947. namespace:
  20948. description: |-
  20949. The namespace the Provider type is in.
  20950. Can only be defined when used in a ClusterSecretStore.
  20951. maxLength: 63
  20952. minLength: 1
  20953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20954. type: string
  20955. type:
  20956. description: The type of provider to use such as "Secret", or "ConfigMap".
  20957. enum:
  20958. - Secret
  20959. - ConfigMap
  20960. type: string
  20961. required:
  20962. - name
  20963. - type
  20964. type: object
  20965. checkAndSet:
  20966. description: |-
  20967. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  20968. Only applies to Vault KV v2 stores. When enabled, write operations must include
  20969. the current version of the secret to prevent unintentional overwrites.
  20970. properties:
  20971. required:
  20972. description: |-
  20973. Required when true, all write operations must include a check-and-set parameter.
  20974. This helps prevent unintentional overwrites of secrets.
  20975. type: boolean
  20976. type: object
  20977. forwardInconsistent:
  20978. description: |-
  20979. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  20980. leader instead of simply retrying within a loop. This can increase performance if
  20981. the option is enabled serverside.
  20982. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  20983. type: boolean
  20984. headers:
  20985. additionalProperties:
  20986. type: string
  20987. description: Headers to be added in Vault request
  20988. type: object
  20989. namespace:
  20990. description: |-
  20991. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  20992. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  20993. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  20994. type: string
  20995. path:
  20996. description: |-
  20997. Path is the mount path of the Vault KV backend endpoint, e.g:
  20998. "secret". The v2 KV secret engine version specific "/data" path suffix
  20999. for fetching secrets from Vault is optional and will be appended
  21000. if not present in specified path.
  21001. type: string
  21002. readYourWrites:
  21003. description: |-
  21004. ReadYourWrites ensures isolated read-after-write semantics by
  21005. providing discovered cluster replication states in each request.
  21006. More information about eventual consistency in Vault can be found here
  21007. https://www.vaultproject.io/docs/enterprise/consistency
  21008. type: boolean
  21009. server:
  21010. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21011. type: string
  21012. tls:
  21013. description: |-
  21014. The configuration used for client side related TLS communication, when the Vault server
  21015. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21016. This parameter is ignored for plain HTTP protocol connection.
  21017. It's worth noting this configuration is different from the "TLS certificates auth method",
  21018. which is available under the `auth.cert` section.
  21019. properties:
  21020. certSecretRef:
  21021. description: |-
  21022. CertSecretRef is a certificate added to the transport layer
  21023. when communicating with the Vault server.
  21024. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21025. properties:
  21026. key:
  21027. description: |-
  21028. A key in the referenced Secret.
  21029. Some instances of this field may be defaulted, in others it may be required.
  21030. maxLength: 253
  21031. minLength: 1
  21032. pattern: ^[-._a-zA-Z0-9]+$
  21033. type: string
  21034. name:
  21035. description: The name of the Secret resource being referred to.
  21036. maxLength: 253
  21037. minLength: 1
  21038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21039. type: string
  21040. namespace:
  21041. description: |-
  21042. The namespace of the Secret resource being referred to.
  21043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21044. maxLength: 63
  21045. minLength: 1
  21046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21047. type: string
  21048. type: object
  21049. keySecretRef:
  21050. description: |-
  21051. KeySecretRef to a key in a Secret resource containing client private key
  21052. added to the transport layer when communicating with the Vault server.
  21053. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21054. properties:
  21055. key:
  21056. description: |-
  21057. A key in the referenced Secret.
  21058. Some instances of this field may be defaulted, in others it may be required.
  21059. maxLength: 253
  21060. minLength: 1
  21061. pattern: ^[-._a-zA-Z0-9]+$
  21062. type: string
  21063. name:
  21064. description: The name of the Secret resource being referred to.
  21065. maxLength: 253
  21066. minLength: 1
  21067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21068. type: string
  21069. namespace:
  21070. description: |-
  21071. The namespace of the Secret resource being referred to.
  21072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21073. maxLength: 63
  21074. minLength: 1
  21075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21076. type: string
  21077. type: object
  21078. type: object
  21079. version:
  21080. default: v2
  21081. description: |-
  21082. Version is the Vault KV secret engine version. This can be either "v1" or
  21083. "v2". Version defaults to "v2".
  21084. enum:
  21085. - v1
  21086. - v2
  21087. type: string
  21088. required:
  21089. - server
  21090. type: object
  21091. volcengine:
  21092. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21093. properties:
  21094. auth:
  21095. description: |-
  21096. Auth defines the authentication method to use.
  21097. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21098. properties:
  21099. secretRef:
  21100. description: |-
  21101. SecretRef defines the static credentials to use for authentication.
  21102. If not set, IRSA is used.
  21103. properties:
  21104. accessKeyID:
  21105. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21106. properties:
  21107. key:
  21108. description: |-
  21109. A key in the referenced Secret.
  21110. Some instances of this field may be defaulted, in others it may be required.
  21111. maxLength: 253
  21112. minLength: 1
  21113. pattern: ^[-._a-zA-Z0-9]+$
  21114. type: string
  21115. name:
  21116. description: The name of the Secret resource being referred to.
  21117. maxLength: 253
  21118. minLength: 1
  21119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21120. type: string
  21121. namespace:
  21122. description: |-
  21123. The namespace of the Secret resource being referred to.
  21124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21125. maxLength: 63
  21126. minLength: 1
  21127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21128. type: string
  21129. type: object
  21130. secretAccessKey:
  21131. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21132. properties:
  21133. key:
  21134. description: |-
  21135. A key in the referenced Secret.
  21136. Some instances of this field may be defaulted, in others it may be required.
  21137. maxLength: 253
  21138. minLength: 1
  21139. pattern: ^[-._a-zA-Z0-9]+$
  21140. type: string
  21141. name:
  21142. description: The name of the Secret resource being referred to.
  21143. maxLength: 253
  21144. minLength: 1
  21145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21146. type: string
  21147. namespace:
  21148. description: |-
  21149. The namespace of the Secret resource being referred to.
  21150. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21151. maxLength: 63
  21152. minLength: 1
  21153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21154. type: string
  21155. type: object
  21156. token:
  21157. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  21158. properties:
  21159. key:
  21160. description: |-
  21161. A key in the referenced Secret.
  21162. Some instances of this field may be defaulted, in others it may be required.
  21163. maxLength: 253
  21164. minLength: 1
  21165. pattern: ^[-._a-zA-Z0-9]+$
  21166. type: string
  21167. name:
  21168. description: The name of the Secret resource being referred to.
  21169. maxLength: 253
  21170. minLength: 1
  21171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21172. type: string
  21173. namespace:
  21174. description: |-
  21175. The namespace of the Secret resource being referred to.
  21176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21177. maxLength: 63
  21178. minLength: 1
  21179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21180. type: string
  21181. type: object
  21182. required:
  21183. - accessKeyID
  21184. - secretAccessKey
  21185. type: object
  21186. type: object
  21187. region:
  21188. description: Region specifies the Volcengine region to connect to.
  21189. type: string
  21190. required:
  21191. - region
  21192. type: object
  21193. webhook:
  21194. description: Webhook configures this store to sync secrets using a generic templated webhook
  21195. properties:
  21196. auth:
  21197. description: Auth specifies a authorization protocol. Only one protocol may be set.
  21198. maxProperties: 1
  21199. minProperties: 1
  21200. properties:
  21201. ntlm:
  21202. description: NTLMProtocol configures the store to use NTLM for auth
  21203. properties:
  21204. passwordSecret:
  21205. description: |-
  21206. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21207. In some instances, `key` is a required field.
  21208. properties:
  21209. key:
  21210. description: |-
  21211. A key in the referenced Secret.
  21212. Some instances of this field may be defaulted, in others it may be required.
  21213. maxLength: 253
  21214. minLength: 1
  21215. pattern: ^[-._a-zA-Z0-9]+$
  21216. type: string
  21217. name:
  21218. description: The name of the Secret resource being referred to.
  21219. maxLength: 253
  21220. minLength: 1
  21221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21222. type: string
  21223. namespace:
  21224. description: |-
  21225. The namespace of the Secret resource being referred to.
  21226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21227. maxLength: 63
  21228. minLength: 1
  21229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21230. type: string
  21231. type: object
  21232. usernameSecret:
  21233. description: |-
  21234. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21235. In some instances, `key` is a required field.
  21236. properties:
  21237. key:
  21238. description: |-
  21239. A key in the referenced Secret.
  21240. Some instances of this field may be defaulted, in others it may be required.
  21241. maxLength: 253
  21242. minLength: 1
  21243. pattern: ^[-._a-zA-Z0-9]+$
  21244. type: string
  21245. name:
  21246. description: The name of the Secret resource being referred to.
  21247. maxLength: 253
  21248. minLength: 1
  21249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21250. type: string
  21251. namespace:
  21252. description: |-
  21253. The namespace of the Secret resource being referred to.
  21254. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21255. maxLength: 63
  21256. minLength: 1
  21257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21258. type: string
  21259. type: object
  21260. required:
  21261. - passwordSecret
  21262. - usernameSecret
  21263. type: object
  21264. type: object
  21265. body:
  21266. description: Body
  21267. type: string
  21268. caBundle:
  21269. description: |-
  21270. PEM encoded CA bundle used to validate webhook server certificate. Only used
  21271. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21272. plain HTTP protocol connection. If not set the system root certificates
  21273. are used to validate the TLS connection.
  21274. format: byte
  21275. type: string
  21276. caProvider:
  21277. description: The provider for the CA bundle to use to validate webhook server certificate.
  21278. properties:
  21279. key:
  21280. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21281. maxLength: 253
  21282. minLength: 1
  21283. pattern: ^[-._a-zA-Z0-9]+$
  21284. type: string
  21285. name:
  21286. description: The name of the object located at the provider type.
  21287. maxLength: 253
  21288. minLength: 1
  21289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21290. type: string
  21291. namespace:
  21292. description: The namespace the Provider type is in.
  21293. maxLength: 63
  21294. minLength: 1
  21295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21296. type: string
  21297. type:
  21298. description: The type of provider to use such as "Secret", or "ConfigMap".
  21299. enum:
  21300. - Secret
  21301. - ConfigMap
  21302. type: string
  21303. required:
  21304. - name
  21305. - type
  21306. type: object
  21307. headers:
  21308. additionalProperties:
  21309. type: string
  21310. description: Headers
  21311. type: object
  21312. method:
  21313. description: Webhook Method
  21314. type: string
  21315. result:
  21316. description: Result formatting
  21317. properties:
  21318. jsonPath:
  21319. description: Json path of return value
  21320. type: string
  21321. type: object
  21322. secrets:
  21323. description: |-
  21324. Secrets to fill in templates
  21325. These secrets will be passed to the templating function as key value pairs under the given name
  21326. items:
  21327. description: WebhookSecret defines a secret that will be passed to the webhook request.
  21328. properties:
  21329. name:
  21330. description: Name of this secret in templates
  21331. type: string
  21332. secretRef:
  21333. description: Secret ref to fill in credentials
  21334. properties:
  21335. key:
  21336. description: |-
  21337. A key in the referenced Secret.
  21338. Some instances of this field may be defaulted, in others it may be required.
  21339. maxLength: 253
  21340. minLength: 1
  21341. pattern: ^[-._a-zA-Z0-9]+$
  21342. type: string
  21343. name:
  21344. description: The name of the Secret resource being referred to.
  21345. maxLength: 253
  21346. minLength: 1
  21347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21348. type: string
  21349. namespace:
  21350. description: |-
  21351. The namespace of the Secret resource being referred to.
  21352. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21353. maxLength: 63
  21354. minLength: 1
  21355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21356. type: string
  21357. type: object
  21358. required:
  21359. - name
  21360. - secretRef
  21361. type: object
  21362. type: array
  21363. timeout:
  21364. description: Timeout
  21365. type: string
  21366. url:
  21367. description: Webhook url to call
  21368. type: string
  21369. required:
  21370. - url
  21371. type: object
  21372. yandexcertificatemanager:
  21373. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  21374. properties:
  21375. apiEndpoint:
  21376. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  21377. type: string
  21378. auth:
  21379. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  21380. properties:
  21381. authorizedKeySecretRef:
  21382. description: The authorized key used for authentication
  21383. properties:
  21384. key:
  21385. description: |-
  21386. A key in the referenced Secret.
  21387. Some instances of this field may be defaulted, in others it may be required.
  21388. maxLength: 253
  21389. minLength: 1
  21390. pattern: ^[-._a-zA-Z0-9]+$
  21391. type: string
  21392. name:
  21393. description: The name of the Secret resource being referred to.
  21394. maxLength: 253
  21395. minLength: 1
  21396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21397. type: string
  21398. namespace:
  21399. description: |-
  21400. The namespace of the Secret resource being referred to.
  21401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21402. maxLength: 63
  21403. minLength: 1
  21404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21405. type: string
  21406. type: object
  21407. type: object
  21408. caProvider:
  21409. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  21410. properties:
  21411. certSecretRef:
  21412. description: |-
  21413. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21414. In some instances, `key` is a required field.
  21415. properties:
  21416. key:
  21417. description: |-
  21418. A key in the referenced Secret.
  21419. Some instances of this field may be defaulted, in others it may be required.
  21420. maxLength: 253
  21421. minLength: 1
  21422. pattern: ^[-._a-zA-Z0-9]+$
  21423. type: string
  21424. name:
  21425. description: The name of the Secret resource being referred to.
  21426. maxLength: 253
  21427. minLength: 1
  21428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21429. type: string
  21430. namespace:
  21431. description: |-
  21432. The namespace of the Secret resource being referred to.
  21433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21434. maxLength: 63
  21435. minLength: 1
  21436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21437. type: string
  21438. type: object
  21439. type: object
  21440. fetching:
  21441. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  21442. maxProperties: 1
  21443. minProperties: 1
  21444. properties:
  21445. byID:
  21446. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  21447. type: object
  21448. byName:
  21449. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  21450. properties:
  21451. folderID:
  21452. description: The folder to fetch secrets from
  21453. type: string
  21454. required:
  21455. - folderID
  21456. type: object
  21457. type: object
  21458. required:
  21459. - auth
  21460. type: object
  21461. yandexlockbox:
  21462. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  21463. properties:
  21464. apiEndpoint:
  21465. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  21466. type: string
  21467. auth:
  21468. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  21469. properties:
  21470. authorizedKeySecretRef:
  21471. description: The authorized key used for authentication
  21472. properties:
  21473. key:
  21474. description: |-
  21475. A key in the referenced Secret.
  21476. Some instances of this field may be defaulted, in others it may be required.
  21477. maxLength: 253
  21478. minLength: 1
  21479. pattern: ^[-._a-zA-Z0-9]+$
  21480. type: string
  21481. name:
  21482. description: The name of the Secret resource being referred to.
  21483. maxLength: 253
  21484. minLength: 1
  21485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21486. type: string
  21487. namespace:
  21488. description: |-
  21489. The namespace of the Secret resource being referred to.
  21490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21491. maxLength: 63
  21492. minLength: 1
  21493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21494. type: string
  21495. type: object
  21496. type: object
  21497. caProvider:
  21498. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  21499. properties:
  21500. certSecretRef:
  21501. description: |-
  21502. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21503. In some instances, `key` is a required field.
  21504. properties:
  21505. key:
  21506. description: |-
  21507. A key in the referenced Secret.
  21508. Some instances of this field may be defaulted, in others it may be required.
  21509. maxLength: 253
  21510. minLength: 1
  21511. pattern: ^[-._a-zA-Z0-9]+$
  21512. type: string
  21513. name:
  21514. description: The name of the Secret resource being referred to.
  21515. maxLength: 253
  21516. minLength: 1
  21517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21518. type: string
  21519. namespace:
  21520. description: |-
  21521. The namespace of the Secret resource being referred to.
  21522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21523. maxLength: 63
  21524. minLength: 1
  21525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21526. type: string
  21527. type: object
  21528. type: object
  21529. fetching:
  21530. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  21531. maxProperties: 1
  21532. minProperties: 1
  21533. properties:
  21534. byID:
  21535. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  21536. type: object
  21537. byName:
  21538. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  21539. properties:
  21540. folderID:
  21541. description: The folder to fetch secrets from
  21542. type: string
  21543. required:
  21544. - folderID
  21545. type: object
  21546. type: object
  21547. required:
  21548. - auth
  21549. type: object
  21550. type: object
  21551. refreshInterval:
  21552. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  21553. type: integer
  21554. retrySettings:
  21555. description: Used to configure HTTP retries on failures.
  21556. properties:
  21557. maxRetries:
  21558. format: int32
  21559. type: integer
  21560. retryInterval:
  21561. type: string
  21562. type: object
  21563. required:
  21564. - provider
  21565. type: object
  21566. status:
  21567. description: SecretStoreStatus defines the observed state of the SecretStore.
  21568. properties:
  21569. capabilities:
  21570. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  21571. type: string
  21572. conditions:
  21573. items:
  21574. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  21575. properties:
  21576. lastTransitionTime:
  21577. format: date-time
  21578. type: string
  21579. message:
  21580. type: string
  21581. reason:
  21582. type: string
  21583. status:
  21584. type: string
  21585. type:
  21586. description: SecretStoreConditionType represents the condition of the SecretStore.
  21587. type: string
  21588. required:
  21589. - status
  21590. - type
  21591. type: object
  21592. type: array
  21593. type: object
  21594. type: object
  21595. served: true
  21596. storage: true
  21597. subresources:
  21598. status: {}
  21599. - additionalPrinterColumns:
  21600. - jsonPath: .metadata.creationTimestamp
  21601. name: AGE
  21602. type: date
  21603. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  21604. name: Status
  21605. type: string
  21606. - jsonPath: .status.capabilities
  21607. name: Capabilities
  21608. type: string
  21609. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  21610. name: Ready
  21611. type: string
  21612. deprecated: true
  21613. name: v1beta1
  21614. schema:
  21615. openAPIV3Schema:
  21616. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  21617. properties:
  21618. apiVersion:
  21619. description: |-
  21620. APIVersion defines the versioned schema of this representation of an object.
  21621. Servers should convert recognized schemas to the latest internal value, and
  21622. may reject unrecognized values.
  21623. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  21624. type: string
  21625. kind:
  21626. description: |-
  21627. Kind is a string value representing the REST resource this object represents.
  21628. Servers may infer this from the endpoint the client submits requests to.
  21629. Cannot be updated.
  21630. In CamelCase.
  21631. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  21632. type: string
  21633. metadata:
  21634. type: object
  21635. spec:
  21636. description: SecretStoreSpec defines the desired state of SecretStore.
  21637. properties:
  21638. conditions:
  21639. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  21640. items:
  21641. description: |-
  21642. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  21643. for a ClusterSecretStore instance.
  21644. properties:
  21645. namespaceRegexes:
  21646. description: Choose namespaces by using regex matching
  21647. items:
  21648. type: string
  21649. type: array
  21650. namespaceSelector:
  21651. description: Choose namespace using a labelSelector
  21652. properties:
  21653. matchExpressions:
  21654. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  21655. items:
  21656. description: |-
  21657. A label selector requirement is a selector that contains values, a key, and an operator that
  21658. relates the key and values.
  21659. properties:
  21660. key:
  21661. description: key is the label key that the selector applies to.
  21662. type: string
  21663. operator:
  21664. description: |-
  21665. operator represents a key's relationship to a set of values.
  21666. Valid operators are In, NotIn, Exists and DoesNotExist.
  21667. type: string
  21668. values:
  21669. description: |-
  21670. values is an array of string values. If the operator is In or NotIn,
  21671. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  21672. the values array must be empty. This array is replaced during a strategic
  21673. merge patch.
  21674. items:
  21675. type: string
  21676. type: array
  21677. x-kubernetes-list-type: atomic
  21678. required:
  21679. - key
  21680. - operator
  21681. type: object
  21682. type: array
  21683. x-kubernetes-list-type: atomic
  21684. matchLabels:
  21685. additionalProperties:
  21686. type: string
  21687. description: |-
  21688. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  21689. map is equivalent to an element of matchExpressions, whose key field is "key", the
  21690. operator is "In", and the values array contains only "value". The requirements are ANDed.
  21691. type: object
  21692. type: object
  21693. x-kubernetes-map-type: atomic
  21694. namespaces:
  21695. description: Choose namespaces by name
  21696. items:
  21697. maxLength: 63
  21698. minLength: 1
  21699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21700. type: string
  21701. type: array
  21702. type: object
  21703. type: array
  21704. controller:
  21705. description: |-
  21706. Used to select the correct ESO controller (think: ingress.ingressClassName)
  21707. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  21708. type: string
  21709. provider:
  21710. description: Used to configure the provider. Only one provider may be set
  21711. maxProperties: 1
  21712. minProperties: 1
  21713. properties:
  21714. akeyless:
  21715. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  21716. properties:
  21717. akeylessGWApiURL:
  21718. description: Akeyless GW API Url from which the secrets to be fetched from.
  21719. type: string
  21720. authSecretRef:
  21721. description: Auth configures how the operator authenticates with Akeyless.
  21722. properties:
  21723. kubernetesAuth:
  21724. description: |-
  21725. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  21726. token stored in the named Secret resource.
  21727. properties:
  21728. accessID:
  21729. description: the Akeyless Kubernetes auth-method access-id
  21730. type: string
  21731. k8sConfName:
  21732. description: Kubernetes-auth configuration name in Akeyless-Gateway
  21733. type: string
  21734. secretRef:
  21735. description: |-
  21736. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21737. for authenticating with Akeyless. If a name is specified without a key,
  21738. `token` is the default. If one is not specified, the one bound to
  21739. the controller will be used.
  21740. properties:
  21741. key:
  21742. description: |-
  21743. A key in the referenced Secret.
  21744. Some instances of this field may be defaulted, in others it may be required.
  21745. maxLength: 253
  21746. minLength: 1
  21747. pattern: ^[-._a-zA-Z0-9]+$
  21748. type: string
  21749. name:
  21750. description: The name of the Secret resource being referred to.
  21751. maxLength: 253
  21752. minLength: 1
  21753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21754. type: string
  21755. namespace:
  21756. description: |-
  21757. The namespace of the Secret resource being referred to.
  21758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21759. maxLength: 63
  21760. minLength: 1
  21761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21762. type: string
  21763. type: object
  21764. serviceAccountRef:
  21765. description: |-
  21766. Optional service account field containing the name of a kubernetes ServiceAccount.
  21767. If the service account is specified, the service account secret token JWT will be used
  21768. for authenticating with Akeyless. If the service account selector is not supplied,
  21769. the secretRef will be used instead.
  21770. properties:
  21771. audiences:
  21772. description: |-
  21773. Audience specifies the `aud` claim for the service account token
  21774. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21775. then this audiences will be appended to the list
  21776. items:
  21777. type: string
  21778. type: array
  21779. name:
  21780. description: The name of the ServiceAccount resource being referred to.
  21781. maxLength: 253
  21782. minLength: 1
  21783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21784. type: string
  21785. namespace:
  21786. description: |-
  21787. Namespace of the resource being referred to.
  21788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21789. maxLength: 63
  21790. minLength: 1
  21791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21792. type: string
  21793. required:
  21794. - name
  21795. type: object
  21796. required:
  21797. - accessID
  21798. - k8sConfName
  21799. type: object
  21800. secretRef:
  21801. description: |-
  21802. Reference to a Secret that contains the details
  21803. to authenticate with Akeyless.
  21804. properties:
  21805. accessID:
  21806. description: The SecretAccessID is used for authentication
  21807. properties:
  21808. key:
  21809. description: |-
  21810. A key in the referenced Secret.
  21811. Some instances of this field may be defaulted, in others it may be required.
  21812. maxLength: 253
  21813. minLength: 1
  21814. pattern: ^[-._a-zA-Z0-9]+$
  21815. type: string
  21816. name:
  21817. description: The name of the Secret resource being referred to.
  21818. maxLength: 253
  21819. minLength: 1
  21820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21821. type: string
  21822. namespace:
  21823. description: |-
  21824. The namespace of the Secret resource being referred to.
  21825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21826. maxLength: 63
  21827. minLength: 1
  21828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21829. type: string
  21830. type: object
  21831. accessType:
  21832. description: |-
  21833. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21834. In some instances, `key` is a required field.
  21835. properties:
  21836. key:
  21837. description: |-
  21838. A key in the referenced Secret.
  21839. Some instances of this field may be defaulted, in others it may be required.
  21840. maxLength: 253
  21841. minLength: 1
  21842. pattern: ^[-._a-zA-Z0-9]+$
  21843. type: string
  21844. name:
  21845. description: The name of the Secret resource being referred to.
  21846. maxLength: 253
  21847. minLength: 1
  21848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21849. type: string
  21850. namespace:
  21851. description: |-
  21852. The namespace of the Secret resource being referred to.
  21853. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21854. maxLength: 63
  21855. minLength: 1
  21856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21857. type: string
  21858. type: object
  21859. accessTypeParam:
  21860. description: |-
  21861. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21862. In some instances, `key` is a required field.
  21863. properties:
  21864. key:
  21865. description: |-
  21866. A key in the referenced Secret.
  21867. Some instances of this field may be defaulted, in others it may be required.
  21868. maxLength: 253
  21869. minLength: 1
  21870. pattern: ^[-._a-zA-Z0-9]+$
  21871. type: string
  21872. name:
  21873. description: The name of the Secret resource being referred to.
  21874. maxLength: 253
  21875. minLength: 1
  21876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21877. type: string
  21878. namespace:
  21879. description: |-
  21880. The namespace of the Secret resource being referred to.
  21881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21882. maxLength: 63
  21883. minLength: 1
  21884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21885. type: string
  21886. type: object
  21887. type: object
  21888. type: object
  21889. caBundle:
  21890. description: |-
  21891. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  21892. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  21893. are used to validate the TLS connection.
  21894. format: byte
  21895. type: string
  21896. caProvider:
  21897. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  21898. properties:
  21899. key:
  21900. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21901. maxLength: 253
  21902. minLength: 1
  21903. pattern: ^[-._a-zA-Z0-9]+$
  21904. type: string
  21905. name:
  21906. description: The name of the object located at the provider type.
  21907. maxLength: 253
  21908. minLength: 1
  21909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21910. type: string
  21911. namespace:
  21912. description: |-
  21913. The namespace the Provider type is in.
  21914. Can only be defined when used in a ClusterSecretStore.
  21915. maxLength: 63
  21916. minLength: 1
  21917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21918. type: string
  21919. type:
  21920. description: The type of provider to use such as "Secret", or "ConfigMap".
  21921. enum:
  21922. - Secret
  21923. - ConfigMap
  21924. type: string
  21925. required:
  21926. - name
  21927. - type
  21928. type: object
  21929. required:
  21930. - akeylessGWApiURL
  21931. - authSecretRef
  21932. type: object
  21933. alibaba:
  21934. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  21935. properties:
  21936. auth:
  21937. description: AlibabaAuth contains a secretRef for credentials.
  21938. properties:
  21939. rrsa:
  21940. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  21941. properties:
  21942. oidcProviderArn:
  21943. type: string
  21944. oidcTokenFilePath:
  21945. type: string
  21946. roleArn:
  21947. type: string
  21948. sessionName:
  21949. type: string
  21950. required:
  21951. - oidcProviderArn
  21952. - oidcTokenFilePath
  21953. - roleArn
  21954. - sessionName
  21955. type: object
  21956. secretRef:
  21957. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  21958. properties:
  21959. accessKeyIDSecretRef:
  21960. description: The AccessKeyID is used for authentication
  21961. properties:
  21962. key:
  21963. description: |-
  21964. A key in the referenced Secret.
  21965. Some instances of this field may be defaulted, in others it may be required.
  21966. maxLength: 253
  21967. minLength: 1
  21968. pattern: ^[-._a-zA-Z0-9]+$
  21969. type: string
  21970. name:
  21971. description: The name of the Secret resource being referred to.
  21972. maxLength: 253
  21973. minLength: 1
  21974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21975. type: string
  21976. namespace:
  21977. description: |-
  21978. The namespace of the Secret resource being referred to.
  21979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21980. maxLength: 63
  21981. minLength: 1
  21982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21983. type: string
  21984. type: object
  21985. accessKeySecretSecretRef:
  21986. description: The AccessKeySecret is used for authentication
  21987. properties:
  21988. key:
  21989. description: |-
  21990. A key in the referenced Secret.
  21991. Some instances of this field may be defaulted, in others it may be required.
  21992. maxLength: 253
  21993. minLength: 1
  21994. pattern: ^[-._a-zA-Z0-9]+$
  21995. type: string
  21996. name:
  21997. description: The name of the Secret resource being referred to.
  21998. maxLength: 253
  21999. minLength: 1
  22000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22001. type: string
  22002. namespace:
  22003. description: |-
  22004. The namespace of the Secret resource being referred to.
  22005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22006. maxLength: 63
  22007. minLength: 1
  22008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22009. type: string
  22010. type: object
  22011. required:
  22012. - accessKeyIDSecretRef
  22013. - accessKeySecretSecretRef
  22014. type: object
  22015. type: object
  22016. regionID:
  22017. description: Alibaba Region to be used for the provider
  22018. type: string
  22019. required:
  22020. - auth
  22021. - regionID
  22022. type: object
  22023. aws:
  22024. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22025. properties:
  22026. additionalRoles:
  22027. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22028. items:
  22029. type: string
  22030. type: array
  22031. auth:
  22032. description: |-
  22033. Auth defines the information necessary to authenticate against AWS
  22034. if not set aws sdk will infer credentials from your environment
  22035. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22036. properties:
  22037. jwt:
  22038. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22039. properties:
  22040. serviceAccountRef:
  22041. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22042. properties:
  22043. audiences:
  22044. description: |-
  22045. Audience specifies the `aud` claim for the service account token
  22046. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22047. then this audiences will be appended to the list
  22048. items:
  22049. type: string
  22050. type: array
  22051. name:
  22052. description: The name of the ServiceAccount resource being referred to.
  22053. maxLength: 253
  22054. minLength: 1
  22055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22056. type: string
  22057. namespace:
  22058. description: |-
  22059. Namespace of the resource being referred to.
  22060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22061. maxLength: 63
  22062. minLength: 1
  22063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22064. type: string
  22065. required:
  22066. - name
  22067. type: object
  22068. type: object
  22069. secretRef:
  22070. description: |-
  22071. AWSAuthSecretRef holds secret references for AWS credentials
  22072. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22073. properties:
  22074. accessKeyIDSecretRef:
  22075. description: The AccessKeyID is used for authentication
  22076. properties:
  22077. key:
  22078. description: |-
  22079. A key in the referenced Secret.
  22080. Some instances of this field may be defaulted, in others it may be required.
  22081. maxLength: 253
  22082. minLength: 1
  22083. pattern: ^[-._a-zA-Z0-9]+$
  22084. type: string
  22085. name:
  22086. description: The name of the Secret resource being referred to.
  22087. maxLength: 253
  22088. minLength: 1
  22089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22090. type: string
  22091. namespace:
  22092. description: |-
  22093. The namespace of the Secret resource being referred to.
  22094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22095. maxLength: 63
  22096. minLength: 1
  22097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22098. type: string
  22099. type: object
  22100. secretAccessKeySecretRef:
  22101. description: The SecretAccessKey is used for authentication
  22102. properties:
  22103. key:
  22104. description: |-
  22105. A key in the referenced Secret.
  22106. Some instances of this field may be defaulted, in others it may be required.
  22107. maxLength: 253
  22108. minLength: 1
  22109. pattern: ^[-._a-zA-Z0-9]+$
  22110. type: string
  22111. name:
  22112. description: The name of the Secret resource being referred to.
  22113. maxLength: 253
  22114. minLength: 1
  22115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22116. type: string
  22117. namespace:
  22118. description: |-
  22119. The namespace of the Secret resource being referred to.
  22120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22121. maxLength: 63
  22122. minLength: 1
  22123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22124. type: string
  22125. type: object
  22126. sessionTokenSecretRef:
  22127. description: |-
  22128. The SessionToken used for authentication
  22129. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22130. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22131. properties:
  22132. key:
  22133. description: |-
  22134. A key in the referenced Secret.
  22135. Some instances of this field may be defaulted, in others it may be required.
  22136. maxLength: 253
  22137. minLength: 1
  22138. pattern: ^[-._a-zA-Z0-9]+$
  22139. type: string
  22140. name:
  22141. description: The name of the Secret resource being referred to.
  22142. maxLength: 253
  22143. minLength: 1
  22144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22145. type: string
  22146. namespace:
  22147. description: |-
  22148. The namespace of the Secret resource being referred to.
  22149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22150. maxLength: 63
  22151. minLength: 1
  22152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22153. type: string
  22154. type: object
  22155. type: object
  22156. type: object
  22157. externalID:
  22158. description: AWS External ID set on assumed IAM roles
  22159. type: string
  22160. prefix:
  22161. description: Prefix adds a prefix to all retrieved values.
  22162. type: string
  22163. region:
  22164. description: AWS Region to be used for the provider
  22165. type: string
  22166. role:
  22167. description: Role is a Role ARN which the provider will assume
  22168. type: string
  22169. secretsManager:
  22170. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  22171. properties:
  22172. forceDeleteWithoutRecovery:
  22173. description: |-
  22174. Specifies whether to delete the secret without any recovery window. You
  22175. can't use both this parameter and RecoveryWindowInDays in the same call.
  22176. If you don't use either, then by default Secrets Manager uses a 30 day
  22177. recovery window.
  22178. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  22179. type: boolean
  22180. recoveryWindowInDays:
  22181. description: |-
  22182. The number of days from 7 to 30 that Secrets Manager waits before
  22183. permanently deleting the secret. You can't use both this parameter and
  22184. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  22185. then by default Secrets Manager uses a 30 day recovery window.
  22186. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  22187. format: int64
  22188. type: integer
  22189. type: object
  22190. service:
  22191. description: Service defines which service should be used to fetch the secrets
  22192. enum:
  22193. - SecretsManager
  22194. - ParameterStore
  22195. type: string
  22196. sessionTags:
  22197. description: AWS STS assume role session tags
  22198. items:
  22199. description: Tag defines a tag key and value for AWS resources.
  22200. properties:
  22201. key:
  22202. type: string
  22203. value:
  22204. type: string
  22205. required:
  22206. - key
  22207. - value
  22208. type: object
  22209. type: array
  22210. transitiveTagKeys:
  22211. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  22212. items:
  22213. type: string
  22214. type: array
  22215. required:
  22216. - region
  22217. - service
  22218. type: object
  22219. azurekv:
  22220. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  22221. properties:
  22222. authSecretRef:
  22223. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  22224. properties:
  22225. clientCertificate:
  22226. description: The Azure ClientCertificate of the service principle used for authentication.
  22227. properties:
  22228. key:
  22229. description: |-
  22230. A key in the referenced Secret.
  22231. Some instances of this field may be defaulted, in others it may be required.
  22232. maxLength: 253
  22233. minLength: 1
  22234. pattern: ^[-._a-zA-Z0-9]+$
  22235. type: string
  22236. name:
  22237. description: The name of the Secret resource being referred to.
  22238. maxLength: 253
  22239. minLength: 1
  22240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22241. type: string
  22242. namespace:
  22243. description: |-
  22244. The namespace of the Secret resource being referred to.
  22245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22246. maxLength: 63
  22247. minLength: 1
  22248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22249. type: string
  22250. type: object
  22251. clientId:
  22252. description: The Azure clientId of the service principle or managed identity used for authentication.
  22253. properties:
  22254. key:
  22255. description: |-
  22256. A key in the referenced Secret.
  22257. Some instances of this field may be defaulted, in others it may be required.
  22258. maxLength: 253
  22259. minLength: 1
  22260. pattern: ^[-._a-zA-Z0-9]+$
  22261. type: string
  22262. name:
  22263. description: The name of the Secret resource being referred to.
  22264. maxLength: 253
  22265. minLength: 1
  22266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22267. type: string
  22268. namespace:
  22269. description: |-
  22270. The namespace of the Secret resource being referred to.
  22271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22272. maxLength: 63
  22273. minLength: 1
  22274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22275. type: string
  22276. type: object
  22277. clientSecret:
  22278. description: The Azure ClientSecret of the service principle used for authentication.
  22279. properties:
  22280. key:
  22281. description: |-
  22282. A key in the referenced Secret.
  22283. Some instances of this field may be defaulted, in others it may be required.
  22284. maxLength: 253
  22285. minLength: 1
  22286. pattern: ^[-._a-zA-Z0-9]+$
  22287. type: string
  22288. name:
  22289. description: The name of the Secret resource being referred to.
  22290. maxLength: 253
  22291. minLength: 1
  22292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22293. type: string
  22294. namespace:
  22295. description: |-
  22296. The namespace of the Secret resource being referred to.
  22297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22298. maxLength: 63
  22299. minLength: 1
  22300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22301. type: string
  22302. type: object
  22303. tenantId:
  22304. description: The Azure tenantId of the managed identity used for authentication.
  22305. properties:
  22306. key:
  22307. description: |-
  22308. A key in the referenced Secret.
  22309. Some instances of this field may be defaulted, in others it may be required.
  22310. maxLength: 253
  22311. minLength: 1
  22312. pattern: ^[-._a-zA-Z0-9]+$
  22313. type: string
  22314. name:
  22315. description: The name of the Secret resource being referred to.
