bundle.yaml 1.8 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. type: string
  561. deletionPolicy:
  562. default: Retain
  563. description: |-
  564. DeletionPolicy defines rules on how to delete the resulting Secret.
  565. Defaults to "Retain"
  566. enum:
  567. - Delete
  568. - Merge
  569. - Retain
  570. type: string
  571. immutable:
  572. description: Immutable defines if the final secret will be immutable
  573. type: boolean
  574. manifest:
  575. description: |-
  576. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  577. When specified, ExternalSecret will create the resource type defined here
  578. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  579. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  580. properties:
  581. apiVersion:
  582. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  583. minLength: 1
  584. type: string
  585. kind:
  586. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  587. minLength: 1
  588. type: string
  589. required:
  590. - apiVersion
  591. - kind
  592. type: object
  593. name:
  594. description: |-
  595. The name of the Secret resource to be managed.
  596. Defaults to the .metadata.name of the ExternalSecret resource
  597. maxLength: 253
  598. minLength: 1
  599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  600. type: string
  601. template:
  602. description: Template defines a blueprint for the created Secret resource.
  603. properties:
  604. data:
  605. additionalProperties:
  606. type: string
  607. type: object
  608. engineVersion:
  609. default: v2
  610. description: |-
  611. EngineVersion specifies the template engine version
  612. that should be used to compile/execute the
  613. template specified in .data and .templateFrom[].
  614. enum:
  615. - v2
  616. type: string
  617. mergePolicy:
  618. default: Replace
  619. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  620. enum:
  621. - Replace
  622. - Merge
  623. type: string
  624. metadata:
  625. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  626. properties:
  627. annotations:
  628. additionalProperties:
  629. type: string
  630. type: object
  631. finalizers:
  632. items:
  633. type: string
  634. type: array
  635. labels:
  636. additionalProperties:
  637. type: string
  638. type: object
  639. type: object
  640. templateFrom:
  641. items:
  642. description: |-
  643. TemplateFrom specifies a source for templates.
  644. Each item in the list can either reference a ConfigMap or a Secret resource.
  645. properties:
  646. configMap:
  647. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  648. properties:
  649. items:
  650. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  651. items:
  652. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  653. properties:
  654. key:
  655. description: A key in the ConfigMap/Secret
  656. maxLength: 253
  657. minLength: 1
  658. pattern: ^[-._a-zA-Z0-9]+$
  659. type: string
  660. templateAs:
  661. default: Values
  662. description: TemplateScope specifies how the template keys should be interpreted.
  663. enum:
  664. - Values
  665. - KeysAndValues
  666. type: string
  667. required:
  668. - key
  669. type: object
  670. type: array
  671. name:
  672. description: The name of the ConfigMap/Secret resource
  673. maxLength: 253
  674. minLength: 1
  675. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  676. type: string
  677. required:
  678. - items
  679. - name
  680. type: object
  681. literal:
  682. type: string
  683. secret:
  684. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  685. properties:
  686. items:
  687. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  688. items:
  689. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  690. properties:
  691. key:
  692. description: A key in the ConfigMap/Secret
  693. maxLength: 253
  694. minLength: 1
  695. pattern: ^[-._a-zA-Z0-9]+$
  696. type: string
  697. templateAs:
  698. default: Values
  699. description: TemplateScope specifies how the template keys should be interpreted.
  700. enum:
  701. - Values
  702. - KeysAndValues
  703. type: string
  704. required:
  705. - key
  706. type: object
  707. type: array
  708. name:
  709. description: The name of the ConfigMap/Secret resource
  710. maxLength: 253
  711. minLength: 1
  712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  713. type: string
  714. required:
  715. - items
  716. - name
  717. type: object
  718. target:
  719. default: Data
  720. description: |-
  721. Target specifies where to place the template result.
  722. For Secret resources, common values are: "Data", "Annotations", "Labels".
  723. For custom resources (when spec.target.manifest is set), this supports
  724. nested paths like "spec.database.config" or "data".
  725. type: string
  726. valuesDecodingStrategy:
  727. default: None
  728. description: Used to define a decoding Strategy for the rendered template values.
  729. enum:
  730. - Auto
  731. - Base64
  732. - Base64URL
  733. - None
  734. type: string
  735. type: object
  736. type: array
  737. type:
  738. type: string
  739. type: object
  740. type: object
  741. type: object
  742. namespaceSelector:
  743. description: |-
  744. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  745. Deprecated: Use NamespaceSelectors instead.
  746. properties:
  747. matchExpressions:
  748. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  749. items:
  750. description: |-
  751. A label selector requirement is a selector that contains values, a key, and an operator that
  752. relates the key and values.
  753. properties:
  754. key:
  755. description: key is the label key that the selector applies to.
  756. type: string
  757. operator:
  758. description: |-
  759. operator represents a key's relationship to a set of values.
  760. Valid operators are In, NotIn, Exists and DoesNotExist.
  761. type: string
  762. values:
  763. description: |-
  764. values is an array of string values. If the operator is In or NotIn,
  765. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  766. the values array must be empty. This array is replaced during a strategic
  767. merge patch.
  768. items:
  769. type: string
  770. type: array
  771. x-kubernetes-list-type: atomic
  772. required:
  773. - key
  774. - operator
  775. type: object
  776. type: array
  777. x-kubernetes-list-type: atomic
  778. matchLabels:
  779. additionalProperties:
  780. type: string
  781. description: |-
  782. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  783. map is equivalent to an element of matchExpressions, whose key field is "key", the
  784. operator is "In", and the values array contains only "value". The requirements are ANDed.
  785. type: object
  786. type: object
  787. x-kubernetes-map-type: atomic
  788. namespaceSelectors:
  789. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  790. items:
  791. description: |-
  792. A label selector is a label query over a set of resources. The result of matchLabels and
  793. matchExpressions are ANDed. An empty label selector matches all objects. A null
  794. label selector matches no objects.
  795. properties:
  796. matchExpressions:
  797. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  798. items:
  799. description: |-
  800. A label selector requirement is a selector that contains values, a key, and an operator that
  801. relates the key and values.
  802. properties:
  803. key:
  804. description: key is the label key that the selector applies to.
  805. type: string
  806. operator:
  807. description: |-
  808. operator represents a key's relationship to a set of values.
  809. Valid operators are In, NotIn, Exists and DoesNotExist.
  810. type: string
  811. values:
  812. description: |-
  813. values is an array of string values. If the operator is In or NotIn,
  814. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  815. the values array must be empty. This array is replaced during a strategic
  816. merge patch.
  817. items:
  818. type: string
  819. type: array
  820. x-kubernetes-list-type: atomic
  821. required:
  822. - key
  823. - operator
  824. type: object
  825. type: array
  826. x-kubernetes-list-type: atomic
  827. matchLabels:
  828. additionalProperties:
  829. type: string
  830. description: |-
  831. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  832. map is equivalent to an element of matchExpressions, whose key field is "key", the
  833. operator is "In", and the values array contains only "value". The requirements are ANDed.
  834. type: object
  835. type: object
  836. x-kubernetes-map-type: atomic
  837. type: array
  838. namespaces:
  839. description: |-
  840. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  841. Deprecated: Use NamespaceSelectors instead.
  842. items:
  843. maxLength: 63
  844. minLength: 1
  845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  846. type: string
  847. type: array
  848. refreshTime:
  849. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  850. type: string
  851. required:
  852. - externalSecretSpec
  853. type: object
  854. status:
  855. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  856. properties:
  857. conditions:
  858. items:
  859. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  860. properties:
  861. message:
  862. type: string
  863. status:
  864. type: string
  865. type:
  866. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  867. type: string
  868. required:
  869. - status
  870. - type
  871. type: object
  872. type: array
  873. externalSecretName:
  874. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  875. type: string
  876. failedNamespaces:
  877. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  878. items:
  879. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  880. properties:
  881. namespace:
  882. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  883. type: string
  884. reason:
  885. description: Reason is why the ExternalSecret failed to apply to the namespace
  886. type: string
  887. required:
  888. - namespace
  889. type: object
  890. type: array
  891. provisionedNamespaces:
  892. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  893. items:
  894. type: string
  895. type: array
  896. type: object
  897. type: object
  898. served: true
  899. storage: true
  900. subresources:
  901. status: {}
  902. - additionalPrinterColumns:
  903. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  904. name: Store
  905. type: string
  906. - jsonPath: .spec.refreshTime
  907. name: Refresh Interval
  908. type: string
  909. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  910. name: Ready
  911. type: string
  912. deprecated: true
  913. name: v1beta1
  914. schema:
  915. openAPIV3Schema:
  916. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  917. properties:
  918. apiVersion:
  919. description: |-
  920. APIVersion defines the versioned schema of this representation of an object.
  921. Servers should convert recognized schemas to the latest internal value, and
  922. may reject unrecognized values.
  923. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  924. type: string
  925. kind:
  926. description: |-
  927. Kind is a string value representing the REST resource this object represents.
  928. Servers may infer this from the endpoint the client submits requests to.
  929. Cannot be updated.
  930. In CamelCase.
  931. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  932. type: string
  933. metadata:
  934. type: object
  935. spec:
  936. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  937. properties:
  938. externalSecretMetadata:
  939. description: The metadata of the external secrets to be created
  940. properties:
  941. annotations:
  942. additionalProperties:
  943. type: string
  944. type: object
  945. labels:
  946. additionalProperties:
  947. type: string
  948. type: object
  949. type: object
  950. externalSecretName:
  951. description: |-
  952. The name of the external secrets to be created.
  953. Defaults to the name of the ClusterExternalSecret
  954. maxLength: 253
  955. minLength: 1
  956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  957. type: string
  958. externalSecretSpec:
  959. description: The spec for the ExternalSecrets to be created
  960. properties:
  961. data:
  962. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  963. items:
  964. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  965. properties:
  966. remoteRef:
  967. description: |-
  968. RemoteRef points to the remote secret and defines
  969. which secret (version/property/..) to fetch.
  970. properties:
  971. conversionStrategy:
  972. default: Default
  973. description: Used to define a conversion Strategy
  974. enum:
  975. - Default
  976. - Unicode
  977. type: string
  978. decodingStrategy:
  979. default: None
  980. description: Used to define a decoding Strategy
  981. enum:
  982. - Auto
  983. - Base64
  984. - Base64URL
  985. - None
  986. type: string
  987. key:
  988. description: Key is the key used in the Provider, mandatory
  989. type: string
  990. metadataPolicy:
  991. default: None
  992. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  993. enum:
  994. - None
  995. - Fetch
  996. type: string
  997. property:
  998. description: Used to select a specific property of the Provider value (if a map), if supported
  999. type: string
  1000. version:
  1001. description: Used to select a specific version of the Provider value, if supported
  1002. type: string
  1003. required:
  1004. - key
  1005. type: object
  1006. secretKey:
  1007. description: The key in the Kubernetes Secret to store the value.
  1008. maxLength: 253
  1009. minLength: 1
  1010. pattern: ^[-._a-zA-Z0-9]+$
  1011. type: string
  1012. sourceRef:
  1013. description: |-
  1014. SourceRef allows you to override the source
  1015. from which the value will be pulled.
  1016. maxProperties: 1
  1017. minProperties: 1
  1018. properties:
  1019. generatorRef:
  1020. description: |-
  1021. GeneratorRef points to a generator custom resource.
  1022. Deprecated: The generatorRef is not implemented in .data[].
  1023. this will be removed with v1.
  1024. properties:
  1025. apiVersion:
  1026. default: generators.external-secrets.io/v1alpha1
  1027. description: Specify the apiVersion of the generator resource
  1028. type: string
  1029. kind:
  1030. description: Specify the Kind of the generator resource
  1031. enum:
  1032. - ACRAccessToken
  1033. - ClusterGenerator
  1034. - ECRAuthorizationToken
  1035. - Fake
  1036. - GCRAccessToken
  1037. - GithubAccessToken
  1038. - QuayAccessToken
  1039. - Password
  1040. - SSHKey
  1041. - STSSessionToken
  1042. - UUID
  1043. - VaultDynamicSecret
  1044. - Webhook
  1045. - Grafana
  1046. type: string
  1047. name:
  1048. description: Specify the name of the generator resource
  1049. maxLength: 253
  1050. minLength: 1
  1051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1052. type: string
  1053. required:
  1054. - kind
  1055. - name
  1056. type: object
  1057. storeRef:
  1058. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1059. properties:
  1060. kind:
  1061. description: |-
  1062. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1063. Defaults to `SecretStore`
  1064. enum:
  1065. - SecretStore
  1066. - ClusterSecretStore
  1067. type: string
  1068. name:
  1069. description: Name of the SecretStore resource
  1070. maxLength: 253
  1071. minLength: 1
  1072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1073. type: string
  1074. type: object
  1075. type: object
  1076. required:
  1077. - remoteRef
  1078. - secretKey
  1079. type: object
  1080. type: array
  1081. dataFrom:
  1082. description: |-
  1083. DataFrom is used to fetch all properties from a specific Provider data
  1084. If multiple entries are specified, the Secret keys are merged in the specified order
  1085. items:
  1086. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1087. properties:
  1088. extract:
  1089. description: |-
  1090. Used to extract multiple key/value pairs from one secret
  1091. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1092. properties:
  1093. conversionStrategy:
  1094. default: Default
  1095. description: Used to define a conversion Strategy
  1096. enum:
  1097. - Default
  1098. - Unicode
  1099. type: string
  1100. decodingStrategy:
  1101. default: None
  1102. description: Used to define a decoding Strategy
  1103. enum:
  1104. - Auto
  1105. - Base64
  1106. - Base64URL
  1107. - None
  1108. type: string
  1109. key:
  1110. description: Key is the key used in the Provider, mandatory
  1111. type: string
  1112. metadataPolicy:
  1113. default: None
  1114. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1115. enum:
  1116. - None
  1117. - Fetch
  1118. type: string
  1119. property:
  1120. description: Used to select a specific property of the Provider value (if a map), if supported
  1121. type: string
  1122. version:
  1123. description: Used to select a specific version of the Provider value, if supported
  1124. type: string
  1125. required:
  1126. - key
  1127. type: object
  1128. find:
  1129. description: |-
  1130. Used to find secrets based on tags or regular expressions
  1131. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1132. properties:
  1133. conversionStrategy:
  1134. default: Default
  1135. description: Used to define a conversion Strategy
  1136. enum:
  1137. - Default
  1138. - Unicode
  1139. type: string
  1140. decodingStrategy:
  1141. default: None
  1142. description: Used to define a decoding Strategy
  1143. enum:
  1144. - Auto
  1145. - Base64
  1146. - Base64URL
  1147. - None
  1148. type: string
  1149. name:
  1150. description: Finds secrets based on the name.
  1151. properties:
  1152. regexp:
  1153. description: Finds secrets base
  1154. type: string
  1155. type: object
  1156. path:
  1157. description: A root path to start the find operations.
  1158. type: string
  1159. tags:
  1160. additionalProperties:
  1161. type: string
  1162. description: Find secrets based on tags.
  1163. type: object
  1164. type: object
  1165. rewrite:
  1166. description: |-
  1167. Used to rewrite secret Keys after getting them from the secret Provider
  1168. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1169. items:
  1170. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1171. maxProperties: 1
  1172. minProperties: 1
  1173. properties:
  1174. regexp:
  1175. description: |-
  1176. Used to rewrite with regular expressions.
  1177. The resulting key will be the output of a regexp.ReplaceAll operation.
  1178. properties:
  1179. source:
  1180. description: Used to define the regular expression of a re.Compiler.
  1181. type: string
  1182. target:
  1183. description: Used to define the target pattern of a ReplaceAll operation.
  1184. type: string
  1185. required:
  1186. - source
  1187. - target
  1188. type: object
  1189. transform:
  1190. description: |-
  1191. Used to apply string transformation on the secrets.
  1192. The resulting key will be the output of the template applied by the operation.
  1193. properties:
  1194. template:
  1195. description: |-
  1196. Used to define the template to apply on the secret name.
  1197. `.value ` will specify the secret name in the template.
  1198. type: string
  1199. required:
  1200. - template
  1201. type: object
  1202. type: object
  1203. type: array
  1204. sourceRef:
  1205. description: |-
  1206. SourceRef points to a store or generator
  1207. which contains secret values ready to use.
  1208. Use this in combination with Extract or Find pull values out of
  1209. a specific SecretStore.
  1210. When sourceRef points to a generator Extract or Find is not supported.
  1211. The generator returns a static map of values
  1212. maxProperties: 1
  1213. minProperties: 1
  1214. properties:
  1215. generatorRef:
  1216. description: GeneratorRef points to a generator custom resource.
  1217. properties:
  1218. apiVersion:
  1219. default: generators.external-secrets.io/v1alpha1
  1220. description: Specify the apiVersion of the generator resource
  1221. type: string
  1222. kind:
  1223. description: Specify the Kind of the generator resource
  1224. enum:
  1225. - ACRAccessToken
  1226. - ClusterGenerator
  1227. - ECRAuthorizationToken
  1228. - Fake
  1229. - GCRAccessToken
  1230. - GithubAccessToken
  1231. - QuayAccessToken
  1232. - Password
  1233. - SSHKey
  1234. - STSSessionToken
  1235. - UUID
  1236. - VaultDynamicSecret
  1237. - Webhook
  1238. - Grafana
  1239. type: string
  1240. name:
  1241. description: Specify the name of the generator resource
  1242. maxLength: 253
  1243. minLength: 1
  1244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1245. type: string
  1246. required:
  1247. - kind
  1248. - name
  1249. type: object
  1250. storeRef:
  1251. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1252. properties:
  1253. kind:
  1254. description: |-
  1255. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1256. Defaults to `SecretStore`
  1257. enum:
  1258. - SecretStore
  1259. - ClusterSecretStore
  1260. type: string
  1261. name:
  1262. description: Name of the SecretStore resource
  1263. maxLength: 253
  1264. minLength: 1
  1265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1266. type: string
  1267. type: object
  1268. type: object
  1269. type: object
  1270. type: array
  1271. refreshInterval:
  1272. default: 1h0m0s
  1273. description: |-
  1274. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1275. specified as Golang Duration strings.
  1276. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1277. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1278. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1279. type: string
  1280. refreshPolicy:
  1281. description: |-
  1282. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1283. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1284. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1285. No periodic updates occur if refreshInterval is 0.
  1286. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1287. enum:
  1288. - CreatedOnce
  1289. - Periodic
  1290. - OnChange
  1291. type: string
  1292. secretStoreRef:
  1293. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1294. properties:
  1295. kind:
  1296. description: |-
  1297. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1298. Defaults to `SecretStore`
  1299. enum:
  1300. - SecretStore
  1301. - ClusterSecretStore
  1302. type: string
  1303. name:
  1304. description: Name of the SecretStore resource
  1305. maxLength: 253
  1306. minLength: 1
  1307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1308. type: string
  1309. type: object
  1310. target:
  1311. default:
  1312. creationPolicy: Owner
  1313. deletionPolicy: Retain
  1314. description: |-
  1315. ExternalSecretTarget defines the Kubernetes Secret to be created
  1316. There can be only one target per ExternalSecret.
  1317. properties:
  1318. creationPolicy:
  1319. default: Owner
  1320. description: |-
  1321. CreationPolicy defines rules on how to create the resulting Secret.
  1322. Defaults to "Owner"
  1323. enum:
  1324. - Owner
  1325. - Orphan
  1326. - Merge
  1327. - None
  1328. type: string
  1329. deletionPolicy:
  1330. default: Retain
  1331. description: |-
  1332. DeletionPolicy defines rules on how to delete the resulting Secret.
  1333. Defaults to "Retain"
  1334. enum:
  1335. - Delete
  1336. - Merge
  1337. - Retain
  1338. type: string
  1339. immutable:
  1340. description: Immutable defines if the final secret will be immutable
  1341. type: boolean
  1342. name:
  1343. description: |-
  1344. The name of the Secret resource to be managed.
  1345. Defaults to the .metadata.name of the ExternalSecret resource
  1346. maxLength: 253
  1347. minLength: 1
  1348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1349. type: string
  1350. template:
  1351. description: Template defines a blueprint for the created Secret resource.
  1352. properties:
  1353. data:
  1354. additionalProperties:
  1355. type: string
  1356. type: object
  1357. engineVersion:
  1358. default: v2
  1359. description: |-
  1360. EngineVersion specifies the template engine version
  1361. that should be used to compile/execute the
  1362. template specified in .data and .templateFrom[].
  1363. enum:
  1364. - v2
  1365. type: string
  1366. mergePolicy:
  1367. default: Replace
  1368. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1369. enum:
  1370. - Replace
  1371. - Merge
  1372. type: string
  1373. metadata:
  1374. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1375. properties:
  1376. annotations:
  1377. additionalProperties:
  1378. type: string
  1379. type: object
  1380. labels:
  1381. additionalProperties:
  1382. type: string
  1383. type: object
  1384. type: object
  1385. templateFrom:
  1386. items:
  1387. description: TemplateFrom defines a source for template data.
  1388. properties:
  1389. configMap:
  1390. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1391. properties:
  1392. items:
  1393. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1394. items:
  1395. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1396. properties:
  1397. key:
  1398. description: A key in the ConfigMap/Secret
  1399. maxLength: 253
  1400. minLength: 1
  1401. pattern: ^[-._a-zA-Z0-9]+$
  1402. type: string
  1403. templateAs:
  1404. default: Values
  1405. description: TemplateScope defines the scope of the template when processing template data.
  1406. enum:
  1407. - Values
  1408. - KeysAndValues
  1409. type: string
  1410. required:
  1411. - key
  1412. type: object
  1413. type: array
  1414. name:
  1415. description: The name of the ConfigMap/Secret resource
  1416. maxLength: 253
  1417. minLength: 1
  1418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1419. type: string
  1420. required:
  1421. - items
  1422. - name
  1423. type: object
  1424. literal:
  1425. type: string
  1426. secret:
  1427. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1428. properties:
  1429. items:
  1430. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1431. items:
  1432. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1433. properties:
  1434. key:
  1435. description: A key in the ConfigMap/Secret
  1436. maxLength: 253
  1437. minLength: 1
  1438. pattern: ^[-._a-zA-Z0-9]+$
  1439. type: string
  1440. templateAs:
  1441. default: Values
  1442. description: TemplateScope defines the scope of the template when processing template data.
  1443. enum:
  1444. - Values
  1445. - KeysAndValues
  1446. type: string
  1447. required:
  1448. - key
  1449. type: object
  1450. type: array
  1451. name:
  1452. description: The name of the ConfigMap/Secret resource
  1453. maxLength: 253
  1454. minLength: 1
  1455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1456. type: string
  1457. required:
  1458. - items
  1459. - name
  1460. type: object
  1461. target:
  1462. default: Data
  1463. description: TemplateTarget defines the target field where the template result will be stored.
  1464. enum:
  1465. - Data
  1466. - Annotations
  1467. - Labels
  1468. type: string
  1469. type: object
  1470. type: array
  1471. type:
  1472. type: string
  1473. type: object
  1474. type: object
  1475. type: object
  1476. namespaceSelector:
  1477. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1478. properties:
  1479. matchExpressions:
  1480. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1481. items:
  1482. description: |-
  1483. A label selector requirement is a selector that contains values, a key, and an operator that
  1484. relates the key and values.
  1485. properties:
  1486. key:
  1487. description: key is the label key that the selector applies to.
  1488. type: string
  1489. operator:
  1490. description: |-
  1491. operator represents a key's relationship to a set of values.
  1492. Valid operators are In, NotIn, Exists and DoesNotExist.
  1493. type: string
  1494. values:
  1495. description: |-
  1496. values is an array of string values. If the operator is In or NotIn,
  1497. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1498. the values array must be empty. This array is replaced during a strategic
  1499. merge patch.
  1500. items:
  1501. type: string
  1502. type: array
  1503. x-kubernetes-list-type: atomic
  1504. required:
  1505. - key
  1506. - operator
  1507. type: object
  1508. type: array
  1509. x-kubernetes-list-type: atomic
  1510. matchLabels:
  1511. additionalProperties:
  1512. type: string
  1513. description: |-
  1514. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1515. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1516. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1517. type: object
  1518. type: object
  1519. x-kubernetes-map-type: atomic
  1520. namespaceSelectors:
  1521. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1522. items:
  1523. description: |-
  1524. A label selector is a label query over a set of resources. The result of matchLabels and
  1525. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1526. label selector matches no objects.
  1527. properties:
  1528. matchExpressions:
  1529. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1530. items:
  1531. description: |-
  1532. A label selector requirement is a selector that contains values, a key, and an operator that
  1533. relates the key and values.
  1534. properties:
  1535. key:
  1536. description: key is the label key that the selector applies to.
  1537. type: string
  1538. operator:
  1539. description: |-
  1540. operator represents a key's relationship to a set of values.
  1541. Valid operators are In, NotIn, Exists and DoesNotExist.
  1542. type: string
  1543. values:
  1544. description: |-
  1545. values is an array of string values. If the operator is In or NotIn,
  1546. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1547. the values array must be empty. This array is replaced during a strategic
  1548. merge patch.
  1549. items:
  1550. type: string
  1551. type: array
  1552. x-kubernetes-list-type: atomic
  1553. required:
  1554. - key
  1555. - operator
  1556. type: object
  1557. type: array
  1558. x-kubernetes-list-type: atomic
  1559. matchLabels:
  1560. additionalProperties:
  1561. type: string
  1562. description: |-
  1563. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1564. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1565. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1566. type: object
  1567. type: object
  1568. x-kubernetes-map-type: atomic
  1569. type: array
  1570. namespaces:
  1571. description: |-
  1572. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1573. Deprecated: Use NamespaceSelectors instead.
  1574. items:
  1575. maxLength: 63
  1576. minLength: 1
  1577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1578. type: string
  1579. type: array
  1580. refreshTime:
  1581. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1582. type: string
  1583. required:
  1584. - externalSecretSpec
  1585. type: object
  1586. status:
  1587. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1588. properties:
  1589. conditions:
  1590. items:
  1591. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1592. properties:
  1593. message:
  1594. type: string
  1595. status:
  1596. type: string
  1597. type:
  1598. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1599. type: string
  1600. required:
  1601. - status
  1602. - type
  1603. type: object
  1604. type: array
  1605. externalSecretName:
  1606. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1607. type: string
  1608. failedNamespaces:
  1609. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1610. items:
  1611. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1612. properties:
  1613. namespace:
  1614. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1615. type: string
  1616. reason:
  1617. description: Reason is why the ExternalSecret failed to apply to the namespace
  1618. type: string
  1619. required:
  1620. - namespace
  1621. type: object
  1622. type: array
  1623. provisionedNamespaces:
  1624. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1625. items:
  1626. type: string
  1627. type: array
  1628. type: object
  1629. type: object
  1630. served: false
  1631. storage: false
  1632. subresources:
  1633. status: {}
  1634. ---
  1635. apiVersion: apiextensions.k8s.io/v1
  1636. kind: CustomResourceDefinition
  1637. metadata:
  1638. annotations:
  1639. controller-gen.kubebuilder.io/version: v0.19.0
  1640. labels:
  1641. external-secrets.io/component: controller
  1642. name: clusterpushsecrets.external-secrets.io
  1643. spec:
  1644. group: external-secrets.io
  1645. names:
  1646. categories:
  1647. - external-secrets
  1648. kind: ClusterPushSecret
  1649. listKind: ClusterPushSecretList
  1650. plural: clusterpushsecrets
  1651. singular: clusterpushsecret
  1652. scope: Cluster
  1653. versions:
  1654. - additionalPrinterColumns:
  1655. - jsonPath: .metadata.creationTimestamp
  1656. name: AGE
  1657. type: date
  1658. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1659. name: Status
  1660. type: string
  1661. name: v1alpha1
  1662. schema:
  1663. openAPIV3Schema:
  1664. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1665. properties:
  1666. apiVersion:
  1667. description: |-
  1668. APIVersion defines the versioned schema of this representation of an object.
  1669. Servers should convert recognized schemas to the latest internal value, and
  1670. may reject unrecognized values.
  1671. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1672. type: string
  1673. kind:
  1674. description: |-
  1675. Kind is a string value representing the REST resource this object represents.
  1676. Servers may infer this from the endpoint the client submits requests to.
  1677. Cannot be updated.
  1678. In CamelCase.
  1679. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1680. type: string
  1681. metadata:
  1682. type: object
  1683. spec:
  1684. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1685. properties:
  1686. namespaceSelectors:
  1687. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1688. items:
  1689. description: |-
  1690. A label selector is a label query over a set of resources. The result of matchLabels and
  1691. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1692. label selector matches no objects.
  1693. properties:
  1694. matchExpressions:
  1695. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1696. items:
  1697. description: |-
  1698. A label selector requirement is a selector that contains values, a key, and an operator that
  1699. relates the key and values.
  1700. properties:
  1701. key:
  1702. description: key is the label key that the selector applies to.
  1703. type: string
  1704. operator:
  1705. description: |-
  1706. operator represents a key's relationship to a set of values.
  1707. Valid operators are In, NotIn, Exists and DoesNotExist.
  1708. type: string
  1709. values:
  1710. description: |-
  1711. values is an array of string values. If the operator is In or NotIn,
  1712. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1713. the values array must be empty. This array is replaced during a strategic
  1714. merge patch.
  1715. items:
  1716. type: string
  1717. type: array
  1718. x-kubernetes-list-type: atomic
  1719. required:
  1720. - key
  1721. - operator
  1722. type: object
  1723. type: array
  1724. x-kubernetes-list-type: atomic
  1725. matchLabels:
  1726. additionalProperties:
  1727. type: string
  1728. description: |-
  1729. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1730. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1731. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1732. type: object
  1733. type: object
  1734. x-kubernetes-map-type: atomic
  1735. type: array
  1736. pushSecretMetadata:
  1737. description: The metadata of the external secrets to be created
  1738. properties:
  1739. annotations:
  1740. additionalProperties:
  1741. type: string
  1742. type: object
  1743. labels:
  1744. additionalProperties:
  1745. type: string
  1746. type: object
  1747. type: object
  1748. pushSecretName:
  1749. description: |-
  1750. The name of the push secrets to be created.
  1751. Defaults to the name of the ClusterPushSecret
  1752. maxLength: 253
  1753. minLength: 1
  1754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1755. type: string
  1756. pushSecretSpec:
  1757. description: PushSecretSpec defines what to do with the secrets.
  1758. properties:
  1759. data:
  1760. description: Secret Data that should be pushed to providers
  1761. items:
  1762. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1763. properties:
  1764. conversionStrategy:
  1765. default: None
  1766. description: Used to define a conversion Strategy for the secret keys
  1767. enum:
  1768. - None
  1769. - ReverseUnicode
  1770. type: string
  1771. match:
  1772. description: Match a given Secret Key to be pushed to the provider.
  1773. properties:
  1774. remoteRef:
  1775. description: Remote Refs to push to providers.
  1776. properties:
  1777. property:
  1778. description: Name of the property in the resulting secret
  1779. type: string
  1780. remoteKey:
  1781. description: Name of the resulting provider secret.
  1782. type: string
  1783. required:
  1784. - remoteKey
  1785. type: object
  1786. secretKey:
  1787. description: Secret Key to be pushed
  1788. type: string
  1789. required:
  1790. - remoteRef
  1791. type: object
  1792. metadata:
  1793. description: |-
  1794. Metadata is metadata attached to the secret.
  1795. The structure of metadata is provider specific, please look it up in the provider documentation.
  1796. x-kubernetes-preserve-unknown-fields: true
  1797. required:
  1798. - match
  1799. type: object
  1800. type: array
  1801. dataTo:
  1802. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1803. items:
  1804. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1805. properties:
  1806. conversionStrategy:
  1807. default: None
  1808. description: Used to define a conversion Strategy for the secret keys
  1809. enum:
  1810. - None
  1811. - ReverseUnicode
  1812. type: string
  1813. match:
  1814. description: |-
  1815. Match pattern for selecting keys from the source Secret.
  1816. If not specified, all keys are selected.
  1817. properties:
  1818. regexp:
  1819. description: |-
  1820. Regexp matches keys by regular expression.
  1821. If not specified, all keys are matched.
  1822. type: string
  1823. type: object
  1824. metadata:
  1825. description: |-
  1826. Metadata is metadata attached to the secret.
  1827. The structure of metadata is provider specific, please look it up in the provider documentation.
  1828. x-kubernetes-preserve-unknown-fields: true
  1829. remoteKey:
  1830. description: |-
  1831. RemoteKey is the name of the single provider secret that will receive ALL
  1832. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1833. When set, per-key expansion is skipped and a single push is performed.
  1834. The provider's store prefix (if any) is still prepended to this value.
  1835. When not set, each matched key is pushed as its own individual provider secret.
  1836. type: string
  1837. rewrite:
  1838. description: |-
  1839. Rewrite operations to transform keys before pushing to the provider.
  1840. Operations are applied sequentially.
  1841. items:
  1842. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1843. properties:
  1844. regexp:
  1845. description: Used to rewrite with regular expressions.
  1846. properties:
  1847. source:
  1848. description: Used to define the regular expression of a re.Compiler.
  1849. type: string
  1850. target:
  1851. description: Used to define the target pattern of a ReplaceAll operation.
  1852. type: string
  1853. required:
  1854. - source
  1855. - target
  1856. type: object
  1857. transform:
  1858. description: Used to apply string transformation on the secrets.
  1859. properties:
  1860. template:
  1861. description: |-
  1862. Used to define the template to apply on the secret name.
  1863. `.value ` will specify the secret name in the template.
  1864. type: string
  1865. required:
  1866. - template
  1867. type: object
  1868. type: object
  1869. x-kubernetes-validations:
  1870. - message: exactly one of regexp or transform must be set
  1871. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1872. type: array
  1873. storeRef:
  1874. description: StoreRef specifies which SecretStore to push to. Required.
  1875. properties:
  1876. kind:
  1877. default: SecretStore
  1878. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1879. enum:
  1880. - SecretStore
  1881. - ClusterSecretStore
  1882. type: string
  1883. labelSelector:
  1884. description: Optionally, sync to secret stores with label selector
  1885. properties:
  1886. matchExpressions:
  1887. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1888. items:
  1889. description: |-
  1890. A label selector requirement is a selector that contains values, a key, and an operator that
  1891. relates the key and values.
  1892. properties:
  1893. key:
  1894. description: key is the label key that the selector applies to.
  1895. type: string
  1896. operator:
  1897. description: |-
  1898. operator represents a key's relationship to a set of values.
  1899. Valid operators are In, NotIn, Exists and DoesNotExist.
  1900. type: string
  1901. values:
  1902. description: |-
  1903. values is an array of string values. If the operator is In or NotIn,
  1904. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1905. the values array must be empty. This array is replaced during a strategic
  1906. merge patch.
  1907. items:
  1908. type: string
  1909. type: array
  1910. x-kubernetes-list-type: atomic
  1911. required:
  1912. - key
  1913. - operator
  1914. type: object
  1915. type: array
  1916. x-kubernetes-list-type: atomic
  1917. matchLabels:
  1918. additionalProperties:
  1919. type: string
  1920. description: |-
  1921. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1922. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1923. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1924. type: object
  1925. type: object
  1926. x-kubernetes-map-type: atomic
  1927. name:
  1928. description: Optionally, sync to the SecretStore of the given name
  1929. maxLength: 253
  1930. minLength: 1
  1931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1932. type: string
  1933. type: object
  1934. type: object
  1935. x-kubernetes-validations:
  1936. - message: storeRef must specify either name or labelSelector
  1937. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1938. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1939. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1940. type: array
  1941. deletionPolicy:
  1942. default: None
  1943. description: Deletion Policy to handle Secrets in the provider.
  1944. enum:
  1945. - Delete
  1946. - None
  1947. type: string
  1948. refreshInterval:
  1949. default: 1h0m0s
  1950. description: The Interval to which External Secrets will try to push a secret definition
  1951. type: string
  1952. secretStoreRefs:
  1953. items:
  1954. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1955. properties:
  1956. kind:
  1957. default: SecretStore
  1958. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1959. enum:
  1960. - SecretStore
  1961. - ClusterSecretStore
  1962. type: string
  1963. labelSelector:
  1964. description: Optionally, sync to secret stores with label selector
  1965. properties:
  1966. matchExpressions:
  1967. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1968. items:
  1969. description: |-
  1970. A label selector requirement is a selector that contains values, a key, and an operator that
  1971. relates the key and values.
  1972. properties:
  1973. key:
  1974. description: key is the label key that the selector applies to.
  1975. type: string
  1976. operator:
  1977. description: |-
  1978. operator represents a key's relationship to a set of values.
  1979. Valid operators are In, NotIn, Exists and DoesNotExist.
  1980. type: string
  1981. values:
  1982. description: |-
  1983. values is an array of string values. If the operator is In or NotIn,
  1984. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1985. the values array must be empty. This array is replaced during a strategic
  1986. merge patch.
  1987. items:
  1988. type: string
  1989. type: array
  1990. x-kubernetes-list-type: atomic
  1991. required:
  1992. - key
  1993. - operator
  1994. type: object
  1995. type: array
  1996. x-kubernetes-list-type: atomic
  1997. matchLabels:
  1998. additionalProperties:
  1999. type: string
  2000. description: |-
  2001. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2002. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2003. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2004. type: object
  2005. type: object
  2006. x-kubernetes-map-type: atomic
  2007. name:
  2008. description: Optionally, sync to the SecretStore of the given name
  2009. maxLength: 253
  2010. minLength: 1
  2011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2012. type: string
  2013. type: object
  2014. type: array
  2015. selector:
  2016. description: The Secret Selector (k8s source) for the Push Secret
  2017. maxProperties: 1
  2018. minProperties: 1
  2019. properties:
  2020. generatorRef:
  2021. description: Point to a generator to create a Secret.
  2022. properties:
  2023. apiVersion:
  2024. default: generators.external-secrets.io/v1alpha1
  2025. description: Specify the apiVersion of the generator resource
  2026. type: string
  2027. kind:
  2028. description: Specify the Kind of the generator resource
  2029. enum:
  2030. - ACRAccessToken
  2031. - BeyondtrustWorkloadCredentialsDynamicSecret
  2032. - ClusterGenerator
  2033. - CloudsmithAccessToken
  2034. - ECRAuthorizationToken
  2035. - Fake
  2036. - GCRAccessToken
  2037. - GithubAccessToken
  2038. - GitlabDeployToken
  2039. - QuayAccessToken
  2040. - Password
  2041. - SSHKey
  2042. - STSSessionToken
  2043. - UUID
  2044. - VaultDynamicSecret
  2045. - Webhook
  2046. - Grafana
  2047. - MFA
  2048. type: string
  2049. name:
  2050. description: Specify the name of the generator resource
  2051. maxLength: 253
  2052. minLength: 1
  2053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2054. type: string
  2055. required:
  2056. - kind
  2057. - name
  2058. type: object
  2059. secret:
  2060. description: Select a Secret to Push.
  2061. properties:
  2062. name:
  2063. description: |-
  2064. Name of the Secret.
  2065. The Secret must exist in the same namespace as the PushSecret manifest.
  2066. maxLength: 253
  2067. minLength: 1
  2068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2069. type: string
  2070. selector:
  2071. description: Selector chooses secrets using a labelSelector.
  2072. properties:
  2073. matchExpressions:
  2074. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2075. items:
  2076. description: |-
  2077. A label selector requirement is a selector that contains values, a key, and an operator that
  2078. relates the key and values.
  2079. properties:
  2080. key:
  2081. description: key is the label key that the selector applies to.
  2082. type: string
  2083. operator:
  2084. description: |-
  2085. operator represents a key's relationship to a set of values.
  2086. Valid operators are In, NotIn, Exists and DoesNotExist.
  2087. type: string
  2088. values:
  2089. description: |-
  2090. values is an array of string values. If the operator is In or NotIn,
  2091. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2092. the values array must be empty. This array is replaced during a strategic
  2093. merge patch.
  2094. items:
  2095. type: string
  2096. type: array
  2097. x-kubernetes-list-type: atomic
  2098. required:
  2099. - key
  2100. - operator
  2101. type: object
  2102. type: array
  2103. x-kubernetes-list-type: atomic
  2104. matchLabels:
  2105. additionalProperties:
  2106. type: string
  2107. description: |-
  2108. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2109. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2110. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2111. type: object
  2112. type: object
  2113. x-kubernetes-map-type: atomic
  2114. type: object
  2115. type: object
  2116. template:
  2117. description: Template defines a blueprint for the created Secret resource.
  2118. properties:
  2119. data:
  2120. additionalProperties:
  2121. type: string
  2122. type: object
  2123. engineVersion:
  2124. default: v2
  2125. description: |-
  2126. EngineVersion specifies the template engine version
  2127. that should be used to compile/execute the
  2128. template specified in .data and .templateFrom[].
  2129. enum:
  2130. - v2
  2131. type: string
  2132. mergePolicy:
  2133. default: Replace
  2134. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2135. enum:
  2136. - Replace
  2137. - Merge
  2138. type: string
  2139. metadata:
  2140. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2141. properties:
  2142. annotations:
  2143. additionalProperties:
  2144. type: string
  2145. type: object
  2146. finalizers:
  2147. items:
  2148. type: string
  2149. type: array
  2150. labels:
  2151. additionalProperties:
  2152. type: string
  2153. type: object
  2154. type: object
  2155. templateFrom:
  2156. items:
  2157. description: |-
  2158. TemplateFrom specifies a source for templates.
  2159. Each item in the list can either reference a ConfigMap or a Secret resource.
  2160. properties:
  2161. configMap:
  2162. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2163. properties:
  2164. items:
  2165. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2166. items:
  2167. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2168. properties:
  2169. key:
  2170. description: A key in the ConfigMap/Secret
  2171. maxLength: 253
  2172. minLength: 1
  2173. pattern: ^[-._a-zA-Z0-9]+$
  2174. type: string
  2175. templateAs:
  2176. default: Values
  2177. description: TemplateScope specifies how the template keys should be interpreted.
  2178. enum:
  2179. - Values
  2180. - KeysAndValues
  2181. type: string
  2182. required:
  2183. - key
  2184. type: object
  2185. type: array
  2186. name:
  2187. description: The name of the ConfigMap/Secret resource
  2188. maxLength: 253
  2189. minLength: 1
  2190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2191. type: string
  2192. required:
  2193. - items
  2194. - name
  2195. type: object
  2196. literal:
  2197. type: string
  2198. secret:
  2199. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2200. properties:
  2201. items:
  2202. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2203. items:
  2204. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2205. properties:
  2206. key:
  2207. description: A key in the ConfigMap/Secret
  2208. maxLength: 253
  2209. minLength: 1
  2210. pattern: ^[-._a-zA-Z0-9]+$
  2211. type: string
  2212. templateAs:
  2213. default: Values
  2214. description: TemplateScope specifies how the template keys should be interpreted.
  2215. enum:
  2216. - Values
  2217. - KeysAndValues
  2218. type: string
  2219. required:
  2220. - key
  2221. type: object
  2222. type: array
  2223. name:
  2224. description: The name of the ConfigMap/Secret resource
  2225. maxLength: 253
  2226. minLength: 1
  2227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2228. type: string
  2229. required:
  2230. - items
  2231. - name
  2232. type: object
  2233. target:
  2234. default: Data
  2235. description: |-
  2236. Target specifies where to place the template result.
  2237. For Secret resources, common values are: "Data", "Annotations", "Labels".
  2238. For custom resources (when spec.target.manifest is set), this supports
  2239. nested paths like "spec.database.config" or "data".
  2240. type: string
  2241. valuesDecodingStrategy:
  2242. default: None
  2243. description: Used to define a decoding Strategy for the rendered template values.
  2244. enum:
  2245. - Auto
  2246. - Base64
  2247. - Base64URL
  2248. - None
  2249. type: string
  2250. type: object
  2251. type: array
  2252. type:
  2253. type: string
  2254. type: object
  2255. updatePolicy:
  2256. default: Replace
  2257. description: UpdatePolicy to handle Secrets in the provider.
  2258. enum:
  2259. - Replace
  2260. - IfNotExists
  2261. type: string
  2262. required:
  2263. - secretStoreRefs
  2264. - selector
  2265. type: object
  2266. refreshTime:
  2267. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2268. type: string
  2269. required:
  2270. - pushSecretSpec
  2271. type: object
  2272. status:
  2273. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2274. properties:
  2275. conditions:
  2276. items:
  2277. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2278. properties:
  2279. lastTransitionTime:
  2280. format: date-time
  2281. type: string
  2282. message:
  2283. type: string
  2284. reason:
  2285. type: string
  2286. status:
  2287. type: string
  2288. type:
  2289. description: PushSecretConditionType indicates the condition of the PushSecret.
  2290. type: string
  2291. required:
  2292. - status
  2293. - type
  2294. type: object
  2295. type: array
  2296. failedNamespaces:
  2297. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2298. items:
  2299. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2300. properties:
  2301. namespace:
  2302. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2303. type: string
  2304. reason:
  2305. description: Reason is why the PushSecret failed to apply to the namespace
  2306. type: string
  2307. required:
  2308. - namespace
  2309. type: object
  2310. type: array
  2311. provisionedNamespaces:
  2312. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2313. items:
  2314. type: string
  2315. type: array
  2316. pushSecretName:
  2317. type: string
  2318. type: object
  2319. type: object
  2320. served: true
  2321. storage: true
  2322. subresources:
  2323. status: {}
  2324. ---
  2325. apiVersion: apiextensions.k8s.io/v1
  2326. kind: CustomResourceDefinition
  2327. metadata:
  2328. annotations:
  2329. controller-gen.kubebuilder.io/version: v0.19.0
  2330. labels:
  2331. external-secrets.io/component: controller
  2332. name: clustersecretstores.external-secrets.io
  2333. spec:
  2334. group: external-secrets.io
  2335. names:
  2336. categories:
  2337. - external-secrets
  2338. kind: ClusterSecretStore
  2339. listKind: ClusterSecretStoreList
  2340. plural: clustersecretstores
  2341. shortNames:
  2342. - css
  2343. singular: clustersecretstore
  2344. scope: Cluster
  2345. versions:
  2346. - additionalPrinterColumns:
  2347. - jsonPath: .metadata.creationTimestamp
  2348. name: AGE
  2349. type: date
  2350. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2351. name: Status
  2352. type: string
  2353. - jsonPath: .status.capabilities
  2354. name: Capabilities
  2355. type: string
  2356. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2357. name: Ready
  2358. type: string
  2359. name: v1
  2360. schema:
  2361. openAPIV3Schema:
  2362. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2363. properties:
  2364. apiVersion:
  2365. description: |-
  2366. APIVersion defines the versioned schema of this representation of an object.
  2367. Servers should convert recognized schemas to the latest internal value, and
  2368. may reject unrecognized values.
  2369. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2370. type: string
  2371. kind:
  2372. description: |-
  2373. Kind is a string value representing the REST resource this object represents.
  2374. Servers may infer this from the endpoint the client submits requests to.
  2375. Cannot be updated.
  2376. In CamelCase.
  2377. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2378. type: string
  2379. metadata:
  2380. type: object
  2381. spec:
  2382. description: SecretStoreSpec defines the desired state of SecretStore.
  2383. properties:
  2384. conditions:
  2385. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2386. items:
  2387. description: |-
  2388. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2389. for a ClusterSecretStore instance.
  2390. properties:
  2391. namespaceRegexes:
  2392. description: Choose namespaces by using regex matching
  2393. items:
  2394. type: string
  2395. type: array
  2396. namespaceSelector:
  2397. description: Choose namespace using a labelSelector
  2398. properties:
  2399. matchExpressions:
  2400. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2401. items:
  2402. description: |-
  2403. A label selector requirement is a selector that contains values, a key, and an operator that
  2404. relates the key and values.
  2405. properties:
  2406. key:
  2407. description: key is the label key that the selector applies to.
  2408. type: string
  2409. operator:
  2410. description: |-
  2411. operator represents a key's relationship to a set of values.
  2412. Valid operators are In, NotIn, Exists and DoesNotExist.
  2413. type: string
  2414. values:
  2415. description: |-
  2416. values is an array of string values. If the operator is In or NotIn,
  2417. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2418. the values array must be empty. This array is replaced during a strategic
  2419. merge patch.
  2420. items:
  2421. type: string
  2422. type: array
  2423. x-kubernetes-list-type: atomic
  2424. required:
  2425. - key
  2426. - operator
  2427. type: object
  2428. type: array
  2429. x-kubernetes-list-type: atomic
  2430. matchLabels:
  2431. additionalProperties:
  2432. type: string
  2433. description: |-
  2434. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2435. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2436. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2437. type: object
  2438. type: object
  2439. x-kubernetes-map-type: atomic
  2440. namespaces:
  2441. description: Choose namespaces by name
  2442. items:
  2443. maxLength: 63
  2444. minLength: 1
  2445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2446. type: string
  2447. type: array
  2448. type: object
  2449. type: array
  2450. controller:
  2451. description: |-
  2452. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2453. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2454. type: string
  2455. provider:
  2456. description: Used to configure the provider. Only one provider may be set
  2457. maxProperties: 1
  2458. minProperties: 1
  2459. properties:
  2460. akeyless:
  2461. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2462. properties:
  2463. akeylessGWApiURL:
  2464. description: Akeyless GW API Url from which the secrets to be fetched from.
  2465. type: string
  2466. authSecretRef:
  2467. description: Auth configures how the operator authenticates with Akeyless.
  2468. properties:
  2469. kubernetesAuth:
  2470. description: |-
  2471. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2472. token stored in the named Secret resource.
  2473. properties:
  2474. accessID:
  2475. description: the Akeyless Kubernetes auth-method access-id
  2476. type: string
  2477. k8sConfName:
  2478. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2479. type: string
  2480. secretRef:
  2481. description: |-
  2482. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2483. for authenticating with Akeyless. If a name is specified without a key,
  2484. `token` is the default. If one is not specified, the one bound to
  2485. the controller will be used.
  2486. properties:
  2487. key:
  2488. description: |-
  2489. A key in the referenced Secret.
  2490. Some instances of this field may be defaulted, in others it may be required.
  2491. maxLength: 253
  2492. minLength: 1
  2493. pattern: ^[-._a-zA-Z0-9]+$
  2494. type: string
  2495. name:
  2496. description: The name of the Secret resource being referred to.
  2497. maxLength: 253
  2498. minLength: 1
  2499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2500. type: string
  2501. namespace:
  2502. description: |-
  2503. The namespace of the Secret resource being referred to.
  2504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2505. maxLength: 63
  2506. minLength: 1
  2507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2508. type: string
  2509. type: object
  2510. serviceAccountRef:
  2511. description: |-
  2512. Optional service account field containing the name of a kubernetes ServiceAccount.
  2513. If the service account is specified, the service account secret token JWT will be used
  2514. for authenticating with Akeyless. If the service account selector is not supplied,
  2515. the secretRef will be used instead.
  2516. properties:
  2517. audiences:
  2518. description: |-
  2519. Audience specifies the `aud` claim for the service account token
  2520. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2521. then this audiences will be appended to the list
  2522. items:
  2523. type: string
  2524. type: array
  2525. name:
  2526. description: The name of the ServiceAccount resource being referred to.
  2527. maxLength: 253
  2528. minLength: 1
  2529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2530. type: string
  2531. namespace:
  2532. description: |-
  2533. Namespace of the resource being referred to.
  2534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2535. maxLength: 63
  2536. minLength: 1
  2537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2538. type: string
  2539. required:
  2540. - name
  2541. type: object
  2542. required:
  2543. - accessID
  2544. - k8sConfName
  2545. type: object
  2546. secretRef:
  2547. description: |-
  2548. Reference to a Secret that contains the details
  2549. to authenticate with Akeyless.
  2550. properties:
  2551. accessID:
  2552. description: The SecretAccessID is used for authentication
  2553. properties:
  2554. key:
  2555. description: |-
  2556. A key in the referenced Secret.
  2557. Some instances of this field may be defaulted, in others it may be required.
  2558. maxLength: 253
  2559. minLength: 1
  2560. pattern: ^[-._a-zA-Z0-9]+$
  2561. type: string
  2562. name:
  2563. description: The name of the Secret resource being referred to.
  2564. maxLength: 253
  2565. minLength: 1
  2566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2567. type: string
  2568. namespace:
  2569. description: |-
  2570. The namespace of the Secret resource being referred to.
  2571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2572. maxLength: 63
  2573. minLength: 1
  2574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2575. type: string
  2576. type: object
  2577. accessType:
  2578. description: |-
  2579. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2580. In some instances, `key` is a required field.
  2581. properties:
  2582. key:
  2583. description: |-
  2584. A key in the referenced Secret.
  2585. Some instances of this field may be defaulted, in others it may be required.
  2586. maxLength: 253
  2587. minLength: 1
  2588. pattern: ^[-._a-zA-Z0-9]+$
  2589. type: string
  2590. name:
  2591. description: The name of the Secret resource being referred to.
  2592. maxLength: 253
  2593. minLength: 1
  2594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2595. type: string
  2596. namespace:
  2597. description: |-
  2598. The namespace of the Secret resource being referred to.
  2599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2600. maxLength: 63
  2601. minLength: 1
  2602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2603. type: string
  2604. type: object
  2605. accessTypeParam:
  2606. description: |-
  2607. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2608. In some instances, `key` is a required field.
  2609. properties:
  2610. key:
  2611. description: |-
  2612. A key in the referenced Secret.
  2613. Some instances of this field may be defaulted, in others it may be required.
  2614. maxLength: 253
  2615. minLength: 1
  2616. pattern: ^[-._a-zA-Z0-9]+$
  2617. type: string
  2618. name:
  2619. description: The name of the Secret resource being referred to.
  2620. maxLength: 253
  2621. minLength: 1
  2622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2623. type: string
  2624. namespace:
  2625. description: |-
  2626. The namespace of the Secret resource being referred to.
  2627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2628. maxLength: 63
  2629. minLength: 1
  2630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2631. type: string
  2632. type: object
  2633. type: object
  2634. serviceAccountRef:
  2635. description: |-
  2636. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2637. authentication on AKS Workload Identity. The operator obtains a federated
  2638. identity token from this ServiceAccount via the TokenRequest API instead
  2639. of using the ESO controller pod identity. Ignored for other access types.
  2640. properties:
  2641. audiences:
  2642. description: |-
  2643. Audience specifies the `aud` claim for the service account token
  2644. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2645. then this audiences will be appended to the list
  2646. items:
  2647. type: string
  2648. type: array
  2649. name:
  2650. description: The name of the ServiceAccount resource being referred to.
  2651. maxLength: 253
  2652. minLength: 1
  2653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2654. type: string
  2655. namespace:
  2656. description: |-
  2657. Namespace of the resource being referred to.
  2658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2659. maxLength: 63
  2660. minLength: 1
  2661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2662. type: string
  2663. required:
  2664. - name
  2665. type: object
  2666. type: object
  2667. caBundle:
  2668. description: |-
  2669. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2670. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2671. are used to validate the TLS connection.
  2672. format: byte
  2673. type: string
  2674. caProvider:
  2675. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2676. properties:
  2677. key:
  2678. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2679. maxLength: 253
  2680. minLength: 1
  2681. pattern: ^[-._a-zA-Z0-9]+$
  2682. type: string
  2683. name:
  2684. description: The name of the object located at the provider type.
  2685. maxLength: 253
  2686. minLength: 1
  2687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2688. type: string
  2689. namespace:
  2690. description: |-
  2691. The namespace the Provider type is in.
  2692. Can only be defined when used in a ClusterSecretStore.
  2693. maxLength: 63
  2694. minLength: 1
  2695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2696. type: string
  2697. type:
  2698. description: The type of provider to use such as "Secret", or "ConfigMap".
  2699. enum:
  2700. - Secret
  2701. - ConfigMap
  2702. type: string
  2703. required:
  2704. - name
  2705. - type
  2706. type: object
  2707. ignoreCache:
  2708. description: |-
  2709. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2710. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2711. type: boolean
  2712. required:
  2713. - akeylessGWApiURL
  2714. - authSecretRef
  2715. type: object
  2716. aws:
  2717. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2718. properties:
  2719. additionalRoles:
  2720. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2721. items:
  2722. type: string
  2723. type: array
  2724. auth:
  2725. description: |-
  2726. Auth defines the information necessary to authenticate against AWS
  2727. if not set aws sdk will infer credentials from your environment
  2728. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2729. properties:
  2730. jwt:
  2731. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2732. properties:
  2733. serviceAccountRef:
  2734. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2735. properties:
  2736. audiences:
  2737. description: |-
  2738. Audience specifies the `aud` claim for the service account token
  2739. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2740. then this audiences will be appended to the list
  2741. items:
  2742. type: string
  2743. type: array
  2744. name:
  2745. description: The name of the ServiceAccount resource being referred to.
  2746. maxLength: 253
  2747. minLength: 1
  2748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2749. type: string
  2750. namespace:
  2751. description: |-
  2752. Namespace of the resource being referred to.
  2753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2754. maxLength: 63
  2755. minLength: 1
  2756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2757. type: string
  2758. required:
  2759. - name
  2760. type: object
  2761. type: object
  2762. secretRef:
  2763. description: |-
  2764. AWSAuthSecretRef holds secret references for AWS credentials
  2765. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2766. properties:
  2767. accessKeyIDSecretRef:
  2768. description: The AccessKeyID is used for authentication
  2769. properties:
  2770. key:
  2771. description: |-
  2772. A key in the referenced Secret.
  2773. Some instances of this field may be defaulted, in others it may be required.
  2774. maxLength: 253
  2775. minLength: 1
  2776. pattern: ^[-._a-zA-Z0-9]+$
  2777. type: string
  2778. name:
  2779. description: The name of the Secret resource being referred to.
  2780. maxLength: 253
  2781. minLength: 1
  2782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2783. type: string
  2784. namespace:
  2785. description: |-
  2786. The namespace of the Secret resource being referred to.
  2787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2788. maxLength: 63
  2789. minLength: 1
  2790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2791. type: string
  2792. type: object
  2793. secretAccessKeySecretRef:
  2794. description: The SecretAccessKey is used for authentication
  2795. properties:
  2796. key:
  2797. description: |-
  2798. A key in the referenced Secret.
  2799. Some instances of this field may be defaulted, in others it may be required.
  2800. maxLength: 253
  2801. minLength: 1
  2802. pattern: ^[-._a-zA-Z0-9]+$
  2803. type: string
  2804. name:
  2805. description: The name of the Secret resource being referred to.
  2806. maxLength: 253
  2807. minLength: 1
  2808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2809. type: string
  2810. namespace:
  2811. description: |-
  2812. The namespace of the Secret resource being referred to.
  2813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2814. maxLength: 63
  2815. minLength: 1
  2816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2817. type: string
  2818. type: object
  2819. sessionTokenSecretRef:
  2820. description: |-
  2821. The SessionToken used for authentication
  2822. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2823. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2824. properties:
  2825. key:
  2826. description: |-
  2827. A key in the referenced Secret.
  2828. Some instances of this field may be defaulted, in others it may be required.
  2829. maxLength: 253
  2830. minLength: 1
  2831. pattern: ^[-._a-zA-Z0-9]+$
  2832. type: string
  2833. name:
  2834. description: The name of the Secret resource being referred to.
  2835. maxLength: 253
  2836. minLength: 1
  2837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2838. type: string
  2839. namespace:
  2840. description: |-
  2841. The namespace of the Secret resource being referred to.
  2842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2843. maxLength: 63
  2844. minLength: 1
  2845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2846. type: string
  2847. type: object
  2848. type: object
  2849. type: object
  2850. customSessionTags:
  2851. additionalProperties:
  2852. type: string
  2853. description: |-
  2854. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2855. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2856. type: object
  2857. x-kubernetes-validations:
  2858. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2859. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2860. externalID:
  2861. description: AWS External ID set on assumed IAM roles
  2862. type: string
  2863. prefix:
  2864. description: Prefix adds a prefix to all retrieved values.
  2865. type: string
  2866. region:
  2867. description: AWS Region to be used for the provider
  2868. type: string
  2869. role:
  2870. description: Role is a Role ARN which the provider will assume
  2871. type: string
  2872. secretsManager:
  2873. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2874. properties:
  2875. forceDeleteWithoutRecovery:
  2876. description: |-
  2877. Specifies whether to delete the secret without any recovery window. You
  2878. can't use both this parameter and RecoveryWindowInDays in the same call.
  2879. If you don't use either, then by default Secrets Manager uses a 30 day
  2880. recovery window.
  2881. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2882. type: boolean
  2883. recoveryWindowInDays:
  2884. description: |-
  2885. The number of days from 7 to 30 that Secrets Manager waits before
  2886. permanently deleting the secret. You can't use both this parameter and
  2887. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2888. then by default Secrets Manager uses a 30-day recovery window.
  2889. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2890. format: int64
  2891. type: integer
  2892. type: object
  2893. service:
  2894. description: Service defines which service should be used to fetch the secrets
  2895. enum:
  2896. - SecretsManager
  2897. - ParameterStore
  2898. - CertificateManager
  2899. type: string
  2900. sessionTags:
  2901. description: AWS STS assume role session tags
  2902. items:
  2903. description: |-
  2904. Tag is a key-value pair that can be attached to an AWS resource.
  2905. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2906. properties:
  2907. key:
  2908. type: string
  2909. value:
  2910. type: string
  2911. required:
  2912. - key
  2913. - value
  2914. type: object
  2915. type: array
  2916. sessionTagsPolicy:
  2917. default: None
  2918. description: |-
  2919. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2920. None (default): no tags are added.
  2921. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2922. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2923. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2924. enum:
  2925. - None
  2926. - Simple
  2927. - Custom
  2928. type: string
  2929. transitiveTagKeys:
  2930. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2931. items:
  2932. type: string
  2933. type: array
  2934. required:
  2935. - region
  2936. - service
  2937. type: object
  2938. azurekv:
  2939. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2940. properties:
  2941. authSecretRef:
  2942. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2943. properties:
  2944. clientCertificate:
  2945. description: The Azure ClientCertificate of the service principle used for authentication.
  2946. properties:
  2947. key:
  2948. description: |-
  2949. A key in the referenced Secret.
  2950. Some instances of this field may be defaulted, in others it may be required.
  2951. maxLength: 253
  2952. minLength: 1
  2953. pattern: ^[-._a-zA-Z0-9]+$
  2954. type: string
  2955. name:
  2956. description: The name of the Secret resource being referred to.
  2957. maxLength: 253
  2958. minLength: 1
  2959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2960. type: string
  2961. namespace:
  2962. description: |-
  2963. The namespace of the Secret resource being referred to.
  2964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2965. maxLength: 63
  2966. minLength: 1
  2967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2968. type: string
  2969. type: object
  2970. clientId:
  2971. description: The Azure clientId of the service principle or managed identity used for authentication.
  2972. properties:
  2973. key:
  2974. description: |-
  2975. A key in the referenced Secret.
  2976. Some instances of this field may be defaulted, in others it may be required.
  2977. maxLength: 253
  2978. minLength: 1
  2979. pattern: ^[-._a-zA-Z0-9]+$
  2980. type: string
  2981. name:
  2982. description: The name of the Secret resource being referred to.
  2983. maxLength: 253
  2984. minLength: 1
  2985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2986. type: string
  2987. namespace:
  2988. description: |-
  2989. The namespace of the Secret resource being referred to.
  2990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2991. maxLength: 63
  2992. minLength: 1
  2993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2994. type: string
  2995. type: object
  2996. clientSecret:
  2997. description: The Azure ClientSecret of the service principle used for authentication.
  2998. properties:
  2999. key:
  3000. description: |-
  3001. A key in the referenced Secret.
  3002. Some instances of this field may be defaulted, in others it may be required.
  3003. maxLength: 253
  3004. minLength: 1
  3005. pattern: ^[-._a-zA-Z0-9]+$
  3006. type: string
  3007. name:
  3008. description: The name of the Secret resource being referred to.
  3009. maxLength: 253
  3010. minLength: 1
  3011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3012. type: string
  3013. namespace:
  3014. description: |-
  3015. The namespace of the Secret resource being referred to.
  3016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3017. maxLength: 63
  3018. minLength: 1
  3019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3020. type: string
  3021. type: object
  3022. tenantId:
  3023. description: The Azure tenantId of the managed identity used for authentication.
  3024. properties:
  3025. key:
  3026. description: |-
  3027. A key in the referenced Secret.
  3028. Some instances of this field may be defaulted, in others it may be required.
  3029. maxLength: 253
  3030. minLength: 1
  3031. pattern: ^[-._a-zA-Z0-9]+$
  3032. type: string
  3033. name:
  3034. description: The name of the Secret resource being referred to.
  3035. maxLength: 253
  3036. minLength: 1
  3037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3038. type: string
  3039. namespace:
  3040. description: |-
  3041. The namespace of the Secret resource being referred to.
  3042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3043. maxLength: 63
  3044. minLength: 1
  3045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3046. type: string
  3047. type: object
  3048. type: object
  3049. authType:
  3050. default: ServicePrincipal
  3051. description: |-
  3052. Auth type defines how to authenticate to the keyvault service.
  3053. Valid values are:
  3054. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3055. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3056. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3057. enum:
  3058. - ServicePrincipal
  3059. - ManagedIdentity
  3060. - WorkloadIdentity
  3061. type: string
  3062. customCloudConfig:
  3063. description: |-
  3064. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3065. Required when EnvironmentType is AzureStackCloud.
  3066. Optional for other environment types - useful for Azure China when using Workload Identity
  3067. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3068. standard China Cloud endpoint (login.chinacloudapi.cn).
  3069. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3070. configuration is not supported with the legacy go-autorest SDK.
  3071. properties:
  3072. activeDirectoryEndpoint:
  3073. description: |-
  3074. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3075. Required when using custom cloud configuration
  3076. type: string
  3077. keyVaultDNSSuffix:
  3078. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3079. type: string
  3080. keyVaultEndpoint:
  3081. description: KeyVaultEndpoint is the Key Vault service endpoint
  3082. type: string
  3083. resourceManagerEndpoint:
  3084. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3085. type: string
  3086. required:
  3087. - activeDirectoryEndpoint
  3088. type: object
  3089. environmentType:
  3090. default: PublicCloud
  3091. description: |-
  3092. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3093. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3094. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3095. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3096. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3097. enum:
  3098. - PublicCloud
  3099. - USGovernmentCloud
  3100. - ChinaCloud
  3101. - GermanCloud
  3102. - AzureStackCloud
  3103. type: string
  3104. identityId:
  3105. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3106. type: string
  3107. serviceAccountRef:
  3108. description: |-
  3109. ServiceAccountRef specified the service account
  3110. that should be used when authenticating with WorkloadIdentity.
  3111. properties:
  3112. audiences:
  3113. description: |-
  3114. Audience specifies the `aud` claim for the service account token
  3115. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3116. then this audiences will be appended to the list
  3117. items:
  3118. type: string
  3119. type: array
  3120. name:
  3121. description: The name of the ServiceAccount resource being referred to.
  3122. maxLength: 253
  3123. minLength: 1
  3124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3125. type: string
  3126. namespace:
  3127. description: |-
  3128. Namespace of the resource being referred to.
  3129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3130. maxLength: 63
  3131. minLength: 1
  3132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3133. type: string
  3134. required:
  3135. - name
  3136. type: object
  3137. tenantId:
  3138. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3139. type: string
  3140. useAzureSDK:
  3141. default: false
  3142. description: |-
  3143. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3144. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3145. type: boolean
  3146. vaultUrl:
  3147. description: Vault Url from which the secrets to be fetched from.
  3148. type: string
  3149. required:
  3150. - vaultUrl
  3151. type: object
  3152. barbican:
  3153. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3154. properties:
  3155. auth:
  3156. description: BarbicanAuth contains the authentication information for Barbican.
  3157. properties:
  3158. password:
  3159. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3160. properties:
  3161. secretRef:
  3162. description: |-
  3163. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3164. In some instances, `key` is a required field.
  3165. properties:
  3166. key:
  3167. description: |-
  3168. A key in the referenced Secret.
  3169. Some instances of this field may be defaulted, in others it may be required.
  3170. maxLength: 253
  3171. minLength: 1
  3172. pattern: ^[-._a-zA-Z0-9]+$
  3173. type: string
  3174. name:
  3175. description: The name of the Secret resource being referred to.
  3176. maxLength: 253
  3177. minLength: 1
  3178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3179. type: string
  3180. namespace:
  3181. description: |-
  3182. The namespace of the Secret resource being referred to.
  3183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3184. maxLength: 63
  3185. minLength: 1
  3186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3187. type: string
  3188. type: object
  3189. required:
  3190. - secretRef
  3191. type: object
  3192. username:
  3193. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3194. maxProperties: 1
  3195. minProperties: 1
  3196. properties:
  3197. secretRef:
  3198. description: |-
  3199. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3200. In some instances, `key` is a required field.
  3201. properties:
  3202. key:
  3203. description: |-
  3204. A key in the referenced Secret.
  3205. Some instances of this field may be defaulted, in others it may be required.
  3206. maxLength: 253
  3207. minLength: 1
  3208. pattern: ^[-._a-zA-Z0-9]+$
  3209. type: string
  3210. name:
  3211. description: The name of the Secret resource being referred to.
  3212. maxLength: 253
  3213. minLength: 1
  3214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3215. type: string
  3216. namespace:
  3217. description: |-
  3218. The namespace of the Secret resource being referred to.
  3219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3220. maxLength: 63
  3221. minLength: 1
  3222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3223. type: string
  3224. type: object
  3225. value:
  3226. type: string
  3227. type: object
  3228. required:
  3229. - password
  3230. - username
  3231. type: object
  3232. authURL:
  3233. type: string
  3234. domainName:
  3235. type: string
  3236. region:
  3237. type: string
  3238. tenantName:
  3239. type: string
  3240. required:
  3241. - auth
  3242. type: object
  3243. beyondtrust:
  3244. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3245. properties:
  3246. auth:
  3247. description: Auth configures how the operator authenticates with Beyondtrust.
  3248. properties:
  3249. apiKey:
  3250. description: APIKey If not provided then ClientID/ClientSecret become required.
  3251. properties:
  3252. secretRef:
  3253. description: SecretRef references a key in a secret that will be used as value.
  3254. properties:
  3255. key:
  3256. description: |-
  3257. A key in the referenced Secret.
  3258. Some instances of this field may be defaulted, in others it may be required.
  3259. maxLength: 253
  3260. minLength: 1
  3261. pattern: ^[-._a-zA-Z0-9]+$
  3262. type: string
  3263. name:
  3264. description: The name of the Secret resource being referred to.
  3265. maxLength: 253
  3266. minLength: 1
  3267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3268. type: string
  3269. namespace:
  3270. description: |-
  3271. The namespace of the Secret resource being referred to.
  3272. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3273. maxLength: 63
  3274. minLength: 1
  3275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3276. type: string
  3277. type: object
  3278. value:
  3279. description: Value can be specified directly to set a value without using a secret.
  3280. type: string
  3281. type: object
  3282. certificate:
  3283. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3284. properties:
  3285. secretRef:
  3286. description: SecretRef references a key in a secret that will be used as value.
  3287. properties:
  3288. key:
  3289. description: |-
  3290. A key in the referenced Secret.
  3291. Some instances of this field may be defaulted, in others it may be required.
  3292. maxLength: 253
  3293. minLength: 1
  3294. pattern: ^[-._a-zA-Z0-9]+$
  3295. type: string
  3296. name:
  3297. description: The name of the Secret resource being referred to.
  3298. maxLength: 253
  3299. minLength: 1
  3300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3301. type: string
  3302. namespace:
  3303. description: |-
  3304. The namespace of the Secret resource being referred to.
  3305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3306. maxLength: 63
  3307. minLength: 1
  3308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3309. type: string
  3310. type: object
  3311. value:
  3312. description: Value can be specified directly to set a value without using a secret.
  3313. type: string
  3314. type: object
  3315. certificateKey:
  3316. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3317. properties:
  3318. secretRef:
  3319. description: SecretRef references a key in a secret that will be used as value.
  3320. properties:
  3321. key:
  3322. description: |-
  3323. A key in the referenced Secret.
  3324. Some instances of this field may be defaulted, in others it may be required.
  3325. maxLength: 253
  3326. minLength: 1
  3327. pattern: ^[-._a-zA-Z0-9]+$
  3328. type: string
  3329. name:
  3330. description: The name of the Secret resource being referred to.
  3331. maxLength: 253
  3332. minLength: 1
  3333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3334. type: string
  3335. namespace:
  3336. description: |-
  3337. The namespace of the Secret resource being referred to.
  3338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3339. maxLength: 63
  3340. minLength: 1
  3341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3342. type: string
  3343. type: object
  3344. value:
  3345. description: Value can be specified directly to set a value without using a secret.
  3346. type: string
  3347. type: object
  3348. clientId:
  3349. description: ClientID is the API OAuth Client ID.
  3350. properties:
  3351. secretRef:
  3352. description: SecretRef references a key in a secret that will be used as value.
  3353. properties:
  3354. key:
  3355. description: |-
  3356. A key in the referenced Secret.
  3357. Some instances of this field may be defaulted, in others it may be required.
  3358. maxLength: 253
  3359. minLength: 1
  3360. pattern: ^[-._a-zA-Z0-9]+$
  3361. type: string
  3362. name:
  3363. description: The name of the Secret resource being referred to.
  3364. maxLength: 253
  3365. minLength: 1
  3366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3367. type: string
  3368. namespace:
  3369. description: |-
  3370. The namespace of the Secret resource being referred to.
  3371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3372. maxLength: 63
  3373. minLength: 1
  3374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3375. type: string
  3376. type: object
  3377. value:
  3378. description: Value can be specified directly to set a value without using a secret.
  3379. type: string
  3380. type: object
  3381. clientSecret:
  3382. description: ClientSecret is the API OAuth Client Secret.
  3383. properties:
  3384. secretRef:
  3385. description: SecretRef references a key in a secret that will be used as value.
  3386. properties:
  3387. key:
  3388. description: |-
  3389. A key in the referenced Secret.
  3390. Some instances of this field may be defaulted, in others it may be required.
  3391. maxLength: 253
  3392. minLength: 1
  3393. pattern: ^[-._a-zA-Z0-9]+$
  3394. type: string
  3395. name:
  3396. description: The name of the Secret resource being referred to.
  3397. maxLength: 253
  3398. minLength: 1
  3399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3400. type: string
  3401. namespace:
  3402. description: |-
  3403. The namespace of the Secret resource being referred to.
  3404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3405. maxLength: 63
  3406. minLength: 1
  3407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3408. type: string
  3409. type: object
  3410. value:
  3411. description: Value can be specified directly to set a value without using a secret.
  3412. type: string
  3413. type: object
  3414. type: object
  3415. server:
  3416. description: Auth configures how API server works.
  3417. properties:
  3418. apiUrl:
  3419. type: string
  3420. apiVersion:
  3421. type: string
  3422. clientTimeOutSeconds:
  3423. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3424. type: integer
  3425. decrypt:
  3426. default: true
  3427. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3428. type: boolean
  3429. retrievalType:
  3430. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3431. type: string
  3432. separator:
  3433. description: A character that separates the folder names.
  3434. type: string
  3435. verifyCA:
  3436. type: boolean
  3437. required:
  3438. - apiUrl
  3439. - verifyCA
  3440. type: object
  3441. required:
  3442. - auth
  3443. - server
  3444. type: object
  3445. beyondtrustworkloadcredentials:
  3446. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3447. properties:
  3448. auth:
  3449. description: |-
  3450. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3451. Currently supports API key authentication via Kubernetes secret reference.
  3452. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3453. properties:
  3454. apikey:
  3455. description: |-
  3456. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3457. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3458. properties:
  3459. token:
  3460. description: |-
  3461. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3462. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3463. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3464. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3465. properties:
  3466. key:
  3467. description: |-
  3468. A key in the referenced Secret.
  3469. Some instances of this field may be defaulted, in others it may be required.
  3470. maxLength: 253
  3471. minLength: 1
  3472. pattern: ^[-._a-zA-Z0-9]+$
  3473. type: string
  3474. name:
  3475. description: The name of the Secret resource being referred to.
  3476. maxLength: 253
  3477. minLength: 1
  3478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3479. type: string
  3480. namespace:
  3481. description: |-
  3482. The namespace of the Secret resource being referred to.
  3483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3484. maxLength: 63
  3485. minLength: 1
  3486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3487. type: string
  3488. type: object
  3489. required:
  3490. - token
  3491. type: object
  3492. required:
  3493. - apikey
  3494. type: object
  3495. caBundle:
  3496. description: |-
  3497. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3498. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3499. If not set, the system's trusted root certificates are used.
  3500. format: byte
  3501. type: string
  3502. caProvider:
  3503. description: |-
  3504. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3505. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3506. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3507. properties:
  3508. key:
  3509. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3510. maxLength: 253
  3511. minLength: 1
  3512. pattern: ^[-._a-zA-Z0-9]+$
  3513. type: string
  3514. name:
  3515. description: The name of the object located at the provider type.
  3516. maxLength: 253
  3517. minLength: 1
  3518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3519. type: string
  3520. namespace:
  3521. description: |-
  3522. The namespace the Provider type is in.
  3523. Can only be defined when used in a ClusterSecretStore.
  3524. maxLength: 63
  3525. minLength: 1
  3526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3527. type: string
  3528. type:
  3529. description: The type of provider to use such as "Secret", or "ConfigMap".
  3530. enum:
  3531. - Secret
  3532. - ConfigMap
  3533. type: string
  3534. required:
  3535. - name
  3536. - type
  3537. type: object
  3538. folderPath:
  3539. description: |-
  3540. FolderPath specifies the default folder path for secret retrieval.
  3541. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3542. Example: "production/database" or "dev/api-keys"
  3543. Leave empty to retrieve secrets from the root folder.
  3544. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3545. type: string
  3546. server:
  3547. description: |-
  3548. Server configures the BeyondTrust Workload Credentials server connection details.
  3549. Includes the API URL and Site ID for your BeyondTrust instance.
  3550. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3551. properties:
  3552. apiUrl:
  3553. description: |-
  3554. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3555. This should be the full URL to your BeyondTrust instance.
  3556. Example: https://api.beyondtrust.io/siie
  3557. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3558. type: string
  3559. siteId:
  3560. description: |-
  3561. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3562. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3563. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3564. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3565. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3566. type: string
  3567. required:
  3568. - apiUrl
  3569. - siteId
  3570. type: object
  3571. required:
  3572. - auth
  3573. - server
  3574. type: object
  3575. bitwardensecretsmanager:
  3576. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3577. properties:
  3578. apiURL:
  3579. type: string
  3580. auth:
  3581. description: |-
  3582. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3583. Make sure that the token being used has permissions on the given secret.
  3584. properties:
  3585. secretRef:
  3586. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3587. properties:
  3588. credentials:
  3589. description: AccessToken used for the bitwarden instance.
  3590. properties:
  3591. key:
  3592. description: |-
  3593. A key in the referenced Secret.
  3594. Some instances of this field may be defaulted, in others it may be required.
  3595. maxLength: 253
  3596. minLength: 1
  3597. pattern: ^[-._a-zA-Z0-9]+$
  3598. type: string
  3599. name:
  3600. description: The name of the Secret resource being referred to.
  3601. maxLength: 253
  3602. minLength: 1
  3603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3604. type: string
  3605. namespace:
  3606. description: |-
  3607. The namespace of the Secret resource being referred to.
  3608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3609. maxLength: 63
  3610. minLength: 1
  3611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3612. type: string
  3613. type: object
  3614. required:
  3615. - credentials
  3616. type: object
  3617. required:
  3618. - secretRef
  3619. type: object
  3620. bitwardenServerSDKURL:
  3621. type: string
  3622. caBundle:
  3623. description: |-
  3624. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3625. can be performed.
  3626. type: string
  3627. caProvider:
  3628. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3629. properties:
  3630. key:
  3631. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3632. maxLength: 253
  3633. minLength: 1
  3634. pattern: ^[-._a-zA-Z0-9]+$
  3635. type: string
  3636. name:
  3637. description: The name of the object located at the provider type.
  3638. maxLength: 253
  3639. minLength: 1
  3640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3641. type: string
  3642. namespace:
  3643. description: |-
  3644. The namespace the Provider type is in.
  3645. Can only be defined when used in a ClusterSecretStore.
  3646. maxLength: 63
  3647. minLength: 1
  3648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3649. type: string
  3650. type:
  3651. description: The type of provider to use such as "Secret", or "ConfigMap".
  3652. enum:
  3653. - Secret
  3654. - ConfigMap
  3655. type: string
  3656. required:
  3657. - name
  3658. - type
  3659. type: object
  3660. identityURL:
  3661. type: string
  3662. organizationID:
  3663. description: OrganizationID determines which organization this secret store manages.
  3664. type: string
  3665. projectID:
  3666. description: ProjectID determines which project this secret store manages.
  3667. type: string
  3668. required:
  3669. - auth
  3670. - organizationID
  3671. - projectID
  3672. type: object
  3673. chef:
  3674. description: Chef configures this store to sync secrets with chef server
  3675. properties:
  3676. auth:
  3677. description: Auth defines the information necessary to authenticate against chef Server
  3678. properties:
  3679. secretRef:
  3680. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3681. properties:
  3682. privateKeySecretRef:
  3683. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3684. properties:
  3685. key:
  3686. description: |-
  3687. A key in the referenced Secret.
  3688. Some instances of this field may be defaulted, in others it may be required.
  3689. maxLength: 253
  3690. minLength: 1
  3691. pattern: ^[-._a-zA-Z0-9]+$
  3692. type: string
  3693. name:
  3694. description: The name of the Secret resource being referred to.
  3695. maxLength: 253
  3696. minLength: 1
  3697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3698. type: string
  3699. namespace:
  3700. description: |-
  3701. The namespace of the Secret resource being referred to.
  3702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3703. maxLength: 63
  3704. minLength: 1
  3705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3706. type: string
  3707. type: object
  3708. required:
  3709. - privateKeySecretRef
  3710. type: object
  3711. required:
  3712. - secretRef
  3713. type: object
  3714. serverUrl:
  3715. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3716. type: string
  3717. username:
  3718. description: UserName should be the user ID on the chef server
  3719. type: string
  3720. required:
  3721. - auth
  3722. - serverUrl
  3723. - username
  3724. type: object
  3725. cloudrusm:
  3726. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3727. properties:
  3728. auth:
  3729. description: CSMAuth contains a secretRef for credentials.
  3730. properties:
  3731. secretRef:
  3732. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3733. properties:
  3734. accessKeyIDSecretRef:
  3735. description: The AccessKeyID is used for authentication
  3736. properties:
  3737. key:
  3738. description: |-
  3739. A key in the referenced Secret.
  3740. Some instances of this field may be defaulted, in others it may be required.
  3741. maxLength: 253
  3742. minLength: 1
  3743. pattern: ^[-._a-zA-Z0-9]+$
  3744. type: string
  3745. name:
  3746. description: The name of the Secret resource being referred to.
  3747. maxLength: 253
  3748. minLength: 1
  3749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3750. type: string
  3751. namespace:
  3752. description: |-
  3753. The namespace of the Secret resource being referred to.
  3754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3755. maxLength: 63
  3756. minLength: 1
  3757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3758. type: string
  3759. type: object
  3760. accessKeySecretSecretRef:
  3761. description: The AccessKeySecret is used for authentication
  3762. properties:
  3763. key:
  3764. description: |-
  3765. A key in the referenced Secret.
  3766. Some instances of this field may be defaulted, in others it may be required.
  3767. maxLength: 253
  3768. minLength: 1
  3769. pattern: ^[-._a-zA-Z0-9]+$
  3770. type: string
  3771. name:
  3772. description: The name of the Secret resource being referred to.
  3773. maxLength: 253
  3774. minLength: 1
  3775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3776. type: string
  3777. namespace:
  3778. description: |-
  3779. The namespace of the Secret resource being referred to.
  3780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3781. maxLength: 63
  3782. minLength: 1
  3783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3784. type: string
  3785. type: object
  3786. required:
  3787. - accessKeyIDSecretRef
  3788. - accessKeySecretSecretRef
  3789. type: object
  3790. type: object
  3791. projectID:
  3792. description: ProjectID is the project, which the secrets are stored in.
  3793. type: string
  3794. required:
  3795. - auth
  3796. type: object
  3797. conjur:
  3798. description: Conjur configures this store to sync secrets using conjur provider
  3799. properties:
  3800. auth:
  3801. description: Defines authentication settings for connecting to Conjur.
  3802. maxProperties: 1
  3803. minProperties: 1
  3804. properties:
  3805. apikey:
  3806. description: Authenticates with Conjur using an API key.
  3807. properties:
  3808. account:
  3809. description: Account is the Conjur organization account name.
  3810. type: string
  3811. apiKeyRef:
  3812. description: |-
  3813. A reference to a specific 'key' containing the Conjur API key
  3814. within a Secret resource. In some instances, `key` is a required field.
  3815. properties:
  3816. key:
  3817. description: |-
  3818. A key in the referenced Secret.
  3819. Some instances of this field may be defaulted, in others it may be required.
  3820. maxLength: 253
  3821. minLength: 1
  3822. pattern: ^[-._a-zA-Z0-9]+$
  3823. type: string
  3824. name:
  3825. description: The name of the Secret resource being referred to.
  3826. maxLength: 253
  3827. minLength: 1
  3828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3829. type: string
  3830. namespace:
  3831. description: |-
  3832. The namespace of the Secret resource being referred to.
  3833. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3834. maxLength: 63
  3835. minLength: 1
  3836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3837. type: string
  3838. type: object
  3839. userRef:
  3840. description: |-
  3841. A reference to a specific 'key' containing the Conjur username
  3842. within a Secret resource. In some instances, `key` is a required field.
  3843. properties:
  3844. key:
  3845. description: |-
  3846. A key in the referenced Secret.
  3847. Some instances of this field may be defaulted, in others it may be required.
  3848. maxLength: 253
  3849. minLength: 1
  3850. pattern: ^[-._a-zA-Z0-9]+$
  3851. type: string
  3852. name:
  3853. description: The name of the Secret resource being referred to.
  3854. maxLength: 253
  3855. minLength: 1
  3856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3857. type: string
  3858. namespace:
  3859. description: |-
  3860. The namespace of the Secret resource being referred to.
  3861. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3862. maxLength: 63
  3863. minLength: 1
  3864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3865. type: string
  3866. type: object
  3867. required:
  3868. - account
  3869. - apiKeyRef
  3870. - userRef
  3871. type: object
  3872. cert:
  3873. description: Cert enables certificate-based authentication using a client certificate and key.
  3874. properties:
  3875. account:
  3876. description: Account is the Conjur organization account name.
  3877. type: string
  3878. clientCertRef:
  3879. description: |-
  3880. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3881. within a Secret resource. The certificate must be PEM-encoded.
  3882. properties:
  3883. key:
  3884. description: |-
  3885. A key in the referenced Secret.
  3886. Some instances of this field may be defaulted, in others it may be required.
  3887. maxLength: 253
  3888. minLength: 1
  3889. pattern: ^[-._a-zA-Z0-9]+$
  3890. type: string
  3891. name:
  3892. description: The name of the Secret resource being referred to.
  3893. maxLength: 253
  3894. minLength: 1
  3895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3896. type: string
  3897. namespace:
  3898. description: |-
  3899. The namespace of the Secret resource being referred to.
  3900. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3901. maxLength: 63
  3902. minLength: 1
  3903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3904. type: string
  3905. type: object
  3906. clientKeyRef:
  3907. description: |-
  3908. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3909. within a Secret resource. The key must be PEM-encoded.
  3910. properties:
  3911. key:
  3912. description: |-
  3913. A key in the referenced Secret.
  3914. Some instances of this field may be defaulted, in others it may be required.
  3915. maxLength: 253
  3916. minLength: 1
  3917. pattern: ^[-._a-zA-Z0-9]+$
  3918. type: string
  3919. name:
  3920. description: The name of the Secret resource being referred to.
  3921. maxLength: 253
  3922. minLength: 1
  3923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3924. type: string
  3925. namespace:
  3926. description: |-
  3927. The namespace of the Secret resource being referred to.
  3928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3929. maxLength: 63
  3930. minLength: 1
  3931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3932. type: string
  3933. type: object
  3934. hostId:
  3935. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3936. type: string
  3937. serviceID:
  3938. description: The conjur authn cert webservice id
  3939. type: string
  3940. required:
  3941. - account
  3942. - clientCertRef
  3943. - clientKeyRef
  3944. - serviceID
  3945. type: object
  3946. jwt:
  3947. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3948. properties:
  3949. account:
  3950. description: Account is the Conjur organization account name.
  3951. type: string
  3952. hostId:
  3953. description: |-
  3954. Optional HostID for JWT authentication. This may be used depending
  3955. on how the Conjur JWT authenticator policy is configured.
  3956. type: string
  3957. secretRef:
  3958. description: |-
  3959. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3960. authenticate with Conjur using the JWT authentication method.
  3961. properties:
  3962. key:
  3963. description: |-
  3964. A key in the referenced Secret.
  3965. Some instances of this field may be defaulted, in others it may be required.
  3966. maxLength: 253
  3967. minLength: 1
  3968. pattern: ^[-._a-zA-Z0-9]+$
  3969. type: string
  3970. name:
  3971. description: The name of the Secret resource being referred to.
  3972. maxLength: 253
  3973. minLength: 1
  3974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3975. type: string
  3976. namespace:
  3977. description: |-
  3978. The namespace of the Secret resource being referred to.
  3979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3980. maxLength: 63
  3981. minLength: 1
  3982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3983. type: string
  3984. type: object
  3985. serviceAccountRef:
  3986. description: |-
  3987. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3988. a token for with the `TokenRequest` API.
  3989. properties:
  3990. audiences:
  3991. description: |-
  3992. Audience specifies the `aud` claim for the service account token
  3993. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3994. then this audiences will be appended to the list
  3995. items:
  3996. type: string
  3997. type: array
  3998. name:
  3999. description: The name of the ServiceAccount resource being referred to.
  4000. maxLength: 253
  4001. minLength: 1
  4002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4003. type: string
  4004. namespace:
  4005. description: |-
  4006. Namespace of the resource being referred to.
  4007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4008. maxLength: 63
  4009. minLength: 1
  4010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4011. type: string
  4012. required:
  4013. - name
  4014. type: object
  4015. serviceID:
  4016. description: The conjur authn jwt webservice id
  4017. type: string
  4018. required:
  4019. - account
  4020. - serviceID
  4021. type: object
  4022. type: object
  4023. caBundle:
  4024. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4025. type: string
  4026. caProvider:
  4027. description: |-
  4028. Used to provide custom certificate authority (CA) certificates
  4029. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4030. that contains a PEM-encoded certificate.
  4031. properties:
  4032. key:
  4033. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4034. maxLength: 253
  4035. minLength: 1
  4036. pattern: ^[-._a-zA-Z0-9]+$
  4037. type: string
  4038. name:
  4039. description: The name of the object located at the provider type.
  4040. maxLength: 253
  4041. minLength: 1
  4042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4043. type: string
  4044. namespace:
  4045. description: |-
  4046. The namespace the Provider type is in.
  4047. Can only be defined when used in a ClusterSecretStore.
  4048. maxLength: 63
  4049. minLength: 1
  4050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4051. type: string
  4052. type:
  4053. description: The type of provider to use such as "Secret", or "ConfigMap".
  4054. enum:
  4055. - Secret
  4056. - ConfigMap
  4057. type: string
  4058. required:
  4059. - name
  4060. - type
  4061. type: object
  4062. url:
  4063. description: URL is the endpoint of the Conjur instance.
  4064. type: string
  4065. required:
  4066. - auth
  4067. - url
  4068. type: object
  4069. delinea:
  4070. description: |-
  4071. Delinea DevOps Secrets Vault
  4072. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4073. properties:
  4074. clientId:
  4075. description: ClientID is the non-secret part of the credential.
  4076. properties:
  4077. secretRef:
  4078. description: SecretRef references a key in a secret that will be used as value.
  4079. properties:
  4080. key:
  4081. description: |-
  4082. A key in the referenced Secret.
  4083. Some instances of this field may be defaulted, in others it may be required.
  4084. maxLength: 253
  4085. minLength: 1
  4086. pattern: ^[-._a-zA-Z0-9]+$
  4087. type: string
  4088. name:
  4089. description: The name of the Secret resource being referred to.
  4090. maxLength: 253
  4091. minLength: 1
  4092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4093. type: string
  4094. namespace:
  4095. description: |-
  4096. The namespace of the Secret resource being referred to.
  4097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4098. maxLength: 63
  4099. minLength: 1
  4100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4101. type: string
  4102. type: object
  4103. value:
  4104. description: Value can be specified directly to set a value without using a secret.
  4105. type: string
  4106. type: object
  4107. clientSecret:
  4108. description: ClientSecret is the secret part of the credential.
  4109. properties:
  4110. secretRef:
  4111. description: SecretRef references a key in a secret that will be used as value.
  4112. properties:
  4113. key:
  4114. description: |-
  4115. A key in the referenced Secret.
  4116. Some instances of this field may be defaulted, in others it may be required.
  4117. maxLength: 253
  4118. minLength: 1
  4119. pattern: ^[-._a-zA-Z0-9]+$
  4120. type: string
  4121. name:
  4122. description: The name of the Secret resource being referred to.
  4123. maxLength: 253
  4124. minLength: 1
  4125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4126. type: string
  4127. namespace:
  4128. description: |-
  4129. The namespace of the Secret resource being referred to.
  4130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4131. maxLength: 63
  4132. minLength: 1
  4133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4134. type: string
  4135. type: object
  4136. value:
  4137. description: Value can be specified directly to set a value without using a secret.
  4138. type: string
  4139. type: object
  4140. tenant:
  4141. description: Tenant is the chosen hostname / site name.
  4142. type: string
  4143. tld:
  4144. description: |-
  4145. TLD is based on the server location that was chosen during provisioning.
  4146. If unset, defaults to "com".
  4147. type: string
  4148. urlTemplate:
  4149. description: |-
  4150. URLTemplate
  4151. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4152. type: string
  4153. required:
  4154. - clientId
  4155. - clientSecret
  4156. - tenant
  4157. type: object
  4158. doppler:
  4159. description: Doppler configures this store to sync secrets using the Doppler provider
  4160. properties:
  4161. auth:
  4162. description: Auth configures how the Operator authenticates with the Doppler API
  4163. properties:
  4164. oidcConfig:
  4165. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4166. properties:
  4167. expirationSeconds:
  4168. default: 600
  4169. description: |-
  4170. ExpirationSeconds sets the ServiceAccount token validity duration.
  4171. Defaults to 10 minutes.
  4172. format: int64
  4173. type: integer
  4174. identity:
  4175. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4176. type: string
  4177. serviceAccountRef:
  4178. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4179. properties:
  4180. audiences:
  4181. description: |-
  4182. Audience specifies the `aud` claim for the service account token
  4183. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4184. then this audiences will be appended to the list
  4185. items:
  4186. type: string
  4187. type: array
  4188. name:
  4189. description: The name of the ServiceAccount resource being referred to.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4193. type: string
  4194. namespace:
  4195. description: |-
  4196. Namespace of the resource being referred to.
  4197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4198. maxLength: 63
  4199. minLength: 1
  4200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4201. type: string
  4202. required:
  4203. - name
  4204. type: object
  4205. required:
  4206. - identity
  4207. - serviceAccountRef
  4208. type: object
  4209. secretRef:
  4210. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4211. properties:
  4212. dopplerToken:
  4213. description: |-
  4214. The DopplerToken is used for authentication.
  4215. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4216. The Key attribute defaults to dopplerToken if not specified.
  4217. properties:
  4218. key:
  4219. description: |-
  4220. A key in the referenced Secret.
  4221. Some instances of this field may be defaulted, in others it may be required.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[-._a-zA-Z0-9]+$
  4225. type: string
  4226. name:
  4227. description: The name of the Secret resource being referred to.
  4228. maxLength: 253
  4229. minLength: 1
  4230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4231. type: string
  4232. namespace:
  4233. description: |-
  4234. The namespace of the Secret resource being referred to.
  4235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4236. maxLength: 63
  4237. minLength: 1
  4238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4239. type: string
  4240. type: object
  4241. required:
  4242. - dopplerToken
  4243. type: object
  4244. type: object
  4245. x-kubernetes-validations:
  4246. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4247. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4248. config:
  4249. description: Doppler config (required if not using a Service Token)
  4250. type: string
  4251. format:
  4252. description: Format enables the downloading of secrets as a file (string)
  4253. enum:
  4254. - json
  4255. - dotnet-json
  4256. - env
  4257. - yaml
  4258. - docker
  4259. type: string
  4260. nameTransformer:
  4261. description: Environment variable compatible name transforms that change secret names to a different format
  4262. enum:
  4263. - upper-camel
  4264. - camel
  4265. - lower-snake
  4266. - tf-var
  4267. - dotnet-env
  4268. - lower-kebab
  4269. type: string
  4270. project:
  4271. description: Doppler project (required if not using a Service Token)
  4272. type: string
  4273. required:
  4274. - auth
  4275. type: object
  4276. dvls:
  4277. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4278. properties:
  4279. auth:
  4280. description: Auth defines the authentication method to use.
  4281. properties:
  4282. secretRef:
  4283. description: SecretRef contains the Application ID and Application Secret for authentication.
  4284. properties:
  4285. appId:
  4286. description: AppID is the reference to the secret containing the Application ID.
  4287. properties:
  4288. key:
  4289. description: |-
  4290. A key in the referenced Secret.
  4291. Some instances of this field may be defaulted, in others it may be required.
  4292. maxLength: 253
  4293. minLength: 1
  4294. pattern: ^[-._a-zA-Z0-9]+$
  4295. type: string
  4296. name:
  4297. description: The name of the Secret resource being referred to.
  4298. maxLength: 253
  4299. minLength: 1
  4300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4301. type: string
  4302. namespace:
  4303. description: |-
  4304. The namespace of the Secret resource being referred to.
  4305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4306. maxLength: 63
  4307. minLength: 1
  4308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4309. type: string
  4310. type: object
  4311. appSecret:
  4312. description: AppSecret is the reference to the secret containing the Application Secret.
  4313. properties:
  4314. key:
  4315. description: |-
  4316. A key in the referenced Secret.
  4317. Some instances of this field may be defaulted, in others it may be required.
  4318. maxLength: 253
  4319. minLength: 1
  4320. pattern: ^[-._a-zA-Z0-9]+$
  4321. type: string
  4322. name:
  4323. description: The name of the Secret resource being referred to.
  4324. maxLength: 253
  4325. minLength: 1
  4326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4327. type: string
  4328. namespace:
  4329. description: |-
  4330. The namespace of the Secret resource being referred to.
  4331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4332. maxLength: 63
  4333. minLength: 1
  4334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4335. type: string
  4336. type: object
  4337. required:
  4338. - appId
  4339. - appSecret
  4340. type: object
  4341. required:
  4342. - secretRef
  4343. type: object
  4344. insecure:
  4345. description: |-
  4346. Insecure allows connecting to DVLS over plain HTTP.
  4347. This is NOT RECOMMENDED for production use.
  4348. Set to true only if you understand the security implications.
  4349. type: boolean
  4350. serverUrl:
  4351. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4352. type: string
  4353. vault:
  4354. description: |-
  4355. Vault is the name or UUID of the vault to fetch secrets from.
  4356. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4357. type: string
  4358. required:
  4359. - auth
  4360. - serverUrl
  4361. type: object
  4362. fake:
  4363. description: Fake configures a store with static key/value pairs
  4364. properties:
  4365. data:
  4366. items:
  4367. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4368. properties:
  4369. key:
  4370. type: string
  4371. value:
  4372. type: string
  4373. version:
  4374. type: string
  4375. required:
  4376. - key
  4377. - value
  4378. type: object
  4379. type: array
  4380. validationResult:
  4381. description: ValidationResult is defined type for the number of validation results.
  4382. type: integer
  4383. required:
  4384. - data
  4385. type: object
  4386. fortanix:
  4387. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4388. properties:
  4389. apiKey:
  4390. description: APIKey is the API token to access SDKMS Applications.
  4391. properties:
  4392. secretRef:
  4393. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4394. properties:
  4395. key:
  4396. description: |-
  4397. A key in the referenced Secret.
  4398. Some instances of this field may be defaulted, in others it may be required.
  4399. maxLength: 253
  4400. minLength: 1
  4401. pattern: ^[-._a-zA-Z0-9]+$
  4402. type: string
  4403. name:
  4404. description: The name of the Secret resource being referred to.
  4405. maxLength: 253
  4406. minLength: 1
  4407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4408. type: string
  4409. namespace:
  4410. description: |-
  4411. The namespace of the Secret resource being referred to.
  4412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4413. maxLength: 63
  4414. minLength: 1
  4415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4416. type: string
  4417. type: object
  4418. type: object
  4419. apiUrl:
  4420. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4421. type: string
  4422. type: object
  4423. gcpsm:
  4424. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4425. properties:
  4426. auth:
  4427. description: Auth defines the information necessary to authenticate against GCP
  4428. properties:
  4429. secretRef:
  4430. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4431. properties:
  4432. secretAccessKeySecretRef:
  4433. description: The SecretAccessKey is used for authentication
  4434. properties:
  4435. key:
  4436. description: |-
  4437. A key in the referenced Secret.
  4438. Some instances of this field may be defaulted, in others it may be required.
  4439. maxLength: 253
  4440. minLength: 1
  4441. pattern: ^[-._a-zA-Z0-9]+$
  4442. type: string
  4443. name:
  4444. description: The name of the Secret resource being referred to.
  4445. maxLength: 253
  4446. minLength: 1
  4447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4448. type: string
  4449. namespace:
  4450. description: |-
  4451. The namespace of the Secret resource being referred to.
  4452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4453. maxLength: 63
  4454. minLength: 1
  4455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4456. type: string
  4457. type: object
  4458. type: object
  4459. workloadIdentity:
  4460. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4461. properties:
  4462. clusterLocation:
  4463. description: |-
  4464. ClusterLocation is the location of the cluster
  4465. If not specified, it fetches information from the metadata server
  4466. type: string
  4467. clusterName:
  4468. description: |-
  4469. ClusterName is the name of the cluster
  4470. If not specified, it fetches information from the metadata server
  4471. type: string
  4472. clusterProjectID:
  4473. description: |-
  4474. ClusterProjectID is the project ID of the cluster
  4475. If not specified, it fetches information from the metadata server
  4476. type: string
  4477. serviceAccountRef:
  4478. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4479. properties:
  4480. audiences:
  4481. description: |-
  4482. Audience specifies the `aud` claim for the service account token
  4483. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4484. then this audiences will be appended to the list
  4485. items:
  4486. type: string
  4487. type: array
  4488. name:
  4489. description: The name of the ServiceAccount resource being referred to.
  4490. maxLength: 253
  4491. minLength: 1
  4492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4493. type: string
  4494. namespace:
  4495. description: |-
  4496. Namespace of the resource being referred to.
  4497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4498. maxLength: 63
  4499. minLength: 1
  4500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4501. type: string
  4502. required:
  4503. - name
  4504. type: object
  4505. required:
  4506. - serviceAccountRef
  4507. type: object
  4508. workloadIdentityFederation:
  4509. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4510. properties:
  4511. audience:
  4512. description: |-
  4513. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4514. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4515. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4516. type: string
  4517. awsSecurityCredentials:
  4518. description: |-
  4519. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4520. when using the AWS metadata server is not an option.
  4521. properties:
  4522. awsCredentialsSecretRef:
  4523. description: |-
  4524. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4525. Secret should be created with below names for keys
  4526. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4527. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4528. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4529. properties:
  4530. name:
  4531. description: name of the secret.
  4532. maxLength: 253
  4533. minLength: 1
  4534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4535. type: string
  4536. namespace:
  4537. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4538. maxLength: 63
  4539. minLength: 1
  4540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4541. type: string
  4542. required:
  4543. - name
  4544. type: object
  4545. region:
  4546. description: region is for configuring the AWS region to be used.
  4547. example: ap-south-1
  4548. maxLength: 50
  4549. minLength: 1
  4550. pattern: ^[a-z0-9-]+$
  4551. type: string
  4552. required:
  4553. - awsCredentialsSecretRef
  4554. - region
  4555. type: object
  4556. credConfig:
  4557. description: |-
  4558. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4559. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4560. serviceAccountRef must be used by providing operators service account details.
  4561. properties:
  4562. key:
  4563. description: key name holding the external account credential config.
  4564. maxLength: 253
  4565. minLength: 1
  4566. pattern: ^[-._a-zA-Z0-9]+$
  4567. type: string
  4568. name:
  4569. description: name of the configmap.
  4570. maxLength: 253
  4571. minLength: 1
  4572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4573. type: string
  4574. namespace:
  4575. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4576. maxLength: 63
  4577. minLength: 1
  4578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4579. type: string
  4580. required:
  4581. - key
  4582. - name
  4583. type: object
  4584. externalTokenEndpoint:
  4585. description: |-
  4586. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4587. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4588. URL is having the expected value.
  4589. type: string
  4590. gcpServiceAccountEmail:
  4591. description: |-
  4592. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4593. after Workload Identity Federation. Use this to grant access through the service account's
  4594. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4595. service_account_impersonation_url in the external account JSON from credConfig;
  4596. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4597. on that ServiceAccount.
  4598. example: my-gsa@my-project.iam.gserviceaccount.com
  4599. minLength: 1
  4600. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4601. type: string
  4602. serviceAccountRef:
  4603. description: |-
  4604. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4605. when Kubernetes is configured as provider in workload identity pool.
  4606. properties:
  4607. audiences:
  4608. description: |-
  4609. Audience specifies the `aud` claim for the service account token
  4610. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4611. then this audiences will be appended to the list
  4612. items:
  4613. type: string
  4614. type: array
  4615. name:
  4616. description: The name of the ServiceAccount resource being referred to.
