bundle.yaml 1.8 MB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052905390549055905690579058905990609061906290639064906590669067906890699070907190729073907490759076907790789079908090819082908390849085908690879088908990909091909290939094909590969097909890999100910191029103910491059106910791089109911091119112911391149115911691179118911991209121912291239124912591269127912891299130913191329133913491359136913791389139914091419142914391449145914691479148914991509151915291539154915591569157915891599160916191629163916491659166916791689169917091719172917391749175917691779178917991809181918291839184918591869187918891899190919191929193919491959196919791989199920092019202920392049205920692079208920992109211921292139214921592169217921892199220922192229223922492259226922792289229923092319232923392349235923692379238923992409241924292439244924592469247924892499250925192529253925492559256925792589259926092619262926392649265926692679268926992709271927292739274927592769277927892799280928192829283928492859286928792889289929092919292929392949295929692979298929993009301930293039304930593069307930893099310931193129313931493159316931793189319932093219322932393249325932693279328932993309331933293339334933593369337933893399340934193429343934493459346934793489349935093519352935393549355935693579358935993609361936293639364936593669367936893699370937193729373937493759376937793789379938093819382938393849385938693879388938993909391939293939394939593969397939893999400940194029403940494059406940794089409941094119412941394149415941694179418941994209421942294239424942594269427942894299430943194329433943494359436943794389439944094419442944394449445944694479448944994509451945294539454945594569457945894599460946194629463946494659466946794689469947094719472947394749475947694779478947994809481948294839484948594869487948894899490949194929493949494959496949794989499950095019502950395049505950695079508950995109511951295139514951595169517951895199520952195229523952495259526952795289529953095319532953395349535953695379538953995409541954295439544954595469547954895499550955195529553955495559556955795589559956095619562956395649565956695679568956995709571957295739574957595769577957895799580958195829583958495859586958795889589959095919592959395949595959695979598959996009601960296039604960596069607960896099610961196129613961496159616961796189619962096219622962396249625962696279628962996309631963296339634963596369637963896399640964196429643964496459646964796489649965096519652965396549655965696579658965996609661966296639664966596669667966896699670967196729673967496759676967796789679968096819682968396849685968696879688968996909691969296939694969596969697969896999700970197029703970497059706970797089709971097119712971397149715971697179718971997209721972297239724972597269727972897299730973197329733973497359736973797389739974097419742974397449745974697479748974997509751975297539754975597569757975897599760976197629763976497659766976797689769977097719772977397749775977697779778977997809781978297839784978597869787978897899790979197929793979497959796979797989799980098019802980398049805980698079808980998109811981298139814981598169817981898199820982198229823982498259826982798289829983098319832983398349835983698379838983998409841984298439844984598469847984898499850985198529853985498559856985798589859986098619862986398649865986698679868986998709871987298739874987598769877987898799880988198829883988498859886988798889889989098919892989398949895989698979898989999009901990299039904990599069907990899099910991199129913991499159916991799189919992099219922992399249925992699279928992999309931993299339934993599369937993899399940994199429943994499459946994799489949995099519952995399549955995699579958995999609961996299639964996599669967996899699970997199729973997499759976997799789979998099819982998399849985998699879988998999909991999299939994999599969997999899991000010001100021000310004100051000610007100081000910010100111001210013100141001510016100171001810019100201002110022100231002410025100261002710028100291003010031100321003310034100351003610037100381003910040100411004210043100441004510046100471004810049100501005110052100531005410055100561005710058100591006010061100621006310064100651006610067100681006910070100711007210073100741007510076100771007810079100801008110082100831008410085100861008710088100891009010091100921009310094100951009610097100981009910100101011010210103101041010510106101071010810109101101011110112101131011410115101161011710118101191012010121101221012310124101251012610127101281012910130101311013210133101341013510136101371013810139101401014110142101431014410145101461014710148101491015010151101521015310154101551015610157101581015910160101611016210163101641016510166101671016810169101701017110172101731017410175101761017710178101791018010181101821018310184101851018610187101881018910190101911019210193101941019510196101971019810199102001020110202102031020410205102061020710208102091021010211102121021310214102151021610217102181021910220102211022210223102241022510226102271022810229102301023110232102331023410235102361023710238102391024010241102421024310244102451024610247102481024910250102511025210253102541025510256102571025810259102601026110262102631026410265102661026710268102691027010271102721027310274102751027610277102781027910280102811028210283102841028510286102871028810289102901029110292102931029410295102961029710298102991030010301103021030310304103051030610307103081030910310103111031210313103141031510316103171031810319103201032110322103231032410325103261032710328103291033010331103321033310334103351033610337103381033910340103411034210343103441034510346103471034810349103501035110352103531035410355103561035710358103591036010361103621036310364103651036610367103681036910370103711037210373103741037510376103771037810379103801038110382103831038410385103861038710388103891039010391103921039310394103951039610397103981039910400104011040210403104041040510406104071040810409104101041110412104131041410415104161041710418104191042010421104221042310424104251042610427104281042910430104311043210433104341043510436104371043810439104401044110442104431044410445104461044710448104491045010451104521045310454104551045610457104581045910460104611046210463104641046510466104671046810469104701047110472104731047410475104761047710478104791048010481104821048310484104851048610487104881048910490104911049210493104941049510496104971049810499105001050110502105031050410505105061050710508105091051010511105121051310514105151051610517105181051910520105211052210523105241052510526105271052810529105301053110532105331053410535105361053710538105391054010541105421054310544105451054610547105481054910550105511055210553105541055510556105571055810559105601056110562105631056410565105661056710568105691057010571105721057310574105751057610577105781057910580105811058210583105841058510586105871058810589105901059110592105931059410595105961059710598105991060010601106021060310604106051060610607106081060910610106111061210613106141061510616106171061810619106201062110622106231062410625106261062710628106291063010631106321063310634106351063610637106381063910640106411064210643106441064510646106471064810649106501065110652106531065410655106561065710658106591066010661106621066310664106651066610667106681066910670106711067210673106741067510676106771067810679106801068110682106831068410685106861068710688106891069010691106921069310694106951069610697106981069910700107011070210703107041070510706107071070810709107101071110712107131071410715107161071710718107191072010721107221072310724107251072610727107281072910730107311073210733107341073510736107371073810739107401074110742107431074410745107461074710748107491075010751107521075310754107551075610757107581075910760107611076210763107641076510766107671076810769107701077110772107731077410775107761077710778107791078010781107821078310784107851078610787107881078910790107911079210793107941079510796107971079810799108001080110802108031080410805108061080710808108091081010811108121081310814108151081610817108181081910820108211082210823108241082510826108271082810829108301083110832108331083410835108361083710838108391084010841108421084310844108451084610847108481084910850108511085210853108541085510856108571085810859108601086110862108631086410865108661086710868108691087010871108721087310874108751087610877108781087910880108811088210883108841088510886108871088810889108901089110892108931089410895108961089710898108991090010901109021090310904109051090610907109081090910910109111091210913109141091510916109171091810919109201092110922109231092410925109261092710928109291093010931109321093310934109351093610937109381093910940109411094210943109441094510946109471094810949109501095110952109531095410955109561095710958109591096010961109621096310964109651096610967109681096910970109711097210973109741097510976109771097810979109801098110982109831098410985109861098710988109891099010991109921099310994109951099610997109981099911000110011100211003110041100511006110071100811009110101101111012110131101411015110161101711018110191102011021110221102311024110251102611027110281102911030110311103211033110341103511036110371103811039110401104111042110431104411045110461104711048110491105011051110521105311054110551105611057110581105911060110611106211063110641106511066110671106811069110701107111072110731107411075110761107711078110791108011081110821108311084110851108611087110881108911090110911109211093110941109511096110971109811099111001110111102111031110411105111061110711108111091111011111111121111311114111151111611117111181111911120111211112211123111241112511126111271112811129111301113111132111331113411135111361113711138111391114011141111421114311144111451114611147111481114911150111511115211153111541115511156111571115811159111601116111162111631116411165111661116711168111691117011171111721117311174111751117611177111781117911180111811118211183111841118511186111871118811189111901119111192111931119411195111961119711198111991120011201112021120311204112051120611207112081120911210112111121211213112141121511216112171121811219112201122111222112231122411225112261122711228112291123011231112321123311234112351123611237112381123911240112411124211243112441124511246112471124811249112501125111252112531125411255112561125711258112591126011261112621126311264112651126611267112681126911270112711127211273112741127511276112771127811279112801128111282112831128411285112861128711288112891129011291112921129311294112951129611297112981129911300113011130211303113041130511306113071130811309113101131111312113131131411315113161131711318113191132011321113221132311324113251132611327113281132911330113311133211333113341133511336113371133811339113401134111342113431134411345113461134711348113491135011351113521135311354113551135611357113581135911360113611136211363113641136511366113671136811369113701137111372113731137411375113761137711378113791138011381113821138311384113851138611387113881138911390113911139211393113941139511396113971139811399114001140111402114031140411405114061140711408114091141011411114121141311414114151141611417114181141911420114211142211423114241142511426114271142811429114301143111432114331143411435114361143711438114391144011441114421144311444114451144611447114481144911450114511145211453114541145511456114571145811459114601146111462114631146411465114661146711468114691147011471114721147311474114751147611477114781147911480114811148211483114841148511486114871148811489114901149111492114931149411495114961149711498114991150011501115021150311504115051150611507115081150911510115111151211513115141151511516115171151811519115201152111522115231152411525115261152711528115291153011531115321153311534115351153611537115381153911540115411154211543115441154511546115471154811549115501155111552115531155411555115561155711558115591156011561115621156311564115651156611567115681156911570115711157211573115741157511576115771157811579115801158111582115831158411585115861158711588115891159011591115921159311594115951159611597115981159911600116011160211603116041160511606116071160811609116101161111612116131161411615116161161711618116191162011621116221162311624116251162611627116281162911630116311163211633116341163511636116371163811639116401164111642116431164411645116461164711648116491165011651116521165311654116551165611657116581165911660116611166211663116641166511666116671166811669116701167111672116731167411675116761167711678116791168011681116821168311684116851168611687116881168911690116911169211693116941169511696116971169811699117001170111702117031170411705117061170711708117091171011711117121171311714117151171611717117181171911720117211172211723117241172511726117271172811729117301173111732117331173411735117361173711738117391174011741117421174311744117451174611747117481174911750117511175211753117541175511756117571175811759117601176111762117631176411765117661176711768117691177011771117721177311774117751177611777117781177911780117811178211783117841178511786117871178811789117901179111792117931179411795117961179711798117991180011801118021180311804118051180611807118081180911810118111181211813118141181511816118171181811819118201182111822118231182411825118261182711828118291183011831118321183311834118351183611837118381183911840118411184211843118441184511846118471184811849118501185111852118531185411855118561185711858118591186011861118621186311864118651186611867118681186911870118711187211873118741187511876118771187811879118801188111882118831188411885118861188711888118891189011891118921189311894118951189611897118981189911900119011190211903119041190511906119071190811909119101191111912119131191411915119161191711918119191192011921119221192311924119251192611927119281192911930119311193211933119341193511936119371193811939119401194111942119431194411945119461194711948119491195011951119521195311954119551195611957119581195911960119611196211963119641196511966119671196811969119701197111972119731197411975119761197711978119791198011981119821198311984119851198611987119881198911990119911199211993119941199511996119971199811999120001200112002120031200412005120061200712008120091201012011120121201312014120151201612017120181201912020120211202212023120241202512026120271202812029120301203112032120331203412035120361203712038120391204012041120421204312044120451204612047120481204912050120511205212053120541205512056120571205812059120601206112062120631206412065120661206712068120691207012071120721207312074120751207612077120781207912080120811208212083120841208512086120871208812089120901209112092120931209412095120961209712098120991210012101121021210312104121051210612107121081210912110121111211212113121141211512116121171211812119121201212112122121231212412125121261212712128121291213012131121321213312134121351213612137121381213912140121411214212143121441214512146121471214812149121501215112152121531215412155121561215712158121591216012161121621216312164121651216612167121681216912170121711217212173121741217512176121771217812179121801218112182121831218412185121861218712188121891219012191121921219312194121951219612197121981219912200122011220212203122041220512206122071220812209122101221112212122131221412215122161221712218122191222012221122221222312224122251222612227122281222912230122311223212233122341223512236122371223812239122401224112242122431224412245122461224712248122491225012251122521225312254122551225612257122581225912260122611226212263122641226512266122671226812269122701227112272122731227412275122761227712278122791228012281122821228312284122851228612287122881228912290122911229212293122941229512296122971229812299123001230112302123031230412305123061230712308123091231012311123121231312314123151231612317123181231912320123211232212323123241232512326123271232812329123301233112332123331233412335123361233712338123391234012341123421234312344123451234612347123481234912350123511235212353123541235512356123571235812359123601236112362123631236412365123661236712368123691237012371123721237312374123751237612377123781237912380123811238212383123841238512386123871238812389123901239112392123931239412395123961239712398123991240012401124021240312404124051240612407124081240912410124111241212413124141241512416124171241812419124201242112422124231242412425124261242712428124291243012431124321243312434124351243612437124381243912440124411244212443124441244512446124471244812449124501245112452124531245412455124561245712458124591246012461124621246312464124651246612467124681246912470124711247212473124741247512476124771247812479124801248112482124831248412485124861248712488124891249012491124921249312494124951249612497124981249912500125011250212503125041250512506125071250812509125101251112512125131251412515125161251712518125191252012521125221252312524125251252612527125281252912530125311253212533125341253512536125371253812539125401254112542125431254412545125461254712548125491255012551125521255312554125551255612557125581255912560125611256212563125641256512566125671256812569125701257112572125731257412575125761257712578125791258012581125821258312584125851258612587125881258912590125911259212593125941259512596125971259812599126001260112602126031260412605126061260712608126091261012611126121261312614126151261612617126181261912620126211262212623126241262512626126271262812629126301263112632126331263412635126361263712638126391264012641126421264312644126451264612647126481264912650126511265212653126541265512656126571265812659126601266112662126631266412665126661266712668126691267012671126721267312674126751267612677126781267912680126811268212683126841268512686126871268812689126901269112692126931269412695126961269712698126991270012701127021270312704127051270612707127081270912710127111271212713127141271512716127171271812719127201272112722127231272412725127261272712728127291273012731127321273312734127351273612737127381273912740127411274212743127441274512746127471274812749127501275112752127531275412755127561275712758127591276012761127621276312764127651276612767127681276912770127711277212773127741277512776127771277812779127801278112782127831278412785127861278712788127891279012791127921279312794127951279612797127981279912800128011280212803128041280512806128071280812809128101281112812128131281412815128161281712818128191282012821128221282312824128251282612827128281282912830128311283212833128341283512836128371283812839128401284112842128431284412845128461284712848128491285012851128521285312854128551285612857128581285912860128611286212863128641286512866128671286812869128701287112872128731287412875128761287712878128791288012881128821288312884128851288612887128881288912890128911289212893128941289512896128971289812899129001290112902129031290412905129061290712908129091291012911129121291312914129151291612917129181291912920129211292212923129241292512926129271292812929129301293112932129331293412935129361293712938129391294012941129421294312944129451294612947129481294912950129511295212953129541295512956129571295812959129601296112962129631296412965129661296712968129691297012971129721297312974129751297612977129781297912980129811298212983129841298512986129871298812989129901299112992129931299412995129961299712998129991300013001130021300313004130051300613007130081300913010130111301213013130141301513016130171301813019130201302113022130231302413025130261302713028130291303013031130321303313034130351303613037130381303913040130411304213043130441304513046130471304813049130501305113052130531305413055130561305713058130591306013061130621306313064130651306613067130681306913070130711307213073130741307513076130771307813079130801308113082130831308413085130861308713088130891309013091130921309313094130951309613097130981309913100131011310213103131041310513106131071310813109131101311113112131131311413115131161311713118131191312013121131221312313124131251312613127131281312913130131311313213133131341313513136131371313813139131401314113142131431314413145131461314713148131491315013151131521315313154131551315613157131581315913160131611316213163131641316513166131671316813169131701317113172131731317413175131761317713178131791318013181131821318313184131851318613187131881318913190131911319213193131941319513196131971319813199132001320113202132031320413205132061320713208132091321013211132121321313214132151321613217132181321913220132211322213223132241322513226132271322813229132301323113232132331323413235132361323713238132391324013241132421324313244132451324613247132481324913250132511325213253132541325513256132571325813259132601326113262132631326413265132661326713268132691327013271132721327313274132751327613277132781327913280132811328213283132841328513286132871328813289132901329113292132931329413295132961329713298132991330013301133021330313304133051330613307133081330913310133111331213313133141331513316133171331813319133201332113322133231332413325133261332713328133291333013331133321333313334133351333613337133381333913340133411334213343133441334513346133471334813349133501335113352133531335413355133561335713358133591336013361133621336313364133651336613367133681336913370133711337213373133741337513376133771337813379133801338113382133831338413385133861338713388133891339013391133921339313394133951339613397133981339913400134011340213403134041340513406134071340813409134101341113412134131341413415134161341713418134191342013421134221342313424134251342613427134281342913430134311343213433134341343513436134371343813439134401344113442134431344413445134461344713448134491345013451134521345313454134551345613457134581345913460134611346213463134641346513466134671346813469134701347113472134731347413475134761347713478134791348013481134821348313484134851348613487134881348913490134911349213493134941349513496134971349813499135001350113502135031350413505135061350713508135091351013511135121351313514135151351613517135181351913520135211352213523135241352513526135271352813529135301353113532135331353413535135361353713538135391354013541135421354313544135451354613547135481354913550135511355213553135541355513556135571355813559135601356113562135631356413565135661356713568135691357013571135721357313574135751357613577135781357913580135811358213583135841358513586135871358813589135901359113592135931359413595135961359713598135991360013601136021360313604136051360613607136081360913610136111361213613136141361513616136171361813619136201362113622136231362413625136261362713628136291363013631136321363313634136351363613637136381363913640136411364213643136441364513646136471364813649136501365113652136531365413655136561365713658136591366013661136621366313664136651366613667136681366913670136711367213673136741367513676136771367813679136801368113682136831368413685136861368713688136891369013691136921369313694136951369613697136981369913700137011370213703137041370513706137071370813709137101371113712137131371413715137161371713718137191372013721137221372313724137251372613727137281372913730137311373213733137341373513736137371373813739137401374113742137431374413745137461374713748137491375013751137521375313754137551375613757137581375913760137611376213763137641376513766137671376813769137701377113772137731377413775137761377713778137791378013781137821378313784137851378613787137881378913790137911379213793137941379513796137971379813799138001380113802138031380413805138061380713808138091381013811138121381313814138151381613817138181381913820138211382213823138241382513826138271382813829138301383113832138331383413835138361383713838138391384013841138421384313844138451384613847138481384913850138511385213853138541385513856138571385813859138601386113862138631386413865138661386713868138691387013871138721387313874138751387613877138781387913880138811388213883138841388513886138871388813889138901389113892138931389413895138961389713898138991390013901139021390313904139051390613907139081390913910139111391213913139141391513916139171391813919139201392113922139231392413925139261392713928139291393013931139321393313934139351393613937139381393913940139411394213943139441394513946139471394813949139501395113952139531395413955139561395713958139591396013961139621396313964139651396613967139681396913970139711397213973139741397513976139771397813979139801398113982139831398413985139861398713988139891399013991139921399313994139951399613997139981399914000140011400214003140041400514006140071400814009140101401114012140131401414015140161401714018140191402014021140221402314024140251402614027140281402914030140311403214033140341403514036140371403814039140401404114042140431404414045140461404714048140491405014051140521405314054140551405614057140581405914060140611406214063140641406514066140671406814069140701407114072140731407414075140761407714078140791408014081140821408314084140851408614087140881408914090140911409214093140941409514096140971409814099141001410114102141031410414105141061410714108141091411014111141121411314114141151411614117141181411914120141211412214123141241412514126141271412814129141301413114132141331413414135141361413714138141391414014141141421414314144141451414614147141481414914150141511415214153141541415514156141571415814159141601416114162141631416414165141661416714168141691417014171141721417314174141751417614177141781417914180141811418214183141841418514186141871418814189141901419114192141931419414195141961419714198141991420014201142021420314204142051420614207142081420914210142111421214213142141421514216142171421814219142201422114222142231422414225142261422714228142291423014231142321423314234142351423614237142381423914240142411424214243142441424514246142471424814249142501425114252142531425414255142561425714258142591426014261142621426314264142651426614267142681426914270142711427214273142741427514276142771427814279142801428114282142831428414285142861428714288142891429014291142921429314294142951429614297142981429914300143011430214303143041430514306143071430814309143101431114312143131431414315143161431714318143191432014321143221432314324143251432614327143281432914330143311433214333143341433514336143371433814339143401434114342143431434414345143461434714348143491435014351143521435314354143551435614357143581435914360143611436214363143641436514366143671436814369143701437114372143731437414375143761437714378143791438014381143821438314384143851438614387143881438914390143911439214393143941439514396143971439814399144001440114402144031440414405144061440714408144091441014411144121441314414144151441614417144181441914420144211442214423144241442514426144271442814429144301443114432144331443414435144361443714438144391444014441144421444314444144451444614447144481444914450144511445214453144541445514456144571445814459144601446114462144631446414465144661446714468144691447014471144721447314474144751447614477144781447914480144811448214483144841448514486144871448814489144901449114492144931449414495144961449714498144991450014501145021450314504145051450614507145081450914510145111451214513145141451514516145171451814519145201452114522145231452414525145261452714528145291453014531145321453314534145351453614537145381453914540145411454214543145441454514546145471454814549145501455114552145531455414555145561455714558145591456014561145621456314564145651456614567145681456914570145711457214573145741457514576145771457814579145801458114582145831458414585145861458714588145891459014591145921459314594145951459614597145981459914600146011460214603146041460514606146071460814609146101461114612146131461414615146161461714618146191462014621146221462314624146251462614627146281462914630146311463214633146341463514636146371463814639146401464114642146431464414645146461464714648146491465014651146521465314654146551465614657146581465914660146611466214663146641466514666146671466814669146701467114672146731467414675146761467714678146791468014681146821468314684146851468614687146881468914690146911469214693146941469514696146971469814699147001470114702147031470414705147061470714708147091471014711147121471314714147151471614717147181471914720147211472214723147241472514726147271472814729147301473114732147331473414735147361473714738147391474014741147421474314744147451474614747147481474914750147511475214753147541475514756147571475814759147601476114762147631476414765147661476714768147691477014771147721477314774147751477614777147781477914780147811478214783147841478514786147871478814789147901479114792147931479414795147961479714798147991480014801148021480314804148051480614807148081480914810148111481214813148141481514816148171481814819148201482114822148231482414825148261482714828148291483014831148321483314834148351483614837148381483914840148411484214843148441484514846148471484814849148501485114852148531485414855148561485714858148591486014861148621486314864148651486614867148681486914870148711487214873148741487514876148771487814879148801488114882148831488414885148861488714888148891489014891148921489314894148951489614897148981489914900149011490214903149041490514906149071490814909149101491114912149131491414915149161491714918149191492014921149221492314924149251492614927149281492914930149311493214933149341493514936149371493814939149401494114942149431494414945149461494714948149491495014951149521495314954149551495614957149581495914960149611496214963149641496514966149671496814969149701497114972149731497414975149761497714978149791498014981149821498314984149851498614987149881498914990149911499214993149941499514996149971499814999150001500115002150031500415005150061500715008150091501015011150121501315014150151501615017150181501915020150211502215023150241502515026150271502815029150301503115032150331503415035150361503715038150391504015041150421504315044150451504615047150481504915050150511505215053150541505515056150571505815059150601506115062150631506415065150661506715068150691507015071150721507315074150751507615077150781507915080150811508215083150841508515086150871508815089150901509115092150931509415095150961509715098150991510015101151021510315104151051510615107151081510915110151111511215113151141511515116151171511815119151201512115122151231512415125151261512715128151291513015131151321513315134151351513615137151381513915140151411514215143151441514515146151471514815149151501515115152151531515415155151561515715158151591516015161151621516315164151651516615167151681516915170151711517215173151741517515176151771517815179151801518115182151831518415185151861518715188151891519015191151921519315194151951519615197151981519915200152011520215203152041520515206152071520815209152101521115212152131521415215152161521715218152191522015221152221522315224152251522615227152281522915230152311523215233152341523515236152371523815239152401524115242152431524415245152461524715248152491525015251152521525315254152551525615257152581525915260152611526215263152641526515266152671526815269152701527115272152731527415275152761527715278152791528015281152821528315284152851528615287152881528915290152911529215293152941529515296152971529815299153001530115302153031530415305153061530715308153091531015311153121531315314153151531615317153181531915320153211532215323153241532515326153271532815329153301533115332153331533415335153361533715338153391534015341153421534315344153451534615347153481534915350153511535215353153541535515356153571535815359153601536115362153631536415365153661536715368153691537015371153721537315374153751537615377153781537915380153811538215383153841538515386153871538815389153901539115392153931539415395153961539715398153991540015401154021540315404154051540615407154081540915410154111541215413154141541515416154171541815419154201542115422154231542415425154261542715428154291543015431154321543315434154351543615437154381543915440154411544215443154441544515446154471544815449154501545115452154531545415455154561545715458154591546015461154621546315464154651546615467154681546915470154711547215473154741547515476154771547815479154801548115482154831548415485154861548715488154891549015491154921549315494154951549615497154981549915500155011550215503155041550515506155071550815509155101551115512155131551415515155161551715518155191552015521155221552315524155251552615527155281552915530155311553215533155341553515536155371553815539155401554115542155431554415545155461554715548155491555015551155521555315554155551555615557155581555915560155611556215563155641556515566155671556815569155701557115572155731557415575155761557715578155791558015581155821558315584155851558615587155881558915590155911559215593155941559515596155971559815599156001560115602156031560415605156061560715608156091561015611156121561315614156151561615617156181561915620156211562215623156241562515626156271562815629156301563115632156331563415635156361563715638156391564015641156421564315644156451564615647156481564915650156511565215653156541565515656156571565815659156601566115662156631566415665156661566715668156691567015671156721567315674156751567615677156781567915680156811568215683156841568515686156871568815689156901569115692156931569415695156961569715698156991570015701157021570315704157051570615707157081570915710157111571215713157141571515716157171571815719157201572115722157231572415725157261572715728157291573015731157321573315734157351573615737157381573915740157411574215743157441574515746157471574815749157501575115752157531575415755157561575715758157591576015761157621576315764157651576615767157681576915770157711577215773157741577515776157771577815779157801578115782157831578415785157861578715788157891579015791157921579315794157951579615797157981579915800158011580215803158041580515806158071580815809158101581115812158131581415815158161581715818158191582015821158221582315824158251582615827158281582915830158311583215833158341583515836158371583815839158401584115842158431584415845158461584715848158491585015851158521585315854158551585615857158581585915860158611586215863158641586515866158671586815869158701587115872158731587415875158761587715878158791588015881158821588315884158851588615887158881588915890158911589215893158941589515896158971589815899159001590115902159031590415905159061590715908159091591015911159121591315914159151591615917159181591915920159211592215923159241592515926159271592815929159301593115932159331593415935159361593715938159391594015941159421594315944159451594615947159481594915950159511595215953159541595515956159571595815959159601596115962159631596415965159661596715968159691597015971159721597315974159751597615977159781597915980159811598215983159841598515986159871598815989159901599115992159931599415995159961599715998159991600016001160021600316004160051600616007160081600916010160111601216013160141601516016160171601816019160201602116022160231602416025160261602716028160291603016031160321603316034160351603616037160381603916040160411604216043160441604516046160471604816049160501605116052160531605416055160561605716058160591606016061160621606316064160651606616067160681606916070160711607216073160741607516076160771607816079160801608116082160831608416085160861608716088160891609016091160921609316094160951609616097160981609916100161011610216103161041610516106161071610816109161101611116112161131611416115161161611716118161191612016121161221612316124161251612616127161281612916130161311613216133161341613516136161371613816139161401614116142161431614416145161461614716148161491615016151161521615316154161551615616157161581615916160161611616216163161641616516166161671616816169161701617116172161731617416175161761617716178161791618016181161821618316184161851618616187161881618916190161911619216193161941619516196161971619816199162001620116202162031620416205162061620716208162091621016211162121621316214162151621616217162181621916220162211622216223162241622516226162271622816229162301623116232162331623416235162361623716238162391624016241162421624316244162451624616247162481624916250162511625216253162541625516256162571625816259162601626116262162631626416265162661626716268162691627016271162721627316274162751627616277162781627916280162811628216283162841628516286162871628816289162901629116292162931629416295162961629716298162991630016301163021630316304163051630616307163081630916310163111631216313163141631516316163171631816319163201632116322163231632416325163261632716328163291633016331163321633316334163351633616337163381633916340163411634216343163441634516346163471634816349163501635116352163531635416355163561635716358163591636016361163621636316364163651636616367163681636916370163711637216373163741637516376163771637816379163801638116382163831638416385163861638716388163891639016391163921639316394163951639616397163981639916400164011640216403164041640516406164071640816409164101641116412164131641416415164161641716418164191642016421164221642316424164251642616427164281642916430164311643216433164341643516436164371643816439164401644116442164431644416445164461644716448164491645016451164521645316454164551645616457164581645916460164611646216463164641646516466164671646816469164701647116472164731647416475164761647716478164791648016481164821648316484164851648616487164881648916490164911649216493164941649516496164971649816499165001650116502165031650416505165061650716508165091651016511165121651316514165151651616517165181651916520165211652216523165241652516526165271652816529165301653116532165331653416535165361653716538165391654016541165421654316544165451654616547165481654916550165511655216553165541655516556165571655816559165601656116562165631656416565165661656716568165691657016571165721657316574165751657616577165781657916580165811658216583165841658516586165871658816589165901659116592165931659416595165961659716598165991660016601166021660316604166051660616607166081660916610166111661216613166141661516616166171661816619166201662116622166231662416625166261662716628166291663016631166321663316634166351663616637166381663916640166411664216643166441664516646166471664816649166501665116652166531665416655166561665716658166591666016661166621666316664166651666616667166681666916670166711667216673166741667516676166771667816679166801668116682166831668416685166861668716688166891669016691166921669316694166951669616697166981669916700167011670216703167041670516706167071670816709167101671116712167131671416715167161671716718167191672016721167221672316724167251672616727167281672916730167311673216733167341673516736167371673816739167401674116742167431674416745167461674716748167491675016751167521675316754167551675616757167581675916760167611676216763167641676516766167671676816769167701677116772167731677416775167761677716778167791678016781167821678316784167851678616787167881678916790167911679216793167941679516796167971679816799168001680116802168031680416805168061680716808168091681016811168121681316814168151681616817168181681916820168211682216823168241682516826168271682816829168301683116832168331683416835168361683716838168391684016841168421684316844168451684616847168481684916850168511685216853168541685516856168571685816859168601686116862168631686416865168661686716868168691687016871168721687316874168751687616877168781687916880168811688216883168841688516886168871688816889168901689116892168931689416895168961689716898168991690016901169021690316904169051690616907169081690916910169111691216913169141691516916169171691816919169201692116922169231692416925169261692716928169291693016931169321693316934169351693616937169381693916940169411694216943169441694516946169471694816949169501695116952169531695416955169561695716958169591696016961169621696316964169651696616967169681696916970169711697216973169741697516976169771697816979169801698116982169831698416985169861698716988169891699016991169921699316994169951699616997169981699917000170011700217003170041700517006170071700817009170101701117012170131701417015170161701717018170191702017021170221702317024170251702617027170281702917030170311703217033170341703517036170371703817039170401704117042170431704417045170461704717048170491705017051170521705317054170551705617057170581705917060170611706217063170641706517066170671706817069170701707117072170731707417075170761707717078170791708017081170821708317084170851708617087170881708917090170911709217093170941709517096170971709817099171001710117102171031710417105171061710717108171091711017111171121711317114171151711617117171181711917120171211712217123171241712517126171271712817129171301713117132171331713417135171361713717138171391714017141171421714317144171451714617147171481714917150171511715217153171541715517156171571715817159171601716117162171631716417165171661716717168171691717017171171721717317174171751717617177171781717917180171811718217183171841718517186171871718817189171901719117192171931719417195171961719717198171991720017201172021720317204172051720617207172081720917210172111721217213172141721517216172171721817219172201722117222172231722417225172261722717228172291723017231172321723317234172351723617237172381723917240172411724217243172441724517246172471724817249172501725117252172531725417255172561725717258172591726017261172621726317264172651726617267172681726917270172711727217273172741727517276172771727817279172801728117282172831728417285172861728717288172891729017291172921729317294172951729617297172981729917300173011730217303173041730517306173071730817309173101731117312173131731417315173161731717318173191732017321173221732317324173251732617327173281732917330173311733217333173341733517336173371733817339173401734117342173431734417345173461734717348173491735017351173521735317354173551735617357173581735917360173611736217363173641736517366173671736817369173701737117372173731737417375173761737717378173791738017381173821738317384173851738617387173881738917390173911739217393173941739517396173971739817399174001740117402174031740417405174061740717408174091741017411174121741317414174151741617417174181741917420174211742217423174241742517426174271742817429174301743117432174331743417435174361743717438174391744017441174421744317444174451744617447174481744917450174511745217453174541745517456174571745817459174601746117462174631746417465174661746717468174691747017471174721747317474174751747617477174781747917480174811748217483174841748517486174871748817489174901749117492174931749417495174961749717498174991750017501175021750317504175051750617507175081750917510175111751217513175141751517516175171751817519175201752117522175231752417525175261752717528175291753017531175321753317534175351753617537175381753917540175411754217543175441754517546175471754817549175501755117552175531755417555175561755717558175591756017561175621756317564175651756617567175681756917570175711757217573175741757517576175771757817579175801758117582175831758417585175861758717588175891759017591175921759317594175951759617597175981759917600176011760217603176041760517606176071760817609176101761117612176131761417615176161761717618176191762017621176221762317624176251762617627176281762917630176311763217633176341763517636176371763817639176401764117642176431764417645176461764717648176491765017651176521765317654176551765617657176581765917660176611766217663176641766517666176671766817669176701767117672176731767417675176761767717678176791768017681176821768317684176851768617687176881768917690176911769217693176941769517696176971769817699177001770117702177031770417705177061770717708177091771017711177121771317714177151771617717177181771917720177211772217723177241772517726177271772817729177301773117732177331773417735177361773717738177391774017741177421774317744177451774617747177481774917750177511775217753177541775517756177571775817759177601776117762177631776417765177661776717768177691777017771177721777317774177751777617777177781777917780177811778217783177841778517786177871778817789177901779117792177931779417795177961779717798177991780017801178021780317804178051780617807178081780917810178111781217813178141781517816178171781817819178201782117822178231782417825178261782717828178291783017831178321783317834178351783617837178381783917840178411784217843178441784517846178471784817849178501785117852178531785417855178561785717858178591786017861178621786317864178651786617867178681786917870178711787217873178741787517876178771787817879178801788117882178831788417885178861788717888178891789017891178921789317894178951789617897178981789917900179011790217903179041790517906179071790817909179101791117912179131791417915179161791717918179191792017921179221792317924179251792617927179281792917930179311793217933179341793517936179371793817939179401794117942179431794417945179461794717948179491795017951179521795317954179551795617957179581795917960179611796217963179641796517966179671796817969179701797117972179731797417975179761797717978179791798017981179821798317984179851798617987179881798917990179911799217993179941799517996179971799817999180001800118002180031800418005180061800718008180091801018011180121801318014180151801618017180181801918020180211802218023180241802518026180271802818029180301803118032180331803418035180361803718038180391804018041180421804318044180451804618047180481804918050180511805218053180541805518056180571805818059180601806118062180631806418065180661806718068180691807018071180721807318074180751807618077180781807918080180811808218083180841808518086180871808818089180901809118092180931809418095180961809718098180991810018101181021810318104181051810618107181081810918110181111811218113181141811518116181171811818119181201812118122181231812418125181261812718128181291813018131181321813318134181351813618137181381813918140181411814218143181441814518146181471814818149181501815118152181531815418155181561815718158181591816018161181621816318164181651816618167181681816918170181711817218173181741817518176181771817818179181801818118182181831818418185181861818718188181891819018191181921819318194181951819618197181981819918200182011820218203182041820518206182071820818209182101821118212182131821418215182161821718218182191822018221182221822318224182251822618227182281822918230182311823218233182341823518236182371823818239182401824118242182431824418245182461824718248182491825018251182521825318254182551825618257182581825918260182611826218263182641826518266182671826818269182701827118272182731827418275182761827718278182791828018281182821828318284182851828618287182881828918290182911829218293182941829518296182971829818299183001830118302183031830418305183061830718308183091831018311183121831318314183151831618317183181831918320183211832218323183241832518326183271832818329183301833118332183331833418335183361833718338183391834018341183421834318344183451834618347183481834918350183511835218353183541835518356183571835818359183601836118362183631836418365183661836718368183691837018371183721837318374183751837618377183781837918380183811838218383183841838518386183871838818389183901839118392183931839418395183961839718398183991840018401184021840318404184051840618407184081840918410184111841218413184141841518416184171841818419184201842118422184231842418425184261842718428184291843018431184321843318434184351843618437184381843918440184411844218443184441844518446184471844818449184501845118452184531845418455184561845718458184591846018461184621846318464184651846618467184681846918470184711847218473184741847518476184771847818479184801848118482184831848418485184861848718488184891849018491184921849318494184951849618497184981849918500185011850218503185041850518506185071850818509185101851118512185131851418515185161851718518185191852018521185221852318524185251852618527185281852918530185311853218533185341853518536185371853818539185401854118542185431854418545185461854718548185491855018551185521855318554185551855618557185581855918560185611856218563185641856518566185671856818569185701857118572185731857418575185761857718578185791858018581185821858318584185851858618587185881858918590185911859218593185941859518596185971859818599186001860118602186031860418605186061860718608186091861018611186121861318614186151861618617186181861918620186211862218623186241862518626186271862818629186301863118632186331863418635186361863718638186391864018641186421864318644186451864618647186481864918650186511865218653186541865518656186571865818659186601866118662186631866418665186661866718668186691867018671186721867318674186751867618677186781867918680186811868218683186841868518686186871868818689186901869118692186931869418695186961869718698186991870018701187021870318704187051870618707187081870918710187111871218713187141871518716187171871818719187201872118722187231872418725187261872718728187291873018731187321873318734187351873618737187381873918740187411874218743187441874518746187471874818749187501875118752187531875418755187561875718758187591876018761187621876318764187651876618767187681876918770187711877218773187741877518776187771877818779187801878118782187831878418785187861878718788187891879018791187921879318794187951879618797187981879918800188011880218803188041880518806188071880818809188101881118812188131881418815188161881718818188191882018821188221882318824188251882618827188281882918830188311883218833188341883518836188371883818839188401884118842188431884418845188461884718848188491885018851188521885318854188551885618857188581885918860188611886218863188641886518866188671886818869188701887118872188731887418875188761887718878188791888018881188821888318884188851888618887188881888918890188911889218893188941889518896188971889818899189001890118902189031890418905189061890718908189091891018911189121891318914189151891618917189181891918920189211892218923189241892518926189271892818929189301893118932189331893418935189361893718938189391894018941189421894318944189451894618947189481894918950189511895218953189541895518956189571895818959189601896118962189631896418965189661896718968189691897018971189721897318974189751897618977189781897918980189811898218983189841898518986189871898818989189901899118992189931899418995189961899718998189991900019001190021900319004190051900619007190081900919010190111901219013190141901519016190171901819019190201902119022190231902419025190261902719028190291903019031190321903319034190351903619037190381903919040190411904219043190441904519046190471904819049190501905119052190531905419055190561905719058190591906019061190621906319064190651906619067190681906919070190711907219073190741907519076190771907819079190801908119082190831908419085190861908719088190891909019091190921909319094190951909619097190981909919100191011910219103191041910519106191071910819109191101911119112191131911419115191161911719118191191912019121191221912319124191251912619127191281912919130191311913219133191341913519136191371913819139191401914119142191431914419145191461914719148191491915019151191521915319154191551915619157191581915919160191611916219163191641916519166191671916819169191701917119172191731917419175191761917719178191791918019181191821918319184191851918619187191881918919190191911919219193191941919519196191971919819199192001920119202192031920419205192061920719208192091921019211192121921319214192151921619217192181921919220192211922219223192241922519226192271922819229192301923119232192331923419235192361923719238192391924019241192421924319244192451924619247192481924919250192511925219253192541925519256192571925819259192601926119262192631926419265192661926719268192691927019271192721927319274192751927619277192781927919280192811928219283192841928519286192871928819289192901929119292192931929419295192961929719298192991930019301193021930319304193051930619307193081930919310193111931219313193141931519316193171931819319193201932119322193231932419325193261932719328193291933019331193321933319334193351933619337193381933919340193411934219343193441934519346193471934819349193501935119352193531935419355193561935719358193591936019361193621936319364193651936619367193681936919370193711937219373193741937519376193771937819379193801938119382193831938419385193861938719388193891939019391193921939319394193951939619397193981939919400194011940219403194041940519406194071940819409194101941119412194131941419415194161941719418194191942019421194221942319424194251942619427194281942919430194311943219433194341943519436194371943819439194401944119442194431944419445194461944719448194491945019451194521945319454194551945619457194581945919460194611946219463194641946519466194671946819469194701947119472194731947419475194761947719478194791948019481194821948319484194851948619487194881948919490194911949219493194941949519496194971949819499195001950119502195031950419505195061950719508195091951019511195121951319514195151951619517195181951919520195211952219523195241952519526195271952819529195301953119532195331953419535195361953719538195391954019541195421954319544195451954619547195481954919550195511955219553195541955519556195571955819559195601956119562195631956419565195661956719568195691957019571195721957319574195751957619577195781957919580195811958219583195841958519586195871958819589195901959119592195931959419595195961959719598195991960019601196021960319604196051960619607196081960919610196111961219613196141961519616196171961819619196201962119622196231962419625196261962719628196291963019631196321963319634196351963619637196381963919640196411964219643196441964519646196471964819649196501965119652196531965419655196561965719658196591966019661196621966319664196651966619667196681966919670196711967219673196741967519676196771967819679196801968119682196831968419685196861968719688196891969019691196921969319694196951969619697196981969919700197011970219703197041970519706197071970819709197101971119712197131971419715197161971719718197191972019721197221972319724197251972619727197281972919730197311973219733197341973519736197371973819739197401974119742197431974419745197461974719748197491975019751197521975319754197551975619757197581975919760197611976219763197641976519766197671976819769197701977119772197731977419775197761977719778197791978019781197821978319784197851978619787197881978919790197911979219793197941979519796197971979819799198001980119802198031980419805198061980719808198091981019811198121981319814198151981619817198181981919820198211982219823198241982519826198271982819829198301983119832198331983419835198361983719838198391984019841198421984319844198451984619847198481984919850198511985219853198541985519856198571985819859198601986119862198631986419865198661986719868198691987019871198721987319874198751987619877198781987919880198811988219883198841988519886198871988819889198901989119892198931989419895198961989719898198991990019901199021990319904199051990619907199081990919910199111991219913199141991519916199171991819919199201992119922199231992419925199261992719928199291993019931199321993319934199351993619937199381993919940199411994219943199441994519946199471994819949199501995119952199531995419955199561995719958199591996019961199621996319964199651996619967199681996919970199711997219973199741997519976199771997819979199801998119982199831998419985199861998719988199891999019991199921999319994199951999619997199981999920000200012000220003200042000520006200072000820009200102001120012200132001420015200162001720018200192002020021200222002320024200252002620027200282002920030200312003220033200342003520036200372003820039200402004120042200432004420045200462004720048200492005020051200522005320054200552005620057200582005920060200612006220063200642006520066200672006820069200702007120072200732007420075200762007720078200792008020081200822008320084200852008620087200882008920090200912009220093200942009520096200972009820099201002010120102201032010420105201062010720108201092011020111201122011320114201152011620117201182011920120201212012220123201242012520126201272012820129201302013120132201332013420135201362013720138201392014020141201422014320144201452014620147201482014920150201512015220153201542015520156201572015820159201602016120162201632016420165201662016720168201692017020171201722017320174201752017620177201782017920180201812018220183201842018520186201872018820189201902019120192201932019420195201962019720198201992020020201202022020320204202052020620207202082020920210202112021220213202142021520216202172021820219202202022120222202232022420225202262022720228202292023020231202322023320234202352023620237202382023920240202412024220243202442024520246202472024820249202502025120252202532025420255202562025720258202592026020261202622026320264202652026620267202682026920270202712027220273202742027520276202772027820279202802028120282202832028420285202862028720288202892029020291202922029320294202952029620297202982029920300203012030220303203042030520306203072030820309203102031120312203132031420315203162031720318203192032020321203222032320324203252032620327203282032920330203312033220333203342033520336203372033820339203402034120342203432034420345203462034720348203492035020351203522035320354203552035620357203582035920360203612036220363203642036520366203672036820369203702037120372203732037420375203762037720378203792038020381203822038320384203852038620387203882038920390203912039220393203942039520396203972039820399204002040120402204032040420405204062040720408204092041020411204122041320414204152041620417204182041920420204212042220423204242042520426204272042820429204302043120432204332043420435204362043720438204392044020441204422044320444204452044620447204482044920450204512045220453204542045520456204572045820459204602046120462204632046420465204662046720468204692047020471204722047320474204752047620477204782047920480204812048220483204842048520486204872048820489204902049120492204932049420495204962049720498204992050020501205022050320504205052050620507205082050920510205112051220513205142051520516205172051820519205202052120522205232052420525205262052720528205292053020531205322053320534205352053620537205382053920540205412054220543205442054520546205472054820549205502055120552205532055420555205562055720558205592056020561205622056320564205652056620567205682056920570205712057220573205742057520576205772057820579205802058120582205832058420585205862058720588205892059020591205922059320594205952059620597205982059920600206012060220603206042060520606206072060820609206102061120612206132061420615206162061720618206192062020621206222062320624206252062620627206282062920630206312063220633206342063520636206372063820639206402064120642206432064420645206462064720648206492065020651206522065320654206552065620657206582065920660206612066220663206642066520666206672066820669206702067120672206732067420675206762067720678206792068020681206822068320684206852068620687206882068920690206912069220693206942069520696206972069820699207002070120702207032070420705207062070720708207092071020711207122071320714207152071620717207182071920720207212072220723207242072520726207272072820729207302073120732207332073420735207362073720738207392074020741207422074320744207452074620747207482074920750207512075220753207542075520756207572075820759207602076120762207632076420765207662076720768207692077020771207722077320774207752077620777207782077920780207812078220783207842078520786207872078820789207902079120792207932079420795207962079720798207992080020801208022080320804208052080620807208082080920810208112081220813208142081520816208172081820819208202082120822208232082420825208262082720828208292083020831208322083320834208352083620837208382083920840208412084220843208442084520846208472084820849208502085120852208532085420855208562085720858208592086020861208622086320864208652086620867208682086920870208712087220873208742087520876208772087820879208802088120882208832088420885208862088720888208892089020891208922089320894208952089620897208982089920900209012090220903209042090520906209072090820909209102091120912209132091420915209162091720918209192092020921209222092320924209252092620927209282092920930209312093220933209342093520936209372093820939209402094120942209432094420945209462094720948209492095020951209522095320954209552095620957209582095920960209612096220963209642096520966209672096820969209702097120972209732097420975209762097720978209792098020981209822098320984209852098620987209882098920990209912099220993209942099520996209972099820999210002100121002210032100421005210062100721008210092101021011210122101321014210152101621017210182101921020210212102221023210242102521026210272102821029210302103121032210332103421035210362103721038210392104021041210422104321044210452104621047210482104921050210512105221053210542105521056210572105821059210602106121062210632106421065210662106721068210692107021071210722107321074210752107621077210782107921080210812108221083210842108521086210872108821089210902109121092210932109421095210962109721098210992110021101211022110321104211052110621107211082110921110211112111221113211142111521116211172111821119211202112121122211232112421125211262112721128211292113021131211322113321134211352113621137211382113921140211412114221143211442114521146211472114821149211502115121152211532115421155211562115721158211592116021161211622116321164211652116621167211682116921170211712117221173211742117521176211772117821179211802118121182211832118421185211862118721188211892119021191211922119321194211952119621197211982119921200212012120221203212042120521206212072120821209212102121121212212132121421215212162121721218212192122021221212222122321224212252122621227212282122921230212312123221233212342123521236212372123821239212402124121242212432124421245212462124721248212492125021251212522125321254212552125621257212582125921260212612126221263212642126521266212672126821269212702127121272212732127421275212762127721278212792128021281212822128321284212852128621287212882128921290212912129221293212942129521296212972129821299213002130121302213032130421305213062130721308213092131021311213122131321314213152131621317213182131921320213212132221323213242132521326213272132821329213302133121332213332133421335213362133721338213392134021341213422134321344213452134621347213482134921350213512135221353213542135521356213572135821359213602136121362213632136421365213662136721368213692137021371213722137321374213752137621377213782137921380213812138221383213842138521386213872138821389213902139121392213932139421395213962139721398213992140021401214022140321404214052140621407214082140921410214112141221413214142141521416214172141821419214202142121422214232142421425214262142721428214292143021431214322143321434214352143621437214382143921440214412144221443214442144521446214472144821449214502145121452214532145421455214562145721458214592146021461214622146321464214652146621467214682146921470214712147221473214742147521476214772147821479214802148121482214832148421485214862148721488214892149021491214922149321494214952149621497214982149921500215012150221503215042150521506215072150821509215102151121512215132151421515215162151721518215192152021521215222152321524215252152621527215282152921530215312153221533215342153521536215372153821539215402154121542215432154421545215462154721548215492155021551215522155321554215552155621557215582155921560215612156221563215642156521566215672156821569215702157121572215732157421575215762157721578215792158021581215822158321584215852158621587215882158921590215912159221593215942159521596215972159821599216002160121602216032160421605216062160721608216092161021611216122161321614216152161621617216182161921620216212162221623216242162521626216272162821629216302163121632216332163421635216362163721638216392164021641216422164321644216452164621647216482164921650216512165221653216542165521656216572165821659216602166121662216632166421665216662166721668216692167021671216722167321674216752167621677216782167921680216812168221683216842168521686216872168821689216902169121692216932169421695216962169721698216992170021701217022170321704217052170621707217082170921710217112171221713217142171521716217172171821719217202172121722217232172421725217262172721728217292173021731217322173321734217352173621737217382173921740217412174221743217442174521746217472174821749217502175121752217532175421755217562175721758217592176021761217622176321764217652176621767217682176921770217712177221773217742177521776217772177821779217802178121782217832178421785217862178721788217892179021791217922179321794217952179621797217982179921800218012180221803218042180521806218072180821809218102181121812218132181421815218162181721818218192182021821218222182321824218252182621827218282182921830218312183221833218342183521836218372183821839218402184121842218432184421845218462184721848218492185021851218522185321854218552185621857218582185921860218612186221863218642186521866218672186821869218702187121872218732187421875218762187721878218792188021881218822188321884218852188621887218882188921890218912189221893218942189521896218972189821899219002190121902219032190421905219062190721908219092191021911219122191321914219152191621917219182191921920219212192221923219242192521926219272192821929219302193121932219332193421935219362193721938219392194021941219422194321944219452194621947219482194921950219512195221953219542195521956219572195821959219602196121962219632196421965219662196721968219692197021971219722197321974219752197621977219782197921980219812198221983219842198521986219872198821989219902199121992219932199421995219962199721998219992200022001220022200322004220052200622007220082200922010220112201222013220142201522016220172201822019220202202122022220232202422025220262202722028220292203022031220322203322034220352203622037220382203922040220412204222043220442204522046220472204822049220502205122052220532205422055220562205722058220592206022061220622206322064220652206622067220682206922070220712207222073220742207522076220772207822079220802208122082220832208422085220862208722088220892209022091220922209322094220952209622097220982209922100221012210222103221042210522106221072210822109221102211122112221132211422115221162211722118221192212022121221222212322124221252212622127221282212922130221312213222133221342213522136221372213822139221402214122142221432214422145221462214722148221492215022151221522215322154221552215622157221582215922160221612216222163221642216522166221672216822169221702217122172221732217422175221762217722178221792218022181221822218322184221852218622187221882218922190221912219222193221942219522196221972219822199222002220122202222032220422205222062220722208222092221022211222122221322214222152221622217222182221922220222212222222223222242222522226222272222822229222302223122232222332223422235222362223722238222392224022241222422224322244222452224622247222482224922250222512225222253222542225522256222572225822259222602226122262222632226422265222662226722268222692227022271222722227322274222752227622277222782227922280222812228222283222842228522286222872228822289222902229122292222932229422295222962229722298222992230022301223022230322304223052230622307223082230922310223112231222313223142231522316223172231822319223202232122322223232232422325223262232722328223292233022331223322233322334223352233622337223382233922340223412234222343223442234522346223472234822349223502235122352223532235422355223562235722358223592236022361223622236322364223652236622367223682236922370223712237222373223742237522376223772237822379223802238122382223832238422385223862238722388223892239022391223922239322394223952239622397223982239922400224012240222403224042240522406224072240822409224102241122412224132241422415224162241722418224192242022421224222242322424224252242622427224282242922430224312243222433224342243522436224372243822439224402244122442224432244422445224462244722448224492245022451224522245322454224552245622457224582245922460224612246222463224642246522466224672246822469224702247122472224732247422475224762247722478224792248022481224822248322484224852248622487224882248922490224912249222493224942249522496224972249822499225002250122502225032250422505225062250722508225092251022511225122251322514225152251622517225182251922520225212252222523225242252522526225272252822529225302253122532225332253422535225362253722538225392254022541225422254322544225452254622547225482254922550225512255222553225542255522556225572255822559225602256122562225632256422565225662256722568225692257022571225722257322574225752257622577225782257922580225812258222583225842258522586225872258822589225902259122592225932259422595225962259722598225992260022601226022260322604226052260622607226082260922610226112261222613226142261522616226172261822619226202262122622226232262422625226262262722628226292263022631226322263322634226352263622637226382263922640226412264222643226442264522646226472264822649226502265122652226532265422655226562265722658226592266022661226622266322664226652266622667226682266922670226712267222673226742267522676226772267822679226802268122682226832268422685226862268722688226892269022691226922269322694226952269622697226982269922700227012270222703227042270522706227072270822709227102271122712227132271422715227162271722718227192272022721227222272322724227252272622727227282272922730227312273222733227342273522736227372273822739227402274122742227432274422745227462274722748227492275022751227522275322754227552275622757227582275922760227612276222763227642276522766227672276822769227702277122772227732277422775227762277722778227792278022781227822278322784227852278622787227882278922790227912279222793227942279522796227972279822799228002280122802228032280422805228062280722808228092281022811228122281322814228152281622817228182281922820228212282222823228242282522826228272282822829228302283122832228332283422835228362283722838228392284022841228422284322844228452284622847228482284922850228512285222853228542285522856228572285822859228602286122862228632286422865228662286722868228692287022871228722287322874228752287622877228782287922880228812288222883228842288522886228872288822889228902289122892228932289422895228962289722898228992290022901229022290322904229052290622907229082290922910229112291222913229142291522916229172291822919229202292122922229232292422925229262292722928229292293022931229322293322934229352293622937229382293922940229412294222943229442294522946229472294822949229502295122952229532295422955229562295722958229592296022961229622296322964229652296622967229682296922970229712297222973229742297522976229772297822979229802298122982229832298422985229862298722988229892299022991229922299322994229952299622997229982299923000230012300223003230042300523006230072300823009230102301123012230132301423015230162301723018230192302023021230222302323024230252302623027230282302923030230312303223033230342303523036230372303823039230402304123042230432304423045230462304723048230492305023051230522305323054230552305623057230582305923060230612306223063230642306523066230672306823069230702307123072230732307423075230762307723078230792308023081230822308323084230852308623087230882308923090230912309223093230942309523096230972309823099231002310123102231032310423105231062310723108231092311023111231122311323114231152311623117231182311923120231212312223123231242312523126231272312823129231302313123132231332313423135231362313723138231392314023141231422314323144231452314623147231482314923150231512315223153231542315523156231572315823159231602316123162231632316423165231662316723168231692317023171231722317323174231752317623177231782317923180231812318223183231842318523186231872318823189231902319123192231932319423195231962319723198231992320023201232022320323204232052320623207232082320923210232112321223213232142321523216232172321823219232202322123222232232322423225232262322723228232292323023231232322323323234232352323623237232382323923240232412324223243232442324523246232472324823249232502325123252232532325423255232562325723258232592326023261232622326323264232652326623267232682326923270232712327223273232742327523276232772327823279232802328123282232832328423285232862328723288232892329023291232922329323294232952329623297232982329923300233012330223303233042330523306233072330823309233102331123312233132331423315233162331723318233192332023321233222332323324233252332623327233282332923330233312333223333233342333523336233372333823339233402334123342233432334423345233462334723348233492335023351233522335323354233552335623357233582335923360233612336223363233642336523366233672336823369233702337123372233732337423375233762337723378233792338023381233822338323384233852338623387233882338923390233912339223393233942339523396233972339823399234002340123402234032340423405234062340723408234092341023411234122341323414234152341623417234182341923420234212342223423234242342523426234272342823429234302343123432234332343423435234362343723438234392344023441234422344323444234452344623447234482344923450234512345223453234542345523456234572345823459234602346123462234632346423465234662346723468234692347023471234722347323474234752347623477234782347923480234812348223483234842348523486234872348823489234902349123492234932349423495234962349723498234992350023501235022350323504235052350623507235082350923510235112351223513235142351523516235172351823519235202352123522235232352423525235262352723528235292353023531235322353323534235352353623537235382353923540235412354223543235442354523546235472354823549235502355123552235532355423555235562355723558235592356023561235622356323564235652356623567235682356923570235712357223573235742357523576235772357823579235802358123582235832358423585235862358723588235892359023591235922359323594235952359623597235982359923600236012360223603236042360523606236072360823609236102361123612236132361423615236162361723618236192362023621236222362323624236252362623627236282362923630236312363223633236342363523636236372363823639236402364123642236432364423645236462364723648236492365023651236522365323654236552365623657236582365923660236612366223663236642366523666236672366823669236702367123672236732367423675236762367723678236792368023681236822368323684236852368623687236882368923690236912369223693236942369523696236972369823699237002370123702237032370423705237062370723708237092371023711237122371323714237152371623717237182371923720237212372223723237242372523726237272372823729237302373123732237332373423735237362373723738237392374023741237422374323744237452374623747237482374923750237512375223753237542375523756237572375823759237602376123762237632376423765237662376723768237692377023771237722377323774237752377623777237782377923780237812378223783237842378523786237872378823789237902379123792237932379423795237962379723798237992380023801238022380323804238052380623807238082380923810238112381223813238142381523816238172381823819238202382123822238232382423825238262382723828238292383023831238322383323834238352383623837238382383923840238412384223843238442384523846238472384823849238502385123852238532385423855238562385723858238592386023861238622386323864238652386623867238682386923870238712387223873238742387523876238772387823879238802388123882238832388423885238862388723888238892389023891238922389323894238952389623897238982389923900239012390223903239042390523906239072390823909239102391123912239132391423915239162391723918239192392023921239222392323924239252392623927239282392923930239312393223933239342393523936239372393823939239402394123942239432394423945239462394723948239492395023951239522395323954239552395623957239582395923960239612396223963239642396523966239672396823969239702397123972239732397423975239762397723978239792398023981239822398323984239852398623987239882398923990239912399223993239942399523996239972399823999240002400124002240032400424005240062400724008240092401024011240122401324014240152401624017240182401924020240212402224023240242402524026240272402824029240302403124032240332403424035240362403724038240392404024041240422404324044240452404624047240482404924050240512405224053240542405524056240572405824059240602406124062240632406424065240662406724068240692407024071240722407324074240752407624077240782407924080240812408224083240842408524086240872408824089240902409124092240932409424095240962409724098240992410024101241022410324104241052410624107241082410924110241112411224113241142411524116241172411824119241202412124122241232412424125241262412724128241292413024131241322413324134241352413624137241382413924140241412414224143241442414524146241472414824149241502415124152241532415424155241562415724158241592416024161241622416324164241652416624167241682416924170241712417224173241742417524176241772417824179241802418124182241832418424185241862418724188241892419024191241922419324194241952419624197241982419924200242012420224203242042420524206242072420824209242102421124212242132421424215242162421724218242192422024221242222422324224242252422624227242282422924230242312423224233242342423524236242372423824239242402424124242242432424424245242462424724248242492425024251242522425324254242552425624257242582425924260242612426224263242642426524266242672426824269242702427124272242732427424275242762427724278242792428024281242822428324284242852428624287242882428924290242912429224293242942429524296242972429824299243002430124302243032430424305243062430724308243092431024311243122431324314243152431624317243182431924320243212432224323243242432524326243272432824329243302433124332243332433424335243362433724338243392434024341243422434324344243452434624347243482434924350243512435224353243542435524356243572435824359243602436124362243632436424365243662436724368243692437024371243722437324374243752437624377243782437924380243812438224383243842438524386243872438824389243902439124392243932439424395243962439724398243992440024401244022440324404244052440624407244082440924410244112441224413244142441524416244172441824419244202442124422244232442424425244262442724428244292443024431244322443324434244352443624437244382443924440244412444224443244442444524446244472444824449244502445124452244532445424455244562445724458244592446024461244622446324464244652446624467244682446924470244712447224473244742447524476244772447824479244802448124482244832448424485244862448724488244892449024491244922449324494244952449624497244982449924500245012450224503245042450524506245072450824509245102451124512245132451424515245162451724518245192452024521245222452324524245252452624527245282452924530245312453224533245342453524536245372453824539245402454124542245432454424545245462454724548245492455024551245522455324554245552455624557245582455924560245612456224563245642456524566245672456824569245702457124572245732457424575245762457724578245792458024581245822458324584245852458624587245882458924590245912459224593245942459524596245972459824599246002460124602246032460424605246062460724608246092461024611246122461324614246152461624617246182461924620246212462224623246242462524626246272462824629246302463124632246332463424635246362463724638246392464024641246422464324644246452464624647246482464924650246512465224653246542465524656246572465824659246602466124662246632466424665246662466724668246692467024671246722467324674246752467624677246782467924680246812468224683246842468524686246872468824689246902469124692246932469424695246962469724698246992470024701247022470324704247052470624707247082470924710247112471224713247142471524716247172471824719247202472124722247232472424725247262472724728247292473024731247322473324734247352473624737247382473924740247412474224743247442474524746247472474824749247502475124752247532475424755247562475724758247592476024761247622476324764247652476624767247682476924770247712477224773247742477524776247772477824779247802478124782247832478424785247862478724788247892479024791247922479324794247952479624797247982479924800248012480224803248042480524806248072480824809248102481124812248132481424815248162481724818248192482024821248222482324824248252482624827248282482924830248312483224833248342483524836248372483824839248402484124842248432484424845248462484724848248492485024851248522485324854248552485624857248582485924860248612486224863248642486524866248672486824869248702487124872248732487424875248762487724878248792488024881248822488324884248852488624887248882488924890248912489224893248942489524896248972489824899249002490124902249032490424905249062490724908249092491024911249122491324914249152491624917249182491924920249212492224923249242492524926249272492824929249302493124932249332493424935249362493724938249392494024941249422494324944249452494624947249482494924950249512495224953249542495524956249572495824959249602496124962249632496424965249662496724968249692497024971249722497324974249752497624977249782497924980249812498224983249842498524986249872498824989249902499124992249932499424995249962499724998249992500025001250022500325004250052500625007250082500925010250112501225013250142501525016250172501825019250202502125022250232502425025250262502725028250292503025031250322503325034250352503625037250382503925040250412504225043250442504525046250472504825049250502505125052250532505425055250562505725058250592506025061250622506325064250652506625067250682506925070250712507225073250742507525076250772507825079250802508125082250832508425085250862508725088250892509025091250922509325094250952509625097250982509925100251012510225103251042510525106251072510825109251102511125112251132511425115251162511725118251192512025121251222512325124251252512625127251282512925130251312513225133251342513525136251372513825139251402514125142251432514425145251462514725148251492515025151251522515325154251552515625157251582515925160251612516225163251642516525166251672516825169251702517125172251732517425175251762517725178251792518025181251822518325184251852518625187251882518925190251912519225193251942519525196251972519825199252002520125202252032520425205252062520725208252092521025211252122521325214252152521625217252182521925220252212522225223252242522525226252272522825229252302523125232252332523425235252362523725238252392524025241252422524325244252452524625247252482524925250252512525225253252542525525256252572525825259252602526125262252632526425265252662526725268252692527025271252722527325274252752527625277252782527925280252812528225283252842528525286252872528825289252902529125292252932529425295252962529725298252992530025301253022530325304253052530625307253082530925310253112531225313253142531525316253172531825319253202532125322253232532425325253262532725328253292533025331253322533325334253352533625337253382533925340253412534225343253442534525346253472534825349253502535125352253532535425355253562535725358253592536025361253622536325364253652536625367253682536925370253712537225373253742537525376253772537825379253802538125382253832538425385253862538725388253892539025391253922539325394253952539625397253982539925400254012540225403254042540525406254072540825409254102541125412254132541425415254162541725418254192542025421254222542325424254252542625427254282542925430254312543225433254342543525436254372543825439254402544125442254432544425445254462544725448254492545025451254522545325454254552545625457254582545925460254612546225463254642546525466254672546825469254702547125472254732547425475254762547725478254792548025481254822548325484254852548625487254882548925490254912549225493254942549525496254972549825499255002550125502255032550425505255062550725508255092551025511255122551325514255152551625517255182551925520255212552225523255242552525526255272552825529255302553125532255332553425535255362553725538255392554025541255422554325544255452554625547255482554925550255512555225553255542555525556255572555825559255602556125562255632556425565255662556725568255692557025571255722557325574255752557625577255782557925580255812558225583255842558525586255872558825589255902559125592255932559425595255962559725598255992560025601256022560325604256052560625607256082560925610256112561225613256142561525616256172561825619256202562125622256232562425625256262562725628256292563025631256322563325634256352563625637256382563925640256412564225643256442564525646256472564825649256502565125652256532565425655256562565725658256592566025661256622566325664256652566625667256682566925670256712567225673256742567525676