  22316. maxLength: 253
  22317. minLength: 1
  22318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22319. type: string
  22320. namespace:
  22321. description: |-
  22322. The namespace of the Secret resource being referred to.
  22323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22324. maxLength: 63
  22325. minLength: 1
  22326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22327. type: string
  22328. type: object
  22329. type: object
  22330. authType:
  22331. default: ServicePrincipal
  22332. description: |-
  22333. Auth type defines how to authenticate to the keyvault service.
  22334. Valid values are:
  22335. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  22336. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  22337. enum:
  22338. - ServicePrincipal
  22339. - ManagedIdentity
  22340. - WorkloadIdentity
  22341. type: string
  22342. environmentType:
  22343. default: PublicCloud
  22344. description: |-
  22345. EnvironmentType specifies the Azure cloud environment endpoints to use for
  22346. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  22347. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  22348. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  22349. enum:
  22350. - PublicCloud
  22351. - USGovernmentCloud
  22352. - ChinaCloud
  22353. - GermanCloud
  22354. type: string
  22355. identityId:
  22356. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  22357. type: string
  22358. serviceAccountRef:
  22359. description: |-
  22360. ServiceAccountRef specified the service account
  22361. that should be used when authenticating with WorkloadIdentity.
  22362. properties:
  22363. audiences:
  22364. description: |-
  22365. Audience specifies the `aud` claim for the service account token
  22366. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22367. then this audiences will be appended to the list
  22368. items:
  22369. type: string
  22370. type: array
  22371. name:
  22372. description: The name of the ServiceAccount resource being referred to.
  22373. maxLength: 253
  22374. minLength: 1
  22375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22376. type: string
  22377. namespace:
  22378. description: |-
  22379. Namespace of the resource being referred to.
  22380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22381. maxLength: 63
  22382. minLength: 1
  22383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22384. type: string
  22385. required:
  22386. - name
  22387. type: object
  22388. tenantId:
  22389. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  22390. type: string
  22391. vaultUrl:
  22392. description: Vault Url from which the secrets to be fetched from.
  22393. type: string
  22394. required:
  22395. - vaultUrl
  22396. type: object
  22397. beyondtrust:
  22398. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  22399. properties:
  22400. auth:
  22401. description: Auth configures how the operator authenticates with Beyondtrust.
  22402. properties:
  22403. apiKey:
  22404. description: APIKey If not provided then ClientID/ClientSecret become required.
  22405. properties:
  22406. secretRef:
  22407. description: SecretRef references a key in a secret that will be used as value.
  22408. properties:
  22409. key:
  22410. description: |-
  22411. A key in the referenced Secret.
  22412. Some instances of this field may be defaulted, in others it may be required.
  22413. maxLength: 253
  22414. minLength: 1
  22415. pattern: ^[-._a-zA-Z0-9]+$
  22416. type: string
  22417. name:
  22418. description: The name of the Secret resource being referred to.
  22419. maxLength: 253
  22420. minLength: 1
  22421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22422. type: string
  22423. namespace:
  22424. description: |-
  22425. The namespace of the Secret resource being referred to.
  22426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22427. maxLength: 63
  22428. minLength: 1
  22429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22430. type: string
  22431. type: object
  22432. value:
  22433. description: Value can be specified directly to set a value without using a secret.
  22434. type: string
  22435. type: object
  22436. certificate:
  22437. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  22438. properties:
  22439. secretRef:
  22440. description: SecretRef references a key in a secret that will be used as value.
  22441. properties:
  22442. key:
  22443. description: |-
  22444. A key in the referenced Secret.
  22445. Some instances of this field may be defaulted, in others it may be required.
  22446. maxLength: 253
  22447. minLength: 1
  22448. pattern: ^[-._a-zA-Z0-9]+$
  22449. type: string
  22450. name:
  22451. description: The name of the Secret resource being referred to.
  22452. maxLength: 253
  22453. minLength: 1
  22454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22455. type: string
  22456. namespace:
  22457. description: |-
  22458. The namespace of the Secret resource being referred to.
  22459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22460. maxLength: 63
  22461. minLength: 1
  22462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22463. type: string
  22464. type: object
  22465. value:
  22466. description: Value can be specified directly to set a value without using a secret.
  22467. type: string
  22468. type: object
  22469. certificateKey:
  22470. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  22471. properties:
  22472. secretRef:
  22473. description: SecretRef references a key in a secret that will be used as value.
  22474. properties:
  22475. key:
  22476. description: |-
  22477. A key in the referenced Secret.
  22478. Some instances of this field may be defaulted, in others it may be required.
  22479. maxLength: 253
  22480. minLength: 1
  22481. pattern: ^[-._a-zA-Z0-9]+$
  22482. type: string
  22483. name:
  22484. description: The name of the Secret resource being referred to.
  22485. maxLength: 253
  22486. minLength: 1
  22487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22488. type: string
  22489. namespace:
  22490. description: |-
  22491. The namespace of the Secret resource being referred to.
  22492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22493. maxLength: 63
  22494. minLength: 1
  22495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22496. type: string
  22497. type: object
  22498. value:
  22499. description: Value can be specified directly to set a value without using a secret.
  22500. type: string
  22501. type: object
  22502. clientId:
  22503. description: ClientID is the API OAuth Client ID.
  22504. properties:
  22505. secretRef:
  22506. description: SecretRef references a key in a secret that will be used as value.
  22507. properties:
  22508. key:
  22509. description: |-
  22510. A key in the referenced Secret.
  22511. Some instances of this field may be defaulted, in others it may be required.
  22512. maxLength: 253
  22513. minLength: 1
  22514. pattern: ^[-._a-zA-Z0-9]+$
  22515. type: string
  22516. name:
  22517. description: The name of the Secret resource being referred to.
  22518. maxLength: 253
  22519. minLength: 1
  22520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22521. type: string
  22522. namespace:
  22523. description: |-
  22524. The namespace of the Secret resource being referred to.
  22525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22526. maxLength: 63
  22527. minLength: 1
  22528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22529. type: string
  22530. type: object
  22531. value:
  22532. description: Value can be specified directly to set a value without using a secret.
  22533. type: string
  22534. type: object
  22535. clientSecret:
  22536. description: ClientSecret is the API OAuth Client Secret.
  22537. properties:
  22538. secretRef:
  22539. description: SecretRef references a key in a secret that will be used as value.
  22540. properties:
  22541. key:
  22542. description: |-
  22543. A key in the referenced Secret.
  22544. Some instances of this field may be defaulted, in others it may be required.
  22545. maxLength: 253
  22546. minLength: 1
  22547. pattern: ^[-._a-zA-Z0-9]+$
  22548. type: string
  22549. name:
  22550. description: The name of the Secret resource being referred to.
  22551. maxLength: 253
  22552. minLength: 1
  22553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22554. type: string
  22555. namespace:
  22556. description: |-
  22557. The namespace of the Secret resource being referred to.
  22558. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22559. maxLength: 63
  22560. minLength: 1
  22561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22562. type: string
  22563. type: object
  22564. value:
  22565. description: Value can be specified directly to set a value without using a secret.
  22566. type: string
  22567. type: object
  22568. type: object
  22569. server:
  22570. description: Auth configures how API server works.
  22571. properties:
  22572. apiUrl:
  22573. type: string
  22574. apiVersion:
  22575. type: string
  22576. clientTimeOutSeconds:
  22577. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  22578. type: integer
  22579. decrypt:
  22580. default: true
  22581. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  22582. type: boolean
  22583. retrievalType:
  22584. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  22585. type: string
  22586. separator:
  22587. description: A character that separates the folder names.
  22588. type: string
  22589. verifyCA:
  22590. type: boolean
  22591. required:
  22592. - apiUrl
  22593. - verifyCA
  22594. type: object
  22595. required:
  22596. - auth
  22597. - server
  22598. type: object
  22599. bitwardensecretsmanager:
  22600. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  22601. properties:
  22602. apiURL:
  22603. type: string
  22604. auth:
  22605. description: |-
  22606. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  22607. Make sure that the token being used has permissions on the given secret.
  22608. properties:
  22609. secretRef:
  22610. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  22611. properties:
  22612. credentials:
  22613. description: AccessToken used for the bitwarden instance.
  22614. properties:
  22615. key:
  22616. description: |-
  22617. A key in the referenced Secret.
  22618. Some instances of this field may be defaulted, in others it may be required.
  22619. maxLength: 253
  22620. minLength: 1
  22621. pattern: ^[-._a-zA-Z0-9]+$
  22622. type: string
  22623. name:
  22624. description: The name of the Secret resource being referred to.
  22625. maxLength: 253
  22626. minLength: 1
  22627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22628. type: string
  22629. namespace:
  22630. description: |-
  22631. The namespace of the Secret resource being referred to.
  22632. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22633. maxLength: 63
  22634. minLength: 1
  22635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22636. type: string
  22637. type: object
  22638. required:
  22639. - credentials
  22640. type: object
  22641. required:
  22642. - secretRef
  22643. type: object
  22644. bitwardenServerSDKURL:
  22645. type: string
  22646. caBundle:
  22647. description: |-
  22648. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  22649. can be performed.
  22650. type: string
  22651. caProvider:
  22652. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  22653. properties:
  22654. key:
  22655. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22656. maxLength: 253
  22657. minLength: 1
  22658. pattern: ^[-._a-zA-Z0-9]+$
  22659. type: string
  22660. name:
  22661. description: The name of the object located at the provider type.
  22662. maxLength: 253
  22663. minLength: 1
  22664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22665. type: string
  22666. namespace:
  22667. description: |-
  22668. The namespace the Provider type is in.
  22669. Can only be defined when used in a ClusterSecretStore.
  22670. maxLength: 63
  22671. minLength: 1
  22672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22673. type: string
  22674. type:
  22675. description: The type of provider to use such as "Secret", or "ConfigMap".
  22676. enum:
  22677. - Secret
  22678. - ConfigMap
  22679. type: string
  22680. required:
  22681. - name
  22682. - type
  22683. type: object
  22684. identityURL:
  22685. type: string
  22686. organizationID:
  22687. description: OrganizationID determines which organization this secret store manages.
  22688. type: string
  22689. projectID:
  22690. description: ProjectID determines which project this secret store manages.
  22691. type: string
  22692. required:
  22693. - auth
  22694. - organizationID
  22695. - projectID
  22696. type: object
  22697. chef:
  22698. description: Chef configures this store to sync secrets with chef server
  22699. properties:
  22700. auth:
  22701. description: Auth defines the information necessary to authenticate against chef Server
  22702. properties:
  22703. secretRef:
  22704. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  22705. properties:
  22706. privateKeySecretRef:
  22707. description: SecretKey is the Signing Key in PEM format, used for authentication.
  22708. properties:
  22709. key:
  22710. description: |-
  22711. A key in the referenced Secret.
  22712. Some instances of this field may be defaulted, in others it may be required.
  22713. maxLength: 253
  22714. minLength: 1
  22715. pattern: ^[-._a-zA-Z0-9]+$
  22716. type: string
  22717. name:
  22718. description: The name of the Secret resource being referred to.
  22719. maxLength: 253
  22720. minLength: 1
  22721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22722. type: string
  22723. namespace:
  22724. description: |-
  22725. The namespace of the Secret resource being referred to.
  22726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22727. maxLength: 63
  22728. minLength: 1
  22729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22730. type: string
  22731. type: object
  22732. required:
  22733. - privateKeySecretRef
  22734. type: object
  22735. required:
  22736. - secretRef
  22737. type: object
  22738. serverUrl:
  22739. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  22740. type: string
  22741. username:
  22742. description: UserName should be the user ID on the chef server
  22743. type: string
  22744. required:
  22745. - auth
  22746. - serverUrl
  22747. - username
  22748. type: object
  22749. cloudrusm:
  22750. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  22751. properties:
  22752. auth:
  22753. description: CSMAuth contains a secretRef for credentials.
  22754. properties:
  22755. secretRef:
  22756. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  22757. properties:
  22758. accessKeyIDSecretRef:
  22759. description: The AccessKeyID is used for authentication
  22760. properties:
  22761. key:
  22762. description: |-
  22763. A key in the referenced Secret.
  22764. Some instances of this field may be defaulted, in others it may be required.
  22765. maxLength: 253
  22766. minLength: 1
  22767. pattern: ^[-._a-zA-Z0-9]+$
  22768. type: string
  22769. name:
  22770. description: The name of the Secret resource being referred to.
  22771. maxLength: 253
  22772. minLength: 1
  22773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22774. type: string
  22775. namespace:
  22776. description: |-
  22777. The namespace of the Secret resource being referred to.
  22778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22779. maxLength: 63
  22780. minLength: 1
  22781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22782. type: string
  22783. type: object
  22784. accessKeySecretSecretRef:
  22785. description: The AccessKeySecret is used for authentication
  22786. properties:
  22787. key:
  22788. description: |-
  22789. A key in the referenced Secret.
  22790. Some instances of this field may be defaulted, in others it may be required.
  22791. maxLength: 253
  22792. minLength: 1
  22793. pattern: ^[-._a-zA-Z0-9]+$
  22794. type: string
  22795. name:
  22796. description: The name of the Secret resource being referred to.
  22797. maxLength: 253
  22798. minLength: 1
  22799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22800. type: string
  22801. namespace:
  22802. description: |-
  22803. The namespace of the Secret resource being referred to.
  22804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22805. maxLength: 63
  22806. minLength: 1
  22807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22808. type: string
  22809. type: object
  22810. required:
  22811. - accessKeyIDSecretRef
  22812. - accessKeySecretSecretRef
  22813. type: object
  22814. type: object
  22815. projectID:
  22816. description: ProjectID is the project, which the secrets are stored in.
  22817. type: string
  22818. required:
  22819. - auth
  22820. type: object
  22821. conjur:
  22822. description: Conjur configures this store to sync secrets using conjur provider
  22823. properties:
  22824. auth:
  22825. description: Defines authentication settings for connecting to Conjur.
  22826. properties:
  22827. apikey:
  22828. description: Authenticates with Conjur using an API key.
  22829. properties:
  22830. account:
  22831. description: Account is the Conjur organization account name.
  22832. type: string
  22833. apiKeyRef:
  22834. description: |-
  22835. A reference to a specific 'key' containing the Conjur API key
  22836. within a Secret resource. In some instances, `key` is a required field.
  22837. properties:
  22838. key:
  22839. description: |-
  22840. A key in the referenced Secret.
  22841. Some instances of this field may be defaulted, in others it may be required.
  22842. maxLength: 253
  22843. minLength: 1
  22844. pattern: ^[-._a-zA-Z0-9]+$
  22845. type: string
  22846. name:
  22847. description: The name of the Secret resource being referred to.
  22848. maxLength: 253
  22849. minLength: 1
  22850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22851. type: string
  22852. namespace:
  22853. description: |-
  22854. The namespace of the Secret resource being referred to.
  22855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22856. maxLength: 63
  22857. minLength: 1
  22858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22859. type: string
  22860. type: object
  22861. userRef:
  22862. description: |-
  22863. A reference to a specific 'key' containing the Conjur username
  22864. within a Secret resource. In some instances, `key` is a required field.
  22865. properties:
  22866. key:
  22867. description: |-
  22868. A key in the referenced Secret.
  22869. Some instances of this field may be defaulted, in others it may be required.
  22870. maxLength: 253
  22871. minLength: 1
  22872. pattern: ^[-._a-zA-Z0-9]+$
  22873. type: string
  22874. name:
  22875. description: The name of the Secret resource being referred to.
  22876. maxLength: 253
  22877. minLength: 1
  22878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22879. type: string
  22880. namespace:
  22881. description: |-
  22882. The namespace of the Secret resource being referred to.
  22883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22884. maxLength: 63
  22885. minLength: 1
  22886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22887. type: string
  22888. type: object
  22889. required:
  22890. - account
  22891. - apiKeyRef
  22892. - userRef
  22893. type: object
  22894. jwt:
  22895. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  22896. properties:
  22897. account:
  22898. description: Account is the Conjur organization account name.
  22899. type: string
  22900. hostId:
  22901. description: |-
  22902. Optional HostID for JWT authentication. This may be used depending
  22903. on how the Conjur JWT authenticator policy is configured.
  22904. type: string
  22905. secretRef:
  22906. description: |-
  22907. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  22908. authenticate with Conjur using the JWT authentication method.
  22909. properties:
  22910. key:
  22911. description: |-
  22912. A key in the referenced Secret.
  22913. Some instances of this field may be defaulted, in others it may be required.
  22914. maxLength: 253
  22915. minLength: 1
  22916. pattern: ^[-._a-zA-Z0-9]+$
  22917. type: string
  22918. name:
  22919. description: The name of the Secret resource being referred to.
  22920. maxLength: 253
  22921. minLength: 1
  22922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22923. type: string
  22924. namespace:
  22925. description: |-
  22926. The namespace of the Secret resource being referred to.
  22927. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22928. maxLength: 63
  22929. minLength: 1
  22930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22931. type: string
  22932. type: object
  22933. serviceAccountRef:
  22934. description: |-
  22935. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  22936. a token for with the `TokenRequest` API.
  22937. properties:
  22938. audiences:
  22939. description: |-
  22940. Audience specifies the `aud` claim for the service account token
  22941. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22942. then this audiences will be appended to the list
  22943. items:
  22944. type: string
  22945. type: array
  22946. name:
  22947. description: The name of the ServiceAccount resource being referred to.
  22948. maxLength: 253
  22949. minLength: 1
  22950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22951. type: string
  22952. namespace:
  22953. description: |-
  22954. Namespace of the resource being referred to.
  22955. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22956. maxLength: 63
  22957. minLength: 1
  22958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22959. type: string
  22960. required:
  22961. - name
  22962. type: object
  22963. serviceID:
  22964. description: The conjur authn jwt webservice id
  22965. type: string
  22966. required:
  22967. - account
  22968. - serviceID
  22969. type: object
  22970. type: object
  22971. caBundle:
  22972. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  22973. type: string
  22974. caProvider:
  22975. description: |-
  22976. Used to provide custom certificate authority (CA) certificates
  22977. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  22978. that contains a PEM-encoded certificate.
  22979. properties:
  22980. key:
  22981. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22982. maxLength: 253
  22983. minLength: 1
  22984. pattern: ^[-._a-zA-Z0-9]+$
  22985. type: string
  22986. name:
  22987. description: The name of the object located at the provider type.
  22988. maxLength: 253
  22989. minLength: 1
  22990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22991. type: string
  22992. namespace:
  22993. description: |-
  22994. The namespace the Provider type is in.
  22995. Can only be defined when used in a ClusterSecretStore.
  22996. maxLength: 63
  22997. minLength: 1
  22998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22999. type: string
  23000. type:
  23001. description: The type of provider to use such as "Secret", or "ConfigMap".
  23002. enum:
  23003. - Secret
  23004. - ConfigMap
  23005. type: string
  23006. required:
  23007. - name
  23008. - type
  23009. type: object
  23010. url:
  23011. description: URL is the endpoint of the Conjur instance.
  23012. type: string
  23013. required:
  23014. - auth
  23015. - url
  23016. type: object
  23017. delinea:
  23018. description: |-
  23019. Delinea DevOps Secrets Vault
  23020. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23021. properties:
  23022. clientId:
  23023. description: ClientID is the non-secret part of the credential.
  23024. properties:
  23025. secretRef:
  23026. description: SecretRef references a key in a secret that will be used as value.
  23027. properties:
  23028. key:
  23029. description: |-
  23030. A key in the referenced Secret.
  23031. Some instances of this field may be defaulted, in others it may be required.
  23032. maxLength: 253
  23033. minLength: 1
  23034. pattern: ^[-._a-zA-Z0-9]+$
  23035. type: string
  23036. name:
  23037. description: The name of the Secret resource being referred to.
  23038. maxLength: 253
  23039. minLength: 1
  23040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23041. type: string
  23042. namespace:
  23043. description: |-
  23044. The namespace of the Secret resource being referred to.
  23045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23046. maxLength: 63
  23047. minLength: 1
  23048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23049. type: string
  23050. type: object
  23051. value:
  23052. description: Value can be specified directly to set a value without using a secret.
  23053. type: string
  23054. type: object
  23055. clientSecret:
  23056. description: ClientSecret is the secret part of the credential.
  23057. properties:
  23058. secretRef:
  23059. description: SecretRef references a key in a secret that will be used as value.
  23060. properties:
  23061. key:
  23062. description: |-
  23063. A key in the referenced Secret.
  23064. Some instances of this field may be defaulted, in others it may be required.
  23065. maxLength: 253
  23066. minLength: 1
  23067. pattern: ^[-._a-zA-Z0-9]+$
  23068. type: string
  23069. name:
  23070. description: The name of the Secret resource being referred to.
  23071. maxLength: 253
  23072. minLength: 1
  23073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23074. type: string
  23075. namespace:
  23076. description: |-
  23077. The namespace of the Secret resource being referred to.
  23078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23079. maxLength: 63
  23080. minLength: 1
  23081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23082. type: string
  23083. type: object
  23084. value:
  23085. description: Value can be specified directly to set a value without using a secret.
  23086. type: string
  23087. type: object
  23088. tenant:
  23089. description: Tenant is the chosen hostname / site name.
  23090. type: string
  23091. tld:
  23092. description: |-
  23093. TLD is based on the server location that was chosen during provisioning.
  23094. If unset, defaults to "com".
  23095. type: string
  23096. urlTemplate:
  23097. description: |-
  23098. URLTemplate
  23099. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23100. type: string
  23101. required:
  23102. - clientId
  23103. - clientSecret
  23104. - tenant
  23105. type: object
  23106. device42:
  23107. description: Device42 configures this store to sync secrets using the Device42 provider
  23108. properties:
  23109. auth:
  23110. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23111. properties:
  23112. secretRef:
  23113. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23114. properties:
  23115. credentials:
  23116. description: Username / Password is used for authentication.
  23117. properties:
  23118. key:
  23119. description: |-
  23120. A key in the referenced Secret.
  23121. Some instances of this field may be defaulted, in others it may be required.
  23122. maxLength: 253
  23123. minLength: 1
  23124. pattern: ^[-._a-zA-Z0-9]+$
  23125. type: string
  23126. name:
  23127. description: The name of the Secret resource being referred to.
  23128. maxLength: 253
  23129. minLength: 1
  23130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23131. type: string
  23132. namespace:
  23133. description: |-
  23134. The namespace of the Secret resource being referred to.
  23135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23136. maxLength: 63
  23137. minLength: 1
  23138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23139. type: string
  23140. type: object
  23141. type: object
  23142. required:
  23143. - secretRef
  23144. type: object
  23145. host:
  23146. description: URL configures the Device42 instance URL.
  23147. type: string
  23148. required:
  23149. - auth
  23150. - host
  23151. type: object
  23152. doppler:
  23153. description: Doppler configures this store to sync secrets using the Doppler provider
  23154. properties:
  23155. auth:
  23156. description: Auth configures how the Operator authenticates with the Doppler API
  23157. properties:
  23158. secretRef:
  23159. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  23160. properties:
  23161. dopplerToken:
  23162. description: |-
  23163. The DopplerToken is used for authentication.
  23164. See https://docs.doppler.com/reference/api#authentication for auth token types.
  23165. The Key attribute defaults to dopplerToken if not specified.
  23166. properties:
  23167. key:
  23168. description: |-
  23169. A key in the referenced Secret.
  23170. Some instances of this field may be defaulted, in others it may be required.
  23171. maxLength: 253
  23172. minLength: 1
  23173. pattern: ^[-._a-zA-Z0-9]+$
  23174. type: string
  23175. name:
  23176. description: The name of the Secret resource being referred to.
  23177. maxLength: 253
  23178. minLength: 1
  23179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23180. type: string
  23181. namespace:
  23182. description: |-
  23183. The namespace of the Secret resource being referred to.
  23184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23185. maxLength: 63
  23186. minLength: 1
  23187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23188. type: string
  23189. type: object
  23190. required:
  23191. - dopplerToken
  23192. type: object
  23193. required:
  23194. - secretRef
  23195. type: object
  23196. config:
  23197. description: Doppler config (required if not using a Service Token)
  23198. type: string
  23199. format:
  23200. description: Format enables the downloading of secrets as a file (string)
  23201. enum:
  23202. - json
  23203. - dotnet-json
  23204. - env
  23205. - yaml
  23206. - docker
  23207. type: string
  23208. nameTransformer:
  23209. description: Environment variable compatible name transforms that change secret names to a different format
  23210. enum:
  23211. - upper-camel
  23212. - camel
  23213. - lower-snake
  23214. - tf-var
  23215. - dotnet-env
  23216. - lower-kebab
  23217. type: string
  23218. project:
  23219. description: Doppler project (required if not using a Service Token)
  23220. type: string
  23221. required:
  23222. - auth
  23223. type: object
  23224. fake:
  23225. description: Fake configures a store with static key/value pairs
  23226. properties:
  23227. data:
  23228. items:
  23229. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  23230. properties:
  23231. key:
  23232. type: string
  23233. value:
  23234. type: string
  23235. version:
  23236. type: string
  23237. required:
  23238. - key
  23239. - value
  23240. type: object
  23241. type: array
  23242. required:
  23243. - data
  23244. type: object
  23245. fortanix:
  23246. description: Fortanix configures this store to sync secrets using the Fortanix provider
  23247. properties:
  23248. apiKey:
  23249. description: APIKey is the API token to access SDKMS Applications.
  23250. properties:
  23251. secretRef:
  23252. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  23253. properties:
  23254. key:
  23255. description: |-
  23256. A key in the referenced Secret.
  23257. Some instances of this field may be defaulted, in others it may be required.
  23258. maxLength: 253
  23259. minLength: 1
  23260. pattern: ^[-._a-zA-Z0-9]+$
  23261. type: string
  23262. name:
  23263. description: The name of the Secret resource being referred to.
  23264. maxLength: 253
  23265. minLength: 1
  23266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23267. type: string
  23268. namespace:
  23269. description: |-
  23270. The namespace of the Secret resource being referred to.
  23271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23272. maxLength: 63
  23273. minLength: 1
  23274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23275. type: string
  23276. type: object
  23277. type: object
  23278. apiUrl:
  23279. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  23280. type: string
  23281. type: object
  23282. gcpsm:
  23283. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  23284. properties:
  23285. auth:
  23286. description: Auth defines the information necessary to authenticate against GCP
  23287. properties:
  23288. secretRef:
  23289. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  23290. properties:
  23291. secretAccessKeySecretRef:
  23292. description: The SecretAccessKey is used for authentication
  23293. properties:
  23294. key:
  23295. description: |-
  23296. A key in the referenced Secret.
  23297. Some instances of this field may be defaulted, in others it may be required.
  23298. maxLength: 253
  23299. minLength: 1
  23300. pattern: ^[-._a-zA-Z0-9]+$
  23301. type: string
  23302. name:
  23303. description: The name of the Secret resource being referred to.
  23304. maxLength: 253
  23305. minLength: 1
  23306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23307. type: string
  23308. namespace:
  23309. description: |-
  23310. The namespace of the Secret resource being referred to.
  23311. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23312. maxLength: 63
  23313. minLength: 1
  23314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23315. type: string
  23316. type: object
  23317. type: object
  23318. workloadIdentity:
  23319. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  23320. properties:
  23321. clusterLocation:
  23322. description: |-
  23323. ClusterLocation is the location of the cluster
  23324. If not specified, it fetches information from the metadata server
  23325. type: string
  23326. clusterName:
  23327. description: |-
  23328. ClusterName is the name of the cluster
  23329. If not specified, it fetches information from the metadata server
  23330. type: string
  23331. clusterProjectID:
  23332. description: |-
  23333. ClusterProjectID is the project ID of the cluster
  23334. If not specified, it fetches information from the metadata server
  23335. type: string
  23336. serviceAccountRef:
  23337. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23338. properties:
  23339. audiences:
  23340. description: |-
  23341. Audience specifies the `aud` claim for the service account token
  23342. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23343. then this audiences will be appended to the list
  23344. items:
  23345. type: string
  23346. type: array
  23347. name:
  23348. description: The name of the ServiceAccount resource being referred to.
  23349. maxLength: 253
  23350. minLength: 1
  23351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23352. type: string
  23353. namespace:
  23354. description: |-
  23355. Namespace of the resource being referred to.
  23356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23357. maxLength: 63
  23358. minLength: 1
  23359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23360. type: string
  23361. required:
  23362. - name
  23363. type: object
  23364. required:
  23365. - serviceAccountRef
  23366. type: object
  23367. type: object
  23368. location:
  23369. description: Location optionally defines a location for a secret
  23370. type: string
  23371. projectID:
  23372. description: ProjectID project where secret is located
  23373. type: string
  23374. type: object
  23375. github:
  23376. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  23377. properties:
  23378. appID:
  23379. description: appID specifies the Github APP that will be used to authenticate the client
  23380. format: int64
  23381. type: integer
  23382. auth:
  23383. description: auth configures how secret-manager authenticates with a Github instance.
  23384. properties:
  23385. privateKey:
  23386. description: |-
  23387. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23388. In some instances, `key` is a required field.
  23389. properties:
  23390. key:
  23391. description: |-
  23392. A key in the referenced Secret.
  23393. Some instances of this field may be defaulted, in others it may be required.
  23394. maxLength: 253
  23395. minLength: 1
  23396. pattern: ^[-._a-zA-Z0-9]+$
  23397. type: string
  23398. name:
  23399. description: The name of the Secret resource being referred to.
  23400. maxLength: 253
  23401. minLength: 1
  23402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23403. type: string
  23404. namespace:
  23405. description: |-
  23406. The namespace of the Secret resource being referred to.
  23407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23408. maxLength: 63
  23409. minLength: 1
  23410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23411. type: string
  23412. type: object
  23413. required:
  23414. - privateKey
  23415. type: object
  23416. environment:
  23417. description: environment will be used to fetch secrets from a particular environment within a github repository
  23418. type: string
  23419. installationID:
  23420. description: installationID specifies the Github APP installation that will be used to authenticate the client
  23421. format: int64
  23422. type: integer
  23423. organization:
  23424. description: organization will be used to fetch secrets from the Github organization
  23425. type: string
  23426. repository:
  23427. description: repository will be used to fetch secrets from the Github repository within an organization
  23428. type: string
  23429. uploadURL:
  23430. description: Upload URL for enterprise instances. Default to URL.
  23431. type: string
  23432. url:
  23433. default: https://github.com/
  23434. description: URL configures the Github instance URL. Defaults to https://github.com/.
  23435. type: string
  23436. required:
  23437. - appID
  23438. - auth
  23439. - installationID
  23440. - organization
  23441. type: object
  23442. gitlab:
  23443. description: GitLab configures this store to sync secrets using GitLab Variables provider
  23444. properties:
  23445. auth:
  23446. description: Auth configures how secret-manager authenticates with a GitLab instance.
  23447. properties:
  23448. SecretRef:
  23449. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  23450. properties:
  23451. accessToken:
  23452. description: AccessToken is used for authentication.
  23453. properties:
  23454. key:
  23455. description: |-
  23456. A key in the referenced Secret.
  23457. Some instances of this field may be defaulted, in others it may be required.
  23458. maxLength: 253
  23459. minLength: 1
  23460. pattern: ^[-._a-zA-Z0-9]+$
  23461. type: string
  23462. name:
  23463. description: The name of the Secret resource being referred to.
  23464. maxLength: 253
  23465. minLength: 1
  23466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23467. type: string
  23468. namespace:
  23469. description: |-
  23470. The namespace of the Secret resource being referred to.
  23471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23472. maxLength: 63
  23473. minLength: 1
  23474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23475. type: string
  23476. type: object
  23477. type: object
  23478. required:
  23479. - SecretRef
  23480. type: object
  23481. caBundle:
  23482. description: |-
  23483. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23484. can be performed.
  23485. format: byte
  23486. type: string
  23487. caProvider:
  23488. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23489. properties:
  23490. key:
  23491. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23492. maxLength: 253
  23493. minLength: 1
  23494. pattern: ^[-._a-zA-Z0-9]+$
  23495. type: string
  23496. name:
  23497. description: The name of the object located at the provider type.
  23498. maxLength: 253
  23499. minLength: 1
  23500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23501. type: string
  23502. namespace:
  23503. description: |-
  23504. The namespace the Provider type is in.
  23505. Can only be defined when used in a ClusterSecretStore.
  23506. maxLength: 63
  23507. minLength: 1
  23508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23509. type: string
  23510. type:
  23511. description: The type of provider to use such as "Secret", or "ConfigMap".
  23512. enum:
  23513. - Secret
  23514. - ConfigMap
  23515. type: string
  23516. required:
  23517. - name
  23518. - type
  23519. type: object
  23520. environment:
  23521. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  23522. type: string
  23523. groupIDs:
  23524. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  23525. items:
  23526. type: string
  23527. type: array
  23528. inheritFromGroups:
  23529. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  23530. type: boolean
  23531. projectID:
  23532. description: ProjectID specifies a project where secrets are located.
  23533. type: string
  23534. url:
  23535. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  23536. type: string
  23537. required:
  23538. - auth
  23539. type: object
  23540. ibm:
  23541. description: IBM configures this store to sync secrets using IBM Cloud provider
  23542. properties:
  23543. auth:
  23544. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  23545. maxProperties: 1
  23546. minProperties: 1
  23547. properties:
  23548. containerAuth:
  23549. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  23550. properties:
  23551. iamEndpoint:
  23552. type: string
  23553. profile:
  23554. description: the IBM Trusted Profile
  23555. type: string
  23556. tokenLocation:
  23557. description: Location the token is mounted on the pod
  23558. type: string
  23559. required:
  23560. - profile
  23561. type: object
  23562. secretRef:
  23563. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  23564. properties:
  23565. secretApiKeySecretRef:
  23566. description: The SecretAccessKey is used for authentication
  23567. properties:
  23568. key:
  23569. description: |-
  23570. A key in the referenced Secret.
  23571. Some instances of this field may be defaulted, in others it may be required.
  23572. maxLength: 253
  23573. minLength: 1
  23574. pattern: ^[-._a-zA-Z0-9]+$
  23575. type: string
  23576. name:
  23577. description: The name of the Secret resource being referred to.
  23578. maxLength: 253
  23579. minLength: 1
  23580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23581. type: string
  23582. namespace:
  23583. description: |-
  23584. The namespace of the Secret resource being referred to.
  23585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23586. maxLength: 63
  23587. minLength: 1
  23588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23589. type: string
  23590. type: object
  23591. type: object
  23592. type: object
  23593. serviceUrl:
  23594. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  23595. type: string
  23596. required:
  23597. - auth
  23598. type: object
  23599. infisical:
  23600. description: Infisical configures this store to sync secrets using the Infisical provider
  23601. properties:
  23602. auth:
  23603. description: Auth configures how the Operator authenticates with the Infisical API
  23604. properties:
  23605. universalAuthCredentials:
  23606. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  23607. properties:
  23608. clientId:
  23609. description: |-
  23610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23611. In some instances, `key` is a required field.
  23612. properties:
  23613. key:
  23614. description: |-
  23615. A key in the referenced Secret.
  23616. Some instances of this field may be defaulted, in others it may be required.
  23617. maxLength: 253
  23618. minLength: 1
  23619. pattern: ^[-._a-zA-Z0-9]+$
  23620. type: string
  23621. name:
  23622. description: The name of the Secret resource being referred to.
  23623. maxLength: 253
  23624. minLength: 1
  23625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23626. type: string
  23627. namespace:
  23628. description: |-
  23629. The namespace of the Secret resource being referred to.
  23630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23631. maxLength: 63
  23632. minLength: 1
  23633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23634. type: string
  23635. type: object
  23636. clientSecret:
  23637. description: |-
  23638. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23639. In some instances, `key` is a required field.
  23640. properties:
  23641. key:
  23642. description: |-
  23643. A key in the referenced Secret.
  23644. Some instances of this field may be defaulted, in others it may be required.
  23645. maxLength: 253
  23646. minLength: 1
  23647. pattern: ^[-._a-zA-Z0-9]+$
  23648. type: string
  23649. name:
  23650. description: The name of the Secret resource being referred to.
  23651. maxLength: 253
  23652. minLength: 1
  23653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23654. type: string
  23655. namespace:
  23656. description: |-
  23657. The namespace of the Secret resource being referred to.
  23658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23659. maxLength: 63
  23660. minLength: 1
  23661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23662. type: string
  23663. type: object
  23664. required:
  23665. - clientId
  23666. - clientSecret
  23667. type: object
  23668. type: object
  23669. hostAPI:
  23670. default: https://app.infisical.com/api
  23671. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  23672. type: string
  23673. secretsScope:
  23674. description: SecretsScope defines the scope of the secrets within the workspace
  23675. properties:
  23676. environmentSlug:
  23677. description: EnvironmentSlug is the required slug identifier for the environment.
  23678. type: string
  23679. expandSecretReferences:
  23680. default: true
  23681. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  23682. type: boolean
  23683. projectSlug:
  23684. description: ProjectSlug is the required slug identifier for the project.
  23685. type: string
  23686. recursive:
  23687. default: false
  23688. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  23689. type: boolean
  23690. secretsPath:
  23691. default: /
  23692. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  23693. type: string
  23694. required:
  23695. - environmentSlug
  23696. - projectSlug
  23697. type: object
  23698. required:
  23699. - auth
  23700. - secretsScope
  23701. type: object
  23702. keepersecurity:
  23703. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  23704. properties:
  23705. authRef:
  23706. description: |-
  23707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23708. In some instances, `key` is a required field.