  4617. maxLength: 253
  4618. minLength: 1
  4619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4620. type: string
  4621. namespace:
  4622. description: |-
  4623. Namespace of the resource being referred to.
  4624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4625. maxLength: 63
  4626. minLength: 1
  4627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4628. type: string
  4629. required:
  4630. - name
  4631. type: object
  4632. type: object
  4633. type: object
  4634. location:
  4635. description: Location optionally defines a location for a secret
  4636. type: string
  4637. projectID:
  4638. description: ProjectID project where secret is located
  4639. type: string
  4640. secretVersionSelectionPolicy:
  4641. default: LatestOrFail
  4642. description: |-
  4643. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4644. when "latest" is disabled or destroyed.
  4645. Possible values are:
  4646. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4647. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4648. type: string
  4649. type: object
  4650. github:
  4651. description: |-
  4652. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4653. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4654. properties:
  4655. appID:
  4656. description: appID specifies the Github APP that will be used to authenticate the client
  4657. format: int64
  4658. type: integer
  4659. auth:
  4660. description: auth configures how secret-manager authenticates with a Github instance.
  4661. properties:
  4662. privateKey:
  4663. description: |-
  4664. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4665. In some instances, `key` is a required field.
  4666. properties:
  4667. key:
  4668. description: |-
  4669. A key in the referenced Secret.
  4670. Some instances of this field may be defaulted, in others it may be required.
  4671. maxLength: 253
  4672. minLength: 1
  4673. pattern: ^[-._a-zA-Z0-9]+$
  4674. type: string
  4675. name:
  4676. description: The name of the Secret resource being referred to.
  4677. maxLength: 253
  4678. minLength: 1
  4679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4680. type: string
  4681. namespace:
  4682. description: |-
  4683. The namespace of the Secret resource being referred to.
  4684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4685. maxLength: 63
  4686. minLength: 1
  4687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4688. type: string
  4689. type: object
  4690. required:
  4691. - privateKey
  4692. type: object
  4693. environment:
  4694. description: environment will be used to fetch secrets from a particular environment within a github repository
  4695. type: string
  4696. installationID:
  4697. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4698. format: int64
  4699. type: integer
  4700. orgSecretVisibility:
  4701. description: |-
  4702. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4703. Valid values are "all" or "private".
  4704. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4705. whatever visibility they already have in GitHub.
  4706. enum:
  4707. - all
  4708. - private
  4709. type: string
  4710. organization:
  4711. description: organization will be used to fetch secrets from the Github organization
  4712. type: string
  4713. repository:
  4714. description: repository will be used to fetch secrets from the Github repository within an organization
  4715. type: string
  4716. uploadURL:
  4717. description: Upload URL for enterprise instances. Default to URL.
  4718. type: string
  4719. url:
  4720. default: https://github.com/
  4721. description: URL configures the Github instance URL. Defaults to https://github.com/.
  4722. type: string
  4723. required:
  4724. - appID
  4725. - auth
  4726. - installationID
  4727. - organization
  4728. type: object
  4729. gitlab:
  4730. description: GitLab configures this store to sync secrets using GitLab Variables provider
  4731. properties:
  4732. auth:
  4733. description: Auth configures how secret-manager authenticates with a GitLab instance.
  4734. properties:
  4735. SecretRef:
  4736. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  4737. properties:
  4738. accessToken:
  4739. description: AccessToken is used for authentication.
  4740. properties:
  4741. key:
  4742. description: |-
  4743. A key in the referenced Secret.
  4744. Some instances of this field may be defaulted, in others it may be required.
  4745. maxLength: 253
  4746. minLength: 1
  4747. pattern: ^[-._a-zA-Z0-9]+$
  4748. type: string
  4749. name:
  4750. description: The name of the Secret resource being referred to.
  4751. maxLength: 253
  4752. minLength: 1
  4753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4754. type: string
  4755. namespace:
  4756. description: |-
  4757. The namespace of the Secret resource being referred to.
  4758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4759. maxLength: 63
  4760. minLength: 1
  4761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4762. type: string
  4763. type: object
  4764. type: object
  4765. required:
  4766. - SecretRef
  4767. type: object
  4768. caBundle:
  4769. description: |-
  4770. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  4771. can be performed.
  4772. format: byte
  4773. type: string
  4774. caProvider:
  4775. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4776. properties:
  4777. key:
  4778. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4779. maxLength: 253
  4780. minLength: 1
  4781. pattern: ^[-._a-zA-Z0-9]+$
  4782. type: string
  4783. name:
  4784. description: The name of the object located at the provider type.
  4785. maxLength: 253
  4786. minLength: 1
  4787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4788. type: string
  4789. namespace:
  4790. description: |-
  4791. The namespace the Provider type is in.
  4792. Can only be defined when used in a ClusterSecretStore.
  4793. maxLength: 63
  4794. minLength: 1
  4795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4796. type: string
  4797. type:
  4798. description: The type of provider to use such as "Secret", or "ConfigMap".
  4799. enum:
  4800. - Secret
  4801. - ConfigMap
  4802. type: string
  4803. required:
  4804. - name
  4805. - type
  4806. type: object
  4807. environment:
  4808. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  4809. type: string
  4810. groupIDs:
  4811. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  4812. items:
  4813. type: string
  4814. type: array
  4815. inheritFromGroups:
  4816. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  4817. type: boolean
  4818. projectID:
  4819. description: ProjectID specifies a project where secrets are located.
  4820. type: string
  4821. url:
  4822. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  4823. type: string
  4824. required:
  4825. - auth
  4826. type: object
  4827. ibm:
  4828. description: IBM configures this store to sync secrets using IBM Cloud provider
  4829. properties:
  4830. auth:
  4831. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  4832. maxProperties: 1
  4833. minProperties: 1
  4834. properties:
  4835. containerAuth:
  4836. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  4837. properties:
  4838. iamEndpoint:
  4839. type: string
  4840. profile:
  4841. description: the IBM Trusted Profile
  4842. type: string
  4843. tokenLocation:
  4844. description: Location the token is mounted on the pod
  4845. type: string
  4846. required:
  4847. - profile
  4848. type: object
  4849. secretRef:
  4850. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  4851. properties:
  4852. iamEndpoint:
  4853. description: The IAM endpoint used to obain a token
  4854. type: string
  4855. secretApiKeySecretRef:
  4856. description: The SecretAccessKey is used for authentication
  4857. properties:
  4858. key:
  4859. description: |-
  4860. A key in the referenced Secret.
  4861. Some instances of this field may be defaulted, in others it may be required.
  4862. maxLength: 253
  4863. minLength: 1
  4864. pattern: ^[-._a-zA-Z0-9]+$
  4865. type: string
  4866. name:
  4867. description: The name of the Secret resource being referred to.
  4868. maxLength: 253
  4869. minLength: 1
  4870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4871. type: string
  4872. namespace:
  4873. description: |-
  4874. The namespace of the Secret resource being referred to.
  4875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4876. maxLength: 63
  4877. minLength: 1
  4878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4879. type: string
  4880. type: object
  4881. type: object
  4882. type: object
  4883. serviceUrl:
  4884. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  4885. type: string
  4886. required:
  4887. - auth
  4888. type: object
  4889. infisical:
  4890. description: Infisical configures this store to sync secrets using the Infisical provider
  4891. properties:
  4892. auth:
  4893. description: Auth configures how the Operator authenticates with the Infisical API
  4894. properties:
  4895. awsAuthCredentials:
  4896. description: AwsAuthCredentials represents the credentials for AWS authentication.
  4897. properties:
  4898. identityId:
  4899. description: |-
  4900. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4901. In some instances, `key` is a required field.
  4902. properties:
  4903. key:
  4904. description: |-
  4905. A key in the referenced Secret.
  4906. Some instances of this field may be defaulted, in others it may be required.
  4907. maxLength: 253
  4908. minLength: 1
  4909. pattern: ^[-._a-zA-Z0-9]+$
  4910. type: string
  4911. name:
  4912. description: The name of the Secret resource being referred to.
  4913. maxLength: 253
  4914. minLength: 1
  4915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4916. type: string
  4917. namespace:
  4918. description: |-
  4919. The namespace of the Secret resource being referred to.
  4920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4921. maxLength: 63
  4922. minLength: 1
  4923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4924. type: string
  4925. type: object
  4926. required:
  4927. - identityId
  4928. type: object
  4929. azureAuthCredentials:
  4930. description: AzureAuthCredentials represents the credentials for Azure authentication.
  4931. properties:
  4932. identityId:
  4933. description: |-
  4934. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4935. In some instances, `key` is a required field.
  4936. properties:
  4937. key:
  4938. description: |-
  4939. A key in the referenced Secret.
  4940. Some instances of this field may be defaulted, in others it may be required.
  4941. maxLength: 253
  4942. minLength: 1
  4943. pattern: ^[-._a-zA-Z0-9]+$
  4944. type: string
  4945. name:
  4946. description: The name of the Secret resource being referred to.
  4947. maxLength: 253
  4948. minLength: 1
  4949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4950. type: string
  4951. namespace:
  4952. description: |-
  4953. The namespace of the Secret resource being referred to.
  4954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4955. maxLength: 63
  4956. minLength: 1
  4957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4958. type: string
  4959. type: object
  4960. resource:
  4961. description: |-
  4962. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4963. In some instances, `key` is a required field.
  4964. properties:
  4965. key:
  4966. description: |-
  4967. A key in the referenced Secret.
  4968. Some instances of this field may be defaulted, in others it may be required.
  4969. maxLength: 253
  4970. minLength: 1
  4971. pattern: ^[-._a-zA-Z0-9]+$
  4972. type: string
  4973. name:
  4974. description: The name of the Secret resource being referred to.
  4975. maxLength: 253
  4976. minLength: 1
  4977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4978. type: string
  4979. namespace:
  4980. description: |-
  4981. The namespace of the Secret resource being referred to.
  4982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4983. maxLength: 63
  4984. minLength: 1
  4985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4986. type: string
  4987. type: object
  4988. required:
  4989. - identityId
  4990. type: object
  4991. gcpIamAuthCredentials:
  4992. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  4993. properties:
  4994. identityId:
  4995. description: |-
  4996. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4997. In some instances, `key` is a required field.
  4998. properties:
  4999. key:
  5000. description: |-
  5001. A key in the referenced Secret.
  5002. Some instances of this field may be defaulted, in others it may be required.
  5003. maxLength: 253
  5004. minLength: 1
  5005. pattern: ^[-._a-zA-Z0-9]+$
  5006. type: string
  5007. name:
  5008. description: The name of the Secret resource being referred to.
  5009. maxLength: 253
  5010. minLength: 1
  5011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5012. type: string
  5013. namespace:
  5014. description: |-
  5015. The namespace of the Secret resource being referred to.
  5016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5017. maxLength: 63
  5018. minLength: 1
  5019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5020. type: string
  5021. type: object
  5022. serviceAccountKeyFilePath:
  5023. description: |-
  5024. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5025. In some instances, `key` is a required field.
  5026. properties:
  5027. key:
  5028. description: |-
  5029. A key in the referenced Secret.
  5030. Some instances of this field may be defaulted, in others it may be required.
  5031. maxLength: 253
  5032. minLength: 1
  5033. pattern: ^[-._a-zA-Z0-9]+$
  5034. type: string
  5035. name:
  5036. description: The name of the Secret resource being referred to.
  5037. maxLength: 253
  5038. minLength: 1
  5039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5040. type: string
  5041. namespace:
  5042. description: |-
  5043. The namespace of the Secret resource being referred to.
  5044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5045. maxLength: 63
  5046. minLength: 1
  5047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5048. type: string
  5049. type: object
  5050. required:
  5051. - identityId
  5052. - serviceAccountKeyFilePath
  5053. type: object
  5054. gcpIdTokenAuthCredentials:
  5055. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5056. properties:
  5057. identityId:
  5058. description: |-
  5059. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5060. In some instances, `key` is a required field.
  5061. properties:
  5062. key:
  5063. description: |-
  5064. A key in the referenced Secret.
  5065. Some instances of this field may be defaulted, in others it may be required.
  5066. maxLength: 253
  5067. minLength: 1
  5068. pattern: ^[-._a-zA-Z0-9]+$
  5069. type: string
  5070. name:
  5071. description: The name of the Secret resource being referred to.
  5072. maxLength: 253
  5073. minLength: 1
  5074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5075. type: string
  5076. namespace:
  5077. description: |-
  5078. The namespace of the Secret resource being referred to.
  5079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5080. maxLength: 63
  5081. minLength: 1
  5082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5083. type: string
  5084. type: object
  5085. required:
  5086. - identityId
  5087. type: object
  5088. jwtAuthCredentials:
  5089. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5090. properties:
  5091. identityId:
  5092. description: |-
  5093. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5094. In some instances, `key` is a required field.
  5095. properties:
  5096. key:
  5097. description: |-
  5098. A key in the referenced Secret.
  5099. Some instances of this field may be defaulted, in others it may be required.
  5100. maxLength: 253
  5101. minLength: 1
  5102. pattern: ^[-._a-zA-Z0-9]+$
  5103. type: string
  5104. name:
  5105. description: The name of the Secret resource being referred to.
  5106. maxLength: 253
  5107. minLength: 1
  5108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5109. type: string
  5110. namespace:
  5111. description: |-
  5112. The namespace of the Secret resource being referred to.
  5113. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5114. maxLength: 63
  5115. minLength: 1
  5116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5117. type: string
  5118. type: object
  5119. jwt:
  5120. description: |-
  5121. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5122. In some instances, `key` is a required field.
  5123. properties:
  5124. key:
  5125. description: |-
  5126. A key in the referenced Secret.
  5127. Some instances of this field may be defaulted, in others it may be required.
  5128. maxLength: 253
  5129. minLength: 1
  5130. pattern: ^[-._a-zA-Z0-9]+$
  5131. type: string
  5132. name:
  5133. description: The name of the Secret resource being referred to.
  5134. maxLength: 253
  5135. minLength: 1
  5136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5137. type: string
  5138. namespace:
  5139. description: |-
  5140. The namespace of the Secret resource being referred to.
  5141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5142. maxLength: 63
  5143. minLength: 1
  5144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5145. type: string
  5146. type: object
  5147. required:
  5148. - identityId
  5149. - jwt
  5150. type: object
  5151. kubernetesAuthCredentials:
  5152. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5153. properties:
  5154. identityId:
  5155. description: |-
  5156. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5157. In some instances, `key` is a required field.
  5158. properties:
  5159. key:
  5160. description: |-
  5161. A key in the referenced Secret.
  5162. Some instances of this field may be defaulted, in others it may be required.
  5163. maxLength: 253
  5164. minLength: 1
  5165. pattern: ^[-._a-zA-Z0-9]+$
  5166. type: string
  5167. name:
  5168. description: The name of the Secret resource being referred to.
  5169. maxLength: 253
  5170. minLength: 1
  5171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5172. type: string
  5173. namespace:
  5174. description: |-
  5175. The namespace of the Secret resource being referred to.
  5176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5177. maxLength: 63
  5178. minLength: 1
  5179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5180. type: string
  5181. type: object
  5182. serviceAccountTokenPath:
  5183. description: |-
  5184. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5185. In some instances, `key` is a required field.
  5186. properties:
  5187. key:
  5188. description: |-
  5189. A key in the referenced Secret.
  5190. Some instances of this field may be defaulted, in others it may be required.
  5191. maxLength: 253
  5192. minLength: 1
  5193. pattern: ^[-._a-zA-Z0-9]+$
  5194. type: string
  5195. name:
  5196. description: The name of the Secret resource being referred to.
  5197. maxLength: 253
  5198. minLength: 1
  5199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5200. type: string
  5201. namespace:
  5202. description: |-
  5203. The namespace of the Secret resource being referred to.
  5204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5205. maxLength: 63
  5206. minLength: 1
  5207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5208. type: string
  5209. type: object
  5210. required:
  5211. - identityId
  5212. type: object
  5213. ldapAuthCredentials:
  5214. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5215. properties:
  5216. identityId:
  5217. description: |-
  5218. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5219. In some instances, `key` is a required field.
  5220. properties:
  5221. key:
  5222. description: |-
  5223. A key in the referenced Secret.
  5224. Some instances of this field may be defaulted, in others it may be required.
  5225. maxLength: 253
  5226. minLength: 1
  5227. pattern: ^[-._a-zA-Z0-9]+$
  5228. type: string
  5229. name:
  5230. description: The name of the Secret resource being referred to.
  5231. maxLength: 253
  5232. minLength: 1
  5233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5234. type: string
  5235. namespace:
  5236. description: |-
  5237. The namespace of the Secret resource being referred to.
  5238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5239. maxLength: 63
  5240. minLength: 1
  5241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5242. type: string
  5243. type: object
  5244. ldapPassword:
  5245. description: |-
  5246. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5247. In some instances, `key` is a required field.
  5248. properties:
  5249. key:
  5250. description: |-
  5251. A key in the referenced Secret.
  5252. Some instances of this field may be defaulted, in others it may be required.
  5253. maxLength: 253
  5254. minLength: 1
  5255. pattern: ^[-._a-zA-Z0-9]+$
  5256. type: string
  5257. name:
  5258. description: The name of the Secret resource being referred to.
  5259. maxLength: 253
  5260. minLength: 1
  5261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5262. type: string
  5263. namespace:
  5264. description: |-
  5265. The namespace of the Secret resource being referred to.
  5266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5267. maxLength: 63
  5268. minLength: 1
  5269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5270. type: string
  5271. type: object
  5272. ldapUsername:
  5273. description: |-
  5274. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5275. In some instances, `key` is a required field.
  5276. properties:
  5277. key:
  5278. description: |-
  5279. A key in the referenced Secret.
  5280. Some instances of this field may be defaulted, in others it may be required.
  5281. maxLength: 253
  5282. minLength: 1
  5283. pattern: ^[-._a-zA-Z0-9]+$
  5284. type: string
  5285. name:
  5286. description: The name of the Secret resource being referred to.
  5287. maxLength: 253
  5288. minLength: 1
  5289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5290. type: string
  5291. namespace:
  5292. description: |-
  5293. The namespace of the Secret resource being referred to.
  5294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5295. maxLength: 63
  5296. minLength: 1
  5297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5298. type: string
  5299. type: object
  5300. required:
  5301. - identityId
  5302. - ldapPassword
  5303. - ldapUsername
  5304. type: object
  5305. ociAuthCredentials:
  5306. description: OciAuthCredentials represents the credentials for OCI authentication.
  5307. properties:
  5308. fingerprint:
  5309. description: |-
  5310. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5311. In some instances, `key` is a required field.
  5312. properties:
  5313. key:
  5314. description: |-
  5315. A key in the referenced Secret.
  5316. Some instances of this field may be defaulted, in others it may be required.
  5317. maxLength: 253
  5318. minLength: 1
  5319. pattern: ^[-._a-zA-Z0-9]+$
  5320. type: string
  5321. name:
  5322. description: The name of the Secret resource being referred to.
  5323. maxLength: 253
  5324. minLength: 1
  5325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5326. type: string
  5327. namespace:
  5328. description: |-
  5329. The namespace of the Secret resource being referred to.
  5330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5331. maxLength: 63
  5332. minLength: 1
  5333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5334. type: string
  5335. type: object
  5336. identityId:
  5337. description: |-
  5338. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5339. In some instances, `key` is a required field.
  5340. properties:
  5341. key:
  5342. description: |-
  5343. A key in the referenced Secret.
  5344. Some instances of this field may be defaulted, in others it may be required.
  5345. maxLength: 253
  5346. minLength: 1
  5347. pattern: ^[-._a-zA-Z0-9]+$
  5348. type: string
  5349. name:
  5350. description: The name of the Secret resource being referred to.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5354. type: string
  5355. namespace:
  5356. description: |-
  5357. The namespace of the Secret resource being referred to.
  5358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5359. maxLength: 63
  5360. minLength: 1
  5361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5362. type: string
  5363. type: object
  5364. privateKey:
  5365. description: |-
  5366. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5367. In some instances, `key` is a required field.
  5368. properties:
  5369. key:
  5370. description: |-
  5371. A key in the referenced Secret.
  5372. Some instances of this field may be defaulted, in others it may be required.
  5373. maxLength: 253
  5374. minLength: 1
  5375. pattern: ^[-._a-zA-Z0-9]+$
  5376. type: string
  5377. name:
  5378. description: The name of the Secret resource being referred to.
  5379. maxLength: 253
  5380. minLength: 1
  5381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5382. type: string
  5383. namespace:
  5384. description: |-
  5385. The namespace of the Secret resource being referred to.
  5386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5387. maxLength: 63
  5388. minLength: 1
  5389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5390. type: string
  5391. type: object
  5392. privateKeyPassphrase:
  5393. description: |-
  5394. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5395. In some instances, `key` is a required field.
  5396. properties:
  5397. key:
  5398. description: |-
  5399. A key in the referenced Secret.
  5400. Some instances of this field may be defaulted, in others it may be required.
  5401. maxLength: 253
  5402. minLength: 1
  5403. pattern: ^[-._a-zA-Z0-9]+$
  5404. type: string
  5405. name:
  5406. description: The name of the Secret resource being referred to.
  5407. maxLength: 253
  5408. minLength: 1
  5409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5410. type: string
  5411. namespace:
  5412. description: |-
  5413. The namespace of the Secret resource being referred to.
  5414. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5415. maxLength: 63
  5416. minLength: 1
  5417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5418. type: string
  5419. type: object
  5420. region:
  5421. description: |-
  5422. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5423. In some instances, `key` is a required field.
  5424. properties:
  5425. key:
  5426. description: |-
  5427. A key in the referenced Secret.
  5428. Some instances of this field may be defaulted, in others it may be required.
  5429. maxLength: 253
  5430. minLength: 1
  5431. pattern: ^[-._a-zA-Z0-9]+$
  5432. type: string
  5433. name:
  5434. description: The name of the Secret resource being referred to.
  5435. maxLength: 253
  5436. minLength: 1
  5437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5438. type: string
  5439. namespace:
  5440. description: |-
  5441. The namespace of the Secret resource being referred to.
  5442. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5443. maxLength: 63
  5444. minLength: 1
  5445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5446. type: string
  5447. type: object
  5448. tenancyId:
  5449. description: |-
  5450. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5451. In some instances, `key` is a required field.
  5452. properties:
  5453. key:
  5454. description: |-
  5455. A key in the referenced Secret.
  5456. Some instances of this field may be defaulted, in others it may be required.
  5457. maxLength: 253
  5458. minLength: 1
  5459. pattern: ^[-._a-zA-Z0-9]+$
  5460. type: string
  5461. name:
  5462. description: The name of the Secret resource being referred to.
  5463. maxLength: 253
  5464. minLength: 1
  5465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5466. type: string
  5467. namespace:
  5468. description: |-
  5469. The namespace of the Secret resource being referred to.
  5470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5471. maxLength: 63
  5472. minLength: 1
  5473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5474. type: string
  5475. type: object
  5476. userId:
  5477. description: |-
  5478. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5479. In some instances, `key` is a required field.
  5480. properties:
  5481. key:
  5482. description: |-
  5483. A key in the referenced Secret.
  5484. Some instances of this field may be defaulted, in others it may be required.
  5485. maxLength: 253
  5486. minLength: 1
  5487. pattern: ^[-._a-zA-Z0-9]+$
  5488. type: string
  5489. name:
  5490. description: The name of the Secret resource being referred to.
  5491. maxLength: 253
  5492. minLength: 1
  5493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5494. type: string
  5495. namespace:
  5496. description: |-
  5497. The namespace of the Secret resource being referred to.
  5498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5499. maxLength: 63
  5500. minLength: 1
  5501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5502. type: string
  5503. type: object
  5504. required:
  5505. - fingerprint
  5506. - identityId
  5507. - privateKey
  5508. - region
  5509. - tenancyId
  5510. - userId
  5511. type: object
  5512. tokenAuthCredentials:
  5513. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5514. properties:
  5515. accessToken:
  5516. description: |-
  5517. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5518. In some instances, `key` is a required field.
  5519. properties:
  5520. key:
  5521. description: |-
  5522. A key in the referenced Secret.
  5523. Some instances of this field may be defaulted, in others it may be required.
  5524. maxLength: 253
  5525. minLength: 1
  5526. pattern: ^[-._a-zA-Z0-9]+$
  5527. type: string
  5528. name:
  5529. description: The name of the Secret resource being referred to.
  5530. maxLength: 253
  5531. minLength: 1
  5532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5533. type: string
  5534. namespace:
  5535. description: |-
  5536. The namespace of the Secret resource being referred to.
  5537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5538. maxLength: 63
  5539. minLength: 1
  5540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5541. type: string
  5542. type: object
  5543. required:
  5544. - accessToken
  5545. type: object
  5546. universalAuthCredentials:
  5547. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5548. properties:
  5549. clientId:
  5550. description: |-
  5551. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5552. In some instances, `key` is a required field.
  5553. properties:
  5554. key:
  5555. description: |-
  5556. A key in the referenced Secret.
  5557. Some instances of this field may be defaulted, in others it may be required.
  5558. maxLength: 253
  5559. minLength: 1
  5560. pattern: ^[-._a-zA-Z0-9]+$
  5561. type: string
  5562. name:
  5563. description: The name of the Secret resource being referred to.
  5564. maxLength: 253
  5565. minLength: 1
  5566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5567. type: string
  5568. namespace:
  5569. description: |-
  5570. The namespace of the Secret resource being referred to.
  5571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5572. maxLength: 63
  5573. minLength: 1
  5574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5575. type: string
  5576. type: object
  5577. clientSecret:
  5578. description: |-
  5579. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5580. In some instances, `key` is a required field.
  5581. properties:
  5582. key:
  5583. description: |-
  5584. A key in the referenced Secret.
  5585. Some instances of this field may be defaulted, in others it may be required.
  5586. maxLength: 253
  5587. minLength: 1
  5588. pattern: ^[-._a-zA-Z0-9]+$
  5589. type: string
  5590. name:
  5591. description: The name of the Secret resource being referred to.
  5592. maxLength: 253
  5593. minLength: 1
  5594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5595. type: string
  5596. namespace:
  5597. description: |-
  5598. The namespace of the Secret resource being referred to.
  5599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5600. maxLength: 63
  5601. minLength: 1
  5602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5603. type: string
  5604. type: object
  5605. required:
  5606. - clientId
  5607. - clientSecret
  5608. type: object
  5609. type: object
  5610. caBundle:
  5611. description: |-
  5612. CABundle is a PEM-encoded CA certificate bundle used to validate
  5613. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5614. format: byte
  5615. type: string
  5616. caProvider:
  5617. description: |-
  5618. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5619. The certificate is used to validate the Infisical server's TLS certificate.
  5620. Mutually exclusive with CABundle.
  5621. properties:
  5622. key:
  5623. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5624. maxLength: 253
  5625. minLength: 1
  5626. pattern: ^[-._a-zA-Z0-9]+$
  5627. type: string
  5628. name:
  5629. description: The name of the object located at the provider type.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5633. type: string
  5634. namespace:
  5635. description: |-
  5636. The namespace the Provider type is in.
  5637. Can only be defined when used in a ClusterSecretStore.
  5638. maxLength: 63
  5639. minLength: 1
  5640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5641. type: string
  5642. type:
  5643. description: The type of provider to use such as "Secret", or "ConfigMap".
  5644. enum:
  5645. - Secret
  5646. - ConfigMap
  5647. type: string
  5648. required:
  5649. - name
  5650. - type
  5651. type: object
  5652. hostAPI:
  5653. default: https://app.infisical.com/api
  5654. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5655. type: string
  5656. secretsScope:
  5657. description: SecretsScope defines the scope of the secrets within the workspace
  5658. properties:
  5659. environmentSlug:
  5660. description: EnvironmentSlug is the required slug identifier for the environment.
  5661. type: string
  5662. expandSecretReferences:
  5663. default: true
  5664. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5665. type: boolean
  5666. organizationSlug:
  5667. description: |-
  5668. OrganizationSlug is the optional slug that identifies the organization that will be used
  5669. during authentication. Useful for sub-organization setups
  5670. type: string
  5671. projectSlug:
  5672. description: ProjectSlug is the required slug identifier for the project.
  5673. type: string
  5674. recursive:
  5675. default: false
  5676. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5677. type: boolean
  5678. secretsPath:
  5679. default: /
  5680. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5681. type: string
  5682. required:
  5683. - environmentSlug
  5684. - projectSlug
  5685. type: object
  5686. required:
  5687. - auth
  5688. - secretsScope
  5689. type: object
  5690. keepersecurity:
  5691. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5692. properties:
  5693. authRef:
  5694. description: |-
  5695. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5696. In some instances, `key` is a required field.
  5697. properties:
  5698. key:
  5699. description: |-
  5700. A key in the referenced Secret.
  5701. Some instances of this field may be defaulted, in others it may be required.
  5702. maxLength: 253
  5703. minLength: 1
  5704. pattern: ^[-._a-zA-Z0-9]+$
  5705. type: string
  5706. name:
  5707. description: The name of the Secret resource being referred to.
  5708. maxLength: 253
  5709. minLength: 1
  5710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5711. type: string
  5712. namespace:
  5713. description: |-
  5714. The namespace of the Secret resource being referred to.
  5715. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5716. maxLength: 63
  5717. minLength: 1
  5718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5719. type: string
  5720. type: object
  5721. folderID:
  5722. type: string
  5723. getByTitleFallback:
  5724. type: boolean
  5725. required:
  5726. - authRef
  5727. - folderID
  5728. type: object
  5729. kubernetes:
  5730. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  5731. properties:
  5732. auth:
  5733. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  5734. maxProperties: 1
  5735. minProperties: 1
  5736. properties:
  5737. cert:
  5738. description: has both clientCert and clientKey as secretKeySelector
  5739. properties:
  5740. clientCert:
  5741. description: |-
  5742. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5743. In some instances, `key` is a required field.
  5744. properties:
  5745. key:
  5746. description: |-
  5747. A key in the referenced Secret.
  5748. Some instances of this field may be defaulted, in others it may be required.
  5749. maxLength: 253
  5750. minLength: 1
  5751. pattern: ^[-._a-zA-Z0-9]+$
  5752. type: string
  5753. name:
  5754. description: The name of the Secret resource being referred to.
  5755. maxLength: 253
  5756. minLength: 1
  5757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5758. type: string
  5759. namespace:
  5760. description: |-
  5761. The namespace of the Secret resource being referred to.
  5762. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5763. maxLength: 63
  5764. minLength: 1
  5765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5766. type: string
  5767. type: object
  5768. clientKey:
  5769. description: |-
  5770. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5771. In some instances, `key` is a required field.
  5772. properties:
  5773. key:
  5774. description: |-
  5775. A key in the referenced Secret.
  5776. Some instances of this field may be defaulted, in others it may be required.
  5777. maxLength: 253
  5778. minLength: 1
  5779. pattern: ^[-._a-zA-Z0-9]+$
  5780. type: string
  5781. name:
  5782. description: The name of the Secret resource being referred to.
  5783. maxLength: 253
  5784. minLength: 1
  5785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5786. type: string
  5787. namespace:
  5788. description: |-
  5789. The namespace of the Secret resource being referred to.
  5790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5791. maxLength: 63
  5792. minLength: 1
  5793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5794. type: string
  5795. type: object
  5796. type: object
  5797. serviceAccount:
  5798. description: points to a service account that should be used for authentication
  5799. properties:
  5800. audiences:
  5801. description: |-
  5802. Audience specifies the `aud` claim for the service account token
  5803. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  5804. then this audiences will be appended to the list
  5805. items:
  5806. type: string
  5807. type: array
  5808. name:
  5809. description: The name of the ServiceAccount resource being referred to.
  5810. maxLength: 253
  5811. minLength: 1
  5812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5813. type: string
  5814. namespace:
  5815. description: |-
  5816. Namespace of the resource being referred to.
  5817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5818. maxLength: 63
  5819. minLength: 1
  5820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5821. type: string
  5822. required:
  5823. - name
  5824. type: object
  5825. token:
  5826. description: use static token to authenticate with
  5827. properties:
  5828. bearerToken:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. type: object
  5857. type: object
  5858. authRef:
  5859. description: A reference to a secret that contains the auth information.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. remoteNamespace:
  5885. default: default
  5886. description: Remote namespace to fetch the secrets from
  5887. maxLength: 63
  5888. minLength: 1
  5889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5890. type: string
  5891. server:
  5892. description: configures the Kubernetes server Address.
  5893. properties:
  5894. caBundle:
  5895. description: CABundle is a base64-encoded CA certificate
  5896. format: byte
  5897. type: string
  5898. caProvider:
  5899. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  5900. properties:
  5901. key:
  5902. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5903. maxLength: 253
  5904. minLength: 1
  5905. pattern: ^[-._a-zA-Z0-9]+$
  5906. type: string
  5907. name:
  5908. description: The name of the object located at the provider type.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5912. type: string
  5913. namespace:
  5914. description: |-
  5915. The namespace the Provider type is in.
  5916. Can only be defined when used in a ClusterSecretStore.
  5917. maxLength: 63
  5918. minLength: 1
  5919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5920. type: string
  5921. type:
  5922. description: The type of provider to use such as "Secret", or "ConfigMap".
  5923. enum:
  5924. - Secret
  5925. - ConfigMap
  5926. type: string
  5927. required:
  5928. - name
  5929. - type
  5930. type: object
  5931. url:
  5932. default: kubernetes.default
  5933. description: configures the Kubernetes server Address.
  5934. type: string
  5935. type: object
  5936. type: object
  5937. nebiusmysterybox:
  5938. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  5939. properties:
  5940. apiDomain:
  5941. description: NebiusMysterybox API endpoint
  5942. type: string
  5943. auth:
  5944. description: Auth defines parameters to authenticate in MysteryBox
  5945. properties:
  5946. serviceAccountCredsSecretRef:
  5947. description: |-
  5948. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  5949. document with service account credentials used to get an IAM token.
  5950. Expected JSON structure:
  5951. {
  5952. "subject-credentials": {
  5953. "alg": "RS256",
  5954. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  5955. "kid": "<public-key-id>",
  5956. "iss": "<issuer-service-account-id>",
  5957. "sub": "<subject-service-account-id>"
  5958. }
  5959. }
  5960. properties:
  5961. key:
  5962. description: |-
  5963. A key in the referenced Secret.
  5964. Some instances of this field may be defaulted, in others it may be required.
  5965. maxLength: 253
  5966. minLength: 1
  5967. pattern: ^[-._a-zA-Z0-9]+$
  5968. type: string
  5969. name:
  5970. description: The name of the Secret resource being referred to.
  5971. maxLength: 253
  5972. minLength: 1
  5973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5974. type: string
  5975. namespace:
  5976. description: |-
  5977. The namespace of the Secret resource being referred to.
  5978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5979. maxLength: 63
  5980. minLength: 1
  5981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5982. type: string
  5983. type: object
  5984. tokenSecretRef:
  5985. description: Token authenticates with Nebius Mysterybox by presenting a token.
  5986. properties:
  5987. key:
  5988. description: |-
  5989. A key in the referenced Secret.
  5990. Some instances of this field may be defaulted, in others it may be required.
  5991. maxLength: 253
  5992. minLength: 1
  5993. pattern: ^[-._a-zA-Z0-9]+$
  5994. type: string
  5995. name:
  5996. description: The name of the Secret resource being referred to.
  5997. maxLength: 253
  5998. minLength: 1
  5999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6000. type: string
  6001. namespace:
  6002. description: |-
  6003. The namespace of the Secret resource being referred to.
  6004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6005. maxLength: 63
  6006. minLength: 1
  6007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6008. type: string
  6009. type: object
  6010. type: object
  6011. x-kubernetes-validations:
  6012. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6013. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6014. caProvider:
  6015. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6016. properties:
  6017. certSecretRef:
  6018. description: |-
  6019. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6020. In some instances, `key` is a required field.
  6021. properties:
  6022. key:
  6023. description: |-
  6024. A key in the referenced Secret.
  6025. Some instances of this field may be defaulted, in others it may be required.
  6026. maxLength: 253
  6027. minLength: 1
  6028. pattern: ^[-._a-zA-Z0-9]+$
  6029. type: string
  6030. name:
  6031. description: The name of the Secret resource being referred to.
  6032. maxLength: 253
  6033. minLength: 1
  6034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6035. type: string
  6036. namespace:
  6037. description: |-
  6038. The namespace of the Secret resource being referred to.
  6039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6040. maxLength: 63
  6041. minLength: 1
  6042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6043. type: string
  6044. type: object
  6045. type: object
  6046. required:
  6047. - apiDomain
  6048. - auth
  6049. type: object
  6050. ngrok:
  6051. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6052. properties:
  6053. apiUrl:
  6054. default: https://api.ngrok.com
  6055. description: APIURL is the URL of the ngrok API.
  6056. type: string
  6057. auth:
  6058. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6059. maxProperties: 1
  6060. minProperties: 1
  6061. properties:
  6062. apiKey:
  6063. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6064. properties:
  6065. secretRef:
  6066. description: SecretRef is a reference to a secret containing the ngrok API key.
  6067. properties:
  6068. key:
  6069. description: |-
  6070. A key in the referenced Secret.
  6071. Some instances of this field may be defaulted, in others it may be required.
  6072. maxLength: 253
  6073. minLength: 1
  6074. pattern: ^[-._a-zA-Z0-9]+$
  6075. type: string
  6076. name:
  6077. description: The name of the Secret resource being referred to.
  6078. maxLength: 253
  6079. minLength: 1
  6080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6081. type: string
  6082. namespace:
  6083. description: |-
  6084. The namespace of the Secret resource being referred to.
  6085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6086. maxLength: 63
  6087. minLength: 1
  6088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6089. type: string
  6090. type: object
  6091. type: object
  6092. type: object
  6093. vault:
  6094. description: Vault configures the ngrok vault to sync secrets with.
  6095. properties:
  6096. name:
  6097. description: Name is the name of the ngrok vault to sync secrets with.
  6098. type: string
  6099. required:
  6100. - name
  6101. type: object
  6102. required:
  6103. - auth
  6104. - vault
  6105. type: object
  6106. onboardbase:
  6107. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6108. properties:
  6109. apiHost:
  6110. default: https://public.onboardbase.com/api/v1/
  6111. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6112. type: string
  6113. auth:
  6114. description: Auth configures how the Operator authenticates with the Onboardbase API
  6115. properties:
  6116. apiKeyRef:
  6117. description: |-
  6118. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6119. It is used to recognize and authorize access to a project and environment within onboardbase
  6120. properties:
  6121. key:
  6122. description: |-
  6123. A key in the referenced Secret.
  6124. Some instances of this field may be defaulted, in others it may be required.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[-._a-zA-Z0-9]+$
  6128. type: string
  6129. name:
  6130. description: The name of the Secret resource being referred to.
  6131. maxLength: 253
  6132. minLength: 1
  6133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6134. type: string
  6135. namespace:
  6136. description: |-
  6137. The namespace of the Secret resource being referred to.
  6138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6139. maxLength: 63
  6140. minLength: 1
  6141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6142. type: string
  6143. type: object
  6144. passcodeRef:
  6145. description: OnboardbasePasscode is the passcode attached to the API Key
  6146. properties:
  6147. key:
  6148. description: |-
  6149. A key in the referenced Secret.
  6150. Some instances of this field may be defaulted, in others it may be required.
  6151. maxLength: 253
  6152. minLength: 1
  6153. pattern: ^[-._a-zA-Z0-9]+$
  6154. type: string
  6155. name:
  6156. description: The name of the Secret resource being referred to.
  6157. maxLength: 253
  6158. minLength: 1
  6159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6160. type: string
  6161. namespace:
  6162. description: |-
  6163. The namespace of the Secret resource being referred to.
  6164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6165. maxLength: 63
  6166. minLength: 1
  6167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6168. type: string
  6169. type: object
  6170. required:
  6171. - apiKeyRef
  6172. - passcodeRef
  6173. type: object
  6174. environment:
  6175. default: development
  6176. description: Environment is the name of an environmnent within a project to pull the secrets from
  6177. type: string
  6178. project:
  6179. default: development
  6180. description: Project is an onboardbase project that the secrets should be pulled from
  6181. type: string
  6182. required:
  6183. - apiHost
  6184. - auth
  6185. - environment
  6186. - project
  6187. type: object
  6188. onepassword:
  6189. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6190. properties:
  6191. auth:
  6192. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6193. properties:
  6194. secretRef:
  6195. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6196. properties:
  6197. connectTokenSecretRef:
  6198. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6199. properties:
  6200. key:
  6201. description: |-
  6202. A key in the referenced Secret.
  6203. Some instances of this field may be defaulted, in others it may be required.
  6204. maxLength: 253
  6205. minLength: 1
  6206. pattern: ^[-._a-zA-Z0-9]+$
  6207. type: string
  6208. name:
  6209. description: The name of the Secret resource being referred to.
  6210. maxLength: 253
  6211. minLength: 1
  6212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6213. type: string
  6214. namespace:
  6215. description: |-
  6216. The namespace of the Secret resource being referred to.
  6217. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6218. maxLength: 63
  6219. minLength: 1
  6220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6221. type: string
  6222. type: object
  6223. required:
  6224. - connectTokenSecretRef
  6225. type: object
  6226. required:
  6227. - secretRef
  6228. type: object
  6229. connectHost:
  6230. description: ConnectHost defines the OnePassword Connect Server to connect to
  6231. type: string
  6232. vaults:
  6233. additionalProperties:
  6234. type: integer
  6235. description: Vaults defines which OnePassword vaults to search in which order
  6236. type: object
  6237. required:
  6238. - auth
  6239. - connectHost
  6240. - vaults
  6241. type: object
  6242. onepasswordSDK:
  6243. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6244. properties:
  6245. auth:
  6246. description: Auth defines the information necessary to authenticate against OnePassword API.
  6247. properties:
  6248. serviceAccountSecretRef:
  6249. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6250. properties:
  6251. key:
  6252. description: |-
  6253. A key in the referenced Secret.
  6254. Some instances of this field may be defaulted, in others it may be required.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[-._a-zA-Z0-9]+$
  6258. type: string
  6259. name:
  6260. description: The name of the Secret resource being referred to.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6264. type: string
  6265. namespace:
  6266. description: |-
  6267. The namespace of the Secret resource being referred to.
  6268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6269. maxLength: 63
  6270. minLength: 1
  6271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6272. type: string
  6273. type: object
  6274. required:
  6275. - serviceAccountSecretRef
  6276. type: object
  6277. cache:
  6278. description: |-
  6279. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6280. When enabled, secrets are cached with the specified TTL.
  6281. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6282. If omitted, caching is disabled (default).
  6283. cache: {} is a valid option to set.
  6284. properties:
  6285. maxSize:
  6286. default: 100
  6287. description: |-
  6288. MaxSize is the maximum number of secrets to cache.
  6289. When the cache is full, least-recently-used entries are evicted.
  6290. minimum: 1
  6291. type: integer
  6292. ttl:
  6293. default: 5m
  6294. description: |-
  6295. TTL is the time-to-live for cached secrets.
  6296. Format: duration string (e.g., "5m", "1h", "30s")
  6297. type: string
  6298. type: object
  6299. integrationInfo:
  6300. description: |-
  6301. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6302. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6303. properties:
  6304. name:
  6305. default: 1Password SDK
  6306. description: Name defaults to "1Password SDK".
  6307. type: string
  6308. version:
  6309. default: v1.0.0
  6310. description: Version defaults to "v1.0.0".
  6311. type: string
  6312. type: object
  6313. vault:
  6314. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6315. type: string
  6316. required:
  6317. - auth
  6318. - vault
  6319. type: object
  6320. openBao:
  6321. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6322. properties:
  6323. auth:
  6324. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6325. properties:
  6326. appRole:
  6327. description: |-
  6328. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6329. with the role and secret stored in a Kubernetes Secret resource.
  6330. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6331. properties:
  6332. path:
  6333. default: approle
  6334. description: |-
  6335. Path where the App Role authentication backend is mounted
  6336. in OpenBao, e.g: "approle"
  6337. type: string
  6338. roleId:
  6339. description: |-
  6340. RoleID configured in the App Role authentication backend when setting
  6341. up the authentication backend in OpenBao.
  6342. minLength: 1
  6343. type: string
  6344. roleRef:
  6345. description: |-
  6346. Reference to a key in a Secret that contains the App Role ID used
  6347. to authenticate with OpenBao.
  6348. The `key` field must be specified and denotes which entry within the Secret
  6349. resource is used as the app role id.
  6350. properties:
  6351. key:
  6352. description: |-
  6353. A key in the referenced Secret.
  6354. Some instances of this field may be defaulted, in others it may be required.
  6355. maxLength: 253
  6356. minLength: 1
  6357. pattern: ^[-._a-zA-Z0-9]+$
  6358. type: string
  6359. name:
  6360. description: The name of the Secret resource being referred to.
  6361. maxLength: 253
  6362. minLength: 1
  6363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6364. type: string
  6365. namespace:
  6366. description: |-
  6367. The namespace of the Secret resource being referred to.
  6368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6369. maxLength: 63
  6370. minLength: 1
  6371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6372. type: string
  6373. type: object
  6374. secretRef:
  6375. description: |-
  6376. Reference to a key in a Secret that contains the App Role secret used
  6377. to authenticate with OpenBao.
  6378. The `key` field must be specified and denotes which entry within the Secret
  6379. resource is used as the app role secret.
  6380. properties:
  6381. key:
  6382. description: |-
  6383. A key in the referenced Secret.
  6384. Some instances of this field may be defaulted, in others it may be required.
  6385. maxLength: 253
  6386. minLength: 1
  6387. pattern: ^[-._a-zA-Z0-9]+$
  6388. type: string
  6389. name:
  6390. description: The name of the Secret resource being referred to.
  6391. maxLength: 253
  6392. minLength: 1
  6393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6394. type: string
  6395. namespace:
  6396. description: |-
  6397. The namespace of the Secret resource being referred to.
  6398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6399. maxLength: 63
  6400. minLength: 1
  6401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6402. type: string
  6403. type: object
  6404. required:
  6405. - path
  6406. - secretRef
  6407. type: object
  6408. x-kubernetes-validations:
  6409. - message: exactly one of the fields in [roleId roleRef] must be set
  6410. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6411. namespace:
  6412. description: |-
  6413. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6414. than the namespace your secret is in. Namespaces is a set of features
  6415. within OpenBao that allows OpenBao environments to support secure
  6416. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6417. if set, or empty otherwise
  6418. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6419. type: string
  6420. tokenSecretRef:
  6421. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6422. properties:
  6423. key:
  6424. description: |-
  6425. A key in the referenced Secret.
  6426. Some instances of this field may be defaulted, in others it may be required.
  6427. maxLength: 253
  6428. minLength: 1
  6429. pattern: ^[-._a-zA-Z0-9]+$
  6430. type: string
  6431. name:
  6432. description: The name of the Secret resource being referred to.
  6433. maxLength: 253
  6434. minLength: 1
  6435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6436. type: string
  6437. namespace:
  6438. description: |-
  6439. The namespace of the Secret resource being referred to.
  6440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6441. maxLength: 63
  6442. minLength: 1
  6443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6444. type: string
  6445. type: object
  6446. userPass:
  6447. description: UserPass authenticates with OpenBao by passing a username/password pair
  6448. properties:
  6449. path:
  6450. default: userpass
  6451. description: |-
  6452. Path where the UserPassword authentication backend is mounted
  6453. in OpenBao, e.g: "userpass"
  6454. type: string
  6455. secretRef:
  6456. description: |-
  6457. SecretRef to a key in a Secret resource containing password for the user
  6458. used to authenticate with OpenBao using the [UserPass authentication
  6459. method]
  6460. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6461. properties:
  6462. key:
  6463. description: |-
  6464. A key in the referenced Secret.
  6465. Some instances of this field may be defaulted, in others it may be required.
  6466. maxLength: 253
  6467. minLength: 1
  6468. pattern: ^[-._a-zA-Z0-9]+$
  6469. type: string
  6470. name:
  6471. description: The name of the Secret resource being referred to.
  6472. maxLength: 253
  6473. minLength: 1
  6474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6475. type: string
  6476. namespace:
  6477. description: |-
  6478. The namespace of the Secret resource being referred to.
  6479. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6480. maxLength: 63
  6481. minLength: 1
  6482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6483. type: string
  6484. type: object
  6485. username:
  6486. description: |-
  6487. Username is a username used to authenticate using the [UserPass
  6488. authentication method]
  6489. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6490. type: string
  6491. required:
  6492. - path
  6493. - username
  6494. type: object
  6495. type: object
  6496. x-kubernetes-validations:
  6497. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6498. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6499. caBundle:
  6500. description: |-
  6501. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6502. this and `caProvider` are not set the system root certificates are used
  6503. to validate the TLS connection.
  6504. format: byte
  6505. type: string
  6506. caProvider:
  6507. description: |-
  6508. The provider for the CA bundle to use to validate OpenBao server
  6509. certificate. If this and `caBundle` are not set the system root
  6510. certificates are used to validate the TLS connection.
  6511. properties:
  6512. key:
  6513. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6514. maxLength: 253
  6515. minLength: 1
  6516. pattern: ^[-._a-zA-Z0-9]+$
  6517. type: string
  6518. name:
  6519. description: The name of the object located at the provider type.
  6520. maxLength: 253
  6521. minLength: 1
  6522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6523. type: string
  6524. namespace:
  6525. description: |-
  6526. The namespace the Provider type is in.
  6527. Can only be defined when used in a ClusterSecretStore.
  6528. maxLength: 63
  6529. minLength: 1
  6530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6531. type: string
  6532. type:
  6533. description: The type of provider to use such as "Secret", or "ConfigMap".
  6534. enum:
  6535. - Secret
  6536. - ConfigMap
  6537. type: string
  6538. required:
  6539. - name
  6540. - type
  6541. type: object
  6542. namespace:
  6543. description: |-
  6544. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6545. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6546. e.g: "ns1".
  6547. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6548. type: string
  6549. path:
  6550. description: |-
  6551. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6552. "secret". The v2 KV secret engine version specific "/data" path suffix
  6553. for fetching secrets from OpenBao is optional and will be appended
  6554. if not present in specified path.
  6555. type: string
  6556. server:
  6557. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6558. type: string
  6559. version:
  6560. default: v2
  6561. description: |-
  6562. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6563. "v2". Version defaults to "v2".
  6564. enum:
  6565. - v1
  6566. - v2
  6567. type: string
  6568. required:
  6569. - server
  6570. type: object
  6571. x-kubernetes-validations:
  6572. - message: at most one of the fields in [caBundle caProvider] may be set
  6573. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6574. oracle:
  6575. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6576. properties:
  6577. auth:
  6578. description: |-
  6579. Auth configures how secret-manager authenticates with the Oracle Vault.
  6580. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6581. properties:
  6582. secretRef:
  6583. description: SecretRef to pass through sensitive information.
  6584. properties:
  6585. fingerprint:
  6586. description: Fingerprint is the fingerprint of the API private key.
  6587. properties:
  6588. key:
  6589. description: |-
  6590. A key in the referenced Secret.
  6591. Some instances of this field may be defaulted, in others it may be required.
  6592. maxLength: 253
  6593. minLength: 1
  6594. pattern: ^[-._a-zA-Z0-9]+$
  6595. type: string
  6596. name:
  6597. description: The name of the Secret resource being referred to.
  6598. maxLength: 253
  6599. minLength: 1
  6600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6601. type: string
  6602. namespace:
  6603. description: |-
  6604. The namespace of the Secret resource being referred to.
  6605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6606. maxLength: 63
  6607. minLength: 1
  6608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6609. type: string
  6610. type: object
  6611. privatekey:
  6612. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6613. properties:
  6614. key:
  6615. description: |-
  6616. A key in the referenced Secret.
  6617. Some instances of this field may be defaulted, in others it may be required.
  6618. maxLength: 253
  6619. minLength: 1
  6620. pattern: ^[-._a-zA-Z0-9]+$
  6621. type: string
  6622. name:
  6623. description: The name of the Secret resource being referred to.
  6624. maxLength: 253
  6625. minLength: 1
  6626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6627. type: string
  6628. namespace:
  6629. description: |-
  6630. The namespace of the Secret resource being referred to.
  6631. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6632. maxLength: 63
  6633. minLength: 1
  6634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6635. type: string
  6636. type: object
  6637. required:
  6638. - fingerprint
  6639. - privatekey
  6640. type: object
  6641. tenancy:
  6642. description: Tenancy is the tenancy OCID where user is located.
  6643. type: string
  6644. user:
  6645. description: User is an access OCID specific to the account.
  6646. type: string
  6647. required:
  6648. - secretRef
  6649. - tenancy
  6650. - user
  6651. type: object
  6652. compartment:
  6653. description: |-
  6654. Compartment is the vault compartment OCID.
  6655. Required for PushSecret
  6656. type: string
  6657. encryptionKey:
  6658. description: |-
  6659. EncryptionKey is the OCID of the encryption key within the vault.
  6660. Required for PushSecret
  6661. type: string
  6662. principalType:
  6663. description: |-
  6664. The type of principal to use for authentication. If left blank, the Auth struct will
  6665. determine the principal type. This optional field must be specified if using
  6666. workload identity.
  6667. enum:
  6668. - ""
  6669. - UserPrincipal
  6670. - InstancePrincipal
  6671. - Workload
  6672. type: string
  6673. region:
  6674. description: Region is the region where vault is located.
  6675. type: string
  6676. serviceAccountRef:
  6677. description: |-
  6678. ServiceAccountRef specified the service account
  6679. that should be used when authenticating with WorkloadIdentity.
  6680. properties:
  6681. audiences:
  6682. description: |-
  6683. Audience specifies the `aud` claim for the service account token
  6684. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6685. then this audiences will be appended to the list
  6686. items:
  6687. type: string
  6688. type: array
  6689. name:
  6690. description: The name of the ServiceAccount resource being referred to.
  6691. maxLength: 253
  6692. minLength: 1
  6693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6694. type: string
  6695. namespace:
  6696. description: |-
  6697. Namespace of the resource being referred to.
  6698. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6699. maxLength: 63
  6700. minLength: 1
  6701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6702. type: string
  6703. required:
  6704. - name
  6705. type: object
  6706. vault:
  6707. description: Vault is the vault's OCID of the specific vault where secret is located.
  6708. type: string
  6709. required:
  6710. - region
  6711. - vault
  6712. type: object
  6713. ovh:
  6714. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  6715. properties:
  6716. auth:
  6717. description: Authentication method (mtls or token).
  6718. properties:
  6719. mtls:
  6720. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  6721. properties:
  6722. caBundle:
  6723. format: byte
  6724. type: string
  6725. caProvider:
  6726. description: |-
  6727. CAProvider provides a custom certificate authority for accessing the provider's store.
  6728. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  6729. properties:
  6730. key:
  6731. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6732. maxLength: 253
  6733. minLength: 1
  6734. pattern: ^[-._a-zA-Z0-9]+$
  6735. type: string
  6736. name:
  6737. description: The name of the object located at the provider type.
  6738. maxLength: 253
  6739. minLength: 1
  6740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6741. type: string
  6742. namespace:
  6743. description: |-
  6744. The namespace the Provider type is in.
  6745. Can only be defined when used in a ClusterSecretStore.
  6746. maxLength: 63
  6747. minLength: 1
  6748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6749. type: string
  6750. type:
  6751. description: The type of provider to use such as "Secret", or "ConfigMap".
  6752. enum:
  6753. - Secret
  6754. - ConfigMap
  6755. type: string
  6756. required:
  6757. - name
  6758. - type
  6759. type: object
  6760. certSecretRef:
  6761. description: |-
  6762. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6763. In some instances, `key` is a required field.
  6764. properties:
  6765. key:
  6766. description: |-
  6767. A key in the referenced Secret.
  6768. Some instances of this field may be defaulted, in others it may be required.
  6769. maxLength: 253
  6770. minLength: 1
  6771. pattern: ^[-._a-zA-Z0-9]+$
  6772. type: string
  6773. name:
  6774. description: The name of the Secret resource being referred to.
  6775. maxLength: 253
  6776. minLength: 1
  6777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6778. type: string
  6779. namespace:
  6780. description: |-
  6781. The namespace of the Secret resource being referred to.
  6782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6783. maxLength: 63
  6784. minLength: 1
  6785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6786. type: string
  6787. type: object
  6788. keySecretRef:
  6789. description: |-
  6790. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6791. In some instances, `key` is a required field.
  6792. properties:
  6793. key:
  6794. description: |-
  6795. A key in the referenced Secret.
  6796. Some instances of this field may be defaulted, in others it may be required.
  6797. maxLength: 253
  6798. minLength: 1
  6799. pattern: ^[-._a-zA-Z0-9]+$
  6800. type: string
  6801. name:
  6802. description: The name of the Secret resource being referred to.
  6803. maxLength: 253
  6804. minLength: 1
  6805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6806. type: string
  6807. namespace:
  6808. description: |-
  6809. The namespace of the Secret resource being referred to.
  6810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6811. maxLength: 63
  6812. minLength: 1
  6813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6814. type: string
  6815. type: object
  6816. required:
  6817. - certSecretRef
  6818. - keySecretRef
  6819. type: object
  6820. token:
  6821. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  6822. properties:
  6823. tokenSecretRef:
  6824. description: |-
  6825. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6826. In some instances, `key` is a required field.
  6827. properties:
  6828. key:
  6829. description: |-
  6830. A key in the referenced Secret.
  6831. Some instances of this field may be defaulted, in others it may be required.
  6832. maxLength: 253
  6833. minLength: 1
  6834. pattern: ^[-._a-zA-Z0-9]+$
  6835. type: string
  6836. name:
  6837. description: The name of the Secret resource being referred to.
  6838. maxLength: 253
  6839. minLength: 1
  6840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6841. type: string
  6842. namespace:
  6843. description: |-
  6844. The namespace of the Secret resource being referred to.
  6845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6846. maxLength: 63
  6847. minLength: 1
  6848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6849. type: string
  6850. type: object
  6851. required:
  6852. - tokenSecretRef
  6853. type: object
  6854. type: object
  6855. casRequired:
  6856. description: 'Enables or disables check-and-set (CAS) (default: false).'
  6857. type: boolean
  6858. okmsTimeout:
  6859. default: 30
  6860. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  6861. format: int32
  6862. minimum: 1
  6863. type: integer
  6864. okmsid:
  6865. description: specifies the OKMS ID.
  6866. type: string
  6867. server:
  6868. description: specifies the OKMS server endpoint.
  6869. type: string
  6870. required:
  6871. - auth
  6872. - okmsid
  6873. - server
  6874. type: object
  6875. passbolt:
  6876. description: |-
  6877. PassboltProvider provides access to Passbolt secrets manager.
  6878. See: https://www.passbolt.com.
  6879. properties:
  6880. auth:
  6881. description: Auth defines the information necessary to authenticate against Passbolt Server
  6882. properties:
  6883. passwordSecretRef:
  6884. description: |-
  6885. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6886. In some instances, `key` is a required field.
  6887. properties:
  6888. key:
  6889. description: |-
  6890. A key in the referenced Secret.
  6891. Some instances of this field may be defaulted, in others it may be required.
  6892. maxLength: 253
  6893. minLength: 1
  6894. pattern: ^[-._a-zA-Z0-9]+$
  6895. type: string
  6896. name:
  6897. description: The name of the Secret resource being referred to.
  6898. maxLength: 253
  6899. minLength: 1
  6900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6901. type: string
  6902. namespace:
  6903. description: |-
  6904. The namespace of the Secret resource being referred to.
  6905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6906. maxLength: 63
  6907. minLength: 1
  6908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6909. type: string
  6910. type: object
  6911. privateKeySecretRef:
  6912. description: |-
  6913. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6914. In some instances, `key` is a required field.
  6915. properties:
  6916. key:
  6917. description: |-
  6918. A key in the referenced Secret.
  6919. Some instances of this field may be defaulted, in others it may be required.
  6920. maxLength: 253
  6921. minLength: 1
  6922. pattern: ^[-._a-zA-Z0-9]+$
  6923. type: string
  6924. name:
  6925. description: The name of the Secret resource being referred to.
  6926. maxLength: 253
  6927. minLength: 1
  6928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6929. type: string
  6930. namespace:
  6931. description: |-
  6932. The namespace of the Secret resource being referred to.
  6933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6934. maxLength: 63
  6935. minLength: 1
  6936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6937. type: string
  6938. type: object
  6939. required:
  6940. - passwordSecretRef
  6941. - privateKeySecretRef
  6942. type: object
  6943. caBundle:
  6944. description: |-
  6945. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  6946. if the Host URL is using HTTPS protocol. If not set the system root certificates
  6947. are used to validate the TLS connection.
  6948. format: byte
  6949. type: string
  6950. caProvider:
  6951. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  6952. properties:
  6953. key:
  6954. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6955. maxLength: 253
  6956. minLength: 1
  6957. pattern: ^[-._a-zA-Z0-9]+$
  6958. type: string
  6959. name:
  6960. description: The name of the object located at the provider type.
  6961. maxLength: 253
  6962. minLength: 1
  6963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6964. type: string
  6965. namespace:
  6966. description: |-
  6967. The namespace the Provider type is in.
  6968. Can only be defined when used in a ClusterSecretStore.
  6969. maxLength: 63
  6970. minLength: 1
  6971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6972. type: string
  6973. type:
  6974. description: The type of provider to use such as "Secret", or "ConfigMap".
  6975. enum:
  6976. - Secret
  6977. - ConfigMap
  6978. type: string
  6979. required:
  6980. - name
  6981. - type
  6982. type: object
  6983. host:
  6984. description: Host defines the Passbolt Server to connect to
  6985. type: string
  6986. required:
  6987. - auth
  6988. - host
  6989. type: object
  6990. passworddepot:
  6991. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  6992. properties:
  6993. auth:
  6994. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  6995. properties:
  6996. secretRef:
  6997. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  6998. properties:
  6999. credentials:
  7000. description: Username / Password is used for authentication.
  7001. properties:
  7002. key:
  7003. description: |-
  7004. A key in the referenced Secret.
  7005. Some instances of this field may be defaulted, in others it may be required.
  7006. maxLength: 253
  7007. minLength: 1
  7008. pattern: ^[-._a-zA-Z0-9]+$
  7009. type: string
  7010. name:
  7011. description: The name of the Secret resource being referred to.
  7012. maxLength: 253
  7013. minLength: 1
  7014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7015. type: string
  7016. namespace:
  7017. description: |-
  7018. The namespace of the Secret resource being referred to.
  7019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7020. maxLength: 63
  7021. minLength: 1
  7022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7023. type: string
  7024. type: object
  7025. type: object
  7026. required:
  7027. - secretRef
  7028. type: object
  7029. database:
  7030. description: Database to use as source
  7031. type: string
  7032. host:
  7033. description: URL configures the Password Depot instance URL.
  7034. type: string
  7035. required:
  7036. - auth
  7037. - database
  7038. - host
  7039. type: object
  7040. previder:
  7041. description: Previder configures this store to sync secrets using the Previder provider
  7042. properties:
  7043. auth:
  7044. description: PreviderAuth contains a secretRef for credentials.
  7045. properties:
  7046. secretRef:
  7047. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7048. properties:
  7049. accessToken:
  7050. description: The AccessToken is used for authentication
  7051. properties:
  7052. key:
  7053. description: |-
  7054. A key in the referenced Secret.
  7055. Some instances of this field may be defaulted, in others it may be required.
  7056. maxLength: 253
  7057. minLength: 1
  7058. pattern: ^[-._a-zA-Z0-9]+$
  7059. type: string
  7060. name:
  7061. description: The name of the Secret resource being referred to.
  7062. maxLength: 253
  7063. minLength: 1
  7064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7065. type: string
  7066. namespace:
  7067. description: |-
  7068. The namespace of the Secret resource being referred to.
  7069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7070. maxLength: 63
  7071. minLength: 1
  7072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7073. type: string
  7074. type: object
  7075. required:
  7076. - accessToken
  7077. type: object
  7078. type: object
  7079. baseUri:
  7080. type: string
  7081. required:
  7082. - auth
  7083. type: object
  7084. pulumi:
  7085. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7086. properties:
  7087. accessToken:
  7088. description: |-
  7089. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7090. Deprecated: Use auth.accessToken instead.
  7091. properties:
  7092. secretRef:
  7093. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7094. properties:
  7095. key:
  7096. description: |-
  7097. A key in the referenced Secret.
  7098. Some instances of this field may be defaulted, in others it may be required.
  7099. maxLength: 253
  7100. minLength: 1
  7101. pattern: ^[-._a-zA-Z0-9]+$
  7102. type: string
  7103. name:
  7104. description: The name of the Secret resource being referred to.
  7105. maxLength: 253
  7106. minLength: 1
  7107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7108. type: string
  7109. namespace:
  7110. description: |-
  7111. The namespace of the Secret resource being referred to.
  7112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7113. maxLength: 63
  7114. minLength: 1
  7115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7116. type: string
  7117. type: object
  7118. type: object
  7119. apiUrl:
  7120. default: https://api.pulumi.com/api/esc
  7121. description: APIURL is the URL of the Pulumi API.
  7122. type: string
  7123. auth:
  7124. description: |-
  7125. Auth configures how the Operator authenticates with the Pulumi API.
  7126. Either auth or the deprecated accessToken field must be specified.
  7127. properties:
  7128. accessToken:
  7129. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7130. properties:
  7131. secretRef:
  7132. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7133. properties:
  7134. key:
  7135. description: |-
  7136. A key in the referenced Secret.
  7137. Some instances of this field may be defaulted, in others it may be required.
  7138. maxLength: 253
  7139. minLength: 1
  7140. pattern: ^[-._a-zA-Z0-9]+$
  7141. type: string
  7142. name:
  7143. description: The name of the Secret resource being referred to.
  7144. maxLength: 253
  7145. minLength: 1
  7146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7147. type: string
  7148. namespace:
  7149. description: |-
  7150. The namespace of the Secret resource being referred to.
  7151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7152. maxLength: 63
  7153. minLength: 1
  7154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7155. type: string
  7156. type: object
  7157. type: object
  7158. oidcConfig:
  7159. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7160. properties:
  7161. expirationSeconds:
  7162. default: 600
  7163. description: |-
  7164. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7165. Defaults to 10 minutes.
  7166. format: int64
  7167. minimum: 600
  7168. type: integer
  7169. organization:
  7170. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7171. type: string
  7172. serviceAccountRef:
  7173. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7174. properties:
  7175. audiences:
  7176. description: |-
  7177. Audience specifies the `aud` claim for the service account token
  7178. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7179. then this audiences will be appended to the list
  7180. items:
  7181. type: string
  7182. type: array
  7183. name:
  7184. description: The name of the ServiceAccount resource being referred to.
  7185. maxLength: 253
  7186. minLength: 1
  7187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7188. type: string
  7189. namespace:
  7190. description: |-
  7191. Namespace of the resource being referred to.
  7192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7193. maxLength: 63
  7194. minLength: 1
  7195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7196. type: string
  7197. required:
  7198. - name
  7199. type: object
  7200. required:
  7201. - organization
  7202. - serviceAccountRef
  7203. type: object
  7204. type: object
  7205. x-kubernetes-validations:
  7206. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7207. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7208. environment:
  7209. description: |-
  7210. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7211. dynamically retrieved values from supported providers including all major clouds,
  7212. and other Pulumi ESC environments.
  7213. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7214. type: string
  7215. organization:
  7216. description: |-
  7217. Organization are a space to collaborate on shared projects and stacks.
  7218. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7219. type: string
  7220. project:
  7221. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7222. type: string
  7223. required:
  7224. - environment
  7225. - organization
  7226. - project
  7227. type: object
  7228. x-kubernetes-validations:
  7229. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7230. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7231. scaleway:
  7232. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7233. properties:
  7234. accessKey:
  7235. description: AccessKey is the non-secret part of the api key.
  7236. properties:
  7237. secretRef:
  7238. description: SecretRef references a key in a secret that will be used as value.
  7239. properties:
  7240. key:
  7241. description: |-
  7242. A key in the referenced Secret.
  7243. Some instances of this field may be defaulted, in others it may be required.
  7244. maxLength: 253
  7245. minLength: 1
  7246. pattern: ^[-._a-zA-Z0-9]+$
  7247. type: string
  7248. name:
  7249. description: The name of the Secret resource being referred to.
  7250. maxLength: 253
  7251. minLength: 1
  7252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7253. type: string
  7254. namespace:
  7255. description: |-
  7256. The namespace of the Secret resource being referred to.
  7257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7258. maxLength: 63
  7259. minLength: 1
  7260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7261. type: string
  7262. type: object
  7263. value:
  7264. description: Value can be specified directly to set a value without using a secret.
  7265. type: string
  7266. type: object
  7267. apiUrl:
  7268. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7269. type: string
  7270. projectId:
  7271. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7272. type: string
  7273. region:
  7274. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7275. type: string
  7276. secretKey:
  7277. description: SecretKey is the non-secret part of the api key.
  7278. properties:
  7279. secretRef:
  7280. description: SecretRef references a key in a secret that will be used as value.
  7281. properties:
  7282. key:
  7283. description: |-
  7284. A key in the referenced Secret.
  7285. Some instances of this field may be defaulted, in others it may be required.
  7286. maxLength: 253
  7287. minLength: 1
  7288. pattern: ^[-._a-zA-Z0-9]+$
  7289. type: string
  7290. name:
  7291. description: The name of the Secret resource being referred to.
  7292. maxLength: 253
  7293. minLength: 1
  7294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7295. type: string
  7296. namespace:
  7297. description: |-
  7298. The namespace of the Secret resource being referred to.
  7299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7300. maxLength: 63
  7301. minLength: 1
  7302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7303. type: string
  7304. type: object
  7305. value:
  7306. description: Value can be specified directly to set a value without using a secret.
  7307. type: string
  7308. type: object
  7309. required:
  7310. - accessKey
  7311. - projectId
  7312. - region
  7313. - secretKey
  7314. type: object
  7315. secretserver:
  7316. description: |-
  7317. SecretServer configures this store to sync secrets using SecretServer provider
  7318. https://docs.delinea.com/online-help/secret-server/start.htm
  7319. properties:
  7320. caBundle:
  7321. description: |-
  7322. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7323. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7324. are used to validate the TLS connection.
  7325. format: byte
  7326. type: string
  7327. caProvider:
  7328. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7329. properties:
  7330. key:
  7331. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7332. maxLength: 253
  7333. minLength: 1
  7334. pattern: ^[-._a-zA-Z0-9]+$
  7335. type: string
  7336. name:
  7337. description: The name of the object located at the provider type.
  7338. maxLength: 253
  7339. minLength: 1
  7340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7341. type: string
  7342. namespace:
  7343. description: |-
  7344. The namespace the Provider type is in.
  7345. Can only be defined when used in a ClusterSecretStore.
  7346. maxLength: 63
  7347. minLength: 1
  7348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7349. type: string
  7350. type:
  7351. description: The type of provider to use such as "Secret", or "ConfigMap".
  7352. enum:
  7353. - Secret
  7354. - ConfigMap
  7355. type: string
  7356. required:
  7357. - name
  7358. - type
  7359. type: object
  7360. domain:
  7361. description: Domain is the secret server domain.
  7362. type: string
  7363. password:
  7364. description: |-
  7365. Password is the secret server account password.
  7366. Required unless Token is set.
  7367. properties:
  7368. secretRef:
  7369. description: SecretRef references a key in a secret that will be used as value.
  7370. properties:
  7371. key:
  7372. description: |-
  7373. A key in the referenced Secret.
  7374. Some instances of this field may be defaulted, in others it may be required.
  7375. maxLength: 253
  7376. minLength: 1
  7377. pattern: ^[-._a-zA-Z0-9]+$
  7378. type: string
  7379. name:
  7380. description: The name of the Secret resource being referred to.
  7381. maxLength: 253
  7382. minLength: 1
  7383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7384. type: string
  7385. namespace:
  7386. description: |-
  7387. The namespace of the Secret resource being referred to.
  7388. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7389. maxLength: 63
  7390. minLength: 1
  7391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7392. type: string
  7393. type: object
  7394. value:
  7395. description: Value can be specified directly to set a value without using a secret.
  7396. minLength: 1
  7397. type: string
  7398. type: object
  7399. x-kubernetes-validations:
  7400. - message: exactly one of value or secretRef must be set
  7401. rule: has(self.value) != has(self.secretRef)
  7402. serverURL:
  7403. description: |-
  7404. ServerURL
  7405. URL to your secret server installation
  7406. type: string
  7407. token:
  7408. description: |-
  7409. Token is an access token used to authenticate to the secret server,
  7410. as an alternative to Username and Password. When set, Username and
  7411. Password are not required and are ignored.
  7412. properties:
  7413. secretRef:
  7414. description: SecretRef references a key in a secret that will be used as value.
  7415. properties:
  7416. key:
  7417. description: |-
  7418. A key in the referenced Secret.
  7419. Some instances of this field may be defaulted, in others it may be required.
  7420. maxLength: 253
  7421. minLength: 1
  7422. pattern: ^[-._a-zA-Z0-9]+$
  7423. type: string
  7424. name:
  7425. description: The name of the Secret resource being referred to.
  7426. maxLength: 253
  7427. minLength: 1
  7428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7429. type: string
  7430. namespace:
  7431. description: |-
  7432. The namespace of the Secret resource being referred to.
  7433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7434. maxLength: 63
  7435. minLength: 1
  7436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7437. type: string
  7438. type: object
  7439. value:
  7440. description: Value can be specified directly to set a value without using a secret.
  7441. minLength: 1
  7442. type: string
  7443. type: object
  7444. x-kubernetes-validations:
  7445. - message: exactly one of value or secretRef must be set
  7446. rule: has(self.value) != has(self.secretRef)
  7447. username:
  7448. description: |-
  7449. Username is the secret server account username.
  7450. Required unless Token is set.
  7451. properties:
  7452. secretRef:
  7453. description: SecretRef references a key in a secret that will be used as value.
  7454. properties:
  7455. key:
  7456. description: |-
  7457. A key in the referenced Secret.
  7458. Some instances of this field may be defaulted, in others it may be required.
  7459. maxLength: 253
  7460. minLength: 1
  7461. pattern: ^[-._a-zA-Z0-9]+$
  7462. type: string
  7463. name:
  7464. description: The name of the Secret resource being referred to.
  7465. maxLength: 253
  7466. minLength: 1
  7467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7468. type: string
  7469. namespace:
  7470. description: |-
  7471. The namespace of the Secret resource being referred to.
  7472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7473. maxLength: 63
  7474. minLength: 1
  7475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7476. type: string
  7477. type: object
  7478. value:
  7479. description: Value can be specified directly to set a value without using a secret.
  7480. minLength: 1
  7481. type: string
  7482. type: object
  7483. x-kubernetes-validations:
  7484. - message: exactly one of value or secretRef must be set
  7485. rule: has(self.value) != has(self.secretRef)
  7486. required:
  7487. - serverURL
  7488. type: object
  7489. x-kubernetes-validations:
  7490. - message: either token, or both username and password, must be set
  7491. rule: has(self.token) || (has(self.username) && has(self.password))
  7492. senhasegura:
  7493. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7494. properties:
  7495. auth:
  7496. description: Auth defines parameters to authenticate in senhasegura
  7497. properties:
  7498. clientId:
  7499. type: string
  7500. clientSecretSecretRef:
  7501. description: |-
  7502. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7503. In some instances, `key` is a required field.
  7504. properties:
  7505. key:
  7506. description: |-
  7507. A key in the referenced Secret.
  7508. Some instances of this field may be defaulted, in others it may be required.
  7509. maxLength: 253
  7510. minLength: 1
  7511. pattern: ^[-._a-zA-Z0-9]+$
  7512. type: string
  7513. name:
  7514. description: The name of the Secret resource being referred to.
  7515. maxLength: 253
  7516. minLength: 1
  7517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7518. type: string
  7519. namespace:
  7520. description: |-
  7521. The namespace of the Secret resource being referred to.
  7522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7523. maxLength: 63
  7524. minLength: 1
  7525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7526. type: string
  7527. type: object
  7528. required:
  7529. - clientId
  7530. - clientSecretSecretRef
  7531. type: object
  7532. ignoreSslCertificate:
  7533. default: false
  7534. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7535. type: boolean
  7536. module:
  7537. description: Module defines which senhasegura module should be used to get secrets
  7538. type: string
  7539. url:
  7540. description: URL of senhasegura
  7541. type: string
  7542. required:
  7543. - auth
  7544. - module
  7545. - url
  7546. type: object
  7547. vault:
  7548. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7549. properties:
  7550. auth:
  7551. description: Auth configures how secret-manager authenticates with the Vault server.
  7552. properties:
  7553. appRole:
  7554. description: |-
  7555. AppRole authenticates with Vault using the App Role auth mechanism,
  7556. with the role and secret stored in a Kubernetes Secret resource.
  7557. properties:
  7558. path:
  7559. default: approle
  7560. description: |-
  7561. Path where the App Role authentication backend is mounted
  7562. in Vault, e.g: "approle"
  7563. type: string
  7564. roleId:
  7565. description: |-
  7566. RoleID configured in the App Role authentication backend when setting
  7567. up the authentication backend in Vault.
  7568. type: string
  7569. roleRef:
  7570. description: |-
  7571. Reference to a key in a Secret that contains the App Role ID used
  7572. to authenticate with Vault.
  7573. The `key` field must be specified and denotes which entry within the Secret
  7574. resource is used as the app role id.
  7575. properties:
  7576. key:
  7577. description: |-
  7578. A key in the referenced Secret.
  7579. Some instances of this field may be defaulted, in others it may be required.
  7580. maxLength: 253
  7581. minLength: 1
  7582. pattern: ^[-._a-zA-Z0-9]+$
  7583. type: string
  7584. name:
  7585. description: The name of the Secret resource being referred to.
  7586. maxLength: 253
  7587. minLength: 1
  7588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7589. type: string
  7590. namespace:
  7591. description: |-
  7592. The namespace of the Secret resource being referred to.
  7593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7594. maxLength: 63
  7595. minLength: 1
  7596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7597. type: string
  7598. type: object
  7599. secretRef:
  7600. description: |-
  7601. Reference to a key in a Secret that contains the App Role secret used
  7602. to authenticate with Vault.
  7603. The `key` field must be specified and denotes which entry within the Secret
  7604. resource is used as the app role secret.
  7605. properties:
  7606. key:
  7607. description: |-
  7608. A key in the referenced Secret.
  7609. Some instances of this field may be defaulted, in others it may be required.
  7610. maxLength: 253
  7611. minLength: 1
  7612. pattern: ^[-._a-zA-Z0-9]+$
  7613. type: string
  7614. name:
  7615. description: The name of the Secret resource being referred to.
  7616. maxLength: 253
  7617. minLength: 1
  7618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7619. type: string
  7620. namespace:
  7621. description: |-
  7622. The namespace of the Secret resource being referred to.
  7623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7624. maxLength: 63
  7625. minLength: 1
  7626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7627. type: string
  7628. type: object
  7629. required:
  7630. - path
  7631. - secretRef
  7632. type: object
  7633. cert:
  7634. description: |-
  7635. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7636. Cert authentication method
  7637. properties:
  7638. clientCert:
  7639. description: |-
  7640. ClientCert is a certificate to authenticate using the Cert Vault
  7641. authentication method
  7642. properties:
  7643. key:
  7644. description: |-
  7645. A key in the referenced Secret.
  7646. Some instances of this field may be defaulted, in others it may be required.
  7647. maxLength: 253
  7648. minLength: 1
  7649. pattern: ^[-._a-zA-Z0-9]+$
  7650. type: string
  7651. name:
  7652. description: The name of the Secret resource being referred to.
  7653. maxLength: 253
  7654. minLength: 1
  7655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7656. type: string
  7657. namespace:
  7658. description: |-
  7659. The namespace of the Secret resource being referred to.
  7660. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7661. maxLength: 63
  7662. minLength: 1
  7663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7664. type: string
  7665. type: object
  7666. path:
  7667. default: cert
  7668. description: |-
  7669. Path where the Certificate authentication backend is mounted
  7670. in Vault, e.g: "cert"
  7671. type: string
  7672. secretRef:
  7673. description: |-
  7674. SecretRef to a key in a Secret resource containing client private key to
  7675. authenticate with Vault using the Cert authentication method
  7676. properties:
  7677. key:
  7678. description: |-
  7679. A key in the referenced Secret.
  7680. Some instances of this field may be defaulted, in others it may be required.
  7681. maxLength: 253
  7682. minLength: 1
  7683. pattern: ^[-._a-zA-Z0-9]+$
  7684. type: string
  7685. name:
  7686. description: The name of the Secret resource being referred to.
  7687. maxLength: 253
  7688. minLength: 1
  7689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7690. type: string
  7691. namespace:
  7692. description: |-
  7693. The namespace of the Secret resource being referred to.
  7694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7695. maxLength: 63
  7696. minLength: 1
  7697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7698. type: string
  7699. type: object
  7700. vaultRole:
  7701. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7702. type: string
  7703. type: object
  7704. gcp:
  7705. description: |-
  7706. Gcp authenticates with Vault using Google Cloud Platform authentication method
  7707. GCP authentication method
  7708. properties:
  7709. location:
  7710. description: Location optionally defines a location/region for the secret
  7711. type: string
  7712. path:
  7713. default: gcp
  7714. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  7715. type: string
  7716. projectID:
  7717. description: Project ID of the Google Cloud Platform project
  7718. type: string
  7719. role:
  7720. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  7721. type: string
  7722. secretRef:
  7723. description: Specify credentials in a Secret object
  7724. properties:
  7725. secretAccessKeySecretRef:
  7726. description: The SecretAccessKey is used for authentication
  7727. properties:
  7728. key:
  7729. description: |-
  7730. A key in the referenced Secret.
  7731. Some instances of this field may be defaulted, in others it may be required.
  7732. maxLength: 253
  7733. minLength: 1
  7734. pattern: ^[-._a-zA-Z0-9]+$
  7735. type: string
  7736. name:
  7737. description: The name of the Secret resource being referred to.
  7738. maxLength: 253
  7739. minLength: 1
  7740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7741. type: string
  7742. namespace:
  7743. description: |-
  7744. The namespace of the Secret resource being referred to.
  7745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7746. maxLength: 63
  7747. minLength: 1
  7748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7749. type: string
  7750. type: object
  7751. type: object
  7752. serviceAccountRef:
  7753. description: ServiceAccountRef to a service account for impersonation
  7754. properties:
  7755. audiences:
  7756. description: |-
  7757. Audience specifies the `aud` claim for the service account token
  7758. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7759. then this audiences will be appended to the list
  7760. items:
  7761. type: string
  7762. type: array
  7763. name:
  7764. description: The name of the ServiceAccount resource being referred to.
  7765. maxLength: 253
  7766. minLength: 1
  7767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7768. type: string
  7769. namespace:
  7770. description: |-
  7771. Namespace of the resource being referred to.
  7772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7773. maxLength: 63
  7774. minLength: 1
  7775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7776. type: string
  7777. required:
  7778. - name
  7779. type: object
  7780. workloadIdentity:
  7781. description: Specify a service account with Workload Identity
  7782. properties:
  7783. clusterLocation:
  7784. description: |-
  7785. ClusterLocation is the location of the cluster
  7786. If not specified, it fetches information from the metadata server
  7787. type: string
  7788. clusterName:
  7789. description: |-
  7790. ClusterName is the name of the cluster
  7791. If not specified, it fetches information from the metadata server
  7792. type: string
  7793. clusterProjectID:
  7794. description: |-
  7795. ClusterProjectID is the project ID of the cluster
  7796. If not specified, it fetches information from the metadata server
  7797. type: string
  7798. serviceAccountRef:
  7799. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  7800. properties:
  7801. audiences:
  7802. description: |-
  7803. Audience specifies the `aud` claim for the service account token
  7804. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7805. then this audiences will be appended to the list
  7806. items:
  7807. type: string
  7808. type: array
  7809. name:
  7810. description: The name of the ServiceAccount resource being referred to.
  7811. maxLength: 253
  7812. minLength: 1
  7813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7814. type: string
  7815. namespace:
  7816. description: |-
  7817. Namespace of the resource being referred to.
  7818. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7819. maxLength: 63
  7820. minLength: 1
  7821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7822. type: string
  7823. required:
  7824. - name
  7825. type: object
  7826. required:
  7827. - serviceAccountRef
  7828. type: object
  7829. required:
  7830. - role
  7831. type: object
  7832. iam:
  7833. description: |-
  7834. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  7835. AWS IAM authentication method
  7836. properties:
  7837. externalID:
  7838. description: AWS External ID set on assumed IAM roles
  7839. type: string
  7840. jwt:
  7841. description: Specify a service account with IRSA enabled
  7842. properties:
  7843. serviceAccountRef:
  7844. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  7845. properties:
  7846. audiences:
  7847. description: |-
  7848. Audience specifies the `aud` claim for the service account token
  7849. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7850. then this audiences will be appended to the list
  7851. items:
  7852. type: string
  7853. type: array
  7854. name:
  7855. description: The name of the ServiceAccount resource being referred to.
  7856. maxLength: 253
  7857. minLength: 1
  7858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7859. type: string
  7860. namespace:
  7861. description: |-
  7862. Namespace of the resource being referred to.
  7863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7864. maxLength: 63
  7865. minLength: 1
  7866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7867. type: string
  7868. required:
  7869. - name
  7870. type: object
  7871. type: object
  7872. path:
  7873. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  7874. type: string
  7875. region:
  7876. description: AWS region
  7877. type: string
  7878. role:
  7879. description: This is the AWS role to be assumed before talking to vault
  7880. type: string
  7881. secretRef:
  7882. description: Specify credentials in a Secret object
  7883. properties:
  7884. accessKeyIDSecretRef:
  7885. description: The AccessKeyID is used for authentication
  7886. properties:
  7887. key:
  7888. description: |-
  7889. A key in the referenced Secret.
  7890. Some instances of this field may be defaulted, in others it may be required.
  7891. maxLength: 253
  7892. minLength: 1
  7893. pattern: ^[-._a-zA-Z0-9]+$
  7894. type: string
  7895. name:
  7896. description: The name of the Secret resource being referred to.
  7897. maxLength: 253
  7898. minLength: 1
  7899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7900. type: string
  7901. namespace:
  7902. description: |-
  7903. The namespace of the Secret resource being referred to.
  7904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7905. maxLength: 63
  7906. minLength: 1
  7907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7908. type: string
  7909. type: object
  7910. secretAccessKeySecretRef:
  7911. description: The SecretAccessKey is used for authentication
  7912. properties:
  7913. key:
  7914. description: |-
  7915. A key in the referenced Secret.
  7916. Some instances of this field may be defaulted, in others it may be required.
  7917. maxLength: 253
  7918. minLength: 1
  7919. pattern: ^[-._a-zA-Z0-9]+$
  7920. type: string
  7921. name:
  7922. description: The name of the Secret resource being referred to.
  7923. maxLength: 253
  7924. minLength: 1
  7925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7926. type: string
  7927. namespace:
  7928. description: |-
  7929. The namespace of the Secret resource being referred to.
  7930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7931. maxLength: 63
  7932. minLength: 1
  7933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7934. type: string
  7935. type: object
  7936. sessionTokenSecretRef:
  7937. description: |-
  7938. The SessionToken used for authentication
  7939. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  7940. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  7941. properties:
  7942. key:
  7943. description: |-
  7944. A key in the referenced Secret.
  7945. Some instances of this field may be defaulted, in others it may be required.
  7946. maxLength: 253
  7947. minLength: 1
  7948. pattern: ^[-._a-zA-Z0-9]+$
  7949. type: string
  7950. name:
  7951. description: The name of the Secret resource being referred to.
  7952. maxLength: 253
  7953. minLength: 1
  7954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7955. type: string
  7956. namespace:
  7957. description: |-
  7958. The namespace of the Secret resource being referred to.
  7959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7960. maxLength: 63
  7961. minLength: 1
  7962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7963. type: string
  7964. type: object
  7965. type: object
  7966. vaultAwsIamServerID:
  7967. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  7968. type: string
  7969. vaultRole:
  7970. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  7971. type: string
  7972. required:
  7973. - vaultRole
  7974. type: object
  7975. jwt:
  7976. description: |-
  7977. Jwt authenticates with Vault by passing role and JWT token using the
  7978. JWT/OIDC authentication method
  7979. properties:
  7980. kubernetesServiceAccountToken:
  7981. description: |-
  7982. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  7983. a token for with the `TokenRequest` API.
  7984. properties:
  7985. audiences:
  7986. description: |-
  7987. Optional audiences field that will be used to request a temporary Kubernetes service
  7988. account token for the service account referenced by `serviceAccountRef`.
  7989. Defaults to a single audience `vault` it not specified.
  7990. Deprecated: use serviceAccountRef.Audiences instead
  7991. items:
  7992. type: string
  7993. type: array
  7994. expirationSeconds:
  7995. description: |-
  7996. Optional expiration time in seconds that will be used to request a temporary
  7997. Kubernetes service account token for the service account referenced by
  7998. `serviceAccountRef`.
  7999. Deprecated: this will be removed in the future.
  8000. Defaults to 10 minutes.
  8001. format: int64
  8002. type: integer
  8003. serviceAccountRef:
  8004. description: Service account field containing the name of a kubernetes ServiceAccount.
  8005. properties:
  8006. audiences:
  8007. description: |-
  8008. Audience specifies the `aud` claim for the service account token
  8009. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8010. then this audiences will be appended to the list
  8011. items:
  8012. type: string
  8013. type: array
  8014. name:
  8015. description: The name of the ServiceAccount resource being referred to.
  8016. maxLength: 253
  8017. minLength: 1
  8018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8019. type: string
  8020. namespace:
  8021. description: |-
  8022. Namespace of the resource being referred to.
  8023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8024. maxLength: 63
  8025. minLength: 1
  8026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8027. type: string
  8028. required:
  8029. - name
  8030. type: object
  8031. required:
  8032. - serviceAccountRef
  8033. type: object
  8034. path:
  8035. default: jwt
  8036. description: |-
  8037. Path where the JWT authentication backend is mounted
  8038. in Vault, e.g: "jwt"
  8039. type: string
  8040. role:
  8041. description: |-
  8042. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8043. authentication method
  8044. type: string
  8045. secretRef:
  8046. description: |-
  8047. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8048. authenticate with Vault using the JWT/OIDC authentication method.
  8049. properties:
  8050. key:
  8051. description: |-
  8052. A key in the referenced Secret.
  8053. Some instances of this field may be defaulted, in others it may be required.
  8054. maxLength: 253
  8055. minLength: 1
  8056. pattern: ^[-._a-zA-Z0-9]+$
  8057. type: string
  8058. name:
  8059. description: The name of the Secret resource being referred to.
  8060. maxLength: 253
  8061. minLength: 1
  8062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8063. type: string
  8064. namespace:
  8065. description: |-
  8066. The namespace of the Secret resource being referred to.
  8067. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8068. maxLength: 63
  8069. minLength: 1
  8070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8071. type: string
  8072. type: object
  8073. required:
  8074. - path
  8075. type: object
  8076. kubernetes:
  8077. description: |-
  8078. Kubernetes authenticates with Vault by passing the ServiceAccount
  8079. token stored in the named Secret resource to the Vault server.
  8080. properties:
  8081. mountPath:
  8082. default: kubernetes
  8083. description: |-
  8084. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8085. "kubernetes"
  8086. type: string
  8087. role:
  8088. description: |-
  8089. A required field containing the Vault Role to assume. A Role binds a
  8090. Kubernetes ServiceAccount with a set of Vault policies.
  8091. type: string
  8092. secretRef:
  8093. description: |-
  8094. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8095. for authenticating with Vault. If a name is specified without a key,
  8096. `token` is the default. If one is not specified, the one bound to
  8097. the controller will be used.
  8098. properties:
  8099. key:
  8100. description: |-
  8101. A key in the referenced Secret.
  8102. Some instances of this field may be defaulted, in others it may be required.
  8103. maxLength: 253
  8104. minLength: 1
  8105. pattern: ^[-._a-zA-Z0-9]+$
  8106. type: string
  8107. name:
  8108. description: The name of the Secret resource being referred to.
  8109. maxLength: 253
  8110. minLength: 1
  8111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8112. type: string
  8113. namespace:
  8114. description: |-
  8115. The namespace of the Secret resource being referred to.
  8116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8117. maxLength: 63
  8118. minLength: 1
  8119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8120. type: string
  8121. type: object
  8122. serviceAccountRef:
  8123. description: |-
  8124. Optional service account field containing the name of a kubernetes ServiceAccount.
  8125. If the service account is specified, the service account secret token JWT will be used
  8126. for authenticating with Vault. If the service account selector is not supplied,
  8127. the secretRef will be used instead.
  8128. properties:
  8129. audiences:
  8130. description: |-
  8131. Audience specifies the `aud` claim for the service account token
  8132. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8133. then this audiences will be appended to the list
  8134. items:
  8135. type: string
  8136. type: array
  8137. name:
  8138. description: The name of the ServiceAccount resource being referred to.
  8139. maxLength: 253
  8140. minLength: 1
  8141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8142. type: string
  8143. namespace:
  8144. description: |-
  8145. Namespace of the resource being referred to.
  8146. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8147. maxLength: 63
  8148. minLength: 1
  8149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8150. type: string
  8151. required:
  8152. - name
  8153. type: object
  8154. required:
  8155. - mountPath
  8156. - role
  8157. type: object
  8158. ldap:
  8159. description: |-
  8160. Ldap authenticates with Vault by passing username/password pair using
  8161. the LDAP authentication method
  8162. properties:
  8163. path:
  8164. default: ldap
  8165. description: |-
  8166. Path where the LDAP authentication backend is mounted
  8167. in Vault, e.g: "ldap"
  8168. type: string
  8169. secretRef:
  8170. description: |-
  8171. SecretRef to a key in a Secret resource containing password for the LDAP
  8172. user used to authenticate with Vault using the LDAP authentication
  8173. method
  8174. properties:
  8175. key:
  8176. description: |-
  8177. A key in the referenced Secret.
  8178. Some instances of this field may be defaulted, in others it may be required.
  8179. maxLength: 253
  8180. minLength: 1
  8181. pattern: ^[-._a-zA-Z0-9]+$
  8182. type: string
  8183. name:
  8184. description: The name of the Secret resource being referred to.
  8185. maxLength: 253
  8186. minLength: 1
  8187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8188. type: string
  8189. namespace:
  8190. description: |-
  8191. The namespace of the Secret resource being referred to.
  8192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8193. maxLength: 63
  8194. minLength: 1
  8195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8196. type: string
  8197. type: object
  8198. username:
  8199. description: |-
  8200. Username is an LDAP username used to authenticate using the LDAP Vault
  8201. authentication method
  8202. type: string
  8203. required:
  8204. - path
  8205. - username
  8206. type: object
  8207. namespace:
  8208. description: |-
  8209. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8210. Namespaces is a set of features within Vault Enterprise that allows
  8211. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8212. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8213. This will default to Vault.Namespace field if set, or empty otherwise
  8214. type: string
  8215. tokenSecretRef:
  8216. description: TokenSecretRef authenticates with Vault by presenting a token.
  8217. properties:
  8218. key:
  8219. description: |-
  8220. A key in the referenced Secret.
  8221. Some instances of this field may be defaulted, in others it may be required.
  8222. maxLength: 253
  8223. minLength: 1
  8224. pattern: ^[-._a-zA-Z0-9]+$
  8225. type: string
  8226. name:
  8227. description: The name of the Secret resource being referred to.
  8228. maxLength: 253
  8229. minLength: 1
  8230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8231. type: string
  8232. namespace:
  8233. description: |-
  8234. The namespace of the Secret resource being referred to.
  8235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8236. maxLength: 63
  8237. minLength: 1
  8238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8239. type: string
  8240. type: object
  8241. userPass:
  8242. description: UserPass authenticates with Vault by passing username/password pair
  8243. properties:
  8244. path:
  8245. default: userpass
  8246. description: |-
  8247. Path where the UserPassword authentication backend is mounted
  8248. in Vault, e.g: "userpass"
  8249. type: string
  8250. secretRef:
  8251. description: |-
  8252. SecretRef to a key in a Secret resource containing password for the
  8253. user used to authenticate with Vault using the UserPass authentication
  8254. method
  8255. properties:
  8256. key:
  8257. description: |-
  8258. A key in the referenced Secret.
  8259. Some instances of this field may be defaulted, in others it may be required.
  8260. maxLength: 253
  8261. minLength: 1
  8262. pattern: ^[-._a-zA-Z0-9]+$
  8263. type: string
  8264. name:
  8265. description: The name of the Secret resource being referred to.
  8266. maxLength: 253
  8267. minLength: 1
  8268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8269. type: string
  8270. namespace:
  8271. description: |-
  8272. The namespace of the Secret resource being referred to.
  8273. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8274. maxLength: 63
  8275. minLength: 1
  8276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8277. type: string
  8278. type: object
  8279. username:
  8280. description: |-
  8281. Username is a username used to authenticate using the UserPass Vault
  8282. authentication method
  8283. type: string
  8284. required:
  8285. - path
  8286. - username
  8287. type: object
  8288. type: object
  8289. caBundle:
  8290. description: |-
  8291. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8292. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8293. plain HTTP protocol connection. If not set the system root certificates
  8294. are used to validate the TLS connection.
  8295. format: byte
  8296. type: string
  8297. caProvider:
  8298. description: The provider for the CA bundle to use to validate Vault server certificate.
  8299. properties:
  8300. key:
  8301. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8302. maxLength: 253
  8303. minLength: 1
  8304. pattern: ^[-._a-zA-Z0-9]+$
  8305. type: string
  8306. name:
  8307. description: The name of the object located at the provider type.
  8308. maxLength: 253
  8309. minLength: 1
  8310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8311. type: string
  8312. namespace:
  8313. description: |-
  8314. The namespace the Provider type is in.
  8315. Can only be defined when used in a ClusterSecretStore.
  8316. maxLength: 63
  8317. minLength: 1
  8318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8319. type: string
  8320. type:
  8321. description: The type of provider to use such as "Secret", or "ConfigMap".
  8322. enum:
  8323. - Secret
  8324. - ConfigMap
  8325. type: string
  8326. required:
  8327. - name
  8328. - type
  8329. type: object
  8330. checkAndSet:
  8331. description: |-
  8332. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8333. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8334. the current version of the secret to prevent unintentional overwrites.
  8335. properties:
  8336. required:
  8337. description: |-
  8338. Required when true, all write operations must include a check-and-set parameter.
  8339. This helps prevent unintentional overwrites of secrets.
  8340. type: boolean
  8341. type: object
  8342. forwardInconsistent:
  8343. description: |-
  8344. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8345. leader instead of simply retrying within a loop. This can increase performance if
  8346. the option is enabled serverside.
  8347. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8348. type: boolean
  8349. headers:
  8350. additionalProperties:
  8351. type: string
  8352. description: Headers to be added in Vault request
  8353. type: object
  8354. namespace:
  8355. description: |-
  8356. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8357. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8358. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8359. type: string
  8360. path:
  8361. description: |-
  8362. Path is the mount path of the Vault KV backend endpoint, e.g:
  8363. "secret". The v2 KV secret engine version specific "/data" path suffix
  8364. for fetching secrets from Vault is optional and will be appended
  8365. if not present in specified path.
  8366. type: string
  8367. readYourWrites:
  8368. description: |-
  8369. ReadYourWrites ensures isolated read-after-write semantics by
  8370. providing discovered cluster replication states in each request.
  8371. More information about eventual consistency in Vault can be found here
  8372. https://www.vaultproject.io/docs/enterprise/consistency
  8373. type: boolean
  8374. server:
  8375. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8376. type: string
  8377. tls:
  8378. description: |-
  8379. The configuration used for client side related TLS communication, when the Vault server
  8380. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8381. This parameter is ignored for plain HTTP protocol connection.
  8382. It's worth noting this configuration is different from the "TLS certificates auth method",
  8383. which is available under the `auth.cert` section.
  8384. properties:
  8385. certSecretRef:
  8386. description: |-
  8387. CertSecretRef is a certificate added to the transport layer
  8388. when communicating with the Vault server.
  8389. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8390. properties:
  8391. key:
  8392. description: |-
  8393. A key in the referenced Secret.
  8394. Some instances of this field may be defaulted, in others it may be required.
  8395. maxLength: 253
  8396. minLength: 1
  8397. pattern: ^[-._a-zA-Z0-9]+$
  8398. type: string
  8399. name:
  8400. description: The name of the Secret resource being referred to.
  8401. maxLength: 253
  8402. minLength: 1
  8403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8404. type: string
  8405. namespace:
  8406. description: |-
  8407. The namespace of the Secret resource being referred to.
  8408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8409. maxLength: 63
  8410. minLength: 1
  8411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8412. type: string
  8413. type: object
  8414. keySecretRef:
  8415. description: |-
  8416. KeySecretRef to a key in a Secret resource containing client private key
  8417. added to the transport layer when communicating with the Vault server.
  8418. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8419. properties:
  8420. key:
  8421. description: |-
  8422. A key in the referenced Secret.
  8423. Some instances of this field may be defaulted, in others it may be required.
  8424. maxLength: 253
  8425. minLength: 1
  8426. pattern: ^[-._a-zA-Z0-9]+$
  8427. type: string
  8428. name:
  8429. description: The name of the Secret resource being referred to.
  8430. maxLength: 253
  8431. minLength: 1
  8432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8433. type: string
  8434. namespace:
  8435. description: |-
  8436. The namespace of the Secret resource being referred to.
  8437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8438. maxLength: 63
  8439. minLength: 1
  8440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8441. type: string
  8442. type: object
  8443. type: object
  8444. version:
  8445. default: v2
  8446. description: |-
  8447. Version is the Vault KV secret engine version. This can be either "v1" or
  8448. "v2". Version defaults to "v2".
  8449. enum:
  8450. - v1
  8451. - v2
  8452. type: string
  8453. required:
  8454. - server
  8455. type: object
  8456. volcengine:
  8457. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8458. properties:
  8459. auth:
  8460. description: |-
  8461. Auth defines the authentication method to use.
  8462. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8463. properties:
  8464. secretRef:
  8465. description: |-
  8466. SecretRef defines the static credentials to use for authentication.
  8467. If not set, IRSA is used.
  8468. properties:
  8469. accessKeyID:
  8470. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8471. properties:
  8472. key:
  8473. description: |-
  8474. A key in the referenced Secret.
  8475. Some instances of this field may be defaulted, in others it may be required.
  8476. maxLength: 253
  8477. minLength: 1
  8478. pattern: ^[-._a-zA-Z0-9]+$
  8479. type: string
  8480. name:
  8481. description: The name of the Secret resource being referred to.
  8482. maxLength: 253
  8483. minLength: 1
  8484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8485. type: string
  8486. namespace:
  8487. description: |-
  8488. The namespace of the Secret resource being referred to.
  8489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8490. maxLength: 63
  8491. minLength: 1
  8492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8493. type: string
  8494. type: object
  8495. secretAccessKey:
  8496. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8497. properties:
  8498. key:
  8499. description: |-
  8500. A key in the referenced Secret.
  8501. Some instances of this field may be defaulted, in others it may be required.
  8502. maxLength: 253
  8503. minLength: 1
  8504. pattern: ^[-._a-zA-Z0-9]+$
  8505. type: string
  8506. name:
  8507. description: The name of the Secret resource being referred to.
  8508. maxLength: 253
  8509. minLength: 1
  8510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8511. type: string
  8512. namespace:
  8513. description: |-
  8514. The namespace of the Secret resource being referred to.
  8515. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8516. maxLength: 63
  8517. minLength: 1
  8518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8519. type: string
  8520. type: object
  8521. token:
  8522. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8523. properties:
  8524. key:
  8525. description: |-
  8526. A key in the referenced Secret.
  8527. Some instances of this field may be defaulted, in others it may be required.
  8528. maxLength: 253
  8529. minLength: 1
  8530. pattern: ^[-._a-zA-Z0-9]+$
  8531. type: string
  8532. name:
  8533. description: The name of the Secret resource being referred to.
  8534. maxLength: 253
  8535. minLength: 1
  8536. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8537. type: string
  8538. namespace:
  8539. description: |-
  8540. The namespace of the Secret resource being referred to.
  8541. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8542. maxLength: 63
  8543. minLength: 1
  8544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8545. type: string
  8546. type: object
  8547. required:
  8548. - accessKeyID
  8549. - secretAccessKey
  8550. type: object
  8551. type: object
  8552. region:
  8553. description: Region specifies the Volcengine region to connect to.
  8554. type: string
  8555. required:
  8556. - region
  8557. type: object
  8558. webhook:
  8559. description: Webhook configures this store to sync secrets using a generic templated webhook
  8560. properties:
  8561. auth:
  8562. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8563. maxProperties: 1
  8564. minProperties: 1
  8565. properties:
  8566. ntlm:
  8567. description: NTLMProtocol configures the store to use NTLM for auth
  8568. properties:
  8569. passwordSecret:
  8570. description: |-
  8571. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8572. In some instances, `key` is a required field.
  8573. properties:
  8574. key:
  8575. description: |-
  8576. A key in the referenced Secret.
  8577. Some instances of this field may be defaulted, in others it may be required.
  8578. maxLength: 253
  8579. minLength: 1
  8580. pattern: ^[-._a-zA-Z0-9]+$
  8581. type: string
  8582. name:
  8583. description: The name of the Secret resource being referred to.
  8584. maxLength: 253
  8585. minLength: 1
  8586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8587. type: string
  8588. namespace:
  8589. description: |-
  8590. The namespace of the Secret resource being referred to.
  8591. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8592. maxLength: 63
  8593. minLength: 1
  8594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8595. type: string
  8596. type: object
  8597. usernameSecret:
  8598. description: |-
  8599. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8600. In some instances, `key` is a required field.
