bundle.yaml 1.9 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619326203262132622326233262432625326263262732628326293263032631326323263332634326353263632637326383263932640326413264232643326443264532646326473264832649326503265132652326533265432655326563265732658326593266032661326623266332664326653266632667326683266932670326713267232673326743267532676326773267832679326803268132682326833268432685326863268732688326893269032691326923269332694326953269632697326983269932700327013270232703327043270532706327073270832709327103271132712327133271432715327163271732718327193272032721327223272332724327253272632727327283272932730327313273232733327343273532736327373273832739327403274132742327433274432745327463274732748327493275032751327523275332754327553275632757327583275932760327613276232763327643276532766327673276832769327703277132772327733277432775327763277732778327793278032781327823278332784327853278632787327883278932790327913279232793327943279532796327973279832799328003280132802328033280432805328063280732808328093281032811328123281332814328153281632817328183281932820328213282232823328243282532826328273282832829
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: Selector chooses secrets using a labelSelector.
  2067. properties:
  2068. matchExpressions:
  2069. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2070. items:
  2071. description: |-
  2072. A label selector requirement is a selector that contains values, a key, and an operator that
  2073. relates the key and values.
  2074. properties:
  2075. key:
  2076. description: key is the label key that the selector applies to.
  2077. type: string
  2078. operator:
  2079. description: |-
  2080. operator represents a key's relationship to a set of values.
  2081. Valid operators are In, NotIn, Exists and DoesNotExist.
  2082. type: string
  2083. values:
  2084. description: |-
  2085. values is an array of string values. If the operator is In or NotIn,
  2086. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2087. the values array must be empty. This array is replaced during a strategic
  2088. merge patch.
  2089. items:
  2090. type: string
  2091. type: array
  2092. x-kubernetes-list-type: atomic
  2093. required:
  2094. - key
  2095. - operator
  2096. type: object
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. matchLabels:
  2100. additionalProperties:
  2101. type: string
  2102. description: |-
  2103. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2104. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2105. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2106. type: object
  2107. type: object
  2108. x-kubernetes-map-type: atomic
  2109. type: object
  2110. type: object
  2111. template:
  2112. description: Template defines a blueprint for the created Secret resource.
  2113. properties:
  2114. data:
  2115. additionalProperties:
  2116. type: string
  2117. type: object
  2118. engineVersion:
  2119. default: v2
  2120. description: |-
  2121. EngineVersion specifies the template engine version
  2122. that should be used to compile/execute the
  2123. template specified in .data and .templateFrom[].
  2124. enum:
  2125. - v2
  2126. type: string
  2127. mergePolicy:
  2128. default: Replace
  2129. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2130. enum:
  2131. - Replace
  2132. - Merge
  2133. type: string
  2134. metadata:
  2135. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2136. properties:
  2137. annotations:
  2138. additionalProperties:
  2139. type: string
  2140. type: object
  2141. finalizers:
  2142. items:
  2143. type: string
  2144. type: array
  2145. labels:
  2146. additionalProperties:
  2147. type: string
  2148. type: object
  2149. type: object
  2150. templateFrom:
  2151. items:
  2152. description: |-
  2153. TemplateFrom specifies a source for templates.
  2154. Each item in the list can either reference a ConfigMap or a Secret resource.
  2155. properties:
  2156. configMap:
  2157. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2158. properties:
  2159. items:
  2160. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2161. items:
  2162. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2163. properties:
  2164. key:
  2165. description: A key in the ConfigMap/Secret
  2166. maxLength: 253
  2167. minLength: 1
  2168. pattern: ^[-._a-zA-Z0-9]+$
  2169. type: string
  2170. templateAs:
  2171. default: Values
  2172. description: TemplateScope specifies how the template keys should be interpreted.
  2173. enum:
  2174. - Values
  2175. - KeysAndValues
  2176. type: string
  2177. required:
  2178. - key
  2179. type: object
  2180. type: array
  2181. name:
  2182. description: The name of the ConfigMap/Secret resource
  2183. maxLength: 253
  2184. minLength: 1
  2185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2186. type: string
  2187. required:
  2188. - items
  2189. - name
  2190. type: object
  2191. literal:
  2192. type: string
  2193. secret:
  2194. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2195. properties:
  2196. items:
  2197. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2198. items:
  2199. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2200. properties:
  2201. key:
  2202. description: A key in the ConfigMap/Secret
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[-._a-zA-Z0-9]+$
  2206. type: string
  2207. templateAs:
  2208. default: Values
  2209. description: TemplateScope specifies how the template keys should be interpreted.
  2210. enum:
  2211. - Values
  2212. - KeysAndValues
  2213. type: string
  2214. required:
  2215. - key
  2216. type: object
  2217. type: array
  2218. name:
  2219. description: The name of the ConfigMap/Secret resource
  2220. maxLength: 253
  2221. minLength: 1
  2222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2223. type: string
  2224. required:
  2225. - items
  2226. - name
  2227. type: object
  2228. target:
  2229. default: Data
  2230. description: |-
  2231. Target specifies where to place the template result.
  2232. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2233. any other value is rejected because it would allow writes to privileged Secret fields.
  2234. For custom resources (when spec.target.manifest is set), this supports
  2235. nested paths like "spec.database.config" or "data".
  2236. type: string
  2237. valuesDecodingStrategy:
  2238. description: |-
  2239. Used to define a decoding Strategy for the rendered template values.
  2240. Defaults to None when omitted.
  2241. enum:
  2242. - Auto
  2243. - Base64
  2244. - Base64URL
  2245. - None
  2246. type: string
  2247. type: object
  2248. type: array
  2249. type:
  2250. type: string
  2251. type: object
  2252. updatePolicy:
  2253. default: Replace
  2254. description: UpdatePolicy to handle Secrets in the provider.
  2255. enum:
  2256. - Replace
  2257. - IfNotExists
  2258. type: string
  2259. required:
  2260. - secretStoreRefs
  2261. - selector
  2262. type: object
  2263. refreshTime:
  2264. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2265. type: string
  2266. required:
  2267. - pushSecretSpec
  2268. type: object
  2269. status:
  2270. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2271. properties:
  2272. conditions:
  2273. items:
  2274. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2275. properties:
  2276. lastTransitionTime:
  2277. format: date-time
  2278. type: string
  2279. message:
  2280. type: string
  2281. reason:
  2282. type: string
  2283. status:
  2284. type: string
  2285. type:
  2286. description: PushSecretConditionType indicates the condition of the PushSecret.
  2287. type: string
  2288. required:
  2289. - status
  2290. - type
  2291. type: object
  2292. type: array
  2293. failedNamespaces:
  2294. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2295. items:
  2296. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2297. properties:
  2298. namespace:
  2299. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2300. type: string
  2301. reason:
  2302. description: Reason is why the PushSecret failed to apply to the namespace
  2303. type: string
  2304. required:
  2305. - namespace
  2306. type: object
  2307. type: array
  2308. provisionedNamespaces:
  2309. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2310. items:
  2311. type: string
  2312. type: array
  2313. pushSecretName:
  2314. type: string
  2315. type: object
  2316. type: object
  2317. served: true
  2318. storage: true
  2319. subresources:
  2320. status: {}
  2321. ---
  2322. apiVersion: apiextensions.k8s.io/v1
  2323. kind: CustomResourceDefinition
  2324. metadata:
  2325. annotations:
  2326. controller-gen.kubebuilder.io/version: v0.19.0
  2327. labels:
  2328. external-secrets.io/component: controller
  2329. name: clustersecretstores.external-secrets.io
  2330. spec:
  2331. group: external-secrets.io
  2332. names:
  2333. categories:
  2334. - external-secrets
  2335. kind: ClusterSecretStore
  2336. listKind: ClusterSecretStoreList
  2337. plural: clustersecretstores
  2338. shortNames:
  2339. - css
  2340. singular: clustersecretstore
  2341. scope: Cluster
  2342. versions:
  2343. - additionalPrinterColumns:
  2344. - jsonPath: .metadata.creationTimestamp
  2345. name: AGE
  2346. type: date
  2347. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2348. name: Status
  2349. type: string
  2350. - jsonPath: .status.capabilities
  2351. name: Capabilities
  2352. type: string
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2354. name: Ready
  2355. type: string
  2356. name: v1
  2357. schema:
  2358. openAPIV3Schema:
  2359. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2360. properties:
  2361. apiVersion:
  2362. description: |-
  2363. APIVersion defines the versioned schema of this representation of an object.
  2364. Servers should convert recognized schemas to the latest internal value, and
  2365. may reject unrecognized values.
  2366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2367. type: string
  2368. kind:
  2369. description: |-
  2370. Kind is a string value representing the REST resource this object represents.
  2371. Servers may infer this from the endpoint the client submits requests to.
  2372. Cannot be updated.
  2373. In CamelCase.
  2374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2375. type: string
  2376. metadata:
  2377. type: object
  2378. spec:
  2379. description: SecretStoreSpec defines the desired state of SecretStore.
  2380. properties:
  2381. conditions:
  2382. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2383. items:
  2384. description: |-
  2385. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2386. for a ClusterSecretStore instance.
  2387. properties:
  2388. namespaceRegexes:
  2389. description: Choose namespaces by using regex matching
  2390. items:
  2391. type: string
  2392. type: array
  2393. namespaceSelector:
  2394. description: Choose namespace using a labelSelector
  2395. properties:
  2396. matchExpressions:
  2397. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2398. items:
  2399. description: |-
  2400. A label selector requirement is a selector that contains values, a key, and an operator that
  2401. relates the key and values.
  2402. properties:
  2403. key:
  2404. description: key is the label key that the selector applies to.
  2405. type: string
  2406. operator:
  2407. description: |-
  2408. operator represents a key's relationship to a set of values.
  2409. Valid operators are In, NotIn, Exists and DoesNotExist.
  2410. type: string
  2411. values:
  2412. description: |-
  2413. values is an array of string values. If the operator is In or NotIn,
  2414. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2415. the values array must be empty. This array is replaced during a strategic
  2416. merge patch.
  2417. items:
  2418. type: string
  2419. type: array
  2420. x-kubernetes-list-type: atomic
  2421. required:
  2422. - key
  2423. - operator
  2424. type: object
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. matchLabels:
  2428. additionalProperties:
  2429. type: string
  2430. description: |-
  2431. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2432. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2433. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2434. type: object
  2435. type: object
  2436. x-kubernetes-map-type: atomic
  2437. namespaces:
  2438. description: Choose namespaces by name
  2439. items:
  2440. maxLength: 63
  2441. minLength: 1
  2442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2443. type: string
  2444. type: array
  2445. type: object
  2446. type: array
  2447. controller:
  2448. description: |-
  2449. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2450. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2451. type: string
  2452. provider:
  2453. description: Used to configure the provider. Only one provider may be set
  2454. maxProperties: 1
  2455. minProperties: 1
  2456. properties:
  2457. akeyless:
  2458. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2459. properties:
  2460. akeylessGWApiURL:
  2461. description: Akeyless GW API Url from which the secrets to be fetched from.
  2462. type: string
  2463. authSecretRef:
  2464. description: Auth configures how the operator authenticates with Akeyless.
  2465. properties:
  2466. kubernetesAuth:
  2467. description: |-
  2468. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2469. token stored in the named Secret resource.
  2470. properties:
  2471. accessID:
  2472. description: the Akeyless Kubernetes auth-method access-id
  2473. type: string
  2474. k8sConfName:
  2475. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2476. type: string
  2477. secretRef:
  2478. description: |-
  2479. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2480. for authenticating with Akeyless. If a name is specified without a key,
  2481. `token` is the default. If one is not specified, the one bound to
  2482. the controller will be used.
  2483. properties:
  2484. key:
  2485. description: |-
  2486. A key in the referenced Secret.
  2487. Some instances of this field may be defaulted, in others it may be required.
  2488. maxLength: 253
  2489. minLength: 1
  2490. pattern: ^[-._a-zA-Z0-9]+$
  2491. type: string
  2492. name:
  2493. description: The name of the Secret resource being referred to.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2497. type: string
  2498. namespace:
  2499. description: |-
  2500. The namespace of the Secret resource being referred to.
  2501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2502. maxLength: 63
  2503. minLength: 1
  2504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2505. type: string
  2506. type: object
  2507. serviceAccountRef:
  2508. description: |-
  2509. Optional service account field containing the name of a kubernetes ServiceAccount.
  2510. If the service account is specified, the service account secret token JWT will be used
  2511. for authenticating with Akeyless. If the service account selector is not supplied,
  2512. the secretRef will be used instead.
  2513. properties:
  2514. audiences:
  2515. description: |-
  2516. Audience specifies the `aud` claim for the service account token
  2517. Some providers automatically extend the audience field based on well-known annotations for workload
  2518. identity (e.g. IRSA or GCP Workload Identity)
  2519. items:
  2520. type: string
  2521. type: array
  2522. name:
  2523. description: The name of the ServiceAccount resource being referred to.
  2524. maxLength: 253
  2525. minLength: 1
  2526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2527. type: string
  2528. namespace:
  2529. description: |-
  2530. Namespace of the resource being referred to.
  2531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2532. maxLength: 63
  2533. minLength: 1
  2534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2535. type: string
  2536. required:
  2537. - name
  2538. type: object
  2539. required:
  2540. - accessID
  2541. - k8sConfName
  2542. type: object
  2543. secretRef:
  2544. description: |-
  2545. Reference to a Secret that contains the details
  2546. to authenticate with Akeyless.
  2547. properties:
  2548. accessID:
  2549. description: The SecretAccessID is used for authentication
  2550. properties:
  2551. key:
  2552. description: |-
  2553. A key in the referenced Secret.
  2554. Some instances of this field may be defaulted, in others it may be required.
  2555. maxLength: 253
  2556. minLength: 1
  2557. pattern: ^[-._a-zA-Z0-9]+$
  2558. type: string
  2559. name:
  2560. description: The name of the Secret resource being referred to.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2564. type: string
  2565. namespace:
  2566. description: |-
  2567. The namespace of the Secret resource being referred to.
  2568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2569. maxLength: 63
  2570. minLength: 1
  2571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2572. type: string
  2573. type: object
  2574. accessType:
  2575. description: |-
  2576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2577. In some instances, `key` is a required field.
  2578. properties:
  2579. key:
  2580. description: |-
  2581. A key in the referenced Secret.
  2582. Some instances of this field may be defaulted, in others it may be required.
  2583. maxLength: 253
  2584. minLength: 1
  2585. pattern: ^[-._a-zA-Z0-9]+$
  2586. type: string
  2587. name:
  2588. description: The name of the Secret resource being referred to.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2592. type: string
  2593. namespace:
  2594. description: |-
  2595. The namespace of the Secret resource being referred to.
  2596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2597. maxLength: 63
  2598. minLength: 1
  2599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2600. type: string
  2601. type: object
  2602. accessTypeParam:
  2603. description: |-
  2604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2605. In some instances, `key` is a required field.
  2606. properties:
  2607. key:
  2608. description: |-
  2609. A key in the referenced Secret.
  2610. Some instances of this field may be defaulted, in others it may be required.
  2611. maxLength: 253
  2612. minLength: 1
  2613. pattern: ^[-._a-zA-Z0-9]+$
  2614. type: string
  2615. name:
  2616. description: The name of the Secret resource being referred to.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2620. type: string
  2621. namespace:
  2622. description: |-
  2623. The namespace of the Secret resource being referred to.
  2624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2625. maxLength: 63
  2626. minLength: 1
  2627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2628. type: string
  2629. type: object
  2630. type: object
  2631. serviceAccountRef:
  2632. description: |-
  2633. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2634. authentication on AKS Workload Identity. The operator obtains a federated
  2635. identity token from this ServiceAccount via the TokenRequest API instead
  2636. of using the ESO controller pod identity. Ignored for other access types.
  2637. properties:
  2638. audiences:
  2639. description: |-
  2640. Audience specifies the `aud` claim for the service account token
  2641. Some providers automatically extend the audience field based on well-known annotations for workload
  2642. identity (e.g. IRSA or GCP Workload Identity)
  2643. items:
  2644. type: string
  2645. type: array
  2646. name:
  2647. description: The name of the ServiceAccount resource being referred to.
  2648. maxLength: 253
  2649. minLength: 1
  2650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2651. type: string
  2652. namespace:
  2653. description: |-
  2654. Namespace of the resource being referred to.
  2655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2656. maxLength: 63
  2657. minLength: 1
  2658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2659. type: string
  2660. required:
  2661. - name
  2662. type: object
  2663. type: object
  2664. caBundle:
  2665. description: |-
  2666. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2667. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2668. are used to validate the TLS connection.
  2669. format: byte
  2670. type: string
  2671. caProvider:
  2672. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2673. properties:
  2674. key:
  2675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2676. maxLength: 253
  2677. minLength: 1
  2678. pattern: ^[-._a-zA-Z0-9]+$
  2679. type: string
  2680. name:
  2681. description: The name of the object located at the provider type.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2685. type: string
  2686. namespace:
  2687. description: |-
  2688. The namespace the Provider type is in.
  2689. Can only be defined when used in a ClusterSecretStore.
  2690. maxLength: 63
  2691. minLength: 1
  2692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2693. type: string
  2694. type:
  2695. description: The type of provider to use such as "Secret", or "ConfigMap".
  2696. enum:
  2697. - Secret
  2698. - ConfigMap
  2699. type: string
  2700. required:
  2701. - name
  2702. - type
  2703. type: object
  2704. ignoreCache:
  2705. description: |-
  2706. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2707. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2708. type: boolean
  2709. required:
  2710. - akeylessGWApiURL
  2711. - authSecretRef
  2712. type: object
  2713. aws:
  2714. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2715. properties:
  2716. additionalRoles:
  2717. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2718. items:
  2719. type: string
  2720. type: array
  2721. auth:
  2722. description: |-
  2723. Auth defines the information necessary to authenticate against AWS
  2724. if not set aws sdk will infer credentials from your environment
  2725. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2726. properties:
  2727. jwt:
  2728. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2729. properties:
  2730. serviceAccountRef:
  2731. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2732. properties:
  2733. audiences:
  2734. description: |-
  2735. Audience specifies the `aud` claim for the service account token
  2736. Some providers automatically extend the audience field based on well-known annotations for workload
  2737. identity (e.g. IRSA or GCP Workload Identity)
  2738. items:
  2739. type: string
  2740. type: array
  2741. name:
  2742. description: The name of the ServiceAccount resource being referred to.
  2743. maxLength: 253
  2744. minLength: 1
  2745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2746. type: string
  2747. namespace:
  2748. description: |-
  2749. Namespace of the resource being referred to.
  2750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2751. maxLength: 63
  2752. minLength: 1
  2753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2754. type: string
  2755. required:
  2756. - name
  2757. type: object
  2758. type: object
  2759. secretRef:
  2760. description: |-
  2761. AWSAuthSecretRef holds secret references for AWS credentials
  2762. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2763. properties:
  2764. accessKeyIDSecretRef:
  2765. description: The AccessKeyID is used for authentication
  2766. properties:
  2767. key:
  2768. description: |-
  2769. A key in the referenced Secret.
  2770. Some instances of this field may be defaulted, in others it may be required.
  2771. maxLength: 253
  2772. minLength: 1
  2773. pattern: ^[-._a-zA-Z0-9]+$
  2774. type: string
  2775. name:
  2776. description: The name of the Secret resource being referred to.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2780. type: string
  2781. namespace:
  2782. description: |-
  2783. The namespace of the Secret resource being referred to.
  2784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2785. maxLength: 63
  2786. minLength: 1
  2787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2788. type: string
  2789. type: object
  2790. secretAccessKeySecretRef:
  2791. description: The SecretAccessKey is used for authentication
  2792. properties:
  2793. key:
  2794. description: |-
  2795. A key in the referenced Secret.
  2796. Some instances of this field may be defaulted, in others it may be required.
  2797. maxLength: 253
  2798. minLength: 1
  2799. pattern: ^[-._a-zA-Z0-9]+$
  2800. type: string
  2801. name:
  2802. description: The name of the Secret resource being referred to.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2806. type: string
  2807. namespace:
  2808. description: |-
  2809. The namespace of the Secret resource being referred to.
  2810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2811. maxLength: 63
  2812. minLength: 1
  2813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2814. type: string
  2815. type: object
  2816. sessionTokenSecretRef:
  2817. description: |-
  2818. The SessionToken used for authentication
  2819. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2820. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2821. properties:
  2822. key:
  2823. description: |-
  2824. A key in the referenced Secret.
  2825. Some instances of this field may be defaulted, in others it may be required.
  2826. maxLength: 253
  2827. minLength: 1
  2828. pattern: ^[-._a-zA-Z0-9]+$
  2829. type: string
  2830. name:
  2831. description: The name of the Secret resource being referred to.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2835. type: string
  2836. namespace:
  2837. description: |-
  2838. The namespace of the Secret resource being referred to.
  2839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2840. maxLength: 63
  2841. minLength: 1
  2842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2843. type: string
  2844. type: object
  2845. type: object
  2846. type: object
  2847. customSessionTags:
  2848. additionalProperties:
  2849. type: string
  2850. description: |-
  2851. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2852. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2853. type: object
  2854. x-kubernetes-validations:
  2855. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2856. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2857. externalID:
  2858. description: AWS External ID set on assumed IAM roles
  2859. type: string
  2860. prefix:
  2861. description: Prefix adds a prefix to all retrieved values.
  2862. type: string
  2863. region:
  2864. description: AWS Region to be used for the provider
  2865. type: string
  2866. role:
  2867. description: Role is a Role ARN which the provider will assume
  2868. type: string
  2869. secretsManager:
  2870. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2871. properties:
  2872. forceDeleteWithoutRecovery:
  2873. description: |-
  2874. Specifies whether to delete the secret without any recovery window. You
  2875. can't use both this parameter and RecoveryWindowInDays in the same call.
  2876. If you don't use either, then by default Secrets Manager uses a 30 day
  2877. recovery window.
  2878. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2879. type: boolean
  2880. recoveryWindowInDays:
  2881. description: |-
  2882. The number of days from 7 to 30 that Secrets Manager waits before
  2883. permanently deleting the secret. You can't use both this parameter and
  2884. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2885. then by default Secrets Manager uses a 30-day recovery window.
  2886. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2887. format: int64
  2888. type: integer
  2889. type: object
  2890. service:
  2891. description: Service defines which service should be used to fetch the secrets
  2892. enum:
  2893. - SecretsManager
  2894. - ParameterStore
  2895. - CertificateManager
  2896. type: string
  2897. sessionTags:
  2898. description: AWS STS assume role session tags
  2899. items:
  2900. description: |-
  2901. Tag is a key-value pair that can be attached to an AWS resource.
  2902. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2903. properties:
  2904. key:
  2905. type: string
  2906. value:
  2907. type: string
  2908. required:
  2909. - key
  2910. - value
  2911. type: object
  2912. type: array
  2913. sessionTagsPolicy:
  2914. default: None
  2915. description: |-
  2916. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2917. None (default): no tags are added.
  2918. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2919. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2920. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2921. enum:
  2922. - None
  2923. - Simple
  2924. - Custom
  2925. type: string
  2926. transitiveTagKeys:
  2927. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2928. items:
  2929. type: string
  2930. type: array
  2931. required:
  2932. - region
  2933. - service
  2934. type: object
  2935. azurekv:
  2936. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2937. properties:
  2938. authSecretRef:
  2939. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2940. properties:
  2941. clientCertificate:
  2942. description: The Azure ClientCertificate of the service principle used for authentication.
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. clientId:
  2968. description: The Azure clientId of the service principle or managed identity used for authentication.
  2969. properties:
  2970. key:
  2971. description: |-
  2972. A key in the referenced Secret.
  2973. Some instances of this field may be defaulted, in others it may be required.
  2974. maxLength: 253
  2975. minLength: 1
  2976. pattern: ^[-._a-zA-Z0-9]+$
  2977. type: string
  2978. name:
  2979. description: The name of the Secret resource being referred to.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2983. type: string
  2984. namespace:
  2985. description: |-
  2986. The namespace of the Secret resource being referred to.
  2987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2988. maxLength: 63
  2989. minLength: 1
  2990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2991. type: string
  2992. type: object
  2993. clientSecret:
  2994. description: The Azure ClientSecret of the service principle used for authentication.
  2995. properties:
  2996. key:
  2997. description: |-
  2998. A key in the referenced Secret.
  2999. Some instances of this field may be defaulted, in others it may be required.
  3000. maxLength: 253
  3001. minLength: 1
  3002. pattern: ^[-._a-zA-Z0-9]+$
  3003. type: string
  3004. name:
  3005. description: The name of the Secret resource being referred to.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3009. type: string
  3010. namespace:
  3011. description: |-
  3012. The namespace of the Secret resource being referred to.
  3013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3014. maxLength: 63
  3015. minLength: 1
  3016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3017. type: string
  3018. type: object
  3019. tenantId:
  3020. description: The Azure tenantId of the managed identity used for authentication.
  3021. properties:
  3022. key:
  3023. description: |-
  3024. A key in the referenced Secret.
  3025. Some instances of this field may be defaulted, in others it may be required.
  3026. maxLength: 253
  3027. minLength: 1
  3028. pattern: ^[-._a-zA-Z0-9]+$
  3029. type: string
  3030. name:
  3031. description: The name of the Secret resource being referred to.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3035. type: string
  3036. namespace:
  3037. description: |-
  3038. The namespace of the Secret resource being referred to.
  3039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3040. maxLength: 63
  3041. minLength: 1
  3042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3043. type: string
  3044. type: object
  3045. type: object
  3046. authType:
  3047. default: ServicePrincipal
  3048. description: |-
  3049. Auth type defines how to authenticate to the keyvault service.
  3050. Valid values are:
  3051. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3052. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3053. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3054. enum:
  3055. - ServicePrincipal
  3056. - ManagedIdentity
  3057. - WorkloadIdentity
  3058. type: string
  3059. customCloudConfig:
  3060. description: |-
  3061. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3062. Required when EnvironmentType is AzureStackCloud.
  3063. Optional for other environment types - useful for Azure China when using Workload Identity
  3064. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3065. standard China Cloud endpoint (login.chinacloudapi.cn).
  3066. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3067. configuration is not supported with the legacy go-autorest SDK.
  3068. properties:
  3069. activeDirectoryEndpoint:
  3070. description: |-
  3071. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3072. Required when using custom cloud configuration
  3073. type: string
  3074. keyVaultDNSSuffix:
  3075. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3076. type: string
  3077. keyVaultEndpoint:
  3078. description: KeyVaultEndpoint is the Key Vault service endpoint
  3079. type: string
  3080. resourceManagerEndpoint:
  3081. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3082. type: string
  3083. required:
  3084. - activeDirectoryEndpoint
  3085. type: object
  3086. environmentType:
  3087. default: PublicCloud
  3088. description: |-
  3089. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3090. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3091. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3092. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3093. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3094. enum:
  3095. - PublicCloud
  3096. - USGovernmentCloud
  3097. - ChinaCloud
  3098. - GermanCloud
  3099. - AzureStackCloud
  3100. type: string
  3101. identityId:
  3102. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3103. type: string
  3104. serviceAccountRef:
  3105. description: |-
  3106. ServiceAccountRef specified the service account
  3107. that should be used when authenticating with WorkloadIdentity.
  3108. properties:
  3109. audiences:
  3110. description: |-
  3111. Audience specifies the `aud` claim for the service account token
  3112. Some providers automatically extend the audience field based on well-known annotations for workload
  3113. identity (e.g. IRSA or GCP Workload Identity)
  3114. items:
  3115. type: string
  3116. type: array
  3117. name:
  3118. description: The name of the ServiceAccount resource being referred to.
  3119. maxLength: 253
  3120. minLength: 1
  3121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3122. type: string
  3123. namespace:
  3124. description: |-
  3125. Namespace of the resource being referred to.
  3126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3127. maxLength: 63
  3128. minLength: 1
  3129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3130. type: string
  3131. required:
  3132. - name
  3133. type: object
  3134. tenantId:
  3135. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3136. type: string
  3137. useAzureSDK:
  3138. default: false
  3139. description: |-
  3140. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3141. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3142. type: boolean
  3143. vaultUrl:
  3144. description: Vault Url from which the secrets to be fetched from.
  3145. type: string
  3146. required:
  3147. - vaultUrl
  3148. type: object
  3149. barbican:
  3150. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3151. properties:
  3152. auth:
  3153. description: BarbicanAuth contains the authentication information for Barbican.
  3154. properties:
  3155. password:
  3156. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3157. properties:
  3158. secretRef:
  3159. description: |-
  3160. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3161. In some instances, `key` is a required field.
  3162. properties:
  3163. key:
  3164. description: |-
  3165. A key in the referenced Secret.
  3166. Some instances of this field may be defaulted, in others it may be required.
  3167. maxLength: 253
  3168. minLength: 1
  3169. pattern: ^[-._a-zA-Z0-9]+$
  3170. type: string
  3171. name:
  3172. description: The name of the Secret resource being referred to.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3176. type: string
  3177. namespace:
  3178. description: |-
  3179. The namespace of the Secret resource being referred to.
  3180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3181. maxLength: 63
  3182. minLength: 1
  3183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3184. type: string
  3185. type: object
  3186. required:
  3187. - secretRef
  3188. type: object
  3189. username:
  3190. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3191. maxProperties: 1
  3192. minProperties: 1
  3193. properties:
  3194. secretRef:
  3195. description: |-
  3196. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3197. In some instances, `key` is a required field.
  3198. properties:
  3199. key:
  3200. description: |-
  3201. A key in the referenced Secret.
  3202. Some instances of this field may be defaulted, in others it may be required.
  3203. maxLength: 253
  3204. minLength: 1
  3205. pattern: ^[-._a-zA-Z0-9]+$
  3206. type: string
  3207. name:
  3208. description: The name of the Secret resource being referred to.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3212. type: string
  3213. namespace:
  3214. description: |-
  3215. The namespace of the Secret resource being referred to.
  3216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3217. maxLength: 63
  3218. minLength: 1
  3219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3220. type: string
  3221. type: object
  3222. value:
  3223. type: string
  3224. type: object
  3225. required:
  3226. - password
  3227. - username
  3228. type: object
  3229. authURL:
  3230. type: string
  3231. domainName:
  3232. type: string
  3233. region:
  3234. type: string
  3235. tenantName:
  3236. type: string
  3237. required:
  3238. - auth
  3239. type: object
  3240. beyondtrust:
  3241. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3242. properties:
  3243. auth:
  3244. description: Auth configures how the operator authenticates with Beyondtrust.
  3245. properties:
  3246. apiKey:
  3247. description: APIKey If not provided then ClientID/ClientSecret become required.
  3248. properties:
  3249. secretRef:
  3250. description: SecretRef references a key in a secret that will be used as value.
  3251. properties:
  3252. key:
  3253. description: |-
  3254. A key in the referenced Secret.
  3255. Some instances of this field may be defaulted, in others it may be required.
  3256. maxLength: 253
  3257. minLength: 1
  3258. pattern: ^[-._a-zA-Z0-9]+$
  3259. type: string
  3260. name:
  3261. description: The name of the Secret resource being referred to.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3265. type: string
  3266. namespace:
  3267. description: |-
  3268. The namespace of the Secret resource being referred to.
  3269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3270. maxLength: 63
  3271. minLength: 1
  3272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3273. type: string
  3274. type: object
  3275. value:
  3276. description: Value can be specified directly to set a value without using a secret.
  3277. type: string
  3278. type: object
  3279. certificate:
  3280. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3281. properties:
  3282. secretRef:
  3283. description: SecretRef references a key in a secret that will be used as value.
  3284. properties:
  3285. key:
  3286. description: |-
  3287. A key in the referenced Secret.
  3288. Some instances of this field may be defaulted, in others it may be required.
  3289. maxLength: 253
  3290. minLength: 1
  3291. pattern: ^[-._a-zA-Z0-9]+$
  3292. type: string
  3293. name:
  3294. description: The name of the Secret resource being referred to.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3298. type: string
  3299. namespace:
  3300. description: |-
  3301. The namespace of the Secret resource being referred to.
  3302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3303. maxLength: 63
  3304. minLength: 1
  3305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3306. type: string
  3307. type: object
  3308. value:
  3309. description: Value can be specified directly to set a value without using a secret.
  3310. type: string
  3311. type: object
  3312. certificateKey:
  3313. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3314. properties:
  3315. secretRef:
  3316. description: SecretRef references a key in a secret that will be used as value.
  3317. properties:
  3318. key:
  3319. description: |-
  3320. A key in the referenced Secret.
  3321. Some instances of this field may be defaulted, in others it may be required.
  3322. maxLength: 253
  3323. minLength: 1
  3324. pattern: ^[-._a-zA-Z0-9]+$
  3325. type: string
  3326. name:
  3327. description: The name of the Secret resource being referred to.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3331. type: string
  3332. namespace:
  3333. description: |-
  3334. The namespace of the Secret resource being referred to.
  3335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3336. maxLength: 63
  3337. minLength: 1
  3338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3339. type: string
  3340. type: object
  3341. value:
  3342. description: Value can be specified directly to set a value without using a secret.
  3343. type: string
  3344. type: object
  3345. clientId:
  3346. description: ClientID is the API OAuth Client ID.
  3347. properties:
  3348. secretRef:
  3349. description: SecretRef references a key in a secret that will be used as value.
  3350. properties:
  3351. key:
  3352. description: |-
  3353. A key in the referenced Secret.
  3354. Some instances of this field may be defaulted, in others it may be required.
  3355. maxLength: 253
  3356. minLength: 1
  3357. pattern: ^[-._a-zA-Z0-9]+$
  3358. type: string
  3359. name:
  3360. description: The name of the Secret resource being referred to.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3364. type: string
  3365. namespace:
  3366. description: |-
  3367. The namespace of the Secret resource being referred to.
  3368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3369. maxLength: 63
  3370. minLength: 1
  3371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3372. type: string
  3373. type: object
  3374. value:
  3375. description: Value can be specified directly to set a value without using a secret.
  3376. type: string
  3377. type: object
  3378. clientSecret:
  3379. description: ClientSecret is the API OAuth Client Secret.
  3380. properties:
  3381. secretRef:
  3382. description: SecretRef references a key in a secret that will be used as value.
  3383. properties:
  3384. key:
  3385. description: |-
  3386. A key in the referenced Secret.
  3387. Some instances of this field may be defaulted, in others it may be required.
  3388. maxLength: 253
  3389. minLength: 1
  3390. pattern: ^[-._a-zA-Z0-9]+$
  3391. type: string
  3392. name:
  3393. description: The name of the Secret resource being referred to.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3397. type: string
  3398. namespace:
  3399. description: |-
  3400. The namespace of the Secret resource being referred to.
  3401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3402. maxLength: 63
  3403. minLength: 1
  3404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3405. type: string
  3406. type: object
  3407. value:
  3408. description: Value can be specified directly to set a value without using a secret.
  3409. type: string
  3410. type: object
  3411. type: object
  3412. server:
  3413. description: Auth configures how API server works.
  3414. properties:
  3415. apiUrl:
  3416. type: string
  3417. apiVersion:
  3418. type: string
  3419. clientTimeOutSeconds:
  3420. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3421. type: integer
  3422. decrypt:
  3423. default: true
  3424. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3425. type: boolean
  3426. retrievalType:
  3427. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3428. type: string
  3429. separator:
  3430. description: A character that separates the folder names.
  3431. type: string
  3432. verifyCA:
  3433. type: boolean
  3434. required:
  3435. - apiUrl
  3436. - verifyCA
  3437. type: object
  3438. required:
  3439. - auth
  3440. - server
  3441. type: object
  3442. beyondtrustworkloadcredentials:
  3443. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3444. properties:
  3445. auth:
  3446. description: |-
  3447. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3448. Currently supports API key authentication via Kubernetes secret reference.
  3449. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3450. properties:
  3451. apikey:
  3452. description: |-
  3453. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3454. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3455. properties:
  3456. token:
  3457. description: |-
  3458. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3459. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3460. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3461. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3462. properties:
  3463. key:
  3464. description: |-
  3465. A key in the referenced Secret.
  3466. Some instances of this field may be defaulted, in others it may be required.
  3467. maxLength: 253
  3468. minLength: 1
  3469. pattern: ^[-._a-zA-Z0-9]+$
  3470. type: string
  3471. name:
  3472. description: The name of the Secret resource being referred to.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3476. type: string
  3477. namespace:
  3478. description: |-
  3479. The namespace of the Secret resource being referred to.
  3480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3481. maxLength: 63
  3482. minLength: 1
  3483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3484. type: string
  3485. type: object
  3486. required:
  3487. - token
  3488. type: object
  3489. required:
  3490. - apikey
  3491. type: object
  3492. caBundle:
  3493. description: |-
  3494. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3495. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3496. If not set, the system's trusted root certificates are used.
  3497. format: byte
  3498. type: string
  3499. caProvider:
  3500. description: |-
  3501. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3502. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3503. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3504. properties:
  3505. key:
  3506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3507. maxLength: 253
  3508. minLength: 1
  3509. pattern: ^[-._a-zA-Z0-9]+$
  3510. type: string
  3511. name:
  3512. description: The name of the object located at the provider type.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3516. type: string
  3517. namespace:
  3518. description: |-
  3519. The namespace the Provider type is in.
  3520. Can only be defined when used in a ClusterSecretStore.
  3521. maxLength: 63
  3522. minLength: 1
  3523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3524. type: string
  3525. type:
  3526. description: The type of provider to use such as "Secret", or "ConfigMap".
  3527. enum:
  3528. - Secret
  3529. - ConfigMap
  3530. type: string
  3531. required:
  3532. - name
  3533. - type
  3534. type: object
  3535. folderPath:
  3536. description: |-
  3537. FolderPath specifies the default folder path for secret retrieval.
  3538. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3539. Example: "production/database" or "dev/api-keys"
  3540. Leave empty to retrieve secrets from the root folder.
  3541. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3542. type: string
  3543. server:
  3544. description: |-
  3545. Server configures the BeyondTrust Workload Credentials server connection details.
  3546. Includes the API URL and Site ID for your BeyondTrust instance.
  3547. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3548. properties:
  3549. apiUrl:
  3550. description: |-
  3551. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3552. This should be the full URL to your BeyondTrust instance.
  3553. Example: https://api.beyondtrust.io/siie
  3554. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3555. type: string
  3556. siteId:
  3557. description: |-
  3558. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3559. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3560. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3561. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3562. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3563. type: string
  3564. required:
  3565. - apiUrl
  3566. - siteId
  3567. type: object
  3568. required:
  3569. - auth
  3570. - server
  3571. type: object
  3572. bitwardensecretsmanager:
  3573. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3574. properties:
  3575. apiURL:
  3576. type: string
  3577. auth:
  3578. description: |-
  3579. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3580. Make sure that the token being used has permissions on the given secret.
  3581. properties:
  3582. secretRef:
  3583. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3584. properties:
  3585. credentials:
  3586. description: AccessToken used for the bitwarden instance.
  3587. properties:
  3588. key:
  3589. description: |-
  3590. A key in the referenced Secret.
  3591. Some instances of this field may be defaulted, in others it may be required.
  3592. maxLength: 253
  3593. minLength: 1
  3594. pattern: ^[-._a-zA-Z0-9]+$
  3595. type: string
  3596. name:
  3597. description: The name of the Secret resource being referred to.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3601. type: string
  3602. namespace:
  3603. description: |-
  3604. The namespace of the Secret resource being referred to.
  3605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3606. maxLength: 63
  3607. minLength: 1
  3608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3609. type: string
  3610. type: object
  3611. required:
  3612. - credentials
  3613. type: object
  3614. required:
  3615. - secretRef
  3616. type: object
  3617. bitwardenServerSDKURL:
  3618. type: string
  3619. caBundle:
  3620. description: |-
  3621. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3622. can be performed.
  3623. type: string
  3624. caProvider:
  3625. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3626. properties:
  3627. key:
  3628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3629. maxLength: 253
  3630. minLength: 1
  3631. pattern: ^[-._a-zA-Z0-9]+$
  3632. type: string
  3633. name:
  3634. description: The name of the object located at the provider type.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3638. type: string
  3639. namespace:
  3640. description: |-
  3641. The namespace the Provider type is in.
  3642. Can only be defined when used in a ClusterSecretStore.
  3643. maxLength: 63
  3644. minLength: 1
  3645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3646. type: string
  3647. type:
  3648. description: The type of provider to use such as "Secret", or "ConfigMap".
  3649. enum:
  3650. - Secret
  3651. - ConfigMap
  3652. type: string
  3653. required:
  3654. - name
  3655. - type
  3656. type: object
  3657. identityURL:
  3658. type: string
  3659. organizationID:
  3660. description: OrganizationID determines which organization this secret store manages.
  3661. type: string
  3662. projectID:
  3663. description: ProjectID determines which project this secret store manages.
  3664. type: string
  3665. required:
  3666. - auth
  3667. - organizationID
  3668. - projectID
  3669. type: object
  3670. chef:
  3671. description: Chef configures this store to sync secrets with chef server
  3672. properties:
  3673. auth:
  3674. description: Auth defines the information necessary to authenticate against chef Server
  3675. properties:
  3676. secretRef:
  3677. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3678. properties:
  3679. privateKeySecretRef:
  3680. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3681. properties:
  3682. key:
  3683. description: |-
  3684. A key in the referenced Secret.
  3685. Some instances of this field may be defaulted, in others it may be required.
  3686. maxLength: 253
  3687. minLength: 1
  3688. pattern: ^[-._a-zA-Z0-9]+$
  3689. type: string
  3690. name:
  3691. description: The name of the Secret resource being referred to.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3695. type: string
  3696. namespace:
  3697. description: |-
  3698. The namespace of the Secret resource being referred to.
  3699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3700. maxLength: 63
  3701. minLength: 1
  3702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3703. type: string
  3704. type: object
  3705. required:
  3706. - privateKeySecretRef
  3707. type: object
  3708. required:
  3709. - secretRef
  3710. type: object
  3711. serverUrl:
  3712. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3713. type: string
  3714. username:
  3715. description: UserName should be the user ID on the chef server
  3716. type: string
  3717. required:
  3718. - auth
  3719. - serverUrl
  3720. - username
  3721. type: object
  3722. cloudrusm:
  3723. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3724. properties:
  3725. auth:
  3726. description: CSMAuth contains a secretRef for credentials.
  3727. properties:
  3728. secretRef:
  3729. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3730. properties:
  3731. accessKeyIDSecretRef:
  3732. description: The AccessKeyID is used for authentication
  3733. properties:
  3734. key:
  3735. description: |-
  3736. A key in the referenced Secret.
  3737. Some instances of this field may be defaulted, in others it may be required.
  3738. maxLength: 253
  3739. minLength: 1
  3740. pattern: ^[-._a-zA-Z0-9]+$
  3741. type: string
  3742. name:
  3743. description: The name of the Secret resource being referred to.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3747. type: string
  3748. namespace:
  3749. description: |-
  3750. The namespace of the Secret resource being referred to.
  3751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3752. maxLength: 63
  3753. minLength: 1
  3754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3755. type: string
  3756. type: object
  3757. accessKeySecretSecretRef:
  3758. description: The AccessKeySecret is used for authentication
  3759. properties:
  3760. key:
  3761. description: |-
  3762. A key in the referenced Secret.
  3763. Some instances of this field may be defaulted, in others it may be required.
  3764. maxLength: 253
  3765. minLength: 1
  3766. pattern: ^[-._a-zA-Z0-9]+$
  3767. type: string
  3768. name:
  3769. description: The name of the Secret resource being referred to.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3773. type: string
  3774. namespace:
  3775. description: |-
  3776. The namespace of the Secret resource being referred to.
  3777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3778. maxLength: 63
  3779. minLength: 1
  3780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3781. type: string
  3782. type: object
  3783. required:
  3784. - accessKeyIDSecretRef
  3785. - accessKeySecretSecretRef
  3786. type: object
  3787. type: object
  3788. projectID:
  3789. description: ProjectID is the project, which the secrets are stored in.
  3790. type: string
  3791. required:
  3792. - auth
  3793. type: object
  3794. conjur:
  3795. description: Conjur configures this store to sync secrets using conjur provider
  3796. properties:
  3797. auth:
  3798. description: Defines authentication settings for connecting to Conjur.
  3799. maxProperties: 1
  3800. minProperties: 1
  3801. properties:
  3802. apikey:
  3803. description: Authenticates with Conjur using an API key.
  3804. properties:
  3805. account:
  3806. description: Account is the Conjur organization account name.
  3807. type: string
  3808. apiKeyRef:
  3809. description: |-
  3810. A reference to a specific 'key' containing the Conjur API key
  3811. within a Secret resource. In some instances, `key` is a required field.
  3812. properties:
  3813. key:
  3814. description: |-
  3815. A key in the referenced Secret.
  3816. Some instances of this field may be defaulted, in others it may be required.
  3817. maxLength: 253
  3818. minLength: 1
  3819. pattern: ^[-._a-zA-Z0-9]+$
  3820. type: string
  3821. name:
  3822. description: The name of the Secret resource being referred to.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3826. type: string
  3827. namespace:
  3828. description: |-
  3829. The namespace of the Secret resource being referred to.
  3830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3831. maxLength: 63
  3832. minLength: 1
  3833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3834. type: string
  3835. type: object
  3836. userRef:
  3837. description: |-
  3838. A reference to a specific 'key' containing the Conjur username
  3839. within a Secret resource. In some instances, `key` is a required field.
  3840. properties:
  3841. key:
  3842. description: |-
  3843. A key in the referenced Secret.
  3844. Some instances of this field may be defaulted, in others it may be required.
  3845. maxLength: 253
  3846. minLength: 1
  3847. pattern: ^[-._a-zA-Z0-9]+$
  3848. type: string
  3849. name:
  3850. description: The name of the Secret resource being referred to.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3854. type: string
  3855. namespace:
  3856. description: |-
  3857. The namespace of the Secret resource being referred to.
  3858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3859. maxLength: 63
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3862. type: string
  3863. type: object
  3864. required:
  3865. - account
  3866. - apiKeyRef
  3867. - userRef
  3868. type: object
  3869. cert:
  3870. description: Cert enables certificate-based authentication using a client certificate and key.
  3871. properties:
  3872. account:
  3873. description: Account is the Conjur organization account name.
  3874. type: string
  3875. clientCertRef:
  3876. description: |-
  3877. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3878. within a Secret resource. The certificate must be PEM-encoded.
  3879. properties:
  3880. key:
  3881. description: |-
  3882. A key in the referenced Secret.
  3883. Some instances of this field may be defaulted, in others it may be required.
  3884. maxLength: 253
  3885. minLength: 1
  3886. pattern: ^[-._a-zA-Z0-9]+$
  3887. type: string
  3888. name:
  3889. description: The name of the Secret resource being referred to.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3893. type: string
  3894. namespace:
  3895. description: |-
  3896. The namespace of the Secret resource being referred to.
  3897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3898. maxLength: 63
  3899. minLength: 1
  3900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3901. type: string
  3902. type: object
  3903. clientKeyRef:
  3904. description: |-
  3905. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3906. within a Secret resource. The key must be PEM-encoded.
  3907. properties:
  3908. key:
  3909. description: |-
  3910. A key in the referenced Secret.
  3911. Some instances of this field may be defaulted, in others it may be required.
  3912. maxLength: 253
  3913. minLength: 1
  3914. pattern: ^[-._a-zA-Z0-9]+$
  3915. type: string
  3916. name:
  3917. description: The name of the Secret resource being referred to.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3921. type: string
  3922. namespace:
  3923. description: |-
  3924. The namespace of the Secret resource being referred to.
  3925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3926. maxLength: 63
  3927. minLength: 1
  3928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3929. type: string
  3930. type: object
  3931. hostId:
  3932. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3933. type: string
  3934. serviceID:
  3935. description: The conjur authn cert webservice id
  3936. type: string
  3937. required:
  3938. - account
  3939. - clientCertRef
  3940. - clientKeyRef
  3941. - serviceID
  3942. type: object
  3943. jwt:
  3944. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3945. properties:
  3946. account:
  3947. description: Account is the Conjur organization account name.
  3948. type: string
  3949. hostId:
  3950. description: |-
  3951. Optional HostID for JWT authentication. This may be used depending
  3952. on how the Conjur JWT authenticator policy is configured.
  3953. type: string
  3954. secretRef:
  3955. description: |-
  3956. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3957. authenticate with Conjur using the JWT authentication method.
  3958. properties:
  3959. key:
  3960. description: |-
  3961. A key in the referenced Secret.
  3962. Some instances of this field may be defaulted, in others it may be required.
  3963. maxLength: 253
  3964. minLength: 1
  3965. pattern: ^[-._a-zA-Z0-9]+$
  3966. type: string
  3967. name:
  3968. description: The name of the Secret resource being referred to.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3972. type: string
  3973. namespace:
  3974. description: |-
  3975. The namespace of the Secret resource being referred to.
  3976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3977. maxLength: 63
  3978. minLength: 1
  3979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3980. type: string
  3981. type: object
  3982. serviceAccountRef:
  3983. description: |-
  3984. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3985. a token for with the `TokenRequest` API.
  3986. properties:
  3987. audiences:
  3988. description: |-
  3989. Audience specifies the `aud` claim for the service account token
  3990. Some providers automatically extend the audience field based on well-known annotations for workload
  3991. identity (e.g. IRSA or GCP Workload Identity)
  3992. items:
  3993. type: string
  3994. type: array
  3995. name:
  3996. description: The name of the ServiceAccount resource being referred to.
  3997. maxLength: 253
  3998. minLength: 1
  3999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4000. type: string
  4001. namespace:
  4002. description: |-
  4003. Namespace of the resource being referred to.
  4004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4005. maxLength: 63
  4006. minLength: 1
  4007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4008. type: string
  4009. required:
  4010. - name
  4011. type: object
  4012. serviceID:
  4013. description: The conjur authn jwt webservice id
  4014. type: string
  4015. required:
  4016. - account
  4017. - serviceID
  4018. type: object
  4019. type: object
  4020. caBundle:
  4021. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4022. type: string
  4023. caProvider:
  4024. description: |-
  4025. Used to provide custom certificate authority (CA) certificates
  4026. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4027. that contains a PEM-encoded certificate.
  4028. properties:
  4029. key:
  4030. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4031. maxLength: 253
  4032. minLength: 1
  4033. pattern: ^[-._a-zA-Z0-9]+$
  4034. type: string
  4035. name:
  4036. description: The name of the object located at the provider type.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4040. type: string
  4041. namespace:
  4042. description: |-
  4043. The namespace the Provider type is in.
  4044. Can only be defined when used in a ClusterSecretStore.
  4045. maxLength: 63
  4046. minLength: 1
  4047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4048. type: string
  4049. type:
  4050. description: The type of provider to use such as "Secret", or "ConfigMap".
  4051. enum:
  4052. - Secret
  4053. - ConfigMap
  4054. type: string
  4055. required:
  4056. - name
  4057. - type
  4058. type: object
  4059. url:
  4060. description: URL is the endpoint of the Conjur instance.
  4061. type: string
  4062. required:
  4063. - auth
  4064. - url
  4065. type: object
  4066. crd:
  4067. description: |-
  4068. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4069. including both custom resources (CRDs) and core API resources. Resources are
  4070. selected by API group, version and kind, where group can be "" (empty string)
  4071. for core resources such as ConfigMap. Reading the core v1 Secret is
  4072. intentionally blocked — use the Kubernetes provider for that.
  4073. properties:
  4074. auth:
  4075. description: |-
  4076. Auth configures authentication to the Kubernetes API, same as the
  4077. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4078. maxProperties: 1
  4079. minProperties: 1
  4080. properties:
  4081. cert:
  4082. description: has both clientCert and clientKey as secretKeySelector
  4083. properties:
  4084. clientCert:
  4085. description: |-
  4086. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4087. In some instances, `key` is a required field.
  4088. properties:
  4089. key:
  4090. description: |-
  4091. A key in the referenced Secret.
  4092. Some instances of this field may be defaulted, in others it may be required.
  4093. maxLength: 253
  4094. minLength: 1
  4095. pattern: ^[-._a-zA-Z0-9]+$
  4096. type: string
  4097. name:
  4098. description: The name of the Secret resource being referred to.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4102. type: string
  4103. namespace:
  4104. description: |-
  4105. The namespace of the Secret resource being referred to.
  4106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4107. maxLength: 63
  4108. minLength: 1
  4109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4110. type: string
  4111. type: object
  4112. clientKey:
  4113. description: |-
  4114. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4115. In some instances, `key` is a required field.
  4116. properties:
  4117. key:
  4118. description: |-
  4119. A key in the referenced Secret.
  4120. Some instances of this field may be defaulted, in others it may be required.
  4121. maxLength: 253
  4122. minLength: 1
  4123. pattern: ^[-._a-zA-Z0-9]+$
  4124. type: string
  4125. name:
  4126. description: The name of the Secret resource being referred to.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4130. type: string
  4131. namespace:
  4132. description: |-
  4133. The namespace of the Secret resource being referred to.
  4134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4135. maxLength: 63
  4136. minLength: 1
  4137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4138. type: string
  4139. type: object
  4140. required:
  4141. - clientCert
  4142. - clientKey
  4143. type: object
  4144. serviceAccount:
  4145. description: points to a service account that should be used for authentication
  4146. properties:
  4147. audiences:
  4148. description: |-
  4149. Audience specifies the `aud` claim for the service account token
  4150. Some providers automatically extend the audience field based on well-known annotations for workload
  4151. identity (e.g. IRSA or GCP Workload Identity)
  4152. items:
  4153. type: string
  4154. type: array
  4155. name:
  4156. description: The name of the ServiceAccount resource being referred to.
  4157. maxLength: 253
  4158. minLength: 1
  4159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4160. type: string
  4161. namespace:
  4162. description: |-
  4163. Namespace of the resource being referred to.
  4164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4165. maxLength: 63
  4166. minLength: 1
  4167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4168. type: string
  4169. required:
  4170. - name
  4171. type: object
  4172. token:
  4173. description: use static token to authenticate with
  4174. properties:
  4175. bearerToken:
  4176. description: |-
  4177. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4178. In some instances, `key` is a required field.
  4179. properties:
  4180. key:
  4181. description: |-
  4182. A key in the referenced Secret.
  4183. Some instances of this field may be defaulted, in others it may be required.
  4184. maxLength: 253
  4185. minLength: 1
  4186. pattern: ^[-._a-zA-Z0-9]+$
  4187. type: string
  4188. name:
  4189. description: The name of the Secret resource being referred to.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4193. type: string
  4194. namespace:
  4195. description: |-
  4196. The namespace of the Secret resource being referred to.
  4197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4198. maxLength: 63
  4199. minLength: 1
  4200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4201. type: string
  4202. type: object
  4203. required:
  4204. - bearerToken
  4205. type: object
  4206. type: object
  4207. authRef:
  4208. description: |-
  4209. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4210. Kubernetes provider.
  4211. properties:
  4212. key:
  4213. description: |-
  4214. A key in the referenced Secret.
  4215. Some instances of this field may be defaulted, in others it may be required.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[-._a-zA-Z0-9]+$
  4219. type: string
  4220. name:
  4221. description: The name of the Secret resource being referred to.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4225. type: string
  4226. namespace:
  4227. description: |-
  4228. The namespace of the Secret resource being referred to.
  4229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4230. maxLength: 63
  4231. minLength: 1
  4232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4233. type: string
  4234. type: object
  4235. resource:
  4236. description: Resource identifies the CRD by its API group, version and kind.
  4237. properties:
  4238. group:
  4239. description: |-
  4240. Group is the API group of the resource. Use "" (empty string) for core
  4241. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4242. for a CRD. The field is required to be present in the manifest — write
  4243. `group: ""` explicitly for core resources so typos fail at admission
  4244. time rather than later at discovery.
  4245. type: string
  4246. kind:
  4247. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4248. minLength: 1
  4249. type: string
  4250. version:
  4251. description: Version is the API version of the resource (e.g. "v1alpha1").
  4252. minLength: 1
  4253. type: string
  4254. required:
  4255. - group
  4256. - kind
  4257. - version
  4258. type: object
  4259. server:
  4260. description: |-
  4261. Server configures the Kubernetes API address and TLS trust, same as the
  4262. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4263. properties:
  4264. caBundle:
  4265. description: CABundle is a base64-encoded CA certificate
  4266. format: byte
  4267. type: string
  4268. caProvider:
  4269. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4270. properties:
  4271. key:
  4272. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4273. maxLength: 253
  4274. minLength: 1
  4275. pattern: ^[-._a-zA-Z0-9]+$
  4276. type: string
  4277. name:
  4278. description: The name of the object located at the provider type.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4282. type: string
  4283. namespace:
  4284. description: |-
  4285. The namespace the Provider type is in.
  4286. Can only be defined when used in a ClusterSecretStore.
  4287. maxLength: 63
  4288. minLength: 1
  4289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4290. type: string
  4291. type:
  4292. description: The type of provider to use such as "Secret", or "ConfigMap".
  4293. enum:
  4294. - Secret
  4295. - ConfigMap
  4296. type: string
  4297. required:
  4298. - name
  4299. - type
  4300. type: object
  4301. url:
  4302. default: kubernetes.default
  4303. description: configures the Kubernetes server Address.
  4304. type: string
  4305. type: object
  4306. whitelist:
  4307. description: |-
  4308. Whitelist optionally restricts which object names and requested properties
  4309. are allowed to be read.
  4310. properties:
  4311. rules:
  4312. description: |-
  4313. Rules is a list of allow rules. If rules are set, at least one rule must
  4314. match for a request to be allowed.
  4315. items:
  4316. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4317. properties:
  4318. name:
  4319. description: |-
  4320. Name is an optional regular expression matched against the bare object name.
  4321. For both SecretStore and ClusterSecretStore this is always the object name
  4322. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4323. type: string
  4324. namespace:
  4325. description: |-
  4326. Namespace is an optional regular expression matched against the namespace of
  4327. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4328. for SecretStore (where the namespace is fixed to the store namespace).
  4329. type: string
  4330. properties:
  4331. description: |-
  4332. Properties is an optional list of regular expressions matched against
  4333. requested property keys (for example: "spec.secretValue").
  4334. items:
  4335. type: string
  4336. type: array
  4337. type: object
  4338. type: array
  4339. type: object
  4340. required:
  4341. - resource
  4342. type: object
  4343. x-kubernetes-validations:
  4344. - message: one of auth or authRef is required
  4345. rule: has(self.auth) || has(self.authRef)
  4346. - message: at most one of the fields in [auth authRef] may be set
  4347. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4348. delinea:
  4349. description: |-
  4350. Delinea DevOps Secrets Vault
  4351. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4352. properties:
  4353. clientId:
  4354. description: ClientID is the non-secret part of the credential.
  4355. properties:
  4356. secretRef:
  4357. description: SecretRef references a key in a secret that will be used as value.
  4358. properties:
  4359. key:
  4360. description: |-
  4361. A key in the referenced Secret.
  4362. Some instances of this field may be defaulted, in others it may be required.
  4363. maxLength: 253
  4364. minLength: 1
  4365. pattern: ^[-._a-zA-Z0-9]+$
  4366. type: string
  4367. name:
  4368. description: The name of the Secret resource being referred to.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4372. type: string
  4373. namespace:
  4374. description: |-
  4375. The namespace of the Secret resource being referred to.
  4376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4377. maxLength: 63
  4378. minLength: 1
  4379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4380. type: string
  4381. type: object
  4382. value:
  4383. description: Value can be specified directly to set a value without using a secret.
  4384. type: string
  4385. type: object
  4386. clientSecret:
  4387. description: ClientSecret is the secret part of the credential.
  4388. properties:
  4389. secretRef:
  4390. description: SecretRef references a key in a secret that will be used as value.
  4391. properties:
  4392. key:
  4393. description: |-
  4394. A key in the referenced Secret.
  4395. Some instances of this field may be defaulted, in others it may be required.
  4396. maxLength: 253
  4397. minLength: 1
  4398. pattern: ^[-._a-zA-Z0-9]+$
  4399. type: string
  4400. name:
  4401. description: The name of the Secret resource being referred to.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4405. type: string
  4406. namespace:
  4407. description: |-
  4408. The namespace of the Secret resource being referred to.
  4409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4410. maxLength: 63
  4411. minLength: 1
  4412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4413. type: string
  4414. type: object
  4415. value:
  4416. description: Value can be specified directly to set a value without using a secret.
  4417. type: string
  4418. type: object
  4419. tenant:
  4420. description: Tenant is the chosen hostname / site name.
  4421. type: string
  4422. tld:
  4423. description: |-
  4424. TLD is based on the server location that was chosen during provisioning.
  4425. If unset, defaults to "com".
  4426. type: string
  4427. urlTemplate:
  4428. description: |-
  4429. URLTemplate
  4430. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4431. type: string
  4432. required:
  4433. - clientId
  4434. - clientSecret
  4435. - tenant
  4436. type: object
  4437. doppler:
  4438. description: Doppler configures this store to sync secrets using the Doppler provider
  4439. properties:
  4440. auth:
  4441. description: Auth configures how the Operator authenticates with the Doppler API
  4442. properties:
  4443. oidcConfig:
  4444. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4445. properties:
  4446. expirationSeconds:
  4447. default: 600
  4448. description: |-
  4449. ExpirationSeconds sets the ServiceAccount token validity duration.
  4450. Defaults to 10 minutes.
  4451. format: int64
  4452. type: integer
  4453. identity:
  4454. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4455. type: string
  4456. serviceAccountRef:
  4457. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4458. properties:
  4459. audiences:
  4460. description: |-
  4461. Audience specifies the `aud` claim for the service account token
  4462. Some providers automatically extend the audience field based on well-known annotations for workload
  4463. identity (e.g. IRSA or GCP Workload Identity)
  4464. items:
  4465. type: string
  4466. type: array
  4467. name:
  4468. description: The name of the ServiceAccount resource being referred to.
  4469. maxLength: 253
  4470. minLength: 1
  4471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4472. type: string
  4473. namespace:
  4474. description: |-
  4475. Namespace of the resource being referred to.
  4476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4477. maxLength: 63
  4478. minLength: 1
  4479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4480. type: string
  4481. required:
  4482. - name
  4483. type: object
  4484. required:
  4485. - identity
  4486. - serviceAccountRef
  4487. type: object
  4488. secretRef:
  4489. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4490. properties:
  4491. dopplerToken:
  4492. description: |-
  4493. The DopplerToken is used for authentication.
  4494. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4495. The Key attribute defaults to dopplerToken if not specified.
  4496. properties:
  4497. key:
  4498. description: |-
  4499. A key in the referenced Secret.
  4500. Some instances of this field may be defaulted, in others it may be required.
  4501. maxLength: 253
  4502. minLength: 1
  4503. pattern: ^[-._a-zA-Z0-9]+$
  4504. type: string
  4505. name:
  4506. description: The name of the Secret resource being referred to.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4510. type: string
  4511. namespace:
  4512. description: |-
  4513. The namespace of the Secret resource being referred to.
  4514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4515. maxLength: 63
  4516. minLength: 1
  4517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4518. type: string
  4519. type: object
  4520. required:
  4521. - dopplerToken
  4522. type: object
  4523. type: object
  4524. x-kubernetes-validations:
  4525. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4526. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4527. config:
  4528. description: Doppler config (required if not using a Service Token)
  4529. type: string
  4530. format:
  4531. description: Format enables the downloading of secrets as a file (string)
  4532. enum:
  4533. - json
  4534. - dotnet-json
  4535. - env
  4536. - yaml
  4537. - docker
  4538. type: string
  4539. nameTransformer:
  4540. description: Environment variable compatible name transforms that change secret names to a different format
  4541. enum:
  4542. - upper-camel
  4543. - camel
  4544. - lower-snake
  4545. - tf-var
  4546. - dotnet-env
  4547. - lower-kebab
  4548. type: string
  4549. project:
  4550. description: Doppler project (required if not using a Service Token)
  4551. type: string
  4552. required:
  4553. - auth
  4554. type: object
  4555. dvls:
  4556. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4557. properties:
  4558. auth:
  4559. description: Auth defines the authentication method to use.
  4560. properties:
  4561. secretRef:
  4562. description: SecretRef contains the Application ID and Application Secret for authentication.
  4563. properties:
  4564. appId:
  4565. description: AppID is the reference to the secret containing the Application ID.
  4566. properties:
  4567. key:
  4568. description: |-
  4569. A key in the referenced Secret.
  4570. Some instances of this field may be defaulted, in others it may be required.
  4571. maxLength: 253
  4572. minLength: 1
  4573. pattern: ^[-._a-zA-Z0-9]+$
  4574. type: string
  4575. name:
  4576. description: The name of the Secret resource being referred to.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4580. type: string
  4581. namespace:
  4582. description: |-
  4583. The namespace of the Secret resource being referred to.
  4584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4585. maxLength: 63
  4586. minLength: 1
  4587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4588. type: string
  4589. type: object
  4590. appSecret:
  4591. description: AppSecret is the reference to the secret containing the Application Secret.
  4592. properties:
  4593. key:
  4594. description: |-
  4595. A key in the referenced Secret.
  4596. Some instances of this field may be defaulted, in others it may be required.
  4597. maxLength: 253
  4598. minLength: 1
  4599. pattern: ^[-._a-zA-Z0-9]+$
  4600. type: string
  4601. name:
  4602. description: The name of the Secret resource being referred to.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4606. type: string
  4607. namespace:
  4608. description: |-
  4609. The namespace of the Secret resource being referred to.
  4610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4611. maxLength: 63
  4612. minLength: 1
  4613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4614. type: string
  4615. type: object
  4616. required:
  4617. - appId
  4618. - appSecret
  4619. type: object
  4620. required:
  4621. - secretRef
  4622. type: object
  4623. insecure:
  4624. description: |-
  4625. Insecure allows connecting to DVLS over plain HTTP.
  4626. This is NOT RECOMMENDED for production use.
  4627. Set to true only if you understand the security implications.
  4628. type: boolean
  4629. serverUrl:
  4630. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4631. type: string
  4632. vault:
  4633. description: |-
  4634. Vault is the name or UUID of the vault to fetch secrets from.
  4635. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4636. type: string
  4637. required:
  4638. - auth
  4639. - serverUrl
  4640. type: object
  4641. fake:
  4642. description: Fake configures a store with static key/value pairs
  4643. properties:
  4644. data:
  4645. items:
  4646. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4647. properties:
  4648. key:
  4649. type: string
  4650. value:
  4651. type: string
  4652. version:
  4653. type: string
  4654. required:
  4655. - key
  4656. - value
  4657. type: object
  4658. type: array
  4659. validationResult:
  4660. description: ValidationResult is defined type for the number of validation results.
  4661. type: integer
  4662. required:
  4663. - data
  4664. type: object
  4665. fortanix:
  4666. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4667. properties:
  4668. apiKey:
  4669. description: APIKey is the API token to access SDKMS Applications.
  4670. properties:
  4671. secretRef:
  4672. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4673. properties:
  4674. key:
  4675. description: |-
  4676. A key in the referenced Secret.
  4677. Some instances of this field may be defaulted, in others it may be required.
  4678. maxLength: 253
  4679. minLength: 1
  4680. pattern: ^[-._a-zA-Z0-9]+$
  4681. type: string
  4682. name:
  4683. description: The name of the Secret resource being referred to.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4687. type: string
  4688. namespace:
  4689. description: |-
  4690. The namespace of the Secret resource being referred to.
  4691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4692. maxLength: 63
  4693. minLength: 1
  4694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4695. type: string
  4696. type: object
  4697. type: object
  4698. apiUrl:
  4699. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4700. type: string
  4701. type: object
  4702. gcpsm:
  4703. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4704. properties:
  4705. auth:
  4706. description: Auth defines the information necessary to authenticate against GCP
  4707. properties:
  4708. secretRef:
  4709. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4710. properties:
  4711. secretAccessKeySecretRef:
  4712. description: The SecretAccessKey is used for authentication
  4713. properties:
  4714. key:
  4715. description: |-
  4716. A key in the referenced Secret.
  4717. Some instances of this field may be defaulted, in others it may be required.
  4718. maxLength: 253
  4719. minLength: 1
  4720. pattern: ^[-._a-zA-Z0-9]+$
  4721. type: string
  4722. name:
  4723. description: The name of the Secret resource being referred to.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4727. type: string
  4728. namespace:
  4729. description: |-
  4730. The namespace of the Secret resource being referred to.
  4731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4732. maxLength: 63
  4733. minLength: 1
  4734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4735. type: string
  4736. type: object
  4737. type: object
  4738. workloadIdentity:
  4739. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4740. properties:
  4741. clusterLocation:
  4742. description: |-
  4743. ClusterLocation is the location of the cluster
  4744. If not specified, it fetches information from the metadata server
  4745. type: string
  4746. clusterName:
  4747. description: |-
  4748. ClusterName is the name of the cluster
  4749. If not specified, it fetches information from the metadata server
  4750. type: string
  4751. clusterProjectID:
  4752. description: |-
  4753. ClusterProjectID is the project ID of the cluster
  4754. If not specified, it fetches information from the metadata server
  4755. type: string
  4756. serviceAccountRef:
  4757. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4758. properties:
  4759. audiences:
  4760. description: |-
  4761. Audience specifies the `aud` claim for the service account token
  4762. Some providers automatically extend the audience field based on well-known annotations for workload
  4763. identity (e.g. IRSA or GCP Workload Identity)
  4764. items:
  4765. type: string
  4766. type: array
  4767. name:
  4768. description: The name of the ServiceAccount resource being referred to.
  4769. maxLength: 253
  4770. minLength: 1
  4771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4772. type: string
  4773. namespace:
  4774. description: |-
  4775. Namespace of the resource being referred to.
  4776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4777. maxLength: 63
  4778. minLength: 1
  4779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4780. type: string
  4781. required:
  4782. - name
  4783. type: object
  4784. required:
  4785. - serviceAccountRef
  4786. type: object
  4787. workloadIdentityFederation:
  4788. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4789. properties:
  4790. audience:
  4791. description: |-
  4792. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4793. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4794. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4795. type: string
  4796. awsSecurityCredentials:
  4797. description: |-
  4798. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4799. when using the AWS metadata server is not an option.
  4800. properties:
  4801. awsCredentialsSecretRef:
  4802. description: |-
  4803. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4804. Secret should be created with below names for keys
  4805. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4806. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4807. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4808. properties:
  4809. name:
  4810. description: name of the secret.
  4811. maxLength: 253
  4812. minLength: 1
  4813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4814. type: string
  4815. namespace:
  4816. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4817. maxLength: 63
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4820. type: string
  4821. required:
  4822. - name
  4823. type: object
  4824. region:
  4825. description: region is for configuring the AWS region to be used.
  4826. example: ap-south-1
  4827. maxLength: 50
  4828. minLength: 1
  4829. pattern: ^[a-z0-9-]+$
  4830. type: string
  4831. required:
  4832. - awsCredentialsSecretRef
  4833. - region
  4834. type: object
  4835. credConfig:
  4836. description: |-
  4837. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4838. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4839. serviceAccountRef must be used by providing operators service account details.
  4840. properties:
  4841. key:
  4842. description: key name holding the external account credential config.
  4843. maxLength: 253
  4844. minLength: 1
  4845. pattern: ^[-._a-zA-Z0-9]+$
  4846. type: string
  4847. name:
  4848. description: name of the configmap.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4852. type: string
  4853. namespace:
  4854. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4855. maxLength: 63
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4858. type: string
  4859. required:
  4860. - key
  4861. - name
  4862. type: object
  4863. externalTokenEndpoint:
  4864. description: |-
  4865. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4866. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4867. URL is having the expected value.
  4868. type: string
  4869. gcpServiceAccountEmail:
  4870. description: |-
  4871. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4872. after Workload Identity Federation. Use this to grant access through the service account's
  4873. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4874. service_account_impersonation_url in the external account JSON from credConfig;
  4875. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4876. on that ServiceAccount.
  4877. example: my-gsa@my-project.iam.gserviceaccount.com
  4878. minLength: 1
  4879. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4880. type: string
  4881. serviceAccountRef:
  4882. description: |-
  4883. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4884. when Kubernetes is configured as provider in workload identity pool.
  4885. properties:
  4886. audiences:
  4887. description: |-
  4888. Audience specifies the `aud` claim for the service account token
  4889. Some providers automatically extend the audience field based on well-known annotations for workload
  4890. identity (e.g. IRSA or GCP Workload Identity)
  4891. items:
  4892. type: string
  4893. type: array
  4894. name:
  4895. description: The name of the ServiceAccount resource being referred to.
  4896. maxLength: 253
  4897. minLength: 1
  4898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4899. type: string
  4900. namespace:
  4901. description: |-
  4902. Namespace of the resource being referred to.
  4903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4904. maxLength: 63
  4905. minLength: 1
  4906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4907. type: string
  4908. required:
  4909. - name
  4910. type: object
  4911. type: object
  4912. type: object
  4913. location:
  4914. description: Location optionally defines a location for a secret
  4915. type: string
  4916. projectID:
  4917. description: ProjectID project where secret is located
  4918. type: string
  4919. secretVersionSelectionPolicy:
  4920. default: LatestOrFail
  4921. description: |-
  4922. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4923. when "latest" is disabled or destroyed.
  4924. Possible values are:
  4925. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4926. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4927. type: string
  4928. type: object
  4929. github:
  4930. description: |-
  4931. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4932. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4933. properties:
  4934. appID:
  4935. description: appID specifies the Github APP that will be used to authenticate the client
  4936. format: int64
  4937. type: integer
  4938. auth:
  4939. description: auth configures how secret-manager authenticates with a Github instance.
  4940. properties:
  4941. privateKey:
  4942. description: |-
  4943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4944. In some instances, `key` is a required field.
  4945. properties:
  4946. key:
  4947. description: |-
  4948. A key in the referenced Secret.
  4949. Some instances of this field may be defaulted, in others it may be required.
  4950. maxLength: 253
  4951. minLength: 1
  4952. pattern: ^[-._a-zA-Z0-9]+$
  4953. type: string
  4954. name:
  4955. description: The name of the Secret resource being referred to.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4959. type: string
  4960. namespace:
  4961. description: |-
  4962. The namespace of the Secret resource being referred to.
  4963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4964. maxLength: 63
  4965. minLength: 1
  4966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4967. type: string
  4968. type: object
  4969. required:
  4970. - privateKey
  4971. type: object
  4972. environment:
  4973. description: environment will be used to fetch secrets from a particular environment within a github repository
  4974. type: string
  4975. installationID:
  4976. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4977. format: int64
  4978. type: integer
  4979. orgSecretVisibility:
  4980. description: |-
  4981. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4982. Valid values are "all" or "private".
  4983. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4984. whatever visibility they already have in GitHub.
  4985. enum:
  4986. - all
  4987. - private
  4988. type: string
  4989. organization:
  4990. description: organization will be used to fetch secrets from the Github organization
  4991. type: string
  4992. repository:
  4993. description: repository will be used to fetch secrets from the Github repository within an organization
  4994. type: string
  4995. uploadURL:
  4996. description: Upload URL for enterprise instances. Default to URL.
  4997. type: string
  4998. url:
  4999. default: https://github.com/
  5000. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5001. type: string
  5002. required:
  5003. - appID
  5004. - auth
  5005. - installationID
  5006. - organization
  5007. type: object
  5008. gitlab:
  5009. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5010. properties:
  5011. auth:
  5012. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5013. properties:
  5014. SecretRef:
  5015. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5016. properties:
  5017. accessToken:
  5018. description: AccessToken is used for authentication.
  5019. properties:
  5020. key:
  5021. description: |-
  5022. A key in the referenced Secret.
  5023. Some instances of this field may be defaulted, in others it may be required.
  5024. maxLength: 253
  5025. minLength: 1
  5026. pattern: ^[-._a-zA-Z0-9]+$
  5027. type: string
  5028. name:
  5029. description: The name of the Secret resource being referred to.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5033. type: string
  5034. namespace:
  5035. description: |-
  5036. The namespace of the Secret resource being referred to.
  5037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5038. maxLength: 63
  5039. minLength: 1
  5040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5041. type: string
  5042. type: object
  5043. type: object
  5044. required:
  5045. - SecretRef
  5046. type: object
  5047. caBundle:
  5048. description: |-
  5049. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5050. can be performed.
  5051. format: byte
  5052. type: string
  5053. caProvider:
  5054. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5055. properties:
  5056. key:
  5057. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5058. maxLength: 253
  5059. minLength: 1
  5060. pattern: ^[-._a-zA-Z0-9]+$
  5061. type: string
  5062. name:
  5063. description: The name of the object located at the provider type.
  5064. maxLength: 253
  5065. minLength: 1
  5066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5067. type: string
  5068. namespace:
  5069. description: |-
  5070. The namespace the Provider type is in.
  5071. Can only be defined when used in a ClusterSecretStore.
  5072. maxLength: 63
  5073. minLength: 1
  5074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5075. type: string
  5076. type:
  5077. description: The type of provider to use such as "Secret", or "ConfigMap".
  5078. enum:
  5079. - Secret
  5080. - ConfigMap
  5081. type: string
  5082. required:
  5083. - name
  5084. - type
  5085. type: object
  5086. environment:
  5087. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5088. type: string
  5089. groupIDs:
  5090. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5091. items:
  5092. type: string
  5093. type: array
  5094. inheritFromGroups:
  5095. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5096. type: boolean
  5097. projectID:
  5098. description: ProjectID specifies a project where secrets are located.
  5099. type: string
  5100. url:
  5101. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5102. type: string
  5103. required:
  5104. - auth
  5105. type: object
  5106. ibm:
  5107. description: IBM configures this store to sync secrets using IBM Cloud provider
  5108. properties:
  5109. auth:
  5110. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5111. maxProperties: 1
  5112. minProperties: 1
  5113. properties:
  5114. containerAuth:
  5115. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5116. properties:
  5117. iamEndpoint:
  5118. type: string
  5119. profile:
  5120. description: the IBM Trusted Profile
  5121. type: string
  5122. tokenLocation:
  5123. description: Location the token is mounted on the pod
  5124. type: string
  5125. required:
  5126. - profile
  5127. type: object
  5128. secretRef:
  5129. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5130. properties:
  5131. iamEndpoint:
  5132. description: The IAM endpoint used to obain a token
  5133. type: string
  5134. secretApiKeySecretRef:
  5135. description: The SecretAccessKey is used for authentication
  5136. properties:
  5137. key:
  5138. description: |-
  5139. A key in the referenced Secret.
  5140. Some instances of this field may be defaulted, in others it may be required.
  5141. maxLength: 253
  5142. minLength: 1
  5143. pattern: ^[-._a-zA-Z0-9]+$
  5144. type: string
  5145. name:
  5146. description: The name of the Secret resource being referred to.
  5147. maxLength: 253
  5148. minLength: 1
  5149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5150. type: string
  5151. namespace:
  5152. description: |-
  5153. The namespace of the Secret resource being referred to.
  5154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5155. maxLength: 63
  5156. minLength: 1
  5157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5158. type: string
  5159. type: object
  5160. type: object
  5161. type: object
  5162. serviceUrl:
  5163. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5164. type: string
  5165. required:
  5166. - auth
  5167. type: object
  5168. infisical:
  5169. description: Infisical configures this store to sync secrets using the Infisical provider
  5170. properties:
  5171. auth:
  5172. description: Auth configures how the Operator authenticates with the Infisical API
  5173. properties:
  5174. awsAuthCredentials:
  5175. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5176. properties:
  5177. identityId:
  5178. description: |-
  5179. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5180. In some instances, `key` is a required field.
  5181. properties:
  5182. key:
  5183. description: |-
  5184. A key in the referenced Secret.
  5185. Some instances of this field may be defaulted, in others it may be required.
  5186. maxLength: 253
  5187. minLength: 1
  5188. pattern: ^[-._a-zA-Z0-9]+$
  5189. type: string
  5190. name:
  5191. description: The name of the Secret resource being referred to.
  5192. maxLength: 253
  5193. minLength: 1
  5194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5195. type: string
  5196. namespace:
  5197. description: |-
  5198. The namespace of the Secret resource being referred to.
  5199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5200. maxLength: 63
  5201. minLength: 1
  5202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5203. type: string
  5204. type: object
  5205. required:
  5206. - identityId
  5207. type: object
  5208. azureAuthCredentials:
  5209. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5210. properties:
  5211. identityId:
  5212. description: |-
  5213. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5214. In some instances, `key` is a required field.
  5215. properties:
  5216. key:
  5217. description: |-
  5218. A key in the referenced Secret.
  5219. Some instances of this field may be defaulted, in others it may be required.
  5220. maxLength: 253
  5221. minLength: 1
  5222. pattern: ^[-._a-zA-Z0-9]+$
  5223. type: string
  5224. name:
  5225. description: The name of the Secret resource being referred to.
  5226. maxLength: 253
  5227. minLength: 1
  5228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5229. type: string
  5230. namespace:
  5231. description: |-
  5232. The namespace of the Secret resource being referred to.
  5233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5234. maxLength: 63
  5235. minLength: 1
  5236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5237. type: string
  5238. type: object
  5239. resource:
  5240. description: |-
  5241. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5242. In some instances, `key` is a required field.
  5243. properties:
  5244. key:
  5245. description: |-
  5246. A key in the referenced Secret.
  5247. Some instances of this field may be defaulted, in others it may be required.
  5248. maxLength: 253
  5249. minLength: 1
  5250. pattern: ^[-._a-zA-Z0-9]+$
  5251. type: string
  5252. name:
  5253. description: The name of the Secret resource being referred to.
  5254. maxLength: 253
  5255. minLength: 1
  5256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5257. type: string
  5258. namespace:
  5259. description: |-
  5260. The namespace of the Secret resource being referred to.
  5261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5262. maxLength: 63
  5263. minLength: 1
  5264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5265. type: string
  5266. type: object
  5267. required:
  5268. - identityId
  5269. type: object
  5270. gcpIamAuthCredentials:
  5271. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5272. properties:
  5273. identityId:
  5274. description: |-
  5275. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5276. In some instances, `key` is a required field.
  5277. properties:
  5278. key:
  5279. description: |-
  5280. A key in the referenced Secret.
  5281. Some instances of this field may be defaulted, in others it may be required.
  5282. maxLength: 253
  5283. minLength: 1
  5284. pattern: ^[-._a-zA-Z0-9]+$
  5285. type: string
  5286. name:
  5287. description: The name of the Secret resource being referred to.
  5288. maxLength: 253
  5289. minLength: 1
  5290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5291. type: string
  5292. namespace:
  5293. description: |-
  5294. The namespace of the Secret resource being referred to.
  5295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5296. maxLength: 63
  5297. minLength: 1
  5298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5299. type: string
  5300. type: object
  5301. serviceAccountKeyFilePath:
  5302. description: |-
  5303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5304. In some instances, `key` is a required field.
  5305. properties:
  5306. key:
  5307. description: |-
  5308. A key in the referenced Secret.
  5309. Some instances of this field may be defaulted, in others it may be required.
  5310. maxLength: 253
  5311. minLength: 1
  5312. pattern: ^[-._a-zA-Z0-9]+$
  5313. type: string
  5314. name:
  5315. description: The name of the Secret resource being referred to.
  5316. maxLength: 253
  5317. minLength: 1
  5318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5319. type: string
  5320. namespace:
  5321. description: |-
  5322. The namespace of the Secret resource being referred to.
  5323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5324. maxLength: 63
  5325. minLength: 1
  5326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5327. type: string
  5328. type: object
  5329. required:
  5330. - identityId
  5331. - serviceAccountKeyFilePath
  5332. type: object
  5333. gcpIdTokenAuthCredentials:
  5334. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5335. properties:
  5336. identityId:
  5337. description: |-
  5338. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5339. In some instances, `key` is a required field.
  5340. properties:
  5341. key:
  5342. description: |-
  5343. A key in the referenced Secret.
  5344. Some instances of this field may be defaulted, in others it may be required.
  5345. maxLength: 253
  5346. minLength: 1
  5347. pattern: ^[-._a-zA-Z0-9]+$
  5348. type: string
  5349. name:
  5350. description: The name of the Secret resource being referred to.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5354. type: string
  5355. namespace:
  5356. description: |-
  5357. The namespace of the Secret resource being referred to.
  5358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5359. maxLength: 63
  5360. minLength: 1
  5361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5362. type: string
  5363. type: object
  5364. required:
  5365. - identityId
  5366. type: object
  5367. jwtAuthCredentials:
  5368. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5369. properties:
  5370. identityId:
  5371. description: |-
  5372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5373. In some instances, `key` is a required field.
  5374. properties:
  5375. key:
  5376. description: |-
  5377. A key in the referenced Secret.
  5378. Some instances of this field may be defaulted, in others it may be required.
  5379. maxLength: 253
  5380. minLength: 1
  5381. pattern: ^[-._a-zA-Z0-9]+$
  5382. type: string
  5383. name:
  5384. description: The name of the Secret resource being referred to.
  5385. maxLength: 253
  5386. minLength: 1
  5387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5388. type: string
  5389. namespace:
  5390. description: |-
  5391. The namespace of the Secret resource being referred to.
  5392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5393. maxLength: 63
  5394. minLength: 1
  5395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5396. type: string
  5397. type: object
  5398. jwt:
  5399. description: |-
  5400. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5401. In some instances, `key` is a required field.
  5402. properties:
  5403. key:
  5404. description: |-
  5405. A key in the referenced Secret.
  5406. Some instances of this field may be defaulted, in others it may be required.
  5407. maxLength: 253
  5408. minLength: 1
  5409. pattern: ^[-._a-zA-Z0-9]+$
  5410. type: string
  5411. name:
  5412. description: The name of the Secret resource being referred to.
  5413. maxLength: 253
  5414. minLength: 1
  5415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5416. type: string
  5417. namespace:
  5418. description: |-
  5419. The namespace of the Secret resource being referred to.
  5420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5421. maxLength: 63
  5422. minLength: 1
  5423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5424. type: string
  5425. type: object
  5426. required:
  5427. - identityId
  5428. - jwt
  5429. type: object
  5430. kubernetesAuthCredentials:
  5431. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5432. properties:
  5433. identityId:
  5434. description: |-
  5435. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5436. In some instances, `key` is a required field.
  5437. properties:
  5438. key:
  5439. description: |-
  5440. A key in the referenced Secret.
  5441. Some instances of this field may be defaulted, in others it may be required.
  5442. maxLength: 253
  5443. minLength: 1
  5444. pattern: ^[-._a-zA-Z0-9]+$
  5445. type: string
  5446. name:
  5447. description: The name of the Secret resource being referred to.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5451. type: string
  5452. namespace:
  5453. description: |-
  5454. The namespace of the Secret resource being referred to.
  5455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5456. maxLength: 63
  5457. minLength: 1
  5458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5459. type: string
  5460. type: object
  5461. serviceAccountTokenPath:
  5462. description: |-
  5463. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5464. In some instances, `key` is a required field.
  5465. properties:
  5466. key:
  5467. description: |-
  5468. A key in the referenced Secret.
  5469. Some instances of this field may be defaulted, in others it may be required.
  5470. maxLength: 253
  5471. minLength: 1
  5472. pattern: ^[-._a-zA-Z0-9]+$
  5473. type: string
  5474. name:
  5475. description: The name of the Secret resource being referred to.
  5476. maxLength: 253
  5477. minLength: 1
  5478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5479. type: string
  5480. namespace:
  5481. description: |-
  5482. The namespace of the Secret resource being referred to.
  5483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5484. maxLength: 63
  5485. minLength: 1
  5486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5487. type: string
  5488. type: object
  5489. required:
  5490. - identityId
  5491. type: object
  5492. ldapAuthCredentials:
  5493. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5494. properties:
  5495. identityId:
  5496. description: |-
  5497. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5498. In some instances, `key` is a required field.
  5499. properties:
  5500. key:
  5501. description: |-
  5502. A key in the referenced Secret.
  5503. Some instances of this field may be defaulted, in others it may be required.
  5504. maxLength: 253
  5505. minLength: 1
  5506. pattern: ^[-._a-zA-Z0-9]+$
  5507. type: string
  5508. name:
  5509. description: The name of the Secret resource being referred to.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5513. type: string
  5514. namespace:
  5515. description: |-
  5516. The namespace of the Secret resource being referred to.
  5517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5518. maxLength: 63
  5519. minLength: 1
  5520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5521. type: string
  5522. type: object
  5523. ldapPassword:
  5524. description: |-
  5525. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5526. In some instances, `key` is a required field.
  5527. properties:
  5528. key:
  5529. description: |-
  5530. A key in the referenced Secret.
  5531. Some instances of this field may be defaulted, in others it may be required.
  5532. maxLength: 253
  5533. minLength: 1
  5534. pattern: ^[-._a-zA-Z0-9]+$
  5535. type: string
  5536. name:
  5537. description: The name of the Secret resource being referred to.
  5538. maxLength: 253
  5539. minLength: 1
  5540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5541. type: string
  5542. namespace:
  5543. description: |-
  5544. The namespace of the Secret resource being referred to.
  5545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5546. maxLength: 63
  5547. minLength: 1
  5548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5549. type: string
  5550. type: object
  5551. ldapUsername:
  5552. description: |-
  5553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5554. In some instances, `key` is a required field.
  5555. properties:
  5556. key:
  5557. description: |-
  5558. A key in the referenced Secret.
  5559. Some instances of this field may be defaulted, in others it may be required.
  5560. maxLength: 253
  5561. minLength: 1
  5562. pattern: ^[-._a-zA-Z0-9]+$
  5563. type: string
  5564. name:
  5565. description: The name of the Secret resource being referred to.
  5566. maxLength: 253
  5567. minLength: 1
  5568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5569. type: string
  5570. namespace:
  5571. description: |-
  5572. The namespace of the Secret resource being referred to.
  5573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5574. maxLength: 63
  5575. minLength: 1
  5576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5577. type: string
  5578. type: object
  5579. required:
  5580. - identityId
  5581. - ldapPassword
  5582. - ldapUsername
  5583. type: object
  5584. ociAuthCredentials:
  5585. description: OciAuthCredentials represents the credentials for OCI authentication.
  5586. properties:
  5587. fingerprint:
  5588. description: |-
  5589. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5590. In some instances, `key` is a required field.
  5591. properties:
  5592. key:
  5593. description: |-
  5594. A key in the referenced Secret.
  5595. Some instances of this field may be defaulted, in others it may be required.
  5596. maxLength: 253
  5597. minLength: 1
  5598. pattern: ^[-._a-zA-Z0-9]+$
  5599. type: string
  5600. name:
  5601. description: The name of the Secret resource being referred to.
  5602. maxLength: 253
  5603. minLength: 1
  5604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5605. type: string
  5606. namespace:
  5607. description: |-
  5608. The namespace of the Secret resource being referred to.
  5609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5610. maxLength: 63
  5611. minLength: 1
  5612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5613. type: string
  5614. type: object
  5615. identityId:
  5616. description: |-
  5617. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5618. In some instances, `key` is a required field.
  5619. properties:
  5620. key:
  5621. description: |-
  5622. A key in the referenced Secret.
  5623. Some instances of this field may be defaulted, in others it may be required.
  5624. maxLength: 253
  5625. minLength: 1
  5626. pattern: ^[-._a-zA-Z0-9]+$
  5627. type: string
  5628. name:
  5629. description: The name of the Secret resource being referred to.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5633. type: string
  5634. namespace:
  5635. description: |-
  5636. The namespace of the Secret resource being referred to.
  5637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5638. maxLength: 63
  5639. minLength: 1
  5640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5641. type: string
  5642. type: object
  5643. privateKey:
  5644. description: |-
  5645. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5646. In some instances, `key` is a required field.
  5647. properties:
  5648. key:
  5649. description: |-
  5650. A key in the referenced Secret.
  5651. Some instances of this field may be defaulted, in others it may be required.
  5652. maxLength: 253
  5653. minLength: 1
  5654. pattern: ^[-._a-zA-Z0-9]+$
  5655. type: string
  5656. name:
  5657. description: The name of the Secret resource being referred to.
  5658. maxLength: 253
  5659. minLength: 1
  5660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5661. type: string
  5662. namespace:
  5663. description: |-
  5664. The namespace of the Secret resource being referred to.
  5665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5666. maxLength: 63
  5667. minLength: 1
  5668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5669. type: string
  5670. type: object
  5671. privateKeyPassphrase:
  5672. description: |-
  5673. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5674. In some instances, `key` is a required field.
  5675. properties:
  5676. key:
  5677. description: |-
  5678. A key in the referenced Secret.
  5679. Some instances of this field may be defaulted, in others it may be required.
  5680. maxLength: 253
  5681. minLength: 1
  5682. pattern: ^[-._a-zA-Z0-9]+$
  5683. type: string
  5684. name:
  5685. description: The name of the Secret resource being referred to.
  5686. maxLength: 253
  5687. minLength: 1
  5688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5689. type: string
  5690. namespace:
  5691. description: |-
  5692. The namespace of the Secret resource being referred to.
  5693. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5694. maxLength: 63
  5695. minLength: 1
  5696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5697. type: string
  5698. type: object
  5699. region:
  5700. description: |-
  5701. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5702. In some instances, `key` is a required field.
  5703. properties:
  5704. key:
  5705. description: |-
  5706. A key in the referenced Secret.
  5707. Some instances of this field may be defaulted, in others it may be required.
  5708. maxLength: 253
  5709. minLength: 1
  5710. pattern: ^[-._a-zA-Z0-9]+$
  5711. type: string
  5712. name:
  5713. description: The name of the Secret resource being referred to.
  5714. maxLength: 253
  5715. minLength: 1
  5716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5717. type: string
  5718. namespace:
  5719. description: |-
  5720. The namespace of the Secret resource being referred to.
  5721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5722. maxLength: 63
  5723. minLength: 1
  5724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5725. type: string
  5726. type: object
  5727. tenancyId:
  5728. description: |-
  5729. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5730. In some instances, `key` is a required field.
  5731. properties:
  5732. key:
  5733. description: |-
  5734. A key in the referenced Secret.
  5735. Some instances of this field may be defaulted, in others it may be required.
  5736. maxLength: 253
  5737. minLength: 1
  5738. pattern: ^[-._a-zA-Z0-9]+$
  5739. type: string
  5740. name:
  5741. description: The name of the Secret resource being referred to.
  5742. maxLength: 253
  5743. minLength: 1
  5744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5745. type: string
  5746. namespace:
  5747. description: |-
  5748. The namespace of the Secret resource being referred to.
  5749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5750. maxLength: 63
  5751. minLength: 1
  5752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5753. type: string
  5754. type: object
  5755. userId:
  5756. description: |-
  5757. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5758. In some instances, `key` is a required field.
  5759. properties:
  5760. key:
  5761. description: |-
  5762. A key in the referenced Secret.
  5763. Some instances of this field may be defaulted, in others it may be required.
  5764. maxLength: 253
  5765. minLength: 1
  5766. pattern: ^[-._a-zA-Z0-9]+$
  5767. type: string
  5768. name:
  5769. description: The name of the Secret resource being referred to.
  5770. maxLength: 253
  5771. minLength: 1
  5772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5773. type: string
  5774. namespace:
  5775. description: |-
  5776. The namespace of the Secret resource being referred to.
  5777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5778. maxLength: 63
  5779. minLength: 1
  5780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5781. type: string
  5782. type: object
  5783. required:
  5784. - fingerprint
  5785. - identityId
  5786. - privateKey
  5787. - region
  5788. - tenancyId
  5789. - userId
  5790. type: object
  5791. tokenAuthCredentials:
  5792. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5793. properties:
  5794. accessToken:
  5795. description: |-
  5796. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5797. In some instances, `key` is a required field.
  5798. properties:
  5799. key:
  5800. description: |-
  5801. A key in the referenced Secret.
  5802. Some instances of this field may be defaulted, in others it may be required.
  5803. maxLength: 253
  5804. minLength: 1
  5805. pattern: ^[-._a-zA-Z0-9]+$
  5806. type: string
  5807. name:
  5808. description: The name of the Secret resource being referred to.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5812. type: string
  5813. namespace:
  5814. description: |-
  5815. The namespace of the Secret resource being referred to.
  5816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5817. maxLength: 63
  5818. minLength: 1
  5819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5820. type: string
  5821. type: object
  5822. required:
  5823. - accessToken
  5824. type: object
  5825. universalAuthCredentials:
  5826. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5827. properties:
  5828. clientId:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. clientSecret:
  5857. description: |-
  5858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5859. In some instances, `key` is a required field.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. required:
  5885. - clientId
  5886. - clientSecret
  5887. type: object
  5888. type: object
  5889. caBundle:
  5890. description: |-
  5891. CABundle is a PEM-encoded CA certificate bundle used to validate
  5892. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5893. format: byte
  5894. type: string
  5895. caProvider:
  5896. description: |-
  5897. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5898. The certificate is used to validate the Infisical server's TLS certificate.
  5899. Mutually exclusive with CABundle.
  5900. properties:
  5901. key:
  5902. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5903. maxLength: 253
  5904. minLength: 1
  5905. pattern: ^[-._a-zA-Z0-9]+$
  5906. type: string
  5907. name:
  5908. description: The name of the object located at the provider type.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5912. type: string
  5913. namespace:
  5914. description: |-
  5915. The namespace the Provider type is in.
  5916. Can only be defined when used in a ClusterSecretStore.
  5917. maxLength: 63
  5918. minLength: 1
  5919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5920. type: string
  5921. type:
  5922. description: The type of provider to use such as "Secret", or "ConfigMap".
  5923. enum:
  5924. - Secret
  5925. - ConfigMap
  5926. type: string
  5927. required:
  5928. - name
  5929. - type
  5930. type: object
  5931. hostAPI:
  5932. default: https://app.infisical.com/api
  5933. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5934. type: string
  5935. secretsScope:
  5936. description: SecretsScope defines the scope of the secrets within the workspace
  5937. properties:
  5938. environmentSlug:
  5939. description: EnvironmentSlug is the required slug identifier for the environment.
  5940. type: string
  5941. expandSecretReferences:
  5942. default: true
  5943. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5944. type: boolean
  5945. organizationSlug:
  5946. description: |-
  5947. OrganizationSlug is the optional slug that identifies the organization that will be used
  5948. during authentication. Useful for sub-organization setups
  5949. type: string
  5950. projectSlug:
  5951. description: ProjectSlug is the required slug identifier for the project.
  5952. type: string
  5953. recursive:
  5954. default: false
  5955. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5956. type: boolean
  5957. secretsPath:
  5958. default: /
  5959. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5960. type: string
  5961. required:
  5962. - environmentSlug
  5963. - projectSlug
  5964. type: object
  5965. required:
  5966. - auth
  5967. - secretsScope
  5968. type: object
  5969. keepersecurity:
  5970. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5971. properties:
  5972. authRef:
  5973. description: |-
  5974. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5975. In some instances, `key` is a required field.
  5976. properties:
  5977. key:
  5978. description: |-
  5979. A key in the referenced Secret.
  5980. Some instances of this field may be defaulted, in others it may be required.
  5981. maxLength: 253
  5982. minLength: 1
  5983. pattern: ^[-._a-zA-Z0-9]+$
  5984. type: string
  5985. name:
  5986. description: The name of the Secret resource being referred to.
  5987. maxLength: 253
  5988. minLength: 1
  5989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5990. type: string
  5991. namespace:
  5992. description: |-
  5993. The namespace of the Secret resource being referred to.
  5994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5995. maxLength: 63
  5996. minLength: 1
  5997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5998. type: string
  5999. type: object
  6000. folderID:
  6001. type: string
  6002. getByTitleFallback:
  6003. type: boolean
  6004. required:
  6005. - authRef
  6006. - folderID
  6007. type: object
  6008. kubernetes:
  6009. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6010. properties:
  6011. auth:
  6012. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6013. maxProperties: 1
  6014. minProperties: 1
  6015. properties:
  6016. cert:
  6017. description: has both clientCert and clientKey as secretKeySelector
  6018. properties:
  6019. clientCert:
  6020. description: |-
  6021. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6022. In some instances, `key` is a required field.
  6023. properties:
  6024. key:
  6025. description: |-
  6026. A key in the referenced Secret.
  6027. Some instances of this field may be defaulted, in others it may be required.
  6028. maxLength: 253
  6029. minLength: 1
  6030. pattern: ^[-._a-zA-Z0-9]+$
  6031. type: string
  6032. name:
  6033. description: The name of the Secret resource being referred to.
  6034. maxLength: 253
  6035. minLength: 1
  6036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6037. type: string
  6038. namespace:
  6039. description: |-
  6040. The namespace of the Secret resource being referred to.
  6041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6042. maxLength: 63
  6043. minLength: 1
  6044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6045. type: string
  6046. type: object
  6047. clientKey:
  6048. description: |-
  6049. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6050. In some instances, `key` is a required field.
  6051. properties:
  6052. key:
  6053. description: |-
  6054. A key in the referenced Secret.
  6055. Some instances of this field may be defaulted, in others it may be required.
  6056. maxLength: 253
  6057. minLength: 1
  6058. pattern: ^[-._a-zA-Z0-9]+$
  6059. type: string
  6060. name:
  6061. description: The name of the Secret resource being referred to.
  6062. maxLength: 253
  6063. minLength: 1
  6064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6065. type: string
  6066. namespace:
  6067. description: |-
  6068. The namespace of the Secret resource being referred to.
  6069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6070. maxLength: 63
  6071. minLength: 1
  6072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6073. type: string
  6074. type: object
  6075. required:
  6076. - clientCert
  6077. - clientKey
  6078. type: object
  6079. serviceAccount:
  6080. description: points to a service account that should be used for authentication
  6081. properties:
  6082. audiences:
  6083. description: |-
  6084. Audience specifies the `aud` claim for the service account token
  6085. Some providers automatically extend the audience field based on well-known annotations for workload
  6086. identity (e.g. IRSA or GCP Workload Identity)
  6087. items:
  6088. type: string
  6089. type: array
  6090. name:
  6091. description: The name of the ServiceAccount resource being referred to.
  6092. maxLength: 253
  6093. minLength: 1
  6094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6095. type: string
  6096. namespace:
  6097. description: |-
  6098. Namespace of the resource being referred to.
  6099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6100. maxLength: 63
  6101. minLength: 1
  6102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6103. type: string
  6104. required:
  6105. - name
  6106. type: object
  6107. token:
  6108. description: use static token to authenticate with
  6109. properties:
  6110. bearerToken:
  6111. description: |-
  6112. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6113. In some instances, `key` is a required field.
  6114. properties:
  6115. key:
  6116. description: |-
  6117. A key in the referenced Secret.
  6118. Some instances of this field may be defaulted, in others it may be required.
  6119. maxLength: 253
  6120. minLength: 1
  6121. pattern: ^[-._a-zA-Z0-9]+$
  6122. type: string
  6123. name:
  6124. description: The name of the Secret resource being referred to.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6128. type: string
  6129. namespace:
  6130. description: |-
  6131. The namespace of the Secret resource being referred to.
  6132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6133. maxLength: 63
  6134. minLength: 1
  6135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6136. type: string
  6137. type: object
  6138. required:
  6139. - bearerToken
  6140. type: object
  6141. type: object
  6142. authRef:
  6143. description: A reference to a secret that contains the auth information.
  6144. properties:
  6145. key:
  6146. description: |-
  6147. A key in the referenced Secret.
  6148. Some instances of this field may be defaulted, in others it may be required.
  6149. maxLength: 253
  6150. minLength: 1
  6151. pattern: ^[-._a-zA-Z0-9]+$
  6152. type: string
  6153. name:
  6154. description: The name of the Secret resource being referred to.