256772567825679256802568125682256832568425685256862568725688256892569025691256922569325694256952569625697256982569925700257012570225703257042570525706257072570825709257102571125712257132571425715257162571725718257192572025721257222572325724257252572625727257282572925730257312573225733257342573525736257372573825739257402574125742257432574425745257462574725748257492575025751257522575325754257552575625757257582575925760257612576225763257642576525766257672576825769257702577125772257732577425775257762577725778257792578025781257822578325784257852578625787257882578925790257912579225793257942579525796257972579825799258002580125802258032580425805258062580725808258092581025811258122581325814258152581625817258182581925820258212582225823258242582525826258272582825829258302583125832258332583425835258362583725838258392584025841258422584325844258452584625847258482584925850258512585225853258542585525856258572585825859258602586125862258632586425865258662586725868258692587025871258722587325874258752587625877258782587925880258812588225883258842588525886258872588825889258902589125892258932589425895258962589725898258992590025901259022590325904259052590625907259082590925910259112591225913259142591525916259172591825919259202592125922259232592425925259262592725928259292593025931259322593325934259352593625937259382593925940259412594225943259442594525946259472594825949259502595125952259532595425955259562595725958259592596025961259622596325964259652596625967259682596925970259712597225973259742597525976259772597825979259802598125982259832598425985259862598725988259892599025991259922599325994259952599625997259982599926000260012600226003260042600526006260072600826009260102601126012260132601426015260162601726018260192602026021260222602326024260252602626027260282602926030260312603226033260342603526036260372603826039260402604126042260432604426045260462604726048260492605026051260522605326054260552605626057260582605926060260612606226063260642606526066260672606826069260702607126072260732607426075260762607726078260792608026081260822608326084260852608626087260882608926090260912609226093260942609526096260972609826099261002610126102261032610426105261062610726108261092611026111261122611326114261152611626117261182611926120261212612226123261242612526126261272612826129261302613126132261332613426135261362613726138261392614026141261422614326144261452614626147261482614926150261512615226153261542615526156261572615826159261602616126162261632616426165261662616726168261692617026171261722617326174261752617626177261782617926180261812618226183261842618526186261872618826189261902619126192261932619426195261962619726198261992620026201262022620326204262052620626207262082620926210262112621226213262142621526216262172621826219262202622126222262232622426225262262622726228262292623026231262322623326234262352623626237262382623926240262412624226243262442624526246262472624826249262502625126252262532625426255262562625726258262592626026261262622626326264262652626626267262682626926270262712627226273262742627526276262772627826279262802628126282262832628426285262862628726288262892629026291262922629326294262952629626297262982629926300263012630226303263042630526306263072630826309263102631126312263132631426315263162631726318263192632026321263222632326324263252632626327263282632926330263312633226333263342633526336263372633826339263402634126342263432634426345263462634726348263492635026351263522635326354263552635626357263582635926360263612636226363263642636526366263672636826369263702637126372263732637426375263762637726378263792638026381263822638326384263852638626387263882638926390263912639226393263942639526396263972639826399264002640126402264032640426405264062640726408264092641026411264122641326414264152641626417264182641926420264212642226423264242642526426264272642826429264302643126432264332643426435264362643726438264392644026441264422644326444264452644626447264482644926450264512645226453264542645526456264572645826459264602646126462264632646426465264662646726468264692647026471264722647326474264752647626477264782647926480264812648226483264842648526486264872648826489264902649126492264932649426495264962649726498264992650026501265022650326504265052650626507265082650926510265112651226513265142651526516265172651826519265202652126522265232652426525265262652726528265292653026531265322653326534265352653626537265382653926540265412654226543265442654526546265472654826549265502655126552265532655426555265562655726558265592656026561265622656326564265652656626567265682656926570265712657226573265742657526576265772657826579265802658126582265832658426585265862658726588265892659026591265922659326594265952659626597265982659926600266012660226603266042660526606266072660826609266102661126612266132661426615266162661726618266192662026621266222662326624266252662626627266282662926630266312663226633266342663526636266372663826639266402664126642266432664426645266462664726648266492665026651266522665326654266552665626657266582665926660266612666226663266642666526666266672666826669266702667126672266732667426675266762667726678266792668026681266822668326684266852668626687266882668926690266912669226693266942669526696266972669826699267002670126702267032670426705267062670726708267092671026711267122671326714267152671626717267182671926720267212672226723267242672526726267272672826729267302673126732267332673426735267362673726738267392674026741267422674326744267452674626747267482674926750267512675226753267542675526756267572675826759267602676126762267632676426765267662676726768267692677026771267722677326774267752677626777267782677926780267812678226783267842678526786267872678826789267902679126792267932679426795267962679726798267992680026801268022680326804268052680626807268082680926810268112681226813268142681526816268172681826819268202682126822268232682426825268262682726828268292683026831268322683326834268352683626837268382683926840268412684226843268442684526846268472684826849268502685126852268532685426855268562685726858268592686026861268622686326864268652686626867268682686926870268712687226873268742687526876268772687826879268802688126882268832688426885268862688726888268892689026891268922689326894268952689626897268982689926900269012690226903269042690526906269072690826909269102691126912269132691426915269162691726918269192692026921269222692326924269252692626927269282692926930269312693226933269342693526936269372693826939269402694126942269432694426945269462694726948269492695026951269522695326954269552695626957269582695926960269612696226963269642696526966269672696826969269702697126972269732697426975269762697726978269792698026981269822698326984269852698626987269882698926990269912699226993269942699526996269972699826999270002700127002270032700427005270062700727008270092701027011270122701327014270152701627017270182701927020270212702227023270242702527026270272702827029270302703127032270332703427035270362703727038270392704027041270422704327044270452704627047270482704927050270512705227053270542705527056270572705827059270602706127062270632706427065270662706727068270692707027071270722707327074270752707627077270782707927080270812708227083270842708527086270872708827089270902709127092270932709427095270962709727098270992710027101271022710327104271052710627107271082710927110271112711227113271142711527116271172711827119271202712127122271232712427125271262712727128271292713027131271322713327134271352713627137271382713927140271412714227143271442714527146271472714827149271502715127152271532715427155271562715727158271592716027161271622716327164271652716627167271682716927170271712717227173271742717527176271772717827179271802718127182271832718427185271862718727188271892719027191271922719327194271952719627197271982719927200272012720227203272042720527206272072720827209272102721127212272132721427215272162721727218272192722027221272222722327224272252722627227272282722927230272312723227233272342723527236272372723827239272402724127242272432724427245272462724727248272492725027251272522725327254272552725627257272582725927260272612726227263272642726527266272672726827269272702727127272272732727427275272762727727278272792728027281272822728327284272852728627287272882728927290272912729227293272942729527296272972729827299273002730127302273032730427305273062730727308273092731027311273122731327314273152731627317273182731927320273212732227323273242732527326273272732827329273302733127332273332733427335273362733727338273392734027341273422734327344273452734627347273482734927350273512735227353273542735527356273572735827359273602736127362273632736427365273662736727368273692737027371273722737327374273752737627377273782737927380273812738227383273842738527386273872738827389273902739127392273932739427395273962739727398273992740027401274022740327404274052740627407274082740927410274112741227413274142741527416274172741827419274202742127422274232742427425274262742727428274292743027431274322743327434274352743627437274382743927440274412744227443274442744527446274472744827449274502745127452274532745427455274562745727458274592746027461274622746327464274652746627467274682746927470274712747227473274742747527476274772747827479274802748127482274832748427485274862748727488274892749027491274922749327494274952749627497274982749927500275012750227503275042750527506275072750827509275102751127512275132751427515275162751727518275192752027521275222752327524275252752627527275282752927530275312753227533275342753527536275372753827539275402754127542275432754427545275462754727548275492755027551275522755327554275552755627557275582755927560275612756227563275642756527566275672756827569275702757127572275732757427575275762757727578275792758027581275822758327584275852758627587275882758927590275912759227593275942759527596275972759827599276002760127602276032760427605276062760727608276092761027611276122761327614276152761627617276182761927620276212762227623276242762527626276272762827629276302763127632276332763427635276362763727638276392764027641276422764327644276452764627647276482764927650276512765227653276542765527656276572765827659276602766127662276632766427665276662766727668276692767027671276722767327674276752767627677276782767927680276812768227683276842768527686276872768827689276902769127692276932769427695276962769727698276992770027701277022770327704277052770627707277082770927710277112771227713277142771527716277172771827719277202772127722277232772427725277262772727728277292773027731277322773327734277352773627737277382773927740277412774227743277442774527746277472774827749277502775127752277532775427755277562775727758277592776027761277622776327764277652776627767277682776927770277712777227773277742777527776277772777827779277802778127782277832778427785277862778727788277892779027791277922779327794277952779627797277982779927800278012780227803278042780527806278072780827809278102781127812278132781427815278162781727818278192782027821278222782327824278252782627827278282782927830278312783227833278342783527836278372783827839278402784127842278432784427845278462784727848278492785027851278522785327854278552785627857278582785927860278612786227863278642786527866278672786827869278702787127872278732787427875278762787727878278792788027881278822788327884278852788627887278882788927890278912789227893278942789527896278972789827899279002790127902279032790427905279062790727908279092791027911279122791327914279152791627917279182791927920279212792227923279242792527926279272792827929279302793127932279332793427935279362793727938279392794027941279422794327944279452794627947279482794927950279512795227953279542795527956279572795827959279602796127962279632796427965279662796727968279692797027971279722797327974279752797627977279782797927980279812798227983279842798527986279872798827989279902799127992279932799427995279962799727998279992800028001280022800328004280052800628007280082800928010280112801228013280142801528016280172801828019280202802128022280232802428025280262802728028280292803028031280322803328034280352803628037280382803928040280412804228043280442804528046280472804828049280502805128052280532805428055280562805728058280592806028061280622806328064280652806628067280682806928070280712807228073280742807528076280772807828079280802808128082280832808428085280862808728088280892809028091280922809328094280952809628097280982809928100281012810228103281042810528106281072810828109281102811128112281132811428115281162811728118281192812028121281222812328124281252812628127281282812928130281312813228133281342813528136281372813828139281402814128142281432814428145281462814728148281492815028151281522815328154281552815628157281582815928160281612816228163281642816528166281672816828169281702817128172281732817428175281762817728178281792818028181281822818328184281852818628187281882818928190281912819228193281942819528196281972819828199282002820128202282032820428205282062820728208282092821028211282122821328214282152821628217282182821928220282212822228223282242822528226282272822828229282302823128232282332823428235282362823728238282392824028241282422824328244282452824628247282482824928250282512825228253282542825528256282572825828259282602826128262282632826428265282662826728268282692827028271282722827328274282752827628277282782827928280282812828228283282842828528286282872828828289282902829128292282932829428295282962829728298282992830028301283022830328304283052830628307283082830928310283112831228313283142831528316283172831828319283202832128322283232832428325283262832728328283292833028331283322833328334283352833628337283382833928340283412834228343283442834528346283472834828349283502835128352283532835428355283562835728358283592836028361283622836328364283652836628367283682836928370283712837228373283742837528376283772837828379283802838128382283832838428385283862838728388283892839028391283922839328394283952839628397283982839928400284012840228403284042840528406284072840828409284102841128412284132841428415284162841728418284192842028421284222842328424284252842628427284282842928430284312843228433284342843528436284372843828439284402844128442284432844428445284462844728448284492845028451284522845328454284552845628457284582845928460284612846228463284642846528466284672846828469284702847128472284732847428475284762847728478284792848028481284822848328484284852848628487284882848928490284912849228493284942849528496284972849828499285002850128502285032850428505285062850728508285092851028511285122851328514285152851628517285182851928520285212852228523285242852528526285272852828529285302853128532285332853428535285362853728538285392854028541285422854328544285452854628547285482854928550285512855228553285542855528556285572855828559285602856128562285632856428565285662856728568285692857028571285722857328574285752857628577285782857928580285812858228583285842858528586285872858828589285902859128592285932859428595285962859728598285992860028601286022860328604286052860628607286082860928610286112861228613286142861528616286172861828619286202862128622286232862428625286262862728628286292863028631286322863328634286352863628637286382863928640286412864228643286442864528646286472864828649286502865128652286532865428655286562865728658286592866028661286622866328664286652866628667286682866928670286712867228673286742867528676286772867828679286802868128682286832868428685286862868728688286892869028691286922869328694286952869628697286982869928700287012870228703287042870528706287072870828709287102871128712287132871428715287162871728718287192872028721287222872328724287252872628727287282872928730287312873228733287342873528736287372873828739287402874128742287432874428745287462874728748287492875028751287522875328754287552875628757287582875928760287612876228763287642876528766287672876828769287702877128772287732877428775287762877728778287792878028781287822878328784287852878628787287882878928790287912879228793287942879528796287972879828799288002880128802288032880428805288062880728808288092881028811288122881328814288152881628817288182881928820288212882228823288242882528826288272882828829288302883128832288332883428835288362883728838288392884028841288422884328844288452884628847288482884928850288512885228853288542885528856288572885828859288602886128862288632886428865288662886728868288692887028871288722887328874288752887628877288782887928880288812888228883288842888528886288872888828889288902889128892288932889428895288962889728898288992890028901289022890328904289052890628907289082890928910289112891228913289142891528916289172891828919289202892128922289232892428925289262892728928289292893028931289322893328934289352893628937289382893928940289412894228943289442894528946289472894828949289502895128952289532895428955289562895728958289592896028961289622896328964289652896628967289682896928970289712897228973289742897528976289772897828979289802898128982289832898428985289862898728988289892899028991289922899328994289952899628997289982899929000290012900229003290042900529006290072900829009290102901129012290132901429015290162901729018290192902029021290222902329024290252902629027290282902929030290312903229033290342903529036290372903829039290402904129042290432904429045290462904729048290492905029051290522905329054290552905629057290582905929060290612906229063290642906529066290672906829069290702907129072290732907429075290762907729078290792908029081290822908329084290852908629087290882908929090290912909229093290942909529096290972909829099291002910129102291032910429105291062910729108291092911029111291122911329114291152911629117291182911929120291212912229123291242912529126291272912829129291302913129132291332913429135291362913729138291392914029141291422914329144291452914629147291482914929150291512915229153291542915529156291572915829159291602916129162291632916429165291662916729168291692917029171291722917329174291752917629177291782917929180291812918229183291842918529186291872918829189291902919129192291932919429195291962919729198291992920029201292022920329204292052920629207292082920929210292112921229213292142921529216292172921829219292202922129222292232922429225292262922729228292292923029231292322923329234292352923629237292382923929240292412924229243292442924529246292472924829249292502925129252292532925429255292562925729258292592926029261292622926329264292652926629267292682926929270292712927229273292742927529276292772927829279292802928129282292832928429285292862928729288292892929029291292922929329294292952929629297292982929929300293012930229303293042930529306293072930829309293102931129312293132931429315293162931729318293192932029321293222932329324293252932629327293282932929330293312933229333293342933529336293372933829339293402934129342293432934429345293462934729348293492935029351293522935329354293552935629357293582935929360293612936229363293642936529366293672936829369293702937129372293732937429375293762937729378293792938029381293822938329384293852938629387293882938929390293912939229393293942939529396293972939829399294002940129402294032940429405294062940729408294092941029411294122941329414294152941629417294182941929420294212942229423294242942529426294272942829429294302943129432294332943429435294362943729438294392944029441294422944329444294452944629447294482944929450294512945229453294542945529456294572945829459294602946129462294632946429465294662946729468294692947029471294722947329474294752947629477294782947929480294812948229483294842948529486294872948829489294902949129492294932949429495294962949729498294992950029501295022950329504295052950629507295082950929510295112951229513295142951529516295172951829519295202952129522295232952429525295262952729528295292953029531295322953329534295352953629537295382953929540295412954229543295442954529546295472954829549295502955129552295532955429555295562955729558295592956029561295622956329564295652956629567295682956929570295712957229573295742957529576295772957829579295802958129582295832958429585295862958729588295892959029591295922959329594295952959629597295982959929600296012960229603296042960529606296072960829609296102961129612296132961429615296162961729618296192962029621296222962329624296252962629627296282962929630296312963229633296342963529636296372963829639296402964129642296432964429645296462964729648296492965029651296522965329654296552965629657296582965929660296612966229663296642966529666296672966829669296702967129672296732967429675296762967729678296792968029681296822968329684296852968629687296882968929690296912969229693296942969529696296972969829699297002970129702297032970429705297062970729708297092971029711297122971329714297152971629717297182971929720297212972229723297242972529726297272972829729297302973129732297332973429735297362973729738297392974029741297422974329744297452974629747297482974929750297512975229753297542975529756297572975829759297602976129762297632976429765297662976729768297692977029771297722977329774297752977629777297782977929780297812978229783297842978529786297872978829789297902979129792297932979429795297962979729798297992980029801298022980329804298052980629807298082980929810298112981229813298142981529816298172981829819298202982129822298232982429825298262982729828298292983029831298322983329834298352983629837298382983929840298412984229843298442984529846298472984829849298502985129852298532985429855298562985729858298592986029861298622986329864298652986629867298682986929870298712987229873298742987529876298772987829879298802988129882298832988429885298862988729888298892989029891298922989329894298952989629897298982989929900299012990229903299042990529906299072990829909299102991129912299132991429915299162991729918299192992029921299222992329924299252992629927299282992929930299312993229933299342993529936299372993829939299402994129942299432994429945299462994729948299492995029951299522995329954299552995629957299582995929960299612996229963299642996529966299672996829969299702997129972299732997429975299762997729978299792998029981299822998329984299852998629987299882998929990299912999229993299942999529996299972999829999300003000130002300033000430005300063000730008300093001030011300123001330014300153001630017300183001930020300213002230023300243002530026300273002830029300303003130032300333003430035300363003730038300393004030041300423004330044300453004630047300483004930050300513005230053300543005530056300573005830059300603006130062300633006430065300663006730068300693007030071300723007330074300753007630077300783007930080300813008230083300843008530086300873008830089300903009130092300933009430095300963009730098300993010030101301023010330104301053010630107301083010930110301113011230113301143011530116301173011830119301203012130122301233012430125301263012730128301293013030131301323013330134301353013630137301383013930140301413014230143301443014530146301473014830149301503015130152301533015430155301563015730158301593016030161301623016330164301653016630167301683016930170301713017230173301743017530176301773017830179301803018130182301833018430185301863018730188301893019030191301923019330194301953019630197301983019930200302013020230203302043020530206302073020830209302103021130212302133021430215302163021730218302193022030221302223022330224302253022630227302283022930230302313023230233302343023530236302373023830239302403024130242302433024430245302463024730248302493025030251302523025330254302553025630257302583025930260302613026230263302643026530266302673026830269302703027130272302733027430275302763027730278302793028030281302823028330284302853028630287302883028930290302913029230293302943029530296302973029830299303003030130302303033030430305303063030730308303093031030311303123031330314303153031630317303183031930320303213032230323303243032530326303273032830329303303033130332303333033430335303363033730338303393034030341303423034330344303453034630347303483034930350303513035230353303543035530356303573035830359303603036130362303633036430365303663036730368303693037030371303723037330374303753037630377303783037930380303813038230383303843038530386303873038830389303903039130392303933039430395303963039730398303993040030401304023040330404304053040630407304083040930410304113041230413304143041530416304173041830419304203042130422304233042430425304263042730428304293043030431304323043330434304353043630437304383043930440304413044230443304443044530446304473044830449304503045130452304533045430455304563045730458304593046030461304623046330464304653046630467304683046930470304713047230473304743047530476304773047830479304803048130482304833048430485304863048730488304893049030491304923049330494304953049630497304983049930500305013050230503305043050530506305073050830509305103051130512305133051430515305163051730518305193052030521305223052330524305253052630527305283052930530305313053230533305343053530536305373053830539305403054130542305433054430545305463054730548305493055030551305523055330554305553055630557305583055930560305613056230563305643056530566305673056830569305703057130572305733057430575305763057730578305793058030581305823058330584305853058630587305883058930590305913059230593305943059530596305973059830599306003060130602306033060430605306063060730608306093061030611306123061330614306153061630617306183061930620306213062230623306243062530626306273062830629306303063130632306333063430635306363063730638306393064030641306423064330644306453064630647306483064930650306513065230653306543065530656306573065830659306603066130662306633066430665306663066730668306693067030671306723067330674306753067630677306783067930680306813068230683306843068530686306873068830689306903069130692306933069430695306963069730698306993070030701307023070330704307053070630707307083070930710307113071230713307143071530716307173071830719307203072130722307233072430725307263072730728307293073030731307323073330734307353073630737307383073930740307413074230743307443074530746307473074830749307503075130752307533075430755307563075730758307593076030761307623076330764307653076630767307683076930770307713077230773307743077530776307773077830779307803078130782307833078430785307863078730788307893079030791307923079330794307953079630797307983079930800308013080230803308043080530806308073080830809308103081130812308133081430815308163081730818308193082030821308223082330824308253082630827308283082930830308313083230833308343083530836308373083830839308403084130842308433084430845308463084730848308493085030851308523085330854308553085630857308583085930860308613086230863308643086530866308673086830869308703087130872308733087430875308763087730878308793088030881308823088330884308853088630887308883088930890308913089230893308943089530896308973089830899309003090130902309033090430905309063090730908309093091030911309123091330914309153091630917309183091930920309213092230923309243092530926309273092830929309303093130932309333093430935309363093730938309393094030941309423094330944309453094630947309483094930950309513095230953309543095530956309573095830959309603096130962309633096430965309663096730968309693097030971309723097330974309753097630977309783097930980309813098230983309843098530986309873098830989309903099130992309933099430995309963099730998309993100031001310023100331004310053100631007310083100931010310113101231013310143101531016310173101831019310203102131022310233102431025310263102731028310293103031031310323103331034310353103631037310383103931040310413104231043310443104531046310473104831049310503105131052310533105431055310563105731058310593106031061310623106331064310653106631067310683106931070310713107231073310743107531076310773107831079310803108131082310833108431085310863108731088310893109031091310923109331094310953109631097310983109931100311013110231103311043110531106311073110831109311103111131112311133111431115311163111731118311193112031121311223112331124311253112631127311283112931130311313113231133311343113531136311373113831139311403114131142311433114431145311463114731148311493115031151311523115331154311553115631157311583115931160311613116231163311643116531166311673116831169311703117131172311733117431175311763117731178311793118031181311823118331184311853118631187311883118931190311913119231193311943119531196311973119831199312003120131202312033120431205312063120731208312093121031211312123121331214312153121631217312183121931220312213122231223312243122531226312273122831229312303123131232312333123431235312363123731238312393124031241312423124331244312453124631247312483124931250312513125231253312543125531256312573125831259312603126131262312633126431265312663126731268312693127031271312723127331274312753127631277312783127931280312813128231283312843128531286312873128831289312903129131292312933129431295312963129731298312993130031301313023130331304313053130631307313083130931310313113131231313313143131531316313173131831319313203132131322313233132431325313263132731328313293133031331313323133331334313353133631337313383133931340313413134231343313443134531346313473134831349313503135131352313533135431355313563135731358313593136031361313623136331364313653136631367313683136931370313713137231373313743137531376313773137831379313803138131382313833138431385313863138731388313893139031391313923139331394313953139631397313983139931400314013140231403314043140531406314073140831409314103141131412314133141431415314163141731418314193142031421314223142331424314253142631427314283142931430314313143231433314343143531436314373143831439314403144131442314433144431445314463144731448314493145031451314523145331454314553145631457314583145931460314613146231463314643146531466314673146831469314703147131472314733147431475314763147731478314793148031481314823148331484314853148631487314883148931490314913149231493314943149531496314973149831499315003150131502315033150431505315063150731508315093151031511315123151331514315153151631517315183151931520315213152231523315243152531526315273152831529315303153131532315333153431535315363153731538315393154031541315423154331544315453154631547315483154931550315513155231553315543155531556315573155831559315603156131562315633156431565315663156731568315693157031571315723157331574315753157631577315783157931580315813158231583315843158531586315873158831589315903159131592315933159431595315963159731598315993160031601316023160331604316053160631607316083160931610316113161231613316143161531616316173161831619316203162131622316233162431625316263162731628316293163031631316323163331634316353163631637316383163931640316413164231643316443164531646316473164831649316503165131652316533165431655316563165731658316593166031661316623166331664316653166631667316683166931670316713167231673316743167531676316773167831679316803168131682316833168431685316863168731688316893169031691316923169331694316953169631697316983169931700317013170231703317043170531706317073170831709317103171131712317133171431715317163171731718317193172031721317223172331724317253172631727317283172931730317313173231733317343173531736317373173831739317403174131742317433174431745317463174731748317493175031751317523175331754317553175631757317583175931760317613176231763317643176531766317673176831769317703177131772317733177431775317763177731778317793178031781317823178331784317853178631787317883178931790317913179231793317943179531796317973179831799318003180131802318033180431805318063180731808318093181031811318123181331814318153181631817318183181931820318213182231823318243182531826318273182831829318303183131832318333183431835318363183731838318393184031841318423184331844318453184631847318483184931850318513185231853318543185531856318573185831859318603186131862318633186431865318663186731868318693187031871318723187331874318753187631877318783187931880318813188231883318843188531886318873188831889318903189131892318933189431895318963189731898318993190031901319023190331904319053190631907319083190931910319113191231913319143191531916319173191831919319203192131922319233192431925
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. type: string
  561. deletionPolicy:
  562. default: Retain
  563. description: |-
  564. DeletionPolicy defines rules on how to delete the resulting Secret.
  565. Defaults to "Retain"
  566. enum:
  567. - Delete
  568. - Merge
  569. - Retain
  570. type: string
  571. immutable:
  572. description: Immutable defines if the final secret will be immutable
  573. type: boolean
  574. manifest:
  575. description: |-
  576. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  577. When specified, ExternalSecret will create the resource type defined here
  578. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  579. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  580. properties:
  581. apiVersion:
  582. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  583. minLength: 1
  584. type: string
  585. kind:
  586. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  587. minLength: 1
  588. type: string
  589. required:
  590. - apiVersion
  591. - kind
  592. type: object
  593. name:
  594. description: |-
  595. The name of the Secret resource to be managed.
  596. Defaults to the .metadata.name of the ExternalSecret resource
  597. maxLength: 253
  598. minLength: 1
  599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  600. type: string
  601. template:
  602. description: Template defines a blueprint for the created Secret resource.
  603. properties:
  604. data:
  605. additionalProperties:
  606. type: string
  607. type: object
  608. engineVersion:
  609. default: v2
  610. description: |-
  611. EngineVersion specifies the template engine version
  612. that should be used to compile/execute the
  613. template specified in .data and .templateFrom[].
  614. enum:
  615. - v2
  616. type: string
  617. mergePolicy:
  618. default: Replace
  619. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  620. enum:
  621. - Replace
  622. - Merge
  623. type: string
  624. metadata:
  625. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  626. properties:
  627. annotations:
  628. additionalProperties:
  629. type: string
  630. type: object
  631. finalizers:
  632. items:
  633. type: string
  634. type: array
  635. labels:
  636. additionalProperties:
  637. type: string
  638. type: object
  639. type: object
  640. templateFrom:
  641. items:
  642. description: |-
  643. TemplateFrom specifies a source for templates.
  644. Each item in the list can either reference a ConfigMap or a Secret resource.
  645. properties:
  646. configMap:
  647. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  648. properties:
  649. items:
  650. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  651. items:
  652. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  653. properties:
  654. key:
  655. description: A key in the ConfigMap/Secret
  656. maxLength: 253
  657. minLength: 1
  658. pattern: ^[-._a-zA-Z0-9]+$
  659. type: string
  660. templateAs:
  661. default: Values
  662. description: TemplateScope specifies how the template keys should be interpreted.
  663. enum:
  664. - Values
  665. - KeysAndValues
  666. type: string
  667. required:
  668. - key
  669. type: object
  670. type: array
  671. name:
  672. description: The name of the ConfigMap/Secret resource
  673. maxLength: 253
  674. minLength: 1
  675. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  676. type: string
  677. required:
  678. - items
  679. - name
  680. type: object
  681. literal:
  682. type: string
  683. secret:
  684. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  685. properties:
  686. items:
  687. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  688. items:
  689. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  690. properties:
  691. key:
  692. description: A key in the ConfigMap/Secret
  693. maxLength: 253
  694. minLength: 1
  695. pattern: ^[-._a-zA-Z0-9]+$
  696. type: string
  697. templateAs:
  698. default: Values
  699. description: TemplateScope specifies how the template keys should be interpreted.
  700. enum:
  701. - Values
  702. - KeysAndValues
  703. type: string
  704. required:
  705. - key
  706. type: object
  707. type: array
  708. name:
  709. description: The name of the ConfigMap/Secret resource
  710. maxLength: 253
  711. minLength: 1
  712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  713. type: string
  714. required:
  715. - items
  716. - name
  717. type: object
  718. target:
  719. default: Data
  720. description: |-
  721. Target specifies where to place the template result.
  722. For Secret resources, common values are: "Data", "Annotations", "Labels".
  723. For custom resources (when spec.target.manifest is set), this supports
  724. nested paths like "spec.database.config" or "data".
  725. type: string
  726. valuesDecodingStrategy:
  727. default: None
  728. description: Used to define a decoding Strategy for the rendered template values.
  729. enum:
  730. - Auto
  731. - Base64
  732. - Base64URL
  733. - None
  734. type: string
  735. type: object
  736. type: array
  737. type:
  738. type: string
  739. type: object
  740. type: object
  741. type: object
  742. namespaceSelector:
  743. description: |-
  744. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  745. Deprecated: Use NamespaceSelectors instead.
  746. properties:
  747. matchExpressions:
  748. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  749. items:
  750. description: |-
  751. A label selector requirement is a selector that contains values, a key, and an operator that
  752. relates the key and values.
  753. properties:
  754. key:
  755. description: key is the label key that the selector applies to.
  756. type: string
  757. operator:
  758. description: |-
  759. operator represents a key's relationship to a set of values.
  760. Valid operators are In, NotIn, Exists and DoesNotExist.
  761. type: string
  762. values:
  763. description: |-
  764. values is an array of string values. If the operator is In or NotIn,
  765. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  766. the values array must be empty. This array is replaced during a strategic
  767. merge patch.
  768. items:
  769. type: string
  770. type: array
  771. x-kubernetes-list-type: atomic
  772. required:
  773. - key
  774. - operator
  775. type: object
  776. type: array
  777. x-kubernetes-list-type: atomic
  778. matchLabels:
  779. additionalProperties:
  780. type: string
  781. description: |-
  782. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  783. map is equivalent to an element of matchExpressions, whose key field is "key", the
  784. operator is "In", and the values array contains only "value". The requirements are ANDed.
  785. type: object
  786. type: object
  787. x-kubernetes-map-type: atomic
  788. namespaceSelectors:
  789. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  790. items:
  791. description: |-
  792. A label selector is a label query over a set of resources. The result of matchLabels and
  793. matchExpressions are ANDed. An empty label selector matches all objects. A null
  794. label selector matches no objects.
  795. properties:
  796. matchExpressions:
  797. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  798. items:
  799. description: |-
  800. A label selector requirement is a selector that contains values, a key, and an operator that
  801. relates the key and values.
  802. properties:
  803. key:
  804. description: key is the label key that the selector applies to.
  805. type: string
  806. operator:
  807. description: |-
  808. operator represents a key's relationship to a set of values.
  809. Valid operators are In, NotIn, Exists and DoesNotExist.
  810. type: string
  811. values:
  812. description: |-
  813. values is an array of string values. If the operator is In or NotIn,
  814. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  815. the values array must be empty. This array is replaced during a strategic
  816. merge patch.
  817. items:
  818. type: string
  819. type: array
  820. x-kubernetes-list-type: atomic
  821. required:
  822. - key
  823. - operator
  824. type: object
  825. type: array
  826. x-kubernetes-list-type: atomic
  827. matchLabels:
  828. additionalProperties:
  829. type: string
  830. description: |-
  831. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  832. map is equivalent to an element of matchExpressions, whose key field is "key", the
  833. operator is "In", and the values array contains only "value". The requirements are ANDed.
  834. type: object
  835. type: object
  836. x-kubernetes-map-type: atomic
  837. type: array
  838. namespaces:
  839. description: |-
  840. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  841. Deprecated: Use NamespaceSelectors instead.
  842. items:
  843. maxLength: 63
  844. minLength: 1
  845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  846. type: string
  847. type: array
  848. refreshTime:
  849. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  850. type: string
  851. required:
  852. - externalSecretSpec
  853. type: object
  854. status:
  855. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  856. properties:
  857. conditions:
  858. items:
  859. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  860. properties:
  861. message:
  862. type: string
  863. status:
  864. type: string
  865. type:
  866. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  867. type: string
  868. required:
  869. - status
  870. - type
  871. type: object
  872. type: array
  873. externalSecretName:
  874. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  875. type: string
  876. failedNamespaces:
  877. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  878. items:
  879. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  880. properties:
  881. namespace:
  882. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  883. type: string
  884. reason:
  885. description: Reason is why the ExternalSecret failed to apply to the namespace
  886. type: string
  887. required:
  888. - namespace
  889. type: object
  890. type: array
  891. provisionedNamespaces:
  892. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  893. items:
  894. type: string
  895. type: array
  896. type: object
  897. type: object
  898. served: true
  899. storage: true
  900. subresources:
  901. status: {}
  902. - additionalPrinterColumns:
  903. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  904. name: Store
  905. type: string
  906. - jsonPath: .spec.refreshTime
  907. name: Refresh Interval
  908. type: string
  909. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  910. name: Ready
  911. type: string
  912. deprecated: true
  913. name: v1beta1
  914. schema:
  915. openAPIV3Schema:
  916. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  917. properties:
  918. apiVersion:
  919. description: |-
  920. APIVersion defines the versioned schema of this representation of an object.
  921. Servers should convert recognized schemas to the latest internal value, and
  922. may reject unrecognized values.
  923. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  924. type: string
  925. kind:
  926. description: |-
  927. Kind is a string value representing the REST resource this object represents.
  928. Servers may infer this from the endpoint the client submits requests to.
  929. Cannot be updated.
  930. In CamelCase.
  931. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  932. type: string
  933. metadata:
  934. type: object
  935. spec:
  936. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  937. properties:
  938. externalSecretMetadata:
  939. description: The metadata of the external secrets to be created
  940. properties:
  941. annotations:
  942. additionalProperties:
  943. type: string
  944. type: object
  945. labels:
  946. additionalProperties:
  947. type: string
  948. type: object
  949. type: object
  950. externalSecretName:
  951. description: |-
  952. The name of the external secrets to be created.
  953. Defaults to the name of the ClusterExternalSecret
  954. maxLength: 253
  955. minLength: 1
  956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  957. type: string
  958. externalSecretSpec:
  959. description: The spec for the ExternalSecrets to be created
  960. properties:
  961. data:
  962. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  963. items:
  964. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  965. properties:
  966. remoteRef:
  967. description: |-
  968. RemoteRef points to the remote secret and defines
  969. which secret (version/property/..) to fetch.
  970. properties:
  971. conversionStrategy:
  972. default: Default
  973. description: Used to define a conversion Strategy
  974. enum:
  975. - Default
  976. - Unicode
  977. type: string
  978. decodingStrategy:
  979. default: None
  980. description: Used to define a decoding Strategy
  981. enum:
  982. - Auto
  983. - Base64
  984. - Base64URL
  985. - None
  986. type: string
  987. key:
  988. description: Key is the key used in the Provider, mandatory
  989. type: string
  990. metadataPolicy:
  991. default: None
  992. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  993. enum:
  994. - None
  995. - Fetch
  996. type: string
  997. property:
  998. description: Used to select a specific property of the Provider value (if a map), if supported
  999. type: string
  1000. version:
  1001. description: Used to select a specific version of the Provider value, if supported
  1002. type: string
  1003. required:
  1004. - key
  1005. type: object
  1006. secretKey:
  1007. description: The key in the Kubernetes Secret to store the value.
  1008. maxLength: 253
  1009. minLength: 1
  1010. pattern: ^[-._a-zA-Z0-9]+$
  1011. type: string
  1012. sourceRef:
  1013. description: |-
  1014. SourceRef allows you to override the source
  1015. from which the value will be pulled.
  1016. maxProperties: 1
  1017. minProperties: 1
  1018. properties:
  1019. generatorRef:
  1020. description: |-
  1021. GeneratorRef points to a generator custom resource.
  1022. Deprecated: The generatorRef is not implemented in .data[].
  1023. this will be removed with v1.
  1024. properties:
  1025. apiVersion:
  1026. default: generators.external-secrets.io/v1alpha1
  1027. description: Specify the apiVersion of the generator resource
  1028. type: string
  1029. kind:
  1030. description: Specify the Kind of the generator resource
  1031. enum:
  1032. - ACRAccessToken
  1033. - ClusterGenerator
  1034. - ECRAuthorizationToken
  1035. - Fake
  1036. - GCRAccessToken
  1037. - GithubAccessToken
  1038. - QuayAccessToken
  1039. - Password
  1040. - SSHKey
  1041. - STSSessionToken
  1042. - UUID
  1043. - VaultDynamicSecret
  1044. - Webhook
  1045. - Grafana
  1046. type: string
  1047. name:
  1048. description: Specify the name of the generator resource
  1049. maxLength: 253
  1050. minLength: 1
  1051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1052. type: string
  1053. required:
  1054. - kind
  1055. - name
  1056. type: object
  1057. storeRef:
  1058. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1059. properties:
  1060. kind:
  1061. description: |-
  1062. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1063. Defaults to `SecretStore`
  1064. enum:
  1065. - SecretStore
  1066. - ClusterSecretStore
  1067. type: string
  1068. name:
  1069. description: Name of the SecretStore resource
  1070. maxLength: 253
  1071. minLength: 1
  1072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1073. type: string
  1074. type: object
  1075. type: object
  1076. required:
  1077. - remoteRef
  1078. - secretKey
  1079. type: object
  1080. type: array
  1081. dataFrom:
  1082. description: |-
  1083. DataFrom is used to fetch all properties from a specific Provider data
  1084. If multiple entries are specified, the Secret keys are merged in the specified order
  1085. items:
  1086. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1087. properties:
  1088. extract:
  1089. description: |-
  1090. Used to extract multiple key/value pairs from one secret
  1091. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1092. properties:
  1093. conversionStrategy:
  1094. default: Default
  1095. description: Used to define a conversion Strategy
  1096. enum:
  1097. - Default
  1098. - Unicode
  1099. type: string
  1100. decodingStrategy:
  1101. default: None
  1102. description: Used to define a decoding Strategy
  1103. enum:
  1104. - Auto
  1105. - Base64
  1106. - Base64URL
  1107. - None
  1108. type: string
  1109. key:
  1110. description: Key is the key used in the Provider, mandatory
  1111. type: string
  1112. metadataPolicy:
  1113. default: None
  1114. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1115. enum:
  1116. - None
  1117. - Fetch
  1118. type: string
  1119. property:
  1120. description: Used to select a specific property of the Provider value (if a map), if supported
  1121. type: string
  1122. version:
  1123. description: Used to select a specific version of the Provider value, if supported
  1124. type: string
  1125. required:
  1126. - key
  1127. type: object
  1128. find:
  1129. description: |-
  1130. Used to find secrets based on tags or regular expressions
  1131. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1132. properties:
  1133. conversionStrategy:
  1134. default: Default
  1135. description: Used to define a conversion Strategy
  1136. enum:
  1137. - Default
  1138. - Unicode
  1139. type: string
  1140. decodingStrategy:
  1141. default: None
  1142. description: Used to define a decoding Strategy
  1143. enum:
  1144. - Auto
  1145. - Base64
  1146. - Base64URL
  1147. - None
  1148. type: string
  1149. name:
  1150. description: Finds secrets based on the name.
  1151. properties:
  1152. regexp:
  1153. description: Finds secrets base
  1154. type: string
  1155. type: object
  1156. path:
  1157. description: A root path to start the find operations.
  1158. type: string
  1159. tags:
  1160. additionalProperties:
  1161. type: string
  1162. description: Find secrets based on tags.
  1163. type: object
  1164. type: object
  1165. rewrite:
  1166. description: |-
  1167. Used to rewrite secret Keys after getting them from the secret Provider
  1168. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1169. items:
  1170. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1171. maxProperties: 1
  1172. minProperties: 1
  1173. properties:
  1174. regexp:
  1175. description: |-
  1176. Used to rewrite with regular expressions.
  1177. The resulting key will be the output of a regexp.ReplaceAll operation.
  1178. properties:
  1179. source:
  1180. description: Used to define the regular expression of a re.Compiler.
  1181. type: string
  1182. target:
  1183. description: Used to define the target pattern of a ReplaceAll operation.
  1184. type: string
  1185. required:
  1186. - source
  1187. - target
  1188. type: object
  1189. transform:
  1190. description: |-
  1191. Used to apply string transformation on the secrets.
  1192. The resulting key will be the output of the template applied by the operation.
  1193. properties:
  1194. template:
  1195. description: |-
  1196. Used to define the template to apply on the secret name.
  1197. `.value ` will specify the secret name in the template.
  1198. type: string
  1199. required:
  1200. - template
  1201. type: object
  1202. type: object
  1203. type: array
  1204. sourceRef:
  1205. description: |-
  1206. SourceRef points to a store or generator
  1207. which contains secret values ready to use.
  1208. Use this in combination with Extract or Find pull values out of
  1209. a specific SecretStore.
  1210. When sourceRef points to a generator Extract or Find is not supported.
  1211. The generator returns a static map of values
  1212. maxProperties: 1
  1213. minProperties: 1
  1214. properties:
  1215. generatorRef:
  1216. description: GeneratorRef points to a generator custom resource.
  1217. properties:
  1218. apiVersion:
  1219. default: generators.external-secrets.io/v1alpha1
  1220. description: Specify the apiVersion of the generator resource
  1221. type: string
  1222. kind:
  1223. description: Specify the Kind of the generator resource
  1224. enum:
  1225. - ACRAccessToken
  1226. - ClusterGenerator
  1227. - ECRAuthorizationToken
  1228. - Fake
  1229. - GCRAccessToken
  1230. - GithubAccessToken
  1231. - QuayAccessToken
  1232. - Password
  1233. - SSHKey
  1234. - STSSessionToken
  1235. - UUID
  1236. - VaultDynamicSecret
  1237. - Webhook
  1238. - Grafana
  1239. type: string
  1240. name:
  1241. description: Specify the name of the generator resource
  1242. maxLength: 253
  1243. minLength: 1
  1244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1245. type: string
  1246. required:
  1247. - kind
  1248. - name
  1249. type: object
  1250. storeRef:
  1251. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1252. properties:
  1253. kind:
  1254. description: |-
  1255. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1256. Defaults to `SecretStore`
  1257. enum:
  1258. - SecretStore
  1259. - ClusterSecretStore
  1260. type: string
  1261. name:
  1262. description: Name of the SecretStore resource
  1263. maxLength: 253
  1264. minLength: 1
  1265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1266. type: string
  1267. type: object
  1268. type: object
  1269. type: object
  1270. type: array
  1271. refreshInterval:
  1272. default: 1h0m0s
  1273. description: |-
  1274. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1275. specified as Golang Duration strings.
  1276. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1277. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1278. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1279. type: string
  1280. refreshPolicy:
  1281. description: |-
  1282. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1283. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1284. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1285. No periodic updates occur if refreshInterval is 0.
  1286. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1287. enum:
  1288. - CreatedOnce
  1289. - Periodic
  1290. - OnChange
  1291. type: string
  1292. secretStoreRef:
  1293. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1294. properties:
  1295. kind:
  1296. description: |-
  1297. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1298. Defaults to `SecretStore`
  1299. enum:
  1300. - SecretStore
  1301. - ClusterSecretStore
  1302. type: string
  1303. name:
  1304. description: Name of the SecretStore resource
  1305. maxLength: 253
  1306. minLength: 1
  1307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1308. type: string
  1309. type: object
  1310. target:
  1311. default:
  1312. creationPolicy: Owner
  1313. deletionPolicy: Retain
  1314. description: |-
  1315. ExternalSecretTarget defines the Kubernetes Secret to be created
  1316. There can be only one target per ExternalSecret.
  1317. properties:
  1318. creationPolicy:
  1319. default: Owner
  1320. description: |-
  1321. CreationPolicy defines rules on how to create the resulting Secret.
  1322. Defaults to "Owner"
  1323. enum:
  1324. - Owner
  1325. - Orphan
  1326. - Merge
  1327. - None
  1328. type: string
  1329. deletionPolicy:
  1330. default: Retain
  1331. description: |-
  1332. DeletionPolicy defines rules on how to delete the resulting Secret.
  1333. Defaults to "Retain"
  1334. enum:
  1335. - Delete
  1336. - Merge
  1337. - Retain
  1338. type: string
  1339. immutable:
  1340. description: Immutable defines if the final secret will be immutable
  1341. type: boolean
  1342. name:
  1343. description: |-
  1344. The name of the Secret resource to be managed.
  1345. Defaults to the .metadata.name of the ExternalSecret resource
  1346. maxLength: 253
  1347. minLength: 1
  1348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1349. type: string
  1350. template:
  1351. description: Template defines a blueprint for the created Secret resource.
  1352. properties:
  1353. data:
  1354. additionalProperties:
  1355. type: string
  1356. type: object
  1357. engineVersion:
  1358. default: v2
  1359. description: |-
  1360. EngineVersion specifies the template engine version
  1361. that should be used to compile/execute the
  1362. template specified in .data and .templateFrom[].
  1363. enum:
  1364. - v2
  1365. type: string
  1366. mergePolicy:
  1367. default: Replace
  1368. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1369. enum:
  1370. - Replace
  1371. - Merge
  1372. type: string
  1373. metadata:
  1374. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1375. properties:
  1376. annotations:
  1377. additionalProperties:
  1378. type: string
  1379. type: object
  1380. labels:
  1381. additionalProperties:
  1382. type: string
  1383. type: object
  1384. type: object
  1385. templateFrom:
  1386. items:
  1387. description: TemplateFrom defines a source for template data.
  1388. properties:
  1389. configMap:
  1390. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1391. properties:
  1392. items:
  1393. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1394. items:
  1395. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1396. properties:
  1397. key:
  1398. description: A key in the ConfigMap/Secret
  1399. maxLength: 253
  1400. minLength: 1
  1401. pattern: ^[-._a-zA-Z0-9]+$
  1402. type: string
  1403. templateAs:
  1404. default: Values
  1405. description: TemplateScope defines the scope of the template when processing template data.
  1406. enum:
  1407. - Values
  1408. - KeysAndValues
  1409. type: string
  1410. required:
  1411. - key
  1412. type: object
  1413. type: array
  1414. name:
  1415. description: The name of the ConfigMap/Secret resource
  1416. maxLength: 253
  1417. minLength: 1
  1418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1419. type: string
  1420. required:
  1421. - items
  1422. - name
  1423. type: object
  1424. literal:
  1425. type: string
  1426. secret:
  1427. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1428. properties:
  1429. items:
  1430. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1431. items:
  1432. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1433. properties:
  1434. key:
  1435. description: A key in the ConfigMap/Secret
  1436. maxLength: 253
  1437. minLength: 1
  1438. pattern: ^[-._a-zA-Z0-9]+$
  1439. type: string
  1440. templateAs:
  1441. default: Values
  1442. description: TemplateScope defines the scope of the template when processing template data.
  1443. enum:
  1444. - Values
  1445. - KeysAndValues
  1446. type: string
  1447. required:
  1448. - key
  1449. type: object
  1450. type: array
  1451. name:
  1452. description: The name of the ConfigMap/Secret resource
  1453. maxLength: 253
  1454. minLength: 1
  1455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1456. type: string
  1457. required:
  1458. - items
  1459. - name
  1460. type: object
  1461. target:
  1462. default: Data
  1463. description: TemplateTarget defines the target field where the template result will be stored.
  1464. enum:
  1465. - Data
  1466. - Annotations
  1467. - Labels
  1468. type: string
  1469. type: object
  1470. type: array
  1471. type:
  1472. type: string
  1473. type: object
  1474. type: object
  1475. type: object
  1476. namespaceSelector:
  1477. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1478. properties:
  1479. matchExpressions:
  1480. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1481. items:
  1482. description: |-
  1483. A label selector requirement is a selector that contains values, a key, and an operator that
  1484. relates the key and values.
  1485. properties:
  1486. key:
  1487. description: key is the label key that the selector applies to.
  1488. type: string
  1489. operator:
  1490. description: |-
  1491. operator represents a key's relationship to a set of values.
  1492. Valid operators are In, NotIn, Exists and DoesNotExist.
  1493. type: string
  1494. values:
  1495. description: |-
  1496. values is an array of string values. If the operator is In or NotIn,
  1497. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1498. the values array must be empty. This array is replaced during a strategic
  1499. merge patch.
  1500. items:
  1501. type: string
  1502. type: array
  1503. x-kubernetes-list-type: atomic
  1504. required:
  1505. - key
  1506. - operator
  1507. type: object
  1508. type: array
  1509. x-kubernetes-list-type: atomic
  1510. matchLabels:
  1511. additionalProperties:
  1512. type: string
  1513. description: |-
  1514. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1515. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1516. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1517. type: object
  1518. type: object
  1519. x-kubernetes-map-type: atomic
  1520. namespaceSelectors:
  1521. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1522. items:
  1523. description: |-
  1524. A label selector is a label query over a set of resources. The result of matchLabels and
  1525. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1526. label selector matches no objects.
  1527. properties:
  1528. matchExpressions:
  1529. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1530. items:
  1531. description: |-
  1532. A label selector requirement is a selector that contains values, a key, and an operator that
  1533. relates the key and values.
  1534. properties:
  1535. key:
  1536. description: key is the label key that the selector applies to.
  1537. type: string
  1538. operator:
  1539. description: |-
  1540. operator represents a key's relationship to a set of values.
  1541. Valid operators are In, NotIn, Exists and DoesNotExist.
  1542. type: string
  1543. values:
  1544. description: |-
  1545. values is an array of string values. If the operator is In or NotIn,
  1546. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1547. the values array must be empty. This array is replaced during a strategic
  1548. merge patch.
  1549. items:
  1550. type: string
  1551. type: array
  1552. x-kubernetes-list-type: atomic
  1553. required:
  1554. - key
  1555. - operator
  1556. type: object
  1557. type: array
  1558. x-kubernetes-list-type: atomic
  1559. matchLabels:
  1560. additionalProperties:
  1561. type: string
  1562. description: |-
  1563. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1564. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1565. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1566. type: object
  1567. type: object
  1568. x-kubernetes-map-type: atomic
  1569. type: array
  1570. namespaces:
  1571. description: |-
  1572. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1573. Deprecated: Use NamespaceSelectors instead.
  1574. items:
  1575. maxLength: 63
  1576. minLength: 1
  1577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1578. type: string
  1579. type: array
  1580. refreshTime:
  1581. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1582. type: string
  1583. required:
  1584. - externalSecretSpec
  1585. type: object
  1586. status:
  1587. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1588. properties:
  1589. conditions:
  1590. items:
  1591. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1592. properties:
  1593. message:
  1594. type: string
  1595. status:
  1596. type: string
  1597. type:
  1598. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1599. type: string
  1600. required:
  1601. - status
  1602. - type
  1603. type: object
  1604. type: array
  1605. externalSecretName:
  1606. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1607. type: string
  1608. failedNamespaces:
  1609. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1610. items:
  1611. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1612. properties:
  1613. namespace:
  1614. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1615. type: string
  1616. reason:
  1617. description: Reason is why the ExternalSecret failed to apply to the namespace
  1618. type: string
  1619. required:
  1620. - namespace
  1621. type: object
  1622. type: array
  1623. provisionedNamespaces:
  1624. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1625. items:
  1626. type: string
  1627. type: array
  1628. type: object
  1629. type: object
  1630. served: false
  1631. storage: false
  1632. subresources:
  1633. status: {}
  1634. ---
  1635. apiVersion: apiextensions.k8s.io/v1
  1636. kind: CustomResourceDefinition
  1637. metadata:
  1638. annotations:
  1639. controller-gen.kubebuilder.io/version: v0.19.0
  1640. labels:
  1641. external-secrets.io/component: controller
  1642. name: clusterpushsecrets.external-secrets.io
  1643. spec:
  1644. group: external-secrets.io
  1645. names:
  1646. categories:
  1647. - external-secrets
  1648. kind: ClusterPushSecret
  1649. listKind: ClusterPushSecretList
  1650. plural: clusterpushsecrets
  1651. singular: clusterpushsecret
  1652. scope: Cluster
  1653. versions:
  1654. - additionalPrinterColumns:
  1655. - jsonPath: .metadata.creationTimestamp
  1656. name: AGE
  1657. type: date
  1658. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1659. name: Status
  1660. type: string
  1661. name: v1alpha1
  1662. schema:
  1663. openAPIV3Schema:
  1664. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1665. properties:
  1666. apiVersion:
  1667. description: |-
  1668. APIVersion defines the versioned schema of this representation of an object.
  1669. Servers should convert recognized schemas to the latest internal value, and
  1670. may reject unrecognized values.
  1671. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1672. type: string
  1673. kind:
  1674. description: |-
  1675. Kind is a string value representing the REST resource this object represents.
  1676. Servers may infer this from the endpoint the client submits requests to.
  1677. Cannot be updated.
  1678. In CamelCase.
  1679. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1680. type: string
  1681. metadata:
  1682. type: object
  1683. spec:
  1684. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1685. properties:
  1686. namespaceSelectors:
  1687. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1688. items:
  1689. description: |-
  1690. A label selector is a label query over a set of resources. The result of matchLabels and
  1691. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1692. label selector matches no objects.
  1693. properties:
  1694. matchExpressions:
  1695. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1696. items:
  1697. description: |-
  1698. A label selector requirement is a selector that contains values, a key, and an operator that
  1699. relates the key and values.
  1700. properties:
  1701. key:
  1702. description: key is the label key that the selector applies to.
  1703. type: string
  1704. operator:
  1705. description: |-
  1706. operator represents a key's relationship to a set of values.
  1707. Valid operators are In, NotIn, Exists and DoesNotExist.
  1708. type: string
  1709. values:
  1710. description: |-
  1711. values is an array of string values. If the operator is In or NotIn,
  1712. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1713. the values array must be empty. This array is replaced during a strategic
  1714. merge patch.
  1715. items:
  1716. type: string
  1717. type: array
  1718. x-kubernetes-list-type: atomic
  1719. required:
  1720. - key
  1721. - operator
  1722. type: object
  1723. type: array
  1724. x-kubernetes-list-type: atomic
  1725. matchLabels:
  1726. additionalProperties:
  1727. type: string
  1728. description: |-
  1729. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1730. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1731. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1732. type: object
  1733. type: object
  1734. x-kubernetes-map-type: atomic
  1735. type: array
  1736. pushSecretMetadata:
  1737. description: The metadata of the external secrets to be created
  1738. properties:
  1739. annotations:
  1740. additionalProperties:
  1741. type: string
  1742. type: object
  1743. labels:
  1744. additionalProperties:
  1745. type: string
  1746. type: object
  1747. type: object
  1748. pushSecretName:
  1749. description: |-
  1750. The name of the push secrets to be created.
  1751. Defaults to the name of the ClusterPushSecret
  1752. maxLength: 253
  1753. minLength: 1
  1754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1755. type: string
  1756. pushSecretSpec:
  1757. description: PushSecretSpec defines what to do with the secrets.
  1758. properties:
  1759. data:
  1760. description: Secret Data that should be pushed to providers
  1761. items:
  1762. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1763. properties:
  1764. conversionStrategy:
  1765. default: None
  1766. description: Used to define a conversion Strategy for the secret keys
  1767. enum:
  1768. - None
  1769. - ReverseUnicode
  1770. type: string
  1771. match:
  1772. description: Match a given Secret Key to be pushed to the provider.
  1773. properties:
  1774. remoteRef:
  1775. description: Remote Refs to push to providers.
  1776. properties:
  1777. property:
  1778. description: Name of the property in the resulting secret
  1779. type: string
  1780. remoteKey:
  1781. description: Name of the resulting provider secret.
  1782. type: string
  1783. required:
  1784. - remoteKey
  1785. type: object
  1786. secretKey:
  1787. description: Secret Key to be pushed
  1788. type: string
  1789. required:
  1790. - remoteRef
  1791. type: object
  1792. metadata:
  1793. description: |-
  1794. Metadata is metadata attached to the secret.
  1795. The structure of metadata is provider specific, please look it up in the provider documentation.
  1796. x-kubernetes-preserve-unknown-fields: true
  1797. required:
  1798. - match
  1799. type: object
  1800. type: array
  1801. dataTo:
  1802. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1803. items:
  1804. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1805. properties:
  1806. conversionStrategy:
  1807. default: None
  1808. description: Used to define a conversion Strategy for the secret keys
  1809. enum:
  1810. - None
  1811. - ReverseUnicode
  1812. type: string
  1813. match:
  1814. description: |-
  1815. Match pattern for selecting keys from the source Secret.
  1816. If not specified, all keys are selected.
  1817. properties:
  1818. regexp:
  1819. description: |-
  1820. Regexp matches keys by regular expression.
  1821. If not specified, all keys are matched.
  1822. type: string
  1823. type: object
  1824. metadata:
  1825. description: |-
  1826. Metadata is metadata attached to the secret.
  1827. The structure of metadata is provider specific, please look it up in the provider documentation.
  1828. x-kubernetes-preserve-unknown-fields: true
  1829. remoteKey:
  1830. description: |-
  1831. RemoteKey is the name of the single provider secret that will receive ALL
  1832. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1833. When set, per-key expansion is skipped and a single push is performed.
  1834. The provider's store prefix (if any) is still prepended to this value.
  1835. When not set, each matched key is pushed as its own individual provider secret.
  1836. type: string
  1837. rewrite:
  1838. description: |-
  1839. Rewrite operations to transform keys before pushing to the provider.
  1840. Operations are applied sequentially.
  1841. items:
  1842. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1843. properties:
  1844. regexp:
  1845. description: Used to rewrite with regular expressions.
  1846. properties:
  1847. source:
  1848. description: Used to define the regular expression of a re.Compiler.
  1849. type: string
  1850. target:
  1851. description: Used to define the target pattern of a ReplaceAll operation.
  1852. type: string
  1853. required:
  1854. - source
  1855. - target
  1856. type: object
  1857. transform:
  1858. description: Used to apply string transformation on the secrets.
  1859. properties:
  1860. template:
  1861. description: |-
  1862. Used to define the template to apply on the secret name.
  1863. `.value ` will specify the secret name in the template.
  1864. type: string
  1865. required:
  1866. - template
  1867. type: object
  1868. type: object
  1869. x-kubernetes-validations:
  1870. - message: exactly one of regexp or transform must be set
  1871. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1872. type: array
  1873. storeRef:
  1874. description: StoreRef specifies which SecretStore to push to. Required.
  1875. properties:
  1876. kind:
  1877. default: SecretStore
  1878. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1879. enum:
  1880. - SecretStore
  1881. - ClusterSecretStore
  1882. type: string
  1883. labelSelector:
  1884. description: Optionally, sync to secret stores with label selector
  1885. properties:
  1886. matchExpressions:
  1887. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1888. items:
  1889. description: |-
  1890. A label selector requirement is a selector that contains values, a key, and an operator that
  1891. relates the key and values.
  1892. properties:
  1893. key:
  1894. description: key is the label key that the selector applies to.
  1895. type: string
  1896. operator:
  1897. description: |-
  1898. operator represents a key's relationship to a set of values.
  1899. Valid operators are In, NotIn, Exists and DoesNotExist.
  1900. type: string
  1901. values:
  1902. description: |-
  1903. values is an array of string values. If the operator is In or NotIn,
  1904. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1905. the values array must be empty. This array is replaced during a strategic
  1906. merge patch.
  1907. items:
  1908. type: string
  1909. type: array
  1910. x-kubernetes-list-type: atomic
  1911. required:
  1912. - key
  1913. - operator
  1914. type: object
  1915. type: array
  1916. x-kubernetes-list-type: atomic
  1917. matchLabels:
  1918. additionalProperties:
  1919. type: string
  1920. description: |-
  1921. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1922. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1923. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1924. type: object
  1925. type: object
  1926. x-kubernetes-map-type: atomic
  1927. name:
  1928. description: Optionally, sync to the SecretStore of the given name
  1929. maxLength: 253
  1930. minLength: 1
  1931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1932. type: string
  1933. type: object
  1934. type: object
  1935. x-kubernetes-validations:
  1936. - message: storeRef must specify either name or labelSelector
  1937. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1938. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1939. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1940. type: array
  1941. deletionPolicy:
  1942. default: None
  1943. description: Deletion Policy to handle Secrets in the provider.
  1944. enum:
  1945. - Delete
  1946. - None
  1947. type: string
  1948. refreshInterval:
  1949. default: 1h0m0s
  1950. description: The Interval to which External Secrets will try to push a secret definition
  1951. type: string
  1952. secretStoreRefs:
  1953. items:
  1954. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1955. properties:
  1956. kind:
  1957. default: SecretStore
  1958. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1959. enum:
  1960. - SecretStore
  1961. - ClusterSecretStore
  1962. type: string
  1963. labelSelector:
  1964. description: Optionally, sync to secret stores with label selector
  1965. properties:
  1966. matchExpressions:
  1967. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1968. items:
  1969. description: |-
  1970. A label selector requirement is a selector that contains values, a key, and an operator that
  1971. relates the key and values.
  1972. properties:
  1973. key:
  1974. description: key is the label key that the selector applies to.
  1975. type: string
  1976. operator:
  1977. description: |-
  1978. operator represents a key's relationship to a set of values.
  1979. Valid operators are In, NotIn, Exists and DoesNotExist.
  1980. type: string
  1981. values:
  1982. description: |-
  1983. values is an array of string values. If the operator is In or NotIn,
  1984. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1985. the values array must be empty. This array is replaced during a strategic
  1986. merge patch.
  1987. items:
  1988. type: string
  1989. type: array
  1990. x-kubernetes-list-type: atomic
  1991. required:
  1992. - key
  1993. - operator
  1994. type: object
  1995. type: array
  1996. x-kubernetes-list-type: atomic
  1997. matchLabels:
  1998. additionalProperties:
  1999. type: string
  2000. description: |-
  2001. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2002. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2003. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2004. type: object
  2005. type: object
  2006. x-kubernetes-map-type: atomic
  2007. name:
  2008. description: Optionally, sync to the SecretStore of the given name
  2009. maxLength: 253
  2010. minLength: 1
  2011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2012. type: string
  2013. type: object
  2014. type: array
  2015. selector:
  2016. description: The Secret Selector (k8s source) for the Push Secret
  2017. maxProperties: 1
  2018. minProperties: 1
  2019. properties:
  2020. generatorRef:
  2021. description: Point to a generator to create a Secret.
  2022. properties:
  2023. apiVersion:
  2024. default: generators.external-secrets.io/v1alpha1
  2025. description: Specify the apiVersion of the generator resource
  2026. type: string
  2027. kind:
  2028. description: Specify the Kind of the generator resource
  2029. enum:
  2030. - ACRAccessToken
  2031. - BeyondtrustWorkloadCredentialsDynamicSecret
  2032. - ClusterGenerator
  2033. - CloudsmithAccessToken
  2034. - ECRAuthorizationToken
  2035. - Fake
  2036. - GCRAccessToken
  2037. - GithubAccessToken
  2038. - GitlabDeployToken
  2039. - QuayAccessToken
  2040. - Password
  2041. - SSHKey
  2042. - STSSessionToken
  2043. - UUID
  2044. - VaultDynamicSecret
  2045. - Webhook
  2046. - Grafana
  2047. - MFA
  2048. type: string
  2049. name:
  2050. description: Specify the name of the generator resource
  2051. maxLength: 253
  2052. minLength: 1
  2053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2054. type: string
  2055. required:
  2056. - kind
  2057. - name
  2058. type: object
  2059. secret:
  2060. description: Select a Secret to Push.
  2061. properties:
  2062. name:
  2063. description: |-
  2064. Name of the Secret.
  2065. The Secret must exist in the same namespace as the PushSecret manifest.
  2066. maxLength: 253
  2067. minLength: 1
  2068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2069. type: string
  2070. selector:
  2071. description: Selector chooses secrets using a labelSelector.
  2072. properties:
  2073. matchExpressions:
  2074. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2075. items:
  2076. description: |-
  2077. A label selector requirement is a selector that contains values, a key, and an operator that
  2078. relates the key and values.
  2079. properties:
  2080. key:
  2081. description: key is the label key that the selector applies to.
  2082. type: string
  2083. operator:
  2084. description: |-
  2085. operator represents a key's relationship to a set of values.
  2086. Valid operators are In, NotIn, Exists and DoesNotExist.
  2087. type: string
  2088. values:
  2089. description: |-
  2090. values is an array of string values. If the operator is In or NotIn,
  2091. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2092. the values array must be empty. This array is replaced during a strategic
  2093. merge patch.
  2094. items:
  2095. type: string
  2096. type: array
  2097. x-kubernetes-list-type: atomic
  2098. required:
  2099. - key
  2100. - operator
  2101. type: object
  2102. type: array
  2103. x-kubernetes-list-type: atomic
  2104. matchLabels:
  2105. additionalProperties:
  2106. type: string
  2107. description: |-
  2108. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2109. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2110. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2111. type: object
  2112. type: object
  2113. x-kubernetes-map-type: atomic
  2114. type: object
  2115. type: object
  2116. template:
  2117. description: Template defines a blueprint for the created Secret resource.
  2118. properties:
  2119. data:
  2120. additionalProperties:
  2121. type: string
  2122. type: object
  2123. engineVersion:
  2124. default: v2
  2125. description: |-
  2126. EngineVersion specifies the template engine version
  2127. that should be used to compile/execute the
  2128. template specified in .data and .templateFrom[].
  2129. enum:
  2130. - v2
  2131. type: string
  2132. mergePolicy:
  2133. default: Replace
  2134. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2135. enum:
  2136. - Replace
  2137. - Merge
  2138. type: string
  2139. metadata:
  2140. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2141. properties:
  2142. annotations:
  2143. additionalProperties:
  2144. type: string
  2145. type: object
  2146. finalizers:
  2147. items:
  2148. type: string
  2149. type: array
  2150. labels:
  2151. additionalProperties:
  2152. type: string
  2153. type: object
  2154. type: object
  2155. templateFrom:
  2156. items:
  2157. description: |-
  2158. TemplateFrom specifies a source for templates.
  2159. Each item in the list can either reference a ConfigMap or a Secret resource.
  2160. properties:
  2161. configMap:
  2162. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2163. properties:
  2164. items:
  2165. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2166. items:
  2167. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2168. properties:
  2169. key:
  2170. description: A key in the ConfigMap/Secret
  2171. maxLength: 253
  2172. minLength: 1
  2173. pattern: ^[-._a-zA-Z0-9]+$
  2174. type: string
  2175. templateAs:
  2176. default: Values
  2177. description: TemplateScope specifies how the template keys should be interpreted.