  8601. properties:
  8602. key:
  8603. description: |-
  8604. A key in the referenced Secret.
  8605. Some instances of this field may be defaulted, in others it may be required.
  8606. maxLength: 253
  8607. minLength: 1
  8608. pattern: ^[-._a-zA-Z0-9]+$
  8609. type: string
  8610. name:
  8611. description: The name of the Secret resource being referred to.
  8612. maxLength: 253
  8613. minLength: 1
  8614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8615. type: string
  8616. namespace:
  8617. description: |-
  8618. The namespace of the Secret resource being referred to.
  8619. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8620. maxLength: 63
  8621. minLength: 1
  8622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8623. type: string
  8624. type: object
  8625. required:
  8626. - passwordSecret
  8627. - usernameSecret
  8628. type: object
  8629. type: object
  8630. body:
  8631. description: Body
  8632. type: string
  8633. caBundle:
  8634. description: |-
  8635. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8636. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8637. plain HTTP protocol connection. If not set the system root certificates
  8638. are used to validate the TLS connection.
  8639. format: byte
  8640. type: string
  8641. caProvider:
  8642. description: The provider for the CA bundle to use to validate webhook server certificate.
  8643. properties:
  8644. key:
  8645. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8646. maxLength: 253
  8647. minLength: 1
  8648. pattern: ^[-._a-zA-Z0-9]+$
  8649. type: string
  8650. name:
  8651. description: The name of the object located at the provider type.
  8652. maxLength: 253
  8653. minLength: 1
  8654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8655. type: string
  8656. namespace:
  8657. description: The namespace the Provider type is in.
  8658. maxLength: 63
  8659. minLength: 1
  8660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8661. type: string
  8662. type:
  8663. description: The type of provider to use such as "Secret", or "ConfigMap".
  8664. enum:
  8665. - Secret
  8666. - ConfigMap
  8667. type: string
  8668. required:
  8669. - name
  8670. - type
  8671. type: object
  8672. headers:
  8673. additionalProperties:
  8674. type: string
  8675. description: Headers
  8676. type: object
  8677. method:
  8678. description: Webhook Method
  8679. type: string
  8680. result:
  8681. description: Result formatting
  8682. properties:
  8683. jsonPath:
  8684. description: Json path of return value
  8685. type: string
  8686. type: object
  8687. secrets:
  8688. description: |-
  8689. Secrets to fill in templates
  8690. These secrets will be passed to the templating function as key value pairs under the given name
  8691. items:
  8692. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8693. properties:
  8694. name:
  8695. description: Name of this secret in templates
  8696. type: string
  8697. secretRef:
  8698. description: Secret ref to fill in credentials
  8699. properties:
  8700. key:
  8701. description: |-
  8702. A key in the referenced Secret.
  8703. Some instances of this field may be defaulted, in others it may be required.
  8704. maxLength: 253
  8705. minLength: 1
  8706. pattern: ^[-._a-zA-Z0-9]+$
  8707. type: string
  8708. name:
  8709. description: The name of the Secret resource being referred to.
  8710. maxLength: 253
  8711. minLength: 1
  8712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8713. type: string
  8714. namespace:
  8715. description: |-
  8716. The namespace of the Secret resource being referred to.
  8717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8718. maxLength: 63
  8719. minLength: 1
  8720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8721. type: string
  8722. type: object
  8723. required:
  8724. - name
  8725. - secretRef
  8726. type: object
  8727. type: array
  8728. timeout:
  8729. description: Timeout
  8730. type: string
  8731. url:
  8732. description: Webhook url to call
  8733. type: string
  8734. required:
  8735. - url
  8736. type: object
  8737. yandexcertificatemanager:
  8738. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  8739. properties:
  8740. apiEndpoint:
  8741. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  8742. type: string
  8743. auth:
  8744. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  8745. properties:
  8746. authorizedKeySecretRef:
  8747. description: The authorized key used for authentication
  8748. properties:
  8749. key:
  8750. description: |-
  8751. A key in the referenced Secret.
  8752. Some instances of this field may be defaulted, in others it may be required.
  8753. maxLength: 253
  8754. minLength: 1
  8755. pattern: ^[-._a-zA-Z0-9]+$
  8756. type: string
  8757. name:
  8758. description: The name of the Secret resource being referred to.
  8759. maxLength: 253
  8760. minLength: 1
  8761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8762. type: string
  8763. namespace:
  8764. description: |-
  8765. The namespace of the Secret resource being referred to.
  8766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8767. maxLength: 63
  8768. minLength: 1
  8769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8770. type: string
  8771. type: object
  8772. type: object
  8773. caProvider:
  8774. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  8775. properties:
  8776. certSecretRef:
  8777. description: |-
  8778. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8779. In some instances, `key` is a required field.
  8780. properties:
  8781. key:
  8782. description: |-
  8783. A key in the referenced Secret.
  8784. Some instances of this field may be defaulted, in others it may be required.
  8785. maxLength: 253
  8786. minLength: 1
  8787. pattern: ^[-._a-zA-Z0-9]+$
  8788. type: string
  8789. name:
  8790. description: The name of the Secret resource being referred to.
  8791. maxLength: 253
  8792. minLength: 1
  8793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8794. type: string
  8795. namespace:
  8796. description: |-
  8797. The namespace of the Secret resource being referred to.
  8798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8799. maxLength: 63
  8800. minLength: 1
  8801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8802. type: string
  8803. type: object
  8804. type: object
  8805. fetching:
  8806. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  8807. maxProperties: 1
  8808. minProperties: 1
  8809. properties:
  8810. byID:
  8811. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  8812. type: object
  8813. byName:
  8814. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  8815. properties:
  8816. folderID:
  8817. description: The folder to fetch secrets from
  8818. type: string
  8819. required:
  8820. - folderID
  8821. type: object
  8822. type: object
  8823. required:
  8824. - auth
  8825. type: object
  8826. yandexlockbox:
  8827. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  8828. properties:
  8829. apiEndpoint:
  8830. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  8831. type: string
  8832. auth:
  8833. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  8834. properties:
  8835. authorizedKeySecretRef:
  8836. description: The authorized key used for authentication
  8837. properties:
  8838. key:
  8839. description: |-
  8840. A key in the referenced Secret.
  8841. Some instances of this field may be defaulted, in others it may be required.
  8842. maxLength: 253
  8843. minLength: 1
  8844. pattern: ^[-._a-zA-Z0-9]+$
  8845. type: string
  8846. name:
  8847. description: The name of the Secret resource being referred to.
  8848. maxLength: 253
  8849. minLength: 1
  8850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8851. type: string
  8852. namespace:
  8853. description: |-
  8854. The namespace of the Secret resource being referred to.
  8855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8856. maxLength: 63
  8857. minLength: 1
  8858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8859. type: string
  8860. type: object
  8861. type: object
  8862. caProvider:
  8863. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  8864. properties:
  8865. certSecretRef:
  8866. description: |-
  8867. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8868. In some instances, `key` is a required field.
  8869. properties:
  8870. key:
  8871. description: |-
  8872. A key in the referenced Secret.
  8873. Some instances of this field may be defaulted, in others it may be required.
  8874. maxLength: 253
  8875. minLength: 1
  8876. pattern: ^[-._a-zA-Z0-9]+$
  8877. type: string
  8878. name:
  8879. description: The name of the Secret resource being referred to.
  8880. maxLength: 253
  8881. minLength: 1
  8882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8883. type: string
  8884. namespace:
  8885. description: |-
  8886. The namespace of the Secret resource being referred to.
  8887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8888. maxLength: 63
  8889. minLength: 1
  8890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8891. type: string
  8892. type: object
  8893. type: object
  8894. fetching:
  8895. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  8896. maxProperties: 1
  8897. minProperties: 1
  8898. properties:
  8899. byID:
  8900. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  8901. type: object
  8902. byName:
  8903. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  8904. properties:
  8905. folderID:
  8906. description: The folder to fetch secrets from
  8907. type: string
  8908. required:
  8909. - folderID
  8910. type: object
  8911. type: object
  8912. required:
  8913. - auth
  8914. type: object
  8915. type: object
  8916. refreshInterval:
  8917. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  8918. type: integer
  8919. retrySettings:
  8920. description: Used to configure HTTP retries on failures.
  8921. properties:
  8922. maxRetries:
  8923. format: int32
  8924. type: integer
  8925. retryInterval:
  8926. type: string
  8927. type: object
  8928. required:
  8929. - provider
  8930. type: object
  8931. status:
  8932. description: SecretStoreStatus defines the observed state of the SecretStore.
  8933. properties:
  8934. capabilities:
  8935. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  8936. type: string
  8937. conditions:
  8938. items:
  8939. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  8940. properties:
  8941. lastTransitionTime:
  8942. format: date-time
  8943. type: string
  8944. message:
  8945. type: string
  8946. reason:
  8947. type: string
  8948. status:
  8949. type: string
  8950. type:
  8951. description: SecretStoreConditionType represents the condition of the SecretStore.
  8952. type: string
  8953. required:
  8954. - status
  8955. - type
  8956. type: object
  8957. type: array
  8958. type: object
  8959. type: object
  8960. served: true
  8961. storage: true
  8962. subresources:
  8963. status: {}
  8964. - additionalPrinterColumns:
  8965. - jsonPath: .metadata.creationTimestamp
  8966. name: AGE
  8967. type: date
  8968. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  8969. name: Status
  8970. type: string
  8971. - jsonPath: .status.capabilities
  8972. name: Capabilities
  8973. type: string
  8974. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  8975. name: Ready
  8976. type: string
  8977. deprecated: true
  8978. name: v1beta1
  8979. schema:
  8980. openAPIV3Schema:
  8981. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  8982. properties:
  8983. apiVersion:
  8984. description: |-
  8985. APIVersion defines the versioned schema of this representation of an object.
  8986. Servers should convert recognized schemas to the latest internal value, and
  8987. may reject unrecognized values.
  8988. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  8989. type: string
  8990. kind:
  8991. description: |-
  8992. Kind is a string value representing the REST resource this object represents.
  8993. Servers may infer this from the endpoint the client submits requests to.
  8994. Cannot be updated.
  8995. In CamelCase.
  8996. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  8997. type: string
  8998. metadata:
  8999. type: object
  9000. spec:
  9001. description: SecretStoreSpec defines the desired state of SecretStore.
  9002. properties:
  9003. conditions:
  9004. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9005. items:
  9006. description: |-
  9007. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9008. for a ClusterSecretStore instance.
  9009. properties:
  9010. namespaceRegexes:
  9011. description: Choose namespaces by using regex matching
  9012. items:
  9013. type: string
  9014. type: array
  9015. namespaceSelector:
  9016. description: Choose namespace using a labelSelector
  9017. properties:
  9018. matchExpressions:
  9019. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9020. items:
  9021. description: |-
  9022. A label selector requirement is a selector that contains values, a key, and an operator that
  9023. relates the key and values.
  9024. properties:
  9025. key:
  9026. description: key is the label key that the selector applies to.
  9027. type: string
  9028. operator:
  9029. description: |-
  9030. operator represents a key's relationship to a set of values.
  9031. Valid operators are In, NotIn, Exists and DoesNotExist.
  9032. type: string
  9033. values:
  9034. description: |-
  9035. values is an array of string values. If the operator is In or NotIn,
  9036. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9037. the values array must be empty. This array is replaced during a strategic
  9038. merge patch.
  9039. items:
  9040. type: string
  9041. type: array
  9042. x-kubernetes-list-type: atomic
  9043. required:
  9044. - key
  9045. - operator
  9046. type: object
  9047. type: array
  9048. x-kubernetes-list-type: atomic
  9049. matchLabels:
  9050. additionalProperties:
  9051. type: string
  9052. description: |-
  9053. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9054. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9055. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9056. type: object
  9057. type: object
  9058. x-kubernetes-map-type: atomic
  9059. namespaces:
  9060. description: Choose namespaces by name
  9061. items:
  9062. maxLength: 63
  9063. minLength: 1
  9064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9065. type: string
  9066. type: array
  9067. type: object
  9068. type: array
  9069. controller:
  9070. description: |-
  9071. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9072. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9073. type: string
  9074. provider:
  9075. description: Used to configure the provider. Only one provider may be set
  9076. maxProperties: 1
  9077. minProperties: 1
  9078. properties:
  9079. akeyless:
  9080. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9081. properties:
  9082. akeylessGWApiURL:
  9083. description: Akeyless GW API Url from which the secrets to be fetched from.
  9084. type: string
  9085. authSecretRef:
  9086. description: Auth configures how the operator authenticates with Akeyless.
  9087. properties:
  9088. kubernetesAuth:
  9089. description: |-
  9090. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9091. token stored in the named Secret resource.
  9092. properties:
  9093. accessID:
  9094. description: the Akeyless Kubernetes auth-method access-id
  9095. type: string
  9096. k8sConfName:
  9097. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9098. type: string
  9099. secretRef:
  9100. description: |-
  9101. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9102. for authenticating with Akeyless. If a name is specified without a key,
  9103. `token` is the default. If one is not specified, the one bound to
  9104. the controller will be used.
  9105. properties:
  9106. key:
  9107. description: |-
  9108. A key in the referenced Secret.
  9109. Some instances of this field may be defaulted, in others it may be required.
  9110. maxLength: 253
  9111. minLength: 1
  9112. pattern: ^[-._a-zA-Z0-9]+$
  9113. type: string
  9114. name:
  9115. description: The name of the Secret resource being referred to.
  9116. maxLength: 253
  9117. minLength: 1
  9118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9119. type: string
  9120. namespace:
  9121. description: |-
  9122. The namespace of the Secret resource being referred to.
  9123. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9124. maxLength: 63
  9125. minLength: 1
  9126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9127. type: string
  9128. type: object
  9129. serviceAccountRef:
  9130. description: |-
  9131. Optional service account field containing the name of a kubernetes ServiceAccount.
  9132. If the service account is specified, the service account secret token JWT will be used
  9133. for authenticating with Akeyless. If the service account selector is not supplied,
  9134. the secretRef will be used instead.
  9135. properties:
  9136. audiences:
  9137. description: |-
  9138. Audience specifies the `aud` claim for the service account token
  9139. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9140. then this audiences will be appended to the list
  9141. items:
  9142. type: string
  9143. type: array
  9144. name:
  9145. description: The name of the ServiceAccount resource being referred to.
  9146. maxLength: 253
  9147. minLength: 1
  9148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9149. type: string
  9150. namespace:
  9151. description: |-
  9152. Namespace of the resource being referred to.
  9153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9154. maxLength: 63
  9155. minLength: 1
  9156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9157. type: string
  9158. required:
  9159. - name
  9160. type: object
  9161. required:
  9162. - accessID
  9163. - k8sConfName
  9164. type: object
  9165. secretRef:
  9166. description: |-
  9167. Reference to a Secret that contains the details
  9168. to authenticate with Akeyless.
  9169. properties:
  9170. accessID:
  9171. description: The SecretAccessID is used for authentication
  9172. properties:
  9173. key:
  9174. description: |-
  9175. A key in the referenced Secret.
  9176. Some instances of this field may be defaulted, in others it may be required.
  9177. maxLength: 253
  9178. minLength: 1
  9179. pattern: ^[-._a-zA-Z0-9]+$
  9180. type: string
  9181. name:
  9182. description: The name of the Secret resource being referred to.
  9183. maxLength: 253
  9184. minLength: 1
  9185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9186. type: string
  9187. namespace:
  9188. description: |-
  9189. The namespace of the Secret resource being referred to.
  9190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9191. maxLength: 63
  9192. minLength: 1
  9193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9194. type: string
  9195. type: object
  9196. accessType:
  9197. description: |-
  9198. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9199. In some instances, `key` is a required field.
  9200. properties:
  9201. key:
  9202. description: |-
  9203. A key in the referenced Secret.
  9204. Some instances of this field may be defaulted, in others it may be required.
  9205. maxLength: 253
  9206. minLength: 1
  9207. pattern: ^[-._a-zA-Z0-9]+$
  9208. type: string
  9209. name:
  9210. description: The name of the Secret resource being referred to.
  9211. maxLength: 253
  9212. minLength: 1
  9213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9214. type: string
  9215. namespace:
  9216. description: |-
  9217. The namespace of the Secret resource being referred to.
  9218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9219. maxLength: 63
  9220. minLength: 1
  9221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9222. type: string
  9223. type: object
  9224. accessTypeParam:
  9225. description: |-
  9226. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9227. In some instances, `key` is a required field.
  9228. properties:
  9229. key:
  9230. description: |-
  9231. A key in the referenced Secret.
  9232. Some instances of this field may be defaulted, in others it may be required.
  9233. maxLength: 253
  9234. minLength: 1
  9235. pattern: ^[-._a-zA-Z0-9]+$
  9236. type: string
  9237. name:
  9238. description: The name of the Secret resource being referred to.
  9239. maxLength: 253
  9240. minLength: 1
  9241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9242. type: string
  9243. namespace:
  9244. description: |-
  9245. The namespace of the Secret resource being referred to.
  9246. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9247. maxLength: 63
  9248. minLength: 1
  9249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9250. type: string
  9251. type: object
  9252. type: object
  9253. type: object
  9254. caBundle:
  9255. description: |-
  9256. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9257. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9258. are used to validate the TLS connection.
  9259. format: byte
  9260. type: string
  9261. caProvider:
  9262. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9263. properties:
  9264. key:
  9265. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9266. maxLength: 253
  9267. minLength: 1
  9268. pattern: ^[-._a-zA-Z0-9]+$
  9269. type: string
  9270. name:
  9271. description: The name of the object located at the provider type.
  9272. maxLength: 253
  9273. minLength: 1
  9274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9275. type: string
  9276. namespace:
  9277. description: |-
  9278. The namespace the Provider type is in.
  9279. Can only be defined when used in a ClusterSecretStore.
  9280. maxLength: 63
  9281. minLength: 1
  9282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9283. type: string
  9284. type:
  9285. description: The type of provider to use such as "Secret", or "ConfigMap".
  9286. enum:
  9287. - Secret
  9288. - ConfigMap
  9289. type: string
  9290. required:
  9291. - name
  9292. - type
  9293. type: object
  9294. required:
  9295. - akeylessGWApiURL
  9296. - authSecretRef
  9297. type: object
  9298. alibaba:
  9299. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9300. properties:
  9301. auth:
  9302. description: AlibabaAuth contains a secretRef for credentials.
  9303. properties:
  9304. rrsa:
  9305. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9306. properties:
  9307. oidcProviderArn:
  9308. type: string
  9309. oidcTokenFilePath:
  9310. type: string
  9311. roleArn:
  9312. type: string
  9313. sessionName:
  9314. type: string
  9315. required:
  9316. - oidcProviderArn
  9317. - oidcTokenFilePath
  9318. - roleArn
  9319. - sessionName
  9320. type: object
  9321. secretRef:
  9322. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9323. properties:
  9324. accessKeyIDSecretRef:
  9325. description: The AccessKeyID is used for authentication
  9326. properties:
  9327. key:
  9328. description: |-
  9329. A key in the referenced Secret.
  9330. Some instances of this field may be defaulted, in others it may be required.
  9331. maxLength: 253
  9332. minLength: 1
  9333. pattern: ^[-._a-zA-Z0-9]+$
  9334. type: string
  9335. name:
  9336. description: The name of the Secret resource being referred to.
  9337. maxLength: 253
  9338. minLength: 1
  9339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9340. type: string
  9341. namespace:
  9342. description: |-
  9343. The namespace of the Secret resource being referred to.
  9344. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9345. maxLength: 63
  9346. minLength: 1
  9347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9348. type: string
  9349. type: object
  9350. accessKeySecretSecretRef:
  9351. description: The AccessKeySecret is used for authentication
  9352. properties:
  9353. key:
  9354. description: |-
  9355. A key in the referenced Secret.
  9356. Some instances of this field may be defaulted, in others it may be required.
  9357. maxLength: 253
  9358. minLength: 1
  9359. pattern: ^[-._a-zA-Z0-9]+$
  9360. type: string
  9361. name:
  9362. description: The name of the Secret resource being referred to.
  9363. maxLength: 253
  9364. minLength: 1
  9365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9366. type: string
  9367. namespace:
  9368. description: |-
  9369. The namespace of the Secret resource being referred to.
  9370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9371. maxLength: 63
  9372. minLength: 1
  9373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9374. type: string
  9375. type: object
  9376. required:
  9377. - accessKeyIDSecretRef
  9378. - accessKeySecretSecretRef
  9379. type: object
  9380. type: object
  9381. regionID:
  9382. description: Alibaba Region to be used for the provider
  9383. type: string
  9384. required:
  9385. - auth
  9386. - regionID
  9387. type: object
  9388. aws:
  9389. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9390. properties:
  9391. additionalRoles:
  9392. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9393. items:
  9394. type: string
  9395. type: array
  9396. auth:
  9397. description: |-
  9398. Auth defines the information necessary to authenticate against AWS
  9399. if not set aws sdk will infer credentials from your environment
  9400. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9401. properties:
  9402. jwt:
  9403. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9404. properties:
  9405. serviceAccountRef:
  9406. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9407. properties:
  9408. audiences:
  9409. description: |-
  9410. Audience specifies the `aud` claim for the service account token
  9411. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9412. then this audiences will be appended to the list
  9413. items:
  9414. type: string
  9415. type: array
  9416. name:
  9417. description: The name of the ServiceAccount resource being referred to.
  9418. maxLength: 253
  9419. minLength: 1
  9420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9421. type: string
  9422. namespace:
  9423. description: |-
  9424. Namespace of the resource being referred to.
  9425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9426. maxLength: 63
  9427. minLength: 1
  9428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9429. type: string
  9430. required:
  9431. - name
  9432. type: object
  9433. type: object
  9434. secretRef:
  9435. description: |-
  9436. AWSAuthSecretRef holds secret references for AWS credentials
  9437. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9438. properties:
  9439. accessKeyIDSecretRef:
  9440. description: The AccessKeyID is used for authentication
  9441. properties:
  9442. key:
  9443. description: |-
  9444. A key in the referenced Secret.
  9445. Some instances of this field may be defaulted, in others it may be required.
  9446. maxLength: 253
  9447. minLength: 1
  9448. pattern: ^[-._a-zA-Z0-9]+$
  9449. type: string
  9450. name:
  9451. description: The name of the Secret resource being referred to.
  9452. maxLength: 253
  9453. minLength: 1
  9454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9455. type: string
  9456. namespace:
  9457. description: |-
  9458. The namespace of the Secret resource being referred to.
  9459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9460. maxLength: 63
  9461. minLength: 1
  9462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9463. type: string
  9464. type: object
  9465. secretAccessKeySecretRef:
  9466. description: The SecretAccessKey is used for authentication
  9467. properties:
  9468. key:
  9469. description: |-
  9470. A key in the referenced Secret.
  9471. Some instances of this field may be defaulted, in others it may be required.
  9472. maxLength: 253
  9473. minLength: 1
  9474. pattern: ^[-._a-zA-Z0-9]+$
  9475. type: string
  9476. name:
  9477. description: The name of the Secret resource being referred to.
  9478. maxLength: 253
  9479. minLength: 1
  9480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9481. type: string
  9482. namespace:
  9483. description: |-
  9484. The namespace of the Secret resource being referred to.
  9485. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9486. maxLength: 63
  9487. minLength: 1
  9488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9489. type: string
  9490. type: object
  9491. sessionTokenSecretRef:
  9492. description: |-
  9493. The SessionToken used for authentication
  9494. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9495. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9496. properties:
  9497. key:
  9498. description: |-
  9499. A key in the referenced Secret.
  9500. Some instances of this field may be defaulted, in others it may be required.
  9501. maxLength: 253
  9502. minLength: 1
  9503. pattern: ^[-._a-zA-Z0-9]+$
  9504. type: string
  9505. name:
  9506. description: The name of the Secret resource being referred to.
  9507. maxLength: 253
  9508. minLength: 1
  9509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9510. type: string
  9511. namespace:
  9512. description: |-
  9513. The namespace of the Secret resource being referred to.
  9514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9515. maxLength: 63
  9516. minLength: 1
  9517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9518. type: string
  9519. type: object
  9520. type: object
  9521. type: object
  9522. externalID:
  9523. description: AWS External ID set on assumed IAM roles
  9524. type: string
  9525. prefix:
  9526. description: Prefix adds a prefix to all retrieved values.
  9527. type: string
  9528. region:
  9529. description: AWS Region to be used for the provider
  9530. type: string
  9531. role:
  9532. description: Role is a Role ARN which the provider will assume
  9533. type: string
  9534. secretsManager:
  9535. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9536. properties:
  9537. forceDeleteWithoutRecovery:
  9538. description: |-
  9539. Specifies whether to delete the secret without any recovery window. You
  9540. can't use both this parameter and RecoveryWindowInDays in the same call.
  9541. If you don't use either, then by default Secrets Manager uses a 30 day
  9542. recovery window.
  9543. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9544. type: boolean
  9545. recoveryWindowInDays:
  9546. description: |-
  9547. The number of days from 7 to 30 that Secrets Manager waits before
  9548. permanently deleting the secret. You can't use both this parameter and
  9549. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9550. then by default Secrets Manager uses a 30 day recovery window.
  9551. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9552. format: int64
  9553. type: integer
  9554. type: object
  9555. service:
  9556. description: Service defines which service should be used to fetch the secrets
  9557. enum:
  9558. - SecretsManager
  9559. - ParameterStore
  9560. type: string
  9561. sessionTags:
  9562. description: AWS STS assume role session tags
  9563. items:
  9564. description: Tag defines a tag key and value for AWS resources.
  9565. properties:
  9566. key:
  9567. type: string
  9568. value:
  9569. type: string
  9570. required:
  9571. - key
  9572. - value
  9573. type: object
  9574. type: array
  9575. transitiveTagKeys:
  9576. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9577. items:
  9578. type: string
  9579. type: array
  9580. required:
  9581. - region
  9582. - service
  9583. type: object
  9584. azurekv:
  9585. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9586. properties:
  9587. authSecretRef:
  9588. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9589. properties:
  9590. clientCertificate:
  9591. description: The Azure ClientCertificate of the service principle used for authentication.
  9592. properties:
  9593. key:
  9594. description: |-
  9595. A key in the referenced Secret.
  9596. Some instances of this field may be defaulted, in others it may be required.
  9597. maxLength: 253
  9598. minLength: 1
  9599. pattern: ^[-._a-zA-Z0-9]+$
  9600. type: string
  9601. name:
  9602. description: The name of the Secret resource being referred to.
  9603. maxLength: 253
  9604. minLength: 1
  9605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9606. type: string
  9607. namespace:
  9608. description: |-
  9609. The namespace of the Secret resource being referred to.
  9610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9611. maxLength: 63
  9612. minLength: 1
  9613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9614. type: string
  9615. type: object
  9616. clientId:
  9617. description: The Azure clientId of the service principle or managed identity used for authentication.
  9618. properties:
  9619. key:
  9620. description: |-
  9621. A key in the referenced Secret.
  9622. Some instances of this field may be defaulted, in others it may be required.
  9623. maxLength: 253
  9624. minLength: 1
  9625. pattern: ^[-._a-zA-Z0-9]+$
  9626. type: string
  9627. name:
  9628. description: The name of the Secret resource being referred to.
  9629. maxLength: 253
  9630. minLength: 1
  9631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9632. type: string
  9633. namespace:
  9634. description: |-
  9635. The namespace of the Secret resource being referred to.
  9636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9637. maxLength: 63
  9638. minLength: 1
  9639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9640. type: string
  9641. type: object
  9642. clientSecret:
  9643. description: The Azure ClientSecret of the service principle used for authentication.
  9644. properties:
  9645. key:
  9646. description: |-
  9647. A key in the referenced Secret.
  9648. Some instances of this field may be defaulted, in others it may be required.
  9649. maxLength: 253
  9650. minLength: 1
  9651. pattern: ^[-._a-zA-Z0-9]+$
  9652. type: string
  9653. name:
  9654. description: The name of the Secret resource being referred to.
  9655. maxLength: 253
  9656. minLength: 1
  9657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9658. type: string
  9659. namespace:
  9660. description: |-
  9661. The namespace of the Secret resource being referred to.
  9662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9663. maxLength: 63
  9664. minLength: 1
  9665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9666. type: string
  9667. type: object
  9668. tenantId:
  9669. description: The Azure tenantId of the managed identity used for authentication.
  9670. properties:
  9671. key:
  9672. description: |-
  9673. A key in the referenced Secret.
  9674. Some instances of this field may be defaulted, in others it may be required.
  9675. maxLength: 253
  9676. minLength: 1
  9677. pattern: ^[-._a-zA-Z0-9]+$
  9678. type: string
  9679. name:
  9680. description: The name of the Secret resource being referred to.
  9681. maxLength: 253
  9682. minLength: 1
  9683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9684. type: string
  9685. namespace:
  9686. description: |-
  9687. The namespace of the Secret resource being referred to.
  9688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9689. maxLength: 63
  9690. minLength: 1
  9691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9692. type: string
  9693. type: object
  9694. type: object
  9695. authType:
  9696. default: ServicePrincipal
  9697. description: |-
  9698. Auth type defines how to authenticate to the keyvault service.
  9699. Valid values are:
  9700. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  9701. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  9702. enum:
  9703. - ServicePrincipal
  9704. - ManagedIdentity
  9705. - WorkloadIdentity
  9706. type: string
  9707. environmentType:
  9708. default: PublicCloud
  9709. description: |-
  9710. EnvironmentType specifies the Azure cloud environment endpoints to use for
  9711. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  9712. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  9713. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  9714. enum:
  9715. - PublicCloud
  9716. - USGovernmentCloud
  9717. - ChinaCloud
  9718. - GermanCloud
  9719. type: string
  9720. identityId:
  9721. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  9722. type: string
  9723. serviceAccountRef:
  9724. description: |-
  9725. ServiceAccountRef specified the service account
  9726. that should be used when authenticating with WorkloadIdentity.
  9727. properties:
  9728. audiences:
  9729. description: |-
  9730. Audience specifies the `aud` claim for the service account token
  9731. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9732. then this audiences will be appended to the list
  9733. items:
  9734. type: string
  9735. type: array
  9736. name:
  9737. description: The name of the ServiceAccount resource being referred to.
  9738. maxLength: 253
  9739. minLength: 1
  9740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9741. type: string
  9742. namespace:
  9743. description: |-
  9744. Namespace of the resource being referred to.
  9745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9746. maxLength: 63
  9747. minLength: 1
  9748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9749. type: string
  9750. required:
  9751. - name
  9752. type: object
  9753. tenantId:
  9754. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9755. type: string
  9756. vaultUrl:
  9757. description: Vault Url from which the secrets to be fetched from.
  9758. type: string
  9759. required:
  9760. - vaultUrl
  9761. type: object
  9762. beyondtrust:
  9763. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  9764. properties:
  9765. auth:
  9766. description: Auth configures how the operator authenticates with Beyondtrust.
  9767. properties:
  9768. apiKey:
  9769. description: APIKey If not provided then ClientID/ClientSecret become required.
  9770. properties:
  9771. secretRef:
  9772. description: SecretRef references a key in a secret that will be used as value.
  9773. properties:
  9774. key:
  9775. description: |-
  9776. A key in the referenced Secret.
  9777. Some instances of this field may be defaulted, in others it may be required.
  9778. maxLength: 253
  9779. minLength: 1
  9780. pattern: ^[-._a-zA-Z0-9]+$
  9781. type: string
  9782. name:
  9783. description: The name of the Secret resource being referred to.
  9784. maxLength: 253
  9785. minLength: 1
  9786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9787. type: string
  9788. namespace:
  9789. description: |-
  9790. The namespace of the Secret resource being referred to.
  9791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9792. maxLength: 63
  9793. minLength: 1
  9794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9795. type: string
  9796. type: object
  9797. value:
  9798. description: Value can be specified directly to set a value without using a secret.
  9799. type: string
  9800. type: object
  9801. certificate:
  9802. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  9803. properties:
  9804. secretRef:
  9805. description: SecretRef references a key in a secret that will be used as value.
  9806. properties:
  9807. key:
  9808. description: |-
  9809. A key in the referenced Secret.
  9810. Some instances of this field may be defaulted, in others it may be required.
  9811. maxLength: 253
  9812. minLength: 1
  9813. pattern: ^[-._a-zA-Z0-9]+$
  9814. type: string
  9815. name:
  9816. description: The name of the Secret resource being referred to.
  9817. maxLength: 253
  9818. minLength: 1
  9819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9820. type: string
  9821. namespace:
  9822. description: |-
  9823. The namespace of the Secret resource being referred to.
  9824. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9825. maxLength: 63
  9826. minLength: 1
  9827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9828. type: string
  9829. type: object
  9830. value:
  9831. description: Value can be specified directly to set a value without using a secret.
  9832. type: string
  9833. type: object
  9834. certificateKey:
  9835. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  9836. properties:
  9837. secretRef:
  9838. description: SecretRef references a key in a secret that will be used as value.
  9839. properties:
  9840. key:
  9841. description: |-
  9842. A key in the referenced Secret.
  9843. Some instances of this field may be defaulted, in others it may be required.
  9844. maxLength: 253
  9845. minLength: 1
  9846. pattern: ^[-._a-zA-Z0-9]+$
  9847. type: string
  9848. name:
  9849. description: The name of the Secret resource being referred to.
  9850. maxLength: 253
  9851. minLength: 1
  9852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9853. type: string
  9854. namespace:
  9855. description: |-
  9856. The namespace of the Secret resource being referred to.
  9857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9858. maxLength: 63
  9859. minLength: 1
  9860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9861. type: string
  9862. type: object
  9863. value:
  9864. description: Value can be specified directly to set a value without using a secret.
  9865. type: string
  9866. type: object
  9867. clientId:
  9868. description: ClientID is the API OAuth Client ID.
  9869. properties:
  9870. secretRef:
  9871. description: SecretRef references a key in a secret that will be used as value.
  9872. properties:
  9873. key:
  9874. description: |-
  9875. A key in the referenced Secret.
  9876. Some instances of this field may be defaulted, in others it may be required.
  9877. maxLength: 253
  9878. minLength: 1
  9879. pattern: ^[-._a-zA-Z0-9]+$
  9880. type: string
  9881. name:
  9882. description: The name of the Secret resource being referred to.
  9883. maxLength: 253
  9884. minLength: 1
  9885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9886. type: string
  9887. namespace:
  9888. description: |-
  9889. The namespace of the Secret resource being referred to.
  9890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9891. maxLength: 63
  9892. minLength: 1
  9893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9894. type: string
  9895. type: object
  9896. value:
  9897. description: Value can be specified directly to set a value without using a secret.
  9898. type: string
  9899. type: object
  9900. clientSecret:
  9901. description: ClientSecret is the API OAuth Client Secret.
  9902. properties:
  9903. secretRef:
  9904. description: SecretRef references a key in a secret that will be used as value.
  9905. properties:
  9906. key:
  9907. description: |-
  9908. A key in the referenced Secret.
  9909. Some instances of this field may be defaulted, in others it may be required.
  9910. maxLength: 253
  9911. minLength: 1
  9912. pattern: ^[-._a-zA-Z0-9]+$
  9913. type: string
  9914. name:
  9915. description: The name of the Secret resource being referred to.
  9916. maxLength: 253
  9917. minLength: 1
  9918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9919. type: string
  9920. namespace:
  9921. description: |-
  9922. The namespace of the Secret resource being referred to.
  9923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9924. maxLength: 63
  9925. minLength: 1
  9926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9927. type: string
  9928. type: object
  9929. value:
  9930. description: Value can be specified directly to set a value without using a secret.
  9931. type: string
  9932. type: object
  9933. type: object
  9934. server:
  9935. description: Auth configures how API server works.
  9936. properties:
  9937. apiUrl:
  9938. type: string
  9939. apiVersion:
  9940. type: string
  9941. clientTimeOutSeconds:
  9942. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  9943. type: integer
  9944. decrypt:
  9945. default: true
  9946. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  9947. type: boolean
  9948. retrievalType:
  9949. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  9950. type: string
  9951. separator:
  9952. description: A character that separates the folder names.
  9953. type: string
  9954. verifyCA:
  9955. type: boolean
  9956. required:
  9957. - apiUrl
  9958. - verifyCA
  9959. type: object
  9960. required:
  9961. - auth
  9962. - server
  9963. type: object
  9964. bitwardensecretsmanager:
  9965. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  9966. properties:
  9967. apiURL:
  9968. type: string
  9969. auth:
  9970. description: |-
  9971. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  9972. Make sure that the token being used has permissions on the given secret.
  9973. properties:
  9974. secretRef:
  9975. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  9976. properties:
  9977. credentials:
  9978. description: AccessToken used for the bitwarden instance.
  9979. properties:
  9980. key:
  9981. description: |-
  9982. A key in the referenced Secret.
  9983. Some instances of this field may be defaulted, in others it may be required.
  9984. maxLength: 253
  9985. minLength: 1
  9986. pattern: ^[-._a-zA-Z0-9]+$
  9987. type: string
  9988. name:
  9989. description: The name of the Secret resource being referred to.
  9990. maxLength: 253
  9991. minLength: 1
  9992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9993. type: string
  9994. namespace:
  9995. description: |-
  9996. The namespace of the Secret resource being referred to.
  9997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9998. maxLength: 63
  9999. minLength: 1
  10000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10001. type: string
  10002. type: object
  10003. required:
  10004. - credentials
  10005. type: object
  10006. required:
  10007. - secretRef
  10008. type: object
  10009. bitwardenServerSDKURL:
  10010. type: string
  10011. caBundle:
  10012. description: |-
  10013. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10014. can be performed.
  10015. type: string
  10016. caProvider:
  10017. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10018. properties:
  10019. key:
  10020. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10021. maxLength: 253
  10022. minLength: 1
  10023. pattern: ^[-._a-zA-Z0-9]+$
  10024. type: string
  10025. name:
  10026. description: The name of the object located at the provider type.
  10027. maxLength: 253
  10028. minLength: 1
  10029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10030. type: string
  10031. namespace:
  10032. description: |-
  10033. The namespace the Provider type is in.
  10034. Can only be defined when used in a ClusterSecretStore.
  10035. maxLength: 63
  10036. minLength: 1
  10037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10038. type: string
  10039. type:
  10040. description: The type of provider to use such as "Secret", or "ConfigMap".
  10041. enum:
  10042. - Secret
  10043. - ConfigMap
  10044. type: string
  10045. required:
  10046. - name
  10047. - type
  10048. type: object
  10049. identityURL:
  10050. type: string
  10051. organizationID:
  10052. description: OrganizationID determines which organization this secret store manages.
  10053. type: string
  10054. projectID:
  10055. description: ProjectID determines which project this secret store manages.
  10056. type: string
  10057. required:
  10058. - auth
  10059. - organizationID
  10060. - projectID
  10061. type: object
  10062. chef:
  10063. description: Chef configures this store to sync secrets with chef server
  10064. properties:
  10065. auth:
  10066. description: Auth defines the information necessary to authenticate against chef Server
  10067. properties:
  10068. secretRef:
  10069. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10070. properties:
  10071. privateKeySecretRef:
  10072. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10073. properties:
  10074. key:
  10075. description: |-
  10076. A key in the referenced Secret.
  10077. Some instances of this field may be defaulted, in others it may be required.
  10078. maxLength: 253
  10079. minLength: 1
  10080. pattern: ^[-._a-zA-Z0-9]+$
  10081. type: string
  10082. name:
  10083. description: The name of the Secret resource being referred to.
  10084. maxLength: 253
  10085. minLength: 1
  10086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10087. type: string
  10088. namespace:
  10089. description: |-
  10090. The namespace of the Secret resource being referred to.
  10091. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10092. maxLength: 63
  10093. minLength: 1
  10094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10095. type: string
  10096. type: object
  10097. required:
  10098. - privateKeySecretRef
  10099. type: object
  10100. required:
  10101. - secretRef
  10102. type: object
  10103. serverUrl:
  10104. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10105. type: string
  10106. username:
  10107. description: UserName should be the user ID on the chef server
  10108. type: string
  10109. required:
  10110. - auth
  10111. - serverUrl
  10112. - username
  10113. type: object
  10114. cloudrusm:
  10115. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10116. properties:
  10117. auth:
  10118. description: CSMAuth contains a secretRef for credentials.
  10119. properties:
  10120. secretRef:
  10121. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10122. properties:
  10123. accessKeyIDSecretRef:
  10124. description: The AccessKeyID is used for authentication
  10125. properties:
  10126. key:
  10127. description: |-
  10128. A key in the referenced Secret.
  10129. Some instances of this field may be defaulted, in others it may be required.
  10130. maxLength: 253
  10131. minLength: 1
  10132. pattern: ^[-._a-zA-Z0-9]+$
  10133. type: string
  10134. name:
  10135. description: The name of the Secret resource being referred to.
  10136. maxLength: 253
  10137. minLength: 1
  10138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10139. type: string
  10140. namespace:
  10141. description: |-
  10142. The namespace of the Secret resource being referred to.
  10143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10144. maxLength: 63
  10145. minLength: 1
  10146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10147. type: string
  10148. type: object
  10149. accessKeySecretSecretRef:
  10150. description: The AccessKeySecret is used for authentication
  10151. properties:
  10152. key:
  10153. description: |-
  10154. A key in the referenced Secret.
  10155. Some instances of this field may be defaulted, in others it may be required.
  10156. maxLength: 253
  10157. minLength: 1
  10158. pattern: ^[-._a-zA-Z0-9]+$
  10159. type: string
  10160. name:
  10161. description: The name of the Secret resource being referred to.
  10162. maxLength: 253
  10163. minLength: 1
  10164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10165. type: string
  10166. namespace:
  10167. description: |-
  10168. The namespace of the Secret resource being referred to.
  10169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10170. maxLength: 63
  10171. minLength: 1
  10172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10173. type: string
  10174. type: object
  10175. required:
  10176. - accessKeyIDSecretRef
  10177. - accessKeySecretSecretRef
  10178. type: object
  10179. type: object
  10180. projectID:
  10181. description: ProjectID is the project, which the secrets are stored in.
  10182. type: string
  10183. required:
  10184. - auth
  10185. type: object
  10186. conjur:
  10187. description: Conjur configures this store to sync secrets using conjur provider
  10188. properties:
  10189. auth:
  10190. description: Defines authentication settings for connecting to Conjur.
  10191. properties:
  10192. apikey:
  10193. description: Authenticates with Conjur using an API key.
  10194. properties:
  10195. account:
  10196. description: Account is the Conjur organization account name.
  10197. type: string
  10198. apiKeyRef:
  10199. description: |-
  10200. A reference to a specific 'key' containing the Conjur API key
  10201. within a Secret resource. In some instances, `key` is a required field.
  10202. properties:
  10203. key:
  10204. description: |-
  10205. A key in the referenced Secret.
  10206. Some instances of this field may be defaulted, in others it may be required.
  10207. maxLength: 253
  10208. minLength: 1
  10209. pattern: ^[-._a-zA-Z0-9]+$
  10210. type: string
  10211. name:
  10212. description: The name of the Secret resource being referred to.
  10213. maxLength: 253
  10214. minLength: 1
  10215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10216. type: string
  10217. namespace:
  10218. description: |-
  10219. The namespace of the Secret resource being referred to.
  10220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10221. maxLength: 63
  10222. minLength: 1
  10223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10224. type: string
  10225. type: object
  10226. userRef:
  10227. description: |-
  10228. A reference to a specific 'key' containing the Conjur username
  10229. within a Secret resource. In some instances, `key` is a required field.
  10230. properties:
  10231. key:
  10232. description: |-
  10233. A key in the referenced Secret.
  10234. Some instances of this field may be defaulted, in others it may be required.
  10235. maxLength: 253
  10236. minLength: 1
  10237. pattern: ^[-._a-zA-Z0-9]+$
  10238. type: string
  10239. name:
  10240. description: The name of the Secret resource being referred to.
  10241. maxLength: 253
  10242. minLength: 1
  10243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10244. type: string
  10245. namespace:
  10246. description: |-
  10247. The namespace of the Secret resource being referred to.
  10248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10249. maxLength: 63
  10250. minLength: 1
  10251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10252. type: string
  10253. type: object
  10254. required:
  10255. - account
  10256. - apiKeyRef
  10257. - userRef
  10258. type: object
  10259. jwt:
  10260. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10261. properties:
  10262. account:
  10263. description: Account is the Conjur organization account name.
  10264. type: string
  10265. hostId:
  10266. description: |-
  10267. Optional HostID for JWT authentication. This may be used depending
  10268. on how the Conjur JWT authenticator policy is configured.
  10269. type: string
  10270. secretRef:
  10271. description: |-
  10272. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10273. authenticate with Conjur using the JWT authentication method.
  10274. properties:
  10275. key:
  10276. description: |-
  10277. A key in the referenced Secret.
  10278. Some instances of this field may be defaulted, in others it may be required.
  10279. maxLength: 253
  10280. minLength: 1
  10281. pattern: ^[-._a-zA-Z0-9]+$
  10282. type: string
  10283. name:
  10284. description: The name of the Secret resource being referred to.
  10285. maxLength: 253
  10286. minLength: 1
  10287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10288. type: string
  10289. namespace:
  10290. description: |-
  10291. The namespace of the Secret resource being referred to.
  10292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10293. maxLength: 63
  10294. minLength: 1
  10295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10296. type: string
  10297. type: object
  10298. serviceAccountRef:
  10299. description: |-
  10300. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10301. a token for with the `TokenRequest` API.
  10302. properties:
  10303. audiences:
  10304. description: |-
  10305. Audience specifies the `aud` claim for the service account token
  10306. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10307. then this audiences will be appended to the list
  10308. items:
  10309. type: string
  10310. type: array
  10311. name:
  10312. description: The name of the ServiceAccount resource being referred to.
  10313. maxLength: 253
  10314. minLength: 1
  10315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10316. type: string
  10317. namespace:
  10318. description: |-
  10319. Namespace of the resource being referred to.
  10320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10321. maxLength: 63
  10322. minLength: 1
  10323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10324. type: string
  10325. required:
  10326. - name
  10327. type: object
  10328. serviceID:
  10329. description: The conjur authn jwt webservice id
  10330. type: string
  10331. required:
  10332. - account
  10333. - serviceID
  10334. type: object
  10335. type: object
  10336. caBundle:
  10337. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10338. type: string
  10339. caProvider:
  10340. description: |-
  10341. Used to provide custom certificate authority (CA) certificates
  10342. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10343. that contains a PEM-encoded certificate.
  10344. properties:
  10345. key:
  10346. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10347. maxLength: 253
  10348. minLength: 1
  10349. pattern: ^[-._a-zA-Z0-9]+$
  10350. type: string
  10351. name:
  10352. description: The name of the object located at the provider type.
  10353. maxLength: 253
  10354. minLength: 1
  10355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10356. type: string
  10357. namespace:
  10358. description: |-
  10359. The namespace the Provider type is in.
  10360. Can only be defined when used in a ClusterSecretStore.
  10361. maxLength: 63
  10362. minLength: 1
  10363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10364. type: string
  10365. type:
  10366. description: The type of provider to use such as "Secret", or "ConfigMap".
  10367. enum:
  10368. - Secret
  10369. - ConfigMap
  10370. type: string
  10371. required:
  10372. - name
  10373. - type
  10374. type: object
  10375. url:
  10376. description: URL is the endpoint of the Conjur instance.
  10377. type: string
  10378. required:
  10379. - auth
  10380. - url
  10381. type: object
  10382. delinea:
  10383. description: |-
  10384. Delinea DevOps Secrets Vault
  10385. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10386. properties:
  10387. clientId:
  10388. description: ClientID is the non-secret part of the credential.
  10389. properties:
  10390. secretRef:
  10391. description: SecretRef references a key in a secret that will be used as value.
  10392. properties:
  10393. key:
  10394. description: |-
  10395. A key in the referenced Secret.
  10396. Some instances of this field may be defaulted, in others it may be required.
  10397. maxLength: 253
  10398. minLength: 1
  10399. pattern: ^[-._a-zA-Z0-9]+$
  10400. type: string
  10401. name:
  10402. description: The name of the Secret resource being referred to.
  10403. maxLength: 253
  10404. minLength: 1
  10405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10406. type: string
  10407. namespace:
  10408. description: |-
  10409. The namespace of the Secret resource being referred to.
  10410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10411. maxLength: 63
  10412. minLength: 1
  10413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10414. type: string
  10415. type: object
  10416. value:
  10417. description: Value can be specified directly to set a value without using a secret.
  10418. type: string
  10419. type: object
  10420. clientSecret:
  10421. description: ClientSecret is the secret part of the credential.
  10422. properties:
  10423. secretRef:
  10424. description: SecretRef references a key in a secret that will be used as value.
  10425. properties:
  10426. key:
  10427. description: |-
  10428. A key in the referenced Secret.
  10429. Some instances of this field may be defaulted, in others it may be required.
  10430. maxLength: 253
  10431. minLength: 1
  10432. pattern: ^[-._a-zA-Z0-9]+$
  10433. type: string
  10434. name:
  10435. description: The name of the Secret resource being referred to.
  10436. maxLength: 253
  10437. minLength: 1
  10438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10439. type: string
  10440. namespace:
  10441. description: |-
  10442. The namespace of the Secret resource being referred to.
  10443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10444. maxLength: 63
  10445. minLength: 1
  10446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10447. type: string
  10448. type: object
  10449. value:
  10450. description: Value can be specified directly to set a value without using a secret.
  10451. type: string
  10452. type: object
  10453. tenant:
  10454. description: Tenant is the chosen hostname / site name.
  10455. type: string
  10456. tld:
  10457. description: |-
  10458. TLD is based on the server location that was chosen during provisioning.
  10459. If unset, defaults to "com".
  10460. type: string
  10461. urlTemplate:
  10462. description: |-
  10463. URLTemplate
  10464. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10465. type: string
  10466. required:
  10467. - clientId
  10468. - clientSecret
  10469. - tenant
  10470. type: object
  10471. device42:
  10472. description: Device42 configures this store to sync secrets using the Device42 provider
  10473. properties:
  10474. auth:
  10475. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10476. properties:
  10477. secretRef:
  10478. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10479. properties:
  10480. credentials:
  10481. description: Username / Password is used for authentication.
  10482. properties:
  10483. key:
  10484. description: |-
  10485. A key in the referenced Secret.
  10486. Some instances of this field may be defaulted, in others it may be required.
  10487. maxLength: 253
  10488. minLength: 1
  10489. pattern: ^[-._a-zA-Z0-9]+$
  10490. type: string
  10491. name:
  10492. description: The name of the Secret resource being referred to.
  10493. maxLength: 253
  10494. minLength: 1
  10495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10496. type: string
  10497. namespace:
  10498. description: |-
  10499. The namespace of the Secret resource being referred to.
  10500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10501. maxLength: 63
  10502. minLength: 1
  10503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10504. type: string
  10505. type: object
  10506. type: object
  10507. required:
  10508. - secretRef
  10509. type: object
  10510. host:
  10511. description: URL configures the Device42 instance URL.
  10512. type: string
  10513. required:
  10514. - auth
  10515. - host
  10516. type: object
  10517. doppler:
  10518. description: Doppler configures this store to sync secrets using the Doppler provider
  10519. properties:
  10520. auth:
  10521. description: Auth configures how the Operator authenticates with the Doppler API
  10522. properties:
  10523. secretRef:
  10524. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10525. properties:
  10526. dopplerToken:
  10527. description: |-
  10528. The DopplerToken is used for authentication.
  10529. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10530. The Key attribute defaults to dopplerToken if not specified.
  10531. properties:
  10532. key:
  10533. description: |-
  10534. A key in the referenced Secret.
  10535. Some instances of this field may be defaulted, in others it may be required.
  10536. maxLength: 253
  10537. minLength: 1
  10538. pattern: ^[-._a-zA-Z0-9]+$
  10539. type: string
  10540. name:
  10541. description: The name of the Secret resource being referred to.
  10542. maxLength: 253
  10543. minLength: 1
  10544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10545. type: string
  10546. namespace:
  10547. description: |-
  10548. The namespace of the Secret resource being referred to.
  10549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10550. maxLength: 63
  10551. minLength: 1
  10552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10553. type: string
  10554. type: object
  10555. required:
  10556. - dopplerToken
  10557. type: object
  10558. required:
  10559. - secretRef
  10560. type: object
  10561. config:
  10562. description: Doppler config (required if not using a Service Token)
  10563. type: string
  10564. format:
  10565. description: Format enables the downloading of secrets as a file (string)
  10566. enum:
  10567. - json
  10568. - dotnet-json
  10569. - env
  10570. - yaml
  10571. - docker
  10572. type: string
  10573. nameTransformer:
  10574. description: Environment variable compatible name transforms that change secret names to a different format
  10575. enum:
  10576. - upper-camel
  10577. - camel
  10578. - lower-snake
  10579. - tf-var
  10580. - dotnet-env
  10581. - lower-kebab
  10582. type: string
  10583. project:
  10584. description: Doppler project (required if not using a Service Token)
  10585. type: string
  10586. required:
  10587. - auth
  10588. type: object
  10589. fake:
  10590. description: Fake configures a store with static key/value pairs
  10591. properties:
  10592. data:
  10593. items:
  10594. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10595. properties:
  10596. key:
  10597. type: string
  10598. value:
  10599. type: string
  10600. version:
  10601. type: string
  10602. required:
  10603. - key
  10604. - value
  10605. type: object
  10606. type: array
  10607. required:
  10608. - data
  10609. type: object
  10610. fortanix:
  10611. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10612. properties:
  10613. apiKey:
  10614. description: APIKey is the API token to access SDKMS Applications.
  10615. properties:
  10616. secretRef:
  10617. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10618. properties:
  10619. key:
  10620. description: |-
  10621. A key in the referenced Secret.
  10622. Some instances of this field may be defaulted, in others it may be required.
  10623. maxLength: 253
  10624. minLength: 1
  10625. pattern: ^[-._a-zA-Z0-9]+$
  10626. type: string
  10627. name:
  10628. description: The name of the Secret resource being referred to.
  10629. maxLength: 253
  10630. minLength: 1
  10631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10632. type: string
  10633. namespace:
  10634. description: |-
  10635. The namespace of the Secret resource being referred to.
  10636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10637. maxLength: 63
  10638. minLength: 1
  10639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10640. type: string
  10641. type: object
  10642. type: object
  10643. apiUrl:
  10644. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10645. type: string
  10646. type: object
  10647. gcpsm:
  10648. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10649. properties:
  10650. auth:
  10651. description: Auth defines the information necessary to authenticate against GCP
  10652. properties:
  10653. secretRef:
  10654. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10655. properties:
  10656. secretAccessKeySecretRef:
  10657. description: The SecretAccessKey is used for authentication
  10658. properties:
  10659. key:
  10660. description: |-
  10661. A key in the referenced Secret.
  10662. Some instances of this field may be defaulted, in others it may be required.
  10663. maxLength: 253
  10664. minLength: 1
  10665. pattern: ^[-._a-zA-Z0-9]+$
  10666. type: string
  10667. name:
  10668. description: The name of the Secret resource being referred to.
  10669. maxLength: 253
  10670. minLength: 1
  10671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10672. type: string
  10673. namespace:
  10674. description: |-
  10675. The namespace of the Secret resource being referred to.
  10676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10677. maxLength: 63
  10678. minLength: 1
  10679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10680. type: string
  10681. type: object
  10682. type: object
  10683. workloadIdentity:
  10684. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10685. properties:
  10686. clusterLocation:
  10687. description: |-
  10688. ClusterLocation is the location of the cluster
  10689. If not specified, it fetches information from the metadata server
  10690. type: string
  10691. clusterName:
  10692. description: |-
  10693. ClusterName is the name of the cluster
  10694. If not specified, it fetches information from the metadata server
  10695. type: string
  10696. clusterProjectID:
  10697. description: |-
  10698. ClusterProjectID is the project ID of the cluster
  10699. If not specified, it fetches information from the metadata server
  10700. type: string
  10701. serviceAccountRef:
  10702. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  10703. properties:
  10704. audiences:
  10705. description: |-
  10706. Audience specifies the `aud` claim for the service account token
  10707. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10708. then this audiences will be appended to the list
  10709. items:
  10710. type: string
  10711. type: array
  10712. name:
  10713. description: The name of the ServiceAccount resource being referred to.
  10714. maxLength: 253
  10715. minLength: 1
  10716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10717. type: string
  10718. namespace:
  10719. description: |-
  10720. Namespace of the resource being referred to.
  10721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10722. maxLength: 63
  10723. minLength: 1
  10724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10725. type: string
  10726. required:
  10727. - name
  10728. type: object
  10729. required:
  10730. - serviceAccountRef
  10731. type: object
  10732. type: object
  10733. location:
  10734. description: Location optionally defines a location for a secret
  10735. type: string
  10736. projectID:
  10737. description: ProjectID project where secret is located
  10738. type: string
  10739. type: object
  10740. github:
  10741. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  10742. properties:
  10743. appID:
  10744. description: appID specifies the Github APP that will be used to authenticate the client
  10745. format: int64
  10746. type: integer
  10747. auth:
  10748. description: auth configures how secret-manager authenticates with a Github instance.
  10749. properties:
  10750. privateKey:
  10751. description: |-
  10752. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10753. In some instances, `key` is a required field.
  10754. properties:
  10755. key:
  10756. description: |-
  10757. A key in the referenced Secret.
  10758. Some instances of this field may be defaulted, in others it may be required.
  10759. maxLength: 253
  10760. minLength: 1
  10761. pattern: ^[-._a-zA-Z0-9]+$
  10762. type: string
  10763. name:
  10764. description: The name of the Secret resource being referred to.
  10765. maxLength: 253
  10766. minLength: 1
  10767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10768. type: string
  10769. namespace:
  10770. description: |-
  10771. The namespace of the Secret resource being referred to.
  10772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10773. maxLength: 63
  10774. minLength: 1
  10775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10776. type: string
  10777. type: object
  10778. required:
  10779. - privateKey
  10780. type: object
  10781. environment:
  10782. description: environment will be used to fetch secrets from a particular environment within a github repository
  10783. type: string
  10784. installationID:
  10785. description: installationID specifies the Github APP installation that will be used to authenticate the client
  10786. format: int64
  10787. type: integer
  10788. organization:
  10789. description: organization will be used to fetch secrets from the Github organization
  10790. type: string
  10791. repository:
  10792. description: repository will be used to fetch secrets from the Github repository within an organization
  10793. type: string
  10794. uploadURL:
  10795. description: Upload URL for enterprise instances. Default to URL.
  10796. type: string
  10797. url:
  10798. default: https://github.com/
  10799. description: URL configures the Github instance URL. Defaults to https://github.com/.
  10800. type: string
  10801. required:
  10802. - appID
  10803. - auth
  10804. - installationID
  10805. - organization
  10806. type: object
  10807. gitlab:
  10808. description: GitLab configures this store to sync secrets using GitLab Variables provider
  10809. properties:
  10810. auth:
  10811. description: Auth configures how secret-manager authenticates with a GitLab instance.
  10812. properties:
  10813. SecretRef:
  10814. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  10815. properties:
  10816. accessToken:
  10817. description: AccessToken is used for authentication.
  10818. properties:
  10819. key:
  10820. description: |-
  10821. A key in the referenced Secret.
  10822. Some instances of this field may be defaulted, in others it may be required.
  10823. maxLength: 253
  10824. minLength: 1
  10825. pattern: ^[-._a-zA-Z0-9]+$
  10826. type: string
  10827. name:
  10828. description: The name of the Secret resource being referred to.
  10829. maxLength: 253
  10830. minLength: 1
  10831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10832. type: string
  10833. namespace:
  10834. description: |-
  10835. The namespace of the Secret resource being referred to.
  10836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10837. maxLength: 63
  10838. minLength: 1
  10839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10840. type: string
  10841. type: object
  10842. type: object
  10843. required:
  10844. - SecretRef
  10845. type: object
  10846. caBundle:
  10847. description: |-
  10848. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10849. can be performed.
  10850. format: byte
  10851. type: string
  10852. caProvider:
  10853. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10854. properties:
  10855. key:
  10856. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10857. maxLength: 253
  10858. minLength: 1
  10859. pattern: ^[-._a-zA-Z0-9]+$
  10860. type: string
  10861. name:
  10862. description: The name of the object located at the provider type.
  10863. maxLength: 253
  10864. minLength: 1
  10865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10866. type: string
  10867. namespace:
  10868. description: |-
  10869. The namespace the Provider type is in.
  10870. Can only be defined when used in a ClusterSecretStore.
  10871. maxLength: 63
  10872. minLength: 1
  10873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10874. type: string
  10875. type:
  10876. description: The type of provider to use such as "Secret", or "ConfigMap".
  10877. enum:
  10878. - Secret
  10879. - ConfigMap
  10880. type: string
  10881. required:
  10882. - name
  10883. - type
  10884. type: object
  10885. environment:
  10886. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  10887. type: string
  10888. groupIDs:
  10889. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  10890. items:
  10891. type: string
  10892. type: array
  10893. inheritFromGroups:
  10894. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  10895. type: boolean
  10896. projectID:
  10897. description: ProjectID specifies a project where secrets are located.
  10898. type: string
  10899. url:
  10900. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  10901. type: string
  10902. required:
  10903. - auth
  10904. type: object
  10905. ibm:
  10906. description: IBM configures this store to sync secrets using IBM Cloud provider
  10907. properties:
  10908. auth:
  10909. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  10910. maxProperties: 1
  10911. minProperties: 1
  10912. properties:
  10913. containerAuth:
  10914. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  10915. properties:
  10916. iamEndpoint:
  10917. type: string
  10918. profile:
  10919. description: the IBM Trusted Profile
  10920. type: string
  10921. tokenLocation:
  10922. description: Location the token is mounted on the pod
  10923. type: string
  10924. required:
  10925. - profile
  10926. type: object
  10927. secretRef:
  10928. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  10929. properties:
  10930. secretApiKeySecretRef:
  10931. description: The SecretAccessKey is used for authentication
  10932. properties:
  10933. key:
  10934. description: |-
  10935. A key in the referenced Secret.
  10936. Some instances of this field may be defaulted, in others it may be required.
  10937. maxLength: 253
  10938. minLength: 1
  10939. pattern: ^[-._a-zA-Z0-9]+$
  10940. type: string
  10941. name:
  10942. description: The name of the Secret resource being referred to.
  10943. maxLength: 253
  10944. minLength: 1
  10945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10946. type: string
  10947. namespace:
  10948. description: |-
  10949. The namespace of the Secret resource being referred to.
  10950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10951. maxLength: 63
  10952. minLength: 1
  10953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10954. type: string
  10955. type: object
  10956. type: object
  10957. type: object
  10958. serviceUrl:
  10959. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  10960. type: string
  10961. required:
  10962. - auth
  10963. type: object
  10964. infisical:
  10965. description: Infisical configures this store to sync secrets using the Infisical provider
  10966. properties:
  10967. auth:
  10968. description: Auth configures how the Operator authenticates with the Infisical API
  10969. properties:
  10970. universalAuthCredentials:
  10971. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  10972. properties:
  10973. clientId:
  10974. description: |-
  10975. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10976. In some instances, `key` is a required field.
  10977. properties:
  10978. key:
  10979. description: |-
  10980. A key in the referenced Secret.
  10981. Some instances of this field may be defaulted, in others it may be required.
  10982. maxLength: 253
  10983. minLength: 1
  10984. pattern: ^[-._a-zA-Z0-9]+$
  10985. type: string
  10986. name:
  10987. description: The name of the Secret resource being referred to.
  10988. maxLength: 253
  10989. minLength: 1
  10990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10991. type: string
  10992. namespace:
  10993. description: |-
  10994. The namespace of the Secret resource being referred to.
  10995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10996. maxLength: 63
  10997. minLength: 1
  10998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10999. type: string
  11000. type: object
  11001. clientSecret:
  11002. description: |-
  11003. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11004. In some instances, `key` is a required field.
  11005. properties:
  11006. key:
  11007. description: |-
  11008. A key in the referenced Secret.
  11009. Some instances of this field may be defaulted, in others it may be required.
  11010. maxLength: 253
  11011. minLength: 1
  11012. pattern: ^[-._a-zA-Z0-9]+$
  11013. type: string
  11014. name:
  11015. description: The name of the Secret resource being referred to.
  11016. maxLength: 253
  11017. minLength: 1
  11018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11019. type: string
  11020. namespace:
  11021. description: |-
  11022. The namespace of the Secret resource being referred to.
  11023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11024. maxLength: 63
  11025. minLength: 1
  11026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11027. type: string
  11028. type: object
  11029. required:
  11030. - clientId
  11031. - clientSecret
  11032. type: object
  11033. type: object
  11034. hostAPI:
  11035. default: https://app.infisical.com/api
  11036. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11037. type: string
  11038. secretsScope:
  11039. description: SecretsScope defines the scope of the secrets within the workspace
  11040. properties:
  11041. environmentSlug:
  11042. description: EnvironmentSlug is the required slug identifier for the environment.
  11043. type: string
  11044. expandSecretReferences:
  11045. default: true
  11046. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11047. type: boolean
  11048. projectSlug:
  11049. description: ProjectSlug is the required slug identifier for the project.
  11050. type: string
  11051. recursive:
  11052. default: false
  11053. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11054. type: boolean
  11055. secretsPath:
  11056. default: /
  11057. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11058. type: string
  11059. required:
  11060. - environmentSlug
  11061. - projectSlug
  11062. type: object
  11063. required:
  11064. - auth
  11065. - secretsScope
  11066. type: object
  11067. keepersecurity:
  11068. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11069. properties:
  11070. authRef:
  11071. description: |-
  11072. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11073. In some instances, `key` is a required field.
  11074. properties:
  11075. key:
  11076. description: |-
  11077. A key in the referenced Secret.
  11078. Some instances of this field may be defaulted, in others it may be required.
  11079. maxLength: 253
  11080. minLength: 1
  11081. pattern: ^[-._a-zA-Z0-9]+$
  11082. type: string
  11083. name:
  11084. description: The name of the Secret resource being referred to.
  11085. maxLength: 253
  11086. minLength: 1
  11087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11088. type: string
  11089. namespace:
  11090. description: |-
  11091. The namespace of the Secret resource being referred to.
  11092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11093. maxLength: 63
  11094. minLength: 1
  11095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11096. type: string
  11097. type: object
  11098. folderID:
  11099. type: string
  11100. required:
  11101. - authRef
  11102. - folderID
  11103. type: object
  11104. kubernetes:
  11105. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11106. properties:
  11107. auth:
  11108. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11109. maxProperties: 1
  11110. minProperties: 1
  11111. properties:
  11112. cert:
  11113. description: has both clientCert and clientKey as secretKeySelector
  11114. properties:
  11115. clientCert:
  11116. description: |-
  11117. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11118. In some instances, `key` is a required field.
  11119. properties:
  11120. key:
  11121. description: |-
  11122. A key in the referenced Secret.
  11123. Some instances of this field may be defaulted, in others it may be required.
  11124. maxLength: 253
  11125. minLength: 1
  11126. pattern: ^[-._a-zA-Z0-9]+$
  11127. type: string
  11128. name:
  11129. description: The name of the Secret resource being referred to.
  11130. maxLength: 253
  11131. minLength: 1
  11132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11133. type: string
  11134. namespace:
  11135. description: |-
  11136. The namespace of the Secret resource being referred to.
  11137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11138. maxLength: 63
  11139. minLength: 1
  11140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11141. type: string
  11142. type: object
  11143. clientKey:
  11144. description: |-
  11145. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11146. In some instances, `key` is a required field.
  11147. properties:
  11148. key:
  11149. description: |-
  11150. A key in the referenced Secret.
  11151. Some instances of this field may be defaulted, in others it may be required.
  11152. maxLength: 253
  11153. minLength: 1
  11154. pattern: ^[-._a-zA-Z0-9]+$
  11155. type: string
  11156. name:
  11157. description: The name of the Secret resource being referred to.
  11158. maxLength: 253
  11159. minLength: 1
  11160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11161. type: string
  11162. namespace:
  11163. description: |-
  11164. The namespace of the Secret resource being referred to.
  11165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11166. maxLength: 63
  11167. minLength: 1
  11168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11169. type: string
  11170. type: object
  11171. type: object
  11172. serviceAccount:
  11173. description: points to a service account that should be used for authentication
  11174. properties:
  11175. audiences:
  11176. description: |-
  11177. Audience specifies the `aud` claim for the service account token
  11178. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11179. then this audiences will be appended to the list
  11180. items:
  11181. type: string
  11182. type: array
  11183. name:
  11184. description: The name of the ServiceAccount resource being referred to.
  11185. maxLength: 253
  11186. minLength: 1
  11187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11188. type: string
  11189. namespace:
  11190. description: |-
  11191. Namespace of the resource being referred to.
  11192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11193. maxLength: 63
  11194. minLength: 1
  11195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11196. type: string
  11197. required:
  11198. - name
  11199. type: object
  11200. token:
  11201. description: use static token to authenticate with
  11202. properties:
  11203. bearerToken:
  11204. description: |-
  11205. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11206. In some instances, `key` is a required field.
  11207. properties:
  11208. key:
  11209. description: |-
  11210. A key in the referenced Secret.
  11211. Some instances of this field may be defaulted, in others it may be required.
  11212. maxLength: 253
  11213. minLength: 1
  11214. pattern: ^[-._a-zA-Z0-9]+$
  11215. type: string
  11216. name:
  11217. description: The name of the Secret resource being referred to.
  11218. maxLength: 253
  11219. minLength: 1
  11220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11221. type: string
  11222. namespace:
  11223. description: |-
  11224. The namespace of the Secret resource being referred to.
  11225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11226. maxLength: 63
  11227. minLength: 1
  11228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11229. type: string
  11230. type: object
  11231. type: object
  11232. type: object
  11233. authRef:
  11234. description: A reference to a secret that contains the auth information.
  11235. properties:
  11236. key:
  11237. description: |-
  11238. A key in the referenced Secret.
  11239. Some instances of this field may be defaulted, in others it may be required.
  11240. maxLength: 253
  11241. minLength: 1
  11242. pattern: ^[-._a-zA-Z0-9]+$
  11243. type: string
  11244. name:
  11245. description: The name of the Secret resource being referred to.
  11246. maxLength: 253
  11247. minLength: 1
  11248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11249. type: string
  11250. namespace:
  11251. description: |-
  11252. The namespace of the Secret resource being referred to.
  11253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11254. maxLength: 63
  11255. minLength: 1
  11256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11257. type: string
  11258. type: object
  11259. remoteNamespace:
  11260. default: default
  11261. description: Remote namespace to fetch the secrets from
  11262. maxLength: 63
  11263. minLength: 1
  11264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11265. type: string
  11266. server:
  11267. description: configures the Kubernetes server Address.
  11268. properties:
  11269. caBundle:
  11270. description: CABundle is a base64-encoded CA certificate
  11271. format: byte
  11272. type: string
  11273. caProvider:
  11274. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11275. properties:
  11276. key:
  11277. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11278. maxLength: 253
  11279. minLength: 1
  11280. pattern: ^[-._a-zA-Z0-9]+$
  11281. type: string
  11282. name:
  11283. description: The name of the object located at the provider type.
  11284. maxLength: 253
  11285. minLength: 1
  11286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11287. type: string
  11288. namespace:
  11289. description: |-
  11290. The namespace the Provider type is in.
  11291. Can only be defined when used in a ClusterSecretStore.
  11292. maxLength: 63
  11293. minLength: 1
  11294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11295. type: string
  11296. type:
  11297. description: The type of provider to use such as "Secret", or "ConfigMap".
  11298. enum:
  11299. - Secret
  11300. - ConfigMap
  11301. type: string
  11302. required:
  11303. - name
  11304. - type
  11305. type: object
  11306. url:
  11307. default: kubernetes.default
  11308. description: configures the Kubernetes server Address.
  11309. type: string
  11310. type: object
  11311. type: object
  11312. onboardbase:
  11313. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11314. properties:
  11315. apiHost:
  11316. default: https://public.onboardbase.com/api/v1/
  11317. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11318. type: string
  11319. auth:
  11320. description: Auth configures how the Operator authenticates with the Onboardbase API
  11321. properties:
  11322. apiKeyRef:
  11323. description: |-
  11324. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11325. It is used to recognize and authorize access to a project and environment within onboardbase
  11326. properties:
  11327. key:
  11328. description: |-
  11329. A key in the referenced Secret.
  11330. Some instances of this field may be defaulted, in others it may be required.
  11331. maxLength: 253
  11332. minLength: 1
  11333. pattern: ^[-._a-zA-Z0-9]+$
  11334. type: string
  11335. name:
  11336. description: The name of the Secret resource being referred to.
  11337. maxLength: 253
  11338. minLength: 1
  11339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11340. type: string
  11341. namespace:
  11342. description: |-
  11343. The namespace of the Secret resource being referred to.
  11344. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11345. maxLength: 63
  11346. minLength: 1
  11347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11348. type: string
  11349. type: object
  11350. passcodeRef:
  11351. description: OnboardbasePasscode is the passcode attached to the API Key
  11352. properties:
  11353. key:
  11354. description: |-
  11355. A key in the referenced Secret.
  11356. Some instances of this field may be defaulted, in others it may be required.
  11357. maxLength: 253
  11358. minLength: 1
  11359. pattern: ^[-._a-zA-Z0-9]+$
  11360. type: string
  11361. name:
  11362. description: The name of the Secret resource being referred to.
  11363. maxLength: 253
  11364. minLength: 1
  11365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11366. type: string
  11367. namespace:
  11368. description: |-
  11369. The namespace of the Secret resource being referred to.
  11370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11371. maxLength: 63
  11372. minLength: 1
  11373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11374. type: string
  11375. type: object
  11376. required:
  11377. - apiKeyRef
  11378. - passcodeRef
  11379. type: object
  11380. environment:
  11381. default: development
  11382. description: Environment is the name of an environmnent within a project to pull the secrets from
  11383. type: string
  11384. project:
  11385. default: development
  11386. description: Project is an onboardbase project that the secrets should be pulled from
  11387. type: string
  11388. required:
  11389. - apiHost
  11390. - auth
  11391. - environment
  11392. - project
  11393. type: object
  11394. onepassword:
  11395. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11396. properties:
  11397. auth:
  11398. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11399. properties:
  11400. secretRef:
  11401. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11402. properties:
  11403. connectTokenSecretRef:
  11404. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11405. properties:
  11406. key:
  11407. description: |-
  11408. A key in the referenced Secret.
  11409. Some instances of this field may be defaulted, in others it may be required.
  11410. maxLength: 253
  11411. minLength: 1
  11412. pattern: ^[-._a-zA-Z0-9]+$
  11413. type: string
  11414. name:
  11415. description: The name of the Secret resource being referred to.
  11416. maxLength: 253
  11417. minLength: 1
  11418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11419. type: string
  11420. namespace:
  11421. description: |-
  11422. The namespace of the Secret resource being referred to.
  11423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11424. maxLength: 63
  11425. minLength: 1
  11426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11427. type: string
  11428. type: object
  11429. required:
  11430. - connectTokenSecretRef
  11431. type: object
  11432. required:
  11433. - secretRef
  11434. type: object
  11435. connectHost:
  11436. description: ConnectHost defines the OnePassword Connect Server to connect to
  11437. type: string
  11438. vaults:
  11439. additionalProperties:
  11440. type: integer
  11441. description: Vaults defines which OnePassword vaults to search in which order
  11442. type: object
  11443. required:
  11444. - auth
  11445. - connectHost
  11446. - vaults
  11447. type: object
  11448. oracle:
  11449. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11450. properties:
  11451. auth:
  11452. description: |-
  11453. Auth configures how secret-manager authenticates with the Oracle Vault.
  11454. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11455. properties:
  11456. secretRef:
  11457. description: SecretRef to pass through sensitive information.
  11458. properties:
  11459. fingerprint:
  11460. description: Fingerprint is the fingerprint of the API private key.
  11461. properties:
  11462. key:
  11463. description: |-
  11464. A key in the referenced Secret.
  11465. Some instances of this field may be defaulted, in others it may be required.
  11466. maxLength: 253
  11467. minLength: 1
  11468. pattern: ^[-._a-zA-Z0-9]+$
  11469. type: string
  11470. name:
  11471. description: The name of the Secret resource being referred to.
  11472. maxLength: 253
  11473. minLength: 1
  11474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11475. type: string
  11476. namespace:
  11477. description: |-
  11478. The namespace of the Secret resource being referred to.
  11479. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11480. maxLength: 63
  11481. minLength: 1
  11482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11483. type: string
  11484. type: object
  11485. privatekey:
  11486. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11487. properties:
  11488. key:
  11489. description: |-
  11490. A key in the referenced Secret.
  11491. Some instances of this field may be defaulted, in others it may be required.
  11492. maxLength: 253
  11493. minLength: 1
  11494. pattern: ^[-._a-zA-Z0-9]+$
  11495. type: string
  11496. name:
  11497. description: The name of the Secret resource being referred to.
  11498. maxLength: 253
  11499. minLength: 1
  11500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11501. type: string
  11502. namespace:
  11503. description: |-
  11504. The namespace of the Secret resource being referred to.
  11505. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11506. maxLength: 63
  11507. minLength: 1
  11508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11509. type: string
  11510. type: object
  11511. required:
  11512. - fingerprint
  11513. - privatekey
  11514. type: object
  11515. tenancy:
  11516. description: Tenancy is the tenancy OCID where user is located.
  11517. type: string
  11518. user:
  11519. description: User is an access OCID specific to the account.
  11520. type: string
  11521. required:
  11522. - secretRef
  11523. - tenancy
  11524. - user
  11525. type: object
  11526. compartment:
  11527. description: |-
  11528. Compartment is the vault compartment OCID.
  11529. Required for PushSecret
  11530. type: string
  11531. encryptionKey:
  11532. description: |-
  11533. EncryptionKey is the OCID of the encryption key within the vault.
  11534. Required for PushSecret
  11535. type: string
  11536. principalType:
  11537. description: |-
  11538. The type of principal to use for authentication. If left blank, the Auth struct will
  11539. determine the principal type. This optional field must be specified if using
  11540. workload identity.
  11541. enum:
  11542. - ""
  11543. - UserPrincipal
  11544. - InstancePrincipal
  11545. - Workload
  11546. type: string
  11547. region:
  11548. description: Region is the region where vault is located.
  11549. type: string
  11550. serviceAccountRef:
  11551. description: |-
  11552. ServiceAccountRef specified the service account
  11553. that should be used when authenticating with WorkloadIdentity.
  11554. properties:
  11555. audiences:
  11556. description: |-
  11557. Audience specifies the `aud` claim for the service account token
  11558. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11559. then this audiences will be appended to the list
  11560. items:
  11561. type: string
  11562. type: array
  11563. name:
  11564. description: The name of the ServiceAccount resource being referred to.
  11565. maxLength: 253
  11566. minLength: 1
  11567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11568. type: string
  11569. namespace:
  11570. description: |-
  11571. Namespace of the resource being referred to.
  11572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11573. maxLength: 63
  11574. minLength: 1
  11575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11576. type: string
  11577. required:
  11578. - name
  11579. type: object
  11580. vault:
  11581. description: Vault is the vault's OCID of the specific vault where secret is located.
  11582. type: string
  11583. required:
  11584. - region
  11585. - vault
  11586. type: object
  11587. passbolt:
  11588. description: PassboltProvider defines configuration for the Passbolt provider.
  11589. properties:
  11590. auth:
  11591. description: Auth defines the information necessary to authenticate against Passbolt Server
  11592. properties:
  11593. passwordSecretRef:
  11594. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11595. properties:
  11596. key:
  11597. description: |-
  11598. A key in the referenced Secret.
  11599. Some instances of this field may be defaulted, in others it may be required.
  11600. maxLength: 253
  11601. minLength: 1
  11602. pattern: ^[-._a-zA-Z0-9]+$
  11603. type: string
  11604. name:
  11605. description: The name of the Secret resource being referred to.
  11606. maxLength: 253
  11607. minLength: 1
  11608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11609. type: string
  11610. namespace:
  11611. description: |-
  11612. The namespace of the Secret resource being referred to.
  11613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11614. maxLength: 63
  11615. minLength: 1
  11616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11617. type: string
  11618. type: object
  11619. privateKeySecretRef:
  11620. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11621. properties:
  11622. key:
  11623. description: |-
  11624. A key in the referenced Secret.
  11625. Some instances of this field may be defaulted, in others it may be required.
  11626. maxLength: 253
  11627. minLength: 1
  11628. pattern: ^[-._a-zA-Z0-9]+$
  11629. type: string
  11630. name:
  11631. description: The name of the Secret resource being referred to.
  11632. maxLength: 253
  11633. minLength: 1
  11634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11635. type: string
  11636. namespace:
  11637. description: |-
  11638. The namespace of the Secret resource being referred to.
  11639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11640. maxLength: 63
  11641. minLength: 1
  11642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11643. type: string
  11644. type: object
  11645. required:
  11646. - passwordSecretRef
  11647. - privateKeySecretRef
  11648. type: object
  11649. host:
  11650. description: Host defines the Passbolt Server to connect to
  11651. type: string
  11652. required:
  11653. - auth
  11654. - host
  11655. type: object
  11656. passworddepot:
  11657. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11658. properties:
  11659. auth:
  11660. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11661. properties:
  11662. secretRef:
  11663. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11664. properties:
  11665. credentials:
  11666. description: Username / Password is used for authentication.
  11667. properties:
  11668. key:
  11669. description: |-
  11670. A key in the referenced Secret.
  11671. Some instances of this field may be defaulted, in others it may be required.
  11672. maxLength: 253
  11673. minLength: 1
  11674. pattern: ^[-._a-zA-Z0-9]+$
  11675. type: string
  11676. name:
  11677. description: The name of the Secret resource being referred to.
  11678. maxLength: 253
  11679. minLength: 1
  11680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11681. type: string
  11682. namespace:
  11683. description: |-
  11684. The namespace of the Secret resource being referred to.
  11685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11686. maxLength: 63
  11687. minLength: 1
  11688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11689. type: string
  11690. type: object
  11691. type: object
  11692. required:
  11693. - secretRef
  11694. type: object
  11695. database:
  11696. description: Database to use as source
  11697. type: string
  11698. host:
  11699. description: URL configures the Password Depot instance URL.
  11700. type: string
  11701. required:
  11702. - auth
  11703. - database
  11704. - host
  11705. type: object
  11706. previder:
  11707. description: Previder configures this store to sync secrets using the Previder provider
  11708. properties:
  11709. auth:
  11710. description: PreviderAuth contains a secretRef for credentials.
  11711. properties:
  11712. secretRef:
  11713. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  11714. properties:
  11715. accessToken:
  11716. description: The AccessToken is used for authentication
  11717. properties:
  11718. key:
  11719. description: |-
  11720. A key in the referenced Secret.
  11721. Some instances of this field may be defaulted, in others it may be required.
  11722. maxLength: 253
  11723. minLength: 1
  11724. pattern: ^[-._a-zA-Z0-9]+$
  11725. type: string
  11726. name:
  11727. description: The name of the Secret resource being referred to.
  11728. maxLength: 253
  11729. minLength: 1
  11730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11731. type: string
  11732. namespace:
  11733. description: |-
  11734. The namespace of the Secret resource being referred to.
  11735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11736. maxLength: 63
  11737. minLength: 1
  11738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11739. type: string
  11740. type: object
  11741. required:
  11742. - accessToken
  11743. type: object
  11744. type: object
  11745. baseUri:
  11746. type: string
  11747. required:
  11748. - auth
  11749. type: object
  11750. pulumi:
  11751. description: Pulumi configures this store to sync secrets using the Pulumi provider
  11752. properties:
  11753. accessToken:
  11754. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  11755. properties:
  11756. secretRef:
  11757. description: SecretRef is a reference to a secret containing the Pulumi API token.
  11758. properties:
  11759. key:
  11760. description: |-
  11761. A key in the referenced Secret.
  11762. Some instances of this field may be defaulted, in others it may be required.
  11763. maxLength: 253
  11764. minLength: 1
  11765. pattern: ^[-._a-zA-Z0-9]+$
  11766. type: string
  11767. name:
  11768. description: The name of the Secret resource being referred to.
  11769. maxLength: 253
  11770. minLength: 1
  11771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11772. type: string
  11773. namespace:
  11774. description: |-
  11775. The namespace of the Secret resource being referred to.
  11776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11777. maxLength: 63
  11778. minLength: 1
  11779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11780. type: string
  11781. type: object
  11782. type: object
  11783. apiUrl:
  11784. default: https://api.pulumi.com/api/esc
  11785. description: APIURL is the URL of the Pulumi API.
  11786. type: string
  11787. environment:
  11788. description: |-
  11789. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  11790. dynamically retrieved values from supported providers including all major clouds,
  11791. and other Pulumi ESC environments.
  11792. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  11793. type: string
  11794. organization:
  11795. description: |-
  11796. Organization are a space to collaborate on shared projects and stacks.
  11797. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  11798. type: string
  11799. project:
  11800. description: Project is the name of the Pulumi ESC project the environment belongs to.
  11801. type: string
  11802. required:
  11803. - accessToken
  11804. - environment
  11805. - organization
  11806. - project
  11807. type: object
  11808. scaleway:
  11809. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  11810. properties:
  11811. accessKey:
  11812. description: AccessKey is the non-secret part of the api key.
  11813. properties:
  11814. secretRef:
  11815. description: SecretRef references a key in a secret that will be used as value.
  11816. properties:
  11817. key:
  11818. description: |-
  11819. A key in the referenced Secret.
  11820. Some instances of this field may be defaulted, in others it may be required.
  11821. maxLength: 253
  11822. minLength: 1
  11823. pattern: ^[-._a-zA-Z0-9]+$
  11824. type: string
  11825. name:
  11826. description: The name of the Secret resource being referred to.
  11827. maxLength: 253
  11828. minLength: 1
  11829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11830. type: string
  11831. namespace:
  11832. description: |-
  11833. The namespace of the Secret resource being referred to.
  11834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11835. maxLength: 63
  11836. minLength: 1
  11837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11838. type: string
  11839. type: object
  11840. value:
  11841. description: Value can be specified directly to set a value without using a secret.
  11842. type: string
  11843. type: object
  11844. apiUrl:
  11845. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  11846. type: string
  11847. projectId:
  11848. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  11849. type: string
  11850. region:
  11851. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  11852. type: string
  11853. secretKey:
  11854. description: SecretKey is the non-secret part of the api key.
  11855. properties:
  11856. secretRef:
  11857. description: SecretRef references a key in a secret that will be used as value.
  11858. properties:
  11859. key:
  11860. description: |-
  11861. A key in the referenced Secret.
  11862. Some instances of this field may be defaulted, in others it may be required.
  11863. maxLength: 253
  11864. minLength: 1
  11865. pattern: ^[-._a-zA-Z0-9]+$
  11866. type: string
  11867. name:
  11868. description: The name of the Secret resource being referred to.
  11869. maxLength: 253
  11870. minLength: 1
  11871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11872. type: string
  11873. namespace:
  11874. description: |-
  11875. The namespace of the Secret resource being referred to.
  11876. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11877. maxLength: 63
  11878. minLength: 1
  11879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11880. type: string
  11881. type: object
  11882. value:
  11883. description: Value can be specified directly to set a value without using a secret.
  11884. type: string
  11885. type: object
  11886. required:
  11887. - accessKey
  11888. - projectId
  11889. - region
  11890. - secretKey
  11891. type: object
  11892. secretserver:
  11893. description: |-
  11894. SecretServer configures this store to sync secrets using SecretServer provider
  11895. https://docs.delinea.com/online-help/secret-server/start.htm
  11896. properties:
  11897. password:
  11898. description: Password is the secret server account password.
  11899. properties:
  11900. secretRef:
  11901. description: SecretRef references a key in a secret that will be used as value.
  11902. properties:
  11903. key:
  11904. description: |-
  11905. A key in the referenced Secret.
  11906. Some instances of this field may be defaulted, in others it may be required.
  11907. maxLength: 253
  11908. minLength: 1
  11909. pattern: ^[-._a-zA-Z0-9]+$
  11910. type: string
  11911. name:
  11912. description: The name of the Secret resource being referred to.
  11913. maxLength: 253
  11914. minLength: 1
  11915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11916. type: string
  11917. namespace:
  11918. description: |-
  11919. The namespace of the Secret resource being referred to.
  11920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11921. maxLength: 63
  11922. minLength: 1
  11923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11924. type: string
  11925. type: object
  11926. value:
  11927. description: Value can be specified directly to set a value without using a secret.
  11928. type: string
  11929. type: object
  11930. serverURL:
  11931. description: |-
  11932. ServerURL
  11933. URL to your secret server installation
  11934. type: string
  11935. username:
  11936. description: Username is the secret server account username.
  11937. properties:
  11938. secretRef:
  11939. description: SecretRef references a key in a secret that will be used as value.
  11940. properties:
  11941. key:
  11942. description: |-
  11943. A key in the referenced Secret.
  11944. Some instances of this field may be defaulted, in others it may be required.
  11945. maxLength: 253
  11946. minLength: 1
  11947. pattern: ^[-._a-zA-Z0-9]+$
  11948. type: string
  11949. name:
  11950. description: The name of the Secret resource being referred to.
  11951. maxLength: 253
  11952. minLength: 1
  11953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11954. type: string
  11955. namespace:
  11956. description: |-
  11957. The namespace of the Secret resource being referred to.
  11958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11959. maxLength: 63
  11960. minLength: 1
  11961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11962. type: string
  11963. type: object
  11964. value:
  11965. description: Value can be specified directly to set a value without using a secret.
  11966. type: string
  11967. type: object
  11968. required:
  11969. - password
  11970. - serverURL
  11971. - username
  11972. type: object
  11973. senhasegura:
  11974. description: Senhasegura configures this store to sync secrets using senhasegura provider
  11975. properties:
  11976. auth:
  11977. description: Auth defines parameters to authenticate in senhasegura
  11978. properties:
  11979. clientId:
  11980. type: string
  11981. clientSecretSecretRef:
  11982. description: |-
  11983. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11984. In some instances, `key` is a required field.
  11985. properties:
  11986. key:
  11987. description: |-
  11988. A key in the referenced Secret.
  11989. Some instances of this field may be defaulted, in others it may be required.
  11990. maxLength: 253
  11991. minLength: 1
  11992. pattern: ^[-._a-zA-Z0-9]+$
  11993. type: string
  11994. name:
  11995. description: The name of the Secret resource being referred to.
  11996. maxLength: 253
  11997. minLength: 1
  11998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11999. type: string
  12000. namespace:
  12001. description: |-
  12002. The namespace of the Secret resource being referred to.
  12003. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12004. maxLength: 63
  12005. minLength: 1
  12006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12007. type: string
  12008. type: object
  12009. required:
  12010. - clientId
  12011. - clientSecretSecretRef
  12012. type: object
  12013. ignoreSslCertificate:
  12014. default: false
  12015. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12016. type: boolean
  12017. module:
  12018. description: Module defines which senhasegura module should be used to get secrets
  12019. type: string
  12020. url:
  12021. description: URL of senhasegura
  12022. type: string
  12023. required:
  12024. - auth
  12025. - module
  12026. - url
  12027. type: object
  12028. vault:
  12029. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12030. properties:
  12031. auth:
  12032. description: Auth configures how secret-manager authenticates with the Vault server.
  12033. properties:
  12034. appRole:
  12035. description: |-
  12036. AppRole authenticates with Vault using the App Role auth mechanism,
  12037. with the role and secret stored in a Kubernetes Secret resource.
  12038. properties:
  12039. path:
  12040. default: approle
  12041. description: |-
  12042. Path where the App Role authentication backend is mounted
  12043. in Vault, e.g: "approle"
  12044. type: string
  12045. roleId:
  12046. description: |-
  12047. RoleID configured in the App Role authentication backend when setting
  12048. up the authentication backend in Vault.
  12049. type: string
  12050. roleRef:
  12051. description: |-
  12052. Reference to a key in a Secret that contains the App Role ID used
  12053. to authenticate with Vault.
  12054. The `key` field must be specified and denotes which entry within the Secret
  12055. resource is used as the app role id.
  12056. properties:
  12057. key:
  12058. description: |-
  12059. A key in the referenced Secret.
  12060. Some instances of this field may be defaulted, in others it may be required.
  12061. maxLength: 253
  12062. minLength: 1
  12063. pattern: ^[-._a-zA-Z0-9]+$
  12064. type: string
  12065. name:
  12066. description: The name of the Secret resource being referred to.
  12067. maxLength: 253
  12068. minLength: 1
  12069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12070. type: string
  12071. namespace:
  12072. description: |-
  12073. The namespace of the Secret resource being referred to.
  12074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12075. maxLength: 63
  12076. minLength: 1
  12077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12078. type: string
  12079. type: object
  12080. secretRef:
  12081. description: |-
  12082. Reference to a key in a Secret that contains the App Role secret used
  12083. to authenticate with Vault.
  12084. The `key` field must be specified and denotes which entry within the Secret
  12085. resource is used as the app role secret.
  12086. properties:
  12087. key:
  12088. description: |-
  12089. A key in the referenced Secret.
  12090. Some instances of this field may be defaulted, in others it may be required.
  12091. maxLength: 253
  12092. minLength: 1
  12093. pattern: ^[-._a-zA-Z0-9]+$
  12094. type: string
  12095. name:
  12096. description: The name of the Secret resource being referred to.
  12097. maxLength: 253
  12098. minLength: 1
  12099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12100. type: string
  12101. namespace:
  12102. description: |-
  12103. The namespace of the Secret resource being referred to.
  12104. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12105. maxLength: 63
  12106. minLength: 1
  12107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12108. type: string
  12109. type: object
  12110. required:
  12111. - path
  12112. - secretRef
  12113. type: object
  12114. cert:
  12115. description: |-
  12116. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12117. Cert authentication method
  12118. properties:
  12119. clientCert:
  12120. description: |-
  12121. ClientCert is a certificate to authenticate using the Cert Vault
  12122. authentication method
  12123. properties:
  12124. key:
  12125. description: |-
  12126. A key in the referenced Secret.
  12127. Some instances of this field may be defaulted, in others it may be required.
  12128. maxLength: 253
  12129. minLength: 1
  12130. pattern: ^[-._a-zA-Z0-9]+$
  12131. type: string
  12132. name:
  12133. description: The name of the Secret resource being referred to.
  12134. maxLength: 253
  12135. minLength: 1
  12136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12137. type: string
  12138. namespace:
  12139. description: |-
  12140. The namespace of the Secret resource being referred to.
  12141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12142. maxLength: 63
  12143. minLength: 1
  12144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12145. type: string
  12146. type: object
  12147. secretRef:
  12148. description: |-
  12149. SecretRef to a key in a Secret resource containing client private key to
  12150. authenticate with Vault using the Cert authentication method
  12151. properties:
  12152. key:
  12153. description: |-
  12154. A key in the referenced Secret.
  12155. Some instances of this field may be defaulted, in others it may be required.
  12156. maxLength: 253
  12157. minLength: 1
  12158. pattern: ^[-._a-zA-Z0-9]+$
  12159. type: string
  12160. name:
  12161. description: The name of the Secret resource being referred to.
  12162. maxLength: 253
  12163. minLength: 1
  12164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12165. type: string
  12166. namespace:
  12167. description: |-
  12168. The namespace of the Secret resource being referred to.
  12169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12170. maxLength: 63
  12171. minLength: 1
  12172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12173. type: string
  12174. type: object
  12175. type: object
  12176. iam:
  12177. description: |-
  12178. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12179. AWS IAM authentication method
  12180. properties:
  12181. externalID:
  12182. description: AWS External ID set on assumed IAM roles
  12183. type: string
  12184. jwt:
  12185. description: Specify a service account with IRSA enabled
  12186. properties:
  12187. serviceAccountRef:
  12188. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12189. properties:
  12190. audiences:
  12191. description: |-
  12192. Audience specifies the `aud` claim for the service account token
  12193. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12194. then this audiences will be appended to the list
  12195. items:
  12196. type: string
  12197. type: array
  12198. name:
  12199. description: The name of the ServiceAccount resource being referred to.
  12200. maxLength: 253
  12201. minLength: 1
  12202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12203. type: string
  12204. namespace:
  12205. description: |-
  12206. Namespace of the resource being referred to.
  12207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12208. maxLength: 63
  12209. minLength: 1
  12210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12211. type: string
  12212. required:
  12213. - name
  12214. type: object
  12215. type: object
  12216. path:
  12217. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12218. type: string
  12219. region:
  12220. description: AWS region
  12221. type: string
  12222. role:
  12223. description: This is the AWS role to be assumed before talking to vault
  12224. type: string
  12225. secretRef:
  12226. description: Specify credentials in a Secret object
  12227. properties:
  12228. accessKeyIDSecretRef:
  12229. description: The AccessKeyID is used for authentication
  12230. properties:
  12231. key:
  12232. description: |-
  12233. A key in the referenced Secret.
  12234. Some instances of this field may be defaulted, in others it may be required.
  12235. maxLength: 253
  12236. minLength: 1
  12237. pattern: ^[-._a-zA-Z0-9]+$
  12238. type: string
  12239. name:
  12240. description: The name of the Secret resource being referred to.
  12241. maxLength: 253
  12242. minLength: 1
  12243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12244. type: string
  12245. namespace:
  12246. description: |-
  12247. The namespace of the Secret resource being referred to.
  12248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12249. maxLength: 63
  12250. minLength: 1
  12251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12252. type: string
  12253. type: object
  12254. secretAccessKeySecretRef:
  12255. description: The SecretAccessKey is used for authentication
  12256. properties:
  12257. key:
  12258. description: |-
  12259. A key in the referenced Secret.
  12260. Some instances of this field may be defaulted, in others it may be required.
  12261. maxLength: 253
  12262. minLength: 1
  12263. pattern: ^[-._a-zA-Z0-9]+$
  12264. type: string
  12265. name:
  12266. description: The name of the Secret resource being referred to.
  12267. maxLength: 253
  12268. minLength: 1
  12269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12270. type: string
  12271. namespace:
  12272. description: |-
  12273. The namespace of the Secret resource being referred to.
  12274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12275. maxLength: 63
  12276. minLength: 1
  12277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12278. type: string
  12279. type: object
  12280. sessionTokenSecretRef:
  12281. description: |-
  12282. The SessionToken used for authentication
  12283. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12284. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12285. properties:
  12286. key:
  12287. description: |-
  12288. A key in the referenced Secret.
  12289. Some instances of this field may be defaulted, in others it may be required.
  12290. maxLength: 253
  12291. minLength: 1
  12292. pattern: ^[-._a-zA-Z0-9]+$
  12293. type: string
  12294. name:
  12295. description: The name of the Secret resource being referred to.
  12296. maxLength: 253
  12297. minLength: 1
  12298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12299. type: string
  12300. namespace:
  12301. description: |-
  12302. The namespace of the Secret resource being referred to.
  12303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12304. maxLength: 63
  12305. minLength: 1
  12306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12307. type: string
  12308. type: object
  12309. type: object
  12310. vaultAwsIamServerID:
  12311. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12312. type: string
  12313. vaultRole:
  12314. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12315. type: string
  12316. required:
  12317. - vaultRole
  12318. type: object
  12319. jwt:
  12320. description: |-
  12321. Jwt authenticates with Vault by passing role and JWT token using the
  12322. JWT/OIDC authentication method
  12323. properties:
  12324. kubernetesServiceAccountToken:
  12325. description: |-
  12326. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12327. a token for with the `TokenRequest` API.
  12328. properties:
  12329. audiences:
  12330. description: |-
  12331. Optional audiences field that will be used to request a temporary Kubernetes service
  12332. account token for the service account referenced by `serviceAccountRef`.
  12333. Defaults to a single audience `vault` it not specified.
  12334. Deprecated: use serviceAccountRef.Audiences instead
  12335. items:
  12336. type: string
  12337. type: array
  12338. expirationSeconds:
  12339. description: |-
  12340. Optional expiration time in seconds that will be used to request a temporary
  12341. Kubernetes service account token for the service account referenced by
  12342. `serviceAccountRef`.
  12343. Deprecated: this will be removed in the future.
  12344. Defaults to 10 minutes.
  12345. format: int64
  12346. type: integer
  12347. serviceAccountRef:
  12348. description: Service account field containing the name of a kubernetes ServiceAccount.
  12349. properties:
  12350. audiences:
  12351. description: |-
  12352. Audience specifies the `aud` claim for the service account token
  12353. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12354. then this audiences will be appended to the list
  12355. items:
  12356. type: string
  12357. type: array
  12358. name:
  12359. description: The name of the ServiceAccount resource being referred to.
  12360. maxLength: 253
  12361. minLength: 1
  12362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12363. type: string
  12364. namespace:
  12365. description: |-
  12366. Namespace of the resource being referred to.
  12367. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12368. maxLength: 63
  12369. minLength: 1
  12370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12371. type: string
  12372. required:
  12373. - name
  12374. type: object
  12375. required:
  12376. - serviceAccountRef
  12377. type: object
  12378. path:
  12379. default: jwt
  12380. description: |-
  12381. Path where the JWT authentication backend is mounted
  12382. in Vault, e.g: "jwt"
  12383. type: string
  12384. role:
  12385. description: |-
  12386. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12387. authentication method
  12388. type: string
  12389. secretRef:
  12390. description: |-
  12391. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12392. authenticate with Vault using the JWT/OIDC authentication method.
  12393. properties:
  12394. key:
  12395. description: |-
  12396. A key in the referenced Secret.
  12397. Some instances of this field may be defaulted, in others it may be required.
  12398. maxLength: 253
  12399. minLength: 1
  12400. pattern: ^[-._a-zA-Z0-9]+$
  12401. type: string
  12402. name:
  12403. description: The name of the Secret resource being referred to.
  12404. maxLength: 253
  12405. minLength: 1
  12406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12407. type: string
  12408. namespace:
  12409. description: |-
  12410. The namespace of the Secret resource being referred to.
  12411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12412. maxLength: 63
  12413. minLength: 1
  12414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12415. type: string
  12416. type: object
  12417. required:
  12418. - path
  12419. type: object
  12420. kubernetes:
  12421. description: |-
  12422. Kubernetes authenticates with Vault by passing the ServiceAccount
  12423. token stored in the named Secret resource to the Vault server.
  12424. properties:
  12425. mountPath:
  12426. default: kubernetes
  12427. description: |-
  12428. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12429. "kubernetes"
  12430. type: string
  12431. role:
  12432. description: |-
  12433. A required field containing the Vault Role to assume. A Role binds a
  12434. Kubernetes ServiceAccount with a set of Vault policies.
  12435. type: string
  12436. secretRef:
  12437. description: |-
  12438. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12439. for authenticating with Vault. If a name is specified without a key,
  12440. `token` is the default. If one is not specified, the one bound to
  12441. the controller will be used.
  12442. properties:
  12443. key:
  12444. description: |-
  12445. A key in the referenced Secret.
  12446. Some instances of this field may be defaulted, in others it may be required.
  12447. maxLength: 253
  12448. minLength: 1
  12449. pattern: ^[-._a-zA-Z0-9]+$
  12450. type: string
  12451. name:
  12452. description: The name of the Secret resource being referred to.
  12453. maxLength: 253
  12454. minLength: 1
  12455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12456. type: string
  12457. namespace:
  12458. description: |-
  12459. The namespace of the Secret resource being referred to.
  12460. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12461. maxLength: 63
  12462. minLength: 1
  12463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12464. type: string
  12465. type: object
  12466. serviceAccountRef:
  12467. description: |-
  12468. Optional service account field containing the name of a kubernetes ServiceAccount.
  12469. If the service account is specified, the service account secret token JWT will be used
  12470. for authenticating with Vault. If the service account selector is not supplied,
  12471. the secretRef will be used instead.
  12472. properties:
  12473. audiences:
  12474. description: |-
  12475. Audience specifies the `aud` claim for the service account token
  12476. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12477. then this audiences will be appended to the list
  12478. items:
  12479. type: string
  12480. type: array
  12481. name:
  12482. description: The name of the ServiceAccount resource being referred to.
  12483. maxLength: 253
  12484. minLength: 1
  12485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12486. type: string
  12487. namespace:
  12488. description: |-
  12489. Namespace of the resource being referred to.
  12490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12491. maxLength: 63
  12492. minLength: 1
  12493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12494. type: string
  12495. required:
  12496. - name
  12497. type: object
  12498. required:
  12499. - mountPath
  12500. - role
  12501. type: object
  12502. ldap:
  12503. description: |-
  12504. Ldap authenticates with Vault by passing username/password pair using
  12505. the LDAP authentication method
  12506. properties:
  12507. path:
  12508. default: ldap
  12509. description: |-
  12510. Path where the LDAP authentication backend is mounted
  12511. in Vault, e.g: "ldap"
  12512. type: string
  12513. secretRef:
  12514. description: |-
  12515. SecretRef to a key in a Secret resource containing password for the LDAP
  12516. user used to authenticate with Vault using the LDAP authentication
  12517. method
  12518. properties:
  12519. key:
  12520. description: |-
  12521. A key in the referenced Secret.
  12522. Some instances of this field may be defaulted, in others it may be required.
  12523. maxLength: 253
  12524. minLength: 1
  12525. pattern: ^[-._a-zA-Z0-9]+$
  12526. type: string
  12527. name:
  12528. description: The name of the Secret resource being referred to.
  12529. maxLength: 253
  12530. minLength: 1
  12531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12532. type: string
  12533. namespace:
  12534. description: |-
  12535. The namespace of the Secret resource being referred to.
  12536. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12537. maxLength: 63
  12538. minLength: 1
  12539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12540. type: string
  12541. type: object
  12542. username:
  12543. description: |-
  12544. Username is an LDAP username used to authenticate using the LDAP Vault
  12545. authentication method
  12546. type: string
  12547. required:
  12548. - path
  12549. - username
  12550. type: object
  12551. namespace:
  12552. description: |-
  12553. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12554. Namespaces is a set of features within Vault Enterprise that allows
  12555. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12556. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12557. This will default to Vault.Namespace field if set, or empty otherwise
  12558. type: string
  12559. tokenSecretRef:
  12560. description: TokenSecretRef authenticates with Vault by presenting a token.