  6155. maxLength: 253
  6156. minLength: 1
  6157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6158. type: string
  6159. namespace:
  6160. description: |-
  6161. The namespace of the Secret resource being referred to.
  6162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6163. maxLength: 63
  6164. minLength: 1
  6165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6166. type: string
  6167. type: object
  6168. remoteNamespace:
  6169. default: default
  6170. description: Remote namespace to fetch the secrets from
  6171. maxLength: 63
  6172. minLength: 1
  6173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6174. type: string
  6175. server:
  6176. description: configures the Kubernetes server Address.
  6177. properties:
  6178. caBundle:
  6179. description: CABundle is a base64-encoded CA certificate
  6180. format: byte
  6181. type: string
  6182. caProvider:
  6183. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6184. properties:
  6185. key:
  6186. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6187. maxLength: 253
  6188. minLength: 1
  6189. pattern: ^[-._a-zA-Z0-9]+$
  6190. type: string
  6191. name:
  6192. description: The name of the object located at the provider type.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6196. type: string
  6197. namespace:
  6198. description: |-
  6199. The namespace the Provider type is in.
  6200. Can only be defined when used in a ClusterSecretStore.
  6201. maxLength: 63
  6202. minLength: 1
  6203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6204. type: string
  6205. type:
  6206. description: The type of provider to use such as "Secret", or "ConfigMap".
  6207. enum:
  6208. - Secret
  6209. - ConfigMap
  6210. type: string
  6211. required:
  6212. - name
  6213. - type
  6214. type: object
  6215. url:
  6216. default: kubernetes.default
  6217. description: configures the Kubernetes server Address.
  6218. type: string
  6219. type: object
  6220. type: object
  6221. nebiusmysterybox:
  6222. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6223. properties:
  6224. apiDomain:
  6225. description: NebiusMysterybox API endpoint
  6226. type: string
  6227. auth:
  6228. description: Auth defines parameters to authenticate in MysteryBox
  6229. properties:
  6230. serviceAccountCredsSecretRef:
  6231. description: |-
  6232. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6233. document with service account credentials used to get an IAM token.
  6234. Expected JSON structure:
  6235. {
  6236. "subject-credentials": {
  6237. "alg": "RS256",
  6238. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6239. "kid": "<public-key-id>",
  6240. "iss": "<issuer-service-account-id>",
  6241. "sub": "<subject-service-account-id>"
  6242. }
  6243. }
  6244. properties:
  6245. key:
  6246. description: |-
  6247. A key in the referenced Secret.
  6248. Some instances of this field may be defaulted, in others it may be required.
  6249. maxLength: 253
  6250. minLength: 1
  6251. pattern: ^[-._a-zA-Z0-9]+$
  6252. type: string
  6253. name:
  6254. description: The name of the Secret resource being referred to.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6258. type: string
  6259. namespace:
  6260. description: |-
  6261. The namespace of the Secret resource being referred to.
  6262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6263. maxLength: 63
  6264. minLength: 1
  6265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6266. type: string
  6267. type: object
  6268. tokenSecretRef:
  6269. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6270. properties:
  6271. key:
  6272. description: |-
  6273. A key in the referenced Secret.
  6274. Some instances of this field may be defaulted, in others it may be required.
  6275. maxLength: 253
  6276. minLength: 1
  6277. pattern: ^[-._a-zA-Z0-9]+$
  6278. type: string
  6279. name:
  6280. description: The name of the Secret resource being referred to.
  6281. maxLength: 253
  6282. minLength: 1
  6283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6284. type: string
  6285. namespace:
  6286. description: |-
  6287. The namespace of the Secret resource being referred to.
  6288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6289. maxLength: 63
  6290. minLength: 1
  6291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6292. type: string
  6293. type: object
  6294. type: object
  6295. x-kubernetes-validations:
  6296. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6297. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6298. caProvider:
  6299. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6300. properties:
  6301. certSecretRef:
  6302. description: |-
  6303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6304. In some instances, `key` is a required field.
  6305. properties:
  6306. key:
  6307. description: |-
  6308. A key in the referenced Secret.
  6309. Some instances of this field may be defaulted, in others it may be required.
  6310. maxLength: 253
  6311. minLength: 1
  6312. pattern: ^[-._a-zA-Z0-9]+$
  6313. type: string
  6314. name:
  6315. description: The name of the Secret resource being referred to.
  6316. maxLength: 253
  6317. minLength: 1
  6318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6319. type: string
  6320. namespace:
  6321. description: |-
  6322. The namespace of the Secret resource being referred to.
  6323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6324. maxLength: 63
  6325. minLength: 1
  6326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6327. type: string
  6328. type: object
  6329. type: object
  6330. required:
  6331. - apiDomain
  6332. - auth
  6333. type: object
  6334. ngrok:
  6335. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6336. properties:
  6337. apiUrl:
  6338. default: https://api.ngrok.com
  6339. description: APIURL is the URL of the ngrok API.
  6340. type: string
  6341. auth:
  6342. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6343. maxProperties: 1
  6344. minProperties: 1
  6345. properties:
  6346. apiKey:
  6347. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6348. properties:
  6349. secretRef:
  6350. description: SecretRef is a reference to a secret containing the ngrok API key.
  6351. properties:
  6352. key:
  6353. description: |-
  6354. A key in the referenced Secret.
  6355. Some instances of this field may be defaulted, in others it may be required.
  6356. maxLength: 253
  6357. minLength: 1
  6358. pattern: ^[-._a-zA-Z0-9]+$
  6359. type: string
  6360. name:
  6361. description: The name of the Secret resource being referred to.
  6362. maxLength: 253
  6363. minLength: 1
  6364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6365. type: string
  6366. namespace:
  6367. description: |-
  6368. The namespace of the Secret resource being referred to.
  6369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6370. maxLength: 63
  6371. minLength: 1
  6372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6373. type: string
  6374. type: object
  6375. type: object
  6376. type: object
  6377. vault:
  6378. description: Vault configures the ngrok vault to sync secrets with.
  6379. properties:
  6380. name:
  6381. description: Name is the name of the ngrok vault to sync secrets with.
  6382. type: string
  6383. required:
  6384. - name
  6385. type: object
  6386. required:
  6387. - auth
  6388. - vault
  6389. type: object
  6390. onboardbase:
  6391. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6392. properties:
  6393. apiHost:
  6394. default: https://public.onboardbase.com/api/v1/
  6395. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6396. type: string
  6397. auth:
  6398. description: Auth configures how the Operator authenticates with the Onboardbase API
  6399. properties:
  6400. apiKeyRef:
  6401. description: |-
  6402. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6403. It is used to recognize and authorize access to a project and environment within onboardbase
  6404. properties:
  6405. key:
  6406. description: |-
  6407. A key in the referenced Secret.
  6408. Some instances of this field may be defaulted, in others it may be required.
  6409. maxLength: 253
  6410. minLength: 1
  6411. pattern: ^[-._a-zA-Z0-9]+$
  6412. type: string
  6413. name:
  6414. description: The name of the Secret resource being referred to.
  6415. maxLength: 253
  6416. minLength: 1
  6417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6418. type: string
  6419. namespace:
  6420. description: |-
  6421. The namespace of the Secret resource being referred to.
  6422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6423. maxLength: 63
  6424. minLength: 1
  6425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6426. type: string
  6427. type: object
  6428. passcodeRef:
  6429. description: OnboardbasePasscode is the passcode attached to the API Key
  6430. properties:
  6431. key:
  6432. description: |-
  6433. A key in the referenced Secret.
  6434. Some instances of this field may be defaulted, in others it may be required.
  6435. maxLength: 253
  6436. minLength: 1
  6437. pattern: ^[-._a-zA-Z0-9]+$
  6438. type: string
  6439. name:
  6440. description: The name of the Secret resource being referred to.
  6441. maxLength: 253
  6442. minLength: 1
  6443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6444. type: string
  6445. namespace:
  6446. description: |-
  6447. The namespace of the Secret resource being referred to.
  6448. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6449. maxLength: 63
  6450. minLength: 1
  6451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6452. type: string
  6453. type: object
  6454. required:
  6455. - apiKeyRef
  6456. - passcodeRef
  6457. type: object
  6458. environment:
  6459. default: development
  6460. description: Environment is the name of an environmnent within a project to pull the secrets from
  6461. type: string
  6462. project:
  6463. default: development
  6464. description: Project is an onboardbase project that the secrets should be pulled from
  6465. type: string
  6466. required:
  6467. - apiHost
  6468. - auth
  6469. - environment
  6470. - project
  6471. type: object
  6472. onepassword:
  6473. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6474. properties:
  6475. auth:
  6476. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6477. properties:
  6478. secretRef:
  6479. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6480. properties:
  6481. connectTokenSecretRef:
  6482. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6483. properties:
  6484. key:
  6485. description: |-
  6486. A key in the referenced Secret.
  6487. Some instances of this field may be defaulted, in others it may be required.
  6488. maxLength: 253
  6489. minLength: 1
  6490. pattern: ^[-._a-zA-Z0-9]+$
  6491. type: string
  6492. name:
  6493. description: The name of the Secret resource being referred to.
  6494. maxLength: 253
  6495. minLength: 1
  6496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6497. type: string
  6498. namespace:
  6499. description: |-
  6500. The namespace of the Secret resource being referred to.
  6501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6502. maxLength: 63
  6503. minLength: 1
  6504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6505. type: string
  6506. type: object
  6507. required:
  6508. - connectTokenSecretRef
  6509. type: object
  6510. required:
  6511. - secretRef
  6512. type: object
  6513. connectHost:
  6514. description: ConnectHost defines the OnePassword Connect Server to connect to
  6515. type: string
  6516. vaults:
  6517. additionalProperties:
  6518. type: integer
  6519. description: Vaults defines which OnePassword vaults to search in which order
  6520. type: object
  6521. required:
  6522. - auth
  6523. - connectHost
  6524. - vaults
  6525. type: object
  6526. onepasswordSDK:
  6527. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6528. properties:
  6529. auth:
  6530. description: Auth defines the information necessary to authenticate against OnePassword API.
  6531. properties:
  6532. serviceAccountSecretRef:
  6533. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6534. properties:
  6535. key:
  6536. description: |-
  6537. A key in the referenced Secret.
  6538. Some instances of this field may be defaulted, in others it may be required.
  6539. maxLength: 253
  6540. minLength: 1
  6541. pattern: ^[-._a-zA-Z0-9]+$
  6542. type: string
  6543. name:
  6544. description: The name of the Secret resource being referred to.
  6545. maxLength: 253
  6546. minLength: 1
  6547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6548. type: string
  6549. namespace:
  6550. description: |-
  6551. The namespace of the Secret resource being referred to.
  6552. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6553. maxLength: 63
  6554. minLength: 1
  6555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6556. type: string
  6557. type: object
  6558. required:
  6559. - serviceAccountSecretRef
  6560. type: object
  6561. cache:
  6562. description: |-
  6563. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6564. When enabled, secrets are cached with the specified TTL.
  6565. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6566. If omitted, caching is disabled (default).
  6567. cache: {} is a valid option to set.
  6568. properties:
  6569. maxSize:
  6570. default: 100
  6571. description: |-
  6572. MaxSize is the maximum number of secrets to cache.
  6573. When the cache is full, least-recently-used entries are evicted.
  6574. minimum: 1
  6575. type: integer
  6576. ttl:
  6577. default: 5m
  6578. description: |-
  6579. TTL is the time-to-live for cached secrets.
  6580. Format: duration string (e.g., "5m", "1h", "30s")
  6581. type: string
  6582. type: object
  6583. environment:
  6584. description: |-
  6585. Environment defines the 1Password Environment ID to read variables from.
  6586. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6587. Mutually exclusive with Vault.
  6588. type: string
  6589. integrationInfo:
  6590. description: |-
  6591. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6592. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6593. properties:
  6594. name:
  6595. default: 1Password SDK
  6596. description: Name defaults to "1Password SDK".
  6597. type: string
  6598. version:
  6599. default: v1.0.0
  6600. description: Version defaults to "v1.0.0".
  6601. type: string
  6602. type: object
  6603. vault:
  6604. description: |-
  6605. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6606. Mutually exclusive with Environment.
  6607. type: string
  6608. required:
  6609. - auth
  6610. type: object
  6611. x-kubernetes-validations:
  6612. - message: at most one of the fields in [vault environment] may be set
  6613. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6614. openBao:
  6615. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6616. properties:
  6617. auth:
  6618. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6619. properties:
  6620. appRole:
  6621. description: |-
  6622. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6623. with the role and secret stored in a Kubernetes Secret resource.
  6624. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6625. properties:
  6626. path:
  6627. default: approle
  6628. description: |-
  6629. Path where the App Role authentication backend is mounted
  6630. in OpenBao, e.g: "approle"
  6631. type: string
  6632. roleId:
  6633. description: |-
  6634. RoleID configured in the App Role authentication backend when setting
  6635. up the authentication backend in OpenBao.
  6636. minLength: 1
  6637. type: string
  6638. roleRef:
  6639. description: |-
  6640. Reference to a key in a Secret that contains the App Role ID used
  6641. to authenticate with OpenBao.
  6642. The `key` field must be specified and denotes which entry within the Secret
  6643. resource is used as the app role id.
  6644. properties:
  6645. key:
  6646. description: |-
  6647. A key in the referenced Secret.
  6648. Some instances of this field may be defaulted, in others it may be required.
  6649. maxLength: 253
  6650. minLength: 1
  6651. pattern: ^[-._a-zA-Z0-9]+$
  6652. type: string
  6653. name:
  6654. description: The name of the Secret resource being referred to.
  6655. maxLength: 253
  6656. minLength: 1
  6657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6658. type: string
  6659. namespace:
  6660. description: |-
  6661. The namespace of the Secret resource being referred to.
  6662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6663. maxLength: 63
  6664. minLength: 1
  6665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6666. type: string
  6667. type: object
  6668. secretRef:
  6669. description: |-
  6670. Reference to a key in a Secret that contains the App Role secret used
  6671. to authenticate with OpenBao.
  6672. The `key` field must be specified and denotes which entry within the Secret
  6673. resource is used as the app role secret.
  6674. properties:
  6675. key:
  6676. description: |-
  6677. A key in the referenced Secret.
  6678. Some instances of this field may be defaulted, in others it may be required.
  6679. maxLength: 253
  6680. minLength: 1
  6681. pattern: ^[-._a-zA-Z0-9]+$
  6682. type: string
  6683. name:
  6684. description: The name of the Secret resource being referred to.
  6685. maxLength: 253
  6686. minLength: 1
  6687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6688. type: string
  6689. namespace:
  6690. description: |-
  6691. The namespace of the Secret resource being referred to.
  6692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6693. maxLength: 63
  6694. minLength: 1
  6695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6696. type: string
  6697. type: object
  6698. required:
  6699. - path
  6700. - secretRef
  6701. type: object
  6702. x-kubernetes-validations:
  6703. - message: exactly one of the fields in [roleId roleRef] must be set
  6704. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6705. kubernetes:
  6706. description: |-
  6707. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  6708. token to the [Kubernetes auth mechanism].
  6709. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  6710. properties:
  6711. path:
  6712. default: kubernetes
  6713. description: |-
  6714. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  6715. "kubernetes"
  6716. type: string
  6717. role:
  6718. description: |-
  6719. A required field containing the OpenBao Role to assume. A Role binds a
  6720. Kubernetes ServiceAccount with a set of OpenBao policies.
  6721. minLength: 1
  6722. type: string
  6723. secretRef:
  6724. description: |-
  6725. Optional secret field containing a Kubernetes ServiceAccount JWT used
  6726. for authenticating with OpenBao. If a name is specified without a key,
  6727. `token` is the default.
  6728. properties:
  6729. key:
  6730. description: |-
  6731. A key in the referenced Secret.
  6732. Some instances of this field may be defaulted, in others it may be required.
  6733. maxLength: 253
  6734. minLength: 1
  6735. pattern: ^[-._a-zA-Z0-9]+$
  6736. type: string
  6737. name:
  6738. description: The name of the Secret resource being referred to.
  6739. maxLength: 253
  6740. minLength: 1
  6741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6742. type: string
  6743. namespace:
  6744. description: |-
  6745. The namespace of the Secret resource being referred to.
  6746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6747. maxLength: 63
  6748. minLength: 1
  6749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6750. type: string
  6751. type: object
  6752. serviceAccountRef:
  6753. description: |-
  6754. Optional service account field containing the name of a Kubernetes ServiceAccount.
  6755. If the service account is specified, a token will be requested from the Kubernetes
  6756. TokenRequest API for authenticating with OpenBao.
  6757. Any configured audiences will be passed to the TokenRequest as-is.
  6758. properties:
  6759. audiences:
  6760. description: |-
  6761. Audience specifies the `aud` claim for the service account token
  6762. Some providers automatically extend the audience field based on well-known annotations for workload
  6763. identity (e.g. IRSA or GCP Workload Identity)
  6764. items:
  6765. type: string
  6766. type: array
  6767. name:
  6768. description: The name of the ServiceAccount resource being referred to.
  6769. maxLength: 253
  6770. minLength: 1
  6771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6772. type: string
  6773. namespace:
  6774. description: |-
  6775. Namespace of the resource being referred to.
  6776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6777. maxLength: 63
  6778. minLength: 1
  6779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6780. type: string
  6781. required:
  6782. - name
  6783. type: object
  6784. required:
  6785. - path
  6786. - role
  6787. type: object
  6788. x-kubernetes-validations:
  6789. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  6790. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  6791. namespace:
  6792. description: |-
  6793. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6794. than the namespace your secret is in. Namespaces is a set of features
  6795. within OpenBao that allows OpenBao environments to support secure
  6796. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6797. if set, or empty otherwise
  6798. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6799. type: string
  6800. tokenSecretRef:
  6801. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6802. properties:
  6803. key:
  6804. description: |-
  6805. A key in the referenced Secret.
  6806. Some instances of this field may be defaulted, in others it may be required.
  6807. maxLength: 253
  6808. minLength: 1
  6809. pattern: ^[-._a-zA-Z0-9]+$
  6810. type: string
  6811. name:
  6812. description: The name of the Secret resource being referred to.
  6813. maxLength: 253
  6814. minLength: 1
  6815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6816. type: string
  6817. namespace:
  6818. description: |-
  6819. The namespace of the Secret resource being referred to.
  6820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6821. maxLength: 63
  6822. minLength: 1
  6823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6824. type: string
  6825. type: object
  6826. userPass:
  6827. description: UserPass authenticates with OpenBao by passing a username/password pair
  6828. properties:
  6829. path:
  6830. default: userpass
  6831. description: |-
  6832. Path where the UserPassword authentication backend is mounted
  6833. in OpenBao, e.g: "userpass"
  6834. type: string
  6835. secretRef:
  6836. description: |-
  6837. SecretRef to a key in a Secret resource containing password for the user
  6838. used to authenticate with OpenBao using the [UserPass authentication
  6839. method]
  6840. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6841. properties:
  6842. key:
  6843. description: |-
  6844. A key in the referenced Secret.
  6845. Some instances of this field may be defaulted, in others it may be required.
  6846. maxLength: 253
  6847. minLength: 1
  6848. pattern: ^[-._a-zA-Z0-9]+$
  6849. type: string
  6850. name:
  6851. description: The name of the Secret resource being referred to.
  6852. maxLength: 253
  6853. minLength: 1
  6854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6855. type: string
  6856. namespace:
  6857. description: |-
  6858. The namespace of the Secret resource being referred to.
  6859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6860. maxLength: 63
  6861. minLength: 1
  6862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6863. type: string
  6864. type: object
  6865. username:
  6866. description: |-
  6867. Username is a username used to authenticate using the [UserPass
  6868. authentication method]
  6869. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6870. type: string
  6871. required:
  6872. - path
  6873. - username
  6874. type: object
  6875. type: object
  6876. x-kubernetes-validations:
  6877. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  6878. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  6879. caBundle:
  6880. description: |-
  6881. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6882. this and `caProvider` are not set the system root certificates are used
  6883. to validate the TLS connection.
  6884. format: byte
  6885. type: string
  6886. caProvider:
  6887. description: |-
  6888. The provider for the CA bundle to use to validate OpenBao server
  6889. certificate. If this and `caBundle` are not set the system root
  6890. certificates are used to validate the TLS connection.
  6891. properties:
  6892. key:
  6893. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6894. maxLength: 253
  6895. minLength: 1
  6896. pattern: ^[-._a-zA-Z0-9]+$
  6897. type: string
  6898. name:
  6899. description: The name of the object located at the provider type.
  6900. maxLength: 253
  6901. minLength: 1
  6902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6903. type: string
  6904. namespace:
  6905. description: |-
  6906. The namespace the Provider type is in.
  6907. Can only be defined when used in a ClusterSecretStore.
  6908. maxLength: 63
  6909. minLength: 1
  6910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6911. type: string
  6912. type:
  6913. description: The type of provider to use such as "Secret", or "ConfigMap".
  6914. enum:
  6915. - Secret
  6916. - ConfigMap
  6917. type: string
  6918. required:
  6919. - name
  6920. - type
  6921. type: object
  6922. namespace:
  6923. description: |-
  6924. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6925. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6926. e.g: "ns1".
  6927. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6928. type: string
  6929. path:
  6930. description: |-
  6931. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6932. "secret". The v2 KV secret engine version specific "/data" path suffix
  6933. for fetching secrets from OpenBao is optional and will be appended
  6934. if not present in specified path.
  6935. type: string
  6936. server:
  6937. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6938. type: string
  6939. version:
  6940. default: v2
  6941. description: |-
  6942. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6943. "v2". Version defaults to "v2".
  6944. enum:
  6945. - v1
  6946. - v2
  6947. type: string
  6948. required:
  6949. - server
  6950. type: object
  6951. x-kubernetes-validations:
  6952. - message: at most one of the fields in [caBundle caProvider] may be set
  6953. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6954. oracle:
  6955. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6956. properties:
  6957. auth:
  6958. description: |-
  6959. Auth configures how secret-manager authenticates with the Oracle Vault.
  6960. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6961. properties:
  6962. secretRef:
  6963. description: SecretRef to pass through sensitive information.
  6964. properties:
  6965. fingerprint:
  6966. description: Fingerprint is the fingerprint of the API private key.
  6967. properties:
  6968. key:
  6969. description: |-
  6970. A key in the referenced Secret.
  6971. Some instances of this field may be defaulted, in others it may be required.
  6972. maxLength: 253
  6973. minLength: 1
  6974. pattern: ^[-._a-zA-Z0-9]+$
  6975. type: string
  6976. name:
  6977. description: The name of the Secret resource being referred to.
  6978. maxLength: 253
  6979. minLength: 1
  6980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6981. type: string
  6982. namespace:
  6983. description: |-
  6984. The namespace of the Secret resource being referred to.
  6985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6986. maxLength: 63
  6987. minLength: 1
  6988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6989. type: string
  6990. type: object
  6991. privatekey:
  6992. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6993. properties:
  6994. key:
  6995. description: |-
  6996. A key in the referenced Secret.
  6997. Some instances of this field may be defaulted, in others it may be required.
  6998. maxLength: 253
  6999. minLength: 1
  7000. pattern: ^[-._a-zA-Z0-9]+$
  7001. type: string
  7002. name:
  7003. description: The name of the Secret resource being referred to.
  7004. maxLength: 253
  7005. minLength: 1
  7006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7007. type: string
  7008. namespace:
  7009. description: |-
  7010. The namespace of the Secret resource being referred to.
  7011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7012. maxLength: 63
  7013. minLength: 1
  7014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7015. type: string
  7016. type: object
  7017. required:
  7018. - fingerprint
  7019. - privatekey
  7020. type: object
  7021. tenancy:
  7022. description: Tenancy is the tenancy OCID where user is located.
  7023. type: string
  7024. user:
  7025. description: User is an access OCID specific to the account.
  7026. type: string
  7027. required:
  7028. - secretRef
  7029. - tenancy
  7030. - user
  7031. type: object
  7032. compartment:
  7033. description: |-
  7034. Compartment is the vault compartment OCID.
  7035. Required for PushSecret
  7036. type: string
  7037. encryptionKey:
  7038. description: |-
  7039. EncryptionKey is the OCID of the encryption key within the vault.
  7040. Required for PushSecret
  7041. type: string
  7042. principalType:
  7043. description: |-
  7044. The type of principal to use for authentication. If left blank, the Auth struct will
  7045. determine the principal type. This optional field must be specified if using
  7046. workload identity.
  7047. enum:
  7048. - ""
  7049. - UserPrincipal
  7050. - InstancePrincipal
  7051. - Workload
  7052. type: string
  7053. region:
  7054. description: Region is the region where vault is located.
  7055. type: string
  7056. serviceAccountRef:
  7057. description: |-
  7058. ServiceAccountRef specified the service account
  7059. that should be used when authenticating with WorkloadIdentity.
  7060. properties:
  7061. audiences:
  7062. description: |-
  7063. Audience specifies the `aud` claim for the service account token
  7064. Some providers automatically extend the audience field based on well-known annotations for workload
  7065. identity (e.g. IRSA or GCP Workload Identity)
  7066. items:
  7067. type: string
  7068. type: array
  7069. name:
  7070. description: The name of the ServiceAccount resource being referred to.
  7071. maxLength: 253
  7072. minLength: 1
  7073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7074. type: string
  7075. namespace:
  7076. description: |-
  7077. Namespace of the resource being referred to.
  7078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7079. maxLength: 63
  7080. minLength: 1
  7081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7082. type: string
  7083. required:
  7084. - name
  7085. type: object
  7086. vault:
  7087. description: Vault is the vault's OCID of the specific vault where secret is located.
  7088. type: string
  7089. required:
  7090. - region
  7091. - vault
  7092. type: object
  7093. ovh:
  7094. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7095. properties:
  7096. auth:
  7097. description: Authentication method (mtls or token).
  7098. properties:
  7099. mtls:
  7100. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7101. properties:
  7102. caBundle:
  7103. format: byte
  7104. type: string
  7105. caProvider:
  7106. description: |-
  7107. CAProvider provides a custom certificate authority for accessing the provider's store.
  7108. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7109. properties:
  7110. key:
  7111. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7112. maxLength: 253
  7113. minLength: 1
  7114. pattern: ^[-._a-zA-Z0-9]+$
  7115. type: string
  7116. name:
  7117. description: The name of the object located at the provider type.
  7118. maxLength: 253
  7119. minLength: 1
  7120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7121. type: string
  7122. namespace:
  7123. description: |-
  7124. The namespace the Provider type is in.
  7125. Can only be defined when used in a ClusterSecretStore.
  7126. maxLength: 63
  7127. minLength: 1
  7128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7129. type: string
  7130. type:
  7131. description: The type of provider to use such as "Secret", or "ConfigMap".
  7132. enum:
  7133. - Secret
  7134. - ConfigMap
  7135. type: string
  7136. required:
  7137. - name
  7138. - type
  7139. type: object
  7140. certSecretRef:
  7141. description: |-
  7142. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7143. In some instances, `key` is a required field.
  7144. properties:
  7145. key:
  7146. description: |-
  7147. A key in the referenced Secret.
  7148. Some instances of this field may be defaulted, in others it may be required.
  7149. maxLength: 253
  7150. minLength: 1
  7151. pattern: ^[-._a-zA-Z0-9]+$
  7152. type: string
  7153. name:
  7154. description: The name of the Secret resource being referred to.
  7155. maxLength: 253
  7156. minLength: 1
  7157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7158. type: string
  7159. namespace:
  7160. description: |-
  7161. The namespace of the Secret resource being referred to.
  7162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7163. maxLength: 63
  7164. minLength: 1
  7165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7166. type: string
  7167. type: object
  7168. keySecretRef:
  7169. description: |-
  7170. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7171. In some instances, `key` is a required field.
  7172. properties:
  7173. key:
  7174. description: |-
  7175. A key in the referenced Secret.
  7176. Some instances of this field may be defaulted, in others it may be required.
  7177. maxLength: 253
  7178. minLength: 1
  7179. pattern: ^[-._a-zA-Z0-9]+$
  7180. type: string
  7181. name:
  7182. description: The name of the Secret resource being referred to.
  7183. maxLength: 253
  7184. minLength: 1
  7185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7186. type: string
  7187. namespace:
  7188. description: |-
  7189. The namespace of the Secret resource being referred to.
  7190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7191. maxLength: 63
  7192. minLength: 1
  7193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7194. type: string
  7195. type: object
  7196. required:
  7197. - certSecretRef
  7198. - keySecretRef
  7199. type: object
  7200. token:
  7201. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7202. properties:
  7203. tokenSecretRef:
  7204. description: |-
  7205. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7206. In some instances, `key` is a required field.
  7207. properties:
  7208. key:
  7209. description: |-
  7210. A key in the referenced Secret.
  7211. Some instances of this field may be defaulted, in others it may be required.
  7212. maxLength: 253
  7213. minLength: 1
  7214. pattern: ^[-._a-zA-Z0-9]+$
  7215. type: string
  7216. name:
  7217. description: The name of the Secret resource being referred to.
  7218. maxLength: 253
  7219. minLength: 1
  7220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7221. type: string
  7222. namespace:
  7223. description: |-
  7224. The namespace of the Secret resource being referred to.
  7225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7226. maxLength: 63
  7227. minLength: 1
  7228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7229. type: string
  7230. type: object
  7231. required:
  7232. - tokenSecretRef
  7233. type: object
  7234. type: object
  7235. casRequired:
  7236. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7237. type: boolean
  7238. okmsTimeout:
  7239. default: 30
  7240. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7241. format: int32
  7242. minimum: 1
  7243. type: integer
  7244. okmsid:
  7245. description: specifies the OKMS ID.
  7246. type: string
  7247. server:
  7248. description: specifies the OKMS server endpoint.
  7249. type: string
  7250. required:
  7251. - auth
  7252. - okmsid
  7253. - server
  7254. type: object
  7255. passbolt:
  7256. description: |-
  7257. PassboltProvider provides access to Passbolt secrets manager.
  7258. See: https://www.passbolt.com.
  7259. properties:
  7260. auth:
  7261. description: Auth defines the information necessary to authenticate against Passbolt Server
  7262. properties:
  7263. passwordSecretRef:
  7264. description: |-
  7265. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7266. In some instances, `key` is a required field.
  7267. properties:
  7268. key:
  7269. description: |-
  7270. A key in the referenced Secret.
  7271. Some instances of this field may be defaulted, in others it may be required.
  7272. maxLength: 253
  7273. minLength: 1
  7274. pattern: ^[-._a-zA-Z0-9]+$
  7275. type: string
  7276. name:
  7277. description: The name of the Secret resource being referred to.
  7278. maxLength: 253
  7279. minLength: 1
  7280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7281. type: string
  7282. namespace:
  7283. description: |-
  7284. The namespace of the Secret resource being referred to.
  7285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7286. maxLength: 63
  7287. minLength: 1
  7288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7289. type: string
  7290. type: object
  7291. privateKeySecretRef:
  7292. description: |-
  7293. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7294. In some instances, `key` is a required field.
  7295. properties:
  7296. key:
  7297. description: |-
  7298. A key in the referenced Secret.
  7299. Some instances of this field may be defaulted, in others it may be required.
  7300. maxLength: 253
  7301. minLength: 1
  7302. pattern: ^[-._a-zA-Z0-9]+$
  7303. type: string
  7304. name:
  7305. description: The name of the Secret resource being referred to.
  7306. maxLength: 253
  7307. minLength: 1
  7308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7309. type: string
  7310. namespace:
  7311. description: |-
  7312. The namespace of the Secret resource being referred to.
  7313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7314. maxLength: 63
  7315. minLength: 1
  7316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7317. type: string
  7318. type: object
  7319. required:
  7320. - passwordSecretRef
  7321. - privateKeySecretRef
  7322. type: object
  7323. caBundle:
  7324. description: |-
  7325. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7326. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7327. are used to validate the TLS connection.
  7328. format: byte
  7329. type: string
  7330. caProvider:
  7331. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7332. properties:
  7333. key:
  7334. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7335. maxLength: 253
  7336. minLength: 1
  7337. pattern: ^[-._a-zA-Z0-9]+$
  7338. type: string
  7339. name:
  7340. description: The name of the object located at the provider type.
  7341. maxLength: 253
  7342. minLength: 1
  7343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7344. type: string
  7345. namespace:
  7346. description: |-
  7347. The namespace the Provider type is in.
  7348. Can only be defined when used in a ClusterSecretStore.
  7349. maxLength: 63
  7350. minLength: 1
  7351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7352. type: string
  7353. type:
  7354. description: The type of provider to use such as "Secret", or "ConfigMap".
  7355. enum:
  7356. - Secret
  7357. - ConfigMap
  7358. type: string
  7359. required:
  7360. - name
  7361. - type
  7362. type: object
  7363. host:
  7364. description: Host defines the Passbolt Server to connect to
  7365. type: string
  7366. required:
  7367. - auth
  7368. - host
  7369. type: object
  7370. passworddepot:
  7371. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7372. properties:
  7373. auth:
  7374. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7375. properties:
  7376. secretRef:
  7377. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7378. properties:
  7379. credentials:
  7380. description: Username / Password is used for authentication.
  7381. properties:
  7382. key:
  7383. description: |-
  7384. A key in the referenced Secret.
  7385. Some instances of this field may be defaulted, in others it may be required.
  7386. maxLength: 253
  7387. minLength: 1
  7388. pattern: ^[-._a-zA-Z0-9]+$
  7389. type: string
  7390. name:
  7391. description: The name of the Secret resource being referred to.
  7392. maxLength: 253
  7393. minLength: 1
  7394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7395. type: string
  7396. namespace:
  7397. description: |-
  7398. The namespace of the Secret resource being referred to.
  7399. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7400. maxLength: 63
  7401. minLength: 1
  7402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7403. type: string
  7404. type: object
  7405. type: object
  7406. required:
  7407. - secretRef
  7408. type: object
  7409. database:
  7410. description: Database to use as source
  7411. type: string
  7412. host:
  7413. description: URL configures the Password Depot instance URL.
  7414. type: string
  7415. required:
  7416. - auth
  7417. - database
  7418. - host
  7419. type: object
  7420. previder:
  7421. description: Previder configures this store to sync secrets using the Previder provider
  7422. properties:
  7423. auth:
  7424. description: PreviderAuth contains a secretRef for credentials.
  7425. properties:
  7426. secretRef:
  7427. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7428. properties:
  7429. accessToken:
  7430. description: The AccessToken is used for authentication
  7431. properties:
  7432. key:
  7433. description: |-
  7434. A key in the referenced Secret.
  7435. Some instances of this field may be defaulted, in others it may be required.
  7436. maxLength: 253
  7437. minLength: 1
  7438. pattern: ^[-._a-zA-Z0-9]+$
  7439. type: string
  7440. name:
  7441. description: The name of the Secret resource being referred to.
  7442. maxLength: 253
  7443. minLength: 1
  7444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7445. type: string
  7446. namespace:
  7447. description: |-
  7448. The namespace of the Secret resource being referred to.
  7449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7450. maxLength: 63
  7451. minLength: 1
  7452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7453. type: string
  7454. type: object
  7455. required:
  7456. - accessToken
  7457. type: object
  7458. type: object
  7459. baseUri:
  7460. type: string
  7461. required:
  7462. - auth
  7463. type: object
  7464. pulumi:
  7465. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7466. properties:
  7467. accessToken:
  7468. description: |-
  7469. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7470. Deprecated: Use auth.accessToken instead.
  7471. properties:
  7472. secretRef:
  7473. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7474. properties:
  7475. key:
  7476. description: |-
  7477. A key in the referenced Secret.
  7478. Some instances of this field may be defaulted, in others it may be required.
  7479. maxLength: 253
  7480. minLength: 1
  7481. pattern: ^[-._a-zA-Z0-9]+$
  7482. type: string
  7483. name:
  7484. description: The name of the Secret resource being referred to.
  7485. maxLength: 253
  7486. minLength: 1
  7487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7488. type: string
  7489. namespace:
  7490. description: |-
  7491. The namespace of the Secret resource being referred to.
  7492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7493. maxLength: 63
  7494. minLength: 1
  7495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7496. type: string
  7497. type: object
  7498. type: object
  7499. apiUrl:
  7500. default: https://api.pulumi.com/api/esc
  7501. description: APIURL is the URL of the Pulumi API.
  7502. type: string
  7503. auth:
  7504. description: |-
  7505. Auth configures how the Operator authenticates with the Pulumi API.
  7506. Either auth or the deprecated accessToken field must be specified.
  7507. properties:
  7508. accessToken:
  7509. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7510. properties:
  7511. secretRef:
  7512. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7513. properties:
  7514. key:
  7515. description: |-
  7516. A key in the referenced Secret.
  7517. Some instances of this field may be defaulted, in others it may be required.
  7518. maxLength: 253
  7519. minLength: 1
  7520. pattern: ^[-._a-zA-Z0-9]+$
  7521. type: string
  7522. name:
  7523. description: The name of the Secret resource being referred to.
  7524. maxLength: 253
  7525. minLength: 1
  7526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7527. type: string
  7528. namespace:
  7529. description: |-
  7530. The namespace of the Secret resource being referred to.
  7531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7532. maxLength: 63
  7533. minLength: 1
  7534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7535. type: string
  7536. type: object
  7537. type: object
  7538. oidcConfig:
  7539. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7540. properties:
  7541. expirationSeconds:
  7542. default: 600
  7543. description: |-
  7544. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7545. Defaults to 10 minutes.
  7546. format: int64
  7547. minimum: 600
  7548. type: integer
  7549. organization:
  7550. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7551. type: string
  7552. serviceAccountRef:
  7553. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7554. properties:
  7555. audiences:
  7556. description: |-
  7557. Audience specifies the `aud` claim for the service account token
  7558. Some providers automatically extend the audience field based on well-known annotations for workload
  7559. identity (e.g. IRSA or GCP Workload Identity)
  7560. items:
  7561. type: string
  7562. type: array
  7563. name:
  7564. description: The name of the ServiceAccount resource being referred to.
  7565. maxLength: 253
  7566. minLength: 1
  7567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7568. type: string
  7569. namespace:
  7570. description: |-
  7571. Namespace of the resource being referred to.
  7572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7573. maxLength: 63
  7574. minLength: 1
  7575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7576. type: string
  7577. required:
  7578. - name
  7579. type: object
  7580. required:
  7581. - organization
  7582. - serviceAccountRef
  7583. type: object
  7584. type: object
  7585. x-kubernetes-validations:
  7586. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7587. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7588. environment:
  7589. description: |-
  7590. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7591. dynamically retrieved values from supported providers including all major clouds,
  7592. and other Pulumi ESC environments.
  7593. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7594. type: string
  7595. organization:
  7596. description: |-
  7597. Organization are a space to collaborate on shared projects and stacks.
  7598. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7599. type: string
  7600. project:
  7601. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7602. type: string
  7603. required:
  7604. - environment
  7605. - organization
  7606. - project
  7607. type: object
  7608. x-kubernetes-validations:
  7609. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7610. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7611. scaleway:
  7612. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7613. properties:
  7614. accessKey:
  7615. description: AccessKey is the non-secret part of the api key.
  7616. properties:
  7617. secretRef:
  7618. description: SecretRef references a key in a secret that will be used as value.
  7619. properties:
  7620. key:
  7621. description: |-
  7622. A key in the referenced Secret.
  7623. Some instances of this field may be defaulted, in others it may be required.
  7624. maxLength: 253
  7625. minLength: 1
  7626. pattern: ^[-._a-zA-Z0-9]+$
  7627. type: string
  7628. name:
  7629. description: The name of the Secret resource being referred to.
  7630. maxLength: 253
  7631. minLength: 1
  7632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7633. type: string
  7634. namespace:
  7635. description: |-
  7636. The namespace of the Secret resource being referred to.
  7637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7638. maxLength: 63
  7639. minLength: 1
  7640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7641. type: string
  7642. type: object
  7643. value:
  7644. description: Value can be specified directly to set a value without using a secret.
  7645. type: string
  7646. type: object
  7647. apiUrl:
  7648. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7649. type: string
  7650. projectId:
  7651. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7652. type: string
  7653. region:
  7654. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7655. type: string
  7656. secretKey:
  7657. description: SecretKey is the non-secret part of the api key.
  7658. properties:
  7659. secretRef:
  7660. description: SecretRef references a key in a secret that will be used as value.
  7661. properties:
  7662. key:
  7663. description: |-
  7664. A key in the referenced Secret.
  7665. Some instances of this field may be defaulted, in others it may be required.
  7666. maxLength: 253
  7667. minLength: 1
  7668. pattern: ^[-._a-zA-Z0-9]+$
  7669. type: string
  7670. name:
  7671. description: The name of the Secret resource being referred to.
  7672. maxLength: 253
  7673. minLength: 1
  7674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7675. type: string
  7676. namespace:
  7677. description: |-
  7678. The namespace of the Secret resource being referred to.
  7679. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7680. maxLength: 63
  7681. minLength: 1
  7682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7683. type: string
  7684. type: object
  7685. value:
  7686. description: Value can be specified directly to set a value without using a secret.
  7687. type: string
  7688. type: object
  7689. required:
  7690. - accessKey
  7691. - projectId
  7692. - region
  7693. - secretKey
  7694. type: object
  7695. secretserver:
  7696. description: |-
  7697. SecretServer configures this store to sync secrets using SecretServer provider
  7698. https://docs.delinea.com/online-help/secret-server/start.htm
  7699. properties:
  7700. caBundle:
  7701. description: |-
  7702. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7703. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7704. are used to validate the TLS connection.
  7705. format: byte
  7706. type: string
  7707. caProvider:
  7708. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7709. properties:
  7710. key:
  7711. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7712. maxLength: 253
  7713. minLength: 1
  7714. pattern: ^[-._a-zA-Z0-9]+$
  7715. type: string
  7716. name:
  7717. description: The name of the object located at the provider type.
  7718. maxLength: 253
  7719. minLength: 1
  7720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7721. type: string
  7722. namespace:
  7723. description: |-
  7724. The namespace the Provider type is in.
  7725. Can only be defined when used in a ClusterSecretStore.
  7726. maxLength: 63
  7727. minLength: 1
  7728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7729. type: string
  7730. type:
  7731. description: The type of provider to use such as "Secret", or "ConfigMap".
  7732. enum:
  7733. - Secret
  7734. - ConfigMap
  7735. type: string
  7736. required:
  7737. - name
  7738. - type
  7739. type: object
  7740. disableSiteIDValidation:
  7741. description: |-
  7742. DisableSiteIDValidation permits a missing site ID for new secrets.
  7743. The provider sends 0 if no site ID is set.
  7744. type: boolean
  7745. domain:
  7746. description: Domain is the secret server domain.
  7747. type: string
  7748. password:
  7749. description: |-
  7750. Password is the secret server account password.
  7751. Required unless Token is set.
  7752. properties:
  7753. secretRef:
  7754. description: SecretRef references a key in a secret that will be used as value.
  7755. properties:
  7756. key:
  7757. description: |-
  7758. A key in the referenced Secret.
  7759. Some instances of this field may be defaulted, in others it may be required.
  7760. maxLength: 253
  7761. minLength: 1
  7762. pattern: ^[-._a-zA-Z0-9]+$
  7763. type: string
  7764. name:
  7765. description: The name of the Secret resource being referred to.
  7766. maxLength: 253
  7767. minLength: 1
  7768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7769. type: string
  7770. namespace:
  7771. description: |-
  7772. The namespace of the Secret resource being referred to.
  7773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7774. maxLength: 63
  7775. minLength: 1
  7776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7777. type: string
  7778. type: object
  7779. value:
  7780. description: Value can be specified directly to set a value without using a secret.
  7781. minLength: 1
  7782. type: string
  7783. type: object
  7784. x-kubernetes-validations:
  7785. - message: exactly one of value or secretRef must be set
  7786. rule: has(self.value) != has(self.secretRef)
  7787. serverURL:
  7788. description: |-
  7789. ServerURL
  7790. URL to your secret server installation
  7791. type: string
  7792. siteId:
  7793. description: |-
  7794. SiteID is the ID of the Secret Server site for new secrets.
  7795. PushSecret metadata can override this value for one secret.
  7796. The provider uses 1 if this field is not set.
  7797. minimum: 1
  7798. type: integer
  7799. token:
  7800. description: |-
  7801. Token is an access token used to authenticate to the secret server,
  7802. as an alternative to Username and Password. When set, Username and
  7803. Password are not required and are ignored.
  7804. properties:
  7805. secretRef:
  7806. description: SecretRef references a key in a secret that will be used as value.
  7807. properties:
  7808. key:
  7809. description: |-
  7810. A key in the referenced Secret.
  7811. Some instances of this field may be defaulted, in others it may be required.
  7812. maxLength: 253
  7813. minLength: 1
  7814. pattern: ^[-._a-zA-Z0-9]+$
  7815. type: string
  7816. name:
  7817. description: The name of the Secret resource being referred to.
  7818. maxLength: 253
  7819. minLength: 1
  7820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7821. type: string
  7822. namespace:
  7823. description: |-
  7824. The namespace of the Secret resource being referred to.
  7825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7826. maxLength: 63
  7827. minLength: 1
  7828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7829. type: string
  7830. type: object
  7831. value:
  7832. description: Value can be specified directly to set a value without using a secret.
  7833. minLength: 1
  7834. type: string
  7835. type: object
  7836. x-kubernetes-validations:
  7837. - message: exactly one of value or secretRef must be set
  7838. rule: has(self.value) != has(self.secretRef)
  7839. username:
  7840. description: |-
  7841. Username is the secret server account username.
  7842. Required unless Token is set.
  7843. properties:
  7844. secretRef:
  7845. description: SecretRef references a key in a secret that will be used as value.
  7846. properties:
  7847. key:
  7848. description: |-
  7849. A key in the referenced Secret.
  7850. Some instances of this field may be defaulted, in others it may be required.
  7851. maxLength: 253
  7852. minLength: 1
  7853. pattern: ^[-._a-zA-Z0-9]+$
  7854. type: string
  7855. name:
  7856. description: The name of the Secret resource being referred to.
  7857. maxLength: 253
  7858. minLength: 1
  7859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7860. type: string
  7861. namespace:
  7862. description: |-
  7863. The namespace of the Secret resource being referred to.
  7864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7865. maxLength: 63
  7866. minLength: 1
  7867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7868. type: string
  7869. type: object
  7870. value:
  7871. description: Value can be specified directly to set a value without using a secret.
  7872. minLength: 1
  7873. type: string
  7874. type: object
  7875. x-kubernetes-validations:
  7876. - message: exactly one of value or secretRef must be set
  7877. rule: has(self.value) != has(self.secretRef)
  7878. required:
  7879. - serverURL
  7880. type: object
  7881. x-kubernetes-validations:
  7882. - message: either token, or both username and password, must be set
  7883. rule: has(self.token) || (has(self.username) && has(self.password))
  7884. senhasegura:
  7885. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7886. properties:
  7887. auth:
  7888. description: Auth defines parameters to authenticate in senhasegura
  7889. properties:
  7890. clientId:
  7891. type: string
  7892. clientSecretSecretRef:
  7893. description: |-
  7894. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7895. In some instances, `key` is a required field.
  7896. properties:
  7897. key:
  7898. description: |-
  7899. A key in the referenced Secret.
  7900. Some instances of this field may be defaulted, in others it may be required.
  7901. maxLength: 253
  7902. minLength: 1
  7903. pattern: ^[-._a-zA-Z0-9]+$
  7904. type: string
  7905. name:
  7906. description: The name of the Secret resource being referred to.
  7907. maxLength: 253
  7908. minLength: 1
  7909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7910. type: string
  7911. namespace:
  7912. description: |-
  7913. The namespace of the Secret resource being referred to.
  7914. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7915. maxLength: 63
  7916. minLength: 1
  7917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7918. type: string
  7919. type: object
  7920. required:
  7921. - clientId
  7922. - clientSecretSecretRef
  7923. type: object
  7924. ignoreSslCertificate:
  7925. default: false
  7926. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7927. type: boolean
  7928. module:
  7929. description: Module defines which senhasegura module should be used to get secrets
  7930. type: string
  7931. url:
  7932. description: URL of senhasegura
  7933. type: string
  7934. required:
  7935. - auth
  7936. - module
  7937. - url
  7938. type: object
  7939. vault:
  7940. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7941. properties:
  7942. auth:
  7943. description: Auth configures how secret-manager authenticates with the Vault server.
  7944. properties:
  7945. appRole:
  7946. description: |-
  7947. AppRole authenticates with Vault using the App Role auth mechanism,
  7948. with the role and secret stored in a Kubernetes Secret resource.
  7949. properties:
  7950. path:
  7951. default: approle
  7952. description: |-
  7953. Path where the App Role authentication backend is mounted
  7954. in Vault, e.g: "approle"
  7955. type: string
  7956. roleId:
  7957. description: |-
  7958. RoleID configured in the App Role authentication backend when setting
  7959. up the authentication backend in Vault.
  7960. type: string
  7961. roleRef:
  7962. description: |-
  7963. Reference to a key in a Secret that contains the App Role ID used
  7964. to authenticate with Vault.
  7965. The `key` field must be specified and denotes which entry within the Secret
  7966. resource is used as the app role id.
  7967. properties:
  7968. key:
  7969. description: |-
  7970. A key in the referenced Secret.
  7971. Some instances of this field may be defaulted, in others it may be required.
  7972. maxLength: 253
  7973. minLength: 1
  7974. pattern: ^[-._a-zA-Z0-9]+$
  7975. type: string
  7976. name:
  7977. description: The name of the Secret resource being referred to.
  7978. maxLength: 253
  7979. minLength: 1
  7980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7981. type: string
  7982. namespace:
  7983. description: |-
  7984. The namespace of the Secret resource being referred to.
  7985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7986. maxLength: 63
  7987. minLength: 1
  7988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7989. type: string
  7990. type: object
  7991. secretRef:
  7992. description: |-
  7993. Reference to a key in a Secret that contains the App Role secret used
  7994. to authenticate with Vault.
  7995. The `key` field must be specified and denotes which entry within the Secret
  7996. resource is used as the app role secret.
  7997. properties:
  7998. key:
  7999. description: |-
  8000. A key in the referenced Secret.
  8001. Some instances of this field may be defaulted, in others it may be required.
  8002. maxLength: 253
  8003. minLength: 1
  8004. pattern: ^[-._a-zA-Z0-9]+$
  8005. type: string
  8006. name:
  8007. description: The name of the Secret resource being referred to.
  8008. maxLength: 253
  8009. minLength: 1
  8010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8011. type: string
  8012. namespace:
  8013. description: |-
  8014. The namespace of the Secret resource being referred to.
  8015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8016. maxLength: 63
  8017. minLength: 1
  8018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8019. type: string
  8020. type: object
  8021. required:
  8022. - path
  8023. - secretRef
  8024. type: object
  8025. cert:
  8026. description: |-
  8027. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  8028. Cert authentication method
  8029. properties:
  8030. clientCert:
  8031. description: |-
  8032. ClientCert is a certificate to authenticate using the Cert Vault
  8033. authentication method
  8034. properties:
  8035. key:
  8036. description: |-
  8037. A key in the referenced Secret.
  8038. Some instances of this field may be defaulted, in others it may be required.
  8039. maxLength: 253
  8040. minLength: 1
  8041. pattern: ^[-._a-zA-Z0-9]+$
  8042. type: string
  8043. name:
  8044. description: The name of the Secret resource being referred to.
  8045. maxLength: 253
  8046. minLength: 1
  8047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8048. type: string
  8049. namespace:
  8050. description: |-
  8051. The namespace of the Secret resource being referred to.
  8052. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8053. maxLength: 63
  8054. minLength: 1
  8055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8056. type: string
  8057. type: object
  8058. path:
  8059. default: cert
  8060. description: |-
  8061. Path where the Certificate authentication backend is mounted
  8062. in Vault, e.g: "cert"
  8063. type: string
  8064. secretRef:
  8065. description: |-
  8066. SecretRef to a key in a Secret resource containing client private key to
  8067. authenticate with Vault using the Cert authentication method
  8068. properties:
  8069. key:
  8070. description: |-
  8071. A key in the referenced Secret.
  8072. Some instances of this field may be defaulted, in others it may be required.
  8073. maxLength: 253
  8074. minLength: 1
  8075. pattern: ^[-._a-zA-Z0-9]+$
  8076. type: string
  8077. name:
  8078. description: The name of the Secret resource being referred to.
  8079. maxLength: 253
  8080. minLength: 1
  8081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8082. type: string
  8083. namespace:
  8084. description: |-
  8085. The namespace of the Secret resource being referred to.
  8086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8087. maxLength: 63
  8088. minLength: 1
  8089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8090. type: string
  8091. type: object
  8092. vaultRole:
  8093. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8094. type: string
  8095. type: object
  8096. gcp:
  8097. description: |-
  8098. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8099. GCP authentication method
  8100. properties:
  8101. location:
  8102. description: Location optionally defines a location/region for the secret
  8103. type: string
  8104. path:
  8105. default: gcp
  8106. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8107. type: string
  8108. projectID:
  8109. description: Project ID of the Google Cloud Platform project
  8110. type: string
  8111. role:
  8112. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8113. type: string
  8114. secretRef:
  8115. description: Specify credentials in a Secret object
  8116. properties:
  8117. secretAccessKeySecretRef:
  8118. description: The SecretAccessKey is used for authentication
  8119. properties:
  8120. key:
  8121. description: |-
  8122. A key in the referenced Secret.
  8123. Some instances of this field may be defaulted, in others it may be required.
  8124. maxLength: 253
  8125. minLength: 1
  8126. pattern: ^[-._a-zA-Z0-9]+$
  8127. type: string
  8128. name:
  8129. description: The name of the Secret resource being referred to.
  8130. maxLength: 253
  8131. minLength: 1
  8132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8133. type: string
  8134. namespace:
  8135. description: |-
  8136. The namespace of the Secret resource being referred to.
  8137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8138. maxLength: 63
  8139. minLength: 1
  8140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8141. type: string
  8142. type: object
  8143. type: object
  8144. serviceAccountRef:
  8145. description: ServiceAccountRef to a service account for impersonation
  8146. properties:
  8147. audiences:
  8148. description: |-
  8149. Audience specifies the `aud` claim for the service account token
  8150. Some providers automatically extend the audience field based on well-known annotations for workload
  8151. identity (e.g. IRSA or GCP Workload Identity)
  8152. items:
  8153. type: string
  8154. type: array
  8155. name:
  8156. description: The name of the ServiceAccount resource being referred to.
  8157. maxLength: 253
  8158. minLength: 1
  8159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8160. type: string
  8161. namespace:
  8162. description: |-
  8163. Namespace of the resource being referred to.
  8164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8165. maxLength: 63
  8166. minLength: 1
  8167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8168. type: string
  8169. required:
  8170. - name
  8171. type: object
  8172. workloadIdentity:
  8173. description: Specify a service account with Workload Identity
  8174. properties:
  8175. clusterLocation:
  8176. description: |-
  8177. ClusterLocation is the location of the cluster
  8178. If not specified, it fetches information from the metadata server
  8179. type: string
  8180. clusterName:
  8181. description: |-
  8182. ClusterName is the name of the cluster
  8183. If not specified, it fetches information from the metadata server
  8184. type: string
  8185. clusterProjectID:
  8186. description: |-
  8187. ClusterProjectID is the project ID of the cluster
  8188. If not specified, it fetches information from the metadata server
  8189. type: string
  8190. serviceAccountRef:
  8191. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8192. properties:
  8193. audiences:
  8194. description: |-
  8195. Audience specifies the `aud` claim for the service account token
  8196. Some providers automatically extend the audience field based on well-known annotations for workload
  8197. identity (e.g. IRSA or GCP Workload Identity)
  8198. items:
  8199. type: string
  8200. type: array
  8201. name:
  8202. description: The name of the ServiceAccount resource being referred to.
  8203. maxLength: 253
  8204. minLength: 1
  8205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8206. type: string
  8207. namespace:
  8208. description: |-
  8209. Namespace of the resource being referred to.
  8210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8211. maxLength: 63
  8212. minLength: 1
  8213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8214. type: string
  8215. required:
  8216. - name
  8217. type: object
  8218. required:
  8219. - serviceAccountRef
  8220. type: object
  8221. required:
  8222. - role
  8223. type: object
  8224. iam:
  8225. description: |-
  8226. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8227. AWS IAM authentication method
  8228. properties:
  8229. externalID:
  8230. description: AWS External ID set on assumed IAM roles
  8231. type: string
  8232. jwt:
  8233. description: Specify a service account with IRSA enabled
  8234. properties:
  8235. serviceAccountRef:
  8236. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8237. properties:
  8238. audiences:
  8239. description: |-
  8240. Audience specifies the `aud` claim for the service account token
  8241. Some providers automatically extend the audience field based on well-known annotations for workload
  8242. identity (e.g. IRSA or GCP Workload Identity)
  8243. items:
  8244. type: string
  8245. type: array
  8246. name:
  8247. description: The name of the ServiceAccount resource being referred to.
  8248. maxLength: 253
  8249. minLength: 1
  8250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8251. type: string
  8252. namespace:
  8253. description: |-
  8254. Namespace of the resource being referred to.
  8255. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8256. maxLength: 63
  8257. minLength: 1
  8258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8259. type: string
  8260. required:
  8261. - name
  8262. type: object
  8263. type: object
  8264. path:
  8265. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8266. type: string
  8267. region:
  8268. description: AWS region
  8269. type: string
  8270. role:
  8271. description: This is the AWS role to be assumed before talking to vault
  8272. type: string
  8273. secretRef:
  8274. description: Specify credentials in a Secret object
  8275. properties:
  8276. accessKeyIDSecretRef:
  8277. description: The AccessKeyID is used for authentication
  8278. properties:
  8279. key:
  8280. description: |-
  8281. A key in the referenced Secret.
  8282. Some instances of this field may be defaulted, in others it may be required.
  8283. maxLength: 253
  8284. minLength: 1
  8285. pattern: ^[-._a-zA-Z0-9]+$
  8286. type: string
  8287. name:
  8288. description: The name of the Secret resource being referred to.
  8289. maxLength: 253
  8290. minLength: 1
  8291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8292. type: string
  8293. namespace:
  8294. description: |-
  8295. The namespace of the Secret resource being referred to.
  8296. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8297. maxLength: 63
  8298. minLength: 1
  8299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8300. type: string
  8301. type: object
  8302. secretAccessKeySecretRef:
  8303. description: The SecretAccessKey is used for authentication
  8304. properties:
  8305. key:
  8306. description: |-
  8307. A key in the referenced Secret.
  8308. Some instances of this field may be defaulted, in others it may be required.
  8309. maxLength: 253
  8310. minLength: 1
  8311. pattern: ^[-._a-zA-Z0-9]+$
  8312. type: string
  8313. name:
  8314. description: The name of the Secret resource being referred to.
  8315. maxLength: 253
  8316. minLength: 1
  8317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8318. type: string
  8319. namespace:
  8320. description: |-
  8321. The namespace of the Secret resource being referred to.
  8322. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8323. maxLength: 63
  8324. minLength: 1
  8325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8326. type: string
  8327. type: object
  8328. sessionTokenSecretRef:
  8329. description: |-
  8330. The SessionToken used for authentication
  8331. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8332. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8333. properties:
  8334. key:
  8335. description: |-
  8336. A key in the referenced Secret.
  8337. Some instances of this field may be defaulted, in others it may be required.
  8338. maxLength: 253
  8339. minLength: 1
  8340. pattern: ^[-._a-zA-Z0-9]+$
  8341. type: string
  8342. name:
  8343. description: The name of the Secret resource being referred to.
  8344. maxLength: 253
  8345. minLength: 1
  8346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8347. type: string
  8348. namespace:
  8349. description: |-
  8350. The namespace of the Secret resource being referred to.
  8351. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8352. maxLength: 63
  8353. minLength: 1
  8354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8355. type: string
  8356. type: object
  8357. type: object
  8358. vaultAwsIamServerID:
  8359. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8360. type: string
  8361. vaultRole:
  8362. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8363. type: string
  8364. required:
  8365. - vaultRole
  8366. type: object
  8367. jwt:
  8368. description: |-
  8369. Jwt authenticates with Vault by passing role and JWT token using the
  8370. JWT/OIDC authentication method
  8371. properties:
  8372. kubernetesServiceAccountToken:
  8373. description: |-
  8374. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8375. a token for with the `TokenRequest` API.
  8376. properties:
  8377. audiences:
  8378. description: |-
  8379. Optional audiences field that will be used to request a temporary Kubernetes service
  8380. account token for the service account referenced by `serviceAccountRef`.
  8381. Defaults to a single audience `vault` it not specified.
  8382. Deprecated: use serviceAccountRef.Audiences instead
  8383. items:
  8384. type: string
  8385. type: array
  8386. expirationSeconds:
  8387. description: |-
  8388. Optional expiration time in seconds that will be used to request a temporary
  8389. Kubernetes service account token for the service account referenced by
  8390. `serviceAccountRef`.
  8391. Deprecated: this will be removed in the future.
  8392. Defaults to 10 minutes.
  8393. format: int64
  8394. type: integer
  8395. serviceAccountRef:
  8396. description: Service account field containing the name of a kubernetes ServiceAccount.
  8397. properties:
  8398. audiences:
  8399. description: |-
  8400. Audience specifies the `aud` claim for the service account token
  8401. Some providers automatically extend the audience field based on well-known annotations for workload
  8402. identity (e.g. IRSA or GCP Workload Identity)
  8403. items:
  8404. type: string
  8405. type: array
  8406. name:
  8407. description: The name of the ServiceAccount resource being referred to.
  8408. maxLength: 253
  8409. minLength: 1
  8410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8411. type: string
  8412. namespace:
  8413. description: |-
  8414. Namespace of the resource being referred to.
  8415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8416. maxLength: 63
  8417. minLength: 1
  8418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8419. type: string
  8420. required:
  8421. - name
  8422. type: object
  8423. required:
  8424. - serviceAccountRef
  8425. type: object
  8426. path:
  8427. default: jwt
  8428. description: |-
  8429. Path where the JWT authentication backend is mounted
  8430. in Vault, e.g: "jwt"
  8431. type: string
  8432. role:
  8433. description: |-
  8434. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8435. authentication method
  8436. type: string
  8437. secretRef:
  8438. description: |-
  8439. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8440. authenticate with Vault using the JWT/OIDC authentication method.
  8441. properties:
  8442. key:
  8443. description: |-
  8444. A key in the referenced Secret.
  8445. Some instances of this field may be defaulted, in others it may be required.
  8446. maxLength: 253
  8447. minLength: 1
  8448. pattern: ^[-._a-zA-Z0-9]+$
  8449. type: string
  8450. name:
  8451. description: The name of the Secret resource being referred to.
  8452. maxLength: 253
  8453. minLength: 1
  8454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8455. type: string
  8456. namespace:
  8457. description: |-
  8458. The namespace of the Secret resource being referred to.
  8459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8460. maxLength: 63
  8461. minLength: 1
  8462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8463. type: string
  8464. type: object
  8465. required:
  8466. - path
  8467. type: object
  8468. kubernetes:
  8469. description: |-
  8470. Kubernetes authenticates with Vault by passing the ServiceAccount
  8471. token stored in the named Secret resource to the Vault server.
  8472. properties:
  8473. mountPath:
  8474. default: kubernetes
  8475. description: |-
  8476. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8477. "kubernetes"
  8478. type: string
  8479. role:
  8480. description: |-
  8481. A required field containing the Vault Role to assume. A Role binds a
  8482. Kubernetes ServiceAccount with a set of Vault policies.
  8483. type: string
  8484. secretRef:
  8485. description: |-
  8486. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8487. for authenticating with Vault. If a name is specified without a key,
  8488. `token` is the default. If one is not specified, the one bound to
  8489. the controller will be used.
  8490. properties:
  8491. key:
  8492. description: |-
  8493. A key in the referenced Secret.
  8494. Some instances of this field may be defaulted, in others it may be required.
  8495. maxLength: 253
  8496. minLength: 1
  8497. pattern: ^[-._a-zA-Z0-9]+$
  8498. type: string
  8499. name:
  8500. description: The name of the Secret resource being referred to.
  8501. maxLength: 253
  8502. minLength: 1
  8503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8504. type: string
  8505. namespace:
  8506. description: |-
  8507. The namespace of the Secret resource being referred to.
  8508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8509. maxLength: 63
  8510. minLength: 1
  8511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8512. type: string
  8513. type: object
  8514. serviceAccountRef:
  8515. description: |-
  8516. Optional service account field containing the name of a kubernetes ServiceAccount.
  8517. If the service account is specified, the service account secret token JWT will be used
  8518. for authenticating with Vault. If the service account selector is not supplied,
  8519. the secretRef will be used instead.
  8520. properties:
  8521. audiences:
  8522. description: |-
  8523. Audience specifies the `aud` claim for the service account token
  8524. Some providers automatically extend the audience field based on well-known annotations for workload
  8525. identity (e.g. IRSA or GCP Workload Identity)
  8526. items:
  8527. type: string
  8528. type: array
  8529. name:
  8530. description: The name of the ServiceAccount resource being referred to.
  8531. maxLength: 253
  8532. minLength: 1
  8533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8534. type: string
  8535. namespace:
  8536. description: |-
  8537. Namespace of the resource being referred to.
  8538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8539. maxLength: 63
  8540. minLength: 1
  8541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8542. type: string
  8543. required:
  8544. - name
  8545. type: object
  8546. required:
  8547. - mountPath
  8548. - role
  8549. type: object
  8550. ldap:
  8551. description: |-
  8552. Ldap authenticates with Vault by passing username/password pair using
  8553. the LDAP authentication method
  8554. properties:
  8555. path:
  8556. default: ldap
  8557. description: |-
  8558. Path where the LDAP authentication backend is mounted
  8559. in Vault, e.g: "ldap"
  8560. type: string
  8561. secretRef:
  8562. description: |-
  8563. SecretRef to a key in a Secret resource containing password for the LDAP
  8564. user used to authenticate with Vault using the LDAP authentication
  8565. method
  8566. properties:
  8567. key:
  8568. description: |-
  8569. A key in the referenced Secret.
  8570. Some instances of this field may be defaulted, in others it may be required.
  8571. maxLength: 253
  8572. minLength: 1
  8573. pattern: ^[-._a-zA-Z0-9]+$
  8574. type: string
  8575. name:
  8576. description: The name of the Secret resource being referred to.
  8577. maxLength: 253
  8578. minLength: 1
  8579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8580. type: string
  8581. namespace:
  8582. description: |-
  8583. The namespace of the Secret resource being referred to.
  8584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8585. maxLength: 63
  8586. minLength: 1
  8587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8588. type: string
  8589. type: object
  8590. username:
  8591. description: |-
  8592. Username is an LDAP username used to authenticate using the LDAP Vault
  8593. authentication method
  8594. type: string
  8595. required:
  8596. - path
  8597. - username
  8598. type: object
  8599. namespace:
  8600. description: |-
  8601. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8602. Namespaces is a set of features within Vault Enterprise that allows
  8603. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8604. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8605. This will default to Vault.Namespace field if set, or empty otherwise
  8606. type: string
  8607. tokenSecretRef:
  8608. description: TokenSecretRef authenticates with Vault by presenting a token.
  8609. properties:
  8610. key:
  8611. description: |-
  8612. A key in the referenced Secret.
  8613. Some instances of this field may be defaulted, in others it may be required.
  8614. maxLength: 253
  8615. minLength: 1
  8616. pattern: ^[-._a-zA-Z0-9]+$
  8617. type: string
  8618. name:
  8619. description: The name of the Secret resource being referred to.
  8620. maxLength: 253
  8621. minLength: 1
  8622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8623. type: string
  8624. namespace:
  8625. description: |-
  8626. The namespace of the Secret resource being referred to.
  8627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8628. maxLength: 63
  8629. minLength: 1
  8630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8631. type: string
  8632. type: object
  8633. userPass:
  8634. description: UserPass authenticates with Vault by passing username/password pair
  8635. properties:
  8636. path:
  8637. default: userpass
  8638. description: |-
  8639. Path where the UserPassword authentication backend is mounted
  8640. in Vault, e.g: "userpass"
  8641. type: string
  8642. secretRef:
  8643. description: |-
  8644. SecretRef to a key in a Secret resource containing password for the
  8645. user used to authenticate with Vault using the UserPass authentication
  8646. method
  8647. properties:
  8648. key:
  8649. description: |-
  8650. A key in the referenced Secret.
  8651. Some instances of this field may be defaulted, in others it may be required.
  8652. maxLength: 253
  8653. minLength: 1
  8654. pattern: ^[-._a-zA-Z0-9]+$
  8655. type: string
  8656. name:
  8657. description: The name of the Secret resource being referred to.
  8658. maxLength: 253
  8659. minLength: 1
  8660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8661. type: string
  8662. namespace:
  8663. description: |-
  8664. The namespace of the Secret resource being referred to.
  8665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8666. maxLength: 63
  8667. minLength: 1
  8668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8669. type: string
  8670. type: object
  8671. username:
  8672. description: |-
  8673. Username is a username used to authenticate using the UserPass Vault
  8674. authentication method
  8675. type: string
  8676. required:
  8677. - path
  8678. - username
  8679. type: object
  8680. type: object
  8681. caBundle:
  8682. description: |-
  8683. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8684. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8685. plain HTTP protocol connection. If not set the system root certificates
  8686. are used to validate the TLS connection.
  8687. format: byte
  8688. type: string
  8689. caProvider:
  8690. description: The provider for the CA bundle to use to validate Vault server certificate.
  8691. properties:
  8692. key:
  8693. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8694. maxLength: 253
  8695. minLength: 1
  8696. pattern: ^[-._a-zA-Z0-9]+$
  8697. type: string
  8698. name:
  8699. description: The name of the object located at the provider type.
  8700. maxLength: 253
  8701. minLength: 1
  8702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8703. type: string
  8704. namespace:
  8705. description: |-
  8706. The namespace the Provider type is in.
  8707. Can only be defined when used in a ClusterSecretStore.
  8708. maxLength: 63
  8709. minLength: 1
  8710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8711. type: string
  8712. type:
  8713. description: The type of provider to use such as "Secret", or "ConfigMap".
  8714. enum:
  8715. - Secret
  8716. - ConfigMap
  8717. type: string
  8718. required:
  8719. - name
  8720. - type
  8721. type: object
  8722. checkAndSet:
  8723. description: |-
  8724. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8725. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8726. the current version of the secret to prevent unintentional overwrites.
  8727. properties:
  8728. required:
  8729. description: |-
  8730. Required when true, all write operations must include a check-and-set parameter.
  8731. This helps prevent unintentional overwrites of secrets.
  8732. type: boolean
  8733. type: object
  8734. forwardInconsistent:
  8735. description: |-
  8736. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8737. leader instead of simply retrying within a loop. This can increase performance if
  8738. the option is enabled serverside.
  8739. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8740. type: boolean
  8741. headers:
  8742. additionalProperties:
  8743. type: string
  8744. description: Headers to be added in Vault request
  8745. type: object
  8746. namespace:
  8747. description: |-
  8748. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8749. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8750. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8751. type: string
  8752. path:
  8753. description: |-
  8754. Path is the mount path of the Vault KV backend endpoint, e.g:
  8755. "secret". The v2 KV secret engine version specific "/data" path suffix
  8756. for fetching secrets from Vault is optional and will be appended
  8757. if not present in specified path.
  8758. type: string
  8759. readYourWrites:
  8760. description: |-
  8761. ReadYourWrites ensures isolated read-after-write semantics by
  8762. providing discovered cluster replication states in each request.
  8763. More information about eventual consistency in Vault can be found here
  8764. https://www.vaultproject.io/docs/enterprise/consistency
  8765. type: boolean
  8766. server:
  8767. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8768. type: string
  8769. tls:
  8770. description: |-
  8771. The configuration used for client side related TLS communication, when the Vault server
  8772. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8773. This parameter is ignored for plain HTTP protocol connection.
  8774. It's worth noting this configuration is different from the "TLS certificates auth method",
  8775. which is available under the `auth.cert` section.
  8776. properties:
  8777. certSecretRef:
  8778. description: |-
  8779. CertSecretRef is a certificate added to the transport layer
  8780. when communicating with the Vault server.
  8781. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8782. properties:
  8783. key:
  8784. description: |-
  8785. A key in the referenced Secret.
  8786. Some instances of this field may be defaulted, in others it may be required.
  8787. maxLength: 253
  8788. minLength: 1
  8789. pattern: ^[-._a-zA-Z0-9]+$
  8790. type: string
  8791. name:
  8792. description: The name of the Secret resource being referred to.
  8793. maxLength: 253
  8794. minLength: 1
  8795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8796. type: string
  8797. namespace:
  8798. description: |-
  8799. The namespace of the Secret resource being referred to.
  8800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8801. maxLength: 63
  8802. minLength: 1
  8803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8804. type: string
  8805. type: object
  8806. keySecretRef:
  8807. description: |-
  8808. KeySecretRef to a key in a Secret resource containing client private key
  8809. added to the transport layer when communicating with the Vault server.
  8810. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8811. properties:
  8812. key:
  8813. description: |-
  8814. A key in the referenced Secret.
  8815. Some instances of this field may be defaulted, in others it may be required.
  8816. maxLength: 253
  8817. minLength: 1
  8818. pattern: ^[-._a-zA-Z0-9]+$
  8819. type: string
  8820. name:
  8821. description: The name of the Secret resource being referred to.
  8822. maxLength: 253
  8823. minLength: 1
  8824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8825. type: string
  8826. namespace:
  8827. description: |-
  8828. The namespace of the Secret resource being referred to.
  8829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8830. maxLength: 63
  8831. minLength: 1
  8832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8833. type: string
  8834. type: object
  8835. type: object
  8836. version:
  8837. default: v2
  8838. description: |-
  8839. Version is the Vault KV secret engine version. This can be either "v1" or
  8840. "v2". Version defaults to "v2".
  8841. enum:
  8842. - v1
  8843. - v2
  8844. type: string
  8845. required:
  8846. - server
  8847. type: object
  8848. volcengine:
  8849. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8850. properties:
  8851. auth:
  8852. description: |-
  8853. Auth defines the authentication method to use.
  8854. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8855. properties:
  8856. secretRef:
  8857. description: |-
  8858. SecretRef defines the static credentials to use for authentication.
  8859. If not set, IRSA is used.
  8860. properties:
  8861. accessKeyID:
  8862. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8863. properties:
  8864. key:
  8865. description: |-
  8866. A key in the referenced Secret.
  8867. Some instances of this field may be defaulted, in others it may be required.
  8868. maxLength: 253
  8869. minLength: 1
  8870. pattern: ^[-._a-zA-Z0-9]+$
  8871. type: string
  8872. name:
  8873. description: The name of the Secret resource being referred to.
  8874. maxLength: 253
  8875. minLength: 1
  8876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8877. type: string
  8878. namespace:
  8879. description: |-
  8880. The namespace of the Secret resource being referred to.
  8881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8882. maxLength: 63
  8883. minLength: 1
  8884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8885. type: string
  8886. type: object
  8887. secretAccessKey:
  8888. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8889. properties:
  8890. key:
  8891. description: |-
  8892. A key in the referenced Secret.
  8893. Some instances of this field may be defaulted, in others it may be required.
  8894. maxLength: 253
  8895. minLength: 1
  8896. pattern: ^[-._a-zA-Z0-9]+$
  8897. type: string
  8898. name:
  8899. description: The name of the Secret resource being referred to.
  8900. maxLength: 253
  8901. minLength: 1
  8902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8903. type: string
  8904. namespace:
  8905. description: |-
  8906. The namespace of the Secret resource being referred to.
  8907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8908. maxLength: 63
  8909. minLength: 1
  8910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8911. type: string
  8912. type: object
  8913. token:
  8914. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8915. properties:
  8916. key:
  8917. description: |-
  8918. A key in the referenced Secret.
  8919. Some instances of this field may be defaulted, in others it may be required.
  8920. maxLength: 253
  8921. minLength: 1
  8922. pattern: ^[-._a-zA-Z0-9]+$
  8923. type: string
  8924. name:
  8925. description: The name of the Secret resource being referred to.
  8926. maxLength: 253
  8927. minLength: 1
  8928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8929. type: string
  8930. namespace:
  8931. description: |-
  8932. The namespace of the Secret resource being referred to.
  8933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8934. maxLength: 63
  8935. minLength: 1
  8936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8937. type: string
  8938. type: object
  8939. required:
  8940. - accessKeyID
  8941. - secretAccessKey
  8942. type: object
  8943. type: object
  8944. region:
  8945. description: Region specifies the Volcengine region to connect to.
  8946. type: string
  8947. required:
  8948. - region
  8949. type: object
  8950. webhook:
  8951. description: Webhook configures this store to sync secrets using a generic templated webhook
  8952. properties:
  8953. auth:
  8954. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8955. maxProperties: 1
  8956. minProperties: 1
  8957. properties:
  8958. ntlm:
  8959. description: NTLMProtocol configures the store to use NTLM for auth
  8960. properties:
  8961. passwordSecret:
  8962. description: |-
  8963. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8964. In some instances, `key` is a required field.
  8965. properties:
  8966. key:
  8967. description: |-
  8968. A key in the referenced Secret.
  8969. Some instances of this field may be defaulted, in others it may be required.
  8970. maxLength: 253
  8971. minLength: 1
  8972. pattern: ^[-._a-zA-Z0-9]+$
  8973. type: string
  8974. name:
  8975. description: The name of the Secret resource being referred to.
  8976. maxLength: 253
  8977. minLength: 1
  8978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8979. type: string
  8980. namespace:
  8981. description: |-
  8982. The namespace of the Secret resource being referred to.
  8983. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8984. maxLength: 63
  8985. minLength: 1
  8986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8987. type: string
  8988. type: object
  8989. usernameSecret:
  8990. description: |-
  8991. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8992. In some instances, `key` is a required field.
  8993. properties:
  8994. key:
  8995. description: |-
  8996. A key in the referenced Secret.
  8997. Some instances of this field may be defaulted, in others it may be required.
  8998. maxLength: 253
  8999. minLength: 1
  9000. pattern: ^[-._a-zA-Z0-9]+$
  9001. type: string
  9002. name:
  9003. description: The name of the Secret resource being referred to.
  9004. maxLength: 253
  9005. minLength: 1
  9006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9007. type: string
  9008. namespace:
  9009. description: |-
  9010. The namespace of the Secret resource being referred to.
  9011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9012. maxLength: 63
  9013. minLength: 1
  9014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9015. type: string
  9016. type: object
  9017. required:
  9018. - passwordSecret
  9019. - usernameSecret
  9020. type: object
  9021. type: object
  9022. body:
  9023. description: Body
  9024. type: string
  9025. caBundle:
  9026. description: |-
  9027. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9028. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9029. plain HTTP protocol connection. If not set the system root certificates
  9030. are used to validate the TLS connection.
  9031. format: byte
  9032. type: string
  9033. caProvider:
  9034. description: The provider for the CA bundle to use to validate webhook server certificate.
  9035. properties:
  9036. key:
  9037. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9038. maxLength: 253
  9039. minLength: 1
  9040. pattern: ^[-._a-zA-Z0-9]+$
  9041. type: string
  9042. name:
  9043. description: The name of the object located at the provider type.
  9044. maxLength: 253
  9045. minLength: 1
  9046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9047. type: string
  9048. namespace:
  9049. description: The namespace the Provider type is in.
  9050. maxLength: 63
  9051. minLength: 1
  9052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9053. type: string
  9054. type:
  9055. description: The type of provider to use such as "Secret", or "ConfigMap".
  9056. enum:
  9057. - Secret
  9058. - ConfigMap
  9059. type: string
  9060. required:
  9061. - name
  9062. - type
  9063. type: object
  9064. headers:
  9065. additionalProperties:
  9066. type: string
  9067. description: Headers
  9068. type: object
  9069. method:
  9070. description: Webhook Method
  9071. type: string
  9072. result:
  9073. description: Result formatting
  9074. properties:
  9075. jsonPath:
  9076. description: Json path of return value
  9077. type: string
  9078. type: object
  9079. secrets:
  9080. description: |-
  9081. Secrets to fill in templates
  9082. These secrets will be passed to the templating function as key value pairs under the given name
  9083. items:
  9084. description: WebhookSecret defines a secret that will be passed to the webhook request.
  9085. properties:
  9086. name:
  9087. description: Name of this secret in templates
  9088. type: string
  9089. secretRef:
  9090. description: Secret ref to fill in credentials
  9091. properties:
  9092. key:
  9093. description: |-
  9094. A key in the referenced Secret.
  9095. Some instances of this field may be defaulted, in others it may be required.
  9096. maxLength: 253
  9097. minLength: 1
  9098. pattern: ^[-._a-zA-Z0-9]+$
  9099. type: string
  9100. name:
  9101. description: The name of the Secret resource being referred to.
  9102. maxLength: 253
  9103. minLength: 1
  9104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9105. type: string
  9106. namespace:
  9107. description: |-
  9108. The namespace of the Secret resource being referred to.
  9109. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9110. maxLength: 63
  9111. minLength: 1
  9112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9113. type: string
  9114. type: object
  9115. required:
  9116. - name
  9117. - secretRef
  9118. type: object
  9119. type: array
  9120. timeout:
  9121. description: Timeout
  9122. type: string
  9123. url:
  9124. description: Webhook url to call
  9125. type: string
  9126. required:
  9127. - url
  9128. type: object
  9129. yandexcertificatemanager:
  9130. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9131. properties:
  9132. apiEndpoint:
  9133. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9134. type: string
  9135. auth:
  9136. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9137. properties:
  9138. authorizedKeySecretRef:
  9139. description: The authorized key used for authentication
  9140. properties:
  9141. key:
  9142. description: |-
  9143. A key in the referenced Secret.
  9144. Some instances of this field may be defaulted, in others it may be required.
  9145. maxLength: 253
  9146. minLength: 1
  9147. pattern: ^[-._a-zA-Z0-9]+$
  9148. type: string
  9149. name:
  9150. description: The name of the Secret resource being referred to.
  9151. maxLength: 253
  9152. minLength: 1
  9153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9154. type: string
  9155. namespace:
  9156. description: |-
  9157. The namespace of the Secret resource being referred to.
  9158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9159. maxLength: 63
  9160. minLength: 1
  9161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9162. type: string
  9163. type: object
  9164. type: object
  9165. caProvider:
  9166. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9167. properties:
  9168. certSecretRef:
  9169. description: |-
  9170. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9171. In some instances, `key` is a required field.
  9172. properties:
  9173. key:
  9174. description: |-
  9175. A key in the referenced Secret.
  9176. Some instances of this field may be defaulted, in others it may be required.
  9177. maxLength: 253
  9178. minLength: 1
  9179. pattern: ^[-._a-zA-Z0-9]+$
  9180. type: string
  9181. name:
  9182. description: The name of the Secret resource being referred to.
  9183. maxLength: 253
  9184. minLength: 1
  9185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9186. type: string
  9187. namespace:
  9188. description: |-
  9189. The namespace of the Secret resource being referred to.
  9190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9191. maxLength: 63
  9192. minLength: 1
  9193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9194. type: string
  9195. type: object
  9196. type: object
  9197. fetching:
  9198. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9199. maxProperties: 1
  9200. minProperties: 1
  9201. properties:
  9202. byID:
  9203. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9204. type: object
  9205. byName:
  9206. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9207. properties:
  9208. folderID:
  9209. description: The folder to fetch secrets from
  9210. type: string
  9211. required:
  9212. - folderID
  9213. type: object
  9214. type: object
  9215. required:
  9216. - auth
  9217. type: object
  9218. yandexlockbox:
  9219. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9220. properties:
  9221. apiEndpoint:
  9222. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9223. type: string
  9224. auth:
  9225. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9226. properties:
  9227. authorizedKeySecretRef:
  9228. description: The authorized key used for authentication
  9229. properties:
  9230. key:
  9231. description: |-
  9232. A key in the referenced Secret.
  9233. Some instances of this field may be defaulted, in others it may be required.
  9234. maxLength: 253
  9235. minLength: 1
  9236. pattern: ^[-._a-zA-Z0-9]+$
  9237. type: string
  9238. name:
  9239. description: The name of the Secret resource being referred to.
  9240. maxLength: 253
  9241. minLength: 1
  9242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9243. type: string
  9244. namespace:
  9245. description: |-
  9246. The namespace of the Secret resource being referred to.
  9247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9248. maxLength: 63
  9249. minLength: 1
  9250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9251. type: string
  9252. type: object
  9253. type: object
  9254. caProvider:
  9255. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9256. properties:
  9257. certSecretRef:
  9258. description: |-
  9259. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9260. In some instances, `key` is a required field.
  9261. properties:
  9262. key:
  9263. description: |-
  9264. A key in the referenced Secret.
  9265. Some instances of this field may be defaulted, in others it may be required.
  9266. maxLength: 253
  9267. minLength: 1
  9268. pattern: ^[-._a-zA-Z0-9]+$
  9269. type: string
  9270. name:
  9271. description: The name of the Secret resource being referred to.
  9272. maxLength: 253
  9273. minLength: 1
  9274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9275. type: string
  9276. namespace:
  9277. description: |-
  9278. The namespace of the Secret resource being referred to.
  9279. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9280. maxLength: 63
  9281. minLength: 1
  9282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9283. type: string
  9284. type: object
  9285. type: object
  9286. fetching:
  9287. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9288. maxProperties: 1
  9289. minProperties: 1
  9290. properties:
  9291. byID:
  9292. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9293. type: object
  9294. byName:
  9295. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9296. properties:
  9297. folderID:
  9298. description: The folder to fetch secrets from
  9299. type: string
  9300. required:
  9301. - folderID
  9302. type: object
  9303. type: object
  9304. required:
  9305. - auth
  9306. type: object
  9307. type: object
  9308. refreshInterval:
  9309. anyOf:
  9310. - type: integer
  9311. - type: string
  9312. description: |-
  9313. Used to configure store refresh interval. Accepts either an integer number
  9314. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9315. 0 will default to the controller config.
  9316. x-kubernetes-int-or-string: true
  9317. retrySettings:
  9318. description: Used to configure HTTP retries on failures.
  9319. properties:
  9320. maxRetries:
  9321. format: int32
  9322. type: integer
  9323. retryInterval:
  9324. type: string
  9325. type: object
  9326. required:
  9327. - provider
  9328. type: object
  9329. status:
  9330. description: SecretStoreStatus defines the observed state of the SecretStore.
  9331. properties:
  9332. capabilities:
  9333. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9334. type: string
  9335. conditions:
  9336. items:
  9337. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9338. properties:
  9339. lastTransitionTime:
  9340. format: date-time
  9341. type: string
  9342. message:
  9343. type: string
  9344. reason:
  9345. type: string
  9346. status:
  9347. type: string
  9348. type:
  9349. description: SecretStoreConditionType represents the condition of the SecretStore.
  9350. type: string
  9351. required:
  9352. - status
  9353. - type
  9354. type: object
  9355. type: array
  9356. type: object
  9357. type: object
  9358. served: true
  9359. storage: true
  9360. subresources:
  9361. status: {}
  9362. - additionalPrinterColumns:
  9363. - jsonPath: .metadata.creationTimestamp
  9364. name: AGE
  9365. type: date
  9366. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9367. name: Status
  9368. type: string
  9369. - jsonPath: .status.capabilities
  9370. name: Capabilities
  9371. type: string
  9372. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9373. name: Ready
  9374. type: string
  9375. deprecated: true
  9376. name: v1beta1
  9377. schema:
  9378. openAPIV3Schema:
  9379. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9380. properties:
  9381. apiVersion:
  9382. description: |-
  9383. APIVersion defines the versioned schema of this representation of an object.
  9384. Servers should convert recognized schemas to the latest internal value, and
  9385. may reject unrecognized values.
  9386. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9387. type: string
  9388. kind:
  9389. description: |-
  9390. Kind is a string value representing the REST resource this object represents.
  9391. Servers may infer this from the endpoint the client submits requests to.
  9392. Cannot be updated.
  9393. In CamelCase.
  9394. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9395. type: string
  9396. metadata:
  9397. type: object
  9398. spec:
  9399. description: SecretStoreSpec defines the desired state of SecretStore.
  9400. properties:
  9401. conditions:
  9402. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9403. items:
  9404. description: |-
  9405. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9406. for a ClusterSecretStore instance.
  9407. properties:
  9408. namespaceRegexes:
  9409. description: Choose namespaces by using regex matching
  9410. items:
  9411. type: string
  9412. type: array
  9413. namespaceSelector:
  9414. description: Choose namespace using a labelSelector
  9415. properties:
  9416. matchExpressions:
  9417. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9418. items:
  9419. description: |-
  9420. A label selector requirement is a selector that contains values, a key, and an operator that
  9421. relates the key and values.
  9422. properties:
  9423. key:
  9424. description: key is the label key that the selector applies to.
  9425. type: string
  9426. operator:
  9427. description: |-
  9428. operator represents a key's relationship to a set of values.
  9429. Valid operators are In, NotIn, Exists and DoesNotExist.
  9430. type: string
  9431. values:
  9432. description: |-
  9433. values is an array of string values. If the operator is In or NotIn,
  9434. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9435. the values array must be empty. This array is replaced during a strategic
  9436. merge patch.
  9437. items:
  9438. type: string
  9439. type: array
  9440. x-kubernetes-list-type: atomic
  9441. required:
  9442. - key
  9443. - operator
  9444. type: object
  9445. type: array
  9446. x-kubernetes-list-type: atomic
  9447. matchLabels:
  9448. additionalProperties:
  9449. type: string
  9450. description: |-
  9451. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9452. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9453. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9454. type: object
  9455. type: object
  9456. x-kubernetes-map-type: atomic
  9457. namespaces:
  9458. description: Choose namespaces by name
  9459. items:
  9460. maxLength: 63
  9461. minLength: 1
  9462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9463. type: string
  9464. type: array
  9465. type: object
  9466. type: array
  9467. controller:
  9468. description: |-
  9469. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9470. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9471. type: string
  9472. provider:
  9473. description: Used to configure the provider. Only one provider may be set
  9474. maxProperties: 1
  9475. minProperties: 1
  9476. properties:
  9477. akeyless:
  9478. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9479. properties:
  9480. akeylessGWApiURL:
  9481. description: Akeyless GW API Url from which the secrets to be fetched from.
  9482. type: string
  9483. authSecretRef:
  9484. description: Auth configures how the operator authenticates with Akeyless.
  9485. properties:
  9486. kubernetesAuth:
  9487. description: |-
  9488. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9489. token stored in the named Secret resource.
  9490. properties:
  9491. accessID:
  9492. description: the Akeyless Kubernetes auth-method access-id
  9493. type: string
  9494. k8sConfName:
  9495. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9496. type: string
  9497. secretRef:
  9498. description: |-
  9499. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9500. for authenticating with Akeyless. If a name is specified without a key,
  9501. `token` is the default. If one is not specified, the one bound to
  9502. the controller will be used.
  9503. properties:
  9504. key:
  9505. description: |-
  9506. A key in the referenced Secret.
  9507. Some instances of this field may be defaulted, in others it may be required.
  9508. maxLength: 253
  9509. minLength: 1
  9510. pattern: ^[-._a-zA-Z0-9]+$
  9511. type: string
  9512. name:
  9513. description: The name of the Secret resource being referred to.
  9514. maxLength: 253
  9515. minLength: 1
  9516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9517. type: string
  9518. namespace:
  9519. description: |-
  9520. The namespace of the Secret resource being referred to.
  9521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9522. maxLength: 63
  9523. minLength: 1
  9524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9525. type: string
  9526. type: object
  9527. serviceAccountRef:
  9528. description: |-
  9529. Optional service account field containing the name of a kubernetes ServiceAccount.
  9530. If the service account is specified, the service account secret token JWT will be used
  9531. for authenticating with Akeyless. If the service account selector is not supplied,
  9532. the secretRef will be used instead.
  9533. properties:
  9534. audiences:
  9535. description: |-
  9536. Audience specifies the `aud` claim for the service account token
  9537. Some providers automatically extend the audience field based on well-known annotations for workload
  9538. identity (e.g. IRSA or GCP Workload Identity)
  9539. items:
  9540. type: string
  9541. type: array
  9542. name:
  9543. description: The name of the ServiceAccount resource being referred to.
  9544. maxLength: 253
  9545. minLength: 1
  9546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9547. type: string
  9548. namespace:
  9549. description: |-
  9550. Namespace of the resource being referred to.
  9551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9552. maxLength: 63
  9553. minLength: 1
  9554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9555. type: string
  9556. required:
  9557. - name
  9558. type: object
  9559. required:
  9560. - accessID
  9561. - k8sConfName
  9562. type: object
  9563. secretRef:
  9564. description: |-
  9565. Reference to a Secret that contains the details
  9566. to authenticate with Akeyless.
  9567. properties:
  9568. accessID:
  9569. description: The SecretAccessID is used for authentication
  9570. properties:
  9571. key:
  9572. description: |-
  9573. A key in the referenced Secret.
  9574. Some instances of this field may be defaulted, in others it may be required.
  9575. maxLength: 253
  9576. minLength: 1
  9577. pattern: ^[-._a-zA-Z0-9]+$
  9578. type: string
  9579. name:
  9580. description: The name of the Secret resource being referred to.
  9581. maxLength: 253
  9582. minLength: 1
  9583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9584. type: string
  9585. namespace:
  9586. description: |-
  9587. The namespace of the Secret resource being referred to.
  9588. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9589. maxLength: 63
  9590. minLength: 1
  9591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9592. type: string
  9593. type: object
  9594. accessType:
  9595. description: |-
  9596. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9597. In some instances, `key` is a required field.
  9598. properties:
  9599. key:
  9600. description: |-
  9601. A key in the referenced Secret.
  9602. Some instances of this field may be defaulted, in others it may be required.
  9603. maxLength: 253
  9604. minLength: 1
  9605. pattern: ^[-._a-zA-Z0-9]+$
  9606. type: string
  9607. name:
  9608. description: The name of the Secret resource being referred to.
  9609. maxLength: 253
  9610. minLength: 1
  9611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9612. type: string
  9613. namespace:
  9614. description: |-
  9615. The namespace of the Secret resource being referred to.
  9616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9617. maxLength: 63
  9618. minLength: 1
  9619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9620. type: string
  9621. type: object
  9622. accessTypeParam:
  9623. description: |-
  9624. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9625. In some instances, `key` is a required field.
  9626. properties:
  9627. key:
  9628. description: |-
  9629. A key in the referenced Secret.
  9630. Some instances of this field may be defaulted, in others it may be required.
  9631. maxLength: 253
  9632. minLength: 1
  9633. pattern: ^[-._a-zA-Z0-9]+$
  9634. type: string
  9635. name:
  9636. description: The name of the Secret resource being referred to.
  9637. maxLength: 253
  9638. minLength: 1
  9639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9640. type: string
  9641. namespace:
  9642. description: |-
  9643. The namespace of the Secret resource being referred to.
  9644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9645. maxLength: 63
  9646. minLength: 1
  9647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9648. type: string
  9649. type: object
  9650. type: object
  9651. type: object
  9652. caBundle:
  9653. description: |-
  9654. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9655. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9656. are used to validate the TLS connection.
  9657. format: byte
  9658. type: string
  9659. caProvider:
  9660. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9661. properties:
  9662. key:
  9663. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9664. maxLength: 253
  9665. minLength: 1
  9666. pattern: ^[-._a-zA-Z0-9]+$
  9667. type: string
  9668. name:
  9669. description: The name of the object located at the provider type.
  9670. maxLength: 253
  9671. minLength: 1
  9672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9673. type: string
  9674. namespace:
  9675. description: |-
  9676. The namespace the Provider type is in.
  9677. Can only be defined when used in a ClusterSecretStore.
  9678. maxLength: 63
  9679. minLength: 1
  9680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9681. type: string
  9682. type:
  9683. description: The type of provider to use such as "Secret", or "ConfigMap".
  9684. enum:
  9685. - Secret
  9686. - ConfigMap
  9687. type: string
  9688. required:
  9689. - name
  9690. - type
  9691. type: object
  9692. required:
  9693. - akeylessGWApiURL
  9694. - authSecretRef
  9695. type: object
  9696. alibaba:
  9697. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9698. properties:
  9699. auth:
  9700. description: AlibabaAuth contains a secretRef for credentials.
  9701. properties:
  9702. rrsa:
  9703. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9704. properties:
  9705. oidcProviderArn:
  9706. type: string
  9707. oidcTokenFilePath:
  9708. type: string
  9709. roleArn:
  9710. type: string
  9711. sessionName:
  9712. type: string
  9713. required:
  9714. - oidcProviderArn
  9715. - oidcTokenFilePath
  9716. - roleArn
  9717. - sessionName
  9718. type: object
  9719. secretRef:
  9720. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9721. properties:
  9722. accessKeyIDSecretRef:
  9723. description: The AccessKeyID is used for authentication
  9724. properties:
  9725. key:
  9726. description: |-
  9727. A key in the referenced Secret.
  9728. Some instances of this field may be defaulted, in others it may be required.
  9729. maxLength: 253
  9730. minLength: 1
  9731. pattern: ^[-._a-zA-Z0-9]+$
  9732. type: string
  9733. name:
  9734. description: The name of the Secret resource being referred to.
  9735. maxLength: 253
  9736. minLength: 1
  9737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9738. type: string
  9739. namespace:
  9740. description: |-
  9741. The namespace of the Secret resource being referred to.
  9742. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9743. maxLength: 63
  9744. minLength: 1
  9745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9746. type: string
  9747. type: object
  9748. accessKeySecretSecretRef:
  9749. description: The AccessKeySecret is used for authentication
  9750. properties:
  9751. key:
  9752. description: |-
  9753. A key in the referenced Secret.
  9754. Some instances of this field may be defaulted, in others it may be required.
  9755. maxLength: 253
  9756. minLength: 1
  9757. pattern: ^[-._a-zA-Z0-9]+$
  9758. type: string
  9759. name:
  9760. description: The name of the Secret resource being referred to.
  9761. maxLength: 253
  9762. minLength: 1
  9763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9764. type: string
  9765. namespace:
  9766. description: |-
  9767. The namespace of the Secret resource being referred to.
  9768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9769. maxLength: 63
  9770. minLength: 1
  9771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9772. type: string
  9773. type: object
  9774. required:
  9775. - accessKeyIDSecretRef
  9776. - accessKeySecretSecretRef
  9777. type: object
  9778. type: object
  9779. regionID:
  9780. description: Alibaba Region to be used for the provider
  9781. type: string
  9782. required:
  9783. - auth
  9784. - regionID
  9785. type: object
  9786. aws:
  9787. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9788. properties:
  9789. additionalRoles:
  9790. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9791. items:
  9792. type: string
  9793. type: array
  9794. auth:
  9795. description: |-
  9796. Auth defines the information necessary to authenticate against AWS
  9797. if not set aws sdk will infer credentials from your environment
  9798. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9799. properties:
  9800. jwt:
  9801. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9802. properties:
  9803. serviceAccountRef:
  9804. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9805. properties:
  9806. audiences:
  9807. description: |-
  9808. Audience specifies the `aud` claim for the service account token
  9809. Some providers automatically extend the audience field based on well-known annotations for workload
  9810. identity (e.g. IRSA or GCP Workload Identity)
  9811. items:
  9812. type: string
  9813. type: array
  9814. name:
  9815. description: The name of the ServiceAccount resource being referred to.
  9816. maxLength: 253
  9817. minLength: 1
  9818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9819. type: string
  9820. namespace:
  9821. description: |-
  9822. Namespace of the resource being referred to.
  9823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9824. maxLength: 63
  9825. minLength: 1
  9826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9827. type: string
  9828. required:
  9829. - name
  9830. type: object
  9831. type: object
  9832. secretRef:
  9833. description: |-
  9834. AWSAuthSecretRef holds secret references for AWS credentials
  9835. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9836. properties:
  9837. accessKeyIDSecretRef:
  9838. description: The AccessKeyID is used for authentication
  9839. properties:
  9840. key:
  9841. description: |-
  9842. A key in the referenced Secret.
  9843. Some instances of this field may be defaulted, in others it may be required.
  9844. maxLength: 253
  9845. minLength: 1
  9846. pattern: ^[-._a-zA-Z0-9]+$
  9847. type: string
  9848. name:
  9849. description: The name of the Secret resource being referred to.
  9850. maxLength: 253
  9851. minLength: 1
  9852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9853. type: string
  9854. namespace:
  9855. description: |-
  9856. The namespace of the Secret resource being referred to.
  9857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9858. maxLength: 63
  9859. minLength: 1
  9860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9861. type: string
  9862. type: object
  9863. secretAccessKeySecretRef:
  9864. description: The SecretAccessKey is used for authentication
  9865. properties:
  9866. key:
  9867. description: |-
  9868. A key in the referenced Secret.
  9869. Some instances of this field may be defaulted, in others it may be required.
  9870. maxLength: 253
  9871. minLength: 1
  9872. pattern: ^[-._a-zA-Z0-9]+$
  9873. type: string
  9874. name:
  9875. description: The name of the Secret resource being referred to.
  9876. maxLength: 253
  9877. minLength: 1
  9878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9879. type: string
  9880. namespace:
  9881. description: |-
  9882. The namespace of the Secret resource being referred to.
  9883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9884. maxLength: 63
  9885. minLength: 1
  9886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9887. type: string
  9888. type: object
  9889. sessionTokenSecretRef:
  9890. description: |-
  9891. The SessionToken used for authentication
  9892. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9893. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9894. properties:
  9895. key:
  9896. description: |-
  9897. A key in the referenced Secret.
  9898. Some instances of this field may be defaulted, in others it may be required.
  9899. maxLength: 253
  9900. minLength: 1
  9901. pattern: ^[-._a-zA-Z0-9]+$
  9902. type: string
  9903. name:
  9904. description: The name of the Secret resource being referred to.
  9905. maxLength: 253
  9906. minLength: 1
  9907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9908. type: string
  9909. namespace:
  9910. description: |-
  9911. The namespace of the Secret resource being referred to.
  9912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9913. maxLength: 63
  9914. minLength: 1
  9915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9916. type: string
  9917. type: object
  9918. type: object
  9919. type: object
  9920. externalID:
  9921. description: AWS External ID set on assumed IAM roles
  9922. type: string
  9923. prefix:
  9924. description: Prefix adds a prefix to all retrieved values.
  9925. type: string
  9926. region:
  9927. description: AWS Region to be used for the provider
  9928. type: string
  9929. role:
  9930. description: Role is a Role ARN which the provider will assume
  9931. type: string
  9932. secretsManager:
  9933. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9934. properties:
  9935. forceDeleteWithoutRecovery:
  9936. description: |-
  9937. Specifies whether to delete the secret without any recovery window. You
  9938. can't use both this parameter and RecoveryWindowInDays in the same call.
  9939. If you don't use either, then by default Secrets Manager uses a 30 day
  9940. recovery window.
  9941. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9942. type: boolean
  9943. recoveryWindowInDays:
  9944. description: |-
  9945. The number of days from 7 to 30 that Secrets Manager waits before
  9946. permanently deleting the secret. You can't use both this parameter and
  9947. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9948. then by default Secrets Manager uses a 30 day recovery window.