  2178. enum:
  2179. - Values
  2180. - KeysAndValues
  2181. type: string
  2182. required:
  2183. - key
  2184. type: object
  2185. type: array
  2186. name:
  2187. description: The name of the ConfigMap/Secret resource
  2188. maxLength: 253
  2189. minLength: 1
  2190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2191. type: string
  2192. required:
  2193. - items
  2194. - name
  2195. type: object
  2196. literal:
  2197. type: string
  2198. secret:
  2199. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2200. properties:
  2201. items:
  2202. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2203. items:
  2204. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2205. properties:
  2206. key:
  2207. description: A key in the ConfigMap/Secret
  2208. maxLength: 253
  2209. minLength: 1
  2210. pattern: ^[-._a-zA-Z0-9]+$
  2211. type: string
  2212. templateAs:
  2213. default: Values
  2214. description: TemplateScope specifies how the template keys should be interpreted.
  2215. enum:
  2216. - Values
  2217. - KeysAndValues
  2218. type: string
  2219. required:
  2220. - key
  2221. type: object
  2222. type: array
  2223. name:
  2224. description: The name of the ConfigMap/Secret resource
  2225. maxLength: 253
  2226. minLength: 1
  2227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2228. type: string
  2229. required:
  2230. - items
  2231. - name
  2232. type: object
  2233. target:
  2234. default: Data
  2235. description: |-
  2236. Target specifies where to place the template result.
  2237. For Secret resources, common values are: "Data", "Annotations", "Labels".
  2238. For custom resources (when spec.target.manifest is set), this supports
  2239. nested paths like "spec.database.config" or "data".
  2240. type: string
  2241. valuesDecodingStrategy:
  2242. default: None
  2243. description: Used to define a decoding Strategy for the rendered template values.
  2244. enum:
  2245. - Auto
  2246. - Base64
  2247. - Base64URL
  2248. - None
  2249. type: string
  2250. type: object
  2251. type: array
  2252. type:
  2253. type: string
  2254. type: object
  2255. updatePolicy:
  2256. default: Replace
  2257. description: UpdatePolicy to handle Secrets in the provider.
  2258. enum:
  2259. - Replace
  2260. - IfNotExists
  2261. type: string
  2262. required:
  2263. - secretStoreRefs
  2264. - selector
  2265. type: object
  2266. refreshTime:
  2267. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2268. type: string
  2269. required:
  2270. - pushSecretSpec
  2271. type: object
  2272. status:
  2273. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2274. properties:
  2275. conditions:
  2276. items:
  2277. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2278. properties:
  2279. lastTransitionTime:
  2280. format: date-time
  2281. type: string
  2282. message:
  2283. type: string
  2284. reason:
  2285. type: string
  2286. status:
  2287. type: string
  2288. type:
  2289. description: PushSecretConditionType indicates the condition of the PushSecret.
  2290. type: string
  2291. required:
  2292. - status
  2293. - type
  2294. type: object
  2295. type: array
  2296. failedNamespaces:
  2297. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2298. items:
  2299. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2300. properties:
  2301. namespace:
  2302. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2303. type: string
  2304. reason:
  2305. description: Reason is why the PushSecret failed to apply to the namespace
  2306. type: string
  2307. required:
  2308. - namespace
  2309. type: object
  2310. type: array
  2311. provisionedNamespaces:
  2312. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2313. items:
  2314. type: string
  2315. type: array
  2316. pushSecretName:
  2317. type: string
  2318. type: object
  2319. type: object
  2320. served: true
  2321. storage: true
  2322. subresources:
  2323. status: {}
  2324. ---
  2325. apiVersion: apiextensions.k8s.io/v1
  2326. kind: CustomResourceDefinition
  2327. metadata:
  2328. annotations:
  2329. controller-gen.kubebuilder.io/version: v0.19.0
  2330. labels:
  2331. external-secrets.io/component: controller
  2332. name: clustersecretstores.external-secrets.io
  2333. spec:
  2334. group: external-secrets.io
  2335. names:
  2336. categories:
  2337. - external-secrets
  2338. kind: ClusterSecretStore
  2339. listKind: ClusterSecretStoreList
  2340. plural: clustersecretstores
  2341. shortNames:
  2342. - css
  2343. singular: clustersecretstore
  2344. scope: Cluster
  2345. versions:
  2346. - additionalPrinterColumns:
  2347. - jsonPath: .metadata.creationTimestamp
  2348. name: AGE
  2349. type: date
  2350. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2351. name: Status
  2352. type: string
  2353. - jsonPath: .status.capabilities
  2354. name: Capabilities
  2355. type: string
  2356. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2357. name: Ready
  2358. type: string
  2359. name: v1
  2360. schema:
  2361. openAPIV3Schema:
  2362. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2363. properties:
  2364. apiVersion:
  2365. description: |-
  2366. APIVersion defines the versioned schema of this representation of an object.
  2367. Servers should convert recognized schemas to the latest internal value, and
  2368. may reject unrecognized values.
  2369. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2370. type: string
  2371. kind:
  2372. description: |-
  2373. Kind is a string value representing the REST resource this object represents.
  2374. Servers may infer this from the endpoint the client submits requests to.
  2375. Cannot be updated.
  2376. In CamelCase.
  2377. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2378. type: string
  2379. metadata:
  2380. type: object
  2381. spec:
  2382. description: SecretStoreSpec defines the desired state of SecretStore.
  2383. properties:
  2384. conditions:
  2385. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2386. items:
  2387. description: |-
  2388. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2389. for a ClusterSecretStore instance.
  2390. properties:
  2391. namespaceRegexes:
  2392. description: Choose namespaces by using regex matching
  2393. items:
  2394. type: string
  2395. type: array
  2396. namespaceSelector:
  2397. description: Choose namespace using a labelSelector
  2398. properties:
  2399. matchExpressions:
  2400. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2401. items:
  2402. description: |-
  2403. A label selector requirement is a selector that contains values, a key, and an operator that
  2404. relates the key and values.
  2405. properties:
  2406. key:
  2407. description: key is the label key that the selector applies to.
  2408. type: string
  2409. operator:
  2410. description: |-
  2411. operator represents a key's relationship to a set of values.
  2412. Valid operators are In, NotIn, Exists and DoesNotExist.
  2413. type: string
  2414. values:
  2415. description: |-
  2416. values is an array of string values. If the operator is In or NotIn,
  2417. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2418. the values array must be empty. This array is replaced during a strategic
  2419. merge patch.
  2420. items:
  2421. type: string
  2422. type: array
  2423. x-kubernetes-list-type: atomic
  2424. required:
  2425. - key
  2426. - operator
  2427. type: object
  2428. type: array
  2429. x-kubernetes-list-type: atomic
  2430. matchLabels:
  2431. additionalProperties:
  2432. type: string
  2433. description: |-
  2434. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2435. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2436. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2437. type: object
  2438. type: object
  2439. x-kubernetes-map-type: atomic
  2440. namespaces:
  2441. description: Choose namespaces by name
  2442. items:
  2443. maxLength: 63
  2444. minLength: 1
  2445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2446. type: string
  2447. type: array
  2448. type: object
  2449. type: array
  2450. controller:
  2451. description: |-
  2452. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2453. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2454. type: string
  2455. provider:
  2456. description: Used to configure the provider. Only one provider may be set
  2457. maxProperties: 1
  2458. minProperties: 1
  2459. properties:
  2460. akeyless:
  2461. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2462. properties:
  2463. akeylessGWApiURL:
  2464. description: Akeyless GW API Url from which the secrets to be fetched from.
  2465. type: string
  2466. authSecretRef:
  2467. description: Auth configures how the operator authenticates with Akeyless.
  2468. properties:
  2469. kubernetesAuth:
  2470. description: |-
  2471. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2472. token stored in the named Secret resource.
  2473. properties:
  2474. accessID:
  2475. description: the Akeyless Kubernetes auth-method access-id
  2476. type: string
  2477. k8sConfName:
  2478. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2479. type: string
  2480. secretRef:
  2481. description: |-
  2482. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2483. for authenticating with Akeyless. If a name is specified without a key,
  2484. `token` is the default. If one is not specified, the one bound to
  2485. the controller will be used.
  2486. properties:
  2487. key:
  2488. description: |-
  2489. A key in the referenced Secret.
  2490. Some instances of this field may be defaulted, in others it may be required.
  2491. maxLength: 253
  2492. minLength: 1
  2493. pattern: ^[-._a-zA-Z0-9]+$
  2494. type: string
  2495. name:
  2496. description: The name of the Secret resource being referred to.
  2497. maxLength: 253
  2498. minLength: 1
  2499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2500. type: string
  2501. namespace:
  2502. description: |-
  2503. The namespace of the Secret resource being referred to.
  2504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2505. maxLength: 63
  2506. minLength: 1
  2507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2508. type: string
  2509. type: object
  2510. serviceAccountRef:
  2511. description: |-
  2512. Optional service account field containing the name of a kubernetes ServiceAccount.
  2513. If the service account is specified, the service account secret token JWT will be used
  2514. for authenticating with Akeyless. If the service account selector is not supplied,
  2515. the secretRef will be used instead.
  2516. properties:
  2517. audiences:
  2518. description: |-
  2519. Audience specifies the `aud` claim for the service account token
  2520. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2521. then this audiences will be appended to the list
  2522. items:
  2523. type: string
  2524. type: array
  2525. name:
  2526. description: The name of the ServiceAccount resource being referred to.
  2527. maxLength: 253
  2528. minLength: 1
  2529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2530. type: string
  2531. namespace:
  2532. description: |-
  2533. Namespace of the resource being referred to.
  2534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2535. maxLength: 63
  2536. minLength: 1
  2537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2538. type: string
  2539. required:
  2540. - name
  2541. type: object
  2542. required:
  2543. - accessID
  2544. - k8sConfName
  2545. type: object
  2546. secretRef:
  2547. description: |-
  2548. Reference to a Secret that contains the details
  2549. to authenticate with Akeyless.
  2550. properties:
  2551. accessID:
  2552. description: The SecretAccessID is used for authentication
  2553. properties:
  2554. key:
  2555. description: |-
  2556. A key in the referenced Secret.
  2557. Some instances of this field may be defaulted, in others it may be required.
  2558. maxLength: 253
  2559. minLength: 1
  2560. pattern: ^[-._a-zA-Z0-9]+$
  2561. type: string
  2562. name:
  2563. description: The name of the Secret resource being referred to.
  2564. maxLength: 253
  2565. minLength: 1
  2566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2567. type: string
  2568. namespace:
  2569. description: |-
  2570. The namespace of the Secret resource being referred to.
  2571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2572. maxLength: 63
  2573. minLength: 1
  2574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2575. type: string
  2576. type: object
  2577. accessType:
  2578. description: |-
  2579. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2580. In some instances, `key` is a required field.
  2581. properties:
  2582. key:
  2583. description: |-
  2584. A key in the referenced Secret.
  2585. Some instances of this field may be defaulted, in others it may be required.
  2586. maxLength: 253
  2587. minLength: 1
  2588. pattern: ^[-._a-zA-Z0-9]+$
  2589. type: string
  2590. name:
  2591. description: The name of the Secret resource being referred to.
  2592. maxLength: 253
  2593. minLength: 1
  2594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2595. type: string
  2596. namespace:
  2597. description: |-
  2598. The namespace of the Secret resource being referred to.
  2599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2600. maxLength: 63
  2601. minLength: 1
  2602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2603. type: string
  2604. type: object
  2605. accessTypeParam:
  2606. description: |-
  2607. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2608. In some instances, `key` is a required field.
  2609. properties:
  2610. key:
  2611. description: |-
  2612. A key in the referenced Secret.
  2613. Some instances of this field may be defaulted, in others it may be required.
  2614. maxLength: 253
  2615. minLength: 1
  2616. pattern: ^[-._a-zA-Z0-9]+$
  2617. type: string
  2618. name:
  2619. description: The name of the Secret resource being referred to.
  2620. maxLength: 253
  2621. minLength: 1
  2622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2623. type: string
  2624. namespace:
  2625. description: |-
  2626. The namespace of the Secret resource being referred to.
  2627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2628. maxLength: 63
  2629. minLength: 1
  2630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2631. type: string
  2632. type: object
  2633. type: object
  2634. serviceAccountRef:
  2635. description: |-
  2636. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2637. authentication on AKS Workload Identity. The operator obtains a federated
  2638. identity token from this ServiceAccount via the TokenRequest API instead
  2639. of using the ESO controller pod identity. Ignored for other access types.
  2640. properties:
  2641. audiences:
  2642. description: |-
  2643. Audience specifies the `aud` claim for the service account token
  2644. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2645. then this audiences will be appended to the list
  2646. items:
  2647. type: string
  2648. type: array
  2649. name:
  2650. description: The name of the ServiceAccount resource being referred to.
  2651. maxLength: 253
  2652. minLength: 1
  2653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2654. type: string
  2655. namespace:
  2656. description: |-
  2657. Namespace of the resource being referred to.
  2658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2659. maxLength: 63
  2660. minLength: 1
  2661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2662. type: string
  2663. required:
  2664. - name
  2665. type: object
  2666. type: object
  2667. caBundle:
  2668. description: |-
  2669. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2670. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2671. are used to validate the TLS connection.
  2672. format: byte
  2673. type: string
  2674. caProvider:
  2675. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2676. properties:
  2677. key:
  2678. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2679. maxLength: 253
  2680. minLength: 1
  2681. pattern: ^[-._a-zA-Z0-9]+$
  2682. type: string
  2683. name:
  2684. description: The name of the object located at the provider type.
  2685. maxLength: 253
  2686. minLength: 1
  2687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2688. type: string
  2689. namespace:
  2690. description: |-
  2691. The namespace the Provider type is in.
  2692. Can only be defined when used in a ClusterSecretStore.
  2693. maxLength: 63
  2694. minLength: 1
  2695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2696. type: string
  2697. type:
  2698. description: The type of provider to use such as "Secret", or "ConfigMap".
  2699. enum:
  2700. - Secret
  2701. - ConfigMap
  2702. type: string
  2703. required:
  2704. - name
  2705. - type
  2706. type: object
  2707. ignoreCache:
  2708. description: |-
  2709. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2710. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2711. type: boolean
  2712. required:
  2713. - akeylessGWApiURL
  2714. - authSecretRef
  2715. type: object
  2716. aws:
  2717. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2718. properties:
  2719. additionalRoles:
  2720. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2721. items:
  2722. type: string
  2723. type: array
  2724. auth:
  2725. description: |-
  2726. Auth defines the information necessary to authenticate against AWS
  2727. if not set aws sdk will infer credentials from your environment
  2728. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2729. properties:
  2730. jwt:
  2731. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2732. properties:
  2733. serviceAccountRef:
  2734. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2735. properties:
  2736. audiences:
  2737. description: |-
  2738. Audience specifies the `aud` claim for the service account token
  2739. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2740. then this audiences will be appended to the list
  2741. items:
  2742. type: string
  2743. type: array
  2744. name:
  2745. description: The name of the ServiceAccount resource being referred to.
  2746. maxLength: 253
  2747. minLength: 1
  2748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2749. type: string
  2750. namespace:
  2751. description: |-
  2752. Namespace of the resource being referred to.
  2753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2754. maxLength: 63
  2755. minLength: 1
  2756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2757. type: string
  2758. required:
  2759. - name
  2760. type: object
  2761. type: object
  2762. secretRef:
  2763. description: |-
  2764. AWSAuthSecretRef holds secret references for AWS credentials
  2765. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2766. properties:
  2767. accessKeyIDSecretRef:
  2768. description: The AccessKeyID is used for authentication
  2769. properties:
  2770. key:
  2771. description: |-
  2772. A key in the referenced Secret.
  2773. Some instances of this field may be defaulted, in others it may be required.
  2774. maxLength: 253
  2775. minLength: 1
  2776. pattern: ^[-._a-zA-Z0-9]+$
  2777. type: string
  2778. name:
  2779. description: The name of the Secret resource being referred to.
  2780. maxLength: 253
  2781. minLength: 1
  2782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2783. type: string
  2784. namespace:
  2785. description: |-
  2786. The namespace of the Secret resource being referred to.
  2787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2788. maxLength: 63
  2789. minLength: 1
  2790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2791. type: string
  2792. type: object
  2793. secretAccessKeySecretRef:
  2794. description: The SecretAccessKey is used for authentication
  2795. properties:
  2796. key:
  2797. description: |-
  2798. A key in the referenced Secret.
  2799. Some instances of this field may be defaulted, in others it may be required.
  2800. maxLength: 253
  2801. minLength: 1
  2802. pattern: ^[-._a-zA-Z0-9]+$
  2803. type: string
  2804. name:
  2805. description: The name of the Secret resource being referred to.
  2806. maxLength: 253
  2807. minLength: 1
  2808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2809. type: string
  2810. namespace:
  2811. description: |-
  2812. The namespace of the Secret resource being referred to.
  2813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2814. maxLength: 63
  2815. minLength: 1
  2816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2817. type: string
  2818. type: object
  2819. sessionTokenSecretRef:
  2820. description: |-
  2821. The SessionToken used for authentication
  2822. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2823. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2824. properties:
  2825. key:
  2826. description: |-
  2827. A key in the referenced Secret.
  2828. Some instances of this field may be defaulted, in others it may be required.
  2829. maxLength: 253
  2830. minLength: 1
  2831. pattern: ^[-._a-zA-Z0-9]+$
  2832. type: string
  2833. name:
  2834. description: The name of the Secret resource being referred to.
  2835. maxLength: 253
  2836. minLength: 1
  2837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2838. type: string
  2839. namespace:
  2840. description: |-
  2841. The namespace of the Secret resource being referred to.
  2842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2843. maxLength: 63
  2844. minLength: 1
  2845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2846. type: string
  2847. type: object
  2848. type: object
  2849. type: object
  2850. customSessionTags:
  2851. additionalProperties:
  2852. type: string
  2853. description: |-
  2854. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2855. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2856. type: object
  2857. x-kubernetes-validations:
  2858. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2859. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2860. externalID:
  2861. description: AWS External ID set on assumed IAM roles
  2862. type: string
  2863. prefix:
  2864. description: Prefix adds a prefix to all retrieved values.
  2865. type: string
  2866. region:
  2867. description: AWS Region to be used for the provider
  2868. type: string
  2869. role:
  2870. description: Role is a Role ARN which the provider will assume
  2871. type: string
  2872. secretsManager:
  2873. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2874. properties:
  2875. forceDeleteWithoutRecovery:
  2876. description: |-
  2877. Specifies whether to delete the secret without any recovery window. You
  2878. can't use both this parameter and RecoveryWindowInDays in the same call.
  2879. If you don't use either, then by default Secrets Manager uses a 30 day
  2880. recovery window.
  2881. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2882. type: boolean
  2883. recoveryWindowInDays:
  2884. description: |-
  2885. The number of days from 7 to 30 that Secrets Manager waits before
  2886. permanently deleting the secret. You can't use both this parameter and
  2887. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2888. then by default Secrets Manager uses a 30-day recovery window.
  2889. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2890. format: int64
  2891. type: integer
  2892. type: object
  2893. service:
  2894. description: Service defines which service should be used to fetch the secrets
  2895. enum:
  2896. - SecretsManager
  2897. - ParameterStore
  2898. - CertificateManager
  2899. type: string
  2900. sessionTags:
  2901. description: AWS STS assume role session tags
  2902. items:
  2903. description: |-
  2904. Tag is a key-value pair that can be attached to an AWS resource.
  2905. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2906. properties:
  2907. key:
  2908. type: string
  2909. value:
  2910. type: string
  2911. required:
  2912. - key
  2913. - value
  2914. type: object
  2915. type: array
  2916. sessionTagsPolicy:
  2917. default: None
  2918. description: |-
  2919. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2920. None (default): no tags are added.
  2921. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2922. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2923. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2924. enum:
  2925. - None
  2926. - Simple
  2927. - Custom
  2928. type: string
  2929. transitiveTagKeys:
  2930. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2931. items:
  2932. type: string
  2933. type: array
  2934. required:
  2935. - region
  2936. - service
  2937. type: object
  2938. azurekv:
  2939. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2940. properties:
  2941. authSecretRef:
  2942. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2943. properties:
  2944. clientCertificate:
  2945. description: The Azure ClientCertificate of the service principle used for authentication.
  2946. properties:
  2947. key:
  2948. description: |-
  2949. A key in the referenced Secret.
  2950. Some instances of this field may be defaulted, in others it may be required.
  2951. maxLength: 253
  2952. minLength: 1
  2953. pattern: ^[-._a-zA-Z0-9]+$
  2954. type: string
  2955. name:
  2956. description: The name of the Secret resource being referred to.
  2957. maxLength: 253
  2958. minLength: 1
  2959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2960. type: string
  2961. namespace:
  2962. description: |-
  2963. The namespace of the Secret resource being referred to.
  2964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2965. maxLength: 63
  2966. minLength: 1
  2967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2968. type: string
  2969. type: object
  2970. clientId:
  2971. description: The Azure clientId of the service principle or managed identity used for authentication.
  2972. properties:
  2973. key:
  2974. description: |-
  2975. A key in the referenced Secret.
  2976. Some instances of this field may be defaulted, in others it may be required.
  2977. maxLength: 253
  2978. minLength: 1
  2979. pattern: ^[-._a-zA-Z0-9]+$
  2980. type: string
  2981. name:
  2982. description: The name of the Secret resource being referred to.
  2983. maxLength: 253
  2984. minLength: 1
  2985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2986. type: string
  2987. namespace:
  2988. description: |-
  2989. The namespace of the Secret resource being referred to.
  2990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2991. maxLength: 63
  2992. minLength: 1
  2993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2994. type: string
  2995. type: object
  2996. clientSecret:
  2997. description: The Azure ClientSecret of the service principle used for authentication.
  2998. properties:
  2999. key:
  3000. description: |-
  3001. A key in the referenced Secret.
  3002. Some instances of this field may be defaulted, in others it may be required.
  3003. maxLength: 253
  3004. minLength: 1
  3005. pattern: ^[-._a-zA-Z0-9]+$
  3006. type: string
  3007. name:
  3008. description: The name of the Secret resource being referred to.
  3009. maxLength: 253
  3010. minLength: 1
  3011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3012. type: string
  3013. namespace:
  3014. description: |-
  3015. The namespace of the Secret resource being referred to.
  3016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3017. maxLength: 63
  3018. minLength: 1
  3019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3020. type: string
  3021. type: object
  3022. tenantId:
  3023. description: The Azure tenantId of the managed identity used for authentication.
  3024. properties:
  3025. key:
  3026. description: |-
  3027. A key in the referenced Secret.
  3028. Some instances of this field may be defaulted, in others it may be required.
  3029. maxLength: 253
  3030. minLength: 1
  3031. pattern: ^[-._a-zA-Z0-9]+$
  3032. type: string
  3033. name:
  3034. description: The name of the Secret resource being referred to.
  3035. maxLength: 253
  3036. minLength: 1
  3037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3038. type: string
  3039. namespace:
  3040. description: |-
  3041. The namespace of the Secret resource being referred to.
  3042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3043. maxLength: 63
  3044. minLength: 1
  3045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3046. type: string
  3047. type: object
  3048. type: object
  3049. authType:
  3050. default: ServicePrincipal
  3051. description: |-
  3052. Auth type defines how to authenticate to the keyvault service.
  3053. Valid values are:
  3054. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3055. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3056. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3057. enum:
  3058. - ServicePrincipal
  3059. - ManagedIdentity
  3060. - WorkloadIdentity
  3061. type: string
  3062. customCloudConfig:
  3063. description: |-
  3064. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3065. Required when EnvironmentType is AzureStackCloud.
  3066. Optional for other environment types - useful for Azure China when using Workload Identity
  3067. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3068. standard China Cloud endpoint (login.chinacloudapi.cn).
  3069. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3070. configuration is not supported with the legacy go-autorest SDK.
  3071. properties:
  3072. activeDirectoryEndpoint:
  3073. description: |-
  3074. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3075. Required when using custom cloud configuration
  3076. type: string
  3077. keyVaultDNSSuffix:
  3078. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3079. type: string
  3080. keyVaultEndpoint:
  3081. description: KeyVaultEndpoint is the Key Vault service endpoint
  3082. type: string
  3083. resourceManagerEndpoint:
  3084. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3085. type: string
  3086. required:
  3087. - activeDirectoryEndpoint
  3088. type: object
  3089. environmentType:
  3090. default: PublicCloud
  3091. description: |-
  3092. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3093. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3094. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3095. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3096. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3097. enum:
  3098. - PublicCloud
  3099. - USGovernmentCloud
  3100. - ChinaCloud
  3101. - GermanCloud
  3102. - AzureStackCloud
  3103. type: string
  3104. identityId:
  3105. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3106. type: string
  3107. serviceAccountRef:
  3108. description: |-
  3109. ServiceAccountRef specified the service account
  3110. that should be used when authenticating with WorkloadIdentity.
  3111. properties:
  3112. audiences:
  3113. description: |-
  3114. Audience specifies the `aud` claim for the service account token
  3115. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3116. then this audiences will be appended to the list
  3117. items:
  3118. type: string
  3119. type: array
  3120. name:
  3121. description: The name of the ServiceAccount resource being referred to.
  3122. maxLength: 253
  3123. minLength: 1
  3124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3125. type: string
  3126. namespace:
  3127. description: |-
  3128. Namespace of the resource being referred to.
  3129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3130. maxLength: 63
  3131. minLength: 1
  3132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3133. type: string
  3134. required:
  3135. - name
  3136. type: object
  3137. tenantId:
  3138. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3139. type: string
  3140. useAzureSDK:
  3141. default: false
  3142. description: |-
  3143. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3144. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3145. type: boolean
  3146. vaultUrl:
  3147. description: Vault Url from which the secrets to be fetched from.
  3148. type: string
  3149. required:
  3150. - vaultUrl
  3151. type: object
  3152. barbican:
  3153. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3154. properties:
  3155. auth:
  3156. description: BarbicanAuth contains the authentication information for Barbican.
  3157. properties:
  3158. password:
  3159. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3160. properties:
  3161. secretRef:
  3162. description: |-
  3163. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3164. In some instances, `key` is a required field.
  3165. properties:
  3166. key:
  3167. description: |-
  3168. A key in the referenced Secret.
  3169. Some instances of this field may be defaulted, in others it may be required.
  3170. maxLength: 253
  3171. minLength: 1
  3172. pattern: ^[-._a-zA-Z0-9]+$
  3173. type: string
  3174. name:
  3175. description: The name of the Secret resource being referred to.
  3176. maxLength: 253
  3177. minLength: 1
  3178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3179. type: string
  3180. namespace:
  3181. description: |-
  3182. The namespace of the Secret resource being referred to.
  3183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3184. maxLength: 63
  3185. minLength: 1
  3186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3187. type: string
  3188. type: object
  3189. required:
  3190. - secretRef
  3191. type: object
  3192. username:
  3193. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3194. maxProperties: 1
  3195. minProperties: 1
  3196. properties:
  3197. secretRef:
  3198. description: |-
  3199. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3200. In some instances, `key` is a required field.
  3201. properties:
  3202. key:
  3203. description: |-
  3204. A key in the referenced Secret.
  3205. Some instances of this field may be defaulted, in others it may be required.
  3206. maxLength: 253
  3207. minLength: 1
  3208. pattern: ^[-._a-zA-Z0-9]+$
  3209. type: string
  3210. name:
  3211. description: The name of the Secret resource being referred to.
  3212. maxLength: 253
  3213. minLength: 1
  3214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3215. type: string
  3216. namespace:
  3217. description: |-
  3218. The namespace of the Secret resource being referred to.
  3219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3220. maxLength: 63
  3221. minLength: 1
  3222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3223. type: string
  3224. type: object
  3225. value:
  3226. type: string
  3227. type: object
  3228. required:
  3229. - password
  3230. - username
  3231. type: object
  3232. authURL:
  3233. type: string
  3234. domainName:
  3235. type: string
  3236. region:
  3237. type: string
  3238. tenantName:
  3239. type: string
  3240. required:
  3241. - auth
  3242. type: object
  3243. beyondtrust:
  3244. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3245. properties:
  3246. auth:
  3247. description: Auth configures how the operator authenticates with Beyondtrust.
  3248. properties:
  3249. apiKey:
  3250. description: APIKey If not provided then ClientID/ClientSecret become required.
  3251. properties:
  3252. secretRef:
  3253. description: SecretRef references a key in a secret that will be used as value.
  3254. properties:
  3255. key:
  3256. description: |-
  3257. A key in the referenced Secret.
  3258. Some instances of this field may be defaulted, in others it may be required.
  3259. maxLength: 253
  3260. minLength: 1
  3261. pattern: ^[-._a-zA-Z0-9]+$
  3262. type: string
  3263. name:
  3264. description: The name of the Secret resource being referred to.
  3265. maxLength: 253
  3266. minLength: 1
  3267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3268. type: string
  3269. namespace:
  3270. description: |-
  3271. The namespace of the Secret resource being referred to.
  3272. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3273. maxLength: 63
  3274. minLength: 1
  3275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3276. type: string
  3277. type: object
  3278. value:
  3279. description: Value can be specified directly to set a value without using a secret.
  3280. type: string
  3281. type: object
  3282. certificate:
  3283. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3284. properties:
  3285. secretRef:
  3286. description: SecretRef references a key in a secret that will be used as value.
  3287. properties:
  3288. key:
  3289. description: |-
  3290. A key in the referenced Secret.
  3291. Some instances of this field may be defaulted, in others it may be required.
  3292. maxLength: 253
  3293. minLength: 1
  3294. pattern: ^[-._a-zA-Z0-9]+$
  3295. type: string
  3296. name:
  3297. description: The name of the Secret resource being referred to.
  3298. maxLength: 253
  3299. minLength: 1
  3300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3301. type: string
  3302. namespace:
  3303. description: |-
  3304. The namespace of the Secret resource being referred to.
  3305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3306. maxLength: 63
  3307. minLength: 1
  3308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3309. type: string
  3310. type: object
  3311. value:
  3312. description: Value can be specified directly to set a value without using a secret.
  3313. type: string
  3314. type: object
  3315. certificateKey:
  3316. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3317. properties:
  3318. secretRef:
  3319. description: SecretRef references a key in a secret that will be used as value.
  3320. properties:
  3321. key:
  3322. description: |-
  3323. A key in the referenced Secret.
  3324. Some instances of this field may be defaulted, in others it may be required.
  3325. maxLength: 253
  3326. minLength: 1
  3327. pattern: ^[-._a-zA-Z0-9]+$
  3328. type: string
  3329. name:
  3330. description: The name of the Secret resource being referred to.
  3331. maxLength: 253
  3332. minLength: 1
  3333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3334. type: string
  3335. namespace:
  3336. description: |-
  3337. The namespace of the Secret resource being referred to.
  3338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3339. maxLength: 63
  3340. minLength: 1
  3341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3342. type: string
  3343. type: object
  3344. value:
  3345. description: Value can be specified directly to set a value without using a secret.
  3346. type: string
  3347. type: object
  3348. clientId:
  3349. description: ClientID is the API OAuth Client ID.
  3350. properties:
  3351. secretRef:
  3352. description: SecretRef references a key in a secret that will be used as value.
  3353. properties:
  3354. key:
  3355. description: |-
  3356. A key in the referenced Secret.
  3357. Some instances of this field may be defaulted, in others it may be required.
  3358. maxLength: 253
  3359. minLength: 1
  3360. pattern: ^[-._a-zA-Z0-9]+$
  3361. type: string
  3362. name:
  3363. description: The name of the Secret resource being referred to.
  3364. maxLength: 253
  3365. minLength: 1
  3366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3367. type: string
  3368. namespace:
  3369. description: |-
  3370. The namespace of the Secret resource being referred to.
  3371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3372. maxLength: 63
  3373. minLength: 1
  3374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3375. type: string
  3376. type: object
  3377. value:
  3378. description: Value can be specified directly to set a value without using a secret.
  3379. type: string
  3380. type: object
  3381. clientSecret:
  3382. description: ClientSecret is the API OAuth Client Secret.
  3383. properties:
  3384. secretRef:
  3385. description: SecretRef references a key in a secret that will be used as value.
  3386. properties:
  3387. key:
  3388. description: |-
  3389. A key in the referenced Secret.
  3390. Some instances of this field may be defaulted, in others it may be required.
  3391. maxLength: 253
  3392. minLength: 1
  3393. pattern: ^[-._a-zA-Z0-9]+$
  3394. type: string
  3395. name:
  3396. description: The name of the Secret resource being referred to.
  3397. maxLength: 253
  3398. minLength: 1
  3399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3400. type: string
  3401. namespace:
  3402. description: |-
  3403. The namespace of the Secret resource being referred to.
  3404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3405. maxLength: 63
  3406. minLength: 1
  3407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3408. type: string
  3409. type: object
  3410. value:
  3411. description: Value can be specified directly to set a value without using a secret.
  3412. type: string
  3413. type: object
  3414. type: object
  3415. server:
  3416. description: Auth configures how API server works.
  3417. properties:
  3418. apiUrl:
  3419. type: string
  3420. apiVersion:
  3421. type: string
  3422. clientTimeOutSeconds:
  3423. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3424. type: integer
  3425. decrypt:
  3426. default: true
  3427. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3428. type: boolean
  3429. retrievalType:
  3430. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3431. type: string
  3432. separator:
  3433. description: A character that separates the folder names.
  3434. type: string
  3435. verifyCA:
  3436. type: boolean
  3437. required:
  3438. - apiUrl
  3439. - verifyCA
  3440. type: object
  3441. required:
  3442. - auth
  3443. - server
  3444. type: object
  3445. beyondtrustworkloadcredentials:
  3446. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3447. properties:
  3448. auth:
  3449. description: |-
  3450. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3451. Currently supports API key authentication via Kubernetes secret reference.
  3452. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3453. properties:
  3454. apikey:
  3455. description: |-
  3456. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3457. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3458. properties:
  3459. token:
  3460. description: |-
  3461. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3462. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3463. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3464. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3465. properties:
  3466. key:
  3467. description: |-
  3468. A key in the referenced Secret.
  3469. Some instances of this field may be defaulted, in others it may be required.
  3470. maxLength: 253
  3471. minLength: 1
  3472. pattern: ^[-._a-zA-Z0-9]+$
  3473. type: string
  3474. name:
  3475. description: The name of the Secret resource being referred to.
  3476. maxLength: 253
  3477. minLength: 1
  3478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3479. type: string
  3480. namespace:
  3481. description: |-
  3482. The namespace of the Secret resource being referred to.
  3483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3484. maxLength: 63
  3485. minLength: 1
  3486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3487. type: string
  3488. type: object
  3489. required:
  3490. - token
  3491. type: object
  3492. required:
  3493. - apikey
  3494. type: object
  3495. caBundle:
  3496. description: |-
  3497. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3498. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3499. If not set, the system's trusted root certificates are used.
  3500. format: byte
  3501. type: string
  3502. caProvider:
  3503. description: |-
  3504. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3505. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3506. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3507. properties:
  3508. key:
  3509. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3510. maxLength: 253
  3511. minLength: 1
  3512. pattern: ^[-._a-zA-Z0-9]+$
  3513. type: string
  3514. name:
  3515. description: The name of the object located at the provider type.
  3516. maxLength: 253
  3517. minLength: 1
  3518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3519. type: string
  3520. namespace:
  3521. description: |-
  3522. The namespace the Provider type is in.
  3523. Can only be defined when used in a ClusterSecretStore.
  3524. maxLength: 63
  3525. minLength: 1
  3526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3527. type: string
  3528. type:
  3529. description: The type of provider to use such as "Secret", or "ConfigMap".
  3530. enum:
  3531. - Secret
  3532. - ConfigMap
  3533. type: string
  3534. required:
  3535. - name
  3536. - type
  3537. type: object
  3538. folderPath:
  3539. description: |-
  3540. FolderPath specifies the default folder path for secret retrieval.
  3541. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3542. Example: "production/database" or "dev/api-keys"
  3543. Leave empty to retrieve secrets from the root folder.
  3544. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3545. type: string
  3546. server:
  3547. description: |-
  3548. Server configures the BeyondTrust Workload Credentials server connection details.
  3549. Includes the API URL and Site ID for your BeyondTrust instance.
  3550. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3551. properties:
  3552. apiUrl:
  3553. description: |-
  3554. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3555. This should be the full URL to your BeyondTrust instance.
  3556. Example: https://api.beyondtrust.io/siie
  3557. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3558. type: string
  3559. siteId:
  3560. description: |-
  3561. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3562. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3563. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3564. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3565. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3566. type: string
  3567. required:
  3568. - apiUrl
  3569. - siteId
  3570. type: object
  3571. required:
  3572. - auth
  3573. - server
  3574. type: object
  3575. bitwardensecretsmanager:
  3576. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3577. properties:
  3578. apiURL:
  3579. type: string
  3580. auth:
  3581. description: |-
  3582. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3583. Make sure that the token being used has permissions on the given secret.
  3584. properties:
  3585. secretRef:
  3586. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3587. properties:
  3588. credentials:
  3589. description: AccessToken used for the bitwarden instance.
  3590. properties:
  3591. key:
  3592. description: |-
  3593. A key in the referenced Secret.
  3594. Some instances of this field may be defaulted, in others it may be required.
  3595. maxLength: 253
  3596. minLength: 1
  3597. pattern: ^[-._a-zA-Z0-9]+$
  3598. type: string
  3599. name:
  3600. description: The name of the Secret resource being referred to.
  3601. maxLength: 253
  3602. minLength: 1
  3603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3604. type: string
  3605. namespace:
  3606. description: |-
  3607. The namespace of the Secret resource being referred to.
  3608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3609. maxLength: 63
  3610. minLength: 1
  3611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3612. type: string
  3613. type: object
  3614. required:
  3615. - credentials
  3616. type: object
  3617. required:
  3618. - secretRef
  3619. type: object
  3620. bitwardenServerSDKURL:
  3621. type: string
  3622. caBundle:
  3623. description: |-
  3624. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3625. can be performed.
  3626. type: string
  3627. caProvider:
  3628. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3629. properties:
  3630. key:
  3631. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3632. maxLength: 253
  3633. minLength: 1
  3634. pattern: ^[-._a-zA-Z0-9]+$
  3635. type: string
  3636. name:
  3637. description: The name of the object located at the provider type.
  3638. maxLength: 253
  3639. minLength: 1
  3640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3641. type: string
  3642. namespace:
  3643. description: |-
  3644. The namespace the Provider type is in.
  3645. Can only be defined when used in a ClusterSecretStore.
  3646. maxLength: 63
  3647. minLength: 1
  3648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3649. type: string
  3650. type:
  3651. description: The type of provider to use such as "Secret", or "ConfigMap".
  3652. enum:
  3653. - Secret
  3654. - ConfigMap
  3655. type: string
  3656. required:
  3657. - name
  3658. - type
  3659. type: object
  3660. identityURL:
  3661. type: string
  3662. organizationID:
  3663. description: OrganizationID determines which organization this secret store manages.
  3664. type: string
  3665. projectID:
  3666. description: ProjectID determines which project this secret store manages.
  3667. type: string
  3668. required:
  3669. - auth
  3670. - organizationID
  3671. - projectID
  3672. type: object
  3673. chef:
  3674. description: Chef configures this store to sync secrets with chef server
  3675. properties:
  3676. auth:
  3677. description: Auth defines the information necessary to authenticate against chef Server
  3678. properties:
  3679. secretRef:
  3680. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3681. properties:
  3682. privateKeySecretRef:
  3683. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3684. properties:
  3685. key:
  3686. description: |-
  3687. A key in the referenced Secret.
  3688. Some instances of this field may be defaulted, in others it may be required.
  3689. maxLength: 253
  3690. minLength: 1
  3691. pattern: ^[-._a-zA-Z0-9]+$
  3692. type: string
  3693. name:
  3694. description: The name of the Secret resource being referred to.
  3695. maxLength: 253
  3696. minLength: 1
  3697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3698. type: string
  3699. namespace:
  3700. description: |-
  3701. The namespace of the Secret resource being referred to.
  3702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3703. maxLength: 63
  3704. minLength: 1
  3705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3706. type: string
  3707. type: object
  3708. required:
  3709. - privateKeySecretRef
  3710. type: object
  3711. required:
  3712. - secretRef
  3713. type: object
  3714. serverUrl:
  3715. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3716. type: string
  3717. username:
  3718. description: UserName should be the user ID on the chef server
  3719. type: string
  3720. required:
  3721. - auth
  3722. - serverUrl
  3723. - username
  3724. type: object
  3725. cloudrusm:
  3726. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3727. properties:
  3728. auth:
  3729. description: CSMAuth contains a secretRef for credentials.
  3730. properties:
  3731. secretRef:
  3732. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3733. properties:
  3734. accessKeyIDSecretRef:
  3735. description: The AccessKeyID is used for authentication
  3736. properties:
  3737. key:
  3738. description: |-
  3739. A key in the referenced Secret.
  3740. Some instances of this field may be defaulted, in others it may be required.
  3741. maxLength: 253
  3742. minLength: 1
  3743. pattern: ^[-._a-zA-Z0-9]+$
  3744. type: string
  3745. name:
  3746. description: The name of the Secret resource being referred to.
  3747. maxLength: 253
  3748. minLength: 1
  3749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3750. type: string
  3751. namespace:
  3752. description: |-
  3753. The namespace of the Secret resource being referred to.
  3754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3755. maxLength: 63
  3756. minLength: 1
  3757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3758. type: string
  3759. type: object
  3760. accessKeySecretSecretRef:
  3761. description: The AccessKeySecret is used for authentication
  3762. properties:
  3763. key:
  3764. description: |-
  3765. A key in the referenced Secret.
  3766. Some instances of this field may be defaulted, in others it may be required.
  3767. maxLength: 253
  3768. minLength: 1
  3769. pattern: ^[-._a-zA-Z0-9]+$
  3770. type: string
  3771. name:
  3772. description: The name of the Secret resource being referred to.
  3773. maxLength: 253
  3774. minLength: 1
  3775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3776. type: string
  3777. namespace:
  3778. description: |-
  3779. The namespace of the Secret resource being referred to.
  3780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3781. maxLength: 63
  3782. minLength: 1
  3783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3784. type: string
  3785. type: object
  3786. required:
  3787. - accessKeyIDSecretRef
  3788. - accessKeySecretSecretRef
  3789. type: object
  3790. type: object
  3791. projectID:
  3792. description: ProjectID is the project, which the secrets are stored in.
  3793. type: string
  3794. required:
  3795. - auth
  3796. type: object
  3797. conjur:
  3798. description: Conjur configures this store to sync secrets using conjur provider
  3799. properties:
  3800. auth:
  3801. description: Defines authentication settings for connecting to Conjur.
  3802. maxProperties: 1
  3803. minProperties: 1
  3804. properties:
  3805. apikey:
  3806. description: Authenticates with Conjur using an API key.
  3807. properties:
  3808. account:
  3809. description: Account is the Conjur organization account name.
  3810. type: string
  3811. apiKeyRef:
  3812. description: |-
  3813. A reference to a specific 'key' containing the Conjur API key
  3814. within a Secret resource. In some instances, `key` is a required field.
  3815. properties:
  3816. key:
  3817. description: |-
  3818. A key in the referenced Secret.
  3819. Some instances of this field may be defaulted, in others it may be required.
  3820. maxLength: 253
  3821. minLength: 1
  3822. pattern: ^[-._a-zA-Z0-9]+$
  3823. type: string
  3824. name:
  3825. description: The name of the Secret resource being referred to.
  3826. maxLength: 253
  3827. minLength: 1
  3828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3829. type: string
  3830. namespace:
  3831. description: |-
  3832. The namespace of the Secret resource being referred to.
  3833. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3834. maxLength: 63
  3835. minLength: 1
  3836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3837. type: string
  3838. type: object
  3839. userRef:
  3840. description: |-
  3841. A reference to a specific 'key' containing the Conjur username
  3842. within a Secret resource. In some instances, `key` is a required field.
  3843. properties:
  3844. key:
  3845. description: |-
  3846. A key in the referenced Secret.
  3847. Some instances of this field may be defaulted, in others it may be required.
  3848. maxLength: 253
  3849. minLength: 1
  3850. pattern: ^[-._a-zA-Z0-9]+$
  3851. type: string
  3852. name:
  3853. description: The name of the Secret resource being referred to.
  3854. maxLength: 253
  3855. minLength: 1
  3856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3857. type: string
  3858. namespace:
  3859. description: |-
  3860. The namespace of the Secret resource being referred to.
  3861. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3862. maxLength: 63
  3863. minLength: 1
  3864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3865. type: string
  3866. type: object
  3867. required:
  3868. - account
  3869. - apiKeyRef
  3870. - userRef
  3871. type: object
  3872. cert:
  3873. description: Cert enables certificate-based authentication using a client certificate and key.
  3874. properties:
  3875. account:
  3876. description: Account is the Conjur organization account name.
  3877. type: string
  3878. clientCertRef:
  3879. description: |-
  3880. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3881. within a Secret resource. The certificate must be PEM-encoded.
  3882. properties:
  3883. key:
  3884. description: |-
  3885. A key in the referenced Secret.
  3886. Some instances of this field may be defaulted, in others it may be required.
  3887. maxLength: 253
  3888. minLength: 1
  3889. pattern: ^[-._a-zA-Z0-9]+$
  3890. type: string
  3891. name:
  3892. description: The name of the Secret resource being referred to.
  3893. maxLength: 253
  3894. minLength: 1
  3895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3896. type: string
  3897. namespace:
  3898. description: |-
  3899. The namespace of the Secret resource being referred to.
  3900. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3901. maxLength: 63
  3902. minLength: 1
  3903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3904. type: string
  3905. type: object
  3906. clientKeyRef:
  3907. description: |-
  3908. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3909. within a Secret resource. The key must be PEM-encoded.
  3910. properties:
  3911. key:
  3912. description: |-
  3913. A key in the referenced Secret.
  3914. Some instances of this field may be defaulted, in others it may be required.
  3915. maxLength: 253
  3916. minLength: 1
  3917. pattern: ^[-._a-zA-Z0-9]+$
  3918. type: string
  3919. name:
  3920. description: The name of the Secret resource being referred to.
  3921. maxLength: 253
  3922. minLength: 1
  3923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3924. type: string
  3925. namespace:
  3926. description: |-
  3927. The namespace of the Secret resource being referred to.
  3928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3929. maxLength: 63
  3930. minLength: 1
  3931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3932. type: string
  3933. type: object
  3934. hostId:
  3935. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3936. type: string
  3937. serviceID:
  3938. description: The conjur authn cert webservice id
  3939. type: string
  3940. required:
  3941. - account
  3942. - clientCertRef
  3943. - clientKeyRef
  3944. - serviceID
  3945. type: object
  3946. jwt:
  3947. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3948. properties:
  3949. account:
  3950. description: Account is the Conjur organization account name.
  3951. type: string
  3952. hostId:
  3953. description: |-
  3954. Optional HostID for JWT authentication. This may be used depending
  3955. on how the Conjur JWT authenticator policy is configured.
  3956. type: string
  3957. secretRef:
  3958. description: |-
  3959. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3960. authenticate with Conjur using the JWT authentication method.
  3961. properties:
  3962. key:
  3963. description: |-
  3964. A key in the referenced Secret.
  3965. Some instances of this field may be defaulted, in others it may be required.
  3966. maxLength: 253
  3967. minLength: 1
  3968. pattern: ^[-._a-zA-Z0-9]+$
  3969. type: string
  3970. name:
  3971. description: The name of the Secret resource being referred to.
  3972. maxLength: 253
  3973. minLength: 1
  3974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3975. type: string
  3976. namespace:
  3977. description: |-
  3978. The namespace of the Secret resource being referred to.
  3979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3980. maxLength: 63
  3981. minLength: 1
  3982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3983. type: string
  3984. type: object
  3985. serviceAccountRef:
  3986. description: |-
  3987. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3988. a token for with the `TokenRequest` API.
  3989. properties:
  3990. audiences:
  3991. description: |-
  3992. Audience specifies the `aud` claim for the service account token
  3993. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3994. then this audiences will be appended to the list
  3995. items:
  3996. type: string
  3997. type: array
  3998. name:
  3999. description: The name of the ServiceAccount resource being referred to.
  4000. maxLength: 253
  4001. minLength: 1
  4002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4003. type: string
  4004. namespace:
  4005. description: |-
  4006. Namespace of the resource being referred to.
  4007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4008. maxLength: 63
  4009. minLength: 1
  4010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4011. type: string
  4012. required:
  4013. - name
  4014. type: object
  4015. serviceID:
  4016. description: The conjur authn jwt webservice id
  4017. type: string
  4018. required:
  4019. - account
  4020. - serviceID
  4021. type: object
  4022. type: object
  4023. caBundle:
  4024. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4025. type: string
  4026. caProvider:
  4027. description: |-
  4028. Used to provide custom certificate authority (CA) certificates
  4029. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4030. that contains a PEM-encoded certificate.
  4031. properties:
  4032. key:
  4033. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4034. maxLength: 253
  4035. minLength: 1
  4036. pattern: ^[-._a-zA-Z0-9]+$
  4037. type: string
  4038. name:
  4039. description: The name of the object located at the provider type.
  4040. maxLength: 253
  4041. minLength: 1
  4042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4043. type: string
  4044. namespace:
  4045. description: |-
  4046. The namespace the Provider type is in.
  4047. Can only be defined when used in a ClusterSecretStore.
  4048. maxLength: 63
  4049. minLength: 1
  4050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4051. type: string
  4052. type:
  4053. description: The type of provider to use such as "Secret", or "ConfigMap".
  4054. enum:
  4055. - Secret
  4056. - ConfigMap
  4057. type: string
  4058. required:
  4059. - name
  4060. - type
  4061. type: object
  4062. url:
  4063. description: URL is the endpoint of the Conjur instance.
  4064. type: string
  4065. required:
  4066. - auth
  4067. - url
  4068. type: object
  4069. delinea:
  4070. description: |-
  4071. Delinea DevOps Secrets Vault
  4072. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4073. properties:
  4074. clientId:
  4075. description: ClientID is the non-secret part of the credential.
  4076. properties:
  4077. secretRef:
  4078. description: SecretRef references a key in a secret that will be used as value.
  4079. properties:
  4080. key:
  4081. description: |-
  4082. A key in the referenced Secret.
  4083. Some instances of this field may be defaulted, in others it may be required.
  4084. maxLength: 253
  4085. minLength: 1
  4086. pattern: ^[-._a-zA-Z0-9]+$
  4087. type: string
  4088. name:
  4089. description: The name of the Secret resource being referred to.
  4090. maxLength: 253
  4091. minLength: 1
  4092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4093. type: string
  4094. namespace:
  4095. description: |-
  4096. The namespace of the Secret resource being referred to.
  4097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4098. maxLength: 63
  4099. minLength: 1
  4100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4101. type: string
  4102. type: object
  4103. value:
  4104. description: Value can be specified directly to set a value without using a secret.
  4105. type: string
  4106. type: object
  4107. clientSecret:
  4108. description: ClientSecret is the secret part of the credential.
  4109. properties:
  4110. secretRef:
  4111. description: SecretRef references a key in a secret that will be used as value.
  4112. properties:
  4113. key:
  4114. description: |-
  4115. A key in the referenced Secret.
  4116. Some instances of this field may be defaulted, in others it may be required.
  4117. maxLength: 253
  4118. minLength: 1
  4119. pattern: ^[-._a-zA-Z0-9]+$
  4120. type: string
  4121. name:
  4122. description: The name of the Secret resource being referred to.
  4123. maxLength: 253
  4124. minLength: 1
  4125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4126. type: string
  4127. namespace:
  4128. description: |-
  4129. The namespace of the Secret resource being referred to.
  4130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4131. maxLength: 63
  4132. minLength: 1
  4133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4134. type: string
  4135. type: object
  4136. value:
  4137. description: Value can be specified directly to set a value without using a secret.
  4138. type: string
  4139. type: object
  4140. tenant:
  4141. description: Tenant is the chosen hostname / site name.
  4142. type: string
  4143. tld:
  4144. description: |-
  4145. TLD is based on the server location that was chosen during provisioning.
  4146. If unset, defaults to "com".
  4147. type: string
  4148. urlTemplate:
  4149. description: |-
  4150. URLTemplate
  4151. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4152. type: string
  4153. required:
  4154. - clientId
  4155. - clientSecret
  4156. - tenant
  4157. type: object
  4158. doppler:
  4159. description: Doppler configures this store to sync secrets using the Doppler provider
  4160. properties:
  4161. auth:
  4162. description: Auth configures how the Operator authenticates with the Doppler API
  4163. properties:
  4164. oidcConfig:
  4165. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4166. properties:
  4167. expirationSeconds:
  4168. default: 600
  4169. description: |-
  4170. ExpirationSeconds sets the ServiceAccount token validity duration.
  4171. Defaults to 10 minutes.
  4172. format: int64
  4173. type: integer
  4174. identity:
  4175. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4176. type: string
  4177. serviceAccountRef:
  4178. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4179. properties:
  4180. audiences:
  4181. description: |-
  4182. Audience specifies the `aud` claim for the service account token
  4183. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4184. then this audiences will be appended to the list
  4185. items:
  4186. type: string
  4187. type: array
  4188. name:
  4189. description: The name of the ServiceAccount resource being referred to.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4193. type: string
  4194. namespace:
  4195. description: |-
  4196. Namespace of the resource being referred to.
  4197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4198. maxLength: 63
  4199. minLength: 1
  4200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4201. type: string
  4202. required:
  4203. - name
  4204. type: object
  4205. required:
  4206. - identity
  4207. - serviceAccountRef
  4208. type: object
  4209. secretRef:
  4210. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4211. properties:
  4212. dopplerToken:
  4213. description: |-
  4214. The DopplerToken is used for authentication.
  4215. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4216. The Key attribute defaults to dopplerToken if not specified.
  4217. properties:
  4218. key:
  4219. description: |-
  4220. A key in the referenced Secret.
  4221. Some instances of this field may be defaulted, in others it may be required.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[-._a-zA-Z0-9]+$
  4225. type: string
  4226. name:
  4227. description: The name of the Secret resource being referred to.
  4228. maxLength: 253
  4229. minLength: 1
  4230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4231. type: string
  4232. namespace:
  4233. description: |-
  4234. The namespace of the Secret resource being referred to.
  4235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4236. maxLength: 63
  4237. minLength: 1
  4238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4239. type: string
  4240. type: object
  4241. required:
  4242. - dopplerToken
  4243. type: object
  4244. type: object
  4245. x-kubernetes-validations:
  4246. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4247. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4248. config:
  4249. description: Doppler config (required if not using a Service Token)
  4250. type: string
  4251. format:
  4252. description: Format enables the downloading of secrets as a file (string)
  4253. enum:
  4254. - json
  4255. - dotnet-json
  4256. - env
  4257. - yaml
  4258. - docker
  4259. type: string
  4260. nameTransformer:
  4261. description: Environment variable compatible name transforms that change secret names to a different format
  4262. enum:
  4263. - upper-camel
  4264. - camel
  4265. - lower-snake
  4266. - tf-var
  4267. - dotnet-env
  4268. - lower-kebab
  4269. type: string
  4270. project:
  4271. description: Doppler project (required if not using a Service Token)
  4272. type: string
  4273. required:
  4274. - auth
  4275. type: object
  4276. dvls:
  4277. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4278. properties:
  4279. auth:
  4280. description: Auth defines the authentication method to use.
  4281. properties:
  4282. secretRef:
  4283. description: SecretRef contains the Application ID and Application Secret for authentication.
  4284. properties:
  4285. appId:
  4286. description: AppID is the reference to the secret containing the Application ID.
  4287. properties:
  4288. key:
  4289. description: |-
  4290. A key in the referenced Secret.
  4291. Some instances of this field may be defaulted, in others it may be required.
  4292. maxLength: 253
  4293. minLength: 1
  4294. pattern: ^[-._a-zA-Z0-9]+$
  4295. type: string
  4296. name:
  4297. description: The name of the Secret resource being referred to.
  4298. maxLength: 253
  4299. minLength: 1
  4300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4301. type: string
  4302. namespace:
  4303. description: |-
  4304. The namespace of the Secret resource being referred to.
  4305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4306. maxLength: 63
  4307. minLength: 1
  4308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4309. type: string
  4310. type: object
  4311. appSecret:
  4312. description: AppSecret is the reference to the secret containing the Application Secret.
  4313. properties:
  4314. key:
  4315. description: |-
  4316. A key in the referenced Secret.
  4317. Some instances of this field may be defaulted, in others it may be required.
  4318. maxLength: 253
  4319. minLength: 1
  4320. pattern: ^[-._a-zA-Z0-9]+$
  4321. type: string
  4322. name:
  4323. description: The name of the Secret resource being referred to.
  4324. maxLength: 253
  4325. minLength: 1
  4326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4327. type: string
  4328. namespace:
  4329. description: |-
  4330. The namespace of the Secret resource being referred to.
  4331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4332. maxLength: 63
  4333. minLength: 1
  4334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4335. type: string
  4336. type: object
  4337. required:
  4338. - appId
  4339. - appSecret
  4340. type: object
  4341. required:
  4342. - secretRef
  4343. type: object
  4344. insecure:
  4345. description: |-
  4346. Insecure allows connecting to DVLS over plain HTTP.
  4347. This is NOT RECOMMENDED for production use.
  4348. Set to true only if you understand the security implications.
  4349. type: boolean
  4350. serverUrl:
  4351. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4352. type: string
  4353. vault:
  4354. description: |-
  4355. Vault is the name or UUID of the vault to fetch secrets from.
  4356. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4357. type: string
  4358. required:
  4359. - auth
  4360. - serverUrl
  4361. type: object
  4362. fake:
  4363. description: Fake configures a store with static key/value pairs
  4364. properties:
  4365. data:
  4366. items:
  4367. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4368. properties:
  4369. key:
  4370. type: string
  4371. value:
  4372. type: string
  4373. version:
  4374. type: string
  4375. required:
  4376. - key
  4377. - value
  4378. type: object
  4379. type: array
  4380. validationResult:
  4381. description: ValidationResult is defined type for the number of validation results.
  4382. type: integer
  4383. required:
  4384. - data
  4385. type: object
  4386. fortanix:
  4387. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4388. properties:
  4389. apiKey:
  4390. description: APIKey is the API token to access SDKMS Applications.
  4391. properties:
  4392. secretRef:
  4393. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4394. properties:
  4395. key:
  4396. description: |-
  4397. A key in the referenced Secret.
  4398. Some instances of this field may be defaulted, in others it may be required.
  4399. maxLength: 253
  4400. minLength: 1
  4401. pattern: ^[-._a-zA-Z0-9]+$
  4402. type: string
  4403. name:
  4404. description: The name of the Secret resource being referred to.
  4405. maxLength: 253
  4406. minLength: 1
  4407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4408. type: string
  4409. namespace:
  4410. description: |-
  4411. The namespace of the Secret resource being referred to.
  4412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4413. maxLength: 63
  4414. minLength: 1
  4415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4416. type: string
  4417. type: object
  4418. type: object
  4419. apiUrl:
  4420. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4421. type: string
  4422. type: object
  4423. gcpsm:
  4424. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4425. properties:
  4426. auth:
  4427. description: Auth defines the information necessary to authenticate against GCP
  4428. properties:
  4429. secretRef:
  4430. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4431. properties:
  4432. secretAccessKeySecretRef:
  4433. description: The SecretAccessKey is used for authentication
  4434. properties:
  4435. key:
  4436. description: |-
  4437. A key in the referenced Secret.
  4438. Some instances of this field may be defaulted, in others it may be required.
  4439. maxLength: 253
  4440. minLength: 1
  4441. pattern: ^[-._a-zA-Z0-9]+$
  4442. type: string
  4443. name:
  4444. description: The name of the Secret resource being referred to.
  4445. maxLength: 253
  4446. minLength: 1
  4447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4448. type: string
  4449. namespace:
  4450. description: |-
  4451. The namespace of the Secret resource being referred to.
  4452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4453. maxLength: 63
  4454. minLength: 1
  4455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4456. type: string
  4457. type: object
  4458. type: object
  4459. workloadIdentity:
  4460. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4461. properties:
  4462. clusterLocation:
  4463. description: |-
  4464. ClusterLocation is the location of the cluster
  4465. If not specified, it fetches information from the metadata server
  4466. type: string
  4467. clusterName:
  4468. description: |-
  4469. ClusterName is the name of the cluster
  4470. If not specified, it fetches information from the metadata server
  4471. type: string
  4472. clusterProjectID:
  4473. description: |-
  4474. ClusterProjectID is the project ID of the cluster
  4475. If not specified, it fetches information from the metadata server
  4476. type: string
  4477. serviceAccountRef:
  4478. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4479. properties:
  4480. audiences:
  4481. description: |-
  4482. Audience specifies the `aud` claim for the service account token
  4483. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4484. then this audiences will be appended to the list
  4485. items:
  4486. type: string
  4487. type: array
  4488. name:
  4489. description: The name of the ServiceAccount resource being referred to.
  4490. maxLength: 253
  4491. minLength: 1
  4492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4493. type: string
  4494. namespace:
  4495. description: |-
  4496. Namespace of the resource being referred to.
  4497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4498. maxLength: 63
  4499. minLength: 1
  4500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4501. type: string
  4502. required:
  4503. - name
  4504. type: object
  4505. required:
  4506. - serviceAccountRef
  4507. type: object
  4508. workloadIdentityFederation:
  4509. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4510. properties:
  4511. audience:
  4512. description: |-
  4513. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4514. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4515. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4516. type: string
  4517. awsSecurityCredentials:
  4518. description: |-
  4519. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4520. when using the AWS metadata server is not an option.
  4521. properties:
  4522. awsCredentialsSecretRef:
  4523. description: |-
  4524. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4525. Secret should be created with below names for keys
  4526. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4527. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4528. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4529. properties:
  4530. name:
  4531. description: name of the secret.
  4532. maxLength: 253
  4533. minLength: 1
  4534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4535. type: string
  4536. namespace:
  4537. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4538. maxLength: 63
  4539. minLength: 1
  4540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4541. type: string
  4542. required:
  4543. - name
  4544. type: object
  4545. region:
  4546. description: region is for configuring the AWS region to be used.
  4547. example: ap-south-1
  4548. maxLength: 50
  4549. minLength: 1
  4550. pattern: ^[a-z0-9-]+$
  4551. type: string
  4552. required:
  4553. - awsCredentialsSecretRef
  4554. - region
  4555. type: object
  4556. credConfig:
  4557. description: |-
  4558. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4559. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4560. serviceAccountRef must be used by providing operators service account details.
  4561. properties:
  4562. key:
  4563. description: key name holding the external account credential config.
  4564. maxLength: 253
  4565. minLength: 1
  4566. pattern: ^[-._a-zA-Z0-9]+$
  4567. type: string
  4568. name:
  4569. description: name of the configmap.
  4570. maxLength: 253
  4571. minLength: 1
  4572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4573. type: string
  4574. namespace:
  4575. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4576. maxLength: 63
  4577. minLength: 1
  4578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4579. type: string
  4580. required:
  4581. - key
  4582. - name
  4583. type: object
  4584. externalTokenEndpoint:
  4585. description: |-
  4586. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4587. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4588. URL is having the expected value.
  4589. type: string
  4590. gcpServiceAccountEmail:
  4591. description: |-
  4592. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4593. after Workload Identity Federation. Use this to grant access through the service account's
  4594. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4595. service_account_impersonation_url in the external account JSON from credConfig;
  4596. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4597. on that ServiceAccount.
  4598. example: my-gsa@my-project.iam.gserviceaccount.com
  4599. minLength: 1
  4600. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4601. type: string
  4602. serviceAccountRef:
  4603. description: |-
  4604. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4605. when Kubernetes is configured as provider in workload identity pool.
  4606. properties:
  4607. audiences:
  4608. description: |-
  4609. Audience specifies the `aud` claim for the service account token
  4610. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4611. then this audiences will be appended to the list
  4612. items:
  4613. type: string
  4614. type: array
  4615. name:
  4616. description: The name of the ServiceAccount resource being referred to.
  4617. maxLength: 253
  4618. minLength: 1
  4619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4620. type: string
  4621. namespace:
  4622. description: |-
  4623. Namespace of the resource being referred to.
  4624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4625. maxLength: 63
  4626. minLength: 1
  4627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4628. type: string
  4629. required:
  4630. - name
  4631. type: object
  4632. type: object
  4633. type: object
  4634. location:
  4635. description: Location optionally defines a location for a secret
  4636. type: string
  4637. projectID:
  4638. description: ProjectID project where secret is located
  4639. type: string
  4640. secretVersionSelectionPolicy:
  4641. default: LatestOrFail
  4642. description: |-
  4643. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4644. when "latest" is disabled or destroyed.
  4645. Possible values are:
  4646. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4647. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4648. type: string
  4649. type: object
  4650. github:
  4651. description: |-
  4652. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4653. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4654. properties:
  4655. appID:
  4656. description: appID specifies the Github APP that will be used to authenticate the client
  4657. format: int64
  4658. type: integer
  4659. auth:
  4660. description: auth configures how secret-manager authenticates with a Github instance.
  4661. properties:
  4662. privateKey:
  4663. description: |-
  4664. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4665. In some instances, `key` is a required field.
  4666. properties:
  4667. key:
  4668. description: |-
  4669. A key in the referenced Secret.
  4670. Some instances of this field may be defaulted, in others it may be required.
  4671. maxLength: 253
  4672. minLength: 1
  4673. pattern: ^[-._a-zA-Z0-9]+$
  4674. type: string
  4675. name:
  4676. description: The name of the Secret resource being referred to.
  4677. maxLength: 253
  4678. minLength: 1
  4679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4680. type: string
  4681. namespace:
  4682. description: |-
  4683. The namespace of the Secret resource being referred to.
  4684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4685. maxLength: 63
  4686. minLength: 1
  4687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4688. type: string
  4689. type: object
  4690. required:
  4691. - privateKey
  4692. type: object
  4693. environment:
  4694. description: environment will be used to fetch secrets from a particular environment within a github repository
  4695. type: string
  4696. installationID:
  4697. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4698. format: int64
  4699. type: integer
  4700. orgSecretVisibility:
  4701. description: |-
  4702. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4703. Valid values are "all" or "private".
  4704. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4705. whatever visibility they already have in GitHub.
  4706. enum:
  4707. - all
  4708. - private
  4709. type: string
  4710. organization:
  4711. description: organization will be used to fetch secrets from the Github organization
  4712. type: string
  4713. repository:
  4714. description: repository will be used to fetch secrets from the Github repository within an organization
  4715. type: string
  4716. uploadURL:
  4717. description: Upload URL for enterprise instances. Default to URL.
  4718. type: string
  4719. url:
  4720. default: https://github.com/
  4721. description: URL configures the Github instance URL. Defaults to https://github.com/.
  4722. type: string
  4723. required:
  4724. - appID
  4725. - auth
  4726. - installationID
  4727. - organization
  4728. type: object
  4729. gitlab:
  4730. description: GitLab configures this store to sync secrets using GitLab Variables provider
  4731. properties:
  4732. auth:
  4733. description: Auth configures how secret-manager authenticates with a GitLab instance.