  12561. properties:
  12562. key:
  12563. description: |-
  12564. A key in the referenced Secret.
  12565. Some instances of this field may be defaulted, in others it may be required.
  12566. maxLength: 253
  12567. minLength: 1
  12568. pattern: ^[-._a-zA-Z0-9]+$
  12569. type: string
  12570. name:
  12571. description: The name of the Secret resource being referred to.
  12572. maxLength: 253
  12573. minLength: 1
  12574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12575. type: string
  12576. namespace:
  12577. description: |-
  12578. The namespace of the Secret resource being referred to.
  12579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12580. maxLength: 63
  12581. minLength: 1
  12582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12583. type: string
  12584. type: object
  12585. userPass:
  12586. description: UserPass authenticates with Vault by passing username/password pair
  12587. properties:
  12588. path:
  12589. default: userpass
  12590. description: |-
  12591. Path where the UserPassword authentication backend is mounted
  12592. in Vault, e.g: "userpass"
  12593. type: string
  12594. secretRef:
  12595. description: |-
  12596. SecretRef to a key in a Secret resource containing password for the
  12597. user used to authenticate with Vault using the UserPass authentication
  12598. method
  12599. properties:
  12600. key:
  12601. description: |-
  12602. A key in the referenced Secret.
  12603. Some instances of this field may be defaulted, in others it may be required.
  12604. maxLength: 253
  12605. minLength: 1
  12606. pattern: ^[-._a-zA-Z0-9]+$
  12607. type: string
  12608. name:
  12609. description: The name of the Secret resource being referred to.
  12610. maxLength: 253
  12611. minLength: 1
  12612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12613. type: string
  12614. namespace:
  12615. description: |-
  12616. The namespace of the Secret resource being referred to.
  12617. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12618. maxLength: 63
  12619. minLength: 1
  12620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12621. type: string
  12622. type: object
  12623. username:
  12624. description: |-
  12625. Username is a username used to authenticate using the UserPass Vault
  12626. authentication method
  12627. type: string
  12628. required:
  12629. - path
  12630. - username
  12631. type: object
  12632. type: object
  12633. caBundle:
  12634. description: |-
  12635. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12636. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12637. plain HTTP protocol connection. If not set the system root certificates
  12638. are used to validate the TLS connection.
  12639. format: byte
  12640. type: string
  12641. caProvider:
  12642. description: The provider for the CA bundle to use to validate Vault server certificate.
  12643. properties:
  12644. key:
  12645. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12646. maxLength: 253
  12647. minLength: 1
  12648. pattern: ^[-._a-zA-Z0-9]+$
  12649. type: string
  12650. name:
  12651. description: The name of the object located at the provider type.
  12652. maxLength: 253
  12653. minLength: 1
  12654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12655. type: string
  12656. namespace:
  12657. description: |-
  12658. The namespace the Provider type is in.
  12659. Can only be defined when used in a ClusterSecretStore.
  12660. maxLength: 63
  12661. minLength: 1
  12662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12663. type: string
  12664. type:
  12665. description: The type of provider to use such as "Secret", or "ConfigMap".
  12666. enum:
  12667. - Secret
  12668. - ConfigMap
  12669. type: string
  12670. required:
  12671. - name
  12672. - type
  12673. type: object
  12674. forwardInconsistent:
  12675. description: |-
  12676. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12677. leader instead of simply retrying within a loop. This can increase performance if
  12678. the option is enabled serverside.
  12679. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12680. type: boolean
  12681. headers:
  12682. additionalProperties:
  12683. type: string
  12684. description: Headers to be added in Vault request
  12685. type: object
  12686. namespace:
  12687. description: |-
  12688. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12689. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12690. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12691. type: string
  12692. path:
  12693. description: |-
  12694. Path is the mount path of the Vault KV backend endpoint, e.g:
  12695. "secret". The v2 KV secret engine version specific "/data" path suffix
  12696. for fetching secrets from Vault is optional and will be appended
  12697. if not present in specified path.
  12698. type: string
  12699. readYourWrites:
  12700. description: |-
  12701. ReadYourWrites ensures isolated read-after-write semantics by
  12702. providing discovered cluster replication states in each request.
  12703. More information about eventual consistency in Vault can be found here
  12704. https://www.vaultproject.io/docs/enterprise/consistency
  12705. type: boolean
  12706. server:
  12707. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  12708. type: string
  12709. tls:
  12710. description: |-
  12711. The configuration used for client side related TLS communication, when the Vault server
  12712. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  12713. This parameter is ignored for plain HTTP protocol connection.
  12714. It's worth noting this configuration is different from the "TLS certificates auth method",
  12715. which is available under the `auth.cert` section.
  12716. properties:
  12717. certSecretRef:
  12718. description: |-
  12719. CertSecretRef is a certificate added to the transport layer
  12720. when communicating with the Vault server.
  12721. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  12722. properties:
  12723. key:
  12724. description: |-
  12725. A key in the referenced Secret.
  12726. Some instances of this field may be defaulted, in others it may be required.
  12727. maxLength: 253
  12728. minLength: 1
  12729. pattern: ^[-._a-zA-Z0-9]+$
  12730. type: string
  12731. name:
  12732. description: The name of the Secret resource being referred to.
  12733. maxLength: 253
  12734. minLength: 1
  12735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12736. type: string
  12737. namespace:
  12738. description: |-
  12739. The namespace of the Secret resource being referred to.
  12740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12741. maxLength: 63
  12742. minLength: 1
  12743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12744. type: string
  12745. type: object
  12746. keySecretRef:
  12747. description: |-
  12748. KeySecretRef to a key in a Secret resource containing client private key
  12749. added to the transport layer when communicating with the Vault server.
  12750. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  12751. properties:
  12752. key:
  12753. description: |-
  12754. A key in the referenced Secret.
  12755. Some instances of this field may be defaulted, in others it may be required.
  12756. maxLength: 253
  12757. minLength: 1
  12758. pattern: ^[-._a-zA-Z0-9]+$
  12759. type: string
  12760. name:
  12761. description: The name of the Secret resource being referred to.
  12762. maxLength: 253
  12763. minLength: 1
  12764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12765. type: string
  12766. namespace:
  12767. description: |-
  12768. The namespace of the Secret resource being referred to.
  12769. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12770. maxLength: 63
  12771. minLength: 1
  12772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12773. type: string
  12774. type: object
  12775. type: object
  12776. version:
  12777. default: v2
  12778. description: |-
  12779. Version is the Vault KV secret engine version. This can be either "v1" or
  12780. "v2". Version defaults to "v2".
  12781. enum:
  12782. - v1
  12783. - v2
  12784. type: string
  12785. required:
  12786. - server
  12787. type: object
  12788. webhook:
  12789. description: Webhook configures this store to sync secrets using a generic templated webhook
  12790. properties:
  12791. auth:
  12792. description: Auth specifies a authorization protocol. Only one protocol may be set.
  12793. maxProperties: 1
  12794. minProperties: 1
  12795. properties:
  12796. ntlm:
  12797. description: NTLMProtocol configures the store to use NTLM for auth
  12798. properties:
  12799. passwordSecret:
  12800. description: |-
  12801. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12802. In some instances, `key` is a required field.
  12803. properties:
  12804. key:
  12805. description: |-
  12806. A key in the referenced Secret.
  12807. Some instances of this field may be defaulted, in others it may be required.
  12808. maxLength: 253
  12809. minLength: 1
  12810. pattern: ^[-._a-zA-Z0-9]+$
  12811. type: string
  12812. name:
  12813. description: The name of the Secret resource being referred to.
  12814. maxLength: 253
  12815. minLength: 1
  12816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12817. type: string
  12818. namespace:
  12819. description: |-
  12820. The namespace of the Secret resource being referred to.
  12821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12822. maxLength: 63
  12823. minLength: 1
  12824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12825. type: string
  12826. type: object
  12827. usernameSecret:
  12828. description: |-
  12829. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12830. In some instances, `key` is a required field.
  12831. properties:
  12832. key:
  12833. description: |-
  12834. A key in the referenced Secret.
  12835. Some instances of this field may be defaulted, in others it may be required.
  12836. maxLength: 253
  12837. minLength: 1
  12838. pattern: ^[-._a-zA-Z0-9]+$
  12839. type: string
  12840. name:
  12841. description: The name of the Secret resource being referred to.
  12842. maxLength: 253
  12843. minLength: 1
  12844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12845. type: string
  12846. namespace:
  12847. description: |-
  12848. The namespace of the Secret resource being referred to.
  12849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12850. maxLength: 63
  12851. minLength: 1
  12852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12853. type: string
  12854. type: object
  12855. required:
  12856. - passwordSecret
  12857. - usernameSecret
  12858. type: object
  12859. type: object
  12860. body:
  12861. description: Body
  12862. type: string
  12863. caBundle:
  12864. description: |-
  12865. PEM encoded CA bundle used to validate webhook server certificate. Only used
  12866. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12867. plain HTTP protocol connection. If not set the system root certificates
  12868. are used to validate the TLS connection.
  12869. format: byte
  12870. type: string
  12871. caProvider:
  12872. description: The provider for the CA bundle to use to validate webhook server certificate.
  12873. properties:
  12874. key:
  12875. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12876. maxLength: 253
  12877. minLength: 1
  12878. pattern: ^[-._a-zA-Z0-9]+$
  12879. type: string
  12880. name:
  12881. description: The name of the object located at the provider type.
  12882. maxLength: 253
  12883. minLength: 1
  12884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12885. type: string
  12886. namespace:
  12887. description: The namespace the Provider type is in.
  12888. maxLength: 63
  12889. minLength: 1
  12890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12891. type: string
  12892. type:
  12893. description: The type of provider to use such as "Secret", or "ConfigMap".
  12894. enum:
  12895. - Secret
  12896. - ConfigMap
  12897. type: string
  12898. required:
  12899. - name
  12900. - type
  12901. type: object
  12902. headers:
  12903. additionalProperties:
  12904. type: string
  12905. description: Headers
  12906. type: object
  12907. method:
  12908. description: Webhook Method
  12909. type: string
  12910. result:
  12911. description: Result formatting
  12912. properties:
  12913. jsonPath:
  12914. description: Json path of return value
  12915. type: string
  12916. type: object
  12917. secrets:
  12918. description: |-
  12919. Secrets to fill in templates
  12920. These secrets will be passed to the templating function as key value pairs under the given name
  12921. items:
  12922. description: WebhookSecret defines a secret to be used in webhook templates.
  12923. properties:
  12924. name:
  12925. description: Name of this secret in templates
  12926. type: string
  12927. secretRef:
  12928. description: Secret ref to fill in credentials
  12929. properties:
  12930. key:
  12931. description: |-
  12932. A key in the referenced Secret.
  12933. Some instances of this field may be defaulted, in others it may be required.
  12934. maxLength: 253
  12935. minLength: 1
  12936. pattern: ^[-._a-zA-Z0-9]+$
  12937. type: string
  12938. name:
  12939. description: The name of the Secret resource being referred to.
  12940. maxLength: 253
  12941. minLength: 1
  12942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12943. type: string
  12944. namespace:
  12945. description: |-
  12946. The namespace of the Secret resource being referred to.
  12947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12948. maxLength: 63
  12949. minLength: 1
  12950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12951. type: string
  12952. type: object
  12953. required:
  12954. - name
  12955. - secretRef
  12956. type: object
  12957. type: array
  12958. timeout:
  12959. description: Timeout
  12960. type: string
  12961. url:
  12962. description: Webhook url to call
  12963. type: string
  12964. required:
  12965. - result
  12966. - url
  12967. type: object
  12968. yandexcertificatemanager:
  12969. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  12970. properties:
  12971. apiEndpoint:
  12972. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  12973. type: string
  12974. auth:
  12975. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  12976. properties:
  12977. authorizedKeySecretRef:
  12978. description: The authorized key used for authentication
  12979. properties:
  12980. key:
  12981. description: |-
  12982. A key in the referenced Secret.
  12983. Some instances of this field may be defaulted, in others it may be required.
  12984. maxLength: 253
  12985. minLength: 1
  12986. pattern: ^[-._a-zA-Z0-9]+$
  12987. type: string
  12988. name:
  12989. description: The name of the Secret resource being referred to.
  12990. maxLength: 253
  12991. minLength: 1
  12992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12993. type: string
  12994. namespace:
  12995. description: |-
  12996. The namespace of the Secret resource being referred to.
  12997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12998. maxLength: 63
  12999. minLength: 1
  13000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13001. type: string
  13002. type: object
  13003. type: object
  13004. caProvider:
  13005. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13006. properties:
  13007. certSecretRef:
  13008. description: |-
  13009. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13010. In some instances, `key` is a required field.
  13011. properties:
  13012. key:
  13013. description: |-
  13014. A key in the referenced Secret.
  13015. Some instances of this field may be defaulted, in others it may be required.
  13016. maxLength: 253
  13017. minLength: 1
  13018. pattern: ^[-._a-zA-Z0-9]+$
  13019. type: string
  13020. name:
  13021. description: The name of the Secret resource being referred to.
  13022. maxLength: 253
  13023. minLength: 1
  13024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13025. type: string
  13026. namespace:
  13027. description: |-
  13028. The namespace of the Secret resource being referred to.
  13029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13030. maxLength: 63
  13031. minLength: 1
  13032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13033. type: string
  13034. type: object
  13035. type: object
  13036. required:
  13037. - auth
  13038. type: object
  13039. yandexlockbox:
  13040. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13041. properties:
  13042. apiEndpoint:
  13043. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13044. type: string
  13045. auth:
  13046. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13047. properties:
  13048. authorizedKeySecretRef:
  13049. description: The authorized key used for authentication
  13050. properties:
  13051. key:
  13052. description: |-
  13053. A key in the referenced Secret.
  13054. Some instances of this field may be defaulted, in others it may be required.
  13055. maxLength: 253
  13056. minLength: 1
  13057. pattern: ^[-._a-zA-Z0-9]+$
  13058. type: string
  13059. name:
  13060. description: The name of the Secret resource being referred to.
  13061. maxLength: 253
  13062. minLength: 1
  13063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13064. type: string
  13065. namespace:
  13066. description: |-
  13067. The namespace of the Secret resource being referred to.
  13068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13069. maxLength: 63
  13070. minLength: 1
  13071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13072. type: string
  13073. type: object
  13074. type: object
  13075. caProvider:
  13076. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13077. properties:
  13078. certSecretRef:
  13079. description: |-
  13080. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13081. In some instances, `key` is a required field.
  13082. properties:
  13083. key:
  13084. description: |-
  13085. A key in the referenced Secret.
  13086. Some instances of this field may be defaulted, in others it may be required.
  13087. maxLength: 253
  13088. minLength: 1
  13089. pattern: ^[-._a-zA-Z0-9]+$
  13090. type: string
  13091. name:
  13092. description: The name of the Secret resource being referred to.
  13093. maxLength: 253
  13094. minLength: 1
  13095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13096. type: string
  13097. namespace:
  13098. description: |-
  13099. The namespace of the Secret resource being referred to.
  13100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13101. maxLength: 63
  13102. minLength: 1
  13103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13104. type: string
  13105. type: object
  13106. type: object
  13107. required:
  13108. - auth
  13109. type: object
  13110. type: object
  13111. refreshInterval:
  13112. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13113. type: integer
  13114. retrySettings:
  13115. description: Used to configure HTTP retries on failures.
  13116. properties:
  13117. maxRetries:
  13118. description: MaxRetries is the maximum number of retry attempts.
  13119. format: int32
  13120. type: integer
  13121. retryInterval:
  13122. description: RetryInterval is the interval between retry attempts.
  13123. type: string
  13124. type: object
  13125. required:
  13126. - provider
  13127. type: object
  13128. status:
  13129. description: SecretStoreStatus defines the observed state of the SecretStore.
  13130. properties:
  13131. capabilities:
  13132. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13133. type: string
  13134. conditions:
  13135. items:
  13136. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13137. properties:
  13138. lastTransitionTime:
  13139. format: date-time
  13140. type: string
  13141. message:
  13142. type: string
  13143. reason:
  13144. type: string
  13145. status:
  13146. type: string
  13147. type:
  13148. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13149. type: string
  13150. required:
  13151. - status
  13152. - type
  13153. type: object
  13154. type: array
  13155. type: object
  13156. type: object
  13157. served: false
  13158. storage: false
  13159. subresources:
  13160. status: {}
  13161. ---
  13162. apiVersion: apiextensions.k8s.io/v1
  13163. kind: CustomResourceDefinition
  13164. metadata:
  13165. annotations:
  13166. controller-gen.kubebuilder.io/version: v0.19.0
  13167. labels:
  13168. external-secrets.io/component: controller
  13169. name: externalsecrets.external-secrets.io
  13170. spec:
  13171. group: external-secrets.io
  13172. names:
  13173. categories:
  13174. - external-secrets
  13175. kind: ExternalSecret
  13176. listKind: ExternalSecretList
  13177. plural: externalsecrets
  13178. shortNames:
  13179. - es
  13180. singular: externalsecret
  13181. scope: Namespaced
  13182. versions:
  13183. - additionalPrinterColumns:
  13184. - jsonPath: .spec.secretStoreRef.kind
  13185. name: StoreType
  13186. type: string
  13187. - jsonPath: .spec.secretStoreRef.name
  13188. name: Store
  13189. type: string
  13190. - jsonPath: .spec.refreshInterval
  13191. name: Refresh Interval
  13192. type: string
  13193. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13194. name: Status
  13195. type: string
  13196. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13197. name: Ready
  13198. type: string
  13199. - jsonPath: .status.refreshTime
  13200. name: Last Sync
  13201. type: date
  13202. name: v1
  13203. schema:
  13204. openAPIV3Schema:
  13205. description: |-
  13206. ExternalSecret is the Schema for the external-secrets API.
  13207. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13208. properties:
  13209. apiVersion:
  13210. description: |-
  13211. APIVersion defines the versioned schema of this representation of an object.
  13212. Servers should convert recognized schemas to the latest internal value, and
  13213. may reject unrecognized values.
  13214. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13215. type: string
  13216. kind:
  13217. description: |-
  13218. Kind is a string value representing the REST resource this object represents.
  13219. Servers may infer this from the endpoint the client submits requests to.
  13220. Cannot be updated.
  13221. In CamelCase.
  13222. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13223. type: string
  13224. metadata:
  13225. type: object
  13226. spec:
  13227. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13228. properties:
  13229. data:
  13230. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13231. items:
  13232. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13233. properties:
  13234. remoteRef:
  13235. description: |-
  13236. RemoteRef points to the remote secret and defines
  13237. which secret (version/property/..) to fetch.
  13238. properties:
  13239. conversionStrategy:
  13240. default: Default
  13241. description: Used to define a conversion Strategy
  13242. enum:
  13243. - Default
  13244. - Unicode
  13245. type: string
  13246. decodingStrategy:
  13247. default: None
  13248. description: Used to define a decoding Strategy
  13249. enum:
  13250. - Auto
  13251. - Base64
  13252. - Base64URL
  13253. - None
  13254. type: string
  13255. key:
  13256. description: Key is the key used in the Provider, mandatory
  13257. type: string
  13258. metadataPolicy:
  13259. default: None
  13260. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13261. enum:
  13262. - None
  13263. - Fetch
  13264. type: string
  13265. nullBytePolicy:
  13266. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13267. enum:
  13268. - Ignore
  13269. - Fail
  13270. type: string
  13271. property:
  13272. description: Used to select a specific property of the Provider value (if a map), if supported
  13273. type: string
  13274. version:
  13275. description: Used to select a specific version of the Provider value, if supported
  13276. type: string
  13277. required:
  13278. - key
  13279. type: object
  13280. secretKey:
  13281. description: The key in the Kubernetes Secret to store the value.
  13282. maxLength: 253
  13283. minLength: 1
  13284. pattern: ^[-._a-zA-Z0-9]+$
  13285. type: string
  13286. sourceRef:
  13287. description: |-
  13288. SourceRef allows you to override the source
  13289. from which the value will be pulled.
  13290. maxProperties: 1
  13291. minProperties: 1
  13292. properties:
  13293. generatorRef:
  13294. description: |-
  13295. GeneratorRef points to a generator custom resource.
  13296. Deprecated: The generatorRef is not implemented in .data[].
  13297. this will be removed with v1.
  13298. properties:
  13299. apiVersion:
  13300. default: generators.external-secrets.io/v1alpha1
  13301. description: Specify the apiVersion of the generator resource
  13302. type: string
  13303. kind:
  13304. description: Specify the Kind of the generator resource
  13305. enum:
  13306. - ACRAccessToken
  13307. - BeyondtrustWorkloadCredentialsDynamicSecret
  13308. - ClusterGenerator
  13309. - CloudsmithAccessToken
  13310. - ECRAuthorizationToken
  13311. - Fake
  13312. - GCRAccessToken
  13313. - GithubAccessToken
  13314. - GitlabDeployToken
  13315. - QuayAccessToken
  13316. - Password
  13317. - SSHKey
  13318. - STSSessionToken
  13319. - UUID
  13320. - VaultDynamicSecret
  13321. - Webhook
  13322. - Grafana
  13323. - MFA
  13324. type: string
  13325. name:
  13326. description: Specify the name of the generator resource
  13327. maxLength: 253
  13328. minLength: 1
  13329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13330. type: string
  13331. required:
  13332. - kind
  13333. - name
  13334. type: object
  13335. storeRef:
  13336. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13337. properties:
  13338. kind:
  13339. description: |-
  13340. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13341. Defaults to `SecretStore`
  13342. enum:
  13343. - SecretStore
  13344. - ClusterSecretStore
  13345. type: string
  13346. name:
  13347. description: Name of the SecretStore resource
  13348. maxLength: 253
  13349. minLength: 1
  13350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13351. type: string
  13352. type: object
  13353. type: object
  13354. required:
  13355. - remoteRef
  13356. - secretKey
  13357. type: object
  13358. type: array
  13359. dataFrom:
  13360. description: |-
  13361. DataFrom is used to fetch all properties from a specific Provider data
  13362. If multiple entries are specified, the Secret keys are merged in the specified order
  13363. items:
  13364. description: |-
  13365. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13366. when using DataFrom to fetch multiple values from a Provider.
  13367. properties:
  13368. extract:
  13369. description: |-
  13370. Used to extract multiple key/value pairs from one secret
  13371. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13372. properties:
  13373. conversionStrategy:
  13374. default: Default
  13375. description: Used to define a conversion Strategy
  13376. enum:
  13377. - Default
  13378. - Unicode
  13379. type: string
  13380. decodingStrategy:
  13381. default: None
  13382. description: Used to define a decoding Strategy
  13383. enum:
  13384. - Auto
  13385. - Base64
  13386. - Base64URL
  13387. - None
  13388. type: string
  13389. key:
  13390. description: Key is the key used in the Provider, mandatory
  13391. type: string
  13392. metadataPolicy:
  13393. default: None
  13394. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13395. enum:
  13396. - None
  13397. - Fetch
  13398. type: string
  13399. nullBytePolicy:
  13400. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13401. enum:
  13402. - Ignore
  13403. - Fail
  13404. type: string
  13405. property:
  13406. description: Used to select a specific property of the Provider value (if a map), if supported
  13407. type: string
  13408. version:
  13409. description: Used to select a specific version of the Provider value, if supported
  13410. type: string
  13411. required:
  13412. - key
  13413. type: object
  13414. find:
  13415. description: |-
  13416. Used to find secrets based on tags or regular expressions
  13417. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13418. properties:
  13419. conversionStrategy:
  13420. default: Default
  13421. description: Used to define a conversion Strategy
  13422. enum:
  13423. - Default
  13424. - Unicode
  13425. type: string
  13426. decodingStrategy:
  13427. default: None
  13428. description: Used to define a decoding Strategy
  13429. enum:
  13430. - Auto
  13431. - Base64
  13432. - Base64URL
  13433. - None
  13434. type: string
  13435. name:
  13436. description: Finds secrets based on the name.
  13437. properties:
  13438. regexp:
  13439. description: Finds secrets base
  13440. type: string
  13441. type: object
  13442. nullBytePolicy:
  13443. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13444. enum:
  13445. - Ignore
  13446. - Fail
  13447. type: string
  13448. path:
  13449. description: A root path to start the find operations.
  13450. type: string
  13451. tags:
  13452. additionalProperties:
  13453. type: string
  13454. description: Find secrets based on tags.
  13455. type: object
  13456. type: object
  13457. rewrite:
  13458. description: |-
  13459. Used to rewrite secret Keys after getting them from the secret Provider
  13460. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13461. items:
  13462. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13463. maxProperties: 1
  13464. minProperties: 1
  13465. properties:
  13466. merge:
  13467. description: |-
  13468. Used to merge key/values in one single Secret
  13469. The resulting key will contain all values from the specified secrets
  13470. properties:
  13471. conflictPolicy:
  13472. default: Error
  13473. description: Used to define the policy to use in conflict resolution.
  13474. enum:
  13475. - Ignore
  13476. - Error
  13477. type: string
  13478. into:
  13479. default: ""
  13480. description: |-
  13481. Used to define the target key of the merge operation.
  13482. Required if strategy is JSON. Ignored otherwise.
  13483. type: string
  13484. priority:
  13485. description: Used to define key priority in conflict resolution.
  13486. items:
  13487. type: string
  13488. type: array
  13489. priorityPolicy:
  13490. default: Strict
  13491. description: Used to define the policy when a key in the priority list does not exist in the input.
  13492. enum:
  13493. - IgnoreNotFound
  13494. - Strict
  13495. type: string
  13496. strategy:
  13497. default: Extract
  13498. description: Used to define the strategy to use in the merge operation.
  13499. enum:
  13500. - Extract
  13501. - JSON
  13502. type: string
  13503. type: object
  13504. regexp:
  13505. description: |-
  13506. Used to rewrite with regular expressions.
  13507. The resulting key will be the output of a regexp.ReplaceAll operation.
  13508. properties:
  13509. source:
  13510. description: Used to define the regular expression of a re.Compiler.
  13511. type: string
  13512. target:
  13513. description: Used to define the target pattern of a ReplaceAll operation.
  13514. type: string
  13515. required:
  13516. - source
  13517. - target
  13518. type: object
  13519. transform:
  13520. description: |-
  13521. Used to apply string transformation on the secrets.
  13522. The resulting key will be the output of the template applied by the operation.
  13523. properties:
  13524. template:
  13525. description: |-
  13526. Used to define the template to apply on the secret name.
  13527. `.value ` will specify the secret name in the template.
  13528. type: string
  13529. required:
  13530. - template
  13531. type: object
  13532. type: object
  13533. type: array
  13534. sourceRef:
  13535. description: |-
  13536. SourceRef points to a store or generator
  13537. which contains secret values ready to use.
  13538. Use this in combination with Extract or Find pull values out of
  13539. a specific SecretStore.
  13540. When sourceRef points to a generator Extract or Find is not supported.
  13541. The generator returns a static map of values
  13542. maxProperties: 1
  13543. minProperties: 1
  13544. properties:
  13545. generatorRef:
  13546. description: GeneratorRef points to a generator custom resource.
  13547. properties:
  13548. apiVersion:
  13549. default: generators.external-secrets.io/v1alpha1
  13550. description: Specify the apiVersion of the generator resource
  13551. type: string
  13552. kind:
  13553. description: Specify the Kind of the generator resource
  13554. enum:
  13555. - ACRAccessToken
  13556. - BeyondtrustWorkloadCredentialsDynamicSecret
  13557. - ClusterGenerator
  13558. - CloudsmithAccessToken
  13559. - ECRAuthorizationToken
  13560. - Fake
  13561. - GCRAccessToken
  13562. - GithubAccessToken
  13563. - GitlabDeployToken
  13564. - QuayAccessToken
  13565. - Password
  13566. - SSHKey
  13567. - STSSessionToken
  13568. - UUID
  13569. - VaultDynamicSecret
  13570. - Webhook
  13571. - Grafana
  13572. - MFA
  13573. type: string
  13574. name:
  13575. description: Specify the name of the generator resource
  13576. maxLength: 253
  13577. minLength: 1
  13578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13579. type: string
  13580. required:
  13581. - kind
  13582. - name
  13583. type: object
  13584. storeRef:
  13585. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13586. properties:
  13587. kind:
  13588. description: |-
  13589. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13590. Defaults to `SecretStore`
  13591. enum:
  13592. - SecretStore
  13593. - ClusterSecretStore
  13594. type: string
  13595. name:
  13596. description: Name of the SecretStore resource
  13597. maxLength: 253
  13598. minLength: 1
  13599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13600. type: string
  13601. type: object
  13602. type: object
  13603. type: object
  13604. type: array
  13605. refreshInterval:
  13606. default: 1h0m0s
  13607. description: |-
  13608. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13609. specified as Golang Duration strings.
  13610. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13611. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13612. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13613. type: string
  13614. refreshPolicy:
  13615. description: |-
  13616. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13617. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13618. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13619. No periodic updates occur if refreshInterval is 0.
  13620. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13621. enum:
  13622. - CreatedOnce
  13623. - Periodic
  13624. - OnChange
  13625. type: string
  13626. secretStoreRef:
  13627. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13628. properties:
  13629. kind:
  13630. description: |-
  13631. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13632. Defaults to `SecretStore`
  13633. enum:
  13634. - SecretStore
  13635. - ClusterSecretStore
  13636. type: string
  13637. name:
  13638. description: Name of the SecretStore resource
  13639. maxLength: 253
  13640. minLength: 1
  13641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13642. type: string
  13643. type: object
  13644. syncWindows:
  13645. description: |-
  13646. SyncWindows optionally restricts when periodic refreshes may occur.
  13647. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13648. properties:
  13649. kind:
  13650. description: |-
  13651. Kind applies to every window in the list.
  13652. "allow" -- syncs are permitted only while at least one window is active;
  13653. all other times are blocked.
  13654. "deny" -- syncs are blocked while any window is active;
  13655. all other times are permitted.
  13656. enum:
  13657. - allow
  13658. - deny
  13659. type: string
  13660. windows:
  13661. description: Windows is the list of schedule+duration pairs.
  13662. items:
  13663. description: |-
  13664. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13665. within a SyncWindows block.
  13666. properties:
  13667. duration:
  13668. description: |-
  13669. Duration specifies how long the window stays open after each Schedule
  13670. firing. Example: "8h".
  13671. type: string
  13672. schedule:
  13673. description: |-
  13674. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13675. named shorthand such as @daily or @every 1h. It marks the start time of
  13676. each window occurrence.
  13677. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13678. minLength: 1
  13679. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13680. type: string
  13681. required:
  13682. - duration
  13683. - schedule
  13684. type: object
  13685. minItems: 1
  13686. type: array
  13687. required:
  13688. - kind
  13689. - windows
  13690. type: object
  13691. target:
  13692. default:
  13693. creationPolicy: Owner
  13694. deletionPolicy: Retain
  13695. description: |-
  13696. ExternalSecretTarget defines the Kubernetes Secret to be created,
  13697. there can be only one target per ExternalSecret.
  13698. properties:
  13699. creationPolicy:
  13700. default: Owner
  13701. description: |-
  13702. CreationPolicy defines rules on how to create the resulting Secret.
  13703. Defaults to "Owner"
  13704. enum:
  13705. - Owner
  13706. - Orphan
  13707. - Merge
  13708. - None
  13709. type: string
  13710. deletionPolicy:
  13711. default: Retain
  13712. description: |-
  13713. DeletionPolicy defines rules on how to delete the resulting Secret.
  13714. Defaults to "Retain"
  13715. enum:
  13716. - Delete
  13717. - Merge
  13718. - Retain
  13719. type: string
  13720. immutable:
  13721. description: Immutable defines if the final secret will be immutable
  13722. type: boolean
  13723. manifest:
  13724. description: |-
  13725. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  13726. When specified, ExternalSecret will create the resource type defined here
  13727. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  13728. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  13729. properties:
  13730. apiVersion:
  13731. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  13732. minLength: 1
  13733. type: string
  13734. kind:
  13735. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  13736. minLength: 1
  13737. type: string
  13738. required:
  13739. - apiVersion
  13740. - kind
  13741. type: object
  13742. name:
  13743. description: |-
  13744. The name of the Secret resource to be managed.
  13745. Defaults to the .metadata.name of the ExternalSecret resource
  13746. maxLength: 253
  13747. minLength: 1
  13748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13749. type: string
  13750. template:
  13751. description: Template defines a blueprint for the created Secret resource.
  13752. properties:
  13753. data:
  13754. additionalProperties:
  13755. type: string
  13756. type: object
  13757. engineVersion:
  13758. default: v2
  13759. description: |-
  13760. EngineVersion specifies the template engine version
  13761. that should be used to compile/execute the
  13762. template specified in .data and .templateFrom[].
  13763. enum:
  13764. - v2
  13765. type: string
  13766. mergePolicy:
  13767. default: Replace
  13768. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  13769. enum:
  13770. - Replace
  13771. - Merge
  13772. type: string
  13773. metadata:
  13774. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  13775. properties:
  13776. annotations:
  13777. additionalProperties:
  13778. type: string
  13779. type: object
  13780. finalizers:
  13781. items:
  13782. type: string
  13783. type: array
  13784. labels:
  13785. additionalProperties:
  13786. type: string
  13787. type: object
  13788. type: object
  13789. templateFrom:
  13790. items:
  13791. description: |-
  13792. TemplateFrom specifies a source for templates.
  13793. Each item in the list can either reference a ConfigMap or a Secret resource.
  13794. properties:
  13795. configMap:
  13796. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  13797. properties:
  13798. items:
  13799. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  13800. items:
  13801. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  13802. properties:
  13803. key:
  13804. description: A key in the ConfigMap/Secret
  13805. maxLength: 253
  13806. minLength: 1
  13807. pattern: ^[-._a-zA-Z0-9]+$
  13808. type: string
  13809. templateAs:
  13810. default: Values
  13811. description: TemplateScope specifies how the template keys should be interpreted.
  13812. enum:
  13813. - Values
  13814. - KeysAndValues
  13815. type: string
  13816. required:
  13817. - key
  13818. type: object
  13819. type: array
  13820. name:
  13821. description: The name of the ConfigMap/Secret resource
  13822. maxLength: 253
  13823. minLength: 1
  13824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13825. type: string
  13826. required:
  13827. - items
  13828. - name
  13829. type: object
  13830. literal:
  13831. type: string
  13832. secret:
  13833. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  13834. properties:
  13835. items:
  13836. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  13837. items:
  13838. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  13839. properties:
  13840. key:
  13841. description: A key in the ConfigMap/Secret
  13842. maxLength: 253
  13843. minLength: 1
  13844. pattern: ^[-._a-zA-Z0-9]+$
  13845. type: string
  13846. templateAs:
  13847. default: Values
  13848. description: TemplateScope specifies how the template keys should be interpreted.
  13849. enum:
  13850. - Values
  13851. - KeysAndValues
  13852. type: string
  13853. required:
  13854. - key
  13855. type: object
  13856. type: array
  13857. name:
  13858. description: The name of the ConfigMap/Secret resource
  13859. maxLength: 253
  13860. minLength: 1
  13861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13862. type: string
  13863. required:
  13864. - items
  13865. - name
  13866. type: object
  13867. target:
  13868. default: Data
  13869. description: |-
  13870. Target specifies where to place the template result.
  13871. For Secret resources, common values are: "Data", "Annotations", "Labels".
  13872. For custom resources (when spec.target.manifest is set), this supports
  13873. nested paths like "spec.database.config" or "data".
  13874. type: string
  13875. valuesDecodingStrategy:
  13876. default: None
  13877. description: Used to define a decoding Strategy for the rendered template values.
  13878. enum:
  13879. - Auto
  13880. - Base64
  13881. - Base64URL
  13882. - None
  13883. type: string
  13884. type: object
  13885. type: array
  13886. type:
  13887. type: string
  13888. type: object
  13889. type: object
  13890. type: object
  13891. status:
  13892. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  13893. properties:
  13894. binding:
  13895. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  13896. properties:
  13897. name:
  13898. default: ""
  13899. description: |-
  13900. Name of the referent.
  13901. This field is effectively required, but due to backwards compatibility is
  13902. allowed to be empty. Instances of this type with an empty value here are
  13903. almost certainly wrong.
  13904. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  13905. type: string
  13906. type: object
  13907. x-kubernetes-map-type: atomic
  13908. conditions:
  13909. items:
  13910. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  13911. properties:
  13912. lastTransitionTime:
  13913. format: date-time
  13914. type: string
  13915. message:
  13916. type: string
  13917. reason:
  13918. type: string
  13919. status:
  13920. type: string
  13921. type:
  13922. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  13923. enum:
  13924. - Ready
  13925. - Deleted
  13926. type: string
  13927. required:
  13928. - status
  13929. - type
  13930. type: object
  13931. type: array
  13932. refreshTime:
  13933. description: |-
  13934. refreshTime is the time and date the external secret was fetched and
  13935. the target secret updated
  13936. format: date-time
  13937. nullable: true
  13938. type: string
  13939. syncedResourceVersion:
  13940. description: SyncedResourceVersion keeps track of the last synced version
  13941. type: string
  13942. type: object
  13943. type: object
  13944. selectableFields:
  13945. - jsonPath: .spec.secretStoreRef.name
  13946. - jsonPath: .spec.secretStoreRef.kind
  13947. - jsonPath: .spec.target.name
  13948. - jsonPath: .spec.refreshInterval
  13949. served: true
  13950. storage: true
  13951. subresources:
  13952. status: {}
  13953. - additionalPrinterColumns:
  13954. - jsonPath: .spec.secretStoreRef.kind
  13955. name: StoreType
  13956. type: string
  13957. - jsonPath: .spec.secretStoreRef.name
  13958. name: Store
  13959. type: string
  13960. - jsonPath: .spec.refreshInterval
  13961. name: Refresh Interval
  13962. type: string
  13963. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13964. name: Status
  13965. type: string
  13966. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13967. name: Ready
  13968. type: string
  13969. - jsonPath: .status.refreshTime
  13970. name: Last Sync
  13971. type: date
  13972. deprecated: true
  13973. name: v1beta1
  13974. schema:
  13975. openAPIV3Schema:
  13976. description: ExternalSecret is the schema for the external-secrets API.
  13977. properties:
  13978. apiVersion:
  13979. description: |-
  13980. APIVersion defines the versioned schema of this representation of an object.
  13981. Servers should convert recognized schemas to the latest internal value, and
  13982. may reject unrecognized values.
  13983. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13984. type: string
  13985. kind:
  13986. description: |-
  13987. Kind is a string value representing the REST resource this object represents.
  13988. Servers may infer this from the endpoint the client submits requests to.
  13989. Cannot be updated.
  13990. In CamelCase.
  13991. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13992. type: string
  13993. metadata:
  13994. type: object
  13995. spec:
  13996. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13997. properties:
  13998. data:
  13999. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14000. items:
  14001. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14002. properties:
  14003. remoteRef:
  14004. description: |-
  14005. RemoteRef points to the remote secret and defines
  14006. which secret (version/property/..) to fetch.
  14007. properties:
  14008. conversionStrategy:
  14009. default: Default
  14010. description: Used to define a conversion Strategy
  14011. enum:
  14012. - Default
  14013. - Unicode
  14014. type: string
  14015. decodingStrategy:
  14016. default: None
  14017. description: Used to define a decoding Strategy
  14018. enum:
  14019. - Auto
  14020. - Base64
  14021. - Base64URL
  14022. - None
  14023. type: string
  14024. key:
  14025. description: Key is the key used in the Provider, mandatory
  14026. type: string
  14027. metadataPolicy:
  14028. default: None
  14029. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14030. enum:
  14031. - None
  14032. - Fetch
  14033. type: string
  14034. property:
  14035. description: Used to select a specific property of the Provider value (if a map), if supported
  14036. type: string
  14037. version:
  14038. description: Used to select a specific version of the Provider value, if supported
  14039. type: string
  14040. required:
  14041. - key
  14042. type: object
  14043. secretKey:
  14044. description: The key in the Kubernetes Secret to store the value.
  14045. maxLength: 253
  14046. minLength: 1
  14047. pattern: ^[-._a-zA-Z0-9]+$
  14048. type: string
  14049. sourceRef:
  14050. description: |-
  14051. SourceRef allows you to override the source
  14052. from which the value will be pulled.
  14053. maxProperties: 1
  14054. minProperties: 1
  14055. properties:
  14056. generatorRef:
  14057. description: |-
  14058. GeneratorRef points to a generator custom resource.
  14059. Deprecated: The generatorRef is not implemented in .data[].
  14060. this will be removed with v1.
  14061. properties:
  14062. apiVersion:
  14063. default: generators.external-secrets.io/v1alpha1
  14064. description: Specify the apiVersion of the generator resource
  14065. type: string
  14066. kind:
  14067. description: Specify the Kind of the generator resource
  14068. enum:
  14069. - ACRAccessToken
  14070. - ClusterGenerator
  14071. - ECRAuthorizationToken
  14072. - Fake
  14073. - GCRAccessToken
  14074. - GithubAccessToken
  14075. - QuayAccessToken
  14076. - Password
  14077. - SSHKey
  14078. - STSSessionToken
  14079. - UUID
  14080. - VaultDynamicSecret
  14081. - Webhook
  14082. - Grafana
  14083. type: string
  14084. name:
  14085. description: Specify the name of the generator resource
  14086. maxLength: 253
  14087. minLength: 1
  14088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14089. type: string
  14090. required:
  14091. - kind
  14092. - name
  14093. type: object
  14094. storeRef:
  14095. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14096. properties:
  14097. kind:
  14098. description: |-
  14099. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14100. Defaults to `SecretStore`
  14101. enum:
  14102. - SecretStore
  14103. - ClusterSecretStore
  14104. type: string
  14105. name:
  14106. description: Name of the SecretStore resource
  14107. maxLength: 253
  14108. minLength: 1
  14109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14110. type: string
  14111. type: object
  14112. type: object
  14113. required:
  14114. - remoteRef
  14115. - secretKey
  14116. type: object
  14117. type: array
  14118. dataFrom:
  14119. description: |-
  14120. DataFrom is used to fetch all properties from a specific Provider data
  14121. If multiple entries are specified, the Secret keys are merged in the specified order
  14122. items:
  14123. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14124. properties:
  14125. extract:
  14126. description: |-
  14127. Used to extract multiple key/value pairs from one secret
  14128. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14129. properties:
  14130. conversionStrategy:
  14131. default: Default
  14132. description: Used to define a conversion Strategy
  14133. enum:
  14134. - Default
  14135. - Unicode
  14136. type: string
  14137. decodingStrategy:
  14138. default: None
  14139. description: Used to define a decoding Strategy
  14140. enum:
  14141. - Auto
  14142. - Base64
  14143. - Base64URL
  14144. - None
  14145. type: string
  14146. key:
  14147. description: Key is the key used in the Provider, mandatory
  14148. type: string
  14149. metadataPolicy:
  14150. default: None
  14151. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14152. enum:
  14153. - None
  14154. - Fetch
  14155. type: string
  14156. property:
  14157. description: Used to select a specific property of the Provider value (if a map), if supported
  14158. type: string
  14159. version:
  14160. description: Used to select a specific version of the Provider value, if supported
  14161. type: string
  14162. required:
  14163. - key
  14164. type: object
  14165. find:
  14166. description: |-
  14167. Used to find secrets based on tags or regular expressions
  14168. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14169. properties:
  14170. conversionStrategy:
  14171. default: Default
  14172. description: Used to define a conversion Strategy
  14173. enum:
  14174. - Default
  14175. - Unicode
  14176. type: string
  14177. decodingStrategy:
  14178. default: None
  14179. description: Used to define a decoding Strategy
  14180. enum:
  14181. - Auto
  14182. - Base64
  14183. - Base64URL
  14184. - None
  14185. type: string
  14186. name:
  14187. description: Finds secrets based on the name.
  14188. properties:
  14189. regexp:
  14190. description: Finds secrets base
  14191. type: string
  14192. type: object
  14193. path:
  14194. description: A root path to start the find operations.
  14195. type: string
  14196. tags:
  14197. additionalProperties:
  14198. type: string
  14199. description: Find secrets based on tags.
  14200. type: object
  14201. type: object
  14202. rewrite:
  14203. description: |-
  14204. Used to rewrite secret Keys after getting them from the secret Provider
  14205. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14206. items:
  14207. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14208. maxProperties: 1
  14209. minProperties: 1
  14210. properties:
  14211. regexp:
  14212. description: |-
  14213. Used to rewrite with regular expressions.
  14214. The resulting key will be the output of a regexp.ReplaceAll operation.
  14215. properties:
  14216. source:
  14217. description: Used to define the regular expression of a re.Compiler.
  14218. type: string
  14219. target:
  14220. description: Used to define the target pattern of a ReplaceAll operation.
  14221. type: string
  14222. required:
  14223. - source
  14224. - target
  14225. type: object
  14226. transform:
  14227. description: |-
  14228. Used to apply string transformation on the secrets.
  14229. The resulting key will be the output of the template applied by the operation.
  14230. properties:
  14231. template:
  14232. description: |-
  14233. Used to define the template to apply on the secret name.
  14234. `.value ` will specify the secret name in the template.
  14235. type: string
  14236. required:
  14237. - template
  14238. type: object
  14239. type: object
  14240. type: array
  14241. sourceRef:
  14242. description: |-
  14243. SourceRef points to a store or generator
  14244. which contains secret values ready to use.
  14245. Use this in combination with Extract or Find pull values out of
  14246. a specific SecretStore.
  14247. When sourceRef points to a generator Extract or Find is not supported.
  14248. The generator returns a static map of values
  14249. maxProperties: 1
  14250. minProperties: 1
  14251. properties:
  14252. generatorRef:
  14253. description: GeneratorRef points to a generator custom resource.
  14254. properties:
  14255. apiVersion:
  14256. default: generators.external-secrets.io/v1alpha1
  14257. description: Specify the apiVersion of the generator resource
  14258. type: string
  14259. kind:
  14260. description: Specify the Kind of the generator resource
  14261. enum:
  14262. - ACRAccessToken
  14263. - ClusterGenerator
  14264. - ECRAuthorizationToken
  14265. - Fake
  14266. - GCRAccessToken
  14267. - GithubAccessToken
  14268. - QuayAccessToken
  14269. - Password
  14270. - SSHKey
  14271. - STSSessionToken
  14272. - UUID
  14273. - VaultDynamicSecret
  14274. - Webhook
  14275. - Grafana
  14276. type: string
  14277. name:
  14278. description: Specify the name of the generator resource
  14279. maxLength: 253
  14280. minLength: 1
  14281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14282. type: string
  14283. required:
  14284. - kind
  14285. - name
  14286. type: object
  14287. storeRef:
  14288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14289. properties:
  14290. kind:
  14291. description: |-
  14292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14293. Defaults to `SecretStore`
  14294. enum:
  14295. - SecretStore
  14296. - ClusterSecretStore
  14297. type: string
  14298. name:
  14299. description: Name of the SecretStore resource
  14300. maxLength: 253
  14301. minLength: 1
  14302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14303. type: string
  14304. type: object
  14305. type: object
  14306. type: object
  14307. type: array
  14308. refreshInterval:
  14309. default: 1h0m0s
  14310. description: |-
  14311. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14312. specified as Golang Duration strings.
  14313. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14314. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14315. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14316. type: string
  14317. refreshPolicy:
  14318. description: |-
  14319. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14320. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14321. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14322. No periodic updates occur if refreshInterval is 0.
  14323. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14324. enum:
  14325. - CreatedOnce
  14326. - Periodic
  14327. - OnChange
  14328. type: string
  14329. secretStoreRef:
  14330. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14331. properties:
  14332. kind:
  14333. description: |-
  14334. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14335. Defaults to `SecretStore`
  14336. enum:
  14337. - SecretStore
  14338. - ClusterSecretStore
  14339. type: string
  14340. name:
  14341. description: Name of the SecretStore resource
  14342. maxLength: 253
  14343. minLength: 1
  14344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14345. type: string
  14346. type: object
  14347. target:
  14348. default:
  14349. creationPolicy: Owner
  14350. deletionPolicy: Retain
  14351. description: |-
  14352. ExternalSecretTarget defines the Kubernetes Secret to be created
  14353. There can be only one target per ExternalSecret.
  14354. properties:
  14355. creationPolicy:
  14356. default: Owner
  14357. description: |-
  14358. CreationPolicy defines rules on how to create the resulting Secret.
  14359. Defaults to "Owner"
  14360. enum:
  14361. - Owner
  14362. - Orphan
  14363. - Merge
  14364. - None
  14365. type: string
  14366. deletionPolicy:
  14367. default: Retain
  14368. description: |-
  14369. DeletionPolicy defines rules on how to delete the resulting Secret.
  14370. Defaults to "Retain"
  14371. enum:
  14372. - Delete
  14373. - Merge
  14374. - Retain
  14375. type: string
  14376. immutable:
  14377. description: Immutable defines if the final secret will be immutable
  14378. type: boolean
  14379. name:
  14380. description: |-
  14381. The name of the Secret resource to be managed.
  14382. Defaults to the .metadata.name of the ExternalSecret resource
  14383. maxLength: 253
  14384. minLength: 1
  14385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14386. type: string
  14387. template:
  14388. description: Template defines a blueprint for the created Secret resource.
  14389. properties:
  14390. data:
  14391. additionalProperties:
  14392. type: string
  14393. type: object
  14394. engineVersion:
  14395. default: v2
  14396. description: |-
  14397. EngineVersion specifies the template engine version
  14398. that should be used to compile/execute the
  14399. template specified in .data and .templateFrom[].
  14400. enum:
  14401. - v2
  14402. type: string
  14403. mergePolicy:
  14404. default: Replace
  14405. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14406. enum:
  14407. - Replace
  14408. - Merge
  14409. type: string
  14410. metadata:
  14411. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14412. properties:
  14413. annotations:
  14414. additionalProperties:
  14415. type: string
  14416. type: object
  14417. labels:
  14418. additionalProperties:
  14419. type: string
  14420. type: object
  14421. type: object
  14422. templateFrom:
  14423. items:
  14424. description: TemplateFrom defines a source for template data.
  14425. properties:
  14426. configMap:
  14427. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14428. properties:
  14429. items:
  14430. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14431. items:
  14432. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14433. properties:
  14434. key:
  14435. description: A key in the ConfigMap/Secret
  14436. maxLength: 253
  14437. minLength: 1
  14438. pattern: ^[-._a-zA-Z0-9]+$
  14439. type: string
  14440. templateAs:
  14441. default: Values
  14442. description: TemplateScope defines the scope of the template when processing template data.
  14443. enum:
  14444. - Values
  14445. - KeysAndValues
  14446. type: string
  14447. required:
  14448. - key
  14449. type: object
  14450. type: array
  14451. name:
  14452. description: The name of the ConfigMap/Secret resource
  14453. maxLength: 253
  14454. minLength: 1
  14455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14456. type: string
  14457. required:
  14458. - items
  14459. - name
  14460. type: object
  14461. literal:
  14462. type: string
  14463. secret:
  14464. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14465. properties:
  14466. items:
  14467. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14468. items:
  14469. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14470. properties:
  14471. key:
  14472. description: A key in the ConfigMap/Secret
  14473. maxLength: 253
  14474. minLength: 1
  14475. pattern: ^[-._a-zA-Z0-9]+$
  14476. type: string
  14477. templateAs:
  14478. default: Values
  14479. description: TemplateScope defines the scope of the template when processing template data.
  14480. enum:
  14481. - Values
  14482. - KeysAndValues
  14483. type: string
  14484. required:
  14485. - key
  14486. type: object
  14487. type: array
  14488. name:
  14489. description: The name of the ConfigMap/Secret resource
  14490. maxLength: 253
  14491. minLength: 1
  14492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14493. type: string
  14494. required:
  14495. - items
  14496. - name
  14497. type: object
  14498. target:
  14499. default: Data
  14500. description: TemplateTarget defines the target field where the template result will be stored.
  14501. enum:
  14502. - Data
  14503. - Annotations
  14504. - Labels
  14505. type: string
  14506. type: object
  14507. type: array
  14508. type:
  14509. type: string
  14510. type: object
  14511. type: object
  14512. type: object
  14513. status:
  14514. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14515. properties:
  14516. binding:
  14517. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14518. properties:
  14519. name:
  14520. default: ""
  14521. description: |-
  14522. Name of the referent.
  14523. This field is effectively required, but due to backwards compatibility is
  14524. allowed to be empty. Instances of this type with an empty value here are
  14525. almost certainly wrong.
  14526. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14527. type: string
  14528. type: object
  14529. x-kubernetes-map-type: atomic
  14530. conditions:
  14531. items:
  14532. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14533. properties:
  14534. lastTransitionTime:
  14535. format: date-time
  14536. type: string
  14537. message:
  14538. type: string
  14539. reason:
  14540. type: string
  14541. status:
  14542. type: string
  14543. type:
  14544. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14545. type: string
  14546. required:
  14547. - status
  14548. - type
  14549. type: object
  14550. type: array
  14551. refreshTime:
  14552. description: |-
  14553. refreshTime is the time and date the external secret was fetched and
  14554. the target secret updated
  14555. format: date-time
  14556. nullable: true
  14557. type: string
  14558. syncedResourceVersion:
  14559. description: SyncedResourceVersion keeps track of the last synced version
  14560. type: string
  14561. type: object
  14562. type: object
  14563. served: false
  14564. storage: false
  14565. subresources:
  14566. status: {}
  14567. ---
  14568. apiVersion: apiextensions.k8s.io/v1
  14569. kind: CustomResourceDefinition
  14570. metadata:
  14571. annotations:
  14572. controller-gen.kubebuilder.io/version: v0.19.0
  14573. labels:
  14574. external-secrets.io/component: controller
  14575. name: pushsecrets.external-secrets.io
  14576. spec:
  14577. group: external-secrets.io
  14578. names:
  14579. categories:
  14580. - external-secrets
  14581. kind: PushSecret
  14582. listKind: PushSecretList
  14583. plural: pushsecrets
  14584. shortNames:
  14585. - ps
  14586. singular: pushsecret
  14587. scope: Namespaced
  14588. versions:
  14589. - additionalPrinterColumns:
  14590. - jsonPath: .metadata.creationTimestamp
  14591. name: AGE
  14592. type: date
  14593. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14594. name: Status
  14595. type: string
  14596. - jsonPath: .status.refreshTime
  14597. name: Last Sync
  14598. type: date
  14599. name: v1alpha1
  14600. schema:
  14601. openAPIV3Schema:
  14602. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14603. properties:
  14604. apiVersion:
  14605. description: |-
  14606. APIVersion defines the versioned schema of this representation of an object.
  14607. Servers should convert recognized schemas to the latest internal value, and
  14608. may reject unrecognized values.
  14609. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14610. type: string
  14611. kind:
  14612. description: |-
  14613. Kind is a string value representing the REST resource this object represents.
  14614. Servers may infer this from the endpoint the client submits requests to.
  14615. Cannot be updated.
  14616. In CamelCase.
  14617. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14618. type: string
  14619. metadata:
  14620. type: object
  14621. spec:
  14622. description: PushSecretSpec configures the behavior of the PushSecret.
  14623. properties:
  14624. data:
  14625. description: Secret Data that should be pushed to providers
  14626. items:
  14627. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14628. properties:
  14629. conversionStrategy:
  14630. default: None
  14631. description: Used to define a conversion Strategy for the secret keys
  14632. enum:
  14633. - None
  14634. - ReverseUnicode
  14635. type: string
  14636. match:
  14637. description: Match a given Secret Key to be pushed to the provider.
  14638. properties:
  14639. remoteRef:
  14640. description: Remote Refs to push to providers.
  14641. properties:
  14642. property:
  14643. description: Name of the property in the resulting secret
  14644. type: string
  14645. remoteKey:
  14646. description: Name of the resulting provider secret.
  14647. type: string
  14648. required:
  14649. - remoteKey
  14650. type: object
  14651. secretKey:
  14652. description: Secret Key to be pushed
  14653. type: string
  14654. required:
  14655. - remoteRef
  14656. type: object
  14657. metadata:
  14658. description: |-
  14659. Metadata is metadata attached to the secret.
  14660. The structure of metadata is provider specific, please look it up in the provider documentation.
  14661. x-kubernetes-preserve-unknown-fields: true
  14662. required:
  14663. - match
  14664. type: object
  14665. type: array
  14666. dataTo:
  14667. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14668. items:
  14669. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14670. properties:
  14671. conversionStrategy:
  14672. default: None
  14673. description: Used to define a conversion Strategy for the secret keys
  14674. enum:
  14675. - None
  14676. - ReverseUnicode
  14677. type: string
  14678. match:
  14679. description: |-
  14680. Match pattern for selecting keys from the source Secret.
  14681. If not specified, all keys are selected.
  14682. properties:
  14683. regexp:
  14684. description: |-
  14685. Regexp matches keys by regular expression.
  14686. If not specified, all keys are matched.
  14687. type: string
  14688. type: object
  14689. metadata:
  14690. description: |-
  14691. Metadata is metadata attached to the secret.
  14692. The structure of metadata is provider specific, please look it up in the provider documentation.
  14693. x-kubernetes-preserve-unknown-fields: true
  14694. remoteKey:
  14695. description: |-
  14696. RemoteKey is the name of the single provider secret that will receive ALL
  14697. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  14698. When set, per-key expansion is skipped and a single push is performed.
  14699. The provider's store prefix (if any) is still prepended to this value.
  14700. When not set, each matched key is pushed as its own individual provider secret.
  14701. type: string
  14702. rewrite:
  14703. description: |-
  14704. Rewrite operations to transform keys before pushing to the provider.
  14705. Operations are applied sequentially.
  14706. items:
  14707. description: PushSecretRewrite defines how to transform secret keys before pushing.
  14708. properties:
  14709. regexp:
  14710. description: Used to rewrite with regular expressions.
  14711. properties:
  14712. source:
  14713. description: Used to define the regular expression of a re.Compiler.
  14714. type: string
  14715. target:
  14716. description: Used to define the target pattern of a ReplaceAll operation.
  14717. type: string
  14718. required:
  14719. - source
  14720. - target
  14721. type: object
  14722. transform:
  14723. description: Used to apply string transformation on the secrets.
  14724. properties:
  14725. template:
  14726. description: |-
  14727. Used to define the template to apply on the secret name.
  14728. `.value ` will specify the secret name in the template.
  14729. type: string
  14730. required:
  14731. - template
  14732. type: object
  14733. type: object
  14734. x-kubernetes-validations:
  14735. - message: exactly one of regexp or transform must be set
  14736. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  14737. type: array
  14738. storeRef:
  14739. description: StoreRef specifies which SecretStore to push to. Required.
  14740. properties:
  14741. kind:
  14742. default: SecretStore
  14743. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14744. enum:
  14745. - SecretStore
  14746. - ClusterSecretStore
  14747. type: string
  14748. labelSelector:
  14749. description: Optionally, sync to secret stores with label selector
  14750. properties:
  14751. matchExpressions:
  14752. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14753. items:
  14754. description: |-
  14755. A label selector requirement is a selector that contains values, a key, and an operator that
  14756. relates the key and values.
  14757. properties:
  14758. key:
  14759. description: key is the label key that the selector applies to.
  14760. type: string
  14761. operator:
  14762. description: |-
  14763. operator represents a key's relationship to a set of values.
  14764. Valid operators are In, NotIn, Exists and DoesNotExist.
  14765. type: string
  14766. values:
  14767. description: |-
  14768. values is an array of string values. If the operator is In or NotIn,
  14769. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14770. the values array must be empty. This array is replaced during a strategic
  14771. merge patch.
  14772. items:
  14773. type: string
  14774. type: array
  14775. x-kubernetes-list-type: atomic
  14776. required:
  14777. - key
  14778. - operator
  14779. type: object
  14780. type: array
  14781. x-kubernetes-list-type: atomic
  14782. matchLabels:
  14783. additionalProperties:
  14784. type: string
  14785. description: |-
  14786. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14787. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14788. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14789. type: object
  14790. type: object
  14791. x-kubernetes-map-type: atomic
  14792. name:
  14793. description: Optionally, sync to the SecretStore of the given name
  14794. maxLength: 253
  14795. minLength: 1
  14796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14797. type: string
  14798. type: object
  14799. type: object
  14800. x-kubernetes-validations:
  14801. - message: storeRef must specify either name or labelSelector
  14802. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  14803. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  14804. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  14805. type: array
  14806. deletionPolicy:
  14807. default: None
  14808. description: Deletion Policy to handle Secrets in the provider.
  14809. enum:
  14810. - Delete
  14811. - None
  14812. type: string
  14813. refreshInterval:
  14814. default: 1h0m0s
  14815. description: The Interval to which External Secrets will try to push a secret definition
  14816. type: string
  14817. secretStoreRefs:
  14818. items:
  14819. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  14820. properties:
  14821. kind:
  14822. default: SecretStore
  14823. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14824. enum:
  14825. - SecretStore
  14826. - ClusterSecretStore
  14827. type: string
  14828. labelSelector:
  14829. description: Optionally, sync to secret stores with label selector
  14830. properties:
  14831. matchExpressions:
  14832. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14833. items:
  14834. description: |-
  14835. A label selector requirement is a selector that contains values, a key, and an operator that
  14836. relates the key and values.
  14837. properties:
  14838. key:
  14839. description: key is the label key that the selector applies to.
  14840. type: string
  14841. operator:
  14842. description: |-
  14843. operator represents a key's relationship to a set of values.
  14844. Valid operators are In, NotIn, Exists and DoesNotExist.
  14845. type: string
  14846. values:
  14847. description: |-
  14848. values is an array of string values. If the operator is In or NotIn,
  14849. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14850. the values array must be empty. This array is replaced during a strategic
  14851. merge patch.
  14852. items:
  14853. type: string
  14854. type: array
  14855. x-kubernetes-list-type: atomic
  14856. required:
  14857. - key
  14858. - operator
  14859. type: object
  14860. type: array
  14861. x-kubernetes-list-type: atomic
  14862. matchLabels:
  14863. additionalProperties:
  14864. type: string
  14865. description: |-
  14866. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14867. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14868. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14869. type: object
  14870. type: object
  14871. x-kubernetes-map-type: atomic
  14872. name:
  14873. description: Optionally, sync to the SecretStore of the given name
  14874. maxLength: 253
  14875. minLength: 1
  14876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14877. type: string
  14878. type: object
  14879. type: array
  14880. selector:
  14881. description: The Secret Selector (k8s source) for the Push Secret
  14882. maxProperties: 1
  14883. minProperties: 1
  14884. properties:
  14885. generatorRef:
  14886. description: Point to a generator to create a Secret.
  14887. properties:
  14888. apiVersion:
  14889. default: generators.external-secrets.io/v1alpha1
  14890. description: Specify the apiVersion of the generator resource
  14891. type: string
  14892. kind:
  14893. description: Specify the Kind of the generator resource
  14894. enum:
  14895. - ACRAccessToken
  14896. - BeyondtrustWorkloadCredentialsDynamicSecret
  14897. - ClusterGenerator
  14898. - CloudsmithAccessToken
  14899. - ECRAuthorizationToken
  14900. - Fake
  14901. - GCRAccessToken
  14902. - GithubAccessToken
  14903. - GitlabDeployToken
  14904. - QuayAccessToken
  14905. - Password
  14906. - SSHKey
  14907. - STSSessionToken
  14908. - UUID
  14909. - VaultDynamicSecret
  14910. - Webhook
  14911. - Grafana
  14912. - MFA
  14913. type: string
  14914. name:
  14915. description: Specify the name of the generator resource
  14916. maxLength: 253
  14917. minLength: 1
  14918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14919. type: string
  14920. required:
  14921. - kind
  14922. - name
  14923. type: object
  14924. secret:
  14925. description: Select a Secret to Push.
  14926. properties:
  14927. name:
  14928. description: |-
  14929. Name of the Secret.
  14930. The Secret must exist in the same namespace as the PushSecret manifest.
  14931. maxLength: 253
  14932. minLength: 1
  14933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14934. type: string
  14935. selector:
  14936. description: Selector chooses secrets using a labelSelector.
  14937. properties:
  14938. matchExpressions:
  14939. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14940. items:
  14941. description: |-
  14942. A label selector requirement is a selector that contains values, a key, and an operator that
  14943. relates the key and values.
  14944. properties:
  14945. key:
  14946. description: key is the label key that the selector applies to.
  14947. type: string
  14948. operator:
  14949. description: |-
  14950. operator represents a key's relationship to a set of values.
  14951. Valid operators are In, NotIn, Exists and DoesNotExist.
  14952. type: string
  14953. values:
  14954. description: |-
  14955. values is an array of string values. If the operator is In or NotIn,
  14956. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14957. the values array must be empty. This array is replaced during a strategic
  14958. merge patch.
  14959. items:
  14960. type: string
  14961. type: array
  14962. x-kubernetes-list-type: atomic
  14963. required:
  14964. - key
  14965. - operator
  14966. type: object
  14967. type: array
  14968. x-kubernetes-list-type: atomic
  14969. matchLabels:
  14970. additionalProperties:
  14971. type: string
  14972. description: |-
  14973. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14974. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14975. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14976. type: object
  14977. type: object
  14978. x-kubernetes-map-type: atomic
  14979. type: object
  14980. type: object
  14981. template:
  14982. description: Template defines a blueprint for the created Secret resource.
  14983. properties:
  14984. data:
  14985. additionalProperties:
  14986. type: string
  14987. type: object
  14988. engineVersion:
  14989. default: v2
  14990. description: |-
  14991. EngineVersion specifies the template engine version
  14992. that should be used to compile/execute the
  14993. template specified in .data and .templateFrom[].
  14994. enum:
  14995. - v2
  14996. type: string
  14997. mergePolicy:
  14998. default: Replace
  14999. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15000. enum:
  15001. - Replace
  15002. - Merge
  15003. type: string
  15004. metadata:
  15005. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15006. properties:
  15007. annotations:
  15008. additionalProperties:
  15009. type: string
  15010. type: object
  15011. finalizers:
  15012. items:
  15013. type: string
  15014. type: array
  15015. labels:
  15016. additionalProperties:
  15017. type: string
  15018. type: object
  15019. type: object
  15020. templateFrom:
  15021. items:
  15022. description: |-
  15023. TemplateFrom specifies a source for templates.
  15024. Each item in the list can either reference a ConfigMap or a Secret resource.
  15025. properties:
  15026. configMap:
  15027. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15028. properties:
  15029. items:
  15030. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15031. items:
  15032. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15033. properties:
  15034. key:
  15035. description: A key in the ConfigMap/Secret
  15036. maxLength: 253
  15037. minLength: 1
  15038. pattern: ^[-._a-zA-Z0-9]+$
  15039. type: string
  15040. templateAs:
  15041. default: Values
  15042. description: TemplateScope specifies how the template keys should be interpreted.
  15043. enum:
  15044. - Values
  15045. - KeysAndValues
  15046. type: string
  15047. required:
  15048. - key
  15049. type: object
  15050. type: array
  15051. name:
  15052. description: The name of the ConfigMap/Secret resource
  15053. maxLength: 253
  15054. minLength: 1
  15055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15056. type: string
  15057. required:
  15058. - items
  15059. - name
  15060. type: object
  15061. literal:
  15062. type: string
  15063. secret:
  15064. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15065. properties:
  15066. items:
  15067. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15068. items:
  15069. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15070. properties:
  15071. key:
  15072. description: A key in the ConfigMap/Secret
  15073. maxLength: 253
  15074. minLength: 1
  15075. pattern: ^[-._a-zA-Z0-9]+$
  15076. type: string
  15077. templateAs:
  15078. default: Values
  15079. description: TemplateScope specifies how the template keys should be interpreted.
  15080. enum:
  15081. - Values
  15082. - KeysAndValues
  15083. type: string
  15084. required:
  15085. - key
  15086. type: object
  15087. type: array
  15088. name:
  15089. description: The name of the ConfigMap/Secret resource
  15090. maxLength: 253
  15091. minLength: 1
  15092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15093. type: string
  15094. required:
  15095. - items
  15096. - name
  15097. type: object
  15098. target:
  15099. default: Data
  15100. description: |-
  15101. Target specifies where to place the template result.
  15102. For Secret resources, common values are: "Data", "Annotations", "Labels".
  15103. For custom resources (when spec.target.manifest is set), this supports
  15104. nested paths like "spec.database.config" or "data".
  15105. type: string
  15106. valuesDecodingStrategy:
  15107. default: None
  15108. description: Used to define a decoding Strategy for the rendered template values.
  15109. enum:
  15110. - Auto
  15111. - Base64
  15112. - Base64URL
  15113. - None
  15114. type: string
  15115. type: object
  15116. type: array
  15117. type:
  15118. type: string
  15119. type: object
  15120. updatePolicy:
  15121. default: Replace
  15122. description: UpdatePolicy to handle Secrets in the provider.
  15123. enum:
  15124. - Replace
  15125. - IfNotExists
  15126. type: string
  15127. required:
  15128. - secretStoreRefs
  15129. - selector
  15130. type: object
  15131. status:
  15132. description: PushSecretStatus indicates the history of the status of PushSecret.
  15133. properties:
  15134. conditions:
  15135. items:
  15136. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15137. properties:
  15138. lastTransitionTime:
  15139. format: date-time
  15140. type: string
  15141. message:
  15142. type: string
  15143. reason:
  15144. type: string
  15145. status:
  15146. type: string
  15147. type:
  15148. description: PushSecretConditionType indicates the condition of the PushSecret.
  15149. type: string
  15150. required:
  15151. - status
  15152. - type
  15153. type: object
  15154. type: array
  15155. refreshTime:
  15156. description: |-
  15157. refreshTime is the time and date the external secret was fetched and
  15158. the target secret updated
  15159. format: date-time
  15160. nullable: true
  15161. type: string
  15162. syncedPushSecrets:
  15163. additionalProperties:
  15164. additionalProperties:
  15165. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15166. properties:
  15167. conversionStrategy:
  15168. default: None
  15169. description: Used to define a conversion Strategy for the secret keys
  15170. enum:
  15171. - None
  15172. - ReverseUnicode
  15173. type: string
  15174. match:
  15175. description: Match a given Secret Key to be pushed to the provider.
  15176. properties:
  15177. remoteRef:
  15178. description: Remote Refs to push to providers.
  15179. properties:
  15180. property:
  15181. description: Name of the property in the resulting secret
  15182. type: string
  15183. remoteKey:
  15184. description: Name of the resulting provider secret.
  15185. type: string
  15186. required:
  15187. - remoteKey
  15188. type: object
  15189. secretKey:
  15190. description: Secret Key to be pushed
  15191. type: string
  15192. required:
  15193. - remoteRef
  15194. type: object
  15195. metadata:
  15196. description: |-
  15197. Metadata is metadata attached to the secret.
  15198. The structure of metadata is provider specific, please look it up in the provider documentation.
  15199. x-kubernetes-preserve-unknown-fields: true
  15200. required:
  15201. - match
  15202. type: object
  15203. type: object
  15204. description: |-
  15205. Synced PushSecrets, including secrets that already exist in provider.
  15206. Matches secret stores to PushSecretData that was stored to that secret store.
  15207. type: object
  15208. syncedResourceVersion:
  15209. description: SyncedResourceVersion keeps track of the last synced version.
  15210. type: string
  15211. type: object
  15212. type: object
  15213. served: true
  15214. storage: true
  15215. subresources:
  15216. status: {}
  15217. ---
  15218. apiVersion: apiextensions.k8s.io/v1
  15219. kind: CustomResourceDefinition
  15220. metadata:
  15221. annotations:
  15222. controller-gen.kubebuilder.io/version: v0.19.0
  15223. labels:
  15224. external-secrets.io/component: controller
  15225. name: secretstores.external-secrets.io
  15226. spec:
  15227. group: external-secrets.io
  15228. names:
  15229. categories:
  15230. - external-secrets
  15231. kind: SecretStore
  15232. listKind: SecretStoreList
  15233. plural: secretstores
  15234. shortNames:
  15235. - ss
  15236. singular: secretstore
  15237. scope: Namespaced
  15238. versions:
  15239. - additionalPrinterColumns:
  15240. - jsonPath: .metadata.creationTimestamp
  15241. name: AGE
  15242. type: date
  15243. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15244. name: Status
  15245. type: string
  15246. - jsonPath: .status.capabilities
  15247. name: Capabilities
  15248. type: string
  15249. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15250. name: Ready
  15251. type: string
  15252. name: v1
  15253. schema:
  15254. openAPIV3Schema:
  15255. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15256. properties:
  15257. apiVersion:
  15258. description: |-
  15259. APIVersion defines the versioned schema of this representation of an object.
  15260. Servers should convert recognized schemas to the latest internal value, and
  15261. may reject unrecognized values.
  15262. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15263. type: string
  15264. kind:
  15265. description: |-
  15266. Kind is a string value representing the REST resource this object represents.
  15267. Servers may infer this from the endpoint the client submits requests to.
  15268. Cannot be updated.
  15269. In CamelCase.
  15270. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15271. type: string
  15272. metadata:
  15273. type: object
  15274. spec:
  15275. description: SecretStoreSpec defines the desired state of SecretStore.
  15276. properties:
  15277. conditions:
  15278. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15279. items:
  15280. description: |-
  15281. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15282. for a ClusterSecretStore instance.
  15283. properties:
  15284. namespaceRegexes:
  15285. description: Choose namespaces by using regex matching
  15286. items:
  15287. type: string
  15288. type: array
  15289. namespaceSelector:
  15290. description: Choose namespace using a labelSelector
  15291. properties:
  15292. matchExpressions:
  15293. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15294. items:
  15295. description: |-
  15296. A label selector requirement is a selector that contains values, a key, and an operator that
  15297. relates the key and values.
  15298. properties:
  15299. key:
  15300. description: key is the label key that the selector applies to.
  15301. type: string
  15302. operator:
  15303. description: |-
  15304. operator represents a key's relationship to a set of values.
  15305. Valid operators are In, NotIn, Exists and DoesNotExist.
  15306. type: string
  15307. values:
  15308. description: |-
  15309. values is an array of string values. If the operator is In or NotIn,
  15310. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15311. the values array must be empty. This array is replaced during a strategic
  15312. merge patch.
  15313. items:
  15314. type: string
  15315. type: array
  15316. x-kubernetes-list-type: atomic
  15317. required:
  15318. - key
  15319. - operator
  15320. type: object
  15321. type: array
  15322. x-kubernetes-list-type: atomic
  15323. matchLabels:
  15324. additionalProperties:
  15325. type: string
  15326. description: |-
  15327. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15328. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15329. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15330. type: object
  15331. type: object
  15332. x-kubernetes-map-type: atomic
  15333. namespaces:
  15334. description: Choose namespaces by name
  15335. items:
  15336. maxLength: 63
  15337. minLength: 1
  15338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15339. type: string
  15340. type: array
  15341. type: object
  15342. type: array
  15343. controller:
  15344. description: |-
  15345. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15346. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15347. type: string
  15348. provider:
  15349. description: Used to configure the provider. Only one provider may be set
  15350. maxProperties: 1
  15351. minProperties: 1
  15352. properties:
  15353. akeyless:
  15354. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15355. properties:
  15356. akeylessGWApiURL:
  15357. description: Akeyless GW API Url from which the secrets to be fetched from.
  15358. type: string
  15359. authSecretRef:
  15360. description: Auth configures how the operator authenticates with Akeyless.
  15361. properties:
  15362. kubernetesAuth:
  15363. description: |-
  15364. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15365. token stored in the named Secret resource.
  15366. properties:
  15367. accessID:
  15368. description: the Akeyless Kubernetes auth-method access-id
  15369. type: string
  15370. k8sConfName:
  15371. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15372. type: string
  15373. secretRef:
  15374. description: |-
  15375. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15376. for authenticating with Akeyless. If a name is specified without a key,
  15377. `token` is the default. If one is not specified, the one bound to
  15378. the controller will be used.
  15379. properties:
  15380. key:
  15381. description: |-
  15382. A key in the referenced Secret.
  15383. Some instances of this field may be defaulted, in others it may be required.
  15384. maxLength: 253
  15385. minLength: 1
  15386. pattern: ^[-._a-zA-Z0-9]+$
  15387. type: string
  15388. name:
  15389. description: The name of the Secret resource being referred to.
  15390. maxLength: 253
  15391. minLength: 1
  15392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15393. type: string
  15394. namespace:
  15395. description: |-
  15396. The namespace of the Secret resource being referred to.
  15397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15398. maxLength: 63
  15399. minLength: 1
  15400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15401. type: string
  15402. type: object
  15403. serviceAccountRef:
  15404. description: |-
  15405. Optional service account field containing the name of a kubernetes ServiceAccount.
  15406. If the service account is specified, the service account secret token JWT will be used
  15407. for authenticating with Akeyless. If the service account selector is not supplied,
  15408. the secretRef will be used instead.
  15409. properties:
  15410. audiences:
  15411. description: |-
  15412. Audience specifies the `aud` claim for the service account token
  15413. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15414. then this audiences will be appended to the list
  15415. items:
  15416. type: string
  15417. type: array
  15418. name:
  15419. description: The name of the ServiceAccount resource being referred to.
  15420. maxLength: 253
  15421. minLength: 1
  15422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15423. type: string
  15424. namespace:
  15425. description: |-
  15426. Namespace of the resource being referred to.
  15427. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15428. maxLength: 63
  15429. minLength: 1
  15430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15431. type: string
  15432. required:
  15433. - name
  15434. type: object
  15435. required:
  15436. - accessID
  15437. - k8sConfName
  15438. type: object
  15439. secretRef:
  15440. description: |-
  15441. Reference to a Secret that contains the details
  15442. to authenticate with Akeyless.
  15443. properties:
  15444. accessID:
  15445. description: The SecretAccessID is used for authentication
  15446. properties:
  15447. key:
  15448. description: |-
  15449. A key in the referenced Secret.
  15450. Some instances of this field may be defaulted, in others it may be required.
  15451. maxLength: 253
  15452. minLength: 1
  15453. pattern: ^[-._a-zA-Z0-9]+$
  15454. type: string
  15455. name:
  15456. description: The name of the Secret resource being referred to.
  15457. maxLength: 253
  15458. minLength: 1
  15459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15460. type: string
  15461. namespace:
  15462. description: |-
  15463. The namespace of the Secret resource being referred to.
  15464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15465. maxLength: 63
  15466. minLength: 1
  15467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15468. type: string
  15469. type: object
  15470. accessType:
  15471. description: |-
  15472. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15473. In some instances, `key` is a required field.
  15474. properties:
  15475. key:
  15476. description: |-
  15477. A key in the referenced Secret.
  15478. Some instances of this field may be defaulted, in others it may be required.
  15479. maxLength: 253
  15480. minLength: 1
  15481. pattern: ^[-._a-zA-Z0-9]+$
  15482. type: string
  15483. name:
  15484. description: The name of the Secret resource being referred to.
  15485. maxLength: 253
  15486. minLength: 1
  15487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15488. type: string
  15489. namespace:
  15490. description: |-
  15491. The namespace of the Secret resource being referred to.
  15492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15493. maxLength: 63
  15494. minLength: 1
  15495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15496. type: string
  15497. type: object
  15498. accessTypeParam:
  15499. description: |-
  15500. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15501. In some instances, `key` is a required field.
  15502. properties:
  15503. key:
  15504. description: |-
  15505. A key in the referenced Secret.
  15506. Some instances of this field may be defaulted, in others it may be required.
  15507. maxLength: 253
  15508. minLength: 1
  15509. pattern: ^[-._a-zA-Z0-9]+$
  15510. type: string
  15511. name:
  15512. description: The name of the Secret resource being referred to.
  15513. maxLength: 253
  15514. minLength: 1
  15515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15516. type: string
  15517. namespace:
  15518. description: |-
  15519. The namespace of the Secret resource being referred to.
  15520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15521. maxLength: 63
  15522. minLength: 1
  15523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15524. type: string
  15525. type: object
  15526. type: object
  15527. serviceAccountRef:
  15528. description: |-
  15529. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15530. authentication on AKS Workload Identity. The operator obtains a federated
  15531. identity token from this ServiceAccount via the TokenRequest API instead
  15532. of using the ESO controller pod identity. Ignored for other access types.
  15533. properties:
  15534. audiences:
  15535. description: |-
  15536. Audience specifies the `aud` claim for the service account token
  15537. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15538. then this audiences will be appended to the list
  15539. items:
  15540. type: string
  15541. type: array
  15542. name:
  15543. description: The name of the ServiceAccount resource being referred to.
  15544. maxLength: 253
  15545. minLength: 1
  15546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15547. type: string
  15548. namespace:
  15549. description: |-
  15550. Namespace of the resource being referred to.
  15551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15552. maxLength: 63
  15553. minLength: 1
  15554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15555. type: string
  15556. required:
  15557. - name
  15558. type: object
  15559. type: object
  15560. caBundle:
  15561. description: |-
  15562. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15563. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15564. are used to validate the TLS connection.
  15565. format: byte
  15566. type: string
  15567. caProvider:
  15568. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15569. properties:
  15570. key:
  15571. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15572. maxLength: 253
  15573. minLength: 1
  15574. pattern: ^[-._a-zA-Z0-9]+$
  15575. type: string
  15576. name:
  15577. description: The name of the object located at the provider type.
  15578. maxLength: 253
  15579. minLength: 1
  15580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15581. type: string
  15582. namespace:
  15583. description: |-
  15584. The namespace the Provider type is in.
  15585. Can only be defined when used in a ClusterSecretStore.
  15586. maxLength: 63
  15587. minLength: 1
  15588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15589. type: string
  15590. type:
  15591. description: The type of provider to use such as "Secret", or "ConfigMap".
  15592. enum:
  15593. - Secret
  15594. - ConfigMap
  15595. type: string
  15596. required:
  15597. - name
  15598. - type
  15599. type: object
  15600. ignoreCache:
  15601. description: |-
  15602. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15603. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15604. type: boolean
  15605. required:
  15606. - akeylessGWApiURL
  15607. - authSecretRef
  15608. type: object
  15609. aws:
  15610. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15611. properties:
  15612. additionalRoles:
  15613. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15614. items:
  15615. type: string
  15616. type: array
  15617. auth:
  15618. description: |-
  15619. Auth defines the information necessary to authenticate against AWS
  15620. if not set aws sdk will infer credentials from your environment
  15621. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15622. properties:
  15623. jwt:
  15624. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15625. properties:
  15626. serviceAccountRef:
  15627. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15628. properties:
  15629. audiences:
  15630. description: |-
  15631. Audience specifies the `aud` claim for the service account token
  15632. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15633. then this audiences will be appended to the list
  15634. items:
  15635. type: string
  15636. type: array
  15637. name:
  15638. description: The name of the ServiceAccount resource being referred to.
  15639. maxLength: 253
  15640. minLength: 1
  15641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15642. type: string
  15643. namespace:
  15644. description: |-
  15645. Namespace of the resource being referred to.
  15646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15647. maxLength: 63
  15648. minLength: 1
  15649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15650. type: string
  15651. required:
  15652. - name
  15653. type: object
  15654. type: object
  15655. secretRef:
  15656. description: |-
  15657. AWSAuthSecretRef holds secret references for AWS credentials
  15658. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15659. properties:
  15660. accessKeyIDSecretRef:
  15661. description: The AccessKeyID is used for authentication
  15662. properties:
  15663. key:
  15664. description: |-
  15665. A key in the referenced Secret.
  15666. Some instances of this field may be defaulted, in others it may be required.
  15667. maxLength: 253
  15668. minLength: 1
  15669. pattern: ^[-._a-zA-Z0-9]+$
  15670. type: string
  15671. name:
  15672. description: The name of the Secret resource being referred to.
  15673. maxLength: 253
  15674. minLength: 1
  15675. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15676. type: string
  15677. namespace:
  15678. description: |-
  15679. The namespace of the Secret resource being referred to.
  15680. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15681. maxLength: 63
  15682. minLength: 1
  15683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15684. type: string
  15685. type: object
  15686. secretAccessKeySecretRef:
  15687. description: The SecretAccessKey is used for authentication
  15688. properties:
  15689. key:
  15690. description: |-
  15691. A key in the referenced Secret.
  15692. Some instances of this field may be defaulted, in others it may be required.
  15693. maxLength: 253
  15694. minLength: 1
  15695. pattern: ^[-._a-zA-Z0-9]+$
  15696. type: string
  15697. name:
  15698. description: The name of the Secret resource being referred to.
  15699. maxLength: 253
  15700. minLength: 1
  15701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15702. type: string
  15703. namespace:
  15704. description: |-
  15705. The namespace of the Secret resource being referred to.
  15706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15707. maxLength: 63
  15708. minLength: 1
  15709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15710. type: string
  15711. type: object
  15712. sessionTokenSecretRef:
  15713. description: |-
  15714. The SessionToken used for authentication
  15715. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  15716. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  15717. properties:
  15718. key:
  15719. description: |-
  15720. A key in the referenced Secret.
  15721. Some instances of this field may be defaulted, in others it may be required.
  15722. maxLength: 253
  15723. minLength: 1
  15724. pattern: ^[-._a-zA-Z0-9]+$
  15725. type: string
  15726. name:
  15727. description: The name of the Secret resource being referred to.
  15728. maxLength: 253
  15729. minLength: 1
  15730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15731. type: string
  15732. namespace:
  15733. description: |-
  15734. The namespace of the Secret resource being referred to.
  15735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15736. maxLength: 63
  15737. minLength: 1
  15738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15739. type: string
  15740. type: object
  15741. type: object
  15742. type: object
  15743. customSessionTags:
  15744. additionalProperties:
  15745. type: string
  15746. description: |-
  15747. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  15748. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  15749. type: object
  15750. x-kubernetes-validations:
  15751. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  15752. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  15753. externalID:
  15754. description: AWS External ID set on assumed IAM roles
  15755. type: string
  15756. prefix:
  15757. description: Prefix adds a prefix to all retrieved values.
  15758. type: string
  15759. region:
  15760. description: AWS Region to be used for the provider
  15761. type: string
  15762. role:
  15763. description: Role is a Role ARN which the provider will assume
  15764. type: string
  15765. secretsManager:
  15766. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  15767. properties:
  15768. forceDeleteWithoutRecovery:
  15769. description: |-
  15770. Specifies whether to delete the secret without any recovery window. You
  15771. can't use both this parameter and RecoveryWindowInDays in the same call.
  15772. If you don't use either, then by default Secrets Manager uses a 30 day
  15773. recovery window.
  15774. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  15775. type: boolean
  15776. recoveryWindowInDays:
  15777. description: |-
  15778. The number of days from 7 to 30 that Secrets Manager waits before
  15779. permanently deleting the secret. You can't use both this parameter and
  15780. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  15781. then by default Secrets Manager uses a 30-day recovery window.
  15782. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  15783. format: int64
  15784. type: integer
  15785. type: object
  15786. service:
  15787. description: Service defines which service should be used to fetch the secrets
  15788. enum:
  15789. - SecretsManager
  15790. - ParameterStore
  15791. - CertificateManager
  15792. type: string
  15793. sessionTags:
  15794. description: AWS STS assume role session tags
  15795. items:
  15796. description: |-
  15797. Tag is a key-value pair that can be attached to an AWS resource.
  15798. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  15799. properties:
  15800. key:
  15801. type: string
  15802. value:
  15803. type: string
  15804. required:
  15805. - key
  15806. - value
  15807. type: object
  15808. type: array
  15809. sessionTagsPolicy:
  15810. default: None
  15811. description: |-
  15812. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  15813. None (default): no tags are added.
  15814. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  15815. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  15816. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  15817. enum:
  15818. - None
  15819. - Simple
  15820. - Custom
  15821. type: string
  15822. transitiveTagKeys:
  15823. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  15824. items:
  15825. type: string
  15826. type: array
  15827. required:
  15828. - region
  15829. - service
  15830. type: object
  15831. azurekv:
  15832. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  15833. properties:
  15834. authSecretRef:
  15835. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  15836. properties:
  15837. clientCertificate:
  15838. description: The Azure ClientCertificate of the service principle used for authentication.
  15839. properties:
  15840. key:
  15841. description: |-
  15842. A key in the referenced Secret.
  15843. Some instances of this field may be defaulted, in others it may be required.
  15844. maxLength: 253
  15845. minLength: 1
  15846. pattern: ^[-._a-zA-Z0-9]+$
  15847. type: string
  15848. name:
  15849. description: The name of the Secret resource being referred to.
  15850. maxLength: 253
  15851. minLength: 1
  15852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15853. type: string
  15854. namespace:
  15855. description: |-
  15856. The namespace of the Secret resource being referred to.
  15857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15858. maxLength: 63
  15859. minLength: 1
  15860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15861. type: string
  15862. type: object
  15863. clientId:
  15864. description: The Azure clientId of the service principle or managed identity used for authentication.
  15865. properties:
  15866. key:
  15867. description: |-
  15868. A key in the referenced Secret.
  15869. Some instances of this field may be defaulted, in others it may be required.
  15870. maxLength: 253
  15871. minLength: 1
  15872. pattern: ^[-._a-zA-Z0-9]+$
  15873. type: string
  15874. name:
  15875. description: The name of the Secret resource being referred to.
  15876. maxLength: 253
  15877. minLength: 1
  15878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15879. type: string
  15880. namespace:
  15881. description: |-
  15882. The namespace of the Secret resource being referred to.
  15883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15884. maxLength: 63
  15885. minLength: 1
  15886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15887. type: string
  15888. type: object
  15889. clientSecret:
  15890. description: The Azure ClientSecret of the service principle used for authentication.
  15891. properties:
  15892. key:
  15893. description: |-
  15894. A key in the referenced Secret.
  15895. Some instances of this field may be defaulted, in others it may be required.
  15896. maxLength: 253
  15897. minLength: 1
  15898. pattern: ^[-._a-zA-Z0-9]+$
  15899. type: string
  15900. name:
  15901. description: The name of the Secret resource being referred to.
  15902. maxLength: 253
  15903. minLength: 1
  15904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15905. type: string
  15906. namespace:
  15907. description: |-
  15908. The namespace of the Secret resource being referred to.
  15909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15910. maxLength: 63
  15911. minLength: 1
  15912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15913. type: string
  15914. type: object
  15915. tenantId:
  15916. description: The Azure tenantId of the managed identity used for authentication.
  15917. properties:
  15918. key:
  15919. description: |-
  15920. A key in the referenced Secret.
  15921. Some instances of this field may be defaulted, in others it may be required.
  15922. maxLength: 253
  15923. minLength: 1
  15924. pattern: ^[-._a-zA-Z0-9]+$
  15925. type: string
  15926. name:
  15927. description: The name of the Secret resource being referred to.
  15928. maxLength: 253
  15929. minLength: 1
  15930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15931. type: string
  15932. namespace:
  15933. description: |-
  15934. The namespace of the Secret resource being referred to.
  15935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15936. maxLength: 63
  15937. minLength: 1
  15938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15939. type: string
  15940. type: object
  15941. type: object
  15942. authType:
  15943. default: ServicePrincipal
  15944. description: |-
  15945. Auth type defines how to authenticate to the keyvault service.
  15946. Valid values are:
  15947. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  15948. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  15949. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  15950. enum:
  15951. - ServicePrincipal
  15952. - ManagedIdentity
  15953. - WorkloadIdentity
  15954. type: string
  15955. customCloudConfig:
  15956. description: |-
  15957. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  15958. Required when EnvironmentType is AzureStackCloud.
  15959. Optional for other environment types - useful for Azure China when using Workload Identity
  15960. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  15961. standard China Cloud endpoint (login.chinacloudapi.cn).
  15962. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  15963. configuration is not supported with the legacy go-autorest SDK.
  15964. properties:
  15965. activeDirectoryEndpoint:
  15966. description: |-
  15967. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  15968. Required when using custom cloud configuration
  15969. type: string
  15970. keyVaultDNSSuffix:
  15971. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  15972. type: string
  15973. keyVaultEndpoint:
  15974. description: KeyVaultEndpoint is the Key Vault service endpoint
  15975. type: string
  15976. resourceManagerEndpoint:
  15977. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  15978. type: string
  15979. required:
  15980. - activeDirectoryEndpoint
  15981. type: object
  15982. environmentType:
  15983. default: PublicCloud
  15984. description: |-
  15985. EnvironmentType specifies the Azure cloud environment endpoints to use for
  15986. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  15987. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  15988. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  15989. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  15990. enum:
  15991. - PublicCloud
  15992. - USGovernmentCloud
  15993. - ChinaCloud
  15994. - GermanCloud
  15995. - AzureStackCloud
  15996. type: string
  15997. identityId:
  15998. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  15999. type: string
  16000. serviceAccountRef:
  16001. description: |-
  16002. ServiceAccountRef specified the service account
  16003. that should be used when authenticating with WorkloadIdentity.
  16004. properties:
  16005. audiences:
  16006. description: |-
  16007. Audience specifies the `aud` claim for the service account token
  16008. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16009. then this audiences will be appended to the list
  16010. items:
  16011. type: string
  16012. type: array
  16013. name:
  16014. description: The name of the ServiceAccount resource being referred to.
  16015. maxLength: 253
  16016. minLength: 1
  16017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16018. type: string
  16019. namespace:
  16020. description: |-
  16021. Namespace of the resource being referred to.
  16022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16023. maxLength: 63
  16024. minLength: 1
  16025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16026. type: string
  16027. required:
  16028. - name
  16029. type: object
  16030. tenantId:
  16031. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16032. type: string
  16033. useAzureSDK:
  16034. default: false
  16035. description: |-
  16036. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16037. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16038. type: boolean
  16039. vaultUrl:
  16040. description: Vault Url from which the secrets to be fetched from.
  16041. type: string
  16042. required:
  16043. - vaultUrl
  16044. type: object
  16045. barbican:
  16046. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16047. properties:
  16048. auth:
  16049. description: BarbicanAuth contains the authentication information for Barbican.
  16050. properties:
  16051. password:
  16052. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16053. properties:
  16054. secretRef:
  16055. description: |-
  16056. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16057. In some instances, `key` is a required field.
  16058. properties:
  16059. key:
  16060. description: |-
  16061. A key in the referenced Secret.
  16062. Some instances of this field may be defaulted, in others it may be required.
  16063. maxLength: 253
  16064. minLength: 1
  16065. pattern: ^[-._a-zA-Z0-9]+$
  16066. type: string
  16067. name:
  16068. description: The name of the Secret resource being referred to.
  16069. maxLength: 253
  16070. minLength: 1
  16071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16072. type: string
  16073. namespace:
  16074. description: |-
  16075. The namespace of the Secret resource being referred to.
  16076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16077. maxLength: 63
  16078. minLength: 1
  16079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16080. type: string
  16081. type: object
  16082. required:
  16083. - secretRef
  16084. type: object
  16085. username:
  16086. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16087. maxProperties: 1
  16088. minProperties: 1
  16089. properties:
  16090. secretRef:
  16091. description: |-
  16092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16093. In some instances, `key` is a required field.
  16094. properties:
  16095. key:
  16096. description: |-
  16097. A key in the referenced Secret.
  16098. Some instances of this field may be defaulted, in others it may be required.
  16099. maxLength: 253
  16100. minLength: 1
  16101. pattern: ^[-._a-zA-Z0-9]+$
  16102. type: string
  16103. name:
  16104. description: The name of the Secret resource being referred to.
  16105. maxLength: 253
  16106. minLength: 1
  16107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16108. type: string
  16109. namespace:
  16110. description: |-
  16111. The namespace of the Secret resource being referred to.
  16112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16113. maxLength: 63
  16114. minLength: 1
  16115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16116. type: string
  16117. type: object
  16118. value:
  16119. type: string
  16120. type: object
  16121. required:
  16122. - password
  16123. - username
  16124. type: object
  16125. authURL:
  16126. type: string
  16127. domainName:
  16128. type: string
  16129. region:
  16130. type: string
  16131. tenantName:
  16132. type: string
  16133. required:
  16134. - auth
  16135. type: object
  16136. beyondtrust:
  16137. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16138. properties:
  16139. auth:
  16140. description: Auth configures how the operator authenticates with Beyondtrust.
  16141. properties:
  16142. apiKey:
  16143. description: APIKey If not provided then ClientID/ClientSecret become required.
  16144. properties:
  16145. secretRef:
  16146. description: SecretRef references a key in a secret that will be used as value.
  16147. properties:
  16148. key:
  16149. description: |-
  16150. A key in the referenced Secret.
  16151. Some instances of this field may be defaulted, in others it may be required.
  16152. maxLength: 253
  16153. minLength: 1
  16154. pattern: ^[-._a-zA-Z0-9]+$
  16155. type: string
  16156. name:
  16157. description: The name of the Secret resource being referred to.
  16158. maxLength: 253
  16159. minLength: 1
  16160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16161. type: string
  16162. namespace:
  16163. description: |-
  16164. The namespace of the Secret resource being referred to.
  16165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16166. maxLength: 63
  16167. minLength: 1
  16168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16169. type: string
  16170. type: object
  16171. value:
  16172. description: Value can be specified directly to set a value without using a secret.
  16173. type: string
  16174. type: object
  16175. certificate:
  16176. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16177. properties:
  16178. secretRef:
  16179. description: SecretRef references a key in a secret that will be used as value.
  16180. properties:
  16181. key:
  16182. description: |-
  16183. A key in the referenced Secret.
  16184. Some instances of this field may be defaulted, in others it may be required.
  16185. maxLength: 253
  16186. minLength: 1
  16187. pattern: ^[-._a-zA-Z0-9]+$
  16188. type: string
  16189. name:
  16190. description: The name of the Secret resource being referred to.
  16191. maxLength: 253
  16192. minLength: 1
  16193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16194. type: string
  16195. namespace:
  16196. description: |-
  16197. The namespace of the Secret resource being referred to.
  16198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16199. maxLength: 63
  16200. minLength: 1
  16201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16202. type: string
  16203. type: object
  16204. value:
  16205. description: Value can be specified directly to set a value without using a secret.
  16206. type: string
  16207. type: object
  16208. certificateKey:
  16209. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16210. properties:
  16211. secretRef:
  16212. description: SecretRef references a key in a secret that will be used as value.
  16213. properties:
  16214. key:
  16215. description: |-
  16216. A key in the referenced Secret.
  16217. Some instances of this field may be defaulted, in others it may be required.
  16218. maxLength: 253
  16219. minLength: 1
  16220. pattern: ^[-._a-zA-Z0-9]+$
  16221. type: string
  16222. name:
  16223. description: The name of the Secret resource being referred to.
  16224. maxLength: 253
  16225. minLength: 1
  16226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16227. type: string
  16228. namespace:
  16229. description: |-
  16230. The namespace of the Secret resource being referred to.
  16231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16232. maxLength: 63
  16233. minLength: 1
  16234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16235. type: string
  16236. type: object
  16237. value:
  16238. description: Value can be specified directly to set a value without using a secret.
  16239. type: string
  16240. type: object
  16241. clientId:
  16242. description: ClientID is the API OAuth Client ID.
  16243. properties:
  16244. secretRef:
  16245. description: SecretRef references a key in a secret that will be used as value.
  16246. properties:
  16247. key:
  16248. description: |-
  16249. A key in the referenced Secret.
  16250. Some instances of this field may be defaulted, in others it may be required.
  16251. maxLength: 253
  16252. minLength: 1
  16253. pattern: ^[-._a-zA-Z0-9]+$
  16254. type: string
  16255. name:
  16256. description: The name of the Secret resource being referred to.
  16257. maxLength: 253
  16258. minLength: 1
  16259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16260. type: string
  16261. namespace:
  16262. description: |-
  16263. The namespace of the Secret resource being referred to.
  16264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16265. maxLength: 63
  16266. minLength: 1
  16267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16268. type: string
  16269. type: object
  16270. value:
  16271. description: Value can be specified directly to set a value without using a secret.
  16272. type: string
  16273. type: object
  16274. clientSecret:
  16275. description: ClientSecret is the API OAuth Client Secret.
  16276. properties:
  16277. secretRef:
  16278. description: SecretRef references a key in a secret that will be used as value.
  16279. properties:
  16280. key:
  16281. description: |-
  16282. A key in the referenced Secret.
  16283. Some instances of this field may be defaulted, in others it may be required.
  16284. maxLength: 253
  16285. minLength: 1
  16286. pattern: ^[-._a-zA-Z0-9]+$
  16287. type: string
  16288. name:
  16289. description: The name of the Secret resource being referred to.
  16290. maxLength: 253
  16291. minLength: 1
  16292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16293. type: string
  16294. namespace:
  16295. description: |-
  16296. The namespace of the Secret resource being referred to.
  16297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16298. maxLength: 63
  16299. minLength: 1
  16300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16301. type: string
  16302. type: object
  16303. value:
  16304. description: Value can be specified directly to set a value without using a secret.
  16305. type: string
  16306. type: object
  16307. type: object
  16308. server:
  16309. description: Auth configures how API server works.
  16310. properties:
  16311. apiUrl:
  16312. type: string
  16313. apiVersion:
  16314. type: string
  16315. clientTimeOutSeconds:
  16316. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16317. type: integer
  16318. decrypt:
  16319. default: true
  16320. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16321. type: boolean
  16322. retrievalType:
  16323. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16324. type: string
  16325. separator:
  16326. description: A character that separates the folder names.
  16327. type: string
  16328. verifyCA:
  16329. type: boolean
  16330. required:
  16331. - apiUrl
  16332. - verifyCA
  16333. type: object
  16334. required:
  16335. - auth
  16336. - server
  16337. type: object
  16338. beyondtrustworkloadcredentials:
  16339. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16340. properties:
  16341. auth:
  16342. description: |-
  16343. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16344. Currently supports API key authentication via Kubernetes secret reference.
  16345. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16346. properties:
  16347. apikey:
  16348. description: |-
  16349. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16350. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16351. properties:
  16352. token:
  16353. description: |-
  16354. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16355. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16356. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16357. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16358. properties:
  16359. key:
  16360. description: |-
  16361. A key in the referenced Secret.
  16362. Some instances of this field may be defaulted, in others it may be required.
  16363. maxLength: 253
  16364. minLength: 1
  16365. pattern: ^[-._a-zA-Z0-9]+$
  16366. type: string
  16367. name:
  16368. description: The name of the Secret resource being referred to.
  16369. maxLength: 253
  16370. minLength: 1
  16371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16372. type: string
  16373. namespace:
  16374. description: |-
  16375. The namespace of the Secret resource being referred to.
  16376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16377. maxLength: 63
  16378. minLength: 1
  16379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16380. type: string
  16381. type: object
  16382. required:
  16383. - token
  16384. type: object
  16385. required:
  16386. - apikey
  16387. type: object
  16388. caBundle:
  16389. description: |-
  16390. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16391. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16392. If not set, the system's trusted root certificates are used.
  16393. format: byte
  16394. type: string
  16395. caProvider:
  16396. description: |-
  16397. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16398. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16399. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16400. properties:
  16401. key:
  16402. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16403. maxLength: 253
  16404. minLength: 1
  16405. pattern: ^[-._a-zA-Z0-9]+$
  16406. type: string
  16407. name:
  16408. description: The name of the object located at the provider type.
  16409. maxLength: 253
  16410. minLength: 1
  16411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16412. type: string
  16413. namespace:
  16414. description: |-
  16415. The namespace the Provider type is in.
  16416. Can only be defined when used in a ClusterSecretStore.
  16417. maxLength: 63
  16418. minLength: 1
  16419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16420. type: string
  16421. type:
  16422. description: The type of provider to use such as "Secret", or "ConfigMap".
  16423. enum:
  16424. - Secret
  16425. - ConfigMap
  16426. type: string
  16427. required:
  16428. - name
  16429. - type
  16430. type: object
  16431. folderPath:
  16432. description: |-
  16433. FolderPath specifies the default folder path for secret retrieval.
  16434. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16435. Example: "production/database" or "dev/api-keys"
  16436. Leave empty to retrieve secrets from the root folder.
  16437. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16438. type: string
  16439. server:
  16440. description: |-
  16441. Server configures the BeyondTrust Workload Credentials server connection details.
  16442. Includes the API URL and Site ID for your BeyondTrust instance.
  16443. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16444. properties:
  16445. apiUrl:
  16446. description: |-
  16447. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16448. This should be the full URL to your BeyondTrust instance.
  16449. Example: https://api.beyondtrust.io/siie
  16450. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16451. type: string
  16452. siteId:
  16453. description: |-
  16454. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16455. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16456. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16457. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16458. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16459. type: string
  16460. required:
  16461. - apiUrl
  16462. - siteId
  16463. type: object
  16464. required:
  16465. - auth
  16466. - server
  16467. type: object
  16468. bitwardensecretsmanager:
  16469. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16470. properties:
  16471. apiURL:
  16472. type: string
  16473. auth:
  16474. description: |-
  16475. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16476. Make sure that the token being used has permissions on the given secret.
  16477. properties:
  16478. secretRef:
  16479. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16480. properties:
  16481. credentials:
  16482. description: AccessToken used for the bitwarden instance.
  16483. properties:
  16484. key:
  16485. description: |-
  16486. A key in the referenced Secret.
  16487. Some instances of this field may be defaulted, in others it may be required.
  16488. maxLength: 253
  16489. minLength: 1
  16490. pattern: ^[-._a-zA-Z0-9]+$
  16491. type: string
  16492. name:
  16493. description: The name of the Secret resource being referred to.