  9949. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9950. format: int64
  9951. type: integer
  9952. type: object
  9953. service:
  9954. description: Service defines which service should be used to fetch the secrets
  9955. enum:
  9956. - SecretsManager
  9957. - ParameterStore
  9958. type: string
  9959. sessionTags:
  9960. description: AWS STS assume role session tags
  9961. items:
  9962. description: Tag defines a tag key and value for AWS resources.
  9963. properties:
  9964. key:
  9965. type: string
  9966. value:
  9967. type: string
  9968. required:
  9969. - key
  9970. - value
  9971. type: object
  9972. type: array
  9973. transitiveTagKeys:
  9974. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9975. items:
  9976. type: string
  9977. type: array
  9978. required:
  9979. - region
  9980. - service
  9981. type: object
  9982. azurekv:
  9983. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9984. properties:
  9985. authSecretRef:
  9986. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9987. properties:
  9988. clientCertificate:
  9989. description: The Azure ClientCertificate of the service principle used for authentication.
  9990. properties:
  9991. key:
  9992. description: |-
  9993. A key in the referenced Secret.
  9994. Some instances of this field may be defaulted, in others it may be required.
  9995. maxLength: 253
  9996. minLength: 1
  9997. pattern: ^[-._a-zA-Z0-9]+$
  9998. type: string
  9999. name:
  10000. description: The name of the Secret resource being referred to.
  10001. maxLength: 253
  10002. minLength: 1
  10003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10004. type: string
  10005. namespace:
  10006. description: |-
  10007. The namespace of the Secret resource being referred to.
  10008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10009. maxLength: 63
  10010. minLength: 1
  10011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10012. type: string
  10013. type: object
  10014. clientId:
  10015. description: The Azure clientId of the service principle or managed identity used for authentication.
  10016. properties:
  10017. key:
  10018. description: |-
  10019. A key in the referenced Secret.
  10020. Some instances of this field may be defaulted, in others it may be required.
  10021. maxLength: 253
  10022. minLength: 1
  10023. pattern: ^[-._a-zA-Z0-9]+$
  10024. type: string
  10025. name:
  10026. description: The name of the Secret resource being referred to.
  10027. maxLength: 253
  10028. minLength: 1
  10029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10030. type: string
  10031. namespace:
  10032. description: |-
  10033. The namespace of the Secret resource being referred to.
  10034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10035. maxLength: 63
  10036. minLength: 1
  10037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10038. type: string
  10039. type: object
  10040. clientSecret:
  10041. description: The Azure ClientSecret of the service principle used for authentication.
  10042. properties:
  10043. key:
  10044. description: |-
  10045. A key in the referenced Secret.
  10046. Some instances of this field may be defaulted, in others it may be required.
  10047. maxLength: 253
  10048. minLength: 1
  10049. pattern: ^[-._a-zA-Z0-9]+$
  10050. type: string
  10051. name:
  10052. description: The name of the Secret resource being referred to.
  10053. maxLength: 253
  10054. minLength: 1
  10055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10056. type: string
  10057. namespace:
  10058. description: |-
  10059. The namespace of the Secret resource being referred to.
  10060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10061. maxLength: 63
  10062. minLength: 1
  10063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10064. type: string
  10065. type: object
  10066. tenantId:
  10067. description: The Azure tenantId of the managed identity used for authentication.
  10068. properties:
  10069. key:
  10070. description: |-
  10071. A key in the referenced Secret.
  10072. Some instances of this field may be defaulted, in others it may be required.
  10073. maxLength: 253
  10074. minLength: 1
  10075. pattern: ^[-._a-zA-Z0-9]+$
  10076. type: string
  10077. name:
  10078. description: The name of the Secret resource being referred to.
  10079. maxLength: 253
  10080. minLength: 1
  10081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10082. type: string
  10083. namespace:
  10084. description: |-
  10085. The namespace of the Secret resource being referred to.
  10086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10087. maxLength: 63
  10088. minLength: 1
  10089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10090. type: string
  10091. type: object
  10092. type: object
  10093. authType:
  10094. default: ServicePrincipal
  10095. description: |-
  10096. Auth type defines how to authenticate to the keyvault service.
  10097. Valid values are:
  10098. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10099. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10100. enum:
  10101. - ServicePrincipal
  10102. - ManagedIdentity
  10103. - WorkloadIdentity
  10104. type: string
  10105. environmentType:
  10106. default: PublicCloud
  10107. description: |-
  10108. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10109. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10110. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10111. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10112. enum:
  10113. - PublicCloud
  10114. - USGovernmentCloud
  10115. - ChinaCloud
  10116. - GermanCloud
  10117. type: string
  10118. identityId:
  10119. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10120. type: string
  10121. serviceAccountRef:
  10122. description: |-
  10123. ServiceAccountRef specified the service account
  10124. that should be used when authenticating with WorkloadIdentity.
  10125. properties:
  10126. audiences:
  10127. description: |-
  10128. Audience specifies the `aud` claim for the service account token
  10129. Some providers automatically extend the audience field based on well-known annotations for workload
  10130. identity (e.g. IRSA or GCP Workload Identity)
  10131. items:
  10132. type: string
  10133. type: array
  10134. name:
  10135. description: The name of the ServiceAccount resource being referred to.
  10136. maxLength: 253
  10137. minLength: 1
  10138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10139. type: string
  10140. namespace:
  10141. description: |-
  10142. Namespace of the resource being referred to.
  10143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10144. maxLength: 63
  10145. minLength: 1
  10146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10147. type: string
  10148. required:
  10149. - name
  10150. type: object
  10151. tenantId:
  10152. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10153. type: string
  10154. vaultUrl:
  10155. description: Vault Url from which the secrets to be fetched from.
  10156. type: string
  10157. required:
  10158. - vaultUrl
  10159. type: object
  10160. beyondtrust:
  10161. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10162. properties:
  10163. auth:
  10164. description: Auth configures how the operator authenticates with Beyondtrust.
  10165. properties:
  10166. apiKey:
  10167. description: APIKey If not provided then ClientID/ClientSecret become required.
  10168. properties:
  10169. secretRef:
  10170. description: SecretRef references a key in a secret that will be used as value.
  10171. properties:
  10172. key:
  10173. description: |-
  10174. A key in the referenced Secret.
  10175. Some instances of this field may be defaulted, in others it may be required.
  10176. maxLength: 253
  10177. minLength: 1
  10178. pattern: ^[-._a-zA-Z0-9]+$
  10179. type: string
  10180. name:
  10181. description: The name of the Secret resource being referred to.
  10182. maxLength: 253
  10183. minLength: 1
  10184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10185. type: string
  10186. namespace:
  10187. description: |-
  10188. The namespace of the Secret resource being referred to.
  10189. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10190. maxLength: 63
  10191. minLength: 1
  10192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10193. type: string
  10194. type: object
  10195. value:
  10196. description: Value can be specified directly to set a value without using a secret.
  10197. type: string
  10198. type: object
  10199. certificate:
  10200. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10201. properties:
  10202. secretRef:
  10203. description: SecretRef references a key in a secret that will be used as value.
  10204. properties:
  10205. key:
  10206. description: |-
  10207. A key in the referenced Secret.
  10208. Some instances of this field may be defaulted, in others it may be required.
  10209. maxLength: 253
  10210. minLength: 1
  10211. pattern: ^[-._a-zA-Z0-9]+$
  10212. type: string
  10213. name:
  10214. description: The name of the Secret resource being referred to.
  10215. maxLength: 253
  10216. minLength: 1
  10217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10218. type: string
  10219. namespace:
  10220. description: |-
  10221. The namespace of the Secret resource being referred to.
  10222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10223. maxLength: 63
  10224. minLength: 1
  10225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10226. type: string
  10227. type: object
  10228. value:
  10229. description: Value can be specified directly to set a value without using a secret.
  10230. type: string
  10231. type: object
  10232. certificateKey:
  10233. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10234. properties:
  10235. secretRef:
  10236. description: SecretRef references a key in a secret that will be used as value.
  10237. properties:
  10238. key:
  10239. description: |-
  10240. A key in the referenced Secret.
  10241. Some instances of this field may be defaulted, in others it may be required.
  10242. maxLength: 253
  10243. minLength: 1
  10244. pattern: ^[-._a-zA-Z0-9]+$
  10245. type: string
  10246. name:
  10247. description: The name of the Secret resource being referred to.
  10248. maxLength: 253
  10249. minLength: 1
  10250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10251. type: string
  10252. namespace:
  10253. description: |-
  10254. The namespace of the Secret resource being referred to.
  10255. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10256. maxLength: 63
  10257. minLength: 1
  10258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10259. type: string
  10260. type: object
  10261. value:
  10262. description: Value can be specified directly to set a value without using a secret.
  10263. type: string
  10264. type: object
  10265. clientId:
  10266. description: ClientID is the API OAuth Client ID.
  10267. properties:
  10268. secretRef:
  10269. description: SecretRef references a key in a secret that will be used as value.
  10270. properties:
  10271. key:
  10272. description: |-
  10273. A key in the referenced Secret.
  10274. Some instances of this field may be defaulted, in others it may be required.
  10275. maxLength: 253
  10276. minLength: 1
  10277. pattern: ^[-._a-zA-Z0-9]+$
  10278. type: string
  10279. name:
  10280. description: The name of the Secret resource being referred to.
  10281. maxLength: 253
  10282. minLength: 1
  10283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10284. type: string
  10285. namespace:
  10286. description: |-
  10287. The namespace of the Secret resource being referred to.
  10288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10289. maxLength: 63
  10290. minLength: 1
  10291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10292. type: string
  10293. type: object
  10294. value:
  10295. description: Value can be specified directly to set a value without using a secret.
  10296. type: string
  10297. type: object
  10298. clientSecret:
  10299. description: ClientSecret is the API OAuth Client Secret.
  10300. properties:
  10301. secretRef:
  10302. description: SecretRef references a key in a secret that will be used as value.
  10303. properties:
  10304. key:
  10305. description: |-
  10306. A key in the referenced Secret.
  10307. Some instances of this field may be defaulted, in others it may be required.
  10308. maxLength: 253
  10309. minLength: 1
  10310. pattern: ^[-._a-zA-Z0-9]+$
  10311. type: string
  10312. name:
  10313. description: The name of the Secret resource being referred to.
  10314. maxLength: 253
  10315. minLength: 1
  10316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10317. type: string
  10318. namespace:
  10319. description: |-
  10320. The namespace of the Secret resource being referred to.
  10321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10322. maxLength: 63
  10323. minLength: 1
  10324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10325. type: string
  10326. type: object
  10327. value:
  10328. description: Value can be specified directly to set a value without using a secret.
  10329. type: string
  10330. type: object
  10331. type: object
  10332. server:
  10333. description: Auth configures how API server works.
  10334. properties:
  10335. apiUrl:
  10336. type: string
  10337. apiVersion:
  10338. type: string
  10339. clientTimeOutSeconds:
  10340. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10341. type: integer
  10342. decrypt:
  10343. default: true
  10344. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10345. type: boolean
  10346. retrievalType:
  10347. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10348. type: string
  10349. separator:
  10350. description: A character that separates the folder names.
  10351. type: string
  10352. verifyCA:
  10353. type: boolean
  10354. required:
  10355. - apiUrl
  10356. - verifyCA
  10357. type: object
  10358. required:
  10359. - auth
  10360. - server
  10361. type: object
  10362. bitwardensecretsmanager:
  10363. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10364. properties:
  10365. apiURL:
  10366. type: string
  10367. auth:
  10368. description: |-
  10369. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10370. Make sure that the token being used has permissions on the given secret.
  10371. properties:
  10372. secretRef:
  10373. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10374. properties:
  10375. credentials:
  10376. description: AccessToken used for the bitwarden instance.
  10377. properties:
  10378. key:
  10379. description: |-
  10380. A key in the referenced Secret.
  10381. Some instances of this field may be defaulted, in others it may be required.
  10382. maxLength: 253
  10383. minLength: 1
  10384. pattern: ^[-._a-zA-Z0-9]+$
  10385. type: string
  10386. name:
  10387. description: The name of the Secret resource being referred to.
  10388. maxLength: 253
  10389. minLength: 1
  10390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10391. type: string
  10392. namespace:
  10393. description: |-
  10394. The namespace of the Secret resource being referred to.
  10395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10396. maxLength: 63
  10397. minLength: 1
  10398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10399. type: string
  10400. type: object
  10401. required:
  10402. - credentials
  10403. type: object
  10404. required:
  10405. - secretRef
  10406. type: object
  10407. bitwardenServerSDKURL:
  10408. type: string
  10409. caBundle:
  10410. description: |-
  10411. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10412. can be performed.
  10413. type: string
  10414. caProvider:
  10415. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10416. properties:
  10417. key:
  10418. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10419. maxLength: 253
  10420. minLength: 1
  10421. pattern: ^[-._a-zA-Z0-9]+$
  10422. type: string
  10423. name:
  10424. description: The name of the object located at the provider type.
  10425. maxLength: 253
  10426. minLength: 1
  10427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10428. type: string
  10429. namespace:
  10430. description: |-
  10431. The namespace the Provider type is in.
  10432. Can only be defined when used in a ClusterSecretStore.
  10433. maxLength: 63
  10434. minLength: 1
  10435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10436. type: string
  10437. type:
  10438. description: The type of provider to use such as "Secret", or "ConfigMap".
  10439. enum:
  10440. - Secret
  10441. - ConfigMap
  10442. type: string
  10443. required:
  10444. - name
  10445. - type
  10446. type: object
  10447. identityURL:
  10448. type: string
  10449. organizationID:
  10450. description: OrganizationID determines which organization this secret store manages.
  10451. type: string
  10452. projectID:
  10453. description: ProjectID determines which project this secret store manages.
  10454. type: string
  10455. required:
  10456. - auth
  10457. - organizationID
  10458. - projectID
  10459. type: object
  10460. chef:
  10461. description: Chef configures this store to sync secrets with chef server
  10462. properties:
  10463. auth:
  10464. description: Auth defines the information necessary to authenticate against chef Server
  10465. properties:
  10466. secretRef:
  10467. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10468. properties:
  10469. privateKeySecretRef:
  10470. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10471. properties:
  10472. key:
  10473. description: |-
  10474. A key in the referenced Secret.
  10475. Some instances of this field may be defaulted, in others it may be required.
  10476. maxLength: 253
  10477. minLength: 1
  10478. pattern: ^[-._a-zA-Z0-9]+$
  10479. type: string
  10480. name:
  10481. description: The name of the Secret resource being referred to.
  10482. maxLength: 253
  10483. minLength: 1
  10484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10485. type: string
  10486. namespace:
  10487. description: |-
  10488. The namespace of the Secret resource being referred to.
  10489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10490. maxLength: 63
  10491. minLength: 1
  10492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10493. type: string
  10494. type: object
  10495. required:
  10496. - privateKeySecretRef
  10497. type: object
  10498. required:
  10499. - secretRef
  10500. type: object
  10501. serverUrl:
  10502. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10503. type: string
  10504. username:
  10505. description: UserName should be the user ID on the chef server
  10506. type: string
  10507. required:
  10508. - auth
  10509. - serverUrl
  10510. - username
  10511. type: object
  10512. cloudrusm:
  10513. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10514. properties:
  10515. auth:
  10516. description: CSMAuth contains a secretRef for credentials.
  10517. properties:
  10518. secretRef:
  10519. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10520. properties:
  10521. accessKeyIDSecretRef:
  10522. description: The AccessKeyID is used for authentication
  10523. properties:
  10524. key:
  10525. description: |-
  10526. A key in the referenced Secret.
  10527. Some instances of this field may be defaulted, in others it may be required.
  10528. maxLength: 253
  10529. minLength: 1
  10530. pattern: ^[-._a-zA-Z0-9]+$
  10531. type: string
  10532. name:
  10533. description: The name of the Secret resource being referred to.
  10534. maxLength: 253
  10535. minLength: 1
  10536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10537. type: string
  10538. namespace:
  10539. description: |-
  10540. The namespace of the Secret resource being referred to.
  10541. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10542. maxLength: 63
  10543. minLength: 1
  10544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10545. type: string
  10546. type: object
  10547. accessKeySecretSecretRef:
  10548. description: The AccessKeySecret is used for authentication
  10549. properties:
  10550. key:
  10551. description: |-
  10552. A key in the referenced Secret.
  10553. Some instances of this field may be defaulted, in others it may be required.
  10554. maxLength: 253
  10555. minLength: 1
  10556. pattern: ^[-._a-zA-Z0-9]+$
  10557. type: string
  10558. name:
  10559. description: The name of the Secret resource being referred to.
  10560. maxLength: 253
  10561. minLength: 1
  10562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10563. type: string
  10564. namespace:
  10565. description: |-
  10566. The namespace of the Secret resource being referred to.
  10567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10568. maxLength: 63
  10569. minLength: 1
  10570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10571. type: string
  10572. type: object
  10573. required:
  10574. - accessKeyIDSecretRef
  10575. - accessKeySecretSecretRef
  10576. type: object
  10577. type: object
  10578. projectID:
  10579. description: ProjectID is the project, which the secrets are stored in.
  10580. type: string
  10581. required:
  10582. - auth
  10583. type: object
  10584. conjur:
  10585. description: Conjur configures this store to sync secrets using conjur provider
  10586. properties:
  10587. auth:
  10588. description: Defines authentication settings for connecting to Conjur.
  10589. properties:
  10590. apikey:
  10591. description: Authenticates with Conjur using an API key.
  10592. properties:
  10593. account:
  10594. description: Account is the Conjur organization account name.
  10595. type: string
  10596. apiKeyRef:
  10597. description: |-
  10598. A reference to a specific 'key' containing the Conjur API key
  10599. within a Secret resource. In some instances, `key` is a required field.
  10600. properties:
  10601. key:
  10602. description: |-
  10603. A key in the referenced Secret.
  10604. Some instances of this field may be defaulted, in others it may be required.
  10605. maxLength: 253
  10606. minLength: 1
  10607. pattern: ^[-._a-zA-Z0-9]+$
  10608. type: string
  10609. name:
  10610. description: The name of the Secret resource being referred to.
  10611. maxLength: 253
  10612. minLength: 1
  10613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10614. type: string
  10615. namespace:
  10616. description: |-
  10617. The namespace of the Secret resource being referred to.
  10618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10619. maxLength: 63
  10620. minLength: 1
  10621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10622. type: string
  10623. type: object
  10624. userRef:
  10625. description: |-
  10626. A reference to a specific 'key' containing the Conjur username
  10627. within a Secret resource. In some instances, `key` is a required field.
  10628. properties:
  10629. key:
  10630. description: |-
  10631. A key in the referenced Secret.
  10632. Some instances of this field may be defaulted, in others it may be required.
  10633. maxLength: 253
  10634. minLength: 1
  10635. pattern: ^[-._a-zA-Z0-9]+$
  10636. type: string
  10637. name:
  10638. description: The name of the Secret resource being referred to.
  10639. maxLength: 253
  10640. minLength: 1
  10641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10642. type: string
  10643. namespace:
  10644. description: |-
  10645. The namespace of the Secret resource being referred to.
  10646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10647. maxLength: 63
  10648. minLength: 1
  10649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10650. type: string
  10651. type: object
  10652. required:
  10653. - account
  10654. - apiKeyRef
  10655. - userRef
  10656. type: object
  10657. jwt:
  10658. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10659. properties:
  10660. account:
  10661. description: Account is the Conjur organization account name.
  10662. type: string
  10663. hostId:
  10664. description: |-
  10665. Optional HostID for JWT authentication. This may be used depending
  10666. on how the Conjur JWT authenticator policy is configured.
  10667. type: string
  10668. secretRef:
  10669. description: |-
  10670. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10671. authenticate with Conjur using the JWT authentication method.
  10672. properties:
  10673. key:
  10674. description: |-
  10675. A key in the referenced Secret.
  10676. Some instances of this field may be defaulted, in others it may be required.
  10677. maxLength: 253
  10678. minLength: 1
  10679. pattern: ^[-._a-zA-Z0-9]+$
  10680. type: string
  10681. name:
  10682. description: The name of the Secret resource being referred to.
  10683. maxLength: 253
  10684. minLength: 1
  10685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10686. type: string
  10687. namespace:
  10688. description: |-
  10689. The namespace of the Secret resource being referred to.
  10690. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10691. maxLength: 63
  10692. minLength: 1
  10693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10694. type: string
  10695. type: object
  10696. serviceAccountRef:
  10697. description: |-
  10698. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10699. a token for with the `TokenRequest` API.
  10700. properties:
  10701. audiences:
  10702. description: |-
  10703. Audience specifies the `aud` claim for the service account token
  10704. Some providers automatically extend the audience field based on well-known annotations for workload
  10705. identity (e.g. IRSA or GCP Workload Identity)
  10706. items:
  10707. type: string
  10708. type: array
  10709. name:
  10710. description: The name of the ServiceAccount resource being referred to.
  10711. maxLength: 253
  10712. minLength: 1
  10713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10714. type: string
  10715. namespace:
  10716. description: |-
  10717. Namespace of the resource being referred to.
  10718. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10719. maxLength: 63
  10720. minLength: 1
  10721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10722. type: string
  10723. required:
  10724. - name
  10725. type: object
  10726. serviceID:
  10727. description: The conjur authn jwt webservice id
  10728. type: string
  10729. required:
  10730. - account
  10731. - serviceID
  10732. type: object
  10733. type: object
  10734. caBundle:
  10735. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10736. type: string
  10737. caProvider:
  10738. description: |-
  10739. Used to provide custom certificate authority (CA) certificates
  10740. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10741. that contains a PEM-encoded certificate.
  10742. properties:
  10743. key:
  10744. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10745. maxLength: 253
  10746. minLength: 1
  10747. pattern: ^[-._a-zA-Z0-9]+$
  10748. type: string
  10749. name:
  10750. description: The name of the object located at the provider type.
  10751. maxLength: 253
  10752. minLength: 1
  10753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10754. type: string
  10755. namespace:
  10756. description: |-
  10757. The namespace the Provider type is in.
  10758. Can only be defined when used in a ClusterSecretStore.
  10759. maxLength: 63
  10760. minLength: 1
  10761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10762. type: string
  10763. type:
  10764. description: The type of provider to use such as "Secret", or "ConfigMap".
  10765. enum:
  10766. - Secret
  10767. - ConfigMap
  10768. type: string
  10769. required:
  10770. - name
  10771. - type
  10772. type: object
  10773. url:
  10774. description: URL is the endpoint of the Conjur instance.
  10775. type: string
  10776. required:
  10777. - auth
  10778. - url
  10779. type: object
  10780. delinea:
  10781. description: |-
  10782. Delinea DevOps Secrets Vault
  10783. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10784. properties:
  10785. clientId:
  10786. description: ClientID is the non-secret part of the credential.
  10787. properties:
  10788. secretRef:
  10789. description: SecretRef references a key in a secret that will be used as value.
  10790. properties:
  10791. key:
  10792. description: |-
  10793. A key in the referenced Secret.
  10794. Some instances of this field may be defaulted, in others it may be required.
  10795. maxLength: 253
  10796. minLength: 1
  10797. pattern: ^[-._a-zA-Z0-9]+$
  10798. type: string
  10799. name:
  10800. description: The name of the Secret resource being referred to.
  10801. maxLength: 253
  10802. minLength: 1
  10803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10804. type: string
  10805. namespace:
  10806. description: |-
  10807. The namespace of the Secret resource being referred to.
  10808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10809. maxLength: 63
  10810. minLength: 1
  10811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10812. type: string
  10813. type: object
  10814. value:
  10815. description: Value can be specified directly to set a value without using a secret.
  10816. type: string
  10817. type: object
  10818. clientSecret:
  10819. description: ClientSecret is the secret part of the credential.
  10820. properties:
  10821. secretRef:
  10822. description: SecretRef references a key in a secret that will be used as value.
  10823. properties:
  10824. key:
  10825. description: |-
  10826. A key in the referenced Secret.
  10827. Some instances of this field may be defaulted, in others it may be required.
  10828. maxLength: 253
  10829. minLength: 1
  10830. pattern: ^[-._a-zA-Z0-9]+$
  10831. type: string
  10832. name:
  10833. description: The name of the Secret resource being referred to.
  10834. maxLength: 253
  10835. minLength: 1
  10836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10837. type: string
  10838. namespace:
  10839. description: |-
  10840. The namespace of the Secret resource being referred to.
  10841. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10842. maxLength: 63
  10843. minLength: 1
  10844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10845. type: string
  10846. type: object
  10847. value:
  10848. description: Value can be specified directly to set a value without using a secret.
  10849. type: string
  10850. type: object
  10851. tenant:
  10852. description: Tenant is the chosen hostname / site name.
  10853. type: string
  10854. tld:
  10855. description: |-
  10856. TLD is based on the server location that was chosen during provisioning.
  10857. If unset, defaults to "com".
  10858. type: string
  10859. urlTemplate:
  10860. description: |-
  10861. URLTemplate
  10862. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10863. type: string
  10864. required:
  10865. - clientId
  10866. - clientSecret
  10867. - tenant
  10868. type: object
  10869. device42:
  10870. description: Device42 configures this store to sync secrets using the Device42 provider
  10871. properties:
  10872. auth:
  10873. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10874. properties:
  10875. secretRef:
  10876. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10877. properties:
  10878. credentials:
  10879. description: Username / Password is used for authentication.
  10880. properties:
  10881. key:
  10882. description: |-
  10883. A key in the referenced Secret.
  10884. Some instances of this field may be defaulted, in others it may be required.
  10885. maxLength: 253
  10886. minLength: 1
  10887. pattern: ^[-._a-zA-Z0-9]+$
  10888. type: string
  10889. name:
  10890. description: The name of the Secret resource being referred to.
  10891. maxLength: 253
  10892. minLength: 1
  10893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10894. type: string
  10895. namespace:
  10896. description: |-
  10897. The namespace of the Secret resource being referred to.
  10898. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10899. maxLength: 63
  10900. minLength: 1
  10901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10902. type: string
  10903. type: object
  10904. type: object
  10905. required:
  10906. - secretRef
  10907. type: object
  10908. host:
  10909. description: URL configures the Device42 instance URL.
  10910. type: string
  10911. required:
  10912. - auth
  10913. - host
  10914. type: object
  10915. doppler:
  10916. description: Doppler configures this store to sync secrets using the Doppler provider
  10917. properties:
  10918. auth:
  10919. description: Auth configures how the Operator authenticates with the Doppler API
  10920. properties:
  10921. secretRef:
  10922. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10923. properties:
  10924. dopplerToken:
  10925. description: |-
  10926. The DopplerToken is used for authentication.
  10927. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10928. The Key attribute defaults to dopplerToken if not specified.
  10929. properties:
  10930. key:
  10931. description: |-
  10932. A key in the referenced Secret.
  10933. Some instances of this field may be defaulted, in others it may be required.
  10934. maxLength: 253
  10935. minLength: 1
  10936. pattern: ^[-._a-zA-Z0-9]+$
  10937. type: string
  10938. name:
  10939. description: The name of the Secret resource being referred to.
  10940. maxLength: 253
  10941. minLength: 1
  10942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10943. type: string
  10944. namespace:
  10945. description: |-
  10946. The namespace of the Secret resource being referred to.
  10947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10948. maxLength: 63
  10949. minLength: 1
  10950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10951. type: string
  10952. type: object
  10953. required:
  10954. - dopplerToken
  10955. type: object
  10956. required:
  10957. - secretRef
  10958. type: object
  10959. config:
  10960. description: Doppler config (required if not using a Service Token)
  10961. type: string
  10962. format:
  10963. description: Format enables the downloading of secrets as a file (string)
  10964. enum:
  10965. - json
  10966. - dotnet-json
  10967. - env
  10968. - yaml
  10969. - docker
  10970. type: string
  10971. nameTransformer:
  10972. description: Environment variable compatible name transforms that change secret names to a different format
  10973. enum:
  10974. - upper-camel
  10975. - camel
  10976. - lower-snake
  10977. - tf-var
  10978. - dotnet-env
  10979. - lower-kebab
  10980. type: string
  10981. project:
  10982. description: Doppler project (required if not using a Service Token)
  10983. type: string
  10984. required:
  10985. - auth
  10986. type: object
  10987. fake:
  10988. description: Fake configures a store with static key/value pairs
  10989. properties:
  10990. data:
  10991. items:
  10992. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10993. properties:
  10994. key:
  10995. type: string
  10996. value:
  10997. type: string
  10998. version:
  10999. type: string
  11000. required:
  11001. - key
  11002. - value
  11003. type: object
  11004. type: array
  11005. required:
  11006. - data
  11007. type: object
  11008. fortanix:
  11009. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11010. properties:
  11011. apiKey:
  11012. description: APIKey is the API token to access SDKMS Applications.
  11013. properties:
  11014. secretRef:
  11015. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11016. properties:
  11017. key:
  11018. description: |-
  11019. A key in the referenced Secret.
  11020. Some instances of this field may be defaulted, in others it may be required.
  11021. maxLength: 253
  11022. minLength: 1
  11023. pattern: ^[-._a-zA-Z0-9]+$
  11024. type: string
  11025. name:
  11026. description: The name of the Secret resource being referred to.
  11027. maxLength: 253
  11028. minLength: 1
  11029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11030. type: string
  11031. namespace:
  11032. description: |-
  11033. The namespace of the Secret resource being referred to.
  11034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11035. maxLength: 63
  11036. minLength: 1
  11037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11038. type: string
  11039. type: object
  11040. type: object
  11041. apiUrl:
  11042. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11043. type: string
  11044. type: object
  11045. gcpsm:
  11046. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11047. properties:
  11048. auth:
  11049. description: Auth defines the information necessary to authenticate against GCP
  11050. properties:
  11051. secretRef:
  11052. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  11053. properties:
  11054. secretAccessKeySecretRef:
  11055. description: The SecretAccessKey is used for authentication
  11056. properties:
  11057. key:
  11058. description: |-
  11059. A key in the referenced Secret.
  11060. Some instances of this field may be defaulted, in others it may be required.
  11061. maxLength: 253
  11062. minLength: 1
  11063. pattern: ^[-._a-zA-Z0-9]+$
  11064. type: string
  11065. name:
  11066. description: The name of the Secret resource being referred to.
  11067. maxLength: 253
  11068. minLength: 1
  11069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11070. type: string
  11071. namespace:
  11072. description: |-
  11073. The namespace of the Secret resource being referred to.
  11074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11075. maxLength: 63
  11076. minLength: 1
  11077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11078. type: string
  11079. type: object
  11080. type: object
  11081. workloadIdentity:
  11082. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  11083. properties:
  11084. clusterLocation:
  11085. description: |-
  11086. ClusterLocation is the location of the cluster
  11087. If not specified, it fetches information from the metadata server
  11088. type: string
  11089. clusterName:
  11090. description: |-
  11091. ClusterName is the name of the cluster
  11092. If not specified, it fetches information from the metadata server
  11093. type: string
  11094. clusterProjectID:
  11095. description: |-
  11096. ClusterProjectID is the project ID of the cluster
  11097. If not specified, it fetches information from the metadata server
  11098. type: string
  11099. serviceAccountRef:
  11100. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11101. properties:
  11102. audiences:
  11103. description: |-
  11104. Audience specifies the `aud` claim for the service account token
  11105. Some providers automatically extend the audience field based on well-known annotations for workload
  11106. identity (e.g. IRSA or GCP Workload Identity)
  11107. items:
  11108. type: string
  11109. type: array
  11110. name:
  11111. description: The name of the ServiceAccount resource being referred to.
  11112. maxLength: 253
  11113. minLength: 1
  11114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11115. type: string
  11116. namespace:
  11117. description: |-
  11118. Namespace of the resource being referred to.
  11119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11120. maxLength: 63
  11121. minLength: 1
  11122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11123. type: string
  11124. required:
  11125. - name
  11126. type: object
  11127. required:
  11128. - serviceAccountRef
  11129. type: object
  11130. type: object
  11131. location:
  11132. description: Location optionally defines a location for a secret
  11133. type: string
  11134. projectID:
  11135. description: ProjectID project where secret is located
  11136. type: string
  11137. type: object
  11138. github:
  11139. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11140. properties:
  11141. appID:
  11142. description: appID specifies the Github APP that will be used to authenticate the client
  11143. format: int64
  11144. type: integer
  11145. auth:
  11146. description: auth configures how secret-manager authenticates with a Github instance.
  11147. properties:
  11148. privateKey:
  11149. description: |-
  11150. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11151. In some instances, `key` is a required field.
  11152. properties:
  11153. key:
  11154. description: |-
  11155. A key in the referenced Secret.
  11156. Some instances of this field may be defaulted, in others it may be required.
  11157. maxLength: 253
  11158. minLength: 1
  11159. pattern: ^[-._a-zA-Z0-9]+$
  11160. type: string
  11161. name:
  11162. description: The name of the Secret resource being referred to.
  11163. maxLength: 253
  11164. minLength: 1
  11165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11166. type: string
  11167. namespace:
  11168. description: |-
  11169. The namespace of the Secret resource being referred to.
  11170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11171. maxLength: 63
  11172. minLength: 1
  11173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11174. type: string
  11175. type: object
  11176. required:
  11177. - privateKey
  11178. type: object
  11179. environment:
  11180. description: environment will be used to fetch secrets from a particular environment within a github repository
  11181. type: string
  11182. installationID:
  11183. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11184. format: int64
  11185. type: integer
  11186. organization:
  11187. description: organization will be used to fetch secrets from the Github organization
  11188. type: string
  11189. repository:
  11190. description: repository will be used to fetch secrets from the Github repository within an organization
  11191. type: string
  11192. uploadURL:
  11193. description: Upload URL for enterprise instances. Default to URL.
  11194. type: string
  11195. url:
  11196. default: https://github.com/
  11197. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11198. type: string
  11199. required:
  11200. - appID
  11201. - auth
  11202. - installationID
  11203. - organization
  11204. type: object
  11205. gitlab:
  11206. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11207. properties:
  11208. auth:
  11209. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11210. properties:
  11211. SecretRef:
  11212. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11213. properties:
  11214. accessToken:
  11215. description: AccessToken is used for authentication.
  11216. properties:
  11217. key:
  11218. description: |-
  11219. A key in the referenced Secret.
  11220. Some instances of this field may be defaulted, in others it may be required.
  11221. maxLength: 253
  11222. minLength: 1
  11223. pattern: ^[-._a-zA-Z0-9]+$
  11224. type: string
  11225. name:
  11226. description: The name of the Secret resource being referred to.
  11227. maxLength: 253
  11228. minLength: 1
  11229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11230. type: string
  11231. namespace:
  11232. description: |-
  11233. The namespace of the Secret resource being referred to.
  11234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11235. maxLength: 63
  11236. minLength: 1
  11237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11238. type: string
  11239. type: object
  11240. type: object
  11241. required:
  11242. - SecretRef
  11243. type: object
  11244. caBundle:
  11245. description: |-
  11246. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11247. can be performed.
  11248. format: byte
  11249. type: string
  11250. caProvider:
  11251. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11252. properties:
  11253. key:
  11254. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11255. maxLength: 253
  11256. minLength: 1
  11257. pattern: ^[-._a-zA-Z0-9]+$
  11258. type: string
  11259. name:
  11260. description: The name of the object located at the provider type.
  11261. maxLength: 253
  11262. minLength: 1
  11263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11264. type: string
  11265. namespace:
  11266. description: |-
  11267. The namespace the Provider type is in.
  11268. Can only be defined when used in a ClusterSecretStore.
  11269. maxLength: 63
  11270. minLength: 1
  11271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11272. type: string
  11273. type:
  11274. description: The type of provider to use such as "Secret", or "ConfigMap".
  11275. enum:
  11276. - Secret
  11277. - ConfigMap
  11278. type: string
  11279. required:
  11280. - name
  11281. - type
  11282. type: object
  11283. environment:
  11284. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11285. type: string
  11286. groupIDs:
  11287. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11288. items:
  11289. type: string
  11290. type: array
  11291. inheritFromGroups:
  11292. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11293. type: boolean
  11294. projectID:
  11295. description: ProjectID specifies a project where secrets are located.
  11296. type: string
  11297. url:
  11298. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11299. type: string
  11300. required:
  11301. - auth
  11302. type: object
  11303. ibm:
  11304. description: IBM configures this store to sync secrets using IBM Cloud provider
  11305. properties:
  11306. auth:
  11307. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11308. maxProperties: 1
  11309. minProperties: 1
  11310. properties:
  11311. containerAuth:
  11312. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11313. properties:
  11314. iamEndpoint:
  11315. type: string
  11316. profile:
  11317. description: the IBM Trusted Profile
  11318. type: string
  11319. tokenLocation:
  11320. description: Location the token is mounted on the pod
  11321. type: string
  11322. required:
  11323. - profile
  11324. type: object
  11325. secretRef:
  11326. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11327. properties:
  11328. secretApiKeySecretRef:
  11329. description: The SecretAccessKey is used for authentication
  11330. properties:
  11331. key:
  11332. description: |-
  11333. A key in the referenced Secret.
  11334. Some instances of this field may be defaulted, in others it may be required.
  11335. maxLength: 253
  11336. minLength: 1
  11337. pattern: ^[-._a-zA-Z0-9]+$
  11338. type: string
  11339. name:
  11340. description: The name of the Secret resource being referred to.
  11341. maxLength: 253
  11342. minLength: 1
  11343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11344. type: string
  11345. namespace:
  11346. description: |-
  11347. The namespace of the Secret resource being referred to.
  11348. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11349. maxLength: 63
  11350. minLength: 1
  11351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11352. type: string
  11353. type: object
  11354. type: object
  11355. type: object
  11356. serviceUrl:
  11357. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11358. type: string
  11359. required:
  11360. - auth
  11361. type: object
  11362. infisical:
  11363. description: Infisical configures this store to sync secrets using the Infisical provider
  11364. properties:
  11365. auth:
  11366. description: Auth configures how the Operator authenticates with the Infisical API
  11367. properties:
  11368. universalAuthCredentials:
  11369. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11370. properties:
  11371. clientId:
  11372. description: |-
  11373. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11374. In some instances, `key` is a required field.
  11375. properties:
  11376. key:
  11377. description: |-
  11378. A key in the referenced Secret.
  11379. Some instances of this field may be defaulted, in others it may be required.
  11380. maxLength: 253
  11381. minLength: 1
  11382. pattern: ^[-._a-zA-Z0-9]+$
  11383. type: string
  11384. name:
  11385. description: The name of the Secret resource being referred to.
  11386. maxLength: 253
  11387. minLength: 1
  11388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11389. type: string
  11390. namespace:
  11391. description: |-
  11392. The namespace of the Secret resource being referred to.
  11393. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11394. maxLength: 63
  11395. minLength: 1
  11396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11397. type: string
  11398. type: object
  11399. clientSecret:
  11400. description: |-
  11401. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11402. In some instances, `key` is a required field.
  11403. properties:
  11404. key:
  11405. description: |-
  11406. A key in the referenced Secret.
  11407. Some instances of this field may be defaulted, in others it may be required.
  11408. maxLength: 253
  11409. minLength: 1
  11410. pattern: ^[-._a-zA-Z0-9]+$
  11411. type: string
  11412. name:
  11413. description: The name of the Secret resource being referred to.
  11414. maxLength: 253
  11415. minLength: 1
  11416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11417. type: string
  11418. namespace:
  11419. description: |-
  11420. The namespace of the Secret resource being referred to.
  11421. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11422. maxLength: 63
  11423. minLength: 1
  11424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11425. type: string
  11426. type: object
  11427. required:
  11428. - clientId
  11429. - clientSecret
  11430. type: object
  11431. type: object
  11432. hostAPI:
  11433. default: https://app.infisical.com/api
  11434. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11435. type: string
  11436. secretsScope:
  11437. description: SecretsScope defines the scope of the secrets within the workspace
  11438. properties:
  11439. environmentSlug:
  11440. description: EnvironmentSlug is the required slug identifier for the environment.
  11441. type: string
  11442. expandSecretReferences:
  11443. default: true
  11444. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11445. type: boolean
  11446. projectSlug:
  11447. description: ProjectSlug is the required slug identifier for the project.
  11448. type: string
  11449. recursive:
  11450. default: false
  11451. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11452. type: boolean
  11453. secretsPath:
  11454. default: /
  11455. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11456. type: string
  11457. required:
  11458. - environmentSlug
  11459. - projectSlug
  11460. type: object
  11461. required:
  11462. - auth
  11463. - secretsScope
  11464. type: object
  11465. keepersecurity:
  11466. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11467. properties:
  11468. authRef:
  11469. description: |-
  11470. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11471. In some instances, `key` is a required field.
  11472. properties:
  11473. key:
  11474. description: |-
  11475. A key in the referenced Secret.
  11476. Some instances of this field may be defaulted, in others it may be required.
  11477. maxLength: 253
  11478. minLength: 1
  11479. pattern: ^[-._a-zA-Z0-9]+$
  11480. type: string
  11481. name:
  11482. description: The name of the Secret resource being referred to.
  11483. maxLength: 253
  11484. minLength: 1
  11485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11486. type: string
  11487. namespace:
  11488. description: |-
  11489. The namespace of the Secret resource being referred to.
  11490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11491. maxLength: 63
  11492. minLength: 1
  11493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11494. type: string
  11495. type: object
  11496. folderID:
  11497. type: string
  11498. required:
  11499. - authRef
  11500. - folderID
  11501. type: object
  11502. kubernetes:
  11503. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11504. properties:
  11505. auth:
  11506. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11507. maxProperties: 1
  11508. minProperties: 1
  11509. properties:
  11510. cert:
  11511. description: has both clientCert and clientKey as secretKeySelector
  11512. properties:
  11513. clientCert:
  11514. description: |-
  11515. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11516. In some instances, `key` is a required field.
  11517. properties:
  11518. key:
  11519. description: |-
  11520. A key in the referenced Secret.
  11521. Some instances of this field may be defaulted, in others it may be required.
  11522. maxLength: 253
  11523. minLength: 1
  11524. pattern: ^[-._a-zA-Z0-9]+$
  11525. type: string
  11526. name:
  11527. description: The name of the Secret resource being referred to.
  11528. maxLength: 253
  11529. minLength: 1
  11530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11531. type: string
  11532. namespace:
  11533. description: |-
  11534. The namespace of the Secret resource being referred to.
  11535. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11536. maxLength: 63
  11537. minLength: 1
  11538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11539. type: string
  11540. type: object
  11541. clientKey:
  11542. description: |-
  11543. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11544. In some instances, `key` is a required field.
  11545. properties:
  11546. key:
  11547. description: |-
  11548. A key in the referenced Secret.
  11549. Some instances of this field may be defaulted, in others it may be required.
  11550. maxLength: 253
  11551. minLength: 1
  11552. pattern: ^[-._a-zA-Z0-9]+$
  11553. type: string
  11554. name:
  11555. description: The name of the Secret resource being referred to.
  11556. maxLength: 253
  11557. minLength: 1
  11558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11559. type: string
  11560. namespace:
  11561. description: |-
  11562. The namespace of the Secret resource being referred to.
  11563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11564. maxLength: 63
  11565. minLength: 1
  11566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11567. type: string
  11568. type: object
  11569. type: object
  11570. serviceAccount:
  11571. description: points to a service account that should be used for authentication
  11572. properties:
  11573. audiences:
  11574. description: |-
  11575. Audience specifies the `aud` claim for the service account token
  11576. Some providers automatically extend the audience field based on well-known annotations for workload
  11577. identity (e.g. IRSA or GCP Workload Identity)
  11578. items:
  11579. type: string
  11580. type: array
  11581. name:
  11582. description: The name of the ServiceAccount resource being referred to.
  11583. maxLength: 253
  11584. minLength: 1
  11585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11586. type: string
  11587. namespace:
  11588. description: |-
  11589. Namespace of the resource being referred to.
  11590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11591. maxLength: 63
  11592. minLength: 1
  11593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11594. type: string
  11595. required:
  11596. - name
  11597. type: object
  11598. token:
  11599. description: use static token to authenticate with
  11600. properties:
  11601. bearerToken:
  11602. description: |-
  11603. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11604. In some instances, `key` is a required field.
  11605. properties:
  11606. key:
  11607. description: |-
  11608. A key in the referenced Secret.
  11609. Some instances of this field may be defaulted, in others it may be required.
  11610. maxLength: 253
  11611. minLength: 1
  11612. pattern: ^[-._a-zA-Z0-9]+$
  11613. type: string
  11614. name:
  11615. description: The name of the Secret resource being referred to.
  11616. maxLength: 253
  11617. minLength: 1
  11618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11619. type: string
  11620. namespace:
  11621. description: |-
  11622. The namespace of the Secret resource being referred to.
  11623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11624. maxLength: 63
  11625. minLength: 1
  11626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11627. type: string
  11628. type: object
  11629. type: object
  11630. type: object
  11631. authRef:
  11632. description: A reference to a secret that contains the auth information.
  11633. properties:
  11634. key:
  11635. description: |-
  11636. A key in the referenced Secret.
  11637. Some instances of this field may be defaulted, in others it may be required.
  11638. maxLength: 253
  11639. minLength: 1
  11640. pattern: ^[-._a-zA-Z0-9]+$
  11641. type: string
  11642. name:
  11643. description: The name of the Secret resource being referred to.
  11644. maxLength: 253
  11645. minLength: 1
  11646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11647. type: string
  11648. namespace:
  11649. description: |-
  11650. The namespace of the Secret resource being referred to.
  11651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11652. maxLength: 63
  11653. minLength: 1
  11654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11655. type: string
  11656. type: object
  11657. remoteNamespace:
  11658. default: default
  11659. description: Remote namespace to fetch the secrets from
  11660. maxLength: 63
  11661. minLength: 1
  11662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11663. type: string
  11664. server:
  11665. description: configures the Kubernetes server Address.
  11666. properties:
  11667. caBundle:
  11668. description: CABundle is a base64-encoded CA certificate
  11669. format: byte
  11670. type: string
  11671. caProvider:
  11672. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11673. properties:
  11674. key:
  11675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11676. maxLength: 253
  11677. minLength: 1
  11678. pattern: ^[-._a-zA-Z0-9]+$
  11679. type: string
  11680. name:
  11681. description: The name of the object located at the provider type.
  11682. maxLength: 253
  11683. minLength: 1
  11684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11685. type: string
  11686. namespace:
  11687. description: |-
  11688. The namespace the Provider type is in.
  11689. Can only be defined when used in a ClusterSecretStore.
  11690. maxLength: 63
  11691. minLength: 1
  11692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11693. type: string
  11694. type:
  11695. description: The type of provider to use such as "Secret", or "ConfigMap".
  11696. enum:
  11697. - Secret
  11698. - ConfigMap
  11699. type: string
  11700. required:
  11701. - name
  11702. - type
  11703. type: object
  11704. url:
  11705. default: kubernetes.default
  11706. description: configures the Kubernetes server Address.
  11707. type: string
  11708. type: object
  11709. type: object
  11710. onboardbase:
  11711. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11712. properties:
  11713. apiHost:
  11714. default: https://public.onboardbase.com/api/v1/
  11715. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11716. type: string
  11717. auth:
  11718. description: Auth configures how the Operator authenticates with the Onboardbase API
  11719. properties:
  11720. apiKeyRef:
  11721. description: |-
  11722. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11723. It is used to recognize and authorize access to a project and environment within onboardbase
  11724. properties:
  11725. key:
  11726. description: |-
  11727. A key in the referenced Secret.
  11728. Some instances of this field may be defaulted, in others it may be required.
  11729. maxLength: 253
  11730. minLength: 1
  11731. pattern: ^[-._a-zA-Z0-9]+$
  11732. type: string
  11733. name:
  11734. description: The name of the Secret resource being referred to.
  11735. maxLength: 253
  11736. minLength: 1
  11737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11738. type: string
  11739. namespace:
  11740. description: |-
  11741. The namespace of the Secret resource being referred to.
  11742. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11743. maxLength: 63
  11744. minLength: 1
  11745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11746. type: string
  11747. type: object
  11748. passcodeRef:
  11749. description: OnboardbasePasscode is the passcode attached to the API Key
  11750. properties:
  11751. key:
  11752. description: |-
  11753. A key in the referenced Secret.
  11754. Some instances of this field may be defaulted, in others it may be required.
  11755. maxLength: 253
  11756. minLength: 1
  11757. pattern: ^[-._a-zA-Z0-9]+$
  11758. type: string
  11759. name:
  11760. description: The name of the Secret resource being referred to.
  11761. maxLength: 253
  11762. minLength: 1
  11763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11764. type: string
  11765. namespace:
  11766. description: |-
  11767. The namespace of the Secret resource being referred to.
  11768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11769. maxLength: 63
  11770. minLength: 1
  11771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11772. type: string
  11773. type: object
  11774. required:
  11775. - apiKeyRef
  11776. - passcodeRef
  11777. type: object
  11778. environment:
  11779. default: development
  11780. description: Environment is the name of an environmnent within a project to pull the secrets from
  11781. type: string
  11782. project:
  11783. default: development
  11784. description: Project is an onboardbase project that the secrets should be pulled from
  11785. type: string
  11786. required:
  11787. - apiHost
  11788. - auth
  11789. - environment
  11790. - project
  11791. type: object
  11792. onepassword:
  11793. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11794. properties:
  11795. auth:
  11796. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11797. properties:
  11798. secretRef:
  11799. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11800. properties:
  11801. connectTokenSecretRef:
  11802. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11803. properties:
  11804. key:
  11805. description: |-
  11806. A key in the referenced Secret.
  11807. Some instances of this field may be defaulted, in others it may be required.
  11808. maxLength: 253
  11809. minLength: 1
  11810. pattern: ^[-._a-zA-Z0-9]+$
  11811. type: string
  11812. name:
  11813. description: The name of the Secret resource being referred to.
  11814. maxLength: 253
  11815. minLength: 1
  11816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11817. type: string
  11818. namespace:
  11819. description: |-
  11820. The namespace of the Secret resource being referred to.
  11821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11822. maxLength: 63
  11823. minLength: 1
  11824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11825. type: string
  11826. type: object
  11827. required:
  11828. - connectTokenSecretRef
  11829. type: object
  11830. required:
  11831. - secretRef
  11832. type: object
  11833. connectHost:
  11834. description: ConnectHost defines the OnePassword Connect Server to connect to
  11835. type: string
  11836. vaults:
  11837. additionalProperties:
  11838. type: integer
  11839. description: Vaults defines which OnePassword vaults to search in which order
  11840. type: object
  11841. required:
  11842. - auth
  11843. - connectHost
  11844. - vaults
  11845. type: object
  11846. oracle:
  11847. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11848. properties:
  11849. auth:
  11850. description: |-
  11851. Auth configures how secret-manager authenticates with the Oracle Vault.
  11852. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11853. properties:
  11854. secretRef:
  11855. description: SecretRef to pass through sensitive information.
  11856. properties:
  11857. fingerprint:
  11858. description: Fingerprint is the fingerprint of the API private key.
  11859. properties:
  11860. key:
  11861. description: |-
  11862. A key in the referenced Secret.
  11863. Some instances of this field may be defaulted, in others it may be required.
  11864. maxLength: 253
  11865. minLength: 1
  11866. pattern: ^[-._a-zA-Z0-9]+$
  11867. type: string
  11868. name:
  11869. description: The name of the Secret resource being referred to.
  11870. maxLength: 253
  11871. minLength: 1
  11872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11873. type: string
  11874. namespace:
  11875. description: |-
  11876. The namespace of the Secret resource being referred to.
  11877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11878. maxLength: 63
  11879. minLength: 1
  11880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11881. type: string
  11882. type: object
  11883. privatekey:
  11884. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11885. properties:
  11886. key:
  11887. description: |-
  11888. A key in the referenced Secret.
  11889. Some instances of this field may be defaulted, in others it may be required.
  11890. maxLength: 253
  11891. minLength: 1
  11892. pattern: ^[-._a-zA-Z0-9]+$
  11893. type: string
  11894. name:
  11895. description: The name of the Secret resource being referred to.
  11896. maxLength: 253
  11897. minLength: 1
  11898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11899. type: string
  11900. namespace:
  11901. description: |-
  11902. The namespace of the Secret resource being referred to.
  11903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11904. maxLength: 63
  11905. minLength: 1
  11906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11907. type: string
  11908. type: object
  11909. required:
  11910. - fingerprint
  11911. - privatekey
  11912. type: object
  11913. tenancy:
  11914. description: Tenancy is the tenancy OCID where user is located.
  11915. type: string
  11916. user:
  11917. description: User is an access OCID specific to the account.
  11918. type: string
  11919. required:
  11920. - secretRef
  11921. - tenancy
  11922. - user
  11923. type: object
  11924. compartment:
  11925. description: |-
  11926. Compartment is the vault compartment OCID.
  11927. Required for PushSecret
  11928. type: string
  11929. encryptionKey:
  11930. description: |-
  11931. EncryptionKey is the OCID of the encryption key within the vault.
  11932. Required for PushSecret
  11933. type: string
  11934. principalType:
  11935. description: |-
  11936. The type of principal to use for authentication. If left blank, the Auth struct will
  11937. determine the principal type. This optional field must be specified if using
  11938. workload identity.
  11939. enum:
  11940. - ""
  11941. - UserPrincipal
  11942. - InstancePrincipal
  11943. - Workload
  11944. type: string
  11945. region:
  11946. description: Region is the region where vault is located.
  11947. type: string
  11948. serviceAccountRef:
  11949. description: |-
  11950. ServiceAccountRef specified the service account
  11951. that should be used when authenticating with WorkloadIdentity.
  11952. properties:
  11953. audiences:
  11954. description: |-
  11955. Audience specifies the `aud` claim for the service account token
  11956. Some providers automatically extend the audience field based on well-known annotations for workload
  11957. identity (e.g. IRSA or GCP Workload Identity)
  11958. items:
  11959. type: string
  11960. type: array
  11961. name:
  11962. description: The name of the ServiceAccount resource being referred to.
  11963. maxLength: 253
  11964. minLength: 1
  11965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11966. type: string
  11967. namespace:
  11968. description: |-
  11969. Namespace of the resource being referred to.
  11970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11971. maxLength: 63
  11972. minLength: 1
  11973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11974. type: string
  11975. required:
  11976. - name
  11977. type: object
  11978. vault:
  11979. description: Vault is the vault's OCID of the specific vault where secret is located.
  11980. type: string
  11981. required:
  11982. - region
  11983. - vault
  11984. type: object
  11985. passbolt:
  11986. description: PassboltProvider defines configuration for the Passbolt provider.
  11987. properties:
  11988. auth:
  11989. description: Auth defines the information necessary to authenticate against Passbolt Server
  11990. properties:
  11991. passwordSecretRef:
  11992. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11993. properties:
  11994. key:
  11995. description: |-
  11996. A key in the referenced Secret.
  11997. Some instances of this field may be defaulted, in others it may be required.
  11998. maxLength: 253
  11999. minLength: 1
  12000. pattern: ^[-._a-zA-Z0-9]+$
  12001. type: string
  12002. name:
  12003. description: The name of the Secret resource being referred to.
  12004. maxLength: 253
  12005. minLength: 1
  12006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12007. type: string
  12008. namespace:
  12009. description: |-
  12010. The namespace of the Secret resource being referred to.
  12011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12012. maxLength: 63
  12013. minLength: 1
  12014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12015. type: string
  12016. type: object
  12017. privateKeySecretRef:
  12018. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  12019. properties:
  12020. key:
  12021. description: |-
  12022. A key in the referenced Secret.
  12023. Some instances of this field may be defaulted, in others it may be required.
  12024. maxLength: 253
  12025. minLength: 1
  12026. pattern: ^[-._a-zA-Z0-9]+$
  12027. type: string
  12028. name:
  12029. description: The name of the Secret resource being referred to.
  12030. maxLength: 253
  12031. minLength: 1
  12032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12033. type: string
  12034. namespace:
  12035. description: |-
  12036. The namespace of the Secret resource being referred to.
  12037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12038. maxLength: 63
  12039. minLength: 1
  12040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12041. type: string
  12042. type: object
  12043. required:
  12044. - passwordSecretRef
  12045. - privateKeySecretRef
  12046. type: object
  12047. host:
  12048. description: Host defines the Passbolt Server to connect to
  12049. type: string
  12050. required:
  12051. - auth
  12052. - host
  12053. type: object
  12054. passworddepot:
  12055. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  12056. properties:
  12057. auth:
  12058. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12059. properties:
  12060. secretRef:
  12061. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  12062. properties:
  12063. credentials:
  12064. description: Username / Password is used for authentication.
  12065. properties:
  12066. key:
  12067. description: |-
  12068. A key in the referenced Secret.
  12069. Some instances of this field may be defaulted, in others it may be required.
  12070. maxLength: 253
  12071. minLength: 1
  12072. pattern: ^[-._a-zA-Z0-9]+$
  12073. type: string
  12074. name:
  12075. description: The name of the Secret resource being referred to.
  12076. maxLength: 253
  12077. minLength: 1
  12078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12079. type: string
  12080. namespace:
  12081. description: |-
  12082. The namespace of the Secret resource being referred to.
  12083. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12084. maxLength: 63
  12085. minLength: 1
  12086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12087. type: string
  12088. type: object
  12089. type: object
  12090. required:
  12091. - secretRef
  12092. type: object
  12093. database:
  12094. description: Database to use as source
  12095. type: string
  12096. host:
  12097. description: URL configures the Password Depot instance URL.
  12098. type: string
  12099. required:
  12100. - auth
  12101. - database
  12102. - host
  12103. type: object
  12104. previder:
  12105. description: Previder configures this store to sync secrets using the Previder provider
  12106. properties:
  12107. auth:
  12108. description: PreviderAuth contains a secretRef for credentials.
  12109. properties:
  12110. secretRef:
  12111. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12112. properties:
  12113. accessToken:
  12114. description: The AccessToken is used for authentication
  12115. properties:
  12116. key:
  12117. description: |-
  12118. A key in the referenced Secret.
  12119. Some instances of this field may be defaulted, in others it may be required.
  12120. maxLength: 253
  12121. minLength: 1
  12122. pattern: ^[-._a-zA-Z0-9]+$
  12123. type: string
  12124. name:
  12125. description: The name of the Secret resource being referred to.
  12126. maxLength: 253
  12127. minLength: 1
  12128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12129. type: string
  12130. namespace:
  12131. description: |-
  12132. The namespace of the Secret resource being referred to.
  12133. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12134. maxLength: 63
  12135. minLength: 1
  12136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12137. type: string
  12138. type: object
  12139. required:
  12140. - accessToken
  12141. type: object
  12142. type: object
  12143. baseUri:
  12144. type: string
  12145. required:
  12146. - auth
  12147. type: object
  12148. pulumi:
  12149. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12150. properties:
  12151. accessToken:
  12152. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12153. properties:
  12154. secretRef:
  12155. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12156. properties:
  12157. key:
  12158. description: |-
  12159. A key in the referenced Secret.
  12160. Some instances of this field may be defaulted, in others it may be required.
  12161. maxLength: 253
  12162. minLength: 1
  12163. pattern: ^[-._a-zA-Z0-9]+$
  12164. type: string
  12165. name:
  12166. description: The name of the Secret resource being referred to.
  12167. maxLength: 253
  12168. minLength: 1
  12169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12170. type: string
  12171. namespace:
  12172. description: |-
  12173. The namespace of the Secret resource being referred to.
  12174. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12175. maxLength: 63
  12176. minLength: 1
  12177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12178. type: string
  12179. type: object
  12180. type: object
  12181. apiUrl:
  12182. default: https://api.pulumi.com/api/esc
  12183. description: APIURL is the URL of the Pulumi API.
  12184. type: string
  12185. environment:
  12186. description: |-
  12187. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12188. dynamically retrieved values from supported providers including all major clouds,
  12189. and other Pulumi ESC environments.
  12190. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12191. type: string
  12192. organization:
  12193. description: |-
  12194. Organization are a space to collaborate on shared projects and stacks.
  12195. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12196. type: string
  12197. project:
  12198. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12199. type: string
  12200. required:
  12201. - accessToken
  12202. - environment
  12203. - organization
  12204. - project
  12205. type: object
  12206. scaleway:
  12207. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12208. properties:
  12209. accessKey:
  12210. description: AccessKey is the non-secret part of the api key.
  12211. properties:
  12212. secretRef:
  12213. description: SecretRef references a key in a secret that will be used as value.
  12214. properties:
  12215. key:
  12216. description: |-
  12217. A key in the referenced Secret.
  12218. Some instances of this field may be defaulted, in others it may be required.
  12219. maxLength: 253
  12220. minLength: 1
  12221. pattern: ^[-._a-zA-Z0-9]+$
  12222. type: string
  12223. name:
  12224. description: The name of the Secret resource being referred to.
  12225. maxLength: 253
  12226. minLength: 1
  12227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12228. type: string
  12229. namespace:
  12230. description: |-
  12231. The namespace of the Secret resource being referred to.
  12232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12233. maxLength: 63
  12234. minLength: 1
  12235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12236. type: string
  12237. type: object
  12238. value:
  12239. description: Value can be specified directly to set a value without using a secret.
  12240. type: string
  12241. type: object
  12242. apiUrl:
  12243. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12244. type: string
  12245. projectId:
  12246. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12247. type: string
  12248. region:
  12249. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12250. type: string
  12251. secretKey:
  12252. description: SecretKey is the non-secret part of the api key.
  12253. properties:
  12254. secretRef:
  12255. description: SecretRef references a key in a secret that will be used as value.
  12256. properties:
  12257. key:
  12258. description: |-
  12259. A key in the referenced Secret.
  12260. Some instances of this field may be defaulted, in others it may be required.
  12261. maxLength: 253
  12262. minLength: 1
  12263. pattern: ^[-._a-zA-Z0-9]+$
  12264. type: string
  12265. name:
  12266. description: The name of the Secret resource being referred to.
  12267. maxLength: 253
  12268. minLength: 1
  12269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12270. type: string
  12271. namespace:
  12272. description: |-
  12273. The namespace of the Secret resource being referred to.
  12274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12275. maxLength: 63
  12276. minLength: 1
  12277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12278. type: string
  12279. type: object
  12280. value:
  12281. description: Value can be specified directly to set a value without using a secret.
  12282. type: string
  12283. type: object
  12284. required:
  12285. - accessKey
  12286. - projectId
  12287. - region
  12288. - secretKey
  12289. type: object
  12290. secretserver:
  12291. description: |-
  12292. SecretServer configures this store to sync secrets using SecretServer provider
  12293. https://docs.delinea.com/online-help/secret-server/start.htm
  12294. properties:
  12295. password:
  12296. description: Password is the secret server account password.
  12297. properties:
  12298. secretRef:
  12299. description: SecretRef references a key in a secret that will be used as value.
  12300. properties:
  12301. key:
  12302. description: |-
  12303. A key in the referenced Secret.
  12304. Some instances of this field may be defaulted, in others it may be required.
  12305. maxLength: 253
  12306. minLength: 1
  12307. pattern: ^[-._a-zA-Z0-9]+$
  12308. type: string
  12309. name:
  12310. description: The name of the Secret resource being referred to.
  12311. maxLength: 253
  12312. minLength: 1
  12313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12314. type: string
  12315. namespace:
  12316. description: |-
  12317. The namespace of the Secret resource being referred to.
  12318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12319. maxLength: 63
  12320. minLength: 1
  12321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12322. type: string
  12323. type: object
  12324. value:
  12325. description: Value can be specified directly to set a value without using a secret.
  12326. type: string
  12327. type: object
  12328. serverURL:
  12329. description: |-
  12330. ServerURL
  12331. URL to your secret server installation
  12332. type: string
  12333. username:
  12334. description: Username is the secret server account username.
  12335. properties:
  12336. secretRef:
  12337. description: SecretRef references a key in a secret that will be used as value.
  12338. properties:
  12339. key:
  12340. description: |-
  12341. A key in the referenced Secret.
  12342. Some instances of this field may be defaulted, in others it may be required.
  12343. maxLength: 253
  12344. minLength: 1
  12345. pattern: ^[-._a-zA-Z0-9]+$
  12346. type: string
  12347. name:
  12348. description: The name of the Secret resource being referred to.
  12349. maxLength: 253
  12350. minLength: 1
  12351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12352. type: string
  12353. namespace:
  12354. description: |-
  12355. The namespace of the Secret resource being referred to.
  12356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12357. maxLength: 63
  12358. minLength: 1
  12359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12360. type: string
  12361. type: object
  12362. value:
  12363. description: Value can be specified directly to set a value without using a secret.
  12364. type: string
  12365. type: object
  12366. required:
  12367. - password
  12368. - serverURL
  12369. - username
  12370. type: object
  12371. senhasegura:
  12372. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12373. properties:
  12374. auth:
  12375. description: Auth defines parameters to authenticate in senhasegura
  12376. properties:
  12377. clientId:
  12378. type: string
  12379. clientSecretSecretRef:
  12380. description: |-
  12381. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12382. In some instances, `key` is a required field.
  12383. properties:
  12384. key:
  12385. description: |-
  12386. A key in the referenced Secret.
  12387. Some instances of this field may be defaulted, in others it may be required.
  12388. maxLength: 253
  12389. minLength: 1
  12390. pattern: ^[-._a-zA-Z0-9]+$
  12391. type: string
  12392. name:
  12393. description: The name of the Secret resource being referred to.
  12394. maxLength: 253
  12395. minLength: 1
  12396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12397. type: string
  12398. namespace:
  12399. description: |-
  12400. The namespace of the Secret resource being referred to.
  12401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12402. maxLength: 63
  12403. minLength: 1
  12404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12405. type: string
  12406. type: object
  12407. required:
  12408. - clientId
  12409. - clientSecretSecretRef
  12410. type: object
  12411. ignoreSslCertificate:
  12412. default: false
  12413. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12414. type: boolean
  12415. module:
  12416. description: Module defines which senhasegura module should be used to get secrets
  12417. type: string
  12418. url:
  12419. description: URL of senhasegura
  12420. type: string
  12421. required:
  12422. - auth
  12423. - module
  12424. - url
  12425. type: object
  12426. vault:
  12427. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12428. properties:
  12429. auth:
  12430. description: Auth configures how secret-manager authenticates with the Vault server.
  12431. properties:
  12432. appRole:
  12433. description: |-
  12434. AppRole authenticates with Vault using the App Role auth mechanism,
  12435. with the role and secret stored in a Kubernetes Secret resource.
  12436. properties:
  12437. path:
  12438. default: approle
  12439. description: |-
  12440. Path where the App Role authentication backend is mounted
  12441. in Vault, e.g: "approle"
  12442. type: string
  12443. roleId:
  12444. description: |-
  12445. RoleID configured in the App Role authentication backend when setting
  12446. up the authentication backend in Vault.
  12447. type: string
  12448. roleRef:
  12449. description: |-
  12450. Reference to a key in a Secret that contains the App Role ID used
  12451. to authenticate with Vault.
  12452. The `key` field must be specified and denotes which entry within the Secret
  12453. resource is used as the app role id.
  12454. properties:
  12455. key:
  12456. description: |-
  12457. A key in the referenced Secret.
  12458. Some instances of this field may be defaulted, in others it may be required.
  12459. maxLength: 253
  12460. minLength: 1
  12461. pattern: ^[-._a-zA-Z0-9]+$
  12462. type: string
  12463. name:
  12464. description: The name of the Secret resource being referred to.
  12465. maxLength: 253
  12466. minLength: 1
  12467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12468. type: string
  12469. namespace:
  12470. description: |-
  12471. The namespace of the Secret resource being referred to.
  12472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12473. maxLength: 63
  12474. minLength: 1
  12475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12476. type: string
  12477. type: object
  12478. secretRef:
  12479. description: |-
  12480. Reference to a key in a Secret that contains the App Role secret used
  12481. to authenticate with Vault.
  12482. The `key` field must be specified and denotes which entry within the Secret
  12483. resource is used as the app role secret.
  12484. properties:
  12485. key:
  12486. description: |-
  12487. A key in the referenced Secret.
  12488. Some instances of this field may be defaulted, in others it may be required.
  12489. maxLength: 253
  12490. minLength: 1
  12491. pattern: ^[-._a-zA-Z0-9]+$
  12492. type: string
  12493. name:
  12494. description: The name of the Secret resource being referred to.
  12495. maxLength: 253
  12496. minLength: 1
  12497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12498. type: string
  12499. namespace:
  12500. description: |-
  12501. The namespace of the Secret resource being referred to.
  12502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12503. maxLength: 63
  12504. minLength: 1
  12505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12506. type: string
  12507. type: object
  12508. required:
  12509. - path
  12510. - secretRef
  12511. type: object
  12512. cert:
  12513. description: |-
  12514. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12515. Cert authentication method
  12516. properties:
  12517. clientCert:
  12518. description: |-
  12519. ClientCert is a certificate to authenticate using the Cert Vault
  12520. authentication method
  12521. properties:
  12522. key:
  12523. description: |-
  12524. A key in the referenced Secret.
  12525. Some instances of this field may be defaulted, in others it may be required.
  12526. maxLength: 253
  12527. minLength: 1
  12528. pattern: ^[-._a-zA-Z0-9]+$
  12529. type: string
  12530. name:
  12531. description: The name of the Secret resource being referred to.
  12532. maxLength: 253
  12533. minLength: 1
  12534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12535. type: string
  12536. namespace:
  12537. description: |-
  12538. The namespace of the Secret resource being referred to.
  12539. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12540. maxLength: 63
  12541. minLength: 1
  12542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12543. type: string
  12544. type: object
  12545. secretRef:
  12546. description: |-
  12547. SecretRef to a key in a Secret resource containing client private key to
  12548. authenticate with Vault using the Cert authentication method
  12549. properties:
  12550. key:
  12551. description: |-
  12552. A key in the referenced Secret.
  12553. Some instances of this field may be defaulted, in others it may be required.
  12554. maxLength: 253
  12555. minLength: 1
  12556. pattern: ^[-._a-zA-Z0-9]+$
  12557. type: string
  12558. name:
  12559. description: The name of the Secret resource being referred to.
  12560. maxLength: 253
  12561. minLength: 1
  12562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12563. type: string
  12564. namespace:
  12565. description: |-
  12566. The namespace of the Secret resource being referred to.
  12567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12568. maxLength: 63
  12569. minLength: 1
  12570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12571. type: string
  12572. type: object
  12573. type: object
  12574. iam:
  12575. description: |-
  12576. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12577. AWS IAM authentication method
  12578. properties:
  12579. externalID:
  12580. description: AWS External ID set on assumed IAM roles
  12581. type: string
  12582. jwt:
  12583. description: Specify a service account with IRSA enabled
  12584. properties:
  12585. serviceAccountRef:
  12586. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12587. properties:
  12588. audiences:
  12589. description: |-
  12590. Audience specifies the `aud` claim for the service account token
  12591. Some providers automatically extend the audience field based on well-known annotations for workload
  12592. identity (e.g. IRSA or GCP Workload Identity)
  12593. items:
  12594. type: string
  12595. type: array
  12596. name:
  12597. description: The name of the ServiceAccount resource being referred to.
  12598. maxLength: 253
  12599. minLength: 1
  12600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12601. type: string
  12602. namespace:
  12603. description: |-
  12604. Namespace of the resource being referred to.
  12605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12606. maxLength: 63
  12607. minLength: 1
  12608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12609. type: string
  12610. required:
  12611. - name
  12612. type: object
  12613. type: object
  12614. path:
  12615. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12616. type: string
  12617. region:
  12618. description: AWS region
  12619. type: string
  12620. role:
  12621. description: This is the AWS role to be assumed before talking to vault
  12622. type: string
  12623. secretRef:
  12624. description: Specify credentials in a Secret object
  12625. properties:
  12626. accessKeyIDSecretRef:
  12627. description: The AccessKeyID is used for authentication
  12628. properties:
  12629. key:
  12630. description: |-
  12631. A key in the referenced Secret.
  12632. Some instances of this field may be defaulted, in others it may be required.
  12633. maxLength: 253
  12634. minLength: 1
  12635. pattern: ^[-._a-zA-Z0-9]+$
  12636. type: string
  12637. name:
  12638. description: The name of the Secret resource being referred to.
  12639. maxLength: 253
  12640. minLength: 1
  12641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12642. type: string
  12643. namespace:
  12644. description: |-
  12645. The namespace of the Secret resource being referred to.
  12646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12647. maxLength: 63
  12648. minLength: 1
  12649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12650. type: string
  12651. type: object
  12652. secretAccessKeySecretRef:
  12653. description: The SecretAccessKey is used for authentication
  12654. properties:
  12655. key:
  12656. description: |-
  12657. A key in the referenced Secret.
  12658. Some instances of this field may be defaulted, in others it may be required.
  12659. maxLength: 253
  12660. minLength: 1
  12661. pattern: ^[-._a-zA-Z0-9]+$
  12662. type: string
  12663. name:
  12664. description: The name of the Secret resource being referred to.
  12665. maxLength: 253
  12666. minLength: 1
  12667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12668. type: string
  12669. namespace:
  12670. description: |-
  12671. The namespace of the Secret resource being referred to.
  12672. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12673. maxLength: 63
  12674. minLength: 1
  12675. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12676. type: string
  12677. type: object
  12678. sessionTokenSecretRef:
  12679. description: |-
  12680. The SessionToken used for authentication
  12681. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12682. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12683. properties:
  12684. key:
  12685. description: |-
  12686. A key in the referenced Secret.
  12687. Some instances of this field may be defaulted, in others it may be required.
  12688. maxLength: 253
  12689. minLength: 1
  12690. pattern: ^[-._a-zA-Z0-9]+$
  12691. type: string
  12692. name:
  12693. description: The name of the Secret resource being referred to.
  12694. maxLength: 253
  12695. minLength: 1
  12696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12697. type: string
  12698. namespace:
  12699. description: |-
  12700. The namespace of the Secret resource being referred to.
  12701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12702. maxLength: 63
  12703. minLength: 1
  12704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12705. type: string
  12706. type: object
  12707. type: object
  12708. vaultAwsIamServerID:
  12709. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12710. type: string
  12711. vaultRole:
  12712. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12713. type: string
  12714. required:
  12715. - vaultRole
  12716. type: object
  12717. jwt:
  12718. description: |-
  12719. Jwt authenticates with Vault by passing role and JWT token using the
  12720. JWT/OIDC authentication method
  12721. properties:
  12722. kubernetesServiceAccountToken:
  12723. description: |-
  12724. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12725. a token for with the `TokenRequest` API.
  12726. properties:
  12727. audiences:
  12728. description: |-
  12729. Optional audiences field that will be used to request a temporary Kubernetes service
  12730. account token for the service account referenced by `serviceAccountRef`.
  12731. Defaults to a single audience `vault` it not specified.
  12732. Deprecated: use serviceAccountRef.Audiences instead
  12733. items:
  12734. type: string
  12735. type: array
  12736. expirationSeconds:
  12737. description: |-
  12738. Optional expiration time in seconds that will be used to request a temporary
  12739. Kubernetes service account token for the service account referenced by
  12740. `serviceAccountRef`.
  12741. Deprecated: this will be removed in the future.
  12742. Defaults to 10 minutes.
  12743. format: int64
  12744. type: integer
  12745. serviceAccountRef:
  12746. description: Service account field containing the name of a kubernetes ServiceAccount.
  12747. properties:
  12748. audiences:
  12749. description: |-
  12750. Audience specifies the `aud` claim for the service account token
  12751. Some providers automatically extend the audience field based on well-known annotations for workload
  12752. identity (e.g. IRSA or GCP Workload Identity)
  12753. items:
  12754. type: string
  12755. type: array
  12756. name:
  12757. description: The name of the ServiceAccount resource being referred to.
  12758. maxLength: 253
  12759. minLength: 1
  12760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12761. type: string
  12762. namespace:
  12763. description: |-
  12764. Namespace of the resource being referred to.
  12765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12766. maxLength: 63
  12767. minLength: 1
  12768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12769. type: string
  12770. required:
  12771. - name
  12772. type: object
  12773. required:
  12774. - serviceAccountRef
  12775. type: object
  12776. path:
  12777. default: jwt
  12778. description: |-
  12779. Path where the JWT authentication backend is mounted
  12780. in Vault, e.g: "jwt"
  12781. type: string
  12782. role:
  12783. description: |-
  12784. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12785. authentication method
  12786. type: string
  12787. secretRef:
  12788. description: |-
  12789. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12790. authenticate with Vault using the JWT/OIDC authentication method.
  12791. properties:
  12792. key:
  12793. description: |-
  12794. A key in the referenced Secret.
  12795. Some instances of this field may be defaulted, in others it may be required.
  12796. maxLength: 253
  12797. minLength: 1
  12798. pattern: ^[-._a-zA-Z0-9]+$
  12799. type: string
  12800. name:
  12801. description: The name of the Secret resource being referred to.
  12802. maxLength: 253
  12803. minLength: 1
  12804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12805. type: string
  12806. namespace:
  12807. description: |-
  12808. The namespace of the Secret resource being referred to.
  12809. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12810. maxLength: 63
  12811. minLength: 1
  12812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12813. type: string
  12814. type: object
  12815. required:
  12816. - path
  12817. type: object
  12818. kubernetes:
  12819. description: |-
  12820. Kubernetes authenticates with Vault by passing the ServiceAccount
  12821. token stored in the named Secret resource to the Vault server.
  12822. properties:
  12823. mountPath:
  12824. default: kubernetes
  12825. description: |-
  12826. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12827. "kubernetes"
  12828. type: string
  12829. role:
  12830. description: |-
  12831. A required field containing the Vault Role to assume. A Role binds a
  12832. Kubernetes ServiceAccount with a set of Vault policies.
  12833. type: string
  12834. secretRef:
  12835. description: |-
  12836. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12837. for authenticating with Vault. If a name is specified without a key,
  12838. `token` is the default. If one is not specified, the one bound to
  12839. the controller will be used.
  12840. properties:
  12841. key:
  12842. description: |-
  12843. A key in the referenced Secret.
  12844. Some instances of this field may be defaulted, in others it may be required.
  12845. maxLength: 253
  12846. minLength: 1
  12847. pattern: ^[-._a-zA-Z0-9]+$
  12848. type: string
  12849. name:
  12850. description: The name of the Secret resource being referred to.
  12851. maxLength: 253
  12852. minLength: 1
  12853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12854. type: string
  12855. namespace:
  12856. description: |-
  12857. The namespace of the Secret resource being referred to.
  12858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12859. maxLength: 63
  12860. minLength: 1
  12861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12862. type: string
  12863. type: object
  12864. serviceAccountRef:
  12865. description: |-
  12866. Optional service account field containing the name of a kubernetes ServiceAccount.
  12867. If the service account is specified, the service account secret token JWT will be used
  12868. for authenticating with Vault. If the service account selector is not supplied,
  12869. the secretRef will be used instead.
  12870. properties:
  12871. audiences:
  12872. description: |-
  12873. Audience specifies the `aud` claim for the service account token
  12874. Some providers automatically extend the audience field based on well-known annotations for workload
  12875. identity (e.g. IRSA or GCP Workload Identity)
  12876. items:
  12877. type: string
  12878. type: array
  12879. name:
  12880. description: The name of the ServiceAccount resource being referred to.
  12881. maxLength: 253
  12882. minLength: 1
  12883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12884. type: string
  12885. namespace:
  12886. description: |-
  12887. Namespace of the resource being referred to.
  12888. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12889. maxLength: 63
  12890. minLength: 1
  12891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12892. type: string
  12893. required:
  12894. - name
  12895. type: object
  12896. required:
  12897. - mountPath
  12898. - role
  12899. type: object
  12900. ldap:
  12901. description: |-
  12902. Ldap authenticates with Vault by passing username/password pair using
  12903. the LDAP authentication method
  12904. properties:
  12905. path:
  12906. default: ldap
  12907. description: |-
  12908. Path where the LDAP authentication backend is mounted
  12909. in Vault, e.g: "ldap"
  12910. type: string
  12911. secretRef:
  12912. description: |-
  12913. SecretRef to a key in a Secret resource containing password for the LDAP
  12914. user used to authenticate with Vault using the LDAP authentication
  12915. method
  12916. properties:
  12917. key:
  12918. description: |-
  12919. A key in the referenced Secret.
  12920. Some instances of this field may be defaulted, in others it may be required.
  12921. maxLength: 253
  12922. minLength: 1
  12923. pattern: ^[-._a-zA-Z0-9]+$
  12924. type: string
  12925. name:
  12926. description: The name of the Secret resource being referred to.
  12927. maxLength: 253
  12928. minLength: 1
  12929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12930. type: string
  12931. namespace:
  12932. description: |-
  12933. The namespace of the Secret resource being referred to.
  12934. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12935. maxLength: 63
  12936. minLength: 1
  12937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12938. type: string
  12939. type: object
  12940. username:
  12941. description: |-
  12942. Username is an LDAP username used to authenticate using the LDAP Vault
  12943. authentication method
  12944. type: string
  12945. required:
  12946. - path
  12947. - username
  12948. type: object
  12949. namespace:
  12950. description: |-
  12951. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12952. Namespaces is a set of features within Vault Enterprise that allows
  12953. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12954. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12955. This will default to Vault.Namespace field if set, or empty otherwise
  12956. type: string
  12957. tokenSecretRef:
  12958. description: TokenSecretRef authenticates with Vault by presenting a token.
  12959. properties:
  12960. key:
  12961. description: |-
  12962. A key in the referenced Secret.
  12963. Some instances of this field may be defaulted, in others it may be required.
  12964. maxLength: 253
  12965. minLength: 1
  12966. pattern: ^[-._a-zA-Z0-9]+$
  12967. type: string
  12968. name:
  12969. description: The name of the Secret resource being referred to.
  12970. maxLength: 253
  12971. minLength: 1
  12972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12973. type: string
  12974. namespace:
  12975. description: |-
  12976. The namespace of the Secret resource being referred to.
  12977. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12978. maxLength: 63
  12979. minLength: 1
  12980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12981. type: string
  12982. type: object
  12983. userPass:
  12984. description: UserPass authenticates with Vault by passing username/password pair
  12985. properties:
  12986. path:
  12987. default: userpass
  12988. description: |-
  12989. Path where the UserPassword authentication backend is mounted
  12990. in Vault, e.g: "userpass"
  12991. type: string
  12992. secretRef:
  12993. description: |-
  12994. SecretRef to a key in a Secret resource containing password for the
  12995. user used to authenticate with Vault using the UserPass authentication
  12996. method
  12997. properties:
  12998. key:
  12999. description: |-
  13000. A key in the referenced Secret.
  13001. Some instances of this field may be defaulted, in others it may be required.
  13002. maxLength: 253
  13003. minLength: 1
  13004. pattern: ^[-._a-zA-Z0-9]+$
  13005. type: string
  13006. name:
  13007. description: The name of the Secret resource being referred to.
  13008. maxLength: 253
  13009. minLength: 1
  13010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13011. type: string
  13012. namespace:
  13013. description: |-
  13014. The namespace of the Secret resource being referred to.
  13015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13016. maxLength: 63
  13017. minLength: 1
  13018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13019. type: string
  13020. type: object
  13021. username:
  13022. description: |-
  13023. Username is a username used to authenticate using the UserPass Vault
  13024. authentication method
  13025. type: string
  13026. required:
  13027. - path
  13028. - username
  13029. type: object
  13030. type: object
  13031. caBundle:
  13032. description: |-
  13033. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13034. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13035. plain HTTP protocol connection. If not set the system root certificates
  13036. are used to validate the TLS connection.
  13037. format: byte
  13038. type: string
  13039. caProvider:
  13040. description: The provider for the CA bundle to use to validate Vault server certificate.
  13041. properties:
  13042. key:
  13043. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13044. maxLength: 253
  13045. minLength: 1
  13046. pattern: ^[-._a-zA-Z0-9]+$
  13047. type: string
  13048. name:
  13049. description: The name of the object located at the provider type.
  13050. maxLength: 253
  13051. minLength: 1
  13052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13053. type: string
  13054. namespace:
  13055. description: |-
  13056. The namespace the Provider type is in.
  13057. Can only be defined when used in a ClusterSecretStore.
  13058. maxLength: 63
  13059. minLength: 1
  13060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13061. type: string
  13062. type:
  13063. description: The type of provider to use such as "Secret", or "ConfigMap".
  13064. enum:
  13065. - Secret
  13066. - ConfigMap
  13067. type: string
  13068. required:
  13069. - name
  13070. - type
  13071. type: object
  13072. forwardInconsistent:
  13073. description: |-
  13074. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13075. leader instead of simply retrying within a loop. This can increase performance if
  13076. the option is enabled serverside.
  13077. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13078. type: boolean
  13079. headers:
  13080. additionalProperties:
  13081. type: string
  13082. description: Headers to be added in Vault request
  13083. type: object
  13084. namespace:
  13085. description: |-
  13086. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13087. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13088. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13089. type: string
  13090. path:
  13091. description: |-
  13092. Path is the mount path of the Vault KV backend endpoint, e.g:
  13093. "secret". The v2 KV secret engine version specific "/data" path suffix
  13094. for fetching secrets from Vault is optional and will be appended
  13095. if not present in specified path.
  13096. type: string
  13097. readYourWrites:
  13098. description: |-
  13099. ReadYourWrites ensures isolated read-after-write semantics by
  13100. providing discovered cluster replication states in each request.
  13101. More information about eventual consistency in Vault can be found here
  13102. https://www.vaultproject.io/docs/enterprise/consistency
  13103. type: boolean
  13104. server:
  13105. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13106. type: string
  13107. tls:
  13108. description: |-
  13109. The configuration used for client side related TLS communication, when the Vault server
  13110. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13111. This parameter is ignored for plain HTTP protocol connection.
  13112. It's worth noting this configuration is different from the "TLS certificates auth method",
  13113. which is available under the `auth.cert` section.
  13114. properties:
  13115. certSecretRef:
  13116. description: |-
  13117. CertSecretRef is a certificate added to the transport layer
  13118. when communicating with the Vault server.
  13119. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13120. properties:
  13121. key:
  13122. description: |-
  13123. A key in the referenced Secret.
  13124. Some instances of this field may be defaulted, in others it may be required.
  13125. maxLength: 253
  13126. minLength: 1
  13127. pattern: ^[-._a-zA-Z0-9]+$
  13128. type: string
  13129. name:
  13130. description: The name of the Secret resource being referred to.
  13131. maxLength: 253
  13132. minLength: 1
  13133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13134. type: string
  13135. namespace:
  13136. description: |-
  13137. The namespace of the Secret resource being referred to.
  13138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13139. maxLength: 63
  13140. minLength: 1
  13141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13142. type: string
  13143. type: object
  13144. keySecretRef:
  13145. description: |-
  13146. KeySecretRef to a key in a Secret resource containing client private key
  13147. added to the transport layer when communicating with the Vault server.
  13148. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13149. properties:
  13150. key:
  13151. description: |-
  13152. A key in the referenced Secret.
  13153. Some instances of this field may be defaulted, in others it may be required.
  13154. maxLength: 253
  13155. minLength: 1
  13156. pattern: ^[-._a-zA-Z0-9]+$
  13157. type: string
  13158. name:
  13159. description: The name of the Secret resource being referred to.
  13160. maxLength: 253
  13161. minLength: 1
  13162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13163. type: string
  13164. namespace:
  13165. description: |-
  13166. The namespace of the Secret resource being referred to.
  13167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13168. maxLength: 63
  13169. minLength: 1
  13170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13171. type: string
  13172. type: object
  13173. type: object
  13174. version:
  13175. default: v2
  13176. description: |-
  13177. Version is the Vault KV secret engine version. This can be either "v1" or
  13178. "v2". Version defaults to "v2".
  13179. enum:
  13180. - v1
  13181. - v2
  13182. type: string
  13183. required:
  13184. - server
  13185. type: object
  13186. webhook:
  13187. description: Webhook configures this store to sync secrets using a generic templated webhook
  13188. properties:
  13189. auth:
  13190. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13191. maxProperties: 1
  13192. minProperties: 1
  13193. properties:
  13194. ntlm:
  13195. description: NTLMProtocol configures the store to use NTLM for auth
  13196. properties:
  13197. passwordSecret:
  13198. description: |-
  13199. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13200. In some instances, `key` is a required field.
  13201. properties:
  13202. key:
  13203. description: |-
  13204. A key in the referenced Secret.
  13205. Some instances of this field may be defaulted, in others it may be required.
  13206. maxLength: 253
  13207. minLength: 1
  13208. pattern: ^[-._a-zA-Z0-9]+$
  13209. type: string
  13210. name:
  13211. description: The name of the Secret resource being referred to.
  13212. maxLength: 253
  13213. minLength: 1
  13214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13215. type: string
  13216. namespace:
  13217. description: |-
  13218. The namespace of the Secret resource being referred to.
  13219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13220. maxLength: 63
  13221. minLength: 1
  13222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13223. type: string
  13224. type: object
  13225. usernameSecret:
  13226. description: |-
  13227. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13228. In some instances, `key` is a required field.
  13229. properties:
  13230. key:
  13231. description: |-
  13232. A key in the referenced Secret.
  13233. Some instances of this field may be defaulted, in others it may be required.
  13234. maxLength: 253
  13235. minLength: 1
  13236. pattern: ^[-._a-zA-Z0-9]+$
  13237. type: string
  13238. name:
  13239. description: The name of the Secret resource being referred to.
  13240. maxLength: 253
  13241. minLength: 1
  13242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13243. type: string
  13244. namespace:
  13245. description: |-
  13246. The namespace of the Secret resource being referred to.
  13247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13248. maxLength: 63
  13249. minLength: 1
  13250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13251. type: string
  13252. type: object
  13253. required:
  13254. - passwordSecret
  13255. - usernameSecret
  13256. type: object
  13257. type: object
  13258. body:
  13259. description: Body
  13260. type: string
  13261. caBundle:
  13262. description: |-
  13263. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13264. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13265. plain HTTP protocol connection. If not set the system root certificates
  13266. are used to validate the TLS connection.
  13267. format: byte
  13268. type: string
  13269. caProvider:
  13270. description: The provider for the CA bundle to use to validate webhook server certificate.
  13271. properties:
  13272. key:
  13273. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13274. maxLength: 253
  13275. minLength: 1
  13276. pattern: ^[-._a-zA-Z0-9]+$
  13277. type: string
  13278. name:
  13279. description: The name of the object located at the provider type.
  13280. maxLength: 253
  13281. minLength: 1
  13282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13283. type: string
  13284. namespace:
  13285. description: The namespace the Provider type is in.
  13286. maxLength: 63
  13287. minLength: 1
  13288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13289. type: string
  13290. type:
  13291. description: The type of provider to use such as "Secret", or "ConfigMap".
  13292. enum:
  13293. - Secret
  13294. - ConfigMap
  13295. type: string
  13296. required:
  13297. - name
  13298. - type
  13299. type: object
  13300. headers:
  13301. additionalProperties:
  13302. type: string
  13303. description: Headers
  13304. type: object
  13305. method:
  13306. description: Webhook Method
  13307. type: string
  13308. result:
  13309. description: Result formatting
  13310. properties:
  13311. jsonPath:
  13312. description: Json path of return value
  13313. type: string
  13314. type: object
  13315. secrets:
  13316. description: |-
  13317. Secrets to fill in templates
  13318. These secrets will be passed to the templating function as key value pairs under the given name
  13319. items:
  13320. description: WebhookSecret defines a secret to be used in webhook templates.
  13321. properties:
  13322. name:
  13323. description: Name of this secret in templates
  13324. type: string
  13325. secretRef:
  13326. description: Secret ref to fill in credentials
  13327. properties:
  13328. key:
  13329. description: |-
  13330. A key in the referenced Secret.
  13331. Some instances of this field may be defaulted, in others it may be required.
  13332. maxLength: 253
  13333. minLength: 1
  13334. pattern: ^[-._a-zA-Z0-9]+$
  13335. type: string
  13336. name:
  13337. description: The name of the Secret resource being referred to.
  13338. maxLength: 253
  13339. minLength: 1
  13340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13341. type: string
  13342. namespace:
  13343. description: |-
  13344. The namespace of the Secret resource being referred to.
  13345. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13346. maxLength: 63
  13347. minLength: 1
  13348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13349. type: string
  13350. type: object
  13351. required:
  13352. - name
  13353. - secretRef
  13354. type: object
  13355. type: array
  13356. timeout:
  13357. description: Timeout
  13358. type: string
  13359. url:
  13360. description: Webhook url to call
  13361. type: string
  13362. required:
  13363. - result
  13364. - url
  13365. type: object
  13366. yandexcertificatemanager:
  13367. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13368. properties:
  13369. apiEndpoint:
  13370. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13371. type: string
  13372. auth:
  13373. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13374. properties:
  13375. authorizedKeySecretRef:
  13376. description: The authorized key used for authentication
  13377. properties:
  13378. key:
  13379. description: |-
  13380. A key in the referenced Secret.
  13381. Some instances of this field may be defaulted, in others it may be required.
  13382. maxLength: 253
  13383. minLength: 1
  13384. pattern: ^[-._a-zA-Z0-9]+$
  13385. type: string
  13386. name:
  13387. description: The name of the Secret resource being referred to.
  13388. maxLength: 253
  13389. minLength: 1
  13390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13391. type: string
  13392. namespace:
  13393. description: |-
  13394. The namespace of the Secret resource being referred to.
  13395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13396. maxLength: 63
  13397. minLength: 1
  13398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13399. type: string
  13400. type: object
  13401. type: object
  13402. caProvider:
  13403. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13404. properties:
  13405. certSecretRef:
  13406. description: |-
  13407. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13408. In some instances, `key` is a required field.
  13409. properties:
  13410. key:
  13411. description: |-
  13412. A key in the referenced Secret.
  13413. Some instances of this field may be defaulted, in others it may be required.
  13414. maxLength: 253
  13415. minLength: 1
  13416. pattern: ^[-._a-zA-Z0-9]+$
  13417. type: string
  13418. name:
  13419. description: The name of the Secret resource being referred to.
  13420. maxLength: 253
  13421. minLength: 1
  13422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13423. type: string
  13424. namespace:
  13425. description: |-
  13426. The namespace of the Secret resource being referred to.
  13427. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13428. maxLength: 63
  13429. minLength: 1
  13430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13431. type: string
  13432. type: object
  13433. type: object
  13434. required:
  13435. - auth
  13436. type: object
  13437. yandexlockbox:
  13438. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13439. properties:
  13440. apiEndpoint:
  13441. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13442. type: string
  13443. auth:
  13444. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13445. properties:
  13446. authorizedKeySecretRef:
  13447. description: The authorized key used for authentication
  13448. properties:
  13449. key:
  13450. description: |-
  13451. A key in the referenced Secret.
  13452. Some instances of this field may be defaulted, in others it may be required.
  13453. maxLength: 253
  13454. minLength: 1
  13455. pattern: ^[-._a-zA-Z0-9]+$
  13456. type: string
  13457. name:
  13458. description: The name of the Secret resource being referred to.
  13459. maxLength: 253
  13460. minLength: 1
  13461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13462. type: string
  13463. namespace:
  13464. description: |-
  13465. The namespace of the Secret resource being referred to.
  13466. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13467. maxLength: 63
  13468. minLength: 1
  13469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13470. type: string
  13471. type: object
  13472. type: object
  13473. caProvider:
  13474. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13475. properties:
  13476. certSecretRef:
  13477. description: |-
  13478. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13479. In some instances, `key` is a required field.
  13480. properties:
  13481. key:
  13482. description: |-
  13483. A key in the referenced Secret.
  13484. Some instances of this field may be defaulted, in others it may be required.
  13485. maxLength: 253
  13486. minLength: 1
  13487. pattern: ^[-._a-zA-Z0-9]+$
  13488. type: string
  13489. name:
  13490. description: The name of the Secret resource being referred to.
  13491. maxLength: 253
  13492. minLength: 1
  13493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13494. type: string
  13495. namespace:
  13496. description: |-
  13497. The namespace of the Secret resource being referred to.
  13498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13499. maxLength: 63
  13500. minLength: 1
  13501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13502. type: string
  13503. type: object
  13504. type: object
  13505. required:
  13506. - auth
  13507. type: object
  13508. type: object
  13509. refreshInterval:
  13510. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13511. type: integer
  13512. retrySettings:
  13513. description: Used to configure HTTP retries on failures.
  13514. properties:
  13515. maxRetries:
  13516. description: MaxRetries is the maximum number of retry attempts.
  13517. format: int32
  13518. type: integer
  13519. retryInterval:
  13520. description: RetryInterval is the interval between retry attempts.
  13521. type: string
  13522. type: object
  13523. required:
  13524. - provider
  13525. type: object
  13526. status:
  13527. description: SecretStoreStatus defines the observed state of the SecretStore.
  13528. properties:
  13529. capabilities:
  13530. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13531. type: string
  13532. conditions:
  13533. items:
  13534. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13535. properties:
  13536. lastTransitionTime:
  13537. format: date-time
  13538. type: string
  13539. message:
  13540. type: string
  13541. reason:
  13542. type: string
  13543. status:
  13544. type: string
  13545. type:
  13546. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13547. type: string
  13548. required:
  13549. - status
  13550. - type
  13551. type: object
  13552. type: array
  13553. type: object
  13554. type: object
  13555. served: false
  13556. storage: false
  13557. subresources:
  13558. status: {}
  13559. ---
  13560. apiVersion: apiextensions.k8s.io/v1
  13561. kind: CustomResourceDefinition
  13562. metadata:
  13563. annotations:
  13564. controller-gen.kubebuilder.io/version: v0.19.0
  13565. labels:
  13566. external-secrets.io/component: controller
  13567. name: externalsecrets.external-secrets.io
  13568. spec:
  13569. group: external-secrets.io
  13570. names:
  13571. categories:
  13572. - external-secrets
  13573. kind: ExternalSecret
  13574. listKind: ExternalSecretList
  13575. plural: externalsecrets
  13576. shortNames:
  13577. - es
  13578. singular: externalsecret
  13579. scope: Namespaced
  13580. versions:
  13581. - additionalPrinterColumns:
  13582. - jsonPath: .spec.secretStoreRef.kind
  13583. name: StoreType
  13584. type: string
  13585. - jsonPath: .spec.secretStoreRef.name
  13586. name: Store
  13587. type: string
  13588. - jsonPath: .spec.refreshInterval
  13589. name: Refresh Interval
  13590. type: string
  13591. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13592. name: Status
  13593. type: string
  13594. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13595. name: Ready
  13596. type: string
  13597. - jsonPath: .status.refreshTime
  13598. name: Last Sync
  13599. type: date
  13600. name: v1
  13601. schema:
  13602. openAPIV3Schema:
  13603. description: |-
  13604. ExternalSecret is the Schema for the external-secrets API.
  13605. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13606. properties:
  13607. apiVersion:
  13608. description: |-
  13609. APIVersion defines the versioned schema of this representation of an object.
  13610. Servers should convert recognized schemas to the latest internal value, and
  13611. may reject unrecognized values.
  13612. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13613. type: string
  13614. kind:
  13615. description: |-
  13616. Kind is a string value representing the REST resource this object represents.
  13617. Servers may infer this from the endpoint the client submits requests to.
  13618. Cannot be updated.
  13619. In CamelCase.
  13620. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13621. type: string
  13622. metadata:
  13623. type: object
  13624. spec:
  13625. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13626. properties:
  13627. data:
  13628. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13629. items:
  13630. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13631. properties:
  13632. remoteRef:
  13633. description: |-
  13634. RemoteRef points to the remote secret and defines
  13635. which secret (version/property/..) to fetch.
  13636. properties:
  13637. conversionStrategy:
  13638. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13639. enum:
  13640. - Default
  13641. - Unicode
  13642. type: string
  13643. decodingStrategy:
  13644. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13645. enum:
  13646. - Auto
  13647. - Base64
  13648. - Base64URL
  13649. - None
  13650. type: string
  13651. key:
  13652. description: Key is the key used in the Provider, mandatory
  13653. type: string
  13654. metadataPolicy:
  13655. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13656. enum:
  13657. - None
  13658. - Fetch
  13659. type: string
  13660. nullBytePolicy:
  13661. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13662. enum:
  13663. - Ignore
  13664. - Fail
  13665. type: string
  13666. property:
  13667. description: Used to select a specific property of the Provider value (if a map), if supported
  13668. type: string
  13669. version:
  13670. description: Used to select a specific version of the Provider value, if supported
  13671. type: string
  13672. required:
  13673. - key
  13674. type: object
  13675. secretKey:
  13676. description: The key in the Kubernetes Secret to store the value.
  13677. maxLength: 253
  13678. minLength: 1
  13679. pattern: ^[-._a-zA-Z0-9]+$
  13680. type: string
  13681. sourceRef:
  13682. description: |-
  13683. SourceRef allows you to override the source
  13684. from which the value will be pulled.
  13685. maxProperties: 1
  13686. minProperties: 1
  13687. properties:
  13688. generatorRef:
  13689. description: |-
  13690. GeneratorRef points to a generator custom resource.
  13691. Deprecated: The generatorRef is not implemented in .data[].
  13692. this will be removed with v1.
  13693. properties:
  13694. apiVersion:
  13695. default: generators.external-secrets.io/v1alpha1
  13696. description: Specify the apiVersion of the generator resource
  13697. type: string
  13698. kind:
  13699. description: Specify the Kind of the generator resource
  13700. enum:
  13701. - ACRAccessToken
  13702. - BeyondtrustWorkloadCredentialsDynamicSecret
  13703. - ClusterGenerator
  13704. - CloudsmithAccessToken
  13705. - ECRAuthorizationToken
  13706. - Fake
  13707. - GCRAccessToken
  13708. - GithubAccessToken
  13709. - GitlabDeployToken
  13710. - QuayAccessToken
  13711. - Password
  13712. - SSHKey
  13713. - STSSessionToken
  13714. - UUID
  13715. - VaultDynamicSecret
  13716. - Webhook
  13717. - Grafana
  13718. - MFA
  13719. type: string
  13720. name:
  13721. description: Specify the name of the generator resource
  13722. maxLength: 253
  13723. minLength: 1
  13724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13725. type: string
  13726. required:
  13727. - kind
  13728. - name
  13729. type: object
  13730. storeRef:
  13731. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13732. properties:
  13733. kind:
  13734. description: |-
  13735. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13736. Defaults to `SecretStore`
  13737. enum:
  13738. - SecretStore
  13739. - ClusterSecretStore
  13740. type: string
  13741. name:
  13742. description: Name of the SecretStore resource
  13743. maxLength: 253
  13744. minLength: 1
  13745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13746. type: string
  13747. type: object
  13748. type: object
  13749. required:
  13750. - remoteRef
  13751. - secretKey
  13752. type: object
  13753. type: array
  13754. dataFrom:
  13755. description: |-
  13756. DataFrom is used to fetch all properties from a specific Provider data
  13757. If multiple entries are specified, the Secret keys are merged in the specified order
  13758. items:
  13759. description: |-
  13760. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13761. when using DataFrom to fetch multiple values from a Provider.