  4734. properties:
  4735. SecretRef:
  4736. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  4737. properties:
  4738. accessToken:
  4739. description: AccessToken is used for authentication.
  4740. properties:
  4741. key:
  4742. description: |-
  4743. A key in the referenced Secret.
  4744. Some instances of this field may be defaulted, in others it may be required.
  4745. maxLength: 253
  4746. minLength: 1
  4747. pattern: ^[-._a-zA-Z0-9]+$
  4748. type: string
  4749. name:
  4750. description: The name of the Secret resource being referred to.
  4751. maxLength: 253
  4752. minLength: 1
  4753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4754. type: string
  4755. namespace:
  4756. description: |-
  4757. The namespace of the Secret resource being referred to.
  4758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4759. maxLength: 63
  4760. minLength: 1
  4761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4762. type: string
  4763. type: object
  4764. type: object
  4765. required:
  4766. - SecretRef
  4767. type: object
  4768. caBundle:
  4769. description: |-
  4770. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  4771. can be performed.
  4772. format: byte
  4773. type: string
  4774. caProvider:
  4775. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4776. properties:
  4777. key:
  4778. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4779. maxLength: 253
  4780. minLength: 1
  4781. pattern: ^[-._a-zA-Z0-9]+$
  4782. type: string
  4783. name:
  4784. description: The name of the object located at the provider type.
  4785. maxLength: 253
  4786. minLength: 1
  4787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4788. type: string
  4789. namespace:
  4790. description: |-
  4791. The namespace the Provider type is in.
  4792. Can only be defined when used in a ClusterSecretStore.
  4793. maxLength: 63
  4794. minLength: 1
  4795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4796. type: string
  4797. type:
  4798. description: The type of provider to use such as "Secret", or "ConfigMap".
  4799. enum:
  4800. - Secret
  4801. - ConfigMap
  4802. type: string
  4803. required:
  4804. - name
  4805. - type
  4806. type: object
  4807. environment:
  4808. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  4809. type: string
  4810. groupIDs:
  4811. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  4812. items:
  4813. type: string
  4814. type: array
  4815. inheritFromGroups:
  4816. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  4817. type: boolean
  4818. projectID:
  4819. description: ProjectID specifies a project where secrets are located.
  4820. type: string
  4821. url:
  4822. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  4823. type: string
  4824. required:
  4825. - auth
  4826. type: object
  4827. ibm:
  4828. description: IBM configures this store to sync secrets using IBM Cloud provider
  4829. properties:
  4830. auth:
  4831. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  4832. maxProperties: 1
  4833. minProperties: 1
  4834. properties:
  4835. containerAuth:
  4836. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  4837. properties:
  4838. iamEndpoint:
  4839. type: string
  4840. profile:
  4841. description: the IBM Trusted Profile
  4842. type: string
  4843. tokenLocation:
  4844. description: Location the token is mounted on the pod
  4845. type: string
  4846. required:
  4847. - profile
  4848. type: object
  4849. secretRef:
  4850. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  4851. properties:
  4852. iamEndpoint:
  4853. description: The IAM endpoint used to obain a token
  4854. type: string
  4855. secretApiKeySecretRef:
  4856. description: The SecretAccessKey is used for authentication
  4857. properties:
  4858. key:
  4859. description: |-
  4860. A key in the referenced Secret.
  4861. Some instances of this field may be defaulted, in others it may be required.
  4862. maxLength: 253
  4863. minLength: 1
  4864. pattern: ^[-._a-zA-Z0-9]+$
  4865. type: string
  4866. name:
  4867. description: The name of the Secret resource being referred to.
  4868. maxLength: 253
  4869. minLength: 1
  4870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4871. type: string
  4872. namespace:
  4873. description: |-
  4874. The namespace of the Secret resource being referred to.
  4875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4876. maxLength: 63
  4877. minLength: 1
  4878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4879. type: string
  4880. type: object
  4881. type: object
  4882. type: object
  4883. serviceUrl:
  4884. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  4885. type: string
  4886. required:
  4887. - auth
  4888. type: object
  4889. infisical:
  4890. description: Infisical configures this store to sync secrets using the Infisical provider
  4891. properties:
  4892. auth:
  4893. description: Auth configures how the Operator authenticates with the Infisical API
  4894. properties:
  4895. awsAuthCredentials:
  4896. description: AwsAuthCredentials represents the credentials for AWS authentication.
  4897. properties:
  4898. identityId:
  4899. description: |-
  4900. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4901. In some instances, `key` is a required field.
  4902. properties:
  4903. key:
  4904. description: |-
  4905. A key in the referenced Secret.
  4906. Some instances of this field may be defaulted, in others it may be required.
  4907. maxLength: 253
  4908. minLength: 1
  4909. pattern: ^[-._a-zA-Z0-9]+$
  4910. type: string
  4911. name:
  4912. description: The name of the Secret resource being referred to.
  4913. maxLength: 253
  4914. minLength: 1
  4915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4916. type: string
  4917. namespace:
  4918. description: |-
  4919. The namespace of the Secret resource being referred to.
  4920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4921. maxLength: 63
  4922. minLength: 1
  4923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4924. type: string
  4925. type: object
  4926. required:
  4927. - identityId
  4928. type: object
  4929. azureAuthCredentials:
  4930. description: AzureAuthCredentials represents the credentials for Azure authentication.
  4931. properties:
  4932. identityId:
  4933. description: |-
  4934. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4935. In some instances, `key` is a required field.
  4936. properties:
  4937. key:
  4938. description: |-
  4939. A key in the referenced Secret.
  4940. Some instances of this field may be defaulted, in others it may be required.
  4941. maxLength: 253
  4942. minLength: 1
  4943. pattern: ^[-._a-zA-Z0-9]+$
  4944. type: string
  4945. name:
  4946. description: The name of the Secret resource being referred to.
  4947. maxLength: 253
  4948. minLength: 1
  4949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4950. type: string
  4951. namespace:
  4952. description: |-
  4953. The namespace of the Secret resource being referred to.
  4954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4955. maxLength: 63
  4956. minLength: 1
  4957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4958. type: string
  4959. type: object
  4960. resource:
  4961. description: |-
  4962. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4963. In some instances, `key` is a required field.
  4964. properties:
  4965. key:
  4966. description: |-
  4967. A key in the referenced Secret.
  4968. Some instances of this field may be defaulted, in others it may be required.
  4969. maxLength: 253
  4970. minLength: 1
  4971. pattern: ^[-._a-zA-Z0-9]+$
  4972. type: string
  4973. name:
  4974. description: The name of the Secret resource being referred to.
  4975. maxLength: 253
  4976. minLength: 1
  4977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4978. type: string
  4979. namespace:
  4980. description: |-
  4981. The namespace of the Secret resource being referred to.
  4982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4983. maxLength: 63
  4984. minLength: 1
  4985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4986. type: string
  4987. type: object
  4988. required:
  4989. - identityId
  4990. type: object
  4991. gcpIamAuthCredentials:
  4992. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  4993. properties:
  4994. identityId:
  4995. description: |-
  4996. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4997. In some instances, `key` is a required field.
  4998. properties:
  4999. key:
  5000. description: |-
  5001. A key in the referenced Secret.
  5002. Some instances of this field may be defaulted, in others it may be required.
  5003. maxLength: 253
  5004. minLength: 1
  5005. pattern: ^[-._a-zA-Z0-9]+$
  5006. type: string
  5007. name:
  5008. description: The name of the Secret resource being referred to.
  5009. maxLength: 253
  5010. minLength: 1
  5011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5012. type: string
  5013. namespace:
  5014. description: |-
  5015. The namespace of the Secret resource being referred to.
  5016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5017. maxLength: 63
  5018. minLength: 1
  5019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5020. type: string
  5021. type: object
  5022. serviceAccountKeyFilePath:
  5023. description: |-
  5024. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5025. In some instances, `key` is a required field.
  5026. properties:
  5027. key:
  5028. description: |-
  5029. A key in the referenced Secret.
  5030. Some instances of this field may be defaulted, in others it may be required.
  5031. maxLength: 253
  5032. minLength: 1
  5033. pattern: ^[-._a-zA-Z0-9]+$
  5034. type: string
  5035. name:
  5036. description: The name of the Secret resource being referred to.
  5037. maxLength: 253
  5038. minLength: 1
  5039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5040. type: string
  5041. namespace:
  5042. description: |-
  5043. The namespace of the Secret resource being referred to.
  5044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5045. maxLength: 63
  5046. minLength: 1
  5047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5048. type: string
  5049. type: object
  5050. required:
  5051. - identityId
  5052. - serviceAccountKeyFilePath
  5053. type: object
  5054. gcpIdTokenAuthCredentials:
  5055. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5056. properties:
  5057. identityId:
  5058. description: |-
  5059. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5060. In some instances, `key` is a required field.
  5061. properties:
  5062. key:
  5063. description: |-
  5064. A key in the referenced Secret.
  5065. Some instances of this field may be defaulted, in others it may be required.
  5066. maxLength: 253
  5067. minLength: 1
  5068. pattern: ^[-._a-zA-Z0-9]+$
  5069. type: string
  5070. name:
  5071. description: The name of the Secret resource being referred to.
  5072. maxLength: 253
  5073. minLength: 1
  5074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5075. type: string
  5076. namespace:
  5077. description: |-
  5078. The namespace of the Secret resource being referred to.
  5079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5080. maxLength: 63
  5081. minLength: 1
  5082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5083. type: string
  5084. type: object
  5085. required:
  5086. - identityId
  5087. type: object
  5088. jwtAuthCredentials:
  5089. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5090. properties:
  5091. identityId:
  5092. description: |-
  5093. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5094. In some instances, `key` is a required field.
  5095. properties:
  5096. key:
  5097. description: |-
  5098. A key in the referenced Secret.
  5099. Some instances of this field may be defaulted, in others it may be required.
  5100. maxLength: 253
  5101. minLength: 1
  5102. pattern: ^[-._a-zA-Z0-9]+$
  5103. type: string
  5104. name:
  5105. description: The name of the Secret resource being referred to.
  5106. maxLength: 253
  5107. minLength: 1
  5108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5109. type: string
  5110. namespace:
  5111. description: |-
  5112. The namespace of the Secret resource being referred to.
  5113. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5114. maxLength: 63
  5115. minLength: 1
  5116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5117. type: string
  5118. type: object
  5119. jwt:
  5120. description: |-
  5121. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5122. In some instances, `key` is a required field.
  5123. properties:
  5124. key:
  5125. description: |-
  5126. A key in the referenced Secret.
  5127. Some instances of this field may be defaulted, in others it may be required.
  5128. maxLength: 253
  5129. minLength: 1
  5130. pattern: ^[-._a-zA-Z0-9]+$
  5131. type: string
  5132. name:
  5133. description: The name of the Secret resource being referred to.
  5134. maxLength: 253
  5135. minLength: 1
  5136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5137. type: string
  5138. namespace:
  5139. description: |-
  5140. The namespace of the Secret resource being referred to.
  5141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5142. maxLength: 63
  5143. minLength: 1
  5144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5145. type: string
  5146. type: object
  5147. required:
  5148. - identityId
  5149. - jwt
  5150. type: object
  5151. kubernetesAuthCredentials:
  5152. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5153. properties:
  5154. identityId:
  5155. description: |-
  5156. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5157. In some instances, `key` is a required field.
  5158. properties:
  5159. key:
  5160. description: |-
  5161. A key in the referenced Secret.
  5162. Some instances of this field may be defaulted, in others it may be required.
  5163. maxLength: 253
  5164. minLength: 1
  5165. pattern: ^[-._a-zA-Z0-9]+$
  5166. type: string
  5167. name:
  5168. description: The name of the Secret resource being referred to.
  5169. maxLength: 253
  5170. minLength: 1
  5171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5172. type: string
  5173. namespace:
  5174. description: |-
  5175. The namespace of the Secret resource being referred to.
  5176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5177. maxLength: 63
  5178. minLength: 1
  5179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5180. type: string
  5181. type: object
  5182. serviceAccountTokenPath:
  5183. description: |-
  5184. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5185. In some instances, `key` is a required field.
  5186. properties:
  5187. key:
  5188. description: |-
  5189. A key in the referenced Secret.
  5190. Some instances of this field may be defaulted, in others it may be required.
  5191. maxLength: 253
  5192. minLength: 1
  5193. pattern: ^[-._a-zA-Z0-9]+$
  5194. type: string
  5195. name:
  5196. description: The name of the Secret resource being referred to.
  5197. maxLength: 253
  5198. minLength: 1
  5199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5200. type: string
  5201. namespace:
  5202. description: |-
  5203. The namespace of the Secret resource being referred to.
  5204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5205. maxLength: 63
  5206. minLength: 1
  5207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5208. type: string
  5209. type: object
  5210. required:
  5211. - identityId
  5212. type: object
  5213. ldapAuthCredentials:
  5214. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5215. properties:
  5216. identityId:
  5217. description: |-
  5218. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5219. In some instances, `key` is a required field.
  5220. properties:
  5221. key:
  5222. description: |-
  5223. A key in the referenced Secret.
  5224. Some instances of this field may be defaulted, in others it may be required.
  5225. maxLength: 253
  5226. minLength: 1
  5227. pattern: ^[-._a-zA-Z0-9]+$
  5228. type: string
  5229. name:
  5230. description: The name of the Secret resource being referred to.
  5231. maxLength: 253
  5232. minLength: 1
  5233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5234. type: string
  5235. namespace:
  5236. description: |-
  5237. The namespace of the Secret resource being referred to.
  5238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5239. maxLength: 63
  5240. minLength: 1
  5241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5242. type: string
  5243. type: object
  5244. ldapPassword:
  5245. description: |-
  5246. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5247. In some instances, `key` is a required field.
  5248. properties:
  5249. key:
  5250. description: |-
  5251. A key in the referenced Secret.
  5252. Some instances of this field may be defaulted, in others it may be required.
  5253. maxLength: 253
  5254. minLength: 1
  5255. pattern: ^[-._a-zA-Z0-9]+$
  5256. type: string
  5257. name:
  5258. description: The name of the Secret resource being referred to.
  5259. maxLength: 253
  5260. minLength: 1
  5261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5262. type: string
  5263. namespace:
  5264. description: |-
  5265. The namespace of the Secret resource being referred to.
  5266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5267. maxLength: 63
  5268. minLength: 1
  5269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5270. type: string
  5271. type: object
  5272. ldapUsername:
  5273. description: |-
  5274. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5275. In some instances, `key` is a required field.
  5276. properties:
  5277. key:
  5278. description: |-
  5279. A key in the referenced Secret.
  5280. Some instances of this field may be defaulted, in others it may be required.
  5281. maxLength: 253
  5282. minLength: 1
  5283. pattern: ^[-._a-zA-Z0-9]+$
  5284. type: string
  5285. name:
  5286. description: The name of the Secret resource being referred to.
  5287. maxLength: 253
  5288. minLength: 1
  5289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5290. type: string
  5291. namespace:
  5292. description: |-
  5293. The namespace of the Secret resource being referred to.
  5294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5295. maxLength: 63
  5296. minLength: 1
  5297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5298. type: string
  5299. type: object
  5300. required:
  5301. - identityId
  5302. - ldapPassword
  5303. - ldapUsername
  5304. type: object
  5305. ociAuthCredentials:
  5306. description: OciAuthCredentials represents the credentials for OCI authentication.
  5307. properties:
  5308. fingerprint:
  5309. description: |-
  5310. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5311. In some instances, `key` is a required field.
  5312. properties:
  5313. key:
  5314. description: |-
  5315. A key in the referenced Secret.
  5316. Some instances of this field may be defaulted, in others it may be required.
  5317. maxLength: 253
  5318. minLength: 1
  5319. pattern: ^[-._a-zA-Z0-9]+$
  5320. type: string
  5321. name:
  5322. description: The name of the Secret resource being referred to.
  5323. maxLength: 253
  5324. minLength: 1
  5325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5326. type: string
  5327. namespace:
  5328. description: |-
  5329. The namespace of the Secret resource being referred to.
  5330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5331. maxLength: 63
  5332. minLength: 1
  5333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5334. type: string
  5335. type: object
  5336. identityId:
  5337. description: |-
  5338. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5339. In some instances, `key` is a required field.
  5340. properties:
  5341. key:
  5342. description: |-
  5343. A key in the referenced Secret.
  5344. Some instances of this field may be defaulted, in others it may be required.
  5345. maxLength: 253
  5346. minLength: 1
  5347. pattern: ^[-._a-zA-Z0-9]+$
  5348. type: string
  5349. name:
  5350. description: The name of the Secret resource being referred to.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5354. type: string
  5355. namespace:
  5356. description: |-
  5357. The namespace of the Secret resource being referred to.
  5358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5359. maxLength: 63
  5360. minLength: 1
  5361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5362. type: string
  5363. type: object
  5364. privateKey:
  5365. description: |-
  5366. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5367. In some instances, `key` is a required field.
  5368. properties:
  5369. key:
  5370. description: |-
  5371. A key in the referenced Secret.
  5372. Some instances of this field may be defaulted, in others it may be required.
  5373. maxLength: 253
  5374. minLength: 1
  5375. pattern: ^[-._a-zA-Z0-9]+$
  5376. type: string
  5377. name:
  5378. description: The name of the Secret resource being referred to.
  5379. maxLength: 253
  5380. minLength: 1
  5381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5382. type: string
  5383. namespace:
  5384. description: |-
  5385. The namespace of the Secret resource being referred to.
  5386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5387. maxLength: 63
  5388. minLength: 1
  5389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5390. type: string
  5391. type: object
  5392. privateKeyPassphrase:
  5393. description: |-
  5394. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5395. In some instances, `key` is a required field.
  5396. properties:
  5397. key:
  5398. description: |-
  5399. A key in the referenced Secret.
  5400. Some instances of this field may be defaulted, in others it may be required.
  5401. maxLength: 253
  5402. minLength: 1
  5403. pattern: ^[-._a-zA-Z0-9]+$
  5404. type: string
  5405. name:
  5406. description: The name of the Secret resource being referred to.
  5407. maxLength: 253
  5408. minLength: 1
  5409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5410. type: string
  5411. namespace:
  5412. description: |-
  5413. The namespace of the Secret resource being referred to.
  5414. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5415. maxLength: 63
  5416. minLength: 1
  5417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5418. type: string
  5419. type: object
  5420. region:
  5421. description: |-
  5422. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5423. In some instances, `key` is a required field.
  5424. properties:
  5425. key:
  5426. description: |-
  5427. A key in the referenced Secret.
  5428. Some instances of this field may be defaulted, in others it may be required.
  5429. maxLength: 253
  5430. minLength: 1
  5431. pattern: ^[-._a-zA-Z0-9]+$
  5432. type: string
  5433. name:
  5434. description: The name of the Secret resource being referred to.
  5435. maxLength: 253
  5436. minLength: 1
  5437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5438. type: string
  5439. namespace:
  5440. description: |-
  5441. The namespace of the Secret resource being referred to.
  5442. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5443. maxLength: 63
  5444. minLength: 1
  5445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5446. type: string
  5447. type: object
  5448. tenancyId:
  5449. description: |-
  5450. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5451. In some instances, `key` is a required field.
  5452. properties:
  5453. key:
  5454. description: |-
  5455. A key in the referenced Secret.
  5456. Some instances of this field may be defaulted, in others it may be required.
  5457. maxLength: 253
  5458. minLength: 1
  5459. pattern: ^[-._a-zA-Z0-9]+$
  5460. type: string
  5461. name:
  5462. description: The name of the Secret resource being referred to.
  5463. maxLength: 253
  5464. minLength: 1
  5465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5466. type: string
  5467. namespace:
  5468. description: |-
  5469. The namespace of the Secret resource being referred to.
  5470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5471. maxLength: 63
  5472. minLength: 1
  5473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5474. type: string
  5475. type: object
  5476. userId:
  5477. description: |-
  5478. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5479. In some instances, `key` is a required field.
  5480. properties:
  5481. key:
  5482. description: |-
  5483. A key in the referenced Secret.
  5484. Some instances of this field may be defaulted, in others it may be required.
  5485. maxLength: 253
  5486. minLength: 1
  5487. pattern: ^[-._a-zA-Z0-9]+$
  5488. type: string
  5489. name:
  5490. description: The name of the Secret resource being referred to.
  5491. maxLength: 253
  5492. minLength: 1
  5493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5494. type: string
  5495. namespace:
  5496. description: |-
  5497. The namespace of the Secret resource being referred to.
  5498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5499. maxLength: 63
  5500. minLength: 1
  5501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5502. type: string
  5503. type: object
  5504. required:
  5505. - fingerprint
  5506. - identityId
  5507. - privateKey
  5508. - region
  5509. - tenancyId
  5510. - userId
  5511. type: object
  5512. tokenAuthCredentials:
  5513. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5514. properties:
  5515. accessToken:
  5516. description: |-
  5517. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5518. In some instances, `key` is a required field.
  5519. properties:
  5520. key:
  5521. description: |-
  5522. A key in the referenced Secret.
  5523. Some instances of this field may be defaulted, in others it may be required.
  5524. maxLength: 253
  5525. minLength: 1
  5526. pattern: ^[-._a-zA-Z0-9]+$
  5527. type: string
  5528. name:
  5529. description: The name of the Secret resource being referred to.
  5530. maxLength: 253
  5531. minLength: 1
  5532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5533. type: string
  5534. namespace:
  5535. description: |-
  5536. The namespace of the Secret resource being referred to.
  5537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5538. maxLength: 63
  5539. minLength: 1
  5540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5541. type: string
  5542. type: object
  5543. required:
  5544. - accessToken
  5545. type: object
  5546. universalAuthCredentials:
  5547. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5548. properties:
  5549. clientId:
  5550. description: |-
  5551. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5552. In some instances, `key` is a required field.
  5553. properties:
  5554. key:
  5555. description: |-
  5556. A key in the referenced Secret.
  5557. Some instances of this field may be defaulted, in others it may be required.
  5558. maxLength: 253
  5559. minLength: 1
  5560. pattern: ^[-._a-zA-Z0-9]+$
  5561. type: string
  5562. name:
  5563. description: The name of the Secret resource being referred to.
  5564. maxLength: 253
  5565. minLength: 1
  5566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5567. type: string
  5568. namespace:
  5569. description: |-
  5570. The namespace of the Secret resource being referred to.
  5571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5572. maxLength: 63
  5573. minLength: 1
  5574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5575. type: string
  5576. type: object
  5577. clientSecret:
  5578. description: |-
  5579. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5580. In some instances, `key` is a required field.
  5581. properties:
  5582. key:
  5583. description: |-
  5584. A key in the referenced Secret.
  5585. Some instances of this field may be defaulted, in others it may be required.
  5586. maxLength: 253
  5587. minLength: 1
  5588. pattern: ^[-._a-zA-Z0-9]+$
  5589. type: string
  5590. name:
  5591. description: The name of the Secret resource being referred to.
  5592. maxLength: 253
  5593. minLength: 1
  5594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5595. type: string
  5596. namespace:
  5597. description: |-
  5598. The namespace of the Secret resource being referred to.
  5599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5600. maxLength: 63
  5601. minLength: 1
  5602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5603. type: string
  5604. type: object
  5605. required:
  5606. - clientId
  5607. - clientSecret
  5608. type: object
  5609. type: object
  5610. caBundle:
  5611. description: |-
  5612. CABundle is a PEM-encoded CA certificate bundle used to validate
  5613. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5614. format: byte
  5615. type: string
  5616. caProvider:
  5617. description: |-
  5618. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5619. The certificate is used to validate the Infisical server's TLS certificate.
  5620. Mutually exclusive with CABundle.
  5621. properties:
  5622. key:
  5623. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5624. maxLength: 253
  5625. minLength: 1
  5626. pattern: ^[-._a-zA-Z0-9]+$
  5627. type: string
  5628. name:
  5629. description: The name of the object located at the provider type.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5633. type: string
  5634. namespace:
  5635. description: |-
  5636. The namespace the Provider type is in.
  5637. Can only be defined when used in a ClusterSecretStore.
  5638. maxLength: 63
  5639. minLength: 1
  5640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5641. type: string
  5642. type:
  5643. description: The type of provider to use such as "Secret", or "ConfigMap".
  5644. enum:
  5645. - Secret
  5646. - ConfigMap
  5647. type: string
  5648. required:
  5649. - name
  5650. - type
  5651. type: object
  5652. hostAPI:
  5653. default: https://app.infisical.com/api
  5654. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5655. type: string
  5656. secretsScope:
  5657. description: SecretsScope defines the scope of the secrets within the workspace
  5658. properties:
  5659. environmentSlug:
  5660. description: EnvironmentSlug is the required slug identifier for the environment.
  5661. type: string
  5662. expandSecretReferences:
  5663. default: true
  5664. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5665. type: boolean
  5666. organizationSlug:
  5667. description: |-
  5668. OrganizationSlug is the optional slug that identifies the organization that will be used
  5669. during authentication. Useful for sub-organization setups
  5670. type: string
  5671. projectSlug:
  5672. description: ProjectSlug is the required slug identifier for the project.
  5673. type: string
  5674. recursive:
  5675. default: false
  5676. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5677. type: boolean
  5678. secretsPath:
  5679. default: /
  5680. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5681. type: string
  5682. required:
  5683. - environmentSlug
  5684. - projectSlug
  5685. type: object
  5686. required:
  5687. - auth
  5688. - secretsScope
  5689. type: object
  5690. keepersecurity:
  5691. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5692. properties:
  5693. authRef:
  5694. description: |-
  5695. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5696. In some instances, `key` is a required field.
  5697. properties:
  5698. key:
  5699. description: |-
  5700. A key in the referenced Secret.
  5701. Some instances of this field may be defaulted, in others it may be required.
  5702. maxLength: 253
  5703. minLength: 1
  5704. pattern: ^[-._a-zA-Z0-9]+$
  5705. type: string
  5706. name:
  5707. description: The name of the Secret resource being referred to.
  5708. maxLength: 253
  5709. minLength: 1
  5710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5711. type: string
  5712. namespace:
  5713. description: |-
  5714. The namespace of the Secret resource being referred to.
  5715. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5716. maxLength: 63
  5717. minLength: 1
  5718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5719. type: string
  5720. type: object
  5721. folderID:
  5722. type: string
  5723. getByTitleFallback:
  5724. type: boolean
  5725. required:
  5726. - authRef
  5727. - folderID
  5728. type: object
  5729. kubernetes:
  5730. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  5731. properties:
  5732. auth:
  5733. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  5734. maxProperties: 1
  5735. minProperties: 1
  5736. properties:
  5737. cert:
  5738. description: has both clientCert and clientKey as secretKeySelector
  5739. properties:
  5740. clientCert:
  5741. description: |-
  5742. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5743. In some instances, `key` is a required field.
  5744. properties:
  5745. key:
  5746. description: |-
  5747. A key in the referenced Secret.
  5748. Some instances of this field may be defaulted, in others it may be required.
  5749. maxLength: 253
  5750. minLength: 1
  5751. pattern: ^[-._a-zA-Z0-9]+$
  5752. type: string
  5753. name:
  5754. description: The name of the Secret resource being referred to.
  5755. maxLength: 253
  5756. minLength: 1
  5757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5758. type: string
  5759. namespace:
  5760. description: |-
  5761. The namespace of the Secret resource being referred to.
  5762. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5763. maxLength: 63
  5764. minLength: 1
  5765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5766. type: string
  5767. type: object
  5768. clientKey:
  5769. description: |-
  5770. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5771. In some instances, `key` is a required field.
  5772. properties:
  5773. key:
  5774. description: |-
  5775. A key in the referenced Secret.
  5776. Some instances of this field may be defaulted, in others it may be required.
  5777. maxLength: 253
  5778. minLength: 1
  5779. pattern: ^[-._a-zA-Z0-9]+$
  5780. type: string
  5781. name:
  5782. description: The name of the Secret resource being referred to.
  5783. maxLength: 253
  5784. minLength: 1
  5785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5786. type: string
  5787. namespace:
  5788. description: |-
  5789. The namespace of the Secret resource being referred to.
  5790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5791. maxLength: 63
  5792. minLength: 1
  5793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5794. type: string
  5795. type: object
  5796. type: object
  5797. serviceAccount:
  5798. description: points to a service account that should be used for authentication
  5799. properties:
  5800. audiences:
  5801. description: |-
  5802. Audience specifies the `aud` claim for the service account token
  5803. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  5804. then this audiences will be appended to the list
  5805. items:
  5806. type: string
  5807. type: array
  5808. name:
  5809. description: The name of the ServiceAccount resource being referred to.
  5810. maxLength: 253
  5811. minLength: 1
  5812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5813. type: string
  5814. namespace:
  5815. description: |-
  5816. Namespace of the resource being referred to.
  5817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5818. maxLength: 63
  5819. minLength: 1
  5820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5821. type: string
  5822. required:
  5823. - name
  5824. type: object
  5825. token:
  5826. description: use static token to authenticate with
  5827. properties:
  5828. bearerToken:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. type: object
  5857. type: object
  5858. authRef:
  5859. description: A reference to a secret that contains the auth information.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. remoteNamespace:
  5885. default: default
  5886. description: Remote namespace to fetch the secrets from
  5887. maxLength: 63
  5888. minLength: 1
  5889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5890. type: string
  5891. server:
  5892. description: configures the Kubernetes server Address.
  5893. properties:
  5894. caBundle:
  5895. description: CABundle is a base64-encoded CA certificate
  5896. format: byte
  5897. type: string
  5898. caProvider:
  5899. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  5900. properties:
  5901. key:
  5902. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5903. maxLength: 253
  5904. minLength: 1
  5905. pattern: ^[-._a-zA-Z0-9]+$
  5906. type: string
  5907. name:
  5908. description: The name of the object located at the provider type.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5912. type: string
  5913. namespace:
  5914. description: |-
  5915. The namespace the Provider type is in.
  5916. Can only be defined when used in a ClusterSecretStore.
  5917. maxLength: 63
  5918. minLength: 1
  5919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5920. type: string
  5921. type:
  5922. description: The type of provider to use such as "Secret", or "ConfigMap".
  5923. enum:
  5924. - Secret
  5925. - ConfigMap
  5926. type: string
  5927. required:
  5928. - name
  5929. - type
  5930. type: object
  5931. url:
  5932. default: kubernetes.default
  5933. description: configures the Kubernetes server Address.
  5934. type: string
  5935. type: object
  5936. type: object
  5937. nebiusmysterybox:
  5938. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  5939. properties:
  5940. apiDomain:
  5941. description: NebiusMysterybox API endpoint
  5942. type: string
  5943. auth:
  5944. description: Auth defines parameters to authenticate in MysteryBox
  5945. properties:
  5946. serviceAccountCredsSecretRef:
  5947. description: |-
  5948. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  5949. document with service account credentials used to get an IAM token.
  5950. Expected JSON structure:
  5951. {
  5952. "subject-credentials": {
  5953. "alg": "RS256",
  5954. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  5955. "kid": "<public-key-id>",
  5956. "iss": "<issuer-service-account-id>",
  5957. "sub": "<subject-service-account-id>"
  5958. }
  5959. }
  5960. properties:
  5961. key:
  5962. description: |-
  5963. A key in the referenced Secret.
  5964. Some instances of this field may be defaulted, in others it may be required.
  5965. maxLength: 253
  5966. minLength: 1
  5967. pattern: ^[-._a-zA-Z0-9]+$
  5968. type: string
  5969. name:
  5970. description: The name of the Secret resource being referred to.
  5971. maxLength: 253
  5972. minLength: 1
  5973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5974. type: string
  5975. namespace:
  5976. description: |-
  5977. The namespace of the Secret resource being referred to.
  5978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5979. maxLength: 63
  5980. minLength: 1
  5981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5982. type: string
  5983. type: object
  5984. tokenSecretRef:
  5985. description: Token authenticates with Nebius Mysterybox by presenting a token.
  5986. properties:
  5987. key:
  5988. description: |-
  5989. A key in the referenced Secret.
  5990. Some instances of this field may be defaulted, in others it may be required.
  5991. maxLength: 253
  5992. minLength: 1
  5993. pattern: ^[-._a-zA-Z0-9]+$
  5994. type: string
  5995. name:
  5996. description: The name of the Secret resource being referred to.
  5997. maxLength: 253
  5998. minLength: 1
  5999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6000. type: string
  6001. namespace:
  6002. description: |-
  6003. The namespace of the Secret resource being referred to.
  6004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6005. maxLength: 63
  6006. minLength: 1
  6007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6008. type: string
  6009. type: object
  6010. type: object
  6011. x-kubernetes-validations:
  6012. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6013. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6014. caProvider:
  6015. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6016. properties:
  6017. certSecretRef:
  6018. description: |-
  6019. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6020. In some instances, `key` is a required field.
  6021. properties:
  6022. key:
  6023. description: |-
  6024. A key in the referenced Secret.
  6025. Some instances of this field may be defaulted, in others it may be required.
  6026. maxLength: 253
  6027. minLength: 1
  6028. pattern: ^[-._a-zA-Z0-9]+$
  6029. type: string
  6030. name:
  6031. description: The name of the Secret resource being referred to.
  6032. maxLength: 253
  6033. minLength: 1
  6034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6035. type: string
  6036. namespace:
  6037. description: |-
  6038. The namespace of the Secret resource being referred to.
  6039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6040. maxLength: 63
  6041. minLength: 1
  6042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6043. type: string
  6044. type: object
  6045. type: object
  6046. required:
  6047. - apiDomain
  6048. - auth
  6049. type: object
  6050. ngrok:
  6051. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6052. properties:
  6053. apiUrl:
  6054. default: https://api.ngrok.com
  6055. description: APIURL is the URL of the ngrok API.
  6056. type: string
  6057. auth:
  6058. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6059. maxProperties: 1
  6060. minProperties: 1
  6061. properties:
  6062. apiKey:
  6063. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6064. properties:
  6065. secretRef:
  6066. description: SecretRef is a reference to a secret containing the ngrok API key.
  6067. properties:
  6068. key:
  6069. description: |-
  6070. A key in the referenced Secret.
  6071. Some instances of this field may be defaulted, in others it may be required.
  6072. maxLength: 253
  6073. minLength: 1
  6074. pattern: ^[-._a-zA-Z0-9]+$
  6075. type: string
  6076. name:
  6077. description: The name of the Secret resource being referred to.
  6078. maxLength: 253
  6079. minLength: 1
  6080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6081. type: string
  6082. namespace:
  6083. description: |-
  6084. The namespace of the Secret resource being referred to.
  6085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6086. maxLength: 63
  6087. minLength: 1
  6088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6089. type: string
  6090. type: object
  6091. type: object
  6092. type: object
  6093. vault:
  6094. description: Vault configures the ngrok vault to sync secrets with.
  6095. properties:
  6096. name:
  6097. description: Name is the name of the ngrok vault to sync secrets with.
  6098. type: string
  6099. required:
  6100. - name
  6101. type: object
  6102. required:
  6103. - auth
  6104. - vault
  6105. type: object
  6106. onboardbase:
  6107. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6108. properties:
  6109. apiHost:
  6110. default: https://public.onboardbase.com/api/v1/
  6111. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6112. type: string
  6113. auth:
  6114. description: Auth configures how the Operator authenticates with the Onboardbase API
  6115. properties:
  6116. apiKeyRef:
  6117. description: |-
  6118. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6119. It is used to recognize and authorize access to a project and environment within onboardbase
  6120. properties:
  6121. key:
  6122. description: |-
  6123. A key in the referenced Secret.
  6124. Some instances of this field may be defaulted, in others it may be required.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[-._a-zA-Z0-9]+$
  6128. type: string
  6129. name:
  6130. description: The name of the Secret resource being referred to.
  6131. maxLength: 253
  6132. minLength: 1
  6133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6134. type: string
  6135. namespace:
  6136. description: |-
  6137. The namespace of the Secret resource being referred to.
  6138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6139. maxLength: 63
  6140. minLength: 1
  6141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6142. type: string
  6143. type: object
  6144. passcodeRef:
  6145. description: OnboardbasePasscode is the passcode attached to the API Key
  6146. properties:
  6147. key:
  6148. description: |-
  6149. A key in the referenced Secret.
  6150. Some instances of this field may be defaulted, in others it may be required.
  6151. maxLength: 253
  6152. minLength: 1
  6153. pattern: ^[-._a-zA-Z0-9]+$
  6154. type: string
  6155. name:
  6156. description: The name of the Secret resource being referred to.
  6157. maxLength: 253
  6158. minLength: 1
  6159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6160. type: string
  6161. namespace:
  6162. description: |-
  6163. The namespace of the Secret resource being referred to.
  6164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6165. maxLength: 63
  6166. minLength: 1
  6167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6168. type: string
  6169. type: object
  6170. required:
  6171. - apiKeyRef
  6172. - passcodeRef
  6173. type: object
  6174. environment:
  6175. default: development
  6176. description: Environment is the name of an environmnent within a project to pull the secrets from
  6177. type: string
  6178. project:
  6179. default: development
  6180. description: Project is an onboardbase project that the secrets should be pulled from
  6181. type: string
  6182. required:
  6183. - apiHost
  6184. - auth
  6185. - environment
  6186. - project
  6187. type: object
  6188. onepassword:
  6189. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6190. properties:
  6191. auth:
  6192. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6193. properties:
  6194. secretRef:
  6195. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6196. properties:
  6197. connectTokenSecretRef:
  6198. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6199. properties:
  6200. key:
  6201. description: |-
  6202. A key in the referenced Secret.
  6203. Some instances of this field may be defaulted, in others it may be required.
  6204. maxLength: 253
  6205. minLength: 1
  6206. pattern: ^[-._a-zA-Z0-9]+$
  6207. type: string
  6208. name:
  6209. description: The name of the Secret resource being referred to.
  6210. maxLength: 253
  6211. minLength: 1
  6212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6213. type: string
  6214. namespace:
  6215. description: |-
  6216. The namespace of the Secret resource being referred to.
  6217. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6218. maxLength: 63
  6219. minLength: 1
  6220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6221. type: string
  6222. type: object
  6223. required:
  6224. - connectTokenSecretRef
  6225. type: object
  6226. required:
  6227. - secretRef
  6228. type: object
  6229. connectHost:
  6230. description: ConnectHost defines the OnePassword Connect Server to connect to
  6231. type: string
  6232. vaults:
  6233. additionalProperties:
  6234. type: integer
  6235. description: Vaults defines which OnePassword vaults to search in which order
  6236. type: object
  6237. required:
  6238. - auth
  6239. - connectHost
  6240. - vaults
  6241. type: object
  6242. onepasswordSDK:
  6243. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6244. properties:
  6245. auth:
  6246. description: Auth defines the information necessary to authenticate against OnePassword API.
  6247. properties:
  6248. serviceAccountSecretRef:
  6249. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6250. properties:
  6251. key:
  6252. description: |-
  6253. A key in the referenced Secret.
  6254. Some instances of this field may be defaulted, in others it may be required.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[-._a-zA-Z0-9]+$
  6258. type: string
  6259. name:
  6260. description: The name of the Secret resource being referred to.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6264. type: string
  6265. namespace:
  6266. description: |-
  6267. The namespace of the Secret resource being referred to.
  6268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6269. maxLength: 63
  6270. minLength: 1
  6271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6272. type: string
  6273. type: object
  6274. required:
  6275. - serviceAccountSecretRef
  6276. type: object
  6277. cache:
  6278. description: |-
  6279. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6280. When enabled, secrets are cached with the specified TTL.
  6281. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6282. If omitted, caching is disabled (default).
  6283. cache: {} is a valid option to set.
  6284. properties:
  6285. maxSize:
  6286. default: 100
  6287. description: |-
  6288. MaxSize is the maximum number of secrets to cache.
  6289. When the cache is full, least-recently-used entries are evicted.
  6290. minimum: 1
  6291. type: integer
  6292. ttl:
  6293. default: 5m
  6294. description: |-
  6295. TTL is the time-to-live for cached secrets.
  6296. Format: duration string (e.g., "5m", "1h", "30s")
  6297. type: string
  6298. type: object
  6299. integrationInfo:
  6300. description: |-
  6301. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6302. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6303. properties:
  6304. name:
  6305. default: 1Password SDK
  6306. description: Name defaults to "1Password SDK".
  6307. type: string
  6308. version:
  6309. default: v1.0.0
  6310. description: Version defaults to "v1.0.0".
  6311. type: string
  6312. type: object
  6313. vault:
  6314. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6315. type: string
  6316. required:
  6317. - auth
  6318. - vault
  6319. type: object
  6320. openBao:
  6321. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6322. properties:
  6323. auth:
  6324. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6325. properties:
  6326. appRole:
  6327. description: |-
  6328. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6329. with the role and secret stored in a Kubernetes Secret resource.
  6330. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6331. properties:
  6332. path:
  6333. default: approle
  6334. description: |-
  6335. Path where the App Role authentication backend is mounted
  6336. in OpenBao, e.g: "approle"
  6337. type: string
  6338. roleId:
  6339. description: |-
  6340. RoleID configured in the App Role authentication backend when setting
  6341. up the authentication backend in OpenBao.
  6342. minLength: 1
  6343. type: string
  6344. roleRef:
  6345. description: |-
  6346. Reference to a key in a Secret that contains the App Role ID used
  6347. to authenticate with OpenBao.
  6348. The `key` field must be specified and denotes which entry within the Secret
  6349. resource is used as the app role id.
  6350. properties:
  6351. key:
  6352. description: |-
  6353. A key in the referenced Secret.
  6354. Some instances of this field may be defaulted, in others it may be required.
  6355. maxLength: 253
  6356. minLength: 1
  6357. pattern: ^[-._a-zA-Z0-9]+$
  6358. type: string
  6359. name:
  6360. description: The name of the Secret resource being referred to.
  6361. maxLength: 253
  6362. minLength: 1
  6363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6364. type: string
  6365. namespace:
  6366. description: |-
  6367. The namespace of the Secret resource being referred to.
  6368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6369. maxLength: 63
  6370. minLength: 1
  6371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6372. type: string
  6373. type: object
  6374. secretRef:
  6375. description: |-
  6376. Reference to a key in a Secret that contains the App Role secret used
  6377. to authenticate with OpenBao.
  6378. The `key` field must be specified and denotes which entry within the Secret
  6379. resource is used as the app role secret.
  6380. properties:
  6381. key:
  6382. description: |-
  6383. A key in the referenced Secret.
  6384. Some instances of this field may be defaulted, in others it may be required.
  6385. maxLength: 253
  6386. minLength: 1
  6387. pattern: ^[-._a-zA-Z0-9]+$
  6388. type: string
  6389. name:
  6390. description: The name of the Secret resource being referred to.
  6391. maxLength: 253
  6392. minLength: 1
  6393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6394. type: string
  6395. namespace:
  6396. description: |-
  6397. The namespace of the Secret resource being referred to.
  6398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6399. maxLength: 63
  6400. minLength: 1
  6401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6402. type: string
  6403. type: object
  6404. required:
  6405. - path
  6406. - secretRef
  6407. type: object
  6408. x-kubernetes-validations:
  6409. - message: exactly one of the fields in [roleId roleRef] must be set
  6410. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6411. namespace:
  6412. description: |-
  6413. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6414. than the namespace your secret is in. Namespaces is a set of features
  6415. within OpenBao that allows OpenBao environments to support secure
  6416. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6417. if set, or empty otherwise
  6418. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6419. type: string
  6420. tokenSecretRef:
  6421. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6422. properties:
  6423. key:
  6424. description: |-
  6425. A key in the referenced Secret.
  6426. Some instances of this field may be defaulted, in others it may be required.
  6427. maxLength: 253
  6428. minLength: 1
  6429. pattern: ^[-._a-zA-Z0-9]+$
  6430. type: string
  6431. name:
  6432. description: The name of the Secret resource being referred to.
  6433. maxLength: 253
  6434. minLength: 1
  6435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6436. type: string
  6437. namespace:
  6438. description: |-
  6439. The namespace of the Secret resource being referred to.
  6440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6441. maxLength: 63
  6442. minLength: 1
  6443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6444. type: string
  6445. type: object
  6446. userPass:
  6447. description: UserPass authenticates with OpenBao by passing a username/password pair
  6448. properties:
  6449. path:
  6450. default: userpass
  6451. description: |-
  6452. Path where the UserPassword authentication backend is mounted
  6453. in OpenBao, e.g: "userpass"
  6454. type: string
  6455. secretRef:
  6456. description: |-
  6457. SecretRef to a key in a Secret resource containing password for the user
  6458. used to authenticate with OpenBao using the [UserPass authentication
  6459. method]
  6460. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6461. properties:
  6462. key:
  6463. description: |-
  6464. A key in the referenced Secret.
  6465. Some instances of this field may be defaulted, in others it may be required.
  6466. maxLength: 253
  6467. minLength: 1
  6468. pattern: ^[-._a-zA-Z0-9]+$
  6469. type: string
  6470. name:
  6471. description: The name of the Secret resource being referred to.
  6472. maxLength: 253
  6473. minLength: 1
  6474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6475. type: string
  6476. namespace:
  6477. description: |-
  6478. The namespace of the Secret resource being referred to.
  6479. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6480. maxLength: 63
  6481. minLength: 1
  6482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6483. type: string
  6484. type: object
  6485. username:
  6486. description: |-
  6487. Username is a username used to authenticate using the [UserPass
  6488. authentication method]
  6489. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6490. type: string
  6491. required:
  6492. - path
  6493. - username
  6494. type: object
  6495. type: object
  6496. x-kubernetes-validations:
  6497. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6498. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6499. caBundle:
  6500. description: |-
  6501. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6502. this and `caProvider` are not set the system root certificates are used
  6503. to validate the TLS connection.
  6504. format: byte
  6505. type: string
  6506. caProvider:
  6507. description: |-
  6508. The provider for the CA bundle to use to validate OpenBao server
  6509. certificate. If this and `caBundle` are not set the system root
  6510. certificates are used to validate the TLS connection.
  6511. properties:
  6512. key:
  6513. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6514. maxLength: 253
  6515. minLength: 1
  6516. pattern: ^[-._a-zA-Z0-9]+$
  6517. type: string
  6518. name:
  6519. description: The name of the object located at the provider type.
  6520. maxLength: 253
  6521. minLength: 1
  6522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6523. type: string
  6524. namespace:
  6525. description: |-
  6526. The namespace the Provider type is in.
  6527. Can only be defined when used in a ClusterSecretStore.
  6528. maxLength: 63
  6529. minLength: 1
  6530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6531. type: string
  6532. type:
  6533. description: The type of provider to use such as "Secret", or "ConfigMap".
  6534. enum:
  6535. - Secret
  6536. - ConfigMap
  6537. type: string
  6538. required:
  6539. - name
  6540. - type
  6541. type: object
  6542. namespace:
  6543. description: |-
  6544. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6545. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6546. e.g: "ns1".
  6547. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6548. type: string
  6549. path:
  6550. description: |-
  6551. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6552. "secret". The v2 KV secret engine version specific "/data" path suffix
  6553. for fetching secrets from OpenBao is optional and will be appended
  6554. if not present in specified path.
  6555. type: string
  6556. server:
  6557. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6558. type: string
  6559. version:
  6560. default: v2
  6561. description: |-
  6562. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6563. "v2". Version defaults to "v2".
  6564. enum:
  6565. - v1
  6566. - v2
  6567. type: string
  6568. required:
  6569. - server
  6570. type: object
  6571. x-kubernetes-validations:
  6572. - message: at most one of the fields in [caBundle caProvider] may be set
  6573. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6574. oracle:
  6575. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6576. properties:
  6577. auth:
  6578. description: |-
  6579. Auth configures how secret-manager authenticates with the Oracle Vault.
  6580. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6581. properties:
  6582. secretRef:
  6583. description: SecretRef to pass through sensitive information.
  6584. properties:
  6585. fingerprint:
  6586. description: Fingerprint is the fingerprint of the API private key.
  6587. properties:
  6588. key:
  6589. description: |-
  6590. A key in the referenced Secret.
  6591. Some instances of this field may be defaulted, in others it may be required.
  6592. maxLength: 253
  6593. minLength: 1
  6594. pattern: ^[-._a-zA-Z0-9]+$
  6595. type: string
  6596. name:
  6597. description: The name of the Secret resource being referred to.
  6598. maxLength: 253
  6599. minLength: 1
  6600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6601. type: string
  6602. namespace:
  6603. description: |-
  6604. The namespace of the Secret resource being referred to.
  6605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6606. maxLength: 63
  6607. minLength: 1
  6608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6609. type: string
  6610. type: object
  6611. privatekey:
  6612. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6613. properties:
  6614. key:
  6615. description: |-
  6616. A key in the referenced Secret.
  6617. Some instances of this field may be defaulted, in others it may be required.
  6618. maxLength: 253
  6619. minLength: 1
  6620. pattern: ^[-._a-zA-Z0-9]+$
  6621. type: string
  6622. name:
  6623. description: The name of the Secret resource being referred to.
  6624. maxLength: 253
  6625. minLength: 1
  6626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6627. type: string
  6628. namespace:
  6629. description: |-
  6630. The namespace of the Secret resource being referred to.
  6631. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6632. maxLength: 63
  6633. minLength: 1
  6634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6635. type: string
  6636. type: object
  6637. required:
  6638. - fingerprint
  6639. - privatekey
  6640. type: object
  6641. tenancy:
  6642. description: Tenancy is the tenancy OCID where user is located.
  6643. type: string
  6644. user:
  6645. description: User is an access OCID specific to the account.
  6646. type: string
  6647. required:
  6648. - secretRef
  6649. - tenancy
  6650. - user
  6651. type: object
  6652. compartment:
  6653. description: |-
  6654. Compartment is the vault compartment OCID.
  6655. Required for PushSecret
  6656. type: string
  6657. encryptionKey:
  6658. description: |-
  6659. EncryptionKey is the OCID of the encryption key within the vault.
  6660. Required for PushSecret
  6661. type: string
  6662. principalType:
  6663. description: |-
  6664. The type of principal to use for authentication. If left blank, the Auth struct will
  6665. determine the principal type. This optional field must be specified if using
  6666. workload identity.
  6667. enum:
  6668. - ""
  6669. - UserPrincipal
  6670. - InstancePrincipal
  6671. - Workload
  6672. type: string
  6673. region:
  6674. description: Region is the region where vault is located.
  6675. type: string
  6676. serviceAccountRef:
  6677. description: |-
  6678. ServiceAccountRef specified the service account
  6679. that should be used when authenticating with WorkloadIdentity.
  6680. properties:
  6681. audiences:
  6682. description: |-
  6683. Audience specifies the `aud` claim for the service account token
  6684. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6685. then this audiences will be appended to the list
  6686. items:
  6687. type: string
  6688. type: array
  6689. name:
  6690. description: The name of the ServiceAccount resource being referred to.
  6691. maxLength: 253
  6692. minLength: 1
  6693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6694. type: string
  6695. namespace:
  6696. description: |-
  6697. Namespace of the resource being referred to.
  6698. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6699. maxLength: 63
  6700. minLength: 1
  6701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6702. type: string
  6703. required:
  6704. - name
  6705. type: object
  6706. vault:
  6707. description: Vault is the vault's OCID of the specific vault where secret is located.
  6708. type: string
  6709. required:
  6710. - region
  6711. - vault
  6712. type: object
  6713. ovh:
  6714. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  6715. properties:
  6716. auth:
  6717. description: Authentication method (mtls or token).
  6718. properties:
  6719. mtls:
  6720. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  6721. properties:
  6722. caBundle:
  6723. format: byte
  6724. type: string
  6725. caProvider:
  6726. description: |-
  6727. CAProvider provides a custom certificate authority for accessing the provider's store.
  6728. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  6729. properties:
  6730. key:
  6731. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6732. maxLength: 253
  6733. minLength: 1
  6734. pattern: ^[-._a-zA-Z0-9]+$
  6735. type: string
  6736. name:
  6737. description: The name of the object located at the provider type.
  6738. maxLength: 253
  6739. minLength: 1
  6740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6741. type: string
  6742. namespace:
  6743. description: |-
  6744. The namespace the Provider type is in.
  6745. Can only be defined when used in a ClusterSecretStore.
  6746. maxLength: 63
  6747. minLength: 1
  6748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6749. type: string
  6750. type:
  6751. description: The type of provider to use such as "Secret", or "ConfigMap".
  6752. enum:
  6753. - Secret
  6754. - ConfigMap
  6755. type: string
  6756. required:
  6757. - name
  6758. - type
  6759. type: object
  6760. certSecretRef:
  6761. description: |-
  6762. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6763. In some instances, `key` is a required field.
  6764. properties:
  6765. key:
  6766. description: |-
  6767. A key in the referenced Secret.
  6768. Some instances of this field may be defaulted, in others it may be required.
  6769. maxLength: 253
  6770. minLength: 1
  6771. pattern: ^[-._a-zA-Z0-9]+$
  6772. type: string
  6773. name:
  6774. description: The name of the Secret resource being referred to.
  6775. maxLength: 253
  6776. minLength: 1
  6777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6778. type: string
  6779. namespace:
  6780. description: |-
  6781. The namespace of the Secret resource being referred to.
  6782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6783. maxLength: 63
  6784. minLength: 1
  6785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6786. type: string
  6787. type: object
  6788. keySecretRef:
  6789. description: |-
  6790. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6791. In some instances, `key` is a required field.
  6792. properties:
  6793. key:
  6794. description: |-
  6795. A key in the referenced Secret.
  6796. Some instances of this field may be defaulted, in others it may be required.
  6797. maxLength: 253
  6798. minLength: 1
  6799. pattern: ^[-._a-zA-Z0-9]+$
  6800. type: string
  6801. name:
  6802. description: The name of the Secret resource being referred to.
  6803. maxLength: 253
  6804. minLength: 1
  6805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6806. type: string
  6807. namespace:
  6808. description: |-
  6809. The namespace of the Secret resource being referred to.
  6810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6811. maxLength: 63
  6812. minLength: 1
  6813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6814. type: string
  6815. type: object
  6816. required:
  6817. - certSecretRef
  6818. - keySecretRef
  6819. type: object
  6820. token:
  6821. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  6822. properties:
  6823. tokenSecretRef:
  6824. description: |-
  6825. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6826. In some instances, `key` is a required field.
  6827. properties:
  6828. key:
  6829. description: |-
  6830. A key in the referenced Secret.
  6831. Some instances of this field may be defaulted, in others it may be required.
  6832. maxLength: 253
  6833. minLength: 1
  6834. pattern: ^[-._a-zA-Z0-9]+$
  6835. type: string
  6836. name:
  6837. description: The name of the Secret resource being referred to.
  6838. maxLength: 253
  6839. minLength: 1
  6840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6841. type: string
  6842. namespace:
  6843. description: |-
  6844. The namespace of the Secret resource being referred to.
  6845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6846. maxLength: 63
  6847. minLength: 1
  6848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6849. type: string
  6850. type: object
  6851. required:
  6852. - tokenSecretRef
  6853. type: object
  6854. type: object
  6855. casRequired:
  6856. description: 'Enables or disables check-and-set (CAS) (default: false).'
  6857. type: boolean
  6858. okmsTimeout:
  6859. default: 30
  6860. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  6861. format: int32
  6862. minimum: 1
  6863. type: integer
  6864. okmsid:
  6865. description: specifies the OKMS ID.
  6866. type: string
  6867. server:
  6868. description: specifies the OKMS server endpoint.
  6869. type: string
  6870. required:
  6871. - auth
  6872. - okmsid
  6873. - server
  6874. type: object
  6875. passbolt:
  6876. description: |-
  6877. PassboltProvider provides access to Passbolt secrets manager.
  6878. See: https://www.passbolt.com.
  6879. properties:
  6880. auth:
  6881. description: Auth defines the information necessary to authenticate against Passbolt Server
  6882. properties:
  6883. passwordSecretRef:
  6884. description: |-
  6885. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6886. In some instances, `key` is a required field.
  6887. properties:
  6888. key:
  6889. description: |-
  6890. A key in the referenced Secret.
  6891. Some instances of this field may be defaulted, in others it may be required.
  6892. maxLength: 253
  6893. minLength: 1
  6894. pattern: ^[-._a-zA-Z0-9]+$
  6895. type: string
  6896. name:
  6897. description: The name of the Secret resource being referred to.
  6898. maxLength: 253
  6899. minLength: 1
  6900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6901. type: string
  6902. namespace:
  6903. description: |-
  6904. The namespace of the Secret resource being referred to.
  6905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6906. maxLength: 63
  6907. minLength: 1
  6908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6909. type: string
  6910. type: object
  6911. privateKeySecretRef:
  6912. description: |-
  6913. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6914. In some instances, `key` is a required field.
  6915. properties:
  6916. key:
  6917. description: |-
  6918. A key in the referenced Secret.
  6919. Some instances of this field may be defaulted, in others it may be required.
  6920. maxLength: 253
  6921. minLength: 1
  6922. pattern: ^[-._a-zA-Z0-9]+$
  6923. type: string
  6924. name:
  6925. description: The name of the Secret resource being referred to.
  6926. maxLength: 253
  6927. minLength: 1
  6928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6929. type: string
  6930. namespace:
  6931. description: |-
  6932. The namespace of the Secret resource being referred to.
  6933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6934. maxLength: 63
  6935. minLength: 1
  6936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6937. type: string
  6938. type: object
  6939. required:
  6940. - passwordSecretRef
  6941. - privateKeySecretRef
  6942. type: object
  6943. caBundle:
  6944. description: |-
  6945. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  6946. if the Host URL is using HTTPS protocol. If not set the system root certificates
  6947. are used to validate the TLS connection.
  6948. format: byte
  6949. type: string
  6950. caProvider:
  6951. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  6952. properties:
  6953. key:
  6954. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6955. maxLength: 253
  6956. minLength: 1
  6957. pattern: ^[-._a-zA-Z0-9]+$
  6958. type: string
  6959. name:
  6960. description: The name of the object located at the provider type.
  6961. maxLength: 253
  6962. minLength: 1
  6963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6964. type: string
  6965. namespace:
  6966. description: |-
  6967. The namespace the Provider type is in.
  6968. Can only be defined when used in a ClusterSecretStore.
  6969. maxLength: 63
  6970. minLength: 1
  6971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6972. type: string
  6973. type:
  6974. description: The type of provider to use such as "Secret", or "ConfigMap".
  6975. enum:
  6976. - Secret
  6977. - ConfigMap
  6978. type: string
  6979. required:
  6980. - name
  6981. - type
  6982. type: object
  6983. host:
  6984. description: Host defines the Passbolt Server to connect to
  6985. type: string
  6986. required:
  6987. - auth
  6988. - host
  6989. type: object
  6990. passworddepot:
  6991. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  6992. properties:
  6993. auth:
  6994. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  6995. properties:
  6996. secretRef:
  6997. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  6998. properties:
  6999. credentials:
  7000. description: Username / Password is used for authentication.
  7001. properties:
  7002. key:
  7003. description: |-
  7004. A key in the referenced Secret.
  7005. Some instances of this field may be defaulted, in others it may be required.
  7006. maxLength: 253
  7007. minLength: 1
  7008. pattern: ^[-._a-zA-Z0-9]+$
  7009. type: string
  7010. name:
  7011. description: The name of the Secret resource being referred to.
  7012. maxLength: 253
  7013. minLength: 1
  7014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7015. type: string
  7016. namespace:
  7017. description: |-
  7018. The namespace of the Secret resource being referred to.
  7019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7020. maxLength: 63
  7021. minLength: 1
  7022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7023. type: string
  7024. type: object
  7025. type: object
  7026. required:
  7027. - secretRef
  7028. type: object
  7029. database:
  7030. description: Database to use as source
  7031. type: string
  7032. host:
  7033. description: URL configures the Password Depot instance URL.
  7034. type: string
  7035. required:
  7036. - auth
  7037. - database
  7038. - host
  7039. type: object
  7040. previder:
  7041. description: Previder configures this store to sync secrets using the Previder provider
  7042. properties:
  7043. auth:
  7044. description: PreviderAuth contains a secretRef for credentials.
  7045. properties:
  7046. secretRef:
  7047. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7048. properties:
  7049. accessToken:
  7050. description: The AccessToken is used for authentication
  7051. properties:
  7052. key:
  7053. description: |-
  7054. A key in the referenced Secret.
  7055. Some instances of this field may be defaulted, in others it may be required.
  7056. maxLength: 253
  7057. minLength: 1
  7058. pattern: ^[-._a-zA-Z0-9]+$
  7059. type: string
  7060. name:
  7061. description: The name of the Secret resource being referred to.
  7062. maxLength: 253
  7063. minLength: 1
  7064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7065. type: string
  7066. namespace:
  7067. description: |-
  7068. The namespace of the Secret resource being referred to.
  7069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7070. maxLength: 63
  7071. minLength: 1
  7072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7073. type: string
  7074. type: object
  7075. required:
  7076. - accessToken
  7077. type: object
  7078. type: object
  7079. baseUri:
  7080. type: string
  7081. required:
  7082. - auth
  7083. type: object
  7084. pulumi:
  7085. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7086. properties:
  7087. accessToken:
  7088. description: |-
  7089. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7090. Deprecated: Use auth.accessToken instead.
  7091. properties:
  7092. secretRef:
  7093. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7094. properties:
  7095. key:
  7096. description: |-
  7097. A key in the referenced Secret.
  7098. Some instances of this field may be defaulted, in others it may be required.
  7099. maxLength: 253
  7100. minLength: 1
  7101. pattern: ^[-._a-zA-Z0-9]+$
  7102. type: string
  7103. name:
  7104. description: The name of the Secret resource being referred to.
  7105. maxLength: 253
  7106. minLength: 1
  7107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7108. type: string
  7109. namespace:
  7110. description: |-
  7111. The namespace of the Secret resource being referred to.
  7112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7113. maxLength: 63
  7114. minLength: 1
  7115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7116. type: string
  7117. type: object
  7118. type: object
  7119. apiUrl:
  7120. default: https://api.pulumi.com/api/esc
  7121. description: APIURL is the URL of the Pulumi API.
  7122. type: string
  7123. auth:
  7124. description: |-
  7125. Auth configures how the Operator authenticates with the Pulumi API.
  7126. Either auth or the deprecated accessToken field must be specified.
  7127. properties:
  7128. accessToken:
  7129. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7130. properties:
  7131. secretRef:
  7132. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7133. properties:
  7134. key:
  7135. description: |-
  7136. A key in the referenced Secret.
  7137. Some instances of this field may be defaulted, in others it may be required.
  7138. maxLength: 253
  7139. minLength: 1
  7140. pattern: ^[-._a-zA-Z0-9]+$
  7141. type: string
  7142. name:
  7143. description: The name of the Secret resource being referred to.
  7144. maxLength: 253
  7145. minLength: 1
  7146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7147. type: string
  7148. namespace:
  7149. description: |-
  7150. The namespace of the Secret resource being referred to.
  7151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7152. maxLength: 63
  7153. minLength: 1
  7154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7155. type: string
  7156. type: object
  7157. type: object
  7158. oidcConfig:
  7159. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7160. properties:
  7161. expirationSeconds:
  7162. default: 600
  7163. description: |-
  7164. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7165. Defaults to 10 minutes.
  7166. format: int64
  7167. minimum: 600
  7168. type: integer
  7169. organization:
  7170. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7171. type: string
  7172. serviceAccountRef:
  7173. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7174. properties:
  7175. audiences:
  7176. description: |-
  7177. Audience specifies the `aud` claim for the service account token
  7178. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7179. then this audiences will be appended to the list
  7180. items:
  7181. type: string
  7182. type: array
  7183. name:
  7184. description: The name of the ServiceAccount resource being referred to.
  7185. maxLength: 253
  7186. minLength: 1
  7187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7188. type: string
  7189. namespace:
  7190. description: |-
  7191. Namespace of the resource being referred to.
  7192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7193. maxLength: 63
  7194. minLength: 1
  7195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7196. type: string
  7197. required:
  7198. - name
  7199. type: object
  7200. required:
  7201. - organization
  7202. - serviceAccountRef
  7203. type: object
  7204. type: object
  7205. x-kubernetes-validations:
  7206. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7207. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7208. environment:
  7209. description: |-
  7210. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7211. dynamically retrieved values from supported providers including all major clouds,
  7212. and other Pulumi ESC environments.
  7213. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7214. type: string
  7215. organization:
  7216. description: |-
  7217. Organization are a space to collaborate on shared projects and stacks.
  7218. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7219. type: string
  7220. project:
  7221. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7222. type: string
  7223. required:
  7224. - environment
  7225. - organization
  7226. - project
  7227. type: object
  7228. x-kubernetes-validations:
  7229. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7230. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7231. scaleway:
  7232. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7233. properties:
  7234. accessKey:
  7235. description: AccessKey is the non-secret part of the api key.
  7236. properties:
  7237. secretRef:
  7238. description: SecretRef references a key in a secret that will be used as value.
  7239. properties:
  7240. key:
  7241. description: |-
  7242. A key in the referenced Secret.
  7243. Some instances of this field may be defaulted, in others it may be required.
  7244. maxLength: 253
  7245. minLength: 1
  7246. pattern: ^[-._a-zA-Z0-9]+$
  7247. type: string
  7248. name:
  7249. description: The name of the Secret resource being referred to.
  7250. maxLength: 253
  7251. minLength: 1
  7252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7253. type: string
  7254. namespace:
  7255. description: |-
  7256. The namespace of the Secret resource being referred to.
  7257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7258. maxLength: 63
  7259. minLength: 1
  7260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7261. type: string
  7262. type: object
  7263. value:
  7264. description: Value can be specified directly to set a value without using a secret.
  7265. type: string
  7266. type: object
  7267. apiUrl:
  7268. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7269. type: string
  7270. projectId:
  7271. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7272. type: string
  7273. region:
  7274. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7275. type: string
  7276. secretKey:
  7277. description: SecretKey is the non-secret part of the api key.
  7278. properties:
  7279. secretRef:
  7280. description: SecretRef references a key in a secret that will be used as value.
  7281. properties:
  7282. key:
  7283. description: |-
  7284. A key in the referenced Secret.
  7285. Some instances of this field may be defaulted, in others it may be required.
  7286. maxLength: 253
  7287. minLength: 1
  7288. pattern: ^[-._a-zA-Z0-9]+$
  7289. type: string
  7290. name:
  7291. description: The name of the Secret resource being referred to.
  7292. maxLength: 253
  7293. minLength: 1
  7294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7295. type: string
  7296. namespace:
  7297. description: |-
  7298. The namespace of the Secret resource being referred to.
  7299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7300. maxLength: 63
  7301. minLength: 1
  7302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7303. type: string
  7304. type: object
  7305. value:
  7306. description: Value can be specified directly to set a value without using a secret.