  16494. maxLength: 253
  16495. minLength: 1
  16496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16497. type: string
  16498. namespace:
  16499. description: |-
  16500. The namespace of the Secret resource being referred to.
  16501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16502. maxLength: 63
  16503. minLength: 1
  16504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16505. type: string
  16506. type: object
  16507. required:
  16508. - credentials
  16509. type: object
  16510. required:
  16511. - secretRef
  16512. type: object
  16513. bitwardenServerSDKURL:
  16514. type: string
  16515. caBundle:
  16516. description: |-
  16517. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16518. can be performed.
  16519. type: string
  16520. caProvider:
  16521. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16522. properties:
  16523. key:
  16524. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16525. maxLength: 253
  16526. minLength: 1
  16527. pattern: ^[-._a-zA-Z0-9]+$
  16528. type: string
  16529. name:
  16530. description: The name of the object located at the provider type.
  16531. maxLength: 253
  16532. minLength: 1
  16533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16534. type: string
  16535. namespace:
  16536. description: |-
  16537. The namespace the Provider type is in.
  16538. Can only be defined when used in a ClusterSecretStore.
  16539. maxLength: 63
  16540. minLength: 1
  16541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16542. type: string
  16543. type:
  16544. description: The type of provider to use such as "Secret", or "ConfigMap".
  16545. enum:
  16546. - Secret
  16547. - ConfigMap
  16548. type: string
  16549. required:
  16550. - name
  16551. - type
  16552. type: object
  16553. identityURL:
  16554. type: string
  16555. organizationID:
  16556. description: OrganizationID determines which organization this secret store manages.
  16557. type: string
  16558. projectID:
  16559. description: ProjectID determines which project this secret store manages.
  16560. type: string
  16561. required:
  16562. - auth
  16563. - organizationID
  16564. - projectID
  16565. type: object
  16566. chef:
  16567. description: Chef configures this store to sync secrets with chef server
  16568. properties:
  16569. auth:
  16570. description: Auth defines the information necessary to authenticate against chef Server
  16571. properties:
  16572. secretRef:
  16573. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16574. properties:
  16575. privateKeySecretRef:
  16576. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16577. properties:
  16578. key:
  16579. description: |-
  16580. A key in the referenced Secret.
  16581. Some instances of this field may be defaulted, in others it may be required.
  16582. maxLength: 253
  16583. minLength: 1
  16584. pattern: ^[-._a-zA-Z0-9]+$
  16585. type: string
  16586. name:
  16587. description: The name of the Secret resource being referred to.
  16588. maxLength: 253
  16589. minLength: 1
  16590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16591. type: string
  16592. namespace:
  16593. description: |-
  16594. The namespace of the Secret resource being referred to.
  16595. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16596. maxLength: 63
  16597. minLength: 1
  16598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16599. type: string
  16600. type: object
  16601. required:
  16602. - privateKeySecretRef
  16603. type: object
  16604. required:
  16605. - secretRef
  16606. type: object
  16607. serverUrl:
  16608. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16609. type: string
  16610. username:
  16611. description: UserName should be the user ID on the chef server
  16612. type: string
  16613. required:
  16614. - auth
  16615. - serverUrl
  16616. - username
  16617. type: object
  16618. cloudrusm:
  16619. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16620. properties:
  16621. auth:
  16622. description: CSMAuth contains a secretRef for credentials.
  16623. properties:
  16624. secretRef:
  16625. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16626. properties:
  16627. accessKeyIDSecretRef:
  16628. description: The AccessKeyID is used for authentication
  16629. properties:
  16630. key:
  16631. description: |-
  16632. A key in the referenced Secret.
  16633. Some instances of this field may be defaulted, in others it may be required.
  16634. maxLength: 253
  16635. minLength: 1
  16636. pattern: ^[-._a-zA-Z0-9]+$
  16637. type: string
  16638. name:
  16639. description: The name of the Secret resource being referred to.
  16640. maxLength: 253
  16641. minLength: 1
  16642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16643. type: string
  16644. namespace:
  16645. description: |-
  16646. The namespace of the Secret resource being referred to.
  16647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16648. maxLength: 63
  16649. minLength: 1
  16650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16651. type: string
  16652. type: object
  16653. accessKeySecretSecretRef:
  16654. description: The AccessKeySecret is used for authentication
  16655. properties:
  16656. key:
  16657. description: |-
  16658. A key in the referenced Secret.
  16659. Some instances of this field may be defaulted, in others it may be required.
  16660. maxLength: 253
  16661. minLength: 1
  16662. pattern: ^[-._a-zA-Z0-9]+$
  16663. type: string
  16664. name:
  16665. description: The name of the Secret resource being referred to.
  16666. maxLength: 253
  16667. minLength: 1
  16668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16669. type: string
  16670. namespace:
  16671. description: |-
  16672. The namespace of the Secret resource being referred to.
  16673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16674. maxLength: 63
  16675. minLength: 1
  16676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16677. type: string
  16678. type: object
  16679. required:
  16680. - accessKeyIDSecretRef
  16681. - accessKeySecretSecretRef
  16682. type: object
  16683. type: object
  16684. projectID:
  16685. description: ProjectID is the project, which the secrets are stored in.
  16686. type: string
  16687. required:
  16688. - auth
  16689. type: object
  16690. conjur:
  16691. description: Conjur configures this store to sync secrets using conjur provider
  16692. properties:
  16693. auth:
  16694. description: Defines authentication settings for connecting to Conjur.
  16695. maxProperties: 1
  16696. minProperties: 1
  16697. properties:
  16698. apikey:
  16699. description: Authenticates with Conjur using an API key.
  16700. properties:
  16701. account:
  16702. description: Account is the Conjur organization account name.
  16703. type: string
  16704. apiKeyRef:
  16705. description: |-
  16706. A reference to a specific 'key' containing the Conjur API key
  16707. within a Secret resource. In some instances, `key` is a required field.
  16708. properties:
  16709. key:
  16710. description: |-
  16711. A key in the referenced Secret.
  16712. Some instances of this field may be defaulted, in others it may be required.
  16713. maxLength: 253
  16714. minLength: 1
  16715. pattern: ^[-._a-zA-Z0-9]+$
  16716. type: string
  16717. name:
  16718. description: The name of the Secret resource being referred to.
  16719. maxLength: 253
  16720. minLength: 1
  16721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16722. type: string
  16723. namespace:
  16724. description: |-
  16725. The namespace of the Secret resource being referred to.
  16726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16727. maxLength: 63
  16728. minLength: 1
  16729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16730. type: string
  16731. type: object
  16732. userRef:
  16733. description: |-
  16734. A reference to a specific 'key' containing the Conjur username
  16735. within a Secret resource. In some instances, `key` is a required field.
  16736. properties:
  16737. key:
  16738. description: |-
  16739. A key in the referenced Secret.
  16740. Some instances of this field may be defaulted, in others it may be required.
  16741. maxLength: 253
  16742. minLength: 1
  16743. pattern: ^[-._a-zA-Z0-9]+$
  16744. type: string
  16745. name:
  16746. description: The name of the Secret resource being referred to.
  16747. maxLength: 253
  16748. minLength: 1
  16749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16750. type: string
  16751. namespace:
  16752. description: |-
  16753. The namespace of the Secret resource being referred to.
  16754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16755. maxLength: 63
  16756. minLength: 1
  16757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16758. type: string
  16759. type: object
  16760. required:
  16761. - account
  16762. - apiKeyRef
  16763. - userRef
  16764. type: object
  16765. cert:
  16766. description: Cert enables certificate-based authentication using a client certificate and key.
  16767. properties:
  16768. account:
  16769. description: Account is the Conjur organization account name.
  16770. type: string
  16771. clientCertRef:
  16772. description: |-
  16773. ClientCertRef is a reference to a specific 'key' containing the client certificate
  16774. within a Secret resource. The certificate must be PEM-encoded.
  16775. properties:
  16776. key:
  16777. description: |-
  16778. A key in the referenced Secret.
  16779. Some instances of this field may be defaulted, in others it may be required.
  16780. maxLength: 253
  16781. minLength: 1
  16782. pattern: ^[-._a-zA-Z0-9]+$
  16783. type: string
  16784. name:
  16785. description: The name of the Secret resource being referred to.
  16786. maxLength: 253
  16787. minLength: 1
  16788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16789. type: string
  16790. namespace:
  16791. description: |-
  16792. The namespace of the Secret resource being referred to.
  16793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16794. maxLength: 63
  16795. minLength: 1
  16796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16797. type: string
  16798. type: object
  16799. clientKeyRef:
  16800. description: |-
  16801. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  16802. within a Secret resource. The key must be PEM-encoded.
  16803. properties:
  16804. key:
  16805. description: |-
  16806. A key in the referenced Secret.
  16807. Some instances of this field may be defaulted, in others it may be required.
  16808. maxLength: 253
  16809. minLength: 1
  16810. pattern: ^[-._a-zA-Z0-9]+$
  16811. type: string
  16812. name:
  16813. description: The name of the Secret resource being referred to.
  16814. maxLength: 253
  16815. minLength: 1
  16816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16817. type: string
  16818. namespace:
  16819. description: |-
  16820. The namespace of the Secret resource being referred to.
  16821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16822. maxLength: 63
  16823. minLength: 1
  16824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16825. type: string
  16826. type: object
  16827. hostId:
  16828. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  16829. type: string
  16830. serviceID:
  16831. description: The conjur authn cert webservice id
  16832. type: string
  16833. required:
  16834. - account
  16835. - clientCertRef
  16836. - clientKeyRef
  16837. - serviceID
  16838. type: object
  16839. jwt:
  16840. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  16841. properties:
  16842. account:
  16843. description: Account is the Conjur organization account name.
  16844. type: string
  16845. hostId:
  16846. description: |-
  16847. Optional HostID for JWT authentication. This may be used depending
  16848. on how the Conjur JWT authenticator policy is configured.
  16849. type: string
  16850. secretRef:
  16851. description: |-
  16852. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  16853. authenticate with Conjur using the JWT authentication method.
  16854. properties:
  16855. key:
  16856. description: |-
  16857. A key in the referenced Secret.
  16858. Some instances of this field may be defaulted, in others it may be required.
  16859. maxLength: 253
  16860. minLength: 1
  16861. pattern: ^[-._a-zA-Z0-9]+$
  16862. type: string
  16863. name:
  16864. description: The name of the Secret resource being referred to.
  16865. maxLength: 253
  16866. minLength: 1
  16867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16868. type: string
  16869. namespace:
  16870. description: |-
  16871. The namespace of the Secret resource being referred to.
  16872. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16873. maxLength: 63
  16874. minLength: 1
  16875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16876. type: string
  16877. type: object
  16878. serviceAccountRef:
  16879. description: |-
  16880. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  16881. a token for with the `TokenRequest` API.
  16882. properties:
  16883. audiences:
  16884. description: |-
  16885. Audience specifies the `aud` claim for the service account token
  16886. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16887. then this audiences will be appended to the list
  16888. items:
  16889. type: string
  16890. type: array
  16891. name:
  16892. description: The name of the ServiceAccount resource being referred to.
  16893. maxLength: 253
  16894. minLength: 1
  16895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16896. type: string
  16897. namespace:
  16898. description: |-
  16899. Namespace of the resource being referred to.
  16900. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16901. maxLength: 63
  16902. minLength: 1
  16903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16904. type: string
  16905. required:
  16906. - name
  16907. type: object
  16908. serviceID:
  16909. description: The conjur authn jwt webservice id
  16910. type: string
  16911. required:
  16912. - account
  16913. - serviceID
  16914. type: object
  16915. type: object
  16916. caBundle:
  16917. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  16918. type: string
  16919. caProvider:
  16920. description: |-
  16921. Used to provide custom certificate authority (CA) certificates
  16922. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  16923. that contains a PEM-encoded certificate.
  16924. properties:
  16925. key:
  16926. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16927. maxLength: 253
  16928. minLength: 1
  16929. pattern: ^[-._a-zA-Z0-9]+$
  16930. type: string
  16931. name:
  16932. description: The name of the object located at the provider type.
  16933. maxLength: 253
  16934. minLength: 1
  16935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16936. type: string
  16937. namespace:
  16938. description: |-
  16939. The namespace the Provider type is in.
  16940. Can only be defined when used in a ClusterSecretStore.
  16941. maxLength: 63
  16942. minLength: 1
  16943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16944. type: string
  16945. type:
  16946. description: The type of provider to use such as "Secret", or "ConfigMap".
  16947. enum:
  16948. - Secret
  16949. - ConfigMap
  16950. type: string
  16951. required:
  16952. - name
  16953. - type
  16954. type: object
  16955. url:
  16956. description: URL is the endpoint of the Conjur instance.
  16957. type: string
  16958. required:
  16959. - auth
  16960. - url
  16961. type: object
  16962. delinea:
  16963. description: |-
  16964. Delinea DevOps Secrets Vault
  16965. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  16966. properties:
  16967. clientId:
  16968. description: ClientID is the non-secret part of the credential.
  16969. properties:
  16970. secretRef:
  16971. description: SecretRef references a key in a secret that will be used as value.
  16972. properties:
  16973. key:
  16974. description: |-
  16975. A key in the referenced Secret.
  16976. Some instances of this field may be defaulted, in others it may be required.
  16977. maxLength: 253
  16978. minLength: 1
  16979. pattern: ^[-._a-zA-Z0-9]+$
  16980. type: string
  16981. name:
  16982. description: The name of the Secret resource being referred to.
  16983. maxLength: 253
  16984. minLength: 1
  16985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16986. type: string
  16987. namespace:
  16988. description: |-
  16989. The namespace of the Secret resource being referred to.
  16990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16991. maxLength: 63
  16992. minLength: 1
  16993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16994. type: string
  16995. type: object
  16996. value:
  16997. description: Value can be specified directly to set a value without using a secret.
  16998. type: string
  16999. type: object
  17000. clientSecret:
  17001. description: ClientSecret is the secret part of the credential.
  17002. properties:
  17003. secretRef:
  17004. description: SecretRef references a key in a secret that will be used as value.
  17005. properties:
  17006. key:
  17007. description: |-
  17008. A key in the referenced Secret.
  17009. Some instances of this field may be defaulted, in others it may be required.
  17010. maxLength: 253
  17011. minLength: 1
  17012. pattern: ^[-._a-zA-Z0-9]+$
  17013. type: string
  17014. name:
  17015. description: The name of the Secret resource being referred to.
  17016. maxLength: 253
  17017. minLength: 1
  17018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17019. type: string
  17020. namespace:
  17021. description: |-
  17022. The namespace of the Secret resource being referred to.
  17023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17024. maxLength: 63
  17025. minLength: 1
  17026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17027. type: string
  17028. type: object
  17029. value:
  17030. description: Value can be specified directly to set a value without using a secret.
  17031. type: string
  17032. type: object
  17033. tenant:
  17034. description: Tenant is the chosen hostname / site name.
  17035. type: string
  17036. tld:
  17037. description: |-
  17038. TLD is based on the server location that was chosen during provisioning.
  17039. If unset, defaults to "com".
  17040. type: string
  17041. urlTemplate:
  17042. description: |-
  17043. URLTemplate
  17044. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17045. type: string
  17046. required:
  17047. - clientId
  17048. - clientSecret
  17049. - tenant
  17050. type: object
  17051. doppler:
  17052. description: Doppler configures this store to sync secrets using the Doppler provider
  17053. properties:
  17054. auth:
  17055. description: Auth configures how the Operator authenticates with the Doppler API
  17056. properties:
  17057. oidcConfig:
  17058. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17059. properties:
  17060. expirationSeconds:
  17061. default: 600
  17062. description: |-
  17063. ExpirationSeconds sets the ServiceAccount token validity duration.
  17064. Defaults to 10 minutes.
  17065. format: int64
  17066. type: integer
  17067. identity:
  17068. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17069. type: string
  17070. serviceAccountRef:
  17071. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17072. properties:
  17073. audiences:
  17074. description: |-
  17075. Audience specifies the `aud` claim for the service account token
  17076. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17077. then this audiences will be appended to the list
  17078. items:
  17079. type: string
  17080. type: array
  17081. name:
  17082. description: The name of the ServiceAccount resource being referred to.
  17083. maxLength: 253
  17084. minLength: 1
  17085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17086. type: string
  17087. namespace:
  17088. description: |-
  17089. Namespace of the resource being referred to.
  17090. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17091. maxLength: 63
  17092. minLength: 1
  17093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17094. type: string
  17095. required:
  17096. - name
  17097. type: object
  17098. required:
  17099. - identity
  17100. - serviceAccountRef
  17101. type: object
  17102. secretRef:
  17103. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17104. properties:
  17105. dopplerToken:
  17106. description: |-
  17107. The DopplerToken is used for authentication.
  17108. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17109. The Key attribute defaults to dopplerToken if not specified.
  17110. properties:
  17111. key:
  17112. description: |-
  17113. A key in the referenced Secret.
  17114. Some instances of this field may be defaulted, in others it may be required.
  17115. maxLength: 253
  17116. minLength: 1
  17117. pattern: ^[-._a-zA-Z0-9]+$
  17118. type: string
  17119. name:
  17120. description: The name of the Secret resource being referred to.
  17121. maxLength: 253
  17122. minLength: 1
  17123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17124. type: string
  17125. namespace:
  17126. description: |-
  17127. The namespace of the Secret resource being referred to.
  17128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17129. maxLength: 63
  17130. minLength: 1
  17131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17132. type: string
  17133. type: object
  17134. required:
  17135. - dopplerToken
  17136. type: object
  17137. type: object
  17138. x-kubernetes-validations:
  17139. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17140. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17141. config:
  17142. description: Doppler config (required if not using a Service Token)
  17143. type: string
  17144. format:
  17145. description: Format enables the downloading of secrets as a file (string)
  17146. enum:
  17147. - json
  17148. - dotnet-json
  17149. - env
  17150. - yaml
  17151. - docker
  17152. type: string
  17153. nameTransformer:
  17154. description: Environment variable compatible name transforms that change secret names to a different format
  17155. enum:
  17156. - upper-camel
  17157. - camel
  17158. - lower-snake
  17159. - tf-var
  17160. - dotnet-env
  17161. - lower-kebab
  17162. type: string
  17163. project:
  17164. description: Doppler project (required if not using a Service Token)
  17165. type: string
  17166. required:
  17167. - auth
  17168. type: object
  17169. dvls:
  17170. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17171. properties:
  17172. auth:
  17173. description: Auth defines the authentication method to use.
  17174. properties:
  17175. secretRef:
  17176. description: SecretRef contains the Application ID and Application Secret for authentication.
  17177. properties:
  17178. appId:
  17179. description: AppID is the reference to the secret containing the Application ID.
  17180. properties:
  17181. key:
  17182. description: |-
  17183. A key in the referenced Secret.
  17184. Some instances of this field may be defaulted, in others it may be required.
  17185. maxLength: 253
  17186. minLength: 1
  17187. pattern: ^[-._a-zA-Z0-9]+$
  17188. type: string
  17189. name:
  17190. description: The name of the Secret resource being referred to.
  17191. maxLength: 253
  17192. minLength: 1
  17193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17194. type: string
  17195. namespace:
  17196. description: |-
  17197. The namespace of the Secret resource being referred to.
  17198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17199. maxLength: 63
  17200. minLength: 1
  17201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17202. type: string
  17203. type: object
  17204. appSecret:
  17205. description: AppSecret is the reference to the secret containing the Application Secret.
  17206. properties:
  17207. key:
  17208. description: |-
  17209. A key in the referenced Secret.
  17210. Some instances of this field may be defaulted, in others it may be required.
  17211. maxLength: 253
  17212. minLength: 1
  17213. pattern: ^[-._a-zA-Z0-9]+$
  17214. type: string
  17215. name:
  17216. description: The name of the Secret resource being referred to.
  17217. maxLength: 253
  17218. minLength: 1
  17219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17220. type: string
  17221. namespace:
  17222. description: |-
  17223. The namespace of the Secret resource being referred to.
  17224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17225. maxLength: 63
  17226. minLength: 1
  17227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17228. type: string
  17229. type: object
  17230. required:
  17231. - appId
  17232. - appSecret
  17233. type: object
  17234. required:
  17235. - secretRef
  17236. type: object
  17237. insecure:
  17238. description: |-
  17239. Insecure allows connecting to DVLS over plain HTTP.
  17240. This is NOT RECOMMENDED for production use.
  17241. Set to true only if you understand the security implications.
  17242. type: boolean
  17243. serverUrl:
  17244. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17245. type: string
  17246. vault:
  17247. description: |-
  17248. Vault is the name or UUID of the vault to fetch secrets from.
  17249. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17250. type: string
  17251. required:
  17252. - auth
  17253. - serverUrl
  17254. type: object
  17255. fake:
  17256. description: Fake configures a store with static key/value pairs
  17257. properties:
  17258. data:
  17259. items:
  17260. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17261. properties:
  17262. key:
  17263. type: string
  17264. value:
  17265. type: string
  17266. version:
  17267. type: string
  17268. required:
  17269. - key
  17270. - value
  17271. type: object
  17272. type: array
  17273. validationResult:
  17274. description: ValidationResult is defined type for the number of validation results.
  17275. type: integer
  17276. required:
  17277. - data
  17278. type: object
  17279. fortanix:
  17280. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17281. properties:
  17282. apiKey:
  17283. description: APIKey is the API token to access SDKMS Applications.
  17284. properties:
  17285. secretRef:
  17286. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17287. properties:
  17288. key:
  17289. description: |-
  17290. A key in the referenced Secret.
  17291. Some instances of this field may be defaulted, in others it may be required.
  17292. maxLength: 253
  17293. minLength: 1
  17294. pattern: ^[-._a-zA-Z0-9]+$
  17295. type: string
  17296. name:
  17297. description: The name of the Secret resource being referred to.
  17298. maxLength: 253
  17299. minLength: 1
  17300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17301. type: string
  17302. namespace:
  17303. description: |-
  17304. The namespace of the Secret resource being referred to.
  17305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17306. maxLength: 63
  17307. minLength: 1
  17308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17309. type: string
  17310. type: object
  17311. type: object
  17312. apiUrl:
  17313. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17314. type: string
  17315. type: object
  17316. gcpsm:
  17317. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17318. properties:
  17319. auth:
  17320. description: Auth defines the information necessary to authenticate against GCP
  17321. properties:
  17322. secretRef:
  17323. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17324. properties:
  17325. secretAccessKeySecretRef:
  17326. description: The SecretAccessKey is used for authentication
  17327. properties:
  17328. key:
  17329. description: |-
  17330. A key in the referenced Secret.
  17331. Some instances of this field may be defaulted, in others it may be required.
  17332. maxLength: 253
  17333. minLength: 1
  17334. pattern: ^[-._a-zA-Z0-9]+$
  17335. type: string
  17336. name:
  17337. description: The name of the Secret resource being referred to.
  17338. maxLength: 253
  17339. minLength: 1
  17340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17341. type: string
  17342. namespace:
  17343. description: |-
  17344. The namespace of the Secret resource being referred to.
  17345. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17346. maxLength: 63
  17347. minLength: 1
  17348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17349. type: string
  17350. type: object
  17351. type: object
  17352. workloadIdentity:
  17353. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17354. properties:
  17355. clusterLocation:
  17356. description: |-
  17357. ClusterLocation is the location of the cluster
  17358. If not specified, it fetches information from the metadata server
  17359. type: string
  17360. clusterName:
  17361. description: |-
  17362. ClusterName is the name of the cluster
  17363. If not specified, it fetches information from the metadata server
  17364. type: string
  17365. clusterProjectID:
  17366. description: |-
  17367. ClusterProjectID is the project ID of the cluster
  17368. If not specified, it fetches information from the metadata server
  17369. type: string
  17370. serviceAccountRef:
  17371. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17372. properties:
  17373. audiences:
  17374. description: |-
  17375. Audience specifies the `aud` claim for the service account token
  17376. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17377. then this audiences will be appended to the list
  17378. items:
  17379. type: string
  17380. type: array
  17381. name:
  17382. description: The name of the ServiceAccount resource being referred to.
  17383. maxLength: 253
  17384. minLength: 1
  17385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17386. type: string
  17387. namespace:
  17388. description: |-
  17389. Namespace of the resource being referred to.
  17390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17391. maxLength: 63
  17392. minLength: 1
  17393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17394. type: string
  17395. required:
  17396. - name
  17397. type: object
  17398. required:
  17399. - serviceAccountRef
  17400. type: object
  17401. workloadIdentityFederation:
  17402. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17403. properties:
  17404. audience:
  17405. description: |-
  17406. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17407. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17408. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17409. type: string
  17410. awsSecurityCredentials:
  17411. description: |-
  17412. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  17413. when using the AWS metadata server is not an option.
  17414. properties:
  17415. awsCredentialsSecretRef:
  17416. description: |-
  17417. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  17418. Secret should be created with below names for keys
  17419. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  17420. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  17421. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  17422. properties:
  17423. name:
  17424. description: name of the secret.
  17425. maxLength: 253
  17426. minLength: 1
  17427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17428. type: string
  17429. namespace:
  17430. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  17431. maxLength: 63
  17432. minLength: 1
  17433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17434. type: string
  17435. required:
  17436. - name
  17437. type: object
  17438. region:
  17439. description: region is for configuring the AWS region to be used.
  17440. example: ap-south-1
  17441. maxLength: 50
  17442. minLength: 1
  17443. pattern: ^[a-z0-9-]+$
  17444. type: string
  17445. required:
  17446. - awsCredentialsSecretRef
  17447. - region
  17448. type: object
  17449. credConfig:
  17450. description: |-
  17451. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  17452. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  17453. serviceAccountRef must be used by providing operators service account details.
  17454. properties:
  17455. key:
  17456. description: key name holding the external account credential config.
  17457. maxLength: 253
  17458. minLength: 1
  17459. pattern: ^[-._a-zA-Z0-9]+$
  17460. type: string
  17461. name:
  17462. description: name of the configmap.
  17463. maxLength: 253
  17464. minLength: 1
  17465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17466. type: string
  17467. namespace:
  17468. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  17469. maxLength: 63
  17470. minLength: 1
  17471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17472. type: string
  17473. required:
  17474. - key
  17475. - name
  17476. type: object
  17477. externalTokenEndpoint:
  17478. description: |-
  17479. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  17480. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  17481. URL is having the expected value.
  17482. type: string
  17483. gcpServiceAccountEmail:
  17484. description: |-
  17485. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  17486. after Workload Identity Federation. Use this to grant access through the service account's
  17487. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  17488. service_account_impersonation_url in the external account JSON from credConfig;
  17489. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  17490. on that ServiceAccount.
  17491. example: my-gsa@my-project.iam.gserviceaccount.com
  17492. minLength: 1
  17493. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  17494. type: string
  17495. serviceAccountRef:
  17496. description: |-
  17497. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  17498. when Kubernetes is configured as provider in workload identity pool.
  17499. properties:
  17500. audiences:
  17501. description: |-
  17502. Audience specifies the `aud` claim for the service account token
  17503. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17504. then this audiences will be appended to the list
  17505. items:
  17506. type: string
  17507. type: array
  17508. name:
  17509. description: The name of the ServiceAccount resource being referred to.
  17510. maxLength: 253
  17511. minLength: 1
  17512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17513. type: string
  17514. namespace:
  17515. description: |-
  17516. Namespace of the resource being referred to.
  17517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17518. maxLength: 63
  17519. minLength: 1
  17520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17521. type: string
  17522. required:
  17523. - name
  17524. type: object
  17525. type: object
  17526. type: object
  17527. location:
  17528. description: Location optionally defines a location for a secret
  17529. type: string
  17530. projectID:
  17531. description: ProjectID project where secret is located
  17532. type: string
  17533. secretVersionSelectionPolicy:
  17534. default: LatestOrFail
  17535. description: |-
  17536. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  17537. when "latest" is disabled or destroyed.
  17538. Possible values are:
  17539. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  17540. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  17541. type: string
  17542. type: object
  17543. github:
  17544. description: |-
  17545. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  17546. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  17547. properties:
  17548. appID:
  17549. description: appID specifies the Github APP that will be used to authenticate the client
  17550. format: int64
  17551. type: integer
  17552. auth:
  17553. description: auth configures how secret-manager authenticates with a Github instance.
  17554. properties:
  17555. privateKey:
  17556. description: |-
  17557. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17558. In some instances, `key` is a required field.
  17559. properties:
  17560. key:
  17561. description: |-
  17562. A key in the referenced Secret.
  17563. Some instances of this field may be defaulted, in others it may be required.
  17564. maxLength: 253
  17565. minLength: 1
  17566. pattern: ^[-._a-zA-Z0-9]+$
  17567. type: string
  17568. name:
  17569. description: The name of the Secret resource being referred to.
  17570. maxLength: 253
  17571. minLength: 1
  17572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17573. type: string
  17574. namespace:
  17575. description: |-
  17576. The namespace of the Secret resource being referred to.
  17577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17578. maxLength: 63
  17579. minLength: 1
  17580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17581. type: string
  17582. type: object
  17583. required:
  17584. - privateKey
  17585. type: object
  17586. environment:
  17587. description: environment will be used to fetch secrets from a particular environment within a github repository
  17588. type: string
  17589. installationID:
  17590. description: installationID specifies the Github APP installation that will be used to authenticate the client
  17591. format: int64
  17592. type: integer
  17593. orgSecretVisibility:
  17594. description: |-
  17595. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  17596. Valid values are "all" or "private".
  17597. When unset, new secrets are created with visibility "all" and existing secrets preserve
  17598. whatever visibility they already have in GitHub.
  17599. enum:
  17600. - all
  17601. - private
  17602. type: string
  17603. organization:
  17604. description: organization will be used to fetch secrets from the Github organization
  17605. type: string
  17606. repository:
  17607. description: repository will be used to fetch secrets from the Github repository within an organization
  17608. type: string
  17609. uploadURL:
  17610. description: Upload URL for enterprise instances. Default to URL.
  17611. type: string
  17612. url:
  17613. default: https://github.com/
  17614. description: URL configures the Github instance URL. Defaults to https://github.com/.
  17615. type: string
  17616. required:
  17617. - appID
  17618. - auth
  17619. - installationID
  17620. - organization
  17621. type: object
  17622. gitlab:
  17623. description: GitLab configures this store to sync secrets using GitLab Variables provider
  17624. properties:
  17625. auth:
  17626. description: Auth configures how secret-manager authenticates with a GitLab instance.
  17627. properties:
  17628. SecretRef:
  17629. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  17630. properties:
  17631. accessToken:
  17632. description: AccessToken is used for authentication.
  17633. properties:
  17634. key:
  17635. description: |-
  17636. A key in the referenced Secret.
  17637. Some instances of this field may be defaulted, in others it may be required.
  17638. maxLength: 253
  17639. minLength: 1
  17640. pattern: ^[-._a-zA-Z0-9]+$
  17641. type: string
  17642. name:
  17643. description: The name of the Secret resource being referred to.
  17644. maxLength: 253
  17645. minLength: 1
  17646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17647. type: string
  17648. namespace:
  17649. description: |-
  17650. The namespace of the Secret resource being referred to.
  17651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17652. maxLength: 63
  17653. minLength: 1
  17654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17655. type: string
  17656. type: object
  17657. type: object
  17658. required:
  17659. - SecretRef
  17660. type: object
  17661. caBundle:
  17662. description: |-
  17663. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  17664. can be performed.
  17665. format: byte
  17666. type: string
  17667. caProvider:
  17668. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17669. properties:
  17670. key:
  17671. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17672. maxLength: 253
  17673. minLength: 1
  17674. pattern: ^[-._a-zA-Z0-9]+$
  17675. type: string
  17676. name:
  17677. description: The name of the object located at the provider type.
  17678. maxLength: 253
  17679. minLength: 1
  17680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17681. type: string
  17682. namespace:
  17683. description: |-
  17684. The namespace the Provider type is in.
  17685. Can only be defined when used in a ClusterSecretStore.
  17686. maxLength: 63
  17687. minLength: 1
  17688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17689. type: string
  17690. type:
  17691. description: The type of provider to use such as "Secret", or "ConfigMap".
  17692. enum:
  17693. - Secret
  17694. - ConfigMap
  17695. type: string
  17696. required:
  17697. - name
  17698. - type
  17699. type: object
  17700. environment:
  17701. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  17702. type: string
  17703. groupIDs:
  17704. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  17705. items:
  17706. type: string
  17707. type: array
  17708. inheritFromGroups:
  17709. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  17710. type: boolean
  17711. projectID:
  17712. description: ProjectID specifies a project where secrets are located.
  17713. type: string
  17714. url:
  17715. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  17716. type: string
  17717. required:
  17718. - auth
  17719. type: object
  17720. ibm:
  17721. description: IBM configures this store to sync secrets using IBM Cloud provider
  17722. properties:
  17723. auth:
  17724. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  17725. maxProperties: 1
  17726. minProperties: 1
  17727. properties:
  17728. containerAuth:
  17729. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  17730. properties:
  17731. iamEndpoint:
  17732. type: string
  17733. profile:
  17734. description: the IBM Trusted Profile
  17735. type: string
  17736. tokenLocation:
  17737. description: Location the token is mounted on the pod
  17738. type: string
  17739. required:
  17740. - profile
  17741. type: object
  17742. secretRef:
  17743. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  17744. properties:
  17745. iamEndpoint:
  17746. description: The IAM endpoint used to obain a token
  17747. type: string
  17748. secretApiKeySecretRef:
  17749. description: The SecretAccessKey is used for authentication
  17750. properties:
  17751. key:
  17752. description: |-
  17753. A key in the referenced Secret.
  17754. Some instances of this field may be defaulted, in others it may be required.
  17755. maxLength: 253
  17756. minLength: 1
  17757. pattern: ^[-._a-zA-Z0-9]+$
  17758. type: string
  17759. name:
  17760. description: The name of the Secret resource being referred to.
  17761. maxLength: 253
  17762. minLength: 1
  17763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17764. type: string
  17765. namespace:
  17766. description: |-
  17767. The namespace of the Secret resource being referred to.
  17768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17769. maxLength: 63
  17770. minLength: 1
  17771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17772. type: string
  17773. type: object
  17774. type: object
  17775. type: object
  17776. serviceUrl:
  17777. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  17778. type: string
  17779. required:
  17780. - auth
  17781. type: object
  17782. infisical:
  17783. description: Infisical configures this store to sync secrets using the Infisical provider
  17784. properties:
  17785. auth:
  17786. description: Auth configures how the Operator authenticates with the Infisical API
  17787. properties:
  17788. awsAuthCredentials:
  17789. description: AwsAuthCredentials represents the credentials for AWS authentication.
  17790. properties:
  17791. identityId:
  17792. description: |-
  17793. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17794. In some instances, `key` is a required field.
  17795. properties:
  17796. key:
  17797. description: |-
  17798. A key in the referenced Secret.
  17799. Some instances of this field may be defaulted, in others it may be required.
  17800. maxLength: 253
  17801. minLength: 1
  17802. pattern: ^[-._a-zA-Z0-9]+$
  17803. type: string
  17804. name:
  17805. description: The name of the Secret resource being referred to.
  17806. maxLength: 253
  17807. minLength: 1
  17808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17809. type: string
  17810. namespace:
  17811. description: |-
  17812. The namespace of the Secret resource being referred to.
  17813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17814. maxLength: 63
  17815. minLength: 1
  17816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17817. type: string
  17818. type: object
  17819. required:
  17820. - identityId
  17821. type: object
  17822. azureAuthCredentials:
  17823. description: AzureAuthCredentials represents the credentials for Azure authentication.
  17824. properties:
  17825. identityId:
  17826. description: |-
  17827. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17828. In some instances, `key` is a required field.
  17829. properties:
  17830. key:
  17831. description: |-
  17832. A key in the referenced Secret.
  17833. Some instances of this field may be defaulted, in others it may be required.
  17834. maxLength: 253
  17835. minLength: 1
  17836. pattern: ^[-._a-zA-Z0-9]+$
  17837. type: string
  17838. name:
  17839. description: The name of the Secret resource being referred to.
  17840. maxLength: 253
  17841. minLength: 1
  17842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17843. type: string
  17844. namespace:
  17845. description: |-
  17846. The namespace of the Secret resource being referred to.
  17847. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17848. maxLength: 63
  17849. minLength: 1
  17850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17851. type: string
  17852. type: object
  17853. resource:
  17854. description: |-
  17855. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17856. In some instances, `key` is a required field.
  17857. properties:
  17858. key:
  17859. description: |-
  17860. A key in the referenced Secret.
  17861. Some instances of this field may be defaulted, in others it may be required.
  17862. maxLength: 253
  17863. minLength: 1
  17864. pattern: ^[-._a-zA-Z0-9]+$
  17865. type: string
  17866. name:
  17867. description: The name of the Secret resource being referred to.
  17868. maxLength: 253
  17869. minLength: 1
  17870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17871. type: string
  17872. namespace:
  17873. description: |-
  17874. The namespace of the Secret resource being referred to.
  17875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17876. maxLength: 63
  17877. minLength: 1
  17878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17879. type: string
  17880. type: object
  17881. required:
  17882. - identityId
  17883. type: object
  17884. gcpIamAuthCredentials:
  17885. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  17886. properties:
  17887. identityId:
  17888. description: |-
  17889. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17890. In some instances, `key` is a required field.
  17891. properties:
  17892. key:
  17893. description: |-
  17894. A key in the referenced Secret.
  17895. Some instances of this field may be defaulted, in others it may be required.
  17896. maxLength: 253
  17897. minLength: 1
  17898. pattern: ^[-._a-zA-Z0-9]+$
  17899. type: string
  17900. name:
  17901. description: The name of the Secret resource being referred to.
  17902. maxLength: 253
  17903. minLength: 1
  17904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17905. type: string
  17906. namespace:
  17907. description: |-
  17908. The namespace of the Secret resource being referred to.
  17909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17910. maxLength: 63
  17911. minLength: 1
  17912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17913. type: string
  17914. type: object
  17915. serviceAccountKeyFilePath:
  17916. description: |-
  17917. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17918. In some instances, `key` is a required field.
  17919. properties:
  17920. key:
  17921. description: |-
  17922. A key in the referenced Secret.
  17923. Some instances of this field may be defaulted, in others it may be required.
  17924. maxLength: 253
  17925. minLength: 1
  17926. pattern: ^[-._a-zA-Z0-9]+$
  17927. type: string
  17928. name:
  17929. description: The name of the Secret resource being referred to.
  17930. maxLength: 253
  17931. minLength: 1
  17932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17933. type: string
  17934. namespace:
  17935. description: |-
  17936. The namespace of the Secret resource being referred to.
  17937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17938. maxLength: 63
  17939. minLength: 1
  17940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17941. type: string
  17942. type: object
  17943. required:
  17944. - identityId
  17945. - serviceAccountKeyFilePath
  17946. type: object
  17947. gcpIdTokenAuthCredentials:
  17948. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  17949. properties:
  17950. identityId:
  17951. description: |-
  17952. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17953. In some instances, `key` is a required field.
  17954. properties:
  17955. key:
  17956. description: |-
  17957. A key in the referenced Secret.
  17958. Some instances of this field may be defaulted, in others it may be required.
  17959. maxLength: 253
  17960. minLength: 1
  17961. pattern: ^[-._a-zA-Z0-9]+$
  17962. type: string
  17963. name:
  17964. description: The name of the Secret resource being referred to.
  17965. maxLength: 253
  17966. minLength: 1
  17967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17968. type: string
  17969. namespace:
  17970. description: |-
  17971. The namespace of the Secret resource being referred to.
  17972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17973. maxLength: 63
  17974. minLength: 1
  17975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17976. type: string
  17977. type: object
  17978. required:
  17979. - identityId
  17980. type: object
  17981. jwtAuthCredentials:
  17982. description: JwtAuthCredentials represents the credentials for JWT authentication.
  17983. properties:
  17984. identityId:
  17985. description: |-
  17986. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17987. In some instances, `key` is a required field.
  17988. properties:
  17989. key:
  17990. description: |-
  17991. A key in the referenced Secret.
  17992. Some instances of this field may be defaulted, in others it may be required.
  17993. maxLength: 253
  17994. minLength: 1
  17995. pattern: ^[-._a-zA-Z0-9]+$
  17996. type: string
  17997. name:
  17998. description: The name of the Secret resource being referred to.
  17999. maxLength: 253
  18000. minLength: 1
  18001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18002. type: string
  18003. namespace:
  18004. description: |-
  18005. The namespace of the Secret resource being referred to.
  18006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18007. maxLength: 63
  18008. minLength: 1
  18009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18010. type: string
  18011. type: object
  18012. jwt:
  18013. description: |-
  18014. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18015. In some instances, `key` is a required field.
  18016. properties:
  18017. key:
  18018. description: |-
  18019. A key in the referenced Secret.
  18020. Some instances of this field may be defaulted, in others it may be required.
  18021. maxLength: 253
  18022. minLength: 1
  18023. pattern: ^[-._a-zA-Z0-9]+$
  18024. type: string
  18025. name:
  18026. description: The name of the Secret resource being referred to.
  18027. maxLength: 253
  18028. minLength: 1
  18029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18030. type: string
  18031. namespace:
  18032. description: |-
  18033. The namespace of the Secret resource being referred to.
  18034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18035. maxLength: 63
  18036. minLength: 1
  18037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18038. type: string
  18039. type: object
  18040. required:
  18041. - identityId
  18042. - jwt
  18043. type: object
  18044. kubernetesAuthCredentials:
  18045. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18046. properties:
  18047. identityId:
  18048. description: |-
  18049. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18050. In some instances, `key` is a required field.
  18051. properties:
  18052. key:
  18053. description: |-
  18054. A key in the referenced Secret.
  18055. Some instances of this field may be defaulted, in others it may be required.
  18056. maxLength: 253
  18057. minLength: 1
  18058. pattern: ^[-._a-zA-Z0-9]+$
  18059. type: string
  18060. name:
  18061. description: The name of the Secret resource being referred to.
  18062. maxLength: 253
  18063. minLength: 1
  18064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18065. type: string
  18066. namespace:
  18067. description: |-
  18068. The namespace of the Secret resource being referred to.
  18069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18070. maxLength: 63
  18071. minLength: 1
  18072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18073. type: string
  18074. type: object
  18075. serviceAccountTokenPath:
  18076. description: |-
  18077. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18078. In some instances, `key` is a required field.
  18079. properties:
  18080. key:
  18081. description: |-
  18082. A key in the referenced Secret.
  18083. Some instances of this field may be defaulted, in others it may be required.
  18084. maxLength: 253
  18085. minLength: 1
  18086. pattern: ^[-._a-zA-Z0-9]+$
  18087. type: string
  18088. name:
  18089. description: The name of the Secret resource being referred to.
  18090. maxLength: 253
  18091. minLength: 1
  18092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18093. type: string
  18094. namespace:
  18095. description: |-
  18096. The namespace of the Secret resource being referred to.
  18097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18098. maxLength: 63
  18099. minLength: 1
  18100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18101. type: string
  18102. type: object
  18103. required:
  18104. - identityId
  18105. type: object
  18106. ldapAuthCredentials:
  18107. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18108. properties:
  18109. identityId:
  18110. description: |-
  18111. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18112. In some instances, `key` is a required field.
  18113. properties:
  18114. key:
  18115. description: |-
  18116. A key in the referenced Secret.
  18117. Some instances of this field may be defaulted, in others it may be required.
  18118. maxLength: 253
  18119. minLength: 1
  18120. pattern: ^[-._a-zA-Z0-9]+$
  18121. type: string
  18122. name:
  18123. description: The name of the Secret resource being referred to.
  18124. maxLength: 253
  18125. minLength: 1
  18126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18127. type: string
  18128. namespace:
  18129. description: |-
  18130. The namespace of the Secret resource being referred to.
  18131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18132. maxLength: 63
  18133. minLength: 1
  18134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18135. type: string
  18136. type: object
  18137. ldapPassword:
  18138. description: |-
  18139. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18140. In some instances, `key` is a required field.
  18141. properties:
  18142. key:
  18143. description: |-
  18144. A key in the referenced Secret.
  18145. Some instances of this field may be defaulted, in others it may be required.
  18146. maxLength: 253
  18147. minLength: 1
  18148. pattern: ^[-._a-zA-Z0-9]+$
  18149. type: string
  18150. name:
  18151. description: The name of the Secret resource being referred to.
  18152. maxLength: 253
  18153. minLength: 1
  18154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18155. type: string
  18156. namespace:
  18157. description: |-
  18158. The namespace of the Secret resource being referred to.
  18159. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18160. maxLength: 63
  18161. minLength: 1
  18162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18163. type: string
  18164. type: object
  18165. ldapUsername:
  18166. description: |-
  18167. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18168. In some instances, `key` is a required field.
  18169. properties:
  18170. key:
  18171. description: |-
  18172. A key in the referenced Secret.
  18173. Some instances of this field may be defaulted, in others it may be required.
  18174. maxLength: 253
  18175. minLength: 1
  18176. pattern: ^[-._a-zA-Z0-9]+$
  18177. type: string
  18178. name:
  18179. description: The name of the Secret resource being referred to.
  18180. maxLength: 253
  18181. minLength: 1
  18182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18183. type: string
  18184. namespace:
  18185. description: |-
  18186. The namespace of the Secret resource being referred to.
  18187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18188. maxLength: 63
  18189. minLength: 1
  18190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18191. type: string
  18192. type: object
  18193. required:
  18194. - identityId
  18195. - ldapPassword
  18196. - ldapUsername
  18197. type: object
  18198. ociAuthCredentials:
  18199. description: OciAuthCredentials represents the credentials for OCI authentication.
  18200. properties:
  18201. fingerprint:
  18202. description: |-
  18203. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18204. In some instances, `key` is a required field.
  18205. properties:
  18206. key:
  18207. description: |-
  18208. A key in the referenced Secret.
  18209. Some instances of this field may be defaulted, in others it may be required.
  18210. maxLength: 253
  18211. minLength: 1
  18212. pattern: ^[-._a-zA-Z0-9]+$
  18213. type: string
  18214. name:
  18215. description: The name of the Secret resource being referred to.
  18216. maxLength: 253
  18217. minLength: 1
  18218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18219. type: string
  18220. namespace:
  18221. description: |-
  18222. The namespace of the Secret resource being referred to.
  18223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18224. maxLength: 63
  18225. minLength: 1
  18226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18227. type: string
  18228. type: object
  18229. identityId:
  18230. description: |-
  18231. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18232. In some instances, `key` is a required field.
  18233. properties:
  18234. key:
  18235. description: |-
  18236. A key in the referenced Secret.
  18237. Some instances of this field may be defaulted, in others it may be required.
  18238. maxLength: 253
  18239. minLength: 1
  18240. pattern: ^[-._a-zA-Z0-9]+$
  18241. type: string
  18242. name:
  18243. description: The name of the Secret resource being referred to.
  18244. maxLength: 253
  18245. minLength: 1
  18246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18247. type: string
  18248. namespace:
  18249. description: |-
  18250. The namespace of the Secret resource being referred to.
  18251. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18252. maxLength: 63
  18253. minLength: 1
  18254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18255. type: string
  18256. type: object
  18257. privateKey:
  18258. description: |-
  18259. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18260. In some instances, `key` is a required field.
  18261. properties:
  18262. key:
  18263. description: |-
  18264. A key in the referenced Secret.
  18265. Some instances of this field may be defaulted, in others it may be required.
  18266. maxLength: 253
  18267. minLength: 1
  18268. pattern: ^[-._a-zA-Z0-9]+$
  18269. type: string
  18270. name:
  18271. description: The name of the Secret resource being referred to.
  18272. maxLength: 253
  18273. minLength: 1
  18274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18275. type: string
  18276. namespace:
  18277. description: |-
  18278. The namespace of the Secret resource being referred to.
  18279. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18280. maxLength: 63
  18281. minLength: 1
  18282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18283. type: string
  18284. type: object
  18285. privateKeyPassphrase:
  18286. description: |-
  18287. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18288. In some instances, `key` is a required field.
  18289. properties:
  18290. key:
  18291. description: |-
  18292. A key in the referenced Secret.
  18293. Some instances of this field may be defaulted, in others it may be required.
  18294. maxLength: 253
  18295. minLength: 1
  18296. pattern: ^[-._a-zA-Z0-9]+$
  18297. type: string
  18298. name:
  18299. description: The name of the Secret resource being referred to.
  18300. maxLength: 253
  18301. minLength: 1
  18302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18303. type: string
  18304. namespace:
  18305. description: |-
  18306. The namespace of the Secret resource being referred to.
  18307. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18308. maxLength: 63
  18309. minLength: 1
  18310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18311. type: string
  18312. type: object
  18313. region:
  18314. description: |-
  18315. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18316. In some instances, `key` is a required field.
  18317. properties:
  18318. key:
  18319. description: |-
  18320. A key in the referenced Secret.
  18321. Some instances of this field may be defaulted, in others it may be required.
  18322. maxLength: 253
  18323. minLength: 1
  18324. pattern: ^[-._a-zA-Z0-9]+$
  18325. type: string
  18326. name:
  18327. description: The name of the Secret resource being referred to.
  18328. maxLength: 253
  18329. minLength: 1
  18330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18331. type: string
  18332. namespace:
  18333. description: |-
  18334. The namespace of the Secret resource being referred to.
  18335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18336. maxLength: 63
  18337. minLength: 1
  18338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18339. type: string
  18340. type: object
  18341. tenancyId:
  18342. description: |-
  18343. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18344. In some instances, `key` is a required field.
  18345. properties:
  18346. key:
  18347. description: |-
  18348. A key in the referenced Secret.
  18349. Some instances of this field may be defaulted, in others it may be required.
  18350. maxLength: 253
  18351. minLength: 1
  18352. pattern: ^[-._a-zA-Z0-9]+$
  18353. type: string
  18354. name:
  18355. description: The name of the Secret resource being referred to.
  18356. maxLength: 253
  18357. minLength: 1
  18358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18359. type: string
  18360. namespace:
  18361. description: |-
  18362. The namespace of the Secret resource being referred to.
  18363. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18364. maxLength: 63
  18365. minLength: 1
  18366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18367. type: string
  18368. type: object
  18369. userId:
  18370. description: |-
  18371. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18372. In some instances, `key` is a required field.
  18373. properties:
  18374. key:
  18375. description: |-
  18376. A key in the referenced Secret.
  18377. Some instances of this field may be defaulted, in others it may be required.
  18378. maxLength: 253
  18379. minLength: 1
  18380. pattern: ^[-._a-zA-Z0-9]+$
  18381. type: string
  18382. name:
  18383. description: The name of the Secret resource being referred to.
  18384. maxLength: 253
  18385. minLength: 1
  18386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18387. type: string
  18388. namespace:
  18389. description: |-
  18390. The namespace of the Secret resource being referred to.
  18391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18392. maxLength: 63
  18393. minLength: 1
  18394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18395. type: string
  18396. type: object
  18397. required:
  18398. - fingerprint
  18399. - identityId
  18400. - privateKey
  18401. - region
  18402. - tenancyId
  18403. - userId
  18404. type: object
  18405. tokenAuthCredentials:
  18406. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18407. properties:
  18408. accessToken:
  18409. description: |-
  18410. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18411. In some instances, `key` is a required field.
  18412. properties:
  18413. key:
  18414. description: |-
  18415. A key in the referenced Secret.
  18416. Some instances of this field may be defaulted, in others it may be required.
  18417. maxLength: 253
  18418. minLength: 1
  18419. pattern: ^[-._a-zA-Z0-9]+$
  18420. type: string
  18421. name:
  18422. description: The name of the Secret resource being referred to.
  18423. maxLength: 253
  18424. minLength: 1
  18425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18426. type: string
  18427. namespace:
  18428. description: |-
  18429. The namespace of the Secret resource being referred to.
  18430. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18431. maxLength: 63
  18432. minLength: 1
  18433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18434. type: string
  18435. type: object
  18436. required:
  18437. - accessToken
  18438. type: object
  18439. universalAuthCredentials:
  18440. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  18441. properties:
  18442. clientId:
  18443. description: |-
  18444. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18445. In some instances, `key` is a required field.
  18446. properties:
  18447. key:
  18448. description: |-
  18449. A key in the referenced Secret.
  18450. Some instances of this field may be defaulted, in others it may be required.
  18451. maxLength: 253
  18452. minLength: 1
  18453. pattern: ^[-._a-zA-Z0-9]+$
  18454. type: string
  18455. name:
  18456. description: The name of the Secret resource being referred to.
  18457. maxLength: 253
  18458. minLength: 1
  18459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18460. type: string
  18461. namespace:
  18462. description: |-
  18463. The namespace of the Secret resource being referred to.
  18464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18465. maxLength: 63
  18466. minLength: 1
  18467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18468. type: string
  18469. type: object
  18470. clientSecret:
  18471. description: |-
  18472. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18473. In some instances, `key` is a required field.
  18474. properties:
  18475. key:
  18476. description: |-
  18477. A key in the referenced Secret.
  18478. Some instances of this field may be defaulted, in others it may be required.
  18479. maxLength: 253
  18480. minLength: 1
  18481. pattern: ^[-._a-zA-Z0-9]+$
  18482. type: string
  18483. name:
  18484. description: The name of the Secret resource being referred to.
  18485. maxLength: 253
  18486. minLength: 1
  18487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18488. type: string
  18489. namespace:
  18490. description: |-
  18491. The namespace of the Secret resource being referred to.
  18492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18493. maxLength: 63
  18494. minLength: 1
  18495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18496. type: string
  18497. type: object
  18498. required:
  18499. - clientId
  18500. - clientSecret
  18501. type: object
  18502. type: object
  18503. caBundle:
  18504. description: |-
  18505. CABundle is a PEM-encoded CA certificate bundle used to validate
  18506. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  18507. format: byte
  18508. type: string
  18509. caProvider:
  18510. description: |-
  18511. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  18512. The certificate is used to validate the Infisical server's TLS certificate.
  18513. Mutually exclusive with CABundle.
  18514. properties:
  18515. key:
  18516. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18517. maxLength: 253
  18518. minLength: 1
  18519. pattern: ^[-._a-zA-Z0-9]+$
  18520. type: string
  18521. name:
  18522. description: The name of the object located at the provider type.
  18523. maxLength: 253
  18524. minLength: 1
  18525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18526. type: string
  18527. namespace:
  18528. description: |-
  18529. The namespace the Provider type is in.
  18530. Can only be defined when used in a ClusterSecretStore.
  18531. maxLength: 63
  18532. minLength: 1
  18533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18534. type: string
  18535. type:
  18536. description: The type of provider to use such as "Secret", or "ConfigMap".
  18537. enum:
  18538. - Secret
  18539. - ConfigMap
  18540. type: string
  18541. required:
  18542. - name
  18543. - type
  18544. type: object
  18545. hostAPI:
  18546. default: https://app.infisical.com/api
  18547. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  18548. type: string
  18549. secretsScope:
  18550. description: SecretsScope defines the scope of the secrets within the workspace
  18551. properties:
  18552. environmentSlug:
  18553. description: EnvironmentSlug is the required slug identifier for the environment.
  18554. type: string
  18555. expandSecretReferences:
  18556. default: true
  18557. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  18558. type: boolean
  18559. organizationSlug:
  18560. description: |-
  18561. OrganizationSlug is the optional slug that identifies the organization that will be used
  18562. during authentication. Useful for sub-organization setups
  18563. type: string
  18564. projectSlug:
  18565. description: ProjectSlug is the required slug identifier for the project.
  18566. type: string
  18567. recursive:
  18568. default: false
  18569. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  18570. type: boolean
  18571. secretsPath:
  18572. default: /
  18573. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  18574. type: string
  18575. required:
  18576. - environmentSlug
  18577. - projectSlug
  18578. type: object
  18579. required:
  18580. - auth
  18581. - secretsScope
  18582. type: object
  18583. keepersecurity:
  18584. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  18585. properties:
  18586. authRef:
  18587. description: |-
  18588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18589. In some instances, `key` is a required field.
  18590. properties:
  18591. key:
  18592. description: |-
  18593. A key in the referenced Secret.
  18594. Some instances of this field may be defaulted, in others it may be required.
  18595. maxLength: 253
  18596. minLength: 1
  18597. pattern: ^[-._a-zA-Z0-9]+$
  18598. type: string
  18599. name:
  18600. description: The name of the Secret resource being referred to.
  18601. maxLength: 253
  18602. minLength: 1
  18603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18604. type: string
  18605. namespace:
  18606. description: |-
  18607. The namespace of the Secret resource being referred to.
  18608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18609. maxLength: 63
  18610. minLength: 1
  18611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18612. type: string
  18613. type: object
  18614. folderID:
  18615. type: string
  18616. getByTitleFallback:
  18617. type: boolean
  18618. required:
  18619. - authRef
  18620. - folderID
  18621. type: object
  18622. kubernetes:
  18623. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  18624. properties:
  18625. auth:
  18626. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  18627. maxProperties: 1
  18628. minProperties: 1
  18629. properties:
  18630. cert:
  18631. description: has both clientCert and clientKey as secretKeySelector
  18632. properties:
  18633. clientCert:
  18634. description: |-
  18635. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18636. In some instances, `key` is a required field.
  18637. properties:
  18638. key:
  18639. description: |-
  18640. A key in the referenced Secret.
  18641. Some instances of this field may be defaulted, in others it may be required.
  18642. maxLength: 253
  18643. minLength: 1
  18644. pattern: ^[-._a-zA-Z0-9]+$
  18645. type: string
  18646. name:
  18647. description: The name of the Secret resource being referred to.
  18648. maxLength: 253
  18649. minLength: 1
  18650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18651. type: string
  18652. namespace:
  18653. description: |-
  18654. The namespace of the Secret resource being referred to.
  18655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18656. maxLength: 63
  18657. minLength: 1
  18658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18659. type: string
  18660. type: object
  18661. clientKey:
  18662. description: |-
  18663. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18664. In some instances, `key` is a required field.
  18665. properties:
  18666. key:
  18667. description: |-
  18668. A key in the referenced Secret.
  18669. Some instances of this field may be defaulted, in others it may be required.
  18670. maxLength: 253
  18671. minLength: 1
  18672. pattern: ^[-._a-zA-Z0-9]+$
  18673. type: string
  18674. name:
  18675. description: The name of the Secret resource being referred to.
  18676. maxLength: 253
  18677. minLength: 1
  18678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18679. type: string
  18680. namespace:
  18681. description: |-
  18682. The namespace of the Secret resource being referred to.
  18683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18684. maxLength: 63
  18685. minLength: 1
  18686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18687. type: string
  18688. type: object
  18689. type: object
  18690. serviceAccount:
  18691. description: points to a service account that should be used for authentication
  18692. properties:
  18693. audiences:
  18694. description: |-
  18695. Audience specifies the `aud` claim for the service account token
  18696. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18697. then this audiences will be appended to the list
  18698. items:
  18699. type: string
  18700. type: array
  18701. name:
  18702. description: The name of the ServiceAccount resource being referred to.
  18703. maxLength: 253
  18704. minLength: 1
  18705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18706. type: string
  18707. namespace:
  18708. description: |-
  18709. Namespace of the resource being referred to.
  18710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18711. maxLength: 63
  18712. minLength: 1
  18713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18714. type: string
  18715. required:
  18716. - name
  18717. type: object
  18718. token:
  18719. description: use static token to authenticate with
  18720. properties:
  18721. bearerToken:
  18722. description: |-
  18723. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18724. In some instances, `key` is a required field.
  18725. properties:
  18726. key:
  18727. description: |-
  18728. A key in the referenced Secret.
  18729. Some instances of this field may be defaulted, in others it may be required.
  18730. maxLength: 253
  18731. minLength: 1
  18732. pattern: ^[-._a-zA-Z0-9]+$
  18733. type: string
  18734. name:
  18735. description: The name of the Secret resource being referred to.
  18736. maxLength: 253
  18737. minLength: 1
  18738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18739. type: string
  18740. namespace:
  18741. description: |-
  18742. The namespace of the Secret resource being referred to.
  18743. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18744. maxLength: 63
  18745. minLength: 1
  18746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18747. type: string
  18748. type: object
  18749. type: object
  18750. type: object
  18751. authRef:
  18752. description: A reference to a secret that contains the auth information.
  18753. properties:
  18754. key:
  18755. description: |-
  18756. A key in the referenced Secret.
  18757. Some instances of this field may be defaulted, in others it may be required.
  18758. maxLength: 253
  18759. minLength: 1
  18760. pattern: ^[-._a-zA-Z0-9]+$
  18761. type: string
  18762. name:
  18763. description: The name of the Secret resource being referred to.
  18764. maxLength: 253
  18765. minLength: 1
  18766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18767. type: string
  18768. namespace:
  18769. description: |-
  18770. The namespace of the Secret resource being referred to.
  18771. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18772. maxLength: 63
  18773. minLength: 1
  18774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18775. type: string
  18776. type: object
  18777. remoteNamespace:
  18778. default: default
  18779. description: Remote namespace to fetch the secrets from
  18780. maxLength: 63
  18781. minLength: 1
  18782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18783. type: string
  18784. server:
  18785. description: configures the Kubernetes server Address.
  18786. properties:
  18787. caBundle:
  18788. description: CABundle is a base64-encoded CA certificate
  18789. format: byte
  18790. type: string
  18791. caProvider:
  18792. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  18793. properties:
  18794. key:
  18795. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18796. maxLength: 253
  18797. minLength: 1
  18798. pattern: ^[-._a-zA-Z0-9]+$
  18799. type: string
  18800. name:
  18801. description: The name of the object located at the provider type.
  18802. maxLength: 253
  18803. minLength: 1
  18804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18805. type: string
  18806. namespace:
  18807. description: |-
  18808. The namespace the Provider type is in.
  18809. Can only be defined when used in a ClusterSecretStore.
  18810. maxLength: 63
  18811. minLength: 1
  18812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18813. type: string
  18814. type:
  18815. description: The type of provider to use such as "Secret", or "ConfigMap".
  18816. enum:
  18817. - Secret
  18818. - ConfigMap
  18819. type: string
  18820. required:
  18821. - name
  18822. - type
  18823. type: object
  18824. url:
  18825. default: kubernetes.default
  18826. description: configures the Kubernetes server Address.
  18827. type: string
  18828. type: object
  18829. type: object
  18830. nebiusmysterybox:
  18831. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  18832. properties:
  18833. apiDomain:
  18834. description: NebiusMysterybox API endpoint
  18835. type: string
  18836. auth:
  18837. description: Auth defines parameters to authenticate in MysteryBox
  18838. properties:
  18839. serviceAccountCredsSecretRef:
  18840. description: |-
  18841. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  18842. document with service account credentials used to get an IAM token.
  18843. Expected JSON structure:
  18844. {
  18845. "subject-credentials": {
  18846. "alg": "RS256",
  18847. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  18848. "kid": "<public-key-id>",
  18849. "iss": "<issuer-service-account-id>",
  18850. "sub": "<subject-service-account-id>"
  18851. }
  18852. }
  18853. properties:
  18854. key:
  18855. description: |-
  18856. A key in the referenced Secret.
  18857. Some instances of this field may be defaulted, in others it may be required.
  18858. maxLength: 253
  18859. minLength: 1
  18860. pattern: ^[-._a-zA-Z0-9]+$
  18861. type: string
  18862. name:
  18863. description: The name of the Secret resource being referred to.
  18864. maxLength: 253
  18865. minLength: 1
  18866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18867. type: string
  18868. namespace:
  18869. description: |-
  18870. The namespace of the Secret resource being referred to.
  18871. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18872. maxLength: 63
  18873. minLength: 1
  18874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18875. type: string
  18876. type: object
  18877. tokenSecretRef:
  18878. description: Token authenticates with Nebius Mysterybox by presenting a token.
  18879. properties:
  18880. key:
  18881. description: |-
  18882. A key in the referenced Secret.
  18883. Some instances of this field may be defaulted, in others it may be required.
  18884. maxLength: 253
  18885. minLength: 1
  18886. pattern: ^[-._a-zA-Z0-9]+$
  18887. type: string
  18888. name:
  18889. description: The name of the Secret resource being referred to.
  18890. maxLength: 253
  18891. minLength: 1
  18892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18893. type: string
  18894. namespace:
  18895. description: |-
  18896. The namespace of the Secret resource being referred to.
  18897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18898. maxLength: 63
  18899. minLength: 1
  18900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18901. type: string
  18902. type: object
  18903. type: object
  18904. x-kubernetes-validations:
  18905. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  18906. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  18907. caProvider:
  18908. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  18909. properties:
  18910. certSecretRef:
  18911. description: |-
  18912. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18913. In some instances, `key` is a required field.
  18914. properties:
  18915. key:
  18916. description: |-
  18917. A key in the referenced Secret.
  18918. Some instances of this field may be defaulted, in others it may be required.
  18919. maxLength: 253
  18920. minLength: 1
  18921. pattern: ^[-._a-zA-Z0-9]+$
  18922. type: string
  18923. name:
  18924. description: The name of the Secret resource being referred to.
  18925. maxLength: 253
  18926. minLength: 1
  18927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18928. type: string
  18929. namespace:
  18930. description: |-
  18931. The namespace of the Secret resource being referred to.
  18932. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18933. maxLength: 63
  18934. minLength: 1
  18935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18936. type: string
  18937. type: object
  18938. type: object
  18939. required:
  18940. - apiDomain
  18941. - auth
  18942. type: object
  18943. ngrok:
  18944. description: Ngrok configures this store to sync secrets using the ngrok provider.
  18945. properties:
  18946. apiUrl:
  18947. default: https://api.ngrok.com
  18948. description: APIURL is the URL of the ngrok API.
  18949. type: string
  18950. auth:
  18951. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  18952. maxProperties: 1
  18953. minProperties: 1
  18954. properties:
  18955. apiKey:
  18956. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  18957. properties:
  18958. secretRef:
  18959. description: SecretRef is a reference to a secret containing the ngrok API key.
  18960. properties:
  18961. key:
  18962. description: |-
  18963. A key in the referenced Secret.
  18964. Some instances of this field may be defaulted, in others it may be required.
  18965. maxLength: 253
  18966. minLength: 1
  18967. pattern: ^[-._a-zA-Z0-9]+$
  18968. type: string
  18969. name:
  18970. description: The name of the Secret resource being referred to.
  18971. maxLength: 253
  18972. minLength: 1
  18973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18974. type: string
  18975. namespace:
  18976. description: |-
  18977. The namespace of the Secret resource being referred to.
  18978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18979. maxLength: 63
  18980. minLength: 1
  18981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18982. type: string
  18983. type: object
  18984. type: object
  18985. type: object
  18986. vault:
  18987. description: Vault configures the ngrok vault to sync secrets with.
  18988. properties:
  18989. name:
  18990. description: Name is the name of the ngrok vault to sync secrets with.
  18991. type: string
  18992. required:
  18993. - name
  18994. type: object
  18995. required:
  18996. - auth
  18997. - vault
  18998. type: object
  18999. onboardbase:
  19000. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19001. properties:
  19002. apiHost:
  19003. default: https://public.onboardbase.com/api/v1/
  19004. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19005. type: string
  19006. auth:
  19007. description: Auth configures how the Operator authenticates with the Onboardbase API
  19008. properties:
  19009. apiKeyRef:
  19010. description: |-
  19011. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19012. It is used to recognize and authorize access to a project and environment within onboardbase
  19013. properties:
  19014. key:
  19015. description: |-
  19016. A key in the referenced Secret.
  19017. Some instances of this field may be defaulted, in others it may be required.
  19018. maxLength: 253
  19019. minLength: 1
  19020. pattern: ^[-._a-zA-Z0-9]+$
  19021. type: string
  19022. name:
  19023. description: The name of the Secret resource being referred to.
  19024. maxLength: 253
  19025. minLength: 1
  19026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19027. type: string
  19028. namespace:
  19029. description: |-
  19030. The namespace of the Secret resource being referred to.
  19031. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19032. maxLength: 63
  19033. minLength: 1
  19034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19035. type: string
  19036. type: object
  19037. passcodeRef:
  19038. description: OnboardbasePasscode is the passcode attached to the API Key
  19039. properties:
  19040. key:
  19041. description: |-
  19042. A key in the referenced Secret.
  19043. Some instances of this field may be defaulted, in others it may be required.
  19044. maxLength: 253
  19045. minLength: 1
  19046. pattern: ^[-._a-zA-Z0-9]+$
  19047. type: string
  19048. name:
  19049. description: The name of the Secret resource being referred to.
  19050. maxLength: 253
  19051. minLength: 1
  19052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19053. type: string
  19054. namespace:
  19055. description: |-
  19056. The namespace of the Secret resource being referred to.
  19057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19058. maxLength: 63
  19059. minLength: 1
  19060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19061. type: string
  19062. type: object
  19063. required:
  19064. - apiKeyRef
  19065. - passcodeRef
  19066. type: object
  19067. environment:
  19068. default: development
  19069. description: Environment is the name of an environmnent within a project to pull the secrets from
  19070. type: string
  19071. project:
  19072. default: development
  19073. description: Project is an onboardbase project that the secrets should be pulled from
  19074. type: string
  19075. required:
  19076. - apiHost
  19077. - auth
  19078. - environment
  19079. - project
  19080. type: object
  19081. onepassword:
  19082. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19083. properties:
  19084. auth:
  19085. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19086. properties:
  19087. secretRef:
  19088. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19089. properties:
  19090. connectTokenSecretRef:
  19091. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19092. properties:
  19093. key:
  19094. description: |-
  19095. A key in the referenced Secret.
  19096. Some instances of this field may be defaulted, in others it may be required.
  19097. maxLength: 253
  19098. minLength: 1
  19099. pattern: ^[-._a-zA-Z0-9]+$
  19100. type: string
  19101. name:
  19102. description: The name of the Secret resource being referred to.
  19103. maxLength: 253
  19104. minLength: 1
  19105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19106. type: string
  19107. namespace:
  19108. description: |-
  19109. The namespace of the Secret resource being referred to.
  19110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19111. maxLength: 63
  19112. minLength: 1
  19113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19114. type: string
  19115. type: object
  19116. required:
  19117. - connectTokenSecretRef
  19118. type: object
  19119. required:
  19120. - secretRef
  19121. type: object
  19122. connectHost:
  19123. description: ConnectHost defines the OnePassword Connect Server to connect to
  19124. type: string
  19125. vaults:
  19126. additionalProperties:
  19127. type: integer
  19128. description: Vaults defines which OnePassword vaults to search in which order
  19129. type: object
  19130. required:
  19131. - auth
  19132. - connectHost
  19133. - vaults
  19134. type: object
  19135. onepasswordSDK:
  19136. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19137. properties:
  19138. auth:
  19139. description: Auth defines the information necessary to authenticate against OnePassword API.
  19140. properties:
  19141. serviceAccountSecretRef:
  19142. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19143. properties:
  19144. key:
  19145. description: |-
  19146. A key in the referenced Secret.
  19147. Some instances of this field may be defaulted, in others it may be required.
  19148. maxLength: 253
  19149. minLength: 1
  19150. pattern: ^[-._a-zA-Z0-9]+$
  19151. type: string
  19152. name:
  19153. description: The name of the Secret resource being referred to.
  19154. maxLength: 253
  19155. minLength: 1
  19156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19157. type: string
  19158. namespace:
  19159. description: |-
  19160. The namespace of the Secret resource being referred to.
  19161. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19162. maxLength: 63
  19163. minLength: 1
  19164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19165. type: string
  19166. type: object
  19167. required:
  19168. - serviceAccountSecretRef
  19169. type: object
  19170. cache:
  19171. description: |-
  19172. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19173. When enabled, secrets are cached with the specified TTL.
  19174. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19175. If omitted, caching is disabled (default).
  19176. cache: {} is a valid option to set.
  19177. properties:
  19178. maxSize:
  19179. default: 100
  19180. description: |-
  19181. MaxSize is the maximum number of secrets to cache.
  19182. When the cache is full, least-recently-used entries are evicted.
  19183. minimum: 1
  19184. type: integer
  19185. ttl:
  19186. default: 5m
  19187. description: |-
  19188. TTL is the time-to-live for cached secrets.
  19189. Format: duration string (e.g., "5m", "1h", "30s")
  19190. type: string
  19191. type: object
  19192. integrationInfo:
  19193. description: |-
  19194. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19195. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19196. properties:
  19197. name:
  19198. default: 1Password SDK
  19199. description: Name defaults to "1Password SDK".
  19200. type: string
  19201. version:
  19202. default: v1.0.0
  19203. description: Version defaults to "v1.0.0".
  19204. type: string
  19205. type: object
  19206. vault:
  19207. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19208. type: string
  19209. required:
  19210. - auth
  19211. - vault
  19212. type: object
  19213. openBao:
  19214. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19215. properties:
  19216. auth:
  19217. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19218. properties:
  19219. appRole:
  19220. description: |-
  19221. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19222. with the role and secret stored in a Kubernetes Secret resource.
  19223. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19224. properties:
  19225. path:
  19226. default: approle
  19227. description: |-
  19228. Path where the App Role authentication backend is mounted
  19229. in OpenBao, e.g: "approle"
  19230. type: string
  19231. roleId:
  19232. description: |-
  19233. RoleID configured in the App Role authentication backend when setting
  19234. up the authentication backend in OpenBao.
  19235. minLength: 1
  19236. type: string
  19237. roleRef:
  19238. description: |-
  19239. Reference to a key in a Secret that contains the App Role ID used
  19240. to authenticate with OpenBao.
  19241. The `key` field must be specified and denotes which entry within the Secret
  19242. resource is used as the app role id.
  19243. properties:
  19244. key:
  19245. description: |-
  19246. A key in the referenced Secret.
  19247. Some instances of this field may be defaulted, in others it may be required.
  19248. maxLength: 253
  19249. minLength: 1
  19250. pattern: ^[-._a-zA-Z0-9]+$
  19251. type: string
  19252. name:
  19253. description: The name of the Secret resource being referred to.
  19254. maxLength: 253
  19255. minLength: 1
  19256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19257. type: string
  19258. namespace:
  19259. description: |-
  19260. The namespace of the Secret resource being referred to.
  19261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19262. maxLength: 63
  19263. minLength: 1
  19264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19265. type: string
  19266. type: object
  19267. secretRef:
  19268. description: |-
  19269. Reference to a key in a Secret that contains the App Role secret used
  19270. to authenticate with OpenBao.
  19271. The `key` field must be specified and denotes which entry within the Secret
  19272. resource is used as the app role secret.
  19273. properties:
  19274. key:
  19275. description: |-
  19276. A key in the referenced Secret.
  19277. Some instances of this field may be defaulted, in others it may be required.
  19278. maxLength: 253
  19279. minLength: 1
  19280. pattern: ^[-._a-zA-Z0-9]+$
  19281. type: string
  19282. name:
  19283. description: The name of the Secret resource being referred to.
  19284. maxLength: 253
  19285. minLength: 1
  19286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19287. type: string
  19288. namespace:
  19289. description: |-
  19290. The namespace of the Secret resource being referred to.
  19291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19292. maxLength: 63
  19293. minLength: 1
  19294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19295. type: string
  19296. type: object
  19297. required:
  19298. - path
  19299. - secretRef
  19300. type: object
  19301. x-kubernetes-validations:
  19302. - message: exactly one of the fields in [roleId roleRef] must be set
  19303. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19304. namespace:
  19305. description: |-
  19306. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19307. than the namespace your secret is in. Namespaces is a set of features
  19308. within OpenBao that allows OpenBao environments to support secure
  19309. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19310. if set, or empty otherwise
  19311. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19312. type: string
  19313. tokenSecretRef:
  19314. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19315. properties:
  19316. key:
  19317. description: |-
  19318. A key in the referenced Secret.
  19319. Some instances of this field may be defaulted, in others it may be required.
  19320. maxLength: 253
  19321. minLength: 1
  19322. pattern: ^[-._a-zA-Z0-9]+$
  19323. type: string
  19324. name:
  19325. description: The name of the Secret resource being referred to.
  19326. maxLength: 253
  19327. minLength: 1
  19328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19329. type: string
  19330. namespace:
  19331. description: |-
  19332. The namespace of the Secret resource being referred to.
  19333. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19334. maxLength: 63
  19335. minLength: 1
  19336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19337. type: string
  19338. type: object
  19339. userPass:
  19340. description: UserPass authenticates with OpenBao by passing a username/password pair
  19341. properties:
  19342. path:
  19343. default: userpass
  19344. description: |-
  19345. Path where the UserPassword authentication backend is mounted
  19346. in OpenBao, e.g: "userpass"
  19347. type: string
  19348. secretRef:
  19349. description: |-
  19350. SecretRef to a key in a Secret resource containing password for the user
  19351. used to authenticate with OpenBao using the [UserPass authentication
  19352. method]
  19353. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19354. properties:
  19355. key:
  19356. description: |-
  19357. A key in the referenced Secret.
  19358. Some instances of this field may be defaulted, in others it may be required.
  19359. maxLength: 253
  19360. minLength: 1
  19361. pattern: ^[-._a-zA-Z0-9]+$
  19362. type: string
  19363. name:
  19364. description: The name of the Secret resource being referred to.
  19365. maxLength: 253
  19366. minLength: 1
  19367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19368. type: string
  19369. namespace:
  19370. description: |-
  19371. The namespace of the Secret resource being referred to.
  19372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19373. maxLength: 63
  19374. minLength: 1
  19375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19376. type: string
  19377. type: object
  19378. username:
  19379. description: |-
  19380. Username is a username used to authenticate using the [UserPass
  19381. authentication method]
  19382. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19383. type: string
  19384. required:
  19385. - path
  19386. - username
  19387. type: object
  19388. type: object
  19389. x-kubernetes-validations:
  19390. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19391. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19392. caBundle:
  19393. description: |-
  19394. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19395. this and `caProvider` are not set the system root certificates are used
  19396. to validate the TLS connection.
  19397. format: byte
  19398. type: string
  19399. caProvider:
  19400. description: |-
  19401. The provider for the CA bundle to use to validate OpenBao server
  19402. certificate. If this and `caBundle` are not set the system root
  19403. certificates are used to validate the TLS connection.
  19404. properties:
  19405. key:
  19406. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19407. maxLength: 253
  19408. minLength: 1
  19409. pattern: ^[-._a-zA-Z0-9]+$
  19410. type: string
  19411. name:
  19412. description: The name of the object located at the provider type.
  19413. maxLength: 253
  19414. minLength: 1
  19415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19416. type: string
  19417. namespace:
  19418. description: |-
  19419. The namespace the Provider type is in.
  19420. Can only be defined when used in a ClusterSecretStore.
  19421. maxLength: 63
  19422. minLength: 1
  19423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19424. type: string
  19425. type:
  19426. description: The type of provider to use such as "Secret", or "ConfigMap".
  19427. enum:
  19428. - Secret
  19429. - ConfigMap
  19430. type: string
  19431. required:
  19432. - name
  19433. - type
  19434. type: object
  19435. namespace:
  19436. description: |-
  19437. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  19438. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  19439. e.g: "ns1".
  19440. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19441. type: string
  19442. path:
  19443. description: |-
  19444. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  19445. "secret". The v2 KV secret engine version specific "/data" path suffix
  19446. for fetching secrets from OpenBao is optional and will be appended
  19447. if not present in specified path.
  19448. type: string
  19449. server:
  19450. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  19451. type: string
  19452. version:
  19453. default: v2
  19454. description: |-
  19455. Version is the OpenBao KV secret engine version. This can be either "v1" or
  19456. "v2". Version defaults to "v2".
  19457. enum:
  19458. - v1
  19459. - v2
  19460. type: string
  19461. required:
  19462. - server
  19463. type: object
  19464. x-kubernetes-validations:
  19465. - message: at most one of the fields in [caBundle caProvider] may be set
  19466. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  19467. oracle:
  19468. description: Oracle configures this store to sync secrets using Oracle Vault provider
  19469. properties:
  19470. auth:
  19471. description: |-
  19472. Auth configures how secret-manager authenticates with the Oracle Vault.
  19473. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  19474. properties:
  19475. secretRef:
  19476. description: SecretRef to pass through sensitive information.
  19477. properties:
  19478. fingerprint:
  19479. description: Fingerprint is the fingerprint of the API private key.
  19480. properties:
  19481. key:
  19482. description: |-
  19483. A key in the referenced Secret.
  19484. Some instances of this field may be defaulted, in others it may be required.
  19485. maxLength: 253
  19486. minLength: 1
  19487. pattern: ^[-._a-zA-Z0-9]+$
  19488. type: string
  19489. name:
  19490. description: The name of the Secret resource being referred to.
  19491. maxLength: 253
  19492. minLength: 1
  19493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19494. type: string
  19495. namespace:
  19496. description: |-
  19497. The namespace of the Secret resource being referred to.
  19498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19499. maxLength: 63
  19500. minLength: 1
  19501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19502. type: string
  19503. type: object
  19504. privatekey:
  19505. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  19506. properties:
  19507. key:
  19508. description: |-
  19509. A key in the referenced Secret.
  19510. Some instances of this field may be defaulted, in others it may be required.
  19511. maxLength: 253
  19512. minLength: 1
  19513. pattern: ^[-._a-zA-Z0-9]+$
  19514. type: string
  19515. name:
  19516. description: The name of the Secret resource being referred to.
  19517. maxLength: 253
  19518. minLength: 1
  19519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19520. type: string
  19521. namespace:
  19522. description: |-
  19523. The namespace of the Secret resource being referred to.
  19524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19525. maxLength: 63
  19526. minLength: 1
  19527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19528. type: string
  19529. type: object
  19530. required:
  19531. - fingerprint
  19532. - privatekey
  19533. type: object
  19534. tenancy:
  19535. description: Tenancy is the tenancy OCID where user is located.
  19536. type: string
  19537. user:
  19538. description: User is an access OCID specific to the account.
  19539. type: string
  19540. required:
  19541. - secretRef
  19542. - tenancy
  19543. - user
  19544. type: object
  19545. compartment:
  19546. description: |-
  19547. Compartment is the vault compartment OCID.
  19548. Required for PushSecret
  19549. type: string
  19550. encryptionKey:
  19551. description: |-
  19552. EncryptionKey is the OCID of the encryption key within the vault.
  19553. Required for PushSecret
  19554. type: string
  19555. principalType:
  19556. description: |-
  19557. The type of principal to use for authentication. If left blank, the Auth struct will
  19558. determine the principal type. This optional field must be specified if using
  19559. workload identity.
  19560. enum:
  19561. - ""
  19562. - UserPrincipal
  19563. - InstancePrincipal
  19564. - Workload
  19565. type: string
  19566. region:
  19567. description: Region is the region where vault is located.
  19568. type: string
  19569. serviceAccountRef:
  19570. description: |-
  19571. ServiceAccountRef specified the service account
  19572. that should be used when authenticating with WorkloadIdentity.
  19573. properties:
  19574. audiences:
  19575. description: |-
  19576. Audience specifies the `aud` claim for the service account token
  19577. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19578. then this audiences will be appended to the list
  19579. items:
  19580. type: string
  19581. type: array
  19582. name:
  19583. description: The name of the ServiceAccount resource being referred to.
  19584. maxLength: 253
  19585. minLength: 1
  19586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19587. type: string
  19588. namespace:
  19589. description: |-
  19590. Namespace of the resource being referred to.
  19591. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19592. maxLength: 63
  19593. minLength: 1
  19594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19595. type: string
  19596. required:
  19597. - name
  19598. type: object
  19599. vault:
  19600. description: Vault is the vault's OCID of the specific vault where secret is located.
  19601. type: string
  19602. required:
  19603. - region
  19604. - vault
  19605. type: object
  19606. ovh:
  19607. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  19608. properties:
  19609. auth:
  19610. description: Authentication method (mtls or token).
  19611. properties:
  19612. mtls:
  19613. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  19614. properties:
  19615. caBundle:
  19616. format: byte
  19617. type: string
  19618. caProvider:
  19619. description: |-
  19620. CAProvider provides a custom certificate authority for accessing the provider's store.
  19621. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  19622. properties:
  19623. key:
  19624. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19625. maxLength: 253
  19626. minLength: 1
  19627. pattern: ^[-._a-zA-Z0-9]+$
  19628. type: string
  19629. name:
  19630. description: The name of the object located at the provider type.
  19631. maxLength: 253
  19632. minLength: 1
  19633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19634. type: string
  19635. namespace:
  19636. description: |-
  19637. The namespace the Provider type is in.
  19638. Can only be defined when used in a ClusterSecretStore.
  19639. maxLength: 63
  19640. minLength: 1
  19641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19642. type: string
  19643. type:
  19644. description: The type of provider to use such as "Secret", or "ConfigMap".
  19645. enum:
  19646. - Secret
  19647. - ConfigMap
  19648. type: string
  19649. required:
  19650. - name
  19651. - type
  19652. type: object
  19653. certSecretRef:
  19654. description: |-
  19655. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19656. In some instances, `key` is a required field.
  19657. properties:
  19658. key:
  19659. description: |-
  19660. A key in the referenced Secret.
  19661. Some instances of this field may be defaulted, in others it may be required.
  19662. maxLength: 253
  19663. minLength: 1
  19664. pattern: ^[-._a-zA-Z0-9]+$
  19665. type: string
  19666. name:
  19667. description: The name of the Secret resource being referred to.
  19668. maxLength: 253
  19669. minLength: 1
  19670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19671. type: string
  19672. namespace:
  19673. description: |-
  19674. The namespace of the Secret resource being referred to.
  19675. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19676. maxLength: 63
  19677. minLength: 1
  19678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19679. type: string
  19680. type: object
  19681. keySecretRef:
  19682. description: |-
  19683. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19684. In some instances, `key` is a required field.
  19685. properties:
  19686. key:
  19687. description: |-
  19688. A key in the referenced Secret.
  19689. Some instances of this field may be defaulted, in others it may be required.
  19690. maxLength: 253
  19691. minLength: 1
  19692. pattern: ^[-._a-zA-Z0-9]+$
  19693. type: string
  19694. name:
  19695. description: The name of the Secret resource being referred to.
  19696. maxLength: 253
  19697. minLength: 1
  19698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19699. type: string
  19700. namespace:
  19701. description: |-
  19702. The namespace of the Secret resource being referred to.
  19703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19704. maxLength: 63
  19705. minLength: 1
  19706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19707. type: string
  19708. type: object
  19709. required:
  19710. - certSecretRef
  19711. - keySecretRef
  19712. type: object
  19713. token:
  19714. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  19715. properties:
  19716. tokenSecretRef:
  19717. description: |-
  19718. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19719. In some instances, `key` is a required field.
  19720. properties:
  19721. key:
  19722. description: |-
  19723. A key in the referenced Secret.
  19724. Some instances of this field may be defaulted, in others it may be required.
  19725. maxLength: 253
  19726. minLength: 1
  19727. pattern: ^[-._a-zA-Z0-9]+$
  19728. type: string
  19729. name:
  19730. description: The name of the Secret resource being referred to.
  19731. maxLength: 253
  19732. minLength: 1
  19733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19734. type: string
  19735. namespace:
  19736. description: |-
  19737. The namespace of the Secret resource being referred to.
  19738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19739. maxLength: 63
  19740. minLength: 1
  19741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19742. type: string
  19743. type: object
  19744. required:
  19745. - tokenSecretRef
  19746. type: object
  19747. type: object
  19748. casRequired:
  19749. description: 'Enables or disables check-and-set (CAS) (default: false).'
  19750. type: boolean
  19751. okmsTimeout:
  19752. default: 30
  19753. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  19754. format: int32
  19755. minimum: 1
  19756. type: integer
  19757. okmsid:
  19758. description: specifies the OKMS ID.
  19759. type: string
  19760. server:
  19761. description: specifies the OKMS server endpoint.
  19762. type: string
  19763. required:
  19764. - auth
  19765. - okmsid
  19766. - server
  19767. type: object
  19768. passbolt:
  19769. description: |-
  19770. PassboltProvider provides access to Passbolt secrets manager.
  19771. See: https://www.passbolt.com.
  19772. properties:
  19773. auth:
  19774. description: Auth defines the information necessary to authenticate against Passbolt Server
  19775. properties:
  19776. passwordSecretRef:
  19777. description: |-
  19778. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19779. In some instances, `key` is a required field.
  19780. properties:
  19781. key:
  19782. description: |-
  19783. A key in the referenced Secret.
  19784. Some instances of this field may be defaulted, in others it may be required.
  19785. maxLength: 253
  19786. minLength: 1
  19787. pattern: ^[-._a-zA-Z0-9]+$
  19788. type: string
  19789. name:
  19790. description: The name of the Secret resource being referred to.
  19791. maxLength: 253
  19792. minLength: 1
  19793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19794. type: string
  19795. namespace:
  19796. description: |-
  19797. The namespace of the Secret resource being referred to.
  19798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19799. maxLength: 63
  19800. minLength: 1
  19801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19802. type: string
  19803. type: object
  19804. privateKeySecretRef:
  19805. description: |-
  19806. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19807. In some instances, `key` is a required field.
  19808. properties:
  19809. key:
  19810. description: |-
  19811. A key in the referenced Secret.
  19812. Some instances of this field may be defaulted, in others it may be required.
  19813. maxLength: 253
  19814. minLength: 1
  19815. pattern: ^[-._a-zA-Z0-9]+$
  19816. type: string
  19817. name:
  19818. description: The name of the Secret resource being referred to.
  19819. maxLength: 253
  19820. minLength: 1
  19821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19822. type: string
  19823. namespace:
  19824. description: |-
  19825. The namespace of the Secret resource being referred to.
  19826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19827. maxLength: 63
  19828. minLength: 1
  19829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19830. type: string
  19831. type: object
  19832. required:
  19833. - passwordSecretRef
  19834. - privateKeySecretRef
  19835. type: object
  19836. caBundle:
  19837. description: |-
  19838. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  19839. if the Host URL is using HTTPS protocol. If not set the system root certificates
  19840. are used to validate the TLS connection.
  19841. format: byte
  19842. type: string
  19843. caProvider:
  19844. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  19845. properties:
  19846. key:
  19847. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19848. maxLength: 253
  19849. minLength: 1
  19850. pattern: ^[-._a-zA-Z0-9]+$
  19851. type: string
  19852. name:
  19853. description: The name of the object located at the provider type.
  19854. maxLength: 253
  19855. minLength: 1
  19856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19857. type: string
  19858. namespace:
  19859. description: |-
  19860. The namespace the Provider type is in.
  19861. Can only be defined when used in a ClusterSecretStore.
  19862. maxLength: 63
  19863. minLength: 1
  19864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19865. type: string
  19866. type:
  19867. description: The type of provider to use such as "Secret", or "ConfigMap".
  19868. enum:
  19869. - Secret
  19870. - ConfigMap
  19871. type: string
  19872. required:
  19873. - name
  19874. - type
  19875. type: object
  19876. host:
  19877. description: Host defines the Passbolt Server to connect to
  19878. type: string
  19879. required:
  19880. - auth
  19881. - host
  19882. type: object
  19883. passworddepot:
  19884. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  19885. properties:
  19886. auth:
  19887. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  19888. properties:
  19889. secretRef:
  19890. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  19891. properties:
  19892. credentials:
  19893. description: Username / Password is used for authentication.
  19894. properties:
  19895. key:
  19896. description: |-
  19897. A key in the referenced Secret.
  19898. Some instances of this field may be defaulted, in others it may be required.
  19899. maxLength: 253
  19900. minLength: 1
  19901. pattern: ^[-._a-zA-Z0-9]+$
  19902. type: string
  19903. name:
  19904. description: The name of the Secret resource being referred to.
  19905. maxLength: 253
  19906. minLength: 1
  19907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19908. type: string
  19909. namespace:
  19910. description: |-
  19911. The namespace of the Secret resource being referred to.
  19912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19913. maxLength: 63
  19914. minLength: 1
  19915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19916. type: string
  19917. type: object
  19918. type: object
  19919. required:
  19920. - secretRef
  19921. type: object
  19922. database:
  19923. description: Database to use as source
  19924. type: string
  19925. host:
  19926. description: URL configures the Password Depot instance URL.
  19927. type: string
  19928. required:
  19929. - auth
  19930. - database
  19931. - host
  19932. type: object
  19933. previder:
  19934. description: Previder configures this store to sync secrets using the Previder provider
  19935. properties:
  19936. auth:
  19937. description: PreviderAuth contains a secretRef for credentials.
  19938. properties:
  19939. secretRef:
  19940. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  19941. properties:
  19942. accessToken:
  19943. description: The AccessToken is used for authentication
  19944. properties:
  19945. key:
  19946. description: |-
  19947. A key in the referenced Secret.
  19948. Some instances of this field may be defaulted, in others it may be required.
  19949. maxLength: 253
  19950. minLength: 1
  19951. pattern: ^[-._a-zA-Z0-9]+$
  19952. type: string
  19953. name:
  19954. description: The name of the Secret resource being referred to.
  19955. maxLength: 253
  19956. minLength: 1
  19957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19958. type: string
  19959. namespace:
  19960. description: |-
  19961. The namespace of the Secret resource being referred to.
  19962. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19963. maxLength: 63
  19964. minLength: 1
  19965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19966. type: string
  19967. type: object
  19968. required:
  19969. - accessToken
  19970. type: object
  19971. type: object
  19972. baseUri:
  19973. type: string
  19974. required:
  19975. - auth
  19976. type: object
  19977. pulumi:
  19978. description: Pulumi configures this store to sync secrets using the Pulumi provider
  19979. properties:
  19980. accessToken:
  19981. description: |-
  19982. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  19983. Deprecated: Use auth.accessToken instead.
  19984. properties:
  19985. secretRef:
  19986. description: SecretRef is a reference to a secret containing the Pulumi API token.
  19987. properties:
  19988. key:
  19989. description: |-
  19990. A key in the referenced Secret.
  19991. Some instances of this field may be defaulted, in others it may be required.
  19992. maxLength: 253
  19993. minLength: 1
  19994. pattern: ^[-._a-zA-Z0-9]+$
  19995. type: string
  19996. name:
  19997. description: The name of the Secret resource being referred to.
  19998. maxLength: 253
  19999. minLength: 1
  20000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20001. type: string
  20002. namespace:
  20003. description: |-
  20004. The namespace of the Secret resource being referred to.
  20005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20006. maxLength: 63
  20007. minLength: 1
  20008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20009. type: string
  20010. type: object
  20011. type: object
  20012. apiUrl:
  20013. default: https://api.pulumi.com/api/esc
  20014. description: APIURL is the URL of the Pulumi API.
  20015. type: string
  20016. auth:
  20017. description: |-
  20018. Auth configures how the Operator authenticates with the Pulumi API.
  20019. Either auth or the deprecated accessToken field must be specified.
  20020. properties:
  20021. accessToken:
  20022. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20023. properties:
  20024. secretRef:
  20025. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20026. properties:
  20027. key:
  20028. description: |-
  20029. A key in the referenced Secret.
  20030. Some instances of this field may be defaulted, in others it may be required.
  20031. maxLength: 253
  20032. minLength: 1
  20033. pattern: ^[-._a-zA-Z0-9]+$
  20034. type: string
  20035. name:
  20036. description: The name of the Secret resource being referred to.
  20037. maxLength: 253
  20038. minLength: 1
  20039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20040. type: string
  20041. namespace:
  20042. description: |-
  20043. The namespace of the Secret resource being referred to.
  20044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20045. maxLength: 63
  20046. minLength: 1
  20047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20048. type: string
  20049. type: object
  20050. type: object
  20051. oidcConfig:
  20052. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20053. properties:
  20054. expirationSeconds:
  20055. default: 600
  20056. description: |-
  20057. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20058. Defaults to 10 minutes.
  20059. format: int64
  20060. minimum: 600
  20061. type: integer
  20062. organization:
  20063. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20064. type: string
  20065. serviceAccountRef:
  20066. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20067. properties:
  20068. audiences:
  20069. description: |-
  20070. Audience specifies the `aud` claim for the service account token
  20071. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20072. then this audiences will be appended to the list
  20073. items:
  20074. type: string
  20075. type: array
  20076. name:
  20077. description: The name of the ServiceAccount resource being referred to.
  20078. maxLength: 253
  20079. minLength: 1
  20080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20081. type: string
  20082. namespace:
  20083. description: |-
  20084. Namespace of the resource being referred to.
  20085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20086. maxLength: 63
  20087. minLength: 1
  20088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20089. type: string
  20090. required:
  20091. - name
  20092. type: object
  20093. required:
  20094. - organization
  20095. - serviceAccountRef
  20096. type: object
  20097. type: object
  20098. x-kubernetes-validations:
  20099. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20100. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20101. environment:
  20102. description: |-
  20103. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20104. dynamically retrieved values from supported providers including all major clouds,
  20105. and other Pulumi ESC environments.
  20106. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20107. type: string
  20108. organization:
  20109. description: |-
  20110. Organization are a space to collaborate on shared projects and stacks.
  20111. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20112. type: string
  20113. project:
  20114. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20115. type: string
  20116. required:
  20117. - environment
  20118. - organization
  20119. - project
  20120. type: object
  20121. x-kubernetes-validations:
  20122. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20123. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20124. scaleway:
  20125. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20126. properties:
  20127. accessKey:
  20128. description: AccessKey is the non-secret part of the api key.
  20129. properties:
  20130. secretRef:
  20131. description: SecretRef references a key in a secret that will be used as value.
  20132. properties:
  20133. key:
  20134. description: |-
  20135. A key in the referenced Secret.
  20136. Some instances of this field may be defaulted, in others it may be required.
  20137. maxLength: 253
  20138. minLength: 1
  20139. pattern: ^[-._a-zA-Z0-9]+$
  20140. type: string
  20141. name:
  20142. description: The name of the Secret resource being referred to.
  20143. maxLength: 253
  20144. minLength: 1
  20145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20146. type: string
  20147. namespace:
  20148. description: |-
  20149. The namespace of the Secret resource being referred to.
  20150. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20151. maxLength: 63
  20152. minLength: 1
  20153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20154. type: string
  20155. type: object
  20156. value:
  20157. description: Value can be specified directly to set a value without using a secret.
  20158. type: string
  20159. type: object
  20160. apiUrl:
  20161. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20162. type: string
  20163. projectId:
  20164. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20165. type: string
  20166. region:
  20167. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20168. type: string
  20169. secretKey:
  20170. description: SecretKey is the non-secret part of the api key.
  20171. properties:
  20172. secretRef:
  20173. description: SecretRef references a key in a secret that will be used as value.
  20174. properties:
  20175. key:
  20176. description: |-
  20177. A key in the referenced Secret.
  20178. Some instances of this field may be defaulted, in others it may be required.
  20179. maxLength: 253
  20180. minLength: 1
  20181. pattern: ^[-._a-zA-Z0-9]+$
  20182. type: string
  20183. name:
  20184. description: The name of the Secret resource being referred to.
  20185. maxLength: 253
  20186. minLength: 1
  20187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20188. type: string
  20189. namespace:
  20190. description: |-
  20191. The namespace of the Secret resource being referred to.
  20192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20193. maxLength: 63
  20194. minLength: 1
  20195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20196. type: string
  20197. type: object
  20198. value:
  20199. description: Value can be specified directly to set a value without using a secret.
  20200. type: string
  20201. type: object
  20202. required:
  20203. - accessKey
  20204. - projectId
  20205. - region
  20206. - secretKey
  20207. type: object
  20208. secretserver:
  20209. description: |-
  20210. SecretServer configures this store to sync secrets using SecretServer provider
  20211. https://docs.delinea.com/online-help/secret-server/start.htm
  20212. properties:
  20213. caBundle:
  20214. description: |-
  20215. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20216. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20217. are used to validate the TLS connection.
  20218. format: byte
  20219. type: string
  20220. caProvider:
  20221. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20222. properties:
  20223. key:
  20224. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20225. maxLength: 253
  20226. minLength: 1
  20227. pattern: ^[-._a-zA-Z0-9]+$
  20228. type: string
  20229. name:
  20230. description: The name of the object located at the provider type.
  20231. maxLength: 253
  20232. minLength: 1
  20233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20234. type: string
  20235. namespace:
  20236. description: |-
  20237. The namespace the Provider type is in.
  20238. Can only be defined when used in a ClusterSecretStore.
  20239. maxLength: 63
  20240. minLength: 1
  20241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20242. type: string
  20243. type:
  20244. description: The type of provider to use such as "Secret", or "ConfigMap".
  20245. enum:
  20246. - Secret
  20247. - ConfigMap
  20248. type: string
  20249. required:
  20250. - name
  20251. - type
  20252. type: object
  20253. domain:
  20254. description: Domain is the secret server domain.
  20255. type: string
  20256. password:
  20257. description: |-
  20258. Password is the secret server account password.
  20259. Required unless Token is set.
  20260. properties:
  20261. secretRef:
  20262. description: SecretRef references a key in a secret that will be used as value.
  20263. properties:
  20264. key:
  20265. description: |-
  20266. A key in the referenced Secret.
  20267. Some instances of this field may be defaulted, in others it may be required.
  20268. maxLength: 253
  20269. minLength: 1
  20270. pattern: ^[-._a-zA-Z0-9]+$
  20271. type: string
  20272. name:
  20273. description: The name of the Secret resource being referred to.
  20274. maxLength: 253
  20275. minLength: 1
  20276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20277. type: string
  20278. namespace:
  20279. description: |-
  20280. The namespace of the Secret resource being referred to.
  20281. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20282. maxLength: 63
  20283. minLength: 1
  20284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20285. type: string
  20286. type: object
  20287. value:
  20288. description: Value can be specified directly to set a value without using a secret.
  20289. minLength: 1
  20290. type: string
  20291. type: object
  20292. x-kubernetes-validations:
  20293. - message: exactly one of value or secretRef must be set
  20294. rule: has(self.value) != has(self.secretRef)
  20295. serverURL:
  20296. description: |-
  20297. ServerURL
  20298. URL to your secret server installation
  20299. type: string
  20300. token:
  20301. description: |-
  20302. Token is an access token used to authenticate to the secret server,
  20303. as an alternative to Username and Password. When set, Username and
  20304. Password are not required and are ignored.
  20305. properties:
  20306. secretRef:
  20307. description: SecretRef references a key in a secret that will be used as value.
  20308. properties:
  20309. key:
  20310. description: |-
  20311. A key in the referenced Secret.
  20312. Some instances of this field may be defaulted, in others it may be required.
  20313. maxLength: 253
  20314. minLength: 1
  20315. pattern: ^[-._a-zA-Z0-9]+$
  20316. type: string
  20317. name:
  20318. description: The name of the Secret resource being referred to.
  20319. maxLength: 253
  20320. minLength: 1
  20321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20322. type: string
  20323. namespace:
  20324. description: |-
  20325. The namespace of the Secret resource being referred to.
  20326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20327. maxLength: 63
  20328. minLength: 1
  20329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20330. type: string
  20331. type: object
  20332. value:
  20333. description: Value can be specified directly to set a value without using a secret.
  20334. minLength: 1
  20335. type: string
  20336. type: object
  20337. x-kubernetes-validations:
  20338. - message: exactly one of value or secretRef must be set
  20339. rule: has(self.value) != has(self.secretRef)
  20340. username:
  20341. description: |-
  20342. Username is the secret server account username.
  20343. Required unless Token is set.
  20344. properties:
  20345. secretRef:
  20346. description: SecretRef references a key in a secret that will be used as value.
  20347. properties:
  20348. key:
  20349. description: |-
  20350. A key in the referenced Secret.
  20351. Some instances of this field may be defaulted, in others it may be required.
  20352. maxLength: 253
  20353. minLength: 1
  20354. pattern: ^[-._a-zA-Z0-9]+$
  20355. type: string
  20356. name:
  20357. description: The name of the Secret resource being referred to.
  20358. maxLength: 253
  20359. minLength: 1
  20360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20361. type: string
  20362. namespace:
  20363. description: |-
  20364. The namespace of the Secret resource being referred to.
  20365. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20366. maxLength: 63
  20367. minLength: 1
  20368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20369. type: string
  20370. type: object
  20371. value:
  20372. description: Value can be specified directly to set a value without using a secret.
  20373. minLength: 1
  20374. type: string
  20375. type: object
  20376. x-kubernetes-validations:
  20377. - message: exactly one of value or secretRef must be set
  20378. rule: has(self.value) != has(self.secretRef)
  20379. required:
  20380. - serverURL
  20381. type: object
  20382. x-kubernetes-validations:
  20383. - message: either token, or both username and password, must be set
  20384. rule: has(self.token) || (has(self.username) && has(self.password))
  20385. senhasegura:
  20386. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20387. properties:
  20388. auth:
  20389. description: Auth defines parameters to authenticate in senhasegura
  20390. properties:
  20391. clientId:
  20392. type: string
  20393. clientSecretSecretRef:
  20394. description: |-
  20395. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20396. In some instances, `key` is a required field.
  20397. properties:
  20398. key:
  20399. description: |-
  20400. A key in the referenced Secret.
  20401. Some instances of this field may be defaulted, in others it may be required.
  20402. maxLength: 253
  20403. minLength: 1
  20404. pattern: ^[-._a-zA-Z0-9]+$
  20405. type: string
  20406. name:
  20407. description: The name of the Secret resource being referred to.
  20408. maxLength: 253
  20409. minLength: 1
  20410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20411. type: string
  20412. namespace:
  20413. description: |-
  20414. The namespace of the Secret resource being referred to.
  20415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20416. maxLength: 63
  20417. minLength: 1
  20418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20419. type: string
  20420. type: object
  20421. required:
  20422. - clientId
  20423. - clientSecretSecretRef
  20424. type: object
  20425. ignoreSslCertificate:
  20426. default: false
  20427. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  20428. type: boolean
  20429. module:
  20430. description: Module defines which senhasegura module should be used to get secrets
  20431. type: string
  20432. url:
  20433. description: URL of senhasegura
  20434. type: string
  20435. required:
  20436. - auth
  20437. - module
  20438. - url
  20439. type: object
  20440. vault:
  20441. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  20442. properties:
  20443. auth:
  20444. description: Auth configures how secret-manager authenticates with the Vault server.