  13762. properties:
  13763. extract:
  13764. description: |-
  13765. Used to extract multiple key/value pairs from one secret
  13766. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13767. properties:
  13768. conversionStrategy:
  13769. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13770. enum:
  13771. - Default
  13772. - Unicode
  13773. type: string
  13774. decodingStrategy:
  13775. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13776. enum:
  13777. - Auto
  13778. - Base64
  13779. - Base64URL
  13780. - None
  13781. type: string
  13782. key:
  13783. description: Key is the key used in the Provider, mandatory
  13784. type: string
  13785. metadataPolicy:
  13786. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13787. enum:
  13788. - None
  13789. - Fetch
  13790. type: string
  13791. nullBytePolicy:
  13792. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13793. enum:
  13794. - Ignore
  13795. - Fail
  13796. type: string
  13797. property:
  13798. description: Used to select a specific property of the Provider value (if a map), if supported
  13799. type: string
  13800. version:
  13801. description: Used to select a specific version of the Provider value, if supported
  13802. type: string
  13803. required:
  13804. - key
  13805. type: object
  13806. find:
  13807. description: |-
  13808. Used to find secrets based on tags or regular expressions
  13809. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13810. properties:
  13811. conversionStrategy:
  13812. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13813. enum:
  13814. - Default
  13815. - Unicode
  13816. type: string
  13817. decodingStrategy:
  13818. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13819. enum:
  13820. - Auto
  13821. - Base64
  13822. - Base64URL
  13823. - None
  13824. type: string
  13825. name:
  13826. description: Finds secrets based on the name.
  13827. properties:
  13828. regexp:
  13829. description: Finds secrets base
  13830. type: string
  13831. type: object
  13832. nullBytePolicy:
  13833. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13834. enum:
  13835. - Ignore
  13836. - Fail
  13837. type: string
  13838. path:
  13839. description: A root path to start the find operations.
  13840. type: string
  13841. tags:
  13842. additionalProperties:
  13843. type: string
  13844. description: Find secrets based on tags.
  13845. type: object
  13846. type: object
  13847. rewrite:
  13848. description: |-
  13849. Used to rewrite secret Keys after getting them from the secret Provider
  13850. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13851. items:
  13852. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13853. maxProperties: 1
  13854. minProperties: 1
  13855. properties:
  13856. merge:
  13857. description: |-
  13858. Used to merge key/values in one single Secret
  13859. The resulting key will contain all values from the specified secrets
  13860. properties:
  13861. conflictPolicy:
  13862. default: Error
  13863. description: Used to define the policy to use in conflict resolution.
  13864. enum:
  13865. - Ignore
  13866. - Error
  13867. type: string
  13868. into:
  13869. default: ""
  13870. description: |-
  13871. Used to define the target key of the merge operation.
  13872. Required if strategy is JSON. Ignored otherwise.
  13873. type: string
  13874. priority:
  13875. description: Used to define key priority in conflict resolution.
  13876. items:
  13877. type: string
  13878. type: array
  13879. priorityPolicy:
  13880. default: Strict
  13881. description: Used to define the policy when a key in the priority list does not exist in the input.
  13882. enum:
  13883. - IgnoreNotFound
  13884. - Strict
  13885. type: string
  13886. strategy:
  13887. default: Extract
  13888. description: Used to define the strategy to use in the merge operation.
  13889. enum:
  13890. - Extract
  13891. - JSON
  13892. type: string
  13893. type: object
  13894. regexp:
  13895. description: |-
  13896. Used to rewrite with regular expressions.
  13897. The resulting key will be the output of a regexp.ReplaceAll operation.
  13898. properties:
  13899. source:
  13900. description: Used to define the regular expression of a re.Compiler.
  13901. type: string
  13902. target:
  13903. description: Used to define the target pattern of a ReplaceAll operation.
  13904. type: string
  13905. required:
  13906. - source
  13907. - target
  13908. type: object
  13909. transform:
  13910. description: |-
  13911. Used to apply string transformation on the secrets.
  13912. The resulting key will be the output of the template applied by the operation.
  13913. properties:
  13914. template:
  13915. description: |-
  13916. Used to define the template to apply on the secret name.
  13917. `.value ` will specify the secret name in the template.
  13918. type: string
  13919. required:
  13920. - template
  13921. type: object
  13922. type: object
  13923. type: array
  13924. sourceRef:
  13925. description: |-
  13926. SourceRef points to a store or generator
  13927. which contains secret values ready to use.
  13928. Use this in combination with Extract or Find pull values out of
  13929. a specific SecretStore.
  13930. When sourceRef points to a generator Extract or Find is not supported.
  13931. The generator returns a static map of values
  13932. maxProperties: 1
  13933. minProperties: 1
  13934. properties:
  13935. generatorRef:
  13936. description: GeneratorRef points to a generator custom resource.
  13937. properties:
  13938. apiVersion:
  13939. default: generators.external-secrets.io/v1alpha1
  13940. description: Specify the apiVersion of the generator resource
  13941. type: string
  13942. kind:
  13943. description: Specify the Kind of the generator resource
  13944. enum:
  13945. - ACRAccessToken
  13946. - BeyondtrustWorkloadCredentialsDynamicSecret
  13947. - ClusterGenerator
  13948. - CloudsmithAccessToken
  13949. - ECRAuthorizationToken
  13950. - Fake
  13951. - GCRAccessToken
  13952. - GithubAccessToken
  13953. - GitlabDeployToken
  13954. - QuayAccessToken
  13955. - Password
  13956. - SSHKey
  13957. - STSSessionToken
  13958. - UUID
  13959. - VaultDynamicSecret
  13960. - Webhook
  13961. - Grafana
  13962. - MFA
  13963. type: string
  13964. name:
  13965. description: Specify the name of the generator resource
  13966. maxLength: 253
  13967. minLength: 1
  13968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13969. type: string
  13970. required:
  13971. - kind
  13972. - name
  13973. type: object
  13974. storeRef:
  13975. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13976. properties:
  13977. kind:
  13978. description: |-
  13979. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13980. Defaults to `SecretStore`
  13981. enum:
  13982. - SecretStore
  13983. - ClusterSecretStore
  13984. type: string
  13985. name:
  13986. description: Name of the SecretStore resource
  13987. maxLength: 253
  13988. minLength: 1
  13989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13990. type: string
  13991. type: object
  13992. type: object
  13993. type: object
  13994. type: array
  13995. refreshInterval:
  13996. default: 1h0m0s
  13997. description: |-
  13998. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13999. specified as Golang Duration strings.
  14000. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14001. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14002. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14003. type: string
  14004. refreshPolicy:
  14005. description: |-
  14006. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14007. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14008. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14009. No periodic updates occur if refreshInterval is 0.
  14010. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14011. enum:
  14012. - CreatedOnce
  14013. - Periodic
  14014. - OnChange
  14015. type: string
  14016. secretStoreRef:
  14017. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14018. properties:
  14019. kind:
  14020. description: |-
  14021. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14022. Defaults to `SecretStore`
  14023. enum:
  14024. - SecretStore
  14025. - ClusterSecretStore
  14026. type: string
  14027. name:
  14028. description: Name of the SecretStore resource
  14029. maxLength: 253
  14030. minLength: 1
  14031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14032. type: string
  14033. type: object
  14034. syncWindows:
  14035. description: |-
  14036. SyncWindows optionally restricts when periodic refreshes may occur.
  14037. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  14038. properties:
  14039. kind:
  14040. description: |-
  14041. Kind applies to every window in the list.
  14042. "allow" -- syncs are permitted only while at least one window is active;
  14043. all other times are blocked.
  14044. "deny" -- syncs are blocked while any window is active;
  14045. all other times are permitted.
  14046. enum:
  14047. - allow
  14048. - deny
  14049. type: string
  14050. windows:
  14051. description: Windows is the list of schedule+duration pairs.
  14052. items:
  14053. description: |-
  14054. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  14055. within a SyncWindows block.
  14056. properties:
  14057. duration:
  14058. description: |-
  14059. Duration specifies how long the window stays open after each Schedule
  14060. firing. Example: "8h".
  14061. type: string
  14062. schedule:
  14063. description: |-
  14064. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  14065. named shorthand such as @daily or @every 1h. It marks the start time of
  14066. each window occurrence.
  14067. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  14068. minLength: 1
  14069. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  14070. type: string
  14071. required:
  14072. - duration
  14073. - schedule
  14074. type: object
  14075. minItems: 1
  14076. type: array
  14077. required:
  14078. - kind
  14079. - windows
  14080. type: object
  14081. target:
  14082. default:
  14083. creationPolicy: Owner
  14084. deletionPolicy: Retain
  14085. description: |-
  14086. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14087. there can be only one target per ExternalSecret.
  14088. properties:
  14089. creationPolicy:
  14090. default: Owner
  14091. description: |-
  14092. CreationPolicy defines rules on how to create the resulting Secret.
  14093. Defaults to "Owner"
  14094. enum:
  14095. - Owner
  14096. - Orphan
  14097. - Merge
  14098. - None
  14099. - CreateOrMerge
  14100. type: string
  14101. deletionPolicy:
  14102. default: Retain
  14103. description: |-
  14104. DeletionPolicy defines rules on how to delete the resulting Secret.
  14105. Defaults to "Retain"
  14106. enum:
  14107. - Delete
  14108. - Merge
  14109. - Retain
  14110. type: string
  14111. immutable:
  14112. description: Immutable defines if the final secret will be immutable
  14113. type: boolean
  14114. manifest:
  14115. description: |-
  14116. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14117. When specified, ExternalSecret will create the resource type defined here
  14118. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14119. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14120. properties:
  14121. apiVersion:
  14122. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14123. minLength: 1
  14124. type: string
  14125. kind:
  14126. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14127. minLength: 1
  14128. type: string
  14129. required:
  14130. - apiVersion
  14131. - kind
  14132. type: object
  14133. name:
  14134. description: |-
  14135. The name of the Secret resource to be managed.
  14136. Defaults to the .metadata.name of the ExternalSecret resource
  14137. maxLength: 253
  14138. minLength: 1
  14139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14140. type: string
  14141. template:
  14142. description: Template defines a blueprint for the created Secret resource.
  14143. properties:
  14144. data:
  14145. additionalProperties:
  14146. type: string
  14147. type: object
  14148. engineVersion:
  14149. default: v2
  14150. description: |-
  14151. EngineVersion specifies the template engine version
  14152. that should be used to compile/execute the
  14153. template specified in .data and .templateFrom[].
  14154. enum:
  14155. - v2
  14156. type: string
  14157. mergePolicy:
  14158. default: Replace
  14159. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14160. enum:
  14161. - Replace
  14162. - Merge
  14163. type: string
  14164. metadata:
  14165. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14166. properties:
  14167. annotations:
  14168. additionalProperties:
  14169. type: string
  14170. type: object
  14171. finalizers:
  14172. items:
  14173. type: string
  14174. type: array
  14175. labels:
  14176. additionalProperties:
  14177. type: string
  14178. type: object
  14179. type: object
  14180. templateFrom:
  14181. items:
  14182. description: |-
  14183. TemplateFrom specifies a source for templates.
  14184. Each item in the list can either reference a ConfigMap or a Secret resource.
  14185. properties:
  14186. configMap:
  14187. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14188. properties:
  14189. items:
  14190. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14191. items:
  14192. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14193. properties:
  14194. key:
  14195. description: A key in the ConfigMap/Secret
  14196. maxLength: 253
  14197. minLength: 1
  14198. pattern: ^[-._a-zA-Z0-9]+$
  14199. type: string
  14200. templateAs:
  14201. default: Values
  14202. description: TemplateScope specifies how the template keys should be interpreted.
  14203. enum:
  14204. - Values
  14205. - KeysAndValues
  14206. type: string
  14207. required:
  14208. - key
  14209. type: object
  14210. type: array
  14211. name:
  14212. description: The name of the ConfigMap/Secret resource
  14213. maxLength: 253
  14214. minLength: 1
  14215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14216. type: string
  14217. required:
  14218. - items
  14219. - name
  14220. type: object
  14221. literal:
  14222. type: string
  14223. secret:
  14224. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14225. properties:
  14226. items:
  14227. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14228. items:
  14229. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14230. properties:
  14231. key:
  14232. description: A key in the ConfigMap/Secret
  14233. maxLength: 253
  14234. minLength: 1
  14235. pattern: ^[-._a-zA-Z0-9]+$
  14236. type: string
  14237. templateAs:
  14238. default: Values
  14239. description: TemplateScope specifies how the template keys should be interpreted.
  14240. enum:
  14241. - Values
  14242. - KeysAndValues
  14243. type: string
  14244. required:
  14245. - key
  14246. type: object
  14247. type: array
  14248. name:
  14249. description: The name of the ConfigMap/Secret resource
  14250. maxLength: 253
  14251. minLength: 1
  14252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14253. type: string
  14254. required:
  14255. - items
  14256. - name
  14257. type: object
  14258. target:
  14259. default: Data
  14260. description: |-
  14261. Target specifies where to place the template result.
  14262. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14263. any other value is rejected because it would allow writes to privileged Secret fields.
  14264. For custom resources (when spec.target.manifest is set), this supports
  14265. nested paths like "spec.database.config" or "data".
  14266. type: string
  14267. valuesDecodingStrategy:
  14268. description: |-
  14269. Used to define a decoding Strategy for the rendered template values.
  14270. Defaults to None when omitted.
  14271. enum:
  14272. - Auto
  14273. - Base64
  14274. - Base64URL
  14275. - None
  14276. type: string
  14277. type: object
  14278. type: array
  14279. type:
  14280. type: string
  14281. type: object
  14282. type: object
  14283. type: object
  14284. status:
  14285. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14286. properties:
  14287. binding:
  14288. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14289. properties:
  14290. name:
  14291. default: ""
  14292. description: |-
  14293. Name of the referent.
  14294. This field is effectively required, but due to backwards compatibility is
  14295. allowed to be empty. Instances of this type with an empty value here are
  14296. almost certainly wrong.
  14297. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14298. type: string
  14299. type: object
  14300. x-kubernetes-map-type: atomic
  14301. conditions:
  14302. items:
  14303. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14304. properties:
  14305. lastTransitionTime:
  14306. format: date-time
  14307. type: string
  14308. message:
  14309. type: string
  14310. reason:
  14311. type: string
  14312. status:
  14313. type: string
  14314. type:
  14315. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14316. enum:
  14317. - Ready
  14318. - Deleted
  14319. type: string
  14320. required:
  14321. - status
  14322. - type
  14323. type: object
  14324. type: array
  14325. refreshTime:
  14326. description: |-
  14327. refreshTime is the time and date the external secret was fetched and
  14328. the target secret updated
  14329. format: date-time
  14330. nullable: true
  14331. type: string
  14332. syncedResourceVersion:
  14333. description: SyncedResourceVersion keeps track of the last synced version
  14334. type: string
  14335. type: object
  14336. type: object
  14337. selectableFields:
  14338. - jsonPath: .spec.secretStoreRef.name
  14339. - jsonPath: .spec.secretStoreRef.kind
  14340. - jsonPath: .spec.target.name
  14341. - jsonPath: .spec.refreshInterval
  14342. served: true
  14343. storage: true
  14344. subresources:
  14345. status: {}
  14346. - additionalPrinterColumns:
  14347. - jsonPath: .spec.secretStoreRef.kind
  14348. name: StoreType
  14349. type: string
  14350. - jsonPath: .spec.secretStoreRef.name
  14351. name: Store
  14352. type: string
  14353. - jsonPath: .spec.refreshInterval
  14354. name: Refresh Interval
  14355. type: string
  14356. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14357. name: Status
  14358. type: string
  14359. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14360. name: Ready
  14361. type: string
  14362. - jsonPath: .status.refreshTime
  14363. name: Last Sync
  14364. type: date
  14365. deprecated: true
  14366. name: v1beta1
  14367. schema:
  14368. openAPIV3Schema:
  14369. description: ExternalSecret is the schema for the external-secrets API.
  14370. properties:
  14371. apiVersion:
  14372. description: |-
  14373. APIVersion defines the versioned schema of this representation of an object.
  14374. Servers should convert recognized schemas to the latest internal value, and
  14375. may reject unrecognized values.
  14376. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14377. type: string
  14378. kind:
  14379. description: |-
  14380. Kind is a string value representing the REST resource this object represents.
  14381. Servers may infer this from the endpoint the client submits requests to.
  14382. Cannot be updated.
  14383. In CamelCase.
  14384. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14385. type: string
  14386. metadata:
  14387. type: object
  14388. spec:
  14389. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14390. properties:
  14391. data:
  14392. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14393. items:
  14394. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14395. properties:
  14396. remoteRef:
  14397. description: |-
  14398. RemoteRef points to the remote secret and defines
  14399. which secret (version/property/..) to fetch.
  14400. properties:
  14401. conversionStrategy:
  14402. default: Default
  14403. description: Used to define a conversion Strategy
  14404. enum:
  14405. - Default
  14406. - Unicode
  14407. type: string
  14408. decodingStrategy:
  14409. default: None
  14410. description: Used to define a decoding Strategy
  14411. enum:
  14412. - Auto
  14413. - Base64
  14414. - Base64URL
  14415. - None
  14416. type: string
  14417. key:
  14418. description: Key is the key used in the Provider, mandatory
  14419. type: string
  14420. metadataPolicy:
  14421. default: None
  14422. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14423. enum:
  14424. - None
  14425. - Fetch
  14426. type: string
  14427. property:
  14428. description: Used to select a specific property of the Provider value (if a map), if supported
  14429. type: string
  14430. version:
  14431. description: Used to select a specific version of the Provider value, if supported
  14432. type: string
  14433. required:
  14434. - key
  14435. type: object
  14436. secretKey:
  14437. description: The key in the Kubernetes Secret to store the value.
  14438. maxLength: 253
  14439. minLength: 1
  14440. pattern: ^[-._a-zA-Z0-9]+$
  14441. type: string
  14442. sourceRef:
  14443. description: |-
  14444. SourceRef allows you to override the source
  14445. from which the value will be pulled.
  14446. maxProperties: 1
  14447. minProperties: 1
  14448. properties:
  14449. generatorRef:
  14450. description: |-
  14451. GeneratorRef points to a generator custom resource.
  14452. Deprecated: The generatorRef is not implemented in .data[].
  14453. this will be removed with v1.
  14454. properties:
  14455. apiVersion:
  14456. default: generators.external-secrets.io/v1alpha1
  14457. description: Specify the apiVersion of the generator resource
  14458. type: string
  14459. kind:
  14460. description: Specify the Kind of the generator resource
  14461. enum:
  14462. - ACRAccessToken
  14463. - ClusterGenerator
  14464. - ECRAuthorizationToken
  14465. - Fake
  14466. - GCRAccessToken
  14467. - GithubAccessToken
  14468. - QuayAccessToken
  14469. - Password
  14470. - SSHKey
  14471. - STSSessionToken
  14472. - UUID
  14473. - VaultDynamicSecret
  14474. - Webhook
  14475. - Grafana
  14476. type: string
  14477. name:
  14478. description: Specify the name of the generator resource
  14479. maxLength: 253
  14480. minLength: 1
  14481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14482. type: string
  14483. required:
  14484. - kind
  14485. - name
  14486. type: object
  14487. storeRef:
  14488. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14489. properties:
  14490. kind:
  14491. description: |-
  14492. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14493. Defaults to `SecretStore`
  14494. enum:
  14495. - SecretStore
  14496. - ClusterSecretStore
  14497. type: string
  14498. name:
  14499. description: Name of the SecretStore resource
  14500. maxLength: 253
  14501. minLength: 1
  14502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14503. type: string
  14504. type: object
  14505. type: object
  14506. required:
  14507. - remoteRef
  14508. - secretKey
  14509. type: object
  14510. type: array
  14511. dataFrom:
  14512. description: |-
  14513. DataFrom is used to fetch all properties from a specific Provider data
  14514. If multiple entries are specified, the Secret keys are merged in the specified order
  14515. items:
  14516. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14517. properties:
  14518. extract:
  14519. description: |-
  14520. Used to extract multiple key/value pairs from one secret
  14521. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14522. properties:
  14523. conversionStrategy:
  14524. default: Default
  14525. description: Used to define a conversion Strategy
  14526. enum:
  14527. - Default
  14528. - Unicode
  14529. type: string
  14530. decodingStrategy:
  14531. default: None
  14532. description: Used to define a decoding Strategy
  14533. enum:
  14534. - Auto
  14535. - Base64
  14536. - Base64URL
  14537. - None
  14538. type: string
  14539. key:
  14540. description: Key is the key used in the Provider, mandatory
  14541. type: string
  14542. metadataPolicy:
  14543. default: None
  14544. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14545. enum:
  14546. - None
  14547. - Fetch
  14548. type: string
  14549. property:
  14550. description: Used to select a specific property of the Provider value (if a map), if supported
  14551. type: string
  14552. version:
  14553. description: Used to select a specific version of the Provider value, if supported
  14554. type: string
  14555. required:
  14556. - key
  14557. type: object
  14558. find:
  14559. description: |-
  14560. Used to find secrets based on tags or regular expressions
  14561. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14562. properties:
  14563. conversionStrategy:
  14564. default: Default
  14565. description: Used to define a conversion Strategy
  14566. enum:
  14567. - Default
  14568. - Unicode
  14569. type: string
  14570. decodingStrategy:
  14571. default: None
  14572. description: Used to define a decoding Strategy
  14573. enum:
  14574. - Auto
  14575. - Base64
  14576. - Base64URL
  14577. - None
  14578. type: string
  14579. name:
  14580. description: Finds secrets based on the name.
  14581. properties:
  14582. regexp:
  14583. description: Finds secrets base
  14584. type: string
  14585. type: object
  14586. path:
  14587. description: A root path to start the find operations.
  14588. type: string
  14589. tags:
  14590. additionalProperties:
  14591. type: string
  14592. description: Find secrets based on tags.
  14593. type: object
  14594. type: object
  14595. rewrite:
  14596. description: |-
  14597. Used to rewrite secret Keys after getting them from the secret Provider
  14598. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14599. items:
  14600. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14601. maxProperties: 1
  14602. minProperties: 1
  14603. properties:
  14604. regexp:
  14605. description: |-
  14606. Used to rewrite with regular expressions.
  14607. The resulting key will be the output of a regexp.ReplaceAll operation.
  14608. properties:
  14609. source:
  14610. description: Used to define the regular expression of a re.Compiler.
  14611. type: string
  14612. target:
  14613. description: Used to define the target pattern of a ReplaceAll operation.
  14614. type: string
  14615. required:
  14616. - source
  14617. - target
  14618. type: object
  14619. transform:
  14620. description: |-
  14621. Used to apply string transformation on the secrets.
  14622. The resulting key will be the output of the template applied by the operation.
  14623. properties:
  14624. template:
  14625. description: |-
  14626. Used to define the template to apply on the secret name.
  14627. `.value ` will specify the secret name in the template.
  14628. type: string
  14629. required:
  14630. - template
  14631. type: object
  14632. type: object
  14633. type: array
  14634. sourceRef:
  14635. description: |-
  14636. SourceRef points to a store or generator
  14637. which contains secret values ready to use.
  14638. Use this in combination with Extract or Find pull values out of
  14639. a specific SecretStore.
  14640. When sourceRef points to a generator Extract or Find is not supported.
  14641. The generator returns a static map of values
  14642. maxProperties: 1
  14643. minProperties: 1
  14644. properties:
  14645. generatorRef:
  14646. description: GeneratorRef points to a generator custom resource.
  14647. properties:
  14648. apiVersion:
  14649. default: generators.external-secrets.io/v1alpha1
  14650. description: Specify the apiVersion of the generator resource
  14651. type: string
  14652. kind:
  14653. description: Specify the Kind of the generator resource
  14654. enum:
  14655. - ACRAccessToken
  14656. - ClusterGenerator
  14657. - ECRAuthorizationToken
  14658. - Fake
  14659. - GCRAccessToken
  14660. - GithubAccessToken
  14661. - QuayAccessToken
  14662. - Password
  14663. - SSHKey
  14664. - STSSessionToken
  14665. - UUID
  14666. - VaultDynamicSecret
  14667. - Webhook
  14668. - Grafana
  14669. type: string
  14670. name:
  14671. description: Specify the name of the generator resource
  14672. maxLength: 253
  14673. minLength: 1
  14674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14675. type: string
  14676. required:
  14677. - kind
  14678. - name
  14679. type: object
  14680. storeRef:
  14681. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14682. properties:
  14683. kind:
  14684. description: |-
  14685. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14686. Defaults to `SecretStore`
  14687. enum:
  14688. - SecretStore
  14689. - ClusterSecretStore
  14690. type: string
  14691. name:
  14692. description: Name of the SecretStore resource
  14693. maxLength: 253
  14694. minLength: 1
  14695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14696. type: string
  14697. type: object
  14698. type: object
  14699. type: object
  14700. type: array
  14701. refreshInterval:
  14702. default: 1h0m0s
  14703. description: |-
  14704. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14705. specified as Golang Duration strings.
  14706. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14707. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14708. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14709. type: string
  14710. refreshPolicy:
  14711. description: |-
  14712. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14713. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14714. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14715. No periodic updates occur if refreshInterval is 0.
  14716. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14717. enum:
  14718. - CreatedOnce
  14719. - Periodic
  14720. - OnChange
  14721. type: string
  14722. secretStoreRef:
  14723. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14724. properties:
  14725. kind:
  14726. description: |-
  14727. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14728. Defaults to `SecretStore`
  14729. enum:
  14730. - SecretStore
  14731. - ClusterSecretStore
  14732. type: string
  14733. name:
  14734. description: Name of the SecretStore resource
  14735. maxLength: 253
  14736. minLength: 1
  14737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14738. type: string
  14739. type: object
  14740. target:
  14741. default:
  14742. creationPolicy: Owner
  14743. deletionPolicy: Retain
  14744. description: |-
  14745. ExternalSecretTarget defines the Kubernetes Secret to be created
  14746. There can be only one target per ExternalSecret.
  14747. properties:
  14748. creationPolicy:
  14749. default: Owner
  14750. description: |-
  14751. CreationPolicy defines rules on how to create the resulting Secret.
  14752. Defaults to "Owner"
  14753. enum:
  14754. - Owner
  14755. - Orphan
  14756. - Merge
  14757. - None
  14758. type: string
  14759. deletionPolicy:
  14760. default: Retain
  14761. description: |-
  14762. DeletionPolicy defines rules on how to delete the resulting Secret.
  14763. Defaults to "Retain"
  14764. enum:
  14765. - Delete
  14766. - Merge
  14767. - Retain
  14768. type: string
  14769. immutable:
  14770. description: Immutable defines if the final secret will be immutable
  14771. type: boolean
  14772. name:
  14773. description: |-
  14774. The name of the Secret resource to be managed.
  14775. Defaults to the .metadata.name of the ExternalSecret resource
  14776. maxLength: 253
  14777. minLength: 1
  14778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14779. type: string
  14780. template:
  14781. description: Template defines a blueprint for the created Secret resource.
  14782. properties:
  14783. data:
  14784. additionalProperties:
  14785. type: string
  14786. type: object
  14787. engineVersion:
  14788. default: v2
  14789. description: |-
  14790. EngineVersion specifies the template engine version
  14791. that should be used to compile/execute the
  14792. template specified in .data and .templateFrom[].
  14793. enum:
  14794. - v2
  14795. type: string
  14796. mergePolicy:
  14797. default: Replace
  14798. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14799. enum:
  14800. - Replace
  14801. - Merge
  14802. type: string
  14803. metadata:
  14804. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14805. properties:
  14806. annotations:
  14807. additionalProperties:
  14808. type: string
  14809. type: object
  14810. labels:
  14811. additionalProperties:
  14812. type: string
  14813. type: object
  14814. type: object
  14815. templateFrom:
  14816. items:
  14817. description: TemplateFrom defines a source for template data.
  14818. properties:
  14819. configMap:
  14820. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14821. properties:
  14822. items:
  14823. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14824. items:
  14825. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14826. properties:
  14827. key:
  14828. description: A key in the ConfigMap/Secret
  14829. maxLength: 253
  14830. minLength: 1
  14831. pattern: ^[-._a-zA-Z0-9]+$
  14832. type: string
  14833. templateAs:
  14834. default: Values
  14835. description: TemplateScope defines the scope of the template when processing template data.
  14836. enum:
  14837. - Values
  14838. - KeysAndValues
  14839. type: string
  14840. required:
  14841. - key
  14842. type: object
  14843. type: array
  14844. name:
  14845. description: The name of the ConfigMap/Secret resource
  14846. maxLength: 253
  14847. minLength: 1
  14848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14849. type: string
  14850. required:
  14851. - items
  14852. - name
  14853. type: object
  14854. literal:
  14855. type: string
  14856. secret:
  14857. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14858. properties:
  14859. items:
  14860. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14861. items:
  14862. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14863. properties:
  14864. key:
  14865. description: A key in the ConfigMap/Secret
  14866. maxLength: 253
  14867. minLength: 1
  14868. pattern: ^[-._a-zA-Z0-9]+$
  14869. type: string
  14870. templateAs:
  14871. default: Values
  14872. description: TemplateScope defines the scope of the template when processing template data.
  14873. enum:
  14874. - Values
  14875. - KeysAndValues
  14876. type: string
  14877. required:
  14878. - key
  14879. type: object
  14880. type: array
  14881. name:
  14882. description: The name of the ConfigMap/Secret resource
  14883. maxLength: 253
  14884. minLength: 1
  14885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14886. type: string
  14887. required:
  14888. - items
  14889. - name
  14890. type: object
  14891. target:
  14892. default: Data
  14893. description: TemplateTarget defines the target field where the template result will be stored.
  14894. enum:
  14895. - Data
  14896. - Annotations
  14897. - Labels
  14898. type: string
  14899. type: object
  14900. type: array
  14901. type:
  14902. type: string
  14903. type: object
  14904. type: object
  14905. type: object
  14906. status:
  14907. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14908. properties:
  14909. binding:
  14910. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14911. properties:
  14912. name:
  14913. default: ""
  14914. description: |-
  14915. Name of the referent.
  14916. This field is effectively required, but due to backwards compatibility is
  14917. allowed to be empty. Instances of this type with an empty value here are
  14918. almost certainly wrong.
  14919. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14920. type: string
  14921. type: object
  14922. x-kubernetes-map-type: atomic
  14923. conditions:
  14924. items:
  14925. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14926. properties:
  14927. lastTransitionTime:
  14928. format: date-time
  14929. type: string
  14930. message:
  14931. type: string
  14932. reason:
  14933. type: string
  14934. status:
  14935. type: string
  14936. type:
  14937. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14938. type: string
  14939. required:
  14940. - status
  14941. - type
  14942. type: object
  14943. type: array
  14944. refreshTime:
  14945. description: |-
  14946. refreshTime is the time and date the external secret was fetched and
  14947. the target secret updated
  14948. format: date-time
  14949. nullable: true
  14950. type: string
  14951. syncedResourceVersion:
  14952. description: SyncedResourceVersion keeps track of the last synced version
  14953. type: string
  14954. type: object
  14955. type: object
  14956. served: false
  14957. storage: false
  14958. subresources:
  14959. status: {}
  14960. ---
  14961. apiVersion: apiextensions.k8s.io/v1
  14962. kind: CustomResourceDefinition
  14963. metadata:
  14964. annotations:
  14965. controller-gen.kubebuilder.io/version: v0.19.0
  14966. labels:
  14967. external-secrets.io/component: controller
  14968. name: pushsecrets.external-secrets.io
  14969. spec:
  14970. group: external-secrets.io
  14971. names:
  14972. categories:
  14973. - external-secrets
  14974. kind: PushSecret
  14975. listKind: PushSecretList
  14976. plural: pushsecrets
  14977. shortNames:
  14978. - ps
  14979. singular: pushsecret
  14980. scope: Namespaced
  14981. versions:
  14982. - additionalPrinterColumns:
  14983. - jsonPath: .metadata.creationTimestamp
  14984. name: AGE
  14985. type: date
  14986. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14987. name: Status
  14988. type: string
  14989. - jsonPath: .status.refreshTime
  14990. name: Last Sync
  14991. type: date
  14992. name: v1alpha1
  14993. schema:
  14994. openAPIV3Schema:
  14995. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14996. properties:
  14997. apiVersion:
  14998. description: |-
  14999. APIVersion defines the versioned schema of this representation of an object.
  15000. Servers should convert recognized schemas to the latest internal value, and
  15001. may reject unrecognized values.
  15002. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15003. type: string
  15004. kind:
  15005. description: |-
  15006. Kind is a string value representing the REST resource this object represents.
  15007. Servers may infer this from the endpoint the client submits requests to.
  15008. Cannot be updated.
  15009. In CamelCase.
  15010. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15011. type: string
  15012. metadata:
  15013. type: object
  15014. spec:
  15015. description: PushSecretSpec configures the behavior of the PushSecret.
  15016. properties:
  15017. data:
  15018. description: Secret Data that should be pushed to providers
  15019. items:
  15020. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15021. properties:
  15022. conversionStrategy:
  15023. default: None
  15024. description: Used to define a conversion Strategy for the secret keys
  15025. enum:
  15026. - None
  15027. - ReverseUnicode
  15028. type: string
  15029. match:
  15030. description: Match a given Secret Key to be pushed to the provider.
  15031. properties:
  15032. remoteRef:
  15033. description: Remote Refs to push to providers.
  15034. properties:
  15035. property:
  15036. description: Name of the property in the resulting secret
  15037. type: string
  15038. remoteKey:
  15039. description: Name of the resulting provider secret.
  15040. type: string
  15041. required:
  15042. - remoteKey
  15043. type: object
  15044. secretKey:
  15045. description: Secret Key to be pushed
  15046. type: string
  15047. required:
  15048. - remoteRef
  15049. type: object
  15050. metadata:
  15051. description: |-
  15052. Metadata is metadata attached to the secret.
  15053. The structure of metadata is provider specific, please look it up in the provider documentation.
  15054. x-kubernetes-preserve-unknown-fields: true
  15055. required:
  15056. - match
  15057. type: object
  15058. type: array
  15059. dataTo:
  15060. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  15061. items:
  15062. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  15063. properties:
  15064. conversionStrategy:
  15065. default: None
  15066. description: Used to define a conversion Strategy for the secret keys
  15067. enum:
  15068. - None
  15069. - ReverseUnicode
  15070. type: string
  15071. match:
  15072. description: |-
  15073. Match pattern for selecting keys from the source Secret.
  15074. If not specified, all keys are selected.
  15075. properties:
  15076. regexp:
  15077. description: |-
  15078. Regexp matches keys by regular expression.
  15079. If not specified, all keys are matched.
  15080. type: string
  15081. type: object
  15082. metadata:
  15083. description: |-
  15084. Metadata is metadata attached to the secret.
  15085. The structure of metadata is provider specific, please look it up in the provider documentation.
  15086. x-kubernetes-preserve-unknown-fields: true
  15087. remoteKey:
  15088. description: |-
  15089. RemoteKey is the name of the single provider secret that will receive ALL
  15090. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15091. When set, per-key expansion is skipped and a single push is performed.
  15092. The provider's store prefix (if any) is still prepended to this value.
  15093. When not set, each matched key is pushed as its own individual provider secret.
  15094. type: string
  15095. rewrite:
  15096. description: |-
  15097. Rewrite operations to transform keys before pushing to the provider.
  15098. Operations are applied sequentially.
  15099. items:
  15100. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15101. properties:
  15102. regexp:
  15103. description: Used to rewrite with regular expressions.
  15104. properties:
  15105. source:
  15106. description: Used to define the regular expression of a re.Compiler.
  15107. type: string
  15108. target:
  15109. description: Used to define the target pattern of a ReplaceAll operation.
  15110. type: string
  15111. required:
  15112. - source
  15113. - target
  15114. type: object
  15115. transform:
  15116. description: Used to apply string transformation on the secrets.
  15117. properties:
  15118. template:
  15119. description: |-
  15120. Used to define the template to apply on the secret name.
  15121. `.value ` will specify the secret name in the template.
  15122. type: string
  15123. required:
  15124. - template
  15125. type: object
  15126. type: object
  15127. x-kubernetes-validations:
  15128. - message: exactly one of regexp or transform must be set
  15129. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15130. type: array
  15131. storeRef:
  15132. description: StoreRef specifies which SecretStore to push to. Required.
  15133. properties:
  15134. kind:
  15135. default: SecretStore
  15136. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15137. enum:
  15138. - SecretStore
  15139. - ClusterSecretStore
  15140. type: string
  15141. labelSelector:
  15142. description: Optionally, sync to secret stores with label selector
  15143. properties:
  15144. matchExpressions:
  15145. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15146. items:
  15147. description: |-
  15148. A label selector requirement is a selector that contains values, a key, and an operator that
  15149. relates the key and values.
  15150. properties:
  15151. key:
  15152. description: key is the label key that the selector applies to.
  15153. type: string
  15154. operator:
  15155. description: |-
  15156. operator represents a key's relationship to a set of values.
  15157. Valid operators are In, NotIn, Exists and DoesNotExist.
  15158. type: string
  15159. values:
  15160. description: |-
  15161. values is an array of string values. If the operator is In or NotIn,
  15162. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15163. the values array must be empty. This array is replaced during a strategic
  15164. merge patch.
  15165. items:
  15166. type: string
  15167. type: array
  15168. x-kubernetes-list-type: atomic
  15169. required:
  15170. - key
  15171. - operator
  15172. type: object
  15173. type: array
  15174. x-kubernetes-list-type: atomic
  15175. matchLabels:
  15176. additionalProperties:
  15177. type: string
  15178. description: |-
  15179. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15180. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15181. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15182. type: object
  15183. type: object
  15184. x-kubernetes-map-type: atomic
  15185. name:
  15186. description: Optionally, sync to the SecretStore of the given name
  15187. maxLength: 253
  15188. minLength: 1
  15189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15190. type: string
  15191. type: object
  15192. type: object
  15193. x-kubernetes-validations:
  15194. - message: storeRef must specify either name or labelSelector
  15195. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15196. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15197. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15198. type: array
  15199. deletionPolicy:
  15200. default: None
  15201. description: Deletion Policy to handle Secrets in the provider.
  15202. enum:
  15203. - Delete
  15204. - None
  15205. type: string
  15206. refreshInterval:
  15207. default: 1h0m0s
  15208. description: The Interval to which External Secrets will try to push a secret definition
  15209. type: string
  15210. secretStoreRefs:
  15211. items:
  15212. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15213. properties:
  15214. kind:
  15215. default: SecretStore
  15216. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15217. enum:
  15218. - SecretStore
  15219. - ClusterSecretStore
  15220. type: string
  15221. labelSelector:
  15222. description: Optionally, sync to secret stores with label selector
  15223. properties:
  15224. matchExpressions:
  15225. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15226. items:
  15227. description: |-
  15228. A label selector requirement is a selector that contains values, a key, and an operator that
  15229. relates the key and values.
  15230. properties:
  15231. key:
  15232. description: key is the label key that the selector applies to.
  15233. type: string
  15234. operator:
  15235. description: |-
  15236. operator represents a key's relationship to a set of values.
  15237. Valid operators are In, NotIn, Exists and DoesNotExist.
  15238. type: string
  15239. values:
  15240. description: |-
  15241. values is an array of string values. If the operator is In or NotIn,
  15242. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15243. the values array must be empty. This array is replaced during a strategic
  15244. merge patch.
  15245. items:
  15246. type: string
  15247. type: array
  15248. x-kubernetes-list-type: atomic
  15249. required:
  15250. - key
  15251. - operator
  15252. type: object
  15253. type: array
  15254. x-kubernetes-list-type: atomic
  15255. matchLabels:
  15256. additionalProperties:
  15257. type: string
  15258. description: |-
  15259. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15260. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15261. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15262. type: object
  15263. type: object
  15264. x-kubernetes-map-type: atomic
  15265. name:
  15266. description: Optionally, sync to the SecretStore of the given name
  15267. maxLength: 253
  15268. minLength: 1
  15269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15270. type: string
  15271. type: object
  15272. type: array
  15273. selector:
  15274. description: The Secret Selector (k8s source) for the Push Secret
  15275. maxProperties: 1
  15276. minProperties: 1
  15277. properties:
  15278. generatorRef:
  15279. description: Point to a generator to create a Secret.
  15280. properties:
  15281. apiVersion:
  15282. default: generators.external-secrets.io/v1alpha1
  15283. description: Specify the apiVersion of the generator resource
  15284. type: string
  15285. kind:
  15286. description: Specify the Kind of the generator resource
  15287. enum:
  15288. - ACRAccessToken
  15289. - BeyondtrustWorkloadCredentialsDynamicSecret
  15290. - ClusterGenerator
  15291. - CloudsmithAccessToken
  15292. - ECRAuthorizationToken
  15293. - Fake
  15294. - GCRAccessToken
  15295. - GithubAccessToken
  15296. - GitlabDeployToken
  15297. - QuayAccessToken
  15298. - Password
  15299. - SSHKey
  15300. - STSSessionToken
  15301. - UUID
  15302. - VaultDynamicSecret
  15303. - Webhook
  15304. - Grafana
  15305. - MFA
  15306. type: string
  15307. name:
  15308. description: Specify the name of the generator resource
  15309. maxLength: 253
  15310. minLength: 1
  15311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15312. type: string
  15313. required:
  15314. - kind
  15315. - name
  15316. type: object
  15317. secret:
  15318. description: Select a Secret to Push.
  15319. properties:
  15320. name:
  15321. description: |-
  15322. Name of the Secret.
  15323. The Secret must exist in the same namespace as the PushSecret manifest.
  15324. maxLength: 253
  15325. minLength: 1
  15326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15327. type: string
  15328. selector:
  15329. description: Selector chooses secrets using a labelSelector.
  15330. properties:
  15331. matchExpressions:
  15332. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15333. items:
  15334. description: |-
  15335. A label selector requirement is a selector that contains values, a key, and an operator that
  15336. relates the key and values.
  15337. properties:
  15338. key:
  15339. description: key is the label key that the selector applies to.
  15340. type: string
  15341. operator:
  15342. description: |-
  15343. operator represents a key's relationship to a set of values.
  15344. Valid operators are In, NotIn, Exists and DoesNotExist.
  15345. type: string
  15346. values:
  15347. description: |-
  15348. values is an array of string values. If the operator is In or NotIn,
  15349. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15350. the values array must be empty. This array is replaced during a strategic
  15351. merge patch.
  15352. items:
  15353. type: string
  15354. type: array
  15355. x-kubernetes-list-type: atomic
  15356. required:
  15357. - key
  15358. - operator
  15359. type: object
  15360. type: array
  15361. x-kubernetes-list-type: atomic
  15362. matchLabels:
  15363. additionalProperties:
  15364. type: string
  15365. description: |-
  15366. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15367. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15368. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15369. type: object
  15370. type: object
  15371. x-kubernetes-map-type: atomic
  15372. type: object
  15373. type: object
  15374. template:
  15375. description: Template defines a blueprint for the created Secret resource.
  15376. properties:
  15377. data:
  15378. additionalProperties:
  15379. type: string
  15380. type: object
  15381. engineVersion:
  15382. default: v2
  15383. description: |-
  15384. EngineVersion specifies the template engine version
  15385. that should be used to compile/execute the
  15386. template specified in .data and .templateFrom[].
  15387. enum:
  15388. - v2
  15389. type: string
  15390. mergePolicy:
  15391. default: Replace
  15392. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15393. enum:
  15394. - Replace
  15395. - Merge
  15396. type: string
  15397. metadata:
  15398. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15399. properties:
  15400. annotations:
  15401. additionalProperties:
  15402. type: string
  15403. type: object
  15404. finalizers:
  15405. items:
  15406. type: string
  15407. type: array
  15408. labels:
  15409. additionalProperties:
  15410. type: string
  15411. type: object
  15412. type: object
  15413. templateFrom:
  15414. items:
  15415. description: |-
  15416. TemplateFrom specifies a source for templates.
  15417. Each item in the list can either reference a ConfigMap or a Secret resource.
  15418. properties:
  15419. configMap:
  15420. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15421. properties:
  15422. items:
  15423. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15424. items:
  15425. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15426. properties:
  15427. key:
  15428. description: A key in the ConfigMap/Secret
  15429. maxLength: 253
  15430. minLength: 1
  15431. pattern: ^[-._a-zA-Z0-9]+$
  15432. type: string
  15433. templateAs:
  15434. default: Values
  15435. description: TemplateScope specifies how the template keys should be interpreted.
  15436. enum:
  15437. - Values
  15438. - KeysAndValues
  15439. type: string
  15440. required:
  15441. - key
  15442. type: object
  15443. type: array
  15444. name:
  15445. description: The name of the ConfigMap/Secret resource
  15446. maxLength: 253
  15447. minLength: 1
  15448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15449. type: string
  15450. required:
  15451. - items
  15452. - name
  15453. type: object
  15454. literal:
  15455. type: string
  15456. secret:
  15457. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15458. properties:
  15459. items:
  15460. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15461. items:
  15462. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15463. properties:
  15464. key:
  15465. description: A key in the ConfigMap/Secret
  15466. maxLength: 253
  15467. minLength: 1
  15468. pattern: ^[-._a-zA-Z0-9]+$
  15469. type: string
  15470. templateAs:
  15471. default: Values
  15472. description: TemplateScope specifies how the template keys should be interpreted.
  15473. enum:
  15474. - Values
  15475. - KeysAndValues
  15476. type: string
  15477. required:
  15478. - key
  15479. type: object
  15480. type: array
  15481. name:
  15482. description: The name of the ConfigMap/Secret resource
  15483. maxLength: 253
  15484. minLength: 1
  15485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15486. type: string
  15487. required:
  15488. - items
  15489. - name
  15490. type: object
  15491. target:
  15492. default: Data
  15493. description: |-
  15494. Target specifies where to place the template result.
  15495. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15496. any other value is rejected because it would allow writes to privileged Secret fields.
  15497. For custom resources (when spec.target.manifest is set), this supports
  15498. nested paths like "spec.database.config" or "data".
  15499. type: string
  15500. valuesDecodingStrategy:
  15501. description: |-
  15502. Used to define a decoding Strategy for the rendered template values.
  15503. Defaults to None when omitted.
  15504. enum:
  15505. - Auto
  15506. - Base64
  15507. - Base64URL
  15508. - None
  15509. type: string
  15510. type: object
  15511. type: array
  15512. type:
  15513. type: string
  15514. type: object
  15515. updatePolicy:
  15516. default: Replace
  15517. description: UpdatePolicy to handle Secrets in the provider.
  15518. enum:
  15519. - Replace
  15520. - IfNotExists
  15521. type: string
  15522. required:
  15523. - secretStoreRefs
  15524. - selector
  15525. type: object
  15526. status:
  15527. description: PushSecretStatus indicates the history of the status of PushSecret.
  15528. properties:
  15529. conditions:
  15530. items:
  15531. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15532. properties:
  15533. lastTransitionTime:
  15534. format: date-time
  15535. type: string
  15536. message:
  15537. type: string
  15538. reason:
  15539. type: string
  15540. status:
  15541. type: string
  15542. type:
  15543. description: PushSecretConditionType indicates the condition of the PushSecret.
  15544. type: string
  15545. required:
  15546. - status
  15547. - type
  15548. type: object
  15549. type: array
  15550. refreshTime:
  15551. description: |-
  15552. refreshTime is the time and date the external secret was fetched and
  15553. the target secret updated
  15554. format: date-time
  15555. nullable: true
  15556. type: string
  15557. syncedPushSecrets:
  15558. additionalProperties:
  15559. additionalProperties:
  15560. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15561. properties:
  15562. conversionStrategy:
  15563. default: None
  15564. description: Used to define a conversion Strategy for the secret keys
  15565. enum:
  15566. - None
  15567. - ReverseUnicode
  15568. type: string
  15569. match:
  15570. description: Match a given Secret Key to be pushed to the provider.
  15571. properties:
  15572. remoteRef:
  15573. description: Remote Refs to push to providers.
  15574. properties:
  15575. property:
  15576. description: Name of the property in the resulting secret
  15577. type: string
  15578. remoteKey:
  15579. description: Name of the resulting provider secret.
  15580. type: string
  15581. required:
  15582. - remoteKey
  15583. type: object
  15584. secretKey:
  15585. description: Secret Key to be pushed
  15586. type: string
  15587. required:
  15588. - remoteRef
  15589. type: object
  15590. metadata:
  15591. description: |-
  15592. Metadata is metadata attached to the secret.
  15593. The structure of metadata is provider specific, please look it up in the provider documentation.
  15594. x-kubernetes-preserve-unknown-fields: true
  15595. required:
  15596. - match
  15597. type: object
  15598. type: object
  15599. description: |-
  15600. Synced PushSecrets, including secrets that already exist in provider.
  15601. Matches secret stores to PushSecretData that was stored to that secret store.
  15602. type: object
  15603. syncedResourceVersion:
  15604. description: SyncedResourceVersion keeps track of the last synced version.
  15605. type: string
  15606. type: object
  15607. type: object
  15608. served: true
  15609. storage: true
  15610. subresources:
  15611. status: {}
  15612. ---
  15613. apiVersion: apiextensions.k8s.io/v1
  15614. kind: CustomResourceDefinition
  15615. metadata:
  15616. annotations:
  15617. controller-gen.kubebuilder.io/version: v0.19.0
  15618. labels:
  15619. external-secrets.io/component: controller
  15620. name: secretstores.external-secrets.io
  15621. spec:
  15622. group: external-secrets.io
  15623. names:
  15624. categories:
  15625. - external-secrets
  15626. kind: SecretStore
  15627. listKind: SecretStoreList
  15628. plural: secretstores
  15629. shortNames:
  15630. - ss
  15631. singular: secretstore
  15632. scope: Namespaced
  15633. versions:
  15634. - additionalPrinterColumns:
  15635. - jsonPath: .metadata.creationTimestamp
  15636. name: AGE
  15637. type: date
  15638. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15639. name: Status
  15640. type: string
  15641. - jsonPath: .status.capabilities
  15642. name: Capabilities
  15643. type: string
  15644. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15645. name: Ready
  15646. type: string
  15647. name: v1
  15648. schema:
  15649. openAPIV3Schema:
  15650. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15651. properties:
  15652. apiVersion:
  15653. description: |-
  15654. APIVersion defines the versioned schema of this representation of an object.
  15655. Servers should convert recognized schemas to the latest internal value, and
  15656. may reject unrecognized values.
  15657. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15658. type: string
  15659. kind:
  15660. description: |-
  15661. Kind is a string value representing the REST resource this object represents.
  15662. Servers may infer this from the endpoint the client submits requests to.
  15663. Cannot be updated.
  15664. In CamelCase.
  15665. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15666. type: string
  15667. metadata:
  15668. type: object
  15669. spec:
  15670. description: SecretStoreSpec defines the desired state of SecretStore.
  15671. properties:
  15672. conditions:
  15673. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15674. items:
  15675. description: |-
  15676. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15677. for a ClusterSecretStore instance.
  15678. properties:
  15679. namespaceRegexes:
  15680. description: Choose namespaces by using regex matching
  15681. items:
  15682. type: string
  15683. type: array
  15684. namespaceSelector:
  15685. description: Choose namespace using a labelSelector
  15686. properties:
  15687. matchExpressions:
  15688. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15689. items:
  15690. description: |-
  15691. A label selector requirement is a selector that contains values, a key, and an operator that
  15692. relates the key and values.
  15693. properties:
  15694. key:
  15695. description: key is the label key that the selector applies to.
  15696. type: string
  15697. operator:
  15698. description: |-
  15699. operator represents a key's relationship to a set of values.
  15700. Valid operators are In, NotIn, Exists and DoesNotExist.
  15701. type: string
  15702. values:
  15703. description: |-
  15704. values is an array of string values. If the operator is In or NotIn,
  15705. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15706. the values array must be empty. This array is replaced during a strategic
  15707. merge patch.
  15708. items:
  15709. type: string
  15710. type: array
  15711. x-kubernetes-list-type: atomic
  15712. required:
  15713. - key
  15714. - operator
  15715. type: object
  15716. type: array
  15717. x-kubernetes-list-type: atomic
  15718. matchLabels:
  15719. additionalProperties:
  15720. type: string
  15721. description: |-
  15722. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15723. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15724. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15725. type: object
  15726. type: object
  15727. x-kubernetes-map-type: atomic
  15728. namespaces:
  15729. description: Choose namespaces by name
  15730. items:
  15731. maxLength: 63
  15732. minLength: 1
  15733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15734. type: string
  15735. type: array
  15736. type: object
  15737. type: array
  15738. controller:
  15739. description: |-
  15740. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15741. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15742. type: string
  15743. provider:
  15744. description: Used to configure the provider. Only one provider may be set
  15745. maxProperties: 1
  15746. minProperties: 1
  15747. properties:
  15748. akeyless:
  15749. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15750. properties:
  15751. akeylessGWApiURL:
  15752. description: Akeyless GW API Url from which the secrets to be fetched from.
  15753. type: string
  15754. authSecretRef:
  15755. description: Auth configures how the operator authenticates with Akeyless.
  15756. properties:
  15757. kubernetesAuth:
  15758. description: |-
  15759. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15760. token stored in the named Secret resource.
  15761. properties:
  15762. accessID:
  15763. description: the Akeyless Kubernetes auth-method access-id
  15764. type: string
  15765. k8sConfName:
  15766. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15767. type: string
  15768. secretRef:
  15769. description: |-
  15770. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15771. for authenticating with Akeyless. If a name is specified without a key,
  15772. `token` is the default. If one is not specified, the one bound to
  15773. the controller will be used.
  15774. properties:
  15775. key:
  15776. description: |-
  15777. A key in the referenced Secret.
  15778. Some instances of this field may be defaulted, in others it may be required.
  15779. maxLength: 253
  15780. minLength: 1
  15781. pattern: ^[-._a-zA-Z0-9]+$
  15782. type: string
  15783. name:
  15784. description: The name of the Secret resource being referred to.
  15785. maxLength: 253
  15786. minLength: 1
  15787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15788. type: string
  15789. namespace:
  15790. description: |-
  15791. The namespace of the Secret resource being referred to.
  15792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15793. maxLength: 63
  15794. minLength: 1
  15795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15796. type: string
  15797. type: object
  15798. serviceAccountRef:
  15799. description: |-
  15800. Optional service account field containing the name of a kubernetes ServiceAccount.
  15801. If the service account is specified, the service account secret token JWT will be used
  15802. for authenticating with Akeyless. If the service account selector is not supplied,
  15803. the secretRef will be used instead.
  15804. properties:
  15805. audiences:
  15806. description: |-
  15807. Audience specifies the `aud` claim for the service account token
  15808. Some providers automatically extend the audience field based on well-known annotations for workload
  15809. identity (e.g. IRSA or GCP Workload Identity)
  15810. items:
  15811. type: string
  15812. type: array
  15813. name:
  15814. description: The name of the ServiceAccount resource being referred to.
  15815. maxLength: 253
  15816. minLength: 1
  15817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15818. type: string
  15819. namespace:
  15820. description: |-
  15821. Namespace of the resource being referred to.
  15822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15823. maxLength: 63
  15824. minLength: 1
  15825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15826. type: string
  15827. required:
  15828. - name
  15829. type: object
  15830. required:
  15831. - accessID
  15832. - k8sConfName
  15833. type: object
  15834. secretRef:
  15835. description: |-
  15836. Reference to a Secret that contains the details
  15837. to authenticate with Akeyless.
  15838. properties:
  15839. accessID:
  15840. description: The SecretAccessID is used for authentication
  15841. properties:
  15842. key:
  15843. description: |-
  15844. A key in the referenced Secret.
  15845. Some instances of this field may be defaulted, in others it may be required.
  15846. maxLength: 253
  15847. minLength: 1
  15848. pattern: ^[-._a-zA-Z0-9]+$
  15849. type: string
  15850. name:
  15851. description: The name of the Secret resource being referred to.
  15852. maxLength: 253
  15853. minLength: 1
  15854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15855. type: string
  15856. namespace:
  15857. description: |-
  15858. The namespace of the Secret resource being referred to.
  15859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15860. maxLength: 63
  15861. minLength: 1
  15862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15863. type: string
  15864. type: object
  15865. accessType:
  15866. description: |-
  15867. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15868. In some instances, `key` is a required field.
  15869. properties:
  15870. key:
  15871. description: |-
  15872. A key in the referenced Secret.
  15873. Some instances of this field may be defaulted, in others it may be required.
  15874. maxLength: 253
  15875. minLength: 1
  15876. pattern: ^[-._a-zA-Z0-9]+$
  15877. type: string
  15878. name:
  15879. description: The name of the Secret resource being referred to.
  15880. maxLength: 253
  15881. minLength: 1
  15882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15883. type: string
  15884. namespace:
  15885. description: |-
  15886. The namespace of the Secret resource being referred to.
  15887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15888. maxLength: 63
  15889. minLength: 1
  15890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15891. type: string
  15892. type: object
  15893. accessTypeParam:
  15894. description: |-
  15895. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15896. In some instances, `key` is a required field.
  15897. properties:
  15898. key:
  15899. description: |-
  15900. A key in the referenced Secret.
  15901. Some instances of this field may be defaulted, in others it may be required.
  15902. maxLength: 253
  15903. minLength: 1
  15904. pattern: ^[-._a-zA-Z0-9]+$
  15905. type: string
  15906. name:
  15907. description: The name of the Secret resource being referred to.
  15908. maxLength: 253
  15909. minLength: 1
  15910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15911. type: string
  15912. namespace:
  15913. description: |-
  15914. The namespace of the Secret resource being referred to.
  15915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15916. maxLength: 63
  15917. minLength: 1
  15918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15919. type: string
  15920. type: object
  15921. type: object
  15922. serviceAccountRef:
  15923. description: |-
  15924. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15925. authentication on AKS Workload Identity. The operator obtains a federated
  15926. identity token from this ServiceAccount via the TokenRequest API instead
  15927. of using the ESO controller pod identity. Ignored for other access types.
  15928. properties:
  15929. audiences:
  15930. description: |-
  15931. Audience specifies the `aud` claim for the service account token
  15932. Some providers automatically extend the audience field based on well-known annotations for workload
  15933. identity (e.g. IRSA or GCP Workload Identity)
  15934. items:
  15935. type: string
  15936. type: array
  15937. name:
  15938. description: The name of the ServiceAccount resource being referred to.
  15939. maxLength: 253
  15940. minLength: 1
  15941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15942. type: string
  15943. namespace:
  15944. description: |-
  15945. Namespace of the resource being referred to.
  15946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15947. maxLength: 63
  15948. minLength: 1
  15949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15950. type: string
  15951. required:
  15952. - name
  15953. type: object
  15954. type: object
  15955. caBundle:
  15956. description: |-
  15957. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15958. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15959. are used to validate the TLS connection.
  15960. format: byte
  15961. type: string
  15962. caProvider:
  15963. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15964. properties:
  15965. key:
  15966. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15967. maxLength: 253
  15968. minLength: 1
  15969. pattern: ^[-._a-zA-Z0-9]+$
  15970. type: string
  15971. name:
  15972. description: The name of the object located at the provider type.
  15973. maxLength: 253
  15974. minLength: 1
  15975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15976. type: string
  15977. namespace:
  15978. description: |-
  15979. The namespace the Provider type is in.
  15980. Can only be defined when used in a ClusterSecretStore.
  15981. maxLength: 63
  15982. minLength: 1
  15983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15984. type: string
  15985. type:
  15986. description: The type of provider to use such as "Secret", or "ConfigMap".
  15987. enum:
  15988. - Secret
  15989. - ConfigMap
  15990. type: string
  15991. required:
  15992. - name
  15993. - type
  15994. type: object
  15995. ignoreCache:
  15996. description: |-
  15997. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15998. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15999. type: boolean
  16000. required:
  16001. - akeylessGWApiURL
  16002. - authSecretRef
  16003. type: object
  16004. aws:
  16005. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  16006. properties:
  16007. additionalRoles:
  16008. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  16009. items:
  16010. type: string
  16011. type: array
  16012. auth:
  16013. description: |-
  16014. Auth defines the information necessary to authenticate against AWS
  16015. if not set aws sdk will infer credentials from your environment
  16016. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  16017. properties:
  16018. jwt:
  16019. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  16020. properties:
  16021. serviceAccountRef:
  16022. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  16023. properties:
  16024. audiences:
  16025. description: |-
  16026. Audience specifies the `aud` claim for the service account token
  16027. Some providers automatically extend the audience field based on well-known annotations for workload
  16028. identity (e.g. IRSA or GCP Workload Identity)
  16029. items:
  16030. type: string
  16031. type: array
  16032. name:
  16033. description: The name of the ServiceAccount resource being referred to.
  16034. maxLength: 253
  16035. minLength: 1
  16036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16037. type: string
  16038. namespace:
  16039. description: |-
  16040. Namespace of the resource being referred to.
  16041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16042. maxLength: 63
  16043. minLength: 1
  16044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16045. type: string
  16046. required:
  16047. - name
  16048. type: object
  16049. type: object
  16050. secretRef:
  16051. description: |-
  16052. AWSAuthSecretRef holds secret references for AWS credentials
  16053. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16054. properties:
  16055. accessKeyIDSecretRef:
  16056. description: The AccessKeyID is used for authentication
  16057. properties:
  16058. key:
  16059. description: |-
  16060. A key in the referenced Secret.
  16061. Some instances of this field may be defaulted, in others it may be required.
  16062. maxLength: 253
  16063. minLength: 1
  16064. pattern: ^[-._a-zA-Z0-9]+$
  16065. type: string
  16066. name:
  16067. description: The name of the Secret resource being referred to.
  16068. maxLength: 253
  16069. minLength: 1
  16070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16071. type: string
  16072. namespace:
  16073. description: |-
  16074. The namespace of the Secret resource being referred to.
  16075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16076. maxLength: 63
  16077. minLength: 1
  16078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16079. type: string
  16080. type: object
  16081. secretAccessKeySecretRef:
  16082. description: The SecretAccessKey is used for authentication
  16083. properties:
  16084. key:
  16085. description: |-
  16086. A key in the referenced Secret.
  16087. Some instances of this field may be defaulted, in others it may be required.
  16088. maxLength: 253
  16089. minLength: 1
  16090. pattern: ^[-._a-zA-Z0-9]+$
  16091. type: string
  16092. name:
  16093. description: The name of the Secret resource being referred to.
  16094. maxLength: 253
  16095. minLength: 1
  16096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16097. type: string
  16098. namespace:
  16099. description: |-
  16100. The namespace of the Secret resource being referred to.
  16101. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16102. maxLength: 63
  16103. minLength: 1
  16104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16105. type: string
  16106. type: object
  16107. sessionTokenSecretRef:
  16108. description: |-
  16109. The SessionToken used for authentication
  16110. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16111. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16112. properties:
  16113. key:
  16114. description: |-
  16115. A key in the referenced Secret.
  16116. Some instances of this field may be defaulted, in others it may be required.
  16117. maxLength: 253
  16118. minLength: 1
  16119. pattern: ^[-._a-zA-Z0-9]+$
  16120. type: string
  16121. name:
  16122. description: The name of the Secret resource being referred to.
  16123. maxLength: 253
  16124. minLength: 1
  16125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16126. type: string
  16127. namespace:
  16128. description: |-
  16129. The namespace of the Secret resource being referred to.
  16130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16131. maxLength: 63
  16132. minLength: 1
  16133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16134. type: string
  16135. type: object
  16136. type: object
  16137. type: object
  16138. customSessionTags:
  16139. additionalProperties:
  16140. type: string
  16141. description: |-
  16142. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16143. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16144. type: object
  16145. x-kubernetes-validations:
  16146. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16147. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16148. externalID:
  16149. description: AWS External ID set on assumed IAM roles
  16150. type: string
  16151. prefix:
  16152. description: Prefix adds a prefix to all retrieved values.
  16153. type: string
  16154. region:
  16155. description: AWS Region to be used for the provider
  16156. type: string
  16157. role:
  16158. description: Role is a Role ARN which the provider will assume
  16159. type: string
  16160. secretsManager:
  16161. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16162. properties:
  16163. forceDeleteWithoutRecovery:
  16164. description: |-
  16165. Specifies whether to delete the secret without any recovery window. You
  16166. can't use both this parameter and RecoveryWindowInDays in the same call.
  16167. If you don't use either, then by default Secrets Manager uses a 30 day
  16168. recovery window.
  16169. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16170. type: boolean
  16171. recoveryWindowInDays:
  16172. description: |-
  16173. The number of days from 7 to 30 that Secrets Manager waits before
  16174. permanently deleting the secret. You can't use both this parameter and
  16175. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16176. then by default Secrets Manager uses a 30-day recovery window.
  16177. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16178. format: int64
  16179. type: integer
  16180. type: object
  16181. service:
  16182. description: Service defines which service should be used to fetch the secrets
  16183. enum:
  16184. - SecretsManager
  16185. - ParameterStore
  16186. - CertificateManager
  16187. type: string
  16188. sessionTags:
  16189. description: AWS STS assume role session tags
  16190. items:
  16191. description: |-
  16192. Tag is a key-value pair that can be attached to an AWS resource.
  16193. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16194. properties:
  16195. key:
  16196. type: string
  16197. value:
  16198. type: string
  16199. required:
  16200. - key
  16201. - value
  16202. type: object
  16203. type: array
  16204. sessionTagsPolicy:
  16205. default: None
  16206. description: |-
  16207. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16208. None (default): no tags are added.
  16209. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16210. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16211. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16212. enum:
  16213. - None
  16214. - Simple
  16215. - Custom
  16216. type: string
  16217. transitiveTagKeys:
  16218. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16219. items:
  16220. type: string
  16221. type: array
  16222. required:
  16223. - region
  16224. - service
  16225. type: object
  16226. azurekv:
  16227. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16228. properties:
  16229. authSecretRef:
  16230. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16231. properties:
  16232. clientCertificate:
  16233. description: The Azure ClientCertificate of the service principle used for authentication.
  16234. properties:
  16235. key:
  16236. description: |-
  16237. A key in the referenced Secret.
  16238. Some instances of this field may be defaulted, in others it may be required.
  16239. maxLength: 253
  16240. minLength: 1
  16241. pattern: ^[-._a-zA-Z0-9]+$
  16242. type: string
  16243. name:
  16244. description: The name of the Secret resource being referred to.
  16245. maxLength: 253
  16246. minLength: 1
  16247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16248. type: string
  16249. namespace:
  16250. description: |-
  16251. The namespace of the Secret resource being referred to.
  16252. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16253. maxLength: 63
  16254. minLength: 1
  16255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16256. type: string
  16257. type: object
  16258. clientId:
  16259. description: The Azure clientId of the service principle or managed identity used for authentication.
  16260. properties:
  16261. key:
  16262. description: |-
  16263. A key in the referenced Secret.
  16264. Some instances of this field may be defaulted, in others it may be required.
  16265. maxLength: 253
  16266. minLength: 1
  16267. pattern: ^[-._a-zA-Z0-9]+$
  16268. type: string
  16269. name:
  16270. description: The name of the Secret resource being referred to.
  16271. maxLength: 253
  16272. minLength: 1
  16273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16274. type: string
  16275. namespace:
  16276. description: |-
  16277. The namespace of the Secret resource being referred to.
  16278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16279. maxLength: 63
  16280. minLength: 1
  16281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16282. type: string
  16283. type: object
  16284. clientSecret:
  16285. description: The Azure ClientSecret of the service principle used for authentication.
  16286. properties:
  16287. key:
  16288. description: |-
  16289. A key in the referenced Secret.
  16290. Some instances of this field may be defaulted, in others it may be required.
  16291. maxLength: 253
  16292. minLength: 1
  16293. pattern: ^[-._a-zA-Z0-9]+$
  16294. type: string
  16295. name:
  16296. description: The name of the Secret resource being referred to.
  16297. maxLength: 253
  16298. minLength: 1
  16299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16300. type: string
  16301. namespace:
  16302. description: |-
  16303. The namespace of the Secret resource being referred to.
  16304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16305. maxLength: 63
  16306. minLength: 1
  16307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16308. type: string
  16309. type: object
  16310. tenantId:
  16311. description: The Azure tenantId of the managed identity used for authentication.
  16312. properties:
  16313. key:
  16314. description: |-
  16315. A key in the referenced Secret.
  16316. Some instances of this field may be defaulted, in others it may be required.
  16317. maxLength: 253
  16318. minLength: 1
  16319. pattern: ^[-._a-zA-Z0-9]+$
  16320. type: string
  16321. name:
  16322. description: The name of the Secret resource being referred to.
  16323. maxLength: 253
  16324. minLength: 1
  16325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16326. type: string
  16327. namespace:
  16328. description: |-
  16329. The namespace of the Secret resource being referred to.
  16330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16331. maxLength: 63
  16332. minLength: 1
  16333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16334. type: string
  16335. type: object
  16336. type: object
  16337. authType:
  16338. default: ServicePrincipal
  16339. description: |-
  16340. Auth type defines how to authenticate to the keyvault service.
  16341. Valid values are:
  16342. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16343. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16344. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16345. enum:
  16346. - ServicePrincipal
  16347. - ManagedIdentity
  16348. - WorkloadIdentity
  16349. type: string
  16350. customCloudConfig:
  16351. description: |-
  16352. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16353. Required when EnvironmentType is AzureStackCloud.
  16354. Optional for other environment types - useful for Azure China when using Workload Identity
  16355. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16356. standard China Cloud endpoint (login.chinacloudapi.cn).
  16357. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16358. configuration is not supported with the legacy go-autorest SDK.
  16359. properties:
  16360. activeDirectoryEndpoint:
  16361. description: |-
  16362. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16363. Required when using custom cloud configuration
  16364. type: string
  16365. keyVaultDNSSuffix:
  16366. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16367. type: string
  16368. keyVaultEndpoint:
  16369. description: KeyVaultEndpoint is the Key Vault service endpoint
  16370. type: string
  16371. resourceManagerEndpoint:
  16372. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16373. type: string
  16374. required:
  16375. - activeDirectoryEndpoint
  16376. type: object
  16377. environmentType:
  16378. default: PublicCloud
  16379. description: |-
  16380. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16381. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16382. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16383. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16384. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16385. enum:
  16386. - PublicCloud
  16387. - USGovernmentCloud
  16388. - ChinaCloud
  16389. - GermanCloud
  16390. - AzureStackCloud
  16391. type: string
  16392. identityId:
  16393. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16394. type: string
  16395. serviceAccountRef:
  16396. description: |-
  16397. ServiceAccountRef specified the service account
  16398. that should be used when authenticating with WorkloadIdentity.
  16399. properties:
  16400. audiences:
  16401. description: |-
  16402. Audience specifies the `aud` claim for the service account token
  16403. Some providers automatically extend the audience field based on well-known annotations for workload
  16404. identity (e.g. IRSA or GCP Workload Identity)
  16405. items:
  16406. type: string
  16407. type: array
  16408. name:
  16409. description: The name of the ServiceAccount resource being referred to.
  16410. maxLength: 253
  16411. minLength: 1
  16412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16413. type: string
  16414. namespace:
  16415. description: |-
  16416. Namespace of the resource being referred to.
  16417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16418. maxLength: 63
  16419. minLength: 1
  16420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16421. type: string
  16422. required:
  16423. - name
  16424. type: object
  16425. tenantId:
  16426. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16427. type: string
  16428. useAzureSDK:
  16429. default: false
  16430. description: |-
  16431. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16432. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16433. type: boolean
  16434. vaultUrl:
  16435. description: Vault Url from which the secrets to be fetched from.
  16436. type: string
  16437. required:
  16438. - vaultUrl
  16439. type: object
  16440. barbican:
  16441. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16442. properties:
  16443. auth:
  16444. description: BarbicanAuth contains the authentication information for Barbican.
  16445. properties:
  16446. password:
  16447. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16448. properties:
  16449. secretRef:
  16450. description: |-
  16451. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16452. In some instances, `key` is a required field.
  16453. properties:
  16454. key:
  16455. description: |-
  16456. A key in the referenced Secret.
  16457. Some instances of this field may be defaulted, in others it may be required.
  16458. maxLength: 253
  16459. minLength: 1
  16460. pattern: ^[-._a-zA-Z0-9]+$
  16461. type: string
  16462. name:
  16463. description: The name of the Secret resource being referred to.
  16464. maxLength: 253
  16465. minLength: 1
  16466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16467. type: string
  16468. namespace:
  16469. description: |-
  16470. The namespace of the Secret resource being referred to.
  16471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16472. maxLength: 63
  16473. minLength: 1
  16474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16475. type: string
  16476. type: object
  16477. required:
  16478. - secretRef
  16479. type: object
  16480. username:
  16481. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16482. maxProperties: 1
  16483. minProperties: 1
  16484. properties:
  16485. secretRef:
  16486. description: |-
  16487. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16488. In some instances, `key` is a required field.
  16489. properties:
  16490. key:
  16491. description: |-
  16492. A key in the referenced Secret.
  16493. Some instances of this field may be defaulted, in others it may be required.
  16494. maxLength: 253
  16495. minLength: 1
  16496. pattern: ^[-._a-zA-Z0-9]+$
  16497. type: string
  16498. name:
  16499. description: The name of the Secret resource being referred to.
  16500. maxLength: 253
  16501. minLength: 1
  16502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16503. type: string
  16504. namespace:
  16505. description: |-
  16506. The namespace of the Secret resource being referred to.
  16507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16508. maxLength: 63
  16509. minLength: 1
  16510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16511. type: string
  16512. type: object
  16513. value:
  16514. type: string
  16515. type: object
  16516. required:
  16517. - password
  16518. - username
  16519. type: object
  16520. authURL:
  16521. type: string
  16522. domainName:
  16523. type: string
  16524. region:
  16525. type: string
  16526. tenantName:
  16527. type: string
  16528. required:
  16529. - auth
  16530. type: object
  16531. beyondtrust:
  16532. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16533. properties:
  16534. auth:
  16535. description: Auth configures how the operator authenticates with Beyondtrust.
  16536. properties:
  16537. apiKey:
  16538. description: APIKey If not provided then ClientID/ClientSecret become required.
  16539. properties:
  16540. secretRef:
  16541. description: SecretRef references a key in a secret that will be used as value.
  16542. properties:
  16543. key:
  16544. description: |-
  16545. A key in the referenced Secret.
  16546. Some instances of this field may be defaulted, in others it may be required.
  16547. maxLength: 253
  16548. minLength: 1
  16549. pattern: ^[-._a-zA-Z0-9]+$
  16550. type: string
  16551. name:
  16552. description: The name of the Secret resource being referred to.
  16553. maxLength: 253
  16554. minLength: 1
  16555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16556. type: string
  16557. namespace:
  16558. description: |-
  16559. The namespace of the Secret resource being referred to.
  16560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16561. maxLength: 63
  16562. minLength: 1
  16563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16564. type: string
  16565. type: object
  16566. value:
  16567. description: Value can be specified directly to set a value without using a secret.
  16568. type: string
  16569. type: object
  16570. certificate:
  16571. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16572. properties:
  16573. secretRef:
  16574. description: SecretRef references a key in a secret that will be used as value.
  16575. properties:
  16576. key:
  16577. description: |-
  16578. A key in the referenced Secret.
  16579. Some instances of this field may be defaulted, in others it may be required.
  16580. maxLength: 253
  16581. minLength: 1
  16582. pattern: ^[-._a-zA-Z0-9]+$
  16583. type: string
  16584. name:
  16585. description: The name of the Secret resource being referred to.
  16586. maxLength: 253
  16587. minLength: 1
  16588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16589. type: string
  16590. namespace:
  16591. description: |-
  16592. The namespace of the Secret resource being referred to.
  16593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16594. maxLength: 63
  16595. minLength: 1
  16596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16597. type: string
  16598. type: object
  16599. value:
  16600. description: Value can be specified directly to set a value without using a secret.
  16601. type: string
  16602. type: object
  16603. certificateKey:
  16604. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16605. properties:
  16606. secretRef:
  16607. description: SecretRef references a key in a secret that will be used as value.
  16608. properties:
  16609. key:
  16610. description: |-
  16611. A key in the referenced Secret.
  16612. Some instances of this field may be defaulted, in others it may be required.
  16613. maxLength: 253
  16614. minLength: 1
  16615. pattern: ^[-._a-zA-Z0-9]+$
  16616. type: string
  16617. name:
  16618. description: The name of the Secret resource being referred to.
  16619. maxLength: 253
  16620. minLength: 1
  16621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16622. type: string
  16623. namespace:
  16624. description: |-
  16625. The namespace of the Secret resource being referred to.
  16626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16627. maxLength: 63
  16628. minLength: 1
  16629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16630. type: string
  16631. type: object
  16632. value:
  16633. description: Value can be specified directly to set a value without using a secret.
  16634. type: string
  16635. type: object
  16636. clientId:
  16637. description: ClientID is the API OAuth Client ID.
  16638. properties:
  16639. secretRef:
  16640. description: SecretRef references a key in a secret that will be used as value.
  16641. properties:
  16642. key:
  16643. description: |-
  16644. A key in the referenced Secret.
  16645. Some instances of this field may be defaulted, in others it may be required.
  16646. maxLength: 253
  16647. minLength: 1
  16648. pattern: ^[-._a-zA-Z0-9]+$
  16649. type: string
  16650. name:
  16651. description: The name of the Secret resource being referred to.
  16652. maxLength: 253
  16653. minLength: 1
  16654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16655. type: string
  16656. namespace:
  16657. description: |-
  16658. The namespace of the Secret resource being referred to.
  16659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16660. maxLength: 63
  16661. minLength: 1
  16662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16663. type: string
  16664. type: object
  16665. value:
  16666. description: Value can be specified directly to set a value without using a secret.
  16667. type: string
  16668. type: object
  16669. clientSecret:
  16670. description: ClientSecret is the API OAuth Client Secret.
  16671. properties:
  16672. secretRef:
  16673. description: SecretRef references a key in a secret that will be used as value.
  16674. properties:
  16675. key:
  16676. description: |-
  16677. A key in the referenced Secret.
  16678. Some instances of this field may be defaulted, in others it may be required.
  16679. maxLength: 253
  16680. minLength: 1
  16681. pattern: ^[-._a-zA-Z0-9]+$
  16682. type: string
  16683. name:
  16684. description: The name of the Secret resource being referred to.
  16685. maxLength: 253
  16686. minLength: 1
  16687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16688. type: string
  16689. namespace:
  16690. description: |-
  16691. The namespace of the Secret resource being referred to.
  16692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16693. maxLength: 63
  16694. minLength: 1
  16695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16696. type: string
  16697. type: object
  16698. value:
  16699. description: Value can be specified directly to set a value without using a secret.
  16700. type: string
  16701. type: object
  16702. type: object
  16703. server:
  16704. description: Auth configures how API server works.
  16705. properties:
  16706. apiUrl:
  16707. type: string
  16708. apiVersion:
  16709. type: string
  16710. clientTimeOutSeconds:
  16711. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16712. type: integer
  16713. decrypt:
  16714. default: true
  16715. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16716. type: boolean
  16717. retrievalType:
  16718. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16719. type: string
  16720. separator:
  16721. description: A character that separates the folder names.
  16722. type: string
  16723. verifyCA:
  16724. type: boolean
  16725. required:
  16726. - apiUrl
  16727. - verifyCA
  16728. type: object
  16729. required:
  16730. - auth
  16731. - server
  16732. type: object
  16733. beyondtrustworkloadcredentials:
  16734. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16735. properties:
  16736. auth:
  16737. description: |-
  16738. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16739. Currently supports API key authentication via Kubernetes secret reference.
  16740. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16741. properties:
  16742. apikey:
  16743. description: |-
  16744. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16745. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16746. properties:
  16747. token:
  16748. description: |-
  16749. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16750. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16751. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16752. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16753. properties:
  16754. key:
  16755. description: |-
  16756. A key in the referenced Secret.
  16757. Some instances of this field may be defaulted, in others it may be required.
  16758. maxLength: 253
  16759. minLength: 1
  16760. pattern: ^[-._a-zA-Z0-9]+$
  16761. type: string
  16762. name:
  16763. description: The name of the Secret resource being referred to.
  16764. maxLength: 253
  16765. minLength: 1
  16766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16767. type: string
  16768. namespace:
  16769. description: |-
  16770. The namespace of the Secret resource being referred to.
  16771. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16772. maxLength: 63
  16773. minLength: 1
  16774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16775. type: string
  16776. type: object
  16777. required:
  16778. - token
  16779. type: object
  16780. required:
  16781. - apikey
  16782. type: object
  16783. caBundle:
  16784. description: |-
  16785. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16786. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16787. If not set, the system's trusted root certificates are used.
  16788. format: byte
  16789. type: string
  16790. caProvider:
  16791. description: |-
  16792. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16793. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16794. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16795. properties:
  16796. key:
  16797. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16798. maxLength: 253
  16799. minLength: 1
  16800. pattern: ^[-._a-zA-Z0-9]+$
  16801. type: string
  16802. name:
  16803. description: The name of the object located at the provider type.
  16804. maxLength: 253
  16805. minLength: 1
  16806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16807. type: string
  16808. namespace:
  16809. description: |-
  16810. The namespace the Provider type is in.
  16811. Can only be defined when used in a ClusterSecretStore.
  16812. maxLength: 63
  16813. minLength: 1
  16814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16815. type: string
  16816. type:
  16817. description: The type of provider to use such as "Secret", or "ConfigMap".
  16818. enum:
  16819. - Secret
  16820. - ConfigMap
  16821. type: string
  16822. required:
  16823. - name
  16824. - type
  16825. type: object
  16826. folderPath:
  16827. description: |-
  16828. FolderPath specifies the default folder path for secret retrieval.
  16829. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16830. Example: "production/database" or "dev/api-keys"
  16831. Leave empty to retrieve secrets from the root folder.
  16832. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16833. type: string
  16834. server:
  16835. description: |-
  16836. Server configures the BeyondTrust Workload Credentials server connection details.
  16837. Includes the API URL and Site ID for your BeyondTrust instance.
  16838. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16839. properties:
  16840. apiUrl:
  16841. description: |-
  16842. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16843. This should be the full URL to your BeyondTrust instance.
  16844. Example: https://api.beyondtrust.io/siie
  16845. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16846. type: string
  16847. siteId:
  16848. description: |-
  16849. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16850. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16851. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16852. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16853. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16854. type: string
  16855. required:
  16856. - apiUrl
  16857. - siteId
  16858. type: object
  16859. required:
  16860. - auth
  16861. - server
  16862. type: object
  16863. bitwardensecretsmanager:
  16864. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16865. properties:
  16866. apiURL:
  16867. type: string
  16868. auth:
  16869. description: |-
  16870. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16871. Make sure that the token being used has permissions on the given secret.
  16872. properties:
  16873. secretRef:
  16874. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16875. properties:
  16876. credentials:
  16877. description: AccessToken used for the bitwarden instance.
  16878. properties:
  16879. key:
  16880. description: |-
  16881. A key in the referenced Secret.
  16882. Some instances of this field may be defaulted, in others it may be required.
  16883. maxLength: 253
  16884. minLength: 1
  16885. pattern: ^[-._a-zA-Z0-9]+$
  16886. type: string
  16887. name:
  16888. description: The name of the Secret resource being referred to.
  16889. maxLength: 253
  16890. minLength: 1
  16891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16892. type: string
  16893. namespace:
  16894. description: |-
  16895. The namespace of the Secret resource being referred to.
  16896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16897. maxLength: 63
  16898. minLength: 1
  16899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16900. type: string
  16901. type: object
  16902. required:
  16903. - credentials
  16904. type: object
  16905. required:
  16906. - secretRef
  16907. type: object
  16908. bitwardenServerSDKURL:
  16909. type: string
  16910. caBundle:
  16911. description: |-
  16912. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16913. can be performed.
  16914. type: string
  16915. caProvider:
  16916. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16917. properties:
  16918. key:
  16919. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16920. maxLength: 253
  16921. minLength: 1
  16922. pattern: ^[-._a-zA-Z0-9]+$
  16923. type: string
  16924. name:
  16925. description: The name of the object located at the provider type.
  16926. maxLength: 253
  16927. minLength: 1
  16928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16929. type: string
  16930. namespace:
  16931. description: |-
  16932. The namespace the Provider type is in.
  16933. Can only be defined when used in a ClusterSecretStore.
  16934. maxLength: 63
  16935. minLength: 1
  16936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16937. type: string
  16938. type:
  16939. description: The type of provider to use such as "Secret", or "ConfigMap".
  16940. enum:
  16941. - Secret
  16942. - ConfigMap
  16943. type: string
  16944. required:
  16945. - name
  16946. - type
  16947. type: object
  16948. identityURL:
  16949. type: string
  16950. organizationID:
  16951. description: OrganizationID determines which organization this secret store manages.
  16952. type: string
  16953. projectID:
  16954. description: ProjectID determines which project this secret store manages.
  16955. type: string
  16956. required:
  16957. - auth
  16958. - organizationID
  16959. - projectID
  16960. type: object
  16961. chef:
  16962. description: Chef configures this store to sync secrets with chef server
  16963. properties:
  16964. auth:
  16965. description: Auth defines the information necessary to authenticate against chef Server
  16966. properties:
  16967. secretRef:
  16968. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16969. properties:
  16970. privateKeySecretRef:
  16971. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16972. properties:
  16973. key:
  16974. description: |-
  16975. A key in the referenced Secret.
  16976. Some instances of this field may be defaulted, in others it may be required.
  16977. maxLength: 253
  16978. minLength: 1
  16979. pattern: ^[-._a-zA-Z0-9]+$
  16980. type: string
  16981. name:
  16982. description: The name of the Secret resource being referred to.
  16983. maxLength: 253
  16984. minLength: 1
  16985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16986. type: string
  16987. namespace:
  16988. description: |-
  16989. The namespace of the Secret resource being referred to.
  16990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16991. maxLength: 63
  16992. minLength: 1
  16993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16994. type: string
  16995. type: object
  16996. required:
  16997. - privateKeySecretRef
  16998. type: object
  16999. required:
  17000. - secretRef
  17001. type: object
  17002. serverUrl:
  17003. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  17004. type: string
  17005. username:
  17006. description: UserName should be the user ID on the chef server
  17007. type: string
  17008. required:
  17009. - auth
  17010. - serverUrl
  17011. - username
  17012. type: object
  17013. cloudrusm:
  17014. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  17015. properties:
  17016. auth:
  17017. description: CSMAuth contains a secretRef for credentials.
  17018. properties:
  17019. secretRef:
  17020. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  17021. properties:
  17022. accessKeyIDSecretRef:
  17023. description: The AccessKeyID is used for authentication
  17024. properties:
  17025. key:
  17026. description: |-
  17027. A key in the referenced Secret.
  17028. Some instances of this field may be defaulted, in others it may be required.
  17029. maxLength: 253
  17030. minLength: 1
  17031. pattern: ^[-._a-zA-Z0-9]+$
  17032. type: string
  17033. name:
  17034. description: The name of the Secret resource being referred to.
  17035. maxLength: 253
  17036. minLength: 1
  17037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17038. type: string
  17039. namespace:
  17040. description: |-
  17041. The namespace of the Secret resource being referred to.
  17042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17043. maxLength: 63
  17044. minLength: 1
  17045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17046. type: string
  17047. type: object
  17048. accessKeySecretSecretRef:
  17049. description: The AccessKeySecret is used for authentication
  17050. properties:
  17051. key:
  17052. description: |-
  17053. A key in the referenced Secret.
  17054. Some instances of this field may be defaulted, in others it may be required.
  17055. maxLength: 253
  17056. minLength: 1
  17057. pattern: ^[-._a-zA-Z0-9]+$
  17058. type: string
  17059. name:
  17060. description: The name of the Secret resource being referred to.
  17061. maxLength: 253
  17062. minLength: 1
  17063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17064. type: string
  17065. namespace:
  17066. description: |-
  17067. The namespace of the Secret resource being referred to.
  17068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17069. maxLength: 63
  17070. minLength: 1
  17071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17072. type: string
  17073. type: object
  17074. required:
  17075. - accessKeyIDSecretRef
  17076. - accessKeySecretSecretRef
  17077. type: object
  17078. type: object
  17079. projectID:
  17080. description: ProjectID is the project, which the secrets are stored in.
  17081. type: string
  17082. required:
  17083. - auth
  17084. type: object
  17085. conjur:
  17086. description: Conjur configures this store to sync secrets using conjur provider
  17087. properties:
  17088. auth:
  17089. description: Defines authentication settings for connecting to Conjur.
  17090. maxProperties: 1
  17091. minProperties: 1
  17092. properties:
  17093. apikey:
  17094. description: Authenticates with Conjur using an API key.
  17095. properties:
  17096. account:
  17097. description: Account is the Conjur organization account name.
  17098. type: string
  17099. apiKeyRef:
  17100. description: |-
  17101. A reference to a specific 'key' containing the Conjur API key
  17102. within a Secret resource. In some instances, `key` is a required field.
  17103. properties:
  17104. key:
  17105. description: |-
  17106. A key in the referenced Secret.
  17107. Some instances of this field may be defaulted, in others it may be required.
  17108. maxLength: 253
  17109. minLength: 1
  17110. pattern: ^[-._a-zA-Z0-9]+$
  17111. type: string
  17112. name:
  17113. description: The name of the Secret resource being referred to.
  17114. maxLength: 253
  17115. minLength: 1
  17116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17117. type: string
  17118. namespace:
  17119. description: |-
  17120. The namespace of the Secret resource being referred to.
  17121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17122. maxLength: 63
  17123. minLength: 1
  17124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17125. type: string
  17126. type: object
  17127. userRef:
  17128. description: |-
  17129. A reference to a specific 'key' containing the Conjur username
  17130. within a Secret resource. In some instances, `key` is a required field.
  17131. properties:
  17132. key:
  17133. description: |-
  17134. A key in the referenced Secret.
  17135. Some instances of this field may be defaulted, in others it may be required.
  17136. maxLength: 253
  17137. minLength: 1
  17138. pattern: ^[-._a-zA-Z0-9]+$
  17139. type: string
  17140. name:
  17141. description: The name of the Secret resource being referred to.
  17142. maxLength: 253
  17143. minLength: 1
  17144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17145. type: string
  17146. namespace:
  17147. description: |-
  17148. The namespace of the Secret resource being referred to.
  17149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17150. maxLength: 63
  17151. minLength: 1
  17152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17153. type: string
  17154. type: object
  17155. required:
  17156. - account
  17157. - apiKeyRef
  17158. - userRef
  17159. type: object
  17160. cert:
  17161. description: Cert enables certificate-based authentication using a client certificate and key.
  17162. properties:
  17163. account:
  17164. description: Account is the Conjur organization account name.
  17165. type: string
  17166. clientCertRef:
  17167. description: |-
  17168. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17169. within a Secret resource. The certificate must be PEM-encoded.
  17170. properties:
  17171. key:
  17172. description: |-
  17173. A key in the referenced Secret.
  17174. Some instances of this field may be defaulted, in others it may be required.
  17175. maxLength: 253
  17176. minLength: 1
  17177. pattern: ^[-._a-zA-Z0-9]+$
  17178. type: string
  17179. name:
  17180. description: The name of the Secret resource being referred to.
  17181. maxLength: 253
  17182. minLength: 1
  17183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17184. type: string
  17185. namespace:
  17186. description: |-
  17187. The namespace of the Secret resource being referred to.
  17188. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17189. maxLength: 63
  17190. minLength: 1
  17191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17192. type: string
  17193. type: object
  17194. clientKeyRef:
  17195. description: |-
  17196. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17197. within a Secret resource. The key must be PEM-encoded.
  17198. properties:
  17199. key:
  17200. description: |-
  17201. A key in the referenced Secret.
  17202. Some instances of this field may be defaulted, in others it may be required.
  17203. maxLength: 253
  17204. minLength: 1
  17205. pattern: ^[-._a-zA-Z0-9]+$
  17206. type: string
  17207. name:
  17208. description: The name of the Secret resource being referred to.
  17209. maxLength: 253
  17210. minLength: 1
  17211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17212. type: string
  17213. namespace:
  17214. description: |-
  17215. The namespace of the Secret resource being referred to.
  17216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17217. maxLength: 63
  17218. minLength: 1
  17219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17220. type: string
  17221. type: object
  17222. hostId:
  17223. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17224. type: string
  17225. serviceID:
  17226. description: The conjur authn cert webservice id
  17227. type: string
  17228. required:
  17229. - account
  17230. - clientCertRef
  17231. - clientKeyRef
  17232. - serviceID
  17233. type: object
  17234. jwt:
  17235. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17236. properties:
  17237. account:
  17238. description: Account is the Conjur organization account name.
  17239. type: string
  17240. hostId:
  17241. description: |-
  17242. Optional HostID for JWT authentication. This may be used depending
  17243. on how the Conjur JWT authenticator policy is configured.
  17244. type: string
  17245. secretRef:
  17246. description: |-
  17247. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17248. authenticate with Conjur using the JWT authentication method.
  17249. properties:
  17250. key:
  17251. description: |-
  17252. A key in the referenced Secret.
  17253. Some instances of this field may be defaulted, in others it may be required.
  17254. maxLength: 253
  17255. minLength: 1
  17256. pattern: ^[-._a-zA-Z0-9]+$
  17257. type: string
  17258. name:
  17259. description: The name of the Secret resource being referred to.
  17260. maxLength: 253
  17261. minLength: 1
  17262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17263. type: string
  17264. namespace:
  17265. description: |-
  17266. The namespace of the Secret resource being referred to.
  17267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17268. maxLength: 63
  17269. minLength: 1
  17270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17271. type: string
  17272. type: object
  17273. serviceAccountRef:
  17274. description: |-
  17275. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17276. a token for with the `TokenRequest` API.
  17277. properties:
  17278. audiences:
  17279. description: |-
  17280. Audience specifies the `aud` claim for the service account token
  17281. Some providers automatically extend the audience field based on well-known annotations for workload
  17282. identity (e.g. IRSA or GCP Workload Identity)
  17283. items:
  17284. type: string
  17285. type: array
  17286. name:
  17287. description: The name of the ServiceAccount resource being referred to.
  17288. maxLength: 253
  17289. minLength: 1
  17290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17291. type: string
  17292. namespace:
  17293. description: |-
  17294. Namespace of the resource being referred to.
  17295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17296. maxLength: 63
  17297. minLength: 1
  17298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17299. type: string
  17300. required:
  17301. - name
  17302. type: object
  17303. serviceID:
  17304. description: The conjur authn jwt webservice id
  17305. type: string
  17306. required:
  17307. - account
  17308. - serviceID
  17309. type: object
  17310. type: object
  17311. caBundle:
  17312. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17313. type: string
  17314. caProvider:
  17315. description: |-
  17316. Used to provide custom certificate authority (CA) certificates
  17317. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17318. that contains a PEM-encoded certificate.
  17319. properties:
  17320. key:
  17321. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17322. maxLength: 253
  17323. minLength: 1
  17324. pattern: ^[-._a-zA-Z0-9]+$
  17325. type: string
  17326. name:
  17327. description: The name of the object located at the provider type.
  17328. maxLength: 253
  17329. minLength: 1
  17330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17331. type: string
  17332. namespace:
  17333. description: |-
  17334. The namespace the Provider type is in.
  17335. Can only be defined when used in a ClusterSecretStore.
  17336. maxLength: 63
  17337. minLength: 1
  17338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17339. type: string
  17340. type:
  17341. description: The type of provider to use such as "Secret", or "ConfigMap".
  17342. enum:
  17343. - Secret
  17344. - ConfigMap
  17345. type: string
  17346. required:
  17347. - name
  17348. - type
  17349. type: object
  17350. url:
  17351. description: URL is the endpoint of the Conjur instance.
  17352. type: string
  17353. required:
  17354. - auth
  17355. - url
  17356. type: object
  17357. crd:
  17358. description: |-
  17359. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17360. including both custom resources (CRDs) and core API resources. Resources are
  17361. selected by API group, version and kind, where group can be "" (empty string)
  17362. for core resources such as ConfigMap. Reading the core v1 Secret is
  17363. intentionally blocked — use the Kubernetes provider for that.
  17364. properties:
  17365. auth:
  17366. description: |-
  17367. Auth configures authentication to the Kubernetes API, same as the
  17368. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17369. maxProperties: 1
  17370. minProperties: 1
  17371. properties:
  17372. cert:
  17373. description: has both clientCert and clientKey as secretKeySelector
  17374. properties:
  17375. clientCert:
  17376. description: |-
  17377. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17378. In some instances, `key` is a required field.
  17379. properties:
  17380. key:
  17381. description: |-
  17382. A key in the referenced Secret.
  17383. Some instances of this field may be defaulted, in others it may be required.
  17384. maxLength: 253
  17385. minLength: 1
  17386. pattern: ^[-._a-zA-Z0-9]+$
  17387. type: string
  17388. name:
  17389. description: The name of the Secret resource being referred to.
  17390. maxLength: 253
  17391. minLength: 1
  17392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17393. type: string
  17394. namespace:
  17395. description: |-
  17396. The namespace of the Secret resource being referred to.
  17397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17398. maxLength: 63
  17399. minLength: 1
  17400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17401. type: string
  17402. type: object
  17403. clientKey:
  17404. description: |-
  17405. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17406. In some instances, `key` is a required field.
  17407. properties:
  17408. key:
  17409. description: |-
  17410. A key in the referenced Secret.
  17411. Some instances of this field may be defaulted, in others it may be required.
  17412. maxLength: 253
  17413. minLength: 1
  17414. pattern: ^[-._a-zA-Z0-9]+$
  17415. type: string
  17416. name:
  17417. description: The name of the Secret resource being referred to.
  17418. maxLength: 253
  17419. minLength: 1
  17420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17421. type: string
  17422. namespace:
  17423. description: |-
  17424. The namespace of the Secret resource being referred to.
  17425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17426. maxLength: 63
  17427. minLength: 1
  17428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17429. type: string
  17430. type: object
  17431. required:
  17432. - clientCert
  17433. - clientKey
  17434. type: object
  17435. serviceAccount:
  17436. description: points to a service account that should be used for authentication
  17437. properties:
  17438. audiences:
  17439. description: |-
  17440. Audience specifies the `aud` claim for the service account token
  17441. Some providers automatically extend the audience field based on well-known annotations for workload
  17442. identity (e.g. IRSA or GCP Workload Identity)
  17443. items:
  17444. type: string
  17445. type: array
  17446. name:
  17447. description: The name of the ServiceAccount resource being referred to.
  17448. maxLength: 253
  17449. minLength: 1
  17450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17451. type: string
  17452. namespace:
  17453. description: |-
  17454. Namespace of the resource being referred to.
  17455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17456. maxLength: 63
  17457. minLength: 1
  17458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17459. type: string
  17460. required:
  17461. - name
  17462. type: object
  17463. token:
  17464. description: use static token to authenticate with
  17465. properties:
  17466. bearerToken:
  17467. description: |-
  17468. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17469. In some instances, `key` is a required field.
  17470. properties:
  17471. key:
  17472. description: |-
  17473. A key in the referenced Secret.
  17474. Some instances of this field may be defaulted, in others it may be required.
  17475. maxLength: 253
  17476. minLength: 1
  17477. pattern: ^[-._a-zA-Z0-9]+$
  17478. type: string
  17479. name:
  17480. description: The name of the Secret resource being referred to.
  17481. maxLength: 253
  17482. minLength: 1
  17483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17484. type: string
  17485. namespace:
  17486. description: |-
  17487. The namespace of the Secret resource being referred to.
  17488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17489. maxLength: 63
  17490. minLength: 1
  17491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17492. type: string
  17493. type: object
  17494. required:
  17495. - bearerToken
  17496. type: object
  17497. type: object
  17498. authRef:
  17499. description: |-
  17500. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17501. Kubernetes provider.
  17502. properties:
  17503. key:
  17504. description: |-
  17505. A key in the referenced Secret.
  17506. Some instances of this field may be defaulted, in others it may be required.
  17507. maxLength: 253
  17508. minLength: 1
  17509. pattern: ^[-._a-zA-Z0-9]+$
  17510. type: string
  17511. name:
  17512. description: The name of the Secret resource being referred to.
  17513. maxLength: 253
  17514. minLength: 1
  17515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17516. type: string
  17517. namespace:
  17518. description: |-
  17519. The namespace of the Secret resource being referred to.
  17520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17521. maxLength: 63
  17522. minLength: 1
  17523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17524. type: string
  17525. type: object
  17526. resource:
  17527. description: Resource identifies the CRD by its API group, version and kind.
  17528. properties:
  17529. group:
  17530. description: |-
  17531. Group is the API group of the resource. Use "" (empty string) for core
  17532. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17533. for a CRD. The field is required to be present in the manifest — write
  17534. `group: ""` explicitly for core resources so typos fail at admission
  17535. time rather than later at discovery.
  17536. type: string
  17537. kind:
  17538. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17539. minLength: 1
  17540. type: string
  17541. version:
  17542. description: Version is the API version of the resource (e.g. "v1alpha1").
  17543. minLength: 1
  17544. type: string
  17545. required:
  17546. - group
  17547. - kind
  17548. - version
  17549. type: object
  17550. server:
  17551. description: |-
  17552. Server configures the Kubernetes API address and TLS trust, same as the
  17553. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17554. properties:
  17555. caBundle:
  17556. description: CABundle is a base64-encoded CA certificate
  17557. format: byte
  17558. type: string
  17559. caProvider:
  17560. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17561. properties:
  17562. key:
  17563. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17564. maxLength: 253
  17565. minLength: 1
  17566. pattern: ^[-._a-zA-Z0-9]+$
  17567. type: string
  17568. name:
  17569. description: The name of the object located at the provider type.
  17570. maxLength: 253
  17571. minLength: 1
  17572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17573. type: string
  17574. namespace:
  17575. description: |-
  17576. The namespace the Provider type is in.
  17577. Can only be defined when used in a ClusterSecretStore.
  17578. maxLength: 63
  17579. minLength: 1
  17580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17581. type: string
  17582. type:
  17583. description: The type of provider to use such as "Secret", or "ConfigMap".
  17584. enum:
  17585. - Secret
  17586. - ConfigMap
  17587. type: string
  17588. required:
  17589. - name
  17590. - type
  17591. type: object
  17592. url:
  17593. default: kubernetes.default
  17594. description: configures the Kubernetes server Address.
  17595. type: string
  17596. type: object
  17597. whitelist:
  17598. description: |-
  17599. Whitelist optionally restricts which object names and requested properties
  17600. are allowed to be read.
  17601. properties:
  17602. rules:
  17603. description: |-
  17604. Rules is a list of allow rules. If rules are set, at least one rule must
  17605. match for a request to be allowed.
  17606. items:
  17607. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17608. properties:
  17609. name:
  17610. description: |-
  17611. Name is an optional regular expression matched against the bare object name.
  17612. For both SecretStore and ClusterSecretStore this is always the object name
  17613. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17614. type: string
  17615. namespace:
  17616. description: |-
  17617. Namespace is an optional regular expression matched against the namespace of
  17618. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17619. for SecretStore (where the namespace is fixed to the store namespace).
  17620. type: string
  17621. properties:
  17622. description: |-
  17623. Properties is an optional list of regular expressions matched against
  17624. requested property keys (for example: "spec.secretValue").
  17625. items:
  17626. type: string
  17627. type: array
  17628. type: object
  17629. type: array
  17630. type: object
  17631. required:
  17632. - resource
  17633. type: object
  17634. x-kubernetes-validations:
  17635. - message: one of auth or authRef is required
  17636. rule: has(self.auth) || has(self.authRef)
  17637. - message: at most one of the fields in [auth authRef] may be set
  17638. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17639. delinea:
  17640. description: |-
  17641. Delinea DevOps Secrets Vault
  17642. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17643. properties:
  17644. clientId:
  17645. description: ClientID is the non-secret part of the credential.
  17646. properties:
  17647. secretRef:
  17648. description: SecretRef references a key in a secret that will be used as value.
  17649. properties:
  17650. key:
  17651. description: |-
  17652. A key in the referenced Secret.
  17653. Some instances of this field may be defaulted, in others it may be required.
  17654. maxLength: 253
  17655. minLength: 1
  17656. pattern: ^[-._a-zA-Z0-9]+$
  17657. type: string
  17658. name:
  17659. description: The name of the Secret resource being referred to.
