index.html 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963
  1. <!doctype html>
  2. <html lang="en" class="no-js">
  3. <head>
  4. <meta charset="utf-8">
  5. <meta name="viewport" content="width=device-width,initial-scale=1">
  6. <meta http-equiv="x-ua-compatible" content="ie=edge">
  7. <meta name="lang:clipboard.copy" content="Copy to clipboard">
  8. <meta name="lang:clipboard.copied" content="Copied to clipboard">
  9. <meta name="lang:search.language" content="en">
  10. <meta name="lang:search.pipeline.stopwords" content="True">
  11. <meta name="lang:search.pipeline.trimmer" content="True">
  12. <meta name="lang:search.result.none" content="No matching documents">
  13. <meta name="lang:search.result.one" content="1 matching document">
  14. <meta name="lang:search.result.other" content="# matching documents">
  15. <meta name="lang:search.tokenizer" content="[\s\-]+">
  16. <link rel="shortcut icon" href="../assets/images/favicon.png">
  17. <meta name="generator" content="mkdocs-1.0.4, mkdocs-material-4.6.0">
  18. <title>Advanced Templating - External Secrets Operator</title>
  19. <link rel="stylesheet" href="../assets/stylesheets/application.1b62728e.css">
  20. <script src="../assets/javascripts/modernizr.268332fc.js"></script>
  21. <link href="https://fonts.gstatic.com" rel="preconnect" crossorigin>
  22. <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,400,400i,700%7CRoboto+Mono&display=fallback">
  23. <style>body,input{font-family:"Roboto","Helvetica Neue",Helvetica,Arial,sans-serif}code,kbd,pre{font-family:"Roboto Mono","Courier New",Courier,monospace}</style>
  24. <link rel="stylesheet" href="../assets/fonts/material-icons.css">
  25. </head>
  26. <body dir="ltr">
  27. <svg class="md-svg">
  28. <defs>
  29. <svg xmlns="http://www.w3.org/2000/svg" width="416" height="448" viewBox="0 0 416 448" id="__github"><path fill="currentColor" d="M160 304q0 10-3.125 20.5t-10.75 19T128 352t-18.125-8.5-10.75-19T96 304t3.125-20.5 10.75-19T128 256t18.125 8.5 10.75 19T160 304zm160 0q0 10-3.125 20.5t-10.75 19T288 352t-18.125-8.5-10.75-19T256 304t3.125-20.5 10.75-19T288 256t18.125 8.5 10.75 19T320 304zm40 0q0-30-17.25-51T296 232q-10.25 0-48.75 5.25Q229.5 240 208 240t-39.25-2.75Q130.75 232 120 232q-29.5 0-46.75 21T56 304q0 22 8 38.375t20.25 25.75 30.5 15 35 7.375 37.25 1.75h42q20.5 0 37.25-1.75t35-7.375 30.5-15 20.25-25.75T360 304zm56-44q0 51.75-15.25 82.75-9.5 19.25-26.375 33.25t-35.25 21.5-42.5 11.875-42.875 5.5T212 416q-19.5 0-35.5-.75t-36.875-3.125-38.125-7.5-34.25-12.875T37 371.5t-21.5-28.75Q0 312 0 260q0-59.25 34-99-6.75-20.5-6.75-42.5 0-29 12.75-54.5 27 0 47.5 9.875t47.25 30.875Q171.5 96 212 96q37 0 70 8 26.25-20.5 46.75-30.25T376 64q12.75 25.5 12.75 54.5 0 21.75-6.75 42 34 40 34 99.5z"/></svg>
  30. </defs>
  31. </svg>
  32. <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
  33. <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
  34. <label class="md-overlay" data-md-component="overlay" for="__drawer"></label>
  35. <a href="#examples" tabindex="1" class="md-skip">
  36. Skip to content
  37. </a>
  38. <header class="md-header" data-md-component="header">
  39. <nav class="md-header-nav md-grid">
  40. <div class="md-flex">
  41. <div class="md-flex__cell md-flex__cell--shrink">
  42. <a href=".." title="External Secrets Operator" class="md-header-nav__button md-logo">
  43. <i class="md-icon"></i>
  44. </a>
  45. </div>
  46. <div class="md-flex__cell md-flex__cell--shrink">
  47. <label class="md-icon md-icon--menu md-header-nav__button" for="__drawer"></label>
  48. </div>
  49. <div class="md-flex__cell md-flex__cell--stretch">
  50. <div class="md-flex__ellipsis md-header-nav__title" data-md-component="title">
  51. <span class="md-header-nav__topic">