  7307. type: string
  7308. type: object
  7309. required:
  7310. - accessKey
  7311. - projectId
  7312. - region
  7313. - secretKey
  7314. type: object
  7315. secretserver:
  7316. description: |-
  7317. SecretServer configures this store to sync secrets using SecretServer provider
  7318. https://docs.delinea.com/online-help/secret-server/start.htm
  7319. properties:
  7320. caBundle:
  7321. description: |-
  7322. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7323. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7324. are used to validate the TLS connection.
  7325. format: byte
  7326. type: string
  7327. caProvider:
  7328. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7329. properties:
  7330. key:
  7331. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7332. maxLength: 253
  7333. minLength: 1
  7334. pattern: ^[-._a-zA-Z0-9]+$
  7335. type: string
  7336. name:
  7337. description: The name of the object located at the provider type.
  7338. maxLength: 253
  7339. minLength: 1
  7340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7341. type: string
  7342. namespace:
  7343. description: |-
  7344. The namespace the Provider type is in.
  7345. Can only be defined when used in a ClusterSecretStore.
  7346. maxLength: 63
  7347. minLength: 1
  7348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7349. type: string
  7350. type:
  7351. description: The type of provider to use such as "Secret", or "ConfigMap".
  7352. enum:
  7353. - Secret
  7354. - ConfigMap
  7355. type: string
  7356. required:
  7357. - name
  7358. - type
  7359. type: object
  7360. domain:
  7361. description: Domain is the secret server domain.
  7362. type: string
  7363. password:
  7364. description: Password is the secret server account password.
  7365. properties:
  7366. secretRef:
  7367. description: SecretRef references a key in a secret that will be used as value.
  7368. properties:
  7369. key:
  7370. description: |-
  7371. A key in the referenced Secret.
  7372. Some instances of this field may be defaulted, in others it may be required.
  7373. maxLength: 253
  7374. minLength: 1
  7375. pattern: ^[-._a-zA-Z0-9]+$
  7376. type: string
  7377. name:
  7378. description: The name of the Secret resource being referred to.
  7379. maxLength: 253
  7380. minLength: 1
  7381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7382. type: string
  7383. namespace:
  7384. description: |-
  7385. The namespace of the Secret resource being referred to.
  7386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7387. maxLength: 63
  7388. minLength: 1
  7389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7390. type: string
  7391. type: object
  7392. value:
  7393. description: Value can be specified directly to set a value without using a secret.
  7394. type: string
  7395. type: object
  7396. serverURL:
  7397. description: |-
  7398. ServerURL
  7399. URL to your secret server installation
  7400. type: string
  7401. username:
  7402. description: Username is the secret server account username.
  7403. properties:
  7404. secretRef:
  7405. description: SecretRef references a key in a secret that will be used as value.
  7406. properties:
  7407. key:
  7408. description: |-
  7409. A key in the referenced Secret.
  7410. Some instances of this field may be defaulted, in others it may be required.
  7411. maxLength: 253
  7412. minLength: 1
  7413. pattern: ^[-._a-zA-Z0-9]+$
  7414. type: string
  7415. name:
  7416. description: The name of the Secret resource being referred to.
  7417. maxLength: 253
  7418. minLength: 1
  7419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7420. type: string
  7421. namespace:
  7422. description: |-
  7423. The namespace of the Secret resource being referred to.
  7424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7425. maxLength: 63
  7426. minLength: 1
  7427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7428. type: string
  7429. type: object
  7430. value:
  7431. description: Value can be specified directly to set a value without using a secret.
  7432. type: string
  7433. type: object
  7434. required:
  7435. - password
  7436. - serverURL
  7437. - username
  7438. type: object
  7439. senhasegura:
  7440. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7441. properties:
  7442. auth:
  7443. description: Auth defines parameters to authenticate in senhasegura
  7444. properties:
  7445. clientId:
  7446. type: string
  7447. clientSecretSecretRef:
  7448. description: |-
  7449. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7450. In some instances, `key` is a required field.
  7451. properties:
  7452. key:
  7453. description: |-
  7454. A key in the referenced Secret.
  7455. Some instances of this field may be defaulted, in others it may be required.
  7456. maxLength: 253
  7457. minLength: 1
  7458. pattern: ^[-._a-zA-Z0-9]+$
  7459. type: string
  7460. name:
  7461. description: The name of the Secret resource being referred to.
  7462. maxLength: 253
  7463. minLength: 1
  7464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7465. type: string
  7466. namespace:
  7467. description: |-
  7468. The namespace of the Secret resource being referred to.
  7469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7470. maxLength: 63
  7471. minLength: 1
  7472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7473. type: string
  7474. type: object
  7475. required:
  7476. - clientId
  7477. - clientSecretSecretRef
  7478. type: object
  7479. ignoreSslCertificate:
  7480. default: false
  7481. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7482. type: boolean
  7483. module:
  7484. description: Module defines which senhasegura module should be used to get secrets
  7485. type: string
  7486. url:
  7487. description: URL of senhasegura
  7488. type: string
  7489. required:
  7490. - auth
  7491. - module
  7492. - url
  7493. type: object
  7494. vault:
  7495. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7496. properties:
  7497. auth:
  7498. description: Auth configures how secret-manager authenticates with the Vault server.
  7499. properties:
  7500. appRole:
  7501. description: |-
  7502. AppRole authenticates with Vault using the App Role auth mechanism,
  7503. with the role and secret stored in a Kubernetes Secret resource.
  7504. properties:
  7505. path:
  7506. default: approle
  7507. description: |-
  7508. Path where the App Role authentication backend is mounted
  7509. in Vault, e.g: "approle"
  7510. type: string
  7511. roleId:
  7512. description: |-
  7513. RoleID configured in the App Role authentication backend when setting
  7514. up the authentication backend in Vault.
  7515. type: string
  7516. roleRef:
  7517. description: |-
  7518. Reference to a key in a Secret that contains the App Role ID used
  7519. to authenticate with Vault.
  7520. The `key` field must be specified and denotes which entry within the Secret
  7521. resource is used as the app role id.
  7522. properties:
  7523. key:
  7524. description: |-
  7525. A key in the referenced Secret.
  7526. Some instances of this field may be defaulted, in others it may be required.
  7527. maxLength: 253
  7528. minLength: 1
  7529. pattern: ^[-._a-zA-Z0-9]+$
  7530. type: string
  7531. name:
  7532. description: The name of the Secret resource being referred to.
  7533. maxLength: 253
  7534. minLength: 1
  7535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7536. type: string
  7537. namespace:
  7538. description: |-
  7539. The namespace of the Secret resource being referred to.
  7540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7541. maxLength: 63
  7542. minLength: 1
  7543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7544. type: string
  7545. type: object
  7546. secretRef:
  7547. description: |-
  7548. Reference to a key in a Secret that contains the App Role secret used
  7549. to authenticate with Vault.
  7550. The `key` field must be specified and denotes which entry within the Secret
  7551. resource is used as the app role secret.
  7552. properties:
  7553. key:
  7554. description: |-
  7555. A key in the referenced Secret.
  7556. Some instances of this field may be defaulted, in others it may be required.
  7557. maxLength: 253
  7558. minLength: 1
  7559. pattern: ^[-._a-zA-Z0-9]+$
  7560. type: string
  7561. name:
  7562. description: The name of the Secret resource being referred to.
  7563. maxLength: 253
  7564. minLength: 1
  7565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7566. type: string
  7567. namespace:
  7568. description: |-
  7569. The namespace of the Secret resource being referred to.
  7570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7571. maxLength: 63
  7572. minLength: 1
  7573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7574. type: string
  7575. type: object
  7576. required:
  7577. - path
  7578. - secretRef
  7579. type: object
  7580. cert:
  7581. description: |-
  7582. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7583. Cert authentication method
  7584. properties:
  7585. clientCert:
  7586. description: |-
  7587. ClientCert is a certificate to authenticate using the Cert Vault
  7588. authentication method
  7589. properties:
  7590. key:
  7591. description: |-
  7592. A key in the referenced Secret.
  7593. Some instances of this field may be defaulted, in others it may be required.
  7594. maxLength: 253
  7595. minLength: 1
  7596. pattern: ^[-._a-zA-Z0-9]+$
  7597. type: string
  7598. name:
  7599. description: The name of the Secret resource being referred to.
  7600. maxLength: 253
  7601. minLength: 1
  7602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7603. type: string
  7604. namespace:
  7605. description: |-
  7606. The namespace of the Secret resource being referred to.
  7607. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7608. maxLength: 63
  7609. minLength: 1
  7610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7611. type: string
  7612. type: object
  7613. path:
  7614. default: cert
  7615. description: |-
  7616. Path where the Certificate authentication backend is mounted
  7617. in Vault, e.g: "cert"
  7618. type: string
  7619. secretRef:
  7620. description: |-
  7621. SecretRef to a key in a Secret resource containing client private key to
  7622. authenticate with Vault using the Cert authentication method
  7623. properties:
  7624. key:
  7625. description: |-
  7626. A key in the referenced Secret.
  7627. Some instances of this field may be defaulted, in others it may be required.
  7628. maxLength: 253
  7629. minLength: 1
  7630. pattern: ^[-._a-zA-Z0-9]+$
  7631. type: string
  7632. name:
  7633. description: The name of the Secret resource being referred to.
  7634. maxLength: 253
  7635. minLength: 1
  7636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7637. type: string
  7638. namespace:
  7639. description: |-
  7640. The namespace of the Secret resource being referred to.
  7641. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7642. maxLength: 63
  7643. minLength: 1
  7644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7645. type: string
  7646. type: object
  7647. vaultRole:
  7648. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7649. type: string
  7650. type: object
  7651. gcp:
  7652. description: |-
  7653. Gcp authenticates with Vault using Google Cloud Platform authentication method
  7654. GCP authentication method
  7655. properties:
  7656. location:
  7657. description: Location optionally defines a location/region for the secret
  7658. type: string
  7659. path:
  7660. default: gcp
  7661. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  7662. type: string
  7663. projectID:
  7664. description: Project ID of the Google Cloud Platform project
  7665. type: string
  7666. role:
  7667. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  7668. type: string
  7669. secretRef:
  7670. description: Specify credentials in a Secret object
  7671. properties:
  7672. secretAccessKeySecretRef:
  7673. description: The SecretAccessKey is used for authentication
  7674. properties:
  7675. key:
  7676. description: |-
  7677. A key in the referenced Secret.
  7678. Some instances of this field may be defaulted, in others it may be required.
  7679. maxLength: 253
  7680. minLength: 1
  7681. pattern: ^[-._a-zA-Z0-9]+$
  7682. type: string
  7683. name:
  7684. description: The name of the Secret resource being referred to.
  7685. maxLength: 253
  7686. minLength: 1
  7687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7688. type: string
  7689. namespace:
  7690. description: |-
  7691. The namespace of the Secret resource being referred to.
  7692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7693. maxLength: 63
  7694. minLength: 1
  7695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7696. type: string
  7697. type: object
  7698. type: object
  7699. serviceAccountRef:
  7700. description: ServiceAccountRef to a service account for impersonation
  7701. properties:
  7702. audiences:
  7703. description: |-
  7704. Audience specifies the `aud` claim for the service account token
  7705. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7706. then this audiences will be appended to the list
  7707. items:
  7708. type: string
  7709. type: array
  7710. name:
  7711. description: The name of the ServiceAccount resource being referred to.
  7712. maxLength: 253
  7713. minLength: 1
  7714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7715. type: string
  7716. namespace:
  7717. description: |-
  7718. Namespace of the resource being referred to.
  7719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7720. maxLength: 63
  7721. minLength: 1
  7722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7723. type: string
  7724. required:
  7725. - name
  7726. type: object
  7727. workloadIdentity:
  7728. description: Specify a service account with Workload Identity
  7729. properties:
  7730. clusterLocation:
  7731. description: |-
  7732. ClusterLocation is the location of the cluster
  7733. If not specified, it fetches information from the metadata server
  7734. type: string
  7735. clusterName:
  7736. description: |-
  7737. ClusterName is the name of the cluster
  7738. If not specified, it fetches information from the metadata server
  7739. type: string
  7740. clusterProjectID:
  7741. description: |-
  7742. ClusterProjectID is the project ID of the cluster
  7743. If not specified, it fetches information from the metadata server
  7744. type: string
  7745. serviceAccountRef:
  7746. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  7747. properties:
  7748. audiences:
  7749. description: |-
  7750. Audience specifies the `aud` claim for the service account token
  7751. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7752. then this audiences will be appended to the list
  7753. items:
  7754. type: string
  7755. type: array
  7756. name:
  7757. description: The name of the ServiceAccount resource being referred to.
  7758. maxLength: 253
  7759. minLength: 1
  7760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7761. type: string
  7762. namespace:
  7763. description: |-
  7764. Namespace of the resource being referred to.
  7765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7766. maxLength: 63
  7767. minLength: 1
  7768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7769. type: string
  7770. required:
  7771. - name
  7772. type: object
  7773. required:
  7774. - serviceAccountRef
  7775. type: object
  7776. required:
  7777. - role
  7778. type: object
  7779. iam:
  7780. description: |-
  7781. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  7782. AWS IAM authentication method
  7783. properties:
  7784. externalID:
  7785. description: AWS External ID set on assumed IAM roles
  7786. type: string
  7787. jwt:
  7788. description: Specify a service account with IRSA enabled
  7789. properties:
  7790. serviceAccountRef:
  7791. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  7792. properties:
  7793. audiences:
  7794. description: |-
  7795. Audience specifies the `aud` claim for the service account token
  7796. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7797. then this audiences will be appended to the list
  7798. items:
  7799. type: string
  7800. type: array
  7801. name:
  7802. description: The name of the ServiceAccount resource being referred to.
  7803. maxLength: 253
  7804. minLength: 1
  7805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7806. type: string
  7807. namespace:
  7808. description: |-
  7809. Namespace of the resource being referred to.
  7810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7811. maxLength: 63
  7812. minLength: 1
  7813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7814. type: string
  7815. required:
  7816. - name
  7817. type: object
  7818. type: object
  7819. path:
  7820. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  7821. type: string
  7822. region:
  7823. description: AWS region
  7824. type: string
  7825. role:
  7826. description: This is the AWS role to be assumed before talking to vault
  7827. type: string
  7828. secretRef:
  7829. description: Specify credentials in a Secret object
  7830. properties:
  7831. accessKeyIDSecretRef:
  7832. description: The AccessKeyID is used for authentication
  7833. properties:
  7834. key:
  7835. description: |-
  7836. A key in the referenced Secret.
  7837. Some instances of this field may be defaulted, in others it may be required.
  7838. maxLength: 253
  7839. minLength: 1
  7840. pattern: ^[-._a-zA-Z0-9]+$
  7841. type: string
  7842. name:
  7843. description: The name of the Secret resource being referred to.
  7844. maxLength: 253
  7845. minLength: 1
  7846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7847. type: string
  7848. namespace:
  7849. description: |-
  7850. The namespace of the Secret resource being referred to.
  7851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7852. maxLength: 63
  7853. minLength: 1
  7854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7855. type: string
  7856. type: object
  7857. secretAccessKeySecretRef:
  7858. description: The SecretAccessKey is used for authentication
  7859. properties:
  7860. key:
  7861. description: |-
  7862. A key in the referenced Secret.
  7863. Some instances of this field may be defaulted, in others it may be required.
  7864. maxLength: 253
  7865. minLength: 1
  7866. pattern: ^[-._a-zA-Z0-9]+$
  7867. type: string
  7868. name:
  7869. description: The name of the Secret resource being referred to.
  7870. maxLength: 253
  7871. minLength: 1
  7872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7873. type: string
  7874. namespace:
  7875. description: |-
  7876. The namespace of the Secret resource being referred to.
  7877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7878. maxLength: 63
  7879. minLength: 1
  7880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7881. type: string
  7882. type: object
  7883. sessionTokenSecretRef:
  7884. description: |-
  7885. The SessionToken used for authentication
  7886. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  7887. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  7888. properties:
  7889. key:
  7890. description: |-
  7891. A key in the referenced Secret.
  7892. Some instances of this field may be defaulted, in others it may be required.
  7893. maxLength: 253
  7894. minLength: 1
  7895. pattern: ^[-._a-zA-Z0-9]+$
  7896. type: string
  7897. name:
  7898. description: The name of the Secret resource being referred to.
  7899. maxLength: 253
  7900. minLength: 1
  7901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7902. type: string
  7903. namespace:
  7904. description: |-
  7905. The namespace of the Secret resource being referred to.
  7906. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7907. maxLength: 63
  7908. minLength: 1
  7909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7910. type: string
  7911. type: object
  7912. type: object
  7913. vaultAwsIamServerID:
  7914. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  7915. type: string
  7916. vaultRole:
  7917. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  7918. type: string
  7919. required:
  7920. - vaultRole
  7921. type: object
  7922. jwt:
  7923. description: |-
  7924. Jwt authenticates with Vault by passing role and JWT token using the
  7925. JWT/OIDC authentication method
  7926. properties:
  7927. kubernetesServiceAccountToken:
  7928. description: |-
  7929. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  7930. a token for with the `TokenRequest` API.
  7931. properties:
  7932. audiences:
  7933. description: |-
  7934. Optional audiences field that will be used to request a temporary Kubernetes service
  7935. account token for the service account referenced by `serviceAccountRef`.
  7936. Defaults to a single audience `vault` it not specified.
  7937. Deprecated: use serviceAccountRef.Audiences instead
  7938. items:
  7939. type: string
  7940. type: array
  7941. expirationSeconds:
  7942. description: |-
  7943. Optional expiration time in seconds that will be used to request a temporary
  7944. Kubernetes service account token for the service account referenced by
  7945. `serviceAccountRef`.
  7946. Deprecated: this will be removed in the future.
  7947. Defaults to 10 minutes.
  7948. format: int64
  7949. type: integer
  7950. serviceAccountRef:
  7951. description: Service account field containing the name of a kubernetes ServiceAccount.
  7952. properties:
  7953. audiences:
  7954. description: |-
  7955. Audience specifies the `aud` claim for the service account token
  7956. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7957. then this audiences will be appended to the list
  7958. items:
  7959. type: string
  7960. type: array
  7961. name:
  7962. description: The name of the ServiceAccount resource being referred to.
  7963. maxLength: 253
  7964. minLength: 1
  7965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7966. type: string
  7967. namespace:
  7968. description: |-
  7969. Namespace of the resource being referred to.
  7970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7971. maxLength: 63
  7972. minLength: 1
  7973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7974. type: string
  7975. required:
  7976. - name
  7977. type: object
  7978. required:
  7979. - serviceAccountRef
  7980. type: object
  7981. path:
  7982. default: jwt
  7983. description: |-
  7984. Path where the JWT authentication backend is mounted
  7985. in Vault, e.g: "jwt"
  7986. type: string
  7987. role:
  7988. description: |-
  7989. Role is a JWT role to authenticate using the JWT/OIDC Vault
  7990. authentication method
  7991. type: string
  7992. secretRef:
  7993. description: |-
  7994. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  7995. authenticate with Vault using the JWT/OIDC authentication method.
  7996. properties:
  7997. key:
  7998. description: |-
  7999. A key in the referenced Secret.
  8000. Some instances of this field may be defaulted, in others it may be required.
  8001. maxLength: 253
  8002. minLength: 1
  8003. pattern: ^[-._a-zA-Z0-9]+$
  8004. type: string
  8005. name:
  8006. description: The name of the Secret resource being referred to.
  8007. maxLength: 253
  8008. minLength: 1
  8009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8010. type: string
  8011. namespace:
  8012. description: |-
  8013. The namespace of the Secret resource being referred to.
  8014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8015. maxLength: 63
  8016. minLength: 1
  8017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8018. type: string
  8019. type: object
  8020. required:
  8021. - path
  8022. type: object
  8023. kubernetes:
  8024. description: |-
  8025. Kubernetes authenticates with Vault by passing the ServiceAccount
  8026. token stored in the named Secret resource to the Vault server.
  8027. properties:
  8028. mountPath:
  8029. default: kubernetes
  8030. description: |-
  8031. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8032. "kubernetes"
  8033. type: string
  8034. role:
  8035. description: |-
  8036. A required field containing the Vault Role to assume. A Role binds a
  8037. Kubernetes ServiceAccount with a set of Vault policies.
  8038. type: string
  8039. secretRef:
  8040. description: |-
  8041. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8042. for authenticating with Vault. If a name is specified without a key,
  8043. `token` is the default. If one is not specified, the one bound to
  8044. the controller will be used.
  8045. properties:
  8046. key:
  8047. description: |-
  8048. A key in the referenced Secret.
  8049. Some instances of this field may be defaulted, in others it may be required.
  8050. maxLength: 253
  8051. minLength: 1
  8052. pattern: ^[-._a-zA-Z0-9]+$
  8053. type: string
  8054. name:
  8055. description: The name of the Secret resource being referred to.
  8056. maxLength: 253
  8057. minLength: 1
  8058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8059. type: string
  8060. namespace:
  8061. description: |-
  8062. The namespace of the Secret resource being referred to.
  8063. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8064. maxLength: 63
  8065. minLength: 1
  8066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8067. type: string
  8068. type: object
  8069. serviceAccountRef:
  8070. description: |-
  8071. Optional service account field containing the name of a kubernetes ServiceAccount.
  8072. If the service account is specified, the service account secret token JWT will be used
  8073. for authenticating with Vault. If the service account selector is not supplied,
  8074. the secretRef will be used instead.
  8075. properties:
  8076. audiences:
  8077. description: |-
  8078. Audience specifies the `aud` claim for the service account token
  8079. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8080. then this audiences will be appended to the list
  8081. items:
  8082. type: string
  8083. type: array
  8084. name:
  8085. description: The name of the ServiceAccount resource being referred to.
  8086. maxLength: 253
  8087. minLength: 1
  8088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8089. type: string
  8090. namespace:
  8091. description: |-
  8092. Namespace of the resource being referred to.
  8093. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8094. maxLength: 63
  8095. minLength: 1
  8096. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8097. type: string
  8098. required:
  8099. - name
  8100. type: object
  8101. required:
  8102. - mountPath
  8103. - role
  8104. type: object
  8105. ldap:
  8106. description: |-
  8107. Ldap authenticates with Vault by passing username/password pair using
  8108. the LDAP authentication method
  8109. properties:
  8110. path:
  8111. default: ldap
  8112. description: |-
  8113. Path where the LDAP authentication backend is mounted
  8114. in Vault, e.g: "ldap"
  8115. type: string
  8116. secretRef:
  8117. description: |-
  8118. SecretRef to a key in a Secret resource containing password for the LDAP
  8119. user used to authenticate with Vault using the LDAP authentication
  8120. method
  8121. properties:
  8122. key:
  8123. description: |-
  8124. A key in the referenced Secret.
  8125. Some instances of this field may be defaulted, in others it may be required.
  8126. maxLength: 253
  8127. minLength: 1
  8128. pattern: ^[-._a-zA-Z0-9]+$
  8129. type: string
  8130. name:
  8131. description: The name of the Secret resource being referred to.
  8132. maxLength: 253
  8133. minLength: 1
  8134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8135. type: string
  8136. namespace:
  8137. description: |-
  8138. The namespace of the Secret resource being referred to.
  8139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8140. maxLength: 63
  8141. minLength: 1
  8142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8143. type: string
  8144. type: object
  8145. username:
  8146. description: |-
  8147. Username is an LDAP username used to authenticate using the LDAP Vault
  8148. authentication method
  8149. type: string
  8150. required:
  8151. - path
  8152. - username
  8153. type: object
  8154. namespace:
  8155. description: |-
  8156. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8157. Namespaces is a set of features within Vault Enterprise that allows
  8158. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8159. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8160. This will default to Vault.Namespace field if set, or empty otherwise
  8161. type: string
  8162. tokenSecretRef:
  8163. description: TokenSecretRef authenticates with Vault by presenting a token.
  8164. properties:
  8165. key:
  8166. description: |-
  8167. A key in the referenced Secret.
  8168. Some instances of this field may be defaulted, in others it may be required.
  8169. maxLength: 253
  8170. minLength: 1
  8171. pattern: ^[-._a-zA-Z0-9]+$
  8172. type: string
  8173. name:
  8174. description: The name of the Secret resource being referred to.
  8175. maxLength: 253
  8176. minLength: 1
  8177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8178. type: string
  8179. namespace:
  8180. description: |-
  8181. The namespace of the Secret resource being referred to.
  8182. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8183. maxLength: 63
  8184. minLength: 1
  8185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8186. type: string
  8187. type: object
  8188. userPass:
  8189. description: UserPass authenticates with Vault by passing username/password pair
  8190. properties:
  8191. path:
  8192. default: userpass
  8193. description: |-
  8194. Path where the UserPassword authentication backend is mounted
  8195. in Vault, e.g: "userpass"
  8196. type: string
  8197. secretRef:
  8198. description: |-
  8199. SecretRef to a key in a Secret resource containing password for the
  8200. user used to authenticate with Vault using the UserPass authentication
  8201. method
  8202. properties:
  8203. key:
  8204. description: |-
  8205. A key in the referenced Secret.
  8206. Some instances of this field may be defaulted, in others it may be required.
  8207. maxLength: 253
  8208. minLength: 1
  8209. pattern: ^[-._a-zA-Z0-9]+$
  8210. type: string
  8211. name:
  8212. description: The name of the Secret resource being referred to.
  8213. maxLength: 253
  8214. minLength: 1
  8215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8216. type: string
  8217. namespace:
  8218. description: |-
  8219. The namespace of the Secret resource being referred to.
  8220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8221. maxLength: 63
  8222. minLength: 1
  8223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8224. type: string
  8225. type: object
  8226. username:
  8227. description: |-
  8228. Username is a username used to authenticate using the UserPass Vault
  8229. authentication method
  8230. type: string
  8231. required:
  8232. - path
  8233. - username
  8234. type: object
  8235. type: object
  8236. caBundle:
  8237. description: |-
  8238. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8239. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8240. plain HTTP protocol connection. If not set the system root certificates
  8241. are used to validate the TLS connection.
  8242. format: byte
  8243. type: string
  8244. caProvider:
  8245. description: The provider for the CA bundle to use to validate Vault server certificate.
  8246. properties:
  8247. key:
  8248. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8249. maxLength: 253
  8250. minLength: 1
  8251. pattern: ^[-._a-zA-Z0-9]+$
  8252. type: string
  8253. name:
  8254. description: The name of the object located at the provider type.
  8255. maxLength: 253
  8256. minLength: 1
  8257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8258. type: string
  8259. namespace:
  8260. description: |-
  8261. The namespace the Provider type is in.
  8262. Can only be defined when used in a ClusterSecretStore.
  8263. maxLength: 63
  8264. minLength: 1
  8265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8266. type: string
  8267. type:
  8268. description: The type of provider to use such as "Secret", or "ConfigMap".
  8269. enum:
  8270. - Secret
  8271. - ConfigMap
  8272. type: string
  8273. required:
  8274. - name
  8275. - type
  8276. type: object
  8277. checkAndSet:
  8278. description: |-
  8279. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8280. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8281. the current version of the secret to prevent unintentional overwrites.
  8282. properties:
  8283. required:
  8284. description: |-
  8285. Required when true, all write operations must include a check-and-set parameter.
  8286. This helps prevent unintentional overwrites of secrets.
  8287. type: boolean
  8288. type: object
  8289. forwardInconsistent:
  8290. description: |-
  8291. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8292. leader instead of simply retrying within a loop. This can increase performance if
  8293. the option is enabled serverside.
  8294. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8295. type: boolean
  8296. headers:
  8297. additionalProperties:
  8298. type: string
  8299. description: Headers to be added in Vault request
  8300. type: object
  8301. namespace:
  8302. description: |-
  8303. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8304. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8305. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8306. type: string
  8307. path:
  8308. description: |-
  8309. Path is the mount path of the Vault KV backend endpoint, e.g:
  8310. "secret". The v2 KV secret engine version specific "/data" path suffix
  8311. for fetching secrets from Vault is optional and will be appended
  8312. if not present in specified path.
  8313. type: string
  8314. readYourWrites:
  8315. description: |-
  8316. ReadYourWrites ensures isolated read-after-write semantics by
  8317. providing discovered cluster replication states in each request.
  8318. More information about eventual consistency in Vault can be found here
  8319. https://www.vaultproject.io/docs/enterprise/consistency
  8320. type: boolean
  8321. server:
  8322. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8323. type: string
  8324. tls:
  8325. description: |-
  8326. The configuration used for client side related TLS communication, when the Vault server
  8327. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8328. This parameter is ignored for plain HTTP protocol connection.
  8329. It's worth noting this configuration is different from the "TLS certificates auth method",
  8330. which is available under the `auth.cert` section.
  8331. properties:
  8332. certSecretRef:
  8333. description: |-
  8334. CertSecretRef is a certificate added to the transport layer
  8335. when communicating with the Vault server.
  8336. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8337. properties:
  8338. key:
  8339. description: |-
  8340. A key in the referenced Secret.
  8341. Some instances of this field may be defaulted, in others it may be required.
  8342. maxLength: 253
  8343. minLength: 1
  8344. pattern: ^[-._a-zA-Z0-9]+$
  8345. type: string
  8346. name:
  8347. description: The name of the Secret resource being referred to.
  8348. maxLength: 253
  8349. minLength: 1
  8350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8351. type: string
  8352. namespace:
  8353. description: |-
  8354. The namespace of the Secret resource being referred to.
  8355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8356. maxLength: 63
  8357. minLength: 1
  8358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8359. type: string
  8360. type: object
  8361. keySecretRef:
  8362. description: |-
  8363. KeySecretRef to a key in a Secret resource containing client private key
  8364. added to the transport layer when communicating with the Vault server.
  8365. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8366. properties:
  8367. key:
  8368. description: |-
  8369. A key in the referenced Secret.
  8370. Some instances of this field may be defaulted, in others it may be required.
  8371. maxLength: 253
  8372. minLength: 1
  8373. pattern: ^[-._a-zA-Z0-9]+$
  8374. type: string
  8375. name:
  8376. description: The name of the Secret resource being referred to.
  8377. maxLength: 253
  8378. minLength: 1
  8379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8380. type: string
  8381. namespace:
  8382. description: |-
  8383. The namespace of the Secret resource being referred to.
  8384. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8385. maxLength: 63
  8386. minLength: 1
  8387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8388. type: string
  8389. type: object
  8390. type: object
  8391. version:
  8392. default: v2
  8393. description: |-
  8394. Version is the Vault KV secret engine version. This can be either "v1" or
  8395. "v2". Version defaults to "v2".
  8396. enum:
  8397. - v1
  8398. - v2
  8399. type: string
  8400. required:
  8401. - server
  8402. type: object
  8403. volcengine:
  8404. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8405. properties:
  8406. auth:
  8407. description: |-
  8408. Auth defines the authentication method to use.
  8409. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8410. properties:
  8411. secretRef:
  8412. description: |-
  8413. SecretRef defines the static credentials to use for authentication.
  8414. If not set, IRSA is used.
  8415. properties:
  8416. accessKeyID:
  8417. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8418. properties:
  8419. key:
  8420. description: |-
  8421. A key in the referenced Secret.
  8422. Some instances of this field may be defaulted, in others it may be required.
  8423. maxLength: 253
  8424. minLength: 1
  8425. pattern: ^[-._a-zA-Z0-9]+$
  8426. type: string
  8427. name:
  8428. description: The name of the Secret resource being referred to.
  8429. maxLength: 253
  8430. minLength: 1
  8431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8432. type: string
  8433. namespace:
  8434. description: |-
  8435. The namespace of the Secret resource being referred to.
  8436. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8437. maxLength: 63
  8438. minLength: 1
  8439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8440. type: string
  8441. type: object
  8442. secretAccessKey:
  8443. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8444. properties:
  8445. key:
  8446. description: |-
  8447. A key in the referenced Secret.
  8448. Some instances of this field may be defaulted, in others it may be required.
  8449. maxLength: 253
  8450. minLength: 1
  8451. pattern: ^[-._a-zA-Z0-9]+$
  8452. type: string
  8453. name:
  8454. description: The name of the Secret resource being referred to.
  8455. maxLength: 253
  8456. minLength: 1
  8457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8458. type: string
  8459. namespace:
  8460. description: |-
  8461. The namespace of the Secret resource being referred to.
  8462. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8463. maxLength: 63
  8464. minLength: 1
  8465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8466. type: string
  8467. type: object
  8468. token:
  8469. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8470. properties:
  8471. key:
  8472. description: |-
  8473. A key in the referenced Secret.
  8474. Some instances of this field may be defaulted, in others it may be required.
  8475. maxLength: 253
  8476. minLength: 1
  8477. pattern: ^[-._a-zA-Z0-9]+$
  8478. type: string
  8479. name:
  8480. description: The name of the Secret resource being referred to.
  8481. maxLength: 253
  8482. minLength: 1
  8483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8484. type: string
  8485. namespace:
  8486. description: |-
  8487. The namespace of the Secret resource being referred to.
  8488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8489. maxLength: 63
  8490. minLength: 1
  8491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8492. type: string
  8493. type: object
  8494. required:
  8495. - accessKeyID
  8496. - secretAccessKey
  8497. type: object
  8498. type: object
  8499. region:
  8500. description: Region specifies the Volcengine region to connect to.
  8501. type: string
  8502. required:
  8503. - region
  8504. type: object
  8505. webhook:
  8506. description: Webhook configures this store to sync secrets using a generic templated webhook
  8507. properties:
  8508. auth:
  8509. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8510. maxProperties: 1
  8511. minProperties: 1
  8512. properties:
  8513. ntlm:
  8514. description: NTLMProtocol configures the store to use NTLM for auth
  8515. properties:
  8516. passwordSecret:
  8517. description: |-
  8518. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8519. In some instances, `key` is a required field.
  8520. properties:
  8521. key:
  8522. description: |-
  8523. A key in the referenced Secret.
  8524. Some instances of this field may be defaulted, in others it may be required.
  8525. maxLength: 253
  8526. minLength: 1
  8527. pattern: ^[-._a-zA-Z0-9]+$
  8528. type: string
  8529. name:
  8530. description: The name of the Secret resource being referred to.
  8531. maxLength: 253
  8532. minLength: 1
  8533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8534. type: string
  8535. namespace:
  8536. description: |-
  8537. The namespace of the Secret resource being referred to.
  8538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8539. maxLength: 63
  8540. minLength: 1
  8541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8542. type: string
  8543. type: object
  8544. usernameSecret:
  8545. description: |-
  8546. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8547. In some instances, `key` is a required field.
  8548. properties:
  8549. key:
  8550. description: |-
  8551. A key in the referenced Secret.
  8552. Some instances of this field may be defaulted, in others it may be required.
  8553. maxLength: 253
  8554. minLength: 1
  8555. pattern: ^[-._a-zA-Z0-9]+$
  8556. type: string
  8557. name:
  8558. description: The name of the Secret resource being referred to.
  8559. maxLength: 253
  8560. minLength: 1
  8561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8562. type: string
  8563. namespace:
  8564. description: |-
  8565. The namespace of the Secret resource being referred to.
  8566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8567. maxLength: 63
  8568. minLength: 1
  8569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8570. type: string
  8571. type: object
  8572. required:
  8573. - passwordSecret
  8574. - usernameSecret
  8575. type: object
  8576. type: object
  8577. body:
  8578. description: Body
  8579. type: string
  8580. caBundle:
  8581. description: |-
  8582. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8583. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8584. plain HTTP protocol connection. If not set the system root certificates
  8585. are used to validate the TLS connection.
  8586. format: byte
  8587. type: string
  8588. caProvider:
  8589. description: The provider for the CA bundle to use to validate webhook server certificate.
  8590. properties:
  8591. key:
  8592. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8593. maxLength: 253
  8594. minLength: 1
  8595. pattern: ^[-._a-zA-Z0-9]+$
  8596. type: string
  8597. name:
  8598. description: The name of the object located at the provider type.
  8599. maxLength: 253
  8600. minLength: 1
  8601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8602. type: string
  8603. namespace:
  8604. description: The namespace the Provider type is in.
  8605. maxLength: 63
  8606. minLength: 1
  8607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8608. type: string
  8609. type:
  8610. description: The type of provider to use such as "Secret", or "ConfigMap".
  8611. enum:
  8612. - Secret
  8613. - ConfigMap
  8614. type: string
  8615. required:
  8616. - name
  8617. - type
  8618. type: object
  8619. headers:
  8620. additionalProperties:
  8621. type: string
  8622. description: Headers
  8623. type: object
  8624. method:
  8625. description: Webhook Method
  8626. type: string
  8627. result:
  8628. description: Result formatting
  8629. properties:
  8630. jsonPath:
  8631. description: Json path of return value
  8632. type: string
  8633. type: object
  8634. secrets:
  8635. description: |-
  8636. Secrets to fill in templates
  8637. These secrets will be passed to the templating function as key value pairs under the given name
  8638. items:
  8639. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8640. properties:
  8641. name:
  8642. description: Name of this secret in templates
  8643. type: string
  8644. secretRef:
  8645. description: Secret ref to fill in credentials
  8646. properties:
  8647. key:
  8648. description: |-
  8649. A key in the referenced Secret.
  8650. Some instances of this field may be defaulted, in others it may be required.
  8651. maxLength: 253
  8652. minLength: 1
  8653. pattern: ^[-._a-zA-Z0-9]+$
  8654. type: string
  8655. name:
  8656. description: The name of the Secret resource being referred to.
  8657. maxLength: 253
  8658. minLength: 1
  8659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8660. type: string
  8661. namespace:
  8662. description: |-
  8663. The namespace of the Secret resource being referred to.
  8664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8665. maxLength: 63
  8666. minLength: 1
  8667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8668. type: string
  8669. type: object
  8670. required:
  8671. - name
  8672. - secretRef
  8673. type: object
  8674. type: array
  8675. timeout:
  8676. description: Timeout
  8677. type: string
  8678. url:
  8679. description: Webhook url to call
  8680. type: string
  8681. required:
  8682. - url
  8683. type: object
  8684. yandexcertificatemanager:
  8685. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  8686. properties:
  8687. apiEndpoint:
  8688. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  8689. type: string
  8690. auth:
  8691. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  8692. properties:
  8693. authorizedKeySecretRef:
  8694. description: The authorized key used for authentication
  8695. properties:
  8696. key:
  8697. description: |-
  8698. A key in the referenced Secret.
  8699. Some instances of this field may be defaulted, in others it may be required.
  8700. maxLength: 253
  8701. minLength: 1
  8702. pattern: ^[-._a-zA-Z0-9]+$
  8703. type: string
  8704. name:
  8705. description: The name of the Secret resource being referred to.
  8706. maxLength: 253
  8707. minLength: 1
  8708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8709. type: string
  8710. namespace:
  8711. description: |-
  8712. The namespace of the Secret resource being referred to.
  8713. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8714. maxLength: 63
  8715. minLength: 1
  8716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8717. type: string
  8718. type: object
  8719. type: object
  8720. caProvider:
  8721. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  8722. properties:
  8723. certSecretRef:
  8724. description: |-
  8725. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8726. In some instances, `key` is a required field.
  8727. properties:
  8728. key:
  8729. description: |-
  8730. A key in the referenced Secret.
  8731. Some instances of this field may be defaulted, in others it may be required.
  8732. maxLength: 253
  8733. minLength: 1
  8734. pattern: ^[-._a-zA-Z0-9]+$
  8735. type: string
  8736. name:
  8737. description: The name of the Secret resource being referred to.
  8738. maxLength: 253
  8739. minLength: 1
  8740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8741. type: string
  8742. namespace:
  8743. description: |-
  8744. The namespace of the Secret resource being referred to.
  8745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8746. maxLength: 63
  8747. minLength: 1
  8748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8749. type: string
  8750. type: object
  8751. type: object
  8752. fetching:
  8753. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  8754. maxProperties: 1
  8755. minProperties: 1
  8756. properties:
  8757. byID:
  8758. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  8759. type: object
  8760. byName:
  8761. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  8762. properties:
  8763. folderID:
  8764. description: The folder to fetch secrets from
  8765. type: string
  8766. required:
  8767. - folderID
  8768. type: object
  8769. type: object
  8770. required:
  8771. - auth
  8772. type: object
  8773. yandexlockbox:
  8774. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  8775. properties:
  8776. apiEndpoint:
  8777. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  8778. type: string
  8779. auth:
  8780. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  8781. properties:
  8782. authorizedKeySecretRef:
  8783. description: The authorized key used for authentication
  8784. properties:
  8785. key:
  8786. description: |-
  8787. A key in the referenced Secret.
  8788. Some instances of this field may be defaulted, in others it may be required.
  8789. maxLength: 253
  8790. minLength: 1
  8791. pattern: ^[-._a-zA-Z0-9]+$
  8792. type: string
  8793. name:
  8794. description: The name of the Secret resource being referred to.
  8795. maxLength: 253
  8796. minLength: 1
  8797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8798. type: string
  8799. namespace:
  8800. description: |-
  8801. The namespace of the Secret resource being referred to.
  8802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8803. maxLength: 63
  8804. minLength: 1
  8805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8806. type: string
  8807. type: object
  8808. type: object
  8809. caProvider:
  8810. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  8811. properties:
  8812. certSecretRef:
  8813. description: |-
  8814. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8815. In some instances, `key` is a required field.
  8816. properties:
  8817. key:
  8818. description: |-
  8819. A key in the referenced Secret.
  8820. Some instances of this field may be defaulted, in others it may be required.
  8821. maxLength: 253
  8822. minLength: 1
  8823. pattern: ^[-._a-zA-Z0-9]+$
  8824. type: string
  8825. name:
  8826. description: The name of the Secret resource being referred to.
  8827. maxLength: 253
  8828. minLength: 1
  8829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8830. type: string
  8831. namespace:
  8832. description: |-
  8833. The namespace of the Secret resource being referred to.
  8834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8835. maxLength: 63
  8836. minLength: 1
  8837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8838. type: string
  8839. type: object
  8840. type: object
  8841. fetching:
  8842. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  8843. maxProperties: 1
  8844. minProperties: 1
  8845. properties:
  8846. byID:
  8847. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  8848. type: object
  8849. byName:
  8850. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  8851. properties:
  8852. folderID:
  8853. description: The folder to fetch secrets from
  8854. type: string
  8855. required:
  8856. - folderID
  8857. type: object
  8858. type: object
  8859. required:
  8860. - auth
  8861. type: object
  8862. type: object
  8863. refreshInterval:
  8864. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  8865. type: integer
  8866. retrySettings:
  8867. description: Used to configure HTTP retries on failures.
  8868. properties:
  8869. maxRetries:
  8870. format: int32
  8871. type: integer
  8872. retryInterval:
  8873. type: string
  8874. type: object
  8875. required:
  8876. - provider
  8877. type: object
  8878. status:
  8879. description: SecretStoreStatus defines the observed state of the SecretStore.
  8880. properties:
  8881. capabilities:
  8882. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  8883. type: string
  8884. conditions:
  8885. items:
  8886. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  8887. properties:
  8888. lastTransitionTime:
  8889. format: date-time
  8890. type: string
  8891. message:
  8892. type: string
  8893. reason:
  8894. type: string
  8895. status:
  8896. type: string
  8897. type:
  8898. description: SecretStoreConditionType represents the condition of the SecretStore.
  8899. type: string
  8900. required:
  8901. - status
  8902. - type
  8903. type: object
  8904. type: array
  8905. type: object
  8906. type: object
  8907. served: true
  8908. storage: true
  8909. subresources:
  8910. status: {}
  8911. - additionalPrinterColumns:
  8912. - jsonPath: .metadata.creationTimestamp
  8913. name: AGE
  8914. type: date
  8915. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  8916. name: Status
  8917. type: string
  8918. - jsonPath: .status.capabilities
  8919. name: Capabilities
  8920. type: string
  8921. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  8922. name: Ready
  8923. type: string
  8924. deprecated: true
  8925. name: v1beta1
  8926. schema:
  8927. openAPIV3Schema:
  8928. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  8929. properties:
  8930. apiVersion:
  8931. description: |-
  8932. APIVersion defines the versioned schema of this representation of an object.
  8933. Servers should convert recognized schemas to the latest internal value, and
  8934. may reject unrecognized values.
  8935. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  8936. type: string
  8937. kind:
  8938. description: |-
  8939. Kind is a string value representing the REST resource this object represents.
  8940. Servers may infer this from the endpoint the client submits requests to.
  8941. Cannot be updated.
  8942. In CamelCase.
  8943. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  8944. type: string
  8945. metadata:
  8946. type: object
  8947. spec:
  8948. description: SecretStoreSpec defines the desired state of SecretStore.
  8949. properties:
  8950. conditions:
  8951. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  8952. items:
  8953. description: |-
  8954. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  8955. for a ClusterSecretStore instance.
  8956. properties:
  8957. namespaceRegexes:
  8958. description: Choose namespaces by using regex matching
  8959. items:
  8960. type: string
  8961. type: array
  8962. namespaceSelector:
  8963. description: Choose namespace using a labelSelector
  8964. properties:
  8965. matchExpressions:
  8966. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  8967. items:
  8968. description: |-
  8969. A label selector requirement is a selector that contains values, a key, and an operator that
  8970. relates the key and values.
  8971. properties:
  8972. key:
  8973. description: key is the label key that the selector applies to.
  8974. type: string
  8975. operator:
  8976. description: |-
  8977. operator represents a key's relationship to a set of values.
  8978. Valid operators are In, NotIn, Exists and DoesNotExist.
  8979. type: string
  8980. values:
  8981. description: |-
  8982. values is an array of string values. If the operator is In or NotIn,
  8983. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  8984. the values array must be empty. This array is replaced during a strategic
  8985. merge patch.
  8986. items:
  8987. type: string
  8988. type: array
  8989. x-kubernetes-list-type: atomic
  8990. required:
  8991. - key
  8992. - operator
  8993. type: object
  8994. type: array
  8995. x-kubernetes-list-type: atomic
  8996. matchLabels:
  8997. additionalProperties:
  8998. type: string
  8999. description: |-
  9000. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9001. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9002. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9003. type: object
  9004. type: object
  9005. x-kubernetes-map-type: atomic
  9006. namespaces:
  9007. description: Choose namespaces by name
  9008. items:
  9009. maxLength: 63
  9010. minLength: 1
  9011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9012. type: string
  9013. type: array
  9014. type: object
  9015. type: array
  9016. controller:
  9017. description: |-
  9018. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9019. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9020. type: string
  9021. provider:
  9022. description: Used to configure the provider. Only one provider may be set
  9023. maxProperties: 1
  9024. minProperties: 1
  9025. properties:
  9026. akeyless:
  9027. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9028. properties:
  9029. akeylessGWApiURL:
  9030. description: Akeyless GW API Url from which the secrets to be fetched from.
  9031. type: string
  9032. authSecretRef:
  9033. description: Auth configures how the operator authenticates with Akeyless.
  9034. properties:
  9035. kubernetesAuth:
  9036. description: |-
  9037. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9038. token stored in the named Secret resource.
  9039. properties:
  9040. accessID:
  9041. description: the Akeyless Kubernetes auth-method access-id
  9042. type: string
  9043. k8sConfName:
  9044. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9045. type: string
  9046. secretRef:
  9047. description: |-
  9048. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9049. for authenticating with Akeyless. If a name is specified without a key,
  9050. `token` is the default. If one is not specified, the one bound to
  9051. the controller will be used.
  9052. properties:
  9053. key:
  9054. description: |-
  9055. A key in the referenced Secret.
  9056. Some instances of this field may be defaulted, in others it may be required.
  9057. maxLength: 253
  9058. minLength: 1
  9059. pattern: ^[-._a-zA-Z0-9]+$
  9060. type: string
  9061. name:
  9062. description: The name of the Secret resource being referred to.
  9063. maxLength: 253
  9064. minLength: 1
  9065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9066. type: string
  9067. namespace:
  9068. description: |-
  9069. The namespace of the Secret resource being referred to.
  9070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9071. maxLength: 63
  9072. minLength: 1
  9073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9074. type: string
  9075. type: object
  9076. serviceAccountRef:
  9077. description: |-
  9078. Optional service account field containing the name of a kubernetes ServiceAccount.
  9079. If the service account is specified, the service account secret token JWT will be used
  9080. for authenticating with Akeyless. If the service account selector is not supplied,
  9081. the secretRef will be used instead.
  9082. properties:
  9083. audiences:
  9084. description: |-
  9085. Audience specifies the `aud` claim for the service account token
  9086. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9087. then this audiences will be appended to the list
  9088. items:
  9089. type: string
  9090. type: array
  9091. name:
  9092. description: The name of the ServiceAccount resource being referred to.
  9093. maxLength: 253
  9094. minLength: 1
  9095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9096. type: string
  9097. namespace:
  9098. description: |-
  9099. Namespace of the resource being referred to.
  9100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9101. maxLength: 63
  9102. minLength: 1
  9103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9104. type: string
  9105. required:
  9106. - name
  9107. type: object
  9108. required:
  9109. - accessID
  9110. - k8sConfName
  9111. type: object
  9112. secretRef:
  9113. description: |-
  9114. Reference to a Secret that contains the details
  9115. to authenticate with Akeyless.
  9116. properties:
  9117. accessID:
  9118. description: The SecretAccessID is used for authentication
  9119. properties:
  9120. key:
  9121. description: |-
  9122. A key in the referenced Secret.
  9123. Some instances of this field may be defaulted, in others it may be required.
  9124. maxLength: 253
  9125. minLength: 1
  9126. pattern: ^[-._a-zA-Z0-9]+$
  9127. type: string
  9128. name:
  9129. description: The name of the Secret resource being referred to.
  9130. maxLength: 253
  9131. minLength: 1
  9132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9133. type: string
  9134. namespace:
  9135. description: |-
  9136. The namespace of the Secret resource being referred to.
  9137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9138. maxLength: 63
  9139. minLength: 1
  9140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9141. type: string
  9142. type: object
  9143. accessType:
  9144. description: |-
  9145. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9146. In some instances, `key` is a required field.
  9147. properties:
  9148. key:
  9149. description: |-
  9150. A key in the referenced Secret.
  9151. Some instances of this field may be defaulted, in others it may be required.
  9152. maxLength: 253
  9153. minLength: 1
  9154. pattern: ^[-._a-zA-Z0-9]+$
  9155. type: string
  9156. name:
  9157. description: The name of the Secret resource being referred to.
  9158. maxLength: 253
  9159. minLength: 1
  9160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9161. type: string
  9162. namespace:
  9163. description: |-
  9164. The namespace of the Secret resource being referred to.
  9165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9166. maxLength: 63
  9167. minLength: 1
  9168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9169. type: string
  9170. type: object
  9171. accessTypeParam:
  9172. description: |-
  9173. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9174. In some instances, `key` is a required field.
  9175. properties:
  9176. key:
  9177. description: |-
  9178. A key in the referenced Secret.
  9179. Some instances of this field may be defaulted, in others it may be required.
  9180. maxLength: 253
  9181. minLength: 1
  9182. pattern: ^[-._a-zA-Z0-9]+$
  9183. type: string
  9184. name:
  9185. description: The name of the Secret resource being referred to.
  9186. maxLength: 253
  9187. minLength: 1
  9188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9189. type: string
  9190. namespace:
  9191. description: |-
  9192. The namespace of the Secret resource being referred to.
  9193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9194. maxLength: 63
  9195. minLength: 1
  9196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9197. type: string
  9198. type: object
  9199. type: object
  9200. type: object
  9201. caBundle:
  9202. description: |-
  9203. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9204. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9205. are used to validate the TLS connection.
  9206. format: byte
  9207. type: string
  9208. caProvider:
  9209. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9210. properties:
  9211. key:
  9212. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9213. maxLength: 253
  9214. minLength: 1
  9215. pattern: ^[-._a-zA-Z0-9]+$
  9216. type: string
  9217. name:
  9218. description: The name of the object located at the provider type.
  9219. maxLength: 253
  9220. minLength: 1
  9221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9222. type: string
  9223. namespace:
  9224. description: |-
  9225. The namespace the Provider type is in.
  9226. Can only be defined when used in a ClusterSecretStore.
  9227. maxLength: 63
  9228. minLength: 1
  9229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9230. type: string
  9231. type:
  9232. description: The type of provider to use such as "Secret", or "ConfigMap".
  9233. enum:
  9234. - Secret
  9235. - ConfigMap
  9236. type: string
  9237. required:
  9238. - name
  9239. - type
  9240. type: object
  9241. required:
  9242. - akeylessGWApiURL
  9243. - authSecretRef
  9244. type: object
  9245. alibaba:
  9246. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9247. properties:
  9248. auth:
  9249. description: AlibabaAuth contains a secretRef for credentials.
  9250. properties:
  9251. rrsa:
  9252. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9253. properties:
  9254. oidcProviderArn:
  9255. type: string
  9256. oidcTokenFilePath:
  9257. type: string
  9258. roleArn:
  9259. type: string
  9260. sessionName:
  9261. type: string
  9262. required:
  9263. - oidcProviderArn
  9264. - oidcTokenFilePath
  9265. - roleArn
  9266. - sessionName
  9267. type: object
  9268. secretRef:
  9269. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9270. properties:
  9271. accessKeyIDSecretRef:
  9272. description: The AccessKeyID is used for authentication
  9273. properties:
  9274. key:
  9275. description: |-
  9276. A key in the referenced Secret.
  9277. Some instances of this field may be defaulted, in others it may be required.
  9278. maxLength: 253
  9279. minLength: 1
  9280. pattern: ^[-._a-zA-Z0-9]+$
  9281. type: string
  9282. name:
  9283. description: The name of the Secret resource being referred to.
  9284. maxLength: 253
  9285. minLength: 1
  9286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9287. type: string
  9288. namespace:
  9289. description: |-
  9290. The namespace of the Secret resource being referred to.
  9291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9292. maxLength: 63
  9293. minLength: 1
  9294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9295. type: string
  9296. type: object
  9297. accessKeySecretSecretRef:
  9298. description: The AccessKeySecret is used for authentication
  9299. properties:
  9300. key:
  9301. description: |-
  9302. A key in the referenced Secret.
  9303. Some instances of this field may be defaulted, in others it may be required.
  9304. maxLength: 253
  9305. minLength: 1
  9306. pattern: ^[-._a-zA-Z0-9]+$
  9307. type: string
  9308. name:
  9309. description: The name of the Secret resource being referred to.
  9310. maxLength: 253
  9311. minLength: 1
  9312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9313. type: string
  9314. namespace:
  9315. description: |-
  9316. The namespace of the Secret resource being referred to.
  9317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9318. maxLength: 63
  9319. minLength: 1
  9320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9321. type: string
  9322. type: object
  9323. required:
  9324. - accessKeyIDSecretRef
  9325. - accessKeySecretSecretRef
  9326. type: object
  9327. type: object
  9328. regionID:
  9329. description: Alibaba Region to be used for the provider
  9330. type: string
  9331. required:
  9332. - auth
  9333. - regionID
  9334. type: object
  9335. aws:
  9336. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9337. properties:
  9338. additionalRoles:
  9339. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9340. items:
  9341. type: string
  9342. type: array
  9343. auth:
  9344. description: |-
  9345. Auth defines the information necessary to authenticate against AWS
  9346. if not set aws sdk will infer credentials from your environment
  9347. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9348. properties:
  9349. jwt:
  9350. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9351. properties:
  9352. serviceAccountRef:
  9353. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9354. properties:
  9355. audiences:
  9356. description: |-
  9357. Audience specifies the `aud` claim for the service account token
  9358. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9359. then this audiences will be appended to the list
  9360. items:
  9361. type: string
  9362. type: array
  9363. name:
  9364. description: The name of the ServiceAccount resource being referred to.
  9365. maxLength: 253
  9366. minLength: 1
  9367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9368. type: string
  9369. namespace:
  9370. description: |-
  9371. Namespace of the resource being referred to.
  9372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9373. maxLength: 63
  9374. minLength: 1
  9375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9376. type: string
  9377. required:
  9378. - name
  9379. type: object
  9380. type: object
  9381. secretRef:
  9382. description: |-
  9383. AWSAuthSecretRef holds secret references for AWS credentials
  9384. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9385. properties:
  9386. accessKeyIDSecretRef:
  9387. description: The AccessKeyID is used for authentication
  9388. properties:
  9389. key:
  9390. description: |-
  9391. A key in the referenced Secret.
  9392. Some instances of this field may be defaulted, in others it may be required.
  9393. maxLength: 253
  9394. minLength: 1
  9395. pattern: ^[-._a-zA-Z0-9]+$
  9396. type: string
  9397. name:
  9398. description: The name of the Secret resource being referred to.
  9399. maxLength: 253
  9400. minLength: 1
  9401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9402. type: string
  9403. namespace:
  9404. description: |-
  9405. The namespace of the Secret resource being referred to.
  9406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9407. maxLength: 63
  9408. minLength: 1
  9409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9410. type: string
  9411. type: object
  9412. secretAccessKeySecretRef:
  9413. description: The SecretAccessKey is used for authentication
  9414. properties:
  9415. key:
  9416. description: |-
  9417. A key in the referenced Secret.
  9418. Some instances of this field may be defaulted, in others it may be required.
  9419. maxLength: 253
  9420. minLength: 1
  9421. pattern: ^[-._a-zA-Z0-9]+$
  9422. type: string
  9423. name:
  9424. description: The name of the Secret resource being referred to.
  9425. maxLength: 253
  9426. minLength: 1
  9427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9428. type: string
  9429. namespace:
  9430. description: |-
  9431. The namespace of the Secret resource being referred to.
  9432. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9433. maxLength: 63
  9434. minLength: 1
  9435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9436. type: string
  9437. type: object
  9438. sessionTokenSecretRef:
  9439. description: |-
  9440. The SessionToken used for authentication
  9441. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9442. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9443. properties:
  9444. key:
  9445. description: |-
  9446. A key in the referenced Secret.
  9447. Some instances of this field may be defaulted, in others it may be required.
  9448. maxLength: 253
  9449. minLength: 1
  9450. pattern: ^[-._a-zA-Z0-9]+$
  9451. type: string
  9452. name:
  9453. description: The name of the Secret resource being referred to.
  9454. maxLength: 253
  9455. minLength: 1
  9456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9457. type: string
  9458. namespace:
  9459. description: |-
  9460. The namespace of the Secret resource being referred to.
  9461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9462. maxLength: 63
  9463. minLength: 1
  9464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9465. type: string
  9466. type: object
  9467. type: object
  9468. type: object
  9469. externalID:
  9470. description: AWS External ID set on assumed IAM roles
  9471. type: string
  9472. prefix:
  9473. description: Prefix adds a prefix to all retrieved values.
  9474. type: string
  9475. region:
  9476. description: AWS Region to be used for the provider
  9477. type: string
  9478. role:
  9479. description: Role is a Role ARN which the provider will assume
  9480. type: string
  9481. secretsManager:
  9482. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9483. properties:
  9484. forceDeleteWithoutRecovery:
  9485. description: |-
  9486. Specifies whether to delete the secret without any recovery window. You
  9487. can't use both this parameter and RecoveryWindowInDays in the same call.
  9488. If you don't use either, then by default Secrets Manager uses a 30 day
  9489. recovery window.
  9490. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9491. type: boolean
  9492. recoveryWindowInDays:
  9493. description: |-
  9494. The number of days from 7 to 30 that Secrets Manager waits before
  9495. permanently deleting the secret. You can't use both this parameter and
  9496. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9497. then by default Secrets Manager uses a 30 day recovery window.
  9498. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9499. format: int64
  9500. type: integer
  9501. type: object
  9502. service:
  9503. description: Service defines which service should be used to fetch the secrets
  9504. enum:
  9505. - SecretsManager
  9506. - ParameterStore
  9507. type: string
  9508. sessionTags:
  9509. description: AWS STS assume role session tags
  9510. items:
  9511. description: Tag defines a tag key and value for AWS resources.
  9512. properties:
  9513. key:
  9514. type: string
  9515. value:
  9516. type: string
  9517. required:
  9518. - key
  9519. - value
  9520. type: object
  9521. type: array
  9522. transitiveTagKeys:
  9523. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9524. items:
  9525. type: string
  9526. type: array
  9527. required:
  9528. - region
  9529. - service
  9530. type: object
  9531. azurekv:
  9532. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9533. properties:
  9534. authSecretRef:
  9535. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9536. properties:
  9537. clientCertificate:
  9538. description: The Azure ClientCertificate of the service principle used for authentication.
  9539. properties:
  9540. key:
  9541. description: |-
  9542. A key in the referenced Secret.
  9543. Some instances of this field may be defaulted, in others it may be required.
  9544. maxLength: 253
  9545. minLength: 1
  9546. pattern: ^[-._a-zA-Z0-9]+$
  9547. type: string
  9548. name:
  9549. description: The name of the Secret resource being referred to.
  9550. maxLength: 253
  9551. minLength: 1
  9552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9553. type: string
  9554. namespace:
  9555. description: |-
  9556. The namespace of the Secret resource being referred to.
  9557. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9558. maxLength: 63
  9559. minLength: 1
  9560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9561. type: string
  9562. type: object
  9563. clientId:
  9564. description: The Azure clientId of the service principle or managed identity used for authentication.
  9565. properties:
  9566. key:
  9567. description: |-
  9568. A key in the referenced Secret.
  9569. Some instances of this field may be defaulted, in others it may be required.
  9570. maxLength: 253
  9571. minLength: 1
  9572. pattern: ^[-._a-zA-Z0-9]+$
  9573. type: string
  9574. name:
  9575. description: The name of the Secret resource being referred to.
  9576. maxLength: 253
  9577. minLength: 1
  9578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9579. type: string
  9580. namespace:
  9581. description: |-
  9582. The namespace of the Secret resource being referred to.
  9583. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9584. maxLength: 63
  9585. minLength: 1
  9586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9587. type: string
  9588. type: object
  9589. clientSecret:
  9590. description: The Azure ClientSecret of the service principle used for authentication.
  9591. properties:
  9592. key:
  9593. description: |-
  9594. A key in the referenced Secret.
  9595. Some instances of this field may be defaulted, in others it may be required.
  9596. maxLength: 253
  9597. minLength: 1
  9598. pattern: ^[-._a-zA-Z0-9]+$
  9599. type: string
  9600. name:
  9601. description: The name of the Secret resource being referred to.
  9602. maxLength: 253
  9603. minLength: 1
  9604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9605. type: string
  9606. namespace:
  9607. description: |-
  9608. The namespace of the Secret resource being referred to.
  9609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9610. maxLength: 63
  9611. minLength: 1
  9612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9613. type: string
  9614. type: object
  9615. tenantId:
  9616. description: The Azure tenantId of the managed identity used for authentication.
  9617. properties:
  9618. key:
  9619. description: |-
  9620. A key in the referenced Secret.
  9621. Some instances of this field may be defaulted, in others it may be required.
  9622. maxLength: 253
  9623. minLength: 1
  9624. pattern: ^[-._a-zA-Z0-9]+$
  9625. type: string
  9626. name:
  9627. description: The name of the Secret resource being referred to.
  9628. maxLength: 253
  9629. minLength: 1
  9630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9631. type: string
  9632. namespace:
  9633. description: |-
  9634. The namespace of the Secret resource being referred to.
  9635. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9636. maxLength: 63
  9637. minLength: 1
  9638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9639. type: string
  9640. type: object
  9641. type: object
  9642. authType:
  9643. default: ServicePrincipal
  9644. description: |-
  9645. Auth type defines how to authenticate to the keyvault service.
  9646. Valid values are:
  9647. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  9648. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  9649. enum:
  9650. - ServicePrincipal
  9651. - ManagedIdentity
  9652. - WorkloadIdentity
  9653. type: string
  9654. environmentType:
  9655. default: PublicCloud
  9656. description: |-
  9657. EnvironmentType specifies the Azure cloud environment endpoints to use for
  9658. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  9659. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  9660. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  9661. enum:
  9662. - PublicCloud
  9663. - USGovernmentCloud
  9664. - ChinaCloud
  9665. - GermanCloud
  9666. type: string
  9667. identityId:
  9668. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  9669. type: string
  9670. serviceAccountRef:
  9671. description: |-
  9672. ServiceAccountRef specified the service account
  9673. that should be used when authenticating with WorkloadIdentity.
  9674. properties:
  9675. audiences:
  9676. description: |-
  9677. Audience specifies the `aud` claim for the service account token
  9678. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9679. then this audiences will be appended to the list
  9680. items:
  9681. type: string
  9682. type: array
  9683. name:
  9684. description: The name of the ServiceAccount resource being referred to.
  9685. maxLength: 253
  9686. minLength: 1
  9687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9688. type: string
  9689. namespace:
  9690. description: |-
  9691. Namespace of the resource being referred to.
  9692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9693. maxLength: 63
  9694. minLength: 1
  9695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9696. type: string
  9697. required:
  9698. - name
  9699. type: object
  9700. tenantId:
  9701. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9702. type: string
  9703. vaultUrl:
  9704. description: Vault Url from which the secrets to be fetched from.
  9705. type: string
  9706. required:
  9707. - vaultUrl
  9708. type: object
  9709. beyondtrust:
  9710. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  9711. properties:
  9712. auth:
  9713. description: Auth configures how the operator authenticates with Beyondtrust.
  9714. properties:
  9715. apiKey:
  9716. description: APIKey If not provided then ClientID/ClientSecret become required.
  9717. properties:
  9718. secretRef:
  9719. description: SecretRef references a key in a secret that will be used as value.
  9720. properties:
  9721. key:
  9722. description: |-
  9723. A key in the referenced Secret.
  9724. Some instances of this field may be defaulted, in others it may be required.
  9725. maxLength: 253
  9726. minLength: 1
  9727. pattern: ^[-._a-zA-Z0-9]+$
  9728. type: string
  9729. name:
  9730. description: The name of the Secret resource being referred to.
  9731. maxLength: 253
  9732. minLength: 1
  9733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9734. type: string
  9735. namespace:
  9736. description: |-
  9737. The namespace of the Secret resource being referred to.
  9738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9739. maxLength: 63
  9740. minLength: 1
  9741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9742. type: string
  9743. type: object
  9744. value:
  9745. description: Value can be specified directly to set a value without using a secret.
  9746. type: string
  9747. type: object
  9748. certificate:
  9749. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  9750. properties:
  9751. secretRef:
  9752. description: SecretRef references a key in a secret that will be used as value.
  9753. properties:
  9754. key:
  9755. description: |-
  9756. A key in the referenced Secret.
  9757. Some instances of this field may be defaulted, in others it may be required.
  9758. maxLength: 253
  9759. minLength: 1
  9760. pattern: ^[-._a-zA-Z0-9]+$
  9761. type: string
  9762. name:
  9763. description: The name of the Secret resource being referred to.