  20445. properties:
  20446. appRole:
  20447. description: |-
  20448. AppRole authenticates with Vault using the App Role auth mechanism,
  20449. with the role and secret stored in a Kubernetes Secret resource.
  20450. properties:
  20451. path:
  20452. default: approle
  20453. description: |-
  20454. Path where the App Role authentication backend is mounted
  20455. in Vault, e.g: "approle"
  20456. type: string
  20457. roleId:
  20458. description: |-
  20459. RoleID configured in the App Role authentication backend when setting
  20460. up the authentication backend in Vault.
  20461. type: string
  20462. roleRef:
  20463. description: |-
  20464. Reference to a key in a Secret that contains the App Role ID used
  20465. to authenticate with Vault.
  20466. The `key` field must be specified and denotes which entry within the Secret
  20467. resource is used as the app role id.
  20468. properties:
  20469. key:
  20470. description: |-
  20471. A key in the referenced Secret.
  20472. Some instances of this field may be defaulted, in others it may be required.
  20473. maxLength: 253
  20474. minLength: 1
  20475. pattern: ^[-._a-zA-Z0-9]+$
  20476. type: string
  20477. name:
  20478. description: The name of the Secret resource being referred to.
  20479. maxLength: 253
  20480. minLength: 1
  20481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20482. type: string
  20483. namespace:
  20484. description: |-
  20485. The namespace of the Secret resource being referred to.
  20486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20487. maxLength: 63
  20488. minLength: 1
  20489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20490. type: string
  20491. type: object
  20492. secretRef:
  20493. description: |-
  20494. Reference to a key in a Secret that contains the App Role secret used
  20495. to authenticate with Vault.
  20496. The `key` field must be specified and denotes which entry within the Secret
  20497. resource is used as the app role secret.
  20498. properties:
  20499. key:
  20500. description: |-
  20501. A key in the referenced Secret.
  20502. Some instances of this field may be defaulted, in others it may be required.
  20503. maxLength: 253
  20504. minLength: 1
  20505. pattern: ^[-._a-zA-Z0-9]+$
  20506. type: string
  20507. name:
  20508. description: The name of the Secret resource being referred to.
  20509. maxLength: 253
  20510. minLength: 1
  20511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20512. type: string
  20513. namespace:
  20514. description: |-
  20515. The namespace of the Secret resource being referred to.
  20516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20517. maxLength: 63
  20518. minLength: 1
  20519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20520. type: string
  20521. type: object
  20522. required:
  20523. - path
  20524. - secretRef
  20525. type: object
  20526. cert:
  20527. description: |-
  20528. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  20529. Cert authentication method
  20530. properties:
  20531. clientCert:
  20532. description: |-
  20533. ClientCert is a certificate to authenticate using the Cert Vault
  20534. authentication method
  20535. properties:
  20536. key:
  20537. description: |-
  20538. A key in the referenced Secret.
  20539. Some instances of this field may be defaulted, in others it may be required.
  20540. maxLength: 253
  20541. minLength: 1
  20542. pattern: ^[-._a-zA-Z0-9]+$
  20543. type: string
  20544. name:
  20545. description: The name of the Secret resource being referred to.
  20546. maxLength: 253
  20547. minLength: 1
  20548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20549. type: string
  20550. namespace:
  20551. description: |-
  20552. The namespace of the Secret resource being referred to.
  20553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20554. maxLength: 63
  20555. minLength: 1
  20556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20557. type: string
  20558. type: object
  20559. path:
  20560. default: cert
  20561. description: |-
  20562. Path where the Certificate authentication backend is mounted
  20563. in Vault, e.g: "cert"
  20564. type: string
  20565. secretRef:
  20566. description: |-
  20567. SecretRef to a key in a Secret resource containing client private key to
  20568. authenticate with Vault using the Cert authentication method
  20569. properties:
  20570. key:
  20571. description: |-
  20572. A key in the referenced Secret.
  20573. Some instances of this field may be defaulted, in others it may be required.
  20574. maxLength: 253
  20575. minLength: 1
  20576. pattern: ^[-._a-zA-Z0-9]+$
  20577. type: string
  20578. name:
  20579. description: The name of the Secret resource being referred to.
  20580. maxLength: 253
  20581. minLength: 1
  20582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20583. type: string
  20584. namespace:
  20585. description: |-
  20586. The namespace of the Secret resource being referred to.
  20587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20588. maxLength: 63
  20589. minLength: 1
  20590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20591. type: string
  20592. type: object
  20593. vaultRole:
  20594. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  20595. type: string
  20596. type: object
  20597. gcp:
  20598. description: |-
  20599. Gcp authenticates with Vault using Google Cloud Platform authentication method
  20600. GCP authentication method
  20601. properties:
  20602. location:
  20603. description: Location optionally defines a location/region for the secret
  20604. type: string
  20605. path:
  20606. default: gcp
  20607. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  20608. type: string
  20609. projectID:
  20610. description: Project ID of the Google Cloud Platform project
  20611. type: string
  20612. role:
  20613. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  20614. type: string
  20615. secretRef:
  20616. description: Specify credentials in a Secret object
  20617. properties:
  20618. secretAccessKeySecretRef:
  20619. description: The SecretAccessKey is used for authentication
  20620. properties:
  20621. key:
  20622. description: |-
  20623. A key in the referenced Secret.
  20624. Some instances of this field may be defaulted, in others it may be required.
  20625. maxLength: 253
  20626. minLength: 1
  20627. pattern: ^[-._a-zA-Z0-9]+$
  20628. type: string
  20629. name:
  20630. description: The name of the Secret resource being referred to.
  20631. maxLength: 253
  20632. minLength: 1
  20633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20634. type: string
  20635. namespace:
  20636. description: |-
  20637. The namespace of the Secret resource being referred to.
  20638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20639. maxLength: 63
  20640. minLength: 1
  20641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20642. type: string
  20643. type: object
  20644. type: object
  20645. serviceAccountRef:
  20646. description: ServiceAccountRef to a service account for impersonation
  20647. properties:
  20648. audiences:
  20649. description: |-
  20650. Audience specifies the `aud` claim for the service account token
  20651. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20652. then this audiences will be appended to the list
  20653. items:
  20654. type: string
  20655. type: array
  20656. name:
  20657. description: The name of the ServiceAccount resource being referred to.
  20658. maxLength: 253
  20659. minLength: 1
  20660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20661. type: string
  20662. namespace:
  20663. description: |-
  20664. Namespace of the resource being referred to.
  20665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20666. maxLength: 63
  20667. minLength: 1
  20668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20669. type: string
  20670. required:
  20671. - name
  20672. type: object
  20673. workloadIdentity:
  20674. description: Specify a service account with Workload Identity
  20675. properties:
  20676. clusterLocation:
  20677. description: |-
  20678. ClusterLocation is the location of the cluster
  20679. If not specified, it fetches information from the metadata server
  20680. type: string
  20681. clusterName:
  20682. description: |-
  20683. ClusterName is the name of the cluster
  20684. If not specified, it fetches information from the metadata server
  20685. type: string
  20686. clusterProjectID:
  20687. description: |-
  20688. ClusterProjectID is the project ID of the cluster
  20689. If not specified, it fetches information from the metadata server
  20690. type: string
  20691. serviceAccountRef:
  20692. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  20693. properties:
  20694. audiences:
  20695. description: |-
  20696. Audience specifies the `aud` claim for the service account token
  20697. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20698. then this audiences will be appended to the list
  20699. items:
  20700. type: string
  20701. type: array
  20702. name:
  20703. description: The name of the ServiceAccount resource being referred to.
  20704. maxLength: 253
  20705. minLength: 1
  20706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20707. type: string
  20708. namespace:
  20709. description: |-
  20710. Namespace of the resource being referred to.
  20711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20712. maxLength: 63
  20713. minLength: 1
  20714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20715. type: string
  20716. required:
  20717. - name
  20718. type: object
  20719. required:
  20720. - serviceAccountRef
  20721. type: object
  20722. required:
  20723. - role
  20724. type: object
  20725. iam:
  20726. description: |-
  20727. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  20728. AWS IAM authentication method
  20729. properties:
  20730. externalID:
  20731. description: AWS External ID set on assumed IAM roles
  20732. type: string
  20733. jwt:
  20734. description: Specify a service account with IRSA enabled
  20735. properties:
  20736. serviceAccountRef:
  20737. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  20738. properties:
  20739. audiences:
  20740. description: |-
  20741. Audience specifies the `aud` claim for the service account token
  20742. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20743. then this audiences will be appended to the list
  20744. items:
  20745. type: string
  20746. type: array
  20747. name:
  20748. description: The name of the ServiceAccount resource being referred to.
  20749. maxLength: 253
  20750. minLength: 1
  20751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20752. type: string
  20753. namespace:
  20754. description: |-
  20755. Namespace of the resource being referred to.
  20756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20757. maxLength: 63
  20758. minLength: 1
  20759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20760. type: string
  20761. required:
  20762. - name
  20763. type: object
  20764. type: object
  20765. path:
  20766. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  20767. type: string
  20768. region:
  20769. description: AWS region
  20770. type: string
  20771. role:
  20772. description: This is the AWS role to be assumed before talking to vault
  20773. type: string
  20774. secretRef:
  20775. description: Specify credentials in a Secret object
  20776. properties:
  20777. accessKeyIDSecretRef:
  20778. description: The AccessKeyID is used for authentication
  20779. properties:
  20780. key:
  20781. description: |-
  20782. A key in the referenced Secret.
  20783. Some instances of this field may be defaulted, in others it may be required.
  20784. maxLength: 253
  20785. minLength: 1
  20786. pattern: ^[-._a-zA-Z0-9]+$
  20787. type: string
  20788. name:
  20789. description: The name of the Secret resource being referred to.
  20790. maxLength: 253
  20791. minLength: 1
  20792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20793. type: string
  20794. namespace:
  20795. description: |-
  20796. The namespace of the Secret resource being referred to.
  20797. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20798. maxLength: 63
  20799. minLength: 1
  20800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20801. type: string
  20802. type: object
  20803. secretAccessKeySecretRef:
  20804. description: The SecretAccessKey is used for authentication
  20805. properties:
  20806. key:
  20807. description: |-
  20808. A key in the referenced Secret.
  20809. Some instances of this field may be defaulted, in others it may be required.
  20810. maxLength: 253
  20811. minLength: 1
  20812. pattern: ^[-._a-zA-Z0-9]+$
  20813. type: string
  20814. name:
  20815. description: The name of the Secret resource being referred to.
  20816. maxLength: 253
  20817. minLength: 1
  20818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20819. type: string
  20820. namespace:
  20821. description: |-
  20822. The namespace of the Secret resource being referred to.
  20823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20824. maxLength: 63
  20825. minLength: 1
  20826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20827. type: string
  20828. type: object
  20829. sessionTokenSecretRef:
  20830. description: |-
  20831. The SessionToken used for authentication
  20832. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  20833. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  20834. properties:
  20835. key:
  20836. description: |-
  20837. A key in the referenced Secret.
  20838. Some instances of this field may be defaulted, in others it may be required.
  20839. maxLength: 253
  20840. minLength: 1
  20841. pattern: ^[-._a-zA-Z0-9]+$
  20842. type: string
  20843. name:
  20844. description: The name of the Secret resource being referred to.
  20845. maxLength: 253
  20846. minLength: 1
  20847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20848. type: string
  20849. namespace:
  20850. description: |-
  20851. The namespace of the Secret resource being referred to.
  20852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20853. maxLength: 63
  20854. minLength: 1
  20855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20856. type: string
  20857. type: object
  20858. type: object
  20859. vaultAwsIamServerID:
  20860. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  20861. type: string
  20862. vaultRole:
  20863. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  20864. type: string
  20865. required:
  20866. - vaultRole
  20867. type: object
  20868. jwt:
  20869. description: |-
  20870. Jwt authenticates with Vault by passing role and JWT token using the
  20871. JWT/OIDC authentication method
  20872. properties:
  20873. kubernetesServiceAccountToken:
  20874. description: |-
  20875. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  20876. a token for with the `TokenRequest` API.
  20877. properties:
  20878. audiences:
  20879. description: |-
  20880. Optional audiences field that will be used to request a temporary Kubernetes service
  20881. account token for the service account referenced by `serviceAccountRef`.
  20882. Defaults to a single audience `vault` it not specified.
  20883. Deprecated: use serviceAccountRef.Audiences instead
  20884. items:
  20885. type: string
  20886. type: array
  20887. expirationSeconds:
  20888. description: |-
  20889. Optional expiration time in seconds that will be used to request a temporary
  20890. Kubernetes service account token for the service account referenced by
  20891. `serviceAccountRef`.
  20892. Deprecated: this will be removed in the future.
  20893. Defaults to 10 minutes.
  20894. format: int64
  20895. type: integer
  20896. serviceAccountRef:
  20897. description: Service account field containing the name of a kubernetes ServiceAccount.
  20898. properties:
  20899. audiences:
  20900. description: |-
  20901. Audience specifies the `aud` claim for the service account token
  20902. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20903. then this audiences will be appended to the list
  20904. items:
  20905. type: string
  20906. type: array
  20907. name:
  20908. description: The name of the ServiceAccount resource being referred to.
  20909. maxLength: 253
  20910. minLength: 1
  20911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20912. type: string
  20913. namespace:
  20914. description: |-
  20915. Namespace of the resource being referred to.
  20916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20917. maxLength: 63
  20918. minLength: 1
  20919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20920. type: string
  20921. required:
  20922. - name
  20923. type: object
  20924. required:
  20925. - serviceAccountRef
  20926. type: object
  20927. path:
  20928. default: jwt
  20929. description: |-
  20930. Path where the JWT authentication backend is mounted
  20931. in Vault, e.g: "jwt"
  20932. type: string
  20933. role:
  20934. description: |-
  20935. Role is a JWT role to authenticate using the JWT/OIDC Vault
  20936. authentication method
  20937. type: string
  20938. secretRef:
  20939. description: |-
  20940. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  20941. authenticate with Vault using the JWT/OIDC authentication method.
  20942. properties:
  20943. key:
  20944. description: |-
  20945. A key in the referenced Secret.
  20946. Some instances of this field may be defaulted, in others it may be required.
  20947. maxLength: 253
  20948. minLength: 1
  20949. pattern: ^[-._a-zA-Z0-9]+$
  20950. type: string
  20951. name:
  20952. description: The name of the Secret resource being referred to.
  20953. maxLength: 253
  20954. minLength: 1
  20955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20956. type: string
  20957. namespace:
  20958. description: |-
  20959. The namespace of the Secret resource being referred to.
  20960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20961. maxLength: 63
  20962. minLength: 1
  20963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20964. type: string
  20965. type: object
  20966. required:
  20967. - path
  20968. type: object
  20969. kubernetes:
  20970. description: |-
  20971. Kubernetes authenticates with Vault by passing the ServiceAccount
  20972. token stored in the named Secret resource to the Vault server.
  20973. properties:
  20974. mountPath:
  20975. default: kubernetes
  20976. description: |-
  20977. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  20978. "kubernetes"
  20979. type: string
  20980. role:
  20981. description: |-
  20982. A required field containing the Vault Role to assume. A Role binds a
  20983. Kubernetes ServiceAccount with a set of Vault policies.
  20984. type: string
  20985. secretRef:
  20986. description: |-
  20987. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20988. for authenticating with Vault. If a name is specified without a key,
  20989. `token` is the default. If one is not specified, the one bound to
  20990. the controller will be used.
  20991. properties:
  20992. key:
  20993. description: |-
  20994. A key in the referenced Secret.
  20995. Some instances of this field may be defaulted, in others it may be required.
  20996. maxLength: 253
  20997. minLength: 1
  20998. pattern: ^[-._a-zA-Z0-9]+$
  20999. type: string
  21000. name:
  21001. description: The name of the Secret resource being referred to.
  21002. maxLength: 253
  21003. minLength: 1
  21004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21005. type: string
  21006. namespace:
  21007. description: |-
  21008. The namespace of the Secret resource being referred to.
  21009. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21010. maxLength: 63
  21011. minLength: 1
  21012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21013. type: string
  21014. type: object
  21015. serviceAccountRef:
  21016. description: |-
  21017. Optional service account field containing the name of a kubernetes ServiceAccount.
  21018. If the service account is specified, the service account secret token JWT will be used
  21019. for authenticating with Vault. If the service account selector is not supplied,
  21020. the secretRef will be used instead.
  21021. properties:
  21022. audiences:
  21023. description: |-
  21024. Audience specifies the `aud` claim for the service account token
  21025. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21026. then this audiences will be appended to the list
  21027. items:
  21028. type: string
  21029. type: array
  21030. name:
  21031. description: The name of the ServiceAccount resource being referred to.
  21032. maxLength: 253
  21033. minLength: 1
  21034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21035. type: string
  21036. namespace:
  21037. description: |-
  21038. Namespace of the resource being referred to.
  21039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21040. maxLength: 63
  21041. minLength: 1
  21042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21043. type: string
  21044. required:
  21045. - name
  21046. type: object
  21047. required:
  21048. - mountPath
  21049. - role
  21050. type: object
  21051. ldap:
  21052. description: |-
  21053. Ldap authenticates with Vault by passing username/password pair using
  21054. the LDAP authentication method
  21055. properties:
  21056. path:
  21057. default: ldap
  21058. description: |-
  21059. Path where the LDAP authentication backend is mounted
  21060. in Vault, e.g: "ldap"
  21061. type: string
  21062. secretRef:
  21063. description: |-
  21064. SecretRef to a key in a Secret resource containing password for the LDAP
  21065. user used to authenticate with Vault using the LDAP authentication
  21066. method
  21067. properties:
  21068. key:
  21069. description: |-
  21070. A key in the referenced Secret.
  21071. Some instances of this field may be defaulted, in others it may be required.
  21072. maxLength: 253
  21073. minLength: 1
  21074. pattern: ^[-._a-zA-Z0-9]+$
  21075. type: string
  21076. name:
  21077. description: The name of the Secret resource being referred to.
  21078. maxLength: 253
  21079. minLength: 1
  21080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21081. type: string
  21082. namespace:
  21083. description: |-
  21084. The namespace of the Secret resource being referred to.
  21085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21086. maxLength: 63
  21087. minLength: 1
  21088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21089. type: string
  21090. type: object
  21091. username:
  21092. description: |-
  21093. Username is an LDAP username used to authenticate using the LDAP Vault
  21094. authentication method
  21095. type: string
  21096. required:
  21097. - path
  21098. - username
  21099. type: object
  21100. namespace:
  21101. description: |-
  21102. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21103. Namespaces is a set of features within Vault Enterprise that allows
  21104. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21105. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21106. This will default to Vault.Namespace field if set, or empty otherwise
  21107. type: string
  21108. tokenSecretRef:
  21109. description: TokenSecretRef authenticates with Vault by presenting a token.
  21110. properties:
  21111. key:
  21112. description: |-
  21113. A key in the referenced Secret.
  21114. Some instances of this field may be defaulted, in others it may be required.
  21115. maxLength: 253
  21116. minLength: 1
  21117. pattern: ^[-._a-zA-Z0-9]+$
  21118. type: string
  21119. name:
  21120. description: The name of the Secret resource being referred to.
  21121. maxLength: 253
  21122. minLength: 1
  21123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21124. type: string
  21125. namespace:
  21126. description: |-
  21127. The namespace of the Secret resource being referred to.
  21128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21129. maxLength: 63
  21130. minLength: 1
  21131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21132. type: string
  21133. type: object
  21134. userPass:
  21135. description: UserPass authenticates with Vault by passing username/password pair
  21136. properties:
  21137. path:
  21138. default: userpass
  21139. description: |-
  21140. Path where the UserPassword authentication backend is mounted
  21141. in Vault, e.g: "userpass"
  21142. type: string
  21143. secretRef:
  21144. description: |-
  21145. SecretRef to a key in a Secret resource containing password for the
  21146. user used to authenticate with Vault using the UserPass authentication
  21147. method
  21148. properties:
  21149. key:
  21150. description: |-
  21151. A key in the referenced Secret.
  21152. Some instances of this field may be defaulted, in others it may be required.
  21153. maxLength: 253
  21154. minLength: 1
  21155. pattern: ^[-._a-zA-Z0-9]+$
  21156. type: string
  21157. name:
  21158. description: The name of the Secret resource being referred to.
  21159. maxLength: 253
  21160. minLength: 1
  21161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21162. type: string
  21163. namespace:
  21164. description: |-
  21165. The namespace of the Secret resource being referred to.
  21166. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21167. maxLength: 63
  21168. minLength: 1
  21169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21170. type: string
  21171. type: object
  21172. username:
  21173. description: |-
  21174. Username is a username used to authenticate using the UserPass Vault
  21175. authentication method
  21176. type: string
  21177. required:
  21178. - path
  21179. - username
  21180. type: object
  21181. type: object
  21182. caBundle:
  21183. description: |-
  21184. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21185. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21186. plain HTTP protocol connection. If not set the system root certificates
  21187. are used to validate the TLS connection.
  21188. format: byte
  21189. type: string
  21190. caProvider:
  21191. description: The provider for the CA bundle to use to validate Vault server certificate.
  21192. properties:
  21193. key:
  21194. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21195. maxLength: 253
  21196. minLength: 1
  21197. pattern: ^[-._a-zA-Z0-9]+$
  21198. type: string
  21199. name:
  21200. description: The name of the object located at the provider type.
  21201. maxLength: 253
  21202. minLength: 1
  21203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21204. type: string
  21205. namespace:
  21206. description: |-
  21207. The namespace the Provider type is in.
  21208. Can only be defined when used in a ClusterSecretStore.
  21209. maxLength: 63
  21210. minLength: 1
  21211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21212. type: string
  21213. type:
  21214. description: The type of provider to use such as "Secret", or "ConfigMap".
  21215. enum:
  21216. - Secret
  21217. - ConfigMap
  21218. type: string
  21219. required:
  21220. - name
  21221. - type
  21222. type: object
  21223. checkAndSet:
  21224. description: |-
  21225. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21226. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21227. the current version of the secret to prevent unintentional overwrites.
  21228. properties:
  21229. required:
  21230. description: |-
  21231. Required when true, all write operations must include a check-and-set parameter.
  21232. This helps prevent unintentional overwrites of secrets.
  21233. type: boolean
  21234. type: object
  21235. forwardInconsistent:
  21236. description: |-
  21237. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21238. leader instead of simply retrying within a loop. This can increase performance if
  21239. the option is enabled serverside.
  21240. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21241. type: boolean
  21242. headers:
  21243. additionalProperties:
  21244. type: string
  21245. description: Headers to be added in Vault request
  21246. type: object
  21247. namespace:
  21248. description: |-
  21249. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21250. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21251. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21252. type: string
  21253. path:
  21254. description: |-
  21255. Path is the mount path of the Vault KV backend endpoint, e.g:
  21256. "secret". The v2 KV secret engine version specific "/data" path suffix
  21257. for fetching secrets from Vault is optional and will be appended
  21258. if not present in specified path.
  21259. type: string
  21260. readYourWrites:
  21261. description: |-
  21262. ReadYourWrites ensures isolated read-after-write semantics by
  21263. providing discovered cluster replication states in each request.
  21264. More information about eventual consistency in Vault can be found here
  21265. https://www.vaultproject.io/docs/enterprise/consistency
  21266. type: boolean
  21267. server:
  21268. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21269. type: string
  21270. tls:
  21271. description: |-
  21272. The configuration used for client side related TLS communication, when the Vault server
  21273. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21274. This parameter is ignored for plain HTTP protocol connection.
  21275. It's worth noting this configuration is different from the "TLS certificates auth method",
  21276. which is available under the `auth.cert` section.
  21277. properties:
  21278. certSecretRef:
  21279. description: |-
  21280. CertSecretRef is a certificate added to the transport layer
  21281. when communicating with the Vault server.
  21282. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21283. properties:
  21284. key:
  21285. description: |-
  21286. A key in the referenced Secret.
  21287. Some instances of this field may be defaulted, in others it may be required.
  21288. maxLength: 253
  21289. minLength: 1
  21290. pattern: ^[-._a-zA-Z0-9]+$
  21291. type: string
  21292. name:
  21293. description: The name of the Secret resource being referred to.
  21294. maxLength: 253
  21295. minLength: 1
  21296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21297. type: string
  21298. namespace:
  21299. description: |-
  21300. The namespace of the Secret resource being referred to.
  21301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21302. maxLength: 63
  21303. minLength: 1
  21304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21305. type: string
  21306. type: object
  21307. keySecretRef:
  21308. description: |-
  21309. KeySecretRef to a key in a Secret resource containing client private key
  21310. added to the transport layer when communicating with the Vault server.
  21311. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21312. properties:
  21313. key:
  21314. description: |-
  21315. A key in the referenced Secret.
  21316. Some instances of this field may be defaulted, in others it may be required.
  21317. maxLength: 253
  21318. minLength: 1
  21319. pattern: ^[-._a-zA-Z0-9]+$
  21320. type: string
  21321. name:
  21322. description: The name of the Secret resource being referred to.
  21323. maxLength: 253
  21324. minLength: 1
  21325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21326. type: string
  21327. namespace:
  21328. description: |-
  21329. The namespace of the Secret resource being referred to.
  21330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21331. maxLength: 63
  21332. minLength: 1
  21333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21334. type: string
  21335. type: object
  21336. type: object
  21337. version:
  21338. default: v2
  21339. description: |-
  21340. Version is the Vault KV secret engine version. This can be either "v1" or
  21341. "v2". Version defaults to "v2".
  21342. enum:
  21343. - v1
  21344. - v2
  21345. type: string
  21346. required:
  21347. - server
  21348. type: object
  21349. volcengine:
  21350. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21351. properties:
  21352. auth:
  21353. description: |-
  21354. Auth defines the authentication method to use.
  21355. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21356. properties:
  21357. secretRef:
  21358. description: |-
  21359. SecretRef defines the static credentials to use for authentication.
  21360. If not set, IRSA is used.
  21361. properties:
  21362. accessKeyID:
  21363. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21364. properties:
  21365. key:
  21366. description: |-
  21367. A key in the referenced Secret.
  21368. Some instances of this field may be defaulted, in others it may be required.
  21369. maxLength: 253
  21370. minLength: 1
  21371. pattern: ^[-._a-zA-Z0-9]+$
  21372. type: string
  21373. name:
  21374. description: The name of the Secret resource being referred to.
  21375. maxLength: 253
  21376. minLength: 1
  21377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21378. type: string
  21379. namespace:
  21380. description: |-
  21381. The namespace of the Secret resource being referred to.
  21382. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21383. maxLength: 63
  21384. minLength: 1
  21385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21386. type: string
  21387. type: object
  21388. secretAccessKey:
  21389. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21390. properties:
  21391. key:
  21392. description: |-
  21393. A key in the referenced Secret.
  21394. Some instances of this field may be defaulted, in others it may be required.
  21395. maxLength: 253
  21396. minLength: 1
  21397. pattern: ^[-._a-zA-Z0-9]+$
  21398. type: string
  21399. name:
  21400. description: The name of the Secret resource being referred to.
  21401. maxLength: 253
  21402. minLength: 1
  21403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21404. type: string
  21405. namespace:
  21406. description: |-
  21407. The namespace of the Secret resource being referred to.
  21408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21409. maxLength: 63
  21410. minLength: 1
  21411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21412. type: string
  21413. type: object
  21414. token:
  21415. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  21416. properties:
  21417. key:
  21418. description: |-
  21419. A key in the referenced Secret.
  21420. Some instances of this field may be defaulted, in others it may be required.
  21421. maxLength: 253
  21422. minLength: 1
  21423. pattern: ^[-._a-zA-Z0-9]+$
  21424. type: string
  21425. name:
  21426. description: The name of the Secret resource being referred to.
  21427. maxLength: 253
  21428. minLength: 1
  21429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21430. type: string
  21431. namespace:
  21432. description: |-
  21433. The namespace of the Secret resource being referred to.
  21434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21435. maxLength: 63
  21436. minLength: 1
  21437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21438. type: string
  21439. type: object
  21440. required:
  21441. - accessKeyID
  21442. - secretAccessKey
  21443. type: object
  21444. type: object
  21445. region:
  21446. description: Region specifies the Volcengine region to connect to.
  21447. type: string
  21448. required:
  21449. - region
  21450. type: object
  21451. webhook:
  21452. description: Webhook configures this store to sync secrets using a generic templated webhook
  21453. properties:
  21454. auth:
  21455. description: Auth specifies a authorization protocol. Only one protocol may be set.
  21456. maxProperties: 1
  21457. minProperties: 1
  21458. properties:
  21459. ntlm:
  21460. description: NTLMProtocol configures the store to use NTLM for auth
  21461. properties:
  21462. passwordSecret:
  21463. description: |-
  21464. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21465. In some instances, `key` is a required field.
  21466. properties:
  21467. key:
  21468. description: |-
  21469. A key in the referenced Secret.
  21470. Some instances of this field may be defaulted, in others it may be required.
  21471. maxLength: 253
  21472. minLength: 1
  21473. pattern: ^[-._a-zA-Z0-9]+$
  21474. type: string
  21475. name:
  21476. description: The name of the Secret resource being referred to.
  21477. maxLength: 253
  21478. minLength: 1
  21479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21480. type: string
  21481. namespace:
  21482. description: |-
  21483. The namespace of the Secret resource being referred to.
  21484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21485. maxLength: 63
  21486. minLength: 1
  21487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21488. type: string
  21489. type: object
  21490. usernameSecret:
  21491. description: |-
  21492. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21493. In some instances, `key` is a required field.
  21494. properties:
  21495. key:
  21496. description: |-
  21497. A key in the referenced Secret.
  21498. Some instances of this field may be defaulted, in others it may be required.
  21499. maxLength: 253
  21500. minLength: 1
  21501. pattern: ^[-._a-zA-Z0-9]+$
  21502. type: string
  21503. name:
  21504. description: The name of the Secret resource being referred to.
  21505. maxLength: 253
  21506. minLength: 1
  21507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21508. type: string
  21509. namespace:
  21510. description: |-
  21511. The namespace of the Secret resource being referred to.
  21512. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21513. maxLength: 63
  21514. minLength: 1
  21515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21516. type: string
  21517. type: object
  21518. required:
  21519. - passwordSecret
  21520. - usernameSecret
  21521. type: object
  21522. type: object
  21523. body:
  21524. description: Body
  21525. type: string
  21526. caBundle:
  21527. description: |-
  21528. PEM encoded CA bundle used to validate webhook server certificate. Only used
  21529. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21530. plain HTTP protocol connection. If not set the system root certificates
  21531. are used to validate the TLS connection.
  21532. format: byte
  21533. type: string
  21534. caProvider:
  21535. description: The provider for the CA bundle to use to validate webhook server certificate.
  21536. properties:
  21537. key:
  21538. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21539. maxLength: 253
  21540. minLength: 1
  21541. pattern: ^[-._a-zA-Z0-9]+$
  21542. type: string
  21543. name:
  21544. description: The name of the object located at the provider type.
  21545. maxLength: 253
  21546. minLength: 1
  21547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21548. type: string
  21549. namespace:
  21550. description: The namespace the Provider type is in.
  21551. maxLength: 63
  21552. minLength: 1
  21553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21554. type: string
  21555. type:
  21556. description: The type of provider to use such as "Secret", or "ConfigMap".
  21557. enum:
  21558. - Secret
  21559. - ConfigMap
  21560. type: string
  21561. required:
  21562. - name
  21563. - type
  21564. type: object
  21565. headers:
  21566. additionalProperties:
  21567. type: string
  21568. description: Headers
  21569. type: object
  21570. method:
  21571. description: Webhook Method
  21572. type: string
  21573. result:
  21574. description: Result formatting
  21575. properties:
  21576. jsonPath:
  21577. description: Json path of return value
  21578. type: string
  21579. type: object
  21580. secrets:
  21581. description: |-
  21582. Secrets to fill in templates
  21583. These secrets will be passed to the templating function as key value pairs under the given name
  21584. items:
  21585. description: WebhookSecret defines a secret that will be passed to the webhook request.
  21586. properties:
  21587. name:
  21588. description: Name of this secret in templates
  21589. type: string
  21590. secretRef:
  21591. description: Secret ref to fill in credentials
  21592. properties:
  21593. key:
  21594. description: |-
  21595. A key in the referenced Secret.
  21596. Some instances of this field may be defaulted, in others it may be required.
  21597. maxLength: 253
  21598. minLength: 1
  21599. pattern: ^[-._a-zA-Z0-9]+$
  21600. type: string
  21601. name:
  21602. description: The name of the Secret resource being referred to.
  21603. maxLength: 253
  21604. minLength: 1
  21605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21606. type: string
  21607. namespace:
  21608. description: |-
  21609. The namespace of the Secret resource being referred to.
  21610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21611. maxLength: 63
  21612. minLength: 1
  21613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21614. type: string
  21615. type: object
  21616. required:
  21617. - name
  21618. - secretRef
  21619. type: object
  21620. type: array
  21621. timeout:
  21622. description: Timeout
  21623. type: string
  21624. url:
  21625. description: Webhook url to call
  21626. type: string
  21627. required:
  21628. - url
  21629. type: object
  21630. yandexcertificatemanager:
  21631. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  21632. properties:
  21633. apiEndpoint:
  21634. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  21635. type: string
  21636. auth:
  21637. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  21638. properties:
  21639. authorizedKeySecretRef:
  21640. description: The authorized key used for authentication
  21641. properties:
  21642. key:
  21643. description: |-
  21644. A key in the referenced Secret.
  21645. Some instances of this field may be defaulted, in others it may be required.
  21646. maxLength: 253
  21647. minLength: 1
  21648. pattern: ^[-._a-zA-Z0-9]+$
  21649. type: string
  21650. name:
  21651. description: The name of the Secret resource being referred to.
  21652. maxLength: 253
  21653. minLength: 1
  21654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21655. type: string
  21656. namespace:
  21657. description: |-
  21658. The namespace of the Secret resource being referred to.
  21659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21660. maxLength: 63
  21661. minLength: 1
  21662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21663. type: string
  21664. type: object
  21665. type: object
  21666. caProvider:
  21667. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  21668. properties:
  21669. certSecretRef:
  21670. description: |-
  21671. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21672. In some instances, `key` is a required field.
  21673. properties:
  21674. key:
  21675. description: |-
  21676. A key in the referenced Secret.
  21677. Some instances of this field may be defaulted, in others it may be required.
  21678. maxLength: 253
  21679. minLength: 1
  21680. pattern: ^[-._a-zA-Z0-9]+$
  21681. type: string
  21682. name:
  21683. description: The name of the Secret resource being referred to.
  21684. maxLength: 253
  21685. minLength: 1
  21686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21687. type: string
  21688. namespace:
  21689. description: |-
  21690. The namespace of the Secret resource being referred to.
  21691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21692. maxLength: 63
  21693. minLength: 1
  21694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21695. type: string
  21696. type: object
  21697. type: object
  21698. fetching:
  21699. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  21700. maxProperties: 1
  21701. minProperties: 1
  21702. properties:
  21703. byID:
  21704. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  21705. type: object
  21706. byName:
  21707. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  21708. properties:
  21709. folderID:
  21710. description: The folder to fetch secrets from
  21711. type: string
  21712. required:
  21713. - folderID
  21714. type: object
  21715. type: object
  21716. required:
  21717. - auth
  21718. type: object
  21719. yandexlockbox:
  21720. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  21721. properties:
  21722. apiEndpoint:
  21723. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  21724. type: string
  21725. auth:
  21726. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  21727. properties:
  21728. authorizedKeySecretRef:
  21729. description: The authorized key used for authentication
  21730. properties:
  21731. key:
  21732. description: |-
  21733. A key in the referenced Secret.
  21734. Some instances of this field may be defaulted, in others it may be required.
  21735. maxLength: 253
  21736. minLength: 1
  21737. pattern: ^[-._a-zA-Z0-9]+$
  21738. type: string
  21739. name:
  21740. description: The name of the Secret resource being referred to.
  21741. maxLength: 253
  21742. minLength: 1
  21743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21744. type: string
  21745. namespace:
  21746. description: |-
  21747. The namespace of the Secret resource being referred to.
  21748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21749. maxLength: 63
  21750. minLength: 1
  21751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21752. type: string
  21753. type: object
  21754. type: object
  21755. caProvider:
  21756. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  21757. properties:
  21758. certSecretRef:
  21759. description: |-
  21760. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21761. In some instances, `key` is a required field.
  21762. properties:
  21763. key:
  21764. description: |-
  21765. A key in the referenced Secret.
  21766. Some instances of this field may be defaulted, in others it may be required.
  21767. maxLength: 253
  21768. minLength: 1
  21769. pattern: ^[-._a-zA-Z0-9]+$
  21770. type: string
  21771. name:
  21772. description: The name of the Secret resource being referred to.
  21773. maxLength: 253
  21774. minLength: 1
  21775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21776. type: string
  21777. namespace:
  21778. description: |-
  21779. The namespace of the Secret resource being referred to.
  21780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21781. maxLength: 63
  21782. minLength: 1
  21783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21784. type: string
  21785. type: object
  21786. type: object
  21787. fetching:
  21788. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  21789. maxProperties: 1
  21790. minProperties: 1
  21791. properties:
  21792. byID:
  21793. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  21794. type: object
  21795. byName:
  21796. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  21797. properties:
  21798. folderID:
  21799. description: The folder to fetch secrets from
  21800. type: string
  21801. required:
  21802. - folderID
  21803. type: object
  21804. type: object
  21805. required:
  21806. - auth
  21807. type: object
  21808. type: object
  21809. refreshInterval:
  21810. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  21811. type: integer
  21812. retrySettings:
  21813. description: Used to configure HTTP retries on failures.
  21814. properties:
  21815. maxRetries:
  21816. format: int32
  21817. type: integer
  21818. retryInterval:
  21819. type: string
  21820. type: object
  21821. required:
  21822. - provider
  21823. type: object
  21824. status:
  21825. description: SecretStoreStatus defines the observed state of the SecretStore.
  21826. properties:
  21827. capabilities:
  21828. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  21829. type: string
  21830. conditions:
  21831. items:
  21832. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  21833. properties:
  21834. lastTransitionTime:
  21835. format: date-time
  21836. type: string
  21837. message:
  21838. type: string
  21839. reason:
  21840. type: string
  21841. status:
  21842. type: string
  21843. type:
  21844. description: SecretStoreConditionType represents the condition of the SecretStore.
  21845. type: string
  21846. required:
  21847. - status
  21848. - type
  21849. type: object
  21850. type: array
  21851. type: object
  21852. type: object
  21853. served: true
  21854. storage: true
  21855. subresources:
  21856. status: {}
  21857. - additionalPrinterColumns:
  21858. - jsonPath: .metadata.creationTimestamp
  21859. name: AGE
  21860. type: date
  21861. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  21862. name: Status
  21863. type: string
  21864. - jsonPath: .status.capabilities
  21865. name: Capabilities
  21866. type: string
  21867. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  21868. name: Ready
  21869. type: string
  21870. deprecated: true
  21871. name: v1beta1
  21872. schema:
  21873. openAPIV3Schema:
  21874. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  21875. properties:
  21876. apiVersion:
  21877. description: |-
  21878. APIVersion defines the versioned schema of this representation of an object.
  21879. Servers should convert recognized schemas to the latest internal value, and
  21880. may reject unrecognized values.
  21881. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  21882. type: string
  21883. kind:
  21884. description: |-
  21885. Kind is a string value representing the REST resource this object represents.
  21886. Servers may infer this from the endpoint the client submits requests to.
  21887. Cannot be updated.
  21888. In CamelCase.
  21889. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  21890. type: string
  21891. metadata:
  21892. type: object
  21893. spec:
  21894. description: SecretStoreSpec defines the desired state of SecretStore.
  21895. properties:
  21896. conditions:
  21897. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  21898. items:
  21899. description: |-
  21900. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  21901. for a ClusterSecretStore instance.
  21902. properties:
  21903. namespaceRegexes:
  21904. description: Choose namespaces by using regex matching
  21905. items:
  21906. type: string
  21907. type: array
  21908. namespaceSelector:
  21909. description: Choose namespace using a labelSelector
  21910. properties:
  21911. matchExpressions:
  21912. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  21913. items:
  21914. description: |-
  21915. A label selector requirement is a selector that contains values, a key, and an operator that
  21916. relates the key and values.
  21917. properties:
  21918. key:
  21919. description: key is the label key that the selector applies to.
  21920. type: string
  21921. operator:
  21922. description: |-
  21923. operator represents a key's relationship to a set of values.
  21924. Valid operators are In, NotIn, Exists and DoesNotExist.
  21925. type: string
  21926. values:
  21927. description: |-
  21928. values is an array of string values. If the operator is In or NotIn,
  21929. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  21930. the values array must be empty. This array is replaced during a strategic
  21931. merge patch.
  21932. items:
  21933. type: string
  21934. type: array
  21935. x-kubernetes-list-type: atomic
  21936. required:
  21937. - key
  21938. - operator
  21939. type: object
  21940. type: array
  21941. x-kubernetes-list-type: atomic
  21942. matchLabels:
  21943. additionalProperties:
  21944. type: string
  21945. description: |-
  21946. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  21947. map is equivalent to an element of matchExpressions, whose key field is "key", the
  21948. operator is "In", and the values array contains only "value". The requirements are ANDed.
  21949. type: object
  21950. type: object
  21951. x-kubernetes-map-type: atomic
  21952. namespaces:
  21953. description: Choose namespaces by name
  21954. items:
  21955. maxLength: 63
  21956. minLength: 1
  21957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21958. type: string
  21959. type: array
  21960. type: object
  21961. type: array
  21962. controller:
  21963. description: |-
  21964. Used to select the correct ESO controller (think: ingress.ingressClassName)
  21965. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  21966. type: string
  21967. provider:
  21968. description: Used to configure the provider. Only one provider may be set
  21969. maxProperties: 1
  21970. minProperties: 1
  21971. properties:
  21972. akeyless:
  21973. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  21974. properties:
  21975. akeylessGWApiURL:
  21976. description: Akeyless GW API Url from which the secrets to be fetched from.
  21977. type: string
  21978. authSecretRef:
  21979. description: Auth configures how the operator authenticates with Akeyless.
  21980. properties:
  21981. kubernetesAuth:
  21982. description: |-
  21983. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  21984. token stored in the named Secret resource.
  21985. properties:
  21986. accessID:
  21987. description: the Akeyless Kubernetes auth-method access-id
  21988. type: string
  21989. k8sConfName:
  21990. description: Kubernetes-auth configuration name in Akeyless-Gateway
  21991. type: string
  21992. secretRef:
  21993. description: |-
  21994. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21995. for authenticating with Akeyless. If a name is specified without a key,
  21996. `token` is the default. If one is not specified, the one bound to
  21997. the controller will be used.
  21998. properties:
  21999. key:
  22000. description: |-
  22001. A key in the referenced Secret.
  22002. Some instances of this field may be defaulted, in others it may be required.
  22003. maxLength: 253
  22004. minLength: 1
  22005. pattern: ^[-._a-zA-Z0-9]+$
  22006. type: string
  22007. name:
  22008. description: The name of the Secret resource being referred to.
  22009. maxLength: 253
  22010. minLength: 1
  22011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22012. type: string
  22013. namespace:
  22014. description: |-
  22015. The namespace of the Secret resource being referred to.
  22016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22017. maxLength: 63
  22018. minLength: 1
  22019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22020. type: string
  22021. type: object
  22022. serviceAccountRef:
  22023. description: |-
  22024. Optional service account field containing the name of a kubernetes ServiceAccount.
  22025. If the service account is specified, the service account secret token JWT will be used
  22026. for authenticating with Akeyless. If the service account selector is not supplied,
  22027. the secretRef will be used instead.
  22028. properties:
  22029. audiences:
  22030. description: |-
  22031. Audience specifies the `aud` claim for the service account token
  22032. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22033. then this audiences will be appended to the list
  22034. items:
  22035. type: string
  22036. type: array
  22037. name:
  22038. description: The name of the ServiceAccount resource being referred to.
  22039. maxLength: 253
  22040. minLength: 1
  22041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22042. type: string
  22043. namespace:
  22044. description: |-
  22045. Namespace of the resource being referred to.
  22046. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22047. maxLength: 63
  22048. minLength: 1
  22049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22050. type: string
  22051. required:
  22052. - name
  22053. type: object
  22054. required:
  22055. - accessID
  22056. - k8sConfName
  22057. type: object
  22058. secretRef:
  22059. description: |-
  22060. Reference to a Secret that contains the details
  22061. to authenticate with Akeyless.
  22062. properties:
  22063. accessID:
  22064. description: The SecretAccessID is used for authentication
  22065. properties:
  22066. key:
  22067. description: |-
  22068. A key in the referenced Secret.
  22069. Some instances of this field may be defaulted, in others it may be required.
  22070. maxLength: 253
  22071. minLength: 1
  22072. pattern: ^[-._a-zA-Z0-9]+$
  22073. type: string
  22074. name:
  22075. description: The name of the Secret resource being referred to.
  22076. maxLength: 253
  22077. minLength: 1
  22078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22079. type: string
  22080. namespace:
  22081. description: |-
  22082. The namespace of the Secret resource being referred to.
  22083. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22084. maxLength: 63
  22085. minLength: 1
  22086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22087. type: string
  22088. type: object
  22089. accessType:
  22090. description: |-
  22091. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22092. In some instances, `key` is a required field.
  22093. properties:
  22094. key:
  22095. description: |-
  22096. A key in the referenced Secret.
  22097. Some instances of this field may be defaulted, in others it may be required.
  22098. maxLength: 253
  22099. minLength: 1
  22100. pattern: ^[-._a-zA-Z0-9]+$
  22101. type: string
  22102. name:
  22103. description: The name of the Secret resource being referred to.
  22104. maxLength: 253
  22105. minLength: 1
  22106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22107. type: string
  22108. namespace:
  22109. description: |-
  22110. The namespace of the Secret resource being referred to.
  22111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22112. maxLength: 63
  22113. minLength: 1
  22114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22115. type: string
  22116. type: object
  22117. accessTypeParam:
  22118. description: |-
  22119. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22120. In some instances, `key` is a required field.
  22121. properties:
  22122. key:
  22123. description: |-
  22124. A key in the referenced Secret.
  22125. Some instances of this field may be defaulted, in others it may be required.
  22126. maxLength: 253
  22127. minLength: 1
  22128. pattern: ^[-._a-zA-Z0-9]+$
  22129. type: string
  22130. name:
  22131. description: The name of the Secret resource being referred to.
  22132. maxLength: 253
  22133. minLength: 1
  22134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22135. type: string
  22136. namespace:
  22137. description: |-
  22138. The namespace of the Secret resource being referred to.
  22139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22140. maxLength: 63
  22141. minLength: 1
  22142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22143. type: string
  22144. type: object
  22145. type: object
  22146. type: object
  22147. caBundle:
  22148. description: |-
  22149. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22150. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22151. are used to validate the TLS connection.
  22152. format: byte
  22153. type: string
  22154. caProvider:
  22155. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22156. properties:
  22157. key:
  22158. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22159. maxLength: 253
  22160. minLength: 1
  22161. pattern: ^[-._a-zA-Z0-9]+$
  22162. type: string
  22163. name:
  22164. description: The name of the object located at the provider type.
  22165. maxLength: 253
  22166. minLength: 1
  22167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22168. type: string
  22169. namespace:
  22170. description: |-
  22171. The namespace the Provider type is in.
  22172. Can only be defined when used in a ClusterSecretStore.
  22173. maxLength: 63
  22174. minLength: 1
  22175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22176. type: string
  22177. type:
  22178. description: The type of provider to use such as "Secret", or "ConfigMap".
  22179. enum:
  22180. - Secret
  22181. - ConfigMap
  22182. type: string
  22183. required:
  22184. - name
  22185. - type
  22186. type: object
  22187. required:
  22188. - akeylessGWApiURL
  22189. - authSecretRef
  22190. type: object
  22191. alibaba:
  22192. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22193. properties:
  22194. auth:
  22195. description: AlibabaAuth contains a secretRef for credentials.
  22196. properties:
  22197. rrsa:
  22198. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22199. properties:
  22200. oidcProviderArn:
  22201. type: string
  22202. oidcTokenFilePath:
  22203. type: string
  22204. roleArn:
  22205. type: string
  22206. sessionName:
  22207. type: string
  22208. required:
  22209. - oidcProviderArn
  22210. - oidcTokenFilePath
  22211. - roleArn
  22212. - sessionName
  22213. type: object
  22214. secretRef:
  22215. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22216. properties:
  22217. accessKeyIDSecretRef:
  22218. description: The AccessKeyID is used for authentication
  22219. properties:
  22220. key:
  22221. description: |-
  22222. A key in the referenced Secret.
  22223. Some instances of this field may be defaulted, in others it may be required.
  22224. maxLength: 253
  22225. minLength: 1
  22226. pattern: ^[-._a-zA-Z0-9]+$
  22227. type: string
  22228. name:
  22229. description: The name of the Secret resource being referred to.
  22230. maxLength: 253
  22231. minLength: 1
  22232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22233. type: string
  22234. namespace:
  22235. description: |-
  22236. The namespace of the Secret resource being referred to.
  22237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22238. maxLength: 63
  22239. minLength: 1
  22240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22241. type: string
  22242. type: object
  22243. accessKeySecretSecretRef:
  22244. description: The AccessKeySecret is used for authentication
  22245. properties:
  22246. key:
  22247. description: |-
  22248. A key in the referenced Secret.
  22249. Some instances of this field may be defaulted, in others it may be required.
  22250. maxLength: 253
  22251. minLength: 1
  22252. pattern: ^[-._a-zA-Z0-9]+$
  22253. type: string
  22254. name:
  22255. description: The name of the Secret resource being referred to.
  22256. maxLength: 253
  22257. minLength: 1
  22258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22259. type: string
  22260. namespace:
  22261. description: |-
  22262. The namespace of the Secret resource being referred to.
  22263. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22264. maxLength: 63
  22265. minLength: 1
  22266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22267. type: string
  22268. type: object
  22269. required:
  22270. - accessKeyIDSecretRef
  22271. - accessKeySecretSecretRef
  22272. type: object
  22273. type: object
  22274. regionID:
  22275. description: Alibaba Region to be used for the provider
  22276. type: string
  22277. required:
  22278. - auth
  22279. - regionID
  22280. type: object
  22281. aws:
  22282. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22283. properties:
  22284. additionalRoles:
  22285. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22286. items:
  22287. type: string
  22288. type: array
  22289. auth:
  22290. description: |-
  22291. Auth defines the information necessary to authenticate against AWS
  22292. if not set aws sdk will infer credentials from your environment
  22293. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22294. properties:
  22295. jwt:
  22296. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22297. properties:
  22298. serviceAccountRef:
  22299. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22300. properties:
  22301. audiences:
  22302. description: |-
  22303. Audience specifies the `aud` claim for the service account token
  22304. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22305. then this audiences will be appended to the list
  22306. items:
  22307. type: string
  22308. type: array
  22309. name:
  22310. description: The name of the ServiceAccount resource being referred to.
  22311. maxLength: 253
  22312. minLength: 1
  22313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22314. type: string
  22315. namespace:
  22316. description: |-
  22317. Namespace of the resource being referred to.
  22318. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22319. maxLength: 63
  22320. minLength: 1
  22321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22322. type: string
  22323. required:
  22324. - name
  22325. type: object
  22326. type: object
  22327. secretRef:
  22328. description: |-
  22329. AWSAuthSecretRef holds secret references for AWS credentials
  22330. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22331. properties:
  22332. accessKeyIDSecretRef:
  22333. description: The AccessKeyID is used for authentication
  22334. properties:
  22335. key:
  22336. description: |-
  22337. A key in the referenced Secret.
  22338. Some instances of this field may be defaulted, in others it may be required.
  22339. maxLength: 253
  22340. minLength: 1
  22341. pattern: ^[-._a-zA-Z0-9]+$
  22342. type: string
  22343. name:
  22344. description: The name of the Secret resource being referred to.
  22345. maxLength: 253
  22346. minLength: 1
  22347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22348. type: string
  22349. namespace:
  22350. description: |-
  22351. The namespace of the Secret resource being referred to.
  22352. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22353. maxLength: 63
  22354. minLength: 1
  22355. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22356. type: string
  22357. type: object
  22358. secretAccessKeySecretRef:
  22359. description: The SecretAccessKey is used for authentication
  22360. properties:
  22361. key:
  22362. description: |-
  22363. A key in the referenced Secret.
  22364. Some instances of this field may be defaulted, in others it may be required.
  22365. maxLength: 253
  22366. minLength: 1
  22367. pattern: ^[-._a-zA-Z0-9]+$
  22368. type: string
  22369. name:
  22370. description: The name of the Secret resource being referred to.
  22371. maxLength: 253
  22372. minLength: 1
  22373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22374. type: string
  22375. namespace:
  22376. description: |-
  22377. The namespace of the Secret resource being referred to.
  22378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22379. maxLength: 63
  22380. minLength: 1
  22381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22382. type: string
  22383. type: object
  22384. sessionTokenSecretRef:
  22385. description: |-
  22386. The SessionToken used for authentication
  22387. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22388. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22389. properties:
  22390. key:
  22391. description: |-
  22392. A key in the referenced Secret.
  22393. Some instances of this field may be defaulted, in others it may be required.
  22394. maxLength: 253
  22395. minLength: 1
  22396. pattern: ^[-._a-zA-Z0-9]+$
  22397. type: string
  22398. name:
  22399. description: The name of the Secret resource being referred to.
  22400. maxLength: 253
  22401. minLength: 1
  22402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22403. type: string
  22404. namespace:
  22405. description: |-
  22406. The namespace of the Secret resource being referred to.
  22407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22408. maxLength: 63
  22409. minLength: 1
  22410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22411. type: string
  22412. type: object
  22413. type: object
  22414. type: object
  22415. externalID:
  22416. description: AWS External ID set on assumed IAM roles
  22417. type: string
  22418. prefix:
  22419. description: Prefix adds a prefix to all retrieved values.
  22420. type: string
  22421. region:
  22422. description: AWS Region to be used for the provider
  22423. type: string
  22424. role:
  22425. description: Role is a Role ARN which the provider will assume
  22426. type: string
  22427. secretsManager:
  22428. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  22429. properties:
  22430. forceDeleteWithoutRecovery:
  22431. description: |-
  22432. Specifies whether to delete the secret without any recovery window. You
  22433. can't use both this parameter and RecoveryWindowInDays in the same call.
  22434. If you don't use either, then by default Secrets Manager uses a 30 day
  22435. recovery window.
  22436. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  22437. type: boolean
  22438. recoveryWindowInDays:
  22439. description: |-
  22440. The number of days from 7 to 30 that Secrets Manager waits before
  22441. permanently deleting the secret. You can't use both this parameter and
  22442. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  22443. then by default Secrets Manager uses a 30 day recovery window.
  22444. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  22445. format: int64
  22446. type: integer
  22447. type: object
  22448. service:
  22449. description: Service defines which service should be used to fetch the secrets
  22450. enum:
  22451. - SecretsManager
  22452. - ParameterStore
  22453. type: string
  22454. sessionTags:
  22455. description: AWS STS assume role session tags
  22456. items:
  22457. description: Tag defines a tag key and value for AWS resources.
  22458. properties:
  22459. key:
  22460. type: string
  22461. value:
  22462. type: string
  22463. required:
  22464. - key
  22465. - value
  22466. type: object
  22467. type: array
  22468. transitiveTagKeys:
  22469. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  22470. items:
  22471. type: string
  22472. type: array
  22473. required:
  22474. - region
  22475. - service
  22476. type: object
  22477. azurekv:
  22478. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  22479. properties:
  22480. authSecretRef:
  22481. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  22482. properties:
  22483. clientCertificate:
  22484. description: The Azure ClientCertificate of the service principle used for authentication.
  22485. properties:
  22486. key:
  22487. description: |-
  22488. A key in the referenced Secret.
  22489. Some instances of this field may be defaulted, in others it may be required.
  22490. maxLength: 253
  22491. minLength: 1
  22492. pattern: ^[-._a-zA-Z0-9]+$
  22493. type: string
  22494. name:
  22495. description: The name of the Secret resource being referred to.
  22496. maxLength: 253
  22497. minLength: 1
  22498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22499. type: string
  22500. namespace:
  22501. description: |-
  22502. The namespace of the Secret resource being referred to.
  22503. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22504. maxLength: 63
  22505. minLength: 1
  22506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22507. type: string
  22508. type: object
  22509. clientId:
  22510. description: The Azure clientId of the service principle or managed identity used for authentication.
  22511. properties:
  22512. key:
  22513. description: |-
  22514. A key in the referenced Secret.
  22515. Some instances of this field may be defaulted, in others it may be required.
  22516. maxLength: 253
  22517. minLength: 1
  22518. pattern: ^[-._a-zA-Z0-9]+$
  22519. type: string
  22520. name:
  22521. description: The name of the Secret resource being referred to.
  22522. maxLength: 253
  22523. minLength: 1
  22524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22525. type: string
  22526. namespace:
  22527. description: |-
  22528. The namespace of the Secret resource being referred to.
  22529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22530. maxLength: 63
  22531. minLength: 1
  22532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22533. type: string
  22534. type: object
  22535. clientSecret:
  22536. description: The Azure ClientSecret of the service principle used for authentication.
  22537. properties:
  22538. key:
  22539. description: |-
  22540. A key in the referenced Secret.
  22541. Some instances of this field may be defaulted, in others it may be required.
  22542. maxLength: 253
  22543. minLength: 1
  22544. pattern: ^[-._a-zA-Z0-9]+$
  22545. type: string
  22546. name:
  22547. description: The name of the Secret resource being referred to.
  22548. maxLength: 253
  22549. minLength: 1
  22550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22551. type: string
  22552. namespace:
  22553. description: |-
  22554. The namespace of the Secret resource being referred to.
  22555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22556. maxLength: 63
  22557. minLength: 1
  22558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22559. type: string
  22560. type: object
  22561. tenantId:
  22562. description: The Azure tenantId of the managed identity used for authentication.
  22563. properties:
  22564. key:
  22565. description: |-
  22566. A key in the referenced Secret.
  22567. Some instances of this field may be defaulted, in others it may be required.
  22568. maxLength: 253
  22569. minLength: 1
  22570. pattern: ^[-._a-zA-Z0-9]+$
  22571. type: string
  22572. name:
  22573. description: The name of the Secret resource being referred to.
  22574. maxLength: 253
  22575. minLength: 1
  22576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22577. type: string
  22578. namespace:
  22579. description: |-
  22580. The namespace of the Secret resource being referred to.
  22581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22582. maxLength: 63
  22583. minLength: 1
  22584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22585. type: string
  22586. type: object
  22587. type: object
  22588. authType:
  22589. default: ServicePrincipal
  22590. description: |-
  22591. Auth type defines how to authenticate to the keyvault service.
  22592. Valid values are:
  22593. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  22594. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  22595. enum:
  22596. - ServicePrincipal
  22597. - ManagedIdentity
  22598. - WorkloadIdentity
  22599. type: string
  22600. environmentType:
  22601. default: PublicCloud
  22602. description: |-
  22603. EnvironmentType specifies the Azure cloud environment endpoints to use for
  22604. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  22605. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  22606. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  22607. enum:
  22608. - PublicCloud
  22609. - USGovernmentCloud
  22610. - ChinaCloud
  22611. - GermanCloud
  22612. type: string
  22613. identityId:
  22614. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  22615. type: string
  22616. serviceAccountRef:
  22617. description: |-
  22618. ServiceAccountRef specified the service account
  22619. that should be used when authenticating with WorkloadIdentity.
  22620. properties:
  22621. audiences:
  22622. description: |-
  22623. Audience specifies the `aud` claim for the service account token
  22624. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22625. then this audiences will be appended to the list
  22626. items:
  22627. type: string
  22628. type: array
  22629. name:
  22630. description: The name of the ServiceAccount resource being referred to.
  22631. maxLength: 253
  22632. minLength: 1
  22633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22634. type: string
  22635. namespace:
  22636. description: |-
  22637. Namespace of the resource being referred to.
  22638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22639. maxLength: 63
  22640. minLength: 1
  22641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22642. type: string
  22643. required:
  22644. - name
  22645. type: object
  22646. tenantId:
  22647. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  22648. type: string
  22649. vaultUrl:
  22650. description: Vault Url from which the secrets to be fetched from.
  22651. type: string
  22652. required:
  22653. - vaultUrl
  22654. type: object
  22655. beyondtrust:
  22656. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  22657. properties:
  22658. auth:
  22659. description: Auth configures how the operator authenticates with Beyondtrust.
  22660. properties:
  22661. apiKey:
  22662. description: APIKey If not provided then ClientID/ClientSecret become required.
  22663. properties:
  22664. secretRef:
  22665. description: SecretRef references a key in a secret that will be used as value.
  22666. properties:
  22667. key:
  22668. description: |-
  22669. A key in the referenced Secret.
  22670. Some instances of this field may be defaulted, in others it may be required.
  22671. maxLength: 253
  22672. minLength: 1
  22673. pattern: ^[-._a-zA-Z0-9]+$
  22674. type: string
  22675. name:
  22676. description: The name of the Secret resource being referred to.
  22677. maxLength: 253
  22678. minLength: 1
  22679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22680. type: string
  22681. namespace:
  22682. description: |-
  22683. The namespace of the Secret resource being referred to.
  22684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22685. maxLength: 63
  22686. minLength: 1
  22687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22688. type: string
  22689. type: object
  22690. value:
  22691. description: Value can be specified directly to set a value without using a secret.
  22692. type: string
  22693. type: object
  22694. certificate:
  22695. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  22696. properties:
  22697. secretRef:
  22698. description: SecretRef references a key in a secret that will be used as value.
  22699. properties:
  22700. key:
  22701. description: |-
  22702. A key in the referenced Secret.
  22703. Some instances of this field may be defaulted, in others it may be required.
  22704. maxLength: 253
  22705. minLength: 1
  22706. pattern: ^[-._a-zA-Z0-9]+$
  22707. type: string
  22708. name:
  22709. description: The name of the Secret resource being referred to.
  22710. maxLength: 253
  22711. minLength: 1
  22712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22713. type: string
  22714. namespace:
  22715. description: |-
  22716. The namespace of the Secret resource being referred to.
  22717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22718. maxLength: 63
  22719. minLength: 1
  22720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22721. type: string
  22722. type: object
  22723. value:
  22724. description: Value can be specified directly to set a value without using a secret.
  22725. type: string
  22726. type: object
  22727. certificateKey:
  22728. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  22729. properties:
  22730. secretRef:
  22731. description: SecretRef references a key in a secret that will be used as value.
  22732. properties:
  22733. key:
  22734. description: |-
  22735. A key in the referenced Secret.
  22736. Some instances of this field may be defaulted, in others it may be required.
  22737. maxLength: 253
  22738. minLength: 1
  22739. pattern: ^[-._a-zA-Z0-9]+$
  22740. type: string
  22741. name:
  22742. description: The name of the Secret resource being referred to.
  22743. maxLength: 253
  22744. minLength: 1
  22745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22746. type: string
  22747. namespace:
  22748. description: |-
  22749. The namespace of the Secret resource being referred to.
  22750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22751. maxLength: 63
  22752. minLength: 1
  22753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22754. type: string
  22755. type: object
  22756. value:
  22757. description: Value can be specified directly to set a value without using a secret.
  22758. type: string
  22759. type: object
  22760. clientId:
  22761. description: ClientID is the API OAuth Client ID.
  22762. properties:
  22763. secretRef:
  22764. description: SecretRef references a key in a secret that will be used as value.
  22765. properties:
  22766. key:
  22767. description: |-
  22768. A key in the referenced Secret.
  22769. Some instances of this field may be defaulted, in others it may be required.
  22770. maxLength: 253
  22771. minLength: 1
  22772. pattern: ^[-._a-zA-Z0-9]+$
  22773. type: string
  22774. name:
  22775. description: The name of the Secret resource being referred to.
  22776. maxLength: 253
  22777. minLength: 1
  22778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22779. type: string
  22780. namespace:
  22781. description: |-
  22782. The namespace of the Secret resource being referred to.
  22783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22784. maxLength: 63
  22785. minLength: 1
  22786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22787. type: string
  22788. type: object
  22789. value:
  22790. description: Value can be specified directly to set a value without using a secret.
  22791. type: string
  22792. type: object
  22793. clientSecret:
  22794. description: ClientSecret is the API OAuth Client Secret.
  22795. properties:
  22796. secretRef:
  22797. description: SecretRef references a key in a secret that will be used as value.
  22798. properties:
  22799. key:
  22800. description: |-
  22801. A key in the referenced Secret.
  22802. Some instances of this field may be defaulted, in others it may be required.
  22803. maxLength: 253
  22804. minLength: 1
  22805. pattern: ^[-._a-zA-Z0-9]+$
  22806. type: string
  22807. name:
  22808. description: The name of the Secret resource being referred to.
  22809. maxLength: 253
  22810. minLength: 1
  22811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22812. type: string
  22813. namespace:
  22814. description: |-
  22815. The namespace of the Secret resource being referred to.
  22816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22817. maxLength: 63
  22818. minLength: 1
  22819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22820. type: string
  22821. type: object
  22822. value:
  22823. description: Value can be specified directly to set a value without using a secret.
  22824. type: string
  22825. type: object
  22826. type: object
  22827. server:
  22828. description: Auth configures how API server works.
  22829. properties:
  22830. apiUrl:
  22831. type: string
  22832. apiVersion:
  22833. type: string
  22834. clientTimeOutSeconds:
  22835. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  22836. type: integer
  22837. decrypt:
  22838. default: true
  22839. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  22840. type: boolean
  22841. retrievalType:
  22842. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  22843. type: string
  22844. separator:
  22845. description: A character that separates the folder names.
  22846. type: string
  22847. verifyCA:
  22848. type: boolean
  22849. required:
  22850. - apiUrl
  22851. - verifyCA
  22852. type: object
  22853. required:
  22854. - auth
  22855. - server
  22856. type: object
  22857. bitwardensecretsmanager:
  22858. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  22859. properties:
  22860. apiURL:
  22861. type: string
  22862. auth:
  22863. description: |-
  22864. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  22865. Make sure that the token being used has permissions on the given secret.
  22866. properties:
  22867. secretRef:
  22868. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  22869. properties:
  22870. credentials:
  22871. description: AccessToken used for the bitwarden instance.
  22872. properties:
  22873. key:
  22874. description: |-
  22875. A key in the referenced Secret.
  22876. Some instances of this field may be defaulted, in others it may be required.
  22877. maxLength: 253
  22878. minLength: 1
  22879. pattern: ^[-._a-zA-Z0-9]+$
  22880. type: string
  22881. name:
  22882. description: The name of the Secret resource being referred to.
  22883. maxLength: 253
  22884. minLength: 1
  22885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22886. type: string
  22887. namespace:
  22888. description: |-
  22889. The namespace of the Secret resource being referred to.
  22890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22891. maxLength: 63
  22892. minLength: 1
  22893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22894. type: string
  22895. type: object
  22896. required:
  22897. - credentials
  22898. type: object
  22899. required:
  22900. - secretRef
  22901. type: object
  22902. bitwardenServerSDKURL:
  22903. type: string
  22904. caBundle:
  22905. description: |-
  22906. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  22907. can be performed.
  22908. type: string
  22909. caProvider:
  22910. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  22911. properties:
  22912. key:
  22913. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22914. maxLength: 253
  22915. minLength: 1
  22916. pattern: ^[-._a-zA-Z0-9]+$
  22917. type: string
  22918. name:
  22919. description: The name of the object located at the provider type.
  22920. maxLength: 253
  22921. minLength: 1
  22922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22923. type: string
  22924. namespace:
  22925. description: |-
  22926. The namespace the Provider type is in.
  22927. Can only be defined when used in a ClusterSecretStore.
  22928. maxLength: 63
  22929. minLength: 1
  22930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22931. type: string
  22932. type:
  22933. description: The type of provider to use such as "Secret", or "ConfigMap".
  22934. enum:
  22935. - Secret
  22936. - ConfigMap
  22937. type: string
  22938. required:
  22939. - name
  22940. - type
  22941. type: object
  22942. identityURL:
  22943. type: string
  22944. organizationID:
  22945. description: OrganizationID determines which organization this secret store manages.
  22946. type: string
  22947. projectID:
  22948. description: ProjectID determines which project this secret store manages.
  22949. type: string
  22950. required:
  22951. - auth
  22952. - organizationID
  22953. - projectID
  22954. type: object
  22955. chef:
  22956. description: Chef configures this store to sync secrets with chef server
  22957. properties:
  22958. auth:
  22959. description: Auth defines the information necessary to authenticate against chef Server
  22960. properties:
  22961. secretRef:
  22962. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  22963. properties:
  22964. privateKeySecretRef:
  22965. description: SecretKey is the Signing Key in PEM format, used for authentication.
  22966. properties:
  22967. key:
  22968. description: |-
  22969. A key in the referenced Secret.
  22970. Some instances of this field may be defaulted, in others it may be required.
  22971. maxLength: 253
  22972. minLength: 1
  22973. pattern: ^[-._a-zA-Z0-9]+$
  22974. type: string
  22975. name:
  22976. description: The name of the Secret resource being referred to.
  22977. maxLength: 253
  22978. minLength: 1
  22979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22980. type: string
  22981. namespace:
  22982. description: |-
  22983. The namespace of the Secret resource being referred to.
  22984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22985. maxLength: 63
  22986. minLength: 1
  22987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22988. type: string
  22989. type: object
  22990. required:
  22991. - privateKeySecretRef
  22992. type: object
  22993. required:
  22994. - secretRef
  22995. type: object
  22996. serverUrl:
  22997. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  22998. type: string
  22999. username:
  23000. description: UserName should be the user ID on the chef server
  23001. type: string
  23002. required:
  23003. - auth
  23004. - serverUrl
  23005. - username
  23006. type: object
  23007. cloudrusm:
  23008. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23009. properties:
  23010. auth:
  23011. description: CSMAuth contains a secretRef for credentials.
  23012. properties:
  23013. secretRef:
  23014. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23015. properties:
  23016. accessKeyIDSecretRef:
  23017. description: The AccessKeyID is used for authentication
  23018. properties:
  23019. key:
  23020. description: |-
  23021. A key in the referenced Secret.
  23022. Some instances of this field may be defaulted, in others it may be required.
  23023. maxLength: 253
  23024. minLength: 1
  23025. pattern: ^[-._a-zA-Z0-9]+$
  23026. type: string
  23027. name:
  23028. description: The name of the Secret resource being referred to.
  23029. maxLength: 253
  23030. minLength: 1
  23031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23032. type: string
  23033. namespace:
  23034. description: |-
  23035. The namespace of the Secret resource being referred to.
  23036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23037. maxLength: 63
  23038. minLength: 1
  23039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23040. type: string
  23041. type: object
  23042. accessKeySecretSecretRef:
  23043. description: The AccessKeySecret is used for authentication
  23044. properties:
  23045. key:
  23046. description: |-
  23047. A key in the referenced Secret.
  23048. Some instances of this field may be defaulted, in others it may be required.
  23049. maxLength: 253
  23050. minLength: 1
  23051. pattern: ^[-._a-zA-Z0-9]+$
  23052. type: string
  23053. name:
  23054. description: The name of the Secret resource being referred to.
  23055. maxLength: 253
  23056. minLength: 1
  23057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23058. type: string
  23059. namespace:
  23060. description: |-
  23061. The namespace of the Secret resource being referred to.
  23062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23063. maxLength: 63
  23064. minLength: 1
  23065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23066. type: string
  23067. type: object
  23068. required:
  23069. - accessKeyIDSecretRef
  23070. - accessKeySecretSecretRef
  23071. type: object
  23072. type: object
  23073. projectID:
  23074. description: ProjectID is the project, which the secrets are stored in.
  23075. type: string
  23076. required:
  23077. - auth
  23078. type: object
  23079. conjur:
  23080. description: Conjur configures this store to sync secrets using conjur provider
  23081. properties:
  23082. auth:
  23083. description: Defines authentication settings for connecting to Conjur.
  23084. properties:
  23085. apikey:
  23086. description: Authenticates with Conjur using an API key.
  23087. properties:
  23088. account:
  23089. description: Account is the Conjur organization account name.
  23090. type: string
  23091. apiKeyRef:
  23092. description: |-
  23093. A reference to a specific 'key' containing the Conjur API key
  23094. within a Secret resource. In some instances, `key` is a required field.
  23095. properties:
  23096. key:
  23097. description: |-
  23098. A key in the referenced Secret.
  23099. Some instances of this field may be defaulted, in others it may be required.
  23100. maxLength: 253
  23101. minLength: 1
  23102. pattern: ^[-._a-zA-Z0-9]+$
  23103. type: string
  23104. name:
  23105. description: The name of the Secret resource being referred to.
  23106. maxLength: 253
  23107. minLength: 1
  23108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23109. type: string
  23110. namespace:
  23111. description: |-
  23112. The namespace of the Secret resource being referred to.
  23113. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23114. maxLength: 63
  23115. minLength: 1
  23116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23117. type: string
  23118. type: object
  23119. userRef:
  23120. description: |-
  23121. A reference to a specific 'key' containing the Conjur username
  23122. within a Secret resource. In some instances, `key` is a required field.
  23123. properties:
  23124. key:
  23125. description: |-
  23126. A key in the referenced Secret.
  23127. Some instances of this field may be defaulted, in others it may be required.
  23128. maxLength: 253
  23129. minLength: 1
  23130. pattern: ^[-._a-zA-Z0-9]+$
  23131. type: string
  23132. name:
  23133. description: The name of the Secret resource being referred to.
  23134. maxLength: 253
  23135. minLength: 1
  23136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23137. type: string
  23138. namespace:
  23139. description: |-
  23140. The namespace of the Secret resource being referred to.
  23141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23142. maxLength: 63
  23143. minLength: 1
  23144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23145. type: string
  23146. type: object
  23147. required:
  23148. - account
  23149. - apiKeyRef
  23150. - userRef
  23151. type: object
  23152. jwt:
  23153. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23154. properties:
  23155. account:
  23156. description: Account is the Conjur organization account name.
  23157. type: string
  23158. hostId:
  23159. description: |-
  23160. Optional HostID for JWT authentication. This may be used depending
  23161. on how the Conjur JWT authenticator policy is configured.
  23162. type: string
  23163. secretRef:
  23164. description: |-
  23165. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23166. authenticate with Conjur using the JWT authentication method.
  23167. properties:
  23168. key:
  23169. description: |-
  23170. A key in the referenced Secret.
  23171. Some instances of this field may be defaulted, in others it may be required.
  23172. maxLength: 253
  23173. minLength: 1
  23174. pattern: ^[-._a-zA-Z0-9]+$
  23175. type: string
  23176. name:
  23177. description: The name of the Secret resource being referred to.
  23178. maxLength: 253
  23179. minLength: 1
  23180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23181. type: string
  23182. namespace:
  23183. description: |-
  23184. The namespace of the Secret resource being referred to.
  23185. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23186. maxLength: 63
  23187. minLength: 1
  23188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23189. type: string
  23190. type: object
  23191. serviceAccountRef:
  23192. description: |-
  23193. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23194. a token for with the `TokenRequest` API.
  23195. properties:
  23196. audiences:
  23197. description: |-
  23198. Audience specifies the `aud` claim for the service account token
  23199. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23200. then this audiences will be appended to the list
  23201. items:
  23202. type: string
  23203. type: array
  23204. name:
  23205. description: The name of the ServiceAccount resource being referred to.
  23206. maxLength: 253
  23207. minLength: 1
  23208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23209. type: string
  23210. namespace:
  23211. description: |-
  23212. Namespace of the resource being referred to.
  23213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23214. maxLength: 63
  23215. minLength: 1
  23216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23217. type: string
  23218. required:
  23219. - name
  23220. type: object
  23221. serviceID:
  23222. description: The conjur authn jwt webservice id
  23223. type: string
  23224. required:
  23225. - account
  23226. - serviceID
  23227. type: object
  23228. type: object
  23229. caBundle:
  23230. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23231. type: string
  23232. caProvider:
  23233. description: |-
  23234. Used to provide custom certificate authority (CA) certificates
  23235. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23236. that contains a PEM-encoded certificate.
  23237. properties:
  23238. key:
  23239. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23240. maxLength: 253
  23241. minLength: 1
  23242. pattern: ^[-._a-zA-Z0-9]+$
  23243. type: string
  23244. name:
  23245. description: The name of the object located at the provider type.
  23246. maxLength: 253
  23247. minLength: 1
  23248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23249. type: string
  23250. namespace:
  23251. description: |-
  23252. The namespace the Provider type is in.
  23253. Can only be defined when used in a ClusterSecretStore.
  23254. maxLength: 63
  23255. minLength: 1
  23256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23257. type: string
  23258. type:
  23259. description: The type of provider to use such as "Secret", or "ConfigMap".
  23260. enum:
  23261. - Secret
  23262. - ConfigMap
  23263. type: string
  23264. required:
  23265. - name
  23266. - type
  23267. type: object
  23268. url:
  23269. description: URL is the endpoint of the Conjur instance.
  23270. type: string
  23271. required:
  23272. - auth
  23273. - url
  23274. type: object
  23275. delinea:
  23276. description: |-
  23277. Delinea DevOps Secrets Vault
  23278. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23279. properties:
  23280. clientId:
  23281. description: ClientID is the non-secret part of the credential.
  23282. properties:
  23283. secretRef:
  23284. description: SecretRef references a key in a secret that will be used as value.
  23285. properties:
  23286. key:
  23287. description: |-
  23288. A key in the referenced Secret.
  23289. Some instances of this field may be defaulted, in others it may be required.
  23290. maxLength: 253
  23291. minLength: 1
  23292. pattern: ^[-._a-zA-Z0-9]+$
  23293. type: string
  23294. name:
  23295. description: The name of the Secret resource being referred to.
  23296. maxLength: 253
  23297. minLength: 1
  23298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23299. type: string
  23300. namespace:
  23301. description: |-
  23302. The namespace of the Secret resource being referred to.
  23303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23304. maxLength: 63
  23305. minLength: 1
  23306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23307. type: string
  23308. type: object
  23309. value:
  23310. description: Value can be specified directly to set a value without using a secret.
  23311. type: string
  23312. type: object
  23313. clientSecret:
  23314. description: ClientSecret is the secret part of the credential.
  23315. properties:
  23316. secretRef:
  23317. description: SecretRef references a key in a secret that will be used as value.
  23318. properties:
  23319. key:
  23320. description: |-
  23321. A key in the referenced Secret.
  23322. Some instances of this field may be defaulted, in others it may be required.
  23323. maxLength: 253
  23324. minLength: 1
  23325. pattern: ^[-._a-zA-Z0-9]+$
  23326. type: string
  23327. name:
  23328. description: The name of the Secret resource being referred to.
  23329. maxLength: 253
  23330. minLength: 1
  23331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23332. type: string
  23333. namespace:
  23334. description: |-
  23335. The namespace of the Secret resource being referred to.
  23336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23337. maxLength: 63
  23338. minLength: 1
  23339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23340. type: string
  23341. type: object
  23342. value:
  23343. description: Value can be specified directly to set a value without using a secret.
  23344. type: string
  23345. type: object
  23346. tenant:
  23347. description: Tenant is the chosen hostname / site name.
  23348. type: string
  23349. tld:
  23350. description: |-
  23351. TLD is based on the server location that was chosen during provisioning.
  23352. If unset, defaults to "com".
  23353. type: string
  23354. urlTemplate:
  23355. description: |-
  23356. URLTemplate
  23357. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23358. type: string
  23359. required:
  23360. - clientId
  23361. - clientSecret
  23362. - tenant
  23363. type: object
  23364. device42:
  23365. description: Device42 configures this store to sync secrets using the Device42 provider
  23366. properties:
  23367. auth:
  23368. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23369. properties:
  23370. secretRef:
  23371. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23372. properties:
  23373. credentials:
  23374. description: Username / Password is used for authentication.
  23375. properties:
  23376. key:
  23377. description: |-
  23378. A key in the referenced Secret.
  23379. Some instances of this field may be defaulted, in others it may be required.
  23380. maxLength: 253
  23381. minLength: 1
  23382. pattern: ^[-._a-zA-Z0-9]+$
  23383. type: string
  23384. name:
  23385. description: The name of the Secret resource being referred to.
  23386. maxLength: 253
  23387. minLength: 1
  23388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23389. type: string
  23390. namespace:
  23391. description: |-
  23392. The namespace of the Secret resource being referred to.
  23393. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23394. maxLength: 63
  23395. minLength: 1
  23396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23397. type: string
  23398. type: object
  23399. type: object
  23400. required:
  23401. - secretRef
  23402. type: object
  23403. host:
  23404. description: URL configures the Device42 instance URL.
  23405. type: string
  23406. required:
  23407. - auth
  23408. - host
  23409. type: object
  23410. doppler:
  23411. description: Doppler configures this store to sync secrets using the Doppler provider
  23412. properties:
  23413. auth:
  23414. description: Auth configures how the Operator authenticates with the Doppler API
  23415. properties:
  23416. secretRef:
  23417. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  23418. properties:
  23419. dopplerToken:
  23420. description: |-
  23421. The DopplerToken is used for authentication.
  23422. See https://docs.doppler.com/reference/api#authentication for auth token types.
  23423. The Key attribute defaults to dopplerToken if not specified.
  23424. properties:
  23425. key:
  23426. description: |-
  23427. A key in the referenced Secret.
  23428. Some instances of this field may be defaulted, in others it may be required.
  23429. maxLength: 253
  23430. minLength: 1
  23431. pattern: ^[-._a-zA-Z0-9]+$
  23432. type: string
  23433. name:
  23434. description: The name of the Secret resource being referred to.
  23435. maxLength: 253
  23436. minLength: 1
  23437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23438. type: string
  23439. namespace:
  23440. description: |-
  23441. The namespace of the Secret resource being referred to.
  23442. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23443. maxLength: 63
  23444. minLength: 1
  23445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23446. type: string
  23447. type: object
  23448. required:
  23449. - dopplerToken
  23450. type: object
  23451. required:
  23452. - secretRef
  23453. type: object
  23454. config:
  23455. description: Doppler config (required if not using a Service Token)
  23456. type: string
  23457. format:
  23458. description: Format enables the downloading of secrets as a file (string)
  23459. enum:
  23460. - json
  23461. - dotnet-json
  23462. - env
  23463. - yaml
  23464. - docker
  23465. type: string
  23466. nameTransformer:
  23467. description: Environment variable compatible name transforms that change secret names to a different format
  23468. enum:
  23469. - upper-camel
  23470. - camel
  23471. - lower-snake
  23472. - tf-var
  23473. - dotnet-env
  23474. - lower-kebab
  23475. type: string
  23476. project:
  23477. description: Doppler project (required if not using a Service Token)
  23478. type: string
  23479. required:
  23480. - auth
  23481. type: object
  23482. fake:
  23483. description: Fake configures a store with static key/value pairs
  23484. properties:
  23485. data:
  23486. items:
  23487. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  23488. properties:
  23489. key:
  23490. type: string
  23491. value:
  23492. type: string
  23493. version:
  23494. type: string
  23495. required:
  23496. - key
  23497. - value
  23498. type: object
  23499. type: array
  23500. required:
  23501. - data
  23502. type: object
  23503. fortanix:
  23504. description: Fortanix configures this store to sync secrets using the Fortanix provider
  23505. properties:
  23506. apiKey:
  23507. description: APIKey is the API token to access SDKMS Applications.
  23508. properties:
  23509. secretRef:
  23510. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  23511. properties:
  23512. key:
  23513. description: |-
  23514. A key in the referenced Secret.
  23515. Some instances of this field may be defaulted, in others it may be required.
  23516. maxLength: 253
  23517. minLength: 1
  23518. pattern: ^[-._a-zA-Z0-9]+$
  23519. type: string
  23520. name:
  23521. description: The name of the Secret resource being referred to.
  23522. maxLength: 253
  23523. minLength: 1
  23524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23525. type: string
  23526. namespace:
  23527. description: |-
  23528. The namespace of the Secret resource being referred to.
  23529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23530. maxLength: 63
  23531. minLength: 1
  23532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23533. type: string
  23534. type: object
  23535. type: object
  23536. apiUrl:
  23537. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  23538. type: string
  23539. type: object
  23540. gcpsm:
  23541. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  23542. properties:
  23543. auth:
  23544. description: Auth defines the information necessary to authenticate against GCP
  23545. properties:
  23546. secretRef:
  23547. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  23548. properties:
  23549. secretAccessKeySecretRef:
  23550. description: The SecretAccessKey is used for authentication
  23551. properties:
  23552. key:
  23553. description: |-
  23554. A key in the referenced Secret.
  23555. Some instances of this field may be defaulted, in others it may be required.
  23556. maxLength: 253
  23557. minLength: 1
  23558. pattern: ^[-._a-zA-Z0-9]+$
  23559. type: string
  23560. name:
  23561. description: The name of the Secret resource being referred to.
  23562. maxLength: 253
  23563. minLength: 1
  23564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23565. type: string
  23566. namespace:
  23567. description: |-
  23568. The namespace of the Secret resource being referred to.
  23569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23570. maxLength: 63
  23571. minLength: 1
  23572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23573. type: string
  23574. type: object
  23575. type: object
  23576. workloadIdentity:
  23577. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  23578. properties:
  23579. clusterLocation:
  23580. description: |-
  23581. ClusterLocation is the location of the cluster
  23582. If not specified, it fetches information from the metadata server
  23583. type: string
  23584. clusterName:
  23585. description: |-
  23586. ClusterName is the name of the cluster
  23587. If not specified, it fetches information from the metadata server
  23588. type: string
  23589. clusterProjectID:
  23590. description: |-
  23591. ClusterProjectID is the project ID of the cluster
  23592. If not specified, it fetches information from the metadata server
  23593. type: string
  23594. serviceAccountRef:
  23595. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23596. properties:
  23597. audiences:
  23598. description: |-
  23599. Audience specifies the `aud` claim for the service account token
  23600. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23601. then this audiences will be appended to the list
  23602. items:
  23603. type: string
  23604. type: array
  23605. name:
  23606. description: The name of the ServiceAccount resource being referred to.
  23607. maxLength: 253
  23608. minLength: 1
  23609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23610. type: string
  23611. namespace:
  23612. description: |-
  23613. Namespace of the resource being referred to.
  23614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23615. maxLength: 63
  23616. minLength: 1
  23617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23618. type: string
  23619. required:
  23620. - name
  23621. type: object
  23622. required:
  23623. - serviceAccountRef
  23624. type: object
  23625. type: object
  23626. location:
  23627. description: Location optionally defines a location for a secret
  23628. type: string
  23629. projectID:
  23630. description: ProjectID project where secret is located
  23631. type: string
  23632. type: object
  23633. github:
  23634. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  23635. properties:
  23636. appID:
  23637. description: appID specifies the Github APP that will be used to authenticate the client
  23638. format: int64
  23639. type: integer
  23640. auth:
  23641. description: auth configures how secret-manager authenticates with a Github instance.
  23642. properties:
  23643. privateKey:
  23644. description: |-
  23645. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23646. In some instances, `key` is a required field.
  23647. properties:
  23648. key:
  23649. description: |-
  23650. A key in the referenced Secret.
  23651. Some instances of this field may be defaulted, in others it may be required.
  23652. maxLength: 253
  23653. minLength: 1
  23654. pattern: ^[-._a-zA-Z0-9]+$
  23655. type: string
  23656. name:
  23657. description: The name of the Secret resource being referred to.
  23658. maxLength: 253
  23659. minLength: 1
  23660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23661. type: string
  23662. namespace:
  23663. description: |-
  23664. The namespace of the Secret resource being referred to.
  23665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23666. maxLength: 63
  23667. minLength: 1
  23668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23669. type: string
  23670. type: object
  23671. required:
  23672. - privateKey
  23673. type: object
  23674. environment:
  23675. description: environment will be used to fetch secrets from a particular environment within a github repository
  23676. type: string
  23677. installationID:
  23678. description: installationID specifies the Github APP installation that will be used to authenticate the client
  23679. format: int64
  23680. type: integer
  23681. organization:
  23682. description: organization will be used to fetch secrets from the Github organization
  23683. type: string
  23684. repository:
  23685. description: repository will be used to fetch secrets from the Github repository within an organization
  23686. type: string
  23687. uploadURL:
  23688. description: Upload URL for enterprise instances. Default to URL.
  23689. type: string
  23690. url:
  23691. default: https://github.com/
  23692. description: URL configures the Github instance URL. Defaults to https://github.com/.
  23693. type: string
  23694. required:
  23695. - appID
  23696. - auth
  23697. - installationID
  23698. - organization
  23699. type: object
  23700. gitlab:
  23701. description: GitLab configures this store to sync secrets using GitLab Variables provider
  23702. properties:
  23703. auth:
  23704. description: Auth configures how secret-manager authenticates with a GitLab instance.
  23705. properties:
  23706. SecretRef:
  23707. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  23708. properties:
  23709. accessToken:
  23710. description: AccessToken is used for authentication.
  23711. properties:
  23712. key:
  23713. description: |-
  23714. A key in the referenced Secret.
  23715. Some instances of this field may be defaulted, in others it may be required.
  23716. maxLength: 253
  23717. minLength: 1
  23718. pattern: ^[-._a-zA-Z0-9]+$
  23719. type: string
  23720. name:
  23721. description: The name of the Secret resource being referred to.
  23722. maxLength: 253
  23723. minLength: 1
  23724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23725. type: string
  23726. namespace:
  23727. description: |-
  23728. The namespace of the Secret resource being referred to.
  23729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23730. maxLength: 63
  23731. minLength: 1
  23732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23733. type: string
  23734. type: object
  23735. type: object
  23736. required:
  23737. - SecretRef
  23738. type: object
  23739. caBundle:
  23740. description: |-
  23741. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23742. can be performed.
  23743. format: byte
  23744. type: string
  23745. caProvider:
  23746. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23747. properties:
  23748. key:
  23749. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23750. maxLength: 253
  23751. minLength: 1
  23752. pattern: ^[-._a-zA-Z0-9]+$
  23753. type: string
  23754. name:
  23755. description: The name of the object located at the provider type.
  23756. maxLength: 253
  23757. minLength: 1
  23758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23759. type: string
  23760. namespace:
  23761. description: |-
  23762. The namespace the Provider type is in.
  23763. Can only be defined when used in a ClusterSecretStore.
  23764. maxLength: 63
  23765. minLength: 1
  23766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23767. type: string
  23768. type:
  23769. description: The type of provider to use such as "Secret", or "ConfigMap".
  23770. enum:
  23771. - Secret
  23772. - ConfigMap
  23773. type: string
  23774. required:
  23775. - name
  23776. - type
  23777. type: object
  23778. environment:
  23779. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  23780. type: string
  23781. groupIDs:
  23782. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  23783. items:
  23784. type: string
  23785. type: array
  23786. inheritFromGroups:
  23787. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  23788. type: boolean
  23789. projectID:
  23790. description: ProjectID specifies a project where secrets are located.
  23791. type: string
  23792. url:
  23793. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  23794. type: string
  23795. required:
  23796. - auth
  23797. type: object
  23798. ibm:
  23799. description: IBM configures this store to sync secrets using IBM Cloud provider
  23800. properties:
  23801. auth:
  23802. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  23803. maxProperties: 1
  23804. minProperties: 1
  23805. properties:
  23806. containerAuth:
  23807. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  23808. properties:
  23809. iamEndpoint:
  23810. type: string
  23811. profile:
  23812. description: the IBM Trusted Profile
  23813. type: string
  23814. tokenLocation:
  23815. description: Location the token is mounted on the pod
  23816. type: string
  23817. required:
  23818. - profile
  23819. type: object
  23820. secretRef:
  23821. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  23822. properties:
  23823. secretApiKeySecretRef:
  23824. description: The SecretAccessKey is used for authentication
  23825. properties:
  23826. key:
  23827. description: |-
  23828. A key in the referenced Secret.
  23829. Some instances of this field may be defaulted, in others it may be required.
  23830. maxLength: 253
  23831. minLength: 1
  23832. pattern: ^[-._a-zA-Z0-9]+$
  23833. type: string
  23834. name:
  23835. description: The name of the Secret resource being referred to.
  23836. maxLength: 253
  23837. minLength: 1
  23838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23839. type: string
  23840. namespace:
  23841. description: |-
  23842. The namespace of the Secret resource being referred to.
  23843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23844. maxLength: 63
  23845. minLength: 1
  23846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23847. type: string
  23848. type: object
  23849. type: object
  23850. type: object
  23851. serviceUrl:
  23852. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  23853. type: string
  23854. required:
  23855. - auth
  23856. type: object
  23857. infisical:
  23858. description: Infisical configures this store to sync secrets using the Infisical provider
  23859. properties:
  23860. auth:
  23861. description: Auth configures how the Operator authenticates with the Infisical API
  23862. properties:
  23863. universalAuthCredentials:
  23864. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  23865. properties:
  23866. clientId:
  23867. description: |-
  23868. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23869. In some instances, `key` is a required field.
  23870. properties:
  23871. key:
  23872. description: |-
  23873. A key in the referenced Secret.
  23874. Some instances of this field may be defaulted, in others it may be required.
  23875. maxLength: 253
  23876. minLength: 1
  23877. pattern: ^[-._a-zA-Z0-9]+$
  23878. type: string
  23879. name:
  23880. description: The name of the Secret resource being referred to.
  23881. maxLength: 253
  23882. minLength: 1
  23883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23884. type: string
  23885. namespace:
  23886. description: |-
  23887. The namespace of the Secret resource being referred to.
  23888. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23889. maxLength: 63
  23890. minLength: 1
  23891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23892. type: string
  23893. type: object
  23894. clientSecret:
  23895. description: |-
  23896. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23897. In some instances, `key` is a required field.
  23898. properties:
  23899. key:
  23900. description: |-
  23901. A key in the referenced Secret.
  23902. Some instances of this field may be defaulted, in others it may be required.
  23903. maxLength: 253
  23904. minLength: 1
  23905. pattern: ^[-._a-zA-Z0-9]+$
  23906. type: string
  23907. name:
  23908. description: The name of the Secret resource being referred to.
  23909. maxLength: 253
  23910. minLength: 1
  23911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23912. type: string
  23913. namespace:
  23914. description: |-
  23915. The namespace of the Secret resource being referred to.
  23916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23917. maxLength: 63
  23918. minLength: 1
  23919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23920. type: string
  23921. type: object
  23922. required:
  23923. - clientId
  23924. - clientSecret
  23925. type: object
  23926. type: object
  23927. hostAPI:
  23928. default: https://app.infisical.com/api
  23929. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  23930. type: string
  23931. secretsScope:
  23932. description: SecretsScope defines the scope of the secrets within the workspace
  23933. properties:
  23934. environmentSlug:
  23935. description: EnvironmentSlug is the required slug identifier for the environment.
  23936. type: string
  23937. expandSecretReferences:
  23938. default: true
  23939. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  23940. type: boolean
  23941. projectSlug:
  23942. description: ProjectSlug is the required slug identifier for the project.
  23943. type: string
  23944. recursive:
  23945. default: false
  23946. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  23947. type: boolean
  23948. secretsPath:
  23949. default: /
  23950. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  23951. type: string
  23952. required:
  23953. - environmentSlug
  23954. - projectSlug
  23955. type: object
  23956. required:
  23957. - auth
  23958. - secretsScope
  23959. type: object
  23960. keepersecurity:
  23961. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  23962. properties:
  23963. authRef:
  23964. description: |-
  23965. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23966. In some instances, `key` is a required field.
  23967. properties:
  23968. key:
  23969. description: |-
  23970. A key in the referenced Secret.
  23971. Some instances of this field may be defaulted, in others it may be required.
  23972. maxLength: 253
  23973. minLength: 1
  23974. pattern: ^[-._a-zA-Z0-9]+$
  23975. type: string
  23976. name:
  23977. description: The name of the Secret resource being referred to.
  23978. maxLength: 253
  23979. minLength: 1
  23980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23981. type: string
  23982. namespace:
  23983. description: |-
  23984. The namespace of the Secret resource being referred to.
  23985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23986. maxLength: 63
  23987. minLength: 1
  23988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23989. type: string
  23990. type: object
  23991. folderID:
  23992. type: string
  23993. required:
  23994. - authRef
  23995. - folderID
  23996. type: object
  23997. kubernetes:
  23998. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  23999. properties:
  24000. auth:
  24001. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24002. maxProperties: 1
  24003. minProperties: 1
  24004. properties:
  24005. cert:
  24006. description: has both clientCert and clientKey as secretKeySelector
  24007. properties:
  24008. clientCert:
  24009. description: |-
  24010. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24011. In some instances, `key` is a required field.
  24012. properties:
  24013. key:
  24014. description: |-
  24015. A key in the referenced Secret.
  24016. Some instances of this field may be defaulted, in others it may be required.
  24017. maxLength: 253
  24018. minLength: 1
  24019. pattern: ^[-._a-zA-Z0-9]+$
  24020. type: string
  24021. name:
  24022. description: The name of the Secret resource being referred to.
  24023. maxLength: 253
  24024. minLength: 1
  24025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24026. type: string
  24027. namespace:
  24028. description: |-
  24029. The namespace of the Secret resource being referred to.
  24030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24031. maxLength: 63
  24032. minLength: 1
  24033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24034. type: string
  24035. type: object
  24036. clientKey:
  24037. description: |-
  24038. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24039. In some instances, `key` is a required field.
  24040. properties:
  24041. key:
  24042. description: |-
  24043. A key in the referenced Secret.
  24044. Some instances of this field may be defaulted, in others it may be required.
  24045. maxLength: 253
  24046. minLength: 1
  24047. pattern: ^[-._a-zA-Z0-9]+$
  24048. type: string
  24049. name:
  24050. description: The name of the Secret resource being referred to.
  24051. maxLength: 253
  24052. minLength: 1
  24053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24054. type: string
  24055. namespace:
  24056. description: |-
  24057. The namespace of the Secret resource being referred to.
  24058. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24059. maxLength: 63
  24060. minLength: 1
  24061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24062. type: string
  24063. type: object
  24064. type: object
  24065. serviceAccount:
  24066. description: points to a service account that should be used for authentication
  24067. properties:
  24068. audiences:
  24069. description: |-
  24070. Audience specifies the `aud` claim for the service account token
  24071. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24072. then this audiences will be appended to the list
  24073. items:
  24074. type: string
  24075. type: array
  24076. name:
  24077. description: The name of the ServiceAccount resource being referred to.
  24078. maxLength: 253
  24079. minLength: 1
  24080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24081. type: string
  24082. namespace:
  24083. description: |-
  24084. Namespace of the resource being referred to.
  24085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24086. maxLength: 63
  24087. minLength: 1
  24088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24089. type: string
  24090. required:
  24091. - name
  24092. type: object
  24093. token:
  24094. description: use static token to authenticate with
  24095. properties:
  24096. bearerToken:
  24097. description: |-
  24098. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24099. In some instances, `key` is a required field.
  24100. properties:
  24101. key:
  24102. description: |-
  24103. A key in the referenced Secret.
  24104. Some instances of this field may be defaulted, in others it may be required.
  24105. maxLength: 253
  24106. minLength: 1
  24107. pattern: ^[-._a-zA-Z0-9]+$
  24108. type: string
  24109. name:
  24110. description: The name of the Secret resource being referred to.
  24111. maxLength: 253
  24112. minLength: 1
  24113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24114. type: string
  24115. namespace:
  24116. description: |-
  24117. The namespace of the Secret resource being referred to.
  24118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24119. maxLength: 63
  24120. minLength: 1
  24121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24122. type: string
  24123. type: object
  24124. type: object
  24125. type: object
  24126. authRef:
  24127. description: A reference to a secret that contains the auth information.
  24128. properties:
  24129. key:
  24130. description: |-
  24131. A key in the referenced Secret.
  24132. Some instances of this field may be defaulted, in others it may be required.
  24133. maxLength: 253
  24134. minLength: 1
  24135. pattern: ^[-._a-zA-Z0-9]+$
  24136. type: string
  24137. name:
  24138. description: The name of the Secret resource being referred to.
  24139. maxLength: 253
  24140. minLength: 1
  24141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24142. type: string
  24143. namespace:
  24144. description: |-
  24145. The namespace of the Secret resource being referred to.
  24146. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24147. maxLength: 63
  24148. minLength: 1
  24149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24150. type: string
  24151. type: object
  24152. remoteNamespace:
  24153. default: default
  24154. description: Remote namespace to fetch the secrets from
  24155. maxLength: 63
  24156. minLength: 1
  24157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24158. type: string
  24159. server:
  24160. description: configures the Kubernetes server Address.
  24161. properties:
  24162. caBundle:
  24163. description: CABundle is a base64-encoded CA certificate
  24164. format: byte
  24165. type: string
  24166. caProvider:
  24167. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24168. properties:
  24169. key:
  24170. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24171. maxLength: 253
  24172. minLength: 1
  24173. pattern: ^[-._a-zA-Z0-9]+$
  24174. type: string
  24175. name:
  24176. description: The name of the object located at the provider type.
  24177. maxLength: 253
  24178. minLength: 1
  24179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24180. type: string
  24181. namespace:
  24182. description: |-
  24183. The namespace the Provider type is in.
  24184. Can only be defined when used in a ClusterSecretStore.
  24185. maxLength: 63
  24186. minLength: 1
  24187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24188. type: string
  24189. type:
  24190. description: The type of provider to use such as "Secret", or "ConfigMap".
  24191. enum:
  24192. - Secret
  24193. - ConfigMap
  24194. type: string
  24195. required:
  24196. - name
  24197. - type
  24198. type: object
  24199. url:
  24200. default: kubernetes.default
  24201. description: configures the Kubernetes server Address.
  24202. type: string
  24203. type: object
  24204. type: object
  24205. onboardbase:
  24206. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24207. properties:
  24208. apiHost:
  24209. default: https://public.onboardbase.com/api/v1/
  24210. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24211. type: string
  24212. auth:
  24213. description: Auth configures how the Operator authenticates with the Onboardbase API
  24214. properties:
  24215. apiKeyRef:
  24216. description: |-
  24217. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24218. It is used to recognize and authorize access to a project and environment within onboardbase
  24219. properties:
  24220. key:
  24221. description: |-
  24222. A key in the referenced Secret.
  24223. Some instances of this field may be defaulted, in others it may be required.
  24224. maxLength: 253
  24225. minLength: 1
  24226. pattern: ^[-._a-zA-Z0-9]+$
  24227. type: string
  24228. name:
  24229. description: The name of the Secret resource being referred to.
  24230. maxLength: 253
  24231. minLength: 1
  24232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24233. type: string
  24234. namespace:
  24235. description: |-
  24236. The namespace of the Secret resource being referred to.
  24237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24238. maxLength: 63
  24239. minLength: 1
  24240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24241. type: string
  24242. type: object
  24243. passcodeRef:
  24244. description: OnboardbasePasscode is the passcode attached to the API Key
  24245. properties:
  24246. key:
  24247. description: |-
  24248. A key in the referenced Secret.
  24249. Some instances of this field may be defaulted, in others it may be required.
  24250. maxLength: 253
  24251. minLength: 1
  24252. pattern: ^[-._a-zA-Z0-9]+$
  24253. type: string
  24254. name:
  24255. description: The name of the Secret resource being referred to.
  24256. maxLength: 253
  24257. minLength: 1
  24258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24259. type: string
  24260. namespace:
  24261. description: |-
  24262. The namespace of the Secret resource being referred to.
  24263. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24264. maxLength: 63
  24265. minLength: 1
  24266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24267. type: string
  24268. type: object
  24269. required:
  24270. - apiKeyRef
  24271. - passcodeRef
  24272. type: object
  24273. environment:
  24274. default: development
  24275. description: Environment is the name of an environmnent within a project to pull the secrets from
  24276. type: string
  24277. project:
  24278. default: development
  24279. description: Project is an onboardbase project that the secrets should be pulled from
  24280. type: string
  24281. required:
  24282. - apiHost
  24283. - auth
  24284. - environment
  24285. - project
  24286. type: object
  24287. onepassword:
  24288. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24289. properties:
  24290. auth:
  24291. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24292. properties:
  24293. secretRef:
  24294. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24295. properties:
  24296. connectTokenSecretRef:
  24297. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24298. properties:
  24299. key:
  24300. description: |-
  24301. A key in the referenced Secret.
  24302. Some instances of this field may be defaulted, in others it may be required.
  24303. maxLength: 253
  24304. minLength: 1
  24305. pattern: ^[-._a-zA-Z0-9]+$
  24306. type: string
  24307. name:
  24308. description: The name of the Secret resource being referred to.
  24309. maxLength: 253
  24310. minLength: 1
  24311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24312. type: string
  24313. namespace:
  24314. description: |-
  24315. The namespace of the Secret resource being referred to.
  24316. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24317. maxLength: 63
  24318. minLength: 1
  24319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24320. type: string
  24321. type: object
  24322. required:
  24323. - connectTokenSecretRef
  24324. type: object
  24325. required:
  24326. - secretRef
  24327. type: object
  24328. connectHost:
  24329. description: ConnectHost defines the OnePassword Connect Server to connect to
  24330. type: string
  24331. vaults:
  24332. additionalProperties:
  24333. type: integer
  24334. description: Vaults defines which OnePassword vaults to search in which order
  24335. type: object
  24336. required:
  24337. - auth
  24338. - connectHost
  24339. - vaults
  24340. type: object
  24341. oracle:
  24342. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24343. properties:
  24344. auth:
  24345. description: |-
  24346. Auth configures how secret-manager authenticates with the Oracle Vault.
  24347. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24348. properties:
  24349. secretRef:
  24350. description: SecretRef to pass through sensitive information.
  24351. properties:
  24352. fingerprint:
  24353. description: Fingerprint is the fingerprint of the API private key.