  17660. maxLength: 253
  17661. minLength: 1
  17662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17663. type: string
  17664. namespace:
  17665. description: |-
  17666. The namespace of the Secret resource being referred to.
  17667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17668. maxLength: 63
  17669. minLength: 1
  17670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17671. type: string
  17672. type: object
  17673. value:
  17674. description: Value can be specified directly to set a value without using a secret.
  17675. type: string
  17676. type: object
  17677. clientSecret:
  17678. description: ClientSecret is the secret part of the credential.
  17679. properties:
  17680. secretRef:
  17681. description: SecretRef references a key in a secret that will be used as value.
  17682. properties:
  17683. key:
  17684. description: |-
  17685. A key in the referenced Secret.
  17686. Some instances of this field may be defaulted, in others it may be required.
  17687. maxLength: 253
  17688. minLength: 1
  17689. pattern: ^[-._a-zA-Z0-9]+$
  17690. type: string
  17691. name:
  17692. description: The name of the Secret resource being referred to.
  17693. maxLength: 253
  17694. minLength: 1
  17695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17696. type: string
  17697. namespace:
  17698. description: |-
  17699. The namespace of the Secret resource being referred to.
  17700. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17701. maxLength: 63
  17702. minLength: 1
  17703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17704. type: string
  17705. type: object
  17706. value:
  17707. description: Value can be specified directly to set a value without using a secret.
  17708. type: string
  17709. type: object
  17710. tenant:
  17711. description: Tenant is the chosen hostname / site name.
  17712. type: string
  17713. tld:
  17714. description: |-
  17715. TLD is based on the server location that was chosen during provisioning.
  17716. If unset, defaults to "com".
  17717. type: string
  17718. urlTemplate:
  17719. description: |-
  17720. URLTemplate
  17721. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17722. type: string
  17723. required:
  17724. - clientId
  17725. - clientSecret
  17726. - tenant
  17727. type: object
  17728. doppler:
  17729. description: Doppler configures this store to sync secrets using the Doppler provider
  17730. properties:
  17731. auth:
  17732. description: Auth configures how the Operator authenticates with the Doppler API
  17733. properties:
  17734. oidcConfig:
  17735. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17736. properties:
  17737. expirationSeconds:
  17738. default: 600
  17739. description: |-
  17740. ExpirationSeconds sets the ServiceAccount token validity duration.
  17741. Defaults to 10 minutes.
  17742. format: int64
  17743. type: integer
  17744. identity:
  17745. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17746. type: string
  17747. serviceAccountRef:
  17748. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17749. properties:
  17750. audiences:
  17751. description: |-
  17752. Audience specifies the `aud` claim for the service account token
  17753. Some providers automatically extend the audience field based on well-known annotations for workload
  17754. identity (e.g. IRSA or GCP Workload Identity)
  17755. items:
  17756. type: string
  17757. type: array
  17758. name:
  17759. description: The name of the ServiceAccount resource being referred to.
  17760. maxLength: 253
  17761. minLength: 1
  17762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17763. type: string
  17764. namespace:
  17765. description: |-
  17766. Namespace of the resource being referred to.
  17767. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17768. maxLength: 63
  17769. minLength: 1
  17770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17771. type: string
  17772. required:
  17773. - name
  17774. type: object
  17775. required:
  17776. - identity
  17777. - serviceAccountRef
  17778. type: object
  17779. secretRef:
  17780. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17781. properties:
  17782. dopplerToken:
  17783. description: |-
  17784. The DopplerToken is used for authentication.
  17785. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17786. The Key attribute defaults to dopplerToken if not specified.
  17787. properties:
  17788. key:
  17789. description: |-
  17790. A key in the referenced Secret.
  17791. Some instances of this field may be defaulted, in others it may be required.
  17792. maxLength: 253
  17793. minLength: 1
  17794. pattern: ^[-._a-zA-Z0-9]+$
  17795. type: string
  17796. name:
  17797. description: The name of the Secret resource being referred to.
  17798. maxLength: 253
  17799. minLength: 1
  17800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17801. type: string
  17802. namespace:
  17803. description: |-
  17804. The namespace of the Secret resource being referred to.
  17805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17806. maxLength: 63
  17807. minLength: 1
  17808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17809. type: string
  17810. type: object
  17811. required:
  17812. - dopplerToken
  17813. type: object
  17814. type: object
  17815. x-kubernetes-validations:
  17816. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17817. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17818. config:
  17819. description: Doppler config (required if not using a Service Token)
  17820. type: string
  17821. format:
  17822. description: Format enables the downloading of secrets as a file (string)
  17823. enum:
  17824. - json
  17825. - dotnet-json
  17826. - env
  17827. - yaml
  17828. - docker
  17829. type: string
  17830. nameTransformer:
  17831. description: Environment variable compatible name transforms that change secret names to a different format
  17832. enum:
  17833. - upper-camel
  17834. - camel
  17835. - lower-snake
  17836. - tf-var
  17837. - dotnet-env
  17838. - lower-kebab
  17839. type: string
  17840. project:
  17841. description: Doppler project (required if not using a Service Token)
  17842. type: string
  17843. required:
  17844. - auth
  17845. type: object
  17846. dvls:
  17847. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17848. properties:
  17849. auth:
  17850. description: Auth defines the authentication method to use.
  17851. properties:
  17852. secretRef:
  17853. description: SecretRef contains the Application ID and Application Secret for authentication.
  17854. properties:
  17855. appId:
  17856. description: AppID is the reference to the secret containing the Application ID.
  17857. properties:
  17858. key:
  17859. description: |-
  17860. A key in the referenced Secret.
  17861. Some instances of this field may be defaulted, in others it may be required.
  17862. maxLength: 253
  17863. minLength: 1
  17864. pattern: ^[-._a-zA-Z0-9]+$
  17865. type: string
  17866. name:
  17867. description: The name of the Secret resource being referred to.
  17868. maxLength: 253
  17869. minLength: 1
  17870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17871. type: string
  17872. namespace:
  17873. description: |-
  17874. The namespace of the Secret resource being referred to.
  17875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17876. maxLength: 63
  17877. minLength: 1
  17878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17879. type: string
  17880. type: object
  17881. appSecret:
  17882. description: AppSecret is the reference to the secret containing the Application Secret.
  17883. properties:
  17884. key:
  17885. description: |-
  17886. A key in the referenced Secret.
  17887. Some instances of this field may be defaulted, in others it may be required.
  17888. maxLength: 253
  17889. minLength: 1
  17890. pattern: ^[-._a-zA-Z0-9]+$
  17891. type: string
  17892. name:
  17893. description: The name of the Secret resource being referred to.
  17894. maxLength: 253
  17895. minLength: 1
  17896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17897. type: string
  17898. namespace:
  17899. description: |-
  17900. The namespace of the Secret resource being referred to.
  17901. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17902. maxLength: 63
  17903. minLength: 1
  17904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17905. type: string
  17906. type: object
  17907. required:
  17908. - appId
  17909. - appSecret
  17910. type: object
  17911. required:
  17912. - secretRef
  17913. type: object
  17914. insecure:
  17915. description: |-
  17916. Insecure allows connecting to DVLS over plain HTTP.
  17917. This is NOT RECOMMENDED for production use.
  17918. Set to true only if you understand the security implications.
  17919. type: boolean
  17920. serverUrl:
  17921. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17922. type: string
  17923. vault:
  17924. description: |-
  17925. Vault is the name or UUID of the vault to fetch secrets from.
  17926. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17927. type: string
  17928. required:
  17929. - auth
  17930. - serverUrl
  17931. type: object
  17932. fake:
  17933. description: Fake configures a store with static key/value pairs
  17934. properties:
  17935. data:
  17936. items:
  17937. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17938. properties:
  17939. key:
  17940. type: string
  17941. value:
  17942. type: string
  17943. version:
  17944. type: string
  17945. required:
  17946. - key
  17947. - value
  17948. type: object
  17949. type: array
  17950. validationResult:
  17951. description: ValidationResult is defined type for the number of validation results.
  17952. type: integer
  17953. required:
  17954. - data
  17955. type: object
  17956. fortanix:
  17957. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17958. properties:
  17959. apiKey:
  17960. description: APIKey is the API token to access SDKMS Applications.
  17961. properties:
  17962. secretRef:
  17963. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17964. properties:
  17965. key:
  17966. description: |-
  17967. A key in the referenced Secret.
  17968. Some instances of this field may be defaulted, in others it may be required.
  17969. maxLength: 253
  17970. minLength: 1
  17971. pattern: ^[-._a-zA-Z0-9]+$
  17972. type: string
  17973. name:
  17974. description: The name of the Secret resource being referred to.
  17975. maxLength: 253
  17976. minLength: 1
  17977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17978. type: string
  17979. namespace:
  17980. description: |-
  17981. The namespace of the Secret resource being referred to.
  17982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17983. maxLength: 63
  17984. minLength: 1
  17985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17986. type: string
  17987. type: object
  17988. type: object
  17989. apiUrl:
  17990. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17991. type: string
  17992. type: object
  17993. gcpsm:
  17994. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17995. properties:
  17996. auth:
  17997. description: Auth defines the information necessary to authenticate against GCP
  17998. properties:
  17999. secretRef:
  18000. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  18001. properties:
  18002. secretAccessKeySecretRef:
  18003. description: The SecretAccessKey is used for authentication
  18004. properties:
  18005. key:
  18006. description: |-
  18007. A key in the referenced Secret.
  18008. Some instances of this field may be defaulted, in others it may be required.
  18009. maxLength: 253
  18010. minLength: 1
  18011. pattern: ^[-._a-zA-Z0-9]+$
  18012. type: string
  18013. name:
  18014. description: The name of the Secret resource being referred to.
  18015. maxLength: 253
  18016. minLength: 1
  18017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18018. type: string
  18019. namespace:
  18020. description: |-
  18021. The namespace of the Secret resource being referred to.
  18022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18023. maxLength: 63
  18024. minLength: 1
  18025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18026. type: string
  18027. type: object
  18028. type: object
  18029. workloadIdentity:
  18030. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  18031. properties:
  18032. clusterLocation:
  18033. description: |-
  18034. ClusterLocation is the location of the cluster
  18035. If not specified, it fetches information from the metadata server
  18036. type: string
  18037. clusterName:
  18038. description: |-
  18039. ClusterName is the name of the cluster
  18040. If not specified, it fetches information from the metadata server
  18041. type: string
  18042. clusterProjectID:
  18043. description: |-
  18044. ClusterProjectID is the project ID of the cluster
  18045. If not specified, it fetches information from the metadata server
  18046. type: string
  18047. serviceAccountRef:
  18048. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  18049. properties:
  18050. audiences:
  18051. description: |-
  18052. Audience specifies the `aud` claim for the service account token
  18053. Some providers automatically extend the audience field based on well-known annotations for workload
  18054. identity (e.g. IRSA or GCP Workload Identity)
  18055. items:
  18056. type: string
  18057. type: array
  18058. name:
  18059. description: The name of the ServiceAccount resource being referred to.
  18060. maxLength: 253
  18061. minLength: 1
  18062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18063. type: string
  18064. namespace:
  18065. description: |-
  18066. Namespace of the resource being referred to.
  18067. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18068. maxLength: 63
  18069. minLength: 1
  18070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18071. type: string
  18072. required:
  18073. - name
  18074. type: object
  18075. required:
  18076. - serviceAccountRef
  18077. type: object
  18078. workloadIdentityFederation:
  18079. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  18080. properties:
  18081. audience:
  18082. description: |-
  18083. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  18084. If specified, Audience found in the external account credential config will be overridden with the configured value.
  18085. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18086. type: string
  18087. awsSecurityCredentials:
  18088. description: |-
  18089. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18090. when using the AWS metadata server is not an option.
  18091. properties:
  18092. awsCredentialsSecretRef:
  18093. description: |-
  18094. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18095. Secret should be created with below names for keys
  18096. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18097. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18098. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18099. properties:
  18100. name:
  18101. description: name of the secret.
  18102. maxLength: 253
  18103. minLength: 1
  18104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18105. type: string
  18106. namespace:
  18107. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18108. maxLength: 63
  18109. minLength: 1
  18110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18111. type: string
  18112. required:
  18113. - name
  18114. type: object
  18115. region:
  18116. description: region is for configuring the AWS region to be used.
  18117. example: ap-south-1
  18118. maxLength: 50
  18119. minLength: 1
  18120. pattern: ^[a-z0-9-]+$
  18121. type: string
  18122. required:
  18123. - awsCredentialsSecretRef
  18124. - region
  18125. type: object
  18126. credConfig:
  18127. description: |-
  18128. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18129. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18130. serviceAccountRef must be used by providing operators service account details.
  18131. properties:
  18132. key:
  18133. description: key name holding the external account credential config.
  18134. maxLength: 253
  18135. minLength: 1
  18136. pattern: ^[-._a-zA-Z0-9]+$
  18137. type: string
  18138. name:
  18139. description: name of the configmap.
  18140. maxLength: 253
  18141. minLength: 1
  18142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18143. type: string
  18144. namespace:
  18145. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18146. maxLength: 63
  18147. minLength: 1
  18148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18149. type: string
  18150. required:
  18151. - key
  18152. - name
  18153. type: object
  18154. externalTokenEndpoint:
  18155. description: |-
  18156. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18157. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18158. URL is having the expected value.
  18159. type: string
  18160. gcpServiceAccountEmail:
  18161. description: |-
  18162. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18163. after Workload Identity Federation. Use this to grant access through the service account's
  18164. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18165. service_account_impersonation_url in the external account JSON from credConfig;
  18166. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18167. on that ServiceAccount.
  18168. example: my-gsa@my-project.iam.gserviceaccount.com
  18169. minLength: 1
  18170. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18171. type: string
  18172. serviceAccountRef:
  18173. description: |-
  18174. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18175. when Kubernetes is configured as provider in workload identity pool.
  18176. properties:
  18177. audiences:
  18178. description: |-
  18179. Audience specifies the `aud` claim for the service account token
  18180. Some providers automatically extend the audience field based on well-known annotations for workload
  18181. identity (e.g. IRSA or GCP Workload Identity)
  18182. items:
  18183. type: string
  18184. type: array
  18185. name:
  18186. description: The name of the ServiceAccount resource being referred to.
  18187. maxLength: 253
  18188. minLength: 1
  18189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18190. type: string
  18191. namespace:
  18192. description: |-
  18193. Namespace of the resource being referred to.
  18194. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18195. maxLength: 63
  18196. minLength: 1
  18197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18198. type: string
  18199. required:
  18200. - name
  18201. type: object
  18202. type: object
  18203. type: object
  18204. location:
  18205. description: Location optionally defines a location for a secret
  18206. type: string
  18207. projectID:
  18208. description: ProjectID project where secret is located
  18209. type: string
  18210. secretVersionSelectionPolicy:
  18211. default: LatestOrFail
  18212. description: |-
  18213. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18214. when "latest" is disabled or destroyed.
  18215. Possible values are:
  18216. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18217. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18218. type: string
  18219. type: object
  18220. github:
  18221. description: |-
  18222. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18223. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18224. properties:
  18225. appID:
  18226. description: appID specifies the Github APP that will be used to authenticate the client
  18227. format: int64
  18228. type: integer
  18229. auth:
  18230. description: auth configures how secret-manager authenticates with a Github instance.
  18231. properties:
  18232. privateKey:
  18233. description: |-
  18234. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18235. In some instances, `key` is a required field.
  18236. properties:
  18237. key:
  18238. description: |-
  18239. A key in the referenced Secret.
  18240. Some instances of this field may be defaulted, in others it may be required.
  18241. maxLength: 253
  18242. minLength: 1
  18243. pattern: ^[-._a-zA-Z0-9]+$
  18244. type: string
  18245. name:
  18246. description: The name of the Secret resource being referred to.
  18247. maxLength: 253
  18248. minLength: 1
  18249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18250. type: string
  18251. namespace:
  18252. description: |-
  18253. The namespace of the Secret resource being referred to.
  18254. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18255. maxLength: 63
  18256. minLength: 1
  18257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18258. type: string
  18259. type: object
  18260. required:
  18261. - privateKey
  18262. type: object
  18263. environment:
  18264. description: environment will be used to fetch secrets from a particular environment within a github repository
  18265. type: string
  18266. installationID:
  18267. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18268. format: int64
  18269. type: integer
  18270. orgSecretVisibility:
  18271. description: |-
  18272. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18273. Valid values are "all" or "private".
  18274. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18275. whatever visibility they already have in GitHub.
  18276. enum:
  18277. - all
  18278. - private
  18279. type: string
  18280. organization:
  18281. description: organization will be used to fetch secrets from the Github organization
  18282. type: string
  18283. repository:
  18284. description: repository will be used to fetch secrets from the Github repository within an organization
  18285. type: string
  18286. uploadURL:
  18287. description: Upload URL for enterprise instances. Default to URL.
  18288. type: string
  18289. url:
  18290. default: https://github.com/
  18291. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18292. type: string
  18293. required:
  18294. - appID
  18295. - auth
  18296. - installationID
  18297. - organization
  18298. type: object
  18299. gitlab:
  18300. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18301. properties:
  18302. auth:
  18303. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18304. properties:
  18305. SecretRef:
  18306. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18307. properties:
  18308. accessToken:
  18309. description: AccessToken is used for authentication.
  18310. properties:
  18311. key:
  18312. description: |-
  18313. A key in the referenced Secret.
  18314. Some instances of this field may be defaulted, in others it may be required.
  18315. maxLength: 253
  18316. minLength: 1
  18317. pattern: ^[-._a-zA-Z0-9]+$
  18318. type: string
  18319. name:
  18320. description: The name of the Secret resource being referred to.
  18321. maxLength: 253
  18322. minLength: 1
  18323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18324. type: string
  18325. namespace:
  18326. description: |-
  18327. The namespace of the Secret resource being referred to.
  18328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18329. maxLength: 63
  18330. minLength: 1
  18331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18332. type: string
  18333. type: object
  18334. type: object
  18335. required:
  18336. - SecretRef
  18337. type: object
  18338. caBundle:
  18339. description: |-
  18340. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18341. can be performed.
  18342. format: byte
  18343. type: string
  18344. caProvider:
  18345. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18346. properties:
  18347. key:
  18348. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18349. maxLength: 253
  18350. minLength: 1
  18351. pattern: ^[-._a-zA-Z0-9]+$
  18352. type: string
  18353. name:
  18354. description: The name of the object located at the provider type.
  18355. maxLength: 253
  18356. minLength: 1
  18357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18358. type: string
  18359. namespace:
  18360. description: |-
  18361. The namespace the Provider type is in.
  18362. Can only be defined when used in a ClusterSecretStore.
  18363. maxLength: 63
  18364. minLength: 1
  18365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18366. type: string
  18367. type:
  18368. description: The type of provider to use such as "Secret", or "ConfigMap".
  18369. enum:
  18370. - Secret
  18371. - ConfigMap
  18372. type: string
  18373. required:
  18374. - name
  18375. - type
  18376. type: object
  18377. environment:
  18378. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18379. type: string
  18380. groupIDs:
  18381. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18382. items:
  18383. type: string
  18384. type: array
  18385. inheritFromGroups:
  18386. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18387. type: boolean
  18388. projectID:
  18389. description: ProjectID specifies a project where secrets are located.
  18390. type: string
  18391. url:
  18392. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18393. type: string
  18394. required:
  18395. - auth
  18396. type: object
  18397. ibm:
  18398. description: IBM configures this store to sync secrets using IBM Cloud provider
  18399. properties:
  18400. auth:
  18401. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18402. maxProperties: 1
  18403. minProperties: 1
  18404. properties:
  18405. containerAuth:
  18406. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18407. properties:
  18408. iamEndpoint:
  18409. type: string
  18410. profile:
  18411. description: the IBM Trusted Profile
  18412. type: string
  18413. tokenLocation:
  18414. description: Location the token is mounted on the pod
  18415. type: string
  18416. required:
  18417. - profile
  18418. type: object
  18419. secretRef:
  18420. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18421. properties:
  18422. iamEndpoint:
  18423. description: The IAM endpoint used to obain a token
  18424. type: string
  18425. secretApiKeySecretRef:
  18426. description: The SecretAccessKey is used for authentication
  18427. properties:
  18428. key:
  18429. description: |-
  18430. A key in the referenced Secret.
  18431. Some instances of this field may be defaulted, in others it may be required.
  18432. maxLength: 253
  18433. minLength: 1
  18434. pattern: ^[-._a-zA-Z0-9]+$
  18435. type: string
  18436. name:
  18437. description: The name of the Secret resource being referred to.
  18438. maxLength: 253
  18439. minLength: 1
  18440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18441. type: string
  18442. namespace:
  18443. description: |-
  18444. The namespace of the Secret resource being referred to.
  18445. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18446. maxLength: 63
  18447. minLength: 1
  18448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18449. type: string
  18450. type: object
  18451. type: object
  18452. type: object
  18453. serviceUrl:
  18454. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18455. type: string
  18456. required:
  18457. - auth
  18458. type: object
  18459. infisical:
  18460. description: Infisical configures this store to sync secrets using the Infisical provider
  18461. properties:
  18462. auth:
  18463. description: Auth configures how the Operator authenticates with the Infisical API
  18464. properties:
  18465. awsAuthCredentials:
  18466. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18467. properties:
  18468. identityId:
  18469. description: |-
  18470. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18471. In some instances, `key` is a required field.
  18472. properties:
  18473. key:
  18474. description: |-
  18475. A key in the referenced Secret.
  18476. Some instances of this field may be defaulted, in others it may be required.
  18477. maxLength: 253
  18478. minLength: 1
  18479. pattern: ^[-._a-zA-Z0-9]+$
  18480. type: string
  18481. name:
  18482. description: The name of the Secret resource being referred to.
  18483. maxLength: 253
  18484. minLength: 1
  18485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18486. type: string
  18487. namespace:
  18488. description: |-
  18489. The namespace of the Secret resource being referred to.
  18490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18491. maxLength: 63
  18492. minLength: 1
  18493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18494. type: string
  18495. type: object
  18496. required:
  18497. - identityId
  18498. type: object
  18499. azureAuthCredentials:
  18500. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18501. properties:
  18502. identityId:
  18503. description: |-
  18504. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18505. In some instances, `key` is a required field.
  18506. properties:
  18507. key:
  18508. description: |-
  18509. A key in the referenced Secret.
  18510. Some instances of this field may be defaulted, in others it may be required.
  18511. maxLength: 253
  18512. minLength: 1
  18513. pattern: ^[-._a-zA-Z0-9]+$
  18514. type: string
  18515. name:
  18516. description: The name of the Secret resource being referred to.
  18517. maxLength: 253
  18518. minLength: 1
  18519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18520. type: string
  18521. namespace:
  18522. description: |-
  18523. The namespace of the Secret resource being referred to.
  18524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18525. maxLength: 63
  18526. minLength: 1
  18527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18528. type: string
  18529. type: object
  18530. resource:
  18531. description: |-
  18532. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18533. In some instances, `key` is a required field.
  18534. properties:
  18535. key:
  18536. description: |-
  18537. A key in the referenced Secret.
  18538. Some instances of this field may be defaulted, in others it may be required.
  18539. maxLength: 253
  18540. minLength: 1
  18541. pattern: ^[-._a-zA-Z0-9]+$
  18542. type: string
  18543. name:
  18544. description: The name of the Secret resource being referred to.
  18545. maxLength: 253
  18546. minLength: 1
  18547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18548. type: string
  18549. namespace:
  18550. description: |-
  18551. The namespace of the Secret resource being referred to.
  18552. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18553. maxLength: 63
  18554. minLength: 1
  18555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18556. type: string
  18557. type: object
  18558. required:
  18559. - identityId
  18560. type: object
  18561. gcpIamAuthCredentials:
  18562. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18563. properties:
  18564. identityId:
  18565. description: |-
  18566. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18567. In some instances, `key` is a required field.
  18568. properties:
  18569. key:
  18570. description: |-
  18571. A key in the referenced Secret.
  18572. Some instances of this field may be defaulted, in others it may be required.
  18573. maxLength: 253
  18574. minLength: 1
  18575. pattern: ^[-._a-zA-Z0-9]+$
  18576. type: string
  18577. name:
  18578. description: The name of the Secret resource being referred to.
  18579. maxLength: 253
  18580. minLength: 1
  18581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18582. type: string
  18583. namespace:
  18584. description: |-
  18585. The namespace of the Secret resource being referred to.
  18586. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18587. maxLength: 63
  18588. minLength: 1
  18589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18590. type: string
  18591. type: object
  18592. serviceAccountKeyFilePath:
  18593. description: |-
  18594. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18595. In some instances, `key` is a required field.
  18596. properties:
  18597. key:
  18598. description: |-
  18599. A key in the referenced Secret.
  18600. Some instances of this field may be defaulted, in others it may be required.
  18601. maxLength: 253
  18602. minLength: 1
  18603. pattern: ^[-._a-zA-Z0-9]+$
  18604. type: string
  18605. name:
  18606. description: The name of the Secret resource being referred to.
  18607. maxLength: 253
  18608. minLength: 1
  18609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18610. type: string
  18611. namespace:
  18612. description: |-
  18613. The namespace of the Secret resource being referred to.
  18614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18615. maxLength: 63
  18616. minLength: 1
  18617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18618. type: string
  18619. type: object
  18620. required:
  18621. - identityId
  18622. - serviceAccountKeyFilePath
  18623. type: object
  18624. gcpIdTokenAuthCredentials:
  18625. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18626. properties:
  18627. identityId:
  18628. description: |-
  18629. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18630. In some instances, `key` is a required field.
  18631. properties:
  18632. key:
  18633. description: |-
  18634. A key in the referenced Secret.
  18635. Some instances of this field may be defaulted, in others it may be required.
  18636. maxLength: 253
  18637. minLength: 1
  18638. pattern: ^[-._a-zA-Z0-9]+$
  18639. type: string
  18640. name:
  18641. description: The name of the Secret resource being referred to.
  18642. maxLength: 253
  18643. minLength: 1
  18644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18645. type: string
  18646. namespace:
  18647. description: |-
  18648. The namespace of the Secret resource being referred to.
  18649. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18650. maxLength: 63
  18651. minLength: 1
  18652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18653. type: string
  18654. type: object
  18655. required:
  18656. - identityId
  18657. type: object
  18658. jwtAuthCredentials:
  18659. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18660. properties:
  18661. identityId:
  18662. description: |-
  18663. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18664. In some instances, `key` is a required field.
  18665. properties:
  18666. key:
  18667. description: |-
  18668. A key in the referenced Secret.
  18669. Some instances of this field may be defaulted, in others it may be required.
  18670. maxLength: 253
  18671. minLength: 1
  18672. pattern: ^[-._a-zA-Z0-9]+$
  18673. type: string
  18674. name:
  18675. description: The name of the Secret resource being referred to.
  18676. maxLength: 253
  18677. minLength: 1
  18678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18679. type: string
  18680. namespace:
  18681. description: |-
  18682. The namespace of the Secret resource being referred to.
  18683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18684. maxLength: 63
  18685. minLength: 1
  18686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18687. type: string
  18688. type: object
  18689. jwt:
  18690. description: |-
  18691. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18692. In some instances, `key` is a required field.
  18693. properties:
  18694. key:
  18695. description: |-
  18696. A key in the referenced Secret.
  18697. Some instances of this field may be defaulted, in others it may be required.
  18698. maxLength: 253
  18699. minLength: 1
  18700. pattern: ^[-._a-zA-Z0-9]+$
  18701. type: string
  18702. name:
  18703. description: The name of the Secret resource being referred to.
  18704. maxLength: 253
  18705. minLength: 1
  18706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18707. type: string
  18708. namespace:
  18709. description: |-
  18710. The namespace of the Secret resource being referred to.
  18711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18712. maxLength: 63
  18713. minLength: 1
  18714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18715. type: string
  18716. type: object
  18717. required:
  18718. - identityId
  18719. - jwt
  18720. type: object
  18721. kubernetesAuthCredentials:
  18722. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18723. properties:
  18724. identityId:
  18725. description: |-
  18726. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18727. In some instances, `key` is a required field.
  18728. properties:
  18729. key:
  18730. description: |-
  18731. A key in the referenced Secret.
  18732. Some instances of this field may be defaulted, in others it may be required.
  18733. maxLength: 253
  18734. minLength: 1
  18735. pattern: ^[-._a-zA-Z0-9]+$
  18736. type: string
  18737. name:
  18738. description: The name of the Secret resource being referred to.
  18739. maxLength: 253
  18740. minLength: 1
  18741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18742. type: string
  18743. namespace:
  18744. description: |-
  18745. The namespace of the Secret resource being referred to.
  18746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18747. maxLength: 63
  18748. minLength: 1
  18749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18750. type: string
  18751. type: object
  18752. serviceAccountTokenPath:
  18753. description: |-
  18754. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18755. In some instances, `key` is a required field.
  18756. properties:
  18757. key:
  18758. description: |-
  18759. A key in the referenced Secret.
  18760. Some instances of this field may be defaulted, in others it may be required.
  18761. maxLength: 253
  18762. minLength: 1
  18763. pattern: ^[-._a-zA-Z0-9]+$
  18764. type: string
  18765. name:
  18766. description: The name of the Secret resource being referred to.
  18767. maxLength: 253
  18768. minLength: 1
  18769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18770. type: string
  18771. namespace:
  18772. description: |-
  18773. The namespace of the Secret resource being referred to.
  18774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18775. maxLength: 63
  18776. minLength: 1
  18777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18778. type: string
  18779. type: object
  18780. required:
  18781. - identityId
  18782. type: object
  18783. ldapAuthCredentials:
  18784. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18785. properties:
  18786. identityId:
  18787. description: |-
  18788. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18789. In some instances, `key` is a required field.
  18790. properties:
  18791. key:
  18792. description: |-
  18793. A key in the referenced Secret.
  18794. Some instances of this field may be defaulted, in others it may be required.
  18795. maxLength: 253
  18796. minLength: 1
  18797. pattern: ^[-._a-zA-Z0-9]+$
  18798. type: string
  18799. name:
  18800. description: The name of the Secret resource being referred to.
  18801. maxLength: 253
  18802. minLength: 1
  18803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18804. type: string
  18805. namespace:
  18806. description: |-
  18807. The namespace of the Secret resource being referred to.
  18808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18809. maxLength: 63
  18810. minLength: 1
  18811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18812. type: string
  18813. type: object
  18814. ldapPassword:
  18815. description: |-
  18816. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18817. In some instances, `key` is a required field.
  18818. properties:
  18819. key:
  18820. description: |-
  18821. A key in the referenced Secret.
  18822. Some instances of this field may be defaulted, in others it may be required.
  18823. maxLength: 253
  18824. minLength: 1
  18825. pattern: ^[-._a-zA-Z0-9]+$
  18826. type: string
  18827. name:
  18828. description: The name of the Secret resource being referred to.
  18829. maxLength: 253
  18830. minLength: 1
  18831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18832. type: string
  18833. namespace:
  18834. description: |-
  18835. The namespace of the Secret resource being referred to.
  18836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18837. maxLength: 63
  18838. minLength: 1
  18839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18840. type: string
  18841. type: object
  18842. ldapUsername:
  18843. description: |-
  18844. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18845. In some instances, `key` is a required field.
  18846. properties:
  18847. key:
  18848. description: |-
  18849. A key in the referenced Secret.
  18850. Some instances of this field may be defaulted, in others it may be required.
  18851. maxLength: 253
  18852. minLength: 1
  18853. pattern: ^[-._a-zA-Z0-9]+$
  18854. type: string
  18855. name:
  18856. description: The name of the Secret resource being referred to.
  18857. maxLength: 253
  18858. minLength: 1
  18859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18860. type: string
  18861. namespace:
  18862. description: |-
  18863. The namespace of the Secret resource being referred to.
  18864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18865. maxLength: 63
  18866. minLength: 1
  18867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18868. type: string
  18869. type: object
  18870. required:
  18871. - identityId
  18872. - ldapPassword
  18873. - ldapUsername
  18874. type: object
  18875. ociAuthCredentials:
  18876. description: OciAuthCredentials represents the credentials for OCI authentication.
  18877. properties:
  18878. fingerprint:
  18879. description: |-
  18880. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18881. In some instances, `key` is a required field.
  18882. properties:
  18883. key:
  18884. description: |-
  18885. A key in the referenced Secret.
  18886. Some instances of this field may be defaulted, in others it may be required.
  18887. maxLength: 253
  18888. minLength: 1
  18889. pattern: ^[-._a-zA-Z0-9]+$
  18890. type: string
  18891. name:
  18892. description: The name of the Secret resource being referred to.
  18893. maxLength: 253
  18894. minLength: 1
  18895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18896. type: string
  18897. namespace:
  18898. description: |-
  18899. The namespace of the Secret resource being referred to.
  18900. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18901. maxLength: 63
  18902. minLength: 1
  18903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18904. type: string
  18905. type: object
  18906. identityId:
  18907. description: |-
  18908. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18909. In some instances, `key` is a required field.
  18910. properties:
  18911. key:
  18912. description: |-
  18913. A key in the referenced Secret.
  18914. Some instances of this field may be defaulted, in others it may be required.
  18915. maxLength: 253
  18916. minLength: 1
  18917. pattern: ^[-._a-zA-Z0-9]+$
  18918. type: string
  18919. name:
  18920. description: The name of the Secret resource being referred to.
  18921. maxLength: 253
  18922. minLength: 1
  18923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18924. type: string
  18925. namespace:
  18926. description: |-
  18927. The namespace of the Secret resource being referred to.
  18928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18929. maxLength: 63
  18930. minLength: 1
  18931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18932. type: string
  18933. type: object
  18934. privateKey:
  18935. description: |-
  18936. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18937. In some instances, `key` is a required field.
  18938. properties:
  18939. key:
  18940. description: |-
  18941. A key in the referenced Secret.
  18942. Some instances of this field may be defaulted, in others it may be required.
  18943. maxLength: 253
  18944. minLength: 1
  18945. pattern: ^[-._a-zA-Z0-9]+$
  18946. type: string
  18947. name:
  18948. description: The name of the Secret resource being referred to.
  18949. maxLength: 253
  18950. minLength: 1
  18951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18952. type: string
  18953. namespace:
  18954. description: |-
  18955. The namespace of the Secret resource being referred to.
  18956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18957. maxLength: 63
  18958. minLength: 1
  18959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18960. type: string
  18961. type: object
  18962. privateKeyPassphrase:
  18963. description: |-
  18964. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18965. In some instances, `key` is a required field.
  18966. properties:
  18967. key:
  18968. description: |-
  18969. A key in the referenced Secret.
  18970. Some instances of this field may be defaulted, in others it may be required.
  18971. maxLength: 253
  18972. minLength: 1
  18973. pattern: ^[-._a-zA-Z0-9]+$
  18974. type: string
  18975. name:
  18976. description: The name of the Secret resource being referred to.
  18977. maxLength: 253
  18978. minLength: 1
  18979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18980. type: string
  18981. namespace:
  18982. description: |-
  18983. The namespace of the Secret resource being referred to.
  18984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18985. maxLength: 63
  18986. minLength: 1
  18987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18988. type: string
  18989. type: object
  18990. region:
  18991. description: |-
  18992. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18993. In some instances, `key` is a required field.
  18994. properties:
  18995. key:
  18996. description: |-
  18997. A key in the referenced Secret.
  18998. Some instances of this field may be defaulted, in others it may be required.
  18999. maxLength: 253
  19000. minLength: 1
  19001. pattern: ^[-._a-zA-Z0-9]+$
  19002. type: string
  19003. name:
  19004. description: The name of the Secret resource being referred to.
  19005. maxLength: 253
  19006. minLength: 1
  19007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19008. type: string
  19009. namespace:
  19010. description: |-
  19011. The namespace of the Secret resource being referred to.
  19012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19013. maxLength: 63
  19014. minLength: 1
  19015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19016. type: string
  19017. type: object
  19018. tenancyId:
  19019. description: |-
  19020. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19021. In some instances, `key` is a required field.
  19022. properties:
  19023. key:
  19024. description: |-
  19025. A key in the referenced Secret.
  19026. Some instances of this field may be defaulted, in others it may be required.
  19027. maxLength: 253
  19028. minLength: 1
  19029. pattern: ^[-._a-zA-Z0-9]+$
  19030. type: string
  19031. name:
  19032. description: The name of the Secret resource being referred to.
  19033. maxLength: 253
  19034. minLength: 1
  19035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19036. type: string
  19037. namespace:
  19038. description: |-
  19039. The namespace of the Secret resource being referred to.
  19040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19041. maxLength: 63
  19042. minLength: 1
  19043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19044. type: string
  19045. type: object
  19046. userId:
  19047. description: |-
  19048. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19049. In some instances, `key` is a required field.
  19050. properties:
  19051. key:
  19052. description: |-
  19053. A key in the referenced Secret.
  19054. Some instances of this field may be defaulted, in others it may be required.
  19055. maxLength: 253
  19056. minLength: 1
  19057. pattern: ^[-._a-zA-Z0-9]+$
  19058. type: string
  19059. name:
  19060. description: The name of the Secret resource being referred to.
  19061. maxLength: 253
  19062. minLength: 1
  19063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19064. type: string
  19065. namespace:
  19066. description: |-
  19067. The namespace of the Secret resource being referred to.
  19068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19069. maxLength: 63
  19070. minLength: 1
  19071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19072. type: string
  19073. type: object
  19074. required:
  19075. - fingerprint
  19076. - identityId
  19077. - privateKey
  19078. - region
  19079. - tenancyId
  19080. - userId
  19081. type: object
  19082. tokenAuthCredentials:
  19083. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  19084. properties:
  19085. accessToken:
  19086. description: |-
  19087. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19088. In some instances, `key` is a required field.
  19089. properties:
  19090. key:
  19091. description: |-
  19092. A key in the referenced Secret.
  19093. Some instances of this field may be defaulted, in others it may be required.
  19094. maxLength: 253
  19095. minLength: 1
  19096. pattern: ^[-._a-zA-Z0-9]+$
  19097. type: string
  19098. name:
  19099. description: The name of the Secret resource being referred to.
  19100. maxLength: 253
  19101. minLength: 1
  19102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19103. type: string
  19104. namespace:
  19105. description: |-
  19106. The namespace of the Secret resource being referred to.
  19107. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19108. maxLength: 63
  19109. minLength: 1
  19110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19111. type: string
  19112. type: object
  19113. required:
  19114. - accessToken
  19115. type: object
  19116. universalAuthCredentials:
  19117. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19118. properties:
  19119. clientId:
  19120. description: |-
  19121. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19122. In some instances, `key` is a required field.
  19123. properties:
  19124. key:
  19125. description: |-
  19126. A key in the referenced Secret.
  19127. Some instances of this field may be defaulted, in others it may be required.
  19128. maxLength: 253
  19129. minLength: 1
  19130. pattern: ^[-._a-zA-Z0-9]+$
  19131. type: string
  19132. name:
  19133. description: The name of the Secret resource being referred to.
  19134. maxLength: 253
  19135. minLength: 1
  19136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19137. type: string
  19138. namespace:
  19139. description: |-
  19140. The namespace of the Secret resource being referred to.
  19141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19142. maxLength: 63
  19143. minLength: 1
  19144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19145. type: string
  19146. type: object
  19147. clientSecret:
  19148. description: |-
  19149. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19150. In some instances, `key` is a required field.
  19151. properties:
  19152. key:
  19153. description: |-
  19154. A key in the referenced Secret.
  19155. Some instances of this field may be defaulted, in others it may be required.
  19156. maxLength: 253
  19157. minLength: 1
  19158. pattern: ^[-._a-zA-Z0-9]+$
  19159. type: string
  19160. name:
  19161. description: The name of the Secret resource being referred to.
  19162. maxLength: 253
  19163. minLength: 1
  19164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19165. type: string
  19166. namespace:
  19167. description: |-
  19168. The namespace of the Secret resource being referred to.
  19169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19170. maxLength: 63
  19171. minLength: 1
  19172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19173. type: string
  19174. type: object
  19175. required:
  19176. - clientId
  19177. - clientSecret
  19178. type: object
  19179. type: object
  19180. caBundle:
  19181. description: |-
  19182. CABundle is a PEM-encoded CA certificate bundle used to validate
  19183. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19184. format: byte
  19185. type: string
  19186. caProvider:
  19187. description: |-
  19188. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19189. The certificate is used to validate the Infisical server's TLS certificate.
  19190. Mutually exclusive with CABundle.
  19191. properties:
  19192. key:
  19193. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19194. maxLength: 253
  19195. minLength: 1
  19196. pattern: ^[-._a-zA-Z0-9]+$
  19197. type: string
  19198. name:
  19199. description: The name of the object located at the provider type.
  19200. maxLength: 253
  19201. minLength: 1
  19202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19203. type: string
  19204. namespace:
  19205. description: |-
  19206. The namespace the Provider type is in.
  19207. Can only be defined when used in a ClusterSecretStore.
  19208. maxLength: 63
  19209. minLength: 1
  19210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19211. type: string
  19212. type:
  19213. description: The type of provider to use such as "Secret", or "ConfigMap".
  19214. enum:
  19215. - Secret
  19216. - ConfigMap
  19217. type: string
  19218. required:
  19219. - name
  19220. - type
  19221. type: object
  19222. hostAPI:
  19223. default: https://app.infisical.com/api
  19224. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19225. type: string
  19226. secretsScope:
  19227. description: SecretsScope defines the scope of the secrets within the workspace
  19228. properties:
  19229. environmentSlug:
  19230. description: EnvironmentSlug is the required slug identifier for the environment.
  19231. type: string
  19232. expandSecretReferences:
  19233. default: true
  19234. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19235. type: boolean
  19236. organizationSlug:
  19237. description: |-
  19238. OrganizationSlug is the optional slug that identifies the organization that will be used
  19239. during authentication. Useful for sub-organization setups
  19240. type: string
  19241. projectSlug:
  19242. description: ProjectSlug is the required slug identifier for the project.
  19243. type: string
  19244. recursive:
  19245. default: false
  19246. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19247. type: boolean
  19248. secretsPath:
  19249. default: /
  19250. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19251. type: string
  19252. required:
  19253. - environmentSlug
  19254. - projectSlug
  19255. type: object
  19256. required:
  19257. - auth
  19258. - secretsScope
  19259. type: object
  19260. keepersecurity:
  19261. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19262. properties:
  19263. authRef:
  19264. description: |-
  19265. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19266. In some instances, `key` is a required field.
  19267. properties:
  19268. key:
  19269. description: |-
  19270. A key in the referenced Secret.
  19271. Some instances of this field may be defaulted, in others it may be required.
  19272. maxLength: 253
  19273. minLength: 1
  19274. pattern: ^[-._a-zA-Z0-9]+$
  19275. type: string
  19276. name:
  19277. description: The name of the Secret resource being referred to.
  19278. maxLength: 253
  19279. minLength: 1
  19280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19281. type: string
  19282. namespace:
  19283. description: |-
  19284. The namespace of the Secret resource being referred to.
  19285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19286. maxLength: 63
  19287. minLength: 1
  19288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19289. type: string
  19290. type: object
  19291. folderID:
  19292. type: string
  19293. getByTitleFallback:
  19294. type: boolean
  19295. required:
  19296. - authRef
  19297. - folderID
  19298. type: object
  19299. kubernetes:
  19300. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19301. properties:
  19302. auth:
  19303. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19304. maxProperties: 1
  19305. minProperties: 1
  19306. properties:
  19307. cert:
  19308. description: has both clientCert and clientKey as secretKeySelector
  19309. properties:
  19310. clientCert:
  19311. description: |-
  19312. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19313. In some instances, `key` is a required field.
  19314. properties:
  19315. key:
  19316. description: |-
  19317. A key in the referenced Secret.
  19318. Some instances of this field may be defaulted, in others it may be required.
  19319. maxLength: 253
  19320. minLength: 1
  19321. pattern: ^[-._a-zA-Z0-9]+$
  19322. type: string
  19323. name:
  19324. description: The name of the Secret resource being referred to.
  19325. maxLength: 253
  19326. minLength: 1
  19327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19328. type: string
  19329. namespace:
  19330. description: |-
  19331. The namespace of the Secret resource being referred to.
  19332. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19333. maxLength: 63
  19334. minLength: 1
  19335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19336. type: string
  19337. type: object
  19338. clientKey:
  19339. description: |-
  19340. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19341. In some instances, `key` is a required field.
  19342. properties:
  19343. key:
  19344. description: |-
  19345. A key in the referenced Secret.
  19346. Some instances of this field may be defaulted, in others it may be required.
  19347. maxLength: 253
  19348. minLength: 1
  19349. pattern: ^[-._a-zA-Z0-9]+$
  19350. type: string
  19351. name:
  19352. description: The name of the Secret resource being referred to.
  19353. maxLength: 253
  19354. minLength: 1
  19355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19356. type: string
  19357. namespace:
  19358. description: |-
  19359. The namespace of the Secret resource being referred to.
  19360. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19361. maxLength: 63
  19362. minLength: 1
  19363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19364. type: string
  19365. type: object
  19366. required:
  19367. - clientCert
  19368. - clientKey
  19369. type: object
  19370. serviceAccount:
  19371. description: points to a service account that should be used for authentication
  19372. properties:
  19373. audiences:
  19374. description: |-
  19375. Audience specifies the `aud` claim for the service account token
  19376. Some providers automatically extend the audience field based on well-known annotations for workload
  19377. identity (e.g. IRSA or GCP Workload Identity)
  19378. items:
  19379. type: string
  19380. type: array
  19381. name:
  19382. description: The name of the ServiceAccount resource being referred to.
  19383. maxLength: 253
  19384. minLength: 1
  19385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19386. type: string
  19387. namespace:
  19388. description: |-
  19389. Namespace of the resource being referred to.
  19390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19391. maxLength: 63
  19392. minLength: 1
  19393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19394. type: string
  19395. required:
  19396. - name
  19397. type: object
  19398. token:
  19399. description: use static token to authenticate with
  19400. properties:
  19401. bearerToken:
  19402. description: |-
  19403. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19404. In some instances, `key` is a required field.
  19405. properties:
  19406. key:
  19407. description: |-
  19408. A key in the referenced Secret.
  19409. Some instances of this field may be defaulted, in others it may be required.
  19410. maxLength: 253
  19411. minLength: 1
  19412. pattern: ^[-._a-zA-Z0-9]+$
  19413. type: string
  19414. name:
  19415. description: The name of the Secret resource being referred to.
  19416. maxLength: 253
  19417. minLength: 1
  19418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19419. type: string
  19420. namespace:
  19421. description: |-
  19422. The namespace of the Secret resource being referred to.
  19423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19424. maxLength: 63
  19425. minLength: 1
  19426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19427. type: string
  19428. type: object
  19429. required:
  19430. - bearerToken
  19431. type: object
  19432. type: object
  19433. authRef:
  19434. description: A reference to a secret that contains the auth information.
  19435. properties:
  19436. key:
  19437. description: |-
  19438. A key in the referenced Secret.
  19439. Some instances of this field may be defaulted, in others it may be required.
  19440. maxLength: 253
  19441. minLength: 1
  19442. pattern: ^[-._a-zA-Z0-9]+$
  19443. type: string
  19444. name:
  19445. description: The name of the Secret resource being referred to.
  19446. maxLength: 253
  19447. minLength: 1
  19448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19449. type: string
  19450. namespace:
  19451. description: |-
  19452. The namespace of the Secret resource being referred to.
  19453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19454. maxLength: 63
  19455. minLength: 1
  19456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19457. type: string
  19458. type: object
  19459. remoteNamespace:
  19460. default: default
  19461. description: Remote namespace to fetch the secrets from
  19462. maxLength: 63
  19463. minLength: 1
  19464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19465. type: string
  19466. server:
  19467. description: configures the Kubernetes server Address.
  19468. properties:
  19469. caBundle:
  19470. description: CABundle is a base64-encoded CA certificate
  19471. format: byte
  19472. type: string
  19473. caProvider:
  19474. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19475. properties:
  19476. key:
  19477. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19478. maxLength: 253
  19479. minLength: 1
  19480. pattern: ^[-._a-zA-Z0-9]+$
  19481. type: string
  19482. name:
  19483. description: The name of the object located at the provider type.
  19484. maxLength: 253
  19485. minLength: 1
  19486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19487. type: string
  19488. namespace:
  19489. description: |-
  19490. The namespace the Provider type is in.
  19491. Can only be defined when used in a ClusterSecretStore.
  19492. maxLength: 63
  19493. minLength: 1
  19494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19495. type: string
  19496. type:
  19497. description: The type of provider to use such as "Secret", or "ConfigMap".
  19498. enum:
  19499. - Secret
  19500. - ConfigMap
  19501. type: string
  19502. required:
  19503. - name
  19504. - type
  19505. type: object
  19506. url:
  19507. default: kubernetes.default
  19508. description: configures the Kubernetes server Address.
  19509. type: string
  19510. type: object
  19511. type: object
  19512. nebiusmysterybox:
  19513. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19514. properties:
  19515. apiDomain:
  19516. description: NebiusMysterybox API endpoint
  19517. type: string
  19518. auth:
  19519. description: Auth defines parameters to authenticate in MysteryBox
  19520. properties:
  19521. serviceAccountCredsSecretRef:
  19522. description: |-
  19523. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19524. document with service account credentials used to get an IAM token.
  19525. Expected JSON structure:
  19526. {
  19527. "subject-credentials": {
  19528. "alg": "RS256",
  19529. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19530. "kid": "<public-key-id>",
  19531. "iss": "<issuer-service-account-id>",
  19532. "sub": "<subject-service-account-id>"
  19533. }
  19534. }
  19535. properties:
  19536. key:
  19537. description: |-
  19538. A key in the referenced Secret.
  19539. Some instances of this field may be defaulted, in others it may be required.
  19540. maxLength: 253
  19541. minLength: 1
  19542. pattern: ^[-._a-zA-Z0-9]+$
  19543. type: string
  19544. name:
  19545. description: The name of the Secret resource being referred to.
  19546. maxLength: 253
  19547. minLength: 1
  19548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19549. type: string
  19550. namespace:
  19551. description: |-
  19552. The namespace of the Secret resource being referred to.
  19553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19554. maxLength: 63
  19555. minLength: 1
  19556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19557. type: string
  19558. type: object
  19559. tokenSecretRef:
  19560. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19561. properties:
  19562. key:
  19563. description: |-
  19564. A key in the referenced Secret.
  19565. Some instances of this field may be defaulted, in others it may be required.
  19566. maxLength: 253
  19567. minLength: 1
  19568. pattern: ^[-._a-zA-Z0-9]+$
  19569. type: string
  19570. name:
  19571. description: The name of the Secret resource being referred to.
  19572. maxLength: 253
  19573. minLength: 1
  19574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19575. type: string
  19576. namespace:
  19577. description: |-
  19578. The namespace of the Secret resource being referred to.
  19579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19580. maxLength: 63
  19581. minLength: 1
  19582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19583. type: string
  19584. type: object
  19585. type: object
  19586. x-kubernetes-validations:
  19587. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  19588. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  19589. caProvider:
  19590. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19591. properties:
  19592. certSecretRef:
  19593. description: |-
  19594. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19595. In some instances, `key` is a required field.
  19596. properties:
  19597. key:
  19598. description: |-
  19599. A key in the referenced Secret.
  19600. Some instances of this field may be defaulted, in others it may be required.
  19601. maxLength: 253
  19602. minLength: 1
  19603. pattern: ^[-._a-zA-Z0-9]+$
  19604. type: string
  19605. name:
  19606. description: The name of the Secret resource being referred to.
  19607. maxLength: 253
  19608. minLength: 1
  19609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19610. type: string
  19611. namespace:
  19612. description: |-
  19613. The namespace of the Secret resource being referred to.
  19614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19615. maxLength: 63
  19616. minLength: 1
  19617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19618. type: string
  19619. type: object
  19620. type: object
  19621. required:
  19622. - apiDomain
  19623. - auth
  19624. type: object
  19625. ngrok:
  19626. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19627. properties:
  19628. apiUrl:
  19629. default: https://api.ngrok.com
  19630. description: APIURL is the URL of the ngrok API.
  19631. type: string
  19632. auth:
  19633. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19634. maxProperties: 1
  19635. minProperties: 1
  19636. properties:
  19637. apiKey:
  19638. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19639. properties:
  19640. secretRef:
  19641. description: SecretRef is a reference to a secret containing the ngrok API key.
  19642. properties:
  19643. key:
  19644. description: |-
  19645. A key in the referenced Secret.
  19646. Some instances of this field may be defaulted, in others it may be required.
  19647. maxLength: 253
  19648. minLength: 1
  19649. pattern: ^[-._a-zA-Z0-9]+$
  19650. type: string
  19651. name:
  19652. description: The name of the Secret resource being referred to.
  19653. maxLength: 253
  19654. minLength: 1
  19655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19656. type: string
  19657. namespace:
  19658. description: |-
  19659. The namespace of the Secret resource being referred to.
  19660. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19661. maxLength: 63
  19662. minLength: 1
  19663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19664. type: string
  19665. type: object
  19666. type: object
  19667. type: object
  19668. vault:
  19669. description: Vault configures the ngrok vault to sync secrets with.
  19670. properties:
  19671. name:
  19672. description: Name is the name of the ngrok vault to sync secrets with.
  19673. type: string
  19674. required:
  19675. - name
  19676. type: object
  19677. required:
  19678. - auth
  19679. - vault
  19680. type: object
  19681. onboardbase:
  19682. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19683. properties:
  19684. apiHost:
  19685. default: https://public.onboardbase.com/api/v1/
  19686. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19687. type: string
  19688. auth:
  19689. description: Auth configures how the Operator authenticates with the Onboardbase API
  19690. properties:
  19691. apiKeyRef:
  19692. description: |-
  19693. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19694. It is used to recognize and authorize access to a project and environment within onboardbase
  19695. properties:
  19696. key:
  19697. description: |-
  19698. A key in the referenced Secret.
  19699. Some instances of this field may be defaulted, in others it may be required.
  19700. maxLength: 253
  19701. minLength: 1
  19702. pattern: ^[-._a-zA-Z0-9]+$
  19703. type: string
  19704. name:
  19705. description: The name of the Secret resource being referred to.
  19706. maxLength: 253
  19707. minLength: 1
  19708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19709. type: string
  19710. namespace:
  19711. description: |-
  19712. The namespace of the Secret resource being referred to.
  19713. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19714. maxLength: 63
  19715. minLength: 1
  19716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19717. type: string
  19718. type: object
  19719. passcodeRef:
  19720. description: OnboardbasePasscode is the passcode attached to the API Key
  19721. properties:
  19722. key:
  19723. description: |-
  19724. A key in the referenced Secret.
  19725. Some instances of this field may be defaulted, in others it may be required.
  19726. maxLength: 253
  19727. minLength: 1
  19728. pattern: ^[-._a-zA-Z0-9]+$
  19729. type: string
  19730. name:
  19731. description: The name of the Secret resource being referred to.
  19732. maxLength: 253
  19733. minLength: 1
  19734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19735. type: string
  19736. namespace:
  19737. description: |-
  19738. The namespace of the Secret resource being referred to.
  19739. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19740. maxLength: 63
  19741. minLength: 1
  19742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19743. type: string
  19744. type: object
  19745. required:
  19746. - apiKeyRef
  19747. - passcodeRef
  19748. type: object
  19749. environment:
  19750. default: development
  19751. description: Environment is the name of an environmnent within a project to pull the secrets from
  19752. type: string
  19753. project:
  19754. default: development
  19755. description: Project is an onboardbase project that the secrets should be pulled from
  19756. type: string
  19757. required:
  19758. - apiHost
  19759. - auth
  19760. - environment
  19761. - project
  19762. type: object
  19763. onepassword:
  19764. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19765. properties:
  19766. auth:
  19767. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19768. properties:
  19769. secretRef:
  19770. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19771. properties:
  19772. connectTokenSecretRef:
  19773. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19774. properties:
  19775. key:
  19776. description: |-
  19777. A key in the referenced Secret.
  19778. Some instances of this field may be defaulted, in others it may be required.
  19779. maxLength: 253
  19780. minLength: 1
  19781. pattern: ^[-._a-zA-Z0-9]+$
  19782. type: string
  19783. name:
  19784. description: The name of the Secret resource being referred to.
  19785. maxLength: 253
  19786. minLength: 1
  19787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19788. type: string
  19789. namespace:
  19790. description: |-
  19791. The namespace of the Secret resource being referred to.
  19792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19793. maxLength: 63
  19794. minLength: 1
  19795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19796. type: string
  19797. type: object
  19798. required:
  19799. - connectTokenSecretRef
  19800. type: object
  19801. required:
  19802. - secretRef
  19803. type: object
  19804. connectHost:
  19805. description: ConnectHost defines the OnePassword Connect Server to connect to
  19806. type: string
  19807. vaults:
  19808. additionalProperties:
  19809. type: integer
  19810. description: Vaults defines which OnePassword vaults to search in which order
  19811. type: object
  19812. required:
  19813. - auth
  19814. - connectHost
  19815. - vaults
  19816. type: object
  19817. onepasswordSDK:
  19818. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19819. properties:
  19820. auth:
  19821. description: Auth defines the information necessary to authenticate against OnePassword API.
  19822. properties:
  19823. serviceAccountSecretRef:
  19824. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19825. properties:
  19826. key:
  19827. description: |-
  19828. A key in the referenced Secret.
  19829. Some instances of this field may be defaulted, in others it may be required.
  19830. maxLength: 253
  19831. minLength: 1
  19832. pattern: ^[-._a-zA-Z0-9]+$
  19833. type: string
  19834. name:
  19835. description: The name of the Secret resource being referred to.
  19836. maxLength: 253
  19837. minLength: 1
  19838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19839. type: string
  19840. namespace:
  19841. description: |-
  19842. The namespace of the Secret resource being referred to.
  19843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19844. maxLength: 63
  19845. minLength: 1
  19846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19847. type: string
  19848. type: object
  19849. required:
  19850. - serviceAccountSecretRef
  19851. type: object
  19852. cache:
  19853. description: |-
  19854. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19855. When enabled, secrets are cached with the specified TTL.
  19856. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19857. If omitted, caching is disabled (default).
  19858. cache: {} is a valid option to set.
  19859. properties:
  19860. maxSize:
  19861. default: 100
  19862. description: |-
  19863. MaxSize is the maximum number of secrets to cache.
  19864. When the cache is full, least-recently-used entries are evicted.
  19865. minimum: 1
  19866. type: integer
  19867. ttl:
  19868. default: 5m
  19869. description: |-
  19870. TTL is the time-to-live for cached secrets.
  19871. Format: duration string (e.g., "5m", "1h", "30s")
  19872. type: string
  19873. type: object
  19874. environment:
  19875. description: |-
  19876. Environment defines the 1Password Environment ID to read variables from.
  19877. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  19878. Mutually exclusive with Vault.
  19879. type: string
  19880. integrationInfo:
  19881. description: |-
  19882. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19883. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19884. properties:
  19885. name:
  19886. default: 1Password SDK
  19887. description: Name defaults to "1Password SDK".
  19888. type: string
  19889. version:
  19890. default: v1.0.0
  19891. description: Version defaults to "v1.0.0".
  19892. type: string
  19893. type: object
  19894. vault:
  19895. description: |-
  19896. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19897. Mutually exclusive with Environment.
  19898. type: string
  19899. required:
  19900. - auth
  19901. type: object
  19902. x-kubernetes-validations:
  19903. - message: at most one of the fields in [vault environment] may be set
  19904. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  19905. openBao:
  19906. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19907. properties:
  19908. auth:
  19909. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19910. properties:
  19911. appRole:
  19912. description: |-
  19913. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19914. with the role and secret stored in a Kubernetes Secret resource.
  19915. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19916. properties:
  19917. path:
  19918. default: approle
  19919. description: |-
  19920. Path where the App Role authentication backend is mounted
  19921. in OpenBao, e.g: "approle"
  19922. type: string
  19923. roleId:
  19924. description: |-
  19925. RoleID configured in the App Role authentication backend when setting
  19926. up the authentication backend in OpenBao.
  19927. minLength: 1
  19928. type: string
  19929. roleRef:
  19930. description: |-
  19931. Reference to a key in a Secret that contains the App Role ID used
  19932. to authenticate with OpenBao.
  19933. The `key` field must be specified and denotes which entry within the Secret
  19934. resource is used as the app role id.
  19935. properties:
  19936. key:
  19937. description: |-
  19938. A key in the referenced Secret.
  19939. Some instances of this field may be defaulted, in others it may be required.
  19940. maxLength: 253
  19941. minLength: 1
  19942. pattern: ^[-._a-zA-Z0-9]+$
  19943. type: string
  19944. name:
  19945. description: The name of the Secret resource being referred to.
  19946. maxLength: 253
  19947. minLength: 1
  19948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19949. type: string
  19950. namespace:
  19951. description: |-
  19952. The namespace of the Secret resource being referred to.
  19953. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19954. maxLength: 63
  19955. minLength: 1
  19956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19957. type: string
  19958. type: object
  19959. secretRef:
  19960. description: |-
  19961. Reference to a key in a Secret that contains the App Role secret used
  19962. to authenticate with OpenBao.
  19963. The `key` field must be specified and denotes which entry within the Secret
  19964. resource is used as the app role secret.
  19965. properties:
  19966. key:
  19967. description: |-
  19968. A key in the referenced Secret.
  19969. Some instances of this field may be defaulted, in others it may be required.
  19970. maxLength: 253
  19971. minLength: 1
  19972. pattern: ^[-._a-zA-Z0-9]+$
  19973. type: string
  19974. name:
  19975. description: The name of the Secret resource being referred to.
  19976. maxLength: 253
  19977. minLength: 1
  19978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19979. type: string
  19980. namespace:
  19981. description: |-
  19982. The namespace of the Secret resource being referred to.
  19983. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19984. maxLength: 63
  19985. minLength: 1
  19986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19987. type: string
  19988. type: object
  19989. required:
  19990. - path
  19991. - secretRef
  19992. type: object
  19993. x-kubernetes-validations:
  19994. - message: exactly one of the fields in [roleId roleRef] must be set
  19995. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19996. kubernetes:
  19997. description: |-
  19998. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  19999. token to the [Kubernetes auth mechanism].
  20000. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  20001. properties:
  20002. path:
  20003. default: kubernetes
  20004. description: |-
  20005. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  20006. "kubernetes"
  20007. type: string
  20008. role:
  20009. description: |-
  20010. A required field containing the OpenBao Role to assume. A Role binds a
  20011. Kubernetes ServiceAccount with a set of OpenBao policies.
  20012. minLength: 1
  20013. type: string
  20014. secretRef:
  20015. description: |-
  20016. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20017. for authenticating with OpenBao. If a name is specified without a key,
  20018. `token` is the default.
  20019. properties:
  20020. key:
  20021. description: |-
  20022. A key in the referenced Secret.
  20023. Some instances of this field may be defaulted, in others it may be required.
  20024. maxLength: 253
  20025. minLength: 1
  20026. pattern: ^[-._a-zA-Z0-9]+$
  20027. type: string
  20028. name:
  20029. description: The name of the Secret resource being referred to.
  20030. maxLength: 253
  20031. minLength: 1
  20032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20033. type: string
  20034. namespace:
  20035. description: |-
  20036. The namespace of the Secret resource being referred to.
  20037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20038. maxLength: 63
  20039. minLength: 1
  20040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20041. type: string
  20042. type: object
  20043. serviceAccountRef:
  20044. description: |-
  20045. Optional service account field containing the name of a Kubernetes ServiceAccount.
  20046. If the service account is specified, a token will be requested from the Kubernetes
  20047. TokenRequest API for authenticating with OpenBao.
  20048. Any configured audiences will be passed to the TokenRequest as-is.
  20049. properties:
  20050. audiences:
  20051. description: |-
  20052. Audience specifies the `aud` claim for the service account token
  20053. Some providers automatically extend the audience field based on well-known annotations for workload
  20054. identity (e.g. IRSA or GCP Workload Identity)
  20055. items:
  20056. type: string
  20057. type: array
  20058. name:
  20059. description: The name of the ServiceAccount resource being referred to.
  20060. maxLength: 253
  20061. minLength: 1
  20062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20063. type: string
  20064. namespace:
  20065. description: |-
  20066. Namespace of the resource being referred to.
  20067. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20068. maxLength: 63
  20069. minLength: 1
  20070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20071. type: string
  20072. required:
  20073. - name
  20074. type: object
  20075. required:
  20076. - path
  20077. - role
  20078. type: object
  20079. x-kubernetes-validations:
  20080. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  20081. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  20082. namespace:
  20083. description: |-
  20084. Name of the [OpenBao Namespace] to authenticate to. This can be different
  20085. than the namespace your secret is in. Namespaces is a set of features
  20086. within OpenBao that allows OpenBao environments to support secure
  20087. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  20088. if set, or empty otherwise
  20089. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20090. type: string
  20091. tokenSecretRef:
  20092. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  20093. properties:
  20094. key:
  20095. description: |-
  20096. A key in the referenced Secret.
  20097. Some instances of this field may be defaulted, in others it may be required.
  20098. maxLength: 253
  20099. minLength: 1
  20100. pattern: ^[-._a-zA-Z0-9]+$
  20101. type: string
  20102. name:
  20103. description: The name of the Secret resource being referred to.
  20104. maxLength: 253
  20105. minLength: 1
  20106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20107. type: string
  20108. namespace:
  20109. description: |-
  20110. The namespace of the Secret resource being referred to.
  20111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20112. maxLength: 63
  20113. minLength: 1
  20114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20115. type: string
  20116. type: object
  20117. userPass:
  20118. description: UserPass authenticates with OpenBao by passing a username/password pair
  20119. properties:
  20120. path:
  20121. default: userpass
  20122. description: |-
  20123. Path where the UserPassword authentication backend is mounted
  20124. in OpenBao, e.g: "userpass"
  20125. type: string
  20126. secretRef:
  20127. description: |-
  20128. SecretRef to a key in a Secret resource containing password for the user
  20129. used to authenticate with OpenBao using the [UserPass authentication
  20130. method]
  20131. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20132. properties:
  20133. key:
  20134. description: |-
  20135. A key in the referenced Secret.
  20136. Some instances of this field may be defaulted, in others it may be required.
  20137. maxLength: 253
  20138. minLength: 1
  20139. pattern: ^[-._a-zA-Z0-9]+$
  20140. type: string
  20141. name:
  20142. description: The name of the Secret resource being referred to.
  20143. maxLength: 253
  20144. minLength: 1
  20145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20146. type: string
  20147. namespace:
  20148. description: |-
  20149. The namespace of the Secret resource being referred to.
  20150. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20151. maxLength: 63
  20152. minLength: 1
  20153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20154. type: string
  20155. type: object
  20156. username:
  20157. description: |-
  20158. Username is a username used to authenticate using the [UserPass
  20159. authentication method]
  20160. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20161. type: string
  20162. required:
  20163. - path
  20164. - username
  20165. type: object
  20166. type: object
  20167. x-kubernetes-validations:
  20168. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  20169. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  20170. caBundle:
  20171. description: |-
  20172. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20173. this and `caProvider` are not set the system root certificates are used
  20174. to validate the TLS connection.
  20175. format: byte
  20176. type: string
  20177. caProvider:
  20178. description: |-
  20179. The provider for the CA bundle to use to validate OpenBao server
  20180. certificate. If this and `caBundle` are not set the system root
  20181. certificates are used to validate the TLS connection.
  20182. properties:
  20183. key:
  20184. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20185. maxLength: 253
  20186. minLength: 1
  20187. pattern: ^[-._a-zA-Z0-9]+$
  20188. type: string
  20189. name:
  20190. description: The name of the object located at the provider type.
  20191. maxLength: 253
  20192. minLength: 1
  20193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20194. type: string
  20195. namespace:
  20196. description: |-
  20197. The namespace the Provider type is in.
  20198. Can only be defined when used in a ClusterSecretStore.
  20199. maxLength: 63
  20200. minLength: 1
  20201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20202. type: string
  20203. type:
  20204. description: The type of provider to use such as "Secret", or "ConfigMap".
  20205. enum:
  20206. - Secret
  20207. - ConfigMap
  20208. type: string
  20209. required:
  20210. - name
  20211. - type
  20212. type: object
  20213. namespace:
  20214. description: |-
  20215. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20216. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20217. e.g: "ns1".
  20218. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20219. type: string
  20220. path:
  20221. description: |-
  20222. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20223. "secret". The v2 KV secret engine version specific "/data" path suffix
  20224. for fetching secrets from OpenBao is optional and will be appended
  20225. if not present in specified path.
  20226. type: string
  20227. server:
  20228. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20229. type: string
  20230. version:
  20231. default: v2
  20232. description: |-
  20233. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20234. "v2". Version defaults to "v2".
  20235. enum:
  20236. - v1
  20237. - v2
  20238. type: string
  20239. required:
  20240. - server
  20241. type: object
  20242. x-kubernetes-validations:
  20243. - message: at most one of the fields in [caBundle caProvider] may be set
  20244. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20245. oracle:
  20246. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20247. properties:
  20248. auth:
  20249. description: |-
  20250. Auth configures how secret-manager authenticates with the Oracle Vault.
  20251. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20252. properties:
  20253. secretRef:
  20254. description: SecretRef to pass through sensitive information.
  20255. properties:
  20256. fingerprint:
  20257. description: Fingerprint is the fingerprint of the API private key.
  20258. properties:
  20259. key:
  20260. description: |-
  20261. A key in the referenced Secret.
  20262. Some instances of this field may be defaulted, in others it may be required.
  20263. maxLength: 253
  20264. minLength: 1
  20265. pattern: ^[-._a-zA-Z0-9]+$
  20266. type: string
  20267. name:
  20268. description: The name of the Secret resource being referred to.
  20269. maxLength: 253
  20270. minLength: 1
  20271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20272. type: string
  20273. namespace:
  20274. description: |-
  20275. The namespace of the Secret resource being referred to.
  20276. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20277. maxLength: 63
  20278. minLength: 1
  20279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20280. type: string
  20281. type: object
  20282. privatekey:
  20283. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20284. properties:
  20285. key:
  20286. description: |-
  20287. A key in the referenced Secret.
  20288. Some instances of this field may be defaulted, in others it may be required.
  20289. maxLength: 253
  20290. minLength: 1
  20291. pattern: ^[-._a-zA-Z0-9]+$
  20292. type: string
  20293. name:
  20294. description: The name of the Secret resource being referred to.
  20295. maxLength: 253
  20296. minLength: 1
  20297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20298. type: string
  20299. namespace:
  20300. description: |-
  20301. The namespace of the Secret resource being referred to.
  20302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20303. maxLength: 63
  20304. minLength: 1
  20305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20306. type: string
  20307. type: object
  20308. required:
  20309. - fingerprint
  20310. - privatekey
  20311. type: object
  20312. tenancy:
  20313. description: Tenancy is the tenancy OCID where user is located.
  20314. type: string
  20315. user:
  20316. description: User is an access OCID specific to the account.
  20317. type: string
  20318. required:
  20319. - secretRef
  20320. - tenancy
  20321. - user
  20322. type: object
  20323. compartment:
  20324. description: |-
  20325. Compartment is the vault compartment OCID.
  20326. Required for PushSecret
  20327. type: string
  20328. encryptionKey:
  20329. description: |-
  20330. EncryptionKey is the OCID of the encryption key within the vault.
  20331. Required for PushSecret
  20332. type: string
  20333. principalType:
  20334. description: |-
  20335. The type of principal to use for authentication. If left blank, the Auth struct will
  20336. determine the principal type. This optional field must be specified if using
  20337. workload identity.
  20338. enum:
  20339. - ""
  20340. - UserPrincipal
  20341. - InstancePrincipal
  20342. - Workload
  20343. type: string
  20344. region:
  20345. description: Region is the region where vault is located.
  20346. type: string
  20347. serviceAccountRef:
  20348. description: |-
  20349. ServiceAccountRef specified the service account
  20350. that should be used when authenticating with WorkloadIdentity.
  20351. properties:
  20352. audiences:
  20353. description: |-
  20354. Audience specifies the `aud` claim for the service account token
  20355. Some providers automatically extend the audience field based on well-known annotations for workload
  20356. identity (e.g. IRSA or GCP Workload Identity)
  20357. items:
  20358. type: string
  20359. type: array
  20360. name:
  20361. description: The name of the ServiceAccount resource being referred to.
  20362. maxLength: 253
  20363. minLength: 1
  20364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20365. type: string
  20366. namespace:
  20367. description: |-
  20368. Namespace of the resource being referred to.
  20369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20370. maxLength: 63
  20371. minLength: 1
  20372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20373. type: string
  20374. required:
  20375. - name
  20376. type: object
  20377. vault:
  20378. description: Vault is the vault's OCID of the specific vault where secret is located.
  20379. type: string
  20380. required:
  20381. - region
  20382. - vault
  20383. type: object
  20384. ovh:
  20385. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20386. properties:
  20387. auth:
  20388. description: Authentication method (mtls or token).
  20389. properties:
  20390. mtls:
  20391. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20392. properties:
  20393. caBundle:
  20394. format: byte
  20395. type: string
  20396. caProvider:
  20397. description: |-
  20398. CAProvider provides a custom certificate authority for accessing the provider's store.
  20399. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20400. properties:
  20401. key:
  20402. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20403. maxLength: 253
  20404. minLength: 1
  20405. pattern: ^[-._a-zA-Z0-9]+$
  20406. type: string
  20407. name:
  20408. description: The name of the object located at the provider type.
  20409. maxLength: 253
  20410. minLength: 1
  20411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20412. type: string
  20413. namespace:
  20414. description: |-
  20415. The namespace the Provider type is in.
  20416. Can only be defined when used in a ClusterSecretStore.
  20417. maxLength: 63
  20418. minLength: 1
  20419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20420. type: string
  20421. type:
  20422. description: The type of provider to use such as "Secret", or "ConfigMap".
  20423. enum:
  20424. - Secret
  20425. - ConfigMap
  20426. type: string
  20427. required:
  20428. - name
  20429. - type
  20430. type: object
  20431. certSecretRef:
  20432. description: |-
  20433. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20434. In some instances, `key` is a required field.
  20435. properties:
  20436. key:
  20437. description: |-
  20438. A key in the referenced Secret.
  20439. Some instances of this field may be defaulted, in others it may be required.
  20440. maxLength: 253
  20441. minLength: 1
  20442. pattern: ^[-._a-zA-Z0-9]+$
  20443. type: string
  20444. name:
  20445. description: The name of the Secret resource being referred to.
  20446. maxLength: 253
  20447. minLength: 1
  20448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20449. type: string
  20450. namespace:
  20451. description: |-
  20452. The namespace of the Secret resource being referred to.
  20453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20454. maxLength: 63
  20455. minLength: 1
  20456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20457. type: string
  20458. type: object
  20459. keySecretRef:
  20460. description: |-
  20461. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20462. In some instances, `key` is a required field.
  20463. properties:
  20464. key:
  20465. description: |-
  20466. A key in the referenced Secret.
  20467. Some instances of this field may be defaulted, in others it may be required.
  20468. maxLength: 253
  20469. minLength: 1
  20470. pattern: ^[-._a-zA-Z0-9]+$
  20471. type: string
  20472. name:
  20473. description: The name of the Secret resource being referred to.
  20474. maxLength: 253
  20475. minLength: 1
  20476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20477. type: string
  20478. namespace:
  20479. description: |-
  20480. The namespace of the Secret resource being referred to.
  20481. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20482. maxLength: 63
  20483. minLength: 1
  20484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20485. type: string
  20486. type: object
  20487. required:
  20488. - certSecretRef
  20489. - keySecretRef
  20490. type: object
  20491. token:
  20492. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20493. properties:
  20494. tokenSecretRef:
  20495. description: |-
  20496. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20497. In some instances, `key` is a required field.
  20498. properties:
  20499. key:
  20500. description: |-
  20501. A key in the referenced Secret.
  20502. Some instances of this field may be defaulted, in others it may be required.
  20503. maxLength: 253
  20504. minLength: 1
  20505. pattern: ^[-._a-zA-Z0-9]+$
  20506. type: string
  20507. name:
  20508. description: The name of the Secret resource being referred to.
  20509. maxLength: 253
  20510. minLength: 1
  20511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20512. type: string
  20513. namespace:
  20514. description: |-
  20515. The namespace of the Secret resource being referred to.
  20516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20517. maxLength: 63
  20518. minLength: 1
  20519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20520. type: string
  20521. type: object
  20522. required:
  20523. - tokenSecretRef
  20524. type: object
  20525. type: object
  20526. casRequired:
  20527. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20528. type: boolean
  20529. okmsTimeout:
  20530. default: 30
  20531. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20532. format: int32
  20533. minimum: 1
  20534. type: integer
  20535. okmsid:
  20536. description: specifies the OKMS ID.
  20537. type: string
  20538. server:
  20539. description: specifies the OKMS server endpoint.
  20540. type: string
  20541. required:
  20542. - auth
  20543. - okmsid
  20544. - server
  20545. type: object
  20546. passbolt:
  20547. description: |-
  20548. PassboltProvider provides access to Passbolt secrets manager.
  20549. See: https://www.passbolt.com.
  20550. properties:
  20551. auth:
  20552. description: Auth defines the information necessary to authenticate against Passbolt Server
  20553. properties:
  20554. passwordSecretRef:
  20555. description: |-
  20556. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20557. In some instances, `key` is a required field.
  20558. properties:
  20559. key:
  20560. description: |-
  20561. A key in the referenced Secret.
  20562. Some instances of this field may be defaulted, in others it may be required.
  20563. maxLength: 253
  20564. minLength: 1
  20565. pattern: ^[-._a-zA-Z0-9]+$
  20566. type: string
  20567. name:
  20568. description: The name of the Secret resource being referred to.
  20569. maxLength: 253
  20570. minLength: 1
  20571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20572. type: string
  20573. namespace:
  20574. description: |-
  20575. The namespace of the Secret resource being referred to.
  20576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20577. maxLength: 63
  20578. minLength: 1
  20579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20580. type: string
  20581. type: object
  20582. privateKeySecretRef:
  20583. description: |-
  20584. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20585. In some instances, `key` is a required field.
  20586. properties:
  20587. key:
  20588. description: |-
  20589. A key in the referenced Secret.
  20590. Some instances of this field may be defaulted, in others it may be required.
  20591. maxLength: 253
  20592. minLength: 1
  20593. pattern: ^[-._a-zA-Z0-9]+$
  20594. type: string
  20595. name:
  20596. description: The name of the Secret resource being referred to.
  20597. maxLength: 253
  20598. minLength: 1
  20599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20600. type: string
  20601. namespace:
  20602. description: |-
  20603. The namespace of the Secret resource being referred to.
  20604. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20605. maxLength: 63
  20606. minLength: 1
  20607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20608. type: string
  20609. type: object
  20610. required:
  20611. - passwordSecretRef
  20612. - privateKeySecretRef
  20613. type: object
  20614. caBundle:
  20615. description: |-
  20616. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20617. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20618. are used to validate the TLS connection.
  20619. format: byte
  20620. type: string
  20621. caProvider:
  20622. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20623. properties:
  20624. key:
  20625. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20626. maxLength: 253
  20627. minLength: 1
  20628. pattern: ^[-._a-zA-Z0-9]+$
  20629. type: string
  20630. name:
  20631. description: The name of the object located at the provider type.
  20632. maxLength: 253
  20633. minLength: 1
  20634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20635. type: string
  20636. namespace:
  20637. description: |-
  20638. The namespace the Provider type is in.
  20639. Can only be defined when used in a ClusterSecretStore.
  20640. maxLength: 63
  20641. minLength: 1
  20642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20643. type: string
  20644. type:
  20645. description: The type of provider to use such as "Secret", or "ConfigMap".
  20646. enum:
  20647. - Secret
  20648. - ConfigMap
  20649. type: string
  20650. required:
  20651. - name
  20652. - type
  20653. type: object
  20654. host:
  20655. description: Host defines the Passbolt Server to connect to
  20656. type: string
  20657. required:
  20658. - auth
  20659. - host
  20660. type: object
  20661. passworddepot:
  20662. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20663. properties:
  20664. auth:
  20665. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20666. properties:
  20667. secretRef:
  20668. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20669. properties:
  20670. credentials:
  20671. description: Username / Password is used for authentication.
  20672. properties:
  20673. key:
  20674. description: |-
  20675. A key in the referenced Secret.
  20676. Some instances of this field may be defaulted, in others it may be required.
  20677. maxLength: 253
  20678. minLength: 1
  20679. pattern: ^[-._a-zA-Z0-9]+$
  20680. type: string
  20681. name:
  20682. description: The name of the Secret resource being referred to.
  20683. maxLength: 253
  20684. minLength: 1
  20685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20686. type: string
  20687. namespace:
  20688. description: |-
  20689. The namespace of the Secret resource being referred to.
  20690. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20691. maxLength: 63
  20692. minLength: 1
  20693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20694. type: string
  20695. type: object
  20696. type: object
  20697. required:
  20698. - secretRef
  20699. type: object
  20700. database:
  20701. description: Database to use as source
  20702. type: string
  20703. host:
  20704. description: URL configures the Password Depot instance URL.
  20705. type: string
  20706. required:
  20707. - auth
  20708. - database
  20709. - host
  20710. type: object
  20711. previder:
  20712. description: Previder configures this store to sync secrets using the Previder provider
  20713. properties:
  20714. auth:
  20715. description: PreviderAuth contains a secretRef for credentials.
  20716. properties:
  20717. secretRef:
  20718. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20719. properties:
  20720. accessToken:
  20721. description: The AccessToken is used for authentication
  20722. properties:
  20723. key:
  20724. description: |-
  20725. A key in the referenced Secret.
  20726. Some instances of this field may be defaulted, in others it may be required.
  20727. maxLength: 253
  20728. minLength: 1
  20729. pattern: ^[-._a-zA-Z0-9]+$
  20730. type: string
  20731. name:
  20732. description: The name of the Secret resource being referred to.
  20733. maxLength: 253
  20734. minLength: 1
  20735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20736. type: string
  20737. namespace:
  20738. description: |-
  20739. The namespace of the Secret resource being referred to.
  20740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20741. maxLength: 63
  20742. minLength: 1
  20743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20744. type: string
  20745. type: object
  20746. required:
  20747. - accessToken
  20748. type: object
  20749. type: object
  20750. baseUri:
  20751. type: string
  20752. required:
  20753. - auth
  20754. type: object
  20755. pulumi:
  20756. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20757. properties:
  20758. accessToken:
  20759. description: |-
  20760. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20761. Deprecated: Use auth.accessToken instead.
  20762. properties:
  20763. secretRef:
  20764. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20765. properties:
  20766. key:
  20767. description: |-
  20768. A key in the referenced Secret.
  20769. Some instances of this field may be defaulted, in others it may be required.
  20770. maxLength: 253
  20771. minLength: 1
  20772. pattern: ^[-._a-zA-Z0-9]+$
  20773. type: string
  20774. name:
  20775. description: The name of the Secret resource being referred to.
  20776. maxLength: 253
  20777. minLength: 1
  20778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20779. type: string
  20780. namespace:
  20781. description: |-
  20782. The namespace of the Secret resource being referred to.
  20783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20784. maxLength: 63
  20785. minLength: 1
  20786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20787. type: string
  20788. type: object
  20789. type: object
  20790. apiUrl:
  20791. default: https://api.pulumi.com/api/esc
  20792. description: APIURL is the URL of the Pulumi API.
  20793. type: string
  20794. auth:
  20795. description: |-
  20796. Auth configures how the Operator authenticates with the Pulumi API.
  20797. Either auth or the deprecated accessToken field must be specified.
  20798. properties:
  20799. accessToken:
  20800. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20801. properties:
  20802. secretRef:
  20803. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20804. properties:
  20805. key:
  20806. description: |-
  20807. A key in the referenced Secret.
  20808. Some instances of this field may be defaulted, in others it may be required.
  20809. maxLength: 253
  20810. minLength: 1
  20811. pattern: ^[-._a-zA-Z0-9]+$
  20812. type: string
  20813. name:
  20814. description: The name of the Secret resource being referred to.
  20815. maxLength: 253
  20816. minLength: 1
  20817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20818. type: string
  20819. namespace:
  20820. description: |-
  20821. The namespace of the Secret resource being referred to.
  20822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20823. maxLength: 63
  20824. minLength: 1
  20825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20826. type: string
  20827. type: object
  20828. type: object
  20829. oidcConfig:
  20830. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20831. properties:
  20832. expirationSeconds:
  20833. default: 600
  20834. description: |-
  20835. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20836. Defaults to 10 minutes.
  20837. format: int64
  20838. minimum: 600
  20839. type: integer
  20840. organization:
  20841. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20842. type: string
  20843. serviceAccountRef:
  20844. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20845. properties:
  20846. audiences:
  20847. description: |-
  20848. Audience specifies the `aud` claim for the service account token
  20849. Some providers automatically extend the audience field based on well-known annotations for workload
  20850. identity (e.g. IRSA or GCP Workload Identity)
  20851. items:
  20852. type: string
  20853. type: array
  20854. name:
  20855. description: The name of the ServiceAccount resource being referred to.
  20856. maxLength: 253
  20857. minLength: 1
  20858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20859. type: string
  20860. namespace:
  20861. description: |-
  20862. Namespace of the resource being referred to.
  20863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20864. maxLength: 63
  20865. minLength: 1
  20866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20867. type: string
  20868. required:
  20869. - name
  20870. type: object
  20871. required:
  20872. - organization
  20873. - serviceAccountRef
  20874. type: object
  20875. type: object
  20876. x-kubernetes-validations:
  20877. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20878. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20879. environment:
  20880. description: |-
  20881. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20882. dynamically retrieved values from supported providers including all major clouds,
  20883. and other Pulumi ESC environments.
  20884. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20885. type: string
  20886. organization:
  20887. description: |-
  20888. Organization are a space to collaborate on shared projects and stacks.
  20889. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20890. type: string
  20891. project:
  20892. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20893. type: string
  20894. required:
  20895. - environment
  20896. - organization
  20897. - project
  20898. type: object
  20899. x-kubernetes-validations:
  20900. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20901. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20902. scaleway:
  20903. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20904. properties:
  20905. accessKey:
  20906. description: AccessKey is the non-secret part of the api key.
  20907. properties:
  20908. secretRef:
  20909. description: SecretRef references a key in a secret that will be used as value.
  20910. properties:
  20911. key:
  20912. description: |-
  20913. A key in the referenced Secret.
  20914. Some instances of this field may be defaulted, in others it may be required.
  20915. maxLength: 253
  20916. minLength: 1
  20917. pattern: ^[-._a-zA-Z0-9]+$
  20918. type: string
  20919. name:
  20920. description: The name of the Secret resource being referred to.
  20921. maxLength: 253
  20922. minLength: 1
  20923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20924. type: string
  20925. namespace:
  20926. description: |-
  20927. The namespace of the Secret resource being referred to.
  20928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20929. maxLength: 63
  20930. minLength: 1
  20931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20932. type: string
  20933. type: object
  20934. value:
  20935. description: Value can be specified directly to set a value without using a secret.
  20936. type: string
  20937. type: object
  20938. apiUrl:
  20939. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20940. type: string
  20941. projectId:
  20942. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20943. type: string
  20944. region:
  20945. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20946. type: string
  20947. secretKey:
  20948. description: SecretKey is the non-secret part of the api key.
  20949. properties:
  20950. secretRef:
  20951. description: SecretRef references a key in a secret that will be used as value.
  20952. properties:
  20953. key:
  20954. description: |-
  20955. A key in the referenced Secret.
  20956. Some instances of this field may be defaulted, in others it may be required.
  20957. maxLength: 253
  20958. minLength: 1
  20959. pattern: ^[-._a-zA-Z0-9]+$
  20960. type: string
  20961. name:
  20962. description: The name of the Secret resource being referred to.
  20963. maxLength: 253
  20964. minLength: 1
  20965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20966. type: string
  20967. namespace:
  20968. description: |-
  20969. The namespace of the Secret resource being referred to.
  20970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20971. maxLength: 63
  20972. minLength: 1
  20973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20974. type: string
  20975. type: object
  20976. value:
  20977. description: Value can be specified directly to set a value without using a secret.
  20978. type: string
  20979. type: object
  20980. required:
  20981. - accessKey
  20982. - projectId
  20983. - region
  20984. - secretKey
  20985. type: object
  20986. secretserver:
  20987. description: |-
  20988. SecretServer configures this store to sync secrets using SecretServer provider
  20989. https://docs.delinea.com/online-help/secret-server/start.htm
  20990. properties:
  20991. caBundle:
  20992. description: |-
  20993. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20994. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20995. are used to validate the TLS connection.
  20996. format: byte
  20997. type: string
  20998. caProvider:
  20999. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  21000. properties:
  21001. key:
  21002. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21003. maxLength: 253
  21004. minLength: 1
  21005. pattern: ^[-._a-zA-Z0-9]+$
  21006. type: string
  21007. name:
  21008. description: The name of the object located at the provider type.
  21009. maxLength: 253
  21010. minLength: 1
  21011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21012. type: string
  21013. namespace:
  21014. description: |-
  21015. The namespace the Provider type is in.
  21016. Can only be defined when used in a ClusterSecretStore.
  21017. maxLength: 63
  21018. minLength: 1
  21019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21020. type: string
  21021. type:
  21022. description: The type of provider to use such as "Secret", or "ConfigMap".
  21023. enum:
  21024. - Secret
  21025. - ConfigMap
  21026. type: string
  21027. required:
  21028. - name
  21029. - type
  21030. type: object
  21031. disableSiteIDValidation:
  21032. description: |-
  21033. DisableSiteIDValidation permits a missing site ID for new secrets.
  21034. The provider sends 0 if no site ID is set.
  21035. type: boolean
  21036. domain:
  21037. description: Domain is the secret server domain.
  21038. type: string
  21039. password:
  21040. description: |-
  21041. Password is the secret server account password.
  21042. Required unless Token is set.
  21043. properties:
  21044. secretRef:
  21045. description: SecretRef references a key in a secret that will be used as value.
  21046. properties:
  21047. key:
  21048. description: |-
  21049. A key in the referenced Secret.
  21050. Some instances of this field may be defaulted, in others it may be required.
  21051. maxLength: 253
  21052. minLength: 1
  21053. pattern: ^[-._a-zA-Z0-9]+$
  21054. type: string
  21055. name:
  21056. description: The name of the Secret resource being referred to.
  21057. maxLength: 253
  21058. minLength: 1
  21059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21060. type: string
  21061. namespace:
  21062. description: |-
  21063. The namespace of the Secret resource being referred to.
  21064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21065. maxLength: 63
  21066. minLength: 1
  21067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21068. type: string
  21069. type: object
  21070. value:
  21071. description: Value can be specified directly to set a value without using a secret.
  21072. minLength: 1
  21073. type: string
  21074. type: object
  21075. x-kubernetes-validations:
  21076. - message: exactly one of value or secretRef must be set
  21077. rule: has(self.value) != has(self.secretRef)
  21078. serverURL:
  21079. description: |-
  21080. ServerURL
  21081. URL to your secret server installation
  21082. type: string
  21083. siteId:
  21084. description: |-
  21085. SiteID is the ID of the Secret Server site for new secrets.
  21086. PushSecret metadata can override this value for one secret.
  21087. The provider uses 1 if this field is not set.
  21088. minimum: 1
  21089. type: integer
  21090. token:
  21091. description: |-
  21092. Token is an access token used to authenticate to the secret server,
  21093. as an alternative to Username and Password. When set, Username and
  21094. Password are not required and are ignored.
  21095. properties:
  21096. secretRef:
  21097. description: SecretRef references a key in a secret that will be used as value.
  21098. properties:
  21099. key:
  21100. description: |-
  21101. A key in the referenced Secret.
  21102. Some instances of this field may be defaulted, in others it may be required.
  21103. maxLength: 253
  21104. minLength: 1
  21105. pattern: ^[-._a-zA-Z0-9]+$
  21106. type: string
  21107. name:
  21108. description: The name of the Secret resource being referred to.
  21109. maxLength: 253
  21110. minLength: 1
  21111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21112. type: string
  21113. namespace:
  21114. description: |-
  21115. The namespace of the Secret resource being referred to.
  21116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21117. maxLength: 63
  21118. minLength: 1
  21119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21120. type: string
  21121. type: object
  21122. value:
  21123. description: Value can be specified directly to set a value without using a secret.
  21124. minLength: 1
  21125. type: string
  21126. type: object
  21127. x-kubernetes-validations:
  21128. - message: exactly one of value or secretRef must be set
  21129. rule: has(self.value) != has(self.secretRef)
  21130. username:
  21131. description: |-
  21132. Username is the secret server account username.
  21133. Required unless Token is set.
  21134. properties:
  21135. secretRef:
  21136. description: SecretRef references a key in a secret that will be used as value.
  21137. properties:
  21138. key:
  21139. description: |-
  21140. A key in the referenced Secret.
  21141. Some instances of this field may be defaulted, in others it may be required.
  21142. maxLength: 253
  21143. minLength: 1
  21144. pattern: ^[-._a-zA-Z0-9]+$
  21145. type: string
  21146. name:
  21147. description: The name of the Secret resource being referred to.
  21148. maxLength: 253
  21149. minLength: 1
  21150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21151. type: string
  21152. namespace:
  21153. description: |-
  21154. The namespace of the Secret resource being referred to.
  21155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21156. maxLength: 63
  21157. minLength: 1
  21158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21159. type: string
  21160. type: object
  21161. value:
  21162. description: Value can be specified directly to set a value without using a secret.
  21163. minLength: 1
  21164. type: string
  21165. type: object
  21166. x-kubernetes-validations:
  21167. - message: exactly one of value or secretRef must be set
  21168. rule: has(self.value) != has(self.secretRef)
  21169. required:
  21170. - serverURL
  21171. type: object
  21172. x-kubernetes-validations:
  21173. - message: either token, or both username and password, must be set
  21174. rule: has(self.token) || (has(self.username) && has(self.password))
  21175. senhasegura:
  21176. description: Senhasegura configures this store to sync secrets using senhasegura provider
  21177. properties:
  21178. auth:
  21179. description: Auth defines parameters to authenticate in senhasegura
  21180. properties:
  21181. clientId:
  21182. type: string
  21183. clientSecretSecretRef:
  21184. description: |-
  21185. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21186. In some instances, `key` is a required field.
  21187. properties:
  21188. key:
  21189. description: |-
  21190. A key in the referenced Secret.
  21191. Some instances of this field may be defaulted, in others it may be required.
  21192. maxLength: 253
  21193. minLength: 1
  21194. pattern: ^[-._a-zA-Z0-9]+$
  21195. type: string
  21196. name:
  21197. description: The name of the Secret resource being referred to.
  21198. maxLength: 253
  21199. minLength: 1
  21200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21201. type: string
  21202. namespace:
  21203. description: |-
  21204. The namespace of the Secret resource being referred to.
  21205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21206. maxLength: 63
  21207. minLength: 1
  21208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21209. type: string
  21210. type: object
  21211. required:
  21212. - clientId
  21213. - clientSecretSecretRef
  21214. type: object
  21215. ignoreSslCertificate:
  21216. default: false
  21217. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21218. type: boolean
  21219. module:
  21220. description: Module defines which senhasegura module should be used to get secrets
  21221. type: string
  21222. url:
  21223. description: URL of senhasegura
  21224. type: string
  21225. required:
  21226. - auth
  21227. - module
  21228. - url
  21229. type: object
  21230. vault:
  21231. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21232. properties:
  21233. auth:
  21234. description: Auth configures how secret-manager authenticates with the Vault server.
  21235. properties:
  21236. appRole:
  21237. description: |-
  21238. AppRole authenticates with Vault using the App Role auth mechanism,
  21239. with the role and secret stored in a Kubernetes Secret resource.
  21240. properties:
  21241. path:
  21242. default: approle
  21243. description: |-
  21244. Path where the App Role authentication backend is mounted
  21245. in Vault, e.g: "approle"
  21246. type: string
  21247. roleId:
  21248. description: |-
  21249. RoleID configured in the App Role authentication backend when setting
  21250. up the authentication backend in Vault.
  21251. type: string
  21252. roleRef:
  21253. description: |-
  21254. Reference to a key in a Secret that contains the App Role ID used
  21255. to authenticate with Vault.
  21256. The `key` field must be specified and denotes which entry within the Secret
  21257. resource is used as the app role id.
  21258. properties:
  21259. key:
  21260. description: |-
  21261. A key in the referenced Secret.
  21262. Some instances of this field may be defaulted, in others it may be required.
  21263. maxLength: 253
  21264. minLength: 1
  21265. pattern: ^[-._a-zA-Z0-9]+$
  21266. type: string
  21267. name:
  21268. description: The name of the Secret resource being referred to.
  21269. maxLength: 253
  21270. minLength: 1
  21271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21272. type: string
  21273. namespace:
  21274. description: |-
  21275. The namespace of the Secret resource being referred to.
  21276. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21277. maxLength: 63
  21278. minLength: 1
  21279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21280. type: string
  21281. type: object
  21282. secretRef:
  21283. description: |-
  21284. Reference to a key in a Secret that contains the App Role secret used
  21285. to authenticate with Vault.
  21286. The `key` field must be specified and denotes which entry within the Secret
  21287. resource is used as the app role secret.
  21288. properties:
  21289. key:
  21290. description: |-
  21291. A key in the referenced Secret.
  21292. Some instances of this field may be defaulted, in others it may be required.
  21293. maxLength: 253
  21294. minLength: 1
  21295. pattern: ^[-._a-zA-Z0-9]+$
  21296. type: string
  21297. name:
  21298. description: The name of the Secret resource being referred to.
  21299. maxLength: 253
  21300. minLength: 1
  21301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21302. type: string
  21303. namespace:
  21304. description: |-
  21305. The namespace of the Secret resource being referred to.
  21306. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21307. maxLength: 63
  21308. minLength: 1
  21309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21310. type: string
  21311. type: object
  21312. required:
  21313. - path
  21314. - secretRef
  21315. type: object
  21316. cert:
  21317. description: |-
  21318. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21319. Cert authentication method
  21320. properties:
  21321. clientCert:
  21322. description: |-
  21323. ClientCert is a certificate to authenticate using the Cert Vault
  21324. authentication method
  21325. properties:
  21326. key:
  21327. description: |-
  21328. A key in the referenced Secret.
  21329. Some instances of this field may be defaulted, in others it may be required.
  21330. maxLength: 253
  21331. minLength: 1
  21332. pattern: ^[-._a-zA-Z0-9]+$
  21333. type: string
  21334. name:
  21335. description: The name of the Secret resource being referred to.
  21336. maxLength: 253
  21337. minLength: 1
  21338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21339. type: string
  21340. namespace:
  21341. description: |-
  21342. The namespace of the Secret resource being referred to.
  21343. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21344. maxLength: 63
  21345. minLength: 1
  21346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21347. type: string
  21348. type: object
  21349. path:
  21350. default: cert
  21351. description: |-
  21352. Path where the Certificate authentication backend is mounted
  21353. in Vault, e.g: "cert"
  21354. type: string
  21355. secretRef:
  21356. description: |-
  21357. SecretRef to a key in a Secret resource containing client private key to
  21358. authenticate with Vault using the Cert authentication method
  21359. properties:
  21360. key:
  21361. description: |-
  21362. A key in the referenced Secret.
  21363. Some instances of this field may be defaulted, in others it may be required.
  21364. maxLength: 253
  21365. minLength: 1
  21366. pattern: ^[-._a-zA-Z0-9]+$
  21367. type: string
  21368. name:
  21369. description: The name of the Secret resource being referred to.
  21370. maxLength: 253
  21371. minLength: 1
  21372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21373. type: string
  21374. namespace:
  21375. description: |-
  21376. The namespace of the Secret resource being referred to.
  21377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21378. maxLength: 63
  21379. minLength: 1
  21380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21381. type: string
  21382. type: object
  21383. vaultRole:
  21384. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21385. type: string
  21386. type: object
  21387. gcp:
  21388. description: |-
  21389. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21390. GCP authentication method
  21391. properties:
  21392. location:
  21393. description: Location optionally defines a location/region for the secret
  21394. type: string
  21395. path:
  21396. default: gcp
  21397. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21398. type: string
  21399. projectID:
  21400. description: Project ID of the Google Cloud Platform project
  21401. type: string
  21402. role:
  21403. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21404. type: string
  21405. secretRef:
  21406. description: Specify credentials in a Secret object
  21407. properties:
  21408. secretAccessKeySecretRef:
  21409. description: The SecretAccessKey is used for authentication
  21410. properties:
  21411. key:
  21412. description: |-
  21413. A key in the referenced Secret.
  21414. Some instances of this field may be defaulted, in others it may be required.
  21415. maxLength: 253
  21416. minLength: 1
  21417. pattern: ^[-._a-zA-Z0-9]+$
  21418. type: string
  21419. name:
  21420. description: The name of the Secret resource being referred to.
  21421. maxLength: 253
  21422. minLength: 1
  21423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21424. type: string
  21425. namespace:
  21426. description: |-
  21427. The namespace of the Secret resource being referred to.
  21428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21429. maxLength: 63
  21430. minLength: 1
  21431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21432. type: string
  21433. type: object
  21434. type: object
  21435. serviceAccountRef:
  21436. description: ServiceAccountRef to a service account for impersonation
  21437. properties:
  21438. audiences:
  21439. description: |-
  21440. Audience specifies the `aud` claim for the service account token
  21441. Some providers automatically extend the audience field based on well-known annotations for workload
  21442. identity (e.g. IRSA or GCP Workload Identity)
  21443. items:
  21444. type: string
  21445. type: array
  21446. name:
  21447. description: The name of the ServiceAccount resource being referred to.
  21448. maxLength: 253
  21449. minLength: 1
  21450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21451. type: string
  21452. namespace:
  21453. description: |-
  21454. Namespace of the resource being referred to.
  21455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21456. maxLength: 63
  21457. minLength: 1
  21458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21459. type: string
  21460. required:
  21461. - name
  21462. type: object
  21463. workloadIdentity:
  21464. description: Specify a service account with Workload Identity
  21465. properties:
  21466. clusterLocation:
  21467. description: |-
  21468. ClusterLocation is the location of the cluster
  21469. If not specified, it fetches information from the metadata server
  21470. type: string
  21471. clusterName:
  21472. description: |-
  21473. ClusterName is the name of the cluster
  21474. If not specified, it fetches information from the metadata server
  21475. type: string
  21476. clusterProjectID:
  21477. description: |-
  21478. ClusterProjectID is the project ID of the cluster
  21479. If not specified, it fetches information from the metadata server
  21480. type: string
  21481. serviceAccountRef:
  21482. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21483. properties:
  21484. audiences:
  21485. description: |-
  21486. Audience specifies the `aud` claim for the service account token
  21487. Some providers automatically extend the audience field based on well-known annotations for workload
  21488. identity (e.g. IRSA or GCP Workload Identity)
  21489. items:
  21490. type: string
  21491. type: array
  21492. name:
  21493. description: The name of the ServiceAccount resource being referred to.