  52. External Secrets Operator
  53. </span>
  54. <span class="md-header-nav__topic">
  55. Advanced Templating
  56. </span>
  57. </div>
  58. </div>
  59. <div class="md-flex__cell md-flex__cell--shrink">
  60. <label class="md-icon md-icon--search md-header-nav__button" for="__search"></label>
  61. <div class="md-search" data-md-component="search" role="dialog">
  62. <label class="md-search__overlay" for="__search"></label>
  63. <div class="md-search__inner" role="search">
  64. <form class="md-search__form" name="search">
  65. <input type="text" class="md-search__input" name="query" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="query" data-md-state="active">
  66. <label class="md-icon md-search__icon" for="__search"></label>
  67. <button type="reset" class="md-icon md-search__icon" data-md-component="reset" tabindex="-1">
  68. &#xE5CD;
  69. </button>
  70. </form>
  71. <div class="md-search__output">
  72. <div class="md-search__scrollwrap" data-md-scrollfix>
  73. <div class="md-search-result" data-md-component="result">
  74. <div class="md-search-result__meta">
  75. Type to start searching
  76. </div>
  77. <ol class="md-search-result__list"></ol>
  78. </div>
  79. </div>
  80. </div>
  81. </div>
  82. </div>
  83. </div>
  84. <div class="md-flex__cell md-flex__cell--shrink">
  85. <div class="md-header-nav__source">
  86. <a href="https://github.com/external-secrets/external-secrets/" title="Go to repository" class="md-source" data-md-source="github">
  87. <div class="md-source__icon">
  88. <svg viewBox="0 0 24 24" width="24" height="24">
  89. <use xlink:href="#__github" width="24" height="24"></use>
  90. </svg>
  91. </div>
  92. <div class="md-source__repository">
  93. External Secrets Operator
  94. </div>
  95. </a>
  96. </div>
  97. </div>
  98. </div>
  99. </nav>
  100. </header>
  101. <div class="md-container">
  102. <main class="md-main" role="main">
  103. <div class="md-main__inner md-grid" data-md-component="container">
  104. <div class="md-sidebar md-sidebar--primary" data-md-component="navigation">
  105. <div class="md-sidebar__scrollwrap">
  106. <div class="md-sidebar__inner">
  107. <nav class="md-nav md-nav--primary" data-md-level="0">
  108. <label class="md-nav__title md-nav__title--site" for="__drawer">
  109. <a href=".." title="External Secrets Operator" class="md-nav__button md-logo">
  110. <i class="md-icon"></i>
  111. </a>
  112. External Secrets Operator
  113. </label>
  114. <div class="md-nav__source">
  115. <a href="https://github.com/external-secrets/external-secrets/" title="Go to repository" class="md-source" data-md-source="github">
  116. <div class="md-source__icon">
  117. <svg viewBox="0 0 24 24" width="24" height="24">
  118. <use xlink:href="#__github" width="24" height="24"></use>
  119. </svg>
  120. </div>
  121. <div class="md-source__repository">
  122. External Secrets Operator
  123. </div>
  124. </a>
  125. </div>
  126. <ul class="md-nav__list" data-md-scrollfix>
  127. <li class="md-nav__item">
  128. <a href=".." title="Introduction" class="md-nav__link">
  129. Introduction
  130. </a>
  131. </li>
  132. <li class="md-nav__item">
  133. <a href="../api-overview/" title="Overview" class="md-nav__link">
  134. Overview
  135. </a>
  136. </li>
  137. <li class="md-nav__item md-nav__item--nested">
  138. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-3" type="checkbox" id="nav-3">
  139. <label class="md-nav__link" for="nav-3">
  140. API Types
  141. </label>
  142. <nav class="md-nav" data-md-component="collapsible" data-md-level="1">
  143. <label class="md-nav__title" for="nav-3">
  144. API Types
  145. </label>
  146. <ul class="md-nav__list" data-md-scrollfix>
  147. <li class="md-nav__item">