  9764. maxLength: 253
  9765. minLength: 1
  9766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9767. type: string
  9768. namespace:
  9769. description: |-
  9770. The namespace of the Secret resource being referred to.
  9771. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9772. maxLength: 63
  9773. minLength: 1
  9774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9775. type: string
  9776. type: object
  9777. value:
  9778. description: Value can be specified directly to set a value without using a secret.
  9779. type: string
  9780. type: object
  9781. certificateKey:
  9782. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  9783. properties:
  9784. secretRef:
  9785. description: SecretRef references a key in a secret that will be used as value.
  9786. properties:
  9787. key:
  9788. description: |-
  9789. A key in the referenced Secret.
  9790. Some instances of this field may be defaulted, in others it may be required.
  9791. maxLength: 253
  9792. minLength: 1
  9793. pattern: ^[-._a-zA-Z0-9]+$
  9794. type: string
  9795. name:
  9796. description: The name of the Secret resource being referred to.
  9797. maxLength: 253
  9798. minLength: 1
  9799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9800. type: string
  9801. namespace:
  9802. description: |-
  9803. The namespace of the Secret resource being referred to.
  9804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9805. maxLength: 63
  9806. minLength: 1
  9807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9808. type: string
  9809. type: object
  9810. value:
  9811. description: Value can be specified directly to set a value without using a secret.
  9812. type: string
  9813. type: object
  9814. clientId:
  9815. description: ClientID is the API OAuth Client ID.
  9816. properties:
  9817. secretRef:
  9818. description: SecretRef references a key in a secret that will be used as value.
  9819. properties:
  9820. key:
  9821. description: |-
  9822. A key in the referenced Secret.
  9823. Some instances of this field may be defaulted, in others it may be required.
  9824. maxLength: 253
  9825. minLength: 1
  9826. pattern: ^[-._a-zA-Z0-9]+$
  9827. type: string
  9828. name:
  9829. description: The name of the Secret resource being referred to.
  9830. maxLength: 253
  9831. minLength: 1
  9832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9833. type: string
  9834. namespace:
  9835. description: |-
  9836. The namespace of the Secret resource being referred to.
  9837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9838. maxLength: 63
  9839. minLength: 1
  9840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9841. type: string
  9842. type: object
  9843. value:
  9844. description: Value can be specified directly to set a value without using a secret.
  9845. type: string
  9846. type: object
  9847. clientSecret:
  9848. description: ClientSecret is the API OAuth Client Secret.
  9849. properties:
  9850. secretRef:
  9851. description: SecretRef references a key in a secret that will be used as value.
  9852. properties:
  9853. key:
  9854. description: |-
  9855. A key in the referenced Secret.
  9856. Some instances of this field may be defaulted, in others it may be required.
  9857. maxLength: 253
  9858. minLength: 1
  9859. pattern: ^[-._a-zA-Z0-9]+$
  9860. type: string
  9861. name:
  9862. description: The name of the Secret resource being referred to.
  9863. maxLength: 253
  9864. minLength: 1
  9865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9866. type: string
  9867. namespace:
  9868. description: |-
  9869. The namespace of the Secret resource being referred to.
  9870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9871. maxLength: 63
  9872. minLength: 1
  9873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9874. type: string
  9875. type: object
  9876. value:
  9877. description: Value can be specified directly to set a value without using a secret.
  9878. type: string
  9879. type: object
  9880. type: object
  9881. server:
  9882. description: Auth configures how API server works.
  9883. properties:
  9884. apiUrl:
  9885. type: string
  9886. apiVersion:
  9887. type: string
  9888. clientTimeOutSeconds:
  9889. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  9890. type: integer
  9891. decrypt:
  9892. default: true
  9893. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  9894. type: boolean
  9895. retrievalType:
  9896. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  9897. type: string
  9898. separator:
  9899. description: A character that separates the folder names.
  9900. type: string
  9901. verifyCA:
  9902. type: boolean
  9903. required:
  9904. - apiUrl
  9905. - verifyCA
  9906. type: object
  9907. required:
  9908. - auth
  9909. - server
  9910. type: object
  9911. bitwardensecretsmanager:
  9912. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  9913. properties:
  9914. apiURL:
  9915. type: string
  9916. auth:
  9917. description: |-
  9918. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  9919. Make sure that the token being used has permissions on the given secret.
  9920. properties:
  9921. secretRef:
  9922. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  9923. properties:
  9924. credentials:
  9925. description: AccessToken used for the bitwarden instance.
  9926. properties:
  9927. key:
  9928. description: |-
  9929. A key in the referenced Secret.
  9930. Some instances of this field may be defaulted, in others it may be required.
  9931. maxLength: 253
  9932. minLength: 1
  9933. pattern: ^[-._a-zA-Z0-9]+$
  9934. type: string
  9935. name:
  9936. description: The name of the Secret resource being referred to.
  9937. maxLength: 253
  9938. minLength: 1
  9939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9940. type: string
  9941. namespace:
  9942. description: |-
  9943. The namespace of the Secret resource being referred to.
  9944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9945. maxLength: 63
  9946. minLength: 1
  9947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9948. type: string
  9949. type: object
  9950. required:
  9951. - credentials
  9952. type: object
  9953. required:
  9954. - secretRef
  9955. type: object
  9956. bitwardenServerSDKURL:
  9957. type: string
  9958. caBundle:
  9959. description: |-
  9960. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  9961. can be performed.
  9962. type: string
  9963. caProvider:
  9964. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  9965. properties:
  9966. key:
  9967. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9968. maxLength: 253
  9969. minLength: 1
  9970. pattern: ^[-._a-zA-Z0-9]+$
  9971. type: string
  9972. name:
  9973. description: The name of the object located at the provider type.
  9974. maxLength: 253
  9975. minLength: 1
  9976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9977. type: string
  9978. namespace:
  9979. description: |-
  9980. The namespace the Provider type is in.
  9981. Can only be defined when used in a ClusterSecretStore.
  9982. maxLength: 63
  9983. minLength: 1
  9984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9985. type: string
  9986. type:
  9987. description: The type of provider to use such as "Secret", or "ConfigMap".
  9988. enum:
  9989. - Secret
  9990. - ConfigMap
  9991. type: string
  9992. required:
  9993. - name
  9994. - type
  9995. type: object
  9996. identityURL:
  9997. type: string
  9998. organizationID:
  9999. description: OrganizationID determines which organization this secret store manages.
  10000. type: string
  10001. projectID:
  10002. description: ProjectID determines which project this secret store manages.
  10003. type: string
  10004. required:
  10005. - auth
  10006. - organizationID
  10007. - projectID
  10008. type: object
  10009. chef:
  10010. description: Chef configures this store to sync secrets with chef server
  10011. properties:
  10012. auth:
  10013. description: Auth defines the information necessary to authenticate against chef Server
  10014. properties:
  10015. secretRef:
  10016. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10017. properties:
  10018. privateKeySecretRef:
  10019. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10020. properties:
  10021. key:
  10022. description: |-
  10023. A key in the referenced Secret.
  10024. Some instances of this field may be defaulted, in others it may be required.
  10025. maxLength: 253
  10026. minLength: 1
  10027. pattern: ^[-._a-zA-Z0-9]+$
  10028. type: string
  10029. name:
  10030. description: The name of the Secret resource being referred to.
  10031. maxLength: 253
  10032. minLength: 1
  10033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10034. type: string
  10035. namespace:
  10036. description: |-
  10037. The namespace of the Secret resource being referred to.
  10038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10039. maxLength: 63
  10040. minLength: 1
  10041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10042. type: string
  10043. type: object
  10044. required:
  10045. - privateKeySecretRef
  10046. type: object
  10047. required:
  10048. - secretRef
  10049. type: object
  10050. serverUrl:
  10051. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10052. type: string
  10053. username:
  10054. description: UserName should be the user ID on the chef server
  10055. type: string
  10056. required:
  10057. - auth
  10058. - serverUrl
  10059. - username
  10060. type: object
  10061. cloudrusm:
  10062. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10063. properties:
  10064. auth:
  10065. description: CSMAuth contains a secretRef for credentials.
  10066. properties:
  10067. secretRef:
  10068. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10069. properties:
  10070. accessKeyIDSecretRef:
  10071. description: The AccessKeyID is used for authentication
  10072. properties:
  10073. key:
  10074. description: |-
  10075. A key in the referenced Secret.
  10076. Some instances of this field may be defaulted, in others it may be required.
  10077. maxLength: 253
  10078. minLength: 1
  10079. pattern: ^[-._a-zA-Z0-9]+$
  10080. type: string
  10081. name:
  10082. description: The name of the Secret resource being referred to.
  10083. maxLength: 253
  10084. minLength: 1
  10085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10086. type: string
  10087. namespace:
  10088. description: |-
  10089. The namespace of the Secret resource being referred to.
  10090. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10091. maxLength: 63
  10092. minLength: 1
  10093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10094. type: string
  10095. type: object
  10096. accessKeySecretSecretRef:
  10097. description: The AccessKeySecret is used for authentication
  10098. properties:
  10099. key:
  10100. description: |-
  10101. A key in the referenced Secret.
  10102. Some instances of this field may be defaulted, in others it may be required.
  10103. maxLength: 253
  10104. minLength: 1
  10105. pattern: ^[-._a-zA-Z0-9]+$
  10106. type: string
  10107. name:
  10108. description: The name of the Secret resource being referred to.
  10109. maxLength: 253
  10110. minLength: 1
  10111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10112. type: string
  10113. namespace:
  10114. description: |-
  10115. The namespace of the Secret resource being referred to.
  10116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10117. maxLength: 63
  10118. minLength: 1
  10119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10120. type: string
  10121. type: object
  10122. required:
  10123. - accessKeyIDSecretRef
  10124. - accessKeySecretSecretRef
  10125. type: object
  10126. type: object
  10127. projectID:
  10128. description: ProjectID is the project, which the secrets are stored in.
  10129. type: string
  10130. required:
  10131. - auth
  10132. type: object
  10133. conjur:
  10134. description: Conjur configures this store to sync secrets using conjur provider
  10135. properties:
  10136. auth:
  10137. description: Defines authentication settings for connecting to Conjur.
  10138. properties:
  10139. apikey:
  10140. description: Authenticates with Conjur using an API key.
  10141. properties:
  10142. account:
  10143. description: Account is the Conjur organization account name.
  10144. type: string
  10145. apiKeyRef:
  10146. description: |-
  10147. A reference to a specific 'key' containing the Conjur API key
  10148. within a Secret resource. In some instances, `key` is a required field.
  10149. properties:
  10150. key:
  10151. description: |-
  10152. A key in the referenced Secret.
  10153. Some instances of this field may be defaulted, in others it may be required.
  10154. maxLength: 253
  10155. minLength: 1
  10156. pattern: ^[-._a-zA-Z0-9]+$
  10157. type: string
  10158. name:
  10159. description: The name of the Secret resource being referred to.
  10160. maxLength: 253
  10161. minLength: 1
  10162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10163. type: string
  10164. namespace:
  10165. description: |-
  10166. The namespace of the Secret resource being referred to.
  10167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10168. maxLength: 63
  10169. minLength: 1
  10170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10171. type: string
  10172. type: object
  10173. userRef:
  10174. description: |-
  10175. A reference to a specific 'key' containing the Conjur username
  10176. within a Secret resource. In some instances, `key` is a required field.
  10177. properties:
  10178. key:
  10179. description: |-
  10180. A key in the referenced Secret.
  10181. Some instances of this field may be defaulted, in others it may be required.
  10182. maxLength: 253
  10183. minLength: 1
  10184. pattern: ^[-._a-zA-Z0-9]+$
  10185. type: string
  10186. name:
  10187. description: The name of the Secret resource being referred to.
  10188. maxLength: 253
  10189. minLength: 1
  10190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10191. type: string
  10192. namespace:
  10193. description: |-
  10194. The namespace of the Secret resource being referred to.
  10195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10196. maxLength: 63
  10197. minLength: 1
  10198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10199. type: string
  10200. type: object
  10201. required:
  10202. - account
  10203. - apiKeyRef
  10204. - userRef
  10205. type: object
  10206. jwt:
  10207. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10208. properties:
  10209. account:
  10210. description: Account is the Conjur organization account name.
  10211. type: string
  10212. hostId:
  10213. description: |-
  10214. Optional HostID for JWT authentication. This may be used depending
  10215. on how the Conjur JWT authenticator policy is configured.
  10216. type: string
  10217. secretRef:
  10218. description: |-
  10219. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10220. authenticate with Conjur using the JWT authentication method.
  10221. properties:
  10222. key:
  10223. description: |-
  10224. A key in the referenced Secret.
  10225. Some instances of this field may be defaulted, in others it may be required.
  10226. maxLength: 253
  10227. minLength: 1
  10228. pattern: ^[-._a-zA-Z0-9]+$
  10229. type: string
  10230. name:
  10231. description: The name of the Secret resource being referred to.
  10232. maxLength: 253
  10233. minLength: 1
  10234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10235. type: string
  10236. namespace:
  10237. description: |-
  10238. The namespace of the Secret resource being referred to.
  10239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10240. maxLength: 63
  10241. minLength: 1
  10242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10243. type: string
  10244. type: object
  10245. serviceAccountRef:
  10246. description: |-
  10247. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10248. a token for with the `TokenRequest` API.
  10249. properties:
  10250. audiences:
  10251. description: |-
  10252. Audience specifies the `aud` claim for the service account token
  10253. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10254. then this audiences will be appended to the list
  10255. items:
  10256. type: string
  10257. type: array
  10258. name:
  10259. description: The name of the ServiceAccount resource being referred to.
  10260. maxLength: 253
  10261. minLength: 1
  10262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10263. type: string
  10264. namespace:
  10265. description: |-
  10266. Namespace of the resource being referred to.
  10267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10268. maxLength: 63
  10269. minLength: 1
  10270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10271. type: string
  10272. required:
  10273. - name
  10274. type: object
  10275. serviceID:
  10276. description: The conjur authn jwt webservice id
  10277. type: string
  10278. required:
  10279. - account
  10280. - serviceID
  10281. type: object
  10282. type: object
  10283. caBundle:
  10284. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10285. type: string
  10286. caProvider:
  10287. description: |-
  10288. Used to provide custom certificate authority (CA) certificates
  10289. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10290. that contains a PEM-encoded certificate.
  10291. properties:
  10292. key:
  10293. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10294. maxLength: 253
  10295. minLength: 1
  10296. pattern: ^[-._a-zA-Z0-9]+$
  10297. type: string
  10298. name:
  10299. description: The name of the object located at the provider type.
  10300. maxLength: 253
  10301. minLength: 1
  10302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10303. type: string
  10304. namespace:
  10305. description: |-
  10306. The namespace the Provider type is in.
  10307. Can only be defined when used in a ClusterSecretStore.
  10308. maxLength: 63
  10309. minLength: 1
  10310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10311. type: string
  10312. type:
  10313. description: The type of provider to use such as "Secret", or "ConfigMap".
  10314. enum:
  10315. - Secret
  10316. - ConfigMap
  10317. type: string
  10318. required:
  10319. - name
  10320. - type
  10321. type: object
  10322. url:
  10323. description: URL is the endpoint of the Conjur instance.
  10324. type: string
  10325. required:
  10326. - auth
  10327. - url
  10328. type: object
  10329. delinea:
  10330. description: |-
  10331. Delinea DevOps Secrets Vault
  10332. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10333. properties:
  10334. clientId:
  10335. description: ClientID is the non-secret part of the credential.
  10336. properties:
  10337. secretRef:
  10338. description: SecretRef references a key in a secret that will be used as value.
  10339. properties:
  10340. key:
  10341. description: |-
  10342. A key in the referenced Secret.
  10343. Some instances of this field may be defaulted, in others it may be required.
  10344. maxLength: 253
  10345. minLength: 1
  10346. pattern: ^[-._a-zA-Z0-9]+$
  10347. type: string
  10348. name:
  10349. description: The name of the Secret resource being referred to.
  10350. maxLength: 253
  10351. minLength: 1
  10352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10353. type: string
  10354. namespace:
  10355. description: |-
  10356. The namespace of the Secret resource being referred to.
  10357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10358. maxLength: 63
  10359. minLength: 1
  10360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10361. type: string
  10362. type: object
  10363. value:
  10364. description: Value can be specified directly to set a value without using a secret.
  10365. type: string
  10366. type: object
  10367. clientSecret:
  10368. description: ClientSecret is the secret part of the credential.
  10369. properties:
  10370. secretRef:
  10371. description: SecretRef references a key in a secret that will be used as value.
  10372. properties:
  10373. key:
  10374. description: |-
  10375. A key in the referenced Secret.
  10376. Some instances of this field may be defaulted, in others it may be required.
  10377. maxLength: 253
  10378. minLength: 1
  10379. pattern: ^[-._a-zA-Z0-9]+$
  10380. type: string
  10381. name:
  10382. description: The name of the Secret resource being referred to.
  10383. maxLength: 253
  10384. minLength: 1
  10385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10386. type: string
  10387. namespace:
  10388. description: |-
  10389. The namespace of the Secret resource being referred to.
  10390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10391. maxLength: 63
  10392. minLength: 1
  10393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10394. type: string
  10395. type: object
  10396. value:
  10397. description: Value can be specified directly to set a value without using a secret.
  10398. type: string
  10399. type: object
  10400. tenant:
  10401. description: Tenant is the chosen hostname / site name.
  10402. type: string
  10403. tld:
  10404. description: |-
  10405. TLD is based on the server location that was chosen during provisioning.
  10406. If unset, defaults to "com".
  10407. type: string
  10408. urlTemplate:
  10409. description: |-
  10410. URLTemplate
  10411. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10412. type: string
  10413. required:
  10414. - clientId
  10415. - clientSecret
  10416. - tenant
  10417. type: object
  10418. device42:
  10419. description: Device42 configures this store to sync secrets using the Device42 provider
  10420. properties:
  10421. auth:
  10422. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10423. properties:
  10424. secretRef:
  10425. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10426. properties:
  10427. credentials:
  10428. description: Username / Password is used for authentication.
  10429. properties:
  10430. key:
  10431. description: |-
  10432. A key in the referenced Secret.
  10433. Some instances of this field may be defaulted, in others it may be required.
  10434. maxLength: 253
  10435. minLength: 1
  10436. pattern: ^[-._a-zA-Z0-9]+$
  10437. type: string
  10438. name:
  10439. description: The name of the Secret resource being referred to.
  10440. maxLength: 253
  10441. minLength: 1
  10442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10443. type: string
  10444. namespace:
  10445. description: |-
  10446. The namespace of the Secret resource being referred to.
  10447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10448. maxLength: 63
  10449. minLength: 1
  10450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10451. type: string
  10452. type: object
  10453. type: object
  10454. required:
  10455. - secretRef
  10456. type: object
  10457. host:
  10458. description: URL configures the Device42 instance URL.
  10459. type: string
  10460. required:
  10461. - auth
  10462. - host
  10463. type: object
  10464. doppler:
  10465. description: Doppler configures this store to sync secrets using the Doppler provider
  10466. properties:
  10467. auth:
  10468. description: Auth configures how the Operator authenticates with the Doppler API
  10469. properties:
  10470. secretRef:
  10471. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10472. properties:
  10473. dopplerToken:
  10474. description: |-
  10475. The DopplerToken is used for authentication.
  10476. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10477. The Key attribute defaults to dopplerToken if not specified.
  10478. properties:
  10479. key:
  10480. description: |-
  10481. A key in the referenced Secret.
  10482. Some instances of this field may be defaulted, in others it may be required.
  10483. maxLength: 253
  10484. minLength: 1
  10485. pattern: ^[-._a-zA-Z0-9]+$
  10486. type: string
  10487. name:
  10488. description: The name of the Secret resource being referred to.
  10489. maxLength: 253
  10490. minLength: 1
  10491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10492. type: string
  10493. namespace:
  10494. description: |-
  10495. The namespace of the Secret resource being referred to.
  10496. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10497. maxLength: 63
  10498. minLength: 1
  10499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10500. type: string
  10501. type: object
  10502. required:
  10503. - dopplerToken
  10504. type: object
  10505. required:
  10506. - secretRef
  10507. type: object
  10508. config:
  10509. description: Doppler config (required if not using a Service Token)
  10510. type: string
  10511. format:
  10512. description: Format enables the downloading of secrets as a file (string)
  10513. enum:
  10514. - json
  10515. - dotnet-json
  10516. - env
  10517. - yaml
  10518. - docker
  10519. type: string
  10520. nameTransformer:
  10521. description: Environment variable compatible name transforms that change secret names to a different format
  10522. enum:
  10523. - upper-camel
  10524. - camel
  10525. - lower-snake
  10526. - tf-var
  10527. - dotnet-env
  10528. - lower-kebab
  10529. type: string
  10530. project:
  10531. description: Doppler project (required if not using a Service Token)
  10532. type: string
  10533. required:
  10534. - auth
  10535. type: object
  10536. fake:
  10537. description: Fake configures a store with static key/value pairs
  10538. properties:
  10539. data:
  10540. items:
  10541. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10542. properties:
  10543. key:
  10544. type: string
  10545. value:
  10546. type: string
  10547. version:
  10548. type: string
  10549. required:
  10550. - key
  10551. - value
  10552. type: object
  10553. type: array
  10554. required:
  10555. - data
  10556. type: object
  10557. fortanix:
  10558. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10559. properties:
  10560. apiKey:
  10561. description: APIKey is the API token to access SDKMS Applications.
  10562. properties:
  10563. secretRef:
  10564. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10565. properties:
  10566. key:
  10567. description: |-
  10568. A key in the referenced Secret.
  10569. Some instances of this field may be defaulted, in others it may be required.
  10570. maxLength: 253
  10571. minLength: 1
  10572. pattern: ^[-._a-zA-Z0-9]+$
  10573. type: string
  10574. name:
  10575. description: The name of the Secret resource being referred to.
  10576. maxLength: 253
  10577. minLength: 1
  10578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10579. type: string
  10580. namespace:
  10581. description: |-
  10582. The namespace of the Secret resource being referred to.
  10583. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10584. maxLength: 63
  10585. minLength: 1
  10586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10587. type: string
  10588. type: object
  10589. type: object
  10590. apiUrl:
  10591. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10592. type: string
  10593. type: object
  10594. gcpsm:
  10595. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10596. properties:
  10597. auth:
  10598. description: Auth defines the information necessary to authenticate against GCP
  10599. properties:
  10600. secretRef:
  10601. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10602. properties:
  10603. secretAccessKeySecretRef:
  10604. description: The SecretAccessKey is used for authentication
  10605. properties:
  10606. key:
  10607. description: |-
  10608. A key in the referenced Secret.
  10609. Some instances of this field may be defaulted, in others it may be required.
  10610. maxLength: 253
  10611. minLength: 1
  10612. pattern: ^[-._a-zA-Z0-9]+$
  10613. type: string
  10614. name:
  10615. description: The name of the Secret resource being referred to.
  10616. maxLength: 253
  10617. minLength: 1
  10618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10619. type: string
  10620. namespace:
  10621. description: |-
  10622. The namespace of the Secret resource being referred to.
  10623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10624. maxLength: 63
  10625. minLength: 1
  10626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10627. type: string
  10628. type: object
  10629. type: object
  10630. workloadIdentity:
  10631. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10632. properties:
  10633. clusterLocation:
  10634. description: |-
  10635. ClusterLocation is the location of the cluster
  10636. If not specified, it fetches information from the metadata server
  10637. type: string
  10638. clusterName:
  10639. description: |-
  10640. ClusterName is the name of the cluster
  10641. If not specified, it fetches information from the metadata server
  10642. type: string
  10643. clusterProjectID:
  10644. description: |-
  10645. ClusterProjectID is the project ID of the cluster
  10646. If not specified, it fetches information from the metadata server
  10647. type: string
  10648. serviceAccountRef:
  10649. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  10650. properties:
  10651. audiences:
  10652. description: |-
  10653. Audience specifies the `aud` claim for the service account token
  10654. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10655. then this audiences will be appended to the list
  10656. items:
  10657. type: string
  10658. type: array
  10659. name:
  10660. description: The name of the ServiceAccount resource being referred to.
  10661. maxLength: 253
  10662. minLength: 1
  10663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10664. type: string
  10665. namespace:
  10666. description: |-
  10667. Namespace of the resource being referred to.
  10668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10669. maxLength: 63
  10670. minLength: 1
  10671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10672. type: string
  10673. required:
  10674. - name
  10675. type: object
  10676. required:
  10677. - serviceAccountRef
  10678. type: object
  10679. type: object
  10680. location:
  10681. description: Location optionally defines a location for a secret
  10682. type: string
  10683. projectID:
  10684. description: ProjectID project where secret is located
  10685. type: string
  10686. type: object
  10687. github:
  10688. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  10689. properties:
  10690. appID:
  10691. description: appID specifies the Github APP that will be used to authenticate the client
  10692. format: int64
  10693. type: integer
  10694. auth:
  10695. description: auth configures how secret-manager authenticates with a Github instance.
  10696. properties:
  10697. privateKey:
  10698. description: |-
  10699. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10700. In some instances, `key` is a required field.
  10701. properties:
  10702. key:
  10703. description: |-
  10704. A key in the referenced Secret.
  10705. Some instances of this field may be defaulted, in others it may be required.
  10706. maxLength: 253
  10707. minLength: 1
  10708. pattern: ^[-._a-zA-Z0-9]+$
  10709. type: string
  10710. name:
  10711. description: The name of the Secret resource being referred to.
  10712. maxLength: 253
  10713. minLength: 1
  10714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10715. type: string
  10716. namespace:
  10717. description: |-
  10718. The namespace of the Secret resource being referred to.
  10719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10720. maxLength: 63
  10721. minLength: 1
  10722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10723. type: string
  10724. type: object
  10725. required:
  10726. - privateKey
  10727. type: object
  10728. environment:
  10729. description: environment will be used to fetch secrets from a particular environment within a github repository
  10730. type: string
  10731. installationID:
  10732. description: installationID specifies the Github APP installation that will be used to authenticate the client
  10733. format: int64
  10734. type: integer
  10735. organization:
  10736. description: organization will be used to fetch secrets from the Github organization
  10737. type: string
  10738. repository:
  10739. description: repository will be used to fetch secrets from the Github repository within an organization
  10740. type: string
  10741. uploadURL:
  10742. description: Upload URL for enterprise instances. Default to URL.
  10743. type: string
  10744. url:
  10745. default: https://github.com/
  10746. description: URL configures the Github instance URL. Defaults to https://github.com/.
  10747. type: string
  10748. required:
  10749. - appID
  10750. - auth
  10751. - installationID
  10752. - organization
  10753. type: object
  10754. gitlab:
  10755. description: GitLab configures this store to sync secrets using GitLab Variables provider
  10756. properties:
  10757. auth:
  10758. description: Auth configures how secret-manager authenticates with a GitLab instance.
  10759. properties:
  10760. SecretRef:
  10761. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  10762. properties:
  10763. accessToken:
  10764. description: AccessToken is used for authentication.
  10765. properties:
  10766. key:
  10767. description: |-
  10768. A key in the referenced Secret.
  10769. Some instances of this field may be defaulted, in others it may be required.
  10770. maxLength: 253
  10771. minLength: 1
  10772. pattern: ^[-._a-zA-Z0-9]+$
  10773. type: string
  10774. name:
  10775. description: The name of the Secret resource being referred to.
  10776. maxLength: 253
  10777. minLength: 1
  10778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10779. type: string
  10780. namespace:
  10781. description: |-
  10782. The namespace of the Secret resource being referred to.
  10783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10784. maxLength: 63
  10785. minLength: 1
  10786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10787. type: string
  10788. type: object
  10789. type: object
  10790. required:
  10791. - SecretRef
  10792. type: object
  10793. caBundle:
  10794. description: |-
  10795. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10796. can be performed.
  10797. format: byte
  10798. type: string
  10799. caProvider:
  10800. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10801. properties:
  10802. key:
  10803. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10804. maxLength: 253
  10805. minLength: 1
  10806. pattern: ^[-._a-zA-Z0-9]+$
  10807. type: string
  10808. name:
  10809. description: The name of the object located at the provider type.
  10810. maxLength: 253
  10811. minLength: 1
  10812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10813. type: string
  10814. namespace:
  10815. description: |-
  10816. The namespace the Provider type is in.
  10817. Can only be defined when used in a ClusterSecretStore.
  10818. maxLength: 63
  10819. minLength: 1
  10820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10821. type: string
  10822. type:
  10823. description: The type of provider to use such as "Secret", or "ConfigMap".
  10824. enum:
  10825. - Secret
  10826. - ConfigMap
  10827. type: string
  10828. required:
  10829. - name
  10830. - type
  10831. type: object
  10832. environment:
  10833. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  10834. type: string
  10835. groupIDs:
  10836. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  10837. items:
  10838. type: string
  10839. type: array
  10840. inheritFromGroups:
  10841. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  10842. type: boolean
  10843. projectID:
  10844. description: ProjectID specifies a project where secrets are located.
  10845. type: string
  10846. url:
  10847. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  10848. type: string
  10849. required:
  10850. - auth
  10851. type: object
  10852. ibm:
  10853. description: IBM configures this store to sync secrets using IBM Cloud provider
  10854. properties:
  10855. auth:
  10856. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  10857. maxProperties: 1
  10858. minProperties: 1
  10859. properties:
  10860. containerAuth:
  10861. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  10862. properties:
  10863. iamEndpoint:
  10864. type: string
  10865. profile:
  10866. description: the IBM Trusted Profile
  10867. type: string
  10868. tokenLocation:
  10869. description: Location the token is mounted on the pod
  10870. type: string
  10871. required:
  10872. - profile
  10873. type: object
  10874. secretRef:
  10875. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  10876. properties:
  10877. secretApiKeySecretRef:
  10878. description: The SecretAccessKey is used for authentication
  10879. properties:
  10880. key:
  10881. description: |-
  10882. A key in the referenced Secret.
  10883. Some instances of this field may be defaulted, in others it may be required.
  10884. maxLength: 253
  10885. minLength: 1
  10886. pattern: ^[-._a-zA-Z0-9]+$
  10887. type: string
  10888. name:
  10889. description: The name of the Secret resource being referred to.
  10890. maxLength: 253
  10891. minLength: 1
  10892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10893. type: string
  10894. namespace:
  10895. description: |-
  10896. The namespace of the Secret resource being referred to.
  10897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10898. maxLength: 63
  10899. minLength: 1
  10900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10901. type: string
  10902. type: object
  10903. type: object
  10904. type: object
  10905. serviceUrl:
  10906. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  10907. type: string
  10908. required:
  10909. - auth
  10910. type: object
  10911. infisical:
  10912. description: Infisical configures this store to sync secrets using the Infisical provider
  10913. properties:
  10914. auth:
  10915. description: Auth configures how the Operator authenticates with the Infisical API
  10916. properties:
  10917. universalAuthCredentials:
  10918. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  10919. properties:
  10920. clientId:
  10921. description: |-
  10922. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10923. In some instances, `key` is a required field.
  10924. properties:
  10925. key:
  10926. description: |-
  10927. A key in the referenced Secret.
  10928. Some instances of this field may be defaulted, in others it may be required.
  10929. maxLength: 253
  10930. minLength: 1
  10931. pattern: ^[-._a-zA-Z0-9]+$
  10932. type: string
  10933. name:
  10934. description: The name of the Secret resource being referred to.
  10935. maxLength: 253
  10936. minLength: 1
  10937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10938. type: string
  10939. namespace:
  10940. description: |-
  10941. The namespace of the Secret resource being referred to.
  10942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10943. maxLength: 63
  10944. minLength: 1
  10945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10946. type: string
  10947. type: object
  10948. clientSecret:
  10949. description: |-
  10950. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  10951. In some instances, `key` is a required field.
  10952. properties:
  10953. key:
  10954. description: |-
  10955. A key in the referenced Secret.
  10956. Some instances of this field may be defaulted, in others it may be required.
  10957. maxLength: 253
  10958. minLength: 1
  10959. pattern: ^[-._a-zA-Z0-9]+$
  10960. type: string
  10961. name:
  10962. description: The name of the Secret resource being referred to.
  10963. maxLength: 253
  10964. minLength: 1
  10965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10966. type: string
  10967. namespace:
  10968. description: |-
  10969. The namespace of the Secret resource being referred to.
  10970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10971. maxLength: 63
  10972. minLength: 1
  10973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10974. type: string
  10975. type: object
  10976. required:
  10977. - clientId
  10978. - clientSecret
  10979. type: object
  10980. type: object
  10981. hostAPI:
  10982. default: https://app.infisical.com/api
  10983. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  10984. type: string
  10985. secretsScope:
  10986. description: SecretsScope defines the scope of the secrets within the workspace
  10987. properties:
  10988. environmentSlug:
  10989. description: EnvironmentSlug is the required slug identifier for the environment.
  10990. type: string
  10991. expandSecretReferences:
  10992. default: true
  10993. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  10994. type: boolean
  10995. projectSlug:
  10996. description: ProjectSlug is the required slug identifier for the project.
  10997. type: string
  10998. recursive:
  10999. default: false
  11000. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11001. type: boolean
  11002. secretsPath:
  11003. default: /
  11004. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11005. type: string
  11006. required:
  11007. - environmentSlug
  11008. - projectSlug
  11009. type: object
  11010. required:
  11011. - auth
  11012. - secretsScope
  11013. type: object
  11014. keepersecurity:
  11015. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11016. properties:
  11017. authRef:
  11018. description: |-
  11019. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11020. In some instances, `key` is a required field.
  11021. properties:
  11022. key:
  11023. description: |-
  11024. A key in the referenced Secret.
  11025. Some instances of this field may be defaulted, in others it may be required.
  11026. maxLength: 253
  11027. minLength: 1
  11028. pattern: ^[-._a-zA-Z0-9]+$
  11029. type: string
  11030. name:
  11031. description: The name of the Secret resource being referred to.
  11032. maxLength: 253
  11033. minLength: 1
  11034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11035. type: string
  11036. namespace:
  11037. description: |-
  11038. The namespace of the Secret resource being referred to.
  11039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11040. maxLength: 63
  11041. minLength: 1
  11042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11043. type: string
  11044. type: object
  11045. folderID:
  11046. type: string
  11047. required:
  11048. - authRef
  11049. - folderID
  11050. type: object
  11051. kubernetes:
  11052. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11053. properties:
  11054. auth:
  11055. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11056. maxProperties: 1
  11057. minProperties: 1
  11058. properties:
  11059. cert:
  11060. description: has both clientCert and clientKey as secretKeySelector
  11061. properties:
  11062. clientCert:
  11063. description: |-
  11064. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11065. In some instances, `key` is a required field.
  11066. properties:
  11067. key:
  11068. description: |-
  11069. A key in the referenced Secret.
  11070. Some instances of this field may be defaulted, in others it may be required.
  11071. maxLength: 253
  11072. minLength: 1
  11073. pattern: ^[-._a-zA-Z0-9]+$
  11074. type: string
  11075. name:
  11076. description: The name of the Secret resource being referred to.
  11077. maxLength: 253
  11078. minLength: 1
  11079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11080. type: string
  11081. namespace:
  11082. description: |-
  11083. The namespace of the Secret resource being referred to.
  11084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11085. maxLength: 63
  11086. minLength: 1
  11087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11088. type: string
  11089. type: object
  11090. clientKey:
  11091. description: |-
  11092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11093. In some instances, `key` is a required field.
  11094. properties:
  11095. key:
  11096. description: |-
  11097. A key in the referenced Secret.
  11098. Some instances of this field may be defaulted, in others it may be required.
  11099. maxLength: 253
  11100. minLength: 1
  11101. pattern: ^[-._a-zA-Z0-9]+$
  11102. type: string
  11103. name:
  11104. description: The name of the Secret resource being referred to.
  11105. maxLength: 253
  11106. minLength: 1
  11107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11108. type: string
  11109. namespace:
  11110. description: |-
  11111. The namespace of the Secret resource being referred to.
  11112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11113. maxLength: 63
  11114. minLength: 1
  11115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11116. type: string
  11117. type: object
  11118. type: object
  11119. serviceAccount:
  11120. description: points to a service account that should be used for authentication
  11121. properties:
  11122. audiences:
  11123. description: |-
  11124. Audience specifies the `aud` claim for the service account token
  11125. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11126. then this audiences will be appended to the list
  11127. items:
  11128. type: string
  11129. type: array
  11130. name:
  11131. description: The name of the ServiceAccount resource being referred to.
  11132. maxLength: 253
  11133. minLength: 1
  11134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11135. type: string
  11136. namespace:
  11137. description: |-
  11138. Namespace of the resource being referred to.
  11139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11140. maxLength: 63
  11141. minLength: 1
  11142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11143. type: string
  11144. required:
  11145. - name
  11146. type: object
  11147. token:
  11148. description: use static token to authenticate with
  11149. properties:
  11150. bearerToken:
  11151. description: |-
  11152. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11153. In some instances, `key` is a required field.
  11154. properties:
  11155. key:
  11156. description: |-
  11157. A key in the referenced Secret.
  11158. Some instances of this field may be defaulted, in others it may be required.
  11159. maxLength: 253
  11160. minLength: 1
  11161. pattern: ^[-._a-zA-Z0-9]+$
  11162. type: string
  11163. name:
  11164. description: The name of the Secret resource being referred to.
  11165. maxLength: 253
  11166. minLength: 1
  11167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11168. type: string
  11169. namespace:
  11170. description: |-
  11171. The namespace of the Secret resource being referred to.
  11172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11173. maxLength: 63
  11174. minLength: 1
  11175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11176. type: string
  11177. type: object
  11178. type: object
  11179. type: object
  11180. authRef:
  11181. description: A reference to a secret that contains the auth information.
  11182. properties:
  11183. key:
  11184. description: |-
  11185. A key in the referenced Secret.
  11186. Some instances of this field may be defaulted, in others it may be required.
  11187. maxLength: 253
  11188. minLength: 1
  11189. pattern: ^[-._a-zA-Z0-9]+$
  11190. type: string
  11191. name:
  11192. description: The name of the Secret resource being referred to.
  11193. maxLength: 253
  11194. minLength: 1
  11195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11196. type: string
  11197. namespace:
  11198. description: |-
  11199. The namespace of the Secret resource being referred to.
  11200. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11201. maxLength: 63
  11202. minLength: 1
  11203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11204. type: string
  11205. type: object
  11206. remoteNamespace:
  11207. default: default
  11208. description: Remote namespace to fetch the secrets from
  11209. maxLength: 63
  11210. minLength: 1
  11211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11212. type: string
  11213. server:
  11214. description: configures the Kubernetes server Address.
  11215. properties:
  11216. caBundle:
  11217. description: CABundle is a base64-encoded CA certificate
  11218. format: byte
  11219. type: string
  11220. caProvider:
  11221. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11222. properties:
  11223. key:
  11224. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11225. maxLength: 253
  11226. minLength: 1
  11227. pattern: ^[-._a-zA-Z0-9]+$
  11228. type: string
  11229. name:
  11230. description: The name of the object located at the provider type.
  11231. maxLength: 253
  11232. minLength: 1
  11233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11234. type: string
  11235. namespace:
  11236. description: |-
  11237. The namespace the Provider type is in.
  11238. Can only be defined when used in a ClusterSecretStore.
  11239. maxLength: 63
  11240. minLength: 1
  11241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11242. type: string
  11243. type:
  11244. description: The type of provider to use such as "Secret", or "ConfigMap".
  11245. enum:
  11246. - Secret
  11247. - ConfigMap
  11248. type: string
  11249. required:
  11250. - name
  11251. - type
  11252. type: object
  11253. url:
  11254. default: kubernetes.default
  11255. description: configures the Kubernetes server Address.
  11256. type: string
  11257. type: object
  11258. type: object
  11259. onboardbase:
  11260. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11261. properties:
  11262. apiHost:
  11263. default: https://public.onboardbase.com/api/v1/
  11264. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11265. type: string
  11266. auth:
  11267. description: Auth configures how the Operator authenticates with the Onboardbase API
  11268. properties:
  11269. apiKeyRef:
  11270. description: |-
  11271. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11272. It is used to recognize and authorize access to a project and environment within onboardbase
  11273. properties:
  11274. key:
  11275. description: |-
  11276. A key in the referenced Secret.
  11277. Some instances of this field may be defaulted, in others it may be required.
  11278. maxLength: 253
  11279. minLength: 1
  11280. pattern: ^[-._a-zA-Z0-9]+$
  11281. type: string
  11282. name:
  11283. description: The name of the Secret resource being referred to.
  11284. maxLength: 253
  11285. minLength: 1
  11286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11287. type: string
  11288. namespace:
  11289. description: |-
  11290. The namespace of the Secret resource being referred to.
  11291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11292. maxLength: 63
  11293. minLength: 1
  11294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11295. type: string
  11296. type: object
  11297. passcodeRef:
  11298. description: OnboardbasePasscode is the passcode attached to the API Key
  11299. properties:
  11300. key:
  11301. description: |-
  11302. A key in the referenced Secret.
  11303. Some instances of this field may be defaulted, in others it may be required.
  11304. maxLength: 253
  11305. minLength: 1
  11306. pattern: ^[-._a-zA-Z0-9]+$
  11307. type: string
  11308. name:
  11309. description: The name of the Secret resource being referred to.
  11310. maxLength: 253
  11311. minLength: 1
  11312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11313. type: string
  11314. namespace:
  11315. description: |-
  11316. The namespace of the Secret resource being referred to.
  11317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11318. maxLength: 63
  11319. minLength: 1
  11320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11321. type: string
  11322. type: object
  11323. required:
  11324. - apiKeyRef
  11325. - passcodeRef
  11326. type: object
  11327. environment:
  11328. default: development
  11329. description: Environment is the name of an environmnent within a project to pull the secrets from
  11330. type: string
  11331. project:
  11332. default: development
  11333. description: Project is an onboardbase project that the secrets should be pulled from
  11334. type: string
  11335. required:
  11336. - apiHost
  11337. - auth
  11338. - environment
  11339. - project
  11340. type: object
  11341. onepassword:
  11342. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11343. properties:
  11344. auth:
  11345. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11346. properties:
  11347. secretRef:
  11348. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11349. properties:
  11350. connectTokenSecretRef:
  11351. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11352. properties:
  11353. key:
  11354. description: |-
  11355. A key in the referenced Secret.
  11356. Some instances of this field may be defaulted, in others it may be required.
  11357. maxLength: 253
  11358. minLength: 1
  11359. pattern: ^[-._a-zA-Z0-9]+$
  11360. type: string
  11361. name:
  11362. description: The name of the Secret resource being referred to.
  11363. maxLength: 253
  11364. minLength: 1
  11365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11366. type: string
  11367. namespace:
  11368. description: |-
  11369. The namespace of the Secret resource being referred to.
  11370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11371. maxLength: 63
  11372. minLength: 1
  11373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11374. type: string
  11375. type: object
  11376. required:
  11377. - connectTokenSecretRef
  11378. type: object
  11379. required:
  11380. - secretRef
  11381. type: object
  11382. connectHost:
  11383. description: ConnectHost defines the OnePassword Connect Server to connect to
  11384. type: string
  11385. vaults:
  11386. additionalProperties:
  11387. type: integer
  11388. description: Vaults defines which OnePassword vaults to search in which order
  11389. type: object
  11390. required:
  11391. - auth
  11392. - connectHost
  11393. - vaults
  11394. type: object
  11395. oracle:
  11396. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11397. properties:
  11398. auth:
  11399. description: |-
  11400. Auth configures how secret-manager authenticates with the Oracle Vault.
  11401. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11402. properties:
  11403. secretRef:
  11404. description: SecretRef to pass through sensitive information.
  11405. properties:
  11406. fingerprint:
  11407. description: Fingerprint is the fingerprint of the API private key.
  11408. properties:
  11409. key:
  11410. description: |-
  11411. A key in the referenced Secret.
  11412. Some instances of this field may be defaulted, in others it may be required.
  11413. maxLength: 253
  11414. minLength: 1
  11415. pattern: ^[-._a-zA-Z0-9]+$
  11416. type: string
  11417. name:
  11418. description: The name of the Secret resource being referred to.
  11419. maxLength: 253
  11420. minLength: 1
  11421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11422. type: string
  11423. namespace:
  11424. description: |-
  11425. The namespace of the Secret resource being referred to.
  11426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11427. maxLength: 63
  11428. minLength: 1
  11429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11430. type: string
  11431. type: object
  11432. privatekey:
  11433. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11434. properties:
  11435. key:
  11436. description: |-
  11437. A key in the referenced Secret.
  11438. Some instances of this field may be defaulted, in others it may be required.
  11439. maxLength: 253
  11440. minLength: 1
  11441. pattern: ^[-._a-zA-Z0-9]+$
  11442. type: string
  11443. name:
  11444. description: The name of the Secret resource being referred to.
  11445. maxLength: 253
  11446. minLength: 1
  11447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11448. type: string
  11449. namespace:
  11450. description: |-
  11451. The namespace of the Secret resource being referred to.
  11452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11453. maxLength: 63
  11454. minLength: 1
  11455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11456. type: string
  11457. type: object
  11458. required:
  11459. - fingerprint
  11460. - privatekey
  11461. type: object
  11462. tenancy:
  11463. description: Tenancy is the tenancy OCID where user is located.
  11464. type: string
  11465. user:
  11466. description: User is an access OCID specific to the account.
  11467. type: string
  11468. required:
  11469. - secretRef
  11470. - tenancy
  11471. - user
  11472. type: object
  11473. compartment:
  11474. description: |-
  11475. Compartment is the vault compartment OCID.
  11476. Required for PushSecret
  11477. type: string
  11478. encryptionKey:
  11479. description: |-
  11480. EncryptionKey is the OCID of the encryption key within the vault.
  11481. Required for PushSecret
  11482. type: string
  11483. principalType:
  11484. description: |-
  11485. The type of principal to use for authentication. If left blank, the Auth struct will
  11486. determine the principal type. This optional field must be specified if using
  11487. workload identity.
  11488. enum:
  11489. - ""
  11490. - UserPrincipal
  11491. - InstancePrincipal
  11492. - Workload
  11493. type: string
  11494. region:
  11495. description: Region is the region where vault is located.
  11496. type: string
  11497. serviceAccountRef:
  11498. description: |-
  11499. ServiceAccountRef specified the service account
  11500. that should be used when authenticating with WorkloadIdentity.
  11501. properties:
  11502. audiences:
  11503. description: |-
  11504. Audience specifies the `aud` claim for the service account token
  11505. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11506. then this audiences will be appended to the list
  11507. items:
  11508. type: string
  11509. type: array
  11510. name:
  11511. description: The name of the ServiceAccount resource being referred to.
  11512. maxLength: 253
  11513. minLength: 1
  11514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11515. type: string
  11516. namespace:
  11517. description: |-
  11518. Namespace of the resource being referred to.
  11519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11520. maxLength: 63
  11521. minLength: 1
  11522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11523. type: string
  11524. required:
  11525. - name
  11526. type: object
  11527. vault:
  11528. description: Vault is the vault's OCID of the specific vault where secret is located.
  11529. type: string
  11530. required:
  11531. - region
  11532. - vault
  11533. type: object
  11534. passbolt:
  11535. description: PassboltProvider defines configuration for the Passbolt provider.
  11536. properties:
  11537. auth:
  11538. description: Auth defines the information necessary to authenticate against Passbolt Server
  11539. properties:
  11540. passwordSecretRef:
  11541. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11542. properties:
  11543. key:
  11544. description: |-
  11545. A key in the referenced Secret.
  11546. Some instances of this field may be defaulted, in others it may be required.
  11547. maxLength: 253
  11548. minLength: 1
  11549. pattern: ^[-._a-zA-Z0-9]+$
  11550. type: string
  11551. name:
  11552. description: The name of the Secret resource being referred to.
  11553. maxLength: 253
  11554. minLength: 1
  11555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11556. type: string
  11557. namespace:
  11558. description: |-
  11559. The namespace of the Secret resource being referred to.
  11560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11561. maxLength: 63
  11562. minLength: 1
  11563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11564. type: string
  11565. type: object
  11566. privateKeySecretRef:
  11567. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11568. properties:
  11569. key:
  11570. description: |-
  11571. A key in the referenced Secret.
  11572. Some instances of this field may be defaulted, in others it may be required.
  11573. maxLength: 253
  11574. minLength: 1
  11575. pattern: ^[-._a-zA-Z0-9]+$
  11576. type: string
  11577. name:
  11578. description: The name of the Secret resource being referred to.
  11579. maxLength: 253
  11580. minLength: 1
  11581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11582. type: string
  11583. namespace:
  11584. description: |-
  11585. The namespace of the Secret resource being referred to.
  11586. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11587. maxLength: 63
  11588. minLength: 1
  11589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11590. type: string
  11591. type: object
  11592. required:
  11593. - passwordSecretRef
  11594. - privateKeySecretRef
  11595. type: object
  11596. host:
  11597. description: Host defines the Passbolt Server to connect to
  11598. type: string
  11599. required:
  11600. - auth
  11601. - host
  11602. type: object
  11603. passworddepot:
  11604. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11605. properties:
  11606. auth:
  11607. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11608. properties:
  11609. secretRef:
  11610. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11611. properties:
  11612. credentials:
  11613. description: Username / Password is used for authentication.
  11614. properties:
  11615. key:
  11616. description: |-
  11617. A key in the referenced Secret.
  11618. Some instances of this field may be defaulted, in others it may be required.
  11619. maxLength: 253
  11620. minLength: 1
  11621. pattern: ^[-._a-zA-Z0-9]+$
  11622. type: string
  11623. name:
  11624. description: The name of the Secret resource being referred to.
  11625. maxLength: 253
  11626. minLength: 1
  11627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11628. type: string
  11629. namespace:
  11630. description: |-
  11631. The namespace of the Secret resource being referred to.
  11632. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11633. maxLength: 63
  11634. minLength: 1
  11635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11636. type: string
  11637. type: object
  11638. type: object
  11639. required:
  11640. - secretRef
  11641. type: object
  11642. database:
  11643. description: Database to use as source
  11644. type: string
  11645. host:
  11646. description: URL configures the Password Depot instance URL.
  11647. type: string
  11648. required:
  11649. - auth
  11650. - database
  11651. - host
  11652. type: object
  11653. previder:
  11654. description: Previder configures this store to sync secrets using the Previder provider
  11655. properties:
  11656. auth:
  11657. description: PreviderAuth contains a secretRef for credentials.
  11658. properties:
  11659. secretRef:
  11660. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  11661. properties:
  11662. accessToken:
  11663. description: The AccessToken is used for authentication
  11664. properties:
  11665. key:
  11666. description: |-
  11667. A key in the referenced Secret.
  11668. Some instances of this field may be defaulted, in others it may be required.
  11669. maxLength: 253
  11670. minLength: 1
  11671. pattern: ^[-._a-zA-Z0-9]+$
  11672. type: string
  11673. name:
  11674. description: The name of the Secret resource being referred to.
  11675. maxLength: 253
  11676. minLength: 1
  11677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11678. type: string
  11679. namespace:
  11680. description: |-
  11681. The namespace of the Secret resource being referred to.
  11682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11683. maxLength: 63
  11684. minLength: 1
  11685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11686. type: string
  11687. type: object
  11688. required:
  11689. - accessToken
  11690. type: object
  11691. type: object
  11692. baseUri:
  11693. type: string
  11694. required:
  11695. - auth
  11696. type: object
  11697. pulumi:
  11698. description: Pulumi configures this store to sync secrets using the Pulumi provider
  11699. properties:
  11700. accessToken:
  11701. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  11702. properties:
  11703. secretRef:
  11704. description: SecretRef is a reference to a secret containing the Pulumi API token.
  11705. properties:
  11706. key:
  11707. description: |-
  11708. A key in the referenced Secret.
  11709. Some instances of this field may be defaulted, in others it may be required.
  11710. maxLength: 253
  11711. minLength: 1
  11712. pattern: ^[-._a-zA-Z0-9]+$
  11713. type: string
  11714. name:
  11715. description: The name of the Secret resource being referred to.
  11716. maxLength: 253
  11717. minLength: 1
  11718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11719. type: string
  11720. namespace:
  11721. description: |-
  11722. The namespace of the Secret resource being referred to.
  11723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11724. maxLength: 63
  11725. minLength: 1
  11726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11727. type: string
  11728. type: object
  11729. type: object
  11730. apiUrl:
  11731. default: https://api.pulumi.com/api/esc
  11732. description: APIURL is the URL of the Pulumi API.
  11733. type: string
  11734. environment:
  11735. description: |-
  11736. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  11737. dynamically retrieved values from supported providers including all major clouds,
  11738. and other Pulumi ESC environments.
  11739. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  11740. type: string
  11741. organization:
  11742. description: |-
  11743. Organization are a space to collaborate on shared projects and stacks.
  11744. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  11745. type: string
  11746. project:
  11747. description: Project is the name of the Pulumi ESC project the environment belongs to.
  11748. type: string
  11749. required:
  11750. - accessToken
  11751. - environment
  11752. - organization
  11753. - project
  11754. type: object
  11755. scaleway:
  11756. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  11757. properties:
  11758. accessKey:
  11759. description: AccessKey is the non-secret part of the api key.
  11760. properties:
  11761. secretRef:
  11762. description: SecretRef references a key in a secret that will be used as value.
  11763. properties:
  11764. key:
  11765. description: |-
  11766. A key in the referenced Secret.
  11767. Some instances of this field may be defaulted, in others it may be required.
  11768. maxLength: 253
  11769. minLength: 1
  11770. pattern: ^[-._a-zA-Z0-9]+$
  11771. type: string
  11772. name:
  11773. description: The name of the Secret resource being referred to.
  11774. maxLength: 253
  11775. minLength: 1
  11776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11777. type: string
  11778. namespace:
  11779. description: |-
  11780. The namespace of the Secret resource being referred to.
  11781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11782. maxLength: 63
  11783. minLength: 1
  11784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11785. type: string
  11786. type: object
  11787. value:
  11788. description: Value can be specified directly to set a value without using a secret.
  11789. type: string
  11790. type: object
  11791. apiUrl:
  11792. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  11793. type: string
  11794. projectId:
  11795. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  11796. type: string
  11797. region:
  11798. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  11799. type: string
  11800. secretKey:
  11801. description: SecretKey is the non-secret part of the api key.
  11802. properties:
  11803. secretRef:
  11804. description: SecretRef references a key in a secret that will be used as value.
  11805. properties:
  11806. key:
  11807. description: |-
  11808. A key in the referenced Secret.
  11809. Some instances of this field may be defaulted, in others it may be required.
  11810. maxLength: 253
  11811. minLength: 1
  11812. pattern: ^[-._a-zA-Z0-9]+$
  11813. type: string
  11814. name:
  11815. description: The name of the Secret resource being referred to.
  11816. maxLength: 253
  11817. minLength: 1
  11818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11819. type: string
  11820. namespace:
  11821. description: |-
  11822. The namespace of the Secret resource being referred to.
  11823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11824. maxLength: 63
  11825. minLength: 1
  11826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11827. type: string
  11828. type: object
  11829. value:
  11830. description: Value can be specified directly to set a value without using a secret.
  11831. type: string
  11832. type: object
  11833. required:
  11834. - accessKey
  11835. - projectId
  11836. - region
  11837. - secretKey
  11838. type: object
  11839. secretserver:
  11840. description: |-
  11841. SecretServer configures this store to sync secrets using SecretServer provider
  11842. https://docs.delinea.com/online-help/secret-server/start.htm
  11843. properties:
  11844. password:
  11845. description: Password is the secret server account password.
  11846. properties:
  11847. secretRef:
  11848. description: SecretRef references a key in a secret that will be used as value.
  11849. properties:
  11850. key:
  11851. description: |-
  11852. A key in the referenced Secret.
  11853. Some instances of this field may be defaulted, in others it may be required.
  11854. maxLength: 253
  11855. minLength: 1
  11856. pattern: ^[-._a-zA-Z0-9]+$
  11857. type: string
  11858. name:
  11859. description: The name of the Secret resource being referred to.
  11860. maxLength: 253
  11861. minLength: 1
  11862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11863. type: string
  11864. namespace:
  11865. description: |-
  11866. The namespace of the Secret resource being referred to.
  11867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11868. maxLength: 63
  11869. minLength: 1
  11870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11871. type: string
  11872. type: object
  11873. value:
  11874. description: Value can be specified directly to set a value without using a secret.
  11875. type: string
  11876. type: object
  11877. serverURL:
  11878. description: |-
  11879. ServerURL
  11880. URL to your secret server installation
  11881. type: string
  11882. username:
  11883. description: Username is the secret server account username.
  11884. properties:
  11885. secretRef:
  11886. description: SecretRef references a key in a secret that will be used as value.
  11887. properties:
  11888. key:
  11889. description: |-
  11890. A key in the referenced Secret.
  11891. Some instances of this field may be defaulted, in others it may be required.
  11892. maxLength: 253
  11893. minLength: 1
  11894. pattern: ^[-._a-zA-Z0-9]+$
  11895. type: string
  11896. name:
  11897. description: The name of the Secret resource being referred to.
  11898. maxLength: 253
  11899. minLength: 1
  11900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11901. type: string
  11902. namespace:
  11903. description: |-
  11904. The namespace of the Secret resource being referred to.
  11905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11906. maxLength: 63
  11907. minLength: 1
  11908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11909. type: string
  11910. type: object
  11911. value:
  11912. description: Value can be specified directly to set a value without using a secret.
  11913. type: string
  11914. type: object
  11915. required:
  11916. - password
  11917. - serverURL
  11918. - username
  11919. type: object
  11920. senhasegura:
  11921. description: Senhasegura configures this store to sync secrets using senhasegura provider
  11922. properties:
  11923. auth:
  11924. description: Auth defines parameters to authenticate in senhasegura
  11925. properties:
  11926. clientId:
  11927. type: string
  11928. clientSecretSecretRef:
  11929. description: |-
  11930. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11931. In some instances, `key` is a required field.
  11932. properties:
  11933. key:
  11934. description: |-
  11935. A key in the referenced Secret.
  11936. Some instances of this field may be defaulted, in others it may be required.
  11937. maxLength: 253
  11938. minLength: 1
  11939. pattern: ^[-._a-zA-Z0-9]+$
  11940. type: string
  11941. name:
  11942. description: The name of the Secret resource being referred to.
  11943. maxLength: 253
  11944. minLength: 1
  11945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11946. type: string
  11947. namespace:
  11948. description: |-
  11949. The namespace of the Secret resource being referred to.
  11950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11951. maxLength: 63
  11952. minLength: 1
  11953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11954. type: string
  11955. type: object
  11956. required:
  11957. - clientId
  11958. - clientSecretSecretRef
  11959. type: object
  11960. ignoreSslCertificate:
  11961. default: false
  11962. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  11963. type: boolean
  11964. module:
  11965. description: Module defines which senhasegura module should be used to get secrets
  11966. type: string
  11967. url:
  11968. description: URL of senhasegura
  11969. type: string
  11970. required:
  11971. - auth
  11972. - module
  11973. - url
  11974. type: object
  11975. vault:
  11976. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  11977. properties:
  11978. auth:
  11979. description: Auth configures how secret-manager authenticates with the Vault server.
  11980. properties:
  11981. appRole:
  11982. description: |-
  11983. AppRole authenticates with Vault using the App Role auth mechanism,
  11984. with the role and secret stored in a Kubernetes Secret resource.
  11985. properties:
  11986. path:
  11987. default: approle
  11988. description: |-
  11989. Path where the App Role authentication backend is mounted
  11990. in Vault, e.g: "approle"
  11991. type: string
  11992. roleId:
  11993. description: |-
  11994. RoleID configured in the App Role authentication backend when setting
  11995. up the authentication backend in Vault.
  11996. type: string
  11997. roleRef:
  11998. description: |-
  11999. Reference to a key in a Secret that contains the App Role ID used
  12000. to authenticate with Vault.
  12001. The `key` field must be specified and denotes which entry within the Secret
  12002. resource is used as the app role id.
  12003. properties:
  12004. key:
  12005. description: |-
  12006. A key in the referenced Secret.
  12007. Some instances of this field may be defaulted, in others it may be required.
  12008. maxLength: 253
  12009. minLength: 1
  12010. pattern: ^[-._a-zA-Z0-9]+$
  12011. type: string
  12012. name:
  12013. description: The name of the Secret resource being referred to.
  12014. maxLength: 253
  12015. minLength: 1
  12016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12017. type: string
  12018. namespace:
  12019. description: |-
  12020. The namespace of the Secret resource being referred to.
  12021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12022. maxLength: 63
  12023. minLength: 1
  12024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12025. type: string
  12026. type: object
  12027. secretRef:
  12028. description: |-
  12029. Reference to a key in a Secret that contains the App Role secret used
  12030. to authenticate with Vault.
  12031. The `key` field must be specified and denotes which entry within the Secret
  12032. resource is used as the app role secret.
  12033. properties:
  12034. key:
  12035. description: |-
  12036. A key in the referenced Secret.
  12037. Some instances of this field may be defaulted, in others it may be required.
  12038. maxLength: 253
  12039. minLength: 1
  12040. pattern: ^[-._a-zA-Z0-9]+$
  12041. type: string
  12042. name:
  12043. description: The name of the Secret resource being referred to.
  12044. maxLength: 253
  12045. minLength: 1
  12046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12047. type: string
  12048. namespace:
  12049. description: |-
  12050. The namespace of the Secret resource being referred to.
  12051. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12052. maxLength: 63
  12053. minLength: 1
  12054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12055. type: string
  12056. type: object
  12057. required:
  12058. - path
  12059. - secretRef
  12060. type: object
  12061. cert:
  12062. description: |-
  12063. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12064. Cert authentication method
  12065. properties:
  12066. clientCert:
  12067. description: |-
  12068. ClientCert is a certificate to authenticate using the Cert Vault
  12069. authentication method
  12070. properties:
  12071. key:
  12072. description: |-
  12073. A key in the referenced Secret.
  12074. Some instances of this field may be defaulted, in others it may be required.
  12075. maxLength: 253
  12076. minLength: 1
  12077. pattern: ^[-._a-zA-Z0-9]+$
  12078. type: string
  12079. name:
  12080. description: The name of the Secret resource being referred to.
  12081. maxLength: 253
  12082. minLength: 1
  12083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12084. type: string
  12085. namespace:
  12086. description: |-
  12087. The namespace of the Secret resource being referred to.
  12088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12089. maxLength: 63
  12090. minLength: 1
  12091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12092. type: string
  12093. type: object
  12094. secretRef:
  12095. description: |-
  12096. SecretRef to a key in a Secret resource containing client private key to
  12097. authenticate with Vault using the Cert authentication method
  12098. properties:
  12099. key:
  12100. description: |-
  12101. A key in the referenced Secret.
  12102. Some instances of this field may be defaulted, in others it may be required.
  12103. maxLength: 253
  12104. minLength: 1
  12105. pattern: ^[-._a-zA-Z0-9]+$
  12106. type: string
  12107. name:
  12108. description: The name of the Secret resource being referred to.
  12109. maxLength: 253
  12110. minLength: 1
  12111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12112. type: string
  12113. namespace:
  12114. description: |-
  12115. The namespace of the Secret resource being referred to.
  12116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12117. maxLength: 63
  12118. minLength: 1
  12119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12120. type: string
  12121. type: object
  12122. type: object
  12123. iam:
  12124. description: |-
  12125. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12126. AWS IAM authentication method
  12127. properties:
  12128. externalID:
  12129. description: AWS External ID set on assumed IAM roles
  12130. type: string
  12131. jwt:
  12132. description: Specify a service account with IRSA enabled
  12133. properties:
  12134. serviceAccountRef:
  12135. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12136. properties:
  12137. audiences:
  12138. description: |-
  12139. Audience specifies the `aud` claim for the service account token
  12140. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12141. then this audiences will be appended to the list
  12142. items:
  12143. type: string
  12144. type: array
  12145. name:
  12146. description: The name of the ServiceAccount resource being referred to.
  12147. maxLength: 253
  12148. minLength: 1
  12149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12150. type: string
  12151. namespace:
  12152. description: |-
  12153. Namespace of the resource being referred to.
  12154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12155. maxLength: 63
  12156. minLength: 1
  12157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12158. type: string
  12159. required:
  12160. - name
  12161. type: object
  12162. type: object
  12163. path:
  12164. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12165. type: string
  12166. region:
  12167. description: AWS region
  12168. type: string
  12169. role:
  12170. description: This is the AWS role to be assumed before talking to vault
  12171. type: string
  12172. secretRef:
  12173. description: Specify credentials in a Secret object
  12174. properties:
  12175. accessKeyIDSecretRef:
  12176. description: The AccessKeyID is used for authentication
  12177. properties:
  12178. key:
  12179. description: |-
  12180. A key in the referenced Secret.
  12181. Some instances of this field may be defaulted, in others it may be required.
  12182. maxLength: 253
  12183. minLength: 1
  12184. pattern: ^[-._a-zA-Z0-9]+$
  12185. type: string
  12186. name:
  12187. description: The name of the Secret resource being referred to.
  12188. maxLength: 253
  12189. minLength: 1
  12190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12191. type: string
  12192. namespace:
  12193. description: |-
  12194. The namespace of the Secret resource being referred to.
  12195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12196. maxLength: 63
  12197. minLength: 1
  12198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12199. type: string
  12200. type: object
  12201. secretAccessKeySecretRef:
  12202. description: The SecretAccessKey is used for authentication
  12203. properties:
  12204. key:
  12205. description: |-
  12206. A key in the referenced Secret.
  12207. Some instances of this field may be defaulted, in others it may be required.
  12208. maxLength: 253
  12209. minLength: 1
  12210. pattern: ^[-._a-zA-Z0-9]+$
  12211. type: string
  12212. name:
  12213. description: The name of the Secret resource being referred to.
  12214. maxLength: 253
  12215. minLength: 1
  12216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12217. type: string
  12218. namespace:
  12219. description: |-
  12220. The namespace of the Secret resource being referred to.
  12221. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12222. maxLength: 63
  12223. minLength: 1
  12224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12225. type: string
  12226. type: object
  12227. sessionTokenSecretRef:
  12228. description: |-
  12229. The SessionToken used for authentication
  12230. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12231. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12232. properties:
  12233. key:
  12234. description: |-
  12235. A key in the referenced Secret.
  12236. Some instances of this field may be defaulted, in others it may be required.
  12237. maxLength: 253
  12238. minLength: 1
  12239. pattern: ^[-._a-zA-Z0-9]+$
  12240. type: string
  12241. name:
  12242. description: The name of the Secret resource being referred to.