  23709. properties:
  23710. key:
  23711. description: |-
  23712. A key in the referenced Secret.
  23713. Some instances of this field may be defaulted, in others it may be required.
  23714. maxLength: 253
  23715. minLength: 1
  23716. pattern: ^[-._a-zA-Z0-9]+$
  23717. type: string
  23718. name:
  23719. description: The name of the Secret resource being referred to.
  23720. maxLength: 253
  23721. minLength: 1
  23722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23723. type: string
  23724. namespace:
  23725. description: |-
  23726. The namespace of the Secret resource being referred to.
  23727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23728. maxLength: 63
  23729. minLength: 1
  23730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23731. type: string
  23732. type: object
  23733. folderID:
  23734. type: string
  23735. required:
  23736. - authRef
  23737. - folderID
  23738. type: object
  23739. kubernetes:
  23740. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  23741. properties:
  23742. auth:
  23743. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  23744. maxProperties: 1
  23745. minProperties: 1
  23746. properties:
  23747. cert:
  23748. description: has both clientCert and clientKey as secretKeySelector
  23749. properties:
  23750. clientCert:
  23751. description: |-
  23752. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23753. In some instances, `key` is a required field.
  23754. properties:
  23755. key:
  23756. description: |-
  23757. A key in the referenced Secret.
  23758. Some instances of this field may be defaulted, in others it may be required.
  23759. maxLength: 253
  23760. minLength: 1
  23761. pattern: ^[-._a-zA-Z0-9]+$
  23762. type: string
  23763. name:
  23764. description: The name of the Secret resource being referred to.
  23765. maxLength: 253
  23766. minLength: 1
  23767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23768. type: string
  23769. namespace:
  23770. description: |-
  23771. The namespace of the Secret resource being referred to.
  23772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23773. maxLength: 63
  23774. minLength: 1
  23775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23776. type: string
  23777. type: object
  23778. clientKey:
  23779. description: |-
  23780. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23781. In some instances, `key` is a required field.
  23782. properties:
  23783. key:
  23784. description: |-
  23785. A key in the referenced Secret.
  23786. Some instances of this field may be defaulted, in others it may be required.
  23787. maxLength: 253
  23788. minLength: 1
  23789. pattern: ^[-._a-zA-Z0-9]+$
  23790. type: string
  23791. name:
  23792. description: The name of the Secret resource being referred to.
  23793. maxLength: 253
  23794. minLength: 1
  23795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23796. type: string
  23797. namespace:
  23798. description: |-
  23799. The namespace of the Secret resource being referred to.
  23800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23801. maxLength: 63
  23802. minLength: 1
  23803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23804. type: string
  23805. type: object
  23806. type: object
  23807. serviceAccount:
  23808. description: points to a service account that should be used for authentication
  23809. properties:
  23810. audiences:
  23811. description: |-
  23812. Audience specifies the `aud` claim for the service account token
  23813. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23814. then this audiences will be appended to the list
  23815. items:
  23816. type: string
  23817. type: array
  23818. name:
  23819. description: The name of the ServiceAccount resource being referred to.
  23820. maxLength: 253
  23821. minLength: 1
  23822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23823. type: string
  23824. namespace:
  23825. description: |-
  23826. Namespace of the resource being referred to.
  23827. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23828. maxLength: 63
  23829. minLength: 1
  23830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23831. type: string
  23832. required:
  23833. - name
  23834. type: object
  23835. token:
  23836. description: use static token to authenticate with
  23837. properties:
  23838. bearerToken:
  23839. description: |-
  23840. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23841. In some instances, `key` is a required field.
  23842. properties:
  23843. key:
  23844. description: |-
  23845. A key in the referenced Secret.
  23846. Some instances of this field may be defaulted, in others it may be required.
  23847. maxLength: 253
  23848. minLength: 1
  23849. pattern: ^[-._a-zA-Z0-9]+$
  23850. type: string
  23851. name:
  23852. description: The name of the Secret resource being referred to.
  23853. maxLength: 253
  23854. minLength: 1
  23855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23856. type: string
  23857. namespace:
  23858. description: |-
  23859. The namespace of the Secret resource being referred to.
  23860. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23861. maxLength: 63
  23862. minLength: 1
  23863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23864. type: string
  23865. type: object
  23866. type: object
  23867. type: object
  23868. authRef:
  23869. description: A reference to a secret that contains the auth information.
  23870. properties:
  23871. key:
  23872. description: |-
  23873. A key in the referenced Secret.
  23874. Some instances of this field may be defaulted, in others it may be required.
  23875. maxLength: 253
  23876. minLength: 1
  23877. pattern: ^[-._a-zA-Z0-9]+$
  23878. type: string
  23879. name:
  23880. description: The name of the Secret resource being referred to.
  23881. maxLength: 253
  23882. minLength: 1
  23883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23884. type: string
  23885. namespace:
  23886. description: |-
  23887. The namespace of the Secret resource being referred to.
  23888. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23889. maxLength: 63
  23890. minLength: 1
  23891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23892. type: string
  23893. type: object
  23894. remoteNamespace:
  23895. default: default
  23896. description: Remote namespace to fetch the secrets from
  23897. maxLength: 63
  23898. minLength: 1
  23899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23900. type: string
  23901. server:
  23902. description: configures the Kubernetes server Address.
  23903. properties:
  23904. caBundle:
  23905. description: CABundle is a base64-encoded CA certificate
  23906. format: byte
  23907. type: string
  23908. caProvider:
  23909. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  23910. properties:
  23911. key:
  23912. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23913. maxLength: 253
  23914. minLength: 1
  23915. pattern: ^[-._a-zA-Z0-9]+$
  23916. type: string
  23917. name:
  23918. description: The name of the object located at the provider type.
  23919. maxLength: 253
  23920. minLength: 1
  23921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23922. type: string
  23923. namespace:
  23924. description: |-
  23925. The namespace the Provider type is in.
  23926. Can only be defined when used in a ClusterSecretStore.
  23927. maxLength: 63
  23928. minLength: 1
  23929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23930. type: string
  23931. type:
  23932. description: The type of provider to use such as "Secret", or "ConfigMap".
  23933. enum:
  23934. - Secret
  23935. - ConfigMap
  23936. type: string
  23937. required:
  23938. - name
  23939. - type
  23940. type: object
  23941. url:
  23942. default: kubernetes.default
  23943. description: configures the Kubernetes server Address.
  23944. type: string
  23945. type: object
  23946. type: object
  23947. onboardbase:
  23948. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  23949. properties:
  23950. apiHost:
  23951. default: https://public.onboardbase.com/api/v1/
  23952. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  23953. type: string
  23954. auth:
  23955. description: Auth configures how the Operator authenticates with the Onboardbase API
  23956. properties:
  23957. apiKeyRef:
  23958. description: |-
  23959. OnboardbaseAPIKey is the APIKey generated by an admin account.
  23960. It is used to recognize and authorize access to a project and environment within onboardbase
  23961. properties:
  23962. key:
  23963. description: |-
  23964. A key in the referenced Secret.
  23965. Some instances of this field may be defaulted, in others it may be required.
  23966. maxLength: 253
  23967. minLength: 1
  23968. pattern: ^[-._a-zA-Z0-9]+$
  23969. type: string
  23970. name:
  23971. description: The name of the Secret resource being referred to.
  23972. maxLength: 253
  23973. minLength: 1
  23974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23975. type: string
  23976. namespace:
  23977. description: |-
  23978. The namespace of the Secret resource being referred to.
  23979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23980. maxLength: 63
  23981. minLength: 1
  23982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23983. type: string
  23984. type: object
  23985. passcodeRef:
  23986. description: OnboardbasePasscode is the passcode attached to the API Key
  23987. properties:
  23988. key:
  23989. description: |-
  23990. A key in the referenced Secret.
  23991. Some instances of this field may be defaulted, in others it may be required.
  23992. maxLength: 253
  23993. minLength: 1
  23994. pattern: ^[-._a-zA-Z0-9]+$
  23995. type: string
  23996. name:
  23997. description: The name of the Secret resource being referred to.
  23998. maxLength: 253
  23999. minLength: 1
  24000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24001. type: string
  24002. namespace:
  24003. description: |-
  24004. The namespace of the Secret resource being referred to.
  24005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24006. maxLength: 63
  24007. minLength: 1
  24008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24009. type: string
  24010. type: object
  24011. required:
  24012. - apiKeyRef
  24013. - passcodeRef
  24014. type: object
  24015. environment:
  24016. default: development
  24017. description: Environment is the name of an environmnent within a project to pull the secrets from
  24018. type: string
  24019. project:
  24020. default: development
  24021. description: Project is an onboardbase project that the secrets should be pulled from
  24022. type: string
  24023. required:
  24024. - apiHost
  24025. - auth
  24026. - environment
  24027. - project
  24028. type: object
  24029. onepassword:
  24030. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24031. properties:
  24032. auth:
  24033. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24034. properties:
  24035. secretRef:
  24036. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24037. properties:
  24038. connectTokenSecretRef:
  24039. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24040. properties:
  24041. key:
  24042. description: |-
  24043. A key in the referenced Secret.
  24044. Some instances of this field may be defaulted, in others it may be required.
  24045. maxLength: 253
  24046. minLength: 1
  24047. pattern: ^[-._a-zA-Z0-9]+$
  24048. type: string
  24049. name:
  24050. description: The name of the Secret resource being referred to.
  24051. maxLength: 253
  24052. minLength: 1
  24053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24054. type: string
  24055. namespace:
  24056. description: |-
  24057. The namespace of the Secret resource being referred to.
  24058. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24059. maxLength: 63
  24060. minLength: 1
  24061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24062. type: string
  24063. type: object
  24064. required:
  24065. - connectTokenSecretRef
  24066. type: object
  24067. required:
  24068. - secretRef
  24069. type: object
  24070. connectHost:
  24071. description: ConnectHost defines the OnePassword Connect Server to connect to
  24072. type: string
  24073. vaults:
  24074. additionalProperties:
  24075. type: integer
  24076. description: Vaults defines which OnePassword vaults to search in which order
  24077. type: object
  24078. required:
  24079. - auth
  24080. - connectHost
  24081. - vaults
  24082. type: object
  24083. oracle:
  24084. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24085. properties:
  24086. auth:
  24087. description: |-
  24088. Auth configures how secret-manager authenticates with the Oracle Vault.
  24089. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24090. properties:
  24091. secretRef:
  24092. description: SecretRef to pass through sensitive information.
  24093. properties:
  24094. fingerprint:
  24095. description: Fingerprint is the fingerprint of the API private key.
  24096. properties:
  24097. key:
  24098. description: |-
  24099. A key in the referenced Secret.
  24100. Some instances of this field may be defaulted, in others it may be required.
  24101. maxLength: 253
  24102. minLength: 1
  24103. pattern: ^[-._a-zA-Z0-9]+$
  24104. type: string
  24105. name:
  24106. description: The name of the Secret resource being referred to.
  24107. maxLength: 253
  24108. minLength: 1
  24109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24110. type: string
  24111. namespace:
  24112. description: |-
  24113. The namespace of the Secret resource being referred to.
  24114. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24115. maxLength: 63
  24116. minLength: 1
  24117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24118. type: string
  24119. type: object
  24120. privatekey:
  24121. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24122. properties:
  24123. key:
  24124. description: |-
  24125. A key in the referenced Secret.
  24126. Some instances of this field may be defaulted, in others it may be required.
  24127. maxLength: 253
  24128. minLength: 1
  24129. pattern: ^[-._a-zA-Z0-9]+$
  24130. type: string
  24131. name:
  24132. description: The name of the Secret resource being referred to.
  24133. maxLength: 253
  24134. minLength: 1
  24135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24136. type: string
  24137. namespace:
  24138. description: |-
  24139. The namespace of the Secret resource being referred to.
  24140. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24141. maxLength: 63
  24142. minLength: 1
  24143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24144. type: string
  24145. type: object
  24146. required:
  24147. - fingerprint
  24148. - privatekey
  24149. type: object
  24150. tenancy:
  24151. description: Tenancy is the tenancy OCID where user is located.
  24152. type: string
  24153. user:
  24154. description: User is an access OCID specific to the account.
  24155. type: string
  24156. required:
  24157. - secretRef
  24158. - tenancy
  24159. - user
  24160. type: object
  24161. compartment:
  24162. description: |-
  24163. Compartment is the vault compartment OCID.
  24164. Required for PushSecret
  24165. type: string
  24166. encryptionKey:
  24167. description: |-
  24168. EncryptionKey is the OCID of the encryption key within the vault.
  24169. Required for PushSecret
  24170. type: string
  24171. principalType:
  24172. description: |-
  24173. The type of principal to use for authentication. If left blank, the Auth struct will
  24174. determine the principal type. This optional field must be specified if using
  24175. workload identity.
  24176. enum:
  24177. - ""
  24178. - UserPrincipal
  24179. - InstancePrincipal
  24180. - Workload
  24181. type: string
  24182. region:
  24183. description: Region is the region where vault is located.
  24184. type: string
  24185. serviceAccountRef:
  24186. description: |-
  24187. ServiceAccountRef specified the service account
  24188. that should be used when authenticating with WorkloadIdentity.
  24189. properties:
  24190. audiences:
  24191. description: |-
  24192. Audience specifies the `aud` claim for the service account token
  24193. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24194. then this audiences will be appended to the list
  24195. items:
  24196. type: string
  24197. type: array
  24198. name:
  24199. description: The name of the ServiceAccount resource being referred to.
  24200. maxLength: 253
  24201. minLength: 1
  24202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24203. type: string
  24204. namespace:
  24205. description: |-
  24206. Namespace of the resource being referred to.
  24207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24208. maxLength: 63
  24209. minLength: 1
  24210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24211. type: string
  24212. required:
  24213. - name
  24214. type: object
  24215. vault:
  24216. description: Vault is the vault's OCID of the specific vault where secret is located.
  24217. type: string
  24218. required:
  24219. - region
  24220. - vault
  24221. type: object
  24222. passbolt:
  24223. description: PassboltProvider defines configuration for the Passbolt provider.
  24224. properties:
  24225. auth:
  24226. description: Auth defines the information necessary to authenticate against Passbolt Server
  24227. properties:
  24228. passwordSecretRef:
  24229. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  24230. properties:
  24231. key:
  24232. description: |-
  24233. A key in the referenced Secret.
  24234. Some instances of this field may be defaulted, in others it may be required.
  24235. maxLength: 253
  24236. minLength: 1
  24237. pattern: ^[-._a-zA-Z0-9]+$
  24238. type: string
  24239. name:
  24240. description: The name of the Secret resource being referred to.
  24241. maxLength: 253
  24242. minLength: 1
  24243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24244. type: string
  24245. namespace:
  24246. description: |-
  24247. The namespace of the Secret resource being referred to.
  24248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24249. maxLength: 63
  24250. minLength: 1
  24251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24252. type: string
  24253. type: object
  24254. privateKeySecretRef:
  24255. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  24256. properties:
  24257. key:
  24258. description: |-
  24259. A key in the referenced Secret.
  24260. Some instances of this field may be defaulted, in others it may be required.
  24261. maxLength: 253
  24262. minLength: 1
  24263. pattern: ^[-._a-zA-Z0-9]+$
  24264. type: string
  24265. name:
  24266. description: The name of the Secret resource being referred to.
  24267. maxLength: 253
  24268. minLength: 1
  24269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24270. type: string
  24271. namespace:
  24272. description: |-
  24273. The namespace of the Secret resource being referred to.
  24274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24275. maxLength: 63
  24276. minLength: 1
  24277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24278. type: string
  24279. type: object
  24280. required:
  24281. - passwordSecretRef
  24282. - privateKeySecretRef
  24283. type: object
  24284. host:
  24285. description: Host defines the Passbolt Server to connect to
  24286. type: string
  24287. required:
  24288. - auth
  24289. - host
  24290. type: object
  24291. passworddepot:
  24292. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  24293. properties:
  24294. auth:
  24295. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  24296. properties:
  24297. secretRef:
  24298. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  24299. properties:
  24300. credentials:
  24301. description: Username / Password is used for authentication.
  24302. properties:
  24303. key:
  24304. description: |-
  24305. A key in the referenced Secret.
  24306. Some instances of this field may be defaulted, in others it may be required.
  24307. maxLength: 253
  24308. minLength: 1
  24309. pattern: ^[-._a-zA-Z0-9]+$
  24310. type: string
  24311. name:
  24312. description: The name of the Secret resource being referred to.
  24313. maxLength: 253
  24314. minLength: 1
  24315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24316. type: string
  24317. namespace:
  24318. description: |-
  24319. The namespace of the Secret resource being referred to.
  24320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24321. maxLength: 63
  24322. minLength: 1
  24323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24324. type: string
  24325. type: object
  24326. type: object
  24327. required:
  24328. - secretRef
  24329. type: object
  24330. database:
  24331. description: Database to use as source
  24332. type: string
  24333. host:
  24334. description: URL configures the Password Depot instance URL.
  24335. type: string
  24336. required:
  24337. - auth
  24338. - database
  24339. - host
  24340. type: object
  24341. previder:
  24342. description: Previder configures this store to sync secrets using the Previder provider
  24343. properties:
  24344. auth:
  24345. description: PreviderAuth contains a secretRef for credentials.
  24346. properties:
  24347. secretRef:
  24348. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  24349. properties:
  24350. accessToken:
  24351. description: The AccessToken is used for authentication
  24352. properties:
  24353. key:
  24354. description: |-
  24355. A key in the referenced Secret.
  24356. Some instances of this field may be defaulted, in others it may be required.
  24357. maxLength: 253
  24358. minLength: 1
  24359. pattern: ^[-._a-zA-Z0-9]+$
  24360. type: string
  24361. name:
  24362. description: The name of the Secret resource being referred to.
  24363. maxLength: 253
  24364. minLength: 1
  24365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24366. type: string
  24367. namespace:
  24368. description: |-
  24369. The namespace of the Secret resource being referred to.
  24370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24371. maxLength: 63
  24372. minLength: 1
  24373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24374. type: string
  24375. type: object
  24376. required:
  24377. - accessToken
  24378. type: object
  24379. type: object
  24380. baseUri:
  24381. type: string
  24382. required:
  24383. - auth
  24384. type: object
  24385. pulumi:
  24386. description: Pulumi configures this store to sync secrets using the Pulumi provider
  24387. properties:
  24388. accessToken:
  24389. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  24390. properties:
  24391. secretRef:
  24392. description: SecretRef is a reference to a secret containing the Pulumi API token.
  24393. properties:
  24394. key:
  24395. description: |-
  24396. A key in the referenced Secret.
  24397. Some instances of this field may be defaulted, in others it may be required.
  24398. maxLength: 253
  24399. minLength: 1
  24400. pattern: ^[-._a-zA-Z0-9]+$
  24401. type: string
  24402. name:
  24403. description: The name of the Secret resource being referred to.
  24404. maxLength: 253
  24405. minLength: 1
  24406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24407. type: string
  24408. namespace:
  24409. description: |-
  24410. The namespace of the Secret resource being referred to.
  24411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24412. maxLength: 63
  24413. minLength: 1
  24414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24415. type: string
  24416. type: object
  24417. type: object
  24418. apiUrl:
  24419. default: https://api.pulumi.com/api/esc
  24420. description: APIURL is the URL of the Pulumi API.
  24421. type: string
  24422. environment:
  24423. description: |-
  24424. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  24425. dynamically retrieved values from supported providers including all major clouds,
  24426. and other Pulumi ESC environments.
  24427. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  24428. type: string
  24429. organization:
  24430. description: |-
  24431. Organization are a space to collaborate on shared projects and stacks.
  24432. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  24433. type: string
  24434. project:
  24435. description: Project is the name of the Pulumi ESC project the environment belongs to.
  24436. type: string
  24437. required:
  24438. - accessToken
  24439. - environment
  24440. - organization
  24441. - project
  24442. type: object
  24443. scaleway:
  24444. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  24445. properties:
  24446. accessKey:
  24447. description: AccessKey is the non-secret part of the api key.
  24448. properties:
  24449. secretRef:
  24450. description: SecretRef references a key in a secret that will be used as value.
  24451. properties:
  24452. key:
  24453. description: |-
  24454. A key in the referenced Secret.
  24455. Some instances of this field may be defaulted, in others it may be required.
  24456. maxLength: 253
  24457. minLength: 1
  24458. pattern: ^[-._a-zA-Z0-9]+$
  24459. type: string
  24460. name:
  24461. description: The name of the Secret resource being referred to.
  24462. maxLength: 253
  24463. minLength: 1
  24464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24465. type: string
  24466. namespace:
  24467. description: |-
  24468. The namespace of the Secret resource being referred to.
  24469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24470. maxLength: 63
  24471. minLength: 1
  24472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24473. type: string
  24474. type: object
  24475. value:
  24476. description: Value can be specified directly to set a value without using a secret.
  24477. type: string
  24478. type: object
  24479. apiUrl:
  24480. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  24481. type: string
  24482. projectId:
  24483. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  24484. type: string
  24485. region:
  24486. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  24487. type: string
  24488. secretKey:
  24489. description: SecretKey is the non-secret part of the api key.
  24490. properties:
  24491. secretRef:
  24492. description: SecretRef references a key in a secret that will be used as value.
  24493. properties:
  24494. key:
  24495. description: |-
  24496. A key in the referenced Secret.
  24497. Some instances of this field may be defaulted, in others it may be required.
  24498. maxLength: 253
  24499. minLength: 1
  24500. pattern: ^[-._a-zA-Z0-9]+$
  24501. type: string
  24502. name:
  24503. description: The name of the Secret resource being referred to.
  24504. maxLength: 253
  24505. minLength: 1
  24506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24507. type: string
  24508. namespace:
  24509. description: |-
  24510. The namespace of the Secret resource being referred to.
  24511. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24512. maxLength: 63
  24513. minLength: 1
  24514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24515. type: string
  24516. type: object
  24517. value:
  24518. description: Value can be specified directly to set a value without using a secret.
  24519. type: string
  24520. type: object
  24521. required:
  24522. - accessKey
  24523. - projectId
  24524. - region
  24525. - secretKey
  24526. type: object
  24527. secretserver:
  24528. description: |-
  24529. SecretServer configures this store to sync secrets using SecretServer provider
  24530. https://docs.delinea.com/online-help/secret-server/start.htm
  24531. properties:
  24532. password:
  24533. description: Password is the secret server account password.
  24534. properties:
  24535. secretRef:
  24536. description: SecretRef references a key in a secret that will be used as value.
  24537. properties:
  24538. key:
  24539. description: |-
  24540. A key in the referenced Secret.
  24541. Some instances of this field may be defaulted, in others it may be required.
  24542. maxLength: 253
  24543. minLength: 1
  24544. pattern: ^[-._a-zA-Z0-9]+$
  24545. type: string
  24546. name:
  24547. description: The name of the Secret resource being referred to.
  24548. maxLength: 253
  24549. minLength: 1
  24550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24551. type: string
  24552. namespace:
  24553. description: |-
  24554. The namespace of the Secret resource being referred to.
  24555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24556. maxLength: 63
  24557. minLength: 1
  24558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24559. type: string
  24560. type: object
  24561. value:
  24562. description: Value can be specified directly to set a value without using a secret.
  24563. type: string
  24564. type: object
  24565. serverURL:
  24566. description: |-
  24567. ServerURL
  24568. URL to your secret server installation
  24569. type: string
  24570. username:
  24571. description: Username is the secret server account username.
  24572. properties:
  24573. secretRef:
  24574. description: SecretRef references a key in a secret that will be used as value.
  24575. properties:
  24576. key:
  24577. description: |-
  24578. A key in the referenced Secret.
  24579. Some instances of this field may be defaulted, in others it may be required.
  24580. maxLength: 253
  24581. minLength: 1
  24582. pattern: ^[-._a-zA-Z0-9]+$
  24583. type: string
  24584. name:
  24585. description: The name of the Secret resource being referred to.
  24586. maxLength: 253
  24587. minLength: 1
  24588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24589. type: string
  24590. namespace:
  24591. description: |-
  24592. The namespace of the Secret resource being referred to.
  24593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24594. maxLength: 63
  24595. minLength: 1
  24596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24597. type: string
  24598. type: object
  24599. value:
  24600. description: Value can be specified directly to set a value without using a secret.
  24601. type: string
  24602. type: object
  24603. required:
  24604. - password
  24605. - serverURL
  24606. - username
  24607. type: object
  24608. senhasegura:
  24609. description: Senhasegura configures this store to sync secrets using senhasegura provider
  24610. properties:
  24611. auth:
  24612. description: Auth defines parameters to authenticate in senhasegura
  24613. properties:
  24614. clientId:
  24615. type: string
  24616. clientSecretSecretRef:
  24617. description: |-
  24618. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24619. In some instances, `key` is a required field.
  24620. properties:
  24621. key:
  24622. description: |-
  24623. A key in the referenced Secret.
  24624. Some instances of this field may be defaulted, in others it may be required.
  24625. maxLength: 253
  24626. minLength: 1
  24627. pattern: ^[-._a-zA-Z0-9]+$
  24628. type: string
  24629. name:
  24630. description: The name of the Secret resource being referred to.
  24631. maxLength: 253
  24632. minLength: 1
  24633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24634. type: string
  24635. namespace:
  24636. description: |-
  24637. The namespace of the Secret resource being referred to.
  24638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24639. maxLength: 63
  24640. minLength: 1
  24641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24642. type: string
  24643. type: object
  24644. required:
  24645. - clientId
  24646. - clientSecretSecretRef
  24647. type: object
  24648. ignoreSslCertificate:
  24649. default: false
  24650. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  24651. type: boolean
  24652. module:
  24653. description: Module defines which senhasegura module should be used to get secrets
  24654. type: string
  24655. url:
  24656. description: URL of senhasegura
  24657. type: string
  24658. required:
  24659. - auth
  24660. - module
  24661. - url
  24662. type: object
  24663. vault:
  24664. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  24665. properties:
  24666. auth:
  24667. description: Auth configures how secret-manager authenticates with the Vault server.
  24668. properties:
  24669. appRole:
  24670. description: |-
  24671. AppRole authenticates with Vault using the App Role auth mechanism,
  24672. with the role and secret stored in a Kubernetes Secret resource.
  24673. properties:
  24674. path:
  24675. default: approle
  24676. description: |-
  24677. Path where the App Role authentication backend is mounted
  24678. in Vault, e.g: "approle"
  24679. type: string
  24680. roleId:
  24681. description: |-
  24682. RoleID configured in the App Role authentication backend when setting
  24683. up the authentication backend in Vault.
  24684. type: string
  24685. roleRef:
  24686. description: |-
  24687. Reference to a key in a Secret that contains the App Role ID used
  24688. to authenticate with Vault.
  24689. The `key` field must be specified and denotes which entry within the Secret
  24690. resource is used as the app role id.
  24691. properties:
  24692. key:
  24693. description: |-
  24694. A key in the referenced Secret.
  24695. Some instances of this field may be defaulted, in others it may be required.
  24696. maxLength: 253
  24697. minLength: 1
  24698. pattern: ^[-._a-zA-Z0-9]+$
  24699. type: string
  24700. name:
  24701. description: The name of the Secret resource being referred to.
  24702. maxLength: 253
  24703. minLength: 1
  24704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24705. type: string
  24706. namespace:
  24707. description: |-
  24708. The namespace of the Secret resource being referred to.
  24709. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24710. maxLength: 63
  24711. minLength: 1
  24712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24713. type: string
  24714. type: object
  24715. secretRef:
  24716. description: |-
  24717. Reference to a key in a Secret that contains the App Role secret used
  24718. to authenticate with Vault.
  24719. The `key` field must be specified and denotes which entry within the Secret
  24720. resource is used as the app role secret.
  24721. properties:
  24722. key:
  24723. description: |-
  24724. A key in the referenced Secret.
  24725. Some instances of this field may be defaulted, in others it may be required.
  24726. maxLength: 253
  24727. minLength: 1
  24728. pattern: ^[-._a-zA-Z0-9]+$
  24729. type: string
  24730. name:
  24731. description: The name of the Secret resource being referred to.
  24732. maxLength: 253
  24733. minLength: 1
  24734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24735. type: string
  24736. namespace:
  24737. description: |-
  24738. The namespace of the Secret resource being referred to.
  24739. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24740. maxLength: 63
  24741. minLength: 1
  24742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24743. type: string
  24744. type: object
  24745. required:
  24746. - path
  24747. - secretRef
  24748. type: object
  24749. cert:
  24750. description: |-
  24751. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  24752. Cert authentication method
  24753. properties:
  24754. clientCert:
  24755. description: |-
  24756. ClientCert is a certificate to authenticate using the Cert Vault
  24757. authentication method
  24758. properties:
  24759. key:
  24760. description: |-
  24761. A key in the referenced Secret.
  24762. Some instances of this field may be defaulted, in others it may be required.
  24763. maxLength: 253
  24764. minLength: 1
  24765. pattern: ^[-._a-zA-Z0-9]+$
  24766. type: string
  24767. name:
  24768. description: The name of the Secret resource being referred to.
  24769. maxLength: 253
  24770. minLength: 1
  24771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24772. type: string
  24773. namespace:
  24774. description: |-
  24775. The namespace of the Secret resource being referred to.
  24776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24777. maxLength: 63
  24778. minLength: 1
  24779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24780. type: string
  24781. type: object
  24782. secretRef:
  24783. description: |-
  24784. SecretRef to a key in a Secret resource containing client private key to
  24785. authenticate with Vault using the Cert authentication method
  24786. properties:
  24787. key:
  24788. description: |-
  24789. A key in the referenced Secret.
  24790. Some instances of this field may be defaulted, in others it may be required.
  24791. maxLength: 253
  24792. minLength: 1
  24793. pattern: ^[-._a-zA-Z0-9]+$
  24794. type: string
  24795. name:
  24796. description: The name of the Secret resource being referred to.
  24797. maxLength: 253
  24798. minLength: 1
  24799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24800. type: string
  24801. namespace:
  24802. description: |-
  24803. The namespace of the Secret resource being referred to.
  24804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24805. maxLength: 63
  24806. minLength: 1
  24807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24808. type: string
  24809. type: object
  24810. type: object
  24811. iam:
  24812. description: |-
  24813. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  24814. AWS IAM authentication method
  24815. properties:
  24816. externalID:
  24817. description: AWS External ID set on assumed IAM roles
  24818. type: string
  24819. jwt:
  24820. description: Specify a service account with IRSA enabled
  24821. properties:
  24822. serviceAccountRef:
  24823. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24824. properties:
  24825. audiences:
  24826. description: |-
  24827. Audience specifies the `aud` claim for the service account token
  24828. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24829. then this audiences will be appended to the list
  24830. items:
  24831. type: string
  24832. type: array
  24833. name:
  24834. description: The name of the ServiceAccount resource being referred to.
  24835. maxLength: 253
  24836. minLength: 1
  24837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24838. type: string
  24839. namespace:
  24840. description: |-
  24841. Namespace of the resource being referred to.
  24842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24843. maxLength: 63
  24844. minLength: 1
  24845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24846. type: string
  24847. required:
  24848. - name
  24849. type: object
  24850. type: object
  24851. path:
  24852. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  24853. type: string
  24854. region:
  24855. description: AWS region
  24856. type: string
  24857. role:
  24858. description: This is the AWS role to be assumed before talking to vault
  24859. type: string
  24860. secretRef:
  24861. description: Specify credentials in a Secret object
  24862. properties:
  24863. accessKeyIDSecretRef:
  24864. description: The AccessKeyID is used for authentication
  24865. properties:
  24866. key:
  24867. description: |-
  24868. A key in the referenced Secret.
  24869. Some instances of this field may be defaulted, in others it may be required.
  24870. maxLength: 253
  24871. minLength: 1
  24872. pattern: ^[-._a-zA-Z0-9]+$
  24873. type: string
  24874. name:
  24875. description: The name of the Secret resource being referred to.
  24876. maxLength: 253
  24877. minLength: 1
  24878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24879. type: string
  24880. namespace:
  24881. description: |-
  24882. The namespace of the Secret resource being referred to.
  24883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24884. maxLength: 63
  24885. minLength: 1
  24886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24887. type: string
  24888. type: object
  24889. secretAccessKeySecretRef:
  24890. description: The SecretAccessKey is used for authentication
  24891. properties:
  24892. key:
  24893. description: |-
  24894. A key in the referenced Secret.
  24895. Some instances of this field may be defaulted, in others it may be required.
  24896. maxLength: 253
  24897. minLength: 1
  24898. pattern: ^[-._a-zA-Z0-9]+$
  24899. type: string
  24900. name:
  24901. description: The name of the Secret resource being referred to.
  24902. maxLength: 253
  24903. minLength: 1
  24904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24905. type: string
  24906. namespace:
  24907. description: |-
  24908. The namespace of the Secret resource being referred to.
  24909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24910. maxLength: 63
  24911. minLength: 1
  24912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24913. type: string
  24914. type: object
  24915. sessionTokenSecretRef:
  24916. description: |-
  24917. The SessionToken used for authentication
  24918. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  24919. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  24920. properties:
  24921. key:
  24922. description: |-
  24923. A key in the referenced Secret.
  24924. Some instances of this field may be defaulted, in others it may be required.
  24925. maxLength: 253
  24926. minLength: 1
  24927. pattern: ^[-._a-zA-Z0-9]+$
  24928. type: string
  24929. name:
  24930. description: The name of the Secret resource being referred to.
  24931. maxLength: 253
  24932. minLength: 1
  24933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24934. type: string
  24935. namespace:
  24936. description: |-
  24937. The namespace of the Secret resource being referred to.
  24938. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24939. maxLength: 63
  24940. minLength: 1
  24941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24942. type: string
  24943. type: object
  24944. type: object
  24945. vaultAwsIamServerID:
  24946. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  24947. type: string
  24948. vaultRole:
  24949. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  24950. type: string
  24951. required:
  24952. - vaultRole
  24953. type: object
  24954. jwt:
  24955. description: |-
  24956. Jwt authenticates with Vault by passing role and JWT token using the
  24957. JWT/OIDC authentication method
  24958. properties:
  24959. kubernetesServiceAccountToken:
  24960. description: |-
  24961. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  24962. a token for with the `TokenRequest` API.
  24963. properties:
  24964. audiences:
  24965. description: |-
  24966. Optional audiences field that will be used to request a temporary Kubernetes service
  24967. account token for the service account referenced by `serviceAccountRef`.
  24968. Defaults to a single audience `vault` it not specified.
  24969. Deprecated: use serviceAccountRef.Audiences instead
  24970. items:
  24971. type: string
  24972. type: array
  24973. expirationSeconds:
  24974. description: |-
  24975. Optional expiration time in seconds that will be used to request a temporary
  24976. Kubernetes service account token for the service account referenced by
  24977. `serviceAccountRef`.
  24978. Deprecated: this will be removed in the future.
  24979. Defaults to 10 minutes.
  24980. format: int64
  24981. type: integer
  24982. serviceAccountRef:
  24983. description: Service account field containing the name of a kubernetes ServiceAccount.
  24984. properties:
  24985. audiences:
  24986. description: |-
  24987. Audience specifies the `aud` claim for the service account token
  24988. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24989. then this audiences will be appended to the list
  24990. items:
  24991. type: string
  24992. type: array
  24993. name:
  24994. description: The name of the ServiceAccount resource being referred to.
  24995. maxLength: 253
  24996. minLength: 1
  24997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24998. type: string
  24999. namespace:
  25000. description: |-
  25001. Namespace of the resource being referred to.
  25002. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25003. maxLength: 63
  25004. minLength: 1
  25005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25006. type: string
  25007. required:
  25008. - name
  25009. type: object
  25010. required:
  25011. - serviceAccountRef
  25012. type: object
  25013. path:
  25014. default: jwt
  25015. description: |-
  25016. Path where the JWT authentication backend is mounted
  25017. in Vault, e.g: "jwt"
  25018. type: string
  25019. role:
  25020. description: |-
  25021. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25022. authentication method
  25023. type: string
  25024. secretRef:
  25025. description: |-
  25026. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25027. authenticate with Vault using the JWT/OIDC authentication method.
  25028. properties:
  25029. key:
  25030. description: |-
  25031. A key in the referenced Secret.
  25032. Some instances of this field may be defaulted, in others it may be required.
  25033. maxLength: 253
  25034. minLength: 1
  25035. pattern: ^[-._a-zA-Z0-9]+$
  25036. type: string
  25037. name:
  25038. description: The name of the Secret resource being referred to.
  25039. maxLength: 253
  25040. minLength: 1
  25041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25042. type: string
  25043. namespace:
  25044. description: |-
  25045. The namespace of the Secret resource being referred to.
  25046. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25047. maxLength: 63
  25048. minLength: 1
  25049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25050. type: string
  25051. type: object
  25052. required:
  25053. - path
  25054. type: object
  25055. kubernetes:
  25056. description: |-
  25057. Kubernetes authenticates with Vault by passing the ServiceAccount
  25058. token stored in the named Secret resource to the Vault server.