  21494. maxLength: 253
  21495. minLength: 1
  21496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21497. type: string
  21498. namespace:
  21499. description: |-
  21500. Namespace of the resource being referred to.
  21501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21502. maxLength: 63
  21503. minLength: 1
  21504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21505. type: string
  21506. required:
  21507. - name
  21508. type: object
  21509. required:
  21510. - serviceAccountRef
  21511. type: object
  21512. required:
  21513. - role
  21514. type: object
  21515. iam:
  21516. description: |-
  21517. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21518. AWS IAM authentication method
  21519. properties:
  21520. externalID:
  21521. description: AWS External ID set on assumed IAM roles
  21522. type: string
  21523. jwt:
  21524. description: Specify a service account with IRSA enabled
  21525. properties:
  21526. serviceAccountRef:
  21527. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21528. properties:
  21529. audiences:
  21530. description: |-
  21531. Audience specifies the `aud` claim for the service account token
  21532. Some providers automatically extend the audience field based on well-known annotations for workload
  21533. identity (e.g. IRSA or GCP Workload Identity)
  21534. items:
  21535. type: string
  21536. type: array
  21537. name:
  21538. description: The name of the ServiceAccount resource being referred to.
  21539. maxLength: 253
  21540. minLength: 1
  21541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21542. type: string
  21543. namespace:
  21544. description: |-
  21545. Namespace of the resource being referred to.
  21546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21547. maxLength: 63
  21548. minLength: 1
  21549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21550. type: string
  21551. required:
  21552. - name
  21553. type: object
  21554. type: object
  21555. path:
  21556. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21557. type: string
  21558. region:
  21559. description: AWS region
  21560. type: string
  21561. role:
  21562. description: This is the AWS role to be assumed before talking to vault
  21563. type: string
  21564. secretRef:
  21565. description: Specify credentials in a Secret object
  21566. properties:
  21567. accessKeyIDSecretRef:
  21568. description: The AccessKeyID is used for authentication
  21569. properties:
  21570. key:
  21571. description: |-
  21572. A key in the referenced Secret.
  21573. Some instances of this field may be defaulted, in others it may be required.
  21574. maxLength: 253
  21575. minLength: 1
  21576. pattern: ^[-._a-zA-Z0-9]+$
  21577. type: string
  21578. name:
  21579. description: The name of the Secret resource being referred to.
  21580. maxLength: 253
  21581. minLength: 1
  21582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21583. type: string
  21584. namespace:
  21585. description: |-
  21586. The namespace of the Secret resource being referred to.
  21587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21588. maxLength: 63
  21589. minLength: 1
  21590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21591. type: string
  21592. type: object
  21593. secretAccessKeySecretRef:
  21594. description: The SecretAccessKey is used for authentication
  21595. properties:
  21596. key:
  21597. description: |-
  21598. A key in the referenced Secret.
  21599. Some instances of this field may be defaulted, in others it may be required.
  21600. maxLength: 253
  21601. minLength: 1
  21602. pattern: ^[-._a-zA-Z0-9]+$
  21603. type: string
  21604. name:
  21605. description: The name of the Secret resource being referred to.
  21606. maxLength: 253
  21607. minLength: 1
  21608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21609. type: string
  21610. namespace:
  21611. description: |-
  21612. The namespace of the Secret resource being referred to.
  21613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21614. maxLength: 63
  21615. minLength: 1
  21616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21617. type: string
  21618. type: object
  21619. sessionTokenSecretRef:
  21620. description: |-
  21621. The SessionToken used for authentication
  21622. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21623. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21624. properties:
  21625. key:
  21626. description: |-
  21627. A key in the referenced Secret.
  21628. Some instances of this field may be defaulted, in others it may be required.
  21629. maxLength: 253
  21630. minLength: 1
  21631. pattern: ^[-._a-zA-Z0-9]+$
  21632. type: string
  21633. name:
  21634. description: The name of the Secret resource being referred to.
  21635. maxLength: 253
  21636. minLength: 1
  21637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21638. type: string
  21639. namespace:
  21640. description: |-
  21641. The namespace of the Secret resource being referred to.
  21642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21643. maxLength: 63
  21644. minLength: 1
  21645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21646. type: string
  21647. type: object
  21648. type: object
  21649. vaultAwsIamServerID:
  21650. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21651. type: string
  21652. vaultRole:
  21653. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21654. type: string
  21655. required:
  21656. - vaultRole
  21657. type: object
  21658. jwt:
  21659. description: |-
  21660. Jwt authenticates with Vault by passing role and JWT token using the
  21661. JWT/OIDC authentication method
  21662. properties:
  21663. kubernetesServiceAccountToken:
  21664. description: |-
  21665. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21666. a token for with the `TokenRequest` API.
  21667. properties:
  21668. audiences:
  21669. description: |-
  21670. Optional audiences field that will be used to request a temporary Kubernetes service
  21671. account token for the service account referenced by `serviceAccountRef`.
  21672. Defaults to a single audience `vault` it not specified.
  21673. Deprecated: use serviceAccountRef.Audiences instead
  21674. items:
  21675. type: string
  21676. type: array
  21677. expirationSeconds:
  21678. description: |-
  21679. Optional expiration time in seconds that will be used to request a temporary
  21680. Kubernetes service account token for the service account referenced by
  21681. `serviceAccountRef`.
  21682. Deprecated: this will be removed in the future.
  21683. Defaults to 10 minutes.
  21684. format: int64
  21685. type: integer
  21686. serviceAccountRef:
  21687. description: Service account field containing the name of a kubernetes ServiceAccount.
  21688. properties:
  21689. audiences:
  21690. description: |-
  21691. Audience specifies the `aud` claim for the service account token
  21692. Some providers automatically extend the audience field based on well-known annotations for workload
  21693. identity (e.g. IRSA or GCP Workload Identity)
  21694. items:
  21695. type: string
  21696. type: array
  21697. name:
  21698. description: The name of the ServiceAccount resource being referred to.
  21699. maxLength: 253
  21700. minLength: 1
  21701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21702. type: string
  21703. namespace:
  21704. description: |-
  21705. Namespace of the resource being referred to.
  21706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21707. maxLength: 63
  21708. minLength: 1
  21709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21710. type: string
  21711. required:
  21712. - name
  21713. type: object
  21714. required:
  21715. - serviceAccountRef
  21716. type: object
  21717. path:
  21718. default: jwt
  21719. description: |-
  21720. Path where the JWT authentication backend is mounted
  21721. in Vault, e.g: "jwt"
  21722. type: string
  21723. role:
  21724. description: |-
  21725. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21726. authentication method
  21727. type: string
  21728. secretRef:
  21729. description: |-
  21730. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21731. authenticate with Vault using the JWT/OIDC authentication method.
  21732. properties:
  21733. key:
  21734. description: |-
  21735. A key in the referenced Secret.
  21736. Some instances of this field may be defaulted, in others it may be required.
  21737. maxLength: 253
  21738. minLength: 1
  21739. pattern: ^[-._a-zA-Z0-9]+$
  21740. type: string
  21741. name:
  21742. description: The name of the Secret resource being referred to.
  21743. maxLength: 253
  21744. minLength: 1
  21745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21746. type: string
  21747. namespace:
  21748. description: |-
  21749. The namespace of the Secret resource being referred to.
  21750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21751. maxLength: 63
  21752. minLength: 1
  21753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21754. type: string
  21755. type: object
  21756. required:
  21757. - path
  21758. type: object
  21759. kubernetes:
  21760. description: |-
  21761. Kubernetes authenticates with Vault by passing the ServiceAccount
  21762. token stored in the named Secret resource to the Vault server.
  21763. properties:
  21764. mountPath:
  21765. default: kubernetes
  21766. description: |-
  21767. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21768. "kubernetes"
  21769. type: string
  21770. role:
  21771. description: |-
  21772. A required field containing the Vault Role to assume. A Role binds a
  21773. Kubernetes ServiceAccount with a set of Vault policies.
  21774. type: string
  21775. secretRef:
  21776. description: |-
  21777. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21778. for authenticating with Vault. If a name is specified without a key,
  21779. `token` is the default. If one is not specified, the one bound to
  21780. the controller will be used.
  21781. properties:
  21782. key:
  21783. description: |-
  21784. A key in the referenced Secret.
  21785. Some instances of this field may be defaulted, in others it may be required.
  21786. maxLength: 253
  21787. minLength: 1
  21788. pattern: ^[-._a-zA-Z0-9]+$
  21789. type: string
  21790. name:
  21791. description: The name of the Secret resource being referred to.
  21792. maxLength: 253
  21793. minLength: 1
  21794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21795. type: string
  21796. namespace:
  21797. description: |-
  21798. The namespace of the Secret resource being referred to.
  21799. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21800. maxLength: 63
  21801. minLength: 1
  21802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21803. type: string
  21804. type: object
  21805. serviceAccountRef:
  21806. description: |-
  21807. Optional service account field containing the name of a kubernetes ServiceAccount.
  21808. If the service account is specified, the service account secret token JWT will be used
  21809. for authenticating with Vault. If the service account selector is not supplied,
  21810. the secretRef will be used instead.
  21811. properties:
  21812. audiences:
  21813. description: |-
  21814. Audience specifies the `aud` claim for the service account token
  21815. Some providers automatically extend the audience field based on well-known annotations for workload
  21816. identity (e.g. IRSA or GCP Workload Identity)
  21817. items:
  21818. type: string
  21819. type: array
  21820. name:
  21821. description: The name of the ServiceAccount resource being referred to.
  21822. maxLength: 253
  21823. minLength: 1
  21824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21825. type: string
  21826. namespace:
  21827. description: |-
  21828. Namespace of the resource being referred to.
  21829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21830. maxLength: 63
  21831. minLength: 1
  21832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21833. type: string
  21834. required:
  21835. - name
  21836. type: object
  21837. required:
  21838. - mountPath
  21839. - role
  21840. type: object
  21841. ldap:
  21842. description: |-
  21843. Ldap authenticates with Vault by passing username/password pair using
  21844. the LDAP authentication method
  21845. properties:
  21846. path:
  21847. default: ldap
  21848. description: |-
  21849. Path where the LDAP authentication backend is mounted
  21850. in Vault, e.g: "ldap"
  21851. type: string
  21852. secretRef:
  21853. description: |-
  21854. SecretRef to a key in a Secret resource containing password for the LDAP
  21855. user used to authenticate with Vault using the LDAP authentication
  21856. method
  21857. properties:
  21858. key:
  21859. description: |-
  21860. A key in the referenced Secret.
  21861. Some instances of this field may be defaulted, in others it may be required.
  21862. maxLength: 253
  21863. minLength: 1
  21864. pattern: ^[-._a-zA-Z0-9]+$
  21865. type: string
  21866. name:
  21867. description: The name of the Secret resource being referred to.
  21868. maxLength: 253
  21869. minLength: 1
  21870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21871. type: string
  21872. namespace:
  21873. description: |-
  21874. The namespace of the Secret resource being referred to.
  21875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21876. maxLength: 63
  21877. minLength: 1
  21878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21879. type: string
  21880. type: object
  21881. username:
  21882. description: |-
  21883. Username is an LDAP username used to authenticate using the LDAP Vault
  21884. authentication method
  21885. type: string
  21886. required:
  21887. - path
  21888. - username
  21889. type: object
  21890. namespace:
  21891. description: |-
  21892. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21893. Namespaces is a set of features within Vault Enterprise that allows
  21894. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21895. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21896. This will default to Vault.Namespace field if set, or empty otherwise
  21897. type: string
  21898. tokenSecretRef:
  21899. description: TokenSecretRef authenticates with Vault by presenting a token.
  21900. properties:
  21901. key:
  21902. description: |-
  21903. A key in the referenced Secret.
  21904. Some instances of this field may be defaulted, in others it may be required.
  21905. maxLength: 253
  21906. minLength: 1
  21907. pattern: ^[-._a-zA-Z0-9]+$
  21908. type: string
  21909. name:
  21910. description: The name of the Secret resource being referred to.
  21911. maxLength: 253
  21912. minLength: 1
  21913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21914. type: string
  21915. namespace:
  21916. description: |-
  21917. The namespace of the Secret resource being referred to.
  21918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21919. maxLength: 63
  21920. minLength: 1
  21921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21922. type: string
  21923. type: object
  21924. userPass:
  21925. description: UserPass authenticates with Vault by passing username/password pair
  21926. properties:
  21927. path:
  21928. default: userpass
  21929. description: |-
  21930. Path where the UserPassword authentication backend is mounted
  21931. in Vault, e.g: "userpass"
  21932. type: string
  21933. secretRef:
  21934. description: |-
  21935. SecretRef to a key in a Secret resource containing password for the
  21936. user used to authenticate with Vault using the UserPass authentication
  21937. method
  21938. properties:
  21939. key:
  21940. description: |-
  21941. A key in the referenced Secret.
  21942. Some instances of this field may be defaulted, in others it may be required.
  21943. maxLength: 253
  21944. minLength: 1
  21945. pattern: ^[-._a-zA-Z0-9]+$
  21946. type: string
  21947. name:
  21948. description: The name of the Secret resource being referred to.
  21949. maxLength: 253
  21950. minLength: 1
  21951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21952. type: string
  21953. namespace:
  21954. description: |-
  21955. The namespace of the Secret resource being referred to.
  21956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21957. maxLength: 63
  21958. minLength: 1
  21959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21960. type: string
  21961. type: object
  21962. username:
  21963. description: |-
  21964. Username is a username used to authenticate using the UserPass Vault
  21965. authentication method
  21966. type: string
  21967. required:
  21968. - path
  21969. - username
  21970. type: object
  21971. type: object
  21972. caBundle:
  21973. description: |-
  21974. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21975. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21976. plain HTTP protocol connection. If not set the system root certificates
  21977. are used to validate the TLS connection.
  21978. format: byte
  21979. type: string
  21980. caProvider:
  21981. description: The provider for the CA bundle to use to validate Vault server certificate.
  21982. properties:
  21983. key:
  21984. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21985. maxLength: 253
  21986. minLength: 1
  21987. pattern: ^[-._a-zA-Z0-9]+$
  21988. type: string
  21989. name:
  21990. description: The name of the object located at the provider type.
  21991. maxLength: 253
  21992. minLength: 1
  21993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21994. type: string
  21995. namespace:
  21996. description: |-
  21997. The namespace the Provider type is in.
  21998. Can only be defined when used in a ClusterSecretStore.
  21999. maxLength: 63
  22000. minLength: 1
  22001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22002. type: string
  22003. type:
  22004. description: The type of provider to use such as "Secret", or "ConfigMap".
  22005. enum:
  22006. - Secret
  22007. - ConfigMap
  22008. type: string
  22009. required:
  22010. - name
  22011. - type
  22012. type: object
  22013. checkAndSet:
  22014. description: |-
  22015. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  22016. Only applies to Vault KV v2 stores. When enabled, write operations must include
  22017. the current version of the secret to prevent unintentional overwrites.
  22018. properties:
  22019. required:
  22020. description: |-
  22021. Required when true, all write operations must include a check-and-set parameter.
  22022. This helps prevent unintentional overwrites of secrets.
  22023. type: boolean
  22024. type: object
  22025. forwardInconsistent:
  22026. description: |-
  22027. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  22028. leader instead of simply retrying within a loop. This can increase performance if
  22029. the option is enabled serverside.
  22030. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  22031. type: boolean
  22032. headers:
  22033. additionalProperties:
  22034. type: string
  22035. description: Headers to be added in Vault request
  22036. type: object
  22037. namespace:
  22038. description: |-
  22039. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  22040. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22041. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22042. type: string
  22043. path:
  22044. description: |-
  22045. Path is the mount path of the Vault KV backend endpoint, e.g:
  22046. "secret". The v2 KV secret engine version specific "/data" path suffix
  22047. for fetching secrets from Vault is optional and will be appended
  22048. if not present in specified path.
  22049. type: string
  22050. readYourWrites:
  22051. description: |-
  22052. ReadYourWrites ensures isolated read-after-write semantics by
  22053. providing discovered cluster replication states in each request.
  22054. More information about eventual consistency in Vault can be found here
  22055. https://www.vaultproject.io/docs/enterprise/consistency
  22056. type: boolean
  22057. server:
  22058. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  22059. type: string
  22060. tls:
  22061. description: |-
  22062. The configuration used for client side related TLS communication, when the Vault server
  22063. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  22064. This parameter is ignored for plain HTTP protocol connection.
  22065. It's worth noting this configuration is different from the "TLS certificates auth method",
  22066. which is available under the `auth.cert` section.
  22067. properties:
  22068. certSecretRef:
  22069. description: |-
  22070. CertSecretRef is a certificate added to the transport layer
  22071. when communicating with the Vault server.
  22072. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  22073. properties:
  22074. key:
  22075. description: |-
  22076. A key in the referenced Secret.
  22077. Some instances of this field may be defaulted, in others it may be required.
  22078. maxLength: 253
  22079. minLength: 1
  22080. pattern: ^[-._a-zA-Z0-9]+$
  22081. type: string
  22082. name:
  22083. description: The name of the Secret resource being referred to.
  22084. maxLength: 253
  22085. minLength: 1
  22086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22087. type: string
  22088. namespace:
  22089. description: |-
  22090. The namespace of the Secret resource being referred to.
  22091. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22092. maxLength: 63
  22093. minLength: 1
  22094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22095. type: string
  22096. type: object
  22097. keySecretRef:
  22098. description: |-
  22099. KeySecretRef to a key in a Secret resource containing client private key
  22100. added to the transport layer when communicating with the Vault server.
  22101. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  22102. properties:
  22103. key:
  22104. description: |-
  22105. A key in the referenced Secret.
  22106. Some instances of this field may be defaulted, in others it may be required.
  22107. maxLength: 253
  22108. minLength: 1
  22109. pattern: ^[-._a-zA-Z0-9]+$
  22110. type: string
  22111. name:
  22112. description: The name of the Secret resource being referred to.
  22113. maxLength: 253
  22114. minLength: 1
  22115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22116. type: string
  22117. namespace:
  22118. description: |-
  22119. The namespace of the Secret resource being referred to.
  22120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22121. maxLength: 63
  22122. minLength: 1
  22123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22124. type: string
  22125. type: object
  22126. type: object
  22127. version:
  22128. default: v2
  22129. description: |-
  22130. Version is the Vault KV secret engine version. This can be either "v1" or
  22131. "v2". Version defaults to "v2".
  22132. enum:
  22133. - v1
  22134. - v2
  22135. type: string
  22136. required:
  22137. - server
  22138. type: object
  22139. volcengine:
  22140. description: Volcengine configures this store to sync secrets using the Volcengine provider
  22141. properties:
  22142. auth:
  22143. description: |-
  22144. Auth defines the authentication method to use.
  22145. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  22146. properties:
  22147. secretRef:
  22148. description: |-
  22149. SecretRef defines the static credentials to use for authentication.
  22150. If not set, IRSA is used.
  22151. properties:
  22152. accessKeyID:
  22153. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  22154. properties:
  22155. key:
  22156. description: |-
  22157. A key in the referenced Secret.
  22158. Some instances of this field may be defaulted, in others it may be required.
  22159. maxLength: 253
  22160. minLength: 1
  22161. pattern: ^[-._a-zA-Z0-9]+$
  22162. type: string
  22163. name:
  22164. description: The name of the Secret resource being referred to.
  22165. maxLength: 253
  22166. minLength: 1
  22167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22168. type: string
  22169. namespace:
  22170. description: |-
  22171. The namespace of the Secret resource being referred to.
  22172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22173. maxLength: 63
  22174. minLength: 1
  22175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22176. type: string
  22177. type: object
  22178. secretAccessKey:
  22179. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  22180. properties:
  22181. key:
  22182. description: |-
  22183. A key in the referenced Secret.
  22184. Some instances of this field may be defaulted, in others it may be required.
  22185. maxLength: 253
  22186. minLength: 1
  22187. pattern: ^[-._a-zA-Z0-9]+$
  22188. type: string
  22189. name:
  22190. description: The name of the Secret resource being referred to.
  22191. maxLength: 253
  22192. minLength: 1
  22193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22194. type: string
  22195. namespace:
  22196. description: |-
  22197. The namespace of the Secret resource being referred to.
  22198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22199. maxLength: 63
  22200. minLength: 1
  22201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22202. type: string
  22203. type: object
  22204. token:
  22205. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22206. properties:
  22207. key:
  22208. description: |-
  22209. A key in the referenced Secret.
  22210. Some instances of this field may be defaulted, in others it may be required.
  22211. maxLength: 253
  22212. minLength: 1
  22213. pattern: ^[-._a-zA-Z0-9]+$
  22214. type: string
  22215. name:
  22216. description: The name of the Secret resource being referred to.
  22217. maxLength: 253
  22218. minLength: 1
  22219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22220. type: string
  22221. namespace:
  22222. description: |-
  22223. The namespace of the Secret resource being referred to.
  22224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22225. maxLength: 63
  22226. minLength: 1
  22227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22228. type: string
  22229. type: object
  22230. required:
  22231. - accessKeyID
  22232. - secretAccessKey
  22233. type: object
  22234. type: object
  22235. region:
  22236. description: Region specifies the Volcengine region to connect to.
  22237. type: string
  22238. required:
  22239. - region
  22240. type: object
  22241. webhook:
  22242. description: Webhook configures this store to sync secrets using a generic templated webhook
  22243. properties:
  22244. auth:
  22245. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22246. maxProperties: 1
  22247. minProperties: 1
  22248. properties:
  22249. ntlm:
  22250. description: NTLMProtocol configures the store to use NTLM for auth
  22251. properties:
  22252. passwordSecret:
  22253. description: |-
  22254. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22255. In some instances, `key` is a required field.
  22256. properties:
  22257. key:
  22258. description: |-
  22259. A key in the referenced Secret.
  22260. Some instances of this field may be defaulted, in others it may be required.
  22261. maxLength: 253
  22262. minLength: 1
  22263. pattern: ^[-._a-zA-Z0-9]+$
  22264. type: string
  22265. name:
  22266. description: The name of the Secret resource being referred to.
  22267. maxLength: 253
  22268. minLength: 1
  22269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22270. type: string
  22271. namespace:
  22272. description: |-
  22273. The namespace of the Secret resource being referred to.
  22274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22275. maxLength: 63
  22276. minLength: 1
  22277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22278. type: string
  22279. type: object
  22280. usernameSecret:
  22281. description: |-
  22282. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22283. In some instances, `key` is a required field.
  22284. properties:
  22285. key:
  22286. description: |-
  22287. A key in the referenced Secret.
  22288. Some instances of this field may be defaulted, in others it may be required.
  22289. maxLength: 253
  22290. minLength: 1
  22291. pattern: ^[-._a-zA-Z0-9]+$
  22292. type: string
  22293. name:
  22294. description: The name of the Secret resource being referred to.
  22295. maxLength: 253
  22296. minLength: 1
  22297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22298. type: string
  22299. namespace:
  22300. description: |-
  22301. The namespace of the Secret resource being referred to.
  22302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22303. maxLength: 63
  22304. minLength: 1
  22305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22306. type: string
  22307. type: object
  22308. required:
  22309. - passwordSecret
  22310. - usernameSecret
  22311. type: object
  22312. type: object
  22313. body:
  22314. description: Body
  22315. type: string
  22316. caBundle:
  22317. description: |-
  22318. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22319. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22320. plain HTTP protocol connection. If not set the system root certificates
  22321. are used to validate the TLS connection.
  22322. format: byte
  22323. type: string
  22324. caProvider:
  22325. description: The provider for the CA bundle to use to validate webhook server certificate.
  22326. properties:
  22327. key:
  22328. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22329. maxLength: 253
  22330. minLength: 1
  22331. pattern: ^[-._a-zA-Z0-9]+$
  22332. type: string
  22333. name:
  22334. description: The name of the object located at the provider type.
  22335. maxLength: 253
  22336. minLength: 1
  22337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22338. type: string
  22339. namespace:
  22340. description: The namespace the Provider type is in.
  22341. maxLength: 63
  22342. minLength: 1
  22343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22344. type: string
  22345. type:
  22346. description: The type of provider to use such as "Secret", or "ConfigMap".
  22347. enum:
  22348. - Secret
  22349. - ConfigMap
  22350. type: string
  22351. required:
  22352. - name
  22353. - type
  22354. type: object
  22355. headers:
  22356. additionalProperties:
  22357. type: string
  22358. description: Headers
  22359. type: object
  22360. method:
  22361. description: Webhook Method
  22362. type: string
  22363. result:
  22364. description: Result formatting
  22365. properties:
  22366. jsonPath:
  22367. description: Json path of return value
  22368. type: string
  22369. type: object
  22370. secrets:
  22371. description: |-
  22372. Secrets to fill in templates
  22373. These secrets will be passed to the templating function as key value pairs under the given name
  22374. items:
  22375. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22376. properties:
  22377. name:
  22378. description: Name of this secret in templates
  22379. type: string
  22380. secretRef:
  22381. description: Secret ref to fill in credentials
  22382. properties:
  22383. key:
  22384. description: |-
  22385. A key in the referenced Secret.
  22386. Some instances of this field may be defaulted, in others it may be required.
  22387. maxLength: 253
  22388. minLength: 1
  22389. pattern: ^[-._a-zA-Z0-9]+$
  22390. type: string
  22391. name:
  22392. description: The name of the Secret resource being referred to.
  22393. maxLength: 253
  22394. minLength: 1
  22395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22396. type: string
  22397. namespace:
  22398. description: |-
  22399. The namespace of the Secret resource being referred to.
  22400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22401. maxLength: 63
  22402. minLength: 1
  22403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22404. type: string
  22405. type: object
  22406. required:
  22407. - name
  22408. - secretRef
  22409. type: object
  22410. type: array
  22411. timeout:
  22412. description: Timeout
  22413. type: string
  22414. url:
  22415. description: Webhook url to call
  22416. type: string
  22417. required:
  22418. - url
  22419. type: object
  22420. yandexcertificatemanager:
  22421. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22422. properties:
  22423. apiEndpoint:
  22424. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22425. type: string
  22426. auth:
  22427. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22428. properties:
  22429. authorizedKeySecretRef:
  22430. description: The authorized key used for authentication
  22431. properties:
  22432. key:
  22433. description: |-
  22434. A key in the referenced Secret.
  22435. Some instances of this field may be defaulted, in others it may be required.
  22436. maxLength: 253
  22437. minLength: 1
  22438. pattern: ^[-._a-zA-Z0-9]+$
  22439. type: string
  22440. name:
  22441. description: The name of the Secret resource being referred to.
  22442. maxLength: 253
  22443. minLength: 1
  22444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22445. type: string
  22446. namespace:
  22447. description: |-
  22448. The namespace of the Secret resource being referred to.
  22449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22450. maxLength: 63
  22451. minLength: 1
  22452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22453. type: string
  22454. type: object
  22455. type: object
  22456. caProvider:
  22457. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22458. properties:
  22459. certSecretRef:
  22460. description: |-
  22461. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22462. In some instances, `key` is a required field.
  22463. properties:
  22464. key:
  22465. description: |-
  22466. A key in the referenced Secret.
  22467. Some instances of this field may be defaulted, in others it may be required.
  22468. maxLength: 253
  22469. minLength: 1
  22470. pattern: ^[-._a-zA-Z0-9]+$
  22471. type: string
  22472. name:
  22473. description: The name of the Secret resource being referred to.
  22474. maxLength: 253
  22475. minLength: 1
  22476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22477. type: string
  22478. namespace:
  22479. description: |-
  22480. The namespace of the Secret resource being referred to.
  22481. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22482. maxLength: 63
  22483. minLength: 1
  22484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22485. type: string
  22486. type: object
  22487. type: object
  22488. fetching:
  22489. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22490. maxProperties: 1
  22491. minProperties: 1
  22492. properties:
  22493. byID:
  22494. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22495. type: object
  22496. byName:
  22497. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22498. properties:
  22499. folderID:
  22500. description: The folder to fetch secrets from
  22501. type: string
  22502. required:
  22503. - folderID
  22504. type: object
  22505. type: object
  22506. required:
  22507. - auth
  22508. type: object
  22509. yandexlockbox:
  22510. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22511. properties:
  22512. apiEndpoint:
  22513. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22514. type: string
  22515. auth:
  22516. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22517. properties:
  22518. authorizedKeySecretRef:
  22519. description: The authorized key used for authentication
  22520. properties:
  22521. key:
  22522. description: |-
  22523. A key in the referenced Secret.
  22524. Some instances of this field may be defaulted, in others it may be required.
  22525. maxLength: 253
  22526. minLength: 1
  22527. pattern: ^[-._a-zA-Z0-9]+$
  22528. type: string
  22529. name:
  22530. description: The name of the Secret resource being referred to.
  22531. maxLength: 253
  22532. minLength: 1
  22533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22534. type: string
  22535. namespace:
  22536. description: |-
  22537. The namespace of the Secret resource being referred to.
  22538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22539. maxLength: 63
  22540. minLength: 1
  22541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22542. type: string
  22543. type: object
  22544. type: object
  22545. caProvider:
  22546. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22547. properties:
  22548. certSecretRef:
  22549. description: |-
  22550. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22551. In some instances, `key` is a required field.
  22552. properties:
  22553. key:
  22554. description: |-
  22555. A key in the referenced Secret.
  22556. Some instances of this field may be defaulted, in others it may be required.
  22557. maxLength: 253
  22558. minLength: 1
  22559. pattern: ^[-._a-zA-Z0-9]+$
  22560. type: string
  22561. name:
  22562. description: The name of the Secret resource being referred to.
  22563. maxLength: 253
  22564. minLength: 1
  22565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22566. type: string
  22567. namespace:
  22568. description: |-
  22569. The namespace of the Secret resource being referred to.
  22570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22571. maxLength: 63
  22572. minLength: 1
  22573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22574. type: string
  22575. type: object
  22576. type: object
  22577. fetching:
  22578. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22579. maxProperties: 1
  22580. minProperties: 1
  22581. properties:
  22582. byID:
  22583. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22584. type: object
  22585. byName:
  22586. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22587. properties:
  22588. folderID:
  22589. description: The folder to fetch secrets from
  22590. type: string
  22591. required:
  22592. - folderID
  22593. type: object
  22594. type: object
  22595. required:
  22596. - auth
  22597. type: object
  22598. type: object
  22599. refreshInterval:
  22600. anyOf:
  22601. - type: integer
  22602. - type: string
  22603. description: |-
  22604. Used to configure store refresh interval. Accepts either an integer number
  22605. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22606. 0 will default to the controller config.
  22607. x-kubernetes-int-or-string: true
  22608. retrySettings:
  22609. description: Used to configure HTTP retries on failures.
  22610. properties:
  22611. maxRetries:
  22612. format: int32
  22613. type: integer
  22614. retryInterval:
  22615. type: string
  22616. type: object
  22617. required:
  22618. - provider
  22619. type: object
  22620. status:
  22621. description: SecretStoreStatus defines the observed state of the SecretStore.
  22622. properties:
  22623. capabilities:
  22624. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22625. type: string
  22626. conditions:
  22627. items:
  22628. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22629. properties:
  22630. lastTransitionTime:
  22631. format: date-time
  22632. type: string
  22633. message:
  22634. type: string
  22635. reason:
  22636. type: string
  22637. status:
  22638. type: string
  22639. type:
  22640. description: SecretStoreConditionType represents the condition of the SecretStore.
  22641. type: string
  22642. required:
  22643. - status
  22644. - type
  22645. type: object
  22646. type: array
  22647. type: object
  22648. type: object
  22649. served: true
  22650. storage: true
  22651. subresources:
  22652. status: {}
  22653. - additionalPrinterColumns:
  22654. - jsonPath: .metadata.creationTimestamp
  22655. name: AGE
  22656. type: date
  22657. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22658. name: Status
  22659. type: string
  22660. - jsonPath: .status.capabilities
  22661. name: Capabilities
  22662. type: string
  22663. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22664. name: Ready
  22665. type: string
  22666. deprecated: true
  22667. name: v1beta1
  22668. schema:
  22669. openAPIV3Schema:
  22670. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22671. properties:
  22672. apiVersion:
  22673. description: |-
  22674. APIVersion defines the versioned schema of this representation of an object.
  22675. Servers should convert recognized schemas to the latest internal value, and
  22676. may reject unrecognized values.
  22677. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22678. type: string
  22679. kind:
  22680. description: |-
  22681. Kind is a string value representing the REST resource this object represents.
  22682. Servers may infer this from the endpoint the client submits requests to.
  22683. Cannot be updated.
  22684. In CamelCase.
  22685. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22686. type: string
  22687. metadata:
  22688. type: object
  22689. spec:
  22690. description: SecretStoreSpec defines the desired state of SecretStore.
  22691. properties:
  22692. conditions:
  22693. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22694. items:
  22695. description: |-
  22696. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22697. for a ClusterSecretStore instance.
  22698. properties:
  22699. namespaceRegexes:
  22700. description: Choose namespaces by using regex matching
  22701. items:
  22702. type: string
  22703. type: array
  22704. namespaceSelector:
  22705. description: Choose namespace using a labelSelector
  22706. properties:
  22707. matchExpressions:
  22708. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22709. items:
  22710. description: |-
  22711. A label selector requirement is a selector that contains values, a key, and an operator that
  22712. relates the key and values.
  22713. properties:
  22714. key:
  22715. description: key is the label key that the selector applies to.
  22716. type: string
  22717. operator:
  22718. description: |-
  22719. operator represents a key's relationship to a set of values.
  22720. Valid operators are In, NotIn, Exists and DoesNotExist.
  22721. type: string
  22722. values:
  22723. description: |-
  22724. values is an array of string values. If the operator is In or NotIn,
  22725. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22726. the values array must be empty. This array is replaced during a strategic
  22727. merge patch.
  22728. items:
  22729. type: string
  22730. type: array
  22731. x-kubernetes-list-type: atomic
  22732. required:
  22733. - key
  22734. - operator
  22735. type: object
  22736. type: array
  22737. x-kubernetes-list-type: atomic
  22738. matchLabels:
  22739. additionalProperties:
  22740. type: string
  22741. description: |-
  22742. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22743. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22744. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22745. type: object
  22746. type: object
  22747. x-kubernetes-map-type: atomic
  22748. namespaces:
  22749. description: Choose namespaces by name
  22750. items:
  22751. maxLength: 63
  22752. minLength: 1
  22753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22754. type: string
  22755. type: array
  22756. type: object
  22757. type: array
  22758. controller:
  22759. description: |-
  22760. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22761. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22762. type: string
  22763. provider:
  22764. description: Used to configure the provider. Only one provider may be set
  22765. maxProperties: 1
  22766. minProperties: 1
  22767. properties:
  22768. akeyless:
  22769. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22770. properties:
  22771. akeylessGWApiURL:
  22772. description: Akeyless GW API Url from which the secrets to be fetched from.
  22773. type: string
  22774. authSecretRef:
  22775. description: Auth configures how the operator authenticates with Akeyless.
  22776. properties:
  22777. kubernetesAuth:
  22778. description: |-
  22779. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22780. token stored in the named Secret resource.
  22781. properties:
  22782. accessID:
  22783. description: the Akeyless Kubernetes auth-method access-id
  22784. type: string
  22785. k8sConfName:
  22786. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22787. type: string
  22788. secretRef:
  22789. description: |-
  22790. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22791. for authenticating with Akeyless. If a name is specified without a key,
  22792. `token` is the default. If one is not specified, the one bound to
  22793. the controller will be used.
  22794. properties:
  22795. key:
  22796. description: |-
  22797. A key in the referenced Secret.
  22798. Some instances of this field may be defaulted, in others it may be required.
  22799. maxLength: 253
  22800. minLength: 1
  22801. pattern: ^[-._a-zA-Z0-9]+$
  22802. type: string
  22803. name:
  22804. description: The name of the Secret resource being referred to.
  22805. maxLength: 253
  22806. minLength: 1
  22807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22808. type: string
  22809. namespace:
  22810. description: |-
  22811. The namespace of the Secret resource being referred to.
  22812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22813. maxLength: 63
  22814. minLength: 1
  22815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22816. type: string
  22817. type: object
  22818. serviceAccountRef:
  22819. description: |-
  22820. Optional service account field containing the name of a kubernetes ServiceAccount.
  22821. If the service account is specified, the service account secret token JWT will be used
  22822. for authenticating with Akeyless. If the service account selector is not supplied,
  22823. the secretRef will be used instead.
  22824. properties:
  22825. audiences:
  22826. description: |-
  22827. Audience specifies the `aud` claim for the service account token
  22828. Some providers automatically extend the audience field based on well-known annotations for workload
  22829. identity (e.g. IRSA or GCP Workload Identity)
  22830. items:
  22831. type: string
  22832. type: array
  22833. name:
  22834. description: The name of the ServiceAccount resource being referred to.
  22835. maxLength: 253
  22836. minLength: 1
  22837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22838. type: string
  22839. namespace:
  22840. description: |-
  22841. Namespace of the resource being referred to.
  22842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22843. maxLength: 63
  22844. minLength: 1
  22845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22846. type: string
  22847. required:
  22848. - name
  22849. type: object
  22850. required:
  22851. - accessID
  22852. - k8sConfName
  22853. type: object
  22854. secretRef:
  22855. description: |-
  22856. Reference to a Secret that contains the details
  22857. to authenticate with Akeyless.
  22858. properties:
  22859. accessID:
  22860. description: The SecretAccessID is used for authentication
  22861. properties:
  22862. key:
  22863. description: |-
  22864. A key in the referenced Secret.
  22865. Some instances of this field may be defaulted, in others it may be required.
  22866. maxLength: 253
  22867. minLength: 1
  22868. pattern: ^[-._a-zA-Z0-9]+$
  22869. type: string
  22870. name:
  22871. description: The name of the Secret resource being referred to.
  22872. maxLength: 253
  22873. minLength: 1
  22874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22875. type: string
  22876. namespace:
  22877. description: |-
  22878. The namespace of the Secret resource being referred to.
  22879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22880. maxLength: 63
  22881. minLength: 1
  22882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22883. type: string
  22884. type: object
  22885. accessType:
  22886. description: |-
  22887. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22888. In some instances, `key` is a required field.
  22889. properties:
  22890. key:
  22891. description: |-
  22892. A key in the referenced Secret.
  22893. Some instances of this field may be defaulted, in others it may be required.
  22894. maxLength: 253
  22895. minLength: 1
  22896. pattern: ^[-._a-zA-Z0-9]+$
  22897. type: string
  22898. name:
  22899. description: The name of the Secret resource being referred to.
  22900. maxLength: 253
  22901. minLength: 1
  22902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22903. type: string
  22904. namespace:
  22905. description: |-
  22906. The namespace of the Secret resource being referred to.
  22907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22908. maxLength: 63
  22909. minLength: 1
  22910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22911. type: string
  22912. type: object
  22913. accessTypeParam:
  22914. description: |-
  22915. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22916. In some instances, `key` is a required field.
  22917. properties:
  22918. key:
  22919. description: |-
  22920. A key in the referenced Secret.
  22921. Some instances of this field may be defaulted, in others it may be required.
  22922. maxLength: 253
  22923. minLength: 1
  22924. pattern: ^[-._a-zA-Z0-9]+$
  22925. type: string
  22926. name:
  22927. description: The name of the Secret resource being referred to.
  22928. maxLength: 253
  22929. minLength: 1
  22930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22931. type: string
  22932. namespace:
  22933. description: |-
  22934. The namespace of the Secret resource being referred to.
  22935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22936. maxLength: 63
  22937. minLength: 1
  22938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22939. type: string
  22940. type: object
  22941. type: object
  22942. type: object
  22943. caBundle:
  22944. description: |-
  22945. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22946. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22947. are used to validate the TLS connection.
  22948. format: byte
  22949. type: string
  22950. caProvider:
  22951. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22952. properties:
  22953. key:
  22954. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22955. maxLength: 253
  22956. minLength: 1
  22957. pattern: ^[-._a-zA-Z0-9]+$
  22958. type: string
  22959. name:
  22960. description: The name of the object located at the provider type.
  22961. maxLength: 253
  22962. minLength: 1
  22963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22964. type: string
  22965. namespace:
  22966. description: |-
  22967. The namespace the Provider type is in.
  22968. Can only be defined when used in a ClusterSecretStore.
  22969. maxLength: 63
  22970. minLength: 1
  22971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22972. type: string
  22973. type:
  22974. description: The type of provider to use such as "Secret", or "ConfigMap".
  22975. enum:
  22976. - Secret
  22977. - ConfigMap
  22978. type: string
  22979. required:
  22980. - name
  22981. - type
  22982. type: object
  22983. required:
  22984. - akeylessGWApiURL
  22985. - authSecretRef
  22986. type: object
  22987. alibaba:
  22988. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22989. properties:
  22990. auth:
  22991. description: AlibabaAuth contains a secretRef for credentials.
  22992. properties:
  22993. rrsa:
  22994. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22995. properties:
  22996. oidcProviderArn:
  22997. type: string
  22998. oidcTokenFilePath:
  22999. type: string
  23000. roleArn:
  23001. type: string
  23002. sessionName:
  23003. type: string
  23004. required:
  23005. - oidcProviderArn
  23006. - oidcTokenFilePath
  23007. - roleArn
  23008. - sessionName
  23009. type: object
  23010. secretRef:
  23011. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  23012. properties:
  23013. accessKeyIDSecretRef:
  23014. description: The AccessKeyID is used for authentication
  23015. properties:
  23016. key:
  23017. description: |-
  23018. A key in the referenced Secret.
  23019. Some instances of this field may be defaulted, in others it may be required.
  23020. maxLength: 253
  23021. minLength: 1
  23022. pattern: ^[-._a-zA-Z0-9]+$
  23023. type: string
  23024. name:
  23025. description: The name of the Secret resource being referred to.
  23026. maxLength: 253
  23027. minLength: 1
  23028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23029. type: string
  23030. namespace:
  23031. description: |-
  23032. The namespace of the Secret resource being referred to.
  23033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23034. maxLength: 63
  23035. minLength: 1
  23036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23037. type: string
  23038. type: object
  23039. accessKeySecretSecretRef:
  23040. description: The AccessKeySecret is used for authentication
  23041. properties:
  23042. key:
  23043. description: |-
  23044. A key in the referenced Secret.
  23045. Some instances of this field may be defaulted, in others it may be required.
  23046. maxLength: 253
  23047. minLength: 1
  23048. pattern: ^[-._a-zA-Z0-9]+$
  23049. type: string
  23050. name:
  23051. description: The name of the Secret resource being referred to.
  23052. maxLength: 253
  23053. minLength: 1
  23054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23055. type: string
  23056. namespace:
  23057. description: |-
  23058. The namespace of the Secret resource being referred to.
  23059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23060. maxLength: 63
  23061. minLength: 1
  23062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23063. type: string
  23064. type: object
  23065. required:
  23066. - accessKeyIDSecretRef
  23067. - accessKeySecretSecretRef
  23068. type: object
  23069. type: object
  23070. regionID:
  23071. description: Alibaba Region to be used for the provider
  23072. type: string
  23073. required:
  23074. - auth
  23075. - regionID
  23076. type: object
  23077. aws:
  23078. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  23079. properties:
  23080. additionalRoles:
  23081. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  23082. items:
  23083. type: string
  23084. type: array
  23085. auth:
  23086. description: |-
  23087. Auth defines the information necessary to authenticate against AWS
  23088. if not set aws sdk will infer credentials from your environment
  23089. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  23090. properties:
  23091. jwt:
  23092. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  23093. properties:
  23094. serviceAccountRef:
  23095. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23096. properties:
  23097. audiences:
  23098. description: |-
  23099. Audience specifies the `aud` claim for the service account token
  23100. Some providers automatically extend the audience field based on well-known annotations for workload
  23101. identity (e.g. IRSA or GCP Workload Identity)
  23102. items:
  23103. type: string
  23104. type: array
  23105. name:
  23106. description: The name of the ServiceAccount resource being referred to.
  23107. maxLength: 253
  23108. minLength: 1
  23109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23110. type: string
  23111. namespace:
  23112. description: |-
  23113. Namespace of the resource being referred to.
  23114. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23115. maxLength: 63
  23116. minLength: 1
  23117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23118. type: string
  23119. required:
  23120. - name
  23121. type: object
  23122. type: object
  23123. secretRef:
  23124. description: |-
  23125. AWSAuthSecretRef holds secret references for AWS credentials
  23126. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  23127. properties:
  23128. accessKeyIDSecretRef:
  23129. description: The AccessKeyID is used for authentication
  23130. properties:
  23131. key:
  23132. description: |-
  23133. A key in the referenced Secret.
  23134. Some instances of this field may be defaulted, in others it may be required.
  23135. maxLength: 253
  23136. minLength: 1
  23137. pattern: ^[-._a-zA-Z0-9]+$
  23138. type: string
  23139. name:
  23140. description: The name of the Secret resource being referred to.
  23141. maxLength: 253
  23142. minLength: 1
  23143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23144. type: string
  23145. namespace:
  23146. description: |-
  23147. The namespace of the Secret resource being referred to.
  23148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23149. maxLength: 63
  23150. minLength: 1
  23151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23152. type: string
  23153. type: object
  23154. secretAccessKeySecretRef:
  23155. description: The SecretAccessKey is used for authentication
  23156. properties:
  23157. key:
  23158. description: |-
  23159. A key in the referenced Secret.
  23160. Some instances of this field may be defaulted, in others it may be required.
  23161. maxLength: 253
  23162. minLength: 1
  23163. pattern: ^[-._a-zA-Z0-9]+$
  23164. type: string
  23165. name:
  23166. description: The name of the Secret resource being referred to.
  23167. maxLength: 253
  23168. minLength: 1
  23169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23170. type: string
  23171. namespace:
  23172. description: |-
  23173. The namespace of the Secret resource being referred to.
  23174. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23175. maxLength: 63
  23176. minLength: 1
  23177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23178. type: string
  23179. type: object
  23180. sessionTokenSecretRef:
  23181. description: |-
  23182. The SessionToken used for authentication
  23183. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23184. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23185. properties:
  23186. key:
  23187. description: |-
  23188. A key in the referenced Secret.
  23189. Some instances of this field may be defaulted, in others it may be required.
  23190. maxLength: 253
  23191. minLength: 1
  23192. pattern: ^[-._a-zA-Z0-9]+$
  23193. type: string
  23194. name:
  23195. description: The name of the Secret resource being referred to.
  23196. maxLength: 253
  23197. minLength: 1
  23198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23199. type: string
  23200. namespace:
  23201. description: |-
  23202. The namespace of the Secret resource being referred to.
  23203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23204. maxLength: 63
  23205. minLength: 1
  23206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23207. type: string
  23208. type: object
  23209. type: object
  23210. type: object
  23211. externalID:
  23212. description: AWS External ID set on assumed IAM roles
  23213. type: string
  23214. prefix:
  23215. description: Prefix adds a prefix to all retrieved values.
  23216. type: string
  23217. region:
  23218. description: AWS Region to be used for the provider
  23219. type: string
  23220. role:
  23221. description: Role is a Role ARN which the provider will assume
  23222. type: string
  23223. secretsManager:
  23224. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23225. properties:
  23226. forceDeleteWithoutRecovery:
  23227. description: |-
  23228. Specifies whether to delete the secret without any recovery window. You
  23229. can't use both this parameter and RecoveryWindowInDays in the same call.
  23230. If you don't use either, then by default Secrets Manager uses a 30 day
  23231. recovery window.
  23232. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23233. type: boolean
  23234. recoveryWindowInDays:
  23235. description: |-
  23236. The number of days from 7 to 30 that Secrets Manager waits before
  23237. permanently deleting the secret. You can't use both this parameter and
  23238. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23239. then by default Secrets Manager uses a 30 day recovery window.
  23240. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23241. format: int64
  23242. type: integer
  23243. type: object
  23244. service:
  23245. description: Service defines which service should be used to fetch the secrets
  23246. enum:
  23247. - SecretsManager
  23248. - ParameterStore
  23249. type: string
  23250. sessionTags:
  23251. description: AWS STS assume role session tags
  23252. items:
  23253. description: Tag defines a tag key and value for AWS resources.
  23254. properties:
  23255. key:
  23256. type: string
  23257. value:
  23258. type: string
  23259. required:
  23260. - key
  23261. - value
  23262. type: object
  23263. type: array
  23264. transitiveTagKeys:
  23265. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23266. items:
  23267. type: string
  23268. type: array
  23269. required:
  23270. - region
  23271. - service
  23272. type: object
  23273. azurekv:
  23274. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23275. properties:
  23276. authSecretRef:
  23277. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23278. properties:
  23279. clientCertificate:
  23280. description: The Azure ClientCertificate of the service principle used for authentication.
  23281. properties:
  23282. key:
  23283. description: |-
  23284. A key in the referenced Secret.
  23285. Some instances of this field may be defaulted, in others it may be required.
  23286. maxLength: 253
  23287. minLength: 1
  23288. pattern: ^[-._a-zA-Z0-9]+$
  23289. type: string
  23290. name:
  23291. description: The name of the Secret resource being referred to.
  23292. maxLength: 253
  23293. minLength: 1
  23294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23295. type: string
  23296. namespace:
  23297. description: |-
  23298. The namespace of the Secret resource being referred to.
  23299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23300. maxLength: 63
  23301. minLength: 1
  23302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23303. type: string
  23304. type: object
  23305. clientId:
  23306. description: The Azure clientId of the service principle or managed identity used for authentication.
  23307. properties:
  23308. key:
  23309. description: |-
  23310. A key in the referenced Secret.
  23311. Some instances of this field may be defaulted, in others it may be required.
  23312. maxLength: 253
  23313. minLength: 1
  23314. pattern: ^[-._a-zA-Z0-9]+$
  23315. type: string
  23316. name:
  23317. description: The name of the Secret resource being referred to.
  23318. maxLength: 253
  23319. minLength: 1
  23320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23321. type: string
  23322. namespace:
  23323. description: |-
  23324. The namespace of the Secret resource being referred to.
  23325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23326. maxLength: 63
  23327. minLength: 1
  23328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23329. type: string
  23330. type: object
  23331. clientSecret:
  23332. description: The Azure ClientSecret of the service principle used for authentication.
  23333. properties:
  23334. key:
  23335. description: |-
  23336. A key in the referenced Secret.
  23337. Some instances of this field may be defaulted, in others it may be required.
  23338. maxLength: 253
  23339. minLength: 1
  23340. pattern: ^[-._a-zA-Z0-9]+$
  23341. type: string
  23342. name:
  23343. description: The name of the Secret resource being referred to.
  23344. maxLength: 253
  23345. minLength: 1
  23346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23347. type: string
  23348. namespace:
  23349. description: |-
  23350. The namespace of the Secret resource being referred to.
  23351. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23352. maxLength: 63
  23353. minLength: 1
  23354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23355. type: string
  23356. type: object
  23357. tenantId:
  23358. description: The Azure tenantId of the managed identity used for authentication.
  23359. properties:
  23360. key:
  23361. description: |-
  23362. A key in the referenced Secret.
  23363. Some instances of this field may be defaulted, in others it may be required.
  23364. maxLength: 253
  23365. minLength: 1
  23366. pattern: ^[-._a-zA-Z0-9]+$
  23367. type: string
  23368. name:
  23369. description: The name of the Secret resource being referred to.
  23370. maxLength: 253
  23371. minLength: 1
  23372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23373. type: string
  23374. namespace:
  23375. description: |-
  23376. The namespace of the Secret resource being referred to.
  23377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23378. maxLength: 63
  23379. minLength: 1
  23380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23381. type: string
  23382. type: object
  23383. type: object
  23384. authType:
  23385. default: ServicePrincipal
  23386. description: |-
  23387. Auth type defines how to authenticate to the keyvault service.
  23388. Valid values are:
  23389. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23390. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23391. enum:
  23392. - ServicePrincipal
  23393. - ManagedIdentity
  23394. - WorkloadIdentity
  23395. type: string
  23396. environmentType:
  23397. default: PublicCloud
  23398. description: |-
  23399. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23400. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23401. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23402. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23403. enum:
  23404. - PublicCloud
  23405. - USGovernmentCloud
  23406. - ChinaCloud
  23407. - GermanCloud
  23408. type: string
  23409. identityId:
  23410. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23411. type: string
  23412. serviceAccountRef:
  23413. description: |-
  23414. ServiceAccountRef specified the service account
  23415. that should be used when authenticating with WorkloadIdentity.
  23416. properties:
  23417. audiences:
  23418. description: |-
  23419. Audience specifies the `aud` claim for the service account token
  23420. Some providers automatically extend the audience field based on well-known annotations for workload
  23421. identity (e.g. IRSA or GCP Workload Identity)
  23422. items:
  23423. type: string
  23424. type: array
  23425. name:
  23426. description: The name of the ServiceAccount resource being referred to.
  23427. maxLength: 253
  23428. minLength: 1
  23429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23430. type: string
  23431. namespace:
  23432. description: |-
  23433. Namespace of the resource being referred to.
  23434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23435. maxLength: 63
  23436. minLength: 1
  23437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23438. type: string
  23439. required:
  23440. - name
  23441. type: object
  23442. tenantId:
  23443. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23444. type: string
  23445. vaultUrl:
  23446. description: Vault Url from which the secrets to be fetched from.
  23447. type: string
  23448. required:
  23449. - vaultUrl
  23450. type: object
  23451. beyondtrust:
  23452. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23453. properties:
  23454. auth:
  23455. description: Auth configures how the operator authenticates with Beyondtrust.
  23456. properties:
  23457. apiKey:
  23458. description: APIKey If not provided then ClientID/ClientSecret become required.
  23459. properties:
  23460. secretRef:
  23461. description: SecretRef references a key in a secret that will be used as value.
  23462. properties:
  23463. key:
  23464. description: |-
  23465. A key in the referenced Secret.
  23466. Some instances of this field may be defaulted, in others it may be required.
  23467. maxLength: 253
  23468. minLength: 1
  23469. pattern: ^[-._a-zA-Z0-9]+$
  23470. type: string
  23471. name:
  23472. description: The name of the Secret resource being referred to.
  23473. maxLength: 253
  23474. minLength: 1
  23475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23476. type: string
  23477. namespace:
  23478. description: |-
  23479. The namespace of the Secret resource being referred to.
  23480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23481. maxLength: 63
  23482. minLength: 1
  23483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23484. type: string
  23485. type: object
  23486. value:
  23487. description: Value can be specified directly to set a value without using a secret.
  23488. type: string
  23489. type: object
  23490. certificate:
  23491. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23492. properties:
  23493. secretRef:
  23494. description: SecretRef references a key in a secret that will be used as value.
  23495. properties:
  23496. key:
  23497. description: |-
  23498. A key in the referenced Secret.
  23499. Some instances of this field may be defaulted, in others it may be required.
  23500. maxLength: 253
  23501. minLength: 1
  23502. pattern: ^[-._a-zA-Z0-9]+$
  23503. type: string
  23504. name:
  23505. description: The name of the Secret resource being referred to.
  23506. maxLength: 253
  23507. minLength: 1
  23508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23509. type: string
  23510. namespace:
  23511. description: |-
  23512. The namespace of the Secret resource being referred to.
  23513. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23514. maxLength: 63
  23515. minLength: 1
  23516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23517. type: string
  23518. type: object
  23519. value:
  23520. description: Value can be specified directly to set a value without using a secret.
  23521. type: string
  23522. type: object
  23523. certificateKey:
  23524. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23525. properties:
  23526. secretRef:
  23527. description: SecretRef references a key in a secret that will be used as value.
  23528. properties:
  23529. key:
  23530. description: |-
  23531. A key in the referenced Secret.
  23532. Some instances of this field may be defaulted, in others it may be required.
  23533. maxLength: 253
  23534. minLength: 1
  23535. pattern: ^[-._a-zA-Z0-9]+$
  23536. type: string
  23537. name:
  23538. description: The name of the Secret resource being referred to.
  23539. maxLength: 253
  23540. minLength: 1
  23541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23542. type: string
  23543. namespace:
  23544. description: |-
  23545. The namespace of the Secret resource being referred to.
  23546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23547. maxLength: 63
  23548. minLength: 1
  23549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23550. type: string
  23551. type: object
  23552. value:
  23553. description: Value can be specified directly to set a value without using a secret.
  23554. type: string
  23555. type: object
  23556. clientId:
  23557. description: ClientID is the API OAuth Client ID.
  23558. properties:
  23559. secretRef:
  23560. description: SecretRef references a key in a secret that will be used as value.
  23561. properties:
  23562. key:
  23563. description: |-
  23564. A key in the referenced Secret.
  23565. Some instances of this field may be defaulted, in others it may be required.
  23566. maxLength: 253
  23567. minLength: 1
  23568. pattern: ^[-._a-zA-Z0-9]+$
  23569. type: string
  23570. name:
  23571. description: The name of the Secret resource being referred to.
  23572. maxLength: 253
  23573. minLength: 1
  23574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23575. type: string
  23576. namespace:
  23577. description: |-
  23578. The namespace of the Secret resource being referred to.
  23579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23580. maxLength: 63
  23581. minLength: 1
  23582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23583. type: string
  23584. type: object
  23585. value:
  23586. description: Value can be specified directly to set a value without using a secret.
  23587. type: string
  23588. type: object
  23589. clientSecret:
  23590. description: ClientSecret is the API OAuth Client Secret.
  23591. properties:
  23592. secretRef:
  23593. description: SecretRef references a key in a secret that will be used as value.
  23594. properties:
  23595. key:
  23596. description: |-
  23597. A key in the referenced Secret.
  23598. Some instances of this field may be defaulted, in others it may be required.
  23599. maxLength: 253
  23600. minLength: 1
  23601. pattern: ^[-._a-zA-Z0-9]+$
  23602. type: string
  23603. name:
  23604. description: The name of the Secret resource being referred to.
  23605. maxLength: 253
  23606. minLength: 1
  23607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23608. type: string
  23609. namespace:
  23610. description: |-
  23611. The namespace of the Secret resource being referred to.
  23612. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23613. maxLength: 63
  23614. minLength: 1
  23615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23616. type: string
  23617. type: object
  23618. value:
  23619. description: Value can be specified directly to set a value without using a secret.
  23620. type: string
  23621. type: object
  23622. type: object
  23623. server:
  23624. description: Auth configures how API server works.
  23625. properties:
  23626. apiUrl:
  23627. type: string
  23628. apiVersion:
  23629. type: string
  23630. clientTimeOutSeconds:
  23631. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23632. type: integer
  23633. decrypt:
  23634. default: true
  23635. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23636. type: boolean
  23637. retrievalType:
  23638. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23639. type: string
  23640. separator:
  23641. description: A character that separates the folder names.
  23642. type: string
  23643. verifyCA:
  23644. type: boolean
  23645. required:
  23646. - apiUrl
  23647. - verifyCA
  23648. type: object
  23649. required:
  23650. - auth
  23651. - server
  23652. type: object
  23653. bitwardensecretsmanager:
  23654. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23655. properties:
  23656. apiURL:
  23657. type: string
  23658. auth:
  23659. description: |-
  23660. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23661. Make sure that the token being used has permissions on the given secret.
  23662. properties:
  23663. secretRef:
  23664. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23665. properties:
  23666. credentials:
  23667. description: AccessToken used for the bitwarden instance.
  23668. properties:
  23669. key:
  23670. description: |-
  23671. A key in the referenced Secret.
  23672. Some instances of this field may be defaulted, in others it may be required.
  23673. maxLength: 253
  23674. minLength: 1
  23675. pattern: ^[-._a-zA-Z0-9]+$
  23676. type: string
  23677. name:
  23678. description: The name of the Secret resource being referred to.
  23679. maxLength: 253
  23680. minLength: 1
  23681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23682. type: string
  23683. namespace:
  23684. description: |-
  23685. The namespace of the Secret resource being referred to.
  23686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23687. maxLength: 63
  23688. minLength: 1
  23689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23690. type: string
  23691. type: object
  23692. required:
  23693. - credentials
  23694. type: object
  23695. required:
  23696. - secretRef
  23697. type: object
  23698. bitwardenServerSDKURL:
  23699. type: string
  23700. caBundle:
  23701. description: |-
  23702. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23703. can be performed.
  23704. type: string
  23705. caProvider:
  23706. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23707. properties:
  23708. key:
  23709. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23710. maxLength: 253
  23711. minLength: 1
  23712. pattern: ^[-._a-zA-Z0-9]+$
  23713. type: string
  23714. name:
  23715. description: The name of the object located at the provider type.
  23716. maxLength: 253
  23717. minLength: 1
  23718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23719. type: string
  23720. namespace:
  23721. description: |-
  23722. The namespace the Provider type is in.
  23723. Can only be defined when used in a ClusterSecretStore.
  23724. maxLength: 63
  23725. minLength: 1
  23726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23727. type: string
  23728. type:
  23729. description: The type of provider to use such as "Secret", or "ConfigMap".
  23730. enum:
  23731. - Secret
  23732. - ConfigMap
  23733. type: string
  23734. required:
  23735. - name
  23736. - type
  23737. type: object
  23738. identityURL:
  23739. type: string
  23740. organizationID:
  23741. description: OrganizationID determines which organization this secret store manages.
  23742. type: string
  23743. projectID:
  23744. description: ProjectID determines which project this secret store manages.
  23745. type: string
  23746. required:
  23747. - auth
  23748. - organizationID
  23749. - projectID
  23750. type: object
  23751. chef:
  23752. description: Chef configures this store to sync secrets with chef server
  23753. properties:
  23754. auth:
  23755. description: Auth defines the information necessary to authenticate against chef Server
  23756. properties:
  23757. secretRef:
  23758. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23759. properties:
  23760. privateKeySecretRef:
  23761. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23762. properties:
  23763. key:
  23764. description: |-
  23765. A key in the referenced Secret.
  23766. Some instances of this field may be defaulted, in others it may be required.
  23767. maxLength: 253
  23768. minLength: 1
  23769. pattern: ^[-._a-zA-Z0-9]+$
  23770. type: string
  23771. name:
  23772. description: The name of the Secret resource being referred to.
  23773. maxLength: 253
  23774. minLength: 1
  23775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23776. type: string
  23777. namespace:
  23778. description: |-
  23779. The namespace of the Secret resource being referred to.
  23780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23781. maxLength: 63
  23782. minLength: 1
  23783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23784. type: string
  23785. type: object
  23786. required:
  23787. - privateKeySecretRef
  23788. type: object
  23789. required:
  23790. - secretRef
  23791. type: object
  23792. serverUrl:
  23793. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23794. type: string
  23795. username:
  23796. description: UserName should be the user ID on the chef server
  23797. type: string
  23798. required:
  23799. - auth
  23800. - serverUrl
  23801. - username
  23802. type: object
  23803. cloudrusm:
  23804. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23805. properties:
  23806. auth:
  23807. description: CSMAuth contains a secretRef for credentials.
  23808. properties:
  23809. secretRef:
  23810. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23811. properties:
  23812. accessKeyIDSecretRef:
  23813. description: The AccessKeyID is used for authentication
  23814. properties:
  23815. key:
  23816. description: |-
  23817. A key in the referenced Secret.
  23818. Some instances of this field may be defaulted, in others it may be required.
  23819. maxLength: 253
  23820. minLength: 1
  23821. pattern: ^[-._a-zA-Z0-9]+$
  23822. type: string
  23823. name:
  23824. description: The name of the Secret resource being referred to.
  23825. maxLength: 253
  23826. minLength: 1
  23827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23828. type: string
  23829. namespace:
  23830. description: |-
  23831. The namespace of the Secret resource being referred to.
  23832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23833. maxLength: 63
  23834. minLength: 1
  23835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23836. type: string
  23837. type: object
  23838. accessKeySecretSecretRef:
  23839. description: The AccessKeySecret is used for authentication
  23840. properties:
  23841. key:
  23842. description: |-
  23843. A key in the referenced Secret.
  23844. Some instances of this field may be defaulted, in others it may be required.
  23845. maxLength: 253
  23846. minLength: 1
  23847. pattern: ^[-._a-zA-Z0-9]+$
  23848. type: string
  23849. name:
  23850. description: The name of the Secret resource being referred to.
  23851. maxLength: 253
  23852. minLength: 1
  23853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23854. type: string
  23855. namespace:
  23856. description: |-
  23857. The namespace of the Secret resource being referred to.
  23858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23859. maxLength: 63
  23860. minLength: 1
  23861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23862. type: string
  23863. type: object
  23864. required:
  23865. - accessKeyIDSecretRef
  23866. - accessKeySecretSecretRef
  23867. type: object
  23868. type: object
  23869. projectID:
  23870. description: ProjectID is the project, which the secrets are stored in.
  23871. type: string
  23872. required:
  23873. - auth
  23874. type: object
  23875. conjur:
  23876. description: Conjur configures this store to sync secrets using conjur provider
  23877. properties:
  23878. auth:
  23879. description: Defines authentication settings for connecting to Conjur.
  23880. properties:
  23881. apikey:
  23882. description: Authenticates with Conjur using an API key.
  23883. properties:
  23884. account:
  23885. description: Account is the Conjur organization account name.
  23886. type: string
  23887. apiKeyRef:
  23888. description: |-
  23889. A reference to a specific 'key' containing the Conjur API key
  23890. within a Secret resource. In some instances, `key` is a required field.
  23891. properties:
  23892. key:
  23893. description: |-
  23894. A key in the referenced Secret.
  23895. Some instances of this field may be defaulted, in others it may be required.
  23896. maxLength: 253
  23897. minLength: 1
  23898. pattern: ^[-._a-zA-Z0-9]+$
  23899. type: string
  23900. name:
  23901. description: The name of the Secret resource being referred to.
  23902. maxLength: 253
  23903. minLength: 1
  23904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23905. type: string
  23906. namespace:
  23907. description: |-
  23908. The namespace of the Secret resource being referred to.
  23909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23910. maxLength: 63
  23911. minLength: 1
  23912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23913. type: string
  23914. type: object
  23915. userRef:
  23916. description: |-
  23917. A reference to a specific 'key' containing the Conjur username
  23918. within a Secret resource. In some instances, `key` is a required field.
  23919. properties:
  23920. key:
  23921. description: |-
  23922. A key in the referenced Secret.
  23923. Some instances of this field may be defaulted, in others it may be required.
  23924. maxLength: 253
  23925. minLength: 1
  23926. pattern: ^[-._a-zA-Z0-9]+$
  23927. type: string
  23928. name:
  23929. description: The name of the Secret resource being referred to.
  23930. maxLength: 253
  23931. minLength: 1
  23932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23933. type: string
  23934. namespace:
  23935. description: |-
  23936. The namespace of the Secret resource being referred to.
  23937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23938. maxLength: 63
  23939. minLength: 1
  23940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23941. type: string
  23942. type: object
  23943. required:
  23944. - account
  23945. - apiKeyRef
  23946. - userRef
  23947. type: object
  23948. jwt:
  23949. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23950. properties:
  23951. account:
  23952. description: Account is the Conjur organization account name.
  23953. type: string
  23954. hostId:
  23955. description: |-
  23956. Optional HostID for JWT authentication. This may be used depending
  23957. on how the Conjur JWT authenticator policy is configured.
  23958. type: string
  23959. secretRef:
  23960. description: |-
  23961. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23962. authenticate with Conjur using the JWT authentication method.
  23963. properties:
  23964. key:
  23965. description: |-
  23966. A key in the referenced Secret.
  23967. Some instances of this field may be defaulted, in others it may be required.
  23968. maxLength: 253
  23969. minLength: 1
  23970. pattern: ^[-._a-zA-Z0-9]+$
  23971. type: string
  23972. name:
  23973. description: The name of the Secret resource being referred to.
  23974. maxLength: 253
  23975. minLength: 1
  23976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23977. type: string
  23978. namespace:
  23979. description: |-
  23980. The namespace of the Secret resource being referred to.
  23981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23982. maxLength: 63
  23983. minLength: 1
  23984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23985. type: string
  23986. type: object
  23987. serviceAccountRef:
  23988. description: |-
  23989. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23990. a token for with the `TokenRequest` API.
  23991. properties:
  23992. audiences:
  23993. description: |-
  23994. Audience specifies the `aud` claim for the service account token
  23995. Some providers automatically extend the audience field based on well-known annotations for workload
  23996. identity (e.g. IRSA or GCP Workload Identity)
  23997. items:
  23998. type: string
  23999. type: array
  24000. name:
  24001. description: The name of the ServiceAccount resource being referred to.
  24002. maxLength: 253
  24003. minLength: 1
  24004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24005. type: string
  24006. namespace:
  24007. description: |-
  24008. Namespace of the resource being referred to.
  24009. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24010. maxLength: 63
  24011. minLength: 1
  24012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24013. type: string
  24014. required:
  24015. - name
  24016. type: object
  24017. serviceID:
  24018. description: The conjur authn jwt webservice id
  24019. type: string
  24020. required:
  24021. - account
  24022. - serviceID
  24023. type: object
  24024. type: object
  24025. caBundle:
  24026. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  24027. type: string
  24028. caProvider:
  24029. description: |-
  24030. Used to provide custom certificate authority (CA) certificates
  24031. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  24032. that contains a PEM-encoded certificate.
  24033. properties:
  24034. key:
  24035. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24036. maxLength: 253
  24037. minLength: 1
  24038. pattern: ^[-._a-zA-Z0-9]+$
  24039. type: string
  24040. name:
  24041. description: The name of the object located at the provider type.
  24042. maxLength: 253
  24043. minLength: 1
  24044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24045. type: string
  24046. namespace:
  24047. description: |-
  24048. The namespace the Provider type is in.
  24049. Can only be defined when used in a ClusterSecretStore.
  24050. maxLength: 63
  24051. minLength: 1
  24052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24053. type: string
  24054. type:
  24055. description: The type of provider to use such as "Secret", or "ConfigMap".
  24056. enum:
  24057. - Secret
  24058. - ConfigMap
  24059. type: string
  24060. required:
  24061. - name
  24062. - type
  24063. type: object
  24064. url:
  24065. description: URL is the endpoint of the Conjur instance.
  24066. type: string
  24067. required:
  24068. - auth
  24069. - url
  24070. type: object
  24071. delinea:
  24072. description: |-
  24073. Delinea DevOps Secrets Vault
  24074. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  24075. properties:
  24076. clientId:
  24077. description: ClientID is the non-secret part of the credential.
  24078. properties:
  24079. secretRef:
  24080. description: SecretRef references a key in a secret that will be used as value.
  24081. properties:
  24082. key:
  24083. description: |-
  24084. A key in the referenced Secret.
  24085. Some instances of this field may be defaulted, in others it may be required.
  24086. maxLength: 253
  24087. minLength: 1
  24088. pattern: ^[-._a-zA-Z0-9]+$
  24089. type: string
  24090. name:
  24091. description: The name of the Secret resource being referred to.
  24092. maxLength: 253
  24093. minLength: 1
  24094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24095. type: string
  24096. namespace:
  24097. description: |-
  24098. The namespace of the Secret resource being referred to.
  24099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24100. maxLength: 63
  24101. minLength: 1
  24102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24103. type: string
  24104. type: object
  24105. value:
  24106. description: Value can be specified directly to set a value without using a secret.
  24107. type: string
  24108. type: object
  24109. clientSecret:
  24110. description: ClientSecret is the secret part of the credential.
  24111. properties:
  24112. secretRef:
  24113. description: SecretRef references a key in a secret that will be used as value.
  24114. properties:
  24115. key:
  24116. description: |-
  24117. A key in the referenced Secret.
  24118. Some instances of this field may be defaulted, in others it may be required.
  24119. maxLength: 253
  24120. minLength: 1
  24121. pattern: ^[-._a-zA-Z0-9]+$
  24122. type: string
  24123. name:
  24124. description: The name of the Secret resource being referred to.
  24125. maxLength: 253
  24126. minLength: 1
  24127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24128. type: string
  24129. namespace:
  24130. description: |-
  24131. The namespace of the Secret resource being referred to.
  24132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24133. maxLength: 63
  24134. minLength: 1
  24135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24136. type: string
  24137. type: object
  24138. value:
  24139. description: Value can be specified directly to set a value without using a secret.
  24140. type: string
  24141. type: object
  24142. tenant:
  24143. description: Tenant is the chosen hostname / site name.
  24144. type: string
  24145. tld:
  24146. description: |-
  24147. TLD is based on the server location that was chosen during provisioning.
  24148. If unset, defaults to "com".
  24149. type: string
  24150. urlTemplate:
  24151. description: |-
  24152. URLTemplate
  24153. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  24154. type: string
  24155. required:
  24156. - clientId
  24157. - clientSecret
  24158. - tenant
  24159. type: object
  24160. device42:
  24161. description: Device42 configures this store to sync secrets using the Device42 provider
  24162. properties:
  24163. auth:
  24164. description: Auth configures how secret-manager authenticates with a Device42 instance.
  24165. properties:
  24166. secretRef:
  24167. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  24168. properties:
  24169. credentials:
  24170. description: Username / Password is used for authentication.
  24171. properties:
  24172. key:
  24173. description: |-
  24174. A key in the referenced Secret.
  24175. Some instances of this field may be defaulted, in others it may be required.
  24176. maxLength: 253
  24177. minLength: 1
  24178. pattern: ^[-._a-zA-Z0-9]+$
  24179. type: string
  24180. name:
  24181. description: The name of the Secret resource being referred to.
  24182. maxLength: 253
  24183. minLength: 1
  24184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24185. type: string
  24186. namespace:
  24187. description: |-
  24188. The namespace of the Secret resource being referred to.
  24189. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24190. maxLength: 63
  24191. minLength: 1
  24192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24193. type: string
  24194. type: object
  24195. type: object
  24196. required:
  24197. - secretRef
  24198. type: object
  24199. host:
  24200. description: URL configures the Device42 instance URL.
  24201. type: string
  24202. required:
  24203. - auth
  24204. - host
  24205. type: object
  24206. doppler:
  24207. description: Doppler configures this store to sync secrets using the Doppler provider
  24208. properties:
  24209. auth:
  24210. description: Auth configures how the Operator authenticates with the Doppler API
  24211. properties:
  24212. secretRef:
  24213. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24214. properties:
  24215. dopplerToken:
  24216. description: |-
  24217. The DopplerToken is used for authentication.
  24218. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24219. The Key attribute defaults to dopplerToken if not specified.
  24220. properties:
  24221. key:
  24222. description: |-
  24223. A key in the referenced Secret.
  24224. Some instances of this field may be defaulted, in others it may be required.
  24225. maxLength: 253
  24226. minLength: 1
  24227. pattern: ^[-._a-zA-Z0-9]+$
  24228. type: string
  24229. name:
  24230. description: The name of the Secret resource being referred to.
  24231. maxLength: 253
  24232. minLength: 1
  24233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24234. type: string
  24235. namespace:
  24236. description: |-
  24237. The namespace of the Secret resource being referred to.
  24238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24239. maxLength: 63
  24240. minLength: 1
  24241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24242. type: string
  24243. type: object
  24244. required:
  24245. - dopplerToken
  24246. type: object
  24247. required:
  24248. - secretRef
  24249. type: object
  24250. config:
  24251. description: Doppler config (required if not using a Service Token)
  24252. type: string
  24253. format:
  24254. description: Format enables the downloading of secrets as a file (string)
  24255. enum:
  24256. - json
  24257. - dotnet-json
  24258. - env
  24259. - yaml
  24260. - docker
  24261. type: string
  24262. nameTransformer:
  24263. description: Environment variable compatible name transforms that change secret names to a different format
  24264. enum:
  24265. - upper-camel
  24266. - camel
  24267. - lower-snake
  24268. - tf-var
  24269. - dotnet-env
  24270. - lower-kebab
  24271. type: string
  24272. project:
  24273. description: Doppler project (required if not using a Service Token)
  24274. type: string
  24275. required:
  24276. - auth
  24277. type: object
  24278. fake:
  24279. description: Fake configures a store with static key/value pairs
  24280. properties:
  24281. data:
  24282. items:
  24283. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24284. properties:
  24285. key:
  24286. type: string
  24287. value:
  24288. type: string
  24289. version:
  24290. type: string
  24291. required:
  24292. - key
  24293. - value
  24294. type: object
  24295. type: array
  24296. required:
  24297. - data
  24298. type: object
  24299. fortanix:
  24300. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24301. properties:
  24302. apiKey:
  24303. description: APIKey is the API token to access SDKMS Applications.
  24304. properties:
  24305. secretRef:
  24306. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24307. properties:
  24308. key:
  24309. description: |-
  24310. A key in the referenced Secret.
  24311. Some instances of this field may be defaulted, in others it may be required.
  24312. maxLength: 253
  24313. minLength: 1
  24314. pattern: ^[-._a-zA-Z0-9]+$
  24315. type: string
  24316. name:
  24317. description: The name of the Secret resource being referred to.
  24318. maxLength: 253
  24319. minLength: 1
  24320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24321. type: string
  24322. namespace:
  24323. description: |-
  24324. The namespace of the Secret resource being referred to.
  24325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24326. maxLength: 63
  24327. minLength: 1
  24328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24329. type: string
  24330. type: object
  24331. type: object
  24332. apiUrl:
  24333. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24334. type: string
  24335. type: object
  24336. gcpsm:
  24337. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24338. properties:
  24339. auth:
  24340. description: Auth defines the information necessary to authenticate against GCP
  24341. properties:
  24342. secretRef:
  24343. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24344. properties:
  24345. secretAccessKeySecretRef:
  24346. description: The SecretAccessKey is used for authentication
  24347. properties:
  24348. key:
  24349. description: |-
  24350. A key in the referenced Secret.
  24351. Some instances of this field may be defaulted, in others it may be required.
  24352. maxLength: 253
  24353. minLength: 1
  24354. pattern: ^[-._a-zA-Z0-9]+$
  24355. type: string
  24356. name:
  24357. description: The name of the Secret resource being referred to.
  24358. maxLength: 253
  24359. minLength: 1
  24360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24361. type: string
  24362. namespace:
  24363. description: |-
  24364. The namespace of the Secret resource being referred to.
  24365. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24366. maxLength: 63
  24367. minLength: 1
  24368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24369. type: string
  24370. type: object
  24371. type: object
  24372. workloadIdentity:
  24373. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24374. properties:
  24375. clusterLocation:
  24376. description: |-
  24377. ClusterLocation is the location of the cluster
  24378. If not specified, it fetches information from the metadata server
  24379. type: string
  24380. clusterName:
  24381. description: |-
  24382. ClusterName is the name of the cluster
  24383. If not specified, it fetches information from the metadata server
  24384. type: string
  24385. clusterProjectID:
  24386. description: |-
  24387. ClusterProjectID is the project ID of the cluster
  24388. If not specified, it fetches information from the metadata server
  24389. type: string
  24390. serviceAccountRef:
  24391. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24392. properties:
  24393. audiences:
  24394. description: |-
  24395. Audience specifies the `aud` claim for the service account token
  24396. Some providers automatically extend the audience field based on well-known annotations for workload
  24397. identity (e.g. IRSA or GCP Workload Identity)
  24398. items:
  24399. type: string
  24400. type: array
  24401. name:
  24402. description: The name of the ServiceAccount resource being referred to.
  24403. maxLength: 253
  24404. minLength: 1
  24405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24406. type: string
  24407. namespace:
  24408. description: |-
  24409. Namespace of the resource being referred to.
  24410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24411. maxLength: 63
  24412. minLength: 1
  24413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24414. type: string
  24415. required:
  24416. - name
  24417. type: object
  24418. required:
  24419. - serviceAccountRef
  24420. type: object
  24421. type: object
  24422. location:
  24423. description: Location optionally defines a location for a secret
  24424. type: string
  24425. projectID:
  24426. description: ProjectID project where secret is located
  24427. type: string
  24428. type: object
  24429. github:
  24430. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24431. properties:
  24432. appID:
  24433. description: appID specifies the Github APP that will be used to authenticate the client
  24434. format: int64
  24435. type: integer
  24436. auth:
  24437. description: auth configures how secret-manager authenticates with a Github instance.
  24438. properties:
  24439. privateKey:
  24440. description: |-
  24441. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24442. In some instances, `key` is a required field.
  24443. properties:
  24444. key:
  24445. description: |-
  24446. A key in the referenced Secret.
  24447. Some instances of this field may be defaulted, in others it may be required.
  24448. maxLength: 253
  24449. minLength: 1
  24450. pattern: ^[-._a-zA-Z0-9]+$
  24451. type: string
  24452. name:
  24453. description: The name of the Secret resource being referred to.
  24454. maxLength: 253
  24455. minLength: 1
  24456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24457. type: string
  24458. namespace:
  24459. description: |-
  24460. The namespace of the Secret resource being referred to.
  24461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24462. maxLength: 63
  24463. minLength: 1
  24464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24465. type: string
  24466. type: object
  24467. required:
  24468. - privateKey
  24469. type: object
  24470. environment:
  24471. description: environment will be used to fetch secrets from a particular environment within a github repository
  24472. type: string
  24473. installationID:
  24474. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24475. format: int64
  24476. type: integer
  24477. organization:
  24478. description: organization will be used to fetch secrets from the Github organization
  24479. type: string
  24480. repository:
  24481. description: repository will be used to fetch secrets from the Github repository within an organization
  24482. type: string
  24483. uploadURL:
  24484. description: Upload URL for enterprise instances. Default to URL.
  24485. type: string
  24486. url:
  24487. default: https://github.com/
  24488. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24489. type: string
  24490. required:
  24491. - appID
  24492. - auth
  24493. - installationID
  24494. - organization
  24495. type: object
  24496. gitlab:
  24497. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24498. properties:
  24499. auth:
  24500. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24501. properties:
  24502. SecretRef:
  24503. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24504. properties:
  24505. accessToken:
  24506. description: AccessToken is used for authentication.
  24507. properties:
  24508. key:
  24509. description: |-
  24510. A key in the referenced Secret.
  24511. Some instances of this field may be defaulted, in others it may be required.
  24512. maxLength: 253
  24513. minLength: 1
  24514. pattern: ^[-._a-zA-Z0-9]+$
  24515. type: string
  24516. name:
  24517. description: The name of the Secret resource being referred to.
  24518. maxLength: 253
  24519. minLength: 1
  24520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24521. type: string
  24522. namespace:
  24523. description: |-
  24524. The namespace of the Secret resource being referred to.
  24525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24526. maxLength: 63
  24527. minLength: 1
  24528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24529. type: string
  24530. type: object
  24531. type: object
  24532. required:
  24533. - SecretRef
  24534. type: object
  24535. caBundle:
  24536. description: |-
  24537. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24538. can be performed.
  24539. format: byte
  24540. type: string
  24541. caProvider:
  24542. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24543. properties:
  24544. key:
  24545. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24546. maxLength: 253
  24547. minLength: 1
  24548. pattern: ^[-._a-zA-Z0-9]+$
  24549. type: string
  24550. name:
  24551. description: The name of the object located at the provider type.
  24552. maxLength: 253
  24553. minLength: 1
  24554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24555. type: string
  24556. namespace:
  24557. description: |-
  24558. The namespace the Provider type is in.
  24559. Can only be defined when used in a ClusterSecretStore.
  24560. maxLength: 63
  24561. minLength: 1
  24562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24563. type: string
  24564. type:
  24565. description: The type of provider to use such as "Secret", or "ConfigMap".
  24566. enum:
  24567. - Secret
  24568. - ConfigMap
  24569. type: string
  24570. required:
  24571. - name
  24572. - type
  24573. type: object
  24574. environment:
  24575. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24576. type: string
  24577. groupIDs:
  24578. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24579. items:
  24580. type: string
  24581. type: array
  24582. inheritFromGroups:
  24583. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24584. type: boolean
  24585. projectID:
  24586. description: ProjectID specifies a project where secrets are located.
  24587. type: string
  24588. url:
  24589. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24590. type: string
  24591. required:
  24592. - auth
  24593. type: object
  24594. ibm:
  24595. description: IBM configures this store to sync secrets using IBM Cloud provider
  24596. properties:
  24597. auth:
  24598. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24599. maxProperties: 1
  24600. minProperties: 1
  24601. properties:
  24602. containerAuth:
  24603. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24604. properties:
  24605. iamEndpoint:
  24606. type: string
  24607. profile:
  24608. description: the IBM Trusted Profile
  24609. type: string
  24610. tokenLocation:
  24611. description: Location the token is mounted on the pod
  24612. type: string
  24613. required:
  24614. - profile
  24615. type: object
  24616. secretRef:
  24617. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24618. properties:
  24619. secretApiKeySecretRef:
  24620. description: The SecretAccessKey is used for authentication
  24621. properties:
  24622. key:
  24623. description: |-
  24624. A key in the referenced Secret.
  24625. Some instances of this field may be defaulted, in others it may be required.
  24626. maxLength: 253
  24627. minLength: 1
  24628. pattern: ^[-._a-zA-Z0-9]+$
  24629. type: string
  24630. name:
  24631. description: The name of the Secret resource being referred to.
  24632. maxLength: 253
  24633. minLength: 1
  24634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24635. type: string
  24636. namespace:
  24637. description: |-
  24638. The namespace of the Secret resource being referred to.
  24639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24640. maxLength: 63
  24641. minLength: 1
  24642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24643. type: string
  24644. type: object
  24645. type: object
  24646. type: object
  24647. serviceUrl:
  24648. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24649. type: string
  24650. required:
  24651. - auth
  24652. type: object
  24653. infisical:
  24654. description: Infisical configures this store to sync secrets using the Infisical provider
  24655. properties:
  24656. auth:
  24657. description: Auth configures how the Operator authenticates with the Infisical API
  24658. properties:
  24659. universalAuthCredentials:
  24660. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24661. properties:
  24662. clientId:
  24663. description: |-
  24664. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24665. In some instances, `key` is a required field.
  24666. properties:
  24667. key:
  24668. description: |-
  24669. A key in the referenced Secret.
  24670. Some instances of this field may be defaulted, in others it may be required.
  24671. maxLength: 253
  24672. minLength: 1
  24673. pattern: ^[-._a-zA-Z0-9]+$
  24674. type: string
  24675. name:
  24676. description: The name of the Secret resource being referred to.
  24677. maxLength: 253
  24678. minLength: 1
  24679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24680. type: string
  24681. namespace:
  24682. description: |-
  24683. The namespace of the Secret resource being referred to.
  24684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24685. maxLength: 63
  24686. minLength: 1
  24687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24688. type: string
  24689. type: object
  24690. clientSecret:
  24691. description: |-
  24692. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24693. In some instances, `key` is a required field.
  24694. properties:
  24695. key:
  24696. description: |-
  24697. A key in the referenced Secret.
  24698. Some instances of this field may be defaulted, in others it may be required.
  24699. maxLength: 253
  24700. minLength: 1
  24701. pattern: ^[-._a-zA-Z0-9]+$
  24702. type: string
  24703. name:
  24704. description: The name of the Secret resource being referred to.
  24705. maxLength: 253
  24706. minLength: 1
  24707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24708. type: string
  24709. namespace:
  24710. description: |-
  24711. The namespace of the Secret resource being referred to.
  24712. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24713. maxLength: 63
  24714. minLength: 1
  24715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24716. type: string
  24717. type: object
  24718. required:
  24719. - clientId
  24720. - clientSecret
  24721. type: object
  24722. type: object
  24723. hostAPI:
  24724. default: https://app.infisical.com/api
  24725. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24726. type: string
  24727. secretsScope:
  24728. description: SecretsScope defines the scope of the secrets within the workspace
  24729. properties:
  24730. environmentSlug:
  24731. description: EnvironmentSlug is the required slug identifier for the environment.
  24732. type: string
  24733. expandSecretReferences:
  24734. default: true
  24735. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24736. type: boolean
  24737. projectSlug:
  24738. description: ProjectSlug is the required slug identifier for the project.
  24739. type: string
  24740. recursive:
  24741. default: false
  24742. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24743. type: boolean
  24744. secretsPath:
  24745. default: /
  24746. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24747. type: string
  24748. required:
  24749. - environmentSlug
  24750. - projectSlug
  24751. type: object
  24752. required:
  24753. - auth
  24754. - secretsScope
  24755. type: object
  24756. keepersecurity:
  24757. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24758. properties:
  24759. authRef:
  24760. description: |-
  24761. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24762. In some instances, `key` is a required field.
  24763. properties:
  24764. key:
  24765. description: |-
  24766. A key in the referenced Secret.
  24767. Some instances of this field may be defaulted, in others it may be required.
  24768. maxLength: 253
  24769. minLength: 1
  24770. pattern: ^[-._a-zA-Z0-9]+$
  24771. type: string
  24772. name:
  24773. description: The name of the Secret resource being referred to.
  24774. maxLength: 253
  24775. minLength: 1
  24776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24777. type: string
  24778. namespace:
  24779. description: |-
  24780. The namespace of the Secret resource being referred to.
  24781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24782. maxLength: 63
  24783. minLength: 1
  24784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24785. type: string
  24786. type: object
  24787. folderID:
  24788. type: string
  24789. required:
  24790. - authRef
  24791. - folderID
  24792. type: object
  24793. kubernetes:
  24794. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24795. properties:
  24796. auth:
  24797. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24798. maxProperties: 1
  24799. minProperties: 1
  24800. properties:
  24801. cert:
  24802. description: has both clientCert and clientKey as secretKeySelector
  24803. properties:
  24804. clientCert:
  24805. description: |-
  24806. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24807. In some instances, `key` is a required field.
  24808. properties:
  24809. key:
  24810. description: |-
  24811. A key in the referenced Secret.
  24812. Some instances of this field may be defaulted, in others it may be required.
  24813. maxLength: 253
  24814. minLength: 1
  24815. pattern: ^[-._a-zA-Z0-9]+$
  24816. type: string
  24817. name:
  24818. description: The name of the Secret resource being referred to.
  24819. maxLength: 253
  24820. minLength: 1
  24821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24822. type: string
  24823. namespace:
  24824. description: |-
  24825. The namespace of the Secret resource being referred to.
  24826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24827. maxLength: 63
  24828. minLength: 1
  24829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24830. type: string
  24831. type: object
  24832. clientKey:
  24833. description: |-
  24834. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24835. In some instances, `key` is a required field.
  24836. properties:
  24837. key:
  24838. description: |-
  24839. A key in the referenced Secret.
  24840. Some instances of this field may be defaulted, in others it may be required.
  24841. maxLength: 253
  24842. minLength: 1
  24843. pattern: ^[-._a-zA-Z0-9]+$
  24844. type: string
  24845. name:
  24846. description: The name of the Secret resource being referred to.
  24847. maxLength: 253
  24848. minLength: 1
  24849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24850. type: string
  24851. namespace:
  24852. description: |-
  24853. The namespace of the Secret resource being referred to.
  24854. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24855. maxLength: 63
  24856. minLength: 1
  24857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24858. type: string
  24859. type: object
  24860. type: object
  24861. serviceAccount:
  24862. description: points to a service account that should be used for authentication
  24863. properties:
  24864. audiences:
  24865. description: |-
  24866. Audience specifies the `aud` claim for the service account token
  24867. Some providers automatically extend the audience field based on well-known annotations for workload
  24868. identity (e.g. IRSA or GCP Workload Identity)
  24869. items:
  24870. type: string
  24871. type: array
  24872. name:
  24873. description: The name of the ServiceAccount resource being referred to.
  24874. maxLength: 253
  24875. minLength: 1
  24876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24877. type: string
  24878. namespace:
  24879. description: |-
  24880. Namespace of the resource being referred to.
  24881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24882. maxLength: 63
  24883. minLength: 1
  24884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24885. type: string
  24886. required:
  24887. - name
  24888. type: object
  24889. token:
  24890. description: use static token to authenticate with
  24891. properties:
  24892. bearerToken:
  24893. description: |-
  24894. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24895. In some instances, `key` is a required field.
  24896. properties:
  24897. key:
  24898. description: |-
  24899. A key in the referenced Secret.
  24900. Some instances of this field may be defaulted, in others it may be required.
  24901. maxLength: 253
  24902. minLength: 1
  24903. pattern: ^[-._a-zA-Z0-9]+$
  24904. type: string
  24905. name:
  24906. description: The name of the Secret resource being referred to.
  24907. maxLength: 253
  24908. minLength: 1
  24909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24910. type: string
  24911. namespace:
  24912. description: |-
  24913. The namespace of the Secret resource being referred to.
  24914. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24915. maxLength: 63
  24916. minLength: 1
  24917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24918. type: string
  24919. type: object
  24920. type: object
  24921. type: object
  24922. authRef:
  24923. description: A reference to a secret that contains the auth information.
  24924. properties:
  24925. key:
  24926. description: |-
  24927. A key in the referenced Secret.
  24928. Some instances of this field may be defaulted, in others it may be required.
  24929. maxLength: 253
  24930. minLength: 1
  24931. pattern: ^[-._a-zA-Z0-9]+$
  24932. type: string
  24933. name:
  24934. description: The name of the Secret resource being referred to.
  24935. maxLength: 253
  24936. minLength: 1
  24937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24938. type: string
  24939. namespace:
  24940. description: |-
  24941. The namespace of the Secret resource being referred to.
  24942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24943. maxLength: 63
  24944. minLength: 1
  24945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24946. type: string
  24947. type: object
  24948. remoteNamespace:
  24949. default: default
  24950. description: Remote namespace to fetch the secrets from
  24951. maxLength: 63
  24952. minLength: 1
  24953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24954. type: string
  24955. server:
  24956. description: configures the Kubernetes server Address.
  24957. properties:
  24958. caBundle:
  24959. description: CABundle is a base64-encoded CA certificate
  24960. format: byte
  24961. type: string
  24962. caProvider:
  24963. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24964. properties:
  24965. key:
  24966. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24967. maxLength: 253
  24968. minLength: 1
  24969. pattern: ^[-._a-zA-Z0-9]+$
  24970. type: string
  24971. name:
  24972. description: The name of the object located at the provider type.
  24973. maxLength: 253
  24974. minLength: 1
  24975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24976. type: string
  24977. namespace:
  24978. description: |-
  24979. The namespace the Provider type is in.
  24980. Can only be defined when used in a ClusterSecretStore.
  24981. maxLength: 63
  24982. minLength: 1
  24983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24984. type: string
  24985. type:
  24986. description: The type of provider to use such as "Secret", or "ConfigMap".
  24987. enum:
  24988. - Secret
  24989. - ConfigMap
  24990. type: string
  24991. required:
  24992. - name
  24993. - type
  24994. type: object
  24995. url:
  24996. default: kubernetes.default
  24997. description: configures the Kubernetes server Address.
  24998. type: string
  24999. type: object
  25000. type: object
  25001. onboardbase:
  25002. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  25003. properties:
  25004. apiHost:
  25005. default: https://public.onboardbase.com/api/v1/
  25006. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  25007. type: string
  25008. auth:
  25009. description: Auth configures how the Operator authenticates with the Onboardbase API
  25010. properties:
  25011. apiKeyRef:
  25012. description: |-
  25013. OnboardbaseAPIKey is the APIKey generated by an admin account.
  25014. It is used to recognize and authorize access to a project and environment within onboardbase
  25015. properties:
  25016. key:
  25017. description: |-
  25018. A key in the referenced Secret.
  25019. Some instances of this field may be defaulted, in others it may be required.
  25020. maxLength: 253
  25021. minLength: 1
  25022. pattern: ^[-._a-zA-Z0-9]+$
  25023. type: string
  25024. name:
  25025. description: The name of the Secret resource being referred to.
  25026. maxLength: 253
  25027. minLength: 1
  25028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25029. type: string
  25030. namespace:
  25031. description: |-
  25032. The namespace of the Secret resource being referred to.
  25033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25034. maxLength: 63
  25035. minLength: 1
  25036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25037. type: string
  25038. type: object
  25039. passcodeRef:
  25040. description: OnboardbasePasscode is the passcode attached to the API Key
  25041. properties:
  25042. key:
  25043. description: |-
  25044. A key in the referenced Secret.
  25045. Some instances of this field may be defaulted, in others it may be required.
  25046. maxLength: 253
  25047. minLength: 1
  25048. pattern: ^[-._a-zA-Z0-9]+$
  25049. type: string
  25050. name:
  25051. description: The name of the Secret resource being referred to.
  25052. maxLength: 253
  25053. minLength: 1
  25054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25055. type: string
  25056. namespace:
  25057. description: |-
  25058. The namespace of the Secret resource being referred to.
  25059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25060. maxLength: 63
  25061. minLength: 1
  25062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25063. type: string
  25064. type: object
  25065. required:
  25066. - apiKeyRef
  25067. - passcodeRef
  25068. type: object
  25069. environment:
  25070. default: development
  25071. description: Environment is the name of an environmnent within a project to pull the secrets from
  25072. type: string
  25073. project:
  25074. default: development
  25075. description: Project is an onboardbase project that the secrets should be pulled from
  25076. type: string
  25077. required:
  25078. - apiHost
  25079. - auth
  25080. - environment
  25081. - project
  25082. type: object
  25083. onepassword:
  25084. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  25085. properties:
  25086. auth:
  25087. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  25088. properties:
  25089. secretRef:
  25090. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  25091. properties:
  25092. connectTokenSecretRef:
  25093. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  25094. properties:
  25095. key:
  25096. description: |-
  25097. A key in the referenced Secret.
  25098. Some instances of this field may be defaulted, in others it may be required.
  25099. maxLength: 253
  25100. minLength: 1
  25101. pattern: ^[-._a-zA-Z0-9]+$
  25102. type: string
  25103. name:
  25104. description: The name of the Secret resource being referred to.
  25105. maxLength: 253
  25106. minLength: 1
  25107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25108. type: string
  25109. namespace:
  25110. description: |-
  25111. The namespace of the Secret resource being referred to.
  25112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25113. maxLength: 63
  25114. minLength: 1
  25115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25116. type: string
  25117. type: object
  25118. required:
  25119. - connectTokenSecretRef
  25120. type: object
  25121. required:
  25122. - secretRef
  25123. type: object
  25124. connectHost:
  25125. description: ConnectHost defines the OnePassword Connect Server to connect to
  25126. type: string
  25127. vaults:
  25128. additionalProperties:
  25129. type: integer
  25130. description: Vaults defines which OnePassword vaults to search in which order
  25131. type: object
  25132. required:
  25133. - auth
  25134. - connectHost
  25135. - vaults
  25136. type: object
  25137. oracle:
  25138. description: Oracle configures this store to sync secrets using Oracle Vault provider
  25139. properties:
  25140. auth:
  25141. description: |-
  25142. Auth configures how secret-manager authenticates with the Oracle Vault.
  25143. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  25144. properties:
  25145. secretRef:
  25146. description: SecretRef to pass through sensitive information.
  25147. properties:
  25148. fingerprint:
  25149. description: Fingerprint is the fingerprint of the API private key.
  25150. properties:
  25151. key:
  25152. description: |-
  25153. A key in the referenced Secret.
  25154. Some instances of this field may be defaulted, in others it may be required.
  25155. maxLength: 253
  25156. minLength: 1
  25157. pattern: ^[-._a-zA-Z0-9]+$
  25158. type: string
  25159. name:
  25160. description: The name of the Secret resource being referred to.
  25161. maxLength: 253
  25162. minLength: 1
  25163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25164. type: string
  25165. namespace:
  25166. description: |-
  25167. The namespace of the Secret resource being referred to.
  25168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25169. maxLength: 63
  25170. minLength: 1
  25171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25172. type: string
  25173. type: object
  25174. privatekey:
  25175. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  25176. properties:
  25177. key:
  25178. description: |-
  25179. A key in the referenced Secret.
  25180. Some instances of this field may be defaulted, in others it may be required.
  25181. maxLength: 253
  25182. minLength: 1
  25183. pattern: ^[-._a-zA-Z0-9]+$
  25184. type: string
  25185. name:
  25186. description: The name of the Secret resource being referred to.
  25187. maxLength: 253
  25188. minLength: 1
  25189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25190. type: string
  25191. namespace:
  25192. description: |-
  25193. The namespace of the Secret resource being referred to.
  25194. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25195. maxLength: 63
  25196. minLength: 1
  25197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25198. type: string
  25199. type: object
  25200. required:
  25201. - fingerprint
  25202. - privatekey
  25203. type: object
  25204. tenancy:
  25205. description: Tenancy is the tenancy OCID where user is located.
  25206. type: string
  25207. user:
  25208. description: User is an access OCID specific to the account.
  25209. type: string
  25210. required:
  25211. - secretRef
  25212. - tenancy
  25213. - user
  25214. type: object
  25215. compartment:
  25216. description: |-
  25217. Compartment is the vault compartment OCID.
  25218. Required for PushSecret
  25219. type: string
  25220. encryptionKey:
  25221. description: |-
  25222. EncryptionKey is the OCID of the encryption key within the vault.
  25223. Required for PushSecret
  25224. type: string
  25225. principalType:
  25226. description: |-
  25227. The type of principal to use for authentication. If left blank, the Auth struct will
  25228. determine the principal type. This optional field must be specified if using
  25229. workload identity.
  25230. enum:
  25231. - ""
  25232. - UserPrincipal
  25233. - InstancePrincipal
  25234. - Workload
  25235. type: string
  25236. region:
  25237. description: Region is the region where vault is located.
  25238. type: string
  25239. serviceAccountRef:
  25240. description: |-
  25241. ServiceAccountRef specified the service account
  25242. that should be used when authenticating with WorkloadIdentity.
  25243. properties:
  25244. audiences:
  25245. description: |-
  25246. Audience specifies the `aud` claim for the service account token
  25247. Some providers automatically extend the audience field based on well-known annotations for workload
  25248. identity (e.g. IRSA or GCP Workload Identity)
  25249. items:
  25250. type: string
  25251. type: array
  25252. name:
  25253. description: The name of the ServiceAccount resource being referred to.
  25254. maxLength: 253
  25255. minLength: 1
  25256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25257. type: string
  25258. namespace:
  25259. description: |-
  25260. Namespace of the resource being referred to.
  25261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25262. maxLength: 63
  25263. minLength: 1
  25264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25265. type: string
  25266. required:
  25267. - name
  25268. type: object
  25269. vault:
  25270. description: Vault is the vault's OCID of the specific vault where secret is located.
  25271. type: string
  25272. required:
  25273. - region
  25274. - vault
  25275. type: object
  25276. passbolt:
  25277. description: PassboltProvider defines configuration for the Passbolt provider.
  25278. properties:
  25279. auth:
  25280. description: Auth defines the information necessary to authenticate against Passbolt Server
  25281. properties:
  25282. passwordSecretRef:
  25283. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25284. properties:
  25285. key:
  25286. description: |-
  25287. A key in the referenced Secret.
  25288. Some instances of this field may be defaulted, in others it may be required.
  25289. maxLength: 253
  25290. minLength: 1
  25291. pattern: ^[-._a-zA-Z0-9]+$
  25292. type: string
  25293. name:
  25294. description: The name of the Secret resource being referred to.
  25295. maxLength: 253
  25296. minLength: 1
  25297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25298. type: string
  25299. namespace:
  25300. description: |-
  25301. The namespace of the Secret resource being referred to.
  25302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25303. maxLength: 63
  25304. minLength: 1
  25305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25306. type: string
  25307. type: object
  25308. privateKeySecretRef:
  25309. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25310. properties:
  25311. key:
  25312. description: |-
  25313. A key in the referenced Secret.
  25314. Some instances of this field may be defaulted, in others it may be required.
  25315. maxLength: 253
  25316. minLength: 1
  25317. pattern: ^[-._a-zA-Z0-9]+$
  25318. type: string
  25319. name:
  25320. description: The name of the Secret resource being referred to.