  12243. maxLength: 253
  12244. minLength: 1
  12245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12246. type: string
  12247. namespace:
  12248. description: |-
  12249. The namespace of the Secret resource being referred to.
  12250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12251. maxLength: 63
  12252. minLength: 1
  12253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12254. type: string
  12255. type: object
  12256. type: object
  12257. vaultAwsIamServerID:
  12258. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12259. type: string
  12260. vaultRole:
  12261. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12262. type: string
  12263. required:
  12264. - vaultRole
  12265. type: object
  12266. jwt:
  12267. description: |-
  12268. Jwt authenticates with Vault by passing role and JWT token using the
  12269. JWT/OIDC authentication method
  12270. properties:
  12271. kubernetesServiceAccountToken:
  12272. description: |-
  12273. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12274. a token for with the `TokenRequest` API.
  12275. properties:
  12276. audiences:
  12277. description: |-
  12278. Optional audiences field that will be used to request a temporary Kubernetes service
  12279. account token for the service account referenced by `serviceAccountRef`.
  12280. Defaults to a single audience `vault` it not specified.
  12281. Deprecated: use serviceAccountRef.Audiences instead
  12282. items:
  12283. type: string
  12284. type: array
  12285. expirationSeconds:
  12286. description: |-
  12287. Optional expiration time in seconds that will be used to request a temporary
  12288. Kubernetes service account token for the service account referenced by
  12289. `serviceAccountRef`.
  12290. Deprecated: this will be removed in the future.
  12291. Defaults to 10 minutes.
  12292. format: int64
  12293. type: integer
  12294. serviceAccountRef:
  12295. description: Service account field containing the name of a kubernetes ServiceAccount.
  12296. properties:
  12297. audiences:
  12298. description: |-
  12299. Audience specifies the `aud` claim for the service account token
  12300. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12301. then this audiences will be appended to the list
  12302. items:
  12303. type: string
  12304. type: array
  12305. name:
  12306. description: The name of the ServiceAccount resource being referred to.
  12307. maxLength: 253
  12308. minLength: 1
  12309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12310. type: string
  12311. namespace:
  12312. description: |-
  12313. Namespace of the resource being referred to.
  12314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12315. maxLength: 63
  12316. minLength: 1
  12317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12318. type: string
  12319. required:
  12320. - name
  12321. type: object
  12322. required:
  12323. - serviceAccountRef
  12324. type: object
  12325. path:
  12326. default: jwt
  12327. description: |-
  12328. Path where the JWT authentication backend is mounted
  12329. in Vault, e.g: "jwt"
  12330. type: string
  12331. role:
  12332. description: |-
  12333. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12334. authentication method
  12335. type: string
  12336. secretRef:
  12337. description: |-
  12338. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12339. authenticate with Vault using the JWT/OIDC authentication method.
  12340. properties:
  12341. key:
  12342. description: |-
  12343. A key in the referenced Secret.
  12344. Some instances of this field may be defaulted, in others it may be required.
  12345. maxLength: 253
  12346. minLength: 1
  12347. pattern: ^[-._a-zA-Z0-9]+$
  12348. type: string
  12349. name:
  12350. description: The name of the Secret resource being referred to.
  12351. maxLength: 253
  12352. minLength: 1
  12353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12354. type: string
  12355. namespace:
  12356. description: |-
  12357. The namespace of the Secret resource being referred to.
  12358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12359. maxLength: 63
  12360. minLength: 1
  12361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12362. type: string
  12363. type: object
  12364. required:
  12365. - path
  12366. type: object
  12367. kubernetes:
  12368. description: |-
  12369. Kubernetes authenticates with Vault by passing the ServiceAccount
  12370. token stored in the named Secret resource to the Vault server.
  12371. properties:
  12372. mountPath:
  12373. default: kubernetes
  12374. description: |-
  12375. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12376. "kubernetes"
  12377. type: string
  12378. role:
  12379. description: |-
  12380. A required field containing the Vault Role to assume. A Role binds a
  12381. Kubernetes ServiceAccount with a set of Vault policies.
  12382. type: string
  12383. secretRef:
  12384. description: |-
  12385. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12386. for authenticating with Vault. If a name is specified without a key,
  12387. `token` is the default. If one is not specified, the one bound to
  12388. the controller will be used.
  12389. properties:
  12390. key:
  12391. description: |-
  12392. A key in the referenced Secret.
  12393. Some instances of this field may be defaulted, in others it may be required.
  12394. maxLength: 253
  12395. minLength: 1
  12396. pattern: ^[-._a-zA-Z0-9]+$
  12397. type: string
  12398. name:
  12399. description: The name of the Secret resource being referred to.
  12400. maxLength: 253
  12401. minLength: 1
  12402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12403. type: string
  12404. namespace:
  12405. description: |-
  12406. The namespace of the Secret resource being referred to.
  12407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12408. maxLength: 63
  12409. minLength: 1
  12410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12411. type: string
  12412. type: object
  12413. serviceAccountRef:
  12414. description: |-
  12415. Optional service account field containing the name of a kubernetes ServiceAccount.
  12416. If the service account is specified, the service account secret token JWT will be used
  12417. for authenticating with Vault. If the service account selector is not supplied,
  12418. the secretRef will be used instead.
  12419. properties:
  12420. audiences:
  12421. description: |-
  12422. Audience specifies the `aud` claim for the service account token
  12423. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12424. then this audiences will be appended to the list
  12425. items:
  12426. type: string
  12427. type: array
  12428. name:
  12429. description: The name of the ServiceAccount resource being referred to.
  12430. maxLength: 253
  12431. minLength: 1
  12432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12433. type: string
  12434. namespace:
  12435. description: |-
  12436. Namespace of the resource being referred to.
  12437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12438. maxLength: 63
  12439. minLength: 1
  12440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12441. type: string
  12442. required:
  12443. - name
  12444. type: object
  12445. required:
  12446. - mountPath
  12447. - role
  12448. type: object
  12449. ldap:
  12450. description: |-
  12451. Ldap authenticates with Vault by passing username/password pair using
  12452. the LDAP authentication method
  12453. properties:
  12454. path:
  12455. default: ldap
  12456. description: |-
  12457. Path where the LDAP authentication backend is mounted
  12458. in Vault, e.g: "ldap"
  12459. type: string
  12460. secretRef:
  12461. description: |-
  12462. SecretRef to a key in a Secret resource containing password for the LDAP
  12463. user used to authenticate with Vault using the LDAP authentication
  12464. method
  12465. properties:
  12466. key:
  12467. description: |-
  12468. A key in the referenced Secret.
  12469. Some instances of this field may be defaulted, in others it may be required.
  12470. maxLength: 253
  12471. minLength: 1
  12472. pattern: ^[-._a-zA-Z0-9]+$
  12473. type: string
  12474. name:
  12475. description: The name of the Secret resource being referred to.
  12476. maxLength: 253
  12477. minLength: 1
  12478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12479. type: string
  12480. namespace:
  12481. description: |-
  12482. The namespace of the Secret resource being referred to.
  12483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12484. maxLength: 63
  12485. minLength: 1
  12486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12487. type: string
  12488. type: object
  12489. username:
  12490. description: |-
  12491. Username is an LDAP username used to authenticate using the LDAP Vault
  12492. authentication method
  12493. type: string
  12494. required:
  12495. - path
  12496. - username
  12497. type: object
  12498. namespace:
  12499. description: |-
  12500. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12501. Namespaces is a set of features within Vault Enterprise that allows
  12502. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12503. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12504. This will default to Vault.Namespace field if set, or empty otherwise
  12505. type: string
  12506. tokenSecretRef:
  12507. description: TokenSecretRef authenticates with Vault by presenting a token.
  12508. properties:
  12509. key:
  12510. description: |-
  12511. A key in the referenced Secret.
  12512. Some instances of this field may be defaulted, in others it may be required.
  12513. maxLength: 253
  12514. minLength: 1
  12515. pattern: ^[-._a-zA-Z0-9]+$
  12516. type: string
  12517. name:
  12518. description: The name of the Secret resource being referred to.
  12519. maxLength: 253
  12520. minLength: 1
  12521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12522. type: string
  12523. namespace:
  12524. description: |-
  12525. The namespace of the Secret resource being referred to.
  12526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12527. maxLength: 63
  12528. minLength: 1
  12529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12530. type: string
  12531. type: object
  12532. userPass:
  12533. description: UserPass authenticates with Vault by passing username/password pair
  12534. properties:
  12535. path:
  12536. default: userpass
  12537. description: |-
  12538. Path where the UserPassword authentication backend is mounted
  12539. in Vault, e.g: "userpass"
  12540. type: string
  12541. secretRef:
  12542. description: |-
  12543. SecretRef to a key in a Secret resource containing password for the
  12544. user used to authenticate with Vault using the UserPass authentication
  12545. method
  12546. properties:
  12547. key:
  12548. description: |-
  12549. A key in the referenced Secret.
  12550. Some instances of this field may be defaulted, in others it may be required.
  12551. maxLength: 253
  12552. minLength: 1
  12553. pattern: ^[-._a-zA-Z0-9]+$
  12554. type: string
  12555. name:
  12556. description: The name of the Secret resource being referred to.
  12557. maxLength: 253
  12558. minLength: 1
  12559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12560. type: string
  12561. namespace:
  12562. description: |-
  12563. The namespace of the Secret resource being referred to.
  12564. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12565. maxLength: 63
  12566. minLength: 1
  12567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12568. type: string
  12569. type: object
  12570. username:
  12571. description: |-
  12572. Username is a username used to authenticate using the UserPass Vault
  12573. authentication method
  12574. type: string
  12575. required:
  12576. - path
  12577. - username
  12578. type: object
  12579. type: object
  12580. caBundle:
  12581. description: |-
  12582. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12583. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12584. plain HTTP protocol connection. If not set the system root certificates
  12585. are used to validate the TLS connection.
  12586. format: byte
  12587. type: string
  12588. caProvider:
  12589. description: The provider for the CA bundle to use to validate Vault server certificate.
  12590. properties:
  12591. key:
  12592. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12593. maxLength: 253
  12594. minLength: 1
  12595. pattern: ^[-._a-zA-Z0-9]+$
  12596. type: string
  12597. name:
  12598. description: The name of the object located at the provider type.
  12599. maxLength: 253
  12600. minLength: 1
  12601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12602. type: string
  12603. namespace:
  12604. description: |-
  12605. The namespace the Provider type is in.
  12606. Can only be defined when used in a ClusterSecretStore.
  12607. maxLength: 63
  12608. minLength: 1
  12609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12610. type: string
  12611. type:
  12612. description: The type of provider to use such as "Secret", or "ConfigMap".
  12613. enum:
  12614. - Secret
  12615. - ConfigMap
  12616. type: string
  12617. required:
  12618. - name
  12619. - type
  12620. type: object
  12621. forwardInconsistent:
  12622. description: |-
  12623. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12624. leader instead of simply retrying within a loop. This can increase performance if
  12625. the option is enabled serverside.
  12626. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12627. type: boolean
  12628. headers:
  12629. additionalProperties:
  12630. type: string
  12631. description: Headers to be added in Vault request
  12632. type: object
  12633. namespace:
  12634. description: |-
  12635. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12636. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12637. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12638. type: string
  12639. path:
  12640. description: |-
  12641. Path is the mount path of the Vault KV backend endpoint, e.g:
  12642. "secret". The v2 KV secret engine version specific "/data" path suffix
  12643. for fetching secrets from Vault is optional and will be appended
  12644. if not present in specified path.
  12645. type: string
  12646. readYourWrites:
  12647. description: |-
  12648. ReadYourWrites ensures isolated read-after-write semantics by
  12649. providing discovered cluster replication states in each request.
  12650. More information about eventual consistency in Vault can be found here
  12651. https://www.vaultproject.io/docs/enterprise/consistency
  12652. type: boolean
  12653. server:
  12654. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  12655. type: string
  12656. tls:
  12657. description: |-
  12658. The configuration used for client side related TLS communication, when the Vault server
  12659. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  12660. This parameter is ignored for plain HTTP protocol connection.
  12661. It's worth noting this configuration is different from the "TLS certificates auth method",
  12662. which is available under the `auth.cert` section.
  12663. properties:
  12664. certSecretRef:
  12665. description: |-
  12666. CertSecretRef is a certificate added to the transport layer
  12667. when communicating with the Vault server.
  12668. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  12669. properties:
  12670. key:
  12671. description: |-
  12672. A key in the referenced Secret.
  12673. Some instances of this field may be defaulted, in others it may be required.
  12674. maxLength: 253
  12675. minLength: 1
  12676. pattern: ^[-._a-zA-Z0-9]+$
  12677. type: string
  12678. name:
  12679. description: The name of the Secret resource being referred to.
  12680. maxLength: 253
  12681. minLength: 1
  12682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12683. type: string
  12684. namespace:
  12685. description: |-
  12686. The namespace of the Secret resource being referred to.
  12687. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12688. maxLength: 63
  12689. minLength: 1
  12690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12691. type: string
  12692. type: object
  12693. keySecretRef:
  12694. description: |-
  12695. KeySecretRef to a key in a Secret resource containing client private key
  12696. added to the transport layer when communicating with the Vault server.
  12697. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  12698. properties:
  12699. key:
  12700. description: |-
  12701. A key in the referenced Secret.
  12702. Some instances of this field may be defaulted, in others it may be required.
  12703. maxLength: 253
  12704. minLength: 1
  12705. pattern: ^[-._a-zA-Z0-9]+$
  12706. type: string
  12707. name:
  12708. description: The name of the Secret resource being referred to.
  12709. maxLength: 253
  12710. minLength: 1
  12711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12712. type: string
  12713. namespace:
  12714. description: |-
  12715. The namespace of the Secret resource being referred to.
  12716. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12717. maxLength: 63
  12718. minLength: 1
  12719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12720. type: string
  12721. type: object
  12722. type: object
  12723. version:
  12724. default: v2
  12725. description: |-
  12726. Version is the Vault KV secret engine version. This can be either "v1" or
  12727. "v2". Version defaults to "v2".
  12728. enum:
  12729. - v1
  12730. - v2
  12731. type: string
  12732. required:
  12733. - server
  12734. type: object
  12735. webhook:
  12736. description: Webhook configures this store to sync secrets using a generic templated webhook
  12737. properties:
  12738. auth:
  12739. description: Auth specifies a authorization protocol. Only one protocol may be set.
  12740. maxProperties: 1
  12741. minProperties: 1
  12742. properties:
  12743. ntlm:
  12744. description: NTLMProtocol configures the store to use NTLM for auth
  12745. properties:
  12746. passwordSecret:
  12747. description: |-
  12748. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12749. In some instances, `key` is a required field.
  12750. properties:
  12751. key:
  12752. description: |-
  12753. A key in the referenced Secret.
  12754. Some instances of this field may be defaulted, in others it may be required.
  12755. maxLength: 253
  12756. minLength: 1
  12757. pattern: ^[-._a-zA-Z0-9]+$
  12758. type: string
  12759. name:
  12760. description: The name of the Secret resource being referred to.
  12761. maxLength: 253
  12762. minLength: 1
  12763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12764. type: string
  12765. namespace:
  12766. description: |-
  12767. The namespace of the Secret resource being referred to.
  12768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12769. maxLength: 63
  12770. minLength: 1
  12771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12772. type: string
  12773. type: object
  12774. usernameSecret:
  12775. description: |-
  12776. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12777. In some instances, `key` is a required field.
  12778. properties:
  12779. key:
  12780. description: |-
  12781. A key in the referenced Secret.
  12782. Some instances of this field may be defaulted, in others it may be required.
  12783. maxLength: 253
  12784. minLength: 1
  12785. pattern: ^[-._a-zA-Z0-9]+$
  12786. type: string
  12787. name:
  12788. description: The name of the Secret resource being referred to.
  12789. maxLength: 253
  12790. minLength: 1
  12791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12792. type: string
  12793. namespace:
  12794. description: |-
  12795. The namespace of the Secret resource being referred to.
  12796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12797. maxLength: 63
  12798. minLength: 1
  12799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12800. type: string
  12801. type: object
  12802. required:
  12803. - passwordSecret
  12804. - usernameSecret
  12805. type: object
  12806. type: object
  12807. body:
  12808. description: Body
  12809. type: string
  12810. caBundle:
  12811. description: |-
  12812. PEM encoded CA bundle used to validate webhook server certificate. Only used
  12813. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12814. plain HTTP protocol connection. If not set the system root certificates
  12815. are used to validate the TLS connection.
  12816. format: byte
  12817. type: string
  12818. caProvider:
  12819. description: The provider for the CA bundle to use to validate webhook server certificate.
  12820. properties:
  12821. key:
  12822. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12823. maxLength: 253
  12824. minLength: 1
  12825. pattern: ^[-._a-zA-Z0-9]+$
  12826. type: string
  12827. name:
  12828. description: The name of the object located at the provider type.
  12829. maxLength: 253
  12830. minLength: 1
  12831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12832. type: string
  12833. namespace:
  12834. description: The namespace the Provider type is in.
  12835. maxLength: 63
  12836. minLength: 1
  12837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12838. type: string
  12839. type:
  12840. description: The type of provider to use such as "Secret", or "ConfigMap".
  12841. enum:
  12842. - Secret
  12843. - ConfigMap
  12844. type: string
  12845. required:
  12846. - name
  12847. - type
  12848. type: object
  12849. headers:
  12850. additionalProperties:
  12851. type: string
  12852. description: Headers
  12853. type: object
  12854. method:
  12855. description: Webhook Method
  12856. type: string
  12857. result:
  12858. description: Result formatting
  12859. properties:
  12860. jsonPath:
  12861. description: Json path of return value
  12862. type: string
  12863. type: object
  12864. secrets:
  12865. description: |-
  12866. Secrets to fill in templates
  12867. These secrets will be passed to the templating function as key value pairs under the given name
  12868. items:
  12869. description: WebhookSecret defines a secret to be used in webhook templates.
  12870. properties:
  12871. name:
  12872. description: Name of this secret in templates
  12873. type: string
  12874. secretRef:
  12875. description: Secret ref to fill in credentials
  12876. properties:
  12877. key:
  12878. description: |-
  12879. A key in the referenced Secret.
  12880. Some instances of this field may be defaulted, in others it may be required.
  12881. maxLength: 253
  12882. minLength: 1
  12883. pattern: ^[-._a-zA-Z0-9]+$
  12884. type: string
  12885. name:
  12886. description: The name of the Secret resource being referred to.
  12887. maxLength: 253
  12888. minLength: 1
  12889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12890. type: string
  12891. namespace:
  12892. description: |-
  12893. The namespace of the Secret resource being referred to.
  12894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12895. maxLength: 63
  12896. minLength: 1
  12897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12898. type: string
  12899. type: object
  12900. required:
  12901. - name
  12902. - secretRef
  12903. type: object
  12904. type: array
  12905. timeout:
  12906. description: Timeout
  12907. type: string
  12908. url:
  12909. description: Webhook url to call
  12910. type: string
  12911. required:
  12912. - result
  12913. - url
  12914. type: object
  12915. yandexcertificatemanager:
  12916. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  12917. properties:
  12918. apiEndpoint:
  12919. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  12920. type: string
  12921. auth:
  12922. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  12923. properties:
  12924. authorizedKeySecretRef:
  12925. description: The authorized key used for authentication
  12926. properties:
  12927. key:
  12928. description: |-
  12929. A key in the referenced Secret.
  12930. Some instances of this field may be defaulted, in others it may be required.
  12931. maxLength: 253
  12932. minLength: 1
  12933. pattern: ^[-._a-zA-Z0-9]+$
  12934. type: string
  12935. name:
  12936. description: The name of the Secret resource being referred to.
  12937. maxLength: 253
  12938. minLength: 1
  12939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12940. type: string
  12941. namespace:
  12942. description: |-
  12943. The namespace of the Secret resource being referred to.
  12944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12945. maxLength: 63
  12946. minLength: 1
  12947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12948. type: string
  12949. type: object
  12950. type: object
  12951. caProvider:
  12952. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  12953. properties:
  12954. certSecretRef:
  12955. description: |-
  12956. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12957. In some instances, `key` is a required field.
  12958. properties:
  12959. key:
  12960. description: |-
  12961. A key in the referenced Secret.
  12962. Some instances of this field may be defaulted, in others it may be required.
  12963. maxLength: 253
  12964. minLength: 1
  12965. pattern: ^[-._a-zA-Z0-9]+$
  12966. type: string
  12967. name:
  12968. description: The name of the Secret resource being referred to.
  12969. maxLength: 253
  12970. minLength: 1
  12971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12972. type: string
  12973. namespace:
  12974. description: |-
  12975. The namespace of the Secret resource being referred to.
  12976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12977. maxLength: 63
  12978. minLength: 1
  12979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12980. type: string
  12981. type: object
  12982. type: object
  12983. required:
  12984. - auth
  12985. type: object
  12986. yandexlockbox:
  12987. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  12988. properties:
  12989. apiEndpoint:
  12990. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  12991. type: string
  12992. auth:
  12993. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  12994. properties:
  12995. authorizedKeySecretRef:
  12996. description: The authorized key used for authentication
  12997. properties:
  12998. key:
  12999. description: |-
  13000. A key in the referenced Secret.
  13001. Some instances of this field may be defaulted, in others it may be required.
  13002. maxLength: 253
  13003. minLength: 1
  13004. pattern: ^[-._a-zA-Z0-9]+$
  13005. type: string
  13006. name:
  13007. description: The name of the Secret resource being referred to.
  13008. maxLength: 253
  13009. minLength: 1
  13010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13011. type: string
  13012. namespace:
  13013. description: |-
  13014. The namespace of the Secret resource being referred to.
  13015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13016. maxLength: 63
  13017. minLength: 1
  13018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13019. type: string
  13020. type: object
  13021. type: object
  13022. caProvider:
  13023. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13024. properties:
  13025. certSecretRef:
  13026. description: |-
  13027. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13028. In some instances, `key` is a required field.
  13029. properties:
  13030. key:
  13031. description: |-
  13032. A key in the referenced Secret.
  13033. Some instances of this field may be defaulted, in others it may be required.
  13034. maxLength: 253
  13035. minLength: 1
  13036. pattern: ^[-._a-zA-Z0-9]+$
  13037. type: string
  13038. name:
  13039. description: The name of the Secret resource being referred to.
  13040. maxLength: 253
  13041. minLength: 1
  13042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13043. type: string
  13044. namespace:
  13045. description: |-
  13046. The namespace of the Secret resource being referred to.
  13047. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13048. maxLength: 63
  13049. minLength: 1
  13050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13051. type: string
  13052. type: object
  13053. type: object
  13054. required:
  13055. - auth
  13056. type: object
  13057. type: object
  13058. refreshInterval:
  13059. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13060. type: integer
  13061. retrySettings:
  13062. description: Used to configure HTTP retries on failures.
  13063. properties:
  13064. maxRetries:
  13065. description: MaxRetries is the maximum number of retry attempts.
  13066. format: int32
  13067. type: integer
  13068. retryInterval:
  13069. description: RetryInterval is the interval between retry attempts.
  13070. type: string
  13071. type: object
  13072. required:
  13073. - provider
  13074. type: object
  13075. status:
  13076. description: SecretStoreStatus defines the observed state of the SecretStore.
  13077. properties:
  13078. capabilities:
  13079. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13080. type: string
  13081. conditions:
  13082. items:
  13083. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13084. properties:
  13085. lastTransitionTime:
  13086. format: date-time
  13087. type: string
  13088. message:
  13089. type: string
  13090. reason:
  13091. type: string
  13092. status:
  13093. type: string
  13094. type:
  13095. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13096. type: string
  13097. required:
  13098. - status
  13099. - type
  13100. type: object
  13101. type: array
  13102. type: object
  13103. type: object
  13104. served: false
  13105. storage: false
  13106. subresources:
  13107. status: {}
  13108. ---
  13109. apiVersion: apiextensions.k8s.io/v1
  13110. kind: CustomResourceDefinition
  13111. metadata:
  13112. annotations:
  13113. controller-gen.kubebuilder.io/version: v0.19.0
  13114. labels:
  13115. external-secrets.io/component: controller
  13116. name: externalsecrets.external-secrets.io
  13117. spec:
  13118. group: external-secrets.io
  13119. names:
  13120. categories:
  13121. - external-secrets
  13122. kind: ExternalSecret
  13123. listKind: ExternalSecretList
  13124. plural: externalsecrets
  13125. shortNames:
  13126. - es
  13127. singular: externalsecret
  13128. scope: Namespaced
  13129. versions:
  13130. - additionalPrinterColumns:
  13131. - jsonPath: .spec.secretStoreRef.kind
  13132. name: StoreType
  13133. type: string
  13134. - jsonPath: .spec.secretStoreRef.name
  13135. name: Store
  13136. type: string
  13137. - jsonPath: .spec.refreshInterval
  13138. name: Refresh Interval
  13139. type: string
  13140. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13141. name: Status
  13142. type: string
  13143. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13144. name: Ready
  13145. type: string
  13146. - jsonPath: .status.refreshTime
  13147. name: Last Sync
  13148. type: date
  13149. name: v1
  13150. schema:
  13151. openAPIV3Schema:
  13152. description: |-
  13153. ExternalSecret is the Schema for the external-secrets API.
  13154. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13155. properties:
  13156. apiVersion:
  13157. description: |-
  13158. APIVersion defines the versioned schema of this representation of an object.
  13159. Servers should convert recognized schemas to the latest internal value, and
  13160. may reject unrecognized values.
  13161. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13162. type: string
  13163. kind:
  13164. description: |-
  13165. Kind is a string value representing the REST resource this object represents.
  13166. Servers may infer this from the endpoint the client submits requests to.
  13167. Cannot be updated.
  13168. In CamelCase.
  13169. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13170. type: string
  13171. metadata:
  13172. type: object
  13173. spec:
  13174. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13175. properties:
  13176. data:
  13177. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13178. items:
  13179. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13180. properties:
  13181. remoteRef:
  13182. description: |-
  13183. RemoteRef points to the remote secret and defines
  13184. which secret (version/property/..) to fetch.
  13185. properties:
  13186. conversionStrategy:
  13187. default: Default
  13188. description: Used to define a conversion Strategy
  13189. enum:
  13190. - Default
  13191. - Unicode
  13192. type: string
  13193. decodingStrategy:
  13194. default: None
  13195. description: Used to define a decoding Strategy
  13196. enum:
  13197. - Auto
  13198. - Base64
  13199. - Base64URL
  13200. - None
  13201. type: string
  13202. key:
  13203. description: Key is the key used in the Provider, mandatory
  13204. type: string
  13205. metadataPolicy:
  13206. default: None
  13207. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13208. enum:
  13209. - None
  13210. - Fetch
  13211. type: string
  13212. nullBytePolicy:
  13213. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13214. enum:
  13215. - Ignore
  13216. - Fail
  13217. type: string
  13218. property:
  13219. description: Used to select a specific property of the Provider value (if a map), if supported
  13220. type: string
  13221. version:
  13222. description: Used to select a specific version of the Provider value, if supported
  13223. type: string
  13224. required:
  13225. - key
  13226. type: object
  13227. secretKey:
  13228. description: The key in the Kubernetes Secret to store the value.
  13229. maxLength: 253
  13230. minLength: 1
  13231. pattern: ^[-._a-zA-Z0-9]+$
  13232. type: string
  13233. sourceRef:
  13234. description: |-
  13235. SourceRef allows you to override the source
  13236. from which the value will be pulled.
  13237. maxProperties: 1
  13238. minProperties: 1
  13239. properties:
  13240. generatorRef:
  13241. description: |-
  13242. GeneratorRef points to a generator custom resource.
  13243. Deprecated: The generatorRef is not implemented in .data[].
  13244. this will be removed with v1.
  13245. properties:
  13246. apiVersion:
  13247. default: generators.external-secrets.io/v1alpha1
  13248. description: Specify the apiVersion of the generator resource
  13249. type: string
  13250. kind:
  13251. description: Specify the Kind of the generator resource
  13252. enum:
  13253. - ACRAccessToken
  13254. - BeyondtrustWorkloadCredentialsDynamicSecret
  13255. - ClusterGenerator
  13256. - CloudsmithAccessToken
  13257. - ECRAuthorizationToken
  13258. - Fake
  13259. - GCRAccessToken
  13260. - GithubAccessToken
  13261. - GitlabDeployToken
  13262. - QuayAccessToken
  13263. - Password
  13264. - SSHKey
  13265. - STSSessionToken
  13266. - UUID
  13267. - VaultDynamicSecret
  13268. - Webhook
  13269. - Grafana
  13270. - MFA
  13271. type: string
  13272. name:
  13273. description: Specify the name of the generator resource
  13274. maxLength: 253
  13275. minLength: 1
  13276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13277. type: string
  13278. required:
  13279. - kind
  13280. - name
  13281. type: object
  13282. storeRef:
  13283. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13284. properties:
  13285. kind:
  13286. description: |-
  13287. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13288. Defaults to `SecretStore`
  13289. enum:
  13290. - SecretStore
  13291. - ClusterSecretStore
  13292. type: string
  13293. name:
  13294. description: Name of the SecretStore resource
  13295. maxLength: 253
  13296. minLength: 1
  13297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13298. type: string
  13299. type: object
  13300. type: object
  13301. required:
  13302. - remoteRef
  13303. - secretKey
  13304. type: object
  13305. type: array
  13306. dataFrom:
  13307. description: |-
  13308. DataFrom is used to fetch all properties from a specific Provider data
  13309. If multiple entries are specified, the Secret keys are merged in the specified order
  13310. items:
  13311. description: |-
  13312. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13313. when using DataFrom to fetch multiple values from a Provider.
  13314. properties:
  13315. extract:
  13316. description: |-
  13317. Used to extract multiple key/value pairs from one secret
  13318. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13319. properties:
  13320. conversionStrategy:
  13321. default: Default
  13322. description: Used to define a conversion Strategy
  13323. enum:
  13324. - Default
  13325. - Unicode
  13326. type: string
  13327. decodingStrategy:
  13328. default: None
  13329. description: Used to define a decoding Strategy
  13330. enum:
  13331. - Auto
  13332. - Base64
  13333. - Base64URL
  13334. - None
  13335. type: string
  13336. key:
  13337. description: Key is the key used in the Provider, mandatory
  13338. type: string
  13339. metadataPolicy:
  13340. default: None
  13341. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13342. enum:
  13343. - None
  13344. - Fetch
  13345. type: string
  13346. nullBytePolicy:
  13347. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13348. enum:
  13349. - Ignore
  13350. - Fail
  13351. type: string
  13352. property:
  13353. description: Used to select a specific property of the Provider value (if a map), if supported
  13354. type: string
  13355. version:
  13356. description: Used to select a specific version of the Provider value, if supported
  13357. type: string
  13358. required:
  13359. - key
  13360. type: object
  13361. find:
  13362. description: |-
  13363. Used to find secrets based on tags or regular expressions
  13364. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13365. properties:
  13366. conversionStrategy:
  13367. default: Default
  13368. description: Used to define a conversion Strategy
  13369. enum:
  13370. - Default
  13371. - Unicode
  13372. type: string
  13373. decodingStrategy:
  13374. default: None
  13375. description: Used to define a decoding Strategy
  13376. enum:
  13377. - Auto
  13378. - Base64
  13379. - Base64URL
  13380. - None
  13381. type: string
  13382. name:
  13383. description: Finds secrets based on the name.
  13384. properties:
  13385. regexp:
  13386. description: Finds secrets base
  13387. type: string
  13388. type: object
  13389. nullBytePolicy:
  13390. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13391. enum:
  13392. - Ignore
  13393. - Fail
  13394. type: string
  13395. path:
  13396. description: A root path to start the find operations.
  13397. type: string
  13398. tags:
  13399. additionalProperties:
  13400. type: string
  13401. description: Find secrets based on tags.
  13402. type: object
  13403. type: object
  13404. rewrite:
  13405. description: |-
  13406. Used to rewrite secret Keys after getting them from the secret Provider
  13407. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13408. items:
  13409. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13410. maxProperties: 1
  13411. minProperties: 1
  13412. properties:
  13413. merge:
  13414. description: |-
  13415. Used to merge key/values in one single Secret
  13416. The resulting key will contain all values from the specified secrets
  13417. properties:
  13418. conflictPolicy:
  13419. default: Error
  13420. description: Used to define the policy to use in conflict resolution.
  13421. enum:
  13422. - Ignore
  13423. - Error
  13424. type: string
  13425. into:
  13426. default: ""
  13427. description: |-
  13428. Used to define the target key of the merge operation.
  13429. Required if strategy is JSON. Ignored otherwise.
  13430. type: string
  13431. priority:
  13432. description: Used to define key priority in conflict resolution.
  13433. items:
  13434. type: string
  13435. type: array
  13436. priorityPolicy:
  13437. default: Strict
  13438. description: Used to define the policy when a key in the priority list does not exist in the input.
  13439. enum:
  13440. - IgnoreNotFound
  13441. - Strict
  13442. type: string
  13443. strategy:
  13444. default: Extract
  13445. description: Used to define the strategy to use in the merge operation.
  13446. enum:
  13447. - Extract
  13448. - JSON
  13449. type: string
  13450. type: object
  13451. regexp:
  13452. description: |-
  13453. Used to rewrite with regular expressions.
  13454. The resulting key will be the output of a regexp.ReplaceAll operation.
  13455. properties:
  13456. source:
  13457. description: Used to define the regular expression of a re.Compiler.
  13458. type: string
  13459. target:
  13460. description: Used to define the target pattern of a ReplaceAll operation.
  13461. type: string
  13462. required:
  13463. - source
  13464. - target
  13465. type: object
  13466. transform:
  13467. description: |-
  13468. Used to apply string transformation on the secrets.
  13469. The resulting key will be the output of the template applied by the operation.
  13470. properties:
  13471. template:
  13472. description: |-
  13473. Used to define the template to apply on the secret name.
  13474. `.value ` will specify the secret name in the template.
  13475. type: string
  13476. required:
  13477. - template
  13478. type: object
  13479. type: object
  13480. type: array
  13481. sourceRef:
  13482. description: |-
  13483. SourceRef points to a store or generator
  13484. which contains secret values ready to use.
  13485. Use this in combination with Extract or Find pull values out of
  13486. a specific SecretStore.
  13487. When sourceRef points to a generator Extract or Find is not supported.
  13488. The generator returns a static map of values
  13489. maxProperties: 1
  13490. minProperties: 1
  13491. properties:
  13492. generatorRef:
  13493. description: GeneratorRef points to a generator custom resource.
  13494. properties:
  13495. apiVersion:
  13496. default: generators.external-secrets.io/v1alpha1
  13497. description: Specify the apiVersion of the generator resource
  13498. type: string
  13499. kind:
  13500. description: Specify the Kind of the generator resource
  13501. enum:
  13502. - ACRAccessToken
  13503. - BeyondtrustWorkloadCredentialsDynamicSecret
  13504. - ClusterGenerator
  13505. - CloudsmithAccessToken
  13506. - ECRAuthorizationToken
  13507. - Fake
  13508. - GCRAccessToken
  13509. - GithubAccessToken
  13510. - GitlabDeployToken
  13511. - QuayAccessToken
  13512. - Password
  13513. - SSHKey
  13514. - STSSessionToken
  13515. - UUID
  13516. - VaultDynamicSecret
  13517. - Webhook
  13518. - Grafana
  13519. - MFA
  13520. type: string
  13521. name:
  13522. description: Specify the name of the generator resource
  13523. maxLength: 253
  13524. minLength: 1
  13525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13526. type: string
  13527. required:
  13528. - kind
  13529. - name
  13530. type: object
  13531. storeRef:
  13532. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13533. properties:
  13534. kind:
  13535. description: |-
  13536. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13537. Defaults to `SecretStore`
  13538. enum:
  13539. - SecretStore
  13540. - ClusterSecretStore
  13541. type: string
  13542. name:
  13543. description: Name of the SecretStore resource
  13544. maxLength: 253
  13545. minLength: 1
  13546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13547. type: string
  13548. type: object
  13549. type: object
  13550. type: object
  13551. type: array
  13552. refreshInterval:
  13553. default: 1h0m0s
  13554. description: |-
  13555. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13556. specified as Golang Duration strings.
  13557. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13558. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13559. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13560. type: string
  13561. refreshPolicy:
  13562. description: |-
  13563. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13564. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13565. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13566. No periodic updates occur if refreshInterval is 0.
  13567. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13568. enum:
  13569. - CreatedOnce
  13570. - Periodic
  13571. - OnChange
  13572. type: string
  13573. secretStoreRef:
  13574. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13575. properties:
  13576. kind:
  13577. description: |-
  13578. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13579. Defaults to `SecretStore`
  13580. enum:
  13581. - SecretStore
  13582. - ClusterSecretStore
  13583. type: string
  13584. name:
  13585. description: Name of the SecretStore resource
  13586. maxLength: 253
  13587. minLength: 1
  13588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13589. type: string
  13590. type: object
  13591. syncWindows:
  13592. description: |-
  13593. SyncWindows optionally restricts when periodic refreshes may occur.
  13594. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13595. properties:
  13596. kind:
  13597. description: |-
  13598. Kind applies to every window in the list.
  13599. "allow" -- syncs are permitted only while at least one window is active;
  13600. all other times are blocked.
  13601. "deny" -- syncs are blocked while any window is active;
  13602. all other times are permitted.
  13603. enum:
  13604. - allow
  13605. - deny
  13606. type: string
  13607. windows:
  13608. description: Windows is the list of schedule+duration pairs.
  13609. items:
  13610. description: |-
  13611. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13612. within a SyncWindows block.
  13613. properties:
  13614. duration:
  13615. description: |-
  13616. Duration specifies how long the window stays open after each Schedule
  13617. firing. Example: "8h".
  13618. type: string
  13619. schedule:
  13620. description: |-
  13621. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13622. named shorthand such as @daily or @every 1h. It marks the start time of
  13623. each window occurrence.
  13624. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13625. minLength: 1
  13626. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13627. type: string
  13628. required:
  13629. - duration
  13630. - schedule
  13631. type: object
  13632. minItems: 1
  13633. type: array
  13634. required:
  13635. - kind
  13636. - windows
  13637. type: object
  13638. target:
  13639. default:
  13640. creationPolicy: Owner
  13641. deletionPolicy: Retain
  13642. description: |-
  13643. ExternalSecretTarget defines the Kubernetes Secret to be created,
  13644. there can be only one target per ExternalSecret.
  13645. properties:
  13646. creationPolicy:
  13647. default: Owner
  13648. description: |-
  13649. CreationPolicy defines rules on how to create the resulting Secret.
  13650. Defaults to "Owner"
  13651. enum:
  13652. - Owner
  13653. - Orphan
  13654. - Merge
  13655. - None
  13656. type: string
  13657. deletionPolicy:
  13658. default: Retain
  13659. description: |-
  13660. DeletionPolicy defines rules on how to delete the resulting Secret.
  13661. Defaults to "Retain"
  13662. enum:
  13663. - Delete
  13664. - Merge
  13665. - Retain
  13666. type: string
  13667. immutable:
  13668. description: Immutable defines if the final secret will be immutable
  13669. type: boolean
  13670. manifest:
  13671. description: |-
  13672. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  13673. When specified, ExternalSecret will create the resource type defined here
  13674. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  13675. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  13676. properties:
  13677. apiVersion:
  13678. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  13679. minLength: 1
  13680. type: string
  13681. kind:
  13682. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  13683. minLength: 1
  13684. type: string
  13685. required:
  13686. - apiVersion
  13687. - kind
  13688. type: object
  13689. name:
  13690. description: |-
  13691. The name of the Secret resource to be managed.
  13692. Defaults to the .metadata.name of the ExternalSecret resource
  13693. maxLength: 253
  13694. minLength: 1
  13695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13696. type: string
  13697. template:
  13698. description: Template defines a blueprint for the created Secret resource.
  13699. properties:
  13700. data:
  13701. additionalProperties:
  13702. type: string
  13703. type: object
  13704. engineVersion:
  13705. default: v2
  13706. description: |-
  13707. EngineVersion specifies the template engine version
  13708. that should be used to compile/execute the
  13709. template specified in .data and .templateFrom[].
  13710. enum:
  13711. - v2
  13712. type: string
  13713. mergePolicy:
  13714. default: Replace
  13715. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  13716. enum:
  13717. - Replace
  13718. - Merge
  13719. type: string
  13720. metadata:
  13721. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  13722. properties:
  13723. annotations:
  13724. additionalProperties:
  13725. type: string
  13726. type: object
  13727. finalizers:
  13728. items:
  13729. type: string
  13730. type: array
  13731. labels:
  13732. additionalProperties:
  13733. type: string
  13734. type: object
  13735. type: object
  13736. templateFrom:
  13737. items:
  13738. description: |-
  13739. TemplateFrom specifies a source for templates.
  13740. Each item in the list can either reference a ConfigMap or a Secret resource.
  13741. properties:
  13742. configMap:
  13743. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  13744. properties:
  13745. items:
  13746. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  13747. items:
  13748. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  13749. properties:
  13750. key:
  13751. description: A key in the ConfigMap/Secret
  13752. maxLength: 253
  13753. minLength: 1
  13754. pattern: ^[-._a-zA-Z0-9]+$
  13755. type: string
  13756. templateAs:
  13757. default: Values
  13758. description: TemplateScope specifies how the template keys should be interpreted.
  13759. enum:
  13760. - Values
  13761. - KeysAndValues
  13762. type: string
  13763. required:
  13764. - key
  13765. type: object
  13766. type: array
  13767. name:
  13768. description: The name of the ConfigMap/Secret resource
  13769. maxLength: 253
  13770. minLength: 1
  13771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13772. type: string
  13773. required:
  13774. - items
  13775. - name
  13776. type: object
  13777. literal:
  13778. type: string
  13779. secret:
  13780. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  13781. properties:
  13782. items:
  13783. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  13784. items:
  13785. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  13786. properties:
  13787. key:
  13788. description: A key in the ConfigMap/Secret
  13789. maxLength: 253
  13790. minLength: 1
  13791. pattern: ^[-._a-zA-Z0-9]+$
  13792. type: string
  13793. templateAs:
  13794. default: Values
  13795. description: TemplateScope specifies how the template keys should be interpreted.
  13796. enum:
  13797. - Values
  13798. - KeysAndValues
  13799. type: string
  13800. required:
  13801. - key
  13802. type: object
  13803. type: array
  13804. name:
  13805. description: The name of the ConfigMap/Secret resource
  13806. maxLength: 253
  13807. minLength: 1
  13808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13809. type: string
  13810. required:
  13811. - items
  13812. - name
  13813. type: object
  13814. target:
  13815. default: Data
  13816. description: |-
  13817. Target specifies where to place the template result.
  13818. For Secret resources, common values are: "Data", "Annotations", "Labels".
  13819. For custom resources (when spec.target.manifest is set), this supports
  13820. nested paths like "spec.database.config" or "data".
  13821. type: string
  13822. valuesDecodingStrategy:
  13823. default: None
  13824. description: Used to define a decoding Strategy for the rendered template values.
  13825. enum:
  13826. - Auto
  13827. - Base64
  13828. - Base64URL
  13829. - None
  13830. type: string
  13831. type: object
  13832. type: array
  13833. type:
  13834. type: string
  13835. type: object
  13836. type: object
  13837. type: object
  13838. status:
  13839. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  13840. properties:
  13841. binding:
  13842. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  13843. properties:
  13844. name:
  13845. default: ""
  13846. description: |-
  13847. Name of the referent.
  13848. This field is effectively required, but due to backwards compatibility is
  13849. allowed to be empty. Instances of this type with an empty value here are
  13850. almost certainly wrong.
  13851. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  13852. type: string
  13853. type: object
  13854. x-kubernetes-map-type: atomic
  13855. conditions:
  13856. items:
  13857. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  13858. properties:
  13859. lastTransitionTime:
  13860. format: date-time
  13861. type: string
  13862. message:
  13863. type: string
  13864. reason:
  13865. type: string
  13866. status:
  13867. type: string
  13868. type:
  13869. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  13870. enum:
  13871. - Ready
  13872. - Deleted
  13873. type: string
  13874. required:
  13875. - status
  13876. - type
  13877. type: object
  13878. type: array
  13879. refreshTime:
  13880. description: |-
  13881. refreshTime is the time and date the external secret was fetched and
  13882. the target secret updated
  13883. format: date-time
  13884. nullable: true
  13885. type: string
  13886. syncedResourceVersion:
  13887. description: SyncedResourceVersion keeps track of the last synced version
  13888. type: string
  13889. type: object
  13890. type: object
  13891. selectableFields:
  13892. - jsonPath: .spec.secretStoreRef.name
  13893. - jsonPath: .spec.secretStoreRef.kind
  13894. - jsonPath: .spec.target.name
  13895. - jsonPath: .spec.refreshInterval
  13896. served: true
  13897. storage: true
  13898. subresources:
  13899. status: {}
  13900. - additionalPrinterColumns:
  13901. - jsonPath: .spec.secretStoreRef.kind
  13902. name: StoreType
  13903. type: string
  13904. - jsonPath: .spec.secretStoreRef.name
  13905. name: Store
  13906. type: string
  13907. - jsonPath: .spec.refreshInterval
  13908. name: Refresh Interval
  13909. type: string
  13910. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13911. name: Status
  13912. type: string
  13913. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13914. name: Ready
  13915. type: string
  13916. - jsonPath: .status.refreshTime
  13917. name: Last Sync
  13918. type: date
  13919. deprecated: true
  13920. name: v1beta1
  13921. schema:
  13922. openAPIV3Schema:
  13923. description: ExternalSecret is the schema for the external-secrets API.
  13924. properties:
  13925. apiVersion:
  13926. description: |-
  13927. APIVersion defines the versioned schema of this representation of an object.
  13928. Servers should convert recognized schemas to the latest internal value, and
  13929. may reject unrecognized values.
  13930. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13931. type: string
  13932. kind:
  13933. description: |-
  13934. Kind is a string value representing the REST resource this object represents.
  13935. Servers may infer this from the endpoint the client submits requests to.
  13936. Cannot be updated.
  13937. In CamelCase.
  13938. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13939. type: string
  13940. metadata:
  13941. type: object
  13942. spec:
  13943. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13944. properties:
  13945. data:
  13946. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13947. items:
  13948. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13949. properties:
  13950. remoteRef:
  13951. description: |-
  13952. RemoteRef points to the remote secret and defines
  13953. which secret (version/property/..) to fetch.
  13954. properties:
  13955. conversionStrategy:
  13956. default: Default
  13957. description: Used to define a conversion Strategy
  13958. enum:
  13959. - Default
  13960. - Unicode
  13961. type: string
  13962. decodingStrategy:
  13963. default: None
  13964. description: Used to define a decoding Strategy
  13965. enum:
  13966. - Auto
  13967. - Base64
  13968. - Base64URL
  13969. - None
  13970. type: string
  13971. key:
  13972. description: Key is the key used in the Provider, mandatory
  13973. type: string
  13974. metadataPolicy:
  13975. default: None
  13976. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13977. enum:
  13978. - None
  13979. - Fetch
  13980. type: string
  13981. property:
  13982. description: Used to select a specific property of the Provider value (if a map), if supported
  13983. type: string
  13984. version:
  13985. description: Used to select a specific version of the Provider value, if supported
  13986. type: string
  13987. required:
  13988. - key
  13989. type: object
  13990. secretKey:
  13991. description: The key in the Kubernetes Secret to store the value.
  13992. maxLength: 253
  13993. minLength: 1
  13994. pattern: ^[-._a-zA-Z0-9]+$
  13995. type: string
  13996. sourceRef:
  13997. description: |-
  13998. SourceRef allows you to override the source
  13999. from which the value will be pulled.
  14000. maxProperties: 1
  14001. minProperties: 1
  14002. properties:
  14003. generatorRef:
  14004. description: |-
  14005. GeneratorRef points to a generator custom resource.
  14006. Deprecated: The generatorRef is not implemented in .data[].
  14007. this will be removed with v1.
  14008. properties:
  14009. apiVersion:
  14010. default: generators.external-secrets.io/v1alpha1
  14011. description: Specify the apiVersion of the generator resource
  14012. type: string
  14013. kind:
  14014. description: Specify the Kind of the generator resource
  14015. enum:
  14016. - ACRAccessToken
  14017. - ClusterGenerator
  14018. - ECRAuthorizationToken
  14019. - Fake
  14020. - GCRAccessToken
  14021. - GithubAccessToken
  14022. - QuayAccessToken
  14023. - Password
  14024. - SSHKey
  14025. - STSSessionToken
  14026. - UUID
  14027. - VaultDynamicSecret
  14028. - Webhook
  14029. - Grafana
  14030. type: string
  14031. name:
  14032. description: Specify the name of the generator resource
  14033. maxLength: 253
  14034. minLength: 1
  14035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14036. type: string
  14037. required:
  14038. - kind
  14039. - name
  14040. type: object
  14041. storeRef:
  14042. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14043. properties:
  14044. kind:
  14045. description: |-
  14046. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14047. Defaults to `SecretStore`
  14048. enum:
  14049. - SecretStore
  14050. - ClusterSecretStore
  14051. type: string
  14052. name:
  14053. description: Name of the SecretStore resource
  14054. maxLength: 253
  14055. minLength: 1
  14056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14057. type: string
  14058. type: object
  14059. type: object
  14060. required:
  14061. - remoteRef
  14062. - secretKey
  14063. type: object
  14064. type: array
  14065. dataFrom:
  14066. description: |-
  14067. DataFrom is used to fetch all properties from a specific Provider data
  14068. If multiple entries are specified, the Secret keys are merged in the specified order
  14069. items:
  14070. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14071. properties:
  14072. extract:
  14073. description: |-
  14074. Used to extract multiple key/value pairs from one secret
  14075. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14076. properties:
  14077. conversionStrategy:
  14078. default: Default
  14079. description: Used to define a conversion Strategy
  14080. enum:
  14081. - Default
  14082. - Unicode
  14083. type: string
  14084. decodingStrategy:
  14085. default: None
  14086. description: Used to define a decoding Strategy
  14087. enum:
  14088. - Auto
  14089. - Base64
  14090. - Base64URL
  14091. - None
  14092. type: string
  14093. key:
  14094. description: Key is the key used in the Provider, mandatory
  14095. type: string
  14096. metadataPolicy:
  14097. default: None
  14098. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14099. enum:
  14100. - None
  14101. - Fetch
  14102. type: string
  14103. property:
  14104. description: Used to select a specific property of the Provider value (if a map), if supported
  14105. type: string
  14106. version:
  14107. description: Used to select a specific version of the Provider value, if supported
  14108. type: string
  14109. required:
  14110. - key
  14111. type: object
  14112. find:
  14113. description: |-
  14114. Used to find secrets based on tags or regular expressions
  14115. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14116. properties:
  14117. conversionStrategy:
  14118. default: Default
  14119. description: Used to define a conversion Strategy
  14120. enum:
  14121. - Default
  14122. - Unicode
  14123. type: string
  14124. decodingStrategy:
  14125. default: None
  14126. description: Used to define a decoding Strategy
  14127. enum:
  14128. - Auto
  14129. - Base64
  14130. - Base64URL
  14131. - None
  14132. type: string
  14133. name:
  14134. description: Finds secrets based on the name.
  14135. properties:
  14136. regexp:
  14137. description: Finds secrets base
  14138. type: string
  14139. type: object
  14140. path:
  14141. description: A root path to start the find operations.
  14142. type: string
  14143. tags:
  14144. additionalProperties:
  14145. type: string
  14146. description: Find secrets based on tags.
  14147. type: object
  14148. type: object
  14149. rewrite:
  14150. description: |-
  14151. Used to rewrite secret Keys after getting them from the secret Provider
  14152. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14153. items:
  14154. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14155. maxProperties: 1
  14156. minProperties: 1
  14157. properties:
  14158. regexp:
  14159. description: |-
  14160. Used to rewrite with regular expressions.
  14161. The resulting key will be the output of a regexp.ReplaceAll operation.
  14162. properties:
  14163. source:
  14164. description: Used to define the regular expression of a re.Compiler.
  14165. type: string
  14166. target:
  14167. description: Used to define the target pattern of a ReplaceAll operation.
  14168. type: string
  14169. required:
  14170. - source
  14171. - target
  14172. type: object
  14173. transform:
  14174. description: |-
  14175. Used to apply string transformation on the secrets.
  14176. The resulting key will be the output of the template applied by the operation.
  14177. properties:
  14178. template:
  14179. description: |-
  14180. Used to define the template to apply on the secret name.
  14181. `.value ` will specify the secret name in the template.
  14182. type: string
  14183. required:
  14184. - template
  14185. type: object
  14186. type: object
  14187. type: array
  14188. sourceRef:
  14189. description: |-
  14190. SourceRef points to a store or generator
  14191. which contains secret values ready to use.
  14192. Use this in combination with Extract or Find pull values out of
  14193. a specific SecretStore.
  14194. When sourceRef points to a generator Extract or Find is not supported.
  14195. The generator returns a static map of values
  14196. maxProperties: 1
  14197. minProperties: 1
  14198. properties:
  14199. generatorRef:
  14200. description: GeneratorRef points to a generator custom resource.
  14201. properties:
  14202. apiVersion:
  14203. default: generators.external-secrets.io/v1alpha1
  14204. description: Specify the apiVersion of the generator resource
  14205. type: string
  14206. kind:
  14207. description: Specify the Kind of the generator resource
  14208. enum:
  14209. - ACRAccessToken
  14210. - ClusterGenerator
  14211. - ECRAuthorizationToken
  14212. - Fake
  14213. - GCRAccessToken
  14214. - GithubAccessToken
  14215. - QuayAccessToken
  14216. - Password
  14217. - SSHKey
  14218. - STSSessionToken
  14219. - UUID
  14220. - VaultDynamicSecret
  14221. - Webhook
  14222. - Grafana
  14223. type: string
  14224. name:
  14225. description: Specify the name of the generator resource
  14226. maxLength: 253
  14227. minLength: 1
  14228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14229. type: string
  14230. required:
  14231. - kind
  14232. - name
  14233. type: object
  14234. storeRef:
  14235. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14236. properties:
  14237. kind:
  14238. description: |-
  14239. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14240. Defaults to `SecretStore`
  14241. enum:
  14242. - SecretStore
  14243. - ClusterSecretStore
  14244. type: string
  14245. name:
  14246. description: Name of the SecretStore resource
  14247. maxLength: 253
  14248. minLength: 1
  14249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14250. type: string
  14251. type: object
  14252. type: object
  14253. type: object
  14254. type: array
  14255. refreshInterval:
  14256. default: 1h0m0s
  14257. description: |-
  14258. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14259. specified as Golang Duration strings.
  14260. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14261. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14262. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14263. type: string
  14264. refreshPolicy:
  14265. description: |-
  14266. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14267. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14268. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14269. No periodic updates occur if refreshInterval is 0.
  14270. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14271. enum:
  14272. - CreatedOnce
  14273. - Periodic
  14274. - OnChange
  14275. type: string
  14276. secretStoreRef:
  14277. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14278. properties:
  14279. kind:
  14280. description: |-
  14281. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14282. Defaults to `SecretStore`
  14283. enum:
  14284. - SecretStore
  14285. - ClusterSecretStore
  14286. type: string
  14287. name:
  14288. description: Name of the SecretStore resource
  14289. maxLength: 253
  14290. minLength: 1
  14291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14292. type: string
  14293. type: object
  14294. target:
  14295. default:
  14296. creationPolicy: Owner
  14297. deletionPolicy: Retain
  14298. description: |-
  14299. ExternalSecretTarget defines the Kubernetes Secret to be created
  14300. There can be only one target per ExternalSecret.
  14301. properties:
  14302. creationPolicy:
  14303. default: Owner
  14304. description: |-
  14305. CreationPolicy defines rules on how to create the resulting Secret.
  14306. Defaults to "Owner"
  14307. enum:
  14308. - Owner
  14309. - Orphan
  14310. - Merge
  14311. - None
  14312. type: string
  14313. deletionPolicy:
  14314. default: Retain
  14315. description: |-
  14316. DeletionPolicy defines rules on how to delete the resulting Secret.
  14317. Defaults to "Retain"
  14318. enum:
  14319. - Delete
  14320. - Merge
  14321. - Retain
  14322. type: string
  14323. immutable:
  14324. description: Immutable defines if the final secret will be immutable
  14325. type: boolean
  14326. name:
  14327. description: |-
  14328. The name of the Secret resource to be managed.
  14329. Defaults to the .metadata.name of the ExternalSecret resource
  14330. maxLength: 253
  14331. minLength: 1
  14332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14333. type: string
  14334. template:
  14335. description: Template defines a blueprint for the created Secret resource.
  14336. properties:
  14337. data:
  14338. additionalProperties:
  14339. type: string
  14340. type: object
  14341. engineVersion:
  14342. default: v2
  14343. description: |-
  14344. EngineVersion specifies the template engine version
  14345. that should be used to compile/execute the
  14346. template specified in .data and .templateFrom[].
  14347. enum:
  14348. - v2
  14349. type: string
  14350. mergePolicy:
  14351. default: Replace
  14352. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14353. enum:
  14354. - Replace
  14355. - Merge
  14356. type: string
  14357. metadata:
  14358. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14359. properties:
  14360. annotations:
  14361. additionalProperties:
  14362. type: string
  14363. type: object
  14364. labels:
  14365. additionalProperties:
  14366. type: string
  14367. type: object
  14368. type: object
  14369. templateFrom:
  14370. items:
  14371. description: TemplateFrom defines a source for template data.
  14372. properties:
  14373. configMap:
  14374. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14375. properties:
  14376. items:
  14377. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14378. items:
  14379. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14380. properties:
  14381. key:
  14382. description: A key in the ConfigMap/Secret
  14383. maxLength: 253
  14384. minLength: 1
  14385. pattern: ^[-._a-zA-Z0-9]+$
  14386. type: string
  14387. templateAs:
  14388. default: Values
  14389. description: TemplateScope defines the scope of the template when processing template data.
  14390. enum:
  14391. - Values
  14392. - KeysAndValues
  14393. type: string
  14394. required:
  14395. - key
  14396. type: object
  14397. type: array
  14398. name:
  14399. description: The name of the ConfigMap/Secret resource
  14400. maxLength: 253
  14401. minLength: 1
  14402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14403. type: string
  14404. required:
  14405. - items
  14406. - name
  14407. type: object
  14408. literal:
  14409. type: string
  14410. secret:
  14411. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14412. properties:
  14413. items:
  14414. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14415. items:
  14416. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14417. properties:
  14418. key:
  14419. description: A key in the ConfigMap/Secret
  14420. maxLength: 253
  14421. minLength: 1
  14422. pattern: ^[-._a-zA-Z0-9]+$
  14423. type: string
  14424. templateAs:
  14425. default: Values
  14426. description: TemplateScope defines the scope of the template when processing template data.
  14427. enum:
  14428. - Values
  14429. - KeysAndValues
  14430. type: string
  14431. required:
  14432. - key
  14433. type: object
  14434. type: array
  14435. name:
  14436. description: The name of the ConfigMap/Secret resource
  14437. maxLength: 253
  14438. minLength: 1
  14439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14440. type: string
  14441. required:
  14442. - items
  14443. - name
  14444. type: object
  14445. target:
  14446. default: Data
  14447. description: TemplateTarget defines the target field where the template result will be stored.
  14448. enum:
  14449. - Data
  14450. - Annotations
  14451. - Labels
  14452. type: string
  14453. type: object
  14454. type: array
  14455. type:
  14456. type: string
  14457. type: object
  14458. type: object
  14459. type: object
  14460. status:
  14461. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14462. properties:
  14463. binding:
  14464. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14465. properties:
  14466. name:
  14467. default: ""
  14468. description: |-
  14469. Name of the referent.
  14470. This field is effectively required, but due to backwards compatibility is
  14471. allowed to be empty. Instances of this type with an empty value here are
  14472. almost certainly wrong.
  14473. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14474. type: string
  14475. type: object
  14476. x-kubernetes-map-type: atomic
  14477. conditions:
  14478. items:
  14479. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14480. properties:
  14481. lastTransitionTime:
  14482. format: date-time
  14483. type: string
  14484. message:
  14485. type: string
  14486. reason:
  14487. type: string
  14488. status:
  14489. type: string
  14490. type:
  14491. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14492. type: string
  14493. required:
  14494. - status
  14495. - type
  14496. type: object
  14497. type: array
  14498. refreshTime:
  14499. description: |-
  14500. refreshTime is the time and date the external secret was fetched and
  14501. the target secret updated
  14502. format: date-time
  14503. nullable: true
  14504. type: string
  14505. syncedResourceVersion:
  14506. description: SyncedResourceVersion keeps track of the last synced version
  14507. type: string
  14508. type: object
  14509. type: object
  14510. served: false
  14511. storage: false
  14512. subresources:
  14513. status: {}
  14514. ---
  14515. apiVersion: apiextensions.k8s.io/v1
  14516. kind: CustomResourceDefinition
  14517. metadata:
  14518. annotations:
  14519. controller-gen.kubebuilder.io/version: v0.19.0
  14520. labels:
  14521. external-secrets.io/component: controller
  14522. name: pushsecrets.external-secrets.io
  14523. spec:
  14524. group: external-secrets.io
  14525. names:
  14526. categories:
  14527. - external-secrets
  14528. kind: PushSecret
  14529. listKind: PushSecretList
  14530. plural: pushsecrets
  14531. shortNames:
  14532. - ps
  14533. singular: pushsecret
  14534. scope: Namespaced
  14535. versions:
  14536. - additionalPrinterColumns:
  14537. - jsonPath: .metadata.creationTimestamp
  14538. name: AGE
  14539. type: date
  14540. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14541. name: Status
  14542. type: string
  14543. - jsonPath: .status.refreshTime
  14544. name: Last Sync
  14545. type: date
  14546. name: v1alpha1
  14547. schema:
  14548. openAPIV3Schema:
  14549. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14550. properties:
  14551. apiVersion:
  14552. description: |-
  14553. APIVersion defines the versioned schema of this representation of an object.
  14554. Servers should convert recognized schemas to the latest internal value, and
  14555. may reject unrecognized values.
  14556. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14557. type: string
  14558. kind:
  14559. description: |-
  14560. Kind is a string value representing the REST resource this object represents.
  14561. Servers may infer this from the endpoint the client submits requests to.
  14562. Cannot be updated.
  14563. In CamelCase.
  14564. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14565. type: string
  14566. metadata:
  14567. type: object
  14568. spec:
  14569. description: PushSecretSpec configures the behavior of the PushSecret.
  14570. properties:
  14571. data:
  14572. description: Secret Data that should be pushed to providers
  14573. items:
  14574. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14575. properties:
  14576. conversionStrategy:
  14577. default: None
  14578. description: Used to define a conversion Strategy for the secret keys
  14579. enum:
  14580. - None
  14581. - ReverseUnicode
  14582. type: string
  14583. match:
  14584. description: Match a given Secret Key to be pushed to the provider.
  14585. properties:
  14586. remoteRef:
  14587. description: Remote Refs to push to providers.
  14588. properties:
  14589. property:
  14590. description: Name of the property in the resulting secret
  14591. type: string
  14592. remoteKey:
  14593. description: Name of the resulting provider secret.
  14594. type: string
  14595. required:
  14596. - remoteKey
  14597. type: object
  14598. secretKey:
  14599. description: Secret Key to be pushed
  14600. type: string
  14601. required:
  14602. - remoteRef
  14603. type: object
  14604. metadata:
  14605. description: |-
  14606. Metadata is metadata attached to the secret.
  14607. The structure of metadata is provider specific, please look it up in the provider documentation.
  14608. x-kubernetes-preserve-unknown-fields: true
  14609. required:
  14610. - match
  14611. type: object
  14612. type: array
  14613. dataTo:
  14614. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14615. items:
  14616. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14617. properties:
  14618. conversionStrategy:
  14619. default: None
  14620. description: Used to define a conversion Strategy for the secret keys
  14621. enum:
  14622. - None
  14623. - ReverseUnicode
  14624. type: string
  14625. match:
  14626. description: |-
  14627. Match pattern for selecting keys from the source Secret.
  14628. If not specified, all keys are selected.
  14629. properties:
  14630. regexp:
  14631. description: |-
  14632. Regexp matches keys by regular expression.
  14633. If not specified, all keys are matched.
  14634. type: string
  14635. type: object
  14636. metadata:
  14637. description: |-
  14638. Metadata is metadata attached to the secret.
  14639. The structure of metadata is provider specific, please look it up in the provider documentation.
  14640. x-kubernetes-preserve-unknown-fields: true
  14641. remoteKey:
  14642. description: |-
  14643. RemoteKey is the name of the single provider secret that will receive ALL
  14644. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  14645. When set, per-key expansion is skipped and a single push is performed.
  14646. The provider's store prefix (if any) is still prepended to this value.
  14647. When not set, each matched key is pushed as its own individual provider secret.
  14648. type: string
  14649. rewrite:
  14650. description: |-
  14651. Rewrite operations to transform keys before pushing to the provider.
  14652. Operations are applied sequentially.
  14653. items:
  14654. description: PushSecretRewrite defines how to transform secret keys before pushing.
  14655. properties:
  14656. regexp:
  14657. description: Used to rewrite with regular expressions.
  14658. properties:
  14659. source:
  14660. description: Used to define the regular expression of a re.Compiler.
  14661. type: string
  14662. target:
  14663. description: Used to define the target pattern of a ReplaceAll operation.
  14664. type: string
  14665. required:
  14666. - source
  14667. - target
  14668. type: object
  14669. transform:
  14670. description: Used to apply string transformation on the secrets.
  14671. properties:
  14672. template:
  14673. description: |-
  14674. Used to define the template to apply on the secret name.
  14675. `.value ` will specify the secret name in the template.
  14676. type: string
  14677. required:
  14678. - template
  14679. type: object
  14680. type: object
  14681. x-kubernetes-validations:
  14682. - message: exactly one of regexp or transform must be set
  14683. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  14684. type: array
  14685. storeRef:
  14686. description: StoreRef specifies which SecretStore to push to. Required.
  14687. properties:
  14688. kind:
  14689. default: SecretStore
  14690. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14691. enum:
  14692. - SecretStore
  14693. - ClusterSecretStore
  14694. type: string
  14695. labelSelector:
  14696. description: Optionally, sync to secret stores with label selector
  14697. properties:
  14698. matchExpressions:
  14699. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14700. items:
  14701. description: |-
  14702. A label selector requirement is a selector that contains values, a key, and an operator that
  14703. relates the key and values.
  14704. properties:
  14705. key:
  14706. description: key is the label key that the selector applies to.
  14707. type: string
  14708. operator:
  14709. description: |-
  14710. operator represents a key's relationship to a set of values.
  14711. Valid operators are In, NotIn, Exists and DoesNotExist.
  14712. type: string
  14713. values:
  14714. description: |-
  14715. values is an array of string values. If the operator is In or NotIn,
  14716. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14717. the values array must be empty. This array is replaced during a strategic
  14718. merge patch.