  25059. properties:
  25060. mountPath:
  25061. default: kubernetes
  25062. description: |-
  25063. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25064. "kubernetes"
  25065. type: string
  25066. role:
  25067. description: |-
  25068. A required field containing the Vault Role to assume. A Role binds a
  25069. Kubernetes ServiceAccount with a set of Vault policies.
  25070. type: string
  25071. secretRef:
  25072. description: |-
  25073. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25074. for authenticating with Vault. If a name is specified without a key,
  25075. `token` is the default. If one is not specified, the one bound to
  25076. the controller will be used.
  25077. properties:
  25078. key:
  25079. description: |-
  25080. A key in the referenced Secret.
  25081. Some instances of this field may be defaulted, in others it may be required.
  25082. maxLength: 253
  25083. minLength: 1
  25084. pattern: ^[-._a-zA-Z0-9]+$
  25085. type: string
  25086. name:
  25087. description: The name of the Secret resource being referred to.
  25088. maxLength: 253
  25089. minLength: 1
  25090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25091. type: string
  25092. namespace:
  25093. description: |-
  25094. The namespace of the Secret resource being referred to.
  25095. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25096. maxLength: 63
  25097. minLength: 1
  25098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25099. type: string
  25100. type: object
  25101. serviceAccountRef:
  25102. description: |-
  25103. Optional service account field containing the name of a kubernetes ServiceAccount.
  25104. If the service account is specified, the service account secret token JWT will be used
  25105. for authenticating with Vault. If the service account selector is not supplied,
  25106. the secretRef will be used instead.
  25107. properties:
  25108. audiences:
  25109. description: |-
  25110. Audience specifies the `aud` claim for the service account token
  25111. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25112. then this audiences will be appended to the list
  25113. items:
  25114. type: string
  25115. type: array
  25116. name:
  25117. description: The name of the ServiceAccount resource being referred to.
  25118. maxLength: 253
  25119. minLength: 1
  25120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25121. type: string
  25122. namespace:
  25123. description: |-
  25124. Namespace of the resource being referred to.
  25125. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25126. maxLength: 63
  25127. minLength: 1
  25128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25129. type: string
  25130. required:
  25131. - name
  25132. type: object
  25133. required:
  25134. - mountPath
  25135. - role
  25136. type: object
  25137. ldap:
  25138. description: |-
  25139. Ldap authenticates with Vault by passing username/password pair using
  25140. the LDAP authentication method
  25141. properties:
  25142. path:
  25143. default: ldap
  25144. description: |-
  25145. Path where the LDAP authentication backend is mounted
  25146. in Vault, e.g: "ldap"
  25147. type: string
  25148. secretRef:
  25149. description: |-
  25150. SecretRef to a key in a Secret resource containing password for the LDAP
  25151. user used to authenticate with Vault using the LDAP authentication
  25152. method
  25153. properties:
  25154. key:
  25155. description: |-
  25156. A key in the referenced Secret.
  25157. Some instances of this field may be defaulted, in others it may be required.
  25158. maxLength: 253
  25159. minLength: 1
  25160. pattern: ^[-._a-zA-Z0-9]+$
  25161. type: string
  25162. name:
  25163. description: The name of the Secret resource being referred to.
  25164. maxLength: 253
  25165. minLength: 1
  25166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25167. type: string
  25168. namespace:
  25169. description: |-
  25170. The namespace of the Secret resource being referred to.
  25171. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25172. maxLength: 63
  25173. minLength: 1
  25174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25175. type: string
  25176. type: object
  25177. username:
  25178. description: |-
  25179. Username is an LDAP username used to authenticate using the LDAP Vault
  25180. authentication method
  25181. type: string
  25182. required:
  25183. - path
  25184. - username
  25185. type: object
  25186. namespace:
  25187. description: |-
  25188. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  25189. Namespaces is a set of features within Vault Enterprise that allows
  25190. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  25191. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  25192. This will default to Vault.Namespace field if set, or empty otherwise
  25193. type: string
  25194. tokenSecretRef:
  25195. description: TokenSecretRef authenticates with Vault by presenting a token.
  25196. properties:
  25197. key:
  25198. description: |-
  25199. A key in the referenced Secret.
  25200. Some instances of this field may be defaulted, in others it may be required.
  25201. maxLength: 253
  25202. minLength: 1
  25203. pattern: ^[-._a-zA-Z0-9]+$
  25204. type: string
  25205. name:
  25206. description: The name of the Secret resource being referred to.
  25207. maxLength: 253
  25208. minLength: 1
  25209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25210. type: string
  25211. namespace:
  25212. description: |-
  25213. The namespace of the Secret resource being referred to.
  25214. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25215. maxLength: 63
  25216. minLength: 1
  25217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25218. type: string
  25219. type: object
  25220. userPass:
  25221. description: UserPass authenticates with Vault by passing username/password pair
  25222. properties:
  25223. path:
  25224. default: userpass
  25225. description: |-
  25226. Path where the UserPassword authentication backend is mounted
  25227. in Vault, e.g: "userpass"
  25228. type: string
  25229. secretRef:
  25230. description: |-
  25231. SecretRef to a key in a Secret resource containing password for the
  25232. user used to authenticate with Vault using the UserPass authentication
  25233. method
  25234. properties:
  25235. key:
  25236. description: |-
  25237. A key in the referenced Secret.
  25238. Some instances of this field may be defaulted, in others it may be required.
  25239. maxLength: 253
  25240. minLength: 1
  25241. pattern: ^[-._a-zA-Z0-9]+$
  25242. type: string
  25243. name:
  25244. description: The name of the Secret resource being referred to.
  25245. maxLength: 253
  25246. minLength: 1
  25247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25248. type: string
  25249. namespace:
  25250. description: |-
  25251. The namespace of the Secret resource being referred to.
  25252. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25253. maxLength: 63
  25254. minLength: 1
  25255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25256. type: string
  25257. type: object
  25258. username:
  25259. description: |-
  25260. Username is a username used to authenticate using the UserPass Vault
  25261. authentication method
  25262. type: string
  25263. required:
  25264. - path
  25265. - username
  25266. type: object
  25267. type: object
  25268. caBundle:
  25269. description: |-
  25270. PEM encoded CA bundle used to validate Vault server certificate. Only used
  25271. if the Server URL is using HTTPS protocol. This parameter is ignored for
  25272. plain HTTP protocol connection. If not set the system root certificates
  25273. are used to validate the TLS connection.
  25274. format: byte
  25275. type: string
  25276. caProvider:
  25277. description: The provider for the CA bundle to use to validate Vault server certificate.
  25278. properties:
  25279. key:
  25280. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25281. maxLength: 253
  25282. minLength: 1
  25283. pattern: ^[-._a-zA-Z0-9]+$
  25284. type: string
  25285. name:
  25286. description: The name of the object located at the provider type.
  25287. maxLength: 253
  25288. minLength: 1
  25289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25290. type: string
  25291. namespace:
  25292. description: |-
  25293. The namespace the Provider type is in.
  25294. Can only be defined when used in a ClusterSecretStore.
  25295. maxLength: 63
  25296. minLength: 1
  25297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25298. type: string
  25299. type:
  25300. description: The type of provider to use such as "Secret", or "ConfigMap".
  25301. enum:
  25302. - Secret
  25303. - ConfigMap
  25304. type: string
  25305. required:
  25306. - name
  25307. - type
  25308. type: object
  25309. forwardInconsistent:
  25310. description: |-
  25311. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  25312. leader instead of simply retrying within a loop. This can increase performance if
  25313. the option is enabled serverside.
  25314. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  25315. type: boolean
  25316. headers:
  25317. additionalProperties:
  25318. type: string
  25319. description: Headers to be added in Vault request
  25320. type: object
  25321. namespace:
  25322. description: |-
  25323. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  25324. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  25325. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  25326. type: string
  25327. path:
  25328. description: |-
  25329. Path is the mount path of the Vault KV backend endpoint, e.g:
  25330. "secret". The v2 KV secret engine version specific "/data" path suffix
  25331. for fetching secrets from Vault is optional and will be appended
  25332. if not present in specified path.
  25333. type: string
  25334. readYourWrites:
  25335. description: |-
  25336. ReadYourWrites ensures isolated read-after-write semantics by
  25337. providing discovered cluster replication states in each request.
  25338. More information about eventual consistency in Vault can be found here
  25339. https://www.vaultproject.io/docs/enterprise/consistency
  25340. type: boolean
  25341. server:
  25342. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  25343. type: string
  25344. tls:
  25345. description: |-
  25346. The configuration used for client side related TLS communication, when the Vault server
  25347. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  25348. This parameter is ignored for plain HTTP protocol connection.
  25349. It's worth noting this configuration is different from the "TLS certificates auth method",
  25350. which is available under the `auth.cert` section.
  25351. properties:
  25352. certSecretRef:
  25353. description: |-
  25354. CertSecretRef is a certificate added to the transport layer
  25355. when communicating with the Vault server.
  25356. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  25357. properties:
  25358. key:
  25359. description: |-
  25360. A key in the referenced Secret.
  25361. Some instances of this field may be defaulted, in others it may be required.
  25362. maxLength: 253
  25363. minLength: 1
  25364. pattern: ^[-._a-zA-Z0-9]+$
  25365. type: string
  25366. name:
  25367. description: The name of the Secret resource being referred to.
  25368. maxLength: 253
  25369. minLength: 1
  25370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25371. type: string
  25372. namespace:
  25373. description: |-
  25374. The namespace of the Secret resource being referred to.
  25375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25376. maxLength: 63
  25377. minLength: 1
  25378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25379. type: string
  25380. type: object
  25381. keySecretRef:
  25382. description: |-
  25383. KeySecretRef to a key in a Secret resource containing client private key
  25384. added to the transport layer when communicating with the Vault server.
  25385. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  25386. properties:
  25387. key:
  25388. description: |-
  25389. A key in the referenced Secret.
  25390. Some instances of this field may be defaulted, in others it may be required.
  25391. maxLength: 253
  25392. minLength: 1
  25393. pattern: ^[-._a-zA-Z0-9]+$
  25394. type: string
  25395. name:
  25396. description: The name of the Secret resource being referred to.
  25397. maxLength: 253
  25398. minLength: 1
  25399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25400. type: string
  25401. namespace:
  25402. description: |-
  25403. The namespace of the Secret resource being referred to.
  25404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25405. maxLength: 63
  25406. minLength: 1
  25407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25408. type: string
  25409. type: object
  25410. type: object
  25411. version:
  25412. default: v2
  25413. description: |-
  25414. Version is the Vault KV secret engine version. This can be either "v1" or
  25415. "v2". Version defaults to "v2".
  25416. enum:
  25417. - v1
  25418. - v2
  25419. type: string
  25420. required:
  25421. - server
  25422. type: object
  25423. webhook:
  25424. description: Webhook configures this store to sync secrets using a generic templated webhook
  25425. properties:
  25426. auth:
  25427. description: Auth specifies a authorization protocol. Only one protocol may be set.
  25428. maxProperties: 1
  25429. minProperties: 1
  25430. properties:
  25431. ntlm:
  25432. description: NTLMProtocol configures the store to use NTLM for auth
  25433. properties:
  25434. passwordSecret:
  25435. description: |-
  25436. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25437. In some instances, `key` is a required field.
  25438. properties:
  25439. key:
  25440. description: |-
  25441. A key in the referenced Secret.
  25442. Some instances of this field may be defaulted, in others it may be required.
  25443. maxLength: 253
  25444. minLength: 1
  25445. pattern: ^[-._a-zA-Z0-9]+$
  25446. type: string
  25447. name:
  25448. description: The name of the Secret resource being referred to.
  25449. maxLength: 253
  25450. minLength: 1
  25451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25452. type: string
  25453. namespace:
  25454. description: |-
  25455. The namespace of the Secret resource being referred to.
  25456. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25457. maxLength: 63
  25458. minLength: 1
  25459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25460. type: string
  25461. type: object
  25462. usernameSecret:
  25463. description: |-
  25464. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25465. In some instances, `key` is a required field.
  25466. properties:
  25467. key:
  25468. description: |-
  25469. A key in the referenced Secret.
  25470. Some instances of this field may be defaulted, in others it may be required.
  25471. maxLength: 253
  25472. minLength: 1
  25473. pattern: ^[-._a-zA-Z0-9]+$
  25474. type: string
  25475. name:
  25476. description: The name of the Secret resource being referred to.
  25477. maxLength: 253
  25478. minLength: 1
  25479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25480. type: string
  25481. namespace:
  25482. description: |-
  25483. The namespace of the Secret resource being referred to.
  25484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25485. maxLength: 63
  25486. minLength: 1
  25487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25488. type: string
  25489. type: object
  25490. required:
  25491. - passwordSecret
  25492. - usernameSecret
  25493. type: object
  25494. type: object
  25495. body:
  25496. description: Body
  25497. type: string
  25498. caBundle:
  25499. description: |-
  25500. PEM encoded CA bundle used to validate webhook server certificate. Only used
  25501. if the Server URL is using HTTPS protocol. This parameter is ignored for
  25502. plain HTTP protocol connection. If not set the system root certificates
  25503. are used to validate the TLS connection.
  25504. format: byte
  25505. type: string
  25506. caProvider:
  25507. description: The provider for the CA bundle to use to validate webhook server certificate.
  25508. properties:
  25509. key:
  25510. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25511. maxLength: 253
  25512. minLength: 1
  25513. pattern: ^[-._a-zA-Z0-9]+$
  25514. type: string
  25515. name:
  25516. description: The name of the object located at the provider type.
  25517. maxLength: 253
  25518. minLength: 1
  25519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25520. type: string
  25521. namespace:
  25522. description: The namespace the Provider type is in.
  25523. maxLength: 63
  25524. minLength: 1
  25525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25526. type: string
  25527. type:
  25528. description: The type of provider to use such as "Secret", or "ConfigMap".
  25529. enum:
  25530. - Secret
  25531. - ConfigMap
  25532. type: string
  25533. required:
  25534. - name
  25535. - type
  25536. type: object
  25537. headers:
  25538. additionalProperties:
  25539. type: string
  25540. description: Headers
  25541. type: object
  25542. method:
  25543. description: Webhook Method
  25544. type: string
  25545. result:
  25546. description: Result formatting
  25547. properties:
  25548. jsonPath:
  25549. description: Json path of return value
  25550. type: string
  25551. type: object
  25552. secrets:
  25553. description: |-
  25554. Secrets to fill in templates
  25555. These secrets will be passed to the templating function as key value pairs under the given name
  25556. items:
  25557. description: WebhookSecret defines a secret to be used in webhook templates.
  25558. properties:
  25559. name:
  25560. description: Name of this secret in templates
  25561. type: string
  25562. secretRef:
  25563. description: Secret ref to fill in credentials
  25564. properties:
  25565. key:
  25566. description: |-
  25567. A key in the referenced Secret.
  25568. Some instances of this field may be defaulted, in others it may be required.
  25569. maxLength: 253
  25570. minLength: 1
  25571. pattern: ^[-._a-zA-Z0-9]+$
  25572. type: string
  25573. name:
  25574. description: The name of the Secret resource being referred to.
  25575. maxLength: 253
  25576. minLength: 1
  25577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25578. type: string
  25579. namespace:
  25580. description: |-
  25581. The namespace of the Secret resource being referred to.
  25582. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25583. maxLength: 63
  25584. minLength: 1
  25585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25586. type: string
  25587. type: object
  25588. required:
  25589. - name
  25590. - secretRef
  25591. type: object
  25592. type: array
  25593. timeout:
  25594. description: Timeout
  25595. type: string
  25596. url:
  25597. description: Webhook url to call
  25598. type: string
  25599. required:
  25600. - result
  25601. - url
  25602. type: object
  25603. yandexcertificatemanager:
  25604. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  25605. properties:
  25606. apiEndpoint:
  25607. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  25608. type: string
  25609. auth:
  25610. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  25611. properties:
  25612. authorizedKeySecretRef:
  25613. description: The authorized key used for authentication
  25614. properties:
  25615. key:
  25616. description: |-
  25617. A key in the referenced Secret.
  25618. Some instances of this field may be defaulted, in others it may be required.
  25619. maxLength: 253
  25620. minLength: 1
  25621. pattern: ^[-._a-zA-Z0-9]+$
  25622. type: string
  25623. name:
  25624. description: The name of the Secret resource being referred to.
  25625. maxLength: 253
  25626. minLength: 1
  25627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25628. type: string
  25629. namespace:
  25630. description: |-
  25631. The namespace of the Secret resource being referred to.
  25632. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25633. maxLength: 63
  25634. minLength: 1
  25635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25636. type: string
  25637. type: object
  25638. type: object
  25639. caProvider:
  25640. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  25641. properties:
  25642. certSecretRef:
  25643. description: |-
  25644. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25645. In some instances, `key` is a required field.
  25646. properties:
  25647. key:
  25648. description: |-
  25649. A key in the referenced Secret.
  25650. Some instances of this field may be defaulted, in others it may be required.
  25651. maxLength: 253
  25652. minLength: 1
  25653. pattern: ^[-._a-zA-Z0-9]+$
  25654. type: string
  25655. name:
  25656. description: The name of the Secret resource being referred to.
  25657. maxLength: 253
  25658. minLength: 1
  25659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25660. type: string
  25661. namespace:
  25662. description: |-
  25663. The namespace of the Secret resource being referred to.
  25664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25665. maxLength: 63
  25666. minLength: 1
  25667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25668. type: string
  25669. type: object
  25670. type: object
  25671. required:
  25672. - auth
  25673. type: object
  25674. yandexlockbox:
  25675. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  25676. properties:
  25677. apiEndpoint:
  25678. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  25679. type: string
  25680. auth:
  25681. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  25682. properties:
  25683. authorizedKeySecretRef:
  25684. description: The authorized key used for authentication
  25685. properties:
  25686. key:
  25687. description: |-
  25688. A key in the referenced Secret.
  25689. Some instances of this field may be defaulted, in others it may be required.
  25690. maxLength: 253
  25691. minLength: 1
  25692. pattern: ^[-._a-zA-Z0-9]+$
  25693. type: string
  25694. name:
  25695. description: The name of the Secret resource being referred to.
  25696. maxLength: 253
  25697. minLength: 1
  25698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25699. type: string
  25700. namespace:
  25701. description: |-
  25702. The namespace of the Secret resource being referred to.
  25703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25704. maxLength: 63
  25705. minLength: 1
  25706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25707. type: string
  25708. type: object
  25709. type: object
  25710. caProvider:
  25711. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  25712. properties:
  25713. certSecretRef:
  25714. description: |-
  25715. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25716. In some instances, `key` is a required field.
  25717. properties:
  25718. key:
  25719. description: |-
  25720. A key in the referenced Secret.
  25721. Some instances of this field may be defaulted, in others it may be required.
  25722. maxLength: 253
  25723. minLength: 1
  25724. pattern: ^[-._a-zA-Z0-9]+$
  25725. type: string
  25726. name:
  25727. description: The name of the Secret resource being referred to.
  25728. maxLength: 253
  25729. minLength: 1
  25730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25731. type: string
  25732. namespace:
  25733. description: |-
  25734. The namespace of the Secret resource being referred to.
  25735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25736. maxLength: 63
  25737. minLength: 1
  25738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25739. type: string
  25740. type: object
  25741. type: object
  25742. required:
  25743. - auth
  25744. type: object
  25745. type: object
  25746. refreshInterval:
  25747. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  25748. type: integer
  25749. retrySettings:
  25750. description: Used to configure HTTP retries on failures.
  25751. properties:
  25752. maxRetries:
  25753. description: MaxRetries is the maximum number of retry attempts.
  25754. format: int32
  25755. type: integer
  25756. retryInterval:
  25757. description: RetryInterval is the interval between retry attempts.
  25758. type: string
  25759. type: object
  25760. required:
  25761. - provider
  25762. type: object
  25763. status:
  25764. description: SecretStoreStatus defines the observed state of the SecretStore.
  25765. properties:
  25766. capabilities:
  25767. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  25768. type: string
  25769. conditions:
  25770. items:
  25771. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  25772. properties:
  25773. lastTransitionTime:
  25774. format: date-time
  25775. type: string
  25776. message:
  25777. type: string
  25778. reason:
  25779. type: string
  25780. status:
  25781. type: string
  25782. type:
  25783. description: SecretStoreConditionType represents the condition type of the SecretStore.
  25784. type: string
  25785. required:
  25786. - status
  25787. - type
  25788. type: object
  25789. type: array
  25790. type: object
  25791. type: object
  25792. served: false
  25793. storage: false
  25794. subresources:
  25795. status: {}
  25796. ---
  25797. apiVersion: apiextensions.k8s.io/v1
  25798. kind: CustomResourceDefinition
  25799. metadata:
  25800. annotations:
  25801. controller-gen.kubebuilder.io/version: v0.19.0
  25802. labels:
  25803. external-secrets.io/component: controller
  25804. name: acraccesstokens.generators.external-secrets.io
  25805. spec:
  25806. group: generators.external-secrets.io
  25807. names:
  25808. categories:
  25809. - external-secrets
  25810. - external-secrets-generators
  25811. kind: ACRAccessToken
  25812. listKind: ACRAccessTokenList
  25813. plural: acraccesstokens
  25814. singular: acraccesstoken
  25815. scope: Namespaced
  25816. versions:
  25817. - name: v1alpha1
  25818. schema:
  25819. openAPIV3Schema:
  25820. description: |-
  25821. ACRAccessToken returns an Azure Container Registry token
  25822. that can be used for pushing/pulling images.
  25823. Note: by default it will return an ACR Refresh Token with full access
  25824. (depending on the identity).
  25825. This can be scoped down to the repository level using .spec.scope.
  25826. In case scope is defined it will return an ACR Access Token.
  25827. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  25828. properties:
  25829. apiVersion:
  25830. description: |-
  25831. APIVersion defines the versioned schema of this representation of an object.
  25832. Servers should convert recognized schemas to the latest internal value, and
  25833. may reject unrecognized values.
  25834. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  25835. type: string
  25836. kind:
  25837. description: |-
  25838. Kind is a string value representing the REST resource this object represents.
  25839. Servers may infer this from the endpoint the client submits requests to.
  25840. Cannot be updated.
  25841. In CamelCase.
  25842. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  25843. type: string
  25844. metadata:
  25845. type: object
  25846. spec:
  25847. description: |-
  25848. ACRAccessTokenSpec defines how to generate the access token
  25849. e.g. how to authenticate and which registry to use.
  25850. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  25851. properties:
  25852. auth:
  25853. description: ACRAuth defines the authentication methods for Azure Container Registry.
  25854. properties:
  25855. managedIdentity:
  25856. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  25857. properties:
  25858. identityId:
  25859. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  25860. type: string
  25861. type: object
  25862. servicePrincipal:
  25863. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  25864. properties:
  25865. secretRef:
  25866. description: |-
  25867. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  25868. It uses static credentials stored in a Kind=Secret.
  25869. properties:
  25870. clientId:
  25871. description: The Azure clientId of the service principle used for authentication.
  25872. properties:
  25873. key:
  25874. description: |-
  25875. A key in the referenced Secret.
  25876. Some instances of this field may be defaulted, in others it may be required.
  25877. maxLength: 253
  25878. minLength: 1
  25879. pattern: ^[-._a-zA-Z0-9]+$
  25880. type: string
  25881. name:
  25882. description: The name of the Secret resource being referred to.
  25883. maxLength: 253
  25884. minLength: 1
  25885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25886. type: string
  25887. namespace:
  25888. description: |-
  25889. The namespace of the Secret resource being referred to.
  25890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25891. maxLength: 63
  25892. minLength: 1
  25893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25894. type: string
  25895. type: object
  25896. clientSecret:
  25897. description: The Azure ClientSecret of the service principle used for authentication.
  25898. properties:
  25899. key:
  25900. description: |-
  25901. A key in the referenced Secret.
  25902. Some instances of this field may be defaulted, in others it may be required.
  25903. maxLength: 253
  25904. minLength: 1
  25905. pattern: ^[-._a-zA-Z0-9]+$
  25906. type: string
  25907. name:
  25908. description: The name of the Secret resource being referred to.
  25909. maxLength: 253
  25910. minLength: 1
  25911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25912. type: string
  25913. namespace:
  25914. description: |-
  25915. The namespace of the Secret resource being referred to.
  25916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25917. maxLength: 63
  25918. minLength: 1
  25919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25920. type: string
  25921. type: object
  25922. type: object
  25923. required:
  25924. - secretRef
  25925. type: object
  25926. workloadIdentity:
  25927. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  25928. properties:
  25929. serviceAccountRef:
  25930. description: |-
  25931. ServiceAccountRef specified the service account
  25932. that should be used when authenticating with WorkloadIdentity.
  25933. properties:
  25934. audiences:
  25935. description: |-
  25936. Audience specifies the `aud` claim for the service account token
  25937. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25938. then this audiences will be appended to the list
  25939. items:
  25940. type: string
  25941. type: array
  25942. name:
  25943. description: The name of the ServiceAccount resource being referred to.
  25944. maxLength: 253
  25945. minLength: 1
  25946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25947. type: string
  25948. namespace:
  25949. description: |-
  25950. Namespace of the resource being referred to.
  25951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25952. maxLength: 63
  25953. minLength: 1
  25954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25955. type: string
  25956. required:
  25957. - name
  25958. type: object
  25959. type: object
  25960. type: object
  25961. environmentType:
  25962. default: PublicCloud
  25963. description: |-
  25964. EnvironmentType specifies the Azure cloud environment endpoints to use for
  25965. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  25966. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  25967. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  25968. enum:
  25969. - PublicCloud
  25970. - USGovernmentCloud
  25971. - ChinaCloud
  25972. - GermanCloud
  25973. - AzureStackCloud
  25974. type: string
  25975. registry:
  25976. description: |-
  25977. the domain name of the ACR registry
  25978. e.g. foobarexample.azurecr.io
  25979. type: string
  25980. scope:
  25981. description: |-
  25982. Define the scope for the access token, e.g. pull/push access for a repository.
  25983. if not provided it will return a refresh token that has full scope.
  25984. Note: you need to pin it down to the repository level, there is no wildcard available.
  25985. examples:
  25986. repository:my-repository:pull,push
  25987. repository:my-repository:pull
  25988. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  25989. type: string
  25990. tenantId:
  25991. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  25992. type: string
  25993. required:
  25994. - auth
  25995. - registry
  25996. type: object
  25997. type: object
  25998. served: true
  25999. storage: true
  26000. subresources:
  26001. status: {}
  26002. ---
  26003. apiVersion: apiextensions.k8s.io/v1
  26004. kind: CustomResourceDefinition
  26005. metadata:
  26006. annotations:
  26007. controller-gen.kubebuilder.io/version: v0.19.0
  26008. labels:
  26009. external-secrets.io/component: controller
  26010. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26011. spec:
  26012. group: generators.external-secrets.io
  26013. names:
  26014. categories:
  26015. - external-secrets
  26016. - external-secrets-generators
  26017. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26018. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26019. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26020. singular: beyondtrustworkloadcredentialsdynamicsecret
  26021. scope: Namespaced
  26022. versions:
  26023. - name: v1alpha1
  26024. schema:
  26025. openAPIV3Schema:
  26026. description: |-
  26027. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26028. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26029. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26030. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26031. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26032. properties:
  26033. apiVersion:
  26034. description: |-
  26035. APIVersion defines the versioned schema of this representation of an object.
  26036. Servers should convert recognized schemas to the latest internal value, and
  26037. may reject unrecognized values.
  26038. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26039. type: string
  26040. kind:
  26041. description: |-
  26042. Kind is a string value representing the REST resource this object represents.
  26043. Servers may infer this from the endpoint the client submits requests to.
  26044. Cannot be updated.
  26045. In CamelCase.
  26046. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26047. type: string
  26048. metadata:
  26049. type: object
  26050. spec:
  26051. description: |-
  26052. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26053. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26054. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26055. properties:
  26056. controller:
  26057. description: |-
  26058. Controller selects the controller that should handle this generator.
  26059. Leave empty to use the default controller.
  26060. type: string
  26061. provider:
  26062. description: |-
  26063. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26064. server connection details, and the folder path to the dynamic secret definition.
  26065. The folderPath should point to a dynamic secret definition that has been created in
  26066. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26067. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26068. properties:
  26069. auth:
  26070. description: |-
  26071. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26072. Currently supports API key authentication via Kubernetes secret reference.
  26073. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26074. properties:
  26075. apikey:
  26076. description: |-
  26077. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26078. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26079. properties:
  26080. token:
  26081. description: |-
  26082. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26083. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26084. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26085. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26086. properties:
  26087. key:
  26088. description: |-
  26089. A key in the referenced Secret.
  26090. Some instances of this field may be defaulted, in others it may be required.
  26091. maxLength: 253
  26092. minLength: 1
  26093. pattern: ^[-._a-zA-Z0-9]+$
  26094. type: string
  26095. name:
  26096. description: The name of the Secret resource being referred to.
  26097. maxLength: 253
  26098. minLength: 1
  26099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26100. type: string
  26101. namespace:
  26102. description: |-
  26103. The namespace of the Secret resource being referred to.
  26104. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26105. maxLength: 63
  26106. minLength: 1
  26107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26108. type: string
  26109. type: object
  26110. required:
  26111. - token
  26112. type: object
  26113. required:
  26114. - apikey
  26115. type: object
  26116. caBundle:
  26117. description: |-
  26118. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26119. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26120. If not set, the system's trusted root certificates are used.
  26121. format: byte
  26122. type: string
  26123. caProvider:
  26124. description: |-
  26125. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26126. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26127. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26128. properties:
  26129. key:
  26130. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26131. maxLength: 253
  26132. minLength: 1
  26133. pattern: ^[-._a-zA-Z0-9]+$
  26134. type: string
  26135. name:
  26136. description: The name of the object located at the provider type.
  26137. maxLength: 253
  26138. minLength: 1
  26139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26140. type: string
  26141. namespace:
  26142. description: |-
  26143. The namespace the Provider type is in.
  26144. Can only be defined when used in a ClusterSecretStore.
  26145. maxLength: 63
  26146. minLength: 1
  26147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26148. type: string
  26149. type:
  26150. description: The type of provider to use such as "Secret", or "ConfigMap".
  26151. enum:
  26152. - Secret
  26153. - ConfigMap
  26154. type: string
  26155. required:
  26156. - name
  26157. - type
  26158. type: object
  26159. folderPath:
  26160. description: |-
  26161. FolderPath specifies the default folder path for secret retrieval.
  26162. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  26163. Example: "production/database" or "dev/api-keys"
  26164. Leave empty to retrieve secrets from the root folder.
  26165. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  26166. type: string
  26167. server:
  26168. description: |-
  26169. Server configures the BeyondTrust Workload Credentials server connection details.
  26170. Includes the API URL and Site ID for your BeyondTrust instance.
  26171. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26172. properties:
  26173. apiUrl:
  26174. description: |-
  26175. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  26176. This should be the full URL to your BeyondTrust instance.
  26177. Example: https://api.beyondtrust.io/siie
  26178. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  26179. type: string
  26180. siteId:
  26181. description: |-
  26182. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  26183. This identifier is unique to your BeyondTrust Workload Credentials instance.
  26184. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  26185. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  26186. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26187. type: string
  26188. required:
  26189. - apiUrl
  26190. - siteId
  26191. type: object
  26192. required:
  26193. - auth
  26194. - server
  26195. type: object
  26196. retrySettings:
  26197. description: |-
  26198. RetrySettings configures exponential backoff for failed API requests.
  26199. If not specified, uses the default retry settings.
  26200. properties:
  26201. maxRetries:
  26202. format: int32
  26203. type: integer
  26204. retryInterval:
  26205. type: string
  26206. type: object
  26207. required:
  26208. - provider
  26209. type: object
  26210. type: object
  26211. served: true
  26212. storage: true
  26213. subresources:
  26214. status: {}
  26215. ---
  26216. apiVersion: apiextensions.k8s.io/v1
  26217. kind: CustomResourceDefinition
  26218. metadata:
  26219. annotations:
  26220. controller-gen.kubebuilder.io/version: v0.19.0
  26221. labels:
  26222. external-secrets.io/component: controller
  26223. name: cloudsmithaccesstokens.generators.external-secrets.io
  26224. spec:
  26225. group: generators.external-secrets.io
  26226. names:
  26227. categories:
  26228. - external-secrets
  26229. - external-secrets-generators
  26230. kind: CloudsmithAccessToken
  26231. listKind: CloudsmithAccessTokenList
  26232. plural: cloudsmithaccesstokens
  26233. singular: cloudsmithaccesstoken
  26234. scope: Namespaced
  26235. versions:
  26236. - name: v1alpha1
  26237. schema:
  26238. openAPIV3Schema:
  26239. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  26240. properties:
  26241. apiVersion:
  26242. description: |-
  26243. APIVersion defines the versioned schema of this representation of an object.
  26244. Servers should convert recognized schemas to the latest internal value, and
  26245. may reject unrecognized values.
  26246. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26247. type: string
  26248. kind:
  26249. description: |-
  26250. Kind is a string value representing the REST resource this object represents.
  26251. Servers may infer this from the endpoint the client submits requests to.
  26252. Cannot be updated.
  26253. In CamelCase.
  26254. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26255. type: string
  26256. metadata:
  26257. type: object
  26258. spec:
  26259. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  26260. properties:
  26261. apiUrl:
  26262. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  26263. type: string
  26264. orgSlug:
  26265. description: OrgSlug is the organization slug in Cloudsmith
  26266. type: string
  26267. serviceAccountRef:
  26268. description: Name of the service account you are federating with
  26269. properties:
  26270. audiences:
  26271. description: |-
  26272. Audience specifies the `aud` claim for the service account token
  26273. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26274. then this audiences will be appended to the list
  26275. items:
  26276. type: string
  26277. type: array
  26278. name:
  26279. description: The name of the ServiceAccount resource being referred to.
  26280. maxLength: 253
  26281. minLength: 1
  26282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26283. type: string
  26284. namespace:
  26285. description: |-
  26286. Namespace of the resource being referred to.
  26287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26288. maxLength: 63
  26289. minLength: 1
  26290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26291. type: string
  26292. required:
  26293. - name
  26294. type: object
  26295. serviceSlug:
  26296. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  26297. type: string
  26298. required:
  26299. - orgSlug
  26300. - serviceAccountRef
  26301. - serviceSlug
  26302. type: object
  26303. type: object
  26304. served: true
  26305. storage: true
  26306. subresources:
  26307. status: {}
  26308. ---
  26309. apiVersion: apiextensions.k8s.io/v1
  26310. kind: CustomResourceDefinition
  26311. metadata:
  26312. annotations:
  26313. controller-gen.kubebuilder.io/version: v0.19.0
  26314. labels:
  26315. external-secrets.io/component: controller
  26316. name: clustergenerators.generators.external-secrets.io
  26317. spec:
  26318. group: generators.external-secrets.io
  26319. names:
  26320. categories:
  26321. - external-secrets
  26322. - external-secrets-generators
  26323. kind: ClusterGenerator
  26324. listKind: ClusterGeneratorList
  26325. plural: clustergenerators
  26326. singular: clustergenerator
  26327. scope: Cluster
  26328. versions:
  26329. - name: v1alpha1
  26330. schema:
  26331. openAPIV3Schema:
  26332. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  26333. properties:
  26334. apiVersion:
  26335. description: |-
  26336. APIVersion defines the versioned schema of this representation of an object.
  26337. Servers should convert recognized schemas to the latest internal value, and
  26338. may reject unrecognized values.
  26339. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26340. type: string
  26341. kind:
  26342. description: |-
  26343. Kind is a string value representing the REST resource this object represents.
  26344. Servers may infer this from the endpoint the client submits requests to.
  26345. Cannot be updated.
  26346. In CamelCase.
  26347. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26348. type: string
  26349. metadata:
  26350. type: object
  26351. spec:
  26352. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  26353. properties:
  26354. generator:
  26355. description: Generator the spec for this generator, must match the kind.
  26356. maxProperties: 1
  26357. minProperties: 1
  26358. properties:
  26359. acrAccessTokenSpec:
  26360. description: |-
  26361. ACRAccessTokenSpec defines how to generate the access token
  26362. e.g. how to authenticate and which registry to use.
  26363. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26364. properties:
  26365. auth:
  26366. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26367. properties:
  26368. managedIdentity:
  26369. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26370. properties:
  26371. identityId:
  26372. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26373. type: string
  26374. type: object
  26375. servicePrincipal:
  26376. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26377. properties:
  26378. secretRef:
  26379. description: |-
  26380. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26381. It uses static credentials stored in a Kind=Secret.
  26382. properties:
  26383. clientId:
  26384. description: The Azure clientId of the service principle used for authentication.
  26385. properties:
  26386. key:
  26387. description: |-
  26388. A key in the referenced Secret.
  26389. Some instances of this field may be defaulted, in others it may be required.
  26390. maxLength: 253
  26391. minLength: 1
  26392. pattern: ^[-._a-zA-Z0-9]+$
  26393. type: string
  26394. name:
  26395. description: The name of the Secret resource being referred to.
  26396. maxLength: 253
  26397. minLength: 1
  26398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26399. type: string
  26400. namespace:
  26401. description: |-
  26402. The namespace of the Secret resource being referred to.
  26403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26404. maxLength: 63
  26405. minLength: 1
  26406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26407. type: string
  26408. type: object
  26409. clientSecret:
  26410. description: The Azure ClientSecret of the service principle used for authentication.