  25321. maxLength: 253
  25322. minLength: 1
  25323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25324. type: string
  25325. namespace:
  25326. description: |-
  25327. The namespace of the Secret resource being referred to.
  25328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25329. maxLength: 63
  25330. minLength: 1
  25331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25332. type: string
  25333. type: object
  25334. required:
  25335. - passwordSecretRef
  25336. - privateKeySecretRef
  25337. type: object
  25338. host:
  25339. description: Host defines the Passbolt Server to connect to
  25340. type: string
  25341. required:
  25342. - auth
  25343. - host
  25344. type: object
  25345. passworddepot:
  25346. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25347. properties:
  25348. auth:
  25349. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25350. properties:
  25351. secretRef:
  25352. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25353. properties:
  25354. credentials:
  25355. description: Username / Password is used for authentication.
  25356. properties:
  25357. key:
  25358. description: |-
  25359. A key in the referenced Secret.
  25360. Some instances of this field may be defaulted, in others it may be required.
  25361. maxLength: 253
  25362. minLength: 1
  25363. pattern: ^[-._a-zA-Z0-9]+$
  25364. type: string
  25365. name:
  25366. description: The name of the Secret resource being referred to.
  25367. maxLength: 253
  25368. minLength: 1
  25369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25370. type: string
  25371. namespace:
  25372. description: |-
  25373. The namespace of the Secret resource being referred to.
  25374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25375. maxLength: 63
  25376. minLength: 1
  25377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25378. type: string
  25379. type: object
  25380. type: object
  25381. required:
  25382. - secretRef
  25383. type: object
  25384. database:
  25385. description: Database to use as source
  25386. type: string
  25387. host:
  25388. description: URL configures the Password Depot instance URL.
  25389. type: string
  25390. required:
  25391. - auth
  25392. - database
  25393. - host
  25394. type: object
  25395. previder:
  25396. description: Previder configures this store to sync secrets using the Previder provider
  25397. properties:
  25398. auth:
  25399. description: PreviderAuth contains a secretRef for credentials.
  25400. properties:
  25401. secretRef:
  25402. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25403. properties:
  25404. accessToken:
  25405. description: The AccessToken is used for authentication
  25406. properties:
  25407. key:
  25408. description: |-
  25409. A key in the referenced Secret.
  25410. Some instances of this field may be defaulted, in others it may be required.
  25411. maxLength: 253
  25412. minLength: 1
  25413. pattern: ^[-._a-zA-Z0-9]+$
  25414. type: string
  25415. name:
  25416. description: The name of the Secret resource being referred to.
  25417. maxLength: 253
  25418. minLength: 1
  25419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25420. type: string
  25421. namespace:
  25422. description: |-
  25423. The namespace of the Secret resource being referred to.
  25424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25425. maxLength: 63
  25426. minLength: 1
  25427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25428. type: string
  25429. type: object
  25430. required:
  25431. - accessToken
  25432. type: object
  25433. type: object
  25434. baseUri:
  25435. type: string
  25436. required:
  25437. - auth
  25438. type: object
  25439. pulumi:
  25440. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25441. properties:
  25442. accessToken:
  25443. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25444. properties:
  25445. secretRef:
  25446. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25447. properties:
  25448. key:
  25449. description: |-
  25450. A key in the referenced Secret.
  25451. Some instances of this field may be defaulted, in others it may be required.
  25452. maxLength: 253
  25453. minLength: 1
  25454. pattern: ^[-._a-zA-Z0-9]+$
  25455. type: string
  25456. name:
  25457. description: The name of the Secret resource being referred to.
  25458. maxLength: 253
  25459. minLength: 1
  25460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25461. type: string
  25462. namespace:
  25463. description: |-
  25464. The namespace of the Secret resource being referred to.
  25465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25466. maxLength: 63
  25467. minLength: 1
  25468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25469. type: string
  25470. type: object
  25471. type: object
  25472. apiUrl:
  25473. default: https://api.pulumi.com/api/esc
  25474. description: APIURL is the URL of the Pulumi API.
  25475. type: string
  25476. environment:
  25477. description: |-
  25478. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25479. dynamically retrieved values from supported providers including all major clouds,
  25480. and other Pulumi ESC environments.
  25481. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25482. type: string
  25483. organization:
  25484. description: |-
  25485. Organization are a space to collaborate on shared projects and stacks.
  25486. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25487. type: string
  25488. project:
  25489. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25490. type: string
  25491. required:
  25492. - accessToken
  25493. - environment
  25494. - organization
  25495. - project
  25496. type: object
  25497. scaleway:
  25498. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25499. properties:
  25500. accessKey:
  25501. description: AccessKey is the non-secret part of the api key.
  25502. properties:
  25503. secretRef:
  25504. description: SecretRef references a key in a secret that will be used as value.
  25505. properties:
  25506. key:
  25507. description: |-
  25508. A key in the referenced Secret.
  25509. Some instances of this field may be defaulted, in others it may be required.
  25510. maxLength: 253
  25511. minLength: 1
  25512. pattern: ^[-._a-zA-Z0-9]+$
  25513. type: string
  25514. name:
  25515. description: The name of the Secret resource being referred to.
  25516. maxLength: 253
  25517. minLength: 1
  25518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25519. type: string
  25520. namespace:
  25521. description: |-
  25522. The namespace of the Secret resource being referred to.
  25523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25524. maxLength: 63
  25525. minLength: 1
  25526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25527. type: string
  25528. type: object
  25529. value:
  25530. description: Value can be specified directly to set a value without using a secret.
  25531. type: string
  25532. type: object
  25533. apiUrl:
  25534. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25535. type: string
  25536. projectId:
  25537. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25538. type: string
  25539. region:
  25540. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25541. type: string
  25542. secretKey:
  25543. description: SecretKey is the non-secret part of the api key.
  25544. properties:
  25545. secretRef:
  25546. description: SecretRef references a key in a secret that will be used as value.
  25547. properties:
  25548. key:
  25549. description: |-
  25550. A key in the referenced Secret.
  25551. Some instances of this field may be defaulted, in others it may be required.
  25552. maxLength: 253
  25553. minLength: 1
  25554. pattern: ^[-._a-zA-Z0-9]+$
  25555. type: string
  25556. name:
  25557. description: The name of the Secret resource being referred to.
  25558. maxLength: 253
  25559. minLength: 1
  25560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25561. type: string
  25562. namespace:
  25563. description: |-
  25564. The namespace of the Secret resource being referred to.
  25565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25566. maxLength: 63
  25567. minLength: 1
  25568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25569. type: string
  25570. type: object
  25571. value:
  25572. description: Value can be specified directly to set a value without using a secret.
  25573. type: string
  25574. type: object
  25575. required:
  25576. - accessKey
  25577. - projectId
  25578. - region
  25579. - secretKey
  25580. type: object
  25581. secretserver:
  25582. description: |-
  25583. SecretServer configures this store to sync secrets using SecretServer provider
  25584. https://docs.delinea.com/online-help/secret-server/start.htm
  25585. properties:
  25586. password:
  25587. description: Password is the secret server account password.
  25588. properties:
  25589. secretRef:
  25590. description: SecretRef references a key in a secret that will be used as value.
  25591. properties:
  25592. key:
  25593. description: |-
  25594. A key in the referenced Secret.
  25595. Some instances of this field may be defaulted, in others it may be required.
  25596. maxLength: 253
  25597. minLength: 1
  25598. pattern: ^[-._a-zA-Z0-9]+$
  25599. type: string
  25600. name:
  25601. description: The name of the Secret resource being referred to.
  25602. maxLength: 253
  25603. minLength: 1
  25604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25605. type: string
  25606. namespace:
  25607. description: |-
  25608. The namespace of the Secret resource being referred to.
  25609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25610. maxLength: 63
  25611. minLength: 1
  25612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25613. type: string
  25614. type: object
  25615. value:
  25616. description: Value can be specified directly to set a value without using a secret.
  25617. type: string
  25618. type: object
  25619. serverURL:
  25620. description: |-
  25621. ServerURL
  25622. URL to your secret server installation
  25623. type: string
  25624. username:
  25625. description: Username is the secret server account username.
  25626. properties:
  25627. secretRef:
  25628. description: SecretRef references a key in a secret that will be used as value.
  25629. properties:
  25630. key:
  25631. description: |-
  25632. A key in the referenced Secret.
  25633. Some instances of this field may be defaulted, in others it may be required.
  25634. maxLength: 253
  25635. minLength: 1
  25636. pattern: ^[-._a-zA-Z0-9]+$
  25637. type: string
  25638. name:
  25639. description: The name of the Secret resource being referred to.
  25640. maxLength: 253
  25641. minLength: 1
  25642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25643. type: string
  25644. namespace:
  25645. description: |-
  25646. The namespace of the Secret resource being referred to.
  25647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25648. maxLength: 63
  25649. minLength: 1
  25650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25651. type: string
  25652. type: object
  25653. value:
  25654. description: Value can be specified directly to set a value without using a secret.
  25655. type: string
  25656. type: object
  25657. required:
  25658. - password
  25659. - serverURL
  25660. - username
  25661. type: object
  25662. senhasegura:
  25663. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25664. properties:
  25665. auth:
  25666. description: Auth defines parameters to authenticate in senhasegura
  25667. properties:
  25668. clientId:
  25669. type: string
  25670. clientSecretSecretRef:
  25671. description: |-
  25672. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25673. In some instances, `key` is a required field.
  25674. properties:
  25675. key:
  25676. description: |-
  25677. A key in the referenced Secret.
  25678. Some instances of this field may be defaulted, in others it may be required.
  25679. maxLength: 253
  25680. minLength: 1
  25681. pattern: ^[-._a-zA-Z0-9]+$
  25682. type: string
  25683. name:
  25684. description: The name of the Secret resource being referred to.
  25685. maxLength: 253
  25686. minLength: 1
  25687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25688. type: string
  25689. namespace:
  25690. description: |-
  25691. The namespace of the Secret resource being referred to.
  25692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25693. maxLength: 63
  25694. minLength: 1
  25695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25696. type: string
  25697. type: object
  25698. required:
  25699. - clientId
  25700. - clientSecretSecretRef
  25701. type: object
  25702. ignoreSslCertificate:
  25703. default: false
  25704. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25705. type: boolean
  25706. module:
  25707. description: Module defines which senhasegura module should be used to get secrets
  25708. type: string
  25709. url:
  25710. description: URL of senhasegura
  25711. type: string
  25712. required:
  25713. - auth
  25714. - module
  25715. - url
  25716. type: object
  25717. vault:
  25718. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25719. properties:
  25720. auth:
  25721. description: Auth configures how secret-manager authenticates with the Vault server.
  25722. properties:
  25723. appRole:
  25724. description: |-
  25725. AppRole authenticates with Vault using the App Role auth mechanism,
  25726. with the role and secret stored in a Kubernetes Secret resource.
  25727. properties:
  25728. path:
  25729. default: approle
  25730. description: |-
  25731. Path where the App Role authentication backend is mounted
  25732. in Vault, e.g: "approle"
  25733. type: string
  25734. roleId:
  25735. description: |-
  25736. RoleID configured in the App Role authentication backend when setting
  25737. up the authentication backend in Vault.
  25738. type: string
  25739. roleRef:
  25740. description: |-
  25741. Reference to a key in a Secret that contains the App Role ID used
  25742. to authenticate with Vault.
  25743. The `key` field must be specified and denotes which entry within the Secret
  25744. resource is used as the app role id.
  25745. properties:
  25746. key:
  25747. description: |-
  25748. A key in the referenced Secret.
  25749. Some instances of this field may be defaulted, in others it may be required.
  25750. maxLength: 253
  25751. minLength: 1
  25752. pattern: ^[-._a-zA-Z0-9]+$
  25753. type: string
  25754. name:
  25755. description: The name of the Secret resource being referred to.
  25756. maxLength: 253
  25757. minLength: 1
  25758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25759. type: string
  25760. namespace:
  25761. description: |-
  25762. The namespace of the Secret resource being referred to.
  25763. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25764. maxLength: 63
  25765. minLength: 1
  25766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25767. type: string
  25768. type: object
  25769. secretRef:
  25770. description: |-
  25771. Reference to a key in a Secret that contains the App Role secret used
  25772. to authenticate with Vault.
  25773. The `key` field must be specified and denotes which entry within the Secret
  25774. resource is used as the app role secret.
  25775. properties:
  25776. key:
  25777. description: |-
  25778. A key in the referenced Secret.
  25779. Some instances of this field may be defaulted, in others it may be required.
  25780. maxLength: 253
  25781. minLength: 1
  25782. pattern: ^[-._a-zA-Z0-9]+$
  25783. type: string
  25784. name:
  25785. description: The name of the Secret resource being referred to.
  25786. maxLength: 253
  25787. minLength: 1
  25788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25789. type: string
  25790. namespace:
  25791. description: |-
  25792. The namespace of the Secret resource being referred to.
  25793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25794. maxLength: 63
  25795. minLength: 1
  25796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25797. type: string
  25798. type: object
  25799. required:
  25800. - path
  25801. - secretRef
  25802. type: object
  25803. cert:
  25804. description: |-
  25805. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25806. Cert authentication method
  25807. properties:
  25808. clientCert:
  25809. description: |-
  25810. ClientCert is a certificate to authenticate using the Cert Vault
  25811. authentication method
  25812. properties:
  25813. key:
  25814. description: |-
  25815. A key in the referenced Secret.
  25816. Some instances of this field may be defaulted, in others it may be required.
  25817. maxLength: 253
  25818. minLength: 1
  25819. pattern: ^[-._a-zA-Z0-9]+$
  25820. type: string
  25821. name:
  25822. description: The name of the Secret resource being referred to.
  25823. maxLength: 253
  25824. minLength: 1
  25825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25826. type: string
  25827. namespace:
  25828. description: |-
  25829. The namespace of the Secret resource being referred to.
  25830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25831. maxLength: 63
  25832. minLength: 1
  25833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25834. type: string
  25835. type: object
  25836. secretRef:
  25837. description: |-
  25838. SecretRef to a key in a Secret resource containing client private key to
  25839. authenticate with Vault using the Cert authentication method
  25840. properties:
  25841. key:
  25842. description: |-
  25843. A key in the referenced Secret.
  25844. Some instances of this field may be defaulted, in others it may be required.
  25845. maxLength: 253
  25846. minLength: 1
  25847. pattern: ^[-._a-zA-Z0-9]+$
  25848. type: string
  25849. name:
  25850. description: The name of the Secret resource being referred to.
  25851. maxLength: 253
  25852. minLength: 1
  25853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25854. type: string
  25855. namespace:
  25856. description: |-
  25857. The namespace of the Secret resource being referred to.
  25858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25859. maxLength: 63
  25860. minLength: 1
  25861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25862. type: string
  25863. type: object
  25864. type: object
  25865. iam:
  25866. description: |-
  25867. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25868. AWS IAM authentication method
  25869. properties:
  25870. externalID:
  25871. description: AWS External ID set on assumed IAM roles
  25872. type: string
  25873. jwt:
  25874. description: Specify a service account with IRSA enabled
  25875. properties:
  25876. serviceAccountRef:
  25877. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25878. properties:
  25879. audiences:
  25880. description: |-
  25881. Audience specifies the `aud` claim for the service account token
  25882. Some providers automatically extend the audience field based on well-known annotations for workload
  25883. identity (e.g. IRSA or GCP Workload Identity)
  25884. items:
  25885. type: string
  25886. type: array
  25887. name:
  25888. description: The name of the ServiceAccount resource being referred to.
  25889. maxLength: 253
  25890. minLength: 1
  25891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25892. type: string
  25893. namespace:
  25894. description: |-
  25895. Namespace of the resource being referred to.
  25896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25897. maxLength: 63
  25898. minLength: 1
  25899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25900. type: string
  25901. required:
  25902. - name
  25903. type: object
  25904. type: object
  25905. path:
  25906. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25907. type: string
  25908. region:
  25909. description: AWS region
  25910. type: string
  25911. role:
  25912. description: This is the AWS role to be assumed before talking to vault
  25913. type: string
  25914. secretRef:
  25915. description: Specify credentials in a Secret object
  25916. properties:
  25917. accessKeyIDSecretRef:
  25918. description: The AccessKeyID is used for authentication
  25919. properties:
  25920. key:
  25921. description: |-
  25922. A key in the referenced Secret.
  25923. Some instances of this field may be defaulted, in others it may be required.
  25924. maxLength: 253
  25925. minLength: 1
  25926. pattern: ^[-._a-zA-Z0-9]+$
  25927. type: string
  25928. name:
  25929. description: The name of the Secret resource being referred to.
  25930. maxLength: 253
  25931. minLength: 1
  25932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25933. type: string
  25934. namespace:
  25935. description: |-
  25936. The namespace of the Secret resource being referred to.
  25937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25938. maxLength: 63
  25939. minLength: 1
  25940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25941. type: string
  25942. type: object
  25943. secretAccessKeySecretRef:
  25944. description: The SecretAccessKey is used for authentication
  25945. properties:
  25946. key:
  25947. description: |-
  25948. A key in the referenced Secret.
  25949. Some instances of this field may be defaulted, in others it may be required.
  25950. maxLength: 253
  25951. minLength: 1
  25952. pattern: ^[-._a-zA-Z0-9]+$
  25953. type: string
  25954. name:
  25955. description: The name of the Secret resource being referred to.
  25956. maxLength: 253
  25957. minLength: 1
  25958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25959. type: string
  25960. namespace:
  25961. description: |-
  25962. The namespace of the Secret resource being referred to.
  25963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25964. maxLength: 63
  25965. minLength: 1
  25966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25967. type: string
  25968. type: object
  25969. sessionTokenSecretRef:
  25970. description: |-
  25971. The SessionToken used for authentication
  25972. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25973. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25974. properties:
  25975. key:
  25976. description: |-
  25977. A key in the referenced Secret.
  25978. Some instances of this field may be defaulted, in others it may be required.
  25979. maxLength: 253
  25980. minLength: 1
  25981. pattern: ^[-._a-zA-Z0-9]+$
  25982. type: string
  25983. name:
  25984. description: The name of the Secret resource being referred to.
  25985. maxLength: 253
  25986. minLength: 1
  25987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25988. type: string
  25989. namespace:
  25990. description: |-
  25991. The namespace of the Secret resource being referred to.
  25992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25993. maxLength: 63
  25994. minLength: 1
  25995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25996. type: string
  25997. type: object
  25998. type: object
  25999. vaultAwsIamServerID:
  26000. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  26001. type: string
  26002. vaultRole:
  26003. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  26004. type: string
  26005. required:
  26006. - vaultRole
  26007. type: object
  26008. jwt:
  26009. description: |-
  26010. Jwt authenticates with Vault by passing role and JWT token using the
  26011. JWT/OIDC authentication method
  26012. properties:
  26013. kubernetesServiceAccountToken:
  26014. description: |-
  26015. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  26016. a token for with the `TokenRequest` API.
  26017. properties:
  26018. audiences:
  26019. description: |-
  26020. Optional audiences field that will be used to request a temporary Kubernetes service
  26021. account token for the service account referenced by `serviceAccountRef`.
  26022. Defaults to a single audience `vault` it not specified.
  26023. Deprecated: use serviceAccountRef.Audiences instead
  26024. items:
  26025. type: string
  26026. type: array
  26027. expirationSeconds:
  26028. description: |-
  26029. Optional expiration time in seconds that will be used to request a temporary
  26030. Kubernetes service account token for the service account referenced by
  26031. `serviceAccountRef`.
  26032. Deprecated: this will be removed in the future.
  26033. Defaults to 10 minutes.
  26034. format: int64
  26035. type: integer
  26036. serviceAccountRef:
  26037. description: Service account field containing the name of a kubernetes ServiceAccount.
  26038. properties:
  26039. audiences:
  26040. description: |-
  26041. Audience specifies the `aud` claim for the service account token
  26042. Some providers automatically extend the audience field based on well-known annotations for workload
  26043. identity (e.g. IRSA or GCP Workload Identity)
  26044. items:
  26045. type: string
  26046. type: array
  26047. name:
  26048. description: The name of the ServiceAccount resource being referred to.
  26049. maxLength: 253
  26050. minLength: 1
  26051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26052. type: string
  26053. namespace:
  26054. description: |-
  26055. Namespace of the resource being referred to.
  26056. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26057. maxLength: 63
  26058. minLength: 1
  26059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26060. type: string
  26061. required:
  26062. - name
  26063. type: object
  26064. required:
  26065. - serviceAccountRef
  26066. type: object
  26067. path:
  26068. default: jwt
  26069. description: |-
  26070. Path where the JWT authentication backend is mounted
  26071. in Vault, e.g: "jwt"
  26072. type: string
  26073. role:
  26074. description: |-
  26075. Role is a JWT role to authenticate using the JWT/OIDC Vault
  26076. authentication method
  26077. type: string
  26078. secretRef:
  26079. description: |-
  26080. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  26081. authenticate with Vault using the JWT/OIDC authentication method.
  26082. properties:
  26083. key:
  26084. description: |-
  26085. A key in the referenced Secret.
  26086. Some instances of this field may be defaulted, in others it may be required.
  26087. maxLength: 253
  26088. minLength: 1
  26089. pattern: ^[-._a-zA-Z0-9]+$
  26090. type: string
  26091. name:
  26092. description: The name of the Secret resource being referred to.
  26093. maxLength: 253
  26094. minLength: 1
  26095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26096. type: string
  26097. namespace:
  26098. description: |-
  26099. The namespace of the Secret resource being referred to.
  26100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26101. maxLength: 63
  26102. minLength: 1
  26103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26104. type: string
  26105. type: object
  26106. required:
  26107. - path
  26108. type: object
  26109. kubernetes:
  26110. description: |-
  26111. Kubernetes authenticates with Vault by passing the ServiceAccount
  26112. token stored in the named Secret resource to the Vault server.
  26113. properties:
  26114. mountPath:
  26115. default: kubernetes
  26116. description: |-
  26117. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  26118. "kubernetes"
  26119. type: string
  26120. role:
  26121. description: |-
  26122. A required field containing the Vault Role to assume. A Role binds a
  26123. Kubernetes ServiceAccount with a set of Vault policies.
  26124. type: string
  26125. secretRef:
  26126. description: |-
  26127. Optional secret field containing a Kubernetes ServiceAccount JWT used
  26128. for authenticating with Vault. If a name is specified without a key,
  26129. `token` is the default. If one is not specified, the one bound to
  26130. the controller will be used.
  26131. properties:
  26132. key:
  26133. description: |-
  26134. A key in the referenced Secret.
  26135. Some instances of this field may be defaulted, in others it may be required.
  26136. maxLength: 253
  26137. minLength: 1
  26138. pattern: ^[-._a-zA-Z0-9]+$
  26139. type: string
  26140. name:
  26141. description: The name of the Secret resource being referred to.
  26142. maxLength: 253
  26143. minLength: 1
  26144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26145. type: string
  26146. namespace:
  26147. description: |-
  26148. The namespace of the Secret resource being referred to.
  26149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26150. maxLength: 63
  26151. minLength: 1
  26152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26153. type: string
  26154. type: object
  26155. serviceAccountRef:
  26156. description: |-
  26157. Optional service account field containing the name of a kubernetes ServiceAccount.
  26158. If the service account is specified, the service account secret token JWT will be used
  26159. for authenticating with Vault. If the service account selector is not supplied,
  26160. the secretRef will be used instead.
  26161. properties:
  26162. audiences:
  26163. description: |-
  26164. Audience specifies the `aud` claim for the service account token
  26165. Some providers automatically extend the audience field based on well-known annotations for workload
  26166. identity (e.g. IRSA or GCP Workload Identity)
  26167. items:
  26168. type: string
  26169. type: array
  26170. name:
  26171. description: The name of the ServiceAccount resource being referred to.
  26172. maxLength: 253
  26173. minLength: 1
  26174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26175. type: string
  26176. namespace:
  26177. description: |-
  26178. Namespace of the resource being referred to.
  26179. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26180. maxLength: 63
  26181. minLength: 1
  26182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26183. type: string
  26184. required:
  26185. - name
  26186. type: object
  26187. required:
  26188. - mountPath
  26189. - role
  26190. type: object
  26191. ldap:
  26192. description: |-
  26193. Ldap authenticates with Vault by passing username/password pair using
  26194. the LDAP authentication method
  26195. properties:
  26196. path:
  26197. default: ldap
  26198. description: |-
  26199. Path where the LDAP authentication backend is mounted
  26200. in Vault, e.g: "ldap"
  26201. type: string
  26202. secretRef:
  26203. description: |-
  26204. SecretRef to a key in a Secret resource containing password for the LDAP
  26205. user used to authenticate with Vault using the LDAP authentication
  26206. method
  26207. properties:
  26208. key:
  26209. description: |-
  26210. A key in the referenced Secret.
  26211. Some instances of this field may be defaulted, in others it may be required.
  26212. maxLength: 253
  26213. minLength: 1
  26214. pattern: ^[-._a-zA-Z0-9]+$
  26215. type: string
  26216. name:
  26217. description: The name of the Secret resource being referred to.
  26218. maxLength: 253
  26219. minLength: 1
  26220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26221. type: string
  26222. namespace:
  26223. description: |-
  26224. The namespace of the Secret resource being referred to.
  26225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26226. maxLength: 63
  26227. minLength: 1
  26228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26229. type: string
  26230. type: object
  26231. username:
  26232. description: |-
  26233. Username is an LDAP username used to authenticate using the LDAP Vault
  26234. authentication method
  26235. type: string
  26236. required:
  26237. - path
  26238. - username
  26239. type: object
  26240. namespace:
  26241. description: |-
  26242. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26243. Namespaces is a set of features within Vault Enterprise that allows
  26244. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26245. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26246. This will default to Vault.Namespace field if set, or empty otherwise
  26247. type: string
  26248. tokenSecretRef:
  26249. description: TokenSecretRef authenticates with Vault by presenting a token.
  26250. properties:
  26251. key:
  26252. description: |-
  26253. A key in the referenced Secret.
  26254. Some instances of this field may be defaulted, in others it may be required.
  26255. maxLength: 253
  26256. minLength: 1
  26257. pattern: ^[-._a-zA-Z0-9]+$
  26258. type: string
  26259. name:
  26260. description: The name of the Secret resource being referred to.
  26261. maxLength: 253
  26262. minLength: 1
  26263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26264. type: string
  26265. namespace:
  26266. description: |-
  26267. The namespace of the Secret resource being referred to.
  26268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26269. maxLength: 63
  26270. minLength: 1
  26271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26272. type: string
  26273. type: object
  26274. userPass:
  26275. description: UserPass authenticates with Vault by passing username/password pair
  26276. properties:
  26277. path:
  26278. default: userpass
  26279. description: |-
  26280. Path where the UserPassword authentication backend is mounted
  26281. in Vault, e.g: "userpass"
  26282. type: string
  26283. secretRef:
  26284. description: |-
  26285. SecretRef to a key in a Secret resource containing password for the
  26286. user used to authenticate with Vault using the UserPass authentication
  26287. method
  26288. properties:
  26289. key:
  26290. description: |-
  26291. A key in the referenced Secret.
  26292. Some instances of this field may be defaulted, in others it may be required.
  26293. maxLength: 253
  26294. minLength: 1
  26295. pattern: ^[-._a-zA-Z0-9]+$
  26296. type: string
  26297. name:
  26298. description: The name of the Secret resource being referred to.
  26299. maxLength: 253
  26300. minLength: 1
  26301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26302. type: string
  26303. namespace:
  26304. description: |-
  26305. The namespace of the Secret resource being referred to.
  26306. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26307. maxLength: 63
  26308. minLength: 1
  26309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26310. type: string
  26311. type: object
  26312. username:
  26313. description: |-
  26314. Username is a username used to authenticate using the UserPass Vault
  26315. authentication method
  26316. type: string
  26317. required:
  26318. - path
  26319. - username
  26320. type: object
  26321. type: object
  26322. caBundle:
  26323. description: |-
  26324. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26325. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26326. plain HTTP protocol connection. If not set the system root certificates
  26327. are used to validate the TLS connection.
  26328. format: byte
  26329. type: string
  26330. caProvider:
  26331. description: The provider for the CA bundle to use to validate Vault server certificate.
  26332. properties:
  26333. key:
  26334. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26335. maxLength: 253
  26336. minLength: 1
  26337. pattern: ^[-._a-zA-Z0-9]+$
  26338. type: string
  26339. name:
  26340. description: The name of the object located at the provider type.
  26341. maxLength: 253
  26342. minLength: 1
  26343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26344. type: string
  26345. namespace:
  26346. description: |-
  26347. The namespace the Provider type is in.
  26348. Can only be defined when used in a ClusterSecretStore.
  26349. maxLength: 63
  26350. minLength: 1
  26351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26352. type: string
  26353. type:
  26354. description: The type of provider to use such as "Secret", or "ConfigMap".
  26355. enum:
  26356. - Secret
  26357. - ConfigMap
  26358. type: string
  26359. required:
  26360. - name
  26361. - type
  26362. type: object
  26363. forwardInconsistent:
  26364. description: |-
  26365. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26366. leader instead of simply retrying within a loop. This can increase performance if
  26367. the option is enabled serverside.
  26368. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26369. type: boolean
  26370. headers:
  26371. additionalProperties:
  26372. type: string
  26373. description: Headers to be added in Vault request
  26374. type: object
  26375. namespace:
  26376. description: |-
  26377. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26378. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26379. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26380. type: string
  26381. path:
  26382. description: |-
  26383. Path is the mount path of the Vault KV backend endpoint, e.g:
  26384. "secret". The v2 KV secret engine version specific "/data" path suffix
  26385. for fetching secrets from Vault is optional and will be appended
  26386. if not present in specified path.
  26387. type: string
  26388. readYourWrites:
  26389. description: |-
  26390. ReadYourWrites ensures isolated read-after-write semantics by
  26391. providing discovered cluster replication states in each request.
  26392. More information about eventual consistency in Vault can be found here
  26393. https://www.vaultproject.io/docs/enterprise/consistency
  26394. type: boolean
  26395. server:
  26396. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26397. type: string
  26398. tls:
  26399. description: |-
  26400. The configuration used for client side related TLS communication, when the Vault server
  26401. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26402. This parameter is ignored for plain HTTP protocol connection.
  26403. It's worth noting this configuration is different from the "TLS certificates auth method",
  26404. which is available under the `auth.cert` section.
  26405. properties:
  26406. certSecretRef:
  26407. description: |-
  26408. CertSecretRef is a certificate added to the transport layer
  26409. when communicating with the Vault server.
  26410. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26411. properties:
  26412. key:
  26413. description: |-
  26414. A key in the referenced Secret.
  26415. Some instances of this field may be defaulted, in others it may be required.
  26416. maxLength: 253
  26417. minLength: 1
  26418. pattern: ^[-._a-zA-Z0-9]+$
  26419. type: string
  26420. name:
  26421. description: The name of the Secret resource being referred to.
  26422. maxLength: 253
  26423. minLength: 1
  26424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26425. type: string
  26426. namespace:
  26427. description: |-
  26428. The namespace of the Secret resource being referred to.
  26429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26430. maxLength: 63
  26431. minLength: 1
  26432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26433. type: string
  26434. type: object
  26435. keySecretRef:
  26436. description: |-
  26437. KeySecretRef to a key in a Secret resource containing client private key
  26438. added to the transport layer when communicating with the Vault server.
  26439. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26440. properties:
  26441. key:
  26442. description: |-
  26443. A key in the referenced Secret.
  26444. Some instances of this field may be defaulted, in others it may be required.
  26445. maxLength: 253
  26446. minLength: 1
  26447. pattern: ^[-._a-zA-Z0-9]+$
  26448. type: string
  26449. name:
  26450. description: The name of the Secret resource being referred to.
  26451. maxLength: 253
  26452. minLength: 1
  26453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26454. type: string
  26455. namespace:
  26456. description: |-
  26457. The namespace of the Secret resource being referred to.
  26458. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26459. maxLength: 63
  26460. minLength: 1
  26461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26462. type: string
  26463. type: object
  26464. type: object
  26465. version:
  26466. default: v2
  26467. description: |-
  26468. Version is the Vault KV secret engine version. This can be either "v1" or
  26469. "v2". Version defaults to "v2".
  26470. enum:
  26471. - v1
  26472. - v2
  26473. type: string
  26474. required:
  26475. - server
  26476. type: object
  26477. webhook:
  26478. description: Webhook configures this store to sync secrets using a generic templated webhook
  26479. properties:
  26480. auth:
  26481. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26482. maxProperties: 1
  26483. minProperties: 1
  26484. properties:
  26485. ntlm:
  26486. description: NTLMProtocol configures the store to use NTLM for auth
  26487. properties:
  26488. passwordSecret:
  26489. description: |-
  26490. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26491. In some instances, `key` is a required field.
  26492. properties:
  26493. key:
  26494. description: |-
  26495. A key in the referenced Secret.
  26496. Some instances of this field may be defaulted, in others it may be required.
  26497. maxLength: 253
  26498. minLength: 1
  26499. pattern: ^[-._a-zA-Z0-9]+$
  26500. type: string
  26501. name:
  26502. description: The name of the Secret resource being referred to.
  26503. maxLength: 253
  26504. minLength: 1
  26505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26506. type: string
  26507. namespace:
  26508. description: |-
  26509. The namespace of the Secret resource being referred to.
  26510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26511. maxLength: 63
  26512. minLength: 1
  26513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26514. type: string
  26515. type: object
  26516. usernameSecret:
  26517. description: |-
  26518. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26519. In some instances, `key` is a required field.
  26520. properties:
  26521. key:
  26522. description: |-
  26523. A key in the referenced Secret.
  26524. Some instances of this field may be defaulted, in others it may be required.
  26525. maxLength: 253
  26526. minLength: 1
  26527. pattern: ^[-._a-zA-Z0-9]+$
  26528. type: string
  26529. name:
  26530. description: The name of the Secret resource being referred to.
  26531. maxLength: 253
  26532. minLength: 1
  26533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26534. type: string
  26535. namespace:
  26536. description: |-
  26537. The namespace of the Secret resource being referred to.
  26538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26539. maxLength: 63
  26540. minLength: 1
  26541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26542. type: string
  26543. type: object
  26544. required:
  26545. - passwordSecret
  26546. - usernameSecret
  26547. type: object
  26548. type: object
  26549. body:
  26550. description: Body
  26551. type: string
  26552. caBundle:
  26553. description: |-
  26554. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26555. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26556. plain HTTP protocol connection. If not set the system root certificates
  26557. are used to validate the TLS connection.
  26558. format: byte
  26559. type: string
  26560. caProvider:
  26561. description: The provider for the CA bundle to use to validate webhook server certificate.
  26562. properties:
  26563. key:
  26564. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26565. maxLength: 253
  26566. minLength: 1
  26567. pattern: ^[-._a-zA-Z0-9]+$
  26568. type: string
  26569. name:
  26570. description: The name of the object located at the provider type.
  26571. maxLength: 253
  26572. minLength: 1
  26573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26574. type: string
  26575. namespace:
  26576. description: The namespace the Provider type is in.
  26577. maxLength: 63
  26578. minLength: 1
  26579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26580. type: string
  26581. type:
  26582. description: The type of provider to use such as "Secret", or "ConfigMap".
  26583. enum:
  26584. - Secret
  26585. - ConfigMap
  26586. type: string
  26587. required:
  26588. - name
  26589. - type
  26590. type: object
  26591. headers:
  26592. additionalProperties:
  26593. type: string
  26594. description: Headers
  26595. type: object
  26596. method:
  26597. description: Webhook Method
  26598. type: string
  26599. result:
  26600. description: Result formatting
  26601. properties:
  26602. jsonPath:
  26603. description: Json path of return value
  26604. type: string
  26605. type: object
  26606. secrets:
  26607. description: |-
  26608. Secrets to fill in templates
  26609. These secrets will be passed to the templating function as key value pairs under the given name
  26610. items:
  26611. description: WebhookSecret defines a secret to be used in webhook templates.
  26612. properties:
  26613. name:
  26614. description: Name of this secret in templates
  26615. type: string
  26616. secretRef:
  26617. description: Secret ref to fill in credentials
  26618. properties:
  26619. key:
  26620. description: |-
  26621. A key in the referenced Secret.
  26622. Some instances of this field may be defaulted, in others it may be required.
  26623. maxLength: 253
  26624. minLength: 1
  26625. pattern: ^[-._a-zA-Z0-9]+$
  26626. type: string
  26627. name:
  26628. description: The name of the Secret resource being referred to.
  26629. maxLength: 253
  26630. minLength: 1
  26631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26632. type: string
  26633. namespace:
  26634. description: |-
  26635. The namespace of the Secret resource being referred to.
  26636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26637. maxLength: 63
  26638. minLength: 1
  26639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26640. type: string
  26641. type: object
  26642. required:
  26643. - name
  26644. - secretRef
  26645. type: object
  26646. type: array
  26647. timeout:
  26648. description: Timeout
  26649. type: string
  26650. url:
  26651. description: Webhook url to call
  26652. type: string
  26653. required:
  26654. - result
  26655. - url
  26656. type: object
  26657. yandexcertificatemanager:
  26658. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26659. properties:
  26660. apiEndpoint:
  26661. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26662. type: string
  26663. auth:
  26664. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26665. properties:
  26666. authorizedKeySecretRef:
  26667. description: The authorized key used for authentication
  26668. properties:
  26669. key:
  26670. description: |-
  26671. A key in the referenced Secret.
  26672. Some instances of this field may be defaulted, in others it may be required.
  26673. maxLength: 253
  26674. minLength: 1
  26675. pattern: ^[-._a-zA-Z0-9]+$
  26676. type: string
  26677. name:
  26678. description: The name of the Secret resource being referred to.
  26679. maxLength: 253
  26680. minLength: 1
  26681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26682. type: string
  26683. namespace:
  26684. description: |-
  26685. The namespace of the Secret resource being referred to.
  26686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26687. maxLength: 63
  26688. minLength: 1
  26689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26690. type: string
  26691. type: object
  26692. type: object
  26693. caProvider:
  26694. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26695. properties:
  26696. certSecretRef:
  26697. description: |-
  26698. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26699. In some instances, `key` is a required field.
  26700. properties:
  26701. key:
  26702. description: |-
  26703. A key in the referenced Secret.
  26704. Some instances of this field may be defaulted, in others it may be required.
  26705. maxLength: 253
  26706. minLength: 1
  26707. pattern: ^[-._a-zA-Z0-9]+$
  26708. type: string
  26709. name:
  26710. description: The name of the Secret resource being referred to.
  26711. maxLength: 253
  26712. minLength: 1
  26713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26714. type: string
  26715. namespace:
  26716. description: |-
  26717. The namespace of the Secret resource being referred to.
  26718. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26719. maxLength: 63
  26720. minLength: 1
  26721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26722. type: string
  26723. type: object
  26724. type: object
  26725. required:
  26726. - auth
  26727. type: object
  26728. yandexlockbox:
  26729. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26730. properties:
  26731. apiEndpoint:
  26732. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26733. type: string
  26734. auth:
  26735. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26736. properties:
  26737. authorizedKeySecretRef:
  26738. description: The authorized key used for authentication
  26739. properties:
  26740. key:
  26741. description: |-
  26742. A key in the referenced Secret.
  26743. Some instances of this field may be defaulted, in others it may be required.
  26744. maxLength: 253
  26745. minLength: 1
  26746. pattern: ^[-._a-zA-Z0-9]+$
  26747. type: string
  26748. name:
  26749. description: The name of the Secret resource being referred to.
  26750. maxLength: 253
  26751. minLength: 1
  26752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26753. type: string
  26754. namespace:
  26755. description: |-
  26756. The namespace of the Secret resource being referred to.
  26757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26758. maxLength: 63
  26759. minLength: 1
  26760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26761. type: string
  26762. type: object
  26763. type: object
  26764. caProvider:
  26765. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26766. properties:
  26767. certSecretRef:
  26768. description: |-
  26769. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26770. In some instances, `key` is a required field.
  26771. properties:
  26772. key:
  26773. description: |-
  26774. A key in the referenced Secret.
  26775. Some instances of this field may be defaulted, in others it may be required.
  26776. maxLength: 253
  26777. minLength: 1
  26778. pattern: ^[-._a-zA-Z0-9]+$
  26779. type: string
  26780. name:
  26781. description: The name of the Secret resource being referred to.
  26782. maxLength: 253
  26783. minLength: 1
  26784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26785. type: string
  26786. namespace:
  26787. description: |-
  26788. The namespace of the Secret resource being referred to.
  26789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26790. maxLength: 63
  26791. minLength: 1
  26792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26793. type: string
  26794. type: object
  26795. type: object
  26796. required:
  26797. - auth
  26798. type: object
  26799. type: object
  26800. refreshInterval:
  26801. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26802. type: integer
  26803. retrySettings:
  26804. description: Used to configure HTTP retries on failures.
  26805. properties:
  26806. maxRetries:
  26807. description: MaxRetries is the maximum number of retry attempts.
  26808. format: int32
  26809. type: integer
  26810. retryInterval:
  26811. description: RetryInterval is the interval between retry attempts.
  26812. type: string
  26813. type: object
  26814. required:
  26815. - provider
  26816. type: object
  26817. status:
  26818. description: SecretStoreStatus defines the observed state of the SecretStore.
  26819. properties:
  26820. capabilities:
  26821. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26822. type: string
  26823. conditions:
  26824. items:
  26825. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26826. properties:
  26827. lastTransitionTime:
  26828. format: date-time
  26829. type: string
  26830. message:
  26831. type: string
  26832. reason:
  26833. type: string
  26834. status:
  26835. type: string
  26836. type:
  26837. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26838. type: string
  26839. required:
  26840. - status
  26841. - type
  26842. type: object
  26843. type: array
  26844. type: object
  26845. type: object
  26846. served: false
  26847. storage: false
  26848. subresources:
  26849. status: {}
  26850. ---
  26851. apiVersion: apiextensions.k8s.io/v1
  26852. kind: CustomResourceDefinition
  26853. metadata:
  26854. annotations:
  26855. controller-gen.kubebuilder.io/version: v0.19.0
  26856. labels:
  26857. external-secrets.io/component: controller
  26858. name: acraccesstokens.generators.external-secrets.io
  26859. spec:
  26860. group: generators.external-secrets.io
  26861. names:
  26862. categories:
  26863. - external-secrets
  26864. - external-secrets-generators
  26865. kind: ACRAccessToken
  26866. listKind: ACRAccessTokenList
  26867. plural: acraccesstokens
  26868. singular: acraccesstoken
  26869. scope: Namespaced
  26870. versions:
  26871. - name: v1alpha1
  26872. schema:
  26873. openAPIV3Schema:
  26874. description: |-
  26875. ACRAccessToken returns an Azure Container Registry token
  26876. that can be used for pushing/pulling images.
  26877. Note: by default it will return an ACR Refresh Token with full access
  26878. (depending on the identity).
  26879. This can be scoped down to the repository level using .spec.scope.
  26880. In case scope is defined it will return an ACR Access Token.
  26881. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26882. properties:
  26883. apiVersion:
  26884. description: |-
  26885. APIVersion defines the versioned schema of this representation of an object.
  26886. Servers should convert recognized schemas to the latest internal value, and
  26887. may reject unrecognized values.
  26888. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26889. type: string
  26890. kind:
  26891. description: |-
  26892. Kind is a string value representing the REST resource this object represents.
  26893. Servers may infer this from the endpoint the client submits requests to.
  26894. Cannot be updated.
  26895. In CamelCase.
  26896. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26897. type: string
  26898. metadata:
  26899. type: object
  26900. spec:
  26901. description: |-
  26902. ACRAccessTokenSpec defines how to generate the access token
  26903. e.g. how to authenticate and which registry to use.
  26904. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26905. properties:
  26906. auth:
  26907. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26908. properties:
  26909. managedIdentity:
  26910. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26911. properties:
  26912. identityId:
  26913. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26914. type: string
  26915. type: object
  26916. servicePrincipal:
  26917. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26918. properties:
  26919. secretRef:
  26920. description: |-
  26921. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26922. It uses static credentials stored in a Kind=Secret.
  26923. properties:
  26924. clientId:
  26925. description: The Azure clientId of the service principle used for authentication.
  26926. properties:
  26927. key:
  26928. description: |-
  26929. A key in the referenced Secret.
  26930. Some instances of this field may be defaulted, in others it may be required.
  26931. maxLength: 253
  26932. minLength: 1
  26933. pattern: ^[-._a-zA-Z0-9]+$
  26934. type: string
  26935. name:
  26936. description: The name of the Secret resource being referred to.
  26937. maxLength: 253
  26938. minLength: 1
  26939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26940. type: string
  26941. namespace:
  26942. description: |-
  26943. The namespace of the Secret resource being referred to.
  26944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26945. maxLength: 63
  26946. minLength: 1
  26947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26948. type: string
  26949. type: object
  26950. clientSecret:
  26951. description: The Azure ClientSecret of the service principle used for authentication.
  26952. properties:
  26953. key:
  26954. description: |-
  26955. A key in the referenced Secret.
  26956. Some instances of this field may be defaulted, in others it may be required.
  26957. maxLength: 253
  26958. minLength: 1
  26959. pattern: ^[-._a-zA-Z0-9]+$
  26960. type: string
  26961. name:
  26962. description: The name of the Secret resource being referred to.
  26963. maxLength: 253
  26964. minLength: 1
  26965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26966. type: string
  26967. namespace:
  26968. description: |-
  26969. The namespace of the Secret resource being referred to.
  26970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26971. maxLength: 63
  26972. minLength: 1
  26973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26974. type: string
  26975. type: object
  26976. type: object
  26977. required:
  26978. - secretRef
  26979. type: object
  26980. workloadIdentity:
  26981. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26982. properties:
  26983. serviceAccountRef:
  26984. description: |-
  26985. ServiceAccountRef specified the service account
  26986. that should be used when authenticating with WorkloadIdentity.
  26987. properties:
  26988. audiences:
  26989. description: |-
  26990. Audience specifies the `aud` claim for the service account token
  26991. Some providers automatically extend the audience field based on well-known annotations for workload
  26992. identity (e.g. IRSA or GCP Workload Identity)
  26993. items:
  26994. type: string
  26995. type: array
  26996. name:
  26997. description: The name of the ServiceAccount resource being referred to.
  26998. maxLength: 253
  26999. minLength: 1
  27000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27001. type: string
  27002. namespace:
  27003. description: |-
  27004. Namespace of the resource being referred to.
  27005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27006. maxLength: 63
  27007. minLength: 1
  27008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27009. type: string
  27010. required:
  27011. - name
  27012. type: object
  27013. type: object
  27014. type: object
  27015. environmentType:
  27016. default: PublicCloud
  27017. description: |-
  27018. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27019. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27020. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27021. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27022. enum:
  27023. - PublicCloud
  27024. - USGovernmentCloud
  27025. - ChinaCloud
  27026. - GermanCloud
  27027. - AzureStackCloud
  27028. type: string
  27029. registry:
  27030. description: |-
  27031. the domain name of the ACR registry
  27032. e.g. foobarexample.azurecr.io
  27033. type: string
  27034. scope:
  27035. description: |-
  27036. Define the scope for the access token, e.g. pull/push access for a repository.
  27037. if not provided it will return a refresh token that has full scope.
  27038. Note: you need to pin it down to the repository level, there is no wildcard available.
  27039. examples:
  27040. repository:my-repository:pull,push
  27041. repository:my-repository:pull
  27042. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27043. type: string
  27044. tenantId:
  27045. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27046. type: string
  27047. required:
  27048. - auth
  27049. - registry
  27050. type: object
  27051. type: object
  27052. served: true
  27053. storage: true
  27054. subresources:
  27055. status: {}
  27056. ---
  27057. apiVersion: apiextensions.k8s.io/v1
  27058. kind: CustomResourceDefinition
  27059. metadata:
  27060. annotations:
  27061. controller-gen.kubebuilder.io/version: v0.19.0
  27062. labels:
  27063. external-secrets.io/component: controller
  27064. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  27065. spec:
  27066. group: generators.external-secrets.io
  27067. names:
  27068. categories:
  27069. - external-secrets
  27070. - external-secrets-generators
  27071. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  27072. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  27073. plural: beyondtrustworkloadcredentialsdynamicsecrets
  27074. singular: beyondtrustworkloadcredentialsdynamicsecret
  27075. scope: Namespaced
  27076. versions:
  27077. - name: v1alpha1
  27078. schema:
  27079. openAPIV3Schema:
  27080. description: |-
  27081. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  27082. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  27083. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  27084. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  27085. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27086. properties:
  27087. apiVersion:
  27088. description: |-
  27089. APIVersion defines the versioned schema of this representation of an object.
  27090. Servers should convert recognized schemas to the latest internal value, and
  27091. may reject unrecognized values.
  27092. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27093. type: string
  27094. kind:
  27095. description: |-
  27096. Kind is a string value representing the REST resource this object represents.
  27097. Servers may infer this from the endpoint the client submits requests to.
  27098. Cannot be updated.
  27099. In CamelCase.
  27100. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27101. type: string
  27102. metadata:
  27103. type: object
  27104. spec:
  27105. description: |-
  27106. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27107. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27108. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27109. properties:
  27110. controller:
  27111. description: |-
  27112. Controller selects the controller that should handle this generator.
  27113. Leave empty to use the default controller.
  27114. type: string
  27115. provider:
  27116. description: |-
  27117. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27118. server connection details, and the folder path to the dynamic secret definition.
  27119. The folderPath should point to a dynamic secret definition that has been created in
  27120. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27121. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27122. properties:
  27123. auth:
  27124. description: |-
  27125. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27126. Currently supports API key authentication via Kubernetes secret reference.
  27127. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27128. properties:
  27129. apikey:
  27130. description: |-
  27131. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27132. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27133. properties:
  27134. token:
  27135. description: |-
  27136. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27137. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27138. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27139. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27140. properties:
  27141. key:
  27142. description: |-
  27143. A key in the referenced Secret.
  27144. Some instances of this field may be defaulted, in others it may be required.
  27145. maxLength: 253
  27146. minLength: 1
  27147. pattern: ^[-._a-zA-Z0-9]+$
  27148. type: string
  27149. name:
  27150. description: The name of the Secret resource being referred to.
  27151. maxLength: 253
  27152. minLength: 1
  27153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27154. type: string
  27155. namespace:
  27156. description: |-
  27157. The namespace of the Secret resource being referred to.
  27158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27159. maxLength: 63
  27160. minLength: 1
  27161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27162. type: string
  27163. type: object
  27164. required:
  27165. - token
  27166. type: object
  27167. required:
  27168. - apikey
  27169. type: object
  27170. caBundle:
  27171. description: |-
  27172. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27173. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27174. If not set, the system's trusted root certificates are used.
  27175. format: byte
  27176. type: string
  27177. caProvider:
  27178. description: |-
  27179. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27180. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27181. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27182. properties:
  27183. key:
  27184. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27185. maxLength: 253
  27186. minLength: 1
  27187. pattern: ^[-._a-zA-Z0-9]+$
  27188. type: string
  27189. name:
  27190. description: The name of the object located at the provider type.
  27191. maxLength: 253
  27192. minLength: 1
  27193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27194. type: string
  27195. namespace:
  27196. description: |-
  27197. The namespace the Provider type is in.
  27198. Can only be defined when used in a ClusterSecretStore.
  27199. maxLength: 63
  27200. minLength: 1
  27201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27202. type: string
  27203. type:
  27204. description: The type of provider to use such as "Secret", or "ConfigMap".
  27205. enum:
  27206. - Secret
  27207. - ConfigMap
  27208. type: string
  27209. required:
  27210. - name
  27211. - type
  27212. type: object
  27213. folderPath:
  27214. description: |-
  27215. FolderPath specifies the default folder path for secret retrieval.
  27216. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27217. Example: "production/database" or "dev/api-keys"
  27218. Leave empty to retrieve secrets from the root folder.
  27219. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27220. type: string
  27221. server:
  27222. description: |-
  27223. Server configures the BeyondTrust Workload Credentials server connection details.
  27224. Includes the API URL and Site ID for your BeyondTrust instance.
  27225. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27226. properties:
  27227. apiUrl:
  27228. description: |-
  27229. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27230. This should be the full URL to your BeyondTrust instance.
  27231. Example: https://api.beyondtrust.io/siie
  27232. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27233. type: string
  27234. siteId:
  27235. description: |-
  27236. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27237. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27238. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27239. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27240. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27241. type: string
  27242. required:
  27243. - apiUrl
  27244. - siteId
  27245. type: object
  27246. required:
  27247. - auth
  27248. - server
  27249. type: object
  27250. retrySettings:
  27251. description: |-
  27252. RetrySettings configures exponential backoff for failed API requests.
  27253. If not specified, uses the default retry settings.
  27254. properties:
  27255. maxRetries:
  27256. format: int32
  27257. type: integer
  27258. retryInterval:
  27259. type: string
  27260. type: object
  27261. required:
  27262. - provider
  27263. type: object
  27264. type: object
  27265. served: true
  27266. storage: true
  27267. subresources:
  27268. status: {}
  27269. ---
  27270. apiVersion: apiextensions.k8s.io/v1
  27271. kind: CustomResourceDefinition
  27272. metadata:
  27273. annotations:
  27274. controller-gen.kubebuilder.io/version: v0.19.0
  27275. labels:
  27276. external-secrets.io/component: controller
  27277. name: cloudsmithaccesstokens.generators.external-secrets.io
  27278. spec:
  27279. group: generators.external-secrets.io
  27280. names:
  27281. categories:
  27282. - external-secrets
  27283. - external-secrets-generators
  27284. kind: CloudsmithAccessToken
  27285. listKind: CloudsmithAccessTokenList
  27286. plural: cloudsmithaccesstokens
  27287. singular: cloudsmithaccesstoken
  27288. scope: Namespaced
  27289. versions:
  27290. - name: v1alpha1
  27291. schema:
  27292. openAPIV3Schema:
  27293. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27294. properties:
  27295. apiVersion:
  27296. description: |-
  27297. APIVersion defines the versioned schema of this representation of an object.
  27298. Servers should convert recognized schemas to the latest internal value, and
  27299. may reject unrecognized values.
  27300. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27301. type: string
  27302. kind:
  27303. description: |-
  27304. Kind is a string value representing the REST resource this object represents.
  27305. Servers may infer this from the endpoint the client submits requests to.
  27306. Cannot be updated.
  27307. In CamelCase.
  27308. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27309. type: string
  27310. metadata:
  27311. type: object
  27312. spec:
  27313. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27314. properties:
  27315. apiUrl:
  27316. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27317. type: string
  27318. orgSlug:
  27319. description: OrgSlug is the organization slug in Cloudsmith
  27320. type: string
  27321. serviceAccountRef:
  27322. description: Name of the service account you are federating with
  27323. properties:
  27324. audiences:
  27325. description: |-
  27326. Audience specifies the `aud` claim for the service account token
  27327. Some providers automatically extend the audience field based on well-known annotations for workload
  27328. identity (e.g. IRSA or GCP Workload Identity)
  27329. items:
  27330. type: string
  27331. type: array
  27332. name:
  27333. description: The name of the ServiceAccount resource being referred to.
  27334. maxLength: 253
  27335. minLength: 1
  27336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27337. type: string
  27338. namespace:
  27339. description: |-
  27340. Namespace of the resource being referred to.
  27341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27342. maxLength: 63
  27343. minLength: 1
  27344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27345. type: string
  27346. required:
  27347. - name
  27348. type: object
  27349. serviceSlug:
  27350. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27351. type: string
  27352. required:
  27353. - orgSlug
  27354. - serviceAccountRef
  27355. - serviceSlug
  27356. type: object
  27357. type: object
  27358. served: true
  27359. storage: true
  27360. subresources:
  27361. status: {}
  27362. ---
  27363. apiVersion: apiextensions.k8s.io/v1
  27364. kind: CustomResourceDefinition
  27365. metadata:
  27366. annotations:
  27367. controller-gen.kubebuilder.io/version: v0.19.0
  27368. labels:
  27369. external-secrets.io/component: controller
  27370. name: clustergenerators.generators.external-secrets.io
  27371. spec:
  27372. group: generators.external-secrets.io
  27373. names:
  27374. categories:
  27375. - external-secrets
  27376. - external-secrets-generators
  27377. kind: ClusterGenerator
  27378. listKind: ClusterGeneratorList
  27379. plural: clustergenerators
  27380. singular: clustergenerator
  27381. scope: Cluster
  27382. versions:
  27383. - name: v1alpha1
  27384. schema:
  27385. openAPIV3Schema:
  27386. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27387. properties:
  27388. apiVersion:
  27389. description: |-
  27390. APIVersion defines the versioned schema of this representation of an object.
  27391. Servers should convert recognized schemas to the latest internal value, and
  27392. may reject unrecognized values.
  27393. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27394. type: string
  27395. kind:
  27396. description: |-
  27397. Kind is a string value representing the REST resource this object represents.
  27398. Servers may infer this from the endpoint the client submits requests to.
  27399. Cannot be updated.
  27400. In CamelCase.
  27401. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27402. type: string
  27403. metadata:
  27404. type: object
  27405. spec:
  27406. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27407. properties:
  27408. generator:
  27409. description: Generator the spec for this generator, must match the kind.
  27410. maxProperties: 1
  27411. minProperties: 1
  27412. properties:
  27413. acrAccessTokenSpec:
  27414. description: |-
  27415. ACRAccessTokenSpec defines how to generate the access token
  27416. e.g. how to authenticate and which registry to use.
  27417. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27418. properties:
  27419. auth:
  27420. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27421. properties:
  27422. managedIdentity:
  27423. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27424. properties:
  27425. identityId:
  27426. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27427. type: string
  27428. type: object
  27429. servicePrincipal:
  27430. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27431. properties:
  27432. secretRef:
  27433. description: |-
  27434. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27435. It uses static credentials stored in a Kind=Secret.
  27436. properties:
  27437. clientId:
  27438. description: The Azure clientId of the service principle used for authentication.
  27439. properties:
  27440. key:
  27441. description: |-
  27442. A key in the referenced Secret.
  27443. Some instances of this field may be defaulted, in others it may be required.
  27444. maxLength: 253
  27445. minLength: 1
  27446. pattern: ^[-._a-zA-Z0-9]+$
  27447. type: string
  27448. name:
  27449. description: The name of the Secret resource being referred to.
  27450. maxLength: 253
  27451. minLength: 1
  27452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27453. type: string
  27454. namespace:
  27455. description: |-
  27456. The namespace of the Secret resource being referred to.
  27457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27458. maxLength: 63
  27459. minLength: 1
  27460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27461. type: string
  27462. type: object
  27463. clientSecret:
  27464. description: The Azure ClientSecret of the service principle used for authentication.
  27465. properties:
  27466. key:
  27467. description: |-
  27468. A key in the referenced Secret.
  27469. Some instances of this field may be defaulted, in others it may be required.
  27470. maxLength: 253
  27471. minLength: 1
  27472. pattern: ^[-._a-zA-Z0-9]+$
  27473. type: string
  27474. name:
  27475. description: The name of the Secret resource being referred to.
  27476. maxLength: 253
  27477. minLength: 1
  27478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27479. type: string
  27480. namespace:
  27481. description: |-
  27482. The namespace of the Secret resource being referred to.
  27483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27484. maxLength: 63
  27485. minLength: 1
  27486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27487. type: string
  27488. type: object
  27489. type: object
  27490. required:
  27491. - secretRef
  27492. type: object
  27493. workloadIdentity:
  27494. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27495. properties:
  27496. serviceAccountRef:
  27497. description: |-
  27498. ServiceAccountRef specified the service account
  27499. that should be used when authenticating with WorkloadIdentity.
  27500. properties:
  27501. audiences:
  27502. description: |-
  27503. Audience specifies the `aud` claim for the service account token
  27504. Some providers automatically extend the audience field based on well-known annotations for workload
  27505. identity (e.g. IRSA or GCP Workload Identity)
  27506. items:
  27507. type: string
  27508. type: array
  27509. name:
  27510. description: The name of the ServiceAccount resource being referred to.
  27511. maxLength: 253
  27512. minLength: 1
  27513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27514. type: string
  27515. namespace:
  27516. description: |-
  27517. Namespace of the resource being referred to.
  27518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27519. maxLength: 63
  27520. minLength: 1
  27521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27522. type: string
  27523. required:
  27524. - name
  27525. type: object
  27526. type: object
  27527. type: object
  27528. environmentType:
  27529. default: PublicCloud
  27530. description: |-
  27531. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27532. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27533. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27534. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27535. enum:
  27536. - PublicCloud
  27537. - USGovernmentCloud
  27538. - ChinaCloud
  27539. - GermanCloud
  27540. - AzureStackCloud
  27541. type: string
  27542. registry:
  27543. description: |-
  27544. the domain name of the ACR registry
  27545. e.g. foobarexample.azurecr.io
  27546. type: string
  27547. scope:
  27548. description: |-
  27549. Define the scope for the access token, e.g. pull/push access for a repository.
  27550. if not provided it will return a refresh token that has full scope.
  27551. Note: you need to pin it down to the repository level, there is no wildcard available.
  27552. examples:
  27553. repository:my-repository:pull,push
  27554. repository:my-repository:pull
  27555. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27556. type: string
  27557. tenantId:
  27558. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27559. type: string
  27560. required:
  27561. - auth
  27562. - registry
  27563. type: object
  27564. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27565. description: |-
  27566. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27567. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27568. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27569. properties:
  27570. controller:
  27571. description: |-
  27572. Controller selects the controller that should handle this generator.
  27573. Leave empty to use the default controller.
  27574. type: string
  27575. provider:
  27576. description: |-
  27577. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27578. server connection details, and the folder path to the dynamic secret definition.
  27579. The folderPath should point to a dynamic secret definition that has been created in
  27580. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27581. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27582. properties:
  27583. auth:
  27584. description: |-
  27585. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27586. Currently supports API key authentication via Kubernetes secret reference.
  27587. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27588. properties:
  27589. apikey:
  27590. description: |-
  27591. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27592. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27593. properties:
  27594. token:
  27595. description: |-
  27596. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27597. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27598. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27599. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27600. properties:
  27601. key:
  27602. description: |-
  27603. A key in the referenced Secret.
  27604. Some instances of this field may be defaulted, in others it may be required.
  27605. maxLength: 253
  27606. minLength: 1
  27607. pattern: ^[-._a-zA-Z0-9]+$
  27608. type: string
  27609. name:
  27610. description: The name of the Secret resource being referred to.
  27611. maxLength: 253
  27612. minLength: 1
  27613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27614. type: string
  27615. namespace:
  27616. description: |-
  27617. The namespace of the Secret resource being referred to.
  27618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27619. maxLength: 63
  27620. minLength: 1
  27621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27622. type: string
  27623. type: object
  27624. required:
  27625. - token
  27626. type: object
  27627. required:
  27628. - apikey
  27629. type: object
  27630. caBundle:
  27631. description: |-
  27632. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27633. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27634. If not set, the system's trusted root certificates are used.
  27635. format: byte
  27636. type: string
  27637. caProvider:
  27638. description: |-
  27639. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27640. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27641. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27642. properties:
  27643. key:
  27644. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27645. maxLength: 253
  27646. minLength: 1
  27647. pattern: ^[-._a-zA-Z0-9]+$
  27648. type: string
  27649. name:
  27650. description: The name of the object located at the provider type.
  27651. maxLength: 253
  27652. minLength: 1
  27653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27654. type: string
  27655. namespace:
  27656. description: |-
  27657. The namespace the Provider type is in.
  27658. Can only be defined when used in a ClusterSecretStore.
  27659. maxLength: 63
  27660. minLength: 1
  27661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27662. type: string
  27663. type:
  27664. description: The type of provider to use such as "Secret", or "ConfigMap".
  27665. enum:
  27666. - Secret
  27667. - ConfigMap
  27668. type: string
  27669. required:
  27670. - name
  27671. - type
  27672. type: object
  27673. folderPath:
  27674. description: |-
  27675. FolderPath specifies the default folder path for secret retrieval.
  27676. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27677. Example: "production/database" or "dev/api-keys"
  27678. Leave empty to retrieve secrets from the root folder.
  27679. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27680. type: string
  27681. server:
  27682. description: |-
  27683. Server configures the BeyondTrust Workload Credentials server connection details.
  27684. Includes the API URL and Site ID for your BeyondTrust instance.
  27685. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27686. properties:
  27687. apiUrl:
  27688. description: |-
  27689. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27690. This should be the full URL to your BeyondTrust instance.
  27691. Example: https://api.beyondtrust.io/siie
  27692. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27693. type: string
  27694. siteId:
  27695. description: |-
  27696. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27697. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27698. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27699. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27700. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27701. type: string
  27702. required:
  27703. - apiUrl
  27704. - siteId
  27705. type: object
  27706. required:
  27707. - auth
  27708. - server
  27709. type: object
  27710. retrySettings:
  27711. description: |-
  27712. RetrySettings configures exponential backoff for failed API requests.
  27713. If not specified, uses the default retry settings.
  27714. properties:
  27715. maxRetries:
  27716. format: int32
  27717. type: integer
  27718. retryInterval:
  27719. type: string
  27720. type: object
  27721. required:
  27722. - provider
  27723. type: object
  27724. cloudsmithAccessTokenSpec:
  27725. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27726. properties:
  27727. apiUrl:
  27728. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27729. type: string
  27730. orgSlug:
  27731. description: OrgSlug is the organization slug in Cloudsmith
  27732. type: string
  27733. serviceAccountRef:
  27734. description: Name of the service account you are federating with
  27735. properties:
  27736. audiences:
  27737. description: |-
  27738. Audience specifies the `aud` claim for the service account token
  27739. Some providers automatically extend the audience field based on well-known annotations for workload
  27740. identity (e.g. IRSA or GCP Workload Identity)
  27741. items:
  27742. type: string
  27743. type: array
  27744. name:
  27745. description: The name of the ServiceAccount resource being referred to.
  27746. maxLength: 253
  27747. minLength: 1
  27748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27749. type: string
  27750. namespace:
  27751. description: |-
  27752. Namespace of the resource being referred to.
  27753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27754. maxLength: 63
  27755. minLength: 1
  27756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27757. type: string
  27758. required:
  27759. - name
  27760. type: object
  27761. serviceSlug:
  27762. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27763. type: string
  27764. required:
  27765. - orgSlug
  27766. - serviceAccountRef
  27767. - serviceSlug
  27768. type: object
  27769. ecrAuthorizationTokenSpec:
  27770. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27771. properties:
  27772. auth:
  27773. description: Auth defines how to authenticate with AWS
  27774. properties:
  27775. jwt:
  27776. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27777. properties:
  27778. serviceAccountRef:
  27779. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27780. properties:
  27781. audiences:
  27782. description: |-
  27783. Audience specifies the `aud` claim for the service account token
  27784. Some providers automatically extend the audience field based on well-known annotations for workload
  27785. identity (e.g. IRSA or GCP Workload Identity)
  27786. items:
  27787. type: string
  27788. type: array
  27789. name:
  27790. description: The name of the ServiceAccount resource being referred to.
  27791. maxLength: 253
  27792. minLength: 1
  27793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27794. type: string
  27795. namespace:
  27796. description: |-
  27797. Namespace of the resource being referred to.
  27798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27799. maxLength: 63
  27800. minLength: 1
  27801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27802. type: string
  27803. required:
  27804. - name
  27805. type: object
  27806. type: object
  27807. secretRef:
  27808. description: |-
  27809. AWSAuthSecretRef holds secret references for AWS credentials
  27810. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27811. properties:
  27812. accessKeyIDSecretRef:
  27813. description: The AccessKeyID is used for authentication
  27814. properties:
  27815. key:
  27816. description: |-
  27817. A key in the referenced Secret.
  27818. Some instances of this field may be defaulted, in others it may be required.
  27819. maxLength: 253
  27820. minLength: 1
  27821. pattern: ^[-._a-zA-Z0-9]+$
  27822. type: string
  27823. name:
  27824. description: The name of the Secret resource being referred to.
  27825. maxLength: 253
  27826. minLength: 1
  27827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27828. type: string
  27829. namespace:
  27830. description: |-
  27831. The namespace of the Secret resource being referred to.
  27832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27833. maxLength: 63
  27834. minLength: 1
  27835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27836. type: string
  27837. type: object
  27838. secretAccessKeySecretRef:
  27839. description: The SecretAccessKey is used for authentication
  27840. properties:
  27841. key:
  27842. description: |-
  27843. A key in the referenced Secret.
  27844. Some instances of this field may be defaulted, in others it may be required.
  27845. maxLength: 253
  27846. minLength: 1
  27847. pattern: ^[-._a-zA-Z0-9]+$
  27848. type: string
  27849. name:
  27850. description: The name of the Secret resource being referred to.
  27851. maxLength: 253
  27852. minLength: 1
  27853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27854. type: string
  27855. namespace:
  27856. description: |-
  27857. The namespace of the Secret resource being referred to.
  27858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27859. maxLength: 63
  27860. minLength: 1
  27861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27862. type: string
  27863. type: object
  27864. sessionTokenSecretRef:
  27865. description: |-
  27866. The SessionToken used for authentication
  27867. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27868. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27869. properties:
  27870. key:
  27871. description: |-
  27872. A key in the referenced Secret.
  27873. Some instances of this field may be defaulted, in others it may be required.
  27874. maxLength: 253
  27875. minLength: 1
  27876. pattern: ^[-._a-zA-Z0-9]+$
  27877. type: string
  27878. name:
  27879. description: The name of the Secret resource being referred to.
  27880. maxLength: 253
  27881. minLength: 1
  27882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27883. type: string
  27884. namespace:
  27885. description: |-
  27886. The namespace of the Secret resource being referred to.
  27887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27888. maxLength: 63
  27889. minLength: 1
  27890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27891. type: string
  27892. type: object
  27893. type: object
  27894. type: object
  27895. region:
  27896. description: Region specifies the region to operate in.
  27897. type: string
  27898. role:
  27899. description: |-
  27900. You can assume a role before making calls to the
  27901. desired AWS service.
  27902. type: string
  27903. scope:
  27904. description: |-
  27905. Scope specifies the ECR service scope.
  27906. Valid options are private and public.
  27907. type: string
  27908. required:
  27909. - region
  27910. type: object
  27911. fakeSpec:
  27912. description: FakeSpec contains the static data.
  27913. properties:
  27914. controller:
  27915. description: |-
  27916. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27917. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27918. type: string
  27919. data:
  27920. additionalProperties:
  27921. type: string
  27922. description: |-
  27923. Data defines the static data returned
  27924. by this generator.
  27925. type: object
  27926. type: object
  27927. gcrAccessTokenSpec:
  27928. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27929. properties:
  27930. auth:
  27931. description: Auth defines the means for authenticating with GCP
  27932. properties:
  27933. secretRef:
  27934. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27935. properties:
  27936. secretAccessKeySecretRef:
  27937. description: The SecretAccessKey is used for authentication
  27938. properties:
  27939. key:
  27940. description: |-
  27941. A key in the referenced Secret.
  27942. Some instances of this field may be defaulted, in others it may be required.
  27943. maxLength: 253
  27944. minLength: 1
  27945. pattern: ^[-._a-zA-Z0-9]+$
  27946. type: string
  27947. name:
  27948. description: The name of the Secret resource being referred to.
  27949. maxLength: 253
  27950. minLength: 1
  27951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27952. type: string
  27953. namespace:
  27954. description: |-
  27955. The namespace of the Secret resource being referred to.
  27956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27957. maxLength: 63
  27958. minLength: 1
  27959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27960. type: string
  27961. type: object
  27962. type: object
  27963. workloadIdentity:
  27964. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27965. properties:
  27966. clusterLocation:
  27967. type: string
  27968. clusterName:
  27969. type: string
  27970. clusterProjectID:
  27971. type: string
  27972. serviceAccountRef:
  27973. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27974. properties:
  27975. audiences:
  27976. description: |-
  27977. Audience specifies the `aud` claim for the service account token
  27978. Some providers automatically extend the audience field based on well-known annotations for workload
  27979. identity (e.g. IRSA or GCP Workload Identity)
  27980. items:
  27981. type: string
  27982. type: array
  27983. name:
  27984. description: The name of the ServiceAccount resource being referred to.
  27985. maxLength: 253
  27986. minLength: 1
  27987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27988. type: string
  27989. namespace:
  27990. description: |-
  27991. Namespace of the resource being referred to.
  27992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27993. maxLength: 63
  27994. minLength: 1
  27995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27996. type: string
  27997. required:
  27998. - name
  27999. type: object
  28000. required:
  28001. - clusterLocation
  28002. - clusterName
  28003. - serviceAccountRef
  28004. type: object
  28005. workloadIdentityFederation:
  28006. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  28007. properties:
  28008. audience:
  28009. description: |-
  28010. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  28011. If specified, Audience found in the external account credential config will be overridden with the configured value.
  28012. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  28013. type: string
  28014. awsSecurityCredentials:
  28015. description: |-
  28016. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  28017. when using the AWS metadata server is not an option.
  28018. properties:
  28019. awsCredentialsSecretRef:
  28020. description: |-
  28021. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  28022. Secret should be created with below names for keys
  28023. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  28024. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  28025. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  28026. properties:
  28027. name:
  28028. description: name of the secret.
  28029. maxLength: 253
  28030. minLength: 1
  28031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28032. type: string
  28033. namespace:
  28034. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  28035. maxLength: 63
  28036. minLength: 1
  28037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28038. type: string
  28039. required:
  28040. - name
  28041. type: object
  28042. region:
  28043. description: region is for configuring the AWS region to be used.
  28044. example: ap-south-1
  28045. maxLength: 50
  28046. minLength: 1
  28047. pattern: ^[a-z0-9-]+$
  28048. type: string
  28049. required:
  28050. - awsCredentialsSecretRef
  28051. - region
  28052. type: object
  28053. credConfig:
  28054. description: |-
  28055. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  28056. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  28057. serviceAccountRef must be used by providing operators service account details.
  28058. properties:
  28059. key:
  28060. description: key name holding the external account credential config.
  28061. maxLength: 253
  28062. minLength: 1
  28063. pattern: ^[-._a-zA-Z0-9]+$
  28064. type: string
  28065. name:
  28066. description: name of the configmap.
  28067. maxLength: 253
  28068. minLength: 1
  28069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28070. type: string
  28071. namespace:
  28072. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  28073. maxLength: 63
  28074. minLength: 1
  28075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28076. type: string
  28077. required:
  28078. - key
  28079. - name
  28080. type: object
  28081. externalTokenEndpoint:
  28082. description: |-
  28083. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  28084. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  28085. URL is having the expected value.
  28086. type: string
  28087. gcpServiceAccountEmail:
  28088. description: |-
  28089. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  28090. after Workload Identity Federation. Use this to grant access through the service account's
  28091. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  28092. service_account_impersonation_url in the external account JSON from credConfig;
  28093. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  28094. on that ServiceAccount.
  28095. example: my-gsa@my-project.iam.gserviceaccount.com
  28096. minLength: 1
  28097. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  28098. type: string
  28099. serviceAccountRef:
  28100. description: |-
  28101. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  28102. when Kubernetes is configured as provider in workload identity pool.
  28103. properties:
  28104. audiences:
  28105. description: |-
  28106. Audience specifies the `aud` claim for the service account token
  28107. Some providers automatically extend the audience field based on well-known annotations for workload
  28108. identity (e.g. IRSA or GCP Workload Identity)
  28109. items:
  28110. type: string
  28111. type: array
  28112. name:
  28113. description: The name of the ServiceAccount resource being referred to.
  28114. maxLength: 253
  28115. minLength: 1
  28116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28117. type: string
  28118. namespace:
  28119. description: |-
  28120. Namespace of the resource being referred to.
  28121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28122. maxLength: 63
  28123. minLength: 1
  28124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28125. type: string
  28126. required:
  28127. - name
  28128. type: object
  28129. type: object
  28130. type: object
  28131. projectID:
  28132. description: ProjectID defines which project to use to authenticate with
  28133. type: string
  28134. required:
  28135. - auth
  28136. - projectID
  28137. type: object
  28138. githubAccessTokenSpec:
  28139. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  28140. properties:
  28141. appID:
  28142. type: string
  28143. auth:
  28144. description: Auth configures how ESO authenticates with a Github instance.
  28145. properties:
  28146. privateKey:
  28147. description: GithubSecretRef references a secret containing GitHub credentials.
  28148. properties:
  28149. secretRef:
  28150. description: |-
  28151. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28152. In some instances, `key` is a required field.
  28153. properties:
  28154. key:
  28155. description: |-
  28156. A key in the referenced Secret.
  28157. Some instances of this field may be defaulted, in others it may be required.
  28158. maxLength: 253
  28159. minLength: 1
  28160. pattern: ^[-._a-zA-Z0-9]+$
  28161. type: string
  28162. name:
  28163. description: The name of the Secret resource being referred to.
  28164. maxLength: 253
  28165. minLength: 1
  28166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28167. type: string
  28168. namespace:
  28169. description: |-
  28170. The namespace of the Secret resource being referred to.
  28171. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28172. maxLength: 63
  28173. minLength: 1
  28174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28175. type: string
  28176. type: object
  28177. required:
  28178. - secretRef
  28179. type: object
  28180. required:
  28181. - privateKey
  28182. type: object
  28183. installID:
  28184. type: string
  28185. permissions:
  28186. additionalProperties:
  28187. type: string
  28188. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28189. type: object
  28190. repositories:
  28191. description: |-
  28192. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28193. is installed to.
  28194. items:
  28195. type: string
  28196. type: array
  28197. url:
  28198. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28199. type: string
  28200. required:
  28201. - appID
  28202. - auth
  28203. - installID
  28204. type: object
  28205. gitlabDeployTokenSpec:
  28206. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28207. properties:
  28208. auth:
  28209. description: Auth configures how ESO authenticates with the GitLab API.
  28210. properties:
  28211. token:
  28212. description: |-
  28213. Token references a secret containing a GitLab access token (personal, group, or
  28214. project) with the api scope and at least the Maintainer role on the target.
  28215. properties:
  28216. secretRef:
  28217. description: |-
  28218. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28219. In some instances, `key` is a required field.
  28220. properties:
  28221. key:
  28222. description: |-
  28223. A key in the referenced Secret.
  28224. Some instances of this field may be defaulted, in others it may be required.
  28225. maxLength: 253
  28226. minLength: 1
  28227. pattern: ^[-._a-zA-Z0-9]+$
  28228. type: string
  28229. name:
  28230. description: The name of the Secret resource being referred to.
  28231. maxLength: 253
  28232. minLength: 1
  28233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28234. type: string
  28235. namespace:
  28236. description: |-
  28237. The namespace of the Secret resource being referred to.
  28238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28239. maxLength: 63
  28240. minLength: 1
  28241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28242. type: string
  28243. type: object
  28244. required:
  28245. - secretRef
  28246. type: object
  28247. required:
  28248. - token
  28249. type: object
  28250. expiresAt:
  28251. description: |-
  28252. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28253. not expire on the GitLab side and is revoked only when the generator state is
  28254. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28255. format: date-time
  28256. type: string
  28257. groupID:
  28258. description: |-
  28259. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28260. create the deploy token in. The generator URL-escapes paths before calling the
  28261. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28262. minLength: 1
  28263. type: string
  28264. name:
  28265. description: Name of the deploy token.
  28266. minLength: 1
  28267. type: string
  28268. projectID:
  28269. description: |-
  28270. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28271. project to create the deploy token in. The generator URL-escapes paths before
  28272. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28273. minLength: 1
  28274. type: string
  28275. scopes:
  28276. description: Scopes granted to the deploy token. At least one scope is required.
  28277. items:
  28278. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28279. enum:
  28280. - read_repository
  28281. - read_registry
  28282. - write_registry
  28283. - read_package_registry
  28284. - write_package_registry
  28285. - read_virtual_registry
  28286. - write_virtual_registry
  28287. type: string
  28288. minItems: 1
  28289. type: array
  28290. url:
  28291. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28292. type: string
  28293. username:
  28294. description: |-
  28295. Username is an optional username for the deploy token. GitLab defaults it to
  28296. gitlab+deploy-token-{n} when omitted.
  28297. type: string
  28298. required:
  28299. - auth
  28300. - name
  28301. - scopes
  28302. type: object
  28303. x-kubernetes-validations:
  28304. - message: exactly one of projectID or groupID must be set
  28305. rule: has(self.projectID) != has(self.groupID)
  28306. grafanaSpec:
  28307. description: GrafanaSpec controls the behavior of the grafana generator.
  28308. properties:
  28309. auth:
  28310. description: |-
  28311. Auth is the authentication configuration to authenticate
  28312. against the Grafana instance.
  28313. properties:
  28314. basic:
  28315. description: |-
  28316. Basic auth credentials used to authenticate against the Grafana instance.
  28317. Note: you need a token which has elevated permissions to create service accounts.
  28318. See here for the documentation on basic roles offered by Grafana:
  28319. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28320. properties:
  28321. password:
  28322. description: A basic auth password used to authenticate against the Grafana instance.
  28323. properties:
  28324. key:
  28325. description: The key where the token is found.
  28326. maxLength: 253
  28327. minLength: 1
  28328. pattern: ^[-._a-zA-Z0-9]+$
  28329. type: string
  28330. name:
  28331. description: The name of the Secret resource being referred to.
  28332. maxLength: 253
  28333. minLength: 1
  28334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28335. type: string
  28336. type: object
  28337. username:
  28338. description: A basic auth username used to authenticate against the Grafana instance.
  28339. type: string
  28340. required:
  28341. - password
  28342. - username
  28343. type: object
  28344. token:
  28345. description: |-
  28346. A service account token used to authenticate against the Grafana instance.
  28347. Note: you need a token which has elevated permissions to create service accounts.
  28348. See here for the documentation on basic roles offered by Grafana:
  28349. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28350. properties:
  28351. key:
  28352. description: The key where the token is found.
  28353. maxLength: 253
  28354. minLength: 1
  28355. pattern: ^[-._a-zA-Z0-9]+$
  28356. type: string
  28357. name:
  28358. description: The name of the Secret resource being referred to.
  28359. maxLength: 253
  28360. minLength: 1
  28361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28362. type: string
  28363. type: object
  28364. type: object
  28365. serviceAccount:
  28366. description: |-
  28367. ServiceAccount is the configuration for the service account that
  28368. is supposed to be generated by the generator.
  28369. properties:
  28370. name:
  28371. description: Name is the name of the service account that will be created by ESO.
  28372. type: string
  28373. role:
  28374. description: |-
  28375. Role is the role of the service account.
  28376. See here for the documentation on basic roles offered by Grafana:
  28377. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28378. type: string
  28379. secondsToLive:
  28380. description: |-
  28381. SecondsToLive is the number of seconds before the generated service account token will expire.
  28382. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28383. format: int64
  28384. minimum: 1
  28385. type: integer
  28386. required:
  28387. - name
  28388. - role
  28389. type: object
  28390. url:
  28391. description: URL is the URL of the Grafana instance.
  28392. type: string
  28393. required:
  28394. - auth
  28395. - serviceAccount
  28396. - url
  28397. type: object
  28398. mfaSpec:
  28399. description: MFASpec controls the behavior of the mfa generator.
  28400. properties:
  28401. algorithm:
  28402. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28403. type: string
  28404. length:
  28405. description: Length defines the token length. Defaults to 6 characters.
  28406. type: integer
  28407. secret:
  28408. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28409. properties:
  28410. key:
  28411. description: |-
  28412. A key in the referenced Secret.
  28413. Some instances of this field may be defaulted, in others it may be required.
  28414. maxLength: 253
  28415. minLength: 1
  28416. pattern: ^[-._a-zA-Z0-9]+$
  28417. type: string
  28418. name:
  28419. description: The name of the Secret resource being referred to.
  28420. maxLength: 253
  28421. minLength: 1
  28422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28423. type: string
  28424. namespace:
  28425. description: |-
  28426. The namespace of the Secret resource being referred to.
  28427. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28428. maxLength: 63
  28429. minLength: 1
  28430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28431. type: string
  28432. type: object
  28433. timePeriod:
  28434. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28435. type: integer
  28436. when:
  28437. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28438. format: date-time
  28439. type: string
  28440. required:
  28441. - secret
  28442. type: object
  28443. passwordSpec:
  28444. description: PasswordSpec controls the behavior of the password generator.
  28445. properties:
  28446. allowRepeat:
  28447. default: false
  28448. description: set AllowRepeat to true to allow repeating characters.
  28449. type: boolean
  28450. digits:
  28451. description: |-
  28452. Digits specifies the number of digits in the generated
  28453. password. If omitted it defaults to 25% of the length of the password
  28454. type: integer
  28455. encoding:
  28456. default: raw
  28457. description: |-
  28458. Encoding specifies the encoding of the generated password.
  28459. Valid values are:
  28460. - "raw" (default): no encoding
  28461. - "base64": standard base64 encoding
  28462. - "base64url": base64url encoding
  28463. - "base32": base32 encoding
  28464. - "hex": hexadecimal encoding
  28465. enum:
  28466. - base64
  28467. - base64url
  28468. - base32
  28469. - hex
  28470. - raw
  28471. type: string
  28472. length:
  28473. default: 24
  28474. description: |-
  28475. Length of the password to be generated.
  28476. Defaults to 24
  28477. type: integer
  28478. noUpper:
  28479. default: false
  28480. description: Set NoUpper to disable uppercase characters
  28481. type: boolean
  28482. secretKeys:
  28483. description: |-
  28484. SecretKeys defines the keys that will be populated with generated passwords.
  28485. Defaults to "password" when not set.
  28486. items:
  28487. type: string
  28488. minItems: 1
  28489. type: array
  28490. symbolCharacters:
  28491. description: |-
  28492. SymbolCharacters specifies the special characters that should be used
  28493. in the generated password.
  28494. type: string
  28495. symbols:
  28496. description: |-
  28497. Symbols specifies the number of symbol characters in the generated
  28498. password. If omitted it defaults to 25% of the length of the password
  28499. type: integer
  28500. required:
  28501. - allowRepeat
  28502. - length
  28503. - noUpper
  28504. type: object
  28505. quayAccessTokenSpec:
  28506. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28507. properties:
  28508. robotAccount:
  28509. description: Name of the robot account you are federating with
  28510. type: string
  28511. serviceAccountRef:
  28512. description: Name of the service account you are federating with
  28513. properties:
  28514. audiences:
  28515. description: |-
  28516. Audience specifies the `aud` claim for the service account token
  28517. Some providers automatically extend the audience field based on well-known annotations for workload
  28518. identity (e.g. IRSA or GCP Workload Identity)
  28519. items:
  28520. type: string
  28521. type: array
  28522. name:
  28523. description: The name of the ServiceAccount resource being referred to.
  28524. maxLength: 253
  28525. minLength: 1
  28526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28527. type: string
  28528. namespace:
  28529. description: |-
  28530. Namespace of the resource being referred to.
  28531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28532. maxLength: 63
  28533. minLength: 1
  28534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28535. type: string
  28536. required:
  28537. - name
  28538. type: object
  28539. url:
  28540. description: URL configures the Quay instance URL. Defaults to quay.io.
  28541. type: string
  28542. required:
  28543. - robotAccount
  28544. - serviceAccountRef
  28545. type: object
  28546. sshKeySpec:
  28547. description: SSHKeySpec controls the behavior of the ssh key generator.
  28548. properties:
  28549. comment:
  28550. description: Comment specifies an optional comment for the SSH key
  28551. type: string
  28552. keySize:
  28553. description: |-
  28554. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28555. For RSA keys: 2048, 3072, 4096
  28556. For ECDSA keys: 256, 384, 521
  28557. Ignored for ed25519 keys
  28558. maximum: 8192
  28559. minimum: 256
  28560. type: integer
  28561. keyType:
  28562. default: rsa
  28563. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28564. enum:
  28565. - rsa
  28566. - ecdsa
  28567. - ed25519
  28568. type: string
  28569. type: object
  28570. stsSessionTokenSpec:
  28571. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28572. properties:
  28573. auth:
  28574. description: Auth defines how to authenticate with AWS
  28575. properties:
  28576. jwt:
  28577. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28578. properties:
  28579. serviceAccountRef:
  28580. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28581. properties:
  28582. audiences:
  28583. description: |-
  28584. Audience specifies the `aud` claim for the service account token
  28585. Some providers automatically extend the audience field based on well-known annotations for workload
  28586. identity (e.g. IRSA or GCP Workload Identity)
  28587. items:
  28588. type: string
  28589. type: array
  28590. name:
  28591. description: The name of the ServiceAccount resource being referred to.
  28592. maxLength: 253
  28593. minLength: 1
  28594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28595. type: string
  28596. namespace:
  28597. description: |-
  28598. Namespace of the resource being referred to.
  28599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28600. maxLength: 63
  28601. minLength: 1
  28602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28603. type: string
  28604. required:
  28605. - name
  28606. type: object
  28607. type: object
  28608. secretRef:
  28609. description: |-
  28610. AWSAuthSecretRef holds secret references for AWS credentials
  28611. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28612. properties:
  28613. accessKeyIDSecretRef:
  28614. description: The AccessKeyID is used for authentication
  28615. properties:
  28616. key:
  28617. description: |-
  28618. A key in the referenced Secret.
  28619. Some instances of this field may be defaulted, in others it may be required.
  28620. maxLength: 253
  28621. minLength: 1
  28622. pattern: ^[-._a-zA-Z0-9]+$
  28623. type: string
  28624. name:
  28625. description: The name of the Secret resource being referred to.
  28626. maxLength: 253
  28627. minLength: 1
  28628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28629. type: string
  28630. namespace:
  28631. description: |-
  28632. The namespace of the Secret resource being referred to.
  28633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28634. maxLength: 63
  28635. minLength: 1
  28636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28637. type: string
  28638. type: object
  28639. secretAccessKeySecretRef:
  28640. description: The SecretAccessKey is used for authentication
  28641. properties:
  28642. key:
  28643. description: |-
  28644. A key in the referenced Secret.
  28645. Some instances of this field may be defaulted, in others it may be required.
  28646. maxLength: 253
  28647. minLength: 1
  28648. pattern: ^[-._a-zA-Z0-9]+$
  28649. type: string
  28650. name:
  28651. description: The name of the Secret resource being referred to.
  28652. maxLength: 253
  28653. minLength: 1
  28654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28655. type: string
  28656. namespace:
  28657. description: |-
  28658. The namespace of the Secret resource being referred to.
  28659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28660. maxLength: 63
  28661. minLength: 1
  28662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28663. type: string
  28664. type: object
  28665. sessionTokenSecretRef:
  28666. description: |-
  28667. The SessionToken used for authentication
  28668. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28669. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28670. properties:
  28671. key:
  28672. description: |-
  28673. A key in the referenced Secret.
  28674. Some instances of this field may be defaulted, in others it may be required.
  28675. maxLength: 253
  28676. minLength: 1
  28677. pattern: ^[-._a-zA-Z0-9]+$
  28678. type: string
  28679. name:
  28680. description: The name of the Secret resource being referred to.
  28681. maxLength: 253
  28682. minLength: 1
  28683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28684. type: string
  28685. namespace:
  28686. description: |-
  28687. The namespace of the Secret resource being referred to.
  28688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28689. maxLength: 63
  28690. minLength: 1
  28691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28692. type: string
  28693. type: object
  28694. type: object
  28695. type: object
  28696. region:
  28697. description: Region specifies the region to operate in.
  28698. type: string
  28699. requestParameters:
  28700. description: RequestParameters contains parameters that can be passed to the STS service.
  28701. properties:
  28702. serialNumber:
  28703. description: |-
  28704. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28705. the GetSessionToken call.
  28706. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28707. (such as arn:aws:iam::123456789012:mfa/user)
  28708. type: string
  28709. sessionDuration:
  28710. format: int32
  28711. type: integer
  28712. tokenCode:
  28713. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28714. type: string
  28715. type: object
  28716. role:
  28717. description: |-
  28718. You can assume a role before making calls to the
  28719. desired AWS service.
  28720. type: string
  28721. required:
  28722. - region
  28723. type: object
  28724. uuidSpec:
  28725. description: UUIDSpec controls the behavior of the uuid generator.
  28726. type: object
  28727. vaultDynamicSecretSpec:
  28728. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28729. properties:
  28730. allowEmptyResponse:
  28731. default: false
  28732. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28733. type: boolean
  28734. controller:
  28735. description: |-
  28736. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28737. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28738. type: string
  28739. getParameters:
  28740. additionalProperties:
  28741. items:
  28742. type: string
  28743. type: array
  28744. description: |-
  28745. GetParameters are query-string parameters passed to Vault on GET calls.
  28746. Each key may map to multiple values, matching HTTP query-string semantics.
  28747. Ignored for non-GET methods; use Parameters for write bodies.
  28748. type: object
  28749. method:
  28750. description: Vault API method to use (GET/POST/other)
  28751. type: string
  28752. parameters:
  28753. description: Parameters to pass to Vault write (for non-GET methods)
  28754. x-kubernetes-preserve-unknown-fields: true
  28755. path:
  28756. description: Vault path to obtain the dynamic secret from
  28757. type: string
  28758. provider:
  28759. description: Vault provider common spec
  28760. properties:
  28761. auth:
  28762. description: Auth configures how secret-manager authenticates with the Vault server.
  28763. properties:
  28764. appRole:
  28765. description: |-
  28766. AppRole authenticates with Vault using the App Role auth mechanism,
  28767. with the role and secret stored in a Kubernetes Secret resource.
  28768. properties:
  28769. path:
  28770. default: approle
  28771. description: |-
  28772. Path where the App Role authentication backend is mounted
  28773. in Vault, e.g: "approle"
  28774. type: string
  28775. roleId:
  28776. description: |-
  28777. RoleID configured in the App Role authentication backend when setting
  28778. up the authentication backend in Vault.
  28779. type: string
  28780. roleRef:
  28781. description: |-
  28782. Reference to a key in a Secret that contains the App Role ID used
  28783. to authenticate with Vault.
  28784. The `key` field must be specified and denotes which entry within the Secret
  28785. resource is used as the app role id.
  28786. properties:
  28787. key:
  28788. description: |-
  28789. A key in the referenced Secret.
  28790. Some instances of this field may be defaulted, in others it may be required.
  28791. maxLength: 253
  28792. minLength: 1
  28793. pattern: ^[-._a-zA-Z0-9]+$
  28794. type: string
  28795. name:
  28796. description: The name of the Secret resource being referred to.
  28797. maxLength: 253
  28798. minLength: 1
  28799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28800. type: string
  28801. namespace:
  28802. description: |-
  28803. The namespace of the Secret resource being referred to.
  28804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28805. maxLength: 63
  28806. minLength: 1
  28807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28808. type: string
  28809. type: object
  28810. secretRef:
  28811. description: |-
  28812. Reference to a key in a Secret that contains the App Role secret used
  28813. to authenticate with Vault.
  28814. The `key` field must be specified and denotes which entry within the Secret
  28815. resource is used as the app role secret.
  28816. properties:
  28817. key:
  28818. description: |-
  28819. A key in the referenced Secret.
  28820. Some instances of this field may be defaulted, in others it may be required.
  28821. maxLength: 253
  28822. minLength: 1
  28823. pattern: ^[-._a-zA-Z0-9]+$
  28824. type: string
  28825. name:
  28826. description: The name of the Secret resource being referred to.
  28827. maxLength: 253
  28828. minLength: 1
  28829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28830. type: string
  28831. namespace:
  28832. description: |-
  28833. The namespace of the Secret resource being referred to.
  28834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28835. maxLength: 63
  28836. minLength: 1
  28837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28838. type: string
  28839. type: object
  28840. required:
  28841. - path
  28842. - secretRef
  28843. type: object
  28844. cert:
  28845. description: |-
  28846. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28847. Cert authentication method
  28848. properties:
  28849. clientCert:
  28850. description: |-
  28851. ClientCert is a certificate to authenticate using the Cert Vault
  28852. authentication method
  28853. properties:
  28854. key:
  28855. description: |-
  28856. A key in the referenced Secret.
  28857. Some instances of this field may be defaulted, in others it may be required.
  28858. maxLength: 253
  28859. minLength: 1
  28860. pattern: ^[-._a-zA-Z0-9]+$
  28861. type: string
  28862. name:
  28863. description: The name of the Secret resource being referred to.
  28864. maxLength: 253
  28865. minLength: 1
  28866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28867. type: string
  28868. namespace:
  28869. description: |-
  28870. The namespace of the Secret resource being referred to.
  28871. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28872. maxLength: 63
  28873. minLength: 1
  28874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28875. type: string
  28876. type: object
  28877. path:
  28878. default: cert
  28879. description: |-
  28880. Path where the Certificate authentication backend is mounted
  28881. in Vault, e.g: "cert"
  28882. type: string
  28883. secretRef:
  28884. description: |-
  28885. SecretRef to a key in a Secret resource containing client private key to
  28886. authenticate with Vault using the Cert authentication method
  28887. properties:
  28888. key:
  28889. description: |-
  28890. A key in the referenced Secret.
  28891. Some instances of this field may be defaulted, in others it may be required.
  28892. maxLength: 253
  28893. minLength: 1
  28894. pattern: ^[-._a-zA-Z0-9]+$
  28895. type: string
  28896. name:
  28897. description: The name of the Secret resource being referred to.
  28898. maxLength: 253
  28899. minLength: 1
  28900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28901. type: string
  28902. namespace:
  28903. description: |-
  28904. The namespace of the Secret resource being referred to.
  28905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28906. maxLength: 63
  28907. minLength: 1
  28908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28909. type: string
  28910. type: object
  28911. vaultRole:
  28912. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28913. type: string
  28914. type: object
  28915. gcp:
  28916. description: |-
  28917. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28918. GCP authentication method
  28919. properties:
  28920. location:
  28921. description: Location optionally defines a location/region for the secret
  28922. type: string
  28923. path:
  28924. default: gcp
  28925. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28926. type: string
  28927. projectID:
  28928. description: Project ID of the Google Cloud Platform project
  28929. type: string
  28930. role:
  28931. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28932. type: string
  28933. secretRef:
  28934. description: Specify credentials in a Secret object
  28935. properties:
  28936. secretAccessKeySecretRef:
  28937. description: The SecretAccessKey is used for authentication
  28938. properties:
  28939. key:
  28940. description: |-
  28941. A key in the referenced Secret.
  28942. Some instances of this field may be defaulted, in others it may be required.
  28943. maxLength: 253
  28944. minLength: 1
  28945. pattern: ^[-._a-zA-Z0-9]+$
  28946. type: string
  28947. name:
  28948. description: The name of the Secret resource being referred to.
  28949. maxLength: 253
  28950. minLength: 1
  28951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28952. type: string
  28953. namespace:
  28954. description: |-
  28955. The namespace of the Secret resource being referred to.
  28956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28957. maxLength: 63
  28958. minLength: 1
  28959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28960. type: string
  28961. type: object
  28962. type: object
  28963. serviceAccountRef:
  28964. description: ServiceAccountRef to a service account for impersonation
  28965. properties:
  28966. audiences:
  28967. description: |-
  28968. Audience specifies the `aud` claim for the service account token
  28969. Some providers automatically extend the audience field based on well-known annotations for workload
  28970. identity (e.g. IRSA or GCP Workload Identity)
  28971. items:
  28972. type: string
  28973. type: array
  28974. name:
  28975. description: The name of the ServiceAccount resource being referred to.
  28976. maxLength: 253
  28977. minLength: 1
  28978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28979. type: string
  28980. namespace:
  28981. description: |-
  28982. Namespace of the resource being referred to.
  28983. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28984. maxLength: 63
  28985. minLength: 1
  28986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28987. type: string
  28988. required:
  28989. - name
  28990. type: object
  28991. workloadIdentity:
  28992. description: Specify a service account with Workload Identity
  28993. properties:
  28994. clusterLocation:
  28995. description: |-
  28996. ClusterLocation is the location of the cluster
  28997. If not specified, it fetches information from the metadata server
  28998. type: string
  28999. clusterName:
  29000. description: |-
  29001. ClusterName is the name of the cluster
  29002. If not specified, it fetches information from the metadata server
  29003. type: string
  29004. clusterProjectID:
  29005. description: |-
  29006. ClusterProjectID is the project ID of the cluster
  29007. If not specified, it fetches information from the metadata server
  29008. type: string
  29009. serviceAccountRef:
  29010. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29011. properties:
  29012. audiences:
  29013. description: |-
  29014. Audience specifies the `aud` claim for the service account token
  29015. Some providers automatically extend the audience field based on well-known annotations for workload
  29016. identity (e.g. IRSA or GCP Workload Identity)
  29017. items:
  29018. type: string
  29019. type: array
  29020. name:
  29021. description: The name of the ServiceAccount resource being referred to.
  29022. maxLength: 253
  29023. minLength: 1
  29024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29025. type: string
  29026. namespace:
  29027. description: |-
  29028. Namespace of the resource being referred to.
  29029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29030. maxLength: 63
  29031. minLength: 1
  29032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29033. type: string
  29034. required:
  29035. - name
  29036. type: object
  29037. required:
  29038. - serviceAccountRef
  29039. type: object
  29040. required:
  29041. - role
  29042. type: object
  29043. iam:
  29044. description: |-
  29045. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  29046. AWS IAM authentication method
  29047. properties:
  29048. externalID:
  29049. description: AWS External ID set on assumed IAM roles
  29050. type: string
  29051. jwt:
  29052. description: Specify a service account with IRSA enabled
  29053. properties:
  29054. serviceAccountRef:
  29055. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29056. properties:
  29057. audiences:
  29058. description: |-
  29059. Audience specifies the `aud` claim for the service account token
  29060. Some providers automatically extend the audience field based on well-known annotations for workload
  29061. identity (e.g. IRSA or GCP Workload Identity)
  29062. items:
  29063. type: string
  29064. type: array
  29065. name:
  29066. description: The name of the ServiceAccount resource being referred to.
  29067. maxLength: 253
  29068. minLength: 1
  29069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29070. type: string
  29071. namespace:
  29072. description: |-
  29073. Namespace of the resource being referred to.
  29074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29075. maxLength: 63
  29076. minLength: 1
  29077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29078. type: string
  29079. required:
  29080. - name
  29081. type: object
  29082. type: object
  29083. path:
  29084. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  29085. type: string
  29086. region:
  29087. description: AWS region
  29088. type: string
  29089. role:
  29090. description: This is the AWS role to be assumed before talking to vault
  29091. type: string
  29092. secretRef:
  29093. description: Specify credentials in a Secret object
  29094. properties:
  29095. accessKeyIDSecretRef:
  29096. description: The AccessKeyID is used for authentication
  29097. properties:
  29098. key:
  29099. description: |-
  29100. A key in the referenced Secret.
  29101. Some instances of this field may be defaulted, in others it may be required.
  29102. maxLength: 253
  29103. minLength: 1
  29104. pattern: ^[-._a-zA-Z0-9]+$
  29105. type: string
  29106. name:
  29107. description: The name of the Secret resource being referred to.
  29108. maxLength: 253
  29109. minLength: 1
  29110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29111. type: string
  29112. namespace:
  29113. description: |-
  29114. The namespace of the Secret resource being referred to.
  29115. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29116. maxLength: 63
  29117. minLength: 1
  29118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29119. type: string
  29120. type: object
  29121. secretAccessKeySecretRef:
  29122. description: The SecretAccessKey is used for authentication
  29123. properties:
  29124. key:
  29125. description: |-
  29126. A key in the referenced Secret.
  29127. Some instances of this field may be defaulted, in others it may be required.
  29128. maxLength: 253
  29129. minLength: 1
  29130. pattern: ^[-._a-zA-Z0-9]+$
  29131. type: string
  29132. name:
  29133. description: The name of the Secret resource being referred to.