  24354. properties:
  24355. key:
  24356. description: |-
  24357. A key in the referenced Secret.
  24358. Some instances of this field may be defaulted, in others it may be required.
  24359. maxLength: 253
  24360. minLength: 1
  24361. pattern: ^[-._a-zA-Z0-9]+$
  24362. type: string
  24363. name:
  24364. description: The name of the Secret resource being referred to.
  24365. maxLength: 253
  24366. minLength: 1
  24367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24368. type: string
  24369. namespace:
  24370. description: |-
  24371. The namespace of the Secret resource being referred to.
  24372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24373. maxLength: 63
  24374. minLength: 1
  24375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24376. type: string
  24377. type: object
  24378. privatekey:
  24379. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24380. properties:
  24381. key:
  24382. description: |-
  24383. A key in the referenced Secret.
  24384. Some instances of this field may be defaulted, in others it may be required.
  24385. maxLength: 253
  24386. minLength: 1
  24387. pattern: ^[-._a-zA-Z0-9]+$
  24388. type: string
  24389. name:
  24390. description: The name of the Secret resource being referred to.
  24391. maxLength: 253
  24392. minLength: 1
  24393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24394. type: string
  24395. namespace:
  24396. description: |-
  24397. The namespace of the Secret resource being referred to.
  24398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24399. maxLength: 63
  24400. minLength: 1
  24401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24402. type: string
  24403. type: object
  24404. required:
  24405. - fingerprint
  24406. - privatekey
  24407. type: object
  24408. tenancy:
  24409. description: Tenancy is the tenancy OCID where user is located.
  24410. type: string
  24411. user:
  24412. description: User is an access OCID specific to the account.
  24413. type: string
  24414. required:
  24415. - secretRef
  24416. - tenancy
  24417. - user
  24418. type: object
  24419. compartment:
  24420. description: |-
  24421. Compartment is the vault compartment OCID.
  24422. Required for PushSecret
  24423. type: string
  24424. encryptionKey:
  24425. description: |-
  24426. EncryptionKey is the OCID of the encryption key within the vault.
  24427. Required for PushSecret
  24428. type: string
  24429. principalType:
  24430. description: |-
  24431. The type of principal to use for authentication. If left blank, the Auth struct will
  24432. determine the principal type. This optional field must be specified if using
  24433. workload identity.
  24434. enum:
  24435. - ""
  24436. - UserPrincipal
  24437. - InstancePrincipal
  24438. - Workload
  24439. type: string
  24440. region:
  24441. description: Region is the region where vault is located.
  24442. type: string
  24443. serviceAccountRef:
  24444. description: |-
  24445. ServiceAccountRef specified the service account
  24446. that should be used when authenticating with WorkloadIdentity.
  24447. properties:
  24448. audiences:
  24449. description: |-
  24450. Audience specifies the `aud` claim for the service account token
  24451. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24452. then this audiences will be appended to the list
  24453. items:
  24454. type: string
  24455. type: array
  24456. name:
  24457. description: The name of the ServiceAccount resource being referred to.
  24458. maxLength: 253
  24459. minLength: 1
  24460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24461. type: string
  24462. namespace:
  24463. description: |-
  24464. Namespace of the resource being referred to.
  24465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24466. maxLength: 63
  24467. minLength: 1
  24468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24469. type: string
  24470. required:
  24471. - name
  24472. type: object
  24473. vault:
  24474. description: Vault is the vault's OCID of the specific vault where secret is located.
  24475. type: string
  24476. required:
  24477. - region
  24478. - vault
  24479. type: object
  24480. passbolt:
  24481. description: PassboltProvider defines configuration for the Passbolt provider.
  24482. properties:
  24483. auth:
  24484. description: Auth defines the information necessary to authenticate against Passbolt Server
  24485. properties:
  24486. passwordSecretRef:
  24487. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  24488. properties:
  24489. key:
  24490. description: |-
  24491. A key in the referenced Secret.
  24492. Some instances of this field may be defaulted, in others it may be required.
  24493. maxLength: 253
  24494. minLength: 1
  24495. pattern: ^[-._a-zA-Z0-9]+$
  24496. type: string
  24497. name:
  24498. description: The name of the Secret resource being referred to.
  24499. maxLength: 253
  24500. minLength: 1
  24501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24502. type: string
  24503. namespace:
  24504. description: |-
  24505. The namespace of the Secret resource being referred to.
  24506. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24507. maxLength: 63
  24508. minLength: 1
  24509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24510. type: string
  24511. type: object
  24512. privateKeySecretRef:
  24513. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  24514. properties:
  24515. key:
  24516. description: |-
  24517. A key in the referenced Secret.
  24518. Some instances of this field may be defaulted, in others it may be required.
  24519. maxLength: 253
  24520. minLength: 1
  24521. pattern: ^[-._a-zA-Z0-9]+$
  24522. type: string
  24523. name:
  24524. description: The name of the Secret resource being referred to.
  24525. maxLength: 253
  24526. minLength: 1
  24527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24528. type: string
  24529. namespace:
  24530. description: |-
  24531. The namespace of the Secret resource being referred to.
  24532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24533. maxLength: 63
  24534. minLength: 1
  24535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24536. type: string
  24537. type: object
  24538. required:
  24539. - passwordSecretRef
  24540. - privateKeySecretRef
  24541. type: object
  24542. host:
  24543. description: Host defines the Passbolt Server to connect to
  24544. type: string
  24545. required:
  24546. - auth
  24547. - host
  24548. type: object
  24549. passworddepot:
  24550. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  24551. properties:
  24552. auth:
  24553. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  24554. properties:
  24555. secretRef:
  24556. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  24557. properties:
  24558. credentials:
  24559. description: Username / Password is used for authentication.
  24560. properties:
  24561. key:
  24562. description: |-
  24563. A key in the referenced Secret.
  24564. Some instances of this field may be defaulted, in others it may be required.
  24565. maxLength: 253
  24566. minLength: 1
  24567. pattern: ^[-._a-zA-Z0-9]+$
  24568. type: string
  24569. name:
  24570. description: The name of the Secret resource being referred to.
  24571. maxLength: 253
  24572. minLength: 1
  24573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24574. type: string
  24575. namespace:
  24576. description: |-
  24577. The namespace of the Secret resource being referred to.
  24578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24579. maxLength: 63
  24580. minLength: 1
  24581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24582. type: string
  24583. type: object
  24584. type: object
  24585. required:
  24586. - secretRef
  24587. type: object
  24588. database:
  24589. description: Database to use as source
  24590. type: string
  24591. host:
  24592. description: URL configures the Password Depot instance URL.
  24593. type: string
  24594. required:
  24595. - auth
  24596. - database
  24597. - host
  24598. type: object
  24599. previder:
  24600. description: Previder configures this store to sync secrets using the Previder provider
  24601. properties:
  24602. auth:
  24603. description: PreviderAuth contains a secretRef for credentials.
  24604. properties:
  24605. secretRef:
  24606. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  24607. properties:
  24608. accessToken:
  24609. description: The AccessToken is used for authentication
  24610. properties:
  24611. key:
  24612. description: |-
  24613. A key in the referenced Secret.
  24614. Some instances of this field may be defaulted, in others it may be required.
  24615. maxLength: 253
  24616. minLength: 1
  24617. pattern: ^[-._a-zA-Z0-9]+$
  24618. type: string
  24619. name:
  24620. description: The name of the Secret resource being referred to.
  24621. maxLength: 253
  24622. minLength: 1
  24623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24624. type: string
  24625. namespace:
  24626. description: |-
  24627. The namespace of the Secret resource being referred to.
  24628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24629. maxLength: 63
  24630. minLength: 1
  24631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24632. type: string
  24633. type: object
  24634. required:
  24635. - accessToken
  24636. type: object
  24637. type: object
  24638. baseUri:
  24639. type: string
  24640. required:
  24641. - auth
  24642. type: object
  24643. pulumi:
  24644. description: Pulumi configures this store to sync secrets using the Pulumi provider
  24645. properties:
  24646. accessToken:
  24647. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  24648. properties:
  24649. secretRef:
  24650. description: SecretRef is a reference to a secret containing the Pulumi API token.
  24651. properties:
  24652. key:
  24653. description: |-
  24654. A key in the referenced Secret.
  24655. Some instances of this field may be defaulted, in others it may be required.
  24656. maxLength: 253
  24657. minLength: 1
  24658. pattern: ^[-._a-zA-Z0-9]+$
  24659. type: string
  24660. name:
  24661. description: The name of the Secret resource being referred to.
  24662. maxLength: 253
  24663. minLength: 1
  24664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24665. type: string
  24666. namespace:
  24667. description: |-
  24668. The namespace of the Secret resource being referred to.
  24669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24670. maxLength: 63
  24671. minLength: 1
  24672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24673. type: string
  24674. type: object
  24675. type: object
  24676. apiUrl:
  24677. default: https://api.pulumi.com/api/esc
  24678. description: APIURL is the URL of the Pulumi API.
  24679. type: string
  24680. environment:
  24681. description: |-
  24682. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  24683. dynamically retrieved values from supported providers including all major clouds,
  24684. and other Pulumi ESC environments.
  24685. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  24686. type: string
  24687. organization:
  24688. description: |-
  24689. Organization are a space to collaborate on shared projects and stacks.
  24690. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  24691. type: string
  24692. project:
  24693. description: Project is the name of the Pulumi ESC project the environment belongs to.
  24694. type: string
  24695. required:
  24696. - accessToken
  24697. - environment
  24698. - organization
  24699. - project
  24700. type: object
  24701. scaleway:
  24702. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  24703. properties:
  24704. accessKey:
  24705. description: AccessKey is the non-secret part of the api key.
  24706. properties:
  24707. secretRef:
  24708. description: SecretRef references a key in a secret that will be used as value.
  24709. properties:
  24710. key:
  24711. description: |-
  24712. A key in the referenced Secret.
  24713. Some instances of this field may be defaulted, in others it may be required.
  24714. maxLength: 253
  24715. minLength: 1
  24716. pattern: ^[-._a-zA-Z0-9]+$
  24717. type: string
  24718. name:
  24719. description: The name of the Secret resource being referred to.
  24720. maxLength: 253
  24721. minLength: 1
  24722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24723. type: string
  24724. namespace:
  24725. description: |-
  24726. The namespace of the Secret resource being referred to.
  24727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24728. maxLength: 63
  24729. minLength: 1
  24730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24731. type: string
  24732. type: object
  24733. value:
  24734. description: Value can be specified directly to set a value without using a secret.
  24735. type: string
  24736. type: object
  24737. apiUrl:
  24738. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  24739. type: string
  24740. projectId:
  24741. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  24742. type: string
  24743. region:
  24744. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  24745. type: string
  24746. secretKey:
  24747. description: SecretKey is the non-secret part of the api key.
  24748. properties:
  24749. secretRef:
  24750. description: SecretRef references a key in a secret that will be used as value.
  24751. properties:
  24752. key:
  24753. description: |-
  24754. A key in the referenced Secret.
  24755. Some instances of this field may be defaulted, in others it may be required.
  24756. maxLength: 253
  24757. minLength: 1
  24758. pattern: ^[-._a-zA-Z0-9]+$
  24759. type: string
  24760. name:
  24761. description: The name of the Secret resource being referred to.
  24762. maxLength: 253
  24763. minLength: 1
  24764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24765. type: string
  24766. namespace:
  24767. description: |-
  24768. The namespace of the Secret resource being referred to.
  24769. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24770. maxLength: 63
  24771. minLength: 1
  24772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24773. type: string
  24774. type: object
  24775. value:
  24776. description: Value can be specified directly to set a value without using a secret.
  24777. type: string
  24778. type: object
  24779. required:
  24780. - accessKey
  24781. - projectId
  24782. - region
  24783. - secretKey
  24784. type: object
  24785. secretserver:
  24786. description: |-
  24787. SecretServer configures this store to sync secrets using SecretServer provider
  24788. https://docs.delinea.com/online-help/secret-server/start.htm
  24789. properties:
  24790. password:
  24791. description: Password is the secret server account password.
  24792. properties:
  24793. secretRef:
  24794. description: SecretRef references a key in a secret that will be used as value.
  24795. properties:
  24796. key:
  24797. description: |-
  24798. A key in the referenced Secret.
  24799. Some instances of this field may be defaulted, in others it may be required.
  24800. maxLength: 253
  24801. minLength: 1
  24802. pattern: ^[-._a-zA-Z0-9]+$
  24803. type: string
  24804. name:
  24805. description: The name of the Secret resource being referred to.
  24806. maxLength: 253
  24807. minLength: 1
  24808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24809. type: string
  24810. namespace:
  24811. description: |-
  24812. The namespace of the Secret resource being referred to.
  24813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24814. maxLength: 63
  24815. minLength: 1
  24816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24817. type: string
  24818. type: object
  24819. value:
  24820. description: Value can be specified directly to set a value without using a secret.
  24821. type: string
  24822. type: object
  24823. serverURL:
  24824. description: |-
  24825. ServerURL
  24826. URL to your secret server installation
  24827. type: string
  24828. username:
  24829. description: Username is the secret server account username.
  24830. properties:
  24831. secretRef:
  24832. description: SecretRef references a key in a secret that will be used as value.
  24833. properties:
  24834. key:
  24835. description: |-
  24836. A key in the referenced Secret.
  24837. Some instances of this field may be defaulted, in others it may be required.
  24838. maxLength: 253
  24839. minLength: 1
  24840. pattern: ^[-._a-zA-Z0-9]+$
  24841. type: string
  24842. name:
  24843. description: The name of the Secret resource being referred to.
  24844. maxLength: 253
  24845. minLength: 1
  24846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24847. type: string
  24848. namespace:
  24849. description: |-
  24850. The namespace of the Secret resource being referred to.
  24851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24852. maxLength: 63
  24853. minLength: 1
  24854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24855. type: string
  24856. type: object
  24857. value:
  24858. description: Value can be specified directly to set a value without using a secret.
  24859. type: string
  24860. type: object
  24861. required:
  24862. - password
  24863. - serverURL
  24864. - username
  24865. type: object
  24866. senhasegura:
  24867. description: Senhasegura configures this store to sync secrets using senhasegura provider
  24868. properties:
  24869. auth:
  24870. description: Auth defines parameters to authenticate in senhasegura
  24871. properties:
  24872. clientId:
  24873. type: string
  24874. clientSecretSecretRef:
  24875. description: |-
  24876. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24877. In some instances, `key` is a required field.
  24878. properties:
  24879. key:
  24880. description: |-
  24881. A key in the referenced Secret.
  24882. Some instances of this field may be defaulted, in others it may be required.
  24883. maxLength: 253
  24884. minLength: 1
  24885. pattern: ^[-._a-zA-Z0-9]+$
  24886. type: string
  24887. name:
  24888. description: The name of the Secret resource being referred to.
  24889. maxLength: 253
  24890. minLength: 1
  24891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24892. type: string
  24893. namespace:
  24894. description: |-
  24895. The namespace of the Secret resource being referred to.
  24896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24897. maxLength: 63
  24898. minLength: 1
  24899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24900. type: string
  24901. type: object
  24902. required:
  24903. - clientId
  24904. - clientSecretSecretRef
  24905. type: object
  24906. ignoreSslCertificate:
  24907. default: false
  24908. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  24909. type: boolean
  24910. module:
  24911. description: Module defines which senhasegura module should be used to get secrets
  24912. type: string
  24913. url:
  24914. description: URL of senhasegura
  24915. type: string
  24916. required:
  24917. - auth
  24918. - module
  24919. - url
  24920. type: object
  24921. vault:
  24922. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  24923. properties:
  24924. auth:
  24925. description: Auth configures how secret-manager authenticates with the Vault server.
  24926. properties:
  24927. appRole:
  24928. description: |-
  24929. AppRole authenticates with Vault using the App Role auth mechanism,
  24930. with the role and secret stored in a Kubernetes Secret resource.
  24931. properties:
  24932. path:
  24933. default: approle
  24934. description: |-
  24935. Path where the App Role authentication backend is mounted
  24936. in Vault, e.g: "approle"
  24937. type: string
  24938. roleId:
  24939. description: |-
  24940. RoleID configured in the App Role authentication backend when setting
  24941. up the authentication backend in Vault.
  24942. type: string
  24943. roleRef:
  24944. description: |-
  24945. Reference to a key in a Secret that contains the App Role ID used
  24946. to authenticate with Vault.
  24947. The `key` field must be specified and denotes which entry within the Secret
  24948. resource is used as the app role id.
  24949. properties:
  24950. key:
  24951. description: |-
  24952. A key in the referenced Secret.
  24953. Some instances of this field may be defaulted, in others it may be required.
  24954. maxLength: 253
  24955. minLength: 1
  24956. pattern: ^[-._a-zA-Z0-9]+$
  24957. type: string
  24958. name:
  24959. description: The name of the Secret resource being referred to.
  24960. maxLength: 253
  24961. minLength: 1
  24962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24963. type: string
  24964. namespace:
  24965. description: |-
  24966. The namespace of the Secret resource being referred to.
  24967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24968. maxLength: 63
  24969. minLength: 1
  24970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24971. type: string
  24972. type: object
  24973. secretRef:
  24974. description: |-
  24975. Reference to a key in a Secret that contains the App Role secret used
  24976. to authenticate with Vault.
  24977. The `key` field must be specified and denotes which entry within the Secret
  24978. resource is used as the app role secret.
  24979. properties:
  24980. key:
  24981. description: |-
  24982. A key in the referenced Secret.
  24983. Some instances of this field may be defaulted, in others it may be required.
  24984. maxLength: 253
  24985. minLength: 1
  24986. pattern: ^[-._a-zA-Z0-9]+$
  24987. type: string
  24988. name:
  24989. description: The name of the Secret resource being referred to.
  24990. maxLength: 253
  24991. minLength: 1
  24992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24993. type: string
  24994. namespace:
  24995. description: |-
  24996. The namespace of the Secret resource being referred to.
  24997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24998. maxLength: 63
  24999. minLength: 1
  25000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25001. type: string
  25002. type: object
  25003. required:
  25004. - path
  25005. - secretRef
  25006. type: object
  25007. cert:
  25008. description: |-
  25009. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25010. Cert authentication method
  25011. properties:
  25012. clientCert:
  25013. description: |-
  25014. ClientCert is a certificate to authenticate using the Cert Vault
  25015. authentication method
  25016. properties:
  25017. key:
  25018. description: |-
  25019. A key in the referenced Secret.
  25020. Some instances of this field may be defaulted, in others it may be required.
  25021. maxLength: 253
  25022. minLength: 1
  25023. pattern: ^[-._a-zA-Z0-9]+$
  25024. type: string
  25025. name:
  25026. description: The name of the Secret resource being referred to.
  25027. maxLength: 253
  25028. minLength: 1
  25029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25030. type: string
  25031. namespace:
  25032. description: |-
  25033. The namespace of the Secret resource being referred to.
  25034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25035. maxLength: 63
  25036. minLength: 1
  25037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25038. type: string
  25039. type: object
  25040. secretRef:
  25041. description: |-
  25042. SecretRef to a key in a Secret resource containing client private key to
  25043. authenticate with Vault using the Cert authentication method
  25044. properties:
  25045. key:
  25046. description: |-
  25047. A key in the referenced Secret.
  25048. Some instances of this field may be defaulted, in others it may be required.
  25049. maxLength: 253
  25050. minLength: 1
  25051. pattern: ^[-._a-zA-Z0-9]+$
  25052. type: string
  25053. name:
  25054. description: The name of the Secret resource being referred to.
  25055. maxLength: 253
  25056. minLength: 1
  25057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25058. type: string
  25059. namespace:
  25060. description: |-
  25061. The namespace of the Secret resource being referred to.
  25062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25063. maxLength: 63
  25064. minLength: 1
  25065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25066. type: string
  25067. type: object
  25068. type: object
  25069. iam:
  25070. description: |-
  25071. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25072. AWS IAM authentication method
  25073. properties:
  25074. externalID:
  25075. description: AWS External ID set on assumed IAM roles
  25076. type: string
  25077. jwt:
  25078. description: Specify a service account with IRSA enabled
  25079. properties:
  25080. serviceAccountRef:
  25081. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25082. properties:
  25083. audiences:
  25084. description: |-
  25085. Audience specifies the `aud` claim for the service account token
  25086. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25087. then this audiences will be appended to the list
  25088. items:
  25089. type: string
  25090. type: array
  25091. name:
  25092. description: The name of the ServiceAccount resource being referred to.
  25093. maxLength: 253
  25094. minLength: 1
  25095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25096. type: string
  25097. namespace:
  25098. description: |-
  25099. Namespace of the resource being referred to.
  25100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25101. maxLength: 63
  25102. minLength: 1
  25103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25104. type: string
  25105. required:
  25106. - name
  25107. type: object
  25108. type: object
  25109. path:
  25110. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25111. type: string
  25112. region:
  25113. description: AWS region
  25114. type: string
  25115. role:
  25116. description: This is the AWS role to be assumed before talking to vault
  25117. type: string
  25118. secretRef:
  25119. description: Specify credentials in a Secret object
  25120. properties:
  25121. accessKeyIDSecretRef:
  25122. description: The AccessKeyID is used for authentication
  25123. properties:
  25124. key:
  25125. description: |-
  25126. A key in the referenced Secret.
  25127. Some instances of this field may be defaulted, in others it may be required.
  25128. maxLength: 253
  25129. minLength: 1
  25130. pattern: ^[-._a-zA-Z0-9]+$
  25131. type: string
  25132. name:
  25133. description: The name of the Secret resource being referred to.
  25134. maxLength: 253
  25135. minLength: 1
  25136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25137. type: string
  25138. namespace:
  25139. description: |-
  25140. The namespace of the Secret resource being referred to.
  25141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25142. maxLength: 63
  25143. minLength: 1
  25144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25145. type: string
  25146. type: object
  25147. secretAccessKeySecretRef:
  25148. description: The SecretAccessKey is used for authentication
  25149. properties:
  25150. key:
  25151. description: |-
  25152. A key in the referenced Secret.
  25153. Some instances of this field may be defaulted, in others it may be required.
  25154. maxLength: 253
  25155. minLength: 1
  25156. pattern: ^[-._a-zA-Z0-9]+$
  25157. type: string
  25158. name:
  25159. description: The name of the Secret resource being referred to.
  25160. maxLength: 253
  25161. minLength: 1
  25162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25163. type: string
  25164. namespace:
  25165. description: |-
  25166. The namespace of the Secret resource being referred to.
  25167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25168. maxLength: 63
  25169. minLength: 1
  25170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25171. type: string
  25172. type: object
  25173. sessionTokenSecretRef:
  25174. description: |-
  25175. The SessionToken used for authentication
  25176. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25177. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25178. properties:
  25179. key:
  25180. description: |-
  25181. A key in the referenced Secret.
  25182. Some instances of this field may be defaulted, in others it may be required.
  25183. maxLength: 253
  25184. minLength: 1
  25185. pattern: ^[-._a-zA-Z0-9]+$
  25186. type: string
  25187. name:
  25188. description: The name of the Secret resource being referred to.
  25189. maxLength: 253
  25190. minLength: 1
  25191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25192. type: string
  25193. namespace:
  25194. description: |-
  25195. The namespace of the Secret resource being referred to.
  25196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25197. maxLength: 63
  25198. minLength: 1
  25199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25200. type: string
  25201. type: object
  25202. type: object
  25203. vaultAwsIamServerID:
  25204. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25205. type: string
  25206. vaultRole:
  25207. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25208. type: string
  25209. required:
  25210. - vaultRole
  25211. type: object
  25212. jwt:
  25213. description: |-
  25214. Jwt authenticates with Vault by passing role and JWT token using the
  25215. JWT/OIDC authentication method
  25216. properties:
  25217. kubernetesServiceAccountToken:
  25218. description: |-
  25219. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25220. a token for with the `TokenRequest` API.
  25221. properties:
  25222. audiences:
  25223. description: |-
  25224. Optional audiences field that will be used to request a temporary Kubernetes service
  25225. account token for the service account referenced by `serviceAccountRef`.
  25226. Defaults to a single audience `vault` it not specified.
  25227. Deprecated: use serviceAccountRef.Audiences instead
  25228. items:
  25229. type: string
  25230. type: array
  25231. expirationSeconds:
  25232. description: |-
  25233. Optional expiration time in seconds that will be used to request a temporary
  25234. Kubernetes service account token for the service account referenced by
  25235. `serviceAccountRef`.
  25236. Deprecated: this will be removed in the future.
  25237. Defaults to 10 minutes.
  25238. format: int64
  25239. type: integer
  25240. serviceAccountRef:
  25241. description: Service account field containing the name of a kubernetes ServiceAccount.
  25242. properties:
  25243. audiences:
  25244. description: |-
  25245. Audience specifies the `aud` claim for the service account token
  25246. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25247. then this audiences will be appended to the list
  25248. items:
  25249. type: string
  25250. type: array
  25251. name:
  25252. description: The name of the ServiceAccount resource being referred to.
  25253. maxLength: 253
  25254. minLength: 1
  25255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25256. type: string
  25257. namespace:
  25258. description: |-
  25259. Namespace of the resource being referred to.
  25260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25261. maxLength: 63
  25262. minLength: 1
  25263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25264. type: string
  25265. required:
  25266. - name
  25267. type: object
  25268. required:
  25269. - serviceAccountRef
  25270. type: object
  25271. path:
  25272. default: jwt
  25273. description: |-
  25274. Path where the JWT authentication backend is mounted
  25275. in Vault, e.g: "jwt"
  25276. type: string
  25277. role:
  25278. description: |-
  25279. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25280. authentication method
  25281. type: string
  25282. secretRef:
  25283. description: |-
  25284. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25285. authenticate with Vault using the JWT/OIDC authentication method.
  25286. properties:
  25287. key:
  25288. description: |-
  25289. A key in the referenced Secret.
  25290. Some instances of this field may be defaulted, in others it may be required.
  25291. maxLength: 253
  25292. minLength: 1
  25293. pattern: ^[-._a-zA-Z0-9]+$
  25294. type: string
  25295. name:
  25296. description: The name of the Secret resource being referred to.
  25297. maxLength: 253
  25298. minLength: 1
  25299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25300. type: string
  25301. namespace:
  25302. description: |-
  25303. The namespace of the Secret resource being referred to.
  25304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25305. maxLength: 63
  25306. minLength: 1
  25307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25308. type: string
  25309. type: object
  25310. required:
  25311. - path
  25312. type: object
  25313. kubernetes:
  25314. description: |-
  25315. Kubernetes authenticates with Vault by passing the ServiceAccount
  25316. token stored in the named Secret resource to the Vault server.
  25317. properties:
  25318. mountPath:
  25319. default: kubernetes
  25320. description: |-
  25321. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25322. "kubernetes"
  25323. type: string
  25324. role:
  25325. description: |-
  25326. A required field containing the Vault Role to assume. A Role binds a
  25327. Kubernetes ServiceAccount with a set of Vault policies.
  25328. type: string
  25329. secretRef:
  25330. description: |-
  25331. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25332. for authenticating with Vault. If a name is specified without a key,
  25333. `token` is the default. If one is not specified, the one bound to
  25334. the controller will be used.
  25335. properties:
  25336. key:
  25337. description: |-
  25338. A key in the referenced Secret.
  25339. Some instances of this field may be defaulted, in others it may be required.
  25340. maxLength: 253
  25341. minLength: 1
  25342. pattern: ^[-._a-zA-Z0-9]+$
  25343. type: string
  25344. name:
  25345. description: The name of the Secret resource being referred to.
  25346. maxLength: 253
  25347. minLength: 1
  25348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25349. type: string
  25350. namespace:
  25351. description: |-
  25352. The namespace of the Secret resource being referred to.
  25353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25354. maxLength: 63
  25355. minLength: 1
  25356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25357. type: string
  25358. type: object
  25359. serviceAccountRef:
  25360. description: |-
  25361. Optional service account field containing the name of a kubernetes ServiceAccount.
  25362. If the service account is specified, the service account secret token JWT will be used
  25363. for authenticating with Vault. If the service account selector is not supplied,
  25364. the secretRef will be used instead.
  25365. properties:
  25366. audiences:
  25367. description: |-
  25368. Audience specifies the `aud` claim for the service account token
  25369. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25370. then this audiences will be appended to the list
  25371. items:
  25372. type: string
  25373. type: array
  25374. name:
  25375. description: The name of the ServiceAccount resource being referred to.
  25376. maxLength: 253
  25377. minLength: 1
  25378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25379. type: string
  25380. namespace:
  25381. description: |-
  25382. Namespace of the resource being referred to.
  25383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25384. maxLength: 63
  25385. minLength: 1
  25386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25387. type: string
  25388. required:
  25389. - name
  25390. type: object
  25391. required:
  25392. - mountPath
  25393. - role
  25394. type: object
  25395. ldap:
  25396. description: |-
  25397. Ldap authenticates with Vault by passing username/password pair using
  25398. the LDAP authentication method
  25399. properties:
  25400. path:
  25401. default: ldap
  25402. description: |-
  25403. Path where the LDAP authentication backend is mounted
  25404. in Vault, e.g: "ldap"
  25405. type: string
  25406. secretRef:
  25407. description: |-
  25408. SecretRef to a key in a Secret resource containing password for the LDAP
  25409. user used to authenticate with Vault using the LDAP authentication
  25410. method
  25411. properties:
  25412. key:
  25413. description: |-
  25414. A key in the referenced Secret.
  25415. Some instances of this field may be defaulted, in others it may be required.
  25416. maxLength: 253
  25417. minLength: 1
  25418. pattern: ^[-._a-zA-Z0-9]+$
  25419. type: string
  25420. name:
  25421. description: The name of the Secret resource being referred to.
  25422. maxLength: 253
  25423. minLength: 1
  25424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25425. type: string
  25426. namespace:
  25427. description: |-
  25428. The namespace of the Secret resource being referred to.
  25429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25430. maxLength: 63
  25431. minLength: 1
  25432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25433. type: string
  25434. type: object
  25435. username:
  25436. description: |-
  25437. Username is an LDAP username used to authenticate using the LDAP Vault
  25438. authentication method
  25439. type: string
  25440. required:
  25441. - path
  25442. - username
  25443. type: object
  25444. namespace:
  25445. description: |-
  25446. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  25447. Namespaces is a set of features within Vault Enterprise that allows
  25448. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  25449. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  25450. This will default to Vault.Namespace field if set, or empty otherwise
  25451. type: string
  25452. tokenSecretRef:
  25453. description: TokenSecretRef authenticates with Vault by presenting a token.
  25454. properties:
  25455. key:
  25456. description: |-
  25457. A key in the referenced Secret.
  25458. Some instances of this field may be defaulted, in others it may be required.
  25459. maxLength: 253
  25460. minLength: 1
  25461. pattern: ^[-._a-zA-Z0-9]+$
  25462. type: string
  25463. name:
  25464. description: The name of the Secret resource being referred to.
  25465. maxLength: 253
  25466. minLength: 1
  25467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25468. type: string
  25469. namespace:
  25470. description: |-
  25471. The namespace of the Secret resource being referred to.
  25472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25473. maxLength: 63
  25474. minLength: 1
  25475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25476. type: string
  25477. type: object
  25478. userPass:
  25479. description: UserPass authenticates with Vault by passing username/password pair
  25480. properties:
  25481. path:
  25482. default: userpass
  25483. description: |-
  25484. Path where the UserPassword authentication backend is mounted
  25485. in Vault, e.g: "userpass"
  25486. type: string
  25487. secretRef:
  25488. description: |-
  25489. SecretRef to a key in a Secret resource containing password for the
  25490. user used to authenticate with Vault using the UserPass authentication
  25491. method
  25492. properties:
  25493. key:
  25494. description: |-
  25495. A key in the referenced Secret.
  25496. Some instances of this field may be defaulted, in others it may be required.
  25497. maxLength: 253
  25498. minLength: 1
  25499. pattern: ^[-._a-zA-Z0-9]+$
  25500. type: string
  25501. name:
  25502. description: The name of the Secret resource being referred to.
  25503. maxLength: 253
  25504. minLength: 1
  25505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25506. type: string
  25507. namespace:
  25508. description: |-
  25509. The namespace of the Secret resource being referred to.
  25510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25511. maxLength: 63
  25512. minLength: 1
  25513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25514. type: string
  25515. type: object
  25516. username:
  25517. description: |-
  25518. Username is a username used to authenticate using the UserPass Vault
  25519. authentication method
  25520. type: string
  25521. required:
  25522. - path
  25523. - username
  25524. type: object
  25525. type: object
  25526. caBundle:
  25527. description: |-
  25528. PEM encoded CA bundle used to validate Vault server certificate. Only used
  25529. if the Server URL is using HTTPS protocol. This parameter is ignored for
  25530. plain HTTP protocol connection. If not set the system root certificates
  25531. are used to validate the TLS connection.
  25532. format: byte
  25533. type: string
  25534. caProvider:
  25535. description: The provider for the CA bundle to use to validate Vault server certificate.
  25536. properties:
  25537. key:
  25538. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25539. maxLength: 253
  25540. minLength: 1
  25541. pattern: ^[-._a-zA-Z0-9]+$
  25542. type: string
  25543. name:
  25544. description: The name of the object located at the provider type.
  25545. maxLength: 253
  25546. minLength: 1
  25547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25548. type: string
  25549. namespace:
  25550. description: |-
  25551. The namespace the Provider type is in.
  25552. Can only be defined when used in a ClusterSecretStore.
  25553. maxLength: 63
  25554. minLength: 1
  25555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25556. type: string
  25557. type:
  25558. description: The type of provider to use such as "Secret", or "ConfigMap".
  25559. enum:
  25560. - Secret
  25561. - ConfigMap
  25562. type: string
  25563. required:
  25564. - name
  25565. - type
  25566. type: object
  25567. forwardInconsistent:
  25568. description: |-
  25569. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  25570. leader instead of simply retrying within a loop. This can increase performance if
  25571. the option is enabled serverside.
  25572. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  25573. type: boolean
  25574. headers:
  25575. additionalProperties:
  25576. type: string
  25577. description: Headers to be added in Vault request
  25578. type: object
  25579. namespace:
  25580. description: |-
  25581. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  25582. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  25583. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  25584. type: string
  25585. path:
  25586. description: |-
  25587. Path is the mount path of the Vault KV backend endpoint, e.g:
  25588. "secret". The v2 KV secret engine version specific "/data" path suffix
  25589. for fetching secrets from Vault is optional and will be appended
  25590. if not present in specified path.
  25591. type: string
  25592. readYourWrites:
  25593. description: |-
  25594. ReadYourWrites ensures isolated read-after-write semantics by
  25595. providing discovered cluster replication states in each request.
  25596. More information about eventual consistency in Vault can be found here
  25597. https://www.vaultproject.io/docs/enterprise/consistency
  25598. type: boolean
  25599. server:
  25600. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  25601. type: string
  25602. tls:
  25603. description: |-
  25604. The configuration used for client side related TLS communication, when the Vault server
  25605. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  25606. This parameter is ignored for plain HTTP protocol connection.
  25607. It's worth noting this configuration is different from the "TLS certificates auth method",
  25608. which is available under the `auth.cert` section.
  25609. properties:
  25610. certSecretRef:
  25611. description: |-
  25612. CertSecretRef is a certificate added to the transport layer
  25613. when communicating with the Vault server.
  25614. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  25615. properties:
  25616. key:
  25617. description: |-
  25618. A key in the referenced Secret.
  25619. Some instances of this field may be defaulted, in others it may be required.
  25620. maxLength: 253
  25621. minLength: 1
  25622. pattern: ^[-._a-zA-Z0-9]+$
  25623. type: string
  25624. name:
  25625. description: The name of the Secret resource being referred to.
  25626. maxLength: 253
  25627. minLength: 1
  25628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25629. type: string
  25630. namespace:
  25631. description: |-
  25632. The namespace of the Secret resource being referred to.
  25633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25634. maxLength: 63
  25635. minLength: 1
  25636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25637. type: string
  25638. type: object
  25639. keySecretRef:
  25640. description: |-
  25641. KeySecretRef to a key in a Secret resource containing client private key
  25642. added to the transport layer when communicating with the Vault server.
  25643. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  25644. properties:
  25645. key:
  25646. description: |-
  25647. A key in the referenced Secret.
  25648. Some instances of this field may be defaulted, in others it may be required.
  25649. maxLength: 253
  25650. minLength: 1
  25651. pattern: ^[-._a-zA-Z0-9]+$
  25652. type: string
  25653. name:
  25654. description: The name of the Secret resource being referred to.
  25655. maxLength: 253
  25656. minLength: 1
  25657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25658. type: string
  25659. namespace:
  25660. description: |-
  25661. The namespace of the Secret resource being referred to.
  25662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25663. maxLength: 63
  25664. minLength: 1
  25665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25666. type: string
  25667. type: object
  25668. type: object
  25669. version:
  25670. default: v2
  25671. description: |-
  25672. Version is the Vault KV secret engine version. This can be either "v1" or
  25673. "v2". Version defaults to "v2".
  25674. enum:
  25675. - v1
  25676. - v2
  25677. type: string
  25678. required:
  25679. - server
  25680. type: object
  25681. webhook:
  25682. description: Webhook configures this store to sync secrets using a generic templated webhook
  25683. properties:
  25684. auth:
  25685. description: Auth specifies a authorization protocol. Only one protocol may be set.
  25686. maxProperties: 1
  25687. minProperties: 1
  25688. properties:
  25689. ntlm:
  25690. description: NTLMProtocol configures the store to use NTLM for auth
  25691. properties:
  25692. passwordSecret:
  25693. description: |-
  25694. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25695. In some instances, `key` is a required field.
  25696. properties:
  25697. key:
  25698. description: |-
  25699. A key in the referenced Secret.
  25700. Some instances of this field may be defaulted, in others it may be required.
  25701. maxLength: 253
  25702. minLength: 1
  25703. pattern: ^[-._a-zA-Z0-9]+$
  25704. type: string
  25705. name:
  25706. description: The name of the Secret resource being referred to.
  25707. maxLength: 253
  25708. minLength: 1
  25709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25710. type: string
  25711. namespace:
  25712. description: |-
  25713. The namespace of the Secret resource being referred to.
  25714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25715. maxLength: 63
  25716. minLength: 1
  25717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25718. type: string
  25719. type: object
  25720. usernameSecret:
  25721. description: |-
  25722. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25723. In some instances, `key` is a required field.
  25724. properties:
  25725. key:
  25726. description: |-
  25727. A key in the referenced Secret.
  25728. Some instances of this field may be defaulted, in others it may be required.
  25729. maxLength: 253
  25730. minLength: 1
  25731. pattern: ^[-._a-zA-Z0-9]+$
  25732. type: string
  25733. name:
  25734. description: The name of the Secret resource being referred to.
  25735. maxLength: 253
  25736. minLength: 1
  25737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25738. type: string
  25739. namespace:
  25740. description: |-
  25741. The namespace of the Secret resource being referred to.
  25742. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25743. maxLength: 63
  25744. minLength: 1
  25745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25746. type: string
  25747. type: object
  25748. required:
  25749. - passwordSecret
  25750. - usernameSecret
  25751. type: object
  25752. type: object
  25753. body:
  25754. description: Body
  25755. type: string
  25756. caBundle:
  25757. description: |-
  25758. PEM encoded CA bundle used to validate webhook server certificate. Only used
  25759. if the Server URL is using HTTPS protocol. This parameter is ignored for
  25760. plain HTTP protocol connection. If not set the system root certificates
  25761. are used to validate the TLS connection.
  25762. format: byte
  25763. type: string
  25764. caProvider:
  25765. description: The provider for the CA bundle to use to validate webhook server certificate.
  25766. properties:
  25767. key:
  25768. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25769. maxLength: 253
  25770. minLength: 1
  25771. pattern: ^[-._a-zA-Z0-9]+$
  25772. type: string
  25773. name:
  25774. description: The name of the object located at the provider type.
  25775. maxLength: 253
  25776. minLength: 1
  25777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25778. type: string
  25779. namespace:
  25780. description: The namespace the Provider type is in.
  25781. maxLength: 63
  25782. minLength: 1
  25783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25784. type: string
  25785. type:
  25786. description: The type of provider to use such as "Secret", or "ConfigMap".
  25787. enum:
  25788. - Secret
  25789. - ConfigMap
  25790. type: string
  25791. required:
  25792. - name
  25793. - type
  25794. type: object
  25795. headers:
  25796. additionalProperties:
  25797. type: string
  25798. description: Headers
  25799. type: object
  25800. method:
  25801. description: Webhook Method
  25802. type: string
  25803. result:
  25804. description: Result formatting
  25805. properties:
  25806. jsonPath:
  25807. description: Json path of return value
  25808. type: string
  25809. type: object
  25810. secrets:
  25811. description: |-
  25812. Secrets to fill in templates
  25813. These secrets will be passed to the templating function as key value pairs under the given name
  25814. items:
  25815. description: WebhookSecret defines a secret to be used in webhook templates.
  25816. properties:
  25817. name:
  25818. description: Name of this secret in templates
  25819. type: string
  25820. secretRef:
  25821. description: Secret ref to fill in credentials
  25822. properties:
  25823. key:
  25824. description: |-
  25825. A key in the referenced Secret.
  25826. Some instances of this field may be defaulted, in others it may be required.
  25827. maxLength: 253
  25828. minLength: 1
  25829. pattern: ^[-._a-zA-Z0-9]+$
  25830. type: string
  25831. name:
  25832. description: The name of the Secret resource being referred to.
  25833. maxLength: 253
  25834. minLength: 1
  25835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25836. type: string
  25837. namespace:
  25838. description: |-
  25839. The namespace of the Secret resource being referred to.
  25840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25841. maxLength: 63
  25842. minLength: 1
  25843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25844. type: string
  25845. type: object
  25846. required:
  25847. - name
  25848. - secretRef
  25849. type: object
  25850. type: array
  25851. timeout:
  25852. description: Timeout
  25853. type: string
  25854. url:
  25855. description: Webhook url to call
  25856. type: string
  25857. required:
  25858. - result
  25859. - url
  25860. type: object
  25861. yandexcertificatemanager:
  25862. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  25863. properties:
  25864. apiEndpoint:
  25865. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  25866. type: string
  25867. auth:
  25868. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  25869. properties:
  25870. authorizedKeySecretRef:
  25871. description: The authorized key used for authentication
  25872. properties:
  25873. key:
  25874. description: |-
  25875. A key in the referenced Secret.
  25876. Some instances of this field may be defaulted, in others it may be required.
  25877. maxLength: 253
  25878. minLength: 1
  25879. pattern: ^[-._a-zA-Z0-9]+$
  25880. type: string
  25881. name:
  25882. description: The name of the Secret resource being referred to.
  25883. maxLength: 253
  25884. minLength: 1
  25885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25886. type: string
  25887. namespace:
  25888. description: |-
  25889. The namespace of the Secret resource being referred to.
  25890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25891. maxLength: 63
  25892. minLength: 1
  25893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25894. type: string
  25895. type: object
  25896. type: object
  25897. caProvider:
  25898. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  25899. properties:
  25900. certSecretRef:
  25901. description: |-
  25902. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25903. In some instances, `key` is a required field.
  25904. properties:
  25905. key:
  25906. description: |-
  25907. A key in the referenced Secret.
  25908. Some instances of this field may be defaulted, in others it may be required.
  25909. maxLength: 253
  25910. minLength: 1
  25911. pattern: ^[-._a-zA-Z0-9]+$
  25912. type: string
  25913. name:
  25914. description: The name of the Secret resource being referred to.
  25915. maxLength: 253
  25916. minLength: 1
  25917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25918. type: string
  25919. namespace:
  25920. description: |-
  25921. The namespace of the Secret resource being referred to.
  25922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25923. maxLength: 63
  25924. minLength: 1
  25925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25926. type: string
  25927. type: object
  25928. type: object
  25929. required:
  25930. - auth
  25931. type: object
  25932. yandexlockbox:
  25933. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  25934. properties:
  25935. apiEndpoint:
  25936. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  25937. type: string
  25938. auth:
  25939. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  25940. properties:
  25941. authorizedKeySecretRef:
  25942. description: The authorized key used for authentication
  25943. properties:
  25944. key:
  25945. description: |-
  25946. A key in the referenced Secret.
  25947. Some instances of this field may be defaulted, in others it may be required.
  25948. maxLength: 253
  25949. minLength: 1
  25950. pattern: ^[-._a-zA-Z0-9]+$
  25951. type: string
  25952. name:
  25953. description: The name of the Secret resource being referred to.
  25954. maxLength: 253
  25955. minLength: 1
  25956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25957. type: string
  25958. namespace:
  25959. description: |-
  25960. The namespace of the Secret resource being referred to.
  25961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25962. maxLength: 63
  25963. minLength: 1
  25964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25965. type: string
  25966. type: object
  25967. type: object
  25968. caProvider:
  25969. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  25970. properties:
  25971. certSecretRef:
  25972. description: |-
  25973. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25974. In some instances, `key` is a required field.
  25975. properties:
  25976. key:
  25977. description: |-
  25978. A key in the referenced Secret.
  25979. Some instances of this field may be defaulted, in others it may be required.
  25980. maxLength: 253
  25981. minLength: 1
  25982. pattern: ^[-._a-zA-Z0-9]+$
  25983. type: string
  25984. name:
  25985. description: The name of the Secret resource being referred to.
  25986. maxLength: 253
  25987. minLength: 1
  25988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25989. type: string
  25990. namespace:
  25991. description: |-
  25992. The namespace of the Secret resource being referred to.
  25993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25994. maxLength: 63
  25995. minLength: 1
  25996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25997. type: string
  25998. type: object
  25999. type: object
  26000. required:
  26001. - auth
  26002. type: object
  26003. type: object
  26004. refreshInterval:
  26005. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26006. type: integer
  26007. retrySettings:
  26008. description: Used to configure HTTP retries on failures.
  26009. properties:
  26010. maxRetries:
  26011. description: MaxRetries is the maximum number of retry attempts.
  26012. format: int32
  26013. type: integer
  26014. retryInterval:
  26015. description: RetryInterval is the interval between retry attempts.
  26016. type: string
  26017. type: object
  26018. required:
  26019. - provider
  26020. type: object
  26021. status:
  26022. description: SecretStoreStatus defines the observed state of the SecretStore.
  26023. properties:
  26024. capabilities:
  26025. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26026. type: string
  26027. conditions:
  26028. items:
  26029. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26030. properties:
  26031. lastTransitionTime:
  26032. format: date-time
  26033. type: string
  26034. message:
  26035. type: string
  26036. reason:
  26037. type: string
  26038. status:
  26039. type: string
  26040. type:
  26041. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26042. type: string
  26043. required:
  26044. - status
  26045. - type
  26046. type: object
  26047. type: array
  26048. type: object
  26049. type: object
  26050. served: false
  26051. storage: false
  26052. subresources:
  26053. status: {}
  26054. ---
  26055. apiVersion: apiextensions.k8s.io/v1
  26056. kind: CustomResourceDefinition
  26057. metadata:
  26058. annotations:
  26059. controller-gen.kubebuilder.io/version: v0.19.0
  26060. labels:
  26061. external-secrets.io/component: controller
  26062. name: acraccesstokens.generators.external-secrets.io
  26063. spec:
  26064. group: generators.external-secrets.io
  26065. names:
  26066. categories:
  26067. - external-secrets
  26068. - external-secrets-generators
  26069. kind: ACRAccessToken
  26070. listKind: ACRAccessTokenList
  26071. plural: acraccesstokens
  26072. singular: acraccesstoken
  26073. scope: Namespaced
  26074. versions:
  26075. - name: v1alpha1
  26076. schema:
  26077. openAPIV3Schema:
  26078. description: |-
  26079. ACRAccessToken returns an Azure Container Registry token
  26080. that can be used for pushing/pulling images.
  26081. Note: by default it will return an ACR Refresh Token with full access
  26082. (depending on the identity).
  26083. This can be scoped down to the repository level using .spec.scope.
  26084. In case scope is defined it will return an ACR Access Token.
  26085. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26086. properties:
  26087. apiVersion:
  26088. description: |-
  26089. APIVersion defines the versioned schema of this representation of an object.
  26090. Servers should convert recognized schemas to the latest internal value, and
  26091. may reject unrecognized values.
  26092. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26093. type: string
  26094. kind:
  26095. description: |-
  26096. Kind is a string value representing the REST resource this object represents.
  26097. Servers may infer this from the endpoint the client submits requests to.
  26098. Cannot be updated.
  26099. In CamelCase.
  26100. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26101. type: string
  26102. metadata:
  26103. type: object
  26104. spec:
  26105. description: |-
  26106. ACRAccessTokenSpec defines how to generate the access token
  26107. e.g. how to authenticate and which registry to use.
  26108. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26109. properties:
  26110. auth:
  26111. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26112. properties:
  26113. managedIdentity:
  26114. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26115. properties:
  26116. identityId:
  26117. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26118. type: string
  26119. type: object
  26120. servicePrincipal:
  26121. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26122. properties:
  26123. secretRef:
  26124. description: |-
  26125. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26126. It uses static credentials stored in a Kind=Secret.
  26127. properties:
  26128. clientId:
  26129. description: The Azure clientId of the service principle used for authentication.
  26130. properties:
  26131. key:
  26132. description: |-
  26133. A key in the referenced Secret.
  26134. Some instances of this field may be defaulted, in others it may be required.
  26135. maxLength: 253
  26136. minLength: 1
  26137. pattern: ^[-._a-zA-Z0-9]+$
  26138. type: string
  26139. name:
  26140. description: The name of the Secret resource being referred to.
  26141. maxLength: 253
  26142. minLength: 1
  26143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26144. type: string
  26145. namespace:
  26146. description: |-
  26147. The namespace of the Secret resource being referred to.
  26148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26149. maxLength: 63
  26150. minLength: 1
  26151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26152. type: string
  26153. type: object
  26154. clientSecret:
  26155. description: The Azure ClientSecret of the service principle used for authentication.
  26156. properties:
  26157. key:
  26158. description: |-
  26159. A key in the referenced Secret.
  26160. Some instances of this field may be defaulted, in others it may be required.
  26161. maxLength: 253
  26162. minLength: 1
  26163. pattern: ^[-._a-zA-Z0-9]+$
  26164. type: string
  26165. name:
  26166. description: The name of the Secret resource being referred to.
  26167. maxLength: 253
  26168. minLength: 1
  26169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26170. type: string
  26171. namespace:
  26172. description: |-
  26173. The namespace of the Secret resource being referred to.
  26174. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26175. maxLength: 63
  26176. minLength: 1
  26177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26178. type: string
  26179. type: object
  26180. type: object
  26181. required:
  26182. - secretRef
  26183. type: object
  26184. workloadIdentity:
  26185. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26186. properties:
  26187. serviceAccountRef:
  26188. description: |-
  26189. ServiceAccountRef specified the service account
  26190. that should be used when authenticating with WorkloadIdentity.
  26191. properties:
  26192. audiences:
  26193. description: |-
  26194. Audience specifies the `aud` claim for the service account token
  26195. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26196. then this audiences will be appended to the list
  26197. items:
  26198. type: string
  26199. type: array
  26200. name:
  26201. description: The name of the ServiceAccount resource being referred to.
  26202. maxLength: 253
  26203. minLength: 1
  26204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26205. type: string
  26206. namespace:
  26207. description: |-
  26208. Namespace of the resource being referred to.
  26209. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26210. maxLength: 63
  26211. minLength: 1
  26212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26213. type: string
  26214. required:
  26215. - name
  26216. type: object
  26217. type: object
  26218. type: object
  26219. environmentType:
  26220. default: PublicCloud
  26221. description: |-
  26222. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26223. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26224. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26225. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26226. enum:
  26227. - PublicCloud
  26228. - USGovernmentCloud
  26229. - ChinaCloud
  26230. - GermanCloud
  26231. - AzureStackCloud
  26232. type: string
  26233. registry:
  26234. description: |-
  26235. the domain name of the ACR registry
  26236. e.g. foobarexample.azurecr.io
  26237. type: string
  26238. scope:
  26239. description: |-
  26240. Define the scope for the access token, e.g. pull/push access for a repository.
  26241. if not provided it will return a refresh token that has full scope.
  26242. Note: you need to pin it down to the repository level, there is no wildcard available.
  26243. examples:
  26244. repository:my-repository:pull,push
  26245. repository:my-repository:pull
  26246. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26247. type: string
  26248. tenantId:
  26249. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26250. type: string
  26251. required:
  26252. - auth
  26253. - registry
  26254. type: object
  26255. type: object
  26256. served: true
  26257. storage: true
  26258. subresources:
  26259. status: {}
  26260. ---
  26261. apiVersion: apiextensions.k8s.io/v1
  26262. kind: CustomResourceDefinition
  26263. metadata:
  26264. annotations:
  26265. controller-gen.kubebuilder.io/version: v0.19.0
  26266. labels:
  26267. external-secrets.io/component: controller
  26268. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26269. spec:
  26270. group: generators.external-secrets.io
  26271. names:
  26272. categories:
  26273. - external-secrets
  26274. - external-secrets-generators
  26275. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26276. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26277. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26278. singular: beyondtrustworkloadcredentialsdynamicsecret
  26279. scope: Namespaced
  26280. versions:
  26281. - name: v1alpha1
  26282. schema:
  26283. openAPIV3Schema:
  26284. description: |-
  26285. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26286. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26287. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26288. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26289. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26290. properties:
  26291. apiVersion:
  26292. description: |-
  26293. APIVersion defines the versioned schema of this representation of an object.
  26294. Servers should convert recognized schemas to the latest internal value, and
  26295. may reject unrecognized values.
  26296. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26297. type: string
  26298. kind:
  26299. description: |-
  26300. Kind is a string value representing the REST resource this object represents.
  26301. Servers may infer this from the endpoint the client submits requests to.
  26302. Cannot be updated.
  26303. In CamelCase.
  26304. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26305. type: string
  26306. metadata:
  26307. type: object
  26308. spec:
  26309. description: |-
  26310. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26311. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26312. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26313. properties:
  26314. controller:
  26315. description: |-
  26316. Controller selects the controller that should handle this generator.
  26317. Leave empty to use the default controller.
  26318. type: string
  26319. provider:
  26320. description: |-
  26321. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26322. server connection details, and the folder path to the dynamic secret definition.
  26323. The folderPath should point to a dynamic secret definition that has been created in
  26324. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26325. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26326. properties:
  26327. auth:
  26328. description: |-
  26329. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26330. Currently supports API key authentication via Kubernetes secret reference.
  26331. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26332. properties:
  26333. apikey:
  26334. description: |-
  26335. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26336. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26337. properties:
  26338. token:
  26339. description: |-
  26340. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26341. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26342. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26343. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26344. properties:
  26345. key:
  26346. description: |-
  26347. A key in the referenced Secret.
  26348. Some instances of this field may be defaulted, in others it may be required.
  26349. maxLength: 253
  26350. minLength: 1
  26351. pattern: ^[-._a-zA-Z0-9]+$
  26352. type: string
  26353. name:
  26354. description: The name of the Secret resource being referred to.
  26355. maxLength: 253
  26356. minLength: 1
  26357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26358. type: string
  26359. namespace:
  26360. description: |-
  26361. The namespace of the Secret resource being referred to.
  26362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26363. maxLength: 63
  26364. minLength: 1
  26365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26366. type: string
  26367. type: object
  26368. required:
  26369. - token
  26370. type: object
  26371. required:
  26372. - apikey
  26373. type: object
  26374. caBundle:
  26375. description: |-
  26376. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26377. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26378. If not set, the system's trusted root certificates are used.
  26379. format: byte
  26380. type: string
  26381. caProvider:
  26382. description: |-
  26383. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26384. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26385. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26386. properties:
  26387. key:
  26388. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26389. maxLength: 253
  26390. minLength: 1
  26391. pattern: ^[-._a-zA-Z0-9]+$
  26392. type: string
  26393. name:
  26394. description: The name of the object located at the provider type.
  26395. maxLength: 253
  26396. minLength: 1
  26397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26398. type: string
  26399. namespace:
  26400. description: |-
  26401. The namespace the Provider type is in.
  26402. Can only be defined when used in a ClusterSecretStore.
  26403. maxLength: 63
  26404. minLength: 1
  26405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26406. type: string
  26407. type:
  26408. description: The type of provider to use such as "Secret", or "ConfigMap".
  26409. enum:
  26410. - Secret
  26411. - ConfigMap
  26412. type: string
  26413. required:
  26414. - name
  26415. - type
  26416. type: object
  26417. folderPath:
  26418. description: |-
  26419. FolderPath specifies the default folder path for secret retrieval.
  26420. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  26421. Example: "production/database" or "dev/api-keys"
  26422. Leave empty to retrieve secrets from the root folder.
  26423. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  26424. type: string
  26425. server:
  26426. description: |-
  26427. Server configures the BeyondTrust Workload Credentials server connection details.
  26428. Includes the API URL and Site ID for your BeyondTrust instance.
  26429. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26430. properties:
  26431. apiUrl:
  26432. description: |-
  26433. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  26434. This should be the full URL to your BeyondTrust instance.
  26435. Example: https://api.beyondtrust.io/siie
  26436. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  26437. type: string
  26438. siteId:
  26439. description: |-
  26440. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  26441. This identifier is unique to your BeyondTrust Workload Credentials instance.
  26442. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  26443. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  26444. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26445. type: string
  26446. required:
  26447. - apiUrl
  26448. - siteId
  26449. type: object
  26450. required:
  26451. - auth
  26452. - server
  26453. type: object
  26454. retrySettings:
  26455. description: |-
  26456. RetrySettings configures exponential backoff for failed API requests.
  26457. If not specified, uses the default retry settings.
  26458. properties:
  26459. maxRetries:
  26460. format: int32
  26461. type: integer
  26462. retryInterval:
  26463. type: string
  26464. type: object
  26465. required:
  26466. - provider
  26467. type: object
  26468. type: object
  26469. served: true
  26470. storage: true
  26471. subresources:
  26472. status: {}
  26473. ---
  26474. apiVersion: apiextensions.k8s.io/v1
  26475. kind: CustomResourceDefinition
  26476. metadata:
  26477. annotations:
  26478. controller-gen.kubebuilder.io/version: v0.19.0
  26479. labels:
  26480. external-secrets.io/component: controller
  26481. name: cloudsmithaccesstokens.generators.external-secrets.io
  26482. spec:
  26483. group: generators.external-secrets.io
  26484. names:
  26485. categories:
  26486. - external-secrets
  26487. - external-secrets-generators
  26488. kind: CloudsmithAccessToken
  26489. listKind: CloudsmithAccessTokenList
  26490. plural: cloudsmithaccesstokens
  26491. singular: cloudsmithaccesstoken
  26492. scope: Namespaced
  26493. versions:
  26494. - name: v1alpha1
  26495. schema:
  26496. openAPIV3Schema:
  26497. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  26498. properties:
  26499. apiVersion:
  26500. description: |-
  26501. APIVersion defines the versioned schema of this representation of an object.
  26502. Servers should convert recognized schemas to the latest internal value, and
  26503. may reject unrecognized values.
  26504. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26505. type: string
  26506. kind:
  26507. description: |-
  26508. Kind is a string value representing the REST resource this object represents.
  26509. Servers may infer this from the endpoint the client submits requests to.
  26510. Cannot be updated.
  26511. In CamelCase.
  26512. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26513. type: string
  26514. metadata:
  26515. type: object
  26516. spec:
  26517. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  26518. properties:
  26519. apiUrl:
  26520. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  26521. type: string
  26522. orgSlug:
  26523. description: OrgSlug is the organization slug in Cloudsmith
  26524. type: string
  26525. serviceAccountRef:
  26526. description: Name of the service account you are federating with
  26527. properties:
  26528. audiences:
  26529. description: |-
  26530. Audience specifies the `aud` claim for the service account token
  26531. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26532. then this audiences will be appended to the list
  26533. items:
  26534. type: string
  26535. type: array
  26536. name:
  26537. description: The name of the ServiceAccount resource being referred to.
  26538. maxLength: 253
  26539. minLength: 1
  26540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26541. type: string
  26542. namespace:
  26543. description: |-
  26544. Namespace of the resource being referred to.
  26545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26546. maxLength: 63
  26547. minLength: 1
  26548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26549. type: string
  26550. required:
  26551. - name
  26552. type: object
  26553. serviceSlug:
  26554. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  26555. type: string
  26556. required:
  26557. - orgSlug
  26558. - serviceAccountRef
  26559. - serviceSlug
  26560. type: object
  26561. type: object
  26562. served: true
  26563. storage: true
  26564. subresources:
  26565. status: {}
  26566. ---
  26567. apiVersion: apiextensions.k8s.io/v1
  26568. kind: CustomResourceDefinition
  26569. metadata:
  26570. annotations:
  26571. controller-gen.kubebuilder.io/version: v0.19.0
  26572. labels:
  26573. external-secrets.io/component: controller
  26574. name: clustergenerators.generators.external-secrets.io
  26575. spec:
  26576. group: generators.external-secrets.io
  26577. names:
  26578. categories:
  26579. - external-secrets
  26580. - external-secrets-generators
  26581. kind: ClusterGenerator
  26582. listKind: ClusterGeneratorList
  26583. plural: clustergenerators
  26584. singular: clustergenerator
  26585. scope: Cluster
  26586. versions:
  26587. - name: v1alpha1
  26588. schema:
  26589. openAPIV3Schema:
  26590. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  26591. properties:
  26592. apiVersion:
  26593. description: |-
  26594. APIVersion defines the versioned schema of this representation of an object.
  26595. Servers should convert recognized schemas to the latest internal value, and
  26596. may reject unrecognized values.
  26597. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26598. type: string
  26599. kind:
  26600. description: |-
  26601. Kind is a string value representing the REST resource this object represents.
  26602. Servers may infer this from the endpoint the client submits requests to.
  26603. Cannot be updated.
  26604. In CamelCase.
  26605. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26606. type: string
  26607. metadata:
  26608. type: object
  26609. spec:
  26610. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  26611. properties:
  26612. generator:
  26613. description: Generator the spec for this generator, must match the kind.
  26614. maxProperties: 1
  26615. minProperties: 1
  26616. properties:
  26617. acrAccessTokenSpec:
  26618. description: |-
  26619. ACRAccessTokenSpec defines how to generate the access token
  26620. e.g. how to authenticate and which registry to use.
  26621. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26622. properties:
  26623. auth:
  26624. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26625. properties:
  26626. managedIdentity:
  26627. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26628. properties:
  26629. identityId:
  26630. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26631. type: string
  26632. type: object
  26633. servicePrincipal:
  26634. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26635. properties:
  26636. secretRef:
  26637. description: |-
  26638. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26639. It uses static credentials stored in a Kind=Secret.
  26640. properties:
  26641. clientId:
  26642. description: The Azure clientId of the service principle used for authentication.
  26643. properties:
  26644. key:
  26645. description: |-
  26646. A key in the referenced Secret.
  26647. Some instances of this field may be defaulted, in others it may be required.
  26648. maxLength: 253
  26649. minLength: 1
  26650. pattern: ^[-._a-zA-Z0-9]+$
  26651. type: string
  26652. name:
  26653. description: The name of the Secret resource being referred to.
  26654. maxLength: 253
  26655. minLength: 1
  26656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26657. type: string
  26658. namespace:
  26659. description: |-
  26660. The namespace of the Secret resource being referred to.
  26661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26662. maxLength: 63
  26663. minLength: 1
  26664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26665. type: string
  26666. type: object
  26667. clientSecret:
  26668. description: The Azure ClientSecret of the service principle used for authentication.
  26669. properties:
  26670. key:
  26671. description: |-
  26672. A key in the referenced Secret.
  26673. Some instances of this field may be defaulted, in others it may be required.
  26674. maxLength: 253
  26675. minLength: 1
  26676. pattern: ^[-._a-zA-Z0-9]+$
  26677. type: string
  26678. name:
  26679. description: The name of the Secret resource being referred to.
  26680. maxLength: 253
  26681. minLength: 1
  26682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26683. type: string
  26684. namespace:
  26685. description: |-
  26686. The namespace of the Secret resource being referred to.
  26687. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26688. maxLength: 63
  26689. minLength: 1
  26690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26691. type: string
  26692. type: object
  26693. type: object
  26694. required:
  26695. - secretRef
  26696. type: object
  26697. workloadIdentity:
  26698. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26699. properties:
  26700. serviceAccountRef:
  26701. description: |-
  26702. ServiceAccountRef specified the service account
  26703. that should be used when authenticating with WorkloadIdentity.
  26704. properties:
  26705. audiences:
  26706. description: |-
  26707. Audience specifies the `aud` claim for the service account token
  26708. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26709. then this audiences will be appended to the list
  26710. items:
  26711. type: string
  26712. type: array
  26713. name:
  26714. description: The name of the ServiceAccount resource being referred to.
  26715. maxLength: 253
  26716. minLength: 1
  26717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26718. type: string
  26719. namespace:
  26720. description: |-
  26721. Namespace of the resource being referred to.
  26722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26723. maxLength: 63
  26724. minLength: 1
  26725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26726. type: string
  26727. required:
  26728. - name
  26729. type: object
  26730. type: object
  26731. type: object
  26732. environmentType:
  26733. default: PublicCloud
  26734. description: |-
  26735. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26736. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26737. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26738. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26739. enum:
  26740. - PublicCloud
  26741. - USGovernmentCloud
  26742. - ChinaCloud
  26743. - GermanCloud
  26744. - AzureStackCloud
  26745. type: string
  26746. registry:
  26747. description: |-
  26748. the domain name of the ACR registry
  26749. e.g. foobarexample.azurecr.io
  26750. type: string
  26751. scope:
  26752. description: |-
  26753. Define the scope for the access token, e.g. pull/push access for a repository.
  26754. if not provided it will return a refresh token that has full scope.
  26755. Note: you need to pin it down to the repository level, there is no wildcard available.
  26756. examples:
  26757. repository:my-repository:pull,push
  26758. repository:my-repository:pull
  26759. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26760. type: string
  26761. tenantId:
  26762. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26763. type: string
  26764. required:
  26765. - auth
  26766. - registry
  26767. type: object
  26768. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  26769. description: |-
  26770. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26771. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26772. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26773. properties:
  26774. controller:
  26775. description: |-
  26776. Controller selects the controller that should handle this generator.
  26777. Leave empty to use the default controller.
  26778. type: string
  26779. provider:
  26780. description: |-
  26781. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26782. server connection details, and the folder path to the dynamic secret definition.
  26783. The folderPath should point to a dynamic secret definition that has been created in
  26784. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26785. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26786. properties:
  26787. auth:
  26788. description: |-
  26789. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26790. Currently supports API key authentication via Kubernetes secret reference.
  26791. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26792. properties:
  26793. apikey:
  26794. description: |-
  26795. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26796. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26797. properties:
  26798. token:
  26799. description: |-
  26800. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26801. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26802. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26803. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26804. properties:
  26805. key:
  26806. description: |-
  26807. A key in the referenced Secret.
  26808. Some instances of this field may be defaulted, in others it may be required.
  26809. maxLength: 253
  26810. minLength: 1
  26811. pattern: ^[-._a-zA-Z0-9]+$
  26812. type: string
  26813. name:
  26814. description: The name of the Secret resource being referred to.
  26815. maxLength: 253
  26816. minLength: 1
  26817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26818. type: string
  26819. namespace:
  26820. description: |-
  26821. The namespace of the Secret resource being referred to.
  26822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26823. maxLength: 63
  26824. minLength: 1
  26825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26826. type: string
  26827. type: object
  26828. required:
  26829. - token
  26830. type: object
  26831. required:
  26832. - apikey
  26833. type: object
  26834. caBundle:
  26835. description: |-
  26836. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26837. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26838. If not set, the system's trusted root certificates are used.
  26839. format: byte
  26840. type: string
  26841. caProvider:
  26842. description: |-
  26843. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26844. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26845. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26846. properties:
  26847. key:
  26848. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26849. maxLength: 253
  26850. minLength: 1
  26851. pattern: ^[-._a-zA-Z0-9]+$
  26852. type: string
  26853. name:
  26854. description: The name of the object located at the provider type.
  26855. maxLength: 253
  26856. minLength: 1
  26857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26858. type: string
  26859. namespace:
  26860. description: |-
  26861. The namespace the Provider type is in.
  26862. Can only be defined when used in a ClusterSecretStore.
  26863. maxLength: 63
  26864. minLength: 1
  26865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26866. type: string
  26867. type:
  26868. description: The type of provider to use such as "Secret", or "ConfigMap".
  26869. enum:
  26870. - Secret
  26871. - ConfigMap
  26872. type: string
  26873. required:
  26874. - name
  26875. - type
  26876. type: object
  26877. folderPath:
  26878. description: |-
  26879. FolderPath specifies the default folder path for secret retrieval.
  26880. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  26881. Example: "production/database" or "dev/api-keys"
  26882. Leave empty to retrieve secrets from the root folder.
  26883. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  26884. type: string
  26885. server:
  26886. description: |-
  26887. Server configures the BeyondTrust Workload Credentials server connection details.
  26888. Includes the API URL and Site ID for your BeyondTrust instance.
  26889. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26890. properties:
  26891. apiUrl:
  26892. description: |-
  26893. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  26894. This should be the full URL to your BeyondTrust instance.
  26895. Example: https://api.beyondtrust.io/siie
  26896. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  26897. type: string
  26898. siteId:
  26899. description: |-
  26900. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  26901. This identifier is unique to your BeyondTrust Workload Credentials instance.
  26902. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  26903. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  26904. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26905. type: string
  26906. required:
  26907. - apiUrl
  26908. - siteId
  26909. type: object
  26910. required:
  26911. - auth
  26912. - server
  26913. type: object
  26914. retrySettings:
  26915. description: |-
  26916. RetrySettings configures exponential backoff for failed API requests.
  26917. If not specified, uses the default retry settings.
  26918. properties:
  26919. maxRetries:
  26920. format: int32
  26921. type: integer
  26922. retryInterval:
  26923. type: string
  26924. type: object
  26925. required:
  26926. - provider
  26927. type: object
  26928. cloudsmithAccessTokenSpec:
  26929. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  26930. properties:
  26931. apiUrl:
  26932. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  26933. type: string
  26934. orgSlug:
  26935. description: OrgSlug is the organization slug in Cloudsmith
  26936. type: string
  26937. serviceAccountRef:
  26938. description: Name of the service account you are federating with
  26939. properties:
  26940. audiences:
  26941. description: |-
  26942. Audience specifies the `aud` claim for the service account token
  26943. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26944. then this audiences will be appended to the list
  26945. items:
  26946. type: string
  26947. type: array
  26948. name:
  26949. description: The name of the ServiceAccount resource being referred to.
  26950. maxLength: 253
  26951. minLength: 1
  26952. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26953. type: string
  26954. namespace:
  26955. description: |-
  26956. Namespace of the resource being referred to.
  26957. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26958. maxLength: 63
  26959. minLength: 1
  26960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26961. type: string
  26962. required:
  26963. - name
  26964. type: object
  26965. serviceSlug:
  26966. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  26967. type: string
  26968. required:
  26969. - orgSlug
  26970. - serviceAccountRef
  26971. - serviceSlug
  26972. type: object
  26973. ecrAuthorizationTokenSpec:
  26974. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  26975. properties:
  26976. auth:
  26977. description: Auth defines how to authenticate with AWS
  26978. properties:
  26979. jwt:
  26980. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  26981. properties:
  26982. serviceAccountRef:
  26983. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26984. properties:
  26985. audiences:
  26986. description: |-
  26987. Audience specifies the `aud` claim for the service account token
  26988. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26989. then this audiences will be appended to the list
  26990. items:
  26991. type: string
  26992. type: array
  26993. name:
  26994. description: The name of the ServiceAccount resource being referred to.
  26995. maxLength: 253
  26996. minLength: 1
  26997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26998. type: string
  26999. namespace:
  27000. description: |-
  27001. Namespace of the resource being referred to.
  27002. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27003. maxLength: 63
  27004. minLength: 1
  27005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27006. type: string
  27007. required:
  27008. - name
  27009. type: object
  27010. type: object
  27011. secretRef:
  27012. description: |-
  27013. AWSAuthSecretRef holds secret references for AWS credentials
  27014. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27015. properties:
  27016. accessKeyIDSecretRef:
  27017. description: The AccessKeyID is used for authentication
  27018. properties:
  27019. key:
  27020. description: |-
  27021. A key in the referenced Secret.
  27022. Some instances of this field may be defaulted, in others it may be required.
  27023. maxLength: 253
  27024. minLength: 1
  27025. pattern: ^[-._a-zA-Z0-9]+$
  27026. type: string
  27027. name:
  27028. description: The name of the Secret resource being referred to.
  27029. maxLength: 253
  27030. minLength: 1
  27031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27032. type: string
  27033. namespace:
  27034. description: |-
  27035. The namespace of the Secret resource being referred to.
  27036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27037. maxLength: 63
  27038. minLength: 1
  27039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27040. type: string
  27041. type: object
  27042. secretAccessKeySecretRef:
  27043. description: The SecretAccessKey is used for authentication
  27044. properties:
  27045. key:
  27046. description: |-
  27047. A key in the referenced Secret.
  27048. Some instances of this field may be defaulted, in others it may be required.
  27049. maxLength: 253
  27050. minLength: 1
  27051. pattern: ^[-._a-zA-Z0-9]+$
  27052. type: string
  27053. name:
  27054. description: The name of the Secret resource being referred to.
  27055. maxLength: 253
  27056. minLength: 1
  27057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27058. type: string
  27059. namespace:
  27060. description: |-
  27061. The namespace of the Secret resource being referred to.
  27062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27063. maxLength: 63
  27064. minLength: 1
  27065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27066. type: string
  27067. type: object
  27068. sessionTokenSecretRef:
  27069. description: |-
  27070. The SessionToken used for authentication
  27071. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27072. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27073. properties:
  27074. key:
  27075. description: |-
  27076. A key in the referenced Secret.
  27077. Some instances of this field may be defaulted, in others it may be required.
  27078. maxLength: 253
  27079. minLength: 1
  27080. pattern: ^[-._a-zA-Z0-9]+$
  27081. type: string
  27082. name:
  27083. description: The name of the Secret resource being referred to.
  27084. maxLength: 253
  27085. minLength: 1
  27086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27087. type: string
  27088. namespace:
  27089. description: |-
  27090. The namespace of the Secret resource being referred to.
  27091. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27092. maxLength: 63
  27093. minLength: 1
  27094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27095. type: string
  27096. type: object
  27097. type: object
  27098. type: object
  27099. region:
  27100. description: Region specifies the region to operate in.
  27101. type: string
  27102. role:
  27103. description: |-
  27104. You can assume a role before making calls to the
  27105. desired AWS service.
  27106. type: string
  27107. scope:
  27108. description: |-
  27109. Scope specifies the ECR service scope.
  27110. Valid options are private and public.
  27111. type: string
  27112. required:
  27113. - region
  27114. type: object
  27115. fakeSpec:
  27116. description: FakeSpec contains the static data.
  27117. properties:
  27118. controller:
  27119. description: |-
  27120. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27121. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27122. type: string
  27123. data:
  27124. additionalProperties:
  27125. type: string
  27126. description: |-
  27127. Data defines the static data returned
  27128. by this generator.
  27129. type: object
  27130. type: object
  27131. gcrAccessTokenSpec:
  27132. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27133. properties:
  27134. auth:
  27135. description: Auth defines the means for authenticating with GCP
  27136. properties:
  27137. secretRef:
  27138. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27139. properties:
  27140. secretAccessKeySecretRef:
  27141. description: The SecretAccessKey is used for authentication
  27142. properties:
  27143. key:
  27144. description: |-
  27145. A key in the referenced Secret.
  27146. Some instances of this field may be defaulted, in others it may be required.
  27147. maxLength: 253
  27148. minLength: 1
  27149. pattern: ^[-._a-zA-Z0-9]+$
  27150. type: string
  27151. name:
  27152. description: The name of the Secret resource being referred to.
  27153. maxLength: 253
  27154. minLength: 1
  27155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27156. type: string
  27157. namespace:
  27158. description: |-
  27159. The namespace of the Secret resource being referred to.
  27160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27161. maxLength: 63
  27162. minLength: 1
  27163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27164. type: string
  27165. type: object
  27166. type: object
  27167. workloadIdentity:
  27168. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27169. properties:
  27170. clusterLocation:
  27171. type: string
  27172. clusterName:
  27173. type: string
  27174. clusterProjectID:
  27175. type: string
  27176. serviceAccountRef:
  27177. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27178. properties:
  27179. audiences:
  27180. description: |-
  27181. Audience specifies the `aud` claim for the service account token
  27182. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27183. then this audiences will be appended to the list
  27184. items:
  27185. type: string
  27186. type: array
  27187. name:
  27188. description: The name of the ServiceAccount resource being referred to.
  27189. maxLength: 253
  27190. minLength: 1
  27191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27192. type: string
  27193. namespace:
  27194. description: |-
  27195. Namespace of the resource being referred to.
  27196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27197. maxLength: 63
  27198. minLength: 1
  27199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27200. type: string
  27201. required:
  27202. - name
  27203. type: object
  27204. required:
  27205. - clusterLocation
  27206. - clusterName
  27207. - serviceAccountRef
  27208. type: object
  27209. workloadIdentityFederation:
  27210. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27211. properties:
  27212. audience:
  27213. description: |-
  27214. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27215. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27216. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27217. type: string
  27218. awsSecurityCredentials:
  27219. description: |-
  27220. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27221. when using the AWS metadata server is not an option.
  27222. properties:
  27223. awsCredentialsSecretRef:
  27224. description: |-
  27225. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27226. Secret should be created with below names for keys
  27227. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27228. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27229. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27230. properties:
  27231. name:
  27232. description: name of the secret.
  27233. maxLength: 253
  27234. minLength: 1
  27235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27236. type: string
  27237. namespace:
  27238. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27239. maxLength: 63
  27240. minLength: 1
  27241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27242. type: string
  27243. required:
  27244. - name
  27245. type: object
  27246. region:
  27247. description: region is for configuring the AWS region to be used.
  27248. example: ap-south-1
  27249. maxLength: 50
  27250. minLength: 1
  27251. pattern: ^[a-z0-9-]+$
  27252. type: string
  27253. required:
  27254. - awsCredentialsSecretRef
  27255. - region
  27256. type: object
  27257. credConfig:
  27258. description: |-
  27259. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27260. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27261. serviceAccountRef must be used by providing operators service account details.
  27262. properties:
  27263. key:
  27264. description: key name holding the external account credential config.
  27265. maxLength: 253
  27266. minLength: 1
  27267. pattern: ^[-._a-zA-Z0-9]+$
  27268. type: string
  27269. name:
  27270. description: name of the configmap.
  27271. maxLength: 253
  27272. minLength: 1
  27273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27274. type: string
  27275. namespace:
  27276. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27277. maxLength: 63
  27278. minLength: 1
  27279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27280. type: string
  27281. required:
  27282. - key
  27283. - name
  27284. type: object
  27285. externalTokenEndpoint:
  27286. description: |-
  27287. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27288. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27289. URL is having the expected value.
  27290. type: string
  27291. gcpServiceAccountEmail:
  27292. description: |-
  27293. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27294. after Workload Identity Federation. Use this to grant access through the service account's
  27295. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27296. service_account_impersonation_url in the external account JSON from credConfig;
  27297. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27298. on that ServiceAccount.
  27299. example: my-gsa@my-project.iam.gserviceaccount.com
  27300. minLength: 1
  27301. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27302. type: string
  27303. serviceAccountRef:
  27304. description: |-
  27305. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27306. when Kubernetes is configured as provider in workload identity pool.
  27307. properties:
  27308. audiences:
  27309. description: |-
  27310. Audience specifies the `aud` claim for the service account token
  27311. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27312. then this audiences will be appended to the list
  27313. items:
  27314. type: string
  27315. type: array
  27316. name:
  27317. description: The name of the ServiceAccount resource being referred to.
  27318. maxLength: 253
  27319. minLength: 1
  27320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27321. type: string
  27322. namespace:
  27323. description: |-
  27324. Namespace of the resource being referred to.
  27325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27326. maxLength: 63
  27327. minLength: 1
  27328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27329. type: string
  27330. required:
  27331. - name
  27332. type: object
  27333. type: object
  27334. type: object
  27335. projectID:
  27336. description: ProjectID defines which project to use to authenticate with
  27337. type: string
  27338. required:
  27339. - auth
  27340. - projectID
  27341. type: object
  27342. githubAccessTokenSpec:
  27343. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27344. properties:
  27345. appID:
  27346. type: string
  27347. auth:
  27348. description: Auth configures how ESO authenticates with a Github instance.
  27349. properties:
  27350. privateKey:
  27351. description: GithubSecretRef references a secret containing GitHub credentials.
  27352. properties:
  27353. secretRef:
  27354. description: |-
  27355. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27356. In some instances, `key` is a required field.
  27357. properties:
  27358. key:
  27359. description: |-
  27360. A key in the referenced Secret.
  27361. Some instances of this field may be defaulted, in others it may be required.
  27362. maxLength: 253
  27363. minLength: 1
  27364. pattern: ^[-._a-zA-Z0-9]+$
  27365. type: string
  27366. name:
  27367. description: The name of the Secret resource being referred to.
  27368. maxLength: 253
  27369. minLength: 1
  27370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27371. type: string
  27372. namespace:
  27373. description: |-
  27374. The namespace of the Secret resource being referred to.
  27375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27376. maxLength: 63
  27377. minLength: 1
  27378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27379. type: string
  27380. type: object
  27381. required:
  27382. - secretRef
  27383. type: object
  27384. required:
  27385. - privateKey
  27386. type: object
  27387. installID:
  27388. type: string
  27389. permissions:
  27390. additionalProperties:
  27391. type: string
  27392. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27393. type: object
  27394. repositories:
  27395. description: |-
  27396. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  27397. is installed to.
  27398. items:
  27399. type: string
  27400. type: array
  27401. url:
  27402. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  27403. type: string
  27404. required:
  27405. - appID
  27406. - auth
  27407. - installID
  27408. type: object
  27409. gitlabDeployTokenSpec:
  27410. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  27411. properties:
  27412. auth:
  27413. description: Auth configures how ESO authenticates with the GitLab API.
  27414. properties:
  27415. token:
  27416. description: |-
  27417. Token references a secret containing a GitLab access token (personal, group, or
  27418. project) with the api scope and at least the Maintainer role on the target.
  27419. properties:
  27420. secretRef:
  27421. description: |-
  27422. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27423. In some instances, `key` is a required field.
  27424. properties:
  27425. key:
  27426. description: |-
  27427. A key in the referenced Secret.
  27428. Some instances of this field may be defaulted, in others it may be required.
  27429. maxLength: 253
  27430. minLength: 1
  27431. pattern: ^[-._a-zA-Z0-9]+$
  27432. type: string
  27433. name:
  27434. description: The name of the Secret resource being referred to.
  27435. maxLength: 253
  27436. minLength: 1
  27437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27438. type: string
  27439. namespace:
  27440. description: |-
  27441. The namespace of the Secret resource being referred to.
  27442. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27443. maxLength: 63
  27444. minLength: 1
  27445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27446. type: string
  27447. type: object
  27448. required:
  27449. - secretRef
  27450. type: object
  27451. required:
  27452. - token
  27453. type: object
  27454. expiresAt:
  27455. description: |-
  27456. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  27457. not expire on the GitLab side and is revoked only when the generator state is
  27458. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  27459. format: date-time
  27460. type: string
  27461. groupID:
  27462. description: |-
  27463. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  27464. create the deploy token in. The generator URL-escapes paths before calling the
  27465. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  27466. minLength: 1
  27467. type: string
  27468. name:
  27469. description: Name of the deploy token.
  27470. minLength: 1
  27471. type: string
  27472. projectID:
  27473. description: |-
  27474. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  27475. project to create the deploy token in. The generator URL-escapes paths before
  27476. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  27477. minLength: 1
  27478. type: string
  27479. scopes:
  27480. description: Scopes granted to the deploy token. At least one scope is required.
  27481. items:
  27482. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  27483. enum:
  27484. - read_repository
  27485. - read_registry
  27486. - write_registry
  27487. - read_package_registry
  27488. - write_package_registry
  27489. - read_virtual_registry
  27490. - write_virtual_registry
  27491. type: string
  27492. minItems: 1
  27493. type: array
  27494. url:
  27495. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  27496. type: string
  27497. username:
  27498. description: |-
  27499. Username is an optional username for the deploy token. GitLab defaults it to
  27500. gitlab+deploy-token-{n} when omitted.
  27501. type: string
  27502. required:
  27503. - auth
  27504. - name
  27505. - scopes
  27506. type: object
  27507. x-kubernetes-validations:
  27508. - message: exactly one of projectID or groupID must be set
  27509. rule: has(self.projectID) != has(self.groupID)
  27510. grafanaSpec:
  27511. description: GrafanaSpec controls the behavior of the grafana generator.
  27512. properties:
  27513. auth:
  27514. description: |-
  27515. Auth is the authentication configuration to authenticate
  27516. against the Grafana instance.
  27517. properties:
  27518. basic:
  27519. description: |-
  27520. Basic auth credentials used to authenticate against the Grafana instance.
  27521. Note: you need a token which has elevated permissions to create service accounts.
  27522. See here for the documentation on basic roles offered by Grafana:
  27523. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27524. properties:
  27525. password:
  27526. description: A basic auth password used to authenticate against the Grafana instance.
  27527. properties:
  27528. key:
  27529. description: The key where the token is found.
  27530. maxLength: 253
  27531. minLength: 1
  27532. pattern: ^[-._a-zA-Z0-9]+$
  27533. type: string
  27534. name:
  27535. description: The name of the Secret resource being referred to.
  27536. maxLength: 253
  27537. minLength: 1
  27538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27539. type: string
  27540. type: object
  27541. username:
  27542. description: A basic auth username used to authenticate against the Grafana instance.
  27543. type: string
  27544. required:
  27545. - password
  27546. - username
  27547. type: object
  27548. token:
  27549. description: |-
  27550. A service account token used to authenticate against the Grafana instance.
  27551. Note: you need a token which has elevated permissions to create service accounts.
  27552. See here for the documentation on basic roles offered by Grafana:
  27553. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27554. properties:
  27555. key:
  27556. description: The key where the token is found.
  27557. maxLength: 253
  27558. minLength: 1
  27559. pattern: ^[-._a-zA-Z0-9]+$
  27560. type: string
  27561. name:
  27562. description: The name of the Secret resource being referred to.
  27563. maxLength: 253
  27564. minLength: 1
  27565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27566. type: string
  27567. type: object
  27568. type: object
  27569. serviceAccount:
  27570. description: |-
  27571. ServiceAccount is the configuration for the service account that
  27572. is supposed to be generated by the generator.
  27573. properties:
  27574. name:
  27575. description: Name is the name of the service account that will be created by ESO.
  27576. type: string
  27577. role:
  27578. description: |-
  27579. Role is the role of the service account.
  27580. See here for the documentation on basic roles offered by Grafana:
  27581. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27582. type: string
  27583. secondsToLive:
  27584. description: |-
  27585. SecondsToLive is the number of seconds before the generated service account token will expire.
  27586. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  27587. format: int64
  27588. minimum: 1
  27589. type: integer
  27590. required:
  27591. - name
  27592. - role
  27593. type: object
  27594. url:
  27595. description: URL is the URL of the Grafana instance.
  27596. type: string
  27597. required:
  27598. - auth
  27599. - serviceAccount
  27600. - url
  27601. type: object
  27602. mfaSpec:
  27603. description: MFASpec controls the behavior of the mfa generator.
  27604. properties:
  27605. algorithm:
  27606. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  27607. type: string
  27608. length:
  27609. description: Length defines the token length. Defaults to 6 characters.
  27610. type: integer
  27611. secret:
  27612. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  27613. properties:
  27614. key:
  27615. description: |-
  27616. A key in the referenced Secret.
  27617. Some instances of this field may be defaulted, in others it may be required.
  27618. maxLength: 253
  27619. minLength: 1
  27620. pattern: ^[-._a-zA-Z0-9]+$
  27621. type: string
  27622. name:
  27623. description: The name of the Secret resource being referred to.
  27624. maxLength: 253
  27625. minLength: 1
  27626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27627. type: string
  27628. namespace:
  27629. description: |-
  27630. The namespace of the Secret resource being referred to.
  27631. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27632. maxLength: 63
  27633. minLength: 1
  27634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27635. type: string
  27636. type: object
  27637. timePeriod:
  27638. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  27639. type: integer
  27640. when:
  27641. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  27642. format: date-time
  27643. type: string
  27644. required:
  27645. - secret
  27646. type: object
  27647. passwordSpec:
  27648. description: PasswordSpec controls the behavior of the password generator.
  27649. properties:
  27650. allowRepeat:
  27651. default: false
  27652. description: set AllowRepeat to true to allow repeating characters.
  27653. type: boolean
  27654. digits:
  27655. description: |-
  27656. Digits specifies the number of digits in the generated
  27657. password. If omitted it defaults to 25% of the length of the password
  27658. type: integer
  27659. encoding:
  27660. default: raw
  27661. description: |-
  27662. Encoding specifies the encoding of the generated password.
  27663. Valid values are:
  27664. - "raw" (default): no encoding
  27665. - "base64": standard base64 encoding
  27666. - "base64url": base64url encoding
  27667. - "base32": base32 encoding
  27668. - "hex": hexadecimal encoding
  27669. enum:
  27670. - base64
  27671. - base64url
  27672. - base32
  27673. - hex
  27674. - raw
  27675. type: string
  27676. length:
  27677. default: 24
  27678. description: |-
  27679. Length of the password to be generated.
  27680. Defaults to 24
  27681. type: integer
  27682. noUpper:
  27683. default: false
  27684. description: Set NoUpper to disable uppercase characters
  27685. type: boolean
  27686. secretKeys:
  27687. description: |-
  27688. SecretKeys defines the keys that will be populated with generated passwords.
  27689. Defaults to "password" when not set.
  27690. items:
  27691. type: string
  27692. minItems: 1
  27693. type: array
  27694. symbolCharacters:
  27695. description: |-
  27696. SymbolCharacters specifies the special characters that should be used
  27697. in the generated password.
  27698. type: string
  27699. symbols:
  27700. description: |-
  27701. Symbols specifies the number of symbol characters in the generated
  27702. password. If omitted it defaults to 25% of the length of the password
  27703. type: integer
  27704. required:
  27705. - allowRepeat
  27706. - length
  27707. - noUpper
  27708. type: object
  27709. quayAccessTokenSpec:
  27710. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  27711. properties:
  27712. robotAccount:
  27713. description: Name of the robot account you are federating with
  27714. type: string
  27715. serviceAccountRef:
  27716. description: Name of the service account you are federating with
  27717. properties:
  27718. audiences:
  27719. description: |-
  27720. Audience specifies the `aud` claim for the service account token
  27721. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27722. then this audiences will be appended to the list
  27723. items:
  27724. type: string
  27725. type: array
  27726. name:
  27727. description: The name of the ServiceAccount resource being referred to.
  27728. maxLength: 253
  27729. minLength: 1
  27730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27731. type: string
  27732. namespace:
  27733. description: |-
  27734. Namespace of the resource being referred to.
  27735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27736. maxLength: 63
  27737. minLength: 1
  27738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27739. type: string
  27740. required:
  27741. - name
  27742. type: object
  27743. url:
  27744. description: URL configures the Quay instance URL. Defaults to quay.io.
  27745. type: string
  27746. required:
  27747. - robotAccount
  27748. - serviceAccountRef
  27749. type: object
  27750. sshKeySpec:
  27751. description: SSHKeySpec controls the behavior of the ssh key generator.
  27752. properties:
  27753. comment:
  27754. description: Comment specifies an optional comment for the SSH key
  27755. type: string
  27756. keySize:
  27757. description: |-
  27758. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  27759. For RSA keys: 2048, 3072, 4096
  27760. For ECDSA keys: 256, 384, 521
  27761. Ignored for ed25519 keys
  27762. maximum: 8192
  27763. minimum: 256
  27764. type: integer
  27765. keyType:
  27766. default: rsa
  27767. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  27768. enum:
  27769. - rsa
  27770. - ecdsa
  27771. - ed25519
  27772. type: string
  27773. type: object
  27774. stsSessionTokenSpec:
  27775. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  27776. properties:
  27777. auth:
  27778. description: Auth defines how to authenticate with AWS
  27779. properties:
  27780. jwt:
  27781. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27782. properties:
  27783. serviceAccountRef:
  27784. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27785. properties:
  27786. audiences:
  27787. description: |-
  27788. Audience specifies the `aud` claim for the service account token
  27789. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27790. then this audiences will be appended to the list
  27791. items:
  27792. type: string
  27793. type: array
  27794. name:
  27795. description: The name of the ServiceAccount resource being referred to.
  27796. maxLength: 253
  27797. minLength: 1
  27798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27799. type: string
  27800. namespace:
  27801. description: |-
  27802. Namespace of the resource being referred to.
  27803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27804. maxLength: 63
  27805. minLength: 1
  27806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27807. type: string
  27808. required:
  27809. - name
  27810. type: object
  27811. type: object
  27812. secretRef:
  27813. description: |-
  27814. AWSAuthSecretRef holds secret references for AWS credentials
  27815. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27816. properties:
  27817. accessKeyIDSecretRef:
  27818. description: The AccessKeyID is used for authentication
  27819. properties:
  27820. key:
  27821. description: |-
  27822. A key in the referenced Secret.
  27823. Some instances of this field may be defaulted, in others it may be required.
  27824. maxLength: 253
  27825. minLength: 1
  27826. pattern: ^[-._a-zA-Z0-9]+$
  27827. type: string
  27828. name:
  27829. description: The name of the Secret resource being referred to.
  27830. maxLength: 253
  27831. minLength: 1
  27832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27833. type: string
  27834. namespace:
  27835. description: |-
  27836. The namespace of the Secret resource being referred to.
  27837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27838. maxLength: 63
  27839. minLength: 1
  27840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27841. type: string
  27842. type: object
  27843. secretAccessKeySecretRef:
  27844. description: The SecretAccessKey is used for authentication
  27845. properties:
  27846. key:
  27847. description: |-
  27848. A key in the referenced Secret.
  27849. Some instances of this field may be defaulted, in others it may be required.
  27850. maxLength: 253
  27851. minLength: 1
  27852. pattern: ^[-._a-zA-Z0-9]+$
  27853. type: string
  27854. name:
  27855. description: The name of the Secret resource being referred to.
  27856. maxLength: 253
  27857. minLength: 1
  27858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27859. type: string
  27860. namespace:
  27861. description: |-
  27862. The namespace of the Secret resource being referred to.
  27863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27864. maxLength: 63
  27865. minLength: 1
  27866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27867. type: string
  27868. type: object
  27869. sessionTokenSecretRef:
  27870. description: |-
  27871. The SessionToken used for authentication
  27872. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27873. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27874. properties:
  27875. key:
  27876. description: |-
  27877. A key in the referenced Secret.
  27878. Some instances of this field may be defaulted, in others it may be required.
  27879. maxLength: 253
  27880. minLength: 1
  27881. pattern: ^[-._a-zA-Z0-9]+$
  27882. type: string
  27883. name:
  27884. description: The name of the Secret resource being referred to.
  27885. maxLength: 253
  27886. minLength: 1
  27887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27888. type: string
  27889. namespace:
  27890. description: |-
  27891. The namespace of the Secret resource being referred to.
  27892. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27893. maxLength: 63
  27894. minLength: 1
  27895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27896. type: string
  27897. type: object
  27898. type: object
  27899. type: object
  27900. region:
  27901. description: Region specifies the region to operate in.
  27902. type: string
  27903. requestParameters:
  27904. description: RequestParameters contains parameters that can be passed to the STS service.
  27905. properties:
  27906. serialNumber:
  27907. description: |-
  27908. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  27909. the GetSessionToken call.
  27910. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  27911. (such as arn:aws:iam::123456789012:mfa/user)
  27912. type: string
  27913. sessionDuration:
  27914. format: int32
  27915. type: integer
  27916. tokenCode:
  27917. description: TokenCode is the value provided by the MFA device, if MFA is required.
  27918. type: string
  27919. type: object
  27920. role:
  27921. description: |-
  27922. You can assume a role before making calls to the
  27923. desired AWS service.
  27924. type: string
  27925. required:
  27926. - region
  27927. type: object
  27928. uuidSpec:
  27929. description: UUIDSpec controls the behavior of the uuid generator.
  27930. type: object
  27931. vaultDynamicSecretSpec:
  27932. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  27933. properties:
  27934. allowEmptyResponse:
  27935. default: false
  27936. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  27937. type: boolean
  27938. controller:
  27939. description: |-
  27940. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27941. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27942. type: string
  27943. getParameters:
  27944. additionalProperties:
  27945. items:
  27946. type: string
  27947. type: array
  27948. description: |-
  27949. GetParameters are query-string parameters passed to Vault on GET calls.
  27950. Each key may map to multiple values, matching HTTP query-string semantics.
  27951. Ignored for non-GET methods; use Parameters for write bodies.
  27952. type: object
  27953. method:
  27954. description: Vault API method to use (GET/POST/other)
  27955. type: string
  27956. parameters:
  27957. description: Parameters to pass to Vault write (for non-GET methods)
  27958. x-kubernetes-preserve-unknown-fields: true
  27959. path:
  27960. description: Vault path to obtain the dynamic secret from
  27961. type: string
  27962. provider:
  27963. description: Vault provider common spec
  27964. properties:
  27965. auth:
  27966. description: Auth configures how secret-manager authenticates with the Vault server.
  27967. properties:
  27968. appRole:
  27969. description: |-
  27970. AppRole authenticates with Vault using the App Role auth mechanism,
  27971. with the role and secret stored in a Kubernetes Secret resource.
  27972. properties:
  27973. path:
  27974. default: approle
  27975. description: |-
  27976. Path where the App Role authentication backend is mounted
  27977. in Vault, e.g: "approle"
  27978. type: string
  27979. roleId:
  27980. description: |-
  27981. RoleID configured in the App Role authentication backend when setting
  27982. up the authentication backend in Vault.
  27983. type: string
  27984. roleRef:
  27985. description: |-
  27986. Reference to a key in a Secret that contains the App Role ID used
  27987. to authenticate with Vault.
  27988. The `key` field must be specified and denotes which entry within the Secret
  27989. resource is used as the app role id.
  27990. properties:
  27991. key:
  27992. description: |-
  27993. A key in the referenced Secret.
  27994. Some instances of this field may be defaulted, in others it may be required.
  27995. maxLength: 253
  27996. minLength: 1
  27997. pattern: ^[-._a-zA-Z0-9]+$
  27998. type: string
  27999. name:
  28000. description: The name of the Secret resource being referred to.
  28001. maxLength: 253
  28002. minLength: 1
  28003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28004. type: string
  28005. namespace:
  28006. description: |-
  28007. The namespace of the Secret resource being referred to.
  28008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28009. maxLength: 63
  28010. minLength: 1
  28011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28012. type: string
  28013. type: object
  28014. secretRef:
  28015. description: |-
  28016. Reference to a key in a Secret that contains the App Role secret used
  28017. to authenticate with Vault.
  28018. The `key` field must be specified and denotes which entry within the Secret
  28019. resource is used as the app role secret.
  28020. properties:
  28021. key:
  28022. description: |-
  28023. A key in the referenced Secret.
  28024. Some instances of this field may be defaulted, in others it may be required.
  28025. maxLength: 253
  28026. minLength: 1
  28027. pattern: ^[-._a-zA-Z0-9]+$
  28028. type: string
  28029. name:
  28030. description: The name of the Secret resource being referred to.
  28031. maxLength: 253
  28032. minLength: 1
  28033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28034. type: string
  28035. namespace:
  28036. description: |-
  28037. The namespace of the Secret resource being referred to.
  28038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28039. maxLength: 63
  28040. minLength: 1
  28041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28042. type: string
  28043. type: object
  28044. required:
  28045. - path
  28046. - secretRef
  28047. type: object
  28048. cert:
  28049. description: |-
  28050. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28051. Cert authentication method
  28052. properties:
  28053. clientCert:
  28054. description: |-
  28055. ClientCert is a certificate to authenticate using the Cert Vault
  28056. authentication method
  28057. properties:
  28058. key:
  28059. description: |-
  28060. A key in the referenced Secret.
  28061. Some instances of this field may be defaulted, in others it may be required.
  28062. maxLength: 253
  28063. minLength: 1
  28064. pattern: ^[-._a-zA-Z0-9]+$
  28065. type: string
  28066. name:
  28067. description: The name of the Secret resource being referred to.
  28068. maxLength: 253
  28069. minLength: 1
  28070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28071. type: string
  28072. namespace:
  28073. description: |-
  28074. The namespace of the Secret resource being referred to.
  28075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28076. maxLength: 63
  28077. minLength: 1
  28078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28079. type: string
  28080. type: object
  28081. path:
  28082. default: cert
  28083. description: |-
  28084. Path where the Certificate authentication backend is mounted
  28085. in Vault, e.g: "cert"
  28086. type: string
  28087. secretRef:
  28088. description: |-
  28089. SecretRef to a key in a Secret resource containing client private key to
  28090. authenticate with Vault using the Cert authentication method
  28091. properties:
  28092. key:
  28093. description: |-
  28094. A key in the referenced Secret.
  28095. Some instances of this field may be defaulted, in others it may be required.
  28096. maxLength: 253
  28097. minLength: 1
  28098. pattern: ^[-._a-zA-Z0-9]+$
  28099. type: string
  28100. name:
  28101. description: The name of the Secret resource being referred to.
  28102. maxLength: 253
  28103. minLength: 1
  28104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28105. type: string
  28106. namespace:
  28107. description: |-
  28108. The namespace of the Secret resource being referred to.
  28109. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28110. maxLength: 63
  28111. minLength: 1
  28112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28113. type: string
  28114. type: object
  28115. vaultRole:
  28116. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28117. type: string
  28118. type: object
  28119. gcp:
  28120. description: |-
  28121. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28122. GCP authentication method
  28123. properties:
  28124. location:
  28125. description: Location optionally defines a location/region for the secret
  28126. type: string
  28127. path:
  28128. default: gcp
  28129. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28130. type: string
  28131. projectID:
  28132. description: Project ID of the Google Cloud Platform project
  28133. type: string
  28134. role:
  28135. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28136. type: string
  28137. secretRef:
  28138. description: Specify credentials in a Secret object
  28139. properties:
  28140. secretAccessKeySecretRef:
  28141. description: The SecretAccessKey is used for authentication
  28142. properties:
  28143. key:
  28144. description: |-
  28145. A key in the referenced Secret.
  28146. Some instances of this field may be defaulted, in others it may be required.
  28147. maxLength: 253
  28148. minLength: 1
  28149. pattern: ^[-._a-zA-Z0-9]+$
  28150. type: string
  28151. name:
  28152. description: The name of the Secret resource being referred to.
  28153. maxLength: 253
  28154. minLength: 1
  28155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28156. type: string
  28157. namespace:
  28158. description: |-
  28159. The namespace of the Secret resource being referred to.
  28160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28161. maxLength: 63
  28162. minLength: 1
  28163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28164. type: string
  28165. type: object
  28166. type: object
  28167. serviceAccountRef:
  28168. description: ServiceAccountRef to a service account for impersonation
  28169. properties:
  28170. audiences:
  28171. description: |-
  28172. Audience specifies the `aud` claim for the service account token
  28173. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28174. then this audiences will be appended to the list
  28175. items:
  28176. type: string
  28177. type: array
  28178. name:
  28179. description: The name of the ServiceAccount resource being referred to.
  28180. maxLength: 253
  28181. minLength: 1
  28182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28183. type: string
  28184. namespace:
  28185. description: |-
  28186. Namespace of the resource being referred to.
  28187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28188. maxLength: 63
  28189. minLength: 1
  28190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28191. type: string
  28192. required:
  28193. - name
  28194. type: object
  28195. workloadIdentity:
  28196. description: Specify a service account with Workload Identity
  28197. properties:
  28198. clusterLocation:
  28199. description: |-
  28200. ClusterLocation is the location of the cluster
  28201. If not specified, it fetches information from the metadata server
  28202. type: string
  28203. clusterName:
  28204. description: |-
  28205. ClusterName is the name of the cluster
  28206. If not specified, it fetches information from the metadata server
  28207. type: string
  28208. clusterProjectID:
  28209. description: |-
  28210. ClusterProjectID is the project ID of the cluster
  28211. If not specified, it fetches information from the metadata server
  28212. type: string
  28213. serviceAccountRef:
  28214. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28215. properties:
  28216. audiences:
  28217. description: |-
  28218. Audience specifies the `aud` claim for the service account token
  28219. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28220. then this audiences will be appended to the list
  28221. items:
  28222. type: string
  28223. type: array
  28224. name:
  28225. description: The name of the ServiceAccount resource being referred to.
  28226. maxLength: 253
  28227. minLength: 1
  28228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28229. type: string
  28230. namespace:
  28231. description: |-
  28232. Namespace of the resource being referred to.
  28233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28234. maxLength: 63
  28235. minLength: 1
  28236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28237. type: string
  28238. required:
  28239. - name
  28240. type: object
  28241. required:
  28242. - serviceAccountRef
  28243. type: object
  28244. required:
  28245. - role
  28246. type: object
  28247. iam:
  28248. description: |-
  28249. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28250. AWS IAM authentication method
  28251. properties:
  28252. externalID:
  28253. description: AWS External ID set on assumed IAM roles
  28254. type: string
  28255. jwt:
  28256. description: Specify a service account with IRSA enabled
  28257. properties:
  28258. serviceAccountRef:
  28259. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28260. properties:
  28261. audiences:
  28262. description: |-
  28263. Audience specifies the `aud` claim for the service account token
  28264. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28265. then this audiences will be appended to the list
  28266. items:
  28267. type: string
  28268. type: array
  28269. name:
  28270. description: The name of the ServiceAccount resource being referred to.