  26411. properties:
  26412. key:
  26413. description: |-
  26414. A key in the referenced Secret.
  26415. Some instances of this field may be defaulted, in others it may be required.
  26416. maxLength: 253
  26417. minLength: 1
  26418. pattern: ^[-._a-zA-Z0-9]+$
  26419. type: string
  26420. name:
  26421. description: The name of the Secret resource being referred to.
  26422. maxLength: 253
  26423. minLength: 1
  26424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26425. type: string
  26426. namespace:
  26427. description: |-
  26428. The namespace of the Secret resource being referred to.
  26429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26430. maxLength: 63
  26431. minLength: 1
  26432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26433. type: string
  26434. type: object
  26435. type: object
  26436. required:
  26437. - secretRef
  26438. type: object
  26439. workloadIdentity:
  26440. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26441. properties:
  26442. serviceAccountRef:
  26443. description: |-
  26444. ServiceAccountRef specified the service account
  26445. that should be used when authenticating with WorkloadIdentity.
  26446. properties:
  26447. audiences:
  26448. description: |-
  26449. Audience specifies the `aud` claim for the service account token
  26450. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26451. then this audiences will be appended to the list
  26452. items:
  26453. type: string
  26454. type: array
  26455. name:
  26456. description: The name of the ServiceAccount resource being referred to.
  26457. maxLength: 253
  26458. minLength: 1
  26459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26460. type: string
  26461. namespace:
  26462. description: |-
  26463. Namespace of the resource being referred to.
  26464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26465. maxLength: 63
  26466. minLength: 1
  26467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26468. type: string
  26469. required:
  26470. - name
  26471. type: object
  26472. type: object
  26473. type: object
  26474. environmentType:
  26475. default: PublicCloud
  26476. description: |-
  26477. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26478. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26479. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26480. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26481. enum:
  26482. - PublicCloud
  26483. - USGovernmentCloud
  26484. - ChinaCloud
  26485. - GermanCloud
  26486. - AzureStackCloud
  26487. type: string
  26488. registry:
  26489. description: |-
  26490. the domain name of the ACR registry
  26491. e.g. foobarexample.azurecr.io
  26492. type: string
  26493. scope:
  26494. description: |-
  26495. Define the scope for the access token, e.g. pull/push access for a repository.
  26496. if not provided it will return a refresh token that has full scope.
  26497. Note: you need to pin it down to the repository level, there is no wildcard available.
  26498. examples:
  26499. repository:my-repository:pull,push
  26500. repository:my-repository:pull
  26501. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26502. type: string
  26503. tenantId:
  26504. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26505. type: string
  26506. required:
  26507. - auth
  26508. - registry
  26509. type: object
  26510. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  26511. description: |-
  26512. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26513. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26514. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26515. properties:
  26516. controller:
  26517. description: |-
  26518. Controller selects the controller that should handle this generator.
  26519. Leave empty to use the default controller.
  26520. type: string
  26521. provider:
  26522. description: |-
  26523. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26524. server connection details, and the folder path to the dynamic secret definition.
  26525. The folderPath should point to a dynamic secret definition that has been created in
  26526. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26527. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26528. properties:
  26529. auth:
  26530. description: |-
  26531. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26532. Currently supports API key authentication via Kubernetes secret reference.
  26533. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26534. properties:
  26535. apikey:
  26536. description: |-
  26537. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26538. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26539. properties:
  26540. token:
  26541. description: |-
  26542. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26543. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26544. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26545. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26546. properties:
  26547. key:
  26548. description: |-
  26549. A key in the referenced Secret.
  26550. Some instances of this field may be defaulted, in others it may be required.
  26551. maxLength: 253
  26552. minLength: 1
  26553. pattern: ^[-._a-zA-Z0-9]+$
  26554. type: string
  26555. name:
  26556. description: The name of the Secret resource being referred to.
  26557. maxLength: 253
  26558. minLength: 1
  26559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26560. type: string
  26561. namespace:
  26562. description: |-
  26563. The namespace of the Secret resource being referred to.
  26564. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26565. maxLength: 63
  26566. minLength: 1
  26567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26568. type: string
  26569. type: object
  26570. required:
  26571. - token
  26572. type: object
  26573. required:
  26574. - apikey
  26575. type: object
  26576. caBundle:
  26577. description: |-
  26578. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26579. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26580. If not set, the system's trusted root certificates are used.
  26581. format: byte
  26582. type: string
  26583. caProvider:
  26584. description: |-
  26585. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26586. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26587. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26588. properties:
  26589. key:
  26590. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26591. maxLength: 253
  26592. minLength: 1
  26593. pattern: ^[-._a-zA-Z0-9]+$
  26594. type: string
  26595. name:
  26596. description: The name of the object located at the provider type.
  26597. maxLength: 253
  26598. minLength: 1
  26599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26600. type: string
  26601. namespace:
  26602. description: |-
  26603. The namespace the Provider type is in.
  26604. Can only be defined when used in a ClusterSecretStore.
  26605. maxLength: 63
  26606. minLength: 1
  26607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26608. type: string
  26609. type:
  26610. description: The type of provider to use such as "Secret", or "ConfigMap".
  26611. enum:
  26612. - Secret
  26613. - ConfigMap
  26614. type: string
  26615. required:
  26616. - name
  26617. - type
  26618. type: object
  26619. folderPath:
  26620. description: |-
  26621. FolderPath specifies the default folder path for secret retrieval.
  26622. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  26623. Example: "production/database" or "dev/api-keys"
  26624. Leave empty to retrieve secrets from the root folder.
  26625. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  26626. type: string
  26627. server:
  26628. description: |-
  26629. Server configures the BeyondTrust Workload Credentials server connection details.
  26630. Includes the API URL and Site ID for your BeyondTrust instance.
  26631. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26632. properties:
  26633. apiUrl:
  26634. description: |-
  26635. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  26636. This should be the full URL to your BeyondTrust instance.
  26637. Example: https://api.beyondtrust.io/siie
  26638. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  26639. type: string
  26640. siteId:
  26641. description: |-
  26642. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  26643. This identifier is unique to your BeyondTrust Workload Credentials instance.
  26644. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  26645. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  26646. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26647. type: string
  26648. required:
  26649. - apiUrl
  26650. - siteId
  26651. type: object
  26652. required:
  26653. - auth
  26654. - server
  26655. type: object
  26656. retrySettings:
  26657. description: |-
  26658. RetrySettings configures exponential backoff for failed API requests.
  26659. If not specified, uses the default retry settings.
  26660. properties:
  26661. maxRetries:
  26662. format: int32
  26663. type: integer
  26664. retryInterval:
  26665. type: string
  26666. type: object
  26667. required:
  26668. - provider
  26669. type: object
  26670. cloudsmithAccessTokenSpec:
  26671. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  26672. properties:
  26673. apiUrl:
  26674. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  26675. type: string
  26676. orgSlug:
  26677. description: OrgSlug is the organization slug in Cloudsmith
  26678. type: string
  26679. serviceAccountRef:
  26680. description: Name of the service account you are federating with
  26681. properties:
  26682. audiences:
  26683. description: |-
  26684. Audience specifies the `aud` claim for the service account token
  26685. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26686. then this audiences will be appended to the list
  26687. items:
  26688. type: string
  26689. type: array
  26690. name:
  26691. description: The name of the ServiceAccount resource being referred to.
  26692. maxLength: 253
  26693. minLength: 1
  26694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26695. type: string
  26696. namespace:
  26697. description: |-
  26698. Namespace of the resource being referred to.
  26699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26700. maxLength: 63
  26701. minLength: 1
  26702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26703. type: string
  26704. required:
  26705. - name
  26706. type: object
  26707. serviceSlug:
  26708. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  26709. type: string
  26710. required:
  26711. - orgSlug
  26712. - serviceAccountRef
  26713. - serviceSlug
  26714. type: object
  26715. ecrAuthorizationTokenSpec:
  26716. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  26717. properties:
  26718. auth:
  26719. description: Auth defines how to authenticate with AWS
  26720. properties:
  26721. jwt:
  26722. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  26723. properties:
  26724. serviceAccountRef:
  26725. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26726. properties:
  26727. audiences:
  26728. description: |-
  26729. Audience specifies the `aud` claim for the service account token
  26730. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26731. then this audiences will be appended to the list
  26732. items:
  26733. type: string
  26734. type: array
  26735. name:
  26736. description: The name of the ServiceAccount resource being referred to.
  26737. maxLength: 253
  26738. minLength: 1
  26739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26740. type: string
  26741. namespace:
  26742. description: |-
  26743. Namespace of the resource being referred to.
  26744. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26745. maxLength: 63
  26746. minLength: 1
  26747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26748. type: string
  26749. required:
  26750. - name
  26751. type: object
  26752. type: object
  26753. secretRef:
  26754. description: |-
  26755. AWSAuthSecretRef holds secret references for AWS credentials
  26756. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  26757. properties:
  26758. accessKeyIDSecretRef:
  26759. description: The AccessKeyID is used for authentication
  26760. properties:
  26761. key:
  26762. description: |-
  26763. A key in the referenced Secret.
  26764. Some instances of this field may be defaulted, in others it may be required.
  26765. maxLength: 253
  26766. minLength: 1
  26767. pattern: ^[-._a-zA-Z0-9]+$
  26768. type: string
  26769. name:
  26770. description: The name of the Secret resource being referred to.
  26771. maxLength: 253
  26772. minLength: 1
  26773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26774. type: string
  26775. namespace:
  26776. description: |-
  26777. The namespace of the Secret resource being referred to.
  26778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26779. maxLength: 63
  26780. minLength: 1
  26781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26782. type: string
  26783. type: object
  26784. secretAccessKeySecretRef:
  26785. description: The SecretAccessKey is used for authentication
  26786. properties:
  26787. key:
  26788. description: |-
  26789. A key in the referenced Secret.
  26790. Some instances of this field may be defaulted, in others it may be required.
  26791. maxLength: 253
  26792. minLength: 1
  26793. pattern: ^[-._a-zA-Z0-9]+$
  26794. type: string
  26795. name:
  26796. description: The name of the Secret resource being referred to.
  26797. maxLength: 253
  26798. minLength: 1
  26799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26800. type: string
  26801. namespace:
  26802. description: |-
  26803. The namespace of the Secret resource being referred to.
  26804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26805. maxLength: 63
  26806. minLength: 1
  26807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26808. type: string
  26809. type: object
  26810. sessionTokenSecretRef:
  26811. description: |-
  26812. The SessionToken used for authentication
  26813. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26814. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26815. properties:
  26816. key:
  26817. description: |-
  26818. A key in the referenced Secret.
  26819. Some instances of this field may be defaulted, in others it may be required.
  26820. maxLength: 253
  26821. minLength: 1
  26822. pattern: ^[-._a-zA-Z0-9]+$
  26823. type: string
  26824. name:
  26825. description: The name of the Secret resource being referred to.
  26826. maxLength: 253
  26827. minLength: 1
  26828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26829. type: string
  26830. namespace:
  26831. description: |-
  26832. The namespace of the Secret resource being referred to.
  26833. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26834. maxLength: 63
  26835. minLength: 1
  26836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26837. type: string
  26838. type: object
  26839. type: object
  26840. type: object
  26841. region:
  26842. description: Region specifies the region to operate in.
  26843. type: string
  26844. role:
  26845. description: |-
  26846. You can assume a role before making calls to the
  26847. desired AWS service.
  26848. type: string
  26849. scope:
  26850. description: |-
  26851. Scope specifies the ECR service scope.
  26852. Valid options are private and public.
  26853. type: string
  26854. required:
  26855. - region
  26856. type: object
  26857. fakeSpec:
  26858. description: FakeSpec contains the static data.
  26859. properties:
  26860. controller:
  26861. description: |-
  26862. Used to select the correct ESO controller (think: ingress.ingressClassName)
  26863. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  26864. type: string
  26865. data:
  26866. additionalProperties:
  26867. type: string
  26868. description: |-
  26869. Data defines the static data returned
  26870. by this generator.
  26871. type: object
  26872. type: object
  26873. gcrAccessTokenSpec:
  26874. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  26875. properties:
  26876. auth:
  26877. description: Auth defines the means for authenticating with GCP
  26878. properties:
  26879. secretRef:
  26880. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  26881. properties:
  26882. secretAccessKeySecretRef:
  26883. description: The SecretAccessKey is used for authentication
  26884. properties:
  26885. key:
  26886. description: |-
  26887. A key in the referenced Secret.
  26888. Some instances of this field may be defaulted, in others it may be required.
  26889. maxLength: 253
  26890. minLength: 1
  26891. pattern: ^[-._a-zA-Z0-9]+$
  26892. type: string
  26893. name:
  26894. description: The name of the Secret resource being referred to.
  26895. maxLength: 253
  26896. minLength: 1
  26897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26898. type: string
  26899. namespace:
  26900. description: |-
  26901. The namespace of the Secret resource being referred to.
  26902. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26903. maxLength: 63
  26904. minLength: 1
  26905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26906. type: string
  26907. type: object
  26908. type: object
  26909. workloadIdentity:
  26910. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  26911. properties:
  26912. clusterLocation:
  26913. type: string
  26914. clusterName:
  26915. type: string
  26916. clusterProjectID:
  26917. type: string
  26918. serviceAccountRef:
  26919. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26920. properties:
  26921. audiences:
  26922. description: |-
  26923. Audience specifies the `aud` claim for the service account token
  26924. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26925. then this audiences will be appended to the list
  26926. items:
  26927. type: string
  26928. type: array
  26929. name:
  26930. description: The name of the ServiceAccount resource being referred to.
  26931. maxLength: 253
  26932. minLength: 1
  26933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26934. type: string
  26935. namespace:
  26936. description: |-
  26937. Namespace of the resource being referred to.
  26938. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26939. maxLength: 63
  26940. minLength: 1
  26941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26942. type: string
  26943. required:
  26944. - name
  26945. type: object
  26946. required:
  26947. - clusterLocation
  26948. - clusterName
  26949. - serviceAccountRef
  26950. type: object
  26951. workloadIdentityFederation:
  26952. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  26953. properties:
  26954. audience:
  26955. description: |-
  26956. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  26957. If specified, Audience found in the external account credential config will be overridden with the configured value.
  26958. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  26959. type: string
  26960. awsSecurityCredentials:
  26961. description: |-
  26962. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  26963. when using the AWS metadata server is not an option.
  26964. properties:
  26965. awsCredentialsSecretRef:
  26966. description: |-
  26967. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  26968. Secret should be created with below names for keys
  26969. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  26970. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  26971. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  26972. properties:
  26973. name:
  26974. description: name of the secret.
  26975. maxLength: 253
  26976. minLength: 1
  26977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26978. type: string
  26979. namespace:
  26980. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  26981. maxLength: 63
  26982. minLength: 1
  26983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26984. type: string
  26985. required:
  26986. - name
  26987. type: object
  26988. region:
  26989. description: region is for configuring the AWS region to be used.
  26990. example: ap-south-1
  26991. maxLength: 50
  26992. minLength: 1
  26993. pattern: ^[a-z0-9-]+$
  26994. type: string
  26995. required:
  26996. - awsCredentialsSecretRef
  26997. - region
  26998. type: object
  26999. credConfig:
  27000. description: |-
  27001. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27002. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27003. serviceAccountRef must be used by providing operators service account details.
  27004. properties:
  27005. key:
  27006. description: key name holding the external account credential config.
  27007. maxLength: 253
  27008. minLength: 1
  27009. pattern: ^[-._a-zA-Z0-9]+$
  27010. type: string
  27011. name:
  27012. description: name of the configmap.
  27013. maxLength: 253
  27014. minLength: 1
  27015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27016. type: string
  27017. namespace:
  27018. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27019. maxLength: 63
  27020. minLength: 1
  27021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27022. type: string
  27023. required:
  27024. - key
  27025. - name
  27026. type: object
  27027. externalTokenEndpoint:
  27028. description: |-
  27029. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27030. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27031. URL is having the expected value.
  27032. type: string
  27033. gcpServiceAccountEmail:
  27034. description: |-
  27035. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27036. after Workload Identity Federation. Use this to grant access through the service account's
  27037. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27038. service_account_impersonation_url in the external account JSON from credConfig;
  27039. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27040. on that ServiceAccount.
  27041. example: my-gsa@my-project.iam.gserviceaccount.com
  27042. minLength: 1
  27043. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27044. type: string
  27045. serviceAccountRef:
  27046. description: |-
  27047. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27048. when Kubernetes is configured as provider in workload identity pool.
  27049. properties:
  27050. audiences:
  27051. description: |-
  27052. Audience specifies the `aud` claim for the service account token
  27053. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27054. then this audiences will be appended to the list
  27055. items:
  27056. type: string
  27057. type: array
  27058. name:
  27059. description: The name of the ServiceAccount resource being referred to.
  27060. maxLength: 253
  27061. minLength: 1
  27062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27063. type: string
  27064. namespace:
  27065. description: |-
  27066. Namespace of the resource being referred to.
  27067. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27068. maxLength: 63
  27069. minLength: 1
  27070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27071. type: string
  27072. required:
  27073. - name
  27074. type: object
  27075. type: object
  27076. type: object
  27077. projectID:
  27078. description: ProjectID defines which project to use to authenticate with
  27079. type: string
  27080. required:
  27081. - auth
  27082. - projectID
  27083. type: object
  27084. githubAccessTokenSpec:
  27085. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27086. properties:
  27087. appID:
  27088. type: string
  27089. auth:
  27090. description: Auth configures how ESO authenticates with a Github instance.
  27091. properties:
  27092. privateKey:
  27093. description: GithubSecretRef references a secret containing GitHub credentials.
  27094. properties:
  27095. secretRef:
  27096. description: |-
  27097. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27098. In some instances, `key` is a required field.
  27099. properties:
  27100. key:
  27101. description: |-
  27102. A key in the referenced Secret.
  27103. Some instances of this field may be defaulted, in others it may be required.
  27104. maxLength: 253
  27105. minLength: 1
  27106. pattern: ^[-._a-zA-Z0-9]+$
  27107. type: string
  27108. name:
  27109. description: The name of the Secret resource being referred to.
  27110. maxLength: 253
  27111. minLength: 1
  27112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27113. type: string
  27114. namespace:
  27115. description: |-
  27116. The namespace of the Secret resource being referred to.
  27117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27118. maxLength: 63
  27119. minLength: 1
  27120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27121. type: string
  27122. type: object
  27123. required:
  27124. - secretRef
  27125. type: object
  27126. required:
  27127. - privateKey
  27128. type: object
  27129. installID:
  27130. type: string
  27131. permissions:
  27132. additionalProperties:
  27133. type: string
  27134. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27135. type: object
  27136. repositories:
  27137. description: |-
  27138. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  27139. is installed to.
  27140. items:
  27141. type: string
  27142. type: array
  27143. url:
  27144. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  27145. type: string
  27146. required:
  27147. - appID
  27148. - auth
  27149. - installID
  27150. type: object
  27151. gitlabDeployTokenSpec:
  27152. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  27153. properties:
  27154. auth:
  27155. description: Auth configures how ESO authenticates with the GitLab API.
  27156. properties:
  27157. token:
  27158. description: |-
  27159. Token references a secret containing a GitLab access token (personal, group, or
  27160. project) with the api scope and at least the Maintainer role on the target.
  27161. properties:
  27162. secretRef:
  27163. description: |-
  27164. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27165. In some instances, `key` is a required field.
  27166. properties:
  27167. key:
  27168. description: |-
  27169. A key in the referenced Secret.
  27170. Some instances of this field may be defaulted, in others it may be required.
  27171. maxLength: 253
  27172. minLength: 1
  27173. pattern: ^[-._a-zA-Z0-9]+$
  27174. type: string
  27175. name:
  27176. description: The name of the Secret resource being referred to.
  27177. maxLength: 253
  27178. minLength: 1
  27179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27180. type: string
  27181. namespace:
  27182. description: |-
  27183. The namespace of the Secret resource being referred to.
  27184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27185. maxLength: 63
  27186. minLength: 1
  27187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27188. type: string
  27189. type: object
  27190. required:
  27191. - secretRef
  27192. type: object
  27193. required:
  27194. - token
  27195. type: object
  27196. expiresAt:
  27197. description: |-
  27198. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  27199. not expire on the GitLab side and is revoked only when the generator state is
  27200. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  27201. format: date-time
  27202. type: string
  27203. groupID:
  27204. description: |-
  27205. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  27206. create the deploy token in. The generator URL-escapes paths before calling the
  27207. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  27208. minLength: 1
  27209. type: string
  27210. name:
  27211. description: Name of the deploy token.
  27212. minLength: 1
  27213. type: string
  27214. projectID:
  27215. description: |-
  27216. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  27217. project to create the deploy token in. The generator URL-escapes paths before
  27218. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  27219. minLength: 1
  27220. type: string
  27221. scopes:
  27222. description: Scopes granted to the deploy token. At least one scope is required.
  27223. items:
  27224. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  27225. enum:
  27226. - read_repository
  27227. - read_registry
  27228. - write_registry
  27229. - read_package_registry
  27230. - write_package_registry
  27231. - read_virtual_registry
  27232. - write_virtual_registry
  27233. type: string
  27234. minItems: 1
  27235. type: array
  27236. url:
  27237. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  27238. type: string
  27239. username:
  27240. description: |-
  27241. Username is an optional username for the deploy token. GitLab defaults it to
  27242. gitlab+deploy-token-{n} when omitted.
  27243. type: string
  27244. required:
  27245. - auth
  27246. - name
  27247. - scopes
  27248. type: object
  27249. x-kubernetes-validations:
  27250. - message: exactly one of projectID or groupID must be set
  27251. rule: has(self.projectID) != has(self.groupID)
  27252. grafanaSpec:
  27253. description: GrafanaSpec controls the behavior of the grafana generator.
  27254. properties:
  27255. auth:
  27256. description: |-
  27257. Auth is the authentication configuration to authenticate
  27258. against the Grafana instance.
  27259. properties:
  27260. basic:
  27261. description: |-
  27262. Basic auth credentials used to authenticate against the Grafana instance.
  27263. Note: you need a token which has elevated permissions to create service accounts.
  27264. See here for the documentation on basic roles offered by Grafana:
  27265. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27266. properties:
  27267. password:
  27268. description: A basic auth password used to authenticate against the Grafana instance.
  27269. properties:
  27270. key:
  27271. description: The key where the token is found.
  27272. maxLength: 253
  27273. minLength: 1
  27274. pattern: ^[-._a-zA-Z0-9]+$
  27275. type: string
  27276. name:
  27277. description: The name of the Secret resource being referred to.
  27278. maxLength: 253
  27279. minLength: 1
  27280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27281. type: string
  27282. type: object
  27283. username:
  27284. description: A basic auth username used to authenticate against the Grafana instance.
  27285. type: string
  27286. required:
  27287. - password
  27288. - username
  27289. type: object
  27290. token:
  27291. description: |-
  27292. A service account token used to authenticate against the Grafana instance.
  27293. Note: you need a token which has elevated permissions to create service accounts.
  27294. See here for the documentation on basic roles offered by Grafana:
  27295. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27296. properties:
  27297. key:
  27298. description: The key where the token is found.
  27299. maxLength: 253
  27300. minLength: 1
  27301. pattern: ^[-._a-zA-Z0-9]+$
  27302. type: string
  27303. name:
  27304. description: The name of the Secret resource being referred to.
  27305. maxLength: 253
  27306. minLength: 1
  27307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27308. type: string
  27309. type: object
  27310. type: object
  27311. serviceAccount:
  27312. description: |-
  27313. ServiceAccount is the configuration for the service account that
  27314. is supposed to be generated by the generator.
  27315. properties:
  27316. name:
  27317. description: Name is the name of the service account that will be created by ESO.
  27318. type: string
  27319. role:
  27320. description: |-
  27321. Role is the role of the service account.
  27322. See here for the documentation on basic roles offered by Grafana:
  27323. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27324. type: string
  27325. secondsToLive:
  27326. description: |-
  27327. SecondsToLive is the number of seconds before the generated service account token will expire.
  27328. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  27329. format: int64
  27330. minimum: 1
  27331. type: integer
  27332. required:
  27333. - name
  27334. - role
  27335. type: object
  27336. url:
  27337. description: URL is the URL of the Grafana instance.
  27338. type: string
  27339. required:
  27340. - auth
  27341. - serviceAccount
  27342. - url
  27343. type: object
  27344. mfaSpec:
  27345. description: MFASpec controls the behavior of the mfa generator.
  27346. properties:
  27347. algorithm:
  27348. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  27349. type: string
  27350. length:
  27351. description: Length defines the token length. Defaults to 6 characters.
  27352. type: integer
  27353. secret:
  27354. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  27355. properties:
  27356. key:
  27357. description: |-
  27358. A key in the referenced Secret.
  27359. Some instances of this field may be defaulted, in others it may be required.
  27360. maxLength: 253
  27361. minLength: 1
  27362. pattern: ^[-._a-zA-Z0-9]+$
  27363. type: string
  27364. name:
  27365. description: The name of the Secret resource being referred to.
  27366. maxLength: 253
  27367. minLength: 1
  27368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27369. type: string
  27370. namespace:
  27371. description: |-
  27372. The namespace of the Secret resource being referred to.
  27373. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27374. maxLength: 63
  27375. minLength: 1
  27376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27377. type: string
  27378. type: object
  27379. timePeriod:
  27380. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  27381. type: integer
  27382. when:
  27383. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  27384. format: date-time
  27385. type: string
  27386. required:
  27387. - secret
  27388. type: object
  27389. passwordSpec:
  27390. description: PasswordSpec controls the behavior of the password generator.
  27391. properties:
  27392. allowRepeat:
  27393. default: false
  27394. description: set AllowRepeat to true to allow repeating characters.
  27395. type: boolean
  27396. digits:
  27397. description: |-
  27398. Digits specifies the number of digits in the generated
  27399. password. If omitted it defaults to 25% of the length of the password
  27400. type: integer
  27401. encoding:
  27402. default: raw
  27403. description: |-
  27404. Encoding specifies the encoding of the generated password.
  27405. Valid values are:
  27406. - "raw" (default): no encoding
  27407. - "base64": standard base64 encoding
  27408. - "base64url": base64url encoding
  27409. - "base32": base32 encoding
  27410. - "hex": hexadecimal encoding
  27411. enum:
  27412. - base64
  27413. - base64url
  27414. - base32
  27415. - hex
  27416. - raw
  27417. type: string
  27418. length:
  27419. default: 24
  27420. description: |-
  27421. Length of the password to be generated.
  27422. Defaults to 24
  27423. type: integer
  27424. noUpper:
  27425. default: false
  27426. description: Set NoUpper to disable uppercase characters
  27427. type: boolean
  27428. secretKeys:
  27429. description: |-
  27430. SecretKeys defines the keys that will be populated with generated passwords.
  27431. Defaults to "password" when not set.
  27432. items:
  27433. type: string
  27434. minItems: 1
  27435. type: array
  27436. symbolCharacters:
  27437. description: |-
  27438. SymbolCharacters specifies the special characters that should be used
  27439. in the generated password.
  27440. type: string
  27441. symbols:
  27442. description: |-
  27443. Symbols specifies the number of symbol characters in the generated
  27444. password. If omitted it defaults to 25% of the length of the password
  27445. type: integer
  27446. required:
  27447. - allowRepeat
  27448. - length
  27449. - noUpper
  27450. type: object
  27451. quayAccessTokenSpec:
  27452. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  27453. properties:
  27454. robotAccount:
  27455. description: Name of the robot account you are federating with
  27456. type: string
  27457. serviceAccountRef:
  27458. description: Name of the service account you are federating with
  27459. properties:
  27460. audiences:
  27461. description: |-
  27462. Audience specifies the `aud` claim for the service account token
  27463. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27464. then this audiences will be appended to the list
  27465. items:
  27466. type: string
  27467. type: array
  27468. name:
  27469. description: The name of the ServiceAccount resource being referred to.
  27470. maxLength: 253
  27471. minLength: 1
  27472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27473. type: string
  27474. namespace:
  27475. description: |-
  27476. Namespace of the resource being referred to.
  27477. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27478. maxLength: 63
  27479. minLength: 1
  27480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27481. type: string
  27482. required:
  27483. - name
  27484. type: object
  27485. url:
  27486. description: URL configures the Quay instance URL. Defaults to quay.io.
  27487. type: string
  27488. required:
  27489. - robotAccount
  27490. - serviceAccountRef
  27491. type: object
  27492. sshKeySpec:
  27493. description: SSHKeySpec controls the behavior of the ssh key generator.
  27494. properties:
  27495. comment:
  27496. description: Comment specifies an optional comment for the SSH key
  27497. type: string
  27498. keySize:
  27499. description: |-
  27500. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  27501. For RSA keys: 2048, 3072, 4096
  27502. For ECDSA keys: 256, 384, 521
  27503. Ignored for ed25519 keys
  27504. maximum: 8192
  27505. minimum: 256
  27506. type: integer
  27507. keyType:
  27508. default: rsa
  27509. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  27510. enum:
  27511. - rsa
  27512. - ecdsa
  27513. - ed25519
  27514. type: string
  27515. type: object
  27516. stsSessionTokenSpec:
  27517. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  27518. properties:
  27519. auth:
  27520. description: Auth defines how to authenticate with AWS
  27521. properties:
  27522. jwt:
  27523. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27524. properties:
  27525. serviceAccountRef:
  27526. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27527. properties:
  27528. audiences:
  27529. description: |-
  27530. Audience specifies the `aud` claim for the service account token
  27531. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27532. then this audiences will be appended to the list
  27533. items:
  27534. type: string
  27535. type: array
  27536. name:
  27537. description: The name of the ServiceAccount resource being referred to.
  27538. maxLength: 253
  27539. minLength: 1
  27540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27541. type: string
  27542. namespace:
  27543. description: |-
  27544. Namespace of the resource being referred to.
  27545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27546. maxLength: 63
  27547. minLength: 1
  27548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27549. type: string
  27550. required:
  27551. - name
  27552. type: object
  27553. type: object
  27554. secretRef:
  27555. description: |-
  27556. AWSAuthSecretRef holds secret references for AWS credentials
  27557. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27558. properties:
  27559. accessKeyIDSecretRef:
  27560. description: The AccessKeyID is used for authentication
  27561. properties:
  27562. key:
  27563. description: |-
  27564. A key in the referenced Secret.
  27565. Some instances of this field may be defaulted, in others it may be required.
  27566. maxLength: 253
  27567. minLength: 1
  27568. pattern: ^[-._a-zA-Z0-9]+$
  27569. type: string
  27570. name:
  27571. description: The name of the Secret resource being referred to.
  27572. maxLength: 253
  27573. minLength: 1
  27574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27575. type: string
  27576. namespace:
  27577. description: |-
  27578. The namespace of the Secret resource being referred to.
  27579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27580. maxLength: 63
  27581. minLength: 1
  27582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27583. type: string
  27584. type: object
  27585. secretAccessKeySecretRef:
  27586. description: The SecretAccessKey is used for authentication
  27587. properties:
  27588. key:
  27589. description: |-
  27590. A key in the referenced Secret.
  27591. Some instances of this field may be defaulted, in others it may be required.
  27592. maxLength: 253
  27593. minLength: 1
  27594. pattern: ^[-._a-zA-Z0-9]+$
  27595. type: string
  27596. name:
  27597. description: The name of the Secret resource being referred to.
  27598. maxLength: 253
  27599. minLength: 1
  27600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27601. type: string
  27602. namespace:
  27603. description: |-
  27604. The namespace of the Secret resource being referred to.
  27605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27606. maxLength: 63
  27607. minLength: 1
  27608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27609. type: string
  27610. type: object
  27611. sessionTokenSecretRef:
  27612. description: |-
  27613. The SessionToken used for authentication
  27614. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27615. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27616. properties:
  27617. key:
  27618. description: |-
  27619. A key in the referenced Secret.
  27620. Some instances of this field may be defaulted, in others it may be required.
  27621. maxLength: 253
  27622. minLength: 1
  27623. pattern: ^[-._a-zA-Z0-9]+$
  27624. type: string
  27625. name:
  27626. description: The name of the Secret resource being referred to.
  27627. maxLength: 253
  27628. minLength: 1
  27629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27630. type: string
  27631. namespace:
  27632. description: |-
  27633. The namespace of the Secret resource being referred to.
  27634. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27635. maxLength: 63
  27636. minLength: 1
  27637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27638. type: string
  27639. type: object
  27640. type: object
  27641. type: object
  27642. region:
  27643. description: Region specifies the region to operate in.
  27644. type: string
  27645. requestParameters:
  27646. description: RequestParameters contains parameters that can be passed to the STS service.
  27647. properties:
  27648. serialNumber:
  27649. description: |-
  27650. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  27651. the GetSessionToken call.
  27652. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  27653. (such as arn:aws:iam::123456789012:mfa/user)
  27654. type: string
  27655. sessionDuration:
  27656. format: int32
  27657. type: integer
  27658. tokenCode:
  27659. description: TokenCode is the value provided by the MFA device, if MFA is required.
  27660. type: string
  27661. type: object
  27662. role:
  27663. description: |-
  27664. You can assume a role before making calls to the
  27665. desired AWS service.
  27666. type: string
  27667. required:
  27668. - region
  27669. type: object
  27670. uuidSpec:
  27671. description: UUIDSpec controls the behavior of the uuid generator.
  27672. type: object
  27673. vaultDynamicSecretSpec:
  27674. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  27675. properties:
  27676. allowEmptyResponse:
  27677. default: false
  27678. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  27679. type: boolean
  27680. controller:
  27681. description: |-
  27682. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27683. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27684. type: string
  27685. getParameters:
  27686. additionalProperties:
  27687. items:
  27688. type: string
  27689. type: array
  27690. description: |-
  27691. GetParameters are query-string parameters passed to Vault on GET calls.
  27692. Each key may map to multiple values, matching HTTP query-string semantics.
  27693. Ignored for non-GET methods; use Parameters for write bodies.
  27694. type: object
  27695. method:
  27696. description: Vault API method to use (GET/POST/other)
  27697. type: string
  27698. parameters:
  27699. description: Parameters to pass to Vault write (for non-GET methods)
  27700. x-kubernetes-preserve-unknown-fields: true
  27701. path:
  27702. description: Vault path to obtain the dynamic secret from
  27703. type: string
  27704. provider:
  27705. description: Vault provider common spec
  27706. properties:
  27707. auth:
  27708. description: Auth configures how secret-manager authenticates with the Vault server.
  27709. properties:
  27710. appRole:
  27711. description: |-
  27712. AppRole authenticates with Vault using the App Role auth mechanism,
  27713. with the role and secret stored in a Kubernetes Secret resource.
  27714. properties:
  27715. path:
  27716. default: approle
  27717. description: |-
  27718. Path where the App Role authentication backend is mounted
  27719. in Vault, e.g: "approle"
  27720. type: string
  27721. roleId:
  27722. description: |-
  27723. RoleID configured in the App Role authentication backend when setting
  27724. up the authentication backend in Vault.
  27725. type: string
  27726. roleRef:
  27727. description: |-
  27728. Reference to a key in a Secret that contains the App Role ID used
  27729. to authenticate with Vault.
  27730. The `key` field must be specified and denotes which entry within the Secret
  27731. resource is used as the app role id.
  27732. properties:
  27733. key:
  27734. description: |-
  27735. A key in the referenced Secret.
  27736. Some instances of this field may be defaulted, in others it may be required.
  27737. maxLength: 253
  27738. minLength: 1
  27739. pattern: ^[-._a-zA-Z0-9]+$
  27740. type: string
  27741. name:
  27742. description: The name of the Secret resource being referred to.
  27743. maxLength: 253
  27744. minLength: 1
  27745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27746. type: string
  27747. namespace:
  27748. description: |-
  27749. The namespace of the Secret resource being referred to.
  27750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27751. maxLength: 63
  27752. minLength: 1
  27753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27754. type: string
  27755. type: object
  27756. secretRef:
  27757. description: |-
  27758. Reference to a key in a Secret that contains the App Role secret used
  27759. to authenticate with Vault.
  27760. The `key` field must be specified and denotes which entry within the Secret
  27761. resource is used as the app role secret.
  27762. properties:
  27763. key:
  27764. description: |-
  27765. A key in the referenced Secret.
  27766. Some instances of this field may be defaulted, in others it may be required.
  27767. maxLength: 253
  27768. minLength: 1
  27769. pattern: ^[-._a-zA-Z0-9]+$
  27770. type: string
  27771. name:
  27772. description: The name of the Secret resource being referred to.
  27773. maxLength: 253
  27774. minLength: 1
  27775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27776. type: string
  27777. namespace:
  27778. description: |-
  27779. The namespace of the Secret resource being referred to.
  27780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27781. maxLength: 63
  27782. minLength: 1
  27783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27784. type: string
  27785. type: object
  27786. required:
  27787. - path
  27788. - secretRef
  27789. type: object
  27790. cert:
  27791. description: |-
  27792. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  27793. Cert authentication method
  27794. properties:
  27795. clientCert:
  27796. description: |-
  27797. ClientCert is a certificate to authenticate using the Cert Vault
  27798. authentication method
  27799. properties:
  27800. key:
  27801. description: |-
  27802. A key in the referenced Secret.
  27803. Some instances of this field may be defaulted, in others it may be required.
  27804. maxLength: 253
  27805. minLength: 1
  27806. pattern: ^[-._a-zA-Z0-9]+$
  27807. type: string
  27808. name:
  27809. description: The name of the Secret resource being referred to.