  148. <a href="../api-externalsecret/" title="ExternalSecret" class="md-nav__link">
  149. ExternalSecret
  150. </a>
  151. </li>
  152. <li class="md-nav__item">
  153. <a href="../api-secretstore/" title="SecretStore" class="md-nav__link">
  154. SecretStore
  155. </a>
  156. </li>
  157. <li class="md-nav__item">
  158. <a href="../api-clustersecretstore/" title="ClusterSecretStore" class="md-nav__link">
  159. ClusterSecretStore
  160. </a>
  161. </li>
  162. </ul>
  163. </nav>
  164. </li>
  165. <li class="md-nav__item md-nav__item--active md-nav__item--nested">
  166. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-4" type="checkbox" id="nav-4" checked>
  167. <label class="md-nav__link" for="nav-4">
  168. Guides
  169. </label>
  170. <nav class="md-nav" data-md-component="collapsible" data-md-level="1">
  171. <label class="md-nav__title" for="nav-4">
  172. Guides
  173. </label>
  174. <ul class="md-nav__list" data-md-scrollfix>
  175. <li class="md-nav__item">
  176. <a href="../guides-introduction/" title="Introduction" class="md-nav__link">
  177. Introduction
  178. </a>
  179. </li>
  180. <li class="md-nav__item">
  181. <a href="../guides-getting-started/" title="Getting started" class="md-nav__link">
  182. Getting started
  183. </a>
  184. </li>
  185. <li class="md-nav__item md-nav__item--active">
  186. <input class="md-toggle md-nav__toggle" data-md-toggle="toc" type="checkbox" id="__toc">
  187. <label class="md-nav__link md-nav__link--active" for="__toc">
  188. Advanced Templating
  189. </label>
  190. <a href="./" title="Advanced Templating" class="md-nav__link md-nav__link--active">
  191. Advanced Templating
  192. </a>
  193. <nav class="md-nav md-nav--secondary">
  194. <label class="md-nav__title" for="__toc">Table of contents</label>
  195. <ul class="md-nav__list" data-md-scrollfix>
  196. <li class="md-nav__item">
  197. <a href="#examples" class="md-nav__link">
  198. Examples
  199. </a>
  200. </li>
  201. <li class="md-nav__item">
  202. <a href="#helper-functions" class="md-nav__link">
  203. Helper functions
  204. </a>
  205. </li>
  206. </ul>
  207. </nav>
  208. </li>
  209. <li class="md-nav__item">
  210. <a href="../guides-multi-tenancy/" title="Multi Tenancy" class="md-nav__link">
  211. Multi Tenancy
  212. </a>
  213. </li>
  214. <li class="md-nav__item">
  215. <a href="../guides-metrics/" title="Metrics" class="md-nav__link">
  216. Metrics
  217. </a>
  218. </li>
  219. </ul>
  220. </nav>
  221. </li>
  222. <li class="md-nav__item md-nav__item--nested">
  223. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-5" type="checkbox" id="nav-5">
  224. <label class="md-nav__link" for="nav-5">
  225. Provider
  226. </label>
  227. <nav class="md-nav" data-md-component="collapsible" data-md-level="1">
  228. <label class="md-nav__title" for="nav-5">
  229. Provider
  230. </label>
  231. <ul class="md-nav__list" data-md-scrollfix>
  232. <li class="md-nav__item md-nav__item--nested">
  233. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-5-1" type="checkbox" id="nav-5-1">
  234. <label class="md-nav__link" for="nav-5-1">
  235. AWS
  236. </label>
  237. <nav class="md-nav" data-md-component="collapsible" data-md-level="2">
  238. <label class="md-nav__title" for="nav-5-1">
  239. AWS
  240. </label>
  241. <ul class="md-nav__list" data-md-scrollfix>
  242. <li class="md-nav__item">
  243. <a href="../provider-aws-secrets-manager/" title="Secrets Manager" class="md-nav__link">
  244. Secrets Manager
  245. </a>
  246. </li>
  247. <li class="md-nav__item">
  248. <a href="../provider-aws-parameter-store/" title="Parameter Store" class="md-nav__link">
  249. Parameter Store
  250. </a>
  251. </li>
  252. </ul>