  28271. maxLength: 253
  28272. minLength: 1
  28273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28274. type: string
  28275. namespace:
  28276. description: |-
  28277. Namespace of the resource being referred to.
  28278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28279. maxLength: 63
  28280. minLength: 1
  28281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28282. type: string
  28283. required:
  28284. - name
  28285. type: object
  28286. type: object
  28287. path:
  28288. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28289. type: string
  28290. region:
  28291. description: AWS region
  28292. type: string
  28293. role:
  28294. description: This is the AWS role to be assumed before talking to vault
  28295. type: string
  28296. secretRef:
  28297. description: Specify credentials in a Secret object
  28298. properties:
  28299. accessKeyIDSecretRef:
  28300. description: The AccessKeyID is used for authentication
  28301. properties:
  28302. key:
  28303. description: |-
  28304. A key in the referenced Secret.
  28305. Some instances of this field may be defaulted, in others it may be required.
  28306. maxLength: 253
  28307. minLength: 1
  28308. pattern: ^[-._a-zA-Z0-9]+$
  28309. type: string
  28310. name:
  28311. description: The name of the Secret resource being referred to.
  28312. maxLength: 253
  28313. minLength: 1
  28314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28315. type: string
  28316. namespace:
  28317. description: |-
  28318. The namespace of the Secret resource being referred to.
  28319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28320. maxLength: 63
  28321. minLength: 1
  28322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28323. type: string
  28324. type: object
  28325. secretAccessKeySecretRef:
  28326. description: The SecretAccessKey is used for authentication
  28327. properties:
  28328. key:
  28329. description: |-
  28330. A key in the referenced Secret.
  28331. Some instances of this field may be defaulted, in others it may be required.
  28332. maxLength: 253
  28333. minLength: 1
  28334. pattern: ^[-._a-zA-Z0-9]+$
  28335. type: string
  28336. name:
  28337. description: The name of the Secret resource being referred to.
  28338. maxLength: 253
  28339. minLength: 1
  28340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28341. type: string
  28342. namespace:
  28343. description: |-
  28344. The namespace of the Secret resource being referred to.
  28345. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28346. maxLength: 63
  28347. minLength: 1
  28348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28349. type: string
  28350. type: object
  28351. sessionTokenSecretRef:
  28352. description: |-
  28353. The SessionToken used for authentication
  28354. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28355. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28356. properties:
  28357. key:
  28358. description: |-
  28359. A key in the referenced Secret.
  28360. Some instances of this field may be defaulted, in others it may be required.
  28361. maxLength: 253
  28362. minLength: 1
  28363. pattern: ^[-._a-zA-Z0-9]+$
  28364. type: string
  28365. name:
  28366. description: The name of the Secret resource being referred to.
  28367. maxLength: 253
  28368. minLength: 1
  28369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28370. type: string
  28371. namespace:
  28372. description: |-
  28373. The namespace of the Secret resource being referred to.
  28374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28375. maxLength: 63
  28376. minLength: 1
  28377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28378. type: string
  28379. type: object
  28380. type: object
  28381. vaultAwsIamServerID:
  28382. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28383. type: string
  28384. vaultRole:
  28385. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28386. type: string
  28387. required:
  28388. - vaultRole
  28389. type: object
  28390. jwt:
  28391. description: |-
  28392. Jwt authenticates with Vault by passing role and JWT token using the
  28393. JWT/OIDC authentication method
  28394. properties:
  28395. kubernetesServiceAccountToken:
  28396. description: |-
  28397. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  28398. a token for with the `TokenRequest` API.
  28399. properties:
  28400. audiences:
  28401. description: |-
  28402. Optional audiences field that will be used to request a temporary Kubernetes service
  28403. account token for the service account referenced by `serviceAccountRef`.
  28404. Defaults to a single audience `vault` it not specified.
  28405. Deprecated: use serviceAccountRef.Audiences instead
  28406. items:
  28407. type: string
  28408. type: array
  28409. expirationSeconds:
  28410. description: |-
  28411. Optional expiration time in seconds that will be used to request a temporary
  28412. Kubernetes service account token for the service account referenced by
  28413. `serviceAccountRef`.
  28414. Deprecated: this will be removed in the future.
  28415. Defaults to 10 minutes.
  28416. format: int64
  28417. type: integer
  28418. serviceAccountRef:
  28419. description: Service account field containing the name of a kubernetes ServiceAccount.
  28420. properties:
  28421. audiences:
  28422. description: |-
  28423. Audience specifies the `aud` claim for the service account token
  28424. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28425. then this audiences will be appended to the list
  28426. items:
  28427. type: string
  28428. type: array
  28429. name:
  28430. description: The name of the ServiceAccount resource being referred to.
  28431. maxLength: 253
  28432. minLength: 1
  28433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28434. type: string
  28435. namespace:
  28436. description: |-
  28437. Namespace of the resource being referred to.
  28438. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28439. maxLength: 63
  28440. minLength: 1
  28441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28442. type: string
  28443. required:
  28444. - name
  28445. type: object
  28446. required:
  28447. - serviceAccountRef
  28448. type: object
  28449. path:
  28450. default: jwt
  28451. description: |-
  28452. Path where the JWT authentication backend is mounted
  28453. in Vault, e.g: "jwt"
  28454. type: string
  28455. role:
  28456. description: |-
  28457. Role is a JWT role to authenticate using the JWT/OIDC Vault
  28458. authentication method
  28459. type: string
  28460. secretRef:
  28461. description: |-
  28462. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  28463. authenticate with Vault using the JWT/OIDC authentication method.
  28464. properties:
  28465. key:
  28466. description: |-
  28467. A key in the referenced Secret.
  28468. Some instances of this field may be defaulted, in others it may be required.
  28469. maxLength: 253
  28470. minLength: 1
  28471. pattern: ^[-._a-zA-Z0-9]+$
  28472. type: string
  28473. name:
  28474. description: The name of the Secret resource being referred to.
  28475. maxLength: 253
  28476. minLength: 1
  28477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28478. type: string
  28479. namespace:
  28480. description: |-
  28481. The namespace of the Secret resource being referred to.
  28482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28483. maxLength: 63
  28484. minLength: 1
  28485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28486. type: string
  28487. type: object
  28488. required:
  28489. - path
  28490. type: object
  28491. kubernetes:
  28492. description: |-
  28493. Kubernetes authenticates with Vault by passing the ServiceAccount
  28494. token stored in the named Secret resource to the Vault server.
  28495. properties:
  28496. mountPath:
  28497. default: kubernetes
  28498. description: |-
  28499. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  28500. "kubernetes"
  28501. type: string
  28502. role:
  28503. description: |-
  28504. A required field containing the Vault Role to assume. A Role binds a
  28505. Kubernetes ServiceAccount with a set of Vault policies.
  28506. type: string
  28507. secretRef:
  28508. description: |-
  28509. Optional secret field containing a Kubernetes ServiceAccount JWT used
  28510. for authenticating with Vault. If a name is specified without a key,
  28511. `token` is the default. If one is not specified, the one bound to
  28512. the controller will be used.
  28513. properties:
  28514. key:
  28515. description: |-
  28516. A key in the referenced Secret.
  28517. Some instances of this field may be defaulted, in others it may be required.
  28518. maxLength: 253
  28519. minLength: 1
  28520. pattern: ^[-._a-zA-Z0-9]+$
  28521. type: string
  28522. name:
  28523. description: The name of the Secret resource being referred to.
  28524. maxLength: 253
  28525. minLength: 1
  28526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28527. type: string
  28528. namespace:
  28529. description: |-
  28530. The namespace of the Secret resource being referred to.
  28531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28532. maxLength: 63
  28533. minLength: 1
  28534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28535. type: string
  28536. type: object
  28537. serviceAccountRef:
  28538. description: |-
  28539. Optional service account field containing the name of a kubernetes ServiceAccount.
  28540. If the service account is specified, the service account secret token JWT will be used
  28541. for authenticating with Vault. If the service account selector is not supplied,
  28542. the secretRef will be used instead.
  28543. properties:
  28544. audiences:
  28545. description: |-
  28546. Audience specifies the `aud` claim for the service account token
  28547. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28548. then this audiences will be appended to the list
  28549. items:
  28550. type: string
  28551. type: array
  28552. name:
  28553. description: The name of the ServiceAccount resource being referred to.
  28554. maxLength: 253
  28555. minLength: 1
  28556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28557. type: string
  28558. namespace:
  28559. description: |-
  28560. Namespace of the resource being referred to.
  28561. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28562. maxLength: 63
  28563. minLength: 1
  28564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28565. type: string
  28566. required:
  28567. - name
  28568. type: object
  28569. required:
  28570. - mountPath
  28571. - role
  28572. type: object
  28573. ldap:
  28574. description: |-
  28575. Ldap authenticates with Vault by passing username/password pair using
  28576. the LDAP authentication method
  28577. properties:
  28578. path:
  28579. default: ldap
  28580. description: |-
  28581. Path where the LDAP authentication backend is mounted
  28582. in Vault, e.g: "ldap"
  28583. type: string
  28584. secretRef:
  28585. description: |-
  28586. SecretRef to a key in a Secret resource containing password for the LDAP
  28587. user used to authenticate with Vault using the LDAP authentication
  28588. method
  28589. properties:
  28590. key:
  28591. description: |-
  28592. A key in the referenced Secret.
  28593. Some instances of this field may be defaulted, in others it may be required.
  28594. maxLength: 253
  28595. minLength: 1
  28596. pattern: ^[-._a-zA-Z0-9]+$
  28597. type: string
  28598. name:
  28599. description: The name of the Secret resource being referred to.
  28600. maxLength: 253
  28601. minLength: 1
  28602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28603. type: string
  28604. namespace:
  28605. description: |-
  28606. The namespace of the Secret resource being referred to.
  28607. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28608. maxLength: 63
  28609. minLength: 1
  28610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28611. type: string
  28612. type: object
  28613. username:
  28614. description: |-
  28615. Username is an LDAP username used to authenticate using the LDAP Vault
  28616. authentication method
  28617. type: string
  28618. required:
  28619. - path
  28620. - username
  28621. type: object
  28622. namespace:
  28623. description: |-
  28624. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  28625. Namespaces is a set of features within Vault Enterprise that allows
  28626. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  28627. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  28628. This will default to Vault.Namespace field if set, or empty otherwise
  28629. type: string
  28630. tokenSecretRef:
  28631. description: TokenSecretRef authenticates with Vault by presenting a token.
  28632. properties:
  28633. key:
  28634. description: |-
  28635. A key in the referenced Secret.
  28636. Some instances of this field may be defaulted, in others it may be required.
  28637. maxLength: 253
  28638. minLength: 1
  28639. pattern: ^[-._a-zA-Z0-9]+$
  28640. type: string
  28641. name:
  28642. description: The name of the Secret resource being referred to.
  28643. maxLength: 253
  28644. minLength: 1
  28645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28646. type: string
  28647. namespace:
  28648. description: |-
  28649. The namespace of the Secret resource being referred to.
  28650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28651. maxLength: 63
  28652. minLength: 1
  28653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28654. type: string
  28655. type: object
  28656. userPass:
  28657. description: UserPass authenticates with Vault by passing username/password pair
  28658. properties:
  28659. path:
  28660. default: userpass
  28661. description: |-
  28662. Path where the UserPassword authentication backend is mounted
  28663. in Vault, e.g: "userpass"
  28664. type: string
  28665. secretRef:
  28666. description: |-
  28667. SecretRef to a key in a Secret resource containing password for the
  28668. user used to authenticate with Vault using the UserPass authentication
  28669. method
  28670. properties:
  28671. key:
  28672. description: |-
  28673. A key in the referenced Secret.
  28674. Some instances of this field may be defaulted, in others it may be required.
  28675. maxLength: 253
  28676. minLength: 1
  28677. pattern: ^[-._a-zA-Z0-9]+$
  28678. type: string
  28679. name:
  28680. description: The name of the Secret resource being referred to.
  28681. maxLength: 253
  28682. minLength: 1
  28683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28684. type: string
  28685. namespace:
  28686. description: |-
  28687. The namespace of the Secret resource being referred to.
  28688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28689. maxLength: 63
  28690. minLength: 1
  28691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28692. type: string
  28693. type: object
  28694. username:
  28695. description: |-
  28696. Username is a username used to authenticate using the UserPass Vault
  28697. authentication method
  28698. type: string
  28699. required:
  28700. - path
  28701. - username
  28702. type: object
  28703. type: object
  28704. caBundle:
  28705. description: |-
  28706. PEM encoded CA bundle used to validate Vault server certificate. Only used
  28707. if the Server URL is using HTTPS protocol. This parameter is ignored for
  28708. plain HTTP protocol connection. If not set the system root certificates
  28709. are used to validate the TLS connection.
  28710. format: byte
  28711. type: string
  28712. caProvider:
  28713. description: The provider for the CA bundle to use to validate Vault server certificate.
  28714. properties:
  28715. key:
  28716. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  28717. maxLength: 253
  28718. minLength: 1
  28719. pattern: ^[-._a-zA-Z0-9]+$
  28720. type: string
  28721. name:
  28722. description: The name of the object located at the provider type.
  28723. maxLength: 253
  28724. minLength: 1
  28725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28726. type: string
  28727. namespace:
  28728. description: |-
  28729. The namespace the Provider type is in.
  28730. Can only be defined when used in a ClusterSecretStore.
  28731. maxLength: 63
  28732. minLength: 1
  28733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28734. type: string
  28735. type:
  28736. description: The type of provider to use such as "Secret", or "ConfigMap".
  28737. enum:
  28738. - Secret
  28739. - ConfigMap
  28740. type: string
  28741. required:
  28742. - name
  28743. - type
  28744. type: object
  28745. checkAndSet:
  28746. description: |-
  28747. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  28748. Only applies to Vault KV v2 stores. When enabled, write operations must include
  28749. the current version of the secret to prevent unintentional overwrites.
  28750. properties:
  28751. required:
  28752. description: |-
  28753. Required when true, all write operations must include a check-and-set parameter.
  28754. This helps prevent unintentional overwrites of secrets.
  28755. type: boolean
  28756. type: object
  28757. forwardInconsistent:
  28758. description: |-
  28759. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  28760. leader instead of simply retrying within a loop. This can increase performance if
  28761. the option is enabled serverside.
  28762. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  28763. type: boolean
  28764. headers:
  28765. additionalProperties:
  28766. type: string
  28767. description: Headers to be added in Vault request
  28768. type: object
  28769. namespace:
  28770. description: |-
  28771. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  28772. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  28773. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  28774. type: string
  28775. path:
  28776. description: |-
  28777. Path is the mount path of the Vault KV backend endpoint, e.g:
  28778. "secret". The v2 KV secret engine version specific "/data" path suffix
  28779. for fetching secrets from Vault is optional and will be appended
  28780. if not present in specified path.
  28781. type: string
  28782. readYourWrites:
  28783. description: |-
  28784. ReadYourWrites ensures isolated read-after-write semantics by
  28785. providing discovered cluster replication states in each request.
  28786. More information about eventual consistency in Vault can be found here
  28787. https://www.vaultproject.io/docs/enterprise/consistency
  28788. type: boolean
  28789. server:
  28790. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  28791. type: string
  28792. tls:
  28793. description: |-
  28794. The configuration used for client side related TLS communication, when the Vault server
  28795. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  28796. This parameter is ignored for plain HTTP protocol connection.
  28797. It's worth noting this configuration is different from the "TLS certificates auth method",
  28798. which is available under the `auth.cert` section.
  28799. properties:
  28800. certSecretRef:
  28801. description: |-
  28802. CertSecretRef is a certificate added to the transport layer
  28803. when communicating with the Vault server.
  28804. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  28805. properties:
  28806. key:
  28807. description: |-
  28808. A key in the referenced Secret.
  28809. Some instances of this field may be defaulted, in others it may be required.
  28810. maxLength: 253
  28811. minLength: 1
  28812. pattern: ^[-._a-zA-Z0-9]+$
  28813. type: string
  28814. name:
  28815. description: The name of the Secret resource being referred to.
  28816. maxLength: 253
  28817. minLength: 1
  28818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28819. type: string
  28820. namespace:
  28821. description: |-
  28822. The namespace of the Secret resource being referred to.
  28823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28824. maxLength: 63
  28825. minLength: 1
  28826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28827. type: string
  28828. type: object
  28829. keySecretRef:
  28830. description: |-
  28831. KeySecretRef to a key in a Secret resource containing client private key
  28832. added to the transport layer when communicating with the Vault server.
  28833. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  28834. properties:
  28835. key:
  28836. description: |-
  28837. A key in the referenced Secret.
  28838. Some instances of this field may be defaulted, in others it may be required.
  28839. maxLength: 253
  28840. minLength: 1
  28841. pattern: ^[-._a-zA-Z0-9]+$
  28842. type: string
  28843. name:
  28844. description: The name of the Secret resource being referred to.
  28845. maxLength: 253
  28846. minLength: 1
  28847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28848. type: string
  28849. namespace:
  28850. description: |-
  28851. The namespace of the Secret resource being referred to.
  28852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28853. maxLength: 63
  28854. minLength: 1
  28855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28856. type: string
  28857. type: object
  28858. type: object
  28859. version:
  28860. default: v2
  28861. description: |-
  28862. Version is the Vault KV secret engine version. This can be either "v1" or
  28863. "v2". Version defaults to "v2".
  28864. enum:
  28865. - v1
  28866. - v2
  28867. type: string
  28868. required:
  28869. - server
  28870. type: object
  28871. resultType:
  28872. default: Data
  28873. description: |-
  28874. Result type defines which data is returned from the generator.
  28875. By default, it is the "data" section of the Vault API response.
  28876. When using e.g. /auth/token/create the "data" section is empty but
  28877. the "auth" section contains the generated token.
  28878. Please refer to the vault docs regarding the result data structure.
  28879. Additionally, accessing the raw response is possibly by using "Raw" result type.
  28880. enum:
  28881. - Data
  28882. - Auth
  28883. - Raw
  28884. type: string
  28885. retrySettings:
  28886. description: Used to configure http retries if failed
  28887. properties:
  28888. maxRetries:
  28889. format: int32
  28890. type: integer
  28891. retryInterval:
  28892. type: string
  28893. type: object
  28894. required:
  28895. - path
  28896. - provider
  28897. type: object
  28898. webhookSpec:
  28899. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  28900. properties:
  28901. auth:
  28902. description: Auth specifies a authorization protocol. Only one protocol may be set.
  28903. maxProperties: 1
  28904. minProperties: 1
  28905. properties:
  28906. ntlm:
  28907. description: NTLMProtocol configures the store to use NTLM for auth
  28908. properties:
  28909. passwordSecret:
  28910. description: |-
  28911. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28912. In some instances, `key` is a required field.
  28913. properties:
  28914. key:
  28915. description: |-
  28916. A key in the referenced Secret.
  28917. Some instances of this field may be defaulted, in others it may be required.
  28918. maxLength: 253
  28919. minLength: 1
  28920. pattern: ^[-._a-zA-Z0-9]+$
  28921. type: string
  28922. name:
  28923. description: The name of the Secret resource being referred to.
  28924. maxLength: 253
  28925. minLength: 1
  28926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28927. type: string
  28928. namespace:
  28929. description: |-
  28930. The namespace of the Secret resource being referred to.
  28931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28932. maxLength: 63
  28933. minLength: 1
  28934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28935. type: string
  28936. type: object
  28937. usernameSecret:
  28938. description: |-
  28939. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28940. In some instances, `key` is a required field.
  28941. properties:
  28942. key:
  28943. description: |-
  28944. A key in the referenced Secret.
  28945. Some instances of this field may be defaulted, in others it may be required.
  28946. maxLength: 253
  28947. minLength: 1
  28948. pattern: ^[-._a-zA-Z0-9]+$
  28949. type: string
  28950. name:
  28951. description: The name of the Secret resource being referred to.
  28952. maxLength: 253
  28953. minLength: 1
  28954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28955. type: string
  28956. namespace:
  28957. description: |-
  28958. The namespace of the Secret resource being referred to.
  28959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28960. maxLength: 63
  28961. minLength: 1
  28962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28963. type: string
  28964. type: object
  28965. required:
  28966. - passwordSecret
  28967. - usernameSecret
  28968. type: object
  28969. type: object
  28970. body:
  28971. description: Body
  28972. type: string
  28973. caBundle:
  28974. description: |-
  28975. PEM encoded CA bundle used to validate webhook server certificate. Only used
  28976. if the Server URL is using HTTPS protocol. This parameter is ignored for
  28977. plain HTTP protocol connection. If not set the system root certificates
  28978. are used to validate the TLS connection.
  28979. format: byte
  28980. type: string
  28981. caProvider:
  28982. description: The provider for the CA bundle to use to validate webhook server certificate.
  28983. properties:
  28984. key:
  28985. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  28986. maxLength: 253
  28987. minLength: 1
  28988. pattern: ^[-._a-zA-Z0-9]+$
  28989. type: string
  28990. name:
  28991. description: The name of the object located at the provider type.
  28992. maxLength: 253
  28993. minLength: 1
  28994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28995. type: string
  28996. namespace:
  28997. description: The namespace the Provider type is in.
  28998. maxLength: 63
  28999. minLength: 1
  29000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29001. type: string
  29002. type:
  29003. description: The type of provider to use such as "Secret", or "ConfigMap".
  29004. enum:
  29005. - Secret
  29006. - ConfigMap
  29007. type: string
  29008. required:
  29009. - name
  29010. - type
  29011. type: object
  29012. headers:
  29013. additionalProperties:
  29014. type: string
  29015. description: Headers
  29016. type: object
  29017. method:
  29018. description: Webhook Method
  29019. type: string
  29020. result:
  29021. description: Result formatting
  29022. properties:
  29023. jsonPath:
  29024. description: Json path of return value
  29025. type: string
  29026. type: object
  29027. secrets:
  29028. description: |-
  29029. Secrets to fill in templates
  29030. These secrets will be passed to the templating function as key value pairs under the given name
  29031. items:
  29032. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29033. properties:
  29034. name:
  29035. description: Name of this secret in templates
  29036. type: string
  29037. secretRef:
  29038. description: Secret ref to fill in credentials
  29039. properties:
  29040. key:
  29041. description: The key where the token is found.
  29042. maxLength: 253
  29043. minLength: 1
  29044. pattern: ^[-._a-zA-Z0-9]+$
  29045. type: string
  29046. name:
  29047. description: The name of the Secret resource being referred to.
  29048. maxLength: 253
  29049. minLength: 1
  29050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29051. type: string
  29052. type: object
  29053. required:
  29054. - name
  29055. - secretRef
  29056. type: object
  29057. type: array
  29058. timeout:
  29059. description: Timeout
  29060. type: string
  29061. url:
  29062. description: Webhook url to call
  29063. type: string
  29064. required:
  29065. - result
  29066. - url
  29067. type: object
  29068. type: object
  29069. kind:
  29070. description: Kind the kind of this generator.
  29071. enum:
  29072. - ACRAccessToken
  29073. - BeyondtrustWorkloadCredentialsDynamicSecret
  29074. - CloudsmithAccessToken
  29075. - ECRAuthorizationToken
  29076. - Fake
  29077. - GCRAccessToken
  29078. - GithubAccessToken
  29079. - GitlabDeployToken
  29080. - QuayAccessToken
  29081. - Password
  29082. - SSHKey
  29083. - STSSessionToken
  29084. - UUID
  29085. - VaultDynamicSecret
  29086. - Webhook
  29087. - Grafana
  29088. - MFA
  29089. type: string
  29090. required:
  29091. - generator
  29092. - kind
  29093. type: object
  29094. type: object
  29095. served: true
  29096. storage: true
  29097. subresources:
  29098. status: {}
  29099. ---
  29100. apiVersion: apiextensions.k8s.io/v1
  29101. kind: CustomResourceDefinition
  29102. metadata:
  29103. annotations:
  29104. controller-gen.kubebuilder.io/version: v0.19.0
  29105. labels:
  29106. external-secrets.io/component: controller
  29107. name: ecrauthorizationtokens.generators.external-secrets.io
  29108. spec:
  29109. group: generators.external-secrets.io
  29110. names:
  29111. categories:
  29112. - external-secrets
  29113. - external-secrets-generators
  29114. kind: ECRAuthorizationToken
  29115. listKind: ECRAuthorizationTokenList
  29116. plural: ecrauthorizationtokens
  29117. singular: ecrauthorizationtoken
  29118. scope: Namespaced
  29119. versions:
  29120. - name: v1alpha1
  29121. schema:
  29122. openAPIV3Schema:
  29123. description: |-
  29124. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29125. The authorization token is valid for 12 hours.
  29126. The authorizationToken returned is a base64 encoded string that can be decoded
  29127. and used in a docker login command to authenticate to a registry.
  29128. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29129. properties:
  29130. apiVersion:
  29131. description: |-
  29132. APIVersion defines the versioned schema of this representation of an object.
  29133. Servers should convert recognized schemas to the latest internal value, and
  29134. may reject unrecognized values.
  29135. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29136. type: string
  29137. kind:
  29138. description: |-
  29139. Kind is a string value representing the REST resource this object represents.
  29140. Servers may infer this from the endpoint the client submits requests to.
  29141. Cannot be updated.
  29142. In CamelCase.
  29143. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29144. type: string
  29145. metadata:
  29146. type: object
  29147. spec:
  29148. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29149. properties:
  29150. auth:
  29151. description: Auth defines how to authenticate with AWS
  29152. properties:
  29153. jwt:
  29154. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29155. properties:
  29156. serviceAccountRef:
  29157. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29158. properties:
  29159. audiences:
  29160. description: |-
  29161. Audience specifies the `aud` claim for the service account token
  29162. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29163. then this audiences will be appended to the list
  29164. items:
  29165. type: string
  29166. type: array
  29167. name:
  29168. description: The name of the ServiceAccount resource being referred to.
  29169. maxLength: 253
  29170. minLength: 1
  29171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29172. type: string
  29173. namespace:
  29174. description: |-
  29175. Namespace of the resource being referred to.
  29176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29177. maxLength: 63
  29178. minLength: 1
  29179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29180. type: string
  29181. required:
  29182. - name
  29183. type: object
  29184. type: object
  29185. secretRef:
  29186. description: |-
  29187. AWSAuthSecretRef holds secret references for AWS credentials
  29188. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29189. properties:
  29190. accessKeyIDSecretRef:
  29191. description: The AccessKeyID is used for authentication
  29192. properties:
  29193. key:
  29194. description: |-
  29195. A key in the referenced Secret.
  29196. Some instances of this field may be defaulted, in others it may be required.
  29197. maxLength: 253
  29198. minLength: 1
  29199. pattern: ^[-._a-zA-Z0-9]+$
  29200. type: string
  29201. name:
  29202. description: The name of the Secret resource being referred to.
  29203. maxLength: 253
  29204. minLength: 1
  29205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29206. type: string
  29207. namespace:
  29208. description: |-
  29209. The namespace of the Secret resource being referred to.
  29210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29211. maxLength: 63
  29212. minLength: 1
  29213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29214. type: string
  29215. type: object
  29216. secretAccessKeySecretRef:
  29217. description: The SecretAccessKey is used for authentication
  29218. properties:
  29219. key:
  29220. description: |-
  29221. A key in the referenced Secret.
  29222. Some instances of this field may be defaulted, in others it may be required.
  29223. maxLength: 253
  29224. minLength: 1
  29225. pattern: ^[-._a-zA-Z0-9]+$
  29226. type: string
  29227. name:
  29228. description: The name of the Secret resource being referred to.
  29229. maxLength: 253
  29230. minLength: 1
  29231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29232. type: string
  29233. namespace:
  29234. description: |-
  29235. The namespace of the Secret resource being referred to.
  29236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29237. maxLength: 63
  29238. minLength: 1
  29239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29240. type: string
  29241. type: object
  29242. sessionTokenSecretRef:
  29243. description: |-
  29244. The SessionToken used for authentication
  29245. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29246. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29247. properties:
  29248. key:
  29249. description: |-
  29250. A key in the referenced Secret.
  29251. Some instances of this field may be defaulted, in others it may be required.
  29252. maxLength: 253
  29253. minLength: 1
  29254. pattern: ^[-._a-zA-Z0-9]+$
  29255. type: string
  29256. name:
  29257. description: The name of the Secret resource being referred to.
  29258. maxLength: 253
  29259. minLength: 1
  29260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29261. type: string
  29262. namespace:
  29263. description: |-
  29264. The namespace of the Secret resource being referred to.
  29265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29266. maxLength: 63
  29267. minLength: 1
  29268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29269. type: string
  29270. type: object
  29271. type: object
  29272. type: object
  29273. region:
  29274. description: Region specifies the region to operate in.
  29275. type: string
  29276. role:
  29277. description: |-
  29278. You can assume a role before making calls to the
  29279. desired AWS service.
  29280. type: string
  29281. scope:
  29282. description: |-
  29283. Scope specifies the ECR service scope.
  29284. Valid options are private and public.
  29285. type: string
  29286. required:
  29287. - region
  29288. type: object
  29289. type: object
  29290. served: true
  29291. storage: true
  29292. subresources:
  29293. status: {}
  29294. ---
  29295. apiVersion: apiextensions.k8s.io/v1
  29296. kind: CustomResourceDefinition
  29297. metadata:
  29298. annotations:
  29299. controller-gen.kubebuilder.io/version: v0.19.0
  29300. labels:
  29301. external-secrets.io/component: controller
  29302. name: fakes.generators.external-secrets.io
  29303. spec:
  29304. group: generators.external-secrets.io
  29305. names:
  29306. categories:
  29307. - external-secrets
  29308. - external-secrets-generators
  29309. kind: Fake
  29310. listKind: FakeList
  29311. plural: fakes
  29312. singular: fake
  29313. scope: Namespaced
  29314. versions:
  29315. - name: v1alpha1
  29316. schema:
  29317. openAPIV3Schema:
  29318. description: |-
  29319. Fake generator is used for testing. It lets you define
  29320. a static set of credentials that is always returned.
  29321. properties:
  29322. apiVersion:
  29323. description: |-
  29324. APIVersion defines the versioned schema of this representation of an object.
  29325. Servers should convert recognized schemas to the latest internal value, and
  29326. may reject unrecognized values.
  29327. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29328. type: string
  29329. kind:
  29330. description: |-
  29331. Kind is a string value representing the REST resource this object represents.
  29332. Servers may infer this from the endpoint the client submits requests to.
  29333. Cannot be updated.
  29334. In CamelCase.
  29335. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29336. type: string
  29337. metadata:
  29338. type: object
  29339. spec:
  29340. description: FakeSpec contains the static data.
  29341. properties:
  29342. controller:
  29343. description: |-
  29344. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29345. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29346. type: string
  29347. data:
  29348. additionalProperties:
  29349. type: string
  29350. description: |-
  29351. Data defines the static data returned
  29352. by this generator.
  29353. type: object
  29354. type: object
  29355. type: object
  29356. served: true
  29357. storage: true
  29358. subresources:
  29359. status: {}
  29360. ---
  29361. apiVersion: apiextensions.k8s.io/v1
  29362. kind: CustomResourceDefinition
  29363. metadata:
  29364. annotations:
  29365. controller-gen.kubebuilder.io/version: v0.19.0
  29366. labels:
  29367. external-secrets.io/component: controller
  29368. name: gcraccesstokens.generators.external-secrets.io
  29369. spec:
  29370. group: generators.external-secrets.io
  29371. names:
  29372. categories:
  29373. - external-secrets
  29374. - external-secrets-generators
  29375. kind: GCRAccessToken
  29376. listKind: GCRAccessTokenList
  29377. plural: gcraccesstokens
  29378. singular: gcraccesstoken
  29379. scope: Namespaced
  29380. versions:
  29381. - name: v1alpha1
  29382. schema:
  29383. openAPIV3Schema:
  29384. description: |-
  29385. GCRAccessToken generates an GCP access token
  29386. that can be used to authenticate with GCR.
  29387. properties:
  29388. apiVersion:
  29389. description: |-
  29390. APIVersion defines the versioned schema of this representation of an object.
  29391. Servers should convert recognized schemas to the latest internal value, and
  29392. may reject unrecognized values.
  29393. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29394. type: string
  29395. kind:
  29396. description: |-
  29397. Kind is a string value representing the REST resource this object represents.
  29398. Servers may infer this from the endpoint the client submits requests to.
  29399. Cannot be updated.
  29400. In CamelCase.
  29401. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29402. type: string
  29403. metadata:
  29404. type: object
  29405. spec:
  29406. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  29407. properties:
  29408. auth:
  29409. description: Auth defines the means for authenticating with GCP
  29410. properties:
  29411. secretRef:
  29412. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  29413. properties:
  29414. secretAccessKeySecretRef:
  29415. description: The SecretAccessKey is used for authentication
  29416. properties:
  29417. key:
  29418. description: |-
  29419. A key in the referenced Secret.
  29420. Some instances of this field may be defaulted, in others it may be required.
  29421. maxLength: 253
  29422. minLength: 1
  29423. pattern: ^[-._a-zA-Z0-9]+$
  29424. type: string
  29425. name:
  29426. description: The name of the Secret resource being referred to.
  29427. maxLength: 253
  29428. minLength: 1
  29429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29430. type: string
  29431. namespace:
  29432. description: |-
  29433. The namespace of the Secret resource being referred to.
  29434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29435. maxLength: 63
  29436. minLength: 1
  29437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29438. type: string
  29439. type: object
  29440. type: object
  29441. workloadIdentity:
  29442. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  29443. properties:
  29444. clusterLocation:
  29445. type: string
  29446. clusterName:
  29447. type: string
  29448. clusterProjectID:
  29449. type: string
  29450. serviceAccountRef:
  29451. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29452. properties:
  29453. audiences:
  29454. description: |-
  29455. Audience specifies the `aud` claim for the service account token
  29456. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29457. then this audiences will be appended to the list
  29458. items:
  29459. type: string
  29460. type: array
  29461. name:
  29462. description: The name of the ServiceAccount resource being referred to.
  29463. maxLength: 253
  29464. minLength: 1
  29465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29466. type: string
  29467. namespace:
  29468. description: |-
  29469. Namespace of the resource being referred to.
  29470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29471. maxLength: 63
  29472. minLength: 1
  29473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29474. type: string
  29475. required:
  29476. - name
  29477. type: object
  29478. required:
  29479. - clusterLocation
  29480. - clusterName
  29481. - serviceAccountRef
  29482. type: object
  29483. workloadIdentityFederation:
  29484. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  29485. properties:
  29486. audience:
  29487. description: |-
  29488. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  29489. If specified, Audience found in the external account credential config will be overridden with the configured value.
  29490. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  29491. type: string
  29492. awsSecurityCredentials:
  29493. description: |-
  29494. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  29495. when using the AWS metadata server is not an option.
  29496. properties:
  29497. awsCredentialsSecretRef:
  29498. description: |-
  29499. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  29500. Secret should be created with below names for keys
  29501. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  29502. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  29503. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  29504. properties:
  29505. name:
  29506. description: name of the secret.
  29507. maxLength: 253
  29508. minLength: 1
  29509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29510. type: string
  29511. namespace:
  29512. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  29513. maxLength: 63
  29514. minLength: 1
  29515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29516. type: string
  29517. required:
  29518. - name
  29519. type: object
  29520. region:
  29521. description: region is for configuring the AWS region to be used.
  29522. example: ap-south-1
  29523. maxLength: 50
  29524. minLength: 1
  29525. pattern: ^[a-z0-9-]+$
  29526. type: string
  29527. required:
  29528. - awsCredentialsSecretRef
  29529. - region
  29530. type: object
  29531. credConfig:
  29532. description: |-
  29533. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  29534. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  29535. serviceAccountRef must be used by providing operators service account details.
  29536. properties:
  29537. key:
  29538. description: key name holding the external account credential config.
  29539. maxLength: 253
  29540. minLength: 1
  29541. pattern: ^[-._a-zA-Z0-9]+$
  29542. type: string
  29543. name:
  29544. description: name of the configmap.
  29545. maxLength: 253
  29546. minLength: 1
  29547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29548. type: string
  29549. namespace:
  29550. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  29551. maxLength: 63
  29552. minLength: 1
  29553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29554. type: string
  29555. required:
  29556. - key
  29557. - name
  29558. type: object
  29559. externalTokenEndpoint:
  29560. description: |-
  29561. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  29562. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  29563. URL is having the expected value.
  29564. type: string
  29565. gcpServiceAccountEmail:
  29566. description: |-
  29567. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  29568. after Workload Identity Federation. Use this to grant access through the service account's
  29569. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  29570. service_account_impersonation_url in the external account JSON from credConfig;
  29571. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  29572. on that ServiceAccount.
  29573. example: my-gsa@my-project.iam.gserviceaccount.com
  29574. minLength: 1
  29575. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  29576. type: string
  29577. serviceAccountRef:
  29578. description: |-
  29579. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  29580. when Kubernetes is configured as provider in workload identity pool.
  29581. properties:
  29582. audiences:
  29583. description: |-
  29584. Audience specifies the `aud` claim for the service account token
  29585. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29586. then this audiences will be appended to the list
  29587. items:
  29588. type: string
  29589. type: array
  29590. name:
  29591. description: The name of the ServiceAccount resource being referred to.
  29592. maxLength: 253
  29593. minLength: 1
  29594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29595. type: string
  29596. namespace:
  29597. description: |-
  29598. Namespace of the resource being referred to.
  29599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29600. maxLength: 63
  29601. minLength: 1
  29602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29603. type: string
  29604. required:
  29605. - name
  29606. type: object
  29607. type: object
  29608. type: object
  29609. projectID:
  29610. description: ProjectID defines which project to use to authenticate with
  29611. type: string
  29612. required:
  29613. - auth
  29614. - projectID
  29615. type: object
  29616. type: object
  29617. served: true
  29618. storage: true
  29619. subresources:
  29620. status: {}
  29621. ---
  29622. apiVersion: apiextensions.k8s.io/v1
  29623. kind: CustomResourceDefinition
  29624. metadata:
  29625. annotations:
  29626. controller-gen.kubebuilder.io/version: v0.19.0
  29627. labels:
  29628. external-secrets.io/component: controller
  29629. name: generatorstates.generators.external-secrets.io
  29630. spec:
  29631. group: generators.external-secrets.io
  29632. names:
  29633. categories:
  29634. - external-secrets
  29635. - external-secrets-generators
  29636. kind: GeneratorState
  29637. listKind: GeneratorStateList
  29638. plural: generatorstates
  29639. shortNames:
  29640. - gs
  29641. singular: generatorstate
  29642. scope: Namespaced
  29643. versions:
  29644. - additionalPrinterColumns:
  29645. - jsonPath: .spec.garbageCollectionDeadline
  29646. name: GC Deadline
  29647. type: string
  29648. - jsonPath: .metadata.creationTimestamp
  29649. name: Age
  29650. type: date
  29651. name: v1alpha1
  29652. schema:
  29653. openAPIV3Schema:
  29654. description: GeneratorState represents the state created and managed by a generator resource.
  29655. properties:
  29656. apiVersion:
  29657. description: |-
  29658. APIVersion defines the versioned schema of this representation of an object.
  29659. Servers should convert recognized schemas to the latest internal value, and
  29660. may reject unrecognized values.
  29661. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29662. type: string
  29663. kind:
  29664. description: |-
  29665. Kind is a string value representing the REST resource this object represents.
  29666. Servers may infer this from the endpoint the client submits requests to.
  29667. Cannot be updated.
  29668. In CamelCase.
  29669. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29670. type: string
  29671. metadata:
  29672. type: object
  29673. spec:
  29674. description: GeneratorStateSpec defines the desired state of a generator state resource.
  29675. properties:
  29676. garbageCollectionDeadline:
  29677. description: |-
  29678. GarbageCollectionDeadline is the time after which the generator state
  29679. will be deleted.
  29680. It is set by the controller which creates the generator state and
  29681. can be set configured by the user.
  29682. If the garbage collection deadline is not set the generator state will not be deleted.
  29683. format: date-time
  29684. type: string
  29685. resource:
  29686. description: |-
  29687. Resource is the generator manifest that produced the state.
  29688. It is a snapshot of the generator manifest at the time the state was produced.
  29689. This manifest will be used to delete the resource. Any configuration that is referenced
  29690. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  29691. be blocked by a finalizer.
  29692. x-kubernetes-preserve-unknown-fields: true
  29693. state:
  29694. description: State is the state that was produced by the generator implementation.
  29695. x-kubernetes-preserve-unknown-fields: true
  29696. required:
  29697. - resource
  29698. - state
  29699. type: object
  29700. status:
  29701. description: GeneratorStateStatus defines the observed state of a generator state resource.
  29702. properties:
  29703. conditions:
  29704. items:
  29705. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  29706. properties:
  29707. lastTransitionTime:
  29708. format: date-time
  29709. type: string
  29710. message:
  29711. type: string
  29712. reason:
  29713. type: string
  29714. status:
  29715. type: string
  29716. type:
  29717. description: GeneratorStateConditionType represents the type of condition for a generator state.
  29718. type: string
  29719. required:
  29720. - status
  29721. - type
  29722. type: object
  29723. type: array
  29724. type: object
  29725. type: object
  29726. served: true
  29727. storage: true
  29728. subresources: {}
  29729. ---
  29730. apiVersion: apiextensions.k8s.io/v1
  29731. kind: CustomResourceDefinition
  29732. metadata:
  29733. annotations:
  29734. controller-gen.kubebuilder.io/version: v0.19.0
  29735. labels:
  29736. external-secrets.io/component: controller
  29737. name: githubaccesstokens.generators.external-secrets.io
  29738. spec:
  29739. group: generators.external-secrets.io
  29740. names:
  29741. categories:
  29742. - external-secrets
  29743. - external-secrets-generators
  29744. kind: GithubAccessToken
  29745. listKind: GithubAccessTokenList
  29746. plural: githubaccesstokens
  29747. singular: githubaccesstoken
  29748. scope: Namespaced
  29749. versions:
  29750. - name: v1alpha1
  29751. schema:
  29752. openAPIV3Schema:
  29753. description: GithubAccessToken generates ghs_ accessToken
  29754. properties:
  29755. apiVersion:
  29756. description: |-
  29757. APIVersion defines the versioned schema of this representation of an object.
  29758. Servers should convert recognized schemas to the latest internal value, and
  29759. may reject unrecognized values.
  29760. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29761. type: string
  29762. kind:
  29763. description: |-
  29764. Kind is a string value representing the REST resource this object represents.
  29765. Servers may infer this from the endpoint the client submits requests to.
  29766. Cannot be updated.
  29767. In CamelCase.
  29768. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29769. type: string
  29770. metadata:
  29771. type: object
  29772. spec:
  29773. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  29774. properties:
  29775. appID:
  29776. type: string
  29777. auth:
  29778. description: Auth configures how ESO authenticates with a Github instance.
  29779. properties:
  29780. privateKey:
  29781. description: GithubSecretRef references a secret containing GitHub credentials.
  29782. properties:
  29783. secretRef:
  29784. description: |-
  29785. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29786. In some instances, `key` is a required field.
  29787. properties:
  29788. key:
  29789. description: |-
  29790. A key in the referenced Secret.
  29791. Some instances of this field may be defaulted, in others it may be required.
  29792. maxLength: 253
  29793. minLength: 1
  29794. pattern: ^[-._a-zA-Z0-9]+$
  29795. type: string
  29796. name:
  29797. description: The name of the Secret resource being referred to.
  29798. maxLength: 253
  29799. minLength: 1
  29800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29801. type: string
  29802. namespace:
  29803. description: |-
  29804. The namespace of the Secret resource being referred to.
  29805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29806. maxLength: 63
  29807. minLength: 1
  29808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29809. type: string
  29810. type: object
  29811. required:
  29812. - secretRef
  29813. type: object
  29814. required:
  29815. - privateKey
  29816. type: object
  29817. installID:
  29818. type: string
  29819. permissions:
  29820. additionalProperties:
  29821. type: string
  29822. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  29823. type: object
  29824. repositories:
  29825. description: |-
  29826. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  29827. is installed to.
  29828. items:
  29829. type: string
  29830. type: array
  29831. url:
  29832. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  29833. type: string
  29834. required:
  29835. - appID
  29836. - auth
  29837. - installID
  29838. type: object
  29839. type: object
  29840. served: true
  29841. storage: true
  29842. subresources:
  29843. status: {}
  29844. ---
  29845. apiVersion: apiextensions.k8s.io/v1
  29846. kind: CustomResourceDefinition
  29847. metadata:
  29848. annotations:
  29849. controller-gen.kubebuilder.io/version: v0.19.0
  29850. labels:
  29851. external-secrets.io/component: controller
  29852. name: gitlabdeploytokens.generators.external-secrets.io
  29853. spec:
  29854. group: generators.external-secrets.io
  29855. names:
  29856. categories:
  29857. - external-secrets
  29858. - external-secrets-generators
  29859. kind: GitlabDeployToken
  29860. listKind: GitlabDeployTokenList
  29861. plural: gitlabdeploytokens
  29862. singular: gitlabdeploytoken
  29863. scope: Namespaced
  29864. versions:
  29865. - name: v1alpha1
  29866. schema:
  29867. openAPIV3Schema:
  29868. description: GitlabDeployToken generates a GitLab deploy token.
  29869. properties:
  29870. apiVersion:
  29871. description: |-
  29872. APIVersion defines the versioned schema of this representation of an object.
  29873. Servers should convert recognized schemas to the latest internal value, and
  29874. may reject unrecognized values.
  29875. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29876. type: string
  29877. kind:
  29878. description: |-
  29879. Kind is a string value representing the REST resource this object represents.
  29880. Servers may infer this from the endpoint the client submits requests to.
  29881. Cannot be updated.
  29882. In CamelCase.
  29883. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29884. type: string
  29885. metadata:
  29886. type: object
  29887. spec:
  29888. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  29889. properties:
  29890. auth:
  29891. description: Auth configures how ESO authenticates with the GitLab API.
  29892. properties:
  29893. token:
  29894. description: |-
  29895. Token references a secret containing a GitLab access token (personal, group, or
  29896. project) with the api scope and at least the Maintainer role on the target.
  29897. properties:
  29898. secretRef:
  29899. description: |-
  29900. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29901. In some instances, `key` is a required field.
  29902. properties:
  29903. key:
  29904. description: |-
  29905. A key in the referenced Secret.
  29906. Some instances of this field may be defaulted, in others it may be required.
  29907. maxLength: 253
  29908. minLength: 1
  29909. pattern: ^[-._a-zA-Z0-9]+$
  29910. type: string
  29911. name:
  29912. description: The name of the Secret resource being referred to.
  29913. maxLength: 253
  29914. minLength: 1
  29915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29916. type: string
  29917. namespace:
  29918. description: |-
  29919. The namespace of the Secret resource being referred to.
  29920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29921. maxLength: 63
  29922. minLength: 1
  29923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29924. type: string
  29925. type: object
  29926. required:
  29927. - secretRef
  29928. type: object
  29929. required:
  29930. - token
  29931. type: object
  29932. expiresAt:
  29933. description: |-
  29934. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  29935. not expire on the GitLab side and is revoked only when the generator state is
  29936. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  29937. format: date-time
  29938. type: string
  29939. groupID:
  29940. description: |-
  29941. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  29942. create the deploy token in. The generator URL-escapes paths before calling the
  29943. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  29944. minLength: 1
  29945. type: string
  29946. name:
  29947. description: Name of the deploy token.
  29948. minLength: 1
  29949. type: string
  29950. projectID:
  29951. description: |-
  29952. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  29953. project to create the deploy token in. The generator URL-escapes paths before
  29954. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  29955. minLength: 1
  29956. type: string
  29957. scopes:
  29958. description: Scopes granted to the deploy token. At least one scope is required.
  29959. items:
  29960. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  29961. enum:
  29962. - read_repository
  29963. - read_registry
  29964. - write_registry
  29965. - read_package_registry
  29966. - write_package_registry
  29967. - read_virtual_registry
  29968. - write_virtual_registry
  29969. type: string
  29970. minItems: 1
  29971. type: array
  29972. url:
  29973. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  29974. type: string
  29975. username:
  29976. description: |-
  29977. Username is an optional username for the deploy token. GitLab defaults it to
  29978. gitlab+deploy-token-{n} when omitted.
  29979. type: string
  29980. required:
  29981. - auth
  29982. - name
  29983. - scopes
  29984. type: object
  29985. x-kubernetes-validations:
  29986. - message: exactly one of projectID or groupID must be set
  29987. rule: has(self.projectID) != has(self.groupID)
  29988. type: object
  29989. served: true
  29990. storage: true
  29991. subresources:
  29992. status: {}
  29993. ---
  29994. apiVersion: apiextensions.k8s.io/v1
  29995. kind: CustomResourceDefinition
  29996. metadata:
  29997. annotations:
  29998. controller-gen.kubebuilder.io/version: v0.19.0
  29999. labels:
  30000. external-secrets.io/component: controller
  30001. name: grafanas.generators.external-secrets.io
  30002. spec:
  30003. group: generators.external-secrets.io
  30004. names:
  30005. categories:
  30006. - external-secrets
  30007. - external-secrets-generators
  30008. kind: Grafana
  30009. listKind: GrafanaList
  30010. plural: grafanas
  30011. singular: grafana
  30012. scope: Namespaced
  30013. versions:
  30014. - name: v1alpha1
  30015. schema:
  30016. openAPIV3Schema:
  30017. description: Grafana represents a generator for Grafana service account tokens.
  30018. properties:
  30019. apiVersion:
  30020. description: |-
  30021. APIVersion defines the versioned schema of this representation of an object.
  30022. Servers should convert recognized schemas to the latest internal value, and
  30023. may reject unrecognized values.
  30024. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30025. type: string
  30026. kind:
  30027. description: |-
  30028. Kind is a string value representing the REST resource this object represents.
  30029. Servers may infer this from the endpoint the client submits requests to.
  30030. Cannot be updated.
  30031. In CamelCase.
  30032. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30033. type: string
  30034. metadata:
  30035. type: object
  30036. spec:
  30037. description: GrafanaSpec controls the behavior of the grafana generator.
  30038. properties:
  30039. auth:
  30040. description: |-
  30041. Auth is the authentication configuration to authenticate
  30042. against the Grafana instance.
  30043. properties:
  30044. basic:
  30045. description: |-
  30046. Basic auth credentials used to authenticate against the Grafana instance.
  30047. Note: you need a token which has elevated permissions to create service accounts.
  30048. See here for the documentation on basic roles offered by Grafana:
  30049. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30050. properties:
  30051. password:
  30052. description: A basic auth password used to authenticate against the Grafana instance.
  30053. properties:
  30054. key:
  30055. description: The key where the token is found.
  30056. maxLength: 253
  30057. minLength: 1
  30058. pattern: ^[-._a-zA-Z0-9]+$
  30059. type: string
  30060. name:
  30061. description: The name of the Secret resource being referred to.
  30062. maxLength: 253
  30063. minLength: 1
  30064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30065. type: string
  30066. type: object
  30067. username:
  30068. description: A basic auth username used to authenticate against the Grafana instance.
  30069. type: string
  30070. required:
  30071. - password
  30072. - username
  30073. type: object
  30074. token:
  30075. description: |-
  30076. A service account token used to authenticate against the Grafana instance.
  30077. Note: you need a token which has elevated permissions to create service accounts.
  30078. See here for the documentation on basic roles offered by Grafana:
  30079. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30080. properties:
  30081. key:
  30082. description: The key where the token is found.
  30083. maxLength: 253
  30084. minLength: 1
  30085. pattern: ^[-._a-zA-Z0-9]+$
  30086. type: string
  30087. name:
  30088. description: The name of the Secret resource being referred to.
  30089. maxLength: 253
  30090. minLength: 1
  30091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30092. type: string
  30093. type: object
  30094. type: object
  30095. serviceAccount:
  30096. description: |-
  30097. ServiceAccount is the configuration for the service account that
  30098. is supposed to be generated by the generator.
  30099. properties:
  30100. name:
  30101. description: Name is the name of the service account that will be created by ESO.
  30102. type: string
  30103. role:
  30104. description: |-
  30105. Role is the role of the service account.
  30106. See here for the documentation on basic roles offered by Grafana:
  30107. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30108. type: string
  30109. secondsToLive:
  30110. description: |-
  30111. SecondsToLive is the number of seconds before the generated service account token will expire.
  30112. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30113. format: int64
  30114. minimum: 1
  30115. type: integer
  30116. required:
  30117. - name
  30118. - role
  30119. type: object
  30120. url:
  30121. description: URL is the URL of the Grafana instance.
  30122. type: string
  30123. required:
  30124. - auth
  30125. - serviceAccount
  30126. - url
  30127. type: object
  30128. type: object
  30129. served: true
  30130. storage: true
  30131. subresources:
  30132. status: {}
  30133. ---
  30134. apiVersion: apiextensions.k8s.io/v1
  30135. kind: CustomResourceDefinition
  30136. metadata:
  30137. annotations:
  30138. controller-gen.kubebuilder.io/version: v0.19.0
  30139. labels:
  30140. external-secrets.io/component: controller
  30141. name: mfas.generators.external-secrets.io
  30142. spec:
  30143. group: generators.external-secrets.io
  30144. names:
  30145. categories:
  30146. - external-secrets
  30147. - external-secrets-generators
  30148. kind: MFA
  30149. listKind: MFAList
  30150. plural: mfas
  30151. singular: mfa
  30152. scope: Namespaced
  30153. versions:
  30154. - name: v1alpha1
  30155. schema:
  30156. openAPIV3Schema:
  30157. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30158. properties:
  30159. apiVersion:
  30160. description: |-
  30161. APIVersion defines the versioned schema of this representation of an object.
  30162. Servers should convert recognized schemas to the latest internal value, and
  30163. may reject unrecognized values.
  30164. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30165. type: string
  30166. kind:
  30167. description: |-
  30168. Kind is a string value representing the REST resource this object represents.
  30169. Servers may infer this from the endpoint the client submits requests to.
  30170. Cannot be updated.
  30171. In CamelCase.
  30172. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30173. type: string
  30174. metadata:
  30175. type: object
  30176. spec:
  30177. description: MFASpec controls the behavior of the mfa generator.
  30178. properties:
  30179. algorithm:
  30180. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30181. type: string
  30182. length:
  30183. description: Length defines the token length. Defaults to 6 characters.
  30184. type: integer
  30185. secret:
  30186. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30187. properties:
  30188. key:
  30189. description: |-
  30190. A key in the referenced Secret.
  30191. Some instances of this field may be defaulted, in others it may be required.
  30192. maxLength: 253
  30193. minLength: 1
  30194. pattern: ^[-._a-zA-Z0-9]+$
  30195. type: string
  30196. name:
  30197. description: The name of the Secret resource being referred to.
  30198. maxLength: 253
  30199. minLength: 1
  30200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30201. type: string
  30202. namespace:
  30203. description: |-
  30204. The namespace of the Secret resource being referred to.
  30205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30206. maxLength: 63
  30207. minLength: 1
  30208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30209. type: string
  30210. type: object
  30211. timePeriod:
  30212. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30213. type: integer
  30214. when:
  30215. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30216. format: date-time
  30217. type: string
  30218. required:
  30219. - secret
  30220. type: object
  30221. type: object
  30222. served: true
  30223. storage: true
  30224. subresources:
  30225. status: {}
  30226. ---
  30227. apiVersion: apiextensions.k8s.io/v1
  30228. kind: CustomResourceDefinition
  30229. metadata:
  30230. annotations:
  30231. controller-gen.kubebuilder.io/version: v0.19.0
  30232. labels:
  30233. external-secrets.io/component: controller
  30234. name: passwords.generators.external-secrets.io
  30235. spec:
  30236. group: generators.external-secrets.io
  30237. names:
  30238. categories:
  30239. - external-secrets
  30240. - external-secrets-generators
  30241. kind: Password
  30242. listKind: PasswordList
  30243. plural: passwords
  30244. singular: password
  30245. scope: Namespaced
  30246. versions:
  30247. - name: v1alpha1
  30248. schema:
  30249. openAPIV3Schema:
  30250. description: |-
  30251. Password generates a random password based on the
  30252. configuration parameters in spec.
  30253. You can specify the length, characterset and other attributes.
  30254. properties:
  30255. apiVersion:
  30256. description: |-
  30257. APIVersion defines the versioned schema of this representation of an object.
  30258. Servers should convert recognized schemas to the latest internal value, and
  30259. may reject unrecognized values.
  30260. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30261. type: string
  30262. kind:
  30263. description: |-
  30264. Kind is a string value representing the REST resource this object represents.
  30265. Servers may infer this from the endpoint the client submits requests to.
  30266. Cannot be updated.
  30267. In CamelCase.
  30268. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30269. type: string
  30270. metadata:
  30271. type: object
  30272. spec:
  30273. description: PasswordSpec controls the behavior of the password generator.
  30274. properties:
  30275. allowRepeat:
  30276. default: false
  30277. description: set AllowRepeat to true to allow repeating characters.
  30278. type: boolean
  30279. digits:
  30280. description: |-
  30281. Digits specifies the number of digits in the generated
  30282. password. If omitted it defaults to 25% of the length of the password
  30283. type: integer
  30284. encoding:
  30285. default: raw
  30286. description: |-
  30287. Encoding specifies the encoding of the generated password.
  30288. Valid values are:
  30289. - "raw" (default): no encoding
  30290. - "base64": standard base64 encoding
  30291. - "base64url": base64url encoding
  30292. - "base32": base32 encoding
  30293. - "hex": hexadecimal encoding
  30294. enum:
  30295. - base64
  30296. - base64url
  30297. - base32
  30298. - hex
  30299. - raw
  30300. type: string
  30301. length:
  30302. default: 24
  30303. description: |-
  30304. Length of the password to be generated.
  30305. Defaults to 24
  30306. type: integer
  30307. noUpper:
  30308. default: false
  30309. description: Set NoUpper to disable uppercase characters
  30310. type: boolean
  30311. secretKeys:
  30312. description: |-
  30313. SecretKeys defines the keys that will be populated with generated passwords.
  30314. Defaults to "password" when not set.
  30315. items:
  30316. type: string
  30317. minItems: 1
  30318. type: array
  30319. symbolCharacters:
  30320. description: |-
  30321. SymbolCharacters specifies the special characters that should be used
  30322. in the generated password.
  30323. type: string
  30324. symbols:
  30325. description: |-
  30326. Symbols specifies the number of symbol characters in the generated
  30327. password. If omitted it defaults to 25% of the length of the password
  30328. type: integer
  30329. required:
  30330. - allowRepeat
  30331. - length
  30332. - noUpper
  30333. type: object
  30334. type: object
  30335. served: true
  30336. storage: true
  30337. subresources:
  30338. status: {}
  30339. ---
  30340. apiVersion: apiextensions.k8s.io/v1
  30341. kind: CustomResourceDefinition
  30342. metadata:
  30343. annotations:
  30344. controller-gen.kubebuilder.io/version: v0.19.0
  30345. labels:
  30346. external-secrets.io/component: controller
  30347. name: quayaccesstokens.generators.external-secrets.io
  30348. spec:
  30349. group: generators.external-secrets.io
  30350. names:
  30351. categories:
  30352. - external-secrets
  30353. - external-secrets-generators
  30354. kind: QuayAccessToken
  30355. listKind: QuayAccessTokenList
  30356. plural: quayaccesstokens
  30357. singular: quayaccesstoken
  30358. scope: Namespaced
  30359. versions:
  30360. - name: v1alpha1
  30361. schema:
  30362. openAPIV3Schema:
  30363. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30364. properties:
  30365. apiVersion:
  30366. description: |-
  30367. APIVersion defines the versioned schema of this representation of an object.
  30368. Servers should convert recognized schemas to the latest internal value, and
  30369. may reject unrecognized values.
  30370. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30371. type: string
  30372. kind:
  30373. description: |-
  30374. Kind is a string value representing the REST resource this object represents.
  30375. Servers may infer this from the endpoint the client submits requests to.
  30376. Cannot be updated.
  30377. In CamelCase.
  30378. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30379. type: string
  30380. metadata:
  30381. type: object
  30382. spec:
  30383. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30384. properties:
  30385. robotAccount:
  30386. description: Name of the robot account you are federating with
  30387. type: string
  30388. serviceAccountRef:
  30389. description: Name of the service account you are federating with
  30390. properties:
  30391. audiences:
  30392. description: |-
  30393. Audience specifies the `aud` claim for the service account token
  30394. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30395. then this audiences will be appended to the list
  30396. items:
  30397. type: string
  30398. type: array
  30399. name:
  30400. description: The name of the ServiceAccount resource being referred to.
  30401. maxLength: 253
  30402. minLength: 1
  30403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30404. type: string
  30405. namespace:
  30406. description: |-
  30407. Namespace of the resource being referred to.
  30408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30409. maxLength: 63
  30410. minLength: 1
  30411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30412. type: string
  30413. required:
  30414. - name
  30415. type: object
  30416. url:
  30417. description: URL configures the Quay instance URL. Defaults to quay.io.
  30418. type: string
  30419. required:
  30420. - robotAccount
  30421. - serviceAccountRef
  30422. type: object
  30423. type: object
  30424. served: true
  30425. storage: true
  30426. subresources:
  30427. status: {}
  30428. ---
  30429. apiVersion: apiextensions.k8s.io/v1
  30430. kind: CustomResourceDefinition
  30431. metadata:
  30432. annotations:
  30433. controller-gen.kubebuilder.io/version: v0.19.0
  30434. labels:
  30435. external-secrets.io/component: controller
  30436. name: sshkeys.generators.external-secrets.io
  30437. spec:
  30438. group: generators.external-secrets.io
  30439. names:
  30440. categories:
  30441. - external-secrets
  30442. - external-secrets-generators
  30443. kind: SSHKey
  30444. listKind: SSHKeyList
  30445. plural: sshkeys
  30446. singular: sshkey
  30447. scope: Namespaced
  30448. versions:
  30449. - name: v1alpha1
  30450. schema:
  30451. openAPIV3Schema:
  30452. description: SSHKey generates SSH key pairs.
  30453. properties:
  30454. apiVersion:
  30455. description: |-
  30456. APIVersion defines the versioned schema of this representation of an object.
  30457. Servers should convert recognized schemas to the latest internal value, and
  30458. may reject unrecognized values.
  30459. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30460. type: string
  30461. kind:
  30462. description: |-
  30463. Kind is a string value representing the REST resource this object represents.
  30464. Servers may infer this from the endpoint the client submits requests to.
  30465. Cannot be updated.
  30466. In CamelCase.
  30467. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30468. type: string
  30469. metadata:
  30470. type: object
  30471. spec:
  30472. description: SSHKeySpec controls the behavior of the ssh key generator.
  30473. properties:
  30474. comment:
  30475. description: Comment specifies an optional comment for the SSH key
  30476. type: string
  30477. keySize:
  30478. description: |-
  30479. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  30480. For RSA keys: 2048, 3072, 4096
  30481. For ECDSA keys: 256, 384, 521
  30482. Ignored for ed25519 keys
  30483. maximum: 8192
  30484. minimum: 256
  30485. type: integer
  30486. keyType:
  30487. default: rsa
  30488. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  30489. enum:
  30490. - rsa
  30491. - ecdsa
  30492. - ed25519
  30493. type: string
  30494. type: object
  30495. type: object
  30496. served: true
  30497. storage: true
  30498. subresources:
  30499. status: {}
  30500. ---
  30501. apiVersion: apiextensions.k8s.io/v1
  30502. kind: CustomResourceDefinition
  30503. metadata:
  30504. annotations:
  30505. controller-gen.kubebuilder.io/version: v0.19.0
  30506. labels:
  30507. external-secrets.io/component: controller
  30508. name: stssessiontokens.generators.external-secrets.io
  30509. spec:
  30510. group: generators.external-secrets.io
  30511. names:
  30512. categories:
  30513. - external-secrets
  30514. - external-secrets-generators
  30515. kind: STSSessionToken
  30516. listKind: STSSessionTokenList
  30517. plural: stssessiontokens
  30518. singular: stssessiontoken
  30519. scope: Namespaced
  30520. versions:
  30521. - name: v1alpha1
  30522. schema:
  30523. openAPIV3Schema:
  30524. description: |-
  30525. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  30526. The authorization token is valid for 12 hours.
  30527. The authorizationToken returned is a base64 encoded string that can be decoded.
  30528. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  30529. properties:
  30530. apiVersion:
  30531. description: |-
  30532. APIVersion defines the versioned schema of this representation of an object.
  30533. Servers should convert recognized schemas to the latest internal value, and
  30534. may reject unrecognized values.
  30535. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30536. type: string
  30537. kind:
  30538. description: |-
  30539. Kind is a string value representing the REST resource this object represents.
  30540. Servers may infer this from the endpoint the client submits requests to.
  30541. Cannot be updated.
  30542. In CamelCase.
  30543. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30544. type: string
  30545. metadata:
  30546. type: object
  30547. spec:
  30548. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  30549. properties:
  30550. auth:
  30551. description: Auth defines how to authenticate with AWS
  30552. properties:
  30553. jwt:
  30554. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30555. properties:
  30556. serviceAccountRef:
  30557. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30558. properties:
  30559. audiences:
  30560. description: |-
  30561. Audience specifies the `aud` claim for the service account token
  30562. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30563. then this audiences will be appended to the list
  30564. items:
  30565. type: string
  30566. type: array
  30567. name:
  30568. description: The name of the ServiceAccount resource being referred to.
  30569. maxLength: 253
  30570. minLength: 1
  30571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30572. type: string
  30573. namespace:
  30574. description: |-
  30575. Namespace of the resource being referred to.
  30576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30577. maxLength: 63
  30578. minLength: 1
  30579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30580. type: string
  30581. required:
  30582. - name
  30583. type: object
  30584. type: object
  30585. secretRef:
  30586. description: |-
  30587. AWSAuthSecretRef holds secret references for AWS credentials
  30588. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30589. properties:
  30590. accessKeyIDSecretRef:
  30591. description: The AccessKeyID is used for authentication
  30592. properties:
  30593. key:
  30594. description: |-
  30595. A key in the referenced Secret.
  30596. Some instances of this field may be defaulted, in others it may be required.
  30597. maxLength: 253
  30598. minLength: 1
  30599. pattern: ^[-._a-zA-Z0-9]+$
  30600. type: string
  30601. name:
  30602. description: The name of the Secret resource being referred to.
  30603. maxLength: 253
  30604. minLength: 1
  30605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30606. type: string
  30607. namespace:
  30608. description: |-
  30609. The namespace of the Secret resource being referred to.
  30610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30611. maxLength: 63
  30612. minLength: 1
  30613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30614. type: string
  30615. type: object
  30616. secretAccessKeySecretRef:
  30617. description: The SecretAccessKey is used for authentication
  30618. properties:
  30619. key:
  30620. description: |-
  30621. A key in the referenced Secret.
  30622. Some instances of this field may be defaulted, in others it may be required.
  30623. maxLength: 253
  30624. minLength: 1
  30625. pattern: ^[-._a-zA-Z0-9]+$
  30626. type: string
  30627. name:
  30628. description: The name of the Secret resource being referred to.
  30629. maxLength: 253
  30630. minLength: 1
  30631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30632. type: string
  30633. namespace:
  30634. description: |-
  30635. The namespace of the Secret resource being referred to.
  30636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30637. maxLength: 63
  30638. minLength: 1
  30639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30640. type: string
  30641. type: object
  30642. sessionTokenSecretRef:
  30643. description: |-
  30644. The SessionToken used for authentication
  30645. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30646. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30647. properties:
  30648. key:
  30649. description: |-
  30650. A key in the referenced Secret.
  30651. Some instances of this field may be defaulted, in others it may be required.
  30652. maxLength: 253
  30653. minLength: 1
  30654. pattern: ^[-._a-zA-Z0-9]+$
  30655. type: string
  30656. name:
  30657. description: The name of the Secret resource being referred to.
  30658. maxLength: 253
  30659. minLength: 1
  30660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30661. type: string
  30662. namespace:
  30663. description: |-
  30664. The namespace of the Secret resource being referred to.
  30665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30666. maxLength: 63
  30667. minLength: 1
  30668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30669. type: string
  30670. type: object
  30671. type: object
  30672. type: object
  30673. region:
  30674. description: Region specifies the region to operate in.
  30675. type: string
  30676. requestParameters:
  30677. description: RequestParameters contains parameters that can be passed to the STS service.
  30678. properties:
  30679. serialNumber:
  30680. description: |-
  30681. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  30682. the GetSessionToken call.
  30683. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  30684. (such as arn:aws:iam::123456789012:mfa/user)
  30685. type: string
  30686. sessionDuration:
  30687. format: int32
  30688. type: integer
  30689. tokenCode:
  30690. description: TokenCode is the value provided by the MFA device, if MFA is required.
  30691. type: string
  30692. type: object
  30693. role:
  30694. description: |-
  30695. You can assume a role before making calls to the
  30696. desired AWS service.
  30697. type: string
  30698. required:
  30699. - region
  30700. type: object
  30701. type: object
  30702. served: true
  30703. storage: true
  30704. subresources:
  30705. status: {}
  30706. ---
  30707. apiVersion: apiextensions.k8s.io/v1
  30708. kind: CustomResourceDefinition
  30709. metadata:
  30710. annotations:
  30711. controller-gen.kubebuilder.io/version: v0.19.0
  30712. labels:
  30713. external-secrets.io/component: controller
  30714. name: uuids.generators.external-secrets.io
  30715. spec:
  30716. group: generators.external-secrets.io
  30717. names:
  30718. categories:
  30719. - external-secrets
  30720. - external-secrets-generators
  30721. kind: UUID
  30722. listKind: UUIDList
  30723. plural: uuids
  30724. singular: uuid
  30725. scope: Namespaced
  30726. versions:
  30727. - name: v1alpha1
  30728. schema:
  30729. openAPIV3Schema:
  30730. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  30731. properties:
  30732. apiVersion:
  30733. description: |-
  30734. APIVersion defines the versioned schema of this representation of an object.
  30735. Servers should convert recognized schemas to the latest internal value, and
  30736. may reject unrecognized values.
  30737. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30738. type: string
  30739. kind:
  30740. description: |-
  30741. Kind is a string value representing the REST resource this object represents.
  30742. Servers may infer this from the endpoint the client submits requests to.
  30743. Cannot be updated.
  30744. In CamelCase.
  30745. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30746. type: string
  30747. metadata:
  30748. type: object
  30749. spec:
  30750. description: UUIDSpec controls the behavior of the uuid generator.
  30751. type: object
  30752. type: object
  30753. served: true
  30754. storage: true
  30755. subresources:
  30756. status: {}
  30757. ---
  30758. apiVersion: apiextensions.k8s.io/v1
  30759. kind: CustomResourceDefinition
  30760. metadata:
  30761. annotations:
  30762. controller-gen.kubebuilder.io/version: v0.19.0
  30763. labels:
  30764. external-secrets.io/component: controller
  30765. name: vaultdynamicsecrets.generators.external-secrets.io
  30766. spec:
  30767. group: generators.external-secrets.io
  30768. names:
  30769. categories:
  30770. - external-secrets
  30771. - external-secrets-generators
  30772. kind: VaultDynamicSecret
  30773. listKind: VaultDynamicSecretList
  30774. plural: vaultdynamicsecrets
  30775. singular: vaultdynamicsecret
  30776. scope: Namespaced
  30777. versions:
  30778. - name: v1alpha1
  30779. schema:
  30780. openAPIV3Schema:
  30781. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  30782. properties:
  30783. apiVersion:
  30784. description: |-
  30785. APIVersion defines the versioned schema of this representation of an object.
  30786. Servers should convert recognized schemas to the latest internal value, and
  30787. may reject unrecognized values.
  30788. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30789. type: string
  30790. kind:
  30791. description: |-
  30792. Kind is a string value representing the REST resource this object represents.
  30793. Servers may infer this from the endpoint the client submits requests to.
  30794. Cannot be updated.
  30795. In CamelCase.
  30796. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30797. type: string
  30798. metadata:
  30799. type: object
  30800. spec:
  30801. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  30802. properties:
  30803. allowEmptyResponse:
  30804. default: false
  30805. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  30806. type: boolean
  30807. controller:
  30808. description: |-
  30809. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30810. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30811. type: string
  30812. getParameters:
  30813. additionalProperties:
  30814. items:
  30815. type: string
  30816. type: array
  30817. description: |-
  30818. GetParameters are query-string parameters passed to Vault on GET calls.
  30819. Each key may map to multiple values, matching HTTP query-string semantics.
  30820. Ignored for non-GET methods; use Parameters for write bodies.
  30821. type: object
  30822. method:
  30823. description: Vault API method to use (GET/POST/other)
  30824. type: string
  30825. parameters:
  30826. description: Parameters to pass to Vault write (for non-GET methods)
  30827. x-kubernetes-preserve-unknown-fields: true
  30828. path:
  30829. description: Vault path to obtain the dynamic secret from
  30830. type: string
  30831. provider:
  30832. description: Vault provider common spec
  30833. properties:
  30834. auth:
  30835. description: Auth configures how secret-manager authenticates with the Vault server.
  30836. properties:
  30837. appRole:
  30838. description: |-
  30839. AppRole authenticates with Vault using the App Role auth mechanism,
  30840. with the role and secret stored in a Kubernetes Secret resource.
  30841. properties:
  30842. path:
  30843. default: approle
  30844. description: |-
  30845. Path where the App Role authentication backend is mounted
  30846. in Vault, e.g: "approle"
  30847. type: string
  30848. roleId:
  30849. description: |-
  30850. RoleID configured in the App Role authentication backend when setting
  30851. up the authentication backend in Vault.
  30852. type: string
  30853. roleRef:
  30854. description: |-
  30855. Reference to a key in a Secret that contains the App Role ID used
  30856. to authenticate with Vault.
  30857. The `key` field must be specified and denotes which entry within the Secret
  30858. resource is used as the app role id.
  30859. properties:
  30860. key:
  30861. description: |-
  30862. A key in the referenced Secret.
  30863. Some instances of this field may be defaulted, in others it may be required.
  30864. maxLength: 253
  30865. minLength: 1
  30866. pattern: ^[-._a-zA-Z0-9]+$
  30867. type: string
  30868. name:
  30869. description: The name of the Secret resource being referred to.
  30870. maxLength: 253
  30871. minLength: 1
  30872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30873. type: string
  30874. namespace:
  30875. description: |-
  30876. The namespace of the Secret resource being referred to.
  30877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30878. maxLength: 63
  30879. minLength: 1
  30880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30881. type: string
  30882. type: object
  30883. secretRef:
  30884. description: |-
  30885. Reference to a key in a Secret that contains the App Role secret used
  30886. to authenticate with Vault.
  30887. The `key` field must be specified and denotes which entry within the Secret
  30888. resource is used as the app role secret.
  30889. properties:
  30890. key:
  30891. description: |-
  30892. A key in the referenced Secret.
  30893. Some instances of this field may be defaulted, in others it may be required.
  30894. maxLength: 253
  30895. minLength: 1
  30896. pattern: ^[-._a-zA-Z0-9]+$
  30897. type: string
  30898. name:
  30899. description: The name of the Secret resource being referred to.
  30900. maxLength: 253
  30901. minLength: 1
  30902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30903. type: string
  30904. namespace:
  30905. description: |-
  30906. The namespace of the Secret resource being referred to.
  30907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30908. maxLength: 63
  30909. minLength: 1
  30910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30911. type: string
  30912. type: object
  30913. required:
  30914. - path
  30915. - secretRef
  30916. type: object
  30917. cert:
  30918. description: |-
  30919. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  30920. Cert authentication method
  30921. properties:
  30922. clientCert:
  30923. description: |-
  30924. ClientCert is a certificate to authenticate using the Cert Vault
  30925. authentication method
  30926. properties:
  30927. key:
  30928. description: |-
  30929. A key in the referenced Secret.
  30930. Some instances of this field may be defaulted, in others it may be required.
  30931. maxLength: 253
  30932. minLength: 1
  30933. pattern: ^[-._a-zA-Z0-9]+$
  30934. type: string
  30935. name:
  30936. description: The name of the Secret resource being referred to.
  30937. maxLength: 253
  30938. minLength: 1
  30939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30940. type: string
  30941. namespace:
  30942. description: |-
  30943. The namespace of the Secret resource being referred to.
  30944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30945. maxLength: 63
  30946. minLength: 1
  30947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30948. type: string
  30949. type: object
  30950. path:
  30951. default: cert
  30952. description: |-
  30953. Path where the Certificate authentication backend is mounted
  30954. in Vault, e.g: "cert"
  30955. type: string
  30956. secretRef:
  30957. description: |-
  30958. SecretRef to a key in a Secret resource containing client private key to
  30959. authenticate with Vault using the Cert authentication method
  30960. properties:
  30961. key:
  30962. description: |-
  30963. A key in the referenced Secret.
  30964. Some instances of this field may be defaulted, in others it may be required.
  30965. maxLength: 253
  30966. minLength: 1
  30967. pattern: ^[-._a-zA-Z0-9]+$
  30968. type: string
  30969. name:
  30970. description: The name of the Secret resource being referred to.
  30971. maxLength: 253
  30972. minLength: 1
  30973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30974. type: string
  30975. namespace:
  30976. description: |-
  30977. The namespace of the Secret resource being referred to.
  30978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30979. maxLength: 63
  30980. minLength: 1
  30981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30982. type: string
  30983. type: object
  30984. vaultRole:
  30985. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  30986. type: string
  30987. type: object
  30988. gcp:
  30989. description: |-
  30990. Gcp authenticates with Vault using Google Cloud Platform authentication method
  30991. GCP authentication method
  30992. properties:
  30993. location:
  30994. description: Location optionally defines a location/region for the secret
  30995. type: string
  30996. path:
  30997. default: gcp
  30998. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  30999. type: string
  31000. projectID:
  31001. description: Project ID of the Google Cloud Platform project
  31002. type: string
  31003. role:
  31004. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31005. type: string
  31006. secretRef:
  31007. description: Specify credentials in a Secret object
  31008. properties:
  31009. secretAccessKeySecretRef:
  31010. description: The SecretAccessKey is used for authentication
  31011. properties:
  31012. key:
  31013. description: |-
  31014. A key in the referenced Secret.
  31015. Some instances of this field may be defaulted, in others it may be required.
  31016. maxLength: 253
  31017. minLength: 1
  31018. pattern: ^[-._a-zA-Z0-9]+$
  31019. type: string
  31020. name:
  31021. description: The name of the Secret resource being referred to.
  31022. maxLength: 253
  31023. minLength: 1
  31024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31025. type: string
  31026. namespace:
  31027. description: |-
  31028. The namespace of the Secret resource being referred to.
  31029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31030. maxLength: 63
  31031. minLength: 1
  31032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31033. type: string
  31034. type: object
  31035. type: object
  31036. serviceAccountRef:
  31037. description: ServiceAccountRef to a service account for impersonation
  31038. properties:
  31039. audiences:
  31040. description: |-
  31041. Audience specifies the `aud` claim for the service account token
  31042. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31043. then this audiences will be appended to the list
  31044. items:
  31045. type: string
  31046. type: array
  31047. name:
  31048. description: The name of the ServiceAccount resource being referred to.
  31049. maxLength: 253
  31050. minLength: 1
  31051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31052. type: string
  31053. namespace:
  31054. description: |-
  31055. Namespace of the resource being referred to.
  31056. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31057. maxLength: 63
  31058. minLength: 1
  31059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31060. type: string
  31061. required:
  31062. - name
  31063. type: object
  31064. workloadIdentity:
  31065. description: Specify a service account with Workload Identity
  31066. properties:
  31067. clusterLocation:
  31068. description: |-
  31069. ClusterLocation is the location of the cluster
  31070. If not specified, it fetches information from the metadata server
  31071. type: string
  31072. clusterName:
  31073. description: |-
  31074. ClusterName is the name of the cluster
  31075. If not specified, it fetches information from the metadata server
  31076. type: string
  31077. clusterProjectID:
  31078. description: |-
  31079. ClusterProjectID is the project ID of the cluster
  31080. If not specified, it fetches information from the metadata server
  31081. type: string
  31082. serviceAccountRef:
  31083. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31084. properties:
  31085. audiences:
  31086. description: |-
  31087. Audience specifies the `aud` claim for the service account token
  31088. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31089. then this audiences will be appended to the list
  31090. items:
  31091. type: string
  31092. type: array
  31093. name:
  31094. description: The name of the ServiceAccount resource being referred to.
  31095. maxLength: 253
  31096. minLength: 1
  31097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31098. type: string
  31099. namespace:
  31100. description: |-
  31101. Namespace of the resource being referred to.
  31102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31103. maxLength: 63
  31104. minLength: 1
  31105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31106. type: string
  31107. required:
  31108. - name
  31109. type: object
  31110. required:
  31111. - serviceAccountRef
  31112. type: object
  31113. required:
  31114. - role
  31115. type: object
  31116. iam:
  31117. description: |-
  31118. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31119. AWS IAM authentication method
  31120. properties:
  31121. externalID:
  31122. description: AWS External ID set on assumed IAM roles
  31123. type: string
  31124. jwt:
  31125. description: Specify a service account with IRSA enabled
  31126. properties:
  31127. serviceAccountRef:
  31128. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31129. properties:
  31130. audiences:
  31131. description: |-
  31132. Audience specifies the `aud` claim for the service account token
  31133. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31134. then this audiences will be appended to the list
  31135. items:
  31136. type: string
  31137. type: array
  31138. name:
  31139. description: The name of the ServiceAccount resource being referred to.
  31140. maxLength: 253
  31141. minLength: 1
  31142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31143. type: string
  31144. namespace:
  31145. description: |-
  31146. Namespace of the resource being referred to.
  31147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31148. maxLength: 63
  31149. minLength: 1
  31150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31151. type: string
  31152. required:
  31153. - name
  31154. type: object
  31155. type: object
  31156. path:
  31157. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31158. type: string
  31159. region:
  31160. description: AWS region
  31161. type: string
  31162. role:
  31163. description: This is the AWS role to be assumed before talking to vault
  31164. type: string
  31165. secretRef:
  31166. description: Specify credentials in a Secret object
  31167. properties:
  31168. accessKeyIDSecretRef:
  31169. description: The AccessKeyID is used for authentication
  31170. properties:
  31171. key:
  31172. description: |-
  31173. A key in the referenced Secret.
  31174. Some instances of this field may be defaulted, in others it may be required.
  31175. maxLength: 253
  31176. minLength: 1
  31177. pattern: ^[-._a-zA-Z0-9]+$
  31178. type: string
  31179. name:
  31180. description: The name of the Secret resource being referred to.
  31181. maxLength: 253
  31182. minLength: 1
  31183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31184. type: string
  31185. namespace:
  31186. description: |-
  31187. The namespace of the Secret resource being referred to.
  31188. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31189. maxLength: 63
  31190. minLength: 1
  31191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31192. type: string
  31193. type: object
  31194. secretAccessKeySecretRef:
  31195. description: The SecretAccessKey is used for authentication
  31196. properties:
  31197. key:
  31198. description: |-
  31199. A key in the referenced Secret.
  31200. Some instances of this field may be defaulted, in others it may be required.
  31201. maxLength: 253
  31202. minLength: 1
  31203. pattern: ^[-._a-zA-Z0-9]+$
  31204. type: string
  31205. name:
  31206. description: The name of the Secret resource being referred to.
  31207. maxLength: 253
  31208. minLength: 1
  31209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31210. type: string
  31211. namespace:
  31212. description: |-
  31213. The namespace of the Secret resource being referred to.
  31214. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31215. maxLength: 63
  31216. minLength: 1
  31217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31218. type: string
  31219. type: object
  31220. sessionTokenSecretRef:
  31221. description: |-
  31222. The SessionToken used for authentication
  31223. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31224. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31225. properties:
  31226. key:
  31227. description: |-
  31228. A key in the referenced Secret.
  31229. Some instances of this field may be defaulted, in others it may be required.
  31230. maxLength: 253
  31231. minLength: 1
  31232. pattern: ^[-._a-zA-Z0-9]+$
  31233. type: string
  31234. name:
  31235. description: The name of the Secret resource being referred to.
  31236. maxLength: 253
  31237. minLength: 1
  31238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31239. type: string
  31240. namespace:
  31241. description: |-
  31242. The namespace of the Secret resource being referred to.
  31243. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31244. maxLength: 63
  31245. minLength: 1
  31246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31247. type: string
  31248. type: object
  31249. type: object
  31250. vaultAwsIamServerID:
  31251. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31252. type: string
  31253. vaultRole:
  31254. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31255. type: string
  31256. required:
  31257. - vaultRole
  31258. type: object
  31259. jwt:
  31260. description: |-
  31261. Jwt authenticates with Vault by passing role and JWT token using the
  31262. JWT/OIDC authentication method
  31263. properties:
  31264. kubernetesServiceAccountToken:
  31265. description: |-
  31266. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31267. a token for with the `TokenRequest` API.
  31268. properties:
  31269. audiences:
  31270. description: |-
  31271. Optional audiences field that will be used to request a temporary Kubernetes service
  31272. account token for the service account referenced by `serviceAccountRef`.
  31273. Defaults to a single audience `vault` it not specified.
  31274. Deprecated: use serviceAccountRef.Audiences instead
  31275. items:
  31276. type: string
  31277. type: array
  31278. expirationSeconds:
  31279. description: |-
  31280. Optional expiration time in seconds that will be used to request a temporary
  31281. Kubernetes service account token for the service account referenced by
  31282. `serviceAccountRef`.
  31283. Deprecated: this will be removed in the future.
  31284. Defaults to 10 minutes.
  31285. format: int64
  31286. type: integer
  31287. serviceAccountRef:
  31288. description: Service account field containing the name of a kubernetes ServiceAccount.
  31289. properties:
  31290. audiences:
  31291. description: |-
  31292. Audience specifies the `aud` claim for the service account token
  31293. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31294. then this audiences will be appended to the list
  31295. items:
  31296. type: string
  31297. type: array
  31298. name:
  31299. description: The name of the ServiceAccount resource being referred to.
  31300. maxLength: 253
  31301. minLength: 1
  31302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31303. type: string
  31304. namespace:
  31305. description: |-
  31306. Namespace of the resource being referred to.
  31307. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31308. maxLength: 63
  31309. minLength: 1
  31310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31311. type: string
  31312. required:
  31313. - name
  31314. type: object
  31315. required:
  31316. - serviceAccountRef
  31317. type: object
  31318. path:
  31319. default: jwt
  31320. description: |-
  31321. Path where the JWT authentication backend is mounted
  31322. in Vault, e.g: "jwt"
  31323. type: string
  31324. role:
  31325. description: |-
  31326. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31327. authentication method
  31328. type: string
  31329. secretRef:
  31330. description: |-
  31331. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31332. authenticate with Vault using the JWT/OIDC authentication method.
  31333. properties:
  31334. key:
  31335. description: |-
  31336. A key in the referenced Secret.
  31337. Some instances of this field may be defaulted, in others it may be required.
  31338. maxLength: 253
  31339. minLength: 1
  31340. pattern: ^[-._a-zA-Z0-9]+$
  31341. type: string
  31342. name:
  31343. description: The name of the Secret resource being referred to.
  31344. maxLength: 253
  31345. minLength: 1
  31346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31347. type: string
  31348. namespace:
  31349. description: |-
  31350. The namespace of the Secret resource being referred to.
  31351. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31352. maxLength: 63
  31353. minLength: 1
  31354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31355. type: string
  31356. type: object
  31357. required:
  31358. - path
  31359. type: object
  31360. kubernetes:
  31361. description: |-
  31362. Kubernetes authenticates with Vault by passing the ServiceAccount
  31363. token stored in the named Secret resource to the Vault server.
  31364. properties:
  31365. mountPath:
  31366. default: kubernetes
  31367. description: |-
  31368. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31369. "kubernetes"
  31370. type: string
  31371. role:
  31372. description: |-
  31373. A required field containing the Vault Role to assume. A Role binds a
  31374. Kubernetes ServiceAccount with a set of Vault policies.
  31375. type: string
  31376. secretRef:
  31377. description: |-
  31378. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31379. for authenticating with Vault. If a name is specified without a key,
  31380. `token` is the default. If one is not specified, the one bound to
  31381. the controller will be used.
  31382. properties:
  31383. key:
  31384. description: |-
  31385. A key in the referenced Secret.
  31386. Some instances of this field may be defaulted, in others it may be required.
  31387. maxLength: 253
  31388. minLength: 1
  31389. pattern: ^[-._a-zA-Z0-9]+$
  31390. type: string
  31391. name:
  31392. description: The name of the Secret resource being referred to.
  31393. maxLength: 253
  31394. minLength: 1
  31395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31396. type: string
  31397. namespace:
  31398. description: |-
  31399. The namespace of the Secret resource being referred to.
  31400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31401. maxLength: 63
  31402. minLength: 1
  31403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31404. type: string
  31405. type: object
  31406. serviceAccountRef:
  31407. description: |-
  31408. Optional service account field containing the name of a kubernetes ServiceAccount.
  31409. If the service account is specified, the service account secret token JWT will be used
  31410. for authenticating with Vault. If the service account selector is not supplied,
  31411. the secretRef will be used instead.
  31412. properties:
  31413. audiences:
  31414. description: |-
  31415. Audience specifies the `aud` claim for the service account token
  31416. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31417. then this audiences will be appended to the list
  31418. items:
  31419. type: string
  31420. type: array
  31421. name:
  31422. description: The name of the ServiceAccount resource being referred to.
  31423. maxLength: 253
  31424. minLength: 1
  31425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31426. type: string
  31427. namespace:
  31428. description: |-
  31429. Namespace of the resource being referred to.
  31430. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31431. maxLength: 63
  31432. minLength: 1
  31433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31434. type: string
  31435. required:
  31436. - name
  31437. type: object
  31438. required:
  31439. - mountPath
  31440. - role
  31441. type: object
  31442. ldap:
  31443. description: |-
  31444. Ldap authenticates with Vault by passing username/password pair using
  31445. the LDAP authentication method
  31446. properties:
  31447. path:
  31448. default: ldap
  31449. description: |-
  31450. Path where the LDAP authentication backend is mounted
  31451. in Vault, e.g: "ldap"
  31452. type: string
  31453. secretRef:
  31454. description: |-
  31455. SecretRef to a key in a Secret resource containing password for the LDAP
  31456. user used to authenticate with Vault using the LDAP authentication
  31457. method
  31458. properties:
  31459. key:
  31460. description: |-
  31461. A key in the referenced Secret.
  31462. Some instances of this field may be defaulted, in others it may be required.
  31463. maxLength: 253
  31464. minLength: 1
  31465. pattern: ^[-._a-zA-Z0-9]+$
  31466. type: string
  31467. name:
  31468. description: The name of the Secret resource being referred to.
  31469. maxLength: 253
  31470. minLength: 1
  31471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31472. type: string
  31473. namespace:
  31474. description: |-
  31475. The namespace of the Secret resource being referred to.
  31476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31477. maxLength: 63
  31478. minLength: 1
  31479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31480. type: string
  31481. type: object
  31482. username:
  31483. description: |-
  31484. Username is an LDAP username used to authenticate using the LDAP Vault
  31485. authentication method
  31486. type: string
  31487. required:
  31488. - path
  31489. - username
  31490. type: object
  31491. namespace:
  31492. description: |-
  31493. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  31494. Namespaces is a set of features within Vault Enterprise that allows
  31495. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  31496. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  31497. This will default to Vault.Namespace field if set, or empty otherwise
  31498. type: string
  31499. tokenSecretRef:
  31500. description: TokenSecretRef authenticates with Vault by presenting a token.
  31501. properties:
  31502. key:
  31503. description: |-
  31504. A key in the referenced Secret.
  31505. Some instances of this field may be defaulted, in others it may be required.
  31506. maxLength: 253
  31507. minLength: 1
  31508. pattern: ^[-._a-zA-Z0-9]+$
  31509. type: string
  31510. name:
  31511. description: The name of the Secret resource being referred to.
  31512. maxLength: 253
  31513. minLength: 1
  31514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31515. type: string
  31516. namespace:
  31517. description: |-
  31518. The namespace of the Secret resource being referred to.
  31519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31520. maxLength: 63
  31521. minLength: 1
  31522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31523. type: string
  31524. type: object
  31525. userPass:
  31526. description: UserPass authenticates with Vault by passing username/password pair
  31527. properties:
  31528. path:
  31529. default: userpass
  31530. description: |-
  31531. Path where the UserPassword authentication backend is mounted
  31532. in Vault, e.g: "userpass"
  31533. type: string
  31534. secretRef:
  31535. description: |-
  31536. SecretRef to a key in a Secret resource containing password for the
  31537. user used to authenticate with Vault using the UserPass authentication
  31538. method
  31539. properties:
  31540. key:
  31541. description: |-
  31542. A key in the referenced Secret.
  31543. Some instances of this field may be defaulted, in others it may be required.
  31544. maxLength: 253
  31545. minLength: 1
  31546. pattern: ^[-._a-zA-Z0-9]+$
  31547. type: string
  31548. name:
  31549. description: The name of the Secret resource being referred to.
  31550. maxLength: 253
  31551. minLength: 1
  31552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31553. type: string
  31554. namespace:
  31555. description: |-
  31556. The namespace of the Secret resource being referred to.
  31557. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31558. maxLength: 63
  31559. minLength: 1
  31560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31561. type: string
  31562. type: object
  31563. username:
  31564. description: |-
  31565. Username is a username used to authenticate using the UserPass Vault
  31566. authentication method
  31567. type: string
  31568. required:
  31569. - path
  31570. - username
  31571. type: object
  31572. type: object
  31573. caBundle:
  31574. description: |-
  31575. PEM encoded CA bundle used to validate Vault server certificate. Only used
  31576. if the Server URL is using HTTPS protocol. This parameter is ignored for
  31577. plain HTTP protocol connection. If not set the system root certificates
  31578. are used to validate the TLS connection.
  31579. format: byte
  31580. type: string
  31581. caProvider:
  31582. description: The provider for the CA bundle to use to validate Vault server certificate.
  31583. properties:
  31584. key:
  31585. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  31586. maxLength: 253
  31587. minLength: 1
  31588. pattern: ^[-._a-zA-Z0-9]+$
  31589. type: string
  31590. name:
  31591. description: The name of the object located at the provider type.
  31592. maxLength: 253
  31593. minLength: 1
  31594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31595. type: string
  31596. namespace:
  31597. description: |-
  31598. The namespace the Provider type is in.
  31599. Can only be defined when used in a ClusterSecretStore.
  31600. maxLength: 63
  31601. minLength: 1
  31602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31603. type: string
  31604. type:
  31605. description: The type of provider to use such as "Secret", or "ConfigMap".
  31606. enum:
  31607. - Secret
  31608. - ConfigMap
  31609. type: string
  31610. required:
  31611. - name
  31612. - type
  31613. type: object
  31614. checkAndSet:
  31615. description: |-
  31616. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  31617. Only applies to Vault KV v2 stores. When enabled, write operations must include
  31618. the current version of the secret to prevent unintentional overwrites.
  31619. properties:
  31620. required:
  31621. description: |-
  31622. Required when true, all write operations must include a check-and-set parameter.
  31623. This helps prevent unintentional overwrites of secrets.
  31624. type: boolean
  31625. type: object
  31626. forwardInconsistent:
  31627. description: |-
  31628. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  31629. leader instead of simply retrying within a loop. This can increase performance if
  31630. the option is enabled serverside.
  31631. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  31632. type: boolean
  31633. headers:
  31634. additionalProperties:
  31635. type: string
  31636. description: Headers to be added in Vault request
  31637. type: object
  31638. namespace:
  31639. description: |-
  31640. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  31641. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  31642. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  31643. type: string
  31644. path:
  31645. description: |-
  31646. Path is the mount path of the Vault KV backend endpoint, e.g:
  31647. "secret". The v2 KV secret engine version specific "/data" path suffix
  31648. for fetching secrets from Vault is optional and will be appended
  31649. if not present in specified path.
  31650. type: string
  31651. readYourWrites:
  31652. description: |-
  31653. ReadYourWrites ensures isolated read-after-write semantics by
  31654. providing discovered cluster replication states in each request.
  31655. More information about eventual consistency in Vault can be found here
  31656. https://www.vaultproject.io/docs/enterprise/consistency
  31657. type: boolean
  31658. server:
  31659. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  31660. type: string
  31661. tls:
  31662. description: |-
  31663. The configuration used for client side related TLS communication, when the Vault server
  31664. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  31665. This parameter is ignored for plain HTTP protocol connection.
  31666. It's worth noting this configuration is different from the "TLS certificates auth method",
  31667. which is available under the `auth.cert` section.
  31668. properties:
  31669. certSecretRef:
  31670. description: |-
  31671. CertSecretRef is a certificate added to the transport layer
  31672. when communicating with the Vault server.
  31673. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  31674. properties:
  31675. key:
  31676. description: |-
  31677. A key in the referenced Secret.
  31678. Some instances of this field may be defaulted, in others it may be required.
  31679. maxLength: 253
  31680. minLength: 1
  31681. pattern: ^[-._a-zA-Z0-9]+$
  31682. type: string
  31683. name:
  31684. description: The name of the Secret resource being referred to.
  31685. maxLength: 253
  31686. minLength: 1
  31687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31688. type: string
  31689. namespace:
  31690. description: |-
  31691. The namespace of the Secret resource being referred to.
  31692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31693. maxLength: 63
  31694. minLength: 1
  31695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31696. type: string
  31697. type: object
  31698. keySecretRef:
  31699. description: |-
  31700. KeySecretRef to a key in a Secret resource containing client private key
  31701. added to the transport layer when communicating with the Vault server.
  31702. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  31703. properties:
  31704. key:
  31705. description: |-
  31706. A key in the referenced Secret.
  31707. Some instances of this field may be defaulted, in others it may be required.
  31708. maxLength: 253
  31709. minLength: 1
  31710. pattern: ^[-._a-zA-Z0-9]+$
  31711. type: string
  31712. name:
  31713. description: The name of the Secret resource being referred to.
  31714. maxLength: 253
  31715. minLength: 1
  31716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31717. type: string
  31718. namespace:
  31719. description: |-
  31720. The namespace of the Secret resource being referred to.
  31721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31722. maxLength: 63
  31723. minLength: 1
  31724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31725. type: string
  31726. type: object
  31727. type: object
  31728. version:
  31729. default: v2
  31730. description: |-
  31731. Version is the Vault KV secret engine version. This can be either "v1" or
  31732. "v2". Version defaults to "v2".
  31733. enum:
  31734. - v1
  31735. - v2
  31736. type: string
  31737. required:
  31738. - server
  31739. type: object
  31740. resultType:
  31741. default: Data
  31742. description: |-
  31743. Result type defines which data is returned from the generator.
  31744. By default, it is the "data" section of the Vault API response.
  31745. When using e.g. /auth/token/create the "data" section is empty but
  31746. the "auth" section contains the generated token.
  31747. Please refer to the vault docs regarding the result data structure.
  31748. Additionally, accessing the raw response is possibly by using "Raw" result type.
  31749. enum:
  31750. - Data
  31751. - Auth
  31752. - Raw
  31753. type: string
  31754. retrySettings:
  31755. description: Used to configure http retries if failed
  31756. properties:
  31757. maxRetries:
  31758. format: int32
  31759. type: integer
  31760. retryInterval:
  31761. type: string
  31762. type: object
  31763. required:
  31764. - path
  31765. - provider
  31766. type: object
  31767. type: object
  31768. served: true
  31769. storage: true
  31770. subresources:
  31771. status: {}
  31772. ---
  31773. apiVersion: apiextensions.k8s.io/v1
  31774. kind: CustomResourceDefinition
  31775. metadata:
  31776. annotations:
  31777. controller-gen.kubebuilder.io/version: v0.19.0
  31778. labels:
  31779. external-secrets.io/component: controller
  31780. name: webhooks.generators.external-secrets.io
  31781. spec:
  31782. group: generators.external-secrets.io
  31783. names:
  31784. categories:
  31785. - external-secrets
  31786. - external-secrets-generators
  31787. kind: Webhook
  31788. listKind: WebhookList
  31789. plural: webhooks
  31790. singular: webhook
  31791. scope: Namespaced
  31792. versions:
  31793. - name: v1alpha1
  31794. schema:
  31795. openAPIV3Schema:
  31796. description: |-
  31797. Webhook connects to a third party API server to handle the secrets generation
  31798. configuration parameters in spec.
  31799. You can specify the server, the token, and additional body parameters.
  31800. See documentation for the full API specification for requests and responses.
  31801. properties:
  31802. apiVersion:
  31803. description: |-
  31804. APIVersion defines the versioned schema of this representation of an object.
  31805. Servers should convert recognized schemas to the latest internal value, and
  31806. may reject unrecognized values.
  31807. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31808. type: string
  31809. kind:
  31810. description: |-
  31811. Kind is a string value representing the REST resource this object represents.
  31812. Servers may infer this from the endpoint the client submits requests to.
  31813. Cannot be updated.
  31814. In CamelCase.
  31815. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31816. type: string
  31817. metadata:
  31818. type: object
  31819. spec:
  31820. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  31821. properties:
  31822. auth:
  31823. description: Auth specifies a authorization protocol. Only one protocol may be set.
  31824. maxProperties: 1
  31825. minProperties: 1
  31826. properties:
  31827. ntlm:
  31828. description: NTLMProtocol configures the store to use NTLM for auth
  31829. properties:
  31830. passwordSecret:
  31831. description: |-
  31832. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31833. In some instances, `key` is a required field.
  31834. properties:
  31835. key:
  31836. description: |-
  31837. A key in the referenced Secret.
  31838. Some instances of this field may be defaulted, in others it may be required.
  31839. maxLength: 253
  31840. minLength: 1
  31841. pattern: ^[-._a-zA-Z0-9]+$
  31842. type: string
  31843. name:
  31844. description: The name of the Secret resource being referred to.
  31845. maxLength: 253
  31846. minLength: 1
  31847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31848. type: string
  31849. namespace:
  31850. description: |-
  31851. The namespace of the Secret resource being referred to.
  31852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31853. maxLength: 63
  31854. minLength: 1
  31855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31856. type: string
  31857. type: object
  31858. usernameSecret:
  31859. description: |-
  31860. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31861. In some instances, `key` is a required field.
  31862. properties:
  31863. key:
  31864. description: |-
  31865. A key in the referenced Secret.
  31866. Some instances of this field may be defaulted, in others it may be required.
  31867. maxLength: 253
  31868. minLength: 1
  31869. pattern: ^[-._a-zA-Z0-9]+$
  31870. type: string
  31871. name:
  31872. description: The name of the Secret resource being referred to.
  31873. maxLength: 253
  31874. minLength: 1
  31875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31876. type: string
  31877. namespace:
  31878. description: |-
  31879. The namespace of the Secret resource being referred to.
  31880. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31881. maxLength: 63
  31882. minLength: 1
  31883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31884. type: string
  31885. type: object
  31886. required:
  31887. - passwordSecret
  31888. - usernameSecret
  31889. type: object
  31890. type: object
  31891. body:
  31892. description: Body
  31893. type: string
  31894. caBundle:
  31895. description: |-
  31896. PEM encoded CA bundle used to validate webhook server certificate. Only used
  31897. if the Server URL is using HTTPS protocol. This parameter is ignored for
  31898. plain HTTP protocol connection. If not set the system root certificates
  31899. are used to validate the TLS connection.
  31900. format: byte
  31901. type: string
  31902. caProvider:
  31903. description: The provider for the CA bundle to use to validate webhook server certificate.
  31904. properties:
  31905. key:
  31906. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  31907. maxLength: 253
  31908. minLength: 1
  31909. pattern: ^[-._a-zA-Z0-9]+$
  31910. type: string
  31911. name:
  31912. description: The name of the object located at the provider type.
  31913. maxLength: 253
  31914. minLength: 1
  31915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31916. type: string
  31917. namespace:
  31918. description: The namespace the Provider type is in.
  31919. maxLength: 63
  31920. minLength: 1
  31921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31922. type: string
  31923. type:
  31924. description: The type of provider to use such as "Secret", or "ConfigMap".
  31925. enum:
  31926. - Secret
  31927. - ConfigMap
  31928. type: string
  31929. required:
  31930. - name
  31931. - type
  31932. type: object
  31933. headers:
  31934. additionalProperties:
  31935. type: string
  31936. description: Headers
  31937. type: object
  31938. method:
  31939. description: Webhook Method
  31940. type: string
  31941. result:
  31942. description: Result formatting
  31943. properties:
  31944. jsonPath:
  31945. description: Json path of return value
  31946. type: string
  31947. type: object
  31948. secrets:
  31949. description: |-
  31950. Secrets to fill in templates
  31951. These secrets will be passed to the templating function as key value pairs under the given name
  31952. items:
  31953. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  31954. properties:
  31955. name:
  31956. description: Name of this secret in templates
  31957. type: string
  31958. secretRef:
  31959. description: Secret ref to fill in credentials
  31960. properties:
  31961. key:
  31962. description: The key where the token is found.
  31963. maxLength: 253
  31964. minLength: 1
  31965. pattern: ^[-._a-zA-Z0-9]+$
  31966. type: string
  31967. name:
  31968. description: The name of the Secret resource being referred to.
  31969. maxLength: 253
  31970. minLength: 1
  31971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31972. type: string
  31973. type: object
  31974. required:
  31975. - name
  31976. - secretRef
  31977. type: object
  31978. type: array
  31979. timeout:
  31980. description: Timeout
  31981. type: string
  31982. url:
  31983. description: Webhook url to call
  31984. type: string
  31985. required:
  31986. - result
  31987. - url
  31988. type: object
  31989. type: object
  31990. served: true
  31991. storage: true
  31992. subresources:
  31993. status: {}