  27810. maxLength: 253
  27811. minLength: 1
  27812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27813. type: string
  27814. namespace:
  27815. description: |-
  27816. The namespace of the Secret resource being referred to.
  27817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27818. maxLength: 63
  27819. minLength: 1
  27820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27821. type: string
  27822. type: object
  27823. path:
  27824. default: cert
  27825. description: |-
  27826. Path where the Certificate authentication backend is mounted
  27827. in Vault, e.g: "cert"
  27828. type: string
  27829. secretRef:
  27830. description: |-
  27831. SecretRef to a key in a Secret resource containing client private key to
  27832. authenticate with Vault using the Cert authentication method
  27833. properties:
  27834. key:
  27835. description: |-
  27836. A key in the referenced Secret.
  27837. Some instances of this field may be defaulted, in others it may be required.
  27838. maxLength: 253
  27839. minLength: 1
  27840. pattern: ^[-._a-zA-Z0-9]+$
  27841. type: string
  27842. name:
  27843. description: The name of the Secret resource being referred to.
  27844. maxLength: 253
  27845. minLength: 1
  27846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27847. type: string
  27848. namespace:
  27849. description: |-
  27850. The namespace of the Secret resource being referred to.
  27851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27852. maxLength: 63
  27853. minLength: 1
  27854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27855. type: string
  27856. type: object
  27857. vaultRole:
  27858. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  27859. type: string
  27860. type: object
  27861. gcp:
  27862. description: |-
  27863. Gcp authenticates with Vault using Google Cloud Platform authentication method
  27864. GCP authentication method
  27865. properties:
  27866. location:
  27867. description: Location optionally defines a location/region for the secret
  27868. type: string
  27869. path:
  27870. default: gcp
  27871. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  27872. type: string
  27873. projectID:
  27874. description: Project ID of the Google Cloud Platform project
  27875. type: string
  27876. role:
  27877. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  27878. type: string
  27879. secretRef:
  27880. description: Specify credentials in a Secret object
  27881. properties:
  27882. secretAccessKeySecretRef:
  27883. description: The SecretAccessKey is used for authentication
  27884. properties:
  27885. key:
  27886. description: |-
  27887. A key in the referenced Secret.
  27888. Some instances of this field may be defaulted, in others it may be required.
  27889. maxLength: 253
  27890. minLength: 1
  27891. pattern: ^[-._a-zA-Z0-9]+$
  27892. type: string
  27893. name:
  27894. description: The name of the Secret resource being referred to.
  27895. maxLength: 253
  27896. minLength: 1
  27897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27898. type: string
  27899. namespace:
  27900. description: |-
  27901. The namespace of the Secret resource being referred to.
  27902. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27903. maxLength: 63
  27904. minLength: 1
  27905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27906. type: string
  27907. type: object
  27908. type: object
  27909. serviceAccountRef:
  27910. description: ServiceAccountRef to a service account for impersonation
  27911. properties:
  27912. audiences:
  27913. description: |-
  27914. Audience specifies the `aud` claim for the service account token
  27915. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27916. then this audiences will be appended to the list
  27917. items:
  27918. type: string
  27919. type: array
  27920. name:
  27921. description: The name of the ServiceAccount resource being referred to.
  27922. maxLength: 253
  27923. minLength: 1
  27924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27925. type: string
  27926. namespace:
  27927. description: |-
  27928. Namespace of the resource being referred to.
  27929. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27930. maxLength: 63
  27931. minLength: 1
  27932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27933. type: string
  27934. required:
  27935. - name
  27936. type: object
  27937. workloadIdentity:
  27938. description: Specify a service account with Workload Identity
  27939. properties:
  27940. clusterLocation:
  27941. description: |-
  27942. ClusterLocation is the location of the cluster
  27943. If not specified, it fetches information from the metadata server
  27944. type: string
  27945. clusterName:
  27946. description: |-
  27947. ClusterName is the name of the cluster
  27948. If not specified, it fetches information from the metadata server
  27949. type: string
  27950. clusterProjectID:
  27951. description: |-
  27952. ClusterProjectID is the project ID of the cluster
  27953. If not specified, it fetches information from the metadata server
  27954. type: string
  27955. serviceAccountRef:
  27956. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27957. properties:
  27958. audiences:
  27959. description: |-
  27960. Audience specifies the `aud` claim for the service account token
  27961. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27962. then this audiences will be appended to the list
  27963. items:
  27964. type: string
  27965. type: array
  27966. name:
  27967. description: The name of the ServiceAccount resource being referred to.
  27968. maxLength: 253
  27969. minLength: 1
  27970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27971. type: string
  27972. namespace:
  27973. description: |-
  27974. Namespace of the resource being referred to.
  27975. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27976. maxLength: 63
  27977. minLength: 1
  27978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27979. type: string
  27980. required:
  27981. - name
  27982. type: object
  27983. required:
  27984. - serviceAccountRef
  27985. type: object
  27986. required:
  27987. - role
  27988. type: object
  27989. iam:
  27990. description: |-
  27991. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  27992. AWS IAM authentication method
  27993. properties:
  27994. externalID:
  27995. description: AWS External ID set on assumed IAM roles
  27996. type: string
  27997. jwt:
  27998. description: Specify a service account with IRSA enabled
  27999. properties:
  28000. serviceAccountRef:
  28001. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28002. properties:
  28003. audiences:
  28004. description: |-
  28005. Audience specifies the `aud` claim for the service account token
  28006. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28007. then this audiences will be appended to the list
  28008. items:
  28009. type: string
  28010. type: array
  28011. name:
  28012. description: The name of the ServiceAccount resource being referred to.
  28013. maxLength: 253
  28014. minLength: 1
  28015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28016. type: string
  28017. namespace:
  28018. description: |-
  28019. Namespace of the resource being referred to.
  28020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28021. maxLength: 63
  28022. minLength: 1
  28023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28024. type: string
  28025. required:
  28026. - name
  28027. type: object
  28028. type: object
  28029. path:
  28030. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28031. type: string
  28032. region:
  28033. description: AWS region
  28034. type: string
  28035. role:
  28036. description: This is the AWS role to be assumed before talking to vault
  28037. type: string
  28038. secretRef:
  28039. description: Specify credentials in a Secret object
  28040. properties:
  28041. accessKeyIDSecretRef:
  28042. description: The AccessKeyID is used for authentication
  28043. properties:
  28044. key:
  28045. description: |-
  28046. A key in the referenced Secret.
  28047. Some instances of this field may be defaulted, in others it may be required.
  28048. maxLength: 253
  28049. minLength: 1
  28050. pattern: ^[-._a-zA-Z0-9]+$
  28051. type: string
  28052. name:
  28053. description: The name of the Secret resource being referred to.
  28054. maxLength: 253
  28055. minLength: 1
  28056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28057. type: string
  28058. namespace:
  28059. description: |-
  28060. The namespace of the Secret resource being referred to.
  28061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28062. maxLength: 63
  28063. minLength: 1
  28064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28065. type: string
  28066. type: object
  28067. secretAccessKeySecretRef:
  28068. description: The SecretAccessKey is used for authentication
  28069. properties:
  28070. key:
  28071. description: |-
  28072. A key in the referenced Secret.
  28073. Some instances of this field may be defaulted, in others it may be required.
  28074. maxLength: 253
  28075. minLength: 1
  28076. pattern: ^[-._a-zA-Z0-9]+$
  28077. type: string
  28078. name:
  28079. description: The name of the Secret resource being referred to.
  28080. maxLength: 253
  28081. minLength: 1
  28082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28083. type: string
  28084. namespace:
  28085. description: |-
  28086. The namespace of the Secret resource being referred to.
  28087. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28088. maxLength: 63
  28089. minLength: 1
  28090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28091. type: string
  28092. type: object
  28093. sessionTokenSecretRef:
  28094. description: |-
  28095. The SessionToken used for authentication
  28096. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28097. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28098. properties:
  28099. key:
  28100. description: |-
  28101. A key in the referenced Secret.
  28102. Some instances of this field may be defaulted, in others it may be required.
  28103. maxLength: 253
  28104. minLength: 1
  28105. pattern: ^[-._a-zA-Z0-9]+$
  28106. type: string
  28107. name:
  28108. description: The name of the Secret resource being referred to.
  28109. maxLength: 253
  28110. minLength: 1
  28111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28112. type: string
  28113. namespace:
  28114. description: |-
  28115. The namespace of the Secret resource being referred to.
  28116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28117. maxLength: 63
  28118. minLength: 1
  28119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28120. type: string
  28121. type: object
  28122. type: object
  28123. vaultAwsIamServerID:
  28124. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28125. type: string
  28126. vaultRole:
  28127. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28128. type: string
  28129. required:
  28130. - vaultRole
  28131. type: object
  28132. jwt:
  28133. description: |-
  28134. Jwt authenticates with Vault by passing role and JWT token using the
  28135. JWT/OIDC authentication method
  28136. properties:
  28137. kubernetesServiceAccountToken:
  28138. description: |-
  28139. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  28140. a token for with the `TokenRequest` API.
  28141. properties:
  28142. audiences:
  28143. description: |-
  28144. Optional audiences field that will be used to request a temporary Kubernetes service
  28145. account token for the service account referenced by `serviceAccountRef`.
  28146. Defaults to a single audience `vault` it not specified.
  28147. Deprecated: use serviceAccountRef.Audiences instead
  28148. items:
  28149. type: string
  28150. type: array
  28151. expirationSeconds:
  28152. description: |-
  28153. Optional expiration time in seconds that will be used to request a temporary
  28154. Kubernetes service account token for the service account referenced by
  28155. `serviceAccountRef`.
  28156. Deprecated: this will be removed in the future.
  28157. Defaults to 10 minutes.
  28158. format: int64
  28159. type: integer
  28160. serviceAccountRef:
  28161. description: Service account field containing the name of a kubernetes ServiceAccount.
  28162. properties:
  28163. audiences:
  28164. description: |-
  28165. Audience specifies the `aud` claim for the service account token
  28166. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28167. then this audiences will be appended to the list
  28168. items:
  28169. type: string
  28170. type: array
  28171. name:
  28172. description: The name of the ServiceAccount resource being referred to.
  28173. maxLength: 253
  28174. minLength: 1
  28175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28176. type: string
  28177. namespace:
  28178. description: |-
  28179. Namespace of the resource being referred to.
  28180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28181. maxLength: 63
  28182. minLength: 1
  28183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28184. type: string
  28185. required:
  28186. - name
  28187. type: object
  28188. required:
  28189. - serviceAccountRef
  28190. type: object
  28191. path:
  28192. default: jwt
  28193. description: |-
  28194. Path where the JWT authentication backend is mounted
  28195. in Vault, e.g: "jwt"
  28196. type: string
  28197. role:
  28198. description: |-
  28199. Role is a JWT role to authenticate using the JWT/OIDC Vault
  28200. authentication method
  28201. type: string
  28202. secretRef:
  28203. description: |-
  28204. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  28205. authenticate with Vault using the JWT/OIDC authentication method.
  28206. properties:
  28207. key:
  28208. description: |-
  28209. A key in the referenced Secret.
  28210. Some instances of this field may be defaulted, in others it may be required.
  28211. maxLength: 253
  28212. minLength: 1
  28213. pattern: ^[-._a-zA-Z0-9]+$
  28214. type: string
  28215. name:
  28216. description: The name of the Secret resource being referred to.
  28217. maxLength: 253
  28218. minLength: 1
  28219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28220. type: string
  28221. namespace:
  28222. description: |-
  28223. The namespace of the Secret resource being referred to.
  28224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28225. maxLength: 63
  28226. minLength: 1
  28227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28228. type: string
  28229. type: object
  28230. required:
  28231. - path
  28232. type: object
  28233. kubernetes:
  28234. description: |-
  28235. Kubernetes authenticates with Vault by passing the ServiceAccount
  28236. token stored in the named Secret resource to the Vault server.
  28237. properties:
  28238. mountPath:
  28239. default: kubernetes
  28240. description: |-
  28241. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  28242. "kubernetes"
  28243. type: string
  28244. role:
  28245. description: |-
  28246. A required field containing the Vault Role to assume. A Role binds a
  28247. Kubernetes ServiceAccount with a set of Vault policies.
  28248. type: string
  28249. secretRef:
  28250. description: |-
  28251. Optional secret field containing a Kubernetes ServiceAccount JWT used
  28252. for authenticating with Vault. If a name is specified without a key,
  28253. `token` is the default. If one is not specified, the one bound to
  28254. the controller will be used.
  28255. properties:
  28256. key:
  28257. description: |-
  28258. A key in the referenced Secret.
  28259. Some instances of this field may be defaulted, in others it may be required.
  28260. maxLength: 253
  28261. minLength: 1
  28262. pattern: ^[-._a-zA-Z0-9]+$
  28263. type: string
  28264. name:
  28265. description: The name of the Secret resource being referred to.
  28266. maxLength: 253
  28267. minLength: 1
  28268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28269. type: string
  28270. namespace:
  28271. description: |-
  28272. The namespace of the Secret resource being referred to.
  28273. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28274. maxLength: 63
  28275. minLength: 1
  28276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28277. type: string
  28278. type: object
  28279. serviceAccountRef:
  28280. description: |-
  28281. Optional service account field containing the name of a kubernetes ServiceAccount.
  28282. If the service account is specified, the service account secret token JWT will be used
  28283. for authenticating with Vault. If the service account selector is not supplied,
  28284. the secretRef will be used instead.
  28285. properties:
  28286. audiences:
  28287. description: |-
  28288. Audience specifies the `aud` claim for the service account token
  28289. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28290. then this audiences will be appended to the list
  28291. items:
  28292. type: string
  28293. type: array
  28294. name:
  28295. description: The name of the ServiceAccount resource being referred to.
  28296. maxLength: 253
  28297. minLength: 1
  28298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28299. type: string
  28300. namespace:
  28301. description: |-
  28302. Namespace of the resource being referred to.
  28303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28304. maxLength: 63
  28305. minLength: 1
  28306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28307. type: string
  28308. required:
  28309. - name
  28310. type: object
  28311. required:
  28312. - mountPath
  28313. - role
  28314. type: object
  28315. ldap:
  28316. description: |-
  28317. Ldap authenticates with Vault by passing username/password pair using
  28318. the LDAP authentication method
  28319. properties:
  28320. path:
  28321. default: ldap
  28322. description: |-
  28323. Path where the LDAP authentication backend is mounted
  28324. in Vault, e.g: "ldap"
  28325. type: string
  28326. secretRef:
  28327. description: |-
  28328. SecretRef to a key in a Secret resource containing password for the LDAP
  28329. user used to authenticate with Vault using the LDAP authentication
  28330. method
  28331. properties:
  28332. key:
  28333. description: |-
  28334. A key in the referenced Secret.
  28335. Some instances of this field may be defaulted, in others it may be required.
  28336. maxLength: 253
  28337. minLength: 1
  28338. pattern: ^[-._a-zA-Z0-9]+$
  28339. type: string
  28340. name:
  28341. description: The name of the Secret resource being referred to.
  28342. maxLength: 253
  28343. minLength: 1
  28344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28345. type: string
  28346. namespace:
  28347. description: |-
  28348. The namespace of the Secret resource being referred to.
  28349. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28350. maxLength: 63
  28351. minLength: 1
  28352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28353. type: string
  28354. type: object
  28355. username:
  28356. description: |-
  28357. Username is an LDAP username used to authenticate using the LDAP Vault
  28358. authentication method
  28359. type: string
  28360. required:
  28361. - path
  28362. - username
  28363. type: object
  28364. namespace:
  28365. description: |-
  28366. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  28367. Namespaces is a set of features within Vault Enterprise that allows
  28368. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  28369. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  28370. This will default to Vault.Namespace field if set, or empty otherwise
  28371. type: string
  28372. tokenSecretRef:
  28373. description: TokenSecretRef authenticates with Vault by presenting a token.
  28374. properties:
  28375. key:
  28376. description: |-
  28377. A key in the referenced Secret.
  28378. Some instances of this field may be defaulted, in others it may be required.
  28379. maxLength: 253
  28380. minLength: 1
  28381. pattern: ^[-._a-zA-Z0-9]+$
  28382. type: string
  28383. name:
  28384. description: The name of the Secret resource being referred to.
  28385. maxLength: 253
  28386. minLength: 1
  28387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28388. type: string
  28389. namespace:
  28390. description: |-
  28391. The namespace of the Secret resource being referred to.
  28392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28393. maxLength: 63
  28394. minLength: 1
  28395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28396. type: string
  28397. type: object
  28398. userPass:
  28399. description: UserPass authenticates with Vault by passing username/password pair
  28400. properties:
  28401. path:
  28402. default: userpass
  28403. description: |-
  28404. Path where the UserPassword authentication backend is mounted
  28405. in Vault, e.g: "userpass"
  28406. type: string
  28407. secretRef:
  28408. description: |-
  28409. SecretRef to a key in a Secret resource containing password for the
  28410. user used to authenticate with Vault using the UserPass authentication
  28411. method
  28412. properties:
  28413. key:
  28414. description: |-
  28415. A key in the referenced Secret.
  28416. Some instances of this field may be defaulted, in others it may be required.
  28417. maxLength: 253
  28418. minLength: 1
  28419. pattern: ^[-._a-zA-Z0-9]+$
  28420. type: string
  28421. name:
  28422. description: The name of the Secret resource being referred to.
  28423. maxLength: 253
  28424. minLength: 1
  28425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28426. type: string
  28427. namespace:
  28428. description: |-
  28429. The namespace of the Secret resource being referred to.
  28430. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28431. maxLength: 63
  28432. minLength: 1
  28433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28434. type: string
  28435. type: object
  28436. username:
  28437. description: |-
  28438. Username is a username used to authenticate using the UserPass Vault
  28439. authentication method
  28440. type: string
  28441. required:
  28442. - path
  28443. - username
  28444. type: object
  28445. type: object
  28446. caBundle:
  28447. description: |-
  28448. PEM encoded CA bundle used to validate Vault server certificate. Only used
  28449. if the Server URL is using HTTPS protocol. This parameter is ignored for
  28450. plain HTTP protocol connection. If not set the system root certificates
  28451. are used to validate the TLS connection.
  28452. format: byte
  28453. type: string
  28454. caProvider:
  28455. description: The provider for the CA bundle to use to validate Vault server certificate.
  28456. properties:
  28457. key:
  28458. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  28459. maxLength: 253
  28460. minLength: 1
  28461. pattern: ^[-._a-zA-Z0-9]+$
  28462. type: string
  28463. name:
  28464. description: The name of the object located at the provider type.
  28465. maxLength: 253
  28466. minLength: 1
  28467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28468. type: string
  28469. namespace:
  28470. description: |-
  28471. The namespace the Provider type is in.
  28472. Can only be defined when used in a ClusterSecretStore.
  28473. maxLength: 63
  28474. minLength: 1
  28475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28476. type: string
  28477. type:
  28478. description: The type of provider to use such as "Secret", or "ConfigMap".
  28479. enum:
  28480. - Secret
  28481. - ConfigMap
  28482. type: string
  28483. required:
  28484. - name
  28485. - type
  28486. type: object
  28487. checkAndSet:
  28488. description: |-
  28489. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  28490. Only applies to Vault KV v2 stores. When enabled, write operations must include
  28491. the current version of the secret to prevent unintentional overwrites.
  28492. properties:
  28493. required:
  28494. description: |-
  28495. Required when true, all write operations must include a check-and-set parameter.
  28496. This helps prevent unintentional overwrites of secrets.
  28497. type: boolean
  28498. type: object
  28499. forwardInconsistent:
  28500. description: |-
  28501. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  28502. leader instead of simply retrying within a loop. This can increase performance if
  28503. the option is enabled serverside.
  28504. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  28505. type: boolean
  28506. headers:
  28507. additionalProperties:
  28508. type: string
  28509. description: Headers to be added in Vault request
  28510. type: object
  28511. namespace:
  28512. description: |-
  28513. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  28514. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  28515. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  28516. type: string
  28517. path:
  28518. description: |-
  28519. Path is the mount path of the Vault KV backend endpoint, e.g:
  28520. "secret". The v2 KV secret engine version specific "/data" path suffix
  28521. for fetching secrets from Vault is optional and will be appended
  28522. if not present in specified path.
  28523. type: string
  28524. readYourWrites:
  28525. description: |-
  28526. ReadYourWrites ensures isolated read-after-write semantics by
  28527. providing discovered cluster replication states in each request.
  28528. More information about eventual consistency in Vault can be found here
  28529. https://www.vaultproject.io/docs/enterprise/consistency
  28530. type: boolean
  28531. server:
  28532. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  28533. type: string
  28534. tls:
  28535. description: |-
  28536. The configuration used for client side related TLS communication, when the Vault server
  28537. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  28538. This parameter is ignored for plain HTTP protocol connection.
  28539. It's worth noting this configuration is different from the "TLS certificates auth method",
  28540. which is available under the `auth.cert` section.
  28541. properties:
  28542. certSecretRef:
  28543. description: |-
  28544. CertSecretRef is a certificate added to the transport layer
  28545. when communicating with the Vault server.
  28546. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  28547. properties:
  28548. key:
  28549. description: |-
  28550. A key in the referenced Secret.
  28551. Some instances of this field may be defaulted, in others it may be required.
  28552. maxLength: 253
  28553. minLength: 1
  28554. pattern: ^[-._a-zA-Z0-9]+$
  28555. type: string
  28556. name:
  28557. description: The name of the Secret resource being referred to.
  28558. maxLength: 253
  28559. minLength: 1
  28560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28561. type: string
  28562. namespace:
  28563. description: |-
  28564. The namespace of the Secret resource being referred to.
  28565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28566. maxLength: 63
  28567. minLength: 1
  28568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28569. type: string
  28570. type: object
  28571. keySecretRef:
  28572. description: |-
  28573. KeySecretRef to a key in a Secret resource containing client private key
  28574. added to the transport layer when communicating with the Vault server.
  28575. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  28576. properties:
  28577. key:
  28578. description: |-
  28579. A key in the referenced Secret.
  28580. Some instances of this field may be defaulted, in others it may be required.
  28581. maxLength: 253
  28582. minLength: 1
  28583. pattern: ^[-._a-zA-Z0-9]+$
  28584. type: string
  28585. name:
  28586. description: The name of the Secret resource being referred to.
  28587. maxLength: 253
  28588. minLength: 1
  28589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28590. type: string
  28591. namespace:
  28592. description: |-
  28593. The namespace of the Secret resource being referred to.
  28594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28595. maxLength: 63
  28596. minLength: 1
  28597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28598. type: string
  28599. type: object
  28600. type: object
  28601. version:
  28602. default: v2
  28603. description: |-
  28604. Version is the Vault KV secret engine version. This can be either "v1" or
  28605. "v2". Version defaults to "v2".
  28606. enum:
  28607. - v1
  28608. - v2
  28609. type: string
  28610. required:
  28611. - server
  28612. type: object
  28613. resultType:
  28614. default: Data
  28615. description: |-
  28616. Result type defines which data is returned from the generator.
  28617. By default, it is the "data" section of the Vault API response.
  28618. When using e.g. /auth/token/create the "data" section is empty but
  28619. the "auth" section contains the generated token.
  28620. Please refer to the vault docs regarding the result data structure.
  28621. Additionally, accessing the raw response is possibly by using "Raw" result type.
  28622. enum:
  28623. - Data
  28624. - Auth
  28625. - Raw
  28626. type: string
  28627. retrySettings:
  28628. description: Used to configure http retries if failed
  28629. properties:
  28630. maxRetries:
  28631. format: int32
  28632. type: integer
  28633. retryInterval:
  28634. type: string
  28635. type: object
  28636. required:
  28637. - path
  28638. - provider
  28639. type: object
  28640. webhookSpec:
  28641. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  28642. properties:
  28643. auth:
  28644. description: Auth specifies a authorization protocol. Only one protocol may be set.
  28645. maxProperties: 1
  28646. minProperties: 1
  28647. properties:
  28648. ntlm:
  28649. description: NTLMProtocol configures the store to use NTLM for auth
  28650. properties:
  28651. passwordSecret:
  28652. description: |-
  28653. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28654. In some instances, `key` is a required field.
  28655. properties:
  28656. key:
  28657. description: |-
  28658. A key in the referenced Secret.
  28659. Some instances of this field may be defaulted, in others it may be required.
  28660. maxLength: 253
  28661. minLength: 1
  28662. pattern: ^[-._a-zA-Z0-9]+$
  28663. type: string
  28664. name:
  28665. description: The name of the Secret resource being referred to.
  28666. maxLength: 253
  28667. minLength: 1
  28668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28669. type: string
  28670. namespace:
  28671. description: |-
  28672. The namespace of the Secret resource being referred to.
  28673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28674. maxLength: 63
  28675. minLength: 1
  28676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28677. type: string
  28678. type: object
  28679. usernameSecret:
  28680. description: |-
  28681. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28682. In some instances, `key` is a required field.
  28683. properties:
  28684. key:
  28685. description: |-
  28686. A key in the referenced Secret.
  28687. Some instances of this field may be defaulted, in others it may be required.
  28688. maxLength: 253
  28689. minLength: 1
  28690. pattern: ^[-._a-zA-Z0-9]+$
  28691. type: string
  28692. name:
  28693. description: The name of the Secret resource being referred to.
  28694. maxLength: 253
  28695. minLength: 1
  28696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28697. type: string
  28698. namespace:
  28699. description: |-
  28700. The namespace of the Secret resource being referred to.
  28701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28702. maxLength: 63
  28703. minLength: 1
  28704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28705. type: string
  28706. type: object
  28707. required:
  28708. - passwordSecret
  28709. - usernameSecret
  28710. type: object
  28711. type: object
  28712. body:
  28713. description: Body
  28714. type: string
  28715. caBundle:
  28716. description: |-
  28717. PEM encoded CA bundle used to validate webhook server certificate. Only used
  28718. if the Server URL is using HTTPS protocol. This parameter is ignored for
  28719. plain HTTP protocol connection. If not set the system root certificates
  28720. are used to validate the TLS connection.
  28721. format: byte
  28722. type: string
  28723. caProvider:
  28724. description: The provider for the CA bundle to use to validate webhook server certificate.
  28725. properties:
  28726. key:
  28727. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  28728. maxLength: 253
  28729. minLength: 1
  28730. pattern: ^[-._a-zA-Z0-9]+$
  28731. type: string
  28732. name:
  28733. description: The name of the object located at the provider type.
  28734. maxLength: 253
  28735. minLength: 1
  28736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28737. type: string
  28738. namespace:
  28739. description: The namespace the Provider type is in.
  28740. maxLength: 63
  28741. minLength: 1
  28742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28743. type: string
  28744. type:
  28745. description: The type of provider to use such as "Secret", or "ConfigMap".
  28746. enum:
  28747. - Secret
  28748. - ConfigMap
  28749. type: string
  28750. required:
  28751. - name
  28752. - type
  28753. type: object
  28754. headers:
  28755. additionalProperties:
  28756. type: string
  28757. description: Headers
  28758. type: object
  28759. method:
  28760. description: Webhook Method
  28761. type: string
  28762. result:
  28763. description: Result formatting
  28764. properties:
  28765. jsonPath:
  28766. description: Json path of return value
  28767. type: string
  28768. type: object
  28769. secrets:
  28770. description: |-
  28771. Secrets to fill in templates
  28772. These secrets will be passed to the templating function as key value pairs under the given name
  28773. items:
  28774. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  28775. properties:
  28776. name:
  28777. description: Name of this secret in templates
  28778. type: string
  28779. secretRef:
  28780. description: Secret ref to fill in credentials
  28781. properties:
  28782. key:
  28783. description: The key where the token is found.
  28784. maxLength: 253
  28785. minLength: 1
  28786. pattern: ^[-._a-zA-Z0-9]+$
  28787. type: string
  28788. name:
  28789. description: The name of the Secret resource being referred to.
  28790. maxLength: 253
  28791. minLength: 1
  28792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28793. type: string
  28794. type: object
  28795. required:
  28796. - name
  28797. - secretRef
  28798. type: object
  28799. type: array
  28800. timeout:
  28801. description: Timeout
  28802. type: string
  28803. url:
  28804. description: Webhook url to call
  28805. type: string
  28806. required:
  28807. - result
  28808. - url
  28809. type: object
  28810. type: object
  28811. kind:
  28812. description: Kind the kind of this generator.
  28813. enum:
  28814. - ACRAccessToken
  28815. - BeyondtrustWorkloadCredentialsDynamicSecret
  28816. - CloudsmithAccessToken
  28817. - ECRAuthorizationToken
  28818. - Fake
  28819. - GCRAccessToken
  28820. - GithubAccessToken
  28821. - GitlabDeployToken
  28822. - QuayAccessToken
  28823. - Password
  28824. - SSHKey
  28825. - STSSessionToken
  28826. - UUID
  28827. - VaultDynamicSecret
  28828. - Webhook
  28829. - Grafana
  28830. - MFA
  28831. type: string
  28832. required:
  28833. - generator
  28834. - kind
  28835. type: object
  28836. type: object
  28837. served: true
  28838. storage: true
  28839. subresources:
  28840. status: {}
  28841. ---
  28842. apiVersion: apiextensions.k8s.io/v1
  28843. kind: CustomResourceDefinition
  28844. metadata:
  28845. annotations:
  28846. controller-gen.kubebuilder.io/version: v0.19.0
  28847. labels:
  28848. external-secrets.io/component: controller
  28849. name: ecrauthorizationtokens.generators.external-secrets.io
  28850. spec:
  28851. group: generators.external-secrets.io
  28852. names:
  28853. categories:
  28854. - external-secrets
  28855. - external-secrets-generators
  28856. kind: ECRAuthorizationToken
  28857. listKind: ECRAuthorizationTokenList
  28858. plural: ecrauthorizationtokens
  28859. singular: ecrauthorizationtoken
  28860. scope: Namespaced
  28861. versions:
  28862. - name: v1alpha1
  28863. schema:
  28864. openAPIV3Schema:
  28865. description: |-
  28866. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  28867. The authorization token is valid for 12 hours.
  28868. The authorizationToken returned is a base64 encoded string that can be decoded
  28869. and used in a docker login command to authenticate to a registry.
  28870. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  28871. properties:
  28872. apiVersion:
  28873. description: |-
  28874. APIVersion defines the versioned schema of this representation of an object.
  28875. Servers should convert recognized schemas to the latest internal value, and
  28876. may reject unrecognized values.
  28877. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  28878. type: string
  28879. kind:
  28880. description: |-
  28881. Kind is a string value representing the REST resource this object represents.
  28882. Servers may infer this from the endpoint the client submits requests to.
  28883. Cannot be updated.
  28884. In CamelCase.
  28885. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  28886. type: string
  28887. metadata:
  28888. type: object
  28889. spec:
  28890. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  28891. properties:
  28892. auth:
  28893. description: Auth defines how to authenticate with AWS
  28894. properties:
  28895. jwt:
  28896. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28897. properties:
  28898. serviceAccountRef:
  28899. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28900. properties:
  28901. audiences:
  28902. description: |-
  28903. Audience specifies the `aud` claim for the service account token
  28904. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28905. then this audiences will be appended to the list
  28906. items:
  28907. type: string
  28908. type: array
  28909. name:
  28910. description: The name of the ServiceAccount resource being referred to.
  28911. maxLength: 253
  28912. minLength: 1
  28913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28914. type: string
  28915. namespace:
  28916. description: |-
  28917. Namespace of the resource being referred to.
  28918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28919. maxLength: 63
  28920. minLength: 1
  28921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28922. type: string
  28923. required:
  28924. - name
  28925. type: object
  28926. type: object
  28927. secretRef:
  28928. description: |-
  28929. AWSAuthSecretRef holds secret references for AWS credentials
  28930. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28931. properties:
  28932. accessKeyIDSecretRef:
  28933. description: The AccessKeyID is used for authentication
  28934. properties:
  28935. key:
  28936. description: |-
  28937. A key in the referenced Secret.
  28938. Some instances of this field may be defaulted, in others it may be required.
  28939. maxLength: 253
  28940. minLength: 1
  28941. pattern: ^[-._a-zA-Z0-9]+$
  28942. type: string
  28943. name:
  28944. description: The name of the Secret resource being referred to.
  28945. maxLength: 253
  28946. minLength: 1
  28947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28948. type: string
  28949. namespace:
  28950. description: |-
  28951. The namespace of the Secret resource being referred to.
  28952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28953. maxLength: 63
  28954. minLength: 1
  28955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28956. type: string
  28957. type: object
  28958. secretAccessKeySecretRef:
  28959. description: The SecretAccessKey is used for authentication
  28960. properties:
  28961. key:
  28962. description: |-
  28963. A key in the referenced Secret.
  28964. Some instances of this field may be defaulted, in others it may be required.
  28965. maxLength: 253
  28966. minLength: 1
  28967. pattern: ^[-._a-zA-Z0-9]+$
  28968. type: string
  28969. name:
  28970. description: The name of the Secret resource being referred to.
  28971. maxLength: 253
  28972. minLength: 1
  28973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28974. type: string
  28975. namespace:
  28976. description: |-
  28977. The namespace of the Secret resource being referred to.
  28978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28979. maxLength: 63
  28980. minLength: 1
  28981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28982. type: string
  28983. type: object
  28984. sessionTokenSecretRef:
  28985. description: |-
  28986. The SessionToken used for authentication
  28987. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28988. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28989. properties:
  28990. key:
  28991. description: |-
  28992. A key in the referenced Secret.
  28993. Some instances of this field may be defaulted, in others it may be required.
  28994. maxLength: 253
  28995. minLength: 1
  28996. pattern: ^[-._a-zA-Z0-9]+$
  28997. type: string
  28998. name:
  28999. description: The name of the Secret resource being referred to.
  29000. maxLength: 253
  29001. minLength: 1
  29002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29003. type: string
  29004. namespace:
  29005. description: |-
  29006. The namespace of the Secret resource being referred to.
  29007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29008. maxLength: 63
  29009. minLength: 1
  29010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29011. type: string
  29012. type: object
  29013. type: object
  29014. type: object
  29015. region:
  29016. description: Region specifies the region to operate in.
  29017. type: string
  29018. role:
  29019. description: |-
  29020. You can assume a role before making calls to the
  29021. desired AWS service.
  29022. type: string
  29023. scope:
  29024. description: |-
  29025. Scope specifies the ECR service scope.
  29026. Valid options are private and public.
  29027. type: string
  29028. required:
  29029. - region
  29030. type: object
  29031. type: object
  29032. served: true
  29033. storage: true
  29034. subresources:
  29035. status: {}
  29036. ---
  29037. apiVersion: apiextensions.k8s.io/v1
  29038. kind: CustomResourceDefinition
  29039. metadata:
  29040. annotations:
  29041. controller-gen.kubebuilder.io/version: v0.19.0
  29042. labels:
  29043. external-secrets.io/component: controller
  29044. name: fakes.generators.external-secrets.io
  29045. spec:
  29046. group: generators.external-secrets.io
  29047. names:
  29048. categories:
  29049. - external-secrets
  29050. - external-secrets-generators
  29051. kind: Fake
  29052. listKind: FakeList
  29053. plural: fakes
  29054. singular: fake
  29055. scope: Namespaced
  29056. versions:
  29057. - name: v1alpha1
  29058. schema:
  29059. openAPIV3Schema:
  29060. description: |-
  29061. Fake generator is used for testing. It lets you define
  29062. a static set of credentials that is always returned.
  29063. properties:
  29064. apiVersion:
  29065. description: |-
  29066. APIVersion defines the versioned schema of this representation of an object.
  29067. Servers should convert recognized schemas to the latest internal value, and
  29068. may reject unrecognized values.
  29069. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29070. type: string
  29071. kind:
  29072. description: |-
  29073. Kind is a string value representing the REST resource this object represents.
  29074. Servers may infer this from the endpoint the client submits requests to.
  29075. Cannot be updated.
  29076. In CamelCase.
  29077. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29078. type: string
  29079. metadata:
  29080. type: object
  29081. spec:
  29082. description: FakeSpec contains the static data.
  29083. properties:
  29084. controller:
  29085. description: |-
  29086. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29087. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29088. type: string
  29089. data:
  29090. additionalProperties:
  29091. type: string
  29092. description: |-
  29093. Data defines the static data returned
  29094. by this generator.
  29095. type: object
  29096. type: object
  29097. type: object
  29098. served: true
  29099. storage: true
  29100. subresources:
  29101. status: {}
  29102. ---
  29103. apiVersion: apiextensions.k8s.io/v1
  29104. kind: CustomResourceDefinition
  29105. metadata:
  29106. annotations:
  29107. controller-gen.kubebuilder.io/version: v0.19.0
  29108. labels:
  29109. external-secrets.io/component: controller
  29110. name: gcraccesstokens.generators.external-secrets.io
  29111. spec:
  29112. group: generators.external-secrets.io
  29113. names:
  29114. categories:
  29115. - external-secrets
  29116. - external-secrets-generators
  29117. kind: GCRAccessToken
  29118. listKind: GCRAccessTokenList
  29119. plural: gcraccesstokens
  29120. singular: gcraccesstoken
  29121. scope: Namespaced
  29122. versions:
  29123. - name: v1alpha1
  29124. schema:
  29125. openAPIV3Schema:
  29126. description: |-
  29127. GCRAccessToken generates an GCP access token
  29128. that can be used to authenticate with GCR.