  29134. maxLength: 253
  29135. minLength: 1
  29136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29137. type: string
  29138. namespace:
  29139. description: |-
  29140. The namespace of the Secret resource being referred to.
  29141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29142. maxLength: 63
  29143. minLength: 1
  29144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29145. type: string
  29146. type: object
  29147. sessionTokenSecretRef:
  29148. description: |-
  29149. The SessionToken used for authentication
  29150. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29151. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29152. properties:
  29153. key:
  29154. description: |-
  29155. A key in the referenced Secret.
  29156. Some instances of this field may be defaulted, in others it may be required.
  29157. maxLength: 253
  29158. minLength: 1
  29159. pattern: ^[-._a-zA-Z0-9]+$
  29160. type: string
  29161. name:
  29162. description: The name of the Secret resource being referred to.
  29163. maxLength: 253
  29164. minLength: 1
  29165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29166. type: string
  29167. namespace:
  29168. description: |-
  29169. The namespace of the Secret resource being referred to.
  29170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29171. maxLength: 63
  29172. minLength: 1
  29173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29174. type: string
  29175. type: object
  29176. type: object
  29177. vaultAwsIamServerID:
  29178. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  29179. type: string
  29180. vaultRole:
  29181. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  29182. type: string
  29183. required:
  29184. - vaultRole
  29185. type: object
  29186. jwt:
  29187. description: |-
  29188. Jwt authenticates with Vault by passing role and JWT token using the
  29189. JWT/OIDC authentication method
  29190. properties:
  29191. kubernetesServiceAccountToken:
  29192. description: |-
  29193. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29194. a token for with the `TokenRequest` API.
  29195. properties:
  29196. audiences:
  29197. description: |-
  29198. Optional audiences field that will be used to request a temporary Kubernetes service
  29199. account token for the service account referenced by `serviceAccountRef`.
  29200. Defaults to a single audience `vault` it not specified.
  29201. Deprecated: use serviceAccountRef.Audiences instead
  29202. items:
  29203. type: string
  29204. type: array
  29205. expirationSeconds:
  29206. description: |-
  29207. Optional expiration time in seconds that will be used to request a temporary
  29208. Kubernetes service account token for the service account referenced by
  29209. `serviceAccountRef`.
  29210. Deprecated: this will be removed in the future.
  29211. Defaults to 10 minutes.
  29212. format: int64
  29213. type: integer
  29214. serviceAccountRef:
  29215. description: Service account field containing the name of a kubernetes ServiceAccount.
  29216. properties:
  29217. audiences:
  29218. description: |-
  29219. Audience specifies the `aud` claim for the service account token
  29220. Some providers automatically extend the audience field based on well-known annotations for workload
  29221. identity (e.g. IRSA or GCP Workload Identity)
  29222. items:
  29223. type: string
  29224. type: array
  29225. name:
  29226. description: The name of the ServiceAccount resource being referred to.
  29227. maxLength: 253
  29228. minLength: 1
  29229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29230. type: string
  29231. namespace:
  29232. description: |-
  29233. Namespace of the resource being referred to.
  29234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29235. maxLength: 63
  29236. minLength: 1
  29237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29238. type: string
  29239. required:
  29240. - name
  29241. type: object
  29242. required:
  29243. - serviceAccountRef
  29244. type: object
  29245. path:
  29246. default: jwt
  29247. description: |-
  29248. Path where the JWT authentication backend is mounted
  29249. in Vault, e.g: "jwt"
  29250. type: string
  29251. role:
  29252. description: |-
  29253. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29254. authentication method
  29255. type: string
  29256. secretRef:
  29257. description: |-
  29258. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29259. authenticate with Vault using the JWT/OIDC authentication method.
  29260. properties:
  29261. key:
  29262. description: |-
  29263. A key in the referenced Secret.
  29264. Some instances of this field may be defaulted, in others it may be required.
  29265. maxLength: 253
  29266. minLength: 1
  29267. pattern: ^[-._a-zA-Z0-9]+$
  29268. type: string
  29269. name:
  29270. description: The name of the Secret resource being referred to.
  29271. maxLength: 253
  29272. minLength: 1
  29273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29274. type: string
  29275. namespace:
  29276. description: |-
  29277. The namespace of the Secret resource being referred to.
  29278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29279. maxLength: 63
  29280. minLength: 1
  29281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29282. type: string
  29283. type: object
  29284. required:
  29285. - path
  29286. type: object
  29287. kubernetes:
  29288. description: |-
  29289. Kubernetes authenticates with Vault by passing the ServiceAccount
  29290. token stored in the named Secret resource to the Vault server.
  29291. properties:
  29292. mountPath:
  29293. default: kubernetes
  29294. description: |-
  29295. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29296. "kubernetes"
  29297. type: string
  29298. role:
  29299. description: |-
  29300. A required field containing the Vault Role to assume. A Role binds a
  29301. Kubernetes ServiceAccount with a set of Vault policies.
  29302. type: string
  29303. secretRef:
  29304. description: |-
  29305. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29306. for authenticating with Vault. If a name is specified without a key,
  29307. `token` is the default. If one is not specified, the one bound to
  29308. the controller will be used.
  29309. properties:
  29310. key:
  29311. description: |-
  29312. A key in the referenced Secret.
  29313. Some instances of this field may be defaulted, in others it may be required.
  29314. maxLength: 253
  29315. minLength: 1
  29316. pattern: ^[-._a-zA-Z0-9]+$
  29317. type: string
  29318. name:
  29319. description: The name of the Secret resource being referred to.
  29320. maxLength: 253
  29321. minLength: 1
  29322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29323. type: string
  29324. namespace:
  29325. description: |-
  29326. The namespace of the Secret resource being referred to.
  29327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29328. maxLength: 63
  29329. minLength: 1
  29330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29331. type: string
  29332. type: object
  29333. serviceAccountRef:
  29334. description: |-
  29335. Optional service account field containing the name of a kubernetes ServiceAccount.
  29336. If the service account is specified, the service account secret token JWT will be used
  29337. for authenticating with Vault. If the service account selector is not supplied,
  29338. the secretRef will be used instead.
  29339. properties:
  29340. audiences:
  29341. description: |-
  29342. Audience specifies the `aud` claim for the service account token
  29343. Some providers automatically extend the audience field based on well-known annotations for workload
  29344. identity (e.g. IRSA or GCP Workload Identity)
  29345. items:
  29346. type: string
  29347. type: array
  29348. name:
  29349. description: The name of the ServiceAccount resource being referred to.
  29350. maxLength: 253
  29351. minLength: 1
  29352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29353. type: string
  29354. namespace:
  29355. description: |-
  29356. Namespace of the resource being referred to.
  29357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29358. maxLength: 63
  29359. minLength: 1
  29360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29361. type: string
  29362. required:
  29363. - name
  29364. type: object
  29365. required:
  29366. - mountPath
  29367. - role
  29368. type: object
  29369. ldap:
  29370. description: |-
  29371. Ldap authenticates with Vault by passing username/password pair using
  29372. the LDAP authentication method
  29373. properties:
  29374. path:
  29375. default: ldap
  29376. description: |-
  29377. Path where the LDAP authentication backend is mounted
  29378. in Vault, e.g: "ldap"
  29379. type: string
  29380. secretRef:
  29381. description: |-
  29382. SecretRef to a key in a Secret resource containing password for the LDAP
  29383. user used to authenticate with Vault using the LDAP authentication
  29384. method
  29385. properties:
  29386. key:
  29387. description: |-
  29388. A key in the referenced Secret.
  29389. Some instances of this field may be defaulted, in others it may be required.
  29390. maxLength: 253
  29391. minLength: 1
  29392. pattern: ^[-._a-zA-Z0-9]+$
  29393. type: string
  29394. name:
  29395. description: The name of the Secret resource being referred to.
  29396. maxLength: 253
  29397. minLength: 1
  29398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29399. type: string
  29400. namespace:
  29401. description: |-
  29402. The namespace of the Secret resource being referred to.
  29403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29404. maxLength: 63
  29405. minLength: 1
  29406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29407. type: string
  29408. type: object
  29409. username:
  29410. description: |-
  29411. Username is an LDAP username used to authenticate using the LDAP Vault
  29412. authentication method
  29413. type: string
  29414. required:
  29415. - path
  29416. - username
  29417. type: object
  29418. namespace:
  29419. description: |-
  29420. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29421. Namespaces is a set of features within Vault Enterprise that allows
  29422. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29423. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29424. This will default to Vault.Namespace field if set, or empty otherwise
  29425. type: string
  29426. tokenSecretRef:
  29427. description: TokenSecretRef authenticates with Vault by presenting a token.
  29428. properties:
  29429. key:
  29430. description: |-
  29431. A key in the referenced Secret.
  29432. Some instances of this field may be defaulted, in others it may be required.
  29433. maxLength: 253
  29434. minLength: 1
  29435. pattern: ^[-._a-zA-Z0-9]+$
  29436. type: string
  29437. name:
  29438. description: The name of the Secret resource being referred to.
  29439. maxLength: 253
  29440. minLength: 1
  29441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29442. type: string
  29443. namespace:
  29444. description: |-
  29445. The namespace of the Secret resource being referred to.
  29446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29447. maxLength: 63
  29448. minLength: 1
  29449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29450. type: string
  29451. type: object
  29452. userPass:
  29453. description: UserPass authenticates with Vault by passing username/password pair
  29454. properties:
  29455. path:
  29456. default: userpass
  29457. description: |-
  29458. Path where the UserPassword authentication backend is mounted
  29459. in Vault, e.g: "userpass"
  29460. type: string
  29461. secretRef:
  29462. description: |-
  29463. SecretRef to a key in a Secret resource containing password for the
  29464. user used to authenticate with Vault using the UserPass authentication
  29465. method
  29466. properties:
  29467. key:
  29468. description: |-
  29469. A key in the referenced Secret.
  29470. Some instances of this field may be defaulted, in others it may be required.
  29471. maxLength: 253
  29472. minLength: 1
  29473. pattern: ^[-._a-zA-Z0-9]+$
  29474. type: string
  29475. name:
  29476. description: The name of the Secret resource being referred to.
  29477. maxLength: 253
  29478. minLength: 1
  29479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29480. type: string
  29481. namespace:
  29482. description: |-
  29483. The namespace of the Secret resource being referred to.
  29484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29485. maxLength: 63
  29486. minLength: 1
  29487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29488. type: string
  29489. type: object
  29490. username:
  29491. description: |-
  29492. Username is a username used to authenticate using the UserPass Vault
  29493. authentication method
  29494. type: string
  29495. required:
  29496. - path
  29497. - username
  29498. type: object
  29499. type: object
  29500. caBundle:
  29501. description: |-
  29502. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29503. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29504. plain HTTP protocol connection. If not set the system root certificates
  29505. are used to validate the TLS connection.
  29506. format: byte
  29507. type: string
  29508. caProvider:
  29509. description: The provider for the CA bundle to use to validate Vault server certificate.
  29510. properties:
  29511. key:
  29512. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29513. maxLength: 253
  29514. minLength: 1
  29515. pattern: ^[-._a-zA-Z0-9]+$
  29516. type: string
  29517. name:
  29518. description: The name of the object located at the provider type.
  29519. maxLength: 253
  29520. minLength: 1
  29521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29522. type: string
  29523. namespace:
  29524. description: |-
  29525. The namespace the Provider type is in.
  29526. Can only be defined when used in a ClusterSecretStore.
  29527. maxLength: 63
  29528. minLength: 1
  29529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29530. type: string
  29531. type:
  29532. description: The type of provider to use such as "Secret", or "ConfigMap".
  29533. enum:
  29534. - Secret
  29535. - ConfigMap
  29536. type: string
  29537. required:
  29538. - name
  29539. - type
  29540. type: object
  29541. checkAndSet:
  29542. description: |-
  29543. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29544. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29545. the current version of the secret to prevent unintentional overwrites.
  29546. properties:
  29547. required:
  29548. description: |-
  29549. Required when true, all write operations must include a check-and-set parameter.
  29550. This helps prevent unintentional overwrites of secrets.
  29551. type: boolean
  29552. type: object
  29553. forwardInconsistent:
  29554. description: |-
  29555. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29556. leader instead of simply retrying within a loop. This can increase performance if
  29557. the option is enabled serverside.
  29558. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29559. type: boolean
  29560. headers:
  29561. additionalProperties:
  29562. type: string
  29563. description: Headers to be added in Vault request
  29564. type: object
  29565. namespace:
  29566. description: |-
  29567. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29568. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29569. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29570. type: string
  29571. path:
  29572. description: |-
  29573. Path is the mount path of the Vault KV backend endpoint, e.g:
  29574. "secret". The v2 KV secret engine version specific "/data" path suffix
  29575. for fetching secrets from Vault is optional and will be appended
  29576. if not present in specified path.
  29577. type: string
  29578. readYourWrites:
  29579. description: |-
  29580. ReadYourWrites ensures isolated read-after-write semantics by
  29581. providing discovered cluster replication states in each request.
  29582. More information about eventual consistency in Vault can be found here
  29583. https://www.vaultproject.io/docs/enterprise/consistency
  29584. type: boolean
  29585. server:
  29586. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29587. type: string
  29588. tls:
  29589. description: |-
  29590. The configuration used for client side related TLS communication, when the Vault server
  29591. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29592. This parameter is ignored for plain HTTP protocol connection.
  29593. It's worth noting this configuration is different from the "TLS certificates auth method",
  29594. which is available under the `auth.cert` section.
  29595. properties:
  29596. certSecretRef:
  29597. description: |-
  29598. CertSecretRef is a certificate added to the transport layer
  29599. when communicating with the Vault server.
  29600. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29601. properties:
  29602. key:
  29603. description: |-
  29604. A key in the referenced Secret.
  29605. Some instances of this field may be defaulted, in others it may be required.
  29606. maxLength: 253
  29607. minLength: 1
  29608. pattern: ^[-._a-zA-Z0-9]+$
  29609. type: string
  29610. name:
  29611. description: The name of the Secret resource being referred to.
  29612. maxLength: 253
  29613. minLength: 1
  29614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29615. type: string
  29616. namespace:
  29617. description: |-
  29618. The namespace of the Secret resource being referred to.
  29619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29620. maxLength: 63
  29621. minLength: 1
  29622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29623. type: string
  29624. type: object
  29625. keySecretRef:
  29626. description: |-
  29627. KeySecretRef to a key in a Secret resource containing client private key
  29628. added to the transport layer when communicating with the Vault server.
  29629. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29630. properties:
  29631. key:
  29632. description: |-
  29633. A key in the referenced Secret.
  29634. Some instances of this field may be defaulted, in others it may be required.
  29635. maxLength: 253
  29636. minLength: 1
  29637. pattern: ^[-._a-zA-Z0-9]+$
  29638. type: string
  29639. name:
  29640. description: The name of the Secret resource being referred to.
  29641. maxLength: 253
  29642. minLength: 1
  29643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29644. type: string
  29645. namespace:
  29646. description: |-
  29647. The namespace of the Secret resource being referred to.
  29648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29649. maxLength: 63
  29650. minLength: 1
  29651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29652. type: string
  29653. type: object
  29654. type: object
  29655. version:
  29656. default: v2
  29657. description: |-
  29658. Version is the Vault KV secret engine version. This can be either "v1" or
  29659. "v2". Version defaults to "v2".
  29660. enum:
  29661. - v1
  29662. - v2
  29663. type: string
  29664. required:
  29665. - server
  29666. type: object
  29667. resultType:
  29668. default: Data
  29669. description: |-
  29670. Result type defines which data is returned from the generator.
  29671. By default, it is the "data" section of the Vault API response.
  29672. When using e.g. /auth/token/create the "data" section is empty but
  29673. the "auth" section contains the generated token.
  29674. Please refer to the vault docs regarding the result data structure.
  29675. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29676. enum:
  29677. - Data
  29678. - Auth
  29679. - Raw
  29680. type: string
  29681. retrySettings:
  29682. description: Used to configure http retries if failed
  29683. properties:
  29684. maxRetries:
  29685. format: int32
  29686. type: integer
  29687. retryInterval:
  29688. type: string
  29689. type: object
  29690. required:
  29691. - path
  29692. - provider
  29693. type: object
  29694. webhookSpec:
  29695. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29696. properties:
  29697. auth:
  29698. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29699. maxProperties: 1
  29700. minProperties: 1
  29701. properties:
  29702. ntlm:
  29703. description: NTLMProtocol configures the store to use NTLM for auth
  29704. properties:
  29705. passwordSecret:
  29706. description: |-
  29707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29708. In some instances, `key` is a required field.
  29709. properties:
  29710. key:
  29711. description: |-
  29712. A key in the referenced Secret.
  29713. Some instances of this field may be defaulted, in others it may be required.
  29714. maxLength: 253
  29715. minLength: 1
  29716. pattern: ^[-._a-zA-Z0-9]+$
  29717. type: string
  29718. name:
  29719. description: The name of the Secret resource being referred to.
  29720. maxLength: 253
  29721. minLength: 1
  29722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29723. type: string
  29724. namespace:
  29725. description: |-
  29726. The namespace of the Secret resource being referred to.
  29727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29728. maxLength: 63
  29729. minLength: 1
  29730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29731. type: string
  29732. type: object
  29733. usernameSecret:
  29734. description: |-
  29735. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29736. In some instances, `key` is a required field.
  29737. properties:
  29738. key:
  29739. description: |-
  29740. A key in the referenced Secret.
  29741. Some instances of this field may be defaulted, in others it may be required.
  29742. maxLength: 253
  29743. minLength: 1
  29744. pattern: ^[-._a-zA-Z0-9]+$
  29745. type: string
  29746. name:
  29747. description: The name of the Secret resource being referred to.
  29748. maxLength: 253
  29749. minLength: 1
  29750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29751. type: string
  29752. namespace:
  29753. description: |-
  29754. The namespace of the Secret resource being referred to.
  29755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29756. maxLength: 63
  29757. minLength: 1
  29758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29759. type: string
  29760. type: object
  29761. required:
  29762. - passwordSecret
  29763. - usernameSecret
  29764. type: object
  29765. type: object
  29766. body:
  29767. description: Body
  29768. type: string
  29769. caBundle:
  29770. description: |-
  29771. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29772. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29773. plain HTTP protocol connection. If not set the system root certificates
  29774. are used to validate the TLS connection.
  29775. format: byte
  29776. type: string
  29777. caProvider:
  29778. description: The provider for the CA bundle to use to validate webhook server certificate.
  29779. properties:
  29780. key:
  29781. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29782. maxLength: 253
  29783. minLength: 1
  29784. pattern: ^[-._a-zA-Z0-9]+$
  29785. type: string
  29786. name:
  29787. description: The name of the object located at the provider type.
  29788. maxLength: 253
  29789. minLength: 1
  29790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29791. type: string
  29792. namespace:
  29793. description: The namespace the Provider type is in.
  29794. maxLength: 63
  29795. minLength: 1
  29796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29797. type: string
  29798. type:
  29799. description: The type of provider to use such as "Secret", or "ConfigMap".
  29800. enum:
  29801. - Secret
  29802. - ConfigMap
  29803. type: string
  29804. required:
  29805. - name
  29806. - type
  29807. type: object
  29808. headers:
  29809. additionalProperties:
  29810. type: string
  29811. description: Headers
  29812. type: object
  29813. method:
  29814. description: Webhook Method
  29815. type: string
  29816. result:
  29817. description: Result formatting
  29818. properties:
  29819. jsonPath:
  29820. description: Json path of return value
  29821. type: string
  29822. type: object
  29823. secrets:
  29824. description: |-
  29825. Secrets to fill in templates
  29826. These secrets will be passed to the templating function as key value pairs under the given name
  29827. items:
  29828. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29829. properties:
  29830. name:
  29831. description: Name of this secret in templates
  29832. type: string
  29833. secretRef:
  29834. description: Secret ref to fill in credentials
  29835. properties:
  29836. key:
  29837. description: The key where the token is found.
  29838. maxLength: 253
  29839. minLength: 1
  29840. pattern: ^[-._a-zA-Z0-9]+$
  29841. type: string
  29842. name:
  29843. description: The name of the Secret resource being referred to.
  29844. maxLength: 253
  29845. minLength: 1
  29846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29847. type: string
  29848. type: object
  29849. required:
  29850. - name
  29851. - secretRef
  29852. type: object
  29853. type: array
  29854. timeout:
  29855. description: Timeout
  29856. type: string
  29857. url:
  29858. description: Webhook url to call
  29859. type: string
  29860. required:
  29861. - result
  29862. - url
  29863. type: object
  29864. type: object
  29865. kind:
  29866. description: Kind the kind of this generator.
  29867. enum:
  29868. - ACRAccessToken
  29869. - BeyondtrustWorkloadCredentialsDynamicSecret
  29870. - CloudsmithAccessToken
  29871. - ECRAuthorizationToken
  29872. - Fake
  29873. - GCRAccessToken
  29874. - GithubAccessToken
  29875. - GitlabDeployToken
  29876. - QuayAccessToken
  29877. - Password
  29878. - SSHKey
  29879. - STSSessionToken
  29880. - UUID
  29881. - VaultDynamicSecret
  29882. - Webhook
  29883. - Grafana
  29884. - MFA
  29885. type: string
  29886. required:
  29887. - generator
  29888. - kind
  29889. type: object
  29890. type: object
  29891. served: true
  29892. storage: true
  29893. subresources:
  29894. status: {}
  29895. ---
  29896. apiVersion: apiextensions.k8s.io/v1
  29897. kind: CustomResourceDefinition
  29898. metadata:
  29899. annotations:
  29900. controller-gen.kubebuilder.io/version: v0.19.0
  29901. labels:
  29902. external-secrets.io/component: controller
  29903. name: ecrauthorizationtokens.generators.external-secrets.io
  29904. spec:
  29905. group: generators.external-secrets.io
  29906. names:
  29907. categories:
  29908. - external-secrets
  29909. - external-secrets-generators
  29910. kind: ECRAuthorizationToken
  29911. listKind: ECRAuthorizationTokenList
  29912. plural: ecrauthorizationtokens
  29913. singular: ecrauthorizationtoken
  29914. scope: Namespaced
  29915. versions:
  29916. - name: v1alpha1
  29917. schema:
  29918. openAPIV3Schema:
  29919. description: |-
  29920. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29921. The authorization token is valid for 12 hours.
  29922. The authorizationToken returned is a base64 encoded string that can be decoded
  29923. and used in a docker login command to authenticate to a registry.
  29924. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29925. properties:
  29926. apiVersion:
  29927. description: |-
  29928. APIVersion defines the versioned schema of this representation of an object.
  29929. Servers should convert recognized schemas to the latest internal value, and
  29930. may reject unrecognized values.
  29931. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29932. type: string
  29933. kind:
  29934. description: |-
  29935. Kind is a string value representing the REST resource this object represents.
  29936. Servers may infer this from the endpoint the client submits requests to.
  29937. Cannot be updated.
  29938. In CamelCase.
  29939. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29940. type: string
  29941. metadata:
  29942. type: object
  29943. spec:
  29944. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29945. properties:
  29946. auth:
  29947. description: Auth defines how to authenticate with AWS
  29948. properties:
  29949. jwt:
  29950. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29951. properties:
  29952. serviceAccountRef:
  29953. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29954. properties:
  29955. audiences:
  29956. description: |-
  29957. Audience specifies the `aud` claim for the service account token
  29958. Some providers automatically extend the audience field based on well-known annotations for workload
  29959. identity (e.g. IRSA or GCP Workload Identity)
  29960. items:
  29961. type: string
  29962. type: array
  29963. name:
  29964. description: The name of the ServiceAccount resource being referred to.
  29965. maxLength: 253
  29966. minLength: 1
  29967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29968. type: string
  29969. namespace:
  29970. description: |-
  29971. Namespace of the resource being referred to.
  29972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29973. maxLength: 63
  29974. minLength: 1
  29975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29976. type: string
  29977. required:
  29978. - name
  29979. type: object
  29980. type: object
  29981. secretRef:
  29982. description: |-
  29983. AWSAuthSecretRef holds secret references for AWS credentials
  29984. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29985. properties:
  29986. accessKeyIDSecretRef:
  29987. description: The AccessKeyID is used for authentication
  29988. properties:
  29989. key:
  29990. description: |-
  29991. A key in the referenced Secret.
  29992. Some instances of this field may be defaulted, in others it may be required.
  29993. maxLength: 253
  29994. minLength: 1
  29995. pattern: ^[-._a-zA-Z0-9]+$
  29996. type: string
  29997. name:
  29998. description: The name of the Secret resource being referred to.
  29999. maxLength: 253
  30000. minLength: 1
  30001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30002. type: string
  30003. namespace:
  30004. description: |-
  30005. The namespace of the Secret resource being referred to.
  30006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30007. maxLength: 63
  30008. minLength: 1
  30009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30010. type: string
  30011. type: object
  30012. secretAccessKeySecretRef:
  30013. description: The SecretAccessKey is used for authentication
  30014. properties:
  30015. key:
  30016. description: |-
  30017. A key in the referenced Secret.
  30018. Some instances of this field may be defaulted, in others it may be required.
  30019. maxLength: 253
  30020. minLength: 1
  30021. pattern: ^[-._a-zA-Z0-9]+$
  30022. type: string
  30023. name:
  30024. description: The name of the Secret resource being referred to.
  30025. maxLength: 253
  30026. minLength: 1
  30027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30028. type: string
  30029. namespace:
  30030. description: |-
  30031. The namespace of the Secret resource being referred to.
  30032. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30033. maxLength: 63
  30034. minLength: 1
  30035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30036. type: string
  30037. type: object
  30038. sessionTokenSecretRef:
  30039. description: |-
  30040. The SessionToken used for authentication
  30041. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30042. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30043. properties:
  30044. key:
  30045. description: |-
  30046. A key in the referenced Secret.
  30047. Some instances of this field may be defaulted, in others it may be required.
  30048. maxLength: 253
  30049. minLength: 1
  30050. pattern: ^[-._a-zA-Z0-9]+$
  30051. type: string
  30052. name:
  30053. description: The name of the Secret resource being referred to.
  30054. maxLength: 253
  30055. minLength: 1
  30056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30057. type: string
  30058. namespace:
  30059. description: |-
  30060. The namespace of the Secret resource being referred to.
  30061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30062. maxLength: 63
  30063. minLength: 1
  30064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30065. type: string
  30066. type: object
  30067. type: object
  30068. type: object
  30069. region:
  30070. description: Region specifies the region to operate in.
  30071. type: string
  30072. role:
  30073. description: |-
  30074. You can assume a role before making calls to the
  30075. desired AWS service.
  30076. type: string
  30077. scope:
  30078. description: |-
  30079. Scope specifies the ECR service scope.
  30080. Valid options are private and public.
  30081. type: string
  30082. required:
  30083. - region
  30084. type: object
  30085. type: object
  30086. served: true
  30087. storage: true
  30088. subresources:
  30089. status: {}
  30090. ---
  30091. apiVersion: apiextensions.k8s.io/v1
  30092. kind: CustomResourceDefinition
  30093. metadata:
  30094. annotations:
  30095. controller-gen.kubebuilder.io/version: v0.19.0
  30096. labels:
  30097. external-secrets.io/component: controller
  30098. name: fakes.generators.external-secrets.io
  30099. spec:
  30100. group: generators.external-secrets.io
  30101. names:
  30102. categories:
  30103. - external-secrets
  30104. - external-secrets-generators
  30105. kind: Fake
  30106. listKind: FakeList
  30107. plural: fakes
  30108. singular: fake
  30109. scope: Namespaced
  30110. versions:
  30111. - name: v1alpha1
  30112. schema:
  30113. openAPIV3Schema:
  30114. description: |-
  30115. Fake generator is used for testing. It lets you define
  30116. a static set of credentials that is always returned.
  30117. properties:
  30118. apiVersion:
  30119. description: |-
  30120. APIVersion defines the versioned schema of this representation of an object.
  30121. Servers should convert recognized schemas to the latest internal value, and
  30122. may reject unrecognized values.
  30123. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30124. type: string
  30125. kind:
  30126. description: |-
  30127. Kind is a string value representing the REST resource this object represents.
  30128. Servers may infer this from the endpoint the client submits requests to.
  30129. Cannot be updated.
  30130. In CamelCase.
  30131. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30132. type: string
  30133. metadata:
  30134. type: object
  30135. spec:
  30136. description: FakeSpec contains the static data.
  30137. properties:
  30138. controller:
  30139. description: |-
  30140. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30141. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30142. type: string
  30143. data:
  30144. additionalProperties:
  30145. type: string
  30146. description: |-
  30147. Data defines the static data returned
  30148. by this generator.
  30149. type: object
  30150. type: object
  30151. type: object
  30152. served: true
  30153. storage: true
  30154. subresources:
  30155. status: {}
  30156. ---
  30157. apiVersion: apiextensions.k8s.io/v1
  30158. kind: CustomResourceDefinition
  30159. metadata:
  30160. annotations:
  30161. controller-gen.kubebuilder.io/version: v0.19.0
  30162. labels:
  30163. external-secrets.io/component: controller
  30164. name: gcraccesstokens.generators.external-secrets.io
  30165. spec:
  30166. group: generators.external-secrets.io
  30167. names:
  30168. categories:
  30169. - external-secrets
  30170. - external-secrets-generators
  30171. kind: GCRAccessToken
  30172. listKind: GCRAccessTokenList
  30173. plural: gcraccesstokens
  30174. singular: gcraccesstoken
  30175. scope: Namespaced
  30176. versions:
  30177. - name: v1alpha1
  30178. schema:
  30179. openAPIV3Schema:
  30180. description: |-
  30181. GCRAccessToken generates an GCP access token
  30182. that can be used to authenticate with GCR.
  30183. properties:
  30184. apiVersion:
  30185. description: |-
  30186. APIVersion defines the versioned schema of this representation of an object.
  30187. Servers should convert recognized schemas to the latest internal value, and
  30188. may reject unrecognized values.
  30189. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30190. type: string
  30191. kind:
  30192. description: |-
  30193. Kind is a string value representing the REST resource this object represents.
  30194. Servers may infer this from the endpoint the client submits requests to.
  30195. Cannot be updated.
  30196. In CamelCase.
  30197. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30198. type: string
  30199. metadata:
  30200. type: object
  30201. spec:
  30202. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30203. properties:
  30204. auth:
  30205. description: Auth defines the means for authenticating with GCP
  30206. properties:
  30207. secretRef:
  30208. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30209. properties:
  30210. secretAccessKeySecretRef:
  30211. description: The SecretAccessKey is used for authentication
  30212. properties:
  30213. key:
  30214. description: |-
  30215. A key in the referenced Secret.
  30216. Some instances of this field may be defaulted, in others it may be required.
  30217. maxLength: 253
  30218. minLength: 1
  30219. pattern: ^[-._a-zA-Z0-9]+$
  30220. type: string
  30221. name:
  30222. description: The name of the Secret resource being referred to.
  30223. maxLength: 253
  30224. minLength: 1
  30225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30226. type: string
  30227. namespace:
  30228. description: |-
  30229. The namespace of the Secret resource being referred to.
  30230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30231. maxLength: 63
  30232. minLength: 1
  30233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30234. type: string
  30235. type: object
  30236. type: object
  30237. workloadIdentity:
  30238. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30239. properties:
  30240. clusterLocation:
  30241. type: string
  30242. clusterName:
  30243. type: string
  30244. clusterProjectID:
  30245. type: string
  30246. serviceAccountRef:
  30247. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30248. properties:
  30249. audiences:
  30250. description: |-
  30251. Audience specifies the `aud` claim for the service account token
  30252. Some providers automatically extend the audience field based on well-known annotations for workload
  30253. identity (e.g. IRSA or GCP Workload Identity)
  30254. items:
  30255. type: string
  30256. type: array
  30257. name:
  30258. description: The name of the ServiceAccount resource being referred to.
  30259. maxLength: 253
  30260. minLength: 1
  30261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30262. type: string
  30263. namespace:
  30264. description: |-
  30265. Namespace of the resource being referred to.
  30266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30267. maxLength: 63
  30268. minLength: 1
  30269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30270. type: string
  30271. required:
  30272. - name
  30273. type: object
  30274. required:
  30275. - clusterLocation
  30276. - clusterName
  30277. - serviceAccountRef
  30278. type: object
  30279. workloadIdentityFederation:
  30280. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30281. properties:
  30282. audience:
  30283. description: |-
  30284. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30285. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30286. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30287. type: string
  30288. awsSecurityCredentials:
  30289. description: |-
  30290. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30291. when using the AWS metadata server is not an option.
  30292. properties:
  30293. awsCredentialsSecretRef:
  30294. description: |-
  30295. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30296. Secret should be created with below names for keys
  30297. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30298. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30299. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30300. properties:
  30301. name:
  30302. description: name of the secret.
  30303. maxLength: 253
  30304. minLength: 1
  30305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30306. type: string
  30307. namespace:
  30308. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30309. maxLength: 63
  30310. minLength: 1
  30311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30312. type: string
  30313. required:
  30314. - name
  30315. type: object
  30316. region:
  30317. description: region is for configuring the AWS region to be used.
  30318. example: ap-south-1
  30319. maxLength: 50
  30320. minLength: 1
  30321. pattern: ^[a-z0-9-]+$
  30322. type: string
  30323. required:
  30324. - awsCredentialsSecretRef
  30325. - region
  30326. type: object
  30327. credConfig:
  30328. description: |-
  30329. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30330. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30331. serviceAccountRef must be used by providing operators service account details.
  30332. properties:
  30333. key:
  30334. description: key name holding the external account credential config.
  30335. maxLength: 253
  30336. minLength: 1
  30337. pattern: ^[-._a-zA-Z0-9]+$
  30338. type: string
  30339. name:
  30340. description: name of the configmap.
  30341. maxLength: 253
  30342. minLength: 1
  30343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30344. type: string
  30345. namespace:
  30346. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30347. maxLength: 63
  30348. minLength: 1
  30349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30350. type: string
  30351. required:
  30352. - key
  30353. - name
  30354. type: object
  30355. externalTokenEndpoint:
  30356. description: |-
  30357. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30358. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30359. URL is having the expected value.
  30360. type: string
  30361. gcpServiceAccountEmail:
  30362. description: |-
  30363. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30364. after Workload Identity Federation. Use this to grant access through the service account's
  30365. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30366. service_account_impersonation_url in the external account JSON from credConfig;
  30367. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30368. on that ServiceAccount.
  30369. example: my-gsa@my-project.iam.gserviceaccount.com
  30370. minLength: 1
  30371. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30372. type: string
  30373. serviceAccountRef:
  30374. description: |-
  30375. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30376. when Kubernetes is configured as provider in workload identity pool.
  30377. properties:
  30378. audiences:
  30379. description: |-
  30380. Audience specifies the `aud` claim for the service account token
  30381. Some providers automatically extend the audience field based on well-known annotations for workload
  30382. identity (e.g. IRSA or GCP Workload Identity)
  30383. items:
  30384. type: string
  30385. type: array
  30386. name:
  30387. description: The name of the ServiceAccount resource being referred to.
  30388. maxLength: 253
  30389. minLength: 1
  30390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30391. type: string
  30392. namespace:
  30393. description: |-
  30394. Namespace of the resource being referred to.
  30395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30396. maxLength: 63
  30397. minLength: 1
  30398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30399. type: string
  30400. required:
  30401. - name
  30402. type: object
  30403. type: object
  30404. type: object
  30405. projectID:
  30406. description: ProjectID defines which project to use to authenticate with
  30407. type: string
  30408. required:
  30409. - auth
  30410. - projectID
  30411. type: object
  30412. type: object
  30413. served: true
  30414. storage: true
  30415. subresources:
  30416. status: {}
  30417. ---
  30418. apiVersion: apiextensions.k8s.io/v1
  30419. kind: CustomResourceDefinition
  30420. metadata:
  30421. annotations:
  30422. controller-gen.kubebuilder.io/version: v0.19.0
  30423. labels:
  30424. external-secrets.io/component: controller
  30425. name: generatorstates.generators.external-secrets.io
  30426. spec:
  30427. group: generators.external-secrets.io
  30428. names:
  30429. categories:
  30430. - external-secrets
  30431. - external-secrets-generators
  30432. kind: GeneratorState
  30433. listKind: GeneratorStateList
  30434. plural: generatorstates
  30435. shortNames:
  30436. - gs
  30437. singular: generatorstate
  30438. scope: Namespaced
  30439. versions:
  30440. - additionalPrinterColumns:
  30441. - jsonPath: .spec.garbageCollectionDeadline
  30442. name: GC Deadline
  30443. type: string
  30444. - jsonPath: .metadata.creationTimestamp
  30445. name: Age
  30446. type: date
  30447. name: v1alpha1
  30448. schema:
  30449. openAPIV3Schema:
  30450. description: GeneratorState represents the state created and managed by a generator resource.
  30451. properties:
  30452. apiVersion:
  30453. description: |-
  30454. APIVersion defines the versioned schema of this representation of an object.
  30455. Servers should convert recognized schemas to the latest internal value, and
  30456. may reject unrecognized values.
  30457. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30458. type: string
  30459. kind:
  30460. description: |-
  30461. Kind is a string value representing the REST resource this object represents.
  30462. Servers may infer this from the endpoint the client submits requests to.
  30463. Cannot be updated.
  30464. In CamelCase.
  30465. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30466. type: string
  30467. metadata:
  30468. type: object
  30469. spec:
  30470. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30471. properties:
  30472. garbageCollectionDeadline:
  30473. description: |-
  30474. GarbageCollectionDeadline is the time after which the generator state
  30475. will be deleted.
  30476. It is set by the controller which creates the generator state and
  30477. can be set configured by the user.
  30478. If the garbage collection deadline is not set the generator state will not be deleted.
  30479. format: date-time
  30480. type: string
  30481. resource:
  30482. description: |-
  30483. Resource is the generator manifest that produced the state.
  30484. It is a snapshot of the generator manifest at the time the state was produced.
  30485. This manifest will be used to delete the resource. Any configuration that is referenced
  30486. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30487. be blocked by a finalizer.
  30488. x-kubernetes-preserve-unknown-fields: true
  30489. state:
  30490. description: State is the state that was produced by the generator implementation.
  30491. x-kubernetes-preserve-unknown-fields: true
  30492. required:
  30493. - resource
  30494. - state
  30495. type: object
  30496. status:
  30497. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30498. properties:
  30499. conditions:
  30500. items:
  30501. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30502. properties:
  30503. lastTransitionTime:
  30504. format: date-time
  30505. type: string
  30506. message:
  30507. type: string
  30508. reason:
  30509. type: string
  30510. status:
  30511. type: string
  30512. type:
  30513. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30514. type: string
  30515. required:
  30516. - status
  30517. - type
  30518. type: object
  30519. type: array
  30520. type: object
  30521. type: object
  30522. served: true
  30523. storage: true
  30524. subresources: {}
  30525. ---
  30526. apiVersion: apiextensions.k8s.io/v1
  30527. kind: CustomResourceDefinition
  30528. metadata:
  30529. annotations:
  30530. controller-gen.kubebuilder.io/version: v0.19.0
  30531. labels:
  30532. external-secrets.io/component: controller
  30533. name: githubaccesstokens.generators.external-secrets.io
  30534. spec:
  30535. group: generators.external-secrets.io
  30536. names:
  30537. categories:
  30538. - external-secrets
  30539. - external-secrets-generators
  30540. kind: GithubAccessToken
  30541. listKind: GithubAccessTokenList
  30542. plural: githubaccesstokens
  30543. singular: githubaccesstoken
  30544. scope: Namespaced
  30545. versions:
  30546. - name: v1alpha1
  30547. schema:
  30548. openAPIV3Schema:
  30549. description: GithubAccessToken generates ghs_ accessToken
  30550. properties:
  30551. apiVersion:
  30552. description: |-
  30553. APIVersion defines the versioned schema of this representation of an object.
  30554. Servers should convert recognized schemas to the latest internal value, and
  30555. may reject unrecognized values.
  30556. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30557. type: string
  30558. kind:
  30559. description: |-
  30560. Kind is a string value representing the REST resource this object represents.
  30561. Servers may infer this from the endpoint the client submits requests to.
  30562. Cannot be updated.
  30563. In CamelCase.
  30564. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30565. type: string
  30566. metadata:
  30567. type: object
  30568. spec:
  30569. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30570. properties:
  30571. appID:
  30572. type: string
  30573. auth:
  30574. description: Auth configures how ESO authenticates with a Github instance.
  30575. properties:
  30576. privateKey:
  30577. description: GithubSecretRef references a secret containing GitHub credentials.
  30578. properties:
  30579. secretRef:
  30580. description: |-
  30581. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30582. In some instances, `key` is a required field.
  30583. properties:
  30584. key:
  30585. description: |-
  30586. A key in the referenced Secret.
  30587. Some instances of this field may be defaulted, in others it may be required.
  30588. maxLength: 253
  30589. minLength: 1
  30590. pattern: ^[-._a-zA-Z0-9]+$
  30591. type: string
  30592. name:
  30593. description: The name of the Secret resource being referred to.
  30594. maxLength: 253
  30595. minLength: 1
  30596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30597. type: string
  30598. namespace:
  30599. description: |-
  30600. The namespace of the Secret resource being referred to.
  30601. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30602. maxLength: 63
  30603. minLength: 1
  30604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30605. type: string
  30606. type: object
  30607. required:
  30608. - secretRef
  30609. type: object
  30610. required:
  30611. - privateKey
  30612. type: object
  30613. installID:
  30614. type: string
  30615. permissions:
  30616. additionalProperties:
  30617. type: string
  30618. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30619. type: object
  30620. repositories:
  30621. description: |-
  30622. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30623. is installed to.
  30624. items:
  30625. type: string
  30626. type: array
  30627. url:
  30628. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30629. type: string
  30630. required:
  30631. - appID
  30632. - auth
  30633. - installID
  30634. type: object
  30635. type: object
  30636. served: true
  30637. storage: true
  30638. subresources:
  30639. status: {}
  30640. ---
  30641. apiVersion: apiextensions.k8s.io/v1
  30642. kind: CustomResourceDefinition
  30643. metadata:
  30644. annotations:
  30645. controller-gen.kubebuilder.io/version: v0.19.0
  30646. labels:
  30647. external-secrets.io/component: controller
  30648. name: gitlabdeploytokens.generators.external-secrets.io
  30649. spec:
  30650. group: generators.external-secrets.io
  30651. names:
  30652. categories:
  30653. - external-secrets
  30654. - external-secrets-generators
  30655. kind: GitlabDeployToken
  30656. listKind: GitlabDeployTokenList
  30657. plural: gitlabdeploytokens
  30658. singular: gitlabdeploytoken
  30659. scope: Namespaced
  30660. versions:
  30661. - name: v1alpha1
  30662. schema:
  30663. openAPIV3Schema:
  30664. description: GitlabDeployToken generates a GitLab deploy token.
  30665. properties:
  30666. apiVersion:
  30667. description: |-
  30668. APIVersion defines the versioned schema of this representation of an object.
  30669. Servers should convert recognized schemas to the latest internal value, and
  30670. may reject unrecognized values.
  30671. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30672. type: string
  30673. kind:
  30674. description: |-
  30675. Kind is a string value representing the REST resource this object represents.
  30676. Servers may infer this from the endpoint the client submits requests to.
  30677. Cannot be updated.
  30678. In CamelCase.
  30679. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30680. type: string
  30681. metadata:
  30682. type: object
  30683. spec:
  30684. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30685. properties:
  30686. auth:
  30687. description: Auth configures how ESO authenticates with the GitLab API.
  30688. properties:
  30689. token:
  30690. description: |-
  30691. Token references a secret containing a GitLab access token (personal, group, or
  30692. project) with the api scope and at least the Maintainer role on the target.
  30693. properties:
  30694. secretRef:
  30695. description: |-
  30696. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30697. In some instances, `key` is a required field.
  30698. properties:
  30699. key:
  30700. description: |-
  30701. A key in the referenced Secret.
  30702. Some instances of this field may be defaulted, in others it may be required.
  30703. maxLength: 253
  30704. minLength: 1
  30705. pattern: ^[-._a-zA-Z0-9]+$
  30706. type: string
  30707. name:
  30708. description: The name of the Secret resource being referred to.
  30709. maxLength: 253
  30710. minLength: 1
  30711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30712. type: string
  30713. namespace:
  30714. description: |-
  30715. The namespace of the Secret resource being referred to.
  30716. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30717. maxLength: 63
  30718. minLength: 1
  30719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30720. type: string
  30721. type: object
  30722. required:
  30723. - secretRef
  30724. type: object
  30725. required:
  30726. - token
  30727. type: object
  30728. expiresAt:
  30729. description: |-
  30730. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30731. not expire on the GitLab side and is revoked only when the generator state is
  30732. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30733. format: date-time
  30734. type: string
  30735. groupID:
  30736. description: |-
  30737. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30738. create the deploy token in. The generator URL-escapes paths before calling the
  30739. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30740. minLength: 1
  30741. type: string
  30742. name:
  30743. description: Name of the deploy token.
  30744. minLength: 1
  30745. type: string
  30746. projectID:
  30747. description: |-
  30748. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30749. project to create the deploy token in. The generator URL-escapes paths before
  30750. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30751. minLength: 1
  30752. type: string
  30753. scopes:
  30754. description: Scopes granted to the deploy token. At least one scope is required.
  30755. items:
  30756. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30757. enum:
  30758. - read_repository
  30759. - read_registry
  30760. - write_registry
  30761. - read_package_registry
  30762. - write_package_registry
  30763. - read_virtual_registry
  30764. - write_virtual_registry
  30765. type: string
  30766. minItems: 1
  30767. type: array
  30768. url:
  30769. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30770. type: string
  30771. username:
  30772. description: |-
  30773. Username is an optional username for the deploy token. GitLab defaults it to
  30774. gitlab+deploy-token-{n} when omitted.
  30775. type: string
  30776. required:
  30777. - auth
  30778. - name
  30779. - scopes
  30780. type: object
  30781. x-kubernetes-validations:
  30782. - message: exactly one of projectID or groupID must be set
  30783. rule: has(self.projectID) != has(self.groupID)
  30784. type: object
  30785. served: true
  30786. storage: true
  30787. subresources:
  30788. status: {}
  30789. ---
  30790. apiVersion: apiextensions.k8s.io/v1
  30791. kind: CustomResourceDefinition
  30792. metadata:
  30793. annotations:
  30794. controller-gen.kubebuilder.io/version: v0.19.0
  30795. labels:
  30796. external-secrets.io/component: controller
  30797. name: grafanas.generators.external-secrets.io
  30798. spec:
  30799. group: generators.external-secrets.io
  30800. names:
  30801. categories:
  30802. - external-secrets
  30803. - external-secrets-generators
  30804. kind: Grafana
  30805. listKind: GrafanaList
  30806. plural: grafanas
  30807. singular: grafana
  30808. scope: Namespaced
  30809. versions:
  30810. - name: v1alpha1
  30811. schema:
  30812. openAPIV3Schema:
  30813. description: Grafana represents a generator for Grafana service account tokens.
  30814. properties:
  30815. apiVersion:
  30816. description: |-
  30817. APIVersion defines the versioned schema of this representation of an object.
  30818. Servers should convert recognized schemas to the latest internal value, and
  30819. may reject unrecognized values.
  30820. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30821. type: string
  30822. kind:
  30823. description: |-
  30824. Kind is a string value representing the REST resource this object represents.
  30825. Servers may infer this from the endpoint the client submits requests to.
  30826. Cannot be updated.
  30827. In CamelCase.
  30828. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30829. type: string
  30830. metadata:
  30831. type: object
  30832. spec:
  30833. description: GrafanaSpec controls the behavior of the grafana generator.
  30834. properties:
  30835. auth:
  30836. description: |-
  30837. Auth is the authentication configuration to authenticate
  30838. against the Grafana instance.
  30839. properties:
  30840. basic:
  30841. description: |-
  30842. Basic auth credentials used to authenticate against the Grafana instance.
  30843. Note: you need a token which has elevated permissions to create service accounts.
  30844. See here for the documentation on basic roles offered by Grafana:
  30845. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30846. properties:
  30847. password:
  30848. description: A basic auth password used to authenticate against the Grafana instance.
  30849. properties:
  30850. key:
  30851. description: The key where the token is found.
  30852. maxLength: 253
  30853. minLength: 1
  30854. pattern: ^[-._a-zA-Z0-9]+$
  30855. type: string
  30856. name:
  30857. description: The name of the Secret resource being referred to.
  30858. maxLength: 253
  30859. minLength: 1
  30860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30861. type: string
  30862. type: object
  30863. username:
  30864. description: A basic auth username used to authenticate against the Grafana instance.
  30865. type: string
  30866. required:
  30867. - password
  30868. - username
  30869. type: object
  30870. token:
  30871. description: |-
  30872. A service account token used to authenticate against the Grafana instance.
  30873. Note: you need a token which has elevated permissions to create service accounts.
  30874. See here for the documentation on basic roles offered by Grafana:
  30875. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30876. properties:
  30877. key:
  30878. description: The key where the token is found.
  30879. maxLength: 253
  30880. minLength: 1
  30881. pattern: ^[-._a-zA-Z0-9]+$
  30882. type: string
  30883. name:
  30884. description: The name of the Secret resource being referred to.
  30885. maxLength: 253
  30886. minLength: 1
  30887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30888. type: string
  30889. type: object
  30890. type: object
  30891. serviceAccount:
  30892. description: |-
  30893. ServiceAccount is the configuration for the service account that
  30894. is supposed to be generated by the generator.
  30895. properties:
  30896. name:
  30897. description: Name is the name of the service account that will be created by ESO.
  30898. type: string
  30899. role:
  30900. description: |-
  30901. Role is the role of the service account.
  30902. See here for the documentation on basic roles offered by Grafana:
  30903. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30904. type: string
  30905. secondsToLive:
  30906. description: |-
  30907. SecondsToLive is the number of seconds before the generated service account token will expire.
  30908. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30909. format: int64
  30910. minimum: 1
  30911. type: integer
  30912. required:
  30913. - name
  30914. - role
  30915. type: object
  30916. url:
  30917. description: URL is the URL of the Grafana instance.
  30918. type: string
  30919. required:
  30920. - auth
  30921. - serviceAccount
  30922. - url
  30923. type: object
  30924. type: object
  30925. served: true
  30926. storage: true
  30927. subresources:
  30928. status: {}
  30929. ---
  30930. apiVersion: apiextensions.k8s.io/v1
  30931. kind: CustomResourceDefinition
  30932. metadata:
  30933. annotations:
  30934. controller-gen.kubebuilder.io/version: v0.19.0
  30935. labels:
  30936. external-secrets.io/component: controller
  30937. name: mfas.generators.external-secrets.io
  30938. spec:
  30939. group: generators.external-secrets.io
  30940. names:
  30941. categories:
  30942. - external-secrets
  30943. - external-secrets-generators
  30944. kind: MFA
  30945. listKind: MFAList
  30946. plural: mfas
  30947. singular: mfa
  30948. scope: Namespaced
  30949. versions:
  30950. - name: v1alpha1
  30951. schema:
  30952. openAPIV3Schema:
  30953. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30954. properties:
  30955. apiVersion:
  30956. description: |-
  30957. APIVersion defines the versioned schema of this representation of an object.
  30958. Servers should convert recognized schemas to the latest internal value, and
  30959. may reject unrecognized values.
  30960. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30961. type: string
  30962. kind:
  30963. description: |-
  30964. Kind is a string value representing the REST resource this object represents.
  30965. Servers may infer this from the endpoint the client submits requests to.
  30966. Cannot be updated.
  30967. In CamelCase.
  30968. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30969. type: string
  30970. metadata:
  30971. type: object
  30972. spec:
  30973. description: MFASpec controls the behavior of the mfa generator.
  30974. properties:
  30975. algorithm:
  30976. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30977. type: string
  30978. length:
  30979. description: Length defines the token length. Defaults to 6 characters.
  30980. type: integer
  30981. secret:
  30982. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30983. properties:
  30984. key:
  30985. description: |-
  30986. A key in the referenced Secret.
  30987. Some instances of this field may be defaulted, in others it may be required.
  30988. maxLength: 253
  30989. minLength: 1
  30990. pattern: ^[-._a-zA-Z0-9]+$
  30991. type: string
  30992. name:
  30993. description: The name of the Secret resource being referred to.
  30994. maxLength: 253
  30995. minLength: 1
  30996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30997. type: string
  30998. namespace:
  30999. description: |-
  31000. The namespace of the Secret resource being referred to.
  31001. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31002. maxLength: 63
  31003. minLength: 1
  31004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31005. type: string
  31006. type: object
  31007. timePeriod:
  31008. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  31009. type: integer
  31010. when:
  31011. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  31012. format: date-time
  31013. type: string
  31014. required:
  31015. - secret
  31016. type: object
  31017. type: object
  31018. served: true
  31019. storage: true
  31020. subresources:
  31021. status: {}
  31022. ---
  31023. apiVersion: apiextensions.k8s.io/v1
  31024. kind: CustomResourceDefinition
  31025. metadata:
  31026. annotations:
  31027. controller-gen.kubebuilder.io/version: v0.19.0
  31028. labels:
  31029. external-secrets.io/component: controller
  31030. name: passwords.generators.external-secrets.io
  31031. spec:
  31032. group: generators.external-secrets.io
  31033. names:
  31034. categories:
  31035. - external-secrets
  31036. - external-secrets-generators
  31037. kind: Password
  31038. listKind: PasswordList
  31039. plural: passwords
  31040. singular: password
  31041. scope: Namespaced
  31042. versions:
  31043. - name: v1alpha1
  31044. schema:
  31045. openAPIV3Schema:
  31046. description: |-
  31047. Password generates a random password based on the
  31048. configuration parameters in spec.
  31049. You can specify the length, characterset and other attributes.
  31050. properties:
  31051. apiVersion:
  31052. description: |-
  31053. APIVersion defines the versioned schema of this representation of an object.
  31054. Servers should convert recognized schemas to the latest internal value, and
  31055. may reject unrecognized values.
  31056. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31057. type: string
  31058. kind:
  31059. description: |-
  31060. Kind is a string value representing the REST resource this object represents.
  31061. Servers may infer this from the endpoint the client submits requests to.
  31062. Cannot be updated.
  31063. In CamelCase.
  31064. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31065. type: string
  31066. metadata:
  31067. type: object
  31068. spec:
  31069. description: PasswordSpec controls the behavior of the password generator.
  31070. properties:
  31071. allowRepeat:
  31072. default: false
  31073. description: set AllowRepeat to true to allow repeating characters.
  31074. type: boolean
  31075. digits:
  31076. description: |-
  31077. Digits specifies the number of digits in the generated
  31078. password. If omitted it defaults to 25% of the length of the password
  31079. type: integer
  31080. encoding:
  31081. default: raw
  31082. description: |-
  31083. Encoding specifies the encoding of the generated password.
  31084. Valid values are:
  31085. - "raw" (default): no encoding
  31086. - "base64": standard base64 encoding
  31087. - "base64url": base64url encoding
  31088. - "base32": base32 encoding
  31089. - "hex": hexadecimal encoding
  31090. enum:
  31091. - base64
  31092. - base64url
  31093. - base32
  31094. - hex
  31095. - raw
  31096. type: string
  31097. length:
  31098. default: 24
  31099. description: |-
  31100. Length of the password to be generated.
  31101. Defaults to 24
  31102. type: integer
  31103. noUpper:
  31104. default: false
  31105. description: Set NoUpper to disable uppercase characters
  31106. type: boolean
  31107. secretKeys:
  31108. description: |-
  31109. SecretKeys defines the keys that will be populated with generated passwords.
  31110. Defaults to "password" when not set.
  31111. items:
  31112. type: string
  31113. minItems: 1
  31114. type: array
  31115. symbolCharacters:
  31116. description: |-
  31117. SymbolCharacters specifies the special characters that should be used
  31118. in the generated password.
  31119. type: string
  31120. symbols:
  31121. description: |-
  31122. Symbols specifies the number of symbol characters in the generated
  31123. password. If omitted it defaults to 25% of the length of the password
  31124. type: integer
  31125. required:
  31126. - allowRepeat
  31127. - length
  31128. - noUpper
  31129. type: object
  31130. type: object
  31131. served: true
  31132. storage: true
  31133. subresources:
  31134. status: {}
  31135. ---
  31136. apiVersion: apiextensions.k8s.io/v1
  31137. kind: CustomResourceDefinition
  31138. metadata:
  31139. annotations:
  31140. controller-gen.kubebuilder.io/version: v0.19.0
  31141. labels:
  31142. external-secrets.io/component: controller
  31143. name: quayaccesstokens.generators.external-secrets.io
  31144. spec:
  31145. group: generators.external-secrets.io
  31146. names:
  31147. categories:
  31148. - external-secrets
  31149. - external-secrets-generators
  31150. kind: QuayAccessToken
  31151. listKind: QuayAccessTokenList
  31152. plural: quayaccesstokens
  31153. singular: quayaccesstoken
  31154. scope: Namespaced
  31155. versions:
  31156. - name: v1alpha1
  31157. schema:
  31158. openAPIV3Schema:
  31159. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  31160. properties:
  31161. apiVersion:
  31162. description: |-
  31163. APIVersion defines the versioned schema of this representation of an object.
  31164. Servers should convert recognized schemas to the latest internal value, and
  31165. may reject unrecognized values.
  31166. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31167. type: string
  31168. kind:
  31169. description: |-
  31170. Kind is a string value representing the REST resource this object represents.
  31171. Servers may infer this from the endpoint the client submits requests to.
  31172. Cannot be updated.
  31173. In CamelCase.
  31174. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31175. type: string
  31176. metadata:
  31177. type: object
  31178. spec:
  31179. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  31180. properties:
  31181. robotAccount:
  31182. description: Name of the robot account you are federating with
  31183. type: string
  31184. serviceAccountRef:
  31185. description: Name of the service account you are federating with
  31186. properties:
  31187. audiences:
  31188. description: |-
  31189. Audience specifies the `aud` claim for the service account token
  31190. Some providers automatically extend the audience field based on well-known annotations for workload
  31191. identity (e.g. IRSA or GCP Workload Identity)
  31192. items:
  31193. type: string
  31194. type: array
  31195. name:
  31196. description: The name of the ServiceAccount resource being referred to.
  31197. maxLength: 253
  31198. minLength: 1
  31199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31200. type: string
  31201. namespace:
  31202. description: |-
  31203. Namespace of the resource being referred to.
  31204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31205. maxLength: 63
  31206. minLength: 1
  31207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31208. type: string
  31209. required:
  31210. - name
  31211. type: object
  31212. url:
  31213. description: URL configures the Quay instance URL. Defaults to quay.io.
  31214. type: string
  31215. required:
  31216. - robotAccount
  31217. - serviceAccountRef
  31218. type: object
  31219. type: object
  31220. served: true
  31221. storage: true
  31222. subresources:
  31223. status: {}
  31224. ---
  31225. apiVersion: apiextensions.k8s.io/v1
  31226. kind: CustomResourceDefinition
  31227. metadata:
  31228. annotations:
  31229. controller-gen.kubebuilder.io/version: v0.19.0
  31230. labels:
  31231. external-secrets.io/component: controller
  31232. name: sshkeys.generators.external-secrets.io
  31233. spec:
  31234. group: generators.external-secrets.io
  31235. names:
  31236. categories:
  31237. - external-secrets
  31238. - external-secrets-generators
  31239. kind: SSHKey
  31240. listKind: SSHKeyList
  31241. plural: sshkeys
  31242. singular: sshkey
  31243. scope: Namespaced
  31244. versions:
  31245. - name: v1alpha1
  31246. schema:
  31247. openAPIV3Schema:
  31248. description: SSHKey generates SSH key pairs.
  31249. properties:
  31250. apiVersion:
  31251. description: |-
  31252. APIVersion defines the versioned schema of this representation of an object.
  31253. Servers should convert recognized schemas to the latest internal value, and
  31254. may reject unrecognized values.
  31255. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31256. type: string
  31257. kind:
  31258. description: |-
  31259. Kind is a string value representing the REST resource this object represents.
  31260. Servers may infer this from the endpoint the client submits requests to.
  31261. Cannot be updated.
  31262. In CamelCase.
  31263. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31264. type: string
  31265. metadata:
  31266. type: object
  31267. spec:
  31268. description: SSHKeySpec controls the behavior of the ssh key generator.
  31269. properties:
  31270. comment:
  31271. description: Comment specifies an optional comment for the SSH key
  31272. type: string
  31273. keySize:
  31274. description: |-
  31275. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31276. For RSA keys: 2048, 3072, 4096
  31277. For ECDSA keys: 256, 384, 521
  31278. Ignored for ed25519 keys
  31279. maximum: 8192
  31280. minimum: 256
  31281. type: integer
  31282. keyType:
  31283. default: rsa
  31284. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31285. enum:
  31286. - rsa
  31287. - ecdsa
  31288. - ed25519
  31289. type: string
  31290. type: object
  31291. type: object
  31292. served: true
  31293. storage: true
  31294. subresources:
  31295. status: {}
  31296. ---
  31297. apiVersion: apiextensions.k8s.io/v1
  31298. kind: CustomResourceDefinition
  31299. metadata:
  31300. annotations:
  31301. controller-gen.kubebuilder.io/version: v0.19.0
  31302. labels:
  31303. external-secrets.io/component: controller
  31304. name: stssessiontokens.generators.external-secrets.io
  31305. spec:
  31306. group: generators.external-secrets.io
  31307. names:
  31308. categories:
  31309. - external-secrets
  31310. - external-secrets-generators
  31311. kind: STSSessionToken
  31312. listKind: STSSessionTokenList
  31313. plural: stssessiontokens
  31314. singular: stssessiontoken
  31315. scope: Namespaced
  31316. versions:
  31317. - name: v1alpha1
  31318. schema:
  31319. openAPIV3Schema:
  31320. description: |-
  31321. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31322. The authorization token is valid for 12 hours.
  31323. The authorizationToken returned is a base64 encoded string that can be decoded.
  31324. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31325. properties:
  31326. apiVersion:
  31327. description: |-
  31328. APIVersion defines the versioned schema of this representation of an object.
  31329. Servers should convert recognized schemas to the latest internal value, and
  31330. may reject unrecognized values.
  31331. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31332. type: string
  31333. kind:
  31334. description: |-
  31335. Kind is a string value representing the REST resource this object represents.
  31336. Servers may infer this from the endpoint the client submits requests to.
  31337. Cannot be updated.
  31338. In CamelCase.
  31339. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31340. type: string
  31341. metadata:
  31342. type: object
  31343. spec:
  31344. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31345. properties:
  31346. auth:
  31347. description: Auth defines how to authenticate with AWS
  31348. properties:
  31349. jwt:
  31350. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31351. properties:
  31352. serviceAccountRef:
  31353. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31354. properties:
  31355. audiences:
  31356. description: |-
  31357. Audience specifies the `aud` claim for the service account token
  31358. Some providers automatically extend the audience field based on well-known annotations for workload
  31359. identity (e.g. IRSA or GCP Workload Identity)
  31360. items:
  31361. type: string
  31362. type: array
  31363. name:
  31364. description: The name of the ServiceAccount resource being referred to.
  31365. maxLength: 253
  31366. minLength: 1
  31367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31368. type: string
  31369. namespace:
  31370. description: |-
  31371. Namespace of the resource being referred to.
  31372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31373. maxLength: 63
  31374. minLength: 1
  31375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31376. type: string
  31377. required:
  31378. - name
  31379. type: object
  31380. type: object
  31381. secretRef:
  31382. description: |-
  31383. AWSAuthSecretRef holds secret references for AWS credentials
  31384. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31385. properties:
  31386. accessKeyIDSecretRef:
  31387. description: The AccessKeyID is used for authentication
  31388. properties:
  31389. key:
  31390. description: |-
  31391. A key in the referenced Secret.
  31392. Some instances of this field may be defaulted, in others it may be required.
  31393. maxLength: 253
  31394. minLength: 1
  31395. pattern: ^[-._a-zA-Z0-9]+$
  31396. type: string
  31397. name:
  31398. description: The name of the Secret resource being referred to.
  31399. maxLength: 253
  31400. minLength: 1
  31401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31402. type: string
  31403. namespace:
  31404. description: |-
  31405. The namespace of the Secret resource being referred to.
  31406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31407. maxLength: 63
  31408. minLength: 1
  31409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31410. type: string
  31411. type: object
  31412. secretAccessKeySecretRef:
  31413. description: The SecretAccessKey is used for authentication
  31414. properties:
  31415. key:
  31416. description: |-
  31417. A key in the referenced Secret.
  31418. Some instances of this field may be defaulted, in others it may be required.
  31419. maxLength: 253
  31420. minLength: 1
  31421. pattern: ^[-._a-zA-Z0-9]+$
  31422. type: string
  31423. name:
  31424. description: The name of the Secret resource being referred to.
  31425. maxLength: 253
  31426. minLength: 1
  31427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31428. type: string
  31429. namespace:
  31430. description: |-
  31431. The namespace of the Secret resource being referred to.
  31432. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31433. maxLength: 63
  31434. minLength: 1
  31435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31436. type: string
  31437. type: object
  31438. sessionTokenSecretRef:
  31439. description: |-
  31440. The SessionToken used for authentication
  31441. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31442. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31443. properties:
  31444. key:
  31445. description: |-
  31446. A key in the referenced Secret.
  31447. Some instances of this field may be defaulted, in others it may be required.
  31448. maxLength: 253
  31449. minLength: 1
  31450. pattern: ^[-._a-zA-Z0-9]+$
  31451. type: string
  31452. name:
  31453. description: The name of the Secret resource being referred to.
  31454. maxLength: 253
  31455. minLength: 1
  31456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31457. type: string
  31458. namespace:
  31459. description: |-
  31460. The namespace of the Secret resource being referred to.
  31461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31462. maxLength: 63
  31463. minLength: 1
  31464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31465. type: string
  31466. type: object
  31467. type: object
  31468. type: object
  31469. region:
  31470. description: Region specifies the region to operate in.
  31471. type: string
  31472. requestParameters:
  31473. description: RequestParameters contains parameters that can be passed to the STS service.
  31474. properties:
  31475. serialNumber:
  31476. description: |-
  31477. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31478. the GetSessionToken call.
  31479. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31480. (such as arn:aws:iam::123456789012:mfa/user)
  31481. type: string
  31482. sessionDuration:
  31483. format: int32
  31484. type: integer
  31485. tokenCode:
  31486. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31487. type: string
  31488. type: object
  31489. role:
  31490. description: |-
  31491. You can assume a role before making calls to the
  31492. desired AWS service.
  31493. type: string
  31494. required:
  31495. - region
  31496. type: object
  31497. type: object
  31498. served: true
  31499. storage: true
  31500. subresources:
  31501. status: {}
  31502. ---
  31503. apiVersion: apiextensions.k8s.io/v1
  31504. kind: CustomResourceDefinition
  31505. metadata:
  31506. annotations:
  31507. controller-gen.kubebuilder.io/version: v0.19.0
  31508. labels:
  31509. external-secrets.io/component: controller
  31510. name: uuids.generators.external-secrets.io
  31511. spec:
  31512. group: generators.external-secrets.io
  31513. names:
  31514. categories:
  31515. - external-secrets
  31516. - external-secrets-generators
  31517. kind: UUID
  31518. listKind: UUIDList
  31519. plural: uuids
  31520. singular: uuid
  31521. scope: Namespaced
  31522. versions:
  31523. - name: v1alpha1
  31524. schema:
  31525. openAPIV3Schema:
  31526. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31527. properties:
  31528. apiVersion:
  31529. description: |-
  31530. APIVersion defines the versioned schema of this representation of an object.
  31531. Servers should convert recognized schemas to the latest internal value, and
  31532. may reject unrecognized values.
  31533. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31534. type: string
  31535. kind:
  31536. description: |-
  31537. Kind is a string value representing the REST resource this object represents.
  31538. Servers may infer this from the endpoint the client submits requests to.
  31539. Cannot be updated.
  31540. In CamelCase.
  31541. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31542. type: string
  31543. metadata:
  31544. type: object
  31545. spec:
  31546. description: UUIDSpec controls the behavior of the uuid generator.
  31547. type: object
  31548. type: object
  31549. served: true
  31550. storage: true
  31551. subresources:
  31552. status: {}
  31553. ---
  31554. apiVersion: apiextensions.k8s.io/v1
  31555. kind: CustomResourceDefinition
  31556. metadata:
  31557. annotations:
  31558. controller-gen.kubebuilder.io/version: v0.19.0
  31559. labels:
  31560. external-secrets.io/component: controller
  31561. name: vaultdynamicsecrets.generators.external-secrets.io
  31562. spec:
  31563. group: generators.external-secrets.io
  31564. names:
  31565. categories:
  31566. - external-secrets
  31567. - external-secrets-generators
  31568. kind: VaultDynamicSecret
  31569. listKind: VaultDynamicSecretList
  31570. plural: vaultdynamicsecrets
  31571. singular: vaultdynamicsecret
  31572. scope: Namespaced
  31573. versions:
  31574. - name: v1alpha1
  31575. schema:
  31576. openAPIV3Schema:
  31577. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31578. properties:
  31579. apiVersion:
  31580. description: |-
  31581. APIVersion defines the versioned schema of this representation of an object.
  31582. Servers should convert recognized schemas to the latest internal value, and
  31583. may reject unrecognized values.
  31584. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31585. type: string
  31586. kind:
  31587. description: |-
  31588. Kind is a string value representing the REST resource this object represents.
  31589. Servers may infer this from the endpoint the client submits requests to.
  31590. Cannot be updated.
  31591. In CamelCase.
  31592. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31593. type: string
  31594. metadata:
  31595. type: object
  31596. spec:
  31597. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31598. properties:
  31599. allowEmptyResponse:
  31600. default: false
  31601. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31602. type: boolean
  31603. controller:
  31604. description: |-
  31605. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31606. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31607. type: string
  31608. getParameters:
  31609. additionalProperties:
  31610. items:
  31611. type: string
  31612. type: array
  31613. description: |-
  31614. GetParameters are query-string parameters passed to Vault on GET calls.
  31615. Each key may map to multiple values, matching HTTP query-string semantics.
  31616. Ignored for non-GET methods; use Parameters for write bodies.
  31617. type: object
  31618. method:
  31619. description: Vault API method to use (GET/POST/other)
  31620. type: string
  31621. parameters:
  31622. description: Parameters to pass to Vault write (for non-GET methods)
  31623. x-kubernetes-preserve-unknown-fields: true
  31624. path:
  31625. description: Vault path to obtain the dynamic secret from
  31626. type: string
  31627. provider:
  31628. description: Vault provider common spec
  31629. properties:
  31630. auth:
  31631. description: Auth configures how secret-manager authenticates with the Vault server.
  31632. properties:
  31633. appRole:
  31634. description: |-
  31635. AppRole authenticates with Vault using the App Role auth mechanism,
  31636. with the role and secret stored in a Kubernetes Secret resource.
  31637. properties:
  31638. path:
  31639. default: approle
  31640. description: |-
  31641. Path where the App Role authentication backend is mounted
  31642. in Vault, e.g: "approle"
  31643. type: string
  31644. roleId:
  31645. description: |-
  31646. RoleID configured in the App Role authentication backend when setting
  31647. up the authentication backend in Vault.
  31648. type: string
  31649. roleRef:
  31650. description: |-
  31651. Reference to a key in a Secret that contains the App Role ID used
  31652. to authenticate with Vault.
  31653. The `key` field must be specified and denotes which entry within the Secret
  31654. resource is used as the app role id.
  31655. properties:
  31656. key:
  31657. description: |-
  31658. A key in the referenced Secret.
  31659. Some instances of this field may be defaulted, in others it may be required.
  31660. maxLength: 253
  31661. minLength: 1
  31662. pattern: ^[-._a-zA-Z0-9]+$
  31663. type: string
  31664. name:
  31665. description: The name of the Secret resource being referred to.
  31666. maxLength: 253
  31667. minLength: 1
  31668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31669. type: string
  31670. namespace:
  31671. description: |-
  31672. The namespace of the Secret resource being referred to.
  31673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31674. maxLength: 63
  31675. minLength: 1
  31676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31677. type: string
  31678. type: object
  31679. secretRef:
  31680. description: |-
  31681. Reference to a key in a Secret that contains the App Role secret used
  31682. to authenticate with Vault.
  31683. The `key` field must be specified and denotes which entry within the Secret
  31684. resource is used as the app role secret.
  31685. properties:
  31686. key:
  31687. description: |-
  31688. A key in the referenced Secret.
  31689. Some instances of this field may be defaulted, in others it may be required.
  31690. maxLength: 253
  31691. minLength: 1
  31692. pattern: ^[-._a-zA-Z0-9]+$
  31693. type: string
  31694. name:
  31695. description: The name of the Secret resource being referred to.
  31696. maxLength: 253
  31697. minLength: 1
  31698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31699. type: string
  31700. namespace:
  31701. description: |-
  31702. The namespace of the Secret resource being referred to.
  31703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31704. maxLength: 63
  31705. minLength: 1
  31706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31707. type: string
  31708. type: object
  31709. required:
  31710. - path
  31711. - secretRef
  31712. type: object
  31713. cert:
  31714. description: |-
  31715. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31716. Cert authentication method
  31717. properties:
  31718. clientCert:
  31719. description: |-
  31720. ClientCert is a certificate to authenticate using the Cert Vault
  31721. authentication method
  31722. properties:
  31723. key:
  31724. description: |-
  31725. A key in the referenced Secret.
  31726. Some instances of this field may be defaulted, in others it may be required.
  31727. maxLength: 253
  31728. minLength: 1
  31729. pattern: ^[-._a-zA-Z0-9]+$
  31730. type: string
  31731. name:
  31732. description: The name of the Secret resource being referred to.
  31733. maxLength: 253
  31734. minLength: 1
  31735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31736. type: string
  31737. namespace:
  31738. description: |-
  31739. The namespace of the Secret resource being referred to.
  31740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31741. maxLength: 63
  31742. minLength: 1
  31743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31744. type: string
  31745. type: object
  31746. path:
  31747. default: cert
  31748. description: |-
  31749. Path where the Certificate authentication backend is mounted
  31750. in Vault, e.g: "cert"
  31751. type: string
  31752. secretRef:
  31753. description: |-
  31754. SecretRef to a key in a Secret resource containing client private key to
  31755. authenticate with Vault using the Cert authentication method
  31756. properties:
  31757. key:
  31758. description: |-
  31759. A key in the referenced Secret.
  31760. Some instances of this field may be defaulted, in others it may be required.
  31761. maxLength: 253
  31762. minLength: 1
  31763. pattern: ^[-._a-zA-Z0-9]+$
  31764. type: string
  31765. name:
  31766. description: The name of the Secret resource being referred to.
  31767. maxLength: 253
  31768. minLength: 1
  31769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31770. type: string
  31771. namespace:
  31772. description: |-
  31773. The namespace of the Secret resource being referred to.
  31774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31775. maxLength: 63
  31776. minLength: 1
  31777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31778. type: string
  31779. type: object
  31780. vaultRole:
  31781. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31782. type: string
  31783. type: object
  31784. gcp:
  31785. description: |-
  31786. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31787. GCP authentication method
  31788. properties:
  31789. location:
  31790. description: Location optionally defines a location/region for the secret
  31791. type: string
  31792. path:
  31793. default: gcp
  31794. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31795. type: string
  31796. projectID:
  31797. description: Project ID of the Google Cloud Platform project
  31798. type: string
  31799. role:
  31800. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31801. type: string
  31802. secretRef:
  31803. description: Specify credentials in a Secret object
  31804. properties:
  31805. secretAccessKeySecretRef:
  31806. description: The SecretAccessKey is used for authentication
  31807. properties:
  31808. key:
  31809. description: |-
  31810. A key in the referenced Secret.
  31811. Some instances of this field may be defaulted, in others it may be required.
  31812. maxLength: 253
  31813. minLength: 1
  31814. pattern: ^[-._a-zA-Z0-9]+$
  31815. type: string
  31816. name:
  31817. description: The name of the Secret resource being referred to.
  31818. maxLength: 253
  31819. minLength: 1
  31820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31821. type: string
  31822. namespace:
  31823. description: |-
  31824. The namespace of the Secret resource being referred to.
  31825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31826. maxLength: 63
  31827. minLength: 1
  31828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31829. type: string
  31830. type: object
  31831. type: object
  31832. serviceAccountRef:
  31833. description: ServiceAccountRef to a service account for impersonation
  31834. properties:
  31835. audiences:
  31836. description: |-
  31837. Audience specifies the `aud` claim for the service account token
  31838. Some providers automatically extend the audience field based on well-known annotations for workload
  31839. identity (e.g. IRSA or GCP Workload Identity)
  31840. items:
  31841. type: string
  31842. type: array
  31843. name:
  31844. description: The name of the ServiceAccount resource being referred to.
  31845. maxLength: 253
  31846. minLength: 1
  31847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31848. type: string
  31849. namespace:
  31850. description: |-
  31851. Namespace of the resource being referred to.
  31852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31853. maxLength: 63
  31854. minLength: 1
  31855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31856. type: string
  31857. required:
  31858. - name
  31859. type: object
  31860. workloadIdentity:
  31861. description: Specify a service account with Workload Identity
  31862. properties:
  31863. clusterLocation:
  31864. description: |-
  31865. ClusterLocation is the location of the cluster
  31866. If not specified, it fetches information from the metadata server
  31867. type: string
  31868. clusterName:
  31869. description: |-
  31870. ClusterName is the name of the cluster
  31871. If not specified, it fetches information from the metadata server
  31872. type: string
  31873. clusterProjectID:
  31874. description: |-
  31875. ClusterProjectID is the project ID of the cluster
  31876. If not specified, it fetches information from the metadata server
  31877. type: string
  31878. serviceAccountRef:
  31879. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31880. properties:
  31881. audiences:
  31882. description: |-
  31883. Audience specifies the `aud` claim for the service account token
  31884. Some providers automatically extend the audience field based on well-known annotations for workload
  31885. identity (e.g. IRSA or GCP Workload Identity)
  31886. items:
  31887. type: string
  31888. type: array
  31889. name:
  31890. description: The name of the ServiceAccount resource being referred to.
  31891. maxLength: 253
  31892. minLength: 1
  31893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31894. type: string
  31895. namespace:
  31896. description: |-
  31897. Namespace of the resource being referred to.
  31898. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31899. maxLength: 63
  31900. minLength: 1
  31901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31902. type: string
  31903. required:
  31904. - name
  31905. type: object
  31906. required:
  31907. - serviceAccountRef
  31908. type: object
  31909. required:
  31910. - role
  31911. type: object
  31912. iam:
  31913. description: |-
  31914. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31915. AWS IAM authentication method
  31916. properties:
  31917. externalID:
  31918. description: AWS External ID set on assumed IAM roles
  31919. type: string
  31920. jwt:
  31921. description: Specify a service account with IRSA enabled
  31922. properties:
  31923. serviceAccountRef:
  31924. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31925. properties:
  31926. audiences:
  31927. description: |-
  31928. Audience specifies the `aud` claim for the service account token
  31929. Some providers automatically extend the audience field based on well-known annotations for workload
  31930. identity (e.g. IRSA or GCP Workload Identity)
  31931. items:
  31932. type: string
  31933. type: array
  31934. name:
  31935. description: The name of the ServiceAccount resource being referred to.
  31936. maxLength: 253
  31937. minLength: 1
  31938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31939. type: string
  31940. namespace:
  31941. description: |-
  31942. Namespace of the resource being referred to.
  31943. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31944. maxLength: 63
  31945. minLength: 1
  31946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31947. type: string
  31948. required:
  31949. - name
  31950. type: object
  31951. type: object
  31952. path:
  31953. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31954. type: string
  31955. region:
  31956. description: AWS region
  31957. type: string
  31958. role:
  31959. description: This is the AWS role to be assumed before talking to vault
  31960. type: string
  31961. secretRef:
  31962. description: Specify credentials in a Secret object
  31963. properties:
  31964. accessKeyIDSecretRef:
  31965. description: The AccessKeyID is used for authentication
  31966. properties:
  31967. key:
  31968. description: |-
  31969. A key in the referenced Secret.
  31970. Some instances of this field may be defaulted, in others it may be required.
  31971. maxLength: 253
  31972. minLength: 1
  31973. pattern: ^[-._a-zA-Z0-9]+$
  31974. type: string
  31975. name:
  31976. description: The name of the Secret resource being referred to.
  31977. maxLength: 253
  31978. minLength: 1
  31979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31980. type: string
  31981. namespace:
  31982. description: |-
  31983. The namespace of the Secret resource being referred to.
  31984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31985. maxLength: 63
  31986. minLength: 1
  31987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31988. type: string
  31989. type: object
  31990. secretAccessKeySecretRef:
  31991. description: The SecretAccessKey is used for authentication
  31992. properties:
  31993. key:
  31994. description: |-
  31995. A key in the referenced Secret.
  31996. Some instances of this field may be defaulted, in others it may be required.
  31997. maxLength: 253
  31998. minLength: 1
  31999. pattern: ^[-._a-zA-Z0-9]+$
  32000. type: string
  32001. name:
  32002. description: The name of the Secret resource being referred to.
  32003. maxLength: 253
  32004. minLength: 1
  32005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32006. type: string
  32007. namespace:
  32008. description: |-
  32009. The namespace of the Secret resource being referred to.
  32010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32011. maxLength: 63
  32012. minLength: 1
  32013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32014. type: string
  32015. type: object
  32016. sessionTokenSecretRef:
  32017. description: |-
  32018. The SessionToken used for authentication
  32019. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  32020. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  32021. properties:
  32022. key:
  32023. description: |-
  32024. A key in the referenced Secret.
  32025. Some instances of this field may be defaulted, in others it may be required.
  32026. maxLength: 253
  32027. minLength: 1
  32028. pattern: ^[-._a-zA-Z0-9]+$
  32029. type: string
  32030. name:
  32031. description: The name of the Secret resource being referred to.
  32032. maxLength: 253
  32033. minLength: 1
  32034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32035. type: string
  32036. namespace:
  32037. description: |-
  32038. The namespace of the Secret resource being referred to.
  32039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32040. maxLength: 63
  32041. minLength: 1
  32042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32043. type: string
  32044. type: object
  32045. type: object
  32046. vaultAwsIamServerID:
  32047. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  32048. type: string
  32049. vaultRole:
  32050. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  32051. type: string
  32052. required:
  32053. - vaultRole
  32054. type: object
  32055. jwt:
  32056. description: |-
  32057. Jwt authenticates with Vault by passing role and JWT token using the
  32058. JWT/OIDC authentication method
  32059. properties:
  32060. kubernetesServiceAccountToken:
  32061. description: |-
  32062. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  32063. a token for with the `TokenRequest` API.
  32064. properties:
  32065. audiences:
  32066. description: |-
  32067. Optional audiences field that will be used to request a temporary Kubernetes service
  32068. account token for the service account referenced by `serviceAccountRef`.
  32069. Defaults to a single audience `vault` it not specified.
  32070. Deprecated: use serviceAccountRef.Audiences instead
  32071. items:
  32072. type: string
  32073. type: array
  32074. expirationSeconds:
  32075. description: |-
  32076. Optional expiration time in seconds that will be used to request a temporary
  32077. Kubernetes service account token for the service account referenced by
  32078. `serviceAccountRef`.
  32079. Deprecated: this will be removed in the future.
  32080. Defaults to 10 minutes.
  32081. format: int64
  32082. type: integer
  32083. serviceAccountRef:
  32084. description: Service account field containing the name of a kubernetes ServiceAccount.
  32085. properties:
  32086. audiences:
  32087. description: |-
  32088. Audience specifies the `aud` claim for the service account token
  32089. Some providers automatically extend the audience field based on well-known annotations for workload
  32090. identity (e.g. IRSA or GCP Workload Identity)
  32091. items:
  32092. type: string
  32093. type: array
  32094. name:
  32095. description: The name of the ServiceAccount resource being referred to.
  32096. maxLength: 253
  32097. minLength: 1
  32098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32099. type: string
  32100. namespace:
  32101. description: |-
  32102. Namespace of the resource being referred to.
  32103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32104. maxLength: 63
  32105. minLength: 1
  32106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32107. type: string
  32108. required:
  32109. - name
  32110. type: object
  32111. required:
  32112. - serviceAccountRef
  32113. type: object
  32114. path:
  32115. default: jwt
  32116. description: |-
  32117. Path where the JWT authentication backend is mounted
  32118. in Vault, e.g: "jwt"
  32119. type: string
  32120. role:
  32121. description: |-
  32122. Role is a JWT role to authenticate using the JWT/OIDC Vault
  32123. authentication method
  32124. type: string
  32125. secretRef:
  32126. description: |-
  32127. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  32128. authenticate with Vault using the JWT/OIDC authentication method.
  32129. properties:
  32130. key:
  32131. description: |-
  32132. A key in the referenced Secret.
  32133. Some instances of this field may be defaulted, in others it may be required.
  32134. maxLength: 253
  32135. minLength: 1
  32136. pattern: ^[-._a-zA-Z0-9]+$
  32137. type: string
  32138. name:
  32139. description: The name of the Secret resource being referred to.
  32140. maxLength: 253
  32141. minLength: 1
  32142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32143. type: string
  32144. namespace:
  32145. description: |-
  32146. The namespace of the Secret resource being referred to.
  32147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32148. maxLength: 63
  32149. minLength: 1
  32150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32151. type: string
  32152. type: object
  32153. required:
  32154. - path
  32155. type: object
  32156. kubernetes:
  32157. description: |-
  32158. Kubernetes authenticates with Vault by passing the ServiceAccount
  32159. token stored in the named Secret resource to the Vault server.
  32160. properties:
  32161. mountPath:
  32162. default: kubernetes
  32163. description: |-
  32164. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  32165. "kubernetes"
  32166. type: string
  32167. role:
  32168. description: |-
  32169. A required field containing the Vault Role to assume. A Role binds a
  32170. Kubernetes ServiceAccount with a set of Vault policies.
  32171. type: string
  32172. secretRef:
  32173. description: |-
  32174. Optional secret field containing a Kubernetes ServiceAccount JWT used
  32175. for authenticating with Vault. If a name is specified without a key,
  32176. `token` is the default. If one is not specified, the one bound to
  32177. the controller will be used.
  32178. properties:
  32179. key:
  32180. description: |-
  32181. A key in the referenced Secret.
  32182. Some instances of this field may be defaulted, in others it may be required.
  32183. maxLength: 253
  32184. minLength: 1
  32185. pattern: ^[-._a-zA-Z0-9]+$
  32186. type: string
  32187. name:
  32188. description: The name of the Secret resource being referred to.
  32189. maxLength: 253
  32190. minLength: 1
  32191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32192. type: string
  32193. namespace:
  32194. description: |-
  32195. The namespace of the Secret resource being referred to.
  32196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32197. maxLength: 63
  32198. minLength: 1
  32199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32200. type: string
  32201. type: object
  32202. serviceAccountRef:
  32203. description: |-
  32204. Optional service account field containing the name of a kubernetes ServiceAccount.
  32205. If the service account is specified, the service account secret token JWT will be used
  32206. for authenticating with Vault. If the service account selector is not supplied,
  32207. the secretRef will be used instead.
  32208. properties:
  32209. audiences:
  32210. description: |-
  32211. Audience specifies the `aud` claim for the service account token
  32212. Some providers automatically extend the audience field based on well-known annotations for workload
  32213. identity (e.g. IRSA or GCP Workload Identity)
  32214. items:
  32215. type: string
  32216. type: array
  32217. name:
  32218. description: The name of the ServiceAccount resource being referred to.
  32219. maxLength: 253
  32220. minLength: 1
  32221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32222. type: string
  32223. namespace:
  32224. description: |-
  32225. Namespace of the resource being referred to.
  32226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32227. maxLength: 63
  32228. minLength: 1
  32229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32230. type: string
  32231. required:
  32232. - name
  32233. type: object
  32234. required:
  32235. - mountPath
  32236. - role
  32237. type: object
  32238. ldap:
  32239. description: |-
  32240. Ldap authenticates with Vault by passing username/password pair using
  32241. the LDAP authentication method
  32242. properties:
  32243. path:
  32244. default: ldap
  32245. description: |-
  32246. Path where the LDAP authentication backend is mounted
  32247. in Vault, e.g: "ldap"
  32248. type: string
  32249. secretRef:
  32250. description: |-
  32251. SecretRef to a key in a Secret resource containing password for the LDAP
  32252. user used to authenticate with Vault using the LDAP authentication
  32253. method
  32254. properties:
  32255. key:
  32256. description: |-
  32257. A key in the referenced Secret.
  32258. Some instances of this field may be defaulted, in others it may be required.
  32259. maxLength: 253
  32260. minLength: 1
  32261. pattern: ^[-._a-zA-Z0-9]+$
  32262. type: string
  32263. name:
  32264. description: The name of the Secret resource being referred to.
  32265. maxLength: 253
  32266. minLength: 1
  32267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32268. type: string
  32269. namespace:
  32270. description: |-
  32271. The namespace of the Secret resource being referred to.
  32272. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32273. maxLength: 63
  32274. minLength: 1
  32275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32276. type: string
  32277. type: object
  32278. username:
  32279. description: |-
  32280. Username is an LDAP username used to authenticate using the LDAP Vault
  32281. authentication method
  32282. type: string
  32283. required:
  32284. - path
  32285. - username
  32286. type: object
  32287. namespace:
  32288. description: |-
  32289. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32290. Namespaces is a set of features within Vault Enterprise that allows
  32291. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32292. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32293. This will default to Vault.Namespace field if set, or empty otherwise
  32294. type: string
  32295. tokenSecretRef:
  32296. description: TokenSecretRef authenticates with Vault by presenting a token.
  32297. properties:
  32298. key:
  32299. description: |-
  32300. A key in the referenced Secret.
  32301. Some instances of this field may be defaulted, in others it may be required.
  32302. maxLength: 253
  32303. minLength: 1
  32304. pattern: ^[-._a-zA-Z0-9]+$
  32305. type: string
  32306. name:
  32307. description: The name of the Secret resource being referred to.
  32308. maxLength: 253
  32309. minLength: 1
  32310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32311. type: string
  32312. namespace:
  32313. description: |-
  32314. The namespace of the Secret resource being referred to.
  32315. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32316. maxLength: 63
  32317. minLength: 1
  32318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32319. type: string
  32320. type: object
  32321. userPass:
  32322. description: UserPass authenticates with Vault by passing username/password pair
  32323. properties:
  32324. path:
  32325. default: userpass
  32326. description: |-
  32327. Path where the UserPassword authentication backend is mounted
  32328. in Vault, e.g: "userpass"
  32329. type: string
  32330. secretRef:
  32331. description: |-
  32332. SecretRef to a key in a Secret resource containing password for the
  32333. user used to authenticate with Vault using the UserPass authentication
  32334. method
  32335. properties:
  32336. key:
  32337. description: |-
  32338. A key in the referenced Secret.
  32339. Some instances of this field may be defaulted, in others it may be required.
  32340. maxLength: 253
  32341. minLength: 1
  32342. pattern: ^[-._a-zA-Z0-9]+$
  32343. type: string
  32344. name:
  32345. description: The name of the Secret resource being referred to.
  32346. maxLength: 253
  32347. minLength: 1
  32348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32349. type: string
  32350. namespace:
  32351. description: |-
  32352. The namespace of the Secret resource being referred to.
  32353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32354. maxLength: 63
  32355. minLength: 1
  32356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32357. type: string
  32358. type: object
  32359. username:
  32360. description: |-
  32361. Username is a username used to authenticate using the UserPass Vault
  32362. authentication method
  32363. type: string
  32364. required:
  32365. - path
  32366. - username
  32367. type: object
  32368. type: object
  32369. caBundle:
  32370. description: |-
  32371. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32372. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32373. plain HTTP protocol connection. If not set the system root certificates
  32374. are used to validate the TLS connection.
  32375. format: byte
  32376. type: string
  32377. caProvider:
  32378. description: The provider for the CA bundle to use to validate Vault server certificate.
  32379. properties:
  32380. key:
  32381. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32382. maxLength: 253
  32383. minLength: 1
  32384. pattern: ^[-._a-zA-Z0-9]+$
  32385. type: string
  32386. name:
  32387. description: The name of the object located at the provider type.
  32388. maxLength: 253
  32389. minLength: 1
  32390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32391. type: string
  32392. namespace:
  32393. description: |-
  32394. The namespace the Provider type is in.
  32395. Can only be defined when used in a ClusterSecretStore.
  32396. maxLength: 63
  32397. minLength: 1
  32398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32399. type: string
  32400. type:
  32401. description: The type of provider to use such as "Secret", or "ConfigMap".
  32402. enum:
  32403. - Secret
  32404. - ConfigMap
  32405. type: string
  32406. required:
  32407. - name
  32408. - type
  32409. type: object
  32410. checkAndSet:
  32411. description: |-
  32412. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32413. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32414. the current version of the secret to prevent unintentional overwrites.
  32415. properties:
  32416. required:
  32417. description: |-
  32418. Required when true, all write operations must include a check-and-set parameter.
  32419. This helps prevent unintentional overwrites of secrets.
  32420. type: boolean
  32421. type: object
  32422. forwardInconsistent:
  32423. description: |-
  32424. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32425. leader instead of simply retrying within a loop. This can increase performance if
  32426. the option is enabled serverside.
  32427. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32428. type: boolean
  32429. headers:
  32430. additionalProperties:
  32431. type: string
  32432. description: Headers to be added in Vault request
  32433. type: object
  32434. namespace:
  32435. description: |-
  32436. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32437. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32438. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32439. type: string
  32440. path:
  32441. description: |-
  32442. Path is the mount path of the Vault KV backend endpoint, e.g:
  32443. "secret". The v2 KV secret engine version specific "/data" path suffix
  32444. for fetching secrets from Vault is optional and will be appended
  32445. if not present in specified path.
  32446. type: string
  32447. readYourWrites:
  32448. description: |-
  32449. ReadYourWrites ensures isolated read-after-write semantics by
  32450. providing discovered cluster replication states in each request.
  32451. More information about eventual consistency in Vault can be found here
  32452. https://www.vaultproject.io/docs/enterprise/consistency
  32453. type: boolean
  32454. server:
  32455. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32456. type: string
  32457. tls:
  32458. description: |-
  32459. The configuration used for client side related TLS communication, when the Vault server
  32460. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32461. This parameter is ignored for plain HTTP protocol connection.
  32462. It's worth noting this configuration is different from the "TLS certificates auth method",
  32463. which is available under the `auth.cert` section.
  32464. properties:
  32465. certSecretRef:
  32466. description: |-
  32467. CertSecretRef is a certificate added to the transport layer
  32468. when communicating with the Vault server.
  32469. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32470. properties:
  32471. key:
  32472. description: |-
  32473. A key in the referenced Secret.
  32474. Some instances of this field may be defaulted, in others it may be required.
  32475. maxLength: 253
  32476. minLength: 1
  32477. pattern: ^[-._a-zA-Z0-9]+$
  32478. type: string
  32479. name:
  32480. description: The name of the Secret resource being referred to.
  32481. maxLength: 253
  32482. minLength: 1
  32483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32484. type: string
  32485. namespace:
  32486. description: |-
  32487. The namespace of the Secret resource being referred to.
  32488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32489. maxLength: 63
  32490. minLength: 1
  32491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32492. type: string
  32493. type: object
  32494. keySecretRef:
  32495. description: |-
  32496. KeySecretRef to a key in a Secret resource containing client private key
  32497. added to the transport layer when communicating with the Vault server.
  32498. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32499. properties:
  32500. key:
  32501. description: |-
  32502. A key in the referenced Secret.
  32503. Some instances of this field may be defaulted, in others it may be required.
  32504. maxLength: 253
  32505. minLength: 1
  32506. pattern: ^[-._a-zA-Z0-9]+$
  32507. type: string
  32508. name:
  32509. description: The name of the Secret resource being referred to.
  32510. maxLength: 253
  32511. minLength: 1
  32512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32513. type: string
  32514. namespace:
  32515. description: |-
  32516. The namespace of the Secret resource being referred to.
  32517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32518. maxLength: 63
  32519. minLength: 1
  32520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32521. type: string
  32522. type: object
  32523. type: object
  32524. version:
  32525. default: v2
  32526. description: |-
  32527. Version is the Vault KV secret engine version. This can be either "v1" or
  32528. "v2". Version defaults to "v2".
  32529. enum:
  32530. - v1
  32531. - v2
  32532. type: string
  32533. required:
  32534. - server
  32535. type: object
  32536. resultType:
  32537. default: Data
  32538. description: |-
  32539. Result type defines which data is returned from the generator.
  32540. By default, it is the "data" section of the Vault API response.
  32541. When using e.g. /auth/token/create the "data" section is empty but
  32542. the "auth" section contains the generated token.
  32543. Please refer to the vault docs regarding the result data structure.
  32544. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32545. enum:
  32546. - Data
  32547. - Auth
  32548. - Raw
  32549. type: string
  32550. retrySettings:
  32551. description: Used to configure http retries if failed
  32552. properties:
  32553. maxRetries:
  32554. format: int32
  32555. type: integer
  32556. retryInterval:
  32557. type: string
  32558. type: object
  32559. required:
  32560. - path
  32561. - provider
  32562. type: object
  32563. type: object
  32564. served: true
  32565. storage: true
  32566. subresources:
  32567. status: {}
  32568. ---
  32569. apiVersion: apiextensions.k8s.io/v1
  32570. kind: CustomResourceDefinition
  32571. metadata:
  32572. annotations:
  32573. controller-gen.kubebuilder.io/version: v0.19.0
  32574. labels:
  32575. external-secrets.io/component: controller
  32576. name: webhooks.generators.external-secrets.io
  32577. spec:
  32578. group: generators.external-secrets.io
  32579. names:
  32580. categories:
  32581. - external-secrets
  32582. - external-secrets-generators
  32583. kind: Webhook
  32584. listKind: WebhookList
  32585. plural: webhooks
  32586. singular: webhook
  32587. scope: Namespaced
  32588. versions:
  32589. - name: v1alpha1
  32590. schema:
  32591. openAPIV3Schema:
  32592. description: |-
  32593. Webhook connects to a third party API server to handle the secrets generation
  32594. configuration parameters in spec.
  32595. You can specify the server, the token, and additional body parameters.
  32596. See documentation for the full API specification for requests and responses.
  32597. properties:
  32598. apiVersion:
  32599. description: |-
  32600. APIVersion defines the versioned schema of this representation of an object.
  32601. Servers should convert recognized schemas to the latest internal value, and
  32602. may reject unrecognized values.
  32603. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32604. type: string
  32605. kind:
  32606. description: |-
  32607. Kind is a string value representing the REST resource this object represents.
  32608. Servers may infer this from the endpoint the client submits requests to.
  32609. Cannot be updated.
  32610. In CamelCase.
  32611. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32612. type: string
  32613. metadata:
  32614. type: object
  32615. spec:
  32616. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32617. properties:
  32618. auth:
  32619. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32620. maxProperties: 1
  32621. minProperties: 1
  32622. properties:
  32623. ntlm:
  32624. description: NTLMProtocol configures the store to use NTLM for auth
  32625. properties:
  32626. passwordSecret:
  32627. description: |-
  32628. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32629. In some instances, `key` is a required field.
  32630. properties:
  32631. key:
  32632. description: |-
  32633. A key in the referenced Secret.
  32634. Some instances of this field may be defaulted, in others it may be required.
  32635. maxLength: 253
  32636. minLength: 1
  32637. pattern: ^[-._a-zA-Z0-9]+$
  32638. type: string
  32639. name:
  32640. description: The name of the Secret resource being referred to.
  32641. maxLength: 253
  32642. minLength: 1
  32643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32644. type: string
  32645. namespace:
  32646. description: |-
  32647. The namespace of the Secret resource being referred to.
  32648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32649. maxLength: 63
  32650. minLength: 1
  32651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32652. type: string
  32653. type: object
  32654. usernameSecret:
  32655. description: |-
  32656. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32657. In some instances, `key` is a required field.
  32658. properties:
  32659. key:
  32660. description: |-
  32661. A key in the referenced Secret.
  32662. Some instances of this field may be defaulted, in others it may be required.
  32663. maxLength: 253
  32664. minLength: 1
  32665. pattern: ^[-._a-zA-Z0-9]+$
  32666. type: string
  32667. name:
  32668. description: The name of the Secret resource being referred to.
  32669. maxLength: 253
  32670. minLength: 1
  32671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32672. type: string
  32673. namespace:
  32674. description: |-
  32675. The namespace of the Secret resource being referred to.
  32676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32677. maxLength: 63
  32678. minLength: 1
  32679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32680. type: string
  32681. type: object
  32682. required:
  32683. - passwordSecret
  32684. - usernameSecret
  32685. type: object
  32686. type: object
  32687. body:
  32688. description: Body
  32689. type: string
  32690. caBundle:
  32691. description: |-
  32692. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32693. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32694. plain HTTP protocol connection. If not set the system root certificates
  32695. are used to validate the TLS connection.
  32696. format: byte
  32697. type: string
  32698. caProvider:
  32699. description: The provider for the CA bundle to use to validate webhook server certificate.
  32700. properties:
  32701. key:
  32702. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32703. maxLength: 253
  32704. minLength: 1
  32705. pattern: ^[-._a-zA-Z0-9]+$
  32706. type: string
  32707. name:
  32708. description: The name of the object located at the provider type.
  32709. maxLength: 253
  32710. minLength: 1
  32711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32712. type: string
  32713. namespace:
  32714. description: The namespace the Provider type is in.
  32715. maxLength: 63
  32716. minLength: 1
  32717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32718. type: string
  32719. type:
  32720. description: The type of provider to use such as "Secret", or "ConfigMap".
  32721. enum:
  32722. - Secret
  32723. - ConfigMap
  32724. type: string
  32725. required:
  32726. - name
  32727. - type
  32728. type: object
  32729. headers:
  32730. additionalProperties:
  32731. type: string
  32732. description: Headers
  32733. type: object
  32734. method:
  32735. description: Webhook Method
  32736. type: string
  32737. result:
  32738. description: Result formatting
  32739. properties:
  32740. jsonPath:
  32741. description: Json path of return value
  32742. type: string
  32743. type: object
  32744. secrets:
  32745. description: |-
  32746. Secrets to fill in templates
  32747. These secrets will be passed to the templating function as key value pairs under the given name
  32748. items:
  32749. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32750. properties:
  32751. name:
  32752. description: Name of this secret in templates
  32753. type: string
  32754. secretRef:
  32755. description: Secret ref to fill in credentials
  32756. properties:
  32757. key:
  32758. description: The key where the token is found.
  32759. maxLength: 253
  32760. minLength: 1
  32761. pattern: ^[-._a-zA-Z0-9]+$
  32762. type: string
  32763. name:
  32764. description: The name of the Secret resource being referred to.
  32765. maxLength: 253
  32766. minLength: 1
  32767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32768. type: string
  32769. type: object
  32770. required:
  32771. - name
  32772. - secretRef
  32773. type: object
  32774. type: array
  32775. timeout:
  32776. description: Timeout
  32777. type: string
  32778. url:
  32779. description: Webhook url to call
  32780. type: string
  32781. required:
  32782. - result
  32783. - url
  32784. type: object
  32785. type: object
  32786. served: true
  32787. storage: true
  32788. subresources:
  32789. status: {}