  253. </nav>
  254. </li>
  255. <li class="md-nav__item md-nav__item--nested">
  256. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-5-2" type="checkbox" id="nav-5-2">
  257. <label class="md-nav__link" for="nav-5-2">
  258. Azure
  259. </label>
  260. <nav class="md-nav" data-md-component="collapsible" data-md-level="2">
  261. <label class="md-nav__title" for="nav-5-2">
  262. Azure
  263. </label>
  264. <ul class="md-nav__list" data-md-scrollfix>
  265. <li class="md-nav__item">
  266. <a href="../provider-azure-key-vault/" title="Key Vault" class="md-nav__link">
  267. Key Vault
  268. </a>
  269. </li>
  270. </ul>
  271. </nav>
  272. </li>
  273. <li class="md-nav__item md-nav__item--nested">
  274. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-5-3" type="checkbox" id="nav-5-3">
  275. <label class="md-nav__link" for="nav-5-3">
  276. Google
  277. </label>
  278. <nav class="md-nav" data-md-component="collapsible" data-md-level="2">
  279. <label class="md-nav__title" for="nav-5-3">
  280. Google
  281. </label>
  282. <ul class="md-nav__list" data-md-scrollfix>
  283. <li class="md-nav__item">
  284. <a href="../provider-google-secrets-manager/" title="Secrets Manager" class="md-nav__link">
  285. Secrets Manager
  286. </a>
  287. </li>
  288. </ul>
  289. </nav>
  290. </li>
  291. <li class="md-nav__item">
  292. <a href="../provider-hashicorp-vault/" title="HashiCorp Vault" class="md-nav__link">
  293. HashiCorp Vault
  294. </a>
  295. </li>
  296. </ul>
  297. </nav>
  298. </li>
  299. <li class="md-nav__item md-nav__item--nested">
  300. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-6" type="checkbox" id="nav-6">
  301. <label class="md-nav__link" for="nav-6">
  302. References
  303. </label>
  304. <nav class="md-nav" data-md-component="collapsible" data-md-level="1">
  305. <label class="md-nav__title" for="nav-6">
  306. References
  307. </label>
  308. <ul class="md-nav__list" data-md-scrollfix>
  309. <li class="md-nav__item">
  310. <a href="../spec/" title="API specification" class="md-nav__link">
  311. API specification
  312. </a>
  313. </li>
  314. </ul>
  315. </nav>
  316. </li>
  317. <li class="md-nav__item md-nav__item--nested">
  318. <input class="md-toggle md-nav__toggle" data-md-toggle="nav-7" type="checkbox" id="nav-7">
  319. <label class="md-nav__link" for="nav-7">
  320. Contributing
  321. </label>
  322. <nav class="md-nav" data-md-component="collapsible" data-md-level="1">
  323. <label class="md-nav__title" for="nav-7">
  324. Contributing
  325. </label>
  326. <ul class="md-nav__list" data-md-scrollfix>
  327. <li class="md-nav__item">
  328. <a href="../contributing-devguide/" title="Developer guide" class="md-nav__link">
  329. Developer guide
  330. </a>
  331. </li>
  332. <li class="md-nav__item">
  333. <a href="../contributing-process/" title="Contributing Process" class="md-nav__link">
  334. Contributing Process
  335. </a>
  336. </li>
  337. <li class="md-nav__item">
  338. <a href="../contributing-coc/" title="Code of Conduct" class="md-nav__link">
  339. Code of Conduct
  340. </a>
  341. </li>
  342. </ul>
  343. </nav>
  344. </li>
  345. </ul>
  346. </nav>
  347. </div>
  348. </div>
  349. </div>
  350. <div class="md-sidebar md-sidebar--secondary" data-md-component="toc">
  351. <div class="md-sidebar__scrollwrap">
  352. <div class="md-sidebar__inner">
  353. <nav class="md-nav md-nav--secondary">
  354. <label class="md-nav__title" for="__toc">Table of contents</label>
  355. <ul class="md-nav__list" data-md-scrollfix>
  356. <li class="md-nav__item">
  357. <a href="#examples" class="md-nav__link">
  358. Examples
  359. </a>
  360. </li>
  361. <li class="md-nav__item">