  14719. items:
  14720. type: string
  14721. type: array
  14722. x-kubernetes-list-type: atomic
  14723. required:
  14724. - key
  14725. - operator
  14726. type: object
  14727. type: array
  14728. x-kubernetes-list-type: atomic
  14729. matchLabels:
  14730. additionalProperties:
  14731. type: string
  14732. description: |-
  14733. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14734. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14735. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14736. type: object
  14737. type: object
  14738. x-kubernetes-map-type: atomic
  14739. name:
  14740. description: Optionally, sync to the SecretStore of the given name
  14741. maxLength: 253
  14742. minLength: 1
  14743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14744. type: string
  14745. type: object
  14746. type: object
  14747. x-kubernetes-validations:
  14748. - message: storeRef must specify either name or labelSelector
  14749. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  14750. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  14751. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  14752. type: array
  14753. deletionPolicy:
  14754. default: None
  14755. description: Deletion Policy to handle Secrets in the provider.
  14756. enum:
  14757. - Delete
  14758. - None
  14759. type: string
  14760. refreshInterval:
  14761. default: 1h0m0s
  14762. description: The Interval to which External Secrets will try to push a secret definition
  14763. type: string
  14764. secretStoreRefs:
  14765. items:
  14766. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  14767. properties:
  14768. kind:
  14769. default: SecretStore
  14770. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14771. enum:
  14772. - SecretStore
  14773. - ClusterSecretStore
  14774. type: string
  14775. labelSelector:
  14776. description: Optionally, sync to secret stores with label selector
  14777. properties:
  14778. matchExpressions:
  14779. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14780. items:
  14781. description: |-
  14782. A label selector requirement is a selector that contains values, a key, and an operator that
  14783. relates the key and values.
  14784. properties:
  14785. key:
  14786. description: key is the label key that the selector applies to.
  14787. type: string
  14788. operator:
  14789. description: |-
  14790. operator represents a key's relationship to a set of values.
  14791. Valid operators are In, NotIn, Exists and DoesNotExist.
  14792. type: string
  14793. values:
  14794. description: |-
  14795. values is an array of string values. If the operator is In or NotIn,
  14796. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14797. the values array must be empty. This array is replaced during a strategic
  14798. merge patch.
  14799. items:
  14800. type: string
  14801. type: array
  14802. x-kubernetes-list-type: atomic
  14803. required:
  14804. - key
  14805. - operator
  14806. type: object
  14807. type: array
  14808. x-kubernetes-list-type: atomic
  14809. matchLabels:
  14810. additionalProperties:
  14811. type: string
  14812. description: |-
  14813. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14814. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14815. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14816. type: object
  14817. type: object
  14818. x-kubernetes-map-type: atomic
  14819. name:
  14820. description: Optionally, sync to the SecretStore of the given name
  14821. maxLength: 253
  14822. minLength: 1
  14823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14824. type: string
  14825. type: object
  14826. type: array
  14827. selector:
  14828. description: The Secret Selector (k8s source) for the Push Secret
  14829. maxProperties: 1
  14830. minProperties: 1
  14831. properties:
  14832. generatorRef:
  14833. description: Point to a generator to create a Secret.
  14834. properties:
  14835. apiVersion:
  14836. default: generators.external-secrets.io/v1alpha1
  14837. description: Specify the apiVersion of the generator resource
  14838. type: string
  14839. kind:
  14840. description: Specify the Kind of the generator resource
  14841. enum:
  14842. - ACRAccessToken
  14843. - BeyondtrustWorkloadCredentialsDynamicSecret
  14844. - ClusterGenerator
  14845. - CloudsmithAccessToken
  14846. - ECRAuthorizationToken
  14847. - Fake
  14848. - GCRAccessToken
  14849. - GithubAccessToken
  14850. - GitlabDeployToken
  14851. - QuayAccessToken
  14852. - Password
  14853. - SSHKey
  14854. - STSSessionToken
  14855. - UUID
  14856. - VaultDynamicSecret
  14857. - Webhook
  14858. - Grafana
  14859. - MFA
  14860. type: string
  14861. name:
  14862. description: Specify the name of the generator resource
  14863. maxLength: 253
  14864. minLength: 1
  14865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14866. type: string
  14867. required:
  14868. - kind
  14869. - name
  14870. type: object
  14871. secret:
  14872. description: Select a Secret to Push.
  14873. properties:
  14874. name:
  14875. description: |-
  14876. Name of the Secret.
  14877. The Secret must exist in the same namespace as the PushSecret manifest.
  14878. maxLength: 253
  14879. minLength: 1
  14880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14881. type: string
  14882. selector:
  14883. description: Selector chooses secrets using a labelSelector.
  14884. properties:
  14885. matchExpressions:
  14886. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  14887. items:
  14888. description: |-
  14889. A label selector requirement is a selector that contains values, a key, and an operator that
  14890. relates the key and values.
  14891. properties:
  14892. key:
  14893. description: key is the label key that the selector applies to.
  14894. type: string
  14895. operator:
  14896. description: |-
  14897. operator represents a key's relationship to a set of values.
  14898. Valid operators are In, NotIn, Exists and DoesNotExist.
  14899. type: string
  14900. values:
  14901. description: |-
  14902. values is an array of string values. If the operator is In or NotIn,
  14903. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  14904. the values array must be empty. This array is replaced during a strategic
  14905. merge patch.
  14906. items:
  14907. type: string
  14908. type: array
  14909. x-kubernetes-list-type: atomic
  14910. required:
  14911. - key
  14912. - operator
  14913. type: object
  14914. type: array
  14915. x-kubernetes-list-type: atomic
  14916. matchLabels:
  14917. additionalProperties:
  14918. type: string
  14919. description: |-
  14920. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  14921. map is equivalent to an element of matchExpressions, whose key field is "key", the
  14922. operator is "In", and the values array contains only "value". The requirements are ANDed.
  14923. type: object
  14924. type: object
  14925. x-kubernetes-map-type: atomic
  14926. type: object
  14927. type: object
  14928. template:
  14929. description: Template defines a blueprint for the created Secret resource.
  14930. properties:
  14931. data:
  14932. additionalProperties:
  14933. type: string
  14934. type: object
  14935. engineVersion:
  14936. default: v2
  14937. description: |-
  14938. EngineVersion specifies the template engine version
  14939. that should be used to compile/execute the
  14940. template specified in .data and .templateFrom[].
  14941. enum:
  14942. - v2
  14943. type: string
  14944. mergePolicy:
  14945. default: Replace
  14946. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14947. enum:
  14948. - Replace
  14949. - Merge
  14950. type: string
  14951. metadata:
  14952. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14953. properties:
  14954. annotations:
  14955. additionalProperties:
  14956. type: string
  14957. type: object
  14958. finalizers:
  14959. items:
  14960. type: string
  14961. type: array
  14962. labels:
  14963. additionalProperties:
  14964. type: string
  14965. type: object
  14966. type: object
  14967. templateFrom:
  14968. items:
  14969. description: |-
  14970. TemplateFrom specifies a source for templates.
  14971. Each item in the list can either reference a ConfigMap or a Secret resource.
  14972. properties:
  14973. configMap:
  14974. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14975. properties:
  14976. items:
  14977. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14978. items:
  14979. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14980. properties:
  14981. key:
  14982. description: A key in the ConfigMap/Secret
  14983. maxLength: 253
  14984. minLength: 1
  14985. pattern: ^[-._a-zA-Z0-9]+$
  14986. type: string
  14987. templateAs:
  14988. default: Values
  14989. description: TemplateScope specifies how the template keys should be interpreted.
  14990. enum:
  14991. - Values
  14992. - KeysAndValues
  14993. type: string
  14994. required:
  14995. - key
  14996. type: object
  14997. type: array
  14998. name:
  14999. description: The name of the ConfigMap/Secret resource
  15000. maxLength: 253
  15001. minLength: 1
  15002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15003. type: string
  15004. required:
  15005. - items
  15006. - name
  15007. type: object
  15008. literal:
  15009. type: string
  15010. secret:
  15011. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15012. properties:
  15013. items:
  15014. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15015. items:
  15016. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15017. properties:
  15018. key:
  15019. description: A key in the ConfigMap/Secret
  15020. maxLength: 253
  15021. minLength: 1
  15022. pattern: ^[-._a-zA-Z0-9]+$
  15023. type: string
  15024. templateAs:
  15025. default: Values
  15026. description: TemplateScope specifies how the template keys should be interpreted.
  15027. enum:
  15028. - Values
  15029. - KeysAndValues
  15030. type: string
  15031. required:
  15032. - key
  15033. type: object
  15034. type: array
  15035. name:
  15036. description: The name of the ConfigMap/Secret resource
  15037. maxLength: 253
  15038. minLength: 1
  15039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15040. type: string
  15041. required:
  15042. - items
  15043. - name
  15044. type: object
  15045. target:
  15046. default: Data
  15047. description: |-
  15048. Target specifies where to place the template result.
  15049. For Secret resources, common values are: "Data", "Annotations", "Labels".
  15050. For custom resources (when spec.target.manifest is set), this supports
  15051. nested paths like "spec.database.config" or "data".
  15052. type: string
  15053. valuesDecodingStrategy:
  15054. default: None
  15055. description: Used to define a decoding Strategy for the rendered template values.
  15056. enum:
  15057. - Auto
  15058. - Base64
  15059. - Base64URL
  15060. - None
  15061. type: string
  15062. type: object
  15063. type: array
  15064. type:
  15065. type: string
  15066. type: object
  15067. updatePolicy:
  15068. default: Replace
  15069. description: UpdatePolicy to handle Secrets in the provider.
  15070. enum:
  15071. - Replace
  15072. - IfNotExists
  15073. type: string
  15074. required:
  15075. - secretStoreRefs
  15076. - selector
  15077. type: object
  15078. status:
  15079. description: PushSecretStatus indicates the history of the status of PushSecret.
  15080. properties:
  15081. conditions:
  15082. items:
  15083. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15084. properties:
  15085. lastTransitionTime:
  15086. format: date-time
  15087. type: string
  15088. message:
  15089. type: string
  15090. reason:
  15091. type: string
  15092. status:
  15093. type: string
  15094. type:
  15095. description: PushSecretConditionType indicates the condition of the PushSecret.
  15096. type: string
  15097. required:
  15098. - status
  15099. - type
  15100. type: object
  15101. type: array
  15102. refreshTime:
  15103. description: |-
  15104. refreshTime is the time and date the external secret was fetched and
  15105. the target secret updated
  15106. format: date-time
  15107. nullable: true
  15108. type: string
  15109. syncedPushSecrets:
  15110. additionalProperties:
  15111. additionalProperties:
  15112. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15113. properties:
  15114. conversionStrategy:
  15115. default: None
  15116. description: Used to define a conversion Strategy for the secret keys
  15117. enum:
  15118. - None
  15119. - ReverseUnicode
  15120. type: string
  15121. match:
  15122. description: Match a given Secret Key to be pushed to the provider.
  15123. properties:
  15124. remoteRef:
  15125. description: Remote Refs to push to providers.
  15126. properties:
  15127. property:
  15128. description: Name of the property in the resulting secret
  15129. type: string
  15130. remoteKey:
  15131. description: Name of the resulting provider secret.
  15132. type: string
  15133. required:
  15134. - remoteKey
  15135. type: object
  15136. secretKey:
  15137. description: Secret Key to be pushed
  15138. type: string
  15139. required:
  15140. - remoteRef
  15141. type: object
  15142. metadata:
  15143. description: |-
  15144. Metadata is metadata attached to the secret.
  15145. The structure of metadata is provider specific, please look it up in the provider documentation.
  15146. x-kubernetes-preserve-unknown-fields: true
  15147. required:
  15148. - match
  15149. type: object
  15150. type: object
  15151. description: |-
  15152. Synced PushSecrets, including secrets that already exist in provider.
  15153. Matches secret stores to PushSecretData that was stored to that secret store.
  15154. type: object
  15155. syncedResourceVersion:
  15156. description: SyncedResourceVersion keeps track of the last synced version.
  15157. type: string
  15158. type: object
  15159. type: object
  15160. served: true
  15161. storage: true
  15162. subresources:
  15163. status: {}
  15164. ---
  15165. apiVersion: apiextensions.k8s.io/v1
  15166. kind: CustomResourceDefinition
  15167. metadata:
  15168. annotations:
  15169. controller-gen.kubebuilder.io/version: v0.19.0
  15170. labels:
  15171. external-secrets.io/component: controller
  15172. name: secretstores.external-secrets.io
  15173. spec:
  15174. group: external-secrets.io
  15175. names:
  15176. categories:
  15177. - external-secrets
  15178. kind: SecretStore
  15179. listKind: SecretStoreList
  15180. plural: secretstores
  15181. shortNames:
  15182. - ss
  15183. singular: secretstore
  15184. scope: Namespaced
  15185. versions:
  15186. - additionalPrinterColumns:
  15187. - jsonPath: .metadata.creationTimestamp
  15188. name: AGE
  15189. type: date
  15190. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15191. name: Status
  15192. type: string
  15193. - jsonPath: .status.capabilities
  15194. name: Capabilities
  15195. type: string
  15196. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15197. name: Ready
  15198. type: string
  15199. name: v1
  15200. schema:
  15201. openAPIV3Schema:
  15202. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15203. properties:
  15204. apiVersion:
  15205. description: |-
  15206. APIVersion defines the versioned schema of this representation of an object.
  15207. Servers should convert recognized schemas to the latest internal value, and
  15208. may reject unrecognized values.
  15209. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15210. type: string
  15211. kind:
  15212. description: |-
  15213. Kind is a string value representing the REST resource this object represents.
  15214. Servers may infer this from the endpoint the client submits requests to.
  15215. Cannot be updated.
  15216. In CamelCase.
  15217. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15218. type: string
  15219. metadata:
  15220. type: object
  15221. spec:
  15222. description: SecretStoreSpec defines the desired state of SecretStore.
  15223. properties:
  15224. conditions:
  15225. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15226. items:
  15227. description: |-
  15228. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15229. for a ClusterSecretStore instance.
  15230. properties:
  15231. namespaceRegexes:
  15232. description: Choose namespaces by using regex matching
  15233. items:
  15234. type: string
  15235. type: array
  15236. namespaceSelector:
  15237. description: Choose namespace using a labelSelector
  15238. properties:
  15239. matchExpressions:
  15240. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15241. items:
  15242. description: |-
  15243. A label selector requirement is a selector that contains values, a key, and an operator that
  15244. relates the key and values.
  15245. properties:
  15246. key:
  15247. description: key is the label key that the selector applies to.
  15248. type: string
  15249. operator:
  15250. description: |-
  15251. operator represents a key's relationship to a set of values.
  15252. Valid operators are In, NotIn, Exists and DoesNotExist.
  15253. type: string
  15254. values:
  15255. description: |-
  15256. values is an array of string values. If the operator is In or NotIn,
  15257. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15258. the values array must be empty. This array is replaced during a strategic
  15259. merge patch.
  15260. items:
  15261. type: string
  15262. type: array
  15263. x-kubernetes-list-type: atomic
  15264. required:
  15265. - key
  15266. - operator
  15267. type: object
  15268. type: array
  15269. x-kubernetes-list-type: atomic
  15270. matchLabels:
  15271. additionalProperties:
  15272. type: string
  15273. description: |-
  15274. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15275. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15276. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15277. type: object
  15278. type: object
  15279. x-kubernetes-map-type: atomic
  15280. namespaces:
  15281. description: Choose namespaces by name
  15282. items:
  15283. maxLength: 63
  15284. minLength: 1
  15285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15286. type: string
  15287. type: array
  15288. type: object
  15289. type: array
  15290. controller:
  15291. description: |-
  15292. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15293. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15294. type: string
  15295. provider:
  15296. description: Used to configure the provider. Only one provider may be set
  15297. maxProperties: 1
  15298. minProperties: 1
  15299. properties:
  15300. akeyless:
  15301. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15302. properties:
  15303. akeylessGWApiURL:
  15304. description: Akeyless GW API Url from which the secrets to be fetched from.
  15305. type: string
  15306. authSecretRef:
  15307. description: Auth configures how the operator authenticates with Akeyless.
  15308. properties:
  15309. kubernetesAuth:
  15310. description: |-
  15311. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15312. token stored in the named Secret resource.
  15313. properties:
  15314. accessID:
  15315. description: the Akeyless Kubernetes auth-method access-id
  15316. type: string
  15317. k8sConfName:
  15318. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15319. type: string
  15320. secretRef:
  15321. description: |-
  15322. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15323. for authenticating with Akeyless. If a name is specified without a key,
  15324. `token` is the default. If one is not specified, the one bound to
  15325. the controller will be used.
  15326. properties:
  15327. key:
  15328. description: |-
  15329. A key in the referenced Secret.
  15330. Some instances of this field may be defaulted, in others it may be required.
  15331. maxLength: 253
  15332. minLength: 1
  15333. pattern: ^[-._a-zA-Z0-9]+$
  15334. type: string
  15335. name:
  15336. description: The name of the Secret resource being referred to.
  15337. maxLength: 253
  15338. minLength: 1
  15339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15340. type: string
  15341. namespace:
  15342. description: |-
  15343. The namespace of the Secret resource being referred to.
  15344. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15345. maxLength: 63
  15346. minLength: 1
  15347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15348. type: string
  15349. type: object
  15350. serviceAccountRef:
  15351. description: |-
  15352. Optional service account field containing the name of a kubernetes ServiceAccount.
  15353. If the service account is specified, the service account secret token JWT will be used
  15354. for authenticating with Akeyless. If the service account selector is not supplied,
  15355. the secretRef will be used instead.
  15356. properties:
  15357. audiences:
  15358. description: |-
  15359. Audience specifies the `aud` claim for the service account token
  15360. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15361. then this audiences will be appended to the list
  15362. items:
  15363. type: string
  15364. type: array
  15365. name:
  15366. description: The name of the ServiceAccount resource being referred to.
  15367. maxLength: 253
  15368. minLength: 1
  15369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15370. type: string
  15371. namespace:
  15372. description: |-
  15373. Namespace of the resource being referred to.
  15374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15375. maxLength: 63
  15376. minLength: 1
  15377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15378. type: string
  15379. required:
  15380. - name
  15381. type: object
  15382. required:
  15383. - accessID
  15384. - k8sConfName
  15385. type: object
  15386. secretRef:
  15387. description: |-
  15388. Reference to a Secret that contains the details
  15389. to authenticate with Akeyless.
  15390. properties:
  15391. accessID:
  15392. description: The SecretAccessID is used for authentication
  15393. properties:
  15394. key:
  15395. description: |-
  15396. A key in the referenced Secret.
  15397. Some instances of this field may be defaulted, in others it may be required.
  15398. maxLength: 253
  15399. minLength: 1
  15400. pattern: ^[-._a-zA-Z0-9]+$
  15401. type: string
  15402. name:
  15403. description: The name of the Secret resource being referred to.
  15404. maxLength: 253
  15405. minLength: 1
  15406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15407. type: string
  15408. namespace:
  15409. description: |-
  15410. The namespace of the Secret resource being referred to.
  15411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15412. maxLength: 63
  15413. minLength: 1
  15414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15415. type: string
  15416. type: object
  15417. accessType:
  15418. description: |-
  15419. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15420. In some instances, `key` is a required field.
  15421. properties:
  15422. key:
  15423. description: |-
  15424. A key in the referenced Secret.
  15425. Some instances of this field may be defaulted, in others it may be required.
  15426. maxLength: 253
  15427. minLength: 1
  15428. pattern: ^[-._a-zA-Z0-9]+$
  15429. type: string
  15430. name:
  15431. description: The name of the Secret resource being referred to.
  15432. maxLength: 253
  15433. minLength: 1
  15434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15435. type: string
  15436. namespace:
  15437. description: |-
  15438. The namespace of the Secret resource being referred to.
  15439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15440. maxLength: 63
  15441. minLength: 1
  15442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15443. type: string
  15444. type: object
  15445. accessTypeParam:
  15446. description: |-
  15447. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15448. In some instances, `key` is a required field.
  15449. properties:
  15450. key:
  15451. description: |-
  15452. A key in the referenced Secret.
  15453. Some instances of this field may be defaulted, in others it may be required.
  15454. maxLength: 253
  15455. minLength: 1
  15456. pattern: ^[-._a-zA-Z0-9]+$
  15457. type: string
  15458. name:
  15459. description: The name of the Secret resource being referred to.
  15460. maxLength: 253
  15461. minLength: 1
  15462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15463. type: string
  15464. namespace:
  15465. description: |-
  15466. The namespace of the Secret resource being referred to.
  15467. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15468. maxLength: 63
  15469. minLength: 1
  15470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15471. type: string
  15472. type: object
  15473. type: object
  15474. serviceAccountRef:
  15475. description: |-
  15476. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15477. authentication on AKS Workload Identity. The operator obtains a federated
  15478. identity token from this ServiceAccount via the TokenRequest API instead
  15479. of using the ESO controller pod identity. Ignored for other access types.
  15480. properties:
  15481. audiences:
  15482. description: |-
  15483. Audience specifies the `aud` claim for the service account token
  15484. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15485. then this audiences will be appended to the list
  15486. items:
  15487. type: string
  15488. type: array
  15489. name:
  15490. description: The name of the ServiceAccount resource being referred to.
  15491. maxLength: 253
  15492. minLength: 1
  15493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15494. type: string
  15495. namespace:
  15496. description: |-
  15497. Namespace of the resource being referred to.
  15498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15499. maxLength: 63
  15500. minLength: 1
  15501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15502. type: string
  15503. required:
  15504. - name
  15505. type: object
  15506. type: object
  15507. caBundle:
  15508. description: |-
  15509. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15510. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15511. are used to validate the TLS connection.
  15512. format: byte
  15513. type: string
  15514. caProvider:
  15515. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15516. properties:
  15517. key:
  15518. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15519. maxLength: 253
  15520. minLength: 1
  15521. pattern: ^[-._a-zA-Z0-9]+$
  15522. type: string
  15523. name:
  15524. description: The name of the object located at the provider type.
  15525. maxLength: 253
  15526. minLength: 1
  15527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15528. type: string
  15529. namespace:
  15530. description: |-
  15531. The namespace the Provider type is in.
  15532. Can only be defined when used in a ClusterSecretStore.
  15533. maxLength: 63
  15534. minLength: 1
  15535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15536. type: string
  15537. type:
  15538. description: The type of provider to use such as "Secret", or "ConfigMap".
  15539. enum:
  15540. - Secret
  15541. - ConfigMap
  15542. type: string
  15543. required:
  15544. - name
  15545. - type
  15546. type: object
  15547. ignoreCache:
  15548. description: |-
  15549. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15550. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15551. type: boolean
  15552. required:
  15553. - akeylessGWApiURL
  15554. - authSecretRef
  15555. type: object
  15556. aws:
  15557. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15558. properties:
  15559. additionalRoles:
  15560. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15561. items:
  15562. type: string
  15563. type: array
  15564. auth:
  15565. description: |-
  15566. Auth defines the information necessary to authenticate against AWS
  15567. if not set aws sdk will infer credentials from your environment
  15568. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15569. properties:
  15570. jwt:
  15571. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15572. properties:
  15573. serviceAccountRef:
  15574. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15575. properties:
  15576. audiences:
  15577. description: |-
  15578. Audience specifies the `aud` claim for the service account token
  15579. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15580. then this audiences will be appended to the list
  15581. items:
  15582. type: string
  15583. type: array
  15584. name:
  15585. description: The name of the ServiceAccount resource being referred to.
  15586. maxLength: 253
  15587. minLength: 1
  15588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15589. type: string
  15590. namespace:
  15591. description: |-
  15592. Namespace of the resource being referred to.
  15593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15594. maxLength: 63
  15595. minLength: 1
  15596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15597. type: string
  15598. required:
  15599. - name
  15600. type: object
  15601. type: object
  15602. secretRef:
  15603. description: |-
  15604. AWSAuthSecretRef holds secret references for AWS credentials
  15605. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15606. properties:
  15607. accessKeyIDSecretRef:
  15608. description: The AccessKeyID is used for authentication
  15609. properties:
  15610. key:
  15611. description: |-
  15612. A key in the referenced Secret.
  15613. Some instances of this field may be defaulted, in others it may be required.
  15614. maxLength: 253
  15615. minLength: 1
  15616. pattern: ^[-._a-zA-Z0-9]+$
  15617. type: string
  15618. name:
  15619. description: The name of the Secret resource being referred to.
  15620. maxLength: 253
  15621. minLength: 1
  15622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15623. type: string
  15624. namespace:
  15625. description: |-
  15626. The namespace of the Secret resource being referred to.
  15627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15628. maxLength: 63
  15629. minLength: 1
  15630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15631. type: string
  15632. type: object
  15633. secretAccessKeySecretRef:
  15634. description: The SecretAccessKey is used for authentication
  15635. properties:
  15636. key:
  15637. description: |-
  15638. A key in the referenced Secret.
  15639. Some instances of this field may be defaulted, in others it may be required.
  15640. maxLength: 253
  15641. minLength: 1
  15642. pattern: ^[-._a-zA-Z0-9]+$
  15643. type: string
  15644. name:
  15645. description: The name of the Secret resource being referred to.
  15646. maxLength: 253
  15647. minLength: 1
  15648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15649. type: string
  15650. namespace:
  15651. description: |-
  15652. The namespace of the Secret resource being referred to.
  15653. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15654. maxLength: 63
  15655. minLength: 1
  15656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15657. type: string
  15658. type: object
  15659. sessionTokenSecretRef:
  15660. description: |-
  15661. The SessionToken used for authentication
  15662. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  15663. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  15664. properties:
  15665. key:
  15666. description: |-
  15667. A key in the referenced Secret.
  15668. Some instances of this field may be defaulted, in others it may be required.
  15669. maxLength: 253
  15670. minLength: 1
  15671. pattern: ^[-._a-zA-Z0-9]+$
  15672. type: string
  15673. name:
  15674. description: The name of the Secret resource being referred to.
  15675. maxLength: 253
  15676. minLength: 1
  15677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15678. type: string
  15679. namespace:
  15680. description: |-
  15681. The namespace of the Secret resource being referred to.
  15682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15683. maxLength: 63
  15684. minLength: 1
  15685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15686. type: string
  15687. type: object
  15688. type: object
  15689. type: object
  15690. customSessionTags:
  15691. additionalProperties:
  15692. type: string
  15693. description: |-
  15694. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  15695. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  15696. type: object
  15697. x-kubernetes-validations:
  15698. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  15699. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  15700. externalID:
  15701. description: AWS External ID set on assumed IAM roles
  15702. type: string
  15703. prefix:
  15704. description: Prefix adds a prefix to all retrieved values.
  15705. type: string
  15706. region:
  15707. description: AWS Region to be used for the provider
  15708. type: string
  15709. role:
  15710. description: Role is a Role ARN which the provider will assume
  15711. type: string
  15712. secretsManager:
  15713. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  15714. properties:
  15715. forceDeleteWithoutRecovery:
  15716. description: |-
  15717. Specifies whether to delete the secret without any recovery window. You
  15718. can't use both this parameter and RecoveryWindowInDays in the same call.
  15719. If you don't use either, then by default Secrets Manager uses a 30 day
  15720. recovery window.
  15721. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  15722. type: boolean
  15723. recoveryWindowInDays:
  15724. description: |-
  15725. The number of days from 7 to 30 that Secrets Manager waits before
  15726. permanently deleting the secret. You can't use both this parameter and
  15727. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  15728. then by default Secrets Manager uses a 30-day recovery window.
  15729. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  15730. format: int64
  15731. type: integer
  15732. type: object
  15733. service:
  15734. description: Service defines which service should be used to fetch the secrets
  15735. enum:
  15736. - SecretsManager
  15737. - ParameterStore
  15738. - CertificateManager
  15739. type: string
  15740. sessionTags:
  15741. description: AWS STS assume role session tags
  15742. items:
  15743. description: |-
  15744. Tag is a key-value pair that can be attached to an AWS resource.
  15745. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  15746. properties:
  15747. key:
  15748. type: string
  15749. value:
  15750. type: string
  15751. required:
  15752. - key
  15753. - value
  15754. type: object
  15755. type: array
  15756. sessionTagsPolicy:
  15757. default: None
  15758. description: |-
  15759. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  15760. None (default): no tags are added.
  15761. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  15762. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  15763. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  15764. enum:
  15765. - None
  15766. - Simple
  15767. - Custom
  15768. type: string
  15769. transitiveTagKeys:
  15770. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  15771. items:
  15772. type: string
  15773. type: array
  15774. required:
  15775. - region
  15776. - service
  15777. type: object
  15778. azurekv:
  15779. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  15780. properties:
  15781. authSecretRef:
  15782. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  15783. properties:
  15784. clientCertificate:
  15785. description: The Azure ClientCertificate of the service principle used for authentication.
  15786. properties:
  15787. key:
  15788. description: |-
  15789. A key in the referenced Secret.
  15790. Some instances of this field may be defaulted, in others it may be required.
  15791. maxLength: 253
  15792. minLength: 1
  15793. pattern: ^[-._a-zA-Z0-9]+$
  15794. type: string
  15795. name:
  15796. description: The name of the Secret resource being referred to.
  15797. maxLength: 253
  15798. minLength: 1
  15799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15800. type: string
  15801. namespace:
  15802. description: |-
  15803. The namespace of the Secret resource being referred to.
  15804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15805. maxLength: 63
  15806. minLength: 1
  15807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15808. type: string
  15809. type: object
  15810. clientId:
  15811. description: The Azure clientId of the service principle or managed identity used for authentication.
  15812. properties:
  15813. key:
  15814. description: |-
  15815. A key in the referenced Secret.
  15816. Some instances of this field may be defaulted, in others it may be required.
  15817. maxLength: 253
  15818. minLength: 1
  15819. pattern: ^[-._a-zA-Z0-9]+$
  15820. type: string
  15821. name:
  15822. description: The name of the Secret resource being referred to.
  15823. maxLength: 253
  15824. minLength: 1
  15825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15826. type: string
  15827. namespace:
  15828. description: |-
  15829. The namespace of the Secret resource being referred to.
  15830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15831. maxLength: 63
  15832. minLength: 1
  15833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15834. type: string
  15835. type: object
  15836. clientSecret:
  15837. description: The Azure ClientSecret of the service principle used for authentication.
  15838. properties:
  15839. key:
  15840. description: |-
  15841. A key in the referenced Secret.
  15842. Some instances of this field may be defaulted, in others it may be required.
  15843. maxLength: 253
  15844. minLength: 1
  15845. pattern: ^[-._a-zA-Z0-9]+$
  15846. type: string
  15847. name:
  15848. description: The name of the Secret resource being referred to.
  15849. maxLength: 253
  15850. minLength: 1
  15851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15852. type: string
  15853. namespace:
  15854. description: |-
  15855. The namespace of the Secret resource being referred to.
  15856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15857. maxLength: 63
  15858. minLength: 1
  15859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15860. type: string
  15861. type: object
  15862. tenantId:
  15863. description: The Azure tenantId of the managed identity used for authentication.
  15864. properties:
  15865. key:
  15866. description: |-
  15867. A key in the referenced Secret.
  15868. Some instances of this field may be defaulted, in others it may be required.
  15869. maxLength: 253
  15870. minLength: 1
  15871. pattern: ^[-._a-zA-Z0-9]+$
  15872. type: string
  15873. name:
  15874. description: The name of the Secret resource being referred to.
  15875. maxLength: 253
  15876. minLength: 1
  15877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15878. type: string
  15879. namespace:
  15880. description: |-
  15881. The namespace of the Secret resource being referred to.
  15882. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15883. maxLength: 63
  15884. minLength: 1
  15885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15886. type: string
  15887. type: object
  15888. type: object
  15889. authType:
  15890. default: ServicePrincipal
  15891. description: |-
  15892. Auth type defines how to authenticate to the keyvault service.
  15893. Valid values are:
  15894. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  15895. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  15896. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  15897. enum:
  15898. - ServicePrincipal
  15899. - ManagedIdentity
  15900. - WorkloadIdentity
  15901. type: string
  15902. customCloudConfig:
  15903. description: |-
  15904. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  15905. Required when EnvironmentType is AzureStackCloud.
  15906. Optional for other environment types - useful for Azure China when using Workload Identity
  15907. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  15908. standard China Cloud endpoint (login.chinacloudapi.cn).
  15909. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  15910. configuration is not supported with the legacy go-autorest SDK.
  15911. properties:
  15912. activeDirectoryEndpoint:
  15913. description: |-
  15914. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  15915. Required when using custom cloud configuration
  15916. type: string
  15917. keyVaultDNSSuffix:
  15918. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  15919. type: string
  15920. keyVaultEndpoint:
  15921. description: KeyVaultEndpoint is the Key Vault service endpoint
  15922. type: string
  15923. resourceManagerEndpoint:
  15924. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  15925. type: string
  15926. required:
  15927. - activeDirectoryEndpoint
  15928. type: object
  15929. environmentType:
  15930. default: PublicCloud
  15931. description: |-
  15932. EnvironmentType specifies the Azure cloud environment endpoints to use for
  15933. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  15934. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  15935. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  15936. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  15937. enum:
  15938. - PublicCloud
  15939. - USGovernmentCloud
  15940. - ChinaCloud
  15941. - GermanCloud
  15942. - AzureStackCloud
  15943. type: string
  15944. identityId:
  15945. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  15946. type: string
  15947. serviceAccountRef:
  15948. description: |-
  15949. ServiceAccountRef specified the service account
  15950. that should be used when authenticating with WorkloadIdentity.
  15951. properties:
  15952. audiences:
  15953. description: |-
  15954. Audience specifies the `aud` claim for the service account token
  15955. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15956. then this audiences will be appended to the list
  15957. items:
  15958. type: string
  15959. type: array
  15960. name:
  15961. description: The name of the ServiceAccount resource being referred to.
  15962. maxLength: 253
  15963. minLength: 1
  15964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15965. type: string
  15966. namespace:
  15967. description: |-
  15968. Namespace of the resource being referred to.
  15969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15970. maxLength: 63
  15971. minLength: 1
  15972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15973. type: string
  15974. required:
  15975. - name
  15976. type: object
  15977. tenantId:
  15978. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  15979. type: string
  15980. useAzureSDK:
  15981. default: false
  15982. description: |-
  15983. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  15984. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  15985. type: boolean
  15986. vaultUrl:
  15987. description: Vault Url from which the secrets to be fetched from.
  15988. type: string
  15989. required:
  15990. - vaultUrl
  15991. type: object
  15992. barbican:
  15993. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  15994. properties:
  15995. auth:
  15996. description: BarbicanAuth contains the authentication information for Barbican.
  15997. properties:
  15998. password:
  15999. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16000. properties:
  16001. secretRef:
  16002. description: |-
  16003. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16004. In some instances, `key` is a required field.
  16005. properties:
  16006. key:
  16007. description: |-
  16008. A key in the referenced Secret.
  16009. Some instances of this field may be defaulted, in others it may be required.
  16010. maxLength: 253
  16011. minLength: 1
  16012. pattern: ^[-._a-zA-Z0-9]+$
  16013. type: string
  16014. name:
  16015. description: The name of the Secret resource being referred to.
  16016. maxLength: 253
  16017. minLength: 1
  16018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16019. type: string
  16020. namespace:
  16021. description: |-
  16022. The namespace of the Secret resource being referred to.
  16023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16024. maxLength: 63
  16025. minLength: 1
  16026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16027. type: string
  16028. type: object
  16029. required:
  16030. - secretRef
  16031. type: object
  16032. username:
  16033. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16034. maxProperties: 1
  16035. minProperties: 1
  16036. properties:
  16037. secretRef:
  16038. description: |-
  16039. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16040. In some instances, `key` is a required field.
  16041. properties:
  16042. key:
  16043. description: |-
  16044. A key in the referenced Secret.
  16045. Some instances of this field may be defaulted, in others it may be required.
  16046. maxLength: 253
  16047. minLength: 1
  16048. pattern: ^[-._a-zA-Z0-9]+$
  16049. type: string
  16050. name:
  16051. description: The name of the Secret resource being referred to.
  16052. maxLength: 253
  16053. minLength: 1
  16054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16055. type: string
  16056. namespace:
  16057. description: |-
  16058. The namespace of the Secret resource being referred to.
  16059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16060. maxLength: 63
  16061. minLength: 1
  16062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16063. type: string
  16064. type: object
  16065. value:
  16066. type: string
  16067. type: object
  16068. required:
  16069. - password
  16070. - username
  16071. type: object
  16072. authURL:
  16073. type: string
  16074. domainName:
  16075. type: string
  16076. region:
  16077. type: string
  16078. tenantName:
  16079. type: string
  16080. required:
  16081. - auth
  16082. type: object
  16083. beyondtrust:
  16084. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16085. properties:
  16086. auth:
  16087. description: Auth configures how the operator authenticates with Beyondtrust.
  16088. properties:
  16089. apiKey:
  16090. description: APIKey If not provided then ClientID/ClientSecret become required.
  16091. properties:
  16092. secretRef:
  16093. description: SecretRef references a key in a secret that will be used as value.
  16094. properties:
  16095. key:
  16096. description: |-
  16097. A key in the referenced Secret.
  16098. Some instances of this field may be defaulted, in others it may be required.
  16099. maxLength: 253
  16100. minLength: 1
  16101. pattern: ^[-._a-zA-Z0-9]+$
  16102. type: string
  16103. name:
  16104. description: The name of the Secret resource being referred to.
  16105. maxLength: 253
  16106. minLength: 1
  16107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16108. type: string
  16109. namespace:
  16110. description: |-
  16111. The namespace of the Secret resource being referred to.
  16112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16113. maxLength: 63
  16114. minLength: 1
  16115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16116. type: string
  16117. type: object
  16118. value:
  16119. description: Value can be specified directly to set a value without using a secret.
  16120. type: string
  16121. type: object
  16122. certificate:
  16123. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16124. properties:
  16125. secretRef:
  16126. description: SecretRef references a key in a secret that will be used as value.
  16127. properties:
  16128. key:
  16129. description: |-
  16130. A key in the referenced Secret.
  16131. Some instances of this field may be defaulted, in others it may be required.
  16132. maxLength: 253
  16133. minLength: 1
  16134. pattern: ^[-._a-zA-Z0-9]+$
  16135. type: string
  16136. name:
  16137. description: The name of the Secret resource being referred to.
  16138. maxLength: 253
  16139. minLength: 1
  16140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16141. type: string
  16142. namespace:
  16143. description: |-
  16144. The namespace of the Secret resource being referred to.
  16145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16146. maxLength: 63
  16147. minLength: 1
  16148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16149. type: string
  16150. type: object
  16151. value:
  16152. description: Value can be specified directly to set a value without using a secret.
  16153. type: string
  16154. type: object
  16155. certificateKey:
  16156. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16157. properties:
  16158. secretRef:
  16159. description: SecretRef references a key in a secret that will be used as value.
  16160. properties:
  16161. key:
  16162. description: |-
  16163. A key in the referenced Secret.
  16164. Some instances of this field may be defaulted, in others it may be required.
  16165. maxLength: 253
  16166. minLength: 1
  16167. pattern: ^[-._a-zA-Z0-9]+$
  16168. type: string
  16169. name:
  16170. description: The name of the Secret resource being referred to.
  16171. maxLength: 253
  16172. minLength: 1
  16173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16174. type: string
  16175. namespace:
  16176. description: |-
  16177. The namespace of the Secret resource being referred to.
  16178. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16179. maxLength: 63
  16180. minLength: 1
  16181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16182. type: string
  16183. type: object
  16184. value:
  16185. description: Value can be specified directly to set a value without using a secret.
  16186. type: string
  16187. type: object
  16188. clientId:
  16189. description: ClientID is the API OAuth Client ID.
  16190. properties:
  16191. secretRef:
  16192. description: SecretRef references a key in a secret that will be used as value.
  16193. properties:
  16194. key:
  16195. description: |-
  16196. A key in the referenced Secret.
  16197. Some instances of this field may be defaulted, in others it may be required.
  16198. maxLength: 253
  16199. minLength: 1
  16200. pattern: ^[-._a-zA-Z0-9]+$
  16201. type: string
  16202. name:
  16203. description: The name of the Secret resource being referred to.
  16204. maxLength: 253
  16205. minLength: 1
  16206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16207. type: string
  16208. namespace:
  16209. description: |-
  16210. The namespace of the Secret resource being referred to.
  16211. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16212. maxLength: 63
  16213. minLength: 1
  16214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16215. type: string
  16216. type: object
  16217. value:
  16218. description: Value can be specified directly to set a value without using a secret.
  16219. type: string
  16220. type: object
  16221. clientSecret:
  16222. description: ClientSecret is the API OAuth Client Secret.
  16223. properties:
  16224. secretRef:
  16225. description: SecretRef references a key in a secret that will be used as value.
  16226. properties:
  16227. key:
  16228. description: |-
  16229. A key in the referenced Secret.
  16230. Some instances of this field may be defaulted, in others it may be required.
  16231. maxLength: 253
  16232. minLength: 1
  16233. pattern: ^[-._a-zA-Z0-9]+$
  16234. type: string
  16235. name:
  16236. description: The name of the Secret resource being referred to.
  16237. maxLength: 253
  16238. minLength: 1
  16239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16240. type: string
  16241. namespace:
  16242. description: |-
  16243. The namespace of the Secret resource being referred to.
  16244. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16245. maxLength: 63
  16246. minLength: 1
  16247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16248. type: string
  16249. type: object
  16250. value:
  16251. description: Value can be specified directly to set a value without using a secret.
  16252. type: string
  16253. type: object
  16254. type: object
  16255. server:
  16256. description: Auth configures how API server works.
  16257. properties:
  16258. apiUrl:
  16259. type: string
  16260. apiVersion:
  16261. type: string
  16262. clientTimeOutSeconds:
  16263. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16264. type: integer
  16265. decrypt:
  16266. default: true
  16267. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16268. type: boolean
  16269. retrievalType:
  16270. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16271. type: string
  16272. separator:
  16273. description: A character that separates the folder names.
  16274. type: string
  16275. verifyCA:
  16276. type: boolean
  16277. required:
  16278. - apiUrl
  16279. - verifyCA
  16280. type: object
  16281. required:
  16282. - auth
  16283. - server
  16284. type: object
  16285. beyondtrustworkloadcredentials:
  16286. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16287. properties:
  16288. auth:
  16289. description: |-
  16290. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16291. Currently supports API key authentication via Kubernetes secret reference.
  16292. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16293. properties:
  16294. apikey:
  16295. description: |-
  16296. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16297. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16298. properties:
  16299. token:
  16300. description: |-
  16301. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16302. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16303. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16304. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16305. properties:
  16306. key:
  16307. description: |-
  16308. A key in the referenced Secret.
  16309. Some instances of this field may be defaulted, in others it may be required.
  16310. maxLength: 253
  16311. minLength: 1
  16312. pattern: ^[-._a-zA-Z0-9]+$
  16313. type: string
  16314. name:
  16315. description: The name of the Secret resource being referred to.
  16316. maxLength: 253
  16317. minLength: 1
  16318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16319. type: string
  16320. namespace:
  16321. description: |-
  16322. The namespace of the Secret resource being referred to.
  16323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16324. maxLength: 63
  16325. minLength: 1
  16326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16327. type: string
  16328. type: object
  16329. required:
  16330. - token
  16331. type: object
  16332. required:
  16333. - apikey
  16334. type: object
  16335. caBundle:
  16336. description: |-
  16337. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16338. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16339. If not set, the system's trusted root certificates are used.
  16340. format: byte
  16341. type: string
  16342. caProvider:
  16343. description: |-
  16344. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16345. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16346. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16347. properties:
  16348. key:
  16349. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16350. maxLength: 253
  16351. minLength: 1
  16352. pattern: ^[-._a-zA-Z0-9]+$
  16353. type: string
  16354. name:
  16355. description: The name of the object located at the provider type.
  16356. maxLength: 253
  16357. minLength: 1
  16358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16359. type: string
  16360. namespace:
  16361. description: |-
  16362. The namespace the Provider type is in.
  16363. Can only be defined when used in a ClusterSecretStore.
  16364. maxLength: 63
  16365. minLength: 1
  16366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16367. type: string
  16368. type:
  16369. description: The type of provider to use such as "Secret", or "ConfigMap".
  16370. enum:
  16371. - Secret
  16372. - ConfigMap
  16373. type: string
  16374. required:
  16375. - name
  16376. - type
  16377. type: object
  16378. folderPath:
  16379. description: |-
  16380. FolderPath specifies the default folder path for secret retrieval.
  16381. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16382. Example: "production/database" or "dev/api-keys"
  16383. Leave empty to retrieve secrets from the root folder.
  16384. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16385. type: string
  16386. server:
  16387. description: |-
  16388. Server configures the BeyondTrust Workload Credentials server connection details.
  16389. Includes the API URL and Site ID for your BeyondTrust instance.
  16390. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16391. properties:
  16392. apiUrl:
  16393. description: |-
  16394. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16395. This should be the full URL to your BeyondTrust instance.
  16396. Example: https://api.beyondtrust.io/siie
  16397. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16398. type: string
  16399. siteId:
  16400. description: |-
  16401. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16402. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16403. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16404. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16405. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16406. type: string
  16407. required:
  16408. - apiUrl
  16409. - siteId
  16410. type: object
  16411. required:
  16412. - auth
  16413. - server
  16414. type: object
  16415. bitwardensecretsmanager:
  16416. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16417. properties:
  16418. apiURL:
  16419. type: string
  16420. auth:
  16421. description: |-
  16422. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16423. Make sure that the token being used has permissions on the given secret.
  16424. properties:
  16425. secretRef:
  16426. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16427. properties:
  16428. credentials:
  16429. description: AccessToken used for the bitwarden instance.
  16430. properties:
  16431. key:
  16432. description: |-
  16433. A key in the referenced Secret.
  16434. Some instances of this field may be defaulted, in others it may be required.
  16435. maxLength: 253
  16436. minLength: 1
  16437. pattern: ^[-._a-zA-Z0-9]+$
  16438. type: string
  16439. name:
  16440. description: The name of the Secret resource being referred to.
  16441. maxLength: 253
  16442. minLength: 1
  16443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16444. type: string
  16445. namespace:
  16446. description: |-
  16447. The namespace of the Secret resource being referred to.
  16448. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16449. maxLength: 63
  16450. minLength: 1
  16451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16452. type: string
  16453. type: object
  16454. required:
  16455. - credentials
  16456. type: object
  16457. required:
  16458. - secretRef
  16459. type: object
  16460. bitwardenServerSDKURL:
  16461. type: string
  16462. caBundle:
  16463. description: |-
  16464. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16465. can be performed.
  16466. type: string
  16467. caProvider:
  16468. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16469. properties:
  16470. key:
  16471. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16472. maxLength: 253
  16473. minLength: 1
  16474. pattern: ^[-._a-zA-Z0-9]+$
  16475. type: string
  16476. name:
  16477. description: The name of the object located at the provider type.
  16478. maxLength: 253
  16479. minLength: 1
  16480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16481. type: string
  16482. namespace:
  16483. description: |-
  16484. The namespace the Provider type is in.
  16485. Can only be defined when used in a ClusterSecretStore.
  16486. maxLength: 63
  16487. minLength: 1
  16488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16489. type: string
  16490. type:
  16491. description: The type of provider to use such as "Secret", or "ConfigMap".
  16492. enum:
  16493. - Secret
  16494. - ConfigMap
  16495. type: string
  16496. required:
  16497. - name
  16498. - type
  16499. type: object
  16500. identityURL:
  16501. type: string
  16502. organizationID:
  16503. description: OrganizationID determines which organization this secret store manages.
  16504. type: string
  16505. projectID:
  16506. description: ProjectID determines which project this secret store manages.
  16507. type: string
  16508. required:
  16509. - auth
  16510. - organizationID
  16511. - projectID
  16512. type: object
  16513. chef:
  16514. description: Chef configures this store to sync secrets with chef server
  16515. properties:
  16516. auth:
  16517. description: Auth defines the information necessary to authenticate against chef Server
  16518. properties:
  16519. secretRef:
  16520. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16521. properties:
  16522. privateKeySecretRef:
  16523. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16524. properties:
  16525. key:
  16526. description: |-
  16527. A key in the referenced Secret.
  16528. Some instances of this field may be defaulted, in others it may be required.
  16529. maxLength: 253
  16530. minLength: 1
  16531. pattern: ^[-._a-zA-Z0-9]+$
  16532. type: string
  16533. name:
  16534. description: The name of the Secret resource being referred to.
  16535. maxLength: 253
  16536. minLength: 1
  16537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16538. type: string
  16539. namespace:
  16540. description: |-
  16541. The namespace of the Secret resource being referred to.
  16542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16543. maxLength: 63
  16544. minLength: 1
  16545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16546. type: string
  16547. type: object
  16548. required:
  16549. - privateKeySecretRef
  16550. type: object
  16551. required:
  16552. - secretRef
  16553. type: object
  16554. serverUrl:
  16555. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16556. type: string
  16557. username:
  16558. description: UserName should be the user ID on the chef server
  16559. type: string
  16560. required:
  16561. - auth
  16562. - serverUrl
  16563. - username
  16564. type: object
  16565. cloudrusm:
  16566. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16567. properties:
  16568. auth:
  16569. description: CSMAuth contains a secretRef for credentials.
  16570. properties:
  16571. secretRef:
  16572. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16573. properties:
  16574. accessKeyIDSecretRef:
  16575. description: The AccessKeyID is used for authentication
  16576. properties:
  16577. key:
  16578. description: |-
  16579. A key in the referenced Secret.
  16580. Some instances of this field may be defaulted, in others it may be required.
  16581. maxLength: 253
  16582. minLength: 1
  16583. pattern: ^[-._a-zA-Z0-9]+$
  16584. type: string
  16585. name:
  16586. description: The name of the Secret resource being referred to.
  16587. maxLength: 253
  16588. minLength: 1
  16589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16590. type: string
  16591. namespace:
  16592. description: |-
  16593. The namespace of the Secret resource being referred to.
  16594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16595. maxLength: 63
  16596. minLength: 1
  16597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16598. type: string
  16599. type: object
  16600. accessKeySecretSecretRef:
  16601. description: The AccessKeySecret is used for authentication
  16602. properties:
  16603. key:
  16604. description: |-
  16605. A key in the referenced Secret.
  16606. Some instances of this field may be defaulted, in others it may be required.
  16607. maxLength: 253
  16608. minLength: 1
  16609. pattern: ^[-._a-zA-Z0-9]+$
  16610. type: string
  16611. name:
  16612. description: The name of the Secret resource being referred to.
  16613. maxLength: 253
  16614. minLength: 1
  16615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16616. type: string
  16617. namespace:
  16618. description: |-
  16619. The namespace of the Secret resource being referred to.
  16620. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16621. maxLength: 63
  16622. minLength: 1
  16623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16624. type: string
  16625. type: object
  16626. required:
  16627. - accessKeyIDSecretRef
  16628. - accessKeySecretSecretRef
  16629. type: object
  16630. type: object
  16631. projectID:
  16632. description: ProjectID is the project, which the secrets are stored in.
  16633. type: string
  16634. required:
  16635. - auth
  16636. type: object
  16637. conjur:
  16638. description: Conjur configures this store to sync secrets using conjur provider
  16639. properties:
  16640. auth:
  16641. description: Defines authentication settings for connecting to Conjur.
  16642. maxProperties: 1
  16643. minProperties: 1
  16644. properties:
  16645. apikey:
  16646. description: Authenticates with Conjur using an API key.
  16647. properties:
  16648. account:
  16649. description: Account is the Conjur organization account name.
  16650. type: string
  16651. apiKeyRef:
  16652. description: |-
  16653. A reference to a specific 'key' containing the Conjur API key
  16654. within a Secret resource. In some instances, `key` is a required field.
  16655. properties:
  16656. key:
  16657. description: |-
  16658. A key in the referenced Secret.
  16659. Some instances of this field may be defaulted, in others it may be required.
  16660. maxLength: 253
  16661. minLength: 1
  16662. pattern: ^[-._a-zA-Z0-9]+$
  16663. type: string
  16664. name:
  16665. description: The name of the Secret resource being referred to.
  16666. maxLength: 253
  16667. minLength: 1
  16668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16669. type: string
  16670. namespace:
  16671. description: |-
  16672. The namespace of the Secret resource being referred to.
  16673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16674. maxLength: 63
  16675. minLength: 1
  16676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16677. type: string
  16678. type: object
  16679. userRef:
  16680. description: |-
  16681. A reference to a specific 'key' containing the Conjur username
  16682. within a Secret resource. In some instances, `key` is a required field.
  16683. properties:
  16684. key:
  16685. description: |-
  16686. A key in the referenced Secret.
  16687. Some instances of this field may be defaulted, in others it may be required.
  16688. maxLength: 253
  16689. minLength: 1
  16690. pattern: ^[-._a-zA-Z0-9]+$
  16691. type: string
  16692. name:
  16693. description: The name of the Secret resource being referred to.
  16694. maxLength: 253
  16695. minLength: 1
  16696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16697. type: string
  16698. namespace:
  16699. description: |-
  16700. The namespace of the Secret resource being referred to.
  16701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16702. maxLength: 63
  16703. minLength: 1
  16704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16705. type: string
  16706. type: object
  16707. required:
  16708. - account
  16709. - apiKeyRef
  16710. - userRef
  16711. type: object
  16712. cert:
  16713. description: Cert enables certificate-based authentication using a client certificate and key.
  16714. properties:
  16715. account:
  16716. description: Account is the Conjur organization account name.
  16717. type: string
  16718. clientCertRef:
  16719. description: |-
  16720. ClientCertRef is a reference to a specific 'key' containing the client certificate
  16721. within a Secret resource. The certificate must be PEM-encoded.
  16722. properties:
  16723. key:
  16724. description: |-
  16725. A key in the referenced Secret.
  16726. Some instances of this field may be defaulted, in others it may be required.
  16727. maxLength: 253
  16728. minLength: 1
  16729. pattern: ^[-._a-zA-Z0-9]+$
  16730. type: string
  16731. name:
  16732. description: The name of the Secret resource being referred to.
  16733. maxLength: 253
  16734. minLength: 1
  16735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16736. type: string
  16737. namespace:
  16738. description: |-
  16739. The namespace of the Secret resource being referred to.
  16740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16741. maxLength: 63
  16742. minLength: 1
  16743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16744. type: string
  16745. type: object
  16746. clientKeyRef:
  16747. description: |-
  16748. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  16749. within a Secret resource. The key must be PEM-encoded.
  16750. properties:
  16751. key:
  16752. description: |-
  16753. A key in the referenced Secret.
  16754. Some instances of this field may be defaulted, in others it may be required.
  16755. maxLength: 253
  16756. minLength: 1
  16757. pattern: ^[-._a-zA-Z0-9]+$
  16758. type: string
  16759. name:
  16760. description: The name of the Secret resource being referred to.
  16761. maxLength: 253
  16762. minLength: 1
  16763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16764. type: string
  16765. namespace:
  16766. description: |-
  16767. The namespace of the Secret resource being referred to.
  16768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16769. maxLength: 63
  16770. minLength: 1
  16771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16772. type: string
  16773. type: object
  16774. hostId:
  16775. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  16776. type: string
  16777. serviceID:
  16778. description: The conjur authn cert webservice id
  16779. type: string
  16780. required:
  16781. - account
  16782. - clientCertRef
  16783. - clientKeyRef
  16784. - serviceID
  16785. type: object
  16786. jwt:
  16787. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  16788. properties:
  16789. account:
  16790. description: Account is the Conjur organization account name.
  16791. type: string
  16792. hostId:
  16793. description: |-
  16794. Optional HostID for JWT authentication. This may be used depending
  16795. on how the Conjur JWT authenticator policy is configured.
  16796. type: string
  16797. secretRef:
  16798. description: |-
  16799. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  16800. authenticate with Conjur using the JWT authentication method.
  16801. properties:
  16802. key:
  16803. description: |-
  16804. A key in the referenced Secret.
  16805. Some instances of this field may be defaulted, in others it may be required.
  16806. maxLength: 253
  16807. minLength: 1
  16808. pattern: ^[-._a-zA-Z0-9]+$
  16809. type: string
  16810. name:
  16811. description: The name of the Secret resource being referred to.
  16812. maxLength: 253
  16813. minLength: 1
  16814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16815. type: string
  16816. namespace:
  16817. description: |-
  16818. The namespace of the Secret resource being referred to.
  16819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16820. maxLength: 63
  16821. minLength: 1
  16822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16823. type: string
  16824. type: object
  16825. serviceAccountRef:
  16826. description: |-
  16827. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  16828. a token for with the `TokenRequest` API.
  16829. properties:
  16830. audiences:
  16831. description: |-
  16832. Audience specifies the `aud` claim for the service account token
  16833. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16834. then this audiences will be appended to the list
  16835. items:
  16836. type: string
  16837. type: array
  16838. name:
  16839. description: The name of the ServiceAccount resource being referred to.
  16840. maxLength: 253
  16841. minLength: 1
  16842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16843. type: string
  16844. namespace:
  16845. description: |-
  16846. Namespace of the resource being referred to.
  16847. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16848. maxLength: 63
  16849. minLength: 1
  16850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16851. type: string
  16852. required:
  16853. - name
  16854. type: object
  16855. serviceID:
  16856. description: The conjur authn jwt webservice id
  16857. type: string
  16858. required:
  16859. - account
  16860. - serviceID
  16861. type: object
  16862. type: object
  16863. caBundle:
  16864. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  16865. type: string
  16866. caProvider:
  16867. description: |-
  16868. Used to provide custom certificate authority (CA) certificates
  16869. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  16870. that contains a PEM-encoded certificate.
  16871. properties:
  16872. key:
  16873. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16874. maxLength: 253
  16875. minLength: 1
  16876. pattern: ^[-._a-zA-Z0-9]+$
  16877. type: string
  16878. name:
  16879. description: The name of the object located at the provider type.
  16880. maxLength: 253
  16881. minLength: 1
  16882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16883. type: string
  16884. namespace:
  16885. description: |-
  16886. The namespace the Provider type is in.
  16887. Can only be defined when used in a ClusterSecretStore.
  16888. maxLength: 63
  16889. minLength: 1
  16890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16891. type: string
  16892. type:
  16893. description: The type of provider to use such as "Secret", or "ConfigMap".
  16894. enum:
  16895. - Secret
  16896. - ConfigMap
  16897. type: string
  16898. required:
  16899. - name
  16900. - type
  16901. type: object
  16902. url:
  16903. description: URL is the endpoint of the Conjur instance.
  16904. type: string
  16905. required:
  16906. - auth
  16907. - url
  16908. type: object
  16909. delinea:
  16910. description: |-
  16911. Delinea DevOps Secrets Vault
  16912. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  16913. properties:
  16914. clientId:
  16915. description: ClientID is the non-secret part of the credential.
  16916. properties:
  16917. secretRef:
  16918. description: SecretRef references a key in a secret that will be used as value.
  16919. properties:
  16920. key:
  16921. description: |-
  16922. A key in the referenced Secret.
  16923. Some instances of this field may be defaulted, in others it may be required.
  16924. maxLength: 253
  16925. minLength: 1
  16926. pattern: ^[-._a-zA-Z0-9]+$
  16927. type: string
  16928. name:
  16929. description: The name of the Secret resource being referred to.
  16930. maxLength: 253
  16931. minLength: 1
  16932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16933. type: string
  16934. namespace:
  16935. description: |-
  16936. The namespace of the Secret resource being referred to.
  16937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16938. maxLength: 63
  16939. minLength: 1
  16940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16941. type: string
  16942. type: object
  16943. value:
  16944. description: Value can be specified directly to set a value without using a secret.
  16945. type: string
  16946. type: object
  16947. clientSecret:
  16948. description: ClientSecret is the secret part of the credential.
  16949. properties:
  16950. secretRef:
  16951. description: SecretRef references a key in a secret that will be used as value.
  16952. properties:
  16953. key:
  16954. description: |-
  16955. A key in the referenced Secret.
  16956. Some instances of this field may be defaulted, in others it may be required.
  16957. maxLength: 253
  16958. minLength: 1
  16959. pattern: ^[-._a-zA-Z0-9]+$
  16960. type: string
  16961. name:
  16962. description: The name of the Secret resource being referred to.
  16963. maxLength: 253
  16964. minLength: 1
  16965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16966. type: string
  16967. namespace:
  16968. description: |-
  16969. The namespace of the Secret resource being referred to.
  16970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16971. maxLength: 63
  16972. minLength: 1
  16973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16974. type: string
  16975. type: object
  16976. value:
  16977. description: Value can be specified directly to set a value without using a secret.
  16978. type: string
  16979. type: object
  16980. tenant:
  16981. description: Tenant is the chosen hostname / site name.
  16982. type: string
  16983. tld:
  16984. description: |-
  16985. TLD is based on the server location that was chosen during provisioning.
  16986. If unset, defaults to "com".
  16987. type: string
  16988. urlTemplate:
  16989. description: |-
  16990. URLTemplate
  16991. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  16992. type: string
  16993. required:
  16994. - clientId
  16995. - clientSecret
  16996. - tenant
  16997. type: object
  16998. doppler:
  16999. description: Doppler configures this store to sync secrets using the Doppler provider
  17000. properties:
  17001. auth:
  17002. description: Auth configures how the Operator authenticates with the Doppler API
  17003. properties:
  17004. oidcConfig:
  17005. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17006. properties:
  17007. expirationSeconds:
  17008. default: 600
  17009. description: |-
  17010. ExpirationSeconds sets the ServiceAccount token validity duration.
  17011. Defaults to 10 minutes.
  17012. format: int64
  17013. type: integer
  17014. identity:
  17015. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17016. type: string
  17017. serviceAccountRef:
  17018. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17019. properties:
  17020. audiences:
  17021. description: |-
  17022. Audience specifies the `aud` claim for the service account token
  17023. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17024. then this audiences will be appended to the list
  17025. items:
  17026. type: string
  17027. type: array
  17028. name:
  17029. description: The name of the ServiceAccount resource being referred to.
  17030. maxLength: 253
  17031. minLength: 1
  17032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17033. type: string
  17034. namespace:
  17035. description: |-
  17036. Namespace of the resource being referred to.
  17037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17038. maxLength: 63
  17039. minLength: 1
  17040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17041. type: string
  17042. required:
  17043. - name
  17044. type: object
  17045. required:
  17046. - identity
  17047. - serviceAccountRef
  17048. type: object
  17049. secretRef:
  17050. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17051. properties:
  17052. dopplerToken:
  17053. description: |-
  17054. The DopplerToken is used for authentication.
  17055. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17056. The Key attribute defaults to dopplerToken if not specified.
  17057. properties:
  17058. key:
  17059. description: |-
  17060. A key in the referenced Secret.
  17061. Some instances of this field may be defaulted, in others it may be required.
  17062. maxLength: 253
  17063. minLength: 1
  17064. pattern: ^[-._a-zA-Z0-9]+$
  17065. type: string
  17066. name:
  17067. description: The name of the Secret resource being referred to.
  17068. maxLength: 253
  17069. minLength: 1
  17070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17071. type: string
  17072. namespace:
  17073. description: |-
  17074. The namespace of the Secret resource being referred to.
  17075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17076. maxLength: 63
  17077. minLength: 1
  17078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17079. type: string
  17080. type: object
  17081. required:
  17082. - dopplerToken
  17083. type: object
  17084. type: object
  17085. x-kubernetes-validations:
  17086. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17087. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17088. config:
  17089. description: Doppler config (required if not using a Service Token)
  17090. type: string
  17091. format:
  17092. description: Format enables the downloading of secrets as a file (string)
  17093. enum:
  17094. - json
  17095. - dotnet-json
  17096. - env
  17097. - yaml
  17098. - docker
  17099. type: string
  17100. nameTransformer:
  17101. description: Environment variable compatible name transforms that change secret names to a different format
  17102. enum:
  17103. - upper-camel
  17104. - camel
  17105. - lower-snake
  17106. - tf-var
  17107. - dotnet-env
  17108. - lower-kebab
  17109. type: string
  17110. project:
  17111. description: Doppler project (required if not using a Service Token)
  17112. type: string
  17113. required:
  17114. - auth
  17115. type: object
  17116. dvls:
  17117. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17118. properties:
  17119. auth:
  17120. description: Auth defines the authentication method to use.
  17121. properties:
  17122. secretRef:
  17123. description: SecretRef contains the Application ID and Application Secret for authentication.
  17124. properties:
  17125. appId:
  17126. description: AppID is the reference to the secret containing the Application ID.
  17127. properties:
  17128. key:
  17129. description: |-
  17130. A key in the referenced Secret.
  17131. Some instances of this field may be defaulted, in others it may be required.
  17132. maxLength: 253
  17133. minLength: 1
  17134. pattern: ^[-._a-zA-Z0-9]+$
  17135. type: string
  17136. name:
  17137. description: The name of the Secret resource being referred to.
  17138. maxLength: 253
  17139. minLength: 1
  17140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17141. type: string
  17142. namespace:
  17143. description: |-
  17144. The namespace of the Secret resource being referred to.
  17145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17146. maxLength: 63
  17147. minLength: 1
  17148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17149. type: string
  17150. type: object
  17151. appSecret:
  17152. description: AppSecret is the reference to the secret containing the Application Secret.
  17153. properties:
  17154. key:
  17155. description: |-
  17156. A key in the referenced Secret.
  17157. Some instances of this field may be defaulted, in others it may be required.
  17158. maxLength: 253
  17159. minLength: 1
  17160. pattern: ^[-._a-zA-Z0-9]+$
  17161. type: string
  17162. name:
  17163. description: The name of the Secret resource being referred to.
  17164. maxLength: 253
  17165. minLength: 1
  17166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17167. type: string
  17168. namespace:
  17169. description: |-
  17170. The namespace of the Secret resource being referred to.
  17171. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17172. maxLength: 63
  17173. minLength: 1
  17174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17175. type: string
  17176. type: object
  17177. required:
  17178. - appId
  17179. - appSecret
  17180. type: object
  17181. required:
  17182. - secretRef
  17183. type: object
  17184. insecure:
  17185. description: |-
  17186. Insecure allows connecting to DVLS over plain HTTP.
  17187. This is NOT RECOMMENDED for production use.
  17188. Set to true only if you understand the security implications.
  17189. type: boolean
  17190. serverUrl:
  17191. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17192. type: string
  17193. vault:
  17194. description: |-
  17195. Vault is the name or UUID of the vault to fetch secrets from.
  17196. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17197. type: string
  17198. required:
  17199. - auth
  17200. - serverUrl
  17201. type: object
  17202. fake:
  17203. description: Fake configures a store with static key/value pairs
  17204. properties:
  17205. data:
  17206. items:
  17207. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17208. properties:
  17209. key:
  17210. type: string
  17211. value:
  17212. type: string
  17213. version:
  17214. type: string
  17215. required:
  17216. - key
  17217. - value
  17218. type: object
  17219. type: array
  17220. validationResult:
  17