  29129. properties:
  29130. apiVersion:
  29131. description: |-
  29132. APIVersion defines the versioned schema of this representation of an object.
  29133. Servers should convert recognized schemas to the latest internal value, and
  29134. may reject unrecognized values.
  29135. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29136. type: string
  29137. kind:
  29138. description: |-
  29139. Kind is a string value representing the REST resource this object represents.
  29140. Servers may infer this from the endpoint the client submits requests to.
  29141. Cannot be updated.
  29142. In CamelCase.
  29143. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29144. type: string
  29145. metadata:
  29146. type: object
  29147. spec:
  29148. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  29149. properties:
  29150. auth:
  29151. description: Auth defines the means for authenticating with GCP
  29152. properties:
  29153. secretRef:
  29154. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  29155. properties:
  29156. secretAccessKeySecretRef:
  29157. description: The SecretAccessKey is used for authentication
  29158. properties:
  29159. key:
  29160. description: |-
  29161. A key in the referenced Secret.
  29162. Some instances of this field may be defaulted, in others it may be required.
  29163. maxLength: 253
  29164. minLength: 1
  29165. pattern: ^[-._a-zA-Z0-9]+$
  29166. type: string
  29167. name:
  29168. description: The name of the Secret resource being referred to.
  29169. maxLength: 253
  29170. minLength: 1
  29171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29172. type: string
  29173. namespace:
  29174. description: |-
  29175. The namespace of the Secret resource being referred to.
  29176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29177. maxLength: 63
  29178. minLength: 1
  29179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29180. type: string
  29181. type: object
  29182. type: object
  29183. workloadIdentity:
  29184. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  29185. properties:
  29186. clusterLocation:
  29187. type: string
  29188. clusterName:
  29189. type: string
  29190. clusterProjectID:
  29191. type: string
  29192. serviceAccountRef:
  29193. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29194. properties:
  29195. audiences:
  29196. description: |-
  29197. Audience specifies the `aud` claim for the service account token
  29198. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29199. then this audiences will be appended to the list
  29200. items:
  29201. type: string
  29202. type: array
  29203. name:
  29204. description: The name of the ServiceAccount resource being referred to.
  29205. maxLength: 253
  29206. minLength: 1
  29207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29208. type: string
  29209. namespace:
  29210. description: |-
  29211. Namespace of the resource being referred to.
  29212. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29213. maxLength: 63
  29214. minLength: 1
  29215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29216. type: string
  29217. required:
  29218. - name
  29219. type: object
  29220. required:
  29221. - clusterLocation
  29222. - clusterName
  29223. - serviceAccountRef
  29224. type: object
  29225. workloadIdentityFederation:
  29226. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  29227. properties:
  29228. audience:
  29229. description: |-
  29230. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  29231. If specified, Audience found in the external account credential config will be overridden with the configured value.
  29232. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  29233. type: string
  29234. awsSecurityCredentials:
  29235. description: |-
  29236. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  29237. when using the AWS metadata server is not an option.
  29238. properties:
  29239. awsCredentialsSecretRef:
  29240. description: |-
  29241. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  29242. Secret should be created with below names for keys
  29243. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  29244. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  29245. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  29246. properties:
  29247. name:
  29248. description: name of the secret.
  29249. maxLength: 253
  29250. minLength: 1
  29251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29252. type: string
  29253. namespace:
  29254. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  29255. maxLength: 63
  29256. minLength: 1
  29257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29258. type: string
  29259. required:
  29260. - name
  29261. type: object
  29262. region:
  29263. description: region is for configuring the AWS region to be used.
  29264. example: ap-south-1
  29265. maxLength: 50
  29266. minLength: 1
  29267. pattern: ^[a-z0-9-]+$
  29268. type: string
  29269. required:
  29270. - awsCredentialsSecretRef
  29271. - region
  29272. type: object
  29273. credConfig:
  29274. description: |-
  29275. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  29276. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  29277. serviceAccountRef must be used by providing operators service account details.
  29278. properties:
  29279. key:
  29280. description: key name holding the external account credential config.
  29281. maxLength: 253
  29282. minLength: 1
  29283. pattern: ^[-._a-zA-Z0-9]+$
  29284. type: string
  29285. name:
  29286. description: name of the configmap.
  29287. maxLength: 253
  29288. minLength: 1
  29289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29290. type: string
  29291. namespace:
  29292. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  29293. maxLength: 63
  29294. minLength: 1
  29295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29296. type: string
  29297. required:
  29298. - key
  29299. - name
  29300. type: object
  29301. externalTokenEndpoint:
  29302. description: |-
  29303. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  29304. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  29305. URL is having the expected value.
  29306. type: string
  29307. gcpServiceAccountEmail:
  29308. description: |-
  29309. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  29310. after Workload Identity Federation. Use this to grant access through the service account's
  29311. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  29312. service_account_impersonation_url in the external account JSON from credConfig;
  29313. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  29314. on that ServiceAccount.
  29315. example: my-gsa@my-project.iam.gserviceaccount.com
  29316. minLength: 1
  29317. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  29318. type: string
  29319. serviceAccountRef:
  29320. description: |-
  29321. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  29322. when Kubernetes is configured as provider in workload identity pool.
  29323. properties:
  29324. audiences:
  29325. description: |-
  29326. Audience specifies the `aud` claim for the service account token
  29327. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29328. then this audiences will be appended to the list
  29329. items:
  29330. type: string
  29331. type: array
  29332. name:
  29333. description: The name of the ServiceAccount resource being referred to.
  29334. maxLength: 253
  29335. minLength: 1
  29336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29337. type: string
  29338. namespace:
  29339. description: |-
  29340. Namespace of the resource being referred to.
  29341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29342. maxLength: 63
  29343. minLength: 1
  29344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29345. type: string
  29346. required:
  29347. - name
  29348. type: object
  29349. type: object
  29350. type: object
  29351. projectID:
  29352. description: ProjectID defines which project to use to authenticate with
  29353. type: string
  29354. required:
  29355. - auth
  29356. - projectID
  29357. type: object
  29358. type: object
  29359. served: true
  29360. storage: true
  29361. subresources:
  29362. status: {}
  29363. ---
  29364. apiVersion: apiextensions.k8s.io/v1
  29365. kind: CustomResourceDefinition
  29366. metadata:
  29367. annotations:
  29368. controller-gen.kubebuilder.io/version: v0.19.0
  29369. labels:
  29370. external-secrets.io/component: controller
  29371. name: generatorstates.generators.external-secrets.io
  29372. spec:
  29373. group: generators.external-secrets.io
  29374. names:
  29375. categories:
  29376. - external-secrets
  29377. - external-secrets-generators
  29378. kind: GeneratorState
  29379. listKind: GeneratorStateList
  29380. plural: generatorstates
  29381. shortNames:
  29382. - gs
  29383. singular: generatorstate
  29384. scope: Namespaced
  29385. versions:
  29386. - additionalPrinterColumns:
  29387. - jsonPath: .spec.garbageCollectionDeadline
  29388. name: GC Deadline
  29389. type: string
  29390. - jsonPath: .metadata.creationTimestamp
  29391. name: Age
  29392. type: date
  29393. name: v1alpha1
  29394. schema:
  29395. openAPIV3Schema:
  29396. description: GeneratorState represents the state created and managed by a generator resource.
  29397. properties:
  29398. apiVersion:
  29399. description: |-
  29400. APIVersion defines the versioned schema of this representation of an object.
  29401. Servers should convert recognized schemas to the latest internal value, and
  29402. may reject unrecognized values.
  29403. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29404. type: string
  29405. kind:
  29406. description: |-
  29407. Kind is a string value representing the REST resource this object represents.
  29408. Servers may infer this from the endpoint the client submits requests to.
  29409. Cannot be updated.
  29410. In CamelCase.
  29411. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29412. type: string
  29413. metadata:
  29414. type: object
  29415. spec:
  29416. description: GeneratorStateSpec defines the desired state of a generator state resource.
  29417. properties:
  29418. garbageCollectionDeadline:
  29419. description: |-
  29420. GarbageCollectionDeadline is the time after which the generator state
  29421. will be deleted.
  29422. It is set by the controller which creates the generator state and
  29423. can be set configured by the user.
  29424. If the garbage collection deadline is not set the generator state will not be deleted.
  29425. format: date-time
  29426. type: string
  29427. resource:
  29428. description: |-
  29429. Resource is the generator manifest that produced the state.
  29430. It is a snapshot of the generator manifest at the time the state was produced.
  29431. This manifest will be used to delete the resource. Any configuration that is referenced
  29432. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  29433. be blocked by a finalizer.
  29434. x-kubernetes-preserve-unknown-fields: true
  29435. state:
  29436. description: State is the state that was produced by the generator implementation.
  29437. x-kubernetes-preserve-unknown-fields: true
  29438. required:
  29439. - resource
  29440. - state
  29441. type: object
  29442. status:
  29443. description: GeneratorStateStatus defines the observed state of a generator state resource.
  29444. properties:
  29445. conditions:
  29446. items:
  29447. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  29448. properties:
  29449. lastTransitionTime:
  29450. format: date-time
  29451. type: string
  29452. message:
  29453. type: string
  29454. reason:
  29455. type: string
  29456. status:
  29457. type: string
  29458. type:
  29459. description: GeneratorStateConditionType represents the type of condition for a generator state.
  29460. type: string
  29461. required:
  29462. - status
  29463. - type
  29464. type: object
  29465. type: array
  29466. type: object
  29467. type: object
  29468. served: true
  29469. storage: true
  29470. subresources: {}
  29471. ---
  29472. apiVersion: apiextensions.k8s.io/v1
  29473. kind: CustomResourceDefinition
  29474. metadata:
  29475. annotations:
  29476. controller-gen.kubebuilder.io/version: v0.19.0
  29477. labels:
  29478. external-secrets.io/component: controller
  29479. name: githubaccesstokens.generators.external-secrets.io
  29480. spec:
  29481. group: generators.external-secrets.io
  29482. names:
  29483. categories:
  29484. - external-secrets
  29485. - external-secrets-generators
  29486. kind: GithubAccessToken
  29487. listKind: GithubAccessTokenList
  29488. plural: githubaccesstokens
  29489. singular: githubaccesstoken
  29490. scope: Namespaced
  29491. versions:
  29492. - name: v1alpha1
  29493. schema:
  29494. openAPIV3Schema:
  29495. description: GithubAccessToken generates ghs_ accessToken
  29496. properties:
  29497. apiVersion:
  29498. description: |-
  29499. APIVersion defines the versioned schema of this representation of an object.
  29500. Servers should convert recognized schemas to the latest internal value, and
  29501. may reject unrecognized values.
  29502. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29503. type: string
  29504. kind:
  29505. description: |-
  29506. Kind is a string value representing the REST resource this object represents.
  29507. Servers may infer this from the endpoint the client submits requests to.
  29508. Cannot be updated.
  29509. In CamelCase.
  29510. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29511. type: string
  29512. metadata:
  29513. type: object
  29514. spec:
  29515. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  29516. properties:
  29517. appID:
  29518. type: string
  29519. auth:
  29520. description: Auth configures how ESO authenticates with a Github instance.
  29521. properties:
  29522. privateKey:
  29523. description: GithubSecretRef references a secret containing GitHub credentials.
  29524. properties:
  29525. secretRef:
  29526. description: |-
  29527. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29528. In some instances, `key` is a required field.
  29529. properties:
  29530. key:
  29531. description: |-
  29532. A key in the referenced Secret.
  29533. Some instances of this field may be defaulted, in others it may be required.
  29534. maxLength: 253
  29535. minLength: 1
  29536. pattern: ^[-._a-zA-Z0-9]+$
  29537. type: string
  29538. name:
  29539. description: The name of the Secret resource being referred to.
  29540. maxLength: 253
  29541. minLength: 1
  29542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29543. type: string
  29544. namespace:
  29545. description: |-
  29546. The namespace of the Secret resource being referred to.
  29547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29548. maxLength: 63
  29549. minLength: 1
  29550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29551. type: string
  29552. type: object
  29553. required:
  29554. - secretRef
  29555. type: object
  29556. required:
  29557. - privateKey
  29558. type: object
  29559. installID:
  29560. type: string
  29561. permissions:
  29562. additionalProperties:
  29563. type: string
  29564. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  29565. type: object
  29566. repositories:
  29567. description: |-
  29568. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  29569. is installed to.
  29570. items:
  29571. type: string
  29572. type: array
  29573. url:
  29574. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  29575. type: string
  29576. required:
  29577. - appID
  29578. - auth
  29579. - installID
  29580. type: object
  29581. type: object
  29582. served: true
  29583. storage: true
  29584. subresources:
  29585. status: {}
  29586. ---
  29587. apiVersion: apiextensions.k8s.io/v1
  29588. kind: CustomResourceDefinition
  29589. metadata:
  29590. annotations:
  29591. controller-gen.kubebuilder.io/version: v0.19.0
  29592. labels:
  29593. external-secrets.io/component: controller
  29594. name: gitlabdeploytokens.generators.external-secrets.io
  29595. spec:
  29596. group: generators.external-secrets.io
  29597. names:
  29598. categories:
  29599. - external-secrets
  29600. - external-secrets-generators
  29601. kind: GitlabDeployToken
  29602. listKind: GitlabDeployTokenList
  29603. plural: gitlabdeploytokens
  29604. singular: gitlabdeploytoken
  29605. scope: Namespaced
  29606. versions:
  29607. - name: v1alpha1
  29608. schema:
  29609. openAPIV3Schema:
  29610. description: GitlabDeployToken generates a GitLab deploy token.
  29611. properties:
  29612. apiVersion:
  29613. description: |-
  29614. APIVersion defines the versioned schema of this representation of an object.
  29615. Servers should convert recognized schemas to the latest internal value, and
  29616. may reject unrecognized values.
  29617. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29618. type: string
  29619. kind:
  29620. description: |-
  29621. Kind is a string value representing the REST resource this object represents.
  29622. Servers may infer this from the endpoint the client submits requests to.
  29623. Cannot be updated.
  29624. In CamelCase.
  29625. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29626. type: string
  29627. metadata:
  29628. type: object
  29629. spec:
  29630. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  29631. properties:
  29632. auth:
  29633. description: Auth configures how ESO authenticates with the GitLab API.
  29634. properties:
  29635. token:
  29636. description: |-
  29637. Token references a secret containing a GitLab access token (personal, group, or
  29638. project) with the api scope and at least the Maintainer role on the target.
  29639. properties:
  29640. secretRef:
  29641. description: |-
  29642. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29643. In some instances, `key` is a required field.
  29644. properties:
  29645. key:
  29646. description: |-
  29647. A key in the referenced Secret.
  29648. Some instances of this field may be defaulted, in others it may be required.
  29649. maxLength: 253
  29650. minLength: 1
  29651. pattern: ^[-._a-zA-Z0-9]+$
  29652. type: string
  29653. name:
  29654. description: The name of the Secret resource being referred to.
  29655. maxLength: 253
  29656. minLength: 1
  29657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29658. type: string
  29659. namespace:
  29660. description: |-
  29661. The namespace of the Secret resource being referred to.
  29662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29663. maxLength: 63
  29664. minLength: 1
  29665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29666. type: string
  29667. type: object
  29668. required:
  29669. - secretRef
  29670. type: object
  29671. required:
  29672. - token
  29673. type: object
  29674. expiresAt:
  29675. description: |-
  29676. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  29677. not expire on the GitLab side and is revoked only when the generator state is
  29678. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  29679. format: date-time
  29680. type: string
  29681. groupID:
  29682. description: |-
  29683. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  29684. create the deploy token in. The generator URL-escapes paths before calling the
  29685. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  29686. minLength: 1
  29687. type: string
  29688. name:
  29689. description: Name of the deploy token.
  29690. minLength: 1
  29691. type: string
  29692. projectID:
  29693. description: |-
  29694. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  29695. project to create the deploy token in. The generator URL-escapes paths before
  29696. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  29697. minLength: 1
  29698. type: string
  29699. scopes:
  29700. description: Scopes granted to the deploy token. At least one scope is required.
  29701. items:
  29702. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  29703. enum:
  29704. - read_repository
  29705. - read_registry
  29706. - write_registry
  29707. - read_package_registry
  29708. - write_package_registry
  29709. - read_virtual_registry
  29710. - write_virtual_registry
  29711. type: string
  29712. minItems: 1
  29713. type: array
  29714. url:
  29715. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  29716. type: string
  29717. username:
  29718. description: |-
  29719. Username is an optional username for the deploy token. GitLab defaults it to
  29720. gitlab+deploy-token-{n} when omitted.
  29721. type: string
  29722. required:
  29723. - auth
  29724. - name
  29725. - scopes
  29726. type: object
  29727. x-kubernetes-validations:
  29728. - message: exactly one of projectID or groupID must be set
  29729. rule: has(self.projectID) != has(self.groupID)
  29730. type: object
  29731. served: true
  29732. storage: true
  29733. subresources:
  29734. status: {}
  29735. ---
  29736. apiVersion: apiextensions.k8s.io/v1
  29737. kind: CustomResourceDefinition
  29738. metadata:
  29739. annotations:
  29740. controller-gen.kubebuilder.io/version: v0.19.0
  29741. labels:
  29742. external-secrets.io/component: controller
  29743. name: grafanas.generators.external-secrets.io
  29744. spec:
  29745. group: generators.external-secrets.io
  29746. names:
  29747. categories:
  29748. - external-secrets
  29749. - external-secrets-generators
  29750. kind: Grafana
  29751. listKind: GrafanaList
  29752. plural: grafanas
  29753. singular: grafana
  29754. scope: Namespaced
  29755. versions:
  29756. - name: v1alpha1
  29757. schema:
  29758. openAPIV3Schema:
  29759. description: Grafana represents a generator for Grafana service account tokens.
  29760. properties:
  29761. apiVersion:
  29762. description: |-
  29763. APIVersion defines the versioned schema of this representation of an object.
  29764. Servers should convert recognized schemas to the latest internal value, and
  29765. may reject unrecognized values.
  29766. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29767. type: string
  29768. kind:
  29769. description: |-
  29770. Kind is a string value representing the REST resource this object represents.
  29771. Servers may infer this from the endpoint the client submits requests to.
  29772. Cannot be updated.
  29773. In CamelCase.
  29774. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29775. type: string
  29776. metadata:
  29777. type: object
  29778. spec:
  29779. description: GrafanaSpec controls the behavior of the grafana generator.
  29780. properties:
  29781. auth:
  29782. description: |-
  29783. Auth is the authentication configuration to authenticate
  29784. against the Grafana instance.
  29785. properties:
  29786. basic:
  29787. description: |-
  29788. Basic auth credentials used to authenticate against the Grafana instance.
  29789. Note: you need a token which has elevated permissions to create service accounts.
  29790. See here for the documentation on basic roles offered by Grafana:
  29791. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  29792. properties:
  29793. password:
  29794. description: A basic auth password used to authenticate against the Grafana instance.
  29795. properties:
  29796. key:
  29797. description: The key where the token is found.
  29798. maxLength: 253
  29799. minLength: 1
  29800. pattern: ^[-._a-zA-Z0-9]+$
  29801. type: string
  29802. name:
  29803. description: The name of the Secret resource being referred to.
  29804. maxLength: 253
  29805. minLength: 1
  29806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29807. type: string
  29808. type: object
  29809. username:
  29810. description: A basic auth username used to authenticate against the Grafana instance.
  29811. type: string
  29812. required:
  29813. - password
  29814. - username
  29815. type: object
  29816. token:
  29817. description: |-
  29818. A service account token used to authenticate against the Grafana instance.
  29819. Note: you need a token which has elevated permissions to create service accounts.
  29820. See here for the documentation on basic roles offered by Grafana:
  29821. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  29822. properties:
  29823. key:
  29824. description: The key where the token is found.
  29825. maxLength: 253
  29826. minLength: 1
  29827. pattern: ^[-._a-zA-Z0-9]+$
  29828. type: string
  29829. name:
  29830. description: The name of the Secret resource being referred to.
  29831. maxLength: 253
  29832. minLength: 1
  29833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29834. type: string
  29835. type: object
  29836. type: object
  29837. serviceAccount:
  29838. description: |-
  29839. ServiceAccount is the configuration for the service account that
  29840. is supposed to be generated by the generator.
  29841. properties:
  29842. name:
  29843. description: Name is the name of the service account that will be created by ESO.
  29844. type: string
  29845. role:
  29846. description: |-
  29847. Role is the role of the service account.
  29848. See here for the documentation on basic roles offered by Grafana:
  29849. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  29850. type: string
  29851. secondsToLive:
  29852. description: |-
  29853. SecondsToLive is the number of seconds before the generated service account token will expire.
  29854. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  29855. format: int64
  29856. minimum: 1
  29857. type: integer
  29858. required:
  29859. - name
  29860. - role
  29861. type: object
  29862. url:
  29863. description: URL is the URL of the Grafana instance.
  29864. type: string
  29865. required:
  29866. - auth
  29867. - serviceAccount
  29868. - url
  29869. type: object
  29870. type: object
  29871. served: true
  29872. storage: true
  29873. subresources:
  29874. status: {}
  29875. ---
  29876. apiVersion: apiextensions.k8s.io/v1
  29877. kind: CustomResourceDefinition
  29878. metadata:
  29879. annotations:
  29880. controller-gen.kubebuilder.io/version: v0.19.0
  29881. labels:
  29882. external-secrets.io/component: controller
  29883. name: mfas.generators.external-secrets.io
  29884. spec:
  29885. group: generators.external-secrets.io
  29886. names:
  29887. categories:
  29888. - external-secrets
  29889. - external-secrets-generators
  29890. kind: MFA
  29891. listKind: MFAList
  29892. plural: mfas
  29893. singular: mfa
  29894. scope: Namespaced
  29895. versions:
  29896. - name: v1alpha1
  29897. schema:
  29898. openAPIV3Schema:
  29899. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  29900. properties:
  29901. apiVersion:
  29902. description: |-
  29903. APIVersion defines the versioned schema of this representation of an object.
  29904. Servers should convert recognized schemas to the latest internal value, and
  29905. may reject unrecognized values.
  29906. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29907. type: string
  29908. kind:
  29909. description: |-
  29910. Kind is a string value representing the REST resource this object represents.
  29911. Servers may infer this from the endpoint the client submits requests to.
  29912. Cannot be updated.
  29913. In CamelCase.
  29914. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29915. type: string
  29916. metadata:
  29917. type: object
  29918. spec:
  29919. description: MFASpec controls the behavior of the mfa generator.
  29920. properties:
  29921. algorithm:
  29922. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  29923. type: string
  29924. length:
  29925. description: Length defines the token length. Defaults to 6 characters.
  29926. type: integer
  29927. secret:
  29928. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  29929. properties:
  29930. key:
  29931. description: |-
  29932. A key in the referenced Secret.
  29933. Some instances of this field may be defaulted, in others it may be required.
  29934. maxLength: 253
  29935. minLength: 1
  29936. pattern: ^[-._a-zA-Z0-9]+$
  29937. type: string
  29938. name:
  29939. description: The name of the Secret resource being referred to.
  29940. maxLength: 253
  29941. minLength: 1
  29942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29943. type: string
  29944. namespace:
  29945. description: |-
  29946. The namespace of the Secret resource being referred to.
  29947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29948. maxLength: 63
  29949. minLength: 1
  29950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29951. type: string
  29952. type: object
  29953. timePeriod:
  29954. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  29955. type: integer
  29956. when:
  29957. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  29958. format: date-time
  29959. type: string
  29960. required:
  29961. - secret
  29962. type: object
  29963. type: object
  29964. served: true
  29965. storage: true
  29966. subresources:
  29967. status: {}
  29968. ---
  29969. apiVersion: apiextensions.k8s.io/v1
  29970. kind: CustomResourceDefinition
  29971. metadata:
  29972. annotations:
  29973. controller-gen.kubebuilder.io/version: v0.19.0
  29974. labels:
  29975. external-secrets.io/component: controller
  29976. name: passwords.generators.external-secrets.io
  29977. spec:
  29978. group: generators.external-secrets.io
  29979. names:
  29980. categories:
  29981. - external-secrets
  29982. - external-secrets-generators
  29983. kind: Password
  29984. listKind: PasswordList
  29985. plural: passwords
  29986. singular: password
  29987. scope: Namespaced
  29988. versions:
  29989. - name: v1alpha1
  29990. schema:
  29991. openAPIV3Schema:
  29992. description: |-
  29993. Password generates a random password based on the
  29994. configuration parameters in spec.
  29995. You can specify the length, characterset and other attributes.
  29996. properties:
  29997. apiVersion:
  29998. description: |-
  29999. APIVersion defines the versioned schema of this representation of an object.
  30000. Servers should convert recognized schemas to the latest internal value, and
  30001. may reject unrecognized values.
  30002. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30003. type: string
  30004. kind:
  30005. description: |-
  30006. Kind is a string value representing the REST resource this object represents.
  30007. Servers may infer this from the endpoint the client submits requests to.
  30008. Cannot be updated.
  30009. In CamelCase.
  30010. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30011. type: string
  30012. metadata:
  30013. type: object
  30014. spec:
  30015. description: PasswordSpec controls the behavior of the password generator.
  30016. properties:
  30017. allowRepeat:
  30018. default: false
  30019. description: set AllowRepeat to true to allow repeating characters.
  30020. type: boolean
  30021. digits:
  30022. description: |-
  30023. Digits specifies the number of digits in the generated
  30024. password. If omitted it defaults to 25% of the length of the password
  30025. type: integer
  30026. encoding:
  30027. default: raw
  30028. description: |-
  30029. Encoding specifies the encoding of the generated password.
  30030. Valid values are:
  30031. - "raw" (default): no encoding
  30032. - "base64": standard base64 encoding
  30033. - "base64url": base64url encoding
  30034. - "base32": base32 encoding
  30035. - "hex": hexadecimal encoding
  30036. enum:
  30037. - base64
  30038. - base64url
  30039. - base32
  30040. - hex
  30041. - raw
  30042. type: string
  30043. length:
  30044. default: 24
  30045. description: |-
  30046. Length of the password to be generated.
  30047. Defaults to 24
  30048. type: integer
  30049. noUpper:
  30050. default: false
  30051. description: Set NoUpper to disable uppercase characters
  30052. type: boolean
  30053. secretKeys:
  30054. description: |-
  30055. SecretKeys defines the keys that will be populated with generated passwords.
  30056. Defaults to "password" when not set.
  30057. items:
  30058. type: string
  30059. minItems: 1
  30060. type: array
  30061. symbolCharacters:
  30062. description: |-
  30063. SymbolCharacters specifies the special characters that should be used
  30064. in the generated password.
  30065. type: string
  30066. symbols:
  30067. description: |-
  30068. Symbols specifies the number of symbol characters in the generated
  30069. password. If omitted it defaults to 25% of the length of the password
  30070. type: integer
  30071. required:
  30072. - allowRepeat
  30073. - length
  30074. - noUpper
  30075. type: object
  30076. type: object
  30077. served: true
  30078. storage: true
  30079. subresources:
  30080. status: {}
  30081. ---
  30082. apiVersion: apiextensions.k8s.io/v1
  30083. kind: CustomResourceDefinition
  30084. metadata:
  30085. annotations:
  30086. controller-gen.kubebuilder.io/version: v0.19.0
  30087. labels:
  30088. external-secrets.io/component: controller
  30089. name: quayaccesstokens.generators.external-secrets.io
  30090. spec:
  30091. group: generators.external-secrets.io
  30092. names:
  30093. categories:
  30094. - external-secrets
  30095. - external-secrets-generators
  30096. kind: QuayAccessToken
  30097. listKind: QuayAccessTokenList
  30098. plural: quayaccesstokens
  30099. singular: quayaccesstoken
  30100. scope: Namespaced
  30101. versions:
  30102. - name: v1alpha1
  30103. schema:
  30104. openAPIV3Schema:
  30105. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30106. properties:
  30107. apiVersion:
  30108. description: |-
  30109. APIVersion defines the versioned schema of this representation of an object.
  30110. Servers should convert recognized schemas to the latest internal value, and
  30111. may reject unrecognized values.
  30112. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30113. type: string
  30114. kind:
  30115. description: |-
  30116. Kind is a string value representing the REST resource this object represents.
  30117. Servers may infer this from the endpoint the client submits requests to.
  30118. Cannot be updated.
  30119. In CamelCase.
  30120. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30121. type: string
  30122. metadata:
  30123. type: object
  30124. spec:
  30125. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30126. properties:
  30127. robotAccount:
  30128. description: Name of the robot account you are federating with
  30129. type: string
  30130. serviceAccountRef:
  30131. description: Name of the service account you are federating with
  30132. properties:
  30133. audiences:
  30134. description: |-
  30135. Audience specifies the `aud` claim for the service account token
  30136. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30137. then this audiences will be appended to the list
  30138. items:
  30139. type: string
  30140. type: array
  30141. name:
  30142. description: The name of the ServiceAccount resource being referred to.
  30143. maxLength: 253
  30144. minLength: 1
  30145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30146. type: string
  30147. namespace:
  30148. description: |-
  30149. Namespace of the resource being referred to.
  30150. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30151. maxLength: 63
  30152. minLength: 1
  30153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30154. type: string
  30155. required:
  30156. - name
  30157. type: object
  30158. url:
  30159. description: URL configures the Quay instance URL. Defaults to quay.io.
  30160. type: string
  30161. required:
  30162. - robotAccount
  30163. - serviceAccountRef
  30164. type: object
  30165. type: object
  30166. served: true
  30167. storage: true
  30168. subresources:
  30169. status: {}
  30170. ---
  30171. apiVersion: apiextensions.k8s.io/v1
  30172. kind: CustomResourceDefinition
  30173. metadata:
  30174. annotations:
  30175. controller-gen.kubebuilder.io/version: v0.19.0
  30176. labels:
  30177. external-secrets.io/component: controller
  30178. name: sshkeys.generators.external-secrets.io
  30179. spec:
  30180. group: generators.external-secrets.io
  30181. names:
  30182. categories:
  30183. - external-secrets
  30184. - external-secrets-generators
  30185. kind: SSHKey
  30186. listKind: SSHKeyList
  30187. plural: sshkeys
  30188. singular: sshkey
  30189. scope: Namespaced
  30190. versions:
  30191. - name: v1alpha1
  30192. schema:
  30193. openAPIV3Schema:
  30194. description: SSHKey generates SSH key pairs.
  30195. properties:
  30196. apiVersion:
  30197. description: |-
  30198. APIVersion defines the versioned schema of this representation of an object.
  30199. Servers should convert recognized schemas to the latest internal value, and
  30200. may reject unrecognized values.
  30201. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30202. type: string
  30203. kind:
  30204. description: |-
  30205. Kind is a string value representing the REST resource this object represents.
  30206. Servers may infer this from the endpoint the client submits requests to.
  30207. Cannot be updated.
  30208. In CamelCase.
  30209. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30210. type: string
  30211. metadata:
  30212. type: object
  30213. spec:
  30214. description: SSHKeySpec controls the behavior of the ssh key generator.
  30215. properties:
  30216. comment:
  30217. description: Comment specifies an optional comment for the SSH key
  30218. type: string
  30219. keySize:
  30220. description: |-
  30221. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  30222. For RSA keys: 2048, 3072, 4096
  30223. For ECDSA keys: 256, 384, 521
  30224. Ignored for ed25519 keys
  30225. maximum: 8192
  30226. minimum: 256
  30227. type: integer
  30228. keyType:
  30229. default: rsa
  30230. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  30231. enum:
  30232. - rsa
  30233. - ecdsa
  30234. - ed25519
  30235. type: string
  30236. type: object
  30237. type: object
  30238. served: true
  30239. storage: true
  30240. subresources:
  30241. status: {}
  30242. ---
  30243. apiVersion: apiextensions.k8s.io/v1
  30244. kind: CustomResourceDefinition
  30245. metadata:
  30246. annotations:
  30247. controller-gen.kubebuilder.io/version: v0.19.0
  30248. labels:
  30249. external-secrets.io/component: controller
  30250. name: stssessiontokens.generators.external-secrets.io
  30251. spec:
  30252. group: generators.external-secrets.io
  30253. names:
  30254. categories:
  30255. - external-secrets
  30256. - external-secrets-generators
  30257. kind: STSSessionToken
  30258. listKind: STSSessionTokenList
  30259. plural: stssessiontokens
  30260. singular: stssessiontoken
  30261. scope: Namespaced
  30262. versions:
  30263. - name: v1alpha1
  30264. schema:
  30265. openAPIV3Schema:
  30266. description: |-
  30267. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  30268. The authorization token is valid for 12 hours.
  30269. The authorizationToken returned is a base64 encoded string that can be decoded.
  30270. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  30271. properties:
  30272. apiVersion:
  30273. description: |-
  30274. APIVersion defines the versioned schema of this representation of an object.
  30275. Servers should convert recognized schemas to the latest internal value, and
  30276. may reject unrecognized values.
  30277. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30278. type: string
  30279. kind:
  30280. description: |-
  30281. Kind is a string value representing the REST resource this object represents.
  30282. Servers may infer this from the endpoint the client submits requests to.
  30283. Cannot be updated.
  30284. In CamelCase.
  30285. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30286. type: string
  30287. metadata:
  30288. type: object
  30289. spec:
  30290. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  30291. properties:
  30292. auth:
  30293. description: Auth defines how to authenticate with AWS
  30294. properties:
  30295. jwt:
  30296. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30297. properties:
  30298. serviceAccountRef:
  30299. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30300. properties:
  30301. audiences:
  30302. description: |-
  30303. Audience specifies the `aud` claim for the service account token
  30304. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30305. then this audiences will be appended to the list
  30306. items:
  30307. type: string
  30308. type: array
  30309. name:
  30310. description: The name of the ServiceAccount resource being referred to.
  30311. maxLength: 253
  30312. minLength: 1
  30313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30314. type: string
  30315. namespace:
  30316. description: |-
  30317. Namespace of the resource being referred to.
  30318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30319. maxLength: 63
  30320. minLength: 1
  30321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30322. type: string
  30323. required:
  30324. - name
  30325. type: object
  30326. type: object
  30327. secretRef:
  30328. description: |-
  30329. AWSAuthSecretRef holds secret references for AWS credentials
  30330. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30331. properties:
  30332. accessKeyIDSecretRef:
  30333. description: The AccessKeyID is used for authentication
  30334. properties:
  30335. key:
  30336. description: |-
  30337. A key in the referenced Secret.
  30338. Some instances of this field may be defaulted, in others it may be required.
  30339. maxLength: 253
  30340. minLength: 1
  30341. pattern: ^[-._a-zA-Z0-9]+$
  30342. type: string
  30343. name:
  30344. description: The name of the Secret resource being referred to.
  30345. maxLength: 253
  30346. minLength: 1
  30347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30348. type: string
  30349. namespace:
  30350. description: |-
  30351. The namespace of the Secret resource being referred to.
  30352. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30353. maxLength: 63
  30354. minLength: 1
  30355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30356. type: string
  30357. type: object
  30358. secretAccessKeySecretRef:
  30359. description: The SecretAccessKey is used for authentication
  30360. properties:
  30361. key:
  30362. description: |-
  30363. A key in the referenced Secret.
  30364. Some instances of this field may be defaulted, in others it may be required.
  30365. maxLength: 253
  30366. minLength: 1
  30367. pattern: ^[-._a-zA-Z0-9]+$
  30368. type: string
  30369. name:
  30370. description: The name of the Secret resource being referred to.
  30371. maxLength: 253
  30372. minLength: 1
  30373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30374. type: string
  30375. namespace:
  30376. description: |-
  30377. The namespace of the Secret resource being referred to.
  30378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30379. maxLength: 63
  30380. minLength: 1
  30381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30382. type: string
  30383. type: object
  30384. sessionTokenSecretRef:
  30385. description: |-
  30386. The SessionToken used for authentication
  30387. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30388. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30389. properties:
  30390. key:
  30391. description: |-
  30392. A key in the referenced Secret.
  30393. Some instances of this field may be defaulted, in others it may be required.
  30394. maxLength: 253
  30395. minLength: 1
  30396. pattern: ^[-._a-zA-Z0-9]+$
  30397. type: string
  30398. name:
  30399. description: The name of the Secret resource being referred to.
  30400. maxLength: 253
  30401. minLength: 1
  30402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30403. type: string
  30404. namespace:
  30405. description: |-
  30406. The namespace of the Secret resource being referred to.
  30407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30408. maxLength: 63
  30409. minLength: 1
  30410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30411. type: string
  30412. type: object
  30413. type: object
  30414. type: object
  30415. region:
  30416. description: Region specifies the region to operate in.
  30417. type: string
  30418. requestParameters:
  30419. description: RequestParameters contains parameters that can be passed to the STS service.
  30420. properties:
  30421. serialNumber:
  30422. description: |-
  30423. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  30424. the GetSessionToken call.
  30425. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  30426. (such as arn:aws:iam::123456789012:mfa/user)
  30427. type: string
  30428. sessionDuration:
  30429. format: int32
  30430. type: integer
  30431. tokenCode:
  30432. description: TokenCode is the value provided by the MFA device, if MFA is required.