  362. <a href="#helper-functions" class="md-nav__link">
  363. Helper functions
  364. </a>
  365. </li>
  366. </ul>
  367. </nav>
  368. </div>
  369. </div>
  370. </div>
  371. <div class="md-content">
  372. <article class="md-content__inner md-typeset">
  373. <a href="https://github.com/external-secrets/external-secrets/edit/master/docs/guides-templating.md" title="Edit this page" class="md-icon md-content__icon">&#xE3C9;</a>
  374. <h1>Advanced Templating</h1>
  375. <p>With External Secrets Operator you can transform the data from the external secret provider before it is stored as <code>Kind=Secret</code>. You can do this with the <code>Spec.Target.Template</code>. Each data value is interpreted as a <a href="https://golang.org/pkg/text/template/">golang template</a>.</p>
  376. <h2 id="examples">Examples</h2>
  377. <p>You can use templates to inject your secrets into a configuration file that you mount into your pod:
  378. <div class="highlight"><pre><span></span><span class="nt">apiVersion</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">external-secrets.io/v1alpha1</span>
  379. <span class="nt">kind</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">ExternalSecret</span>
  380. <span class="nt">metadata</span><span class="p">:</span>
  381. <span class="nt">name</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">template</span>
  382. <span class="nt">spec</span><span class="p">:</span>
  383. <span class="nt">refreshInterval</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">1h</span>
  384. <span class="nt">secretStoreRef</span><span class="p">:</span>
  385. <span class="nt">name</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">secretstore-sample</span>
  386. <span class="nt">kind</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">SecretStore</span>
  387. <span class="nt">target</span><span class="p">:</span>
  388. <span class="nt">name</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">secret-to-be-created</span>
  389. <span class="c1"># this is how the Kind=Secret will look like</span>
  390. <span class="nt">template</span><span class="p">:</span>
  391. <span class="nt">type</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">kubernetes.io/tls</span>
  392. <span class="nt">data</span><span class="p">:</span>
  393. <span class="c1"># multiline string</span>
  394. <span class="nt">config</span><span class="p">:</span> <span class="p p-Indicator">|</span>
  395. <span class="no">datasources:</span>
  396. <span class="no">- name: Graphite</span>
  397. <span class="no">type: graphite</span>
  398. <span class="no">access: proxy</span>
  399. <span class="no">url: http://localhost:8080</span>
  400. <span class="no">password: &quot;{{ .password | toString }}&quot; # &lt;-- convert []byte to string</span>
  401. <span class="no">user: &quot;{{ .user | toString }}&quot; # &lt;-- convert []byte to string</span>
  402. <span class="nt">data</span><span class="p">:</span>
  403. <span class="p p-Indicator">-</span> <span class="nt">secretKey</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">user</span>
  404. <span class="nt">remoteRef</span><span class="p">:</span>
  405. <span class="nt">key</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">/grafana/user</span>
  406. <span class="p p-Indicator">-</span> <span class="nt">secretKey</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">password</span>
  407. <span class="nt">remoteRef</span><span class="p">:</span>
  408. <span class="nt">key</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">/grafana/password</span>
  409. </pre></div></p>
  410. <p>You can also use pre-defined functions to extract data from your secrets. Here: extract key/cert from a pkcs12 archive and store it as PEM.