  30433. type: string
  30434. type: object
  30435. role:
  30436. description: |-
  30437. You can assume a role before making calls to the
  30438. desired AWS service.
  30439. type: string
  30440. required:
  30441. - region
  30442. type: object
  30443. type: object
  30444. served: true
  30445. storage: true
  30446. subresources:
  30447. status: {}
  30448. ---
  30449. apiVersion: apiextensions.k8s.io/v1
  30450. kind: CustomResourceDefinition
  30451. metadata:
  30452. annotations:
  30453. controller-gen.kubebuilder.io/version: v0.19.0
  30454. labels:
  30455. external-secrets.io/component: controller
  30456. name: uuids.generators.external-secrets.io
  30457. spec:
  30458. group: generators.external-secrets.io
  30459. names:
  30460. categories:
  30461. - external-secrets
  30462. - external-secrets-generators
  30463. kind: UUID
  30464. listKind: UUIDList
  30465. plural: uuids
  30466. singular: uuid
  30467. scope: Namespaced
  30468. versions:
  30469. - name: v1alpha1
  30470. schema:
  30471. openAPIV3Schema:
  30472. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  30473. properties:
  30474. apiVersion:
  30475. description: |-
  30476. APIVersion defines the versioned schema of this representation of an object.
  30477. Servers should convert recognized schemas to the latest internal value, and
  30478. may reject unrecognized values.
  30479. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30480. type: string
  30481. kind:
  30482. description: |-
  30483. Kind is a string value representing the REST resource this object represents.
  30484. Servers may infer this from the endpoint the client submits requests to.
  30485. Cannot be updated.
  30486. In CamelCase.
  30487. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30488. type: string
  30489. metadata:
  30490. type: object
  30491. spec:
  30492. description: UUIDSpec controls the behavior of the uuid generator.
  30493. type: object
  30494. type: object
  30495. served: true
  30496. storage: true
  30497. subresources:
  30498. status: {}
  30499. ---
  30500. apiVersion: apiextensions.k8s.io/v1
  30501. kind: CustomResourceDefinition
  30502. metadata:
  30503. annotations:
  30504. controller-gen.kubebuilder.io/version: v0.19.0
  30505. labels:
  30506. external-secrets.io/component: controller
  30507. name: vaultdynamicsecrets.generators.external-secrets.io
  30508. spec:
  30509. group: generators.external-secrets.io
  30510. names:
  30511. categories:
  30512. - external-secrets
  30513. - external-secrets-generators
  30514. kind: VaultDynamicSecret
  30515. listKind: VaultDynamicSecretList
  30516. plural: vaultdynamicsecrets
  30517. singular: vaultdynamicsecret
  30518. scope: Namespaced
  30519. versions:
  30520. - name: v1alpha1
  30521. schema:
  30522. openAPIV3Schema:
  30523. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  30524. properties:
  30525. apiVersion:
  30526. description: |-
  30527. APIVersion defines the versioned schema of this representation of an object.
  30528. Servers should convert recognized schemas to the latest internal value, and
  30529. may reject unrecognized values.
  30530. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30531. type: string
  30532. kind:
  30533. description: |-
  30534. Kind is a string value representing the REST resource this object represents.
  30535. Servers may infer this from the endpoint the client submits requests to.
  30536. Cannot be updated.
  30537. In CamelCase.
  30538. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30539. type: string
  30540. metadata:
  30541. type: object
  30542. spec:
  30543. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  30544. properties:
  30545. allowEmptyResponse:
  30546. default: false
  30547. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  30548. type: boolean
  30549. controller:
  30550. description: |-
  30551. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30552. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30553. type: string
  30554. getParameters:
  30555. additionalProperties:
  30556. items:
  30557. type: string
  30558. type: array
  30559. description: |-
  30560. GetParameters are query-string parameters passed to Vault on GET calls.
  30561. Each key may map to multiple values, matching HTTP query-string semantics.
  30562. Ignored for non-GET methods; use Parameters for write bodies.
  30563. type: object
  30564. method:
  30565. description: Vault API method to use (GET/POST/other)
  30566. type: string
  30567. parameters:
  30568. description: Parameters to pass to Vault write (for non-GET methods)
  30569. x-kubernetes-preserve-unknown-fields: true
  30570. path:
  30571. description: Vault path to obtain the dynamic secret from
  30572. type: string
  30573. provider:
  30574. description: Vault provider common spec
  30575. properties:
  30576. auth:
  30577. description: Auth configures how secret-manager authenticates with the Vault server.
  30578. properties:
  30579. appRole:
  30580. description: |-
  30581. AppRole authenticates with Vault using the App Role auth mechanism,
  30582. with the role and secret stored in a Kubernetes Secret resource.
  30583. properties:
  30584. path:
  30585. default: approle
  30586. description: |-
  30587. Path where the App Role authentication backend is mounted
  30588. in Vault, e.g: "approle"
  30589. type: string
  30590. roleId:
  30591. description: |-
  30592. RoleID configured in the App Role authentication backend when setting
  30593. up the authentication backend in Vault.
  30594. type: string
  30595. roleRef:
  30596. description: |-
  30597. Reference to a key in a Secret that contains the App Role ID used
  30598. to authenticate with Vault.
  30599. The `key` field must be specified and denotes which entry within the Secret
  30600. resource is used as the app role id.
  30601. properties:
  30602. key:
  30603. description: |-
  30604. A key in the referenced Secret.
  30605. Some instances of this field may be defaulted, in others it may be required.
  30606. maxLength: 253
  30607. minLength: 1
  30608. pattern: ^[-._a-zA-Z0-9]+$
  30609. type: string
  30610. name:
  30611. description: The name of the Secret resource being referred to.
  30612. maxLength: 253
  30613. minLength: 1
  30614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30615. type: string
  30616. namespace:
  30617. description: |-
  30618. The namespace of the Secret resource being referred to.
  30619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30620. maxLength: 63
  30621. minLength: 1
  30622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30623. type: string
  30624. type: object
  30625. secretRef:
  30626. description: |-
  30627. Reference to a key in a Secret that contains the App Role secret used
  30628. to authenticate with Vault.
  30629. The `key` field must be specified and denotes which entry within the Secret
  30630. resource is used as the app role secret.
  30631. properties:
  30632. key:
  30633. description: |-
  30634. A key in the referenced Secret.
  30635. Some instances of this field may be defaulted, in others it may be required.
  30636. maxLength: 253
  30637. minLength: 1
  30638. pattern: ^[-._a-zA-Z0-9]+$
  30639. type: string
  30640. name:
  30641. description: The name of the Secret resource being referred to.
  30642. maxLength: 253
  30643. minLength: 1
  30644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30645. type: string
  30646. namespace:
  30647. description: |-
  30648. The namespace of the Secret resource being referred to.
  30649. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30650. maxLength: 63
  30651. minLength: 1
  30652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30653. type: string
  30654. type: object
  30655. required:
  30656. - path
  30657. - secretRef
  30658. type: object
  30659. cert:
  30660. description: |-
  30661. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  30662. Cert authentication method
  30663. properties:
  30664. clientCert:
  30665. description: |-
  30666. ClientCert is a certificate to authenticate using the Cert Vault
  30667. authentication method
  30668. properties:
  30669. key:
  30670. description: |-
  30671. A key in the referenced Secret.
  30672. Some instances of this field may be defaulted, in others it may be required.
  30673. maxLength: 253
  30674. minLength: 1
  30675. pattern: ^[-._a-zA-Z0-9]+$
  30676. type: string
  30677. name:
  30678. description: The name of the Secret resource being referred to.
  30679. maxLength: 253
  30680. minLength: 1
  30681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30682. type: string
  30683. namespace:
  30684. description: |-
  30685. The namespace of the Secret resource being referred to.
  30686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30687. maxLength: 63
  30688. minLength: 1
  30689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30690. type: string
  30691. type: object
  30692. path:
  30693. default: cert
  30694. description: |-
  30695. Path where the Certificate authentication backend is mounted
  30696. in Vault, e.g: "cert"
  30697. type: string
  30698. secretRef:
  30699. description: |-
  30700. SecretRef to a key in a Secret resource containing client private key to
  30701. authenticate with Vault using the Cert authentication method
  30702. properties:
  30703. key:
  30704. description: |-
  30705. A key in the referenced Secret.
  30706. Some instances of this field may be defaulted, in others it may be required.
  30707. maxLength: 253
  30708. minLength: 1
  30709. pattern: ^[-._a-zA-Z0-9]+$
  30710. type: string
  30711. name:
  30712. description: The name of the Secret resource being referred to.
  30713. maxLength: 253
  30714. minLength: 1
  30715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30716. type: string
  30717. namespace:
  30718. description: |-
  30719. The namespace of the Secret resource being referred to.
  30720. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30721. maxLength: 63
  30722. minLength: 1
  30723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30724. type: string
  30725. type: object
  30726. vaultRole:
  30727. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  30728. type: string
  30729. type: object
  30730. gcp:
  30731. description: |-
  30732. Gcp authenticates with Vault using Google Cloud Platform authentication method
  30733. GCP authentication method
  30734. properties:
  30735. location:
  30736. description: Location optionally defines a location/region for the secret
  30737. type: string
  30738. path:
  30739. default: gcp
  30740. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  30741. type: string
  30742. projectID:
  30743. description: Project ID of the Google Cloud Platform project
  30744. type: string
  30745. role:
  30746. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  30747. type: string
  30748. secretRef:
  30749. description: Specify credentials in a Secret object
  30750. properties:
  30751. secretAccessKeySecretRef:
  30752. description: The SecretAccessKey is used for authentication
  30753. properties:
  30754. key:
  30755. description: |-
  30756. A key in the referenced Secret.
  30757. Some instances of this field may be defaulted, in others it may be required.
  30758. maxLength: 253
  30759. minLength: 1
  30760. pattern: ^[-._a-zA-Z0-9]+$
  30761. type: string
  30762. name:
  30763. description: The name of the Secret resource being referred to.
  30764. maxLength: 253
  30765. minLength: 1
  30766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30767. type: string
  30768. namespace:
  30769. description: |-
  30770. The namespace of the Secret resource being referred to.
  30771. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30772. maxLength: 63
  30773. minLength: 1
  30774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30775. type: string
  30776. type: object
  30777. type: object
  30778. serviceAccountRef:
  30779. description: ServiceAccountRef to a service account for impersonation
  30780. properties:
  30781. audiences:
  30782. description: |-
  30783. Audience specifies the `aud` claim for the service account token
  30784. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30785. then this audiences will be appended to the list
  30786. items:
  30787. type: string
  30788. type: array
  30789. name:
  30790. description: The name of the ServiceAccount resource being referred to.
  30791. maxLength: 253
  30792. minLength: 1
  30793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30794. type: string
  30795. namespace:
  30796. description: |-
  30797. Namespace of the resource being referred to.
  30798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30799. maxLength: 63
  30800. minLength: 1
  30801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30802. type: string
  30803. required:
  30804. - name
  30805. type: object
  30806. workloadIdentity:
  30807. description: Specify a service account with Workload Identity
  30808. properties:
  30809. clusterLocation:
  30810. description: |-
  30811. ClusterLocation is the location of the cluster
  30812. If not specified, it fetches information from the metadata server
  30813. type: string
  30814. clusterName:
  30815. description: |-
  30816. ClusterName is the name of the cluster
  30817. If not specified, it fetches information from the metadata server
  30818. type: string
  30819. clusterProjectID:
  30820. description: |-
  30821. ClusterProjectID is the project ID of the cluster
  30822. If not specified, it fetches information from the metadata server
  30823. type: string
  30824. serviceAccountRef:
  30825. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30826. properties:
  30827. audiences:
  30828. description: |-
  30829. Audience specifies the `aud` claim for the service account token
  30830. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30831. then this audiences will be appended to the list
  30832. items:
  30833. type: string
  30834. type: array
  30835. name:
  30836. description: The name of the ServiceAccount resource being referred to.
  30837. maxLength: 253
  30838. minLength: 1
  30839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30840. type: string
  30841. namespace:
  30842. description: |-
  30843. Namespace of the resource being referred to.
  30844. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30845. maxLength: 63
  30846. minLength: 1
  30847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30848. type: string
  30849. required:
  30850. - name
  30851. type: object
  30852. required:
  30853. - serviceAccountRef
  30854. type: object
  30855. required:
  30856. - role
  30857. type: object
  30858. iam:
  30859. description: |-
  30860. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  30861. AWS IAM authentication method
  30862. properties:
  30863. externalID:
  30864. description: AWS External ID set on assumed IAM roles
  30865. type: string
  30866. jwt:
  30867. description: Specify a service account with IRSA enabled
  30868. properties:
  30869. serviceAccountRef:
  30870. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30871. properties:
  30872. audiences:
  30873. description: |-
  30874. Audience specifies the `aud` claim for the service account token
  30875. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30876. then this audiences will be appended to the list
  30877. items:
  30878. type: string
  30879. type: array
  30880. name:
  30881. description: The name of the ServiceAccount resource being referred to.
  30882. maxLength: 253
  30883. minLength: 1
  30884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30885. type: string
  30886. namespace:
  30887. description: |-
  30888. Namespace of the resource being referred to.
  30889. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30890. maxLength: 63
  30891. minLength: 1
  30892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30893. type: string
  30894. required:
  30895. - name
  30896. type: object
  30897. type: object
  30898. path:
  30899. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  30900. type: string
  30901. region:
  30902. description: AWS region
  30903. type: string
  30904. role:
  30905. description: This is the AWS role to be assumed before talking to vault
  30906. type: string
  30907. secretRef:
  30908. description: Specify credentials in a Secret object
  30909. properties:
  30910. accessKeyIDSecretRef:
  30911. description: The AccessKeyID is used for authentication
  30912. properties:
  30913. key:
  30914. description: |-
  30915. A key in the referenced Secret.
  30916. Some instances of this field may be defaulted, in others it may be required.
  30917. maxLength: 253
  30918. minLength: 1
  30919. pattern: ^[-._a-zA-Z0-9]+$
  30920. type: string
  30921. name:
  30922. description: The name of the Secret resource being referred to.
  30923. maxLength: 253
  30924. minLength: 1
  30925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30926. type: string
  30927. namespace:
  30928. description: |-
  30929. The namespace of the Secret resource being referred to.
  30930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30931. maxLength: 63
  30932. minLength: 1
  30933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30934. type: string
  30935. type: object
  30936. secretAccessKeySecretRef:
  30937. description: The SecretAccessKey is used for authentication
  30938. properties:
  30939. key:
  30940. description: |-
  30941. A key in the referenced Secret.
  30942. Some instances of this field may be defaulted, in others it may be required.
  30943. maxLength: 253
  30944. minLength: 1
  30945. pattern: ^[-._a-zA-Z0-9]+$
  30946. type: string
  30947. name:
  30948. description: The name of the Secret resource being referred to.
  30949. maxLength: 253
  30950. minLength: 1
  30951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30952. type: string
  30953. namespace:
  30954. description: |-
  30955. The namespace of the Secret resource being referred to.
  30956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30957. maxLength: 63
  30958. minLength: 1
  30959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30960. type: string
  30961. type: object
  30962. sessionTokenSecretRef:
  30963. description: |-
  30964. The SessionToken used for authentication
  30965. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30966. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30967. properties:
  30968. key:
  30969. description: |-
  30970. A key in the referenced Secret.
  30971. Some instances of this field may be defaulted, in others it may be required.
  30972. maxLength: 253
  30973. minLength: 1
  30974. pattern: ^[-._a-zA-Z0-9]+$
  30975. type: string
  30976. name:
  30977. description: The name of the Secret resource being referred to.
  30978. maxLength: 253
  30979. minLength: 1
  30980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30981. type: string
  30982. namespace:
  30983. description: |-
  30984. The namespace of the Secret resource being referred to.
  30985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30986. maxLength: 63
  30987. minLength: 1
  30988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30989. type: string
  30990. type: object
  30991. type: object
  30992. vaultAwsIamServerID:
  30993. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  30994. type: string
  30995. vaultRole:
  30996. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  30997. type: string
  30998. required:
  30999. - vaultRole
  31000. type: object
  31001. jwt:
  31002. description: |-
  31003. Jwt authenticates with Vault by passing role and JWT token using the
  31004. JWT/OIDC authentication method
  31005. properties:
  31006. kubernetesServiceAccountToken:
  31007. description: |-
  31008. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31009. a token for with the `TokenRequest` API.
  31010. properties:
  31011. audiences:
  31012. description: |-
  31013. Optional audiences field that will be used to request a temporary Kubernetes service
  31014. account token for the service account referenced by `serviceAccountRef`.
  31015. Defaults to a single audience `vault` it not specified.
  31016. Deprecated: use serviceAccountRef.Audiences instead
  31017. items:
  31018. type: string
  31019. type: array
  31020. expirationSeconds:
  31021. description: |-
  31022. Optional expiration time in seconds that will be used to request a temporary
  31023. Kubernetes service account token for the service account referenced by
  31024. `serviceAccountRef`.
  31025. Deprecated: this will be removed in the future.
  31026. Defaults to 10 minutes.
  31027. format: int64
  31028. type: integer
  31029. serviceAccountRef:
  31030. description: Service account field containing the name of a kubernetes ServiceAccount.
  31031. properties:
  31032. audiences:
  31033. description: |-
  31034. Audience specifies the `aud` claim for the service account token
  31035. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31036. then this audiences will be appended to the list
  31037. items:
  31038. type: string
  31039. type: array
  31040. name:
  31041. description: The name of the ServiceAccount resource being referred to.
  31042. maxLength: 253
  31043. minLength: 1
  31044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31045. type: string
  31046. namespace:
  31047. description: |-
  31048. Namespace of the resource being referred to.
  31049. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31050. maxLength: 63
  31051. minLength: 1
  31052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31053. type: string
  31054. required:
  31055. - name
  31056. type: object
  31057. required:
  31058. - serviceAccountRef
  31059. type: object
  31060. path:
  31061. default: jwt
  31062. description: |-
  31063. Path where the JWT authentication backend is mounted
  31064. in Vault, e.g: "jwt"
  31065. type: string
  31066. role:
  31067. description: |-
  31068. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31069. authentication method
  31070. type: string
  31071. secretRef:
  31072. description: |-
  31073. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31074. authenticate with Vault using the JWT/OIDC authentication method.
  31075. properties:
  31076. key:
  31077. description: |-
  31078. A key in the referenced Secret.
  31079. Some instances of this field may be defaulted, in others it may be required.
  31080. maxLength: 253
  31081. minLength: 1
  31082. pattern: ^[-._a-zA-Z0-9]+$
  31083. type: string
  31084. name:
  31085. description: The name of the Secret resource being referred to.
  31086. maxLength: 253
  31087. minLength: 1
  31088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31089. type: string
  31090. namespace:
  31091. description: |-
  31092. The namespace of the Secret resource being referred to.
  31093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31094. maxLength: 63
  31095. minLength: 1
  31096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31097. type: string
  31098. type: object
  31099. required:
  31100. - path
  31101. type: object
  31102. kubernetes:
  31103. description: |-
  31104. Kubernetes authenticates with Vault by passing the ServiceAccount
  31105. token stored in the named Secret resource to the Vault server.
  31106. properties:
  31107. mountPath:
  31108. default: kubernetes
  31109. description: |-
  31110. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31111. "kubernetes"
  31112. type: string
  31113. role:
  31114. description: |-
  31115. A required field containing the Vault Role to assume. A Role binds a
  31116. Kubernetes ServiceAccount with a set of Vault policies.
  31117. type: string
  31118. secretRef:
  31119. description: |-
  31120. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31121. for authenticating with Vault. If a name is specified without a key,
  31122. `token` is the default. If one is not specified, the one bound to
  31123. the controller will be used.
  31124. properties:
  31125. key:
  31126. description: |-
  31127. A key in the referenced Secret.
  31128. Some instances of this field may be defaulted, in others it may be required.
  31129. maxLength: 253
  31130. minLength: 1
  31131. pattern: ^[-._a-zA-Z0-9]+$
  31132. type: string
  31133. name:
  31134. description: The name of the Secret resource being referred to.
  31135. maxLength: 253
  31136. minLength: 1
  31137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31138. type: string
  31139. namespace:
  31140. description: |-
  31141. The namespace of the Secret resource being referred to.
  31142. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31143. maxLength: 63
  31144. minLength: 1
  31145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31146. type: string
  31147. type: object
  31148. serviceAccountRef:
  31149. description: |-
  31150. Optional service account field containing the name of a kubernetes ServiceAccount.
  31151. If the service account is specified, the service account secret token JWT will be used
  31152. for authenticating with Vault. If the service account selector is not supplied,
  31153. the secretRef will be used instead.
  31154. properties:
  31155. audiences:
  31156. description: |-
  31157. Audience specifies the `aud` claim for the service account token
  31158. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31159. then this audiences will be appended to the list
  31160. items:
  31161. type: string
  31162. type: array
  31163. name:
  31164. description: The name of the ServiceAccount resource being referred to.
  31165. maxLength: 253
  31166. minLength: 1
  31167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31168. type: string
  31169. namespace:
  31170. description: |-
  31171. Namespace of the resource being referred to.
  31172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31173. maxLength: 63
  31174. minLength: 1
  31175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31176. type: string
  31177. required:
  31178. - name
  31179. type: object
  31180. required:
  31181. - mountPath
  31182. - role
  31183. type: object
  31184. ldap:
  31185. description: |-
  31186. Ldap authenticates with Vault by passing username/password pair using
  31187. the LDAP authentication method
  31188. properties:
  31189. path:
  31190. default: ldap
  31191. description: |-
  31192. Path where the LDAP authentication backend is mounted
  31193. in Vault, e.g: "ldap"
  31194. type: string
  31195. secretRef:
  31196. description: |-
  31197. SecretRef to a key in a Secret resource containing password for the LDAP
  31198. user used to authenticate with Vault using the LDAP authentication
  31199. method
  31200. properties:
  31201. key:
  31202. description: |-
  31203. A key in the referenced Secret.
  31204. Some instances of this field may be defaulted, in others it may be required.
  31205. maxLength: 253
  31206. minLength: 1
  31207. pattern: ^[-._a-zA-Z0-9]+$
  31208. type: string
  31209. name:
  31210. description: The name of the Secret resource being referred to.
  31211. maxLength: 253
  31212. minLength: 1
  31213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31214. type: string
  31215. namespace:
  31216. description: |-
  31217. The namespace of the Secret resource being referred to.
  31218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31219. maxLength: 63
  31220. minLength: 1
  31221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31222. type: string
  31223. type: object
  31224. username:
  31225. description: |-
  31226. Username is an LDAP username used to authenticate using the LDAP Vault
  31227. authentication method
  31228. type: string
  31229. required:
  31230. - path
  31231. - username
  31232. type: object
  31233. namespace:
  31234. description: |-
  31235. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  31236. Namespaces is a set of features within Vault Enterprise that allows
  31237. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  31238. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  31239. This will default to Vault.Namespace field if set, or empty otherwise
  31240. type: string
  31241. tokenSecretRef:
  31242. description: TokenSecretRef authenticates with Vault by presenting a token.
  31243. properties:
  31244. key:
  31245. description: |-
  31246. A key in the referenced Secret.
  31247. Some instances of this field may be defaulted, in others it may be required.
  31248. maxLength: 253
  31249. minLength: 1
  31250. pattern: ^[-._a-zA-Z0-9]+$
  31251. type: string
  31252. name:
  31253. description: The name of the Secret resource being referred to.
  31254. maxLength: 253
  31255. minLength: 1
  31256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31257. type: string
  31258. namespace:
  31259. description: |-
  31260. The namespace of the Secret resource being referred to.
  31261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31262. maxLength: 63
  31263. minLength: 1
  31264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31265. type: string
  31266. type: object
  31267. userPass:
  31268. description: UserPass authenticates with Vault by passing username/password pair
  31269. properties:
  31270. path:
  31271. default: userpass
  31272. description: |-
  31273. Path where the UserPassword authentication backend is mounted
  31274. in Vault, e.g: "userpass"
  31275. type: string
  31276. secretRef:
  31277. description: |-
  31278. SecretRef to a key in a Secret resource containing password for the
  31279. user used to authenticate with Vault using the UserPass authentication
  31280. method
  31281. properties:
  31282. key:
  31283. description: |-
  31284. A key in the referenced Secret.
  31285. Some instances of this field may be defaulted, in others it may be required.
  31286. maxLength: 253
  31287. minLength: 1
  31288. pattern: ^[-._a-zA-Z0-9]+$
  31289. type: string
  31290. name:
  31291. description: The name of the Secret resource being referred to.
  31292. maxLength: 253
  31293. minLength: 1
  31294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31295. type: string
  31296. namespace:
  31297. description: |-
  31298. The namespace of the Secret resource being referred to.
  31299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31300. maxLength: 63
  31301. minLength: 1
  31302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31303. type: string
  31304. type: object
  31305. username:
  31306. description: |-
  31307. Username is a username used to authenticate using the UserPass Vault
  31308. authentication method
  31309. type: string
  31310. required:
  31311. - path
  31312. - username
  31313. type: object
  31314. type: object
  31315. caBundle:
  31316. description: |-
  31317. PEM encoded CA bundle used to validate Vault server certificate. Only used
  31318. if the Server URL is using HTTPS protocol. This parameter is ignored for
  31319. plain HTTP protocol connection. If not set the system root certificates
  31320. are used to validate the TLS connection.
  31321. format: byte
  31322. type: string
  31323. caProvider:
  31324. description: The provider for the CA bundle to use to validate Vault server certificate.
  31325. properties:
  31326. key:
  31327. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  31328. maxLength: 253
  31329. minLength: 1
  31330. pattern: ^[-._a-zA-Z0-9]+$
  31331. type: string
  31332. name:
  31333. description: The name of the object located at the provider type.
  31334. maxLength: 253
  31335. minLength: 1
  31336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31337. type: string
  31338. namespace:
  31339. description: |-
  31340. The namespace the Provider type is in.
  31341. Can only be defined when used in a ClusterSecretStore.
  31342. maxLength: 63
  31343. minLength: 1
  31344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31345. type: string
  31346. type:
  31347. description: The type of provider to use such as "Secret", or "ConfigMap".
  31348. enum:
  31349. - Secret
  31350. - ConfigMap
  31351. type: string
  31352. required:
  31353. - name
  31354. - type
  31355. type: object
  31356. checkAndSet:
  31357. description: |-
  31358. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  31359. Only applies to Vault KV v2 stores. When enabled, write operations must include
  31360. the current version of the secret to prevent unintentional overwrites.
  31361. properties:
  31362. required:
  31363. description: |-
  31364. Required when true, all write operations must include a check-and-set parameter.
  31365. This helps prevent unintentional overwrites of secrets.
  31366. type: boolean
  31367. type: object
  31368. forwardInconsistent:
  31369. description: |-
  31370. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  31371. leader instead of simply retrying within a loop. This can increase performance if
  31372. the option is enabled serverside.
  31373. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  31374. type: boolean
  31375. headers:
  31376. additionalProperties:
  31377. type: string
  31378. description: Headers to be added in Vault request
  31379. type: object
  31380. namespace:
  31381. description: |-
  31382. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  31383. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  31384. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  31385. type: string
  31386. path:
  31387. description: |-
  31388. Path is the mount path of the Vault KV backend endpoint, e.g:
  31389. "secret". The v2 KV secret engine version specific "/data" path suffix
  31390. for fetching secrets from Vault is optional and will be appended
  31391. if not present in specified path.
  31392. type: string
  31393. readYourWrites:
  31394. description: |-
  31395. ReadYourWrites ensures isolated read-after-write semantics by
  31396. providing discovered cluster replication states in each request.
  31397. More information about eventual consistency in Vault can be found here
  31398. https://www.vaultproject.io/docs/enterprise/consistency
  31399. type: boolean
  31400. server:
  31401. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  31402. type: string
  31403. tls:
  31404. description: |-
  31405. The configuration used for client side related TLS communication, when the Vault server
  31406. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  31407. This parameter is ignored for plain HTTP protocol connection.
  31408. It's worth noting this configuration is different from the "TLS certificates auth method",
  31409. which is available under the `auth.cert` section.
  31410. properties:
  31411. certSecretRef:
  31412. description: |-
  31413. CertSecretRef is a certificate added to the transport layer
  31414. when communicating with the Vault server.
  31415. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  31416. properties:
  31417. key:
  31418. description: |-
  31419. A key in the referenced Secret.
  31420. Some instances of this field may be defaulted, in others it may be required.
  31421. maxLength: 253
  31422. minLength: 1
  31423. pattern: ^[-._a-zA-Z0-9]+$
  31424. type: string
  31425. name:
  31426. description: The name of the Secret resource being referred to.
  31427. maxLength: 253
  31428. minLength: 1
  31429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31430. type: string
  31431. namespace:
  31432. description: |-
  31433. The namespace of the Secret resource being referred to.
  31434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31435. maxLength: 63
  31436. minLength: 1
  31437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31438. type: string
  31439. type: object
  31440. keySecretRef:
  31441. description: |-
  31442. KeySecretRef to a key in a Secret resource containing client private key
  31443. added to the transport layer when communicating with the Vault server.
  31444. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  31445. properties:
  31446. key:
  31447. description: |-
  31448. A key in the referenced Secret.
  31449. Some instances of this field may be defaulted, in others it may be required.
  31450. maxLength: 253
  31451. minLength: 1
  31452. pattern: ^[-._a-zA-Z0-9]+$
  31453. type: string
  31454. name:
  31455. description: The name of the Secret resource being referred to.
  31456. maxLength: 253
  31457. minLength: 1
  31458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31459. type: string
  31460. namespace:
  31461. description: |-
  31462. The namespace of the Secret resource being referred to.
  31463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31464. maxLength: 63
  31465. minLength: 1
  31466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31467. type: string
  31468. type: object
  31469. type: object
  31470. version:
  31471. default: v2
  31472. description: |-
  31473. Version is the Vault KV secret engine version. This can be either "v1" or
  31474. "v2". Version defaults to "v2".
  31475. enum:
  31476. - v1
  31477. - v2
  31478. type: string
  31479. required:
  31480. - server
  31481. type: object
  31482. resultType:
  31483. default: Data
  31484. description: |-
  31485. Result type defines which data is returned from the generator.
  31486. By default, it is the "data" section of the Vault API response.
  31487. When using e.g. /auth/token/create the "data" section is empty but
  31488. the "auth" section contains the generated token.
  31489. Please refer to the vault docs regarding the result data structure.
  31490. Additionally, accessing the raw response is possibly by using "Raw" result type.
  31491. enum:
  31492. - Data
  31493. - Auth
  31494. - Raw
  31495. type: string
  31496. retrySettings:
  31497. description: Used to configure http retries if failed
  31498. properties:
  31499. maxRetries:
  31500. format: int32
  31501. type: integer
  31502. retryInterval:
  31503. type: string
  31504. type: object
  31505. required:
  31506. - path
  31507. - provider
  31508. type: object
  31509. type: object
  31510. served: true
  31511. storage: true
  31512. subresources:
  31513. status: {}
  31514. ---
  31515. apiVersion: apiextensions.k8s.io/v1
  31516. kind: CustomResourceDefinition
  31517. metadata:
  31518. annotations:
  31519. controller-gen.kubebuilder.io/version: v0.19.0
  31520. labels:
  31521. external-secrets.io/component: controller
  31522. name: webhooks.generators.external-secrets.io
  31523. spec:
  31524. group: generators.external-secrets.io
  31525. names:
  31526. categories:
  31527. - external-secrets
  31528. - external-secrets-generators
  31529. kind: Webhook
  31530. listKind: WebhookList
  31531. plural: webhooks
  31532. singular: webhook
  31533. scope: Namespaced
  31534. versions:
  31535. - name: v1alpha1
  31536. schema:
  31537. openAPIV3Schema:
  31538. description: |-
  31539. Webhook connects to a third party API server to handle the secrets generation
  31540. configuration parameters in spec.
  31541. You can specify the server, the token, and additional body parameters.
  31542. See documentation for the full API specification for requests and responses.
  31543. properties:
  31544. apiVersion:
  31545. description: |-
  31546. APIVersion defines the versioned schema of this representation of an object.
  31547. Servers should convert recognized schemas to the latest internal value, and
  31548. may reject unrecognized values.
  31549. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31550. type: string
  31551. kind:
  31552. description: |-
  31553. Kind is a string value representing the REST resource this object represents.
  31554. Servers may infer this from the endpoint the client submits requests to.
  31555. Cannot be updated.
  31556. In CamelCase.
  31557. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31558. type: string
  31559. metadata:
  31560. type: object
  31561. spec:
  31562. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  31563. properties:
  31564. auth:
  31565. description: Auth specifies a authorization protocol. Only one protocol may be set.
  31566. maxProperties: 1
  31567. minProperties: 1
  31568. properties:
  31569. ntlm:
  31570. description: NTLMProtocol configures the store to use NTLM for auth
  31571. properties:
  31572. passwordSecret:
  31573. description: |-
  31574. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31575. In some instances, `key` is a required field.
  31576. properties:
  31577. key:
  31578. description: |-
  31579. A key in the referenced Secret.
  31580. Some instances of this field may be defaulted, in others it may be required.
  31581. maxLength: 253
  31582. minLength: 1
  31583. pattern: ^[-._a-zA-Z0-9]+$
  31584. type: string
  31585. name:
  31586. description: The name of the Secret resource being referred to.
  31587. maxLength: 253
  31588. minLength: 1
  31589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31590. type: string
  31591. namespace:
  31592. description: |-
  31593. The namespace of the Secret resource being referred to.
  31594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31595. maxLength: 63
  31596. minLength: 1
  31597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31598. type: string
  31599. type: object
  31600. usernameSecret:
  31601. description: |-
  31602. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31603. In some instances, `key` is a required field.
  31604. properties:
  31605. key:
  31606. description: |-
  31607. A key in the referenced Secret.
  31608. Some instances of this field may be defaulted, in others it may be required.
  31609. maxLength: 253
  31610. minLength: 1
  31611. pattern: ^[-._a-zA-Z0-9]+$
  31612. type: string
  31613. name:
  31614. description: The name of the Secret resource being referred to.
  31615. maxLength: 253
  31616. minLength: 1
  31617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31618. type: string
  31619. namespace:
  31620. description: |-
  31621. The namespace of the Secret resource being referred to.
  31622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31623. maxLength: 63
  31624. minLength: 1
  31625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31626. type: string
  31627. type: object
  31628. required:
  31629. - passwordSecret
  31630. - usernameSecret
  31631. type: object
  31632. type: object
  31633. body:
  31634. description: Body
  31635. type: string
  31636. caBundle:
  31637. description: |-
  31638. PEM encoded CA bundle used to validate webhook server certificate. Only used
  31639. if the Server URL is using HTTPS protocol. This parameter is ignored for
  31640. plain HTTP protocol connection. If not set the system root certificates
  31641. are used to validate the TLS connection.
  31642. format: byte
  31643. type: string
  31644. caProvider:
  31645. description: The provider for the CA bundle to use to validate webhook server certificate.
  31646. properties:
  31647. key:
  31648. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  31649. maxLength: 253
  31650. minLength: 1
  31651. pattern: ^[-._a-zA-Z0-9]+$
  31652. type: string
  31653. name:
  31654. description: The name of the object located at the provider type.
  31655. maxLength: 253
  31656. minLength: 1
  31657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31658. type: string
  31659. namespace:
  31660. description: The namespace the Provider type is in.
  31661. maxLength: 63
  31662. minLength: 1
  31663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31664. type: string
  31665. type:
  31666. description: The type of provider to use such as "Secret", or "ConfigMap".
  31667. enum:
  31668. - Secret
  31669. - ConfigMap
  31670. type: string
  31671. required:
  31672. - name
  31673. - type
  31674. type: object
  31675. headers:
  31676. additionalProperties:
  31677. type: string
  31678. description: Headers
  31679. type: object
  31680. method:
  31681. description: Webhook Method
  31682. type: string
  31683. result:
  31684. description: Result formatting
  31685. properties:
  31686. jsonPath:
  31687. description: Json path of return value
  31688. type: string
  31689. type: object
  31690. secrets:
  31691. description: |-
  31692. Secrets to fill in templates
  31693. These secrets will be passed to the templating function as key value pairs under the given name
  31694. items:
  31695. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  31696. properties:
  31697. name:
  31698. description: Name of this secret in templates
  31699. type: string
  31700. secretRef:
  31701. description: Secret ref to fill in credentials
  31702. properties:
  31703. key:
  31704. description: The key where the token is found.
  31705. maxLength: 253
  31706. minLength: 1
  31707. pattern: ^[-._a-zA-Z0-9]+$
  31708. type: string
  31709. name:
  31710. description: The name of the Secret resource being referred to.
  31711. maxLength: 253
  31712. minLength: 1
  31713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31714. type: string
  31715. type: object
  31716. required:
  31717. - name
  31718. - secretRef
  31719. type: object
  31720. type: array
  31721. timeout:
  31722. description: Timeout
  31723. type: string
  31724. url:
  31725. description: Webhook url to call
  31726. type: string
  31727. required:
  31728. - result
  31729. - url
  31730. type: object
  31731. type: object
  31732. served: true
  31733. storage: true
  31734. subresources:
  31735. status: {}