  411. <div class="highlight"><pre><span></span><span class="nt">apiVersion</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">external-secrets.io/v1alpha1</span>
  412. <span class="nt">kind</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">ExternalSecret</span>
  413. <span class="nt">metadata</span><span class="p">:</span>
  414. <span class="nt">name</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">template</span>
  415. <span class="nt">spec</span><span class="p">:</span>
  416. <span class="nt">refreshInterval</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">1h</span>
  417. <span class="nt">secretStoreRef</span><span class="p">:</span>
  418. <span class="nt">name</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">secretstore-sample</span>
  419. <span class="nt">kind</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">SecretStore</span>
  420. <span class="nt">target</span><span class="p">:</span>
  421. <span class="nt">name</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">secret-to-be-created</span>
  422. <span class="c1"># this is how the Kind=Secret will look like</span>
  423. <span class="nt">template</span><span class="p">:</span>
  424. <span class="nt">type</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">kubernetes.io/tls</span>
  425. <span class="nt">data</span><span class="p">:</span>
  426. <span class="nt">tls.crt</span><span class="p">:</span> <span class="s">&quot;{{</span><span class="nv"> </span><span class="s">.mysecret</span><span class="nv"> </span><span class="s">|</span><span class="nv"> </span><span class="s">pkcs12cert</span><span class="nv"> </span><span class="s">|</span><span class="nv"> </span><span class="s">pemCertificate</span><span class="nv"> </span><span class="s">}}&quot;</span>
  427. <span class="nt">tls.key</span><span class="p">:</span> <span class="s">&quot;{{</span><span class="nv"> </span><span class="s">.mysecret</span><span class="nv"> </span><span class="s">|</span><span class="nv"> </span><span class="s">pkcs12key</span><span class="nv"> </span><span class="s">|</span><span class="nv"> </span><span class="s">pemPrivateKey</span><span class="nv"> </span><span class="s">}}&quot;</span>
  428. <span class="nt">data</span><span class="p">:</span>
  429. <span class="c1"># this is a pkcs12 archive that contains</span>
  430. <span class="c1"># a cert and a private key</span>
  431. <span class="p p-Indicator">-</span> <span class="nt">secretKey</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">mysecret</span>
  432. <span class="nt">remoteRef</span><span class="p">:</span>
  433. <span class="nt">key</span><span class="p">:</span> <span class="l l-Scalar l-Scalar-Plain">example</span>
  434. </pre></div></p>
  435. <h2 id="helper-functions">Helper functions</h2>
  436. <p>We provide a bunch of convenience functions that help you transform your secrets. A secret value is a <code>[]byte</code>.</p>
  437. <table>
  438. <thead>
  439. <tr>
  440. <th>Function</th>
  441. <th>Description</th>
  442. <th>Input</th>
  443. <th>Output</th>
  444. </tr>
  445. </thead>
  446. <tbody>
  447. <tr>
  448. <td>pkcs12key</td>
  449. <td>extracts the private key from a pkcs12 archive</td>
  450. <td><code>[]byte</code></td>
  451. <td><code>[]byte</code></td>
  452. </tr>
  453. <tr>
  454. <td>pkcs12keyPass</td>
  455. <td>extracts the private key from a pkcs12 archive using the provided password</td>
  456. <td>password <code>string</code>, data <code>[]byte</code></td>
  457. <td><code>[]byte</code></td>
  458. </tr>
  459. <tr>
  460. <td>pkcs12cert</td>
  461. <td>extracts the certificate from a pkcs12 archive</td>
  462. <td><code>[]byte</code></td>
  463. <td><code>[]byte</code></td>
  464. </tr>
  465. <tr>
  466. <td>pkcs12certPass</td>
  467. <td>extracts the certificate from a pkcs12 archive using the provided password</td>
  468. <td>password <code>string</code>, data <code>[]byte</code></td>
  469. <td><code>[]byte</code></td>
  470. </tr>
  471. <tr>
  472. <td>pemPrivateKey</td>
  473. <td>PEM encodes the provided bytes as private key</td>
  474. <td><code>[]byte</code></td>
  475. <td><code>string</code></td>
  476. </tr>
  477. <tr>
  478. <td>pemCertificate</td>
  479. <td>PEM encodes the provided bytes as certificate</td>
  480. <td><code>[]byte</code></td>
  481. <td><code>string</code></td>
  482. </tr>
  483. <tr>
  484. <td>base64decode</td>
  485. <td>decodes the provided bytes as base64</td>
  486. <td><code>[]byte</code></td>
  487. <td><code>[]byte</code></td>
  488. </tr>
  489. <tr>
  490. <td>base64encode</td>
  491. <td>encodes the provided bytes as base64</td>
  492. <td><code>[]byte</code></td>
  493. <td><code>[]byte</code></td>
  494. </tr>
  495. <tr>
  496. <td>fromJSON</td>
  497. <td>parses the bytes as JSON so you can access individual properties</td>
  498. <td><code>[]byte</code></td>
  499. <td><code>interface{}</code></td>
  500. </tr>
  501. <tr>
  502. <td>toJSON</td>
  503. <td>encodes the provided object as json string</td>
  504. <td><code>interface{}</code></td>
  505. <td><code>string</code></td>
  506. </tr>
  507. <tr>
  508. <td>toString</td>
  509. <td>converts bytes to string</td>
  510. <td><code>[]byte</code></td>
  511. <td><code>string</code></td>
  512. </tr>
  513. <tr>
  514. <td>toBytes</td>
  515. <td>converts string to bytes</td>
  516. <td><code>string</code></td>
  517. <td><code>[]byte</code></td>
  518. </tr>
  519. <tr>
  520. <td>upper</td>
  521. <td>converts all characters to their upper case</td>
  522. <td><code>string</code></td>
  523. <td><code>string</code></td>
  524. </tr>
  525. <tr>
  526. <td>lower</td>
  527. <td>converts all character to their lower case</td>
  528. <td><code>string</code></td>
  529. <td><code>string</code></td>
  530. </tr>
  531. </tbody>
  532. </table>
  533. </article>
  534. </div>
  535. </div>
  536. </main>
  537. <footer class="md-footer">
  538. <div class="md-footer-nav">
  539. <nav class="md-footer-nav__inner md-grid">
  540. <a href="../guides-getting-started/" title="Getting started" class="md-flex md-footer-nav__link md-footer-nav__link--prev" rel="prev">
  541. <div class="md-flex__cell md-flex__cell--shrink">
  542. <i class="md-icon md-icon--arrow-back md-footer-nav__button"></i>
  543. </div>
  544. <div class="md-flex__cell md-flex__cell--stretch md-footer-nav__title">
  545. <span class="md-flex__ellipsis">
  546. <span class="md-footer-nav__direction">
  547. Previous
  548. </span>
  549. Getting started
  550. </span>
  551. </div>
  552. </a>
  553. <a href="../guides-multi-tenancy/" title="Multi Tenancy" class="md-flex md-footer-nav__link md-footer-nav__link--next" rel="next">
  554. <div class="md-flex__cell md-flex__cell--stretch md-footer-nav__title">
  555. <span class="md-flex__ellipsis">
  556. <span class="md-footer-nav__direction">
  557. Next
  558. </span>
  559. Multi Tenancy
  560. </span>
  561. </div>
  562. <div class="md-flex__cell md-flex__cell--shrink">
  563. <i class="md-icon md-icon--arrow-forward md-footer-nav__button"></i>
  564. </div>
  565. </a>
  566. </nav>
  567. </div>
  568. <div class="md-footer-meta md-typeset">
  569. <div class="md-footer-meta__inner md-grid">
  570. <div class="md-footer-copyright">
  571. powered by
  572. <a href="https://www.mkdocs.org">MkDocs</a>
  573. and
  574. <a href="https://squidfunk.github.io/mkdocs-material/">
  575. Material for MkDocs</a>
  576. </div>
  577. </div>
  578. </div>
  579. </footer>
  580. </div>
  581. <script src="../assets/javascripts/application.808e90bb.js"></script>
  582. <script>app.initialize({version:"1.0.4",url:{base:".."}})</script>
  583. </body>
  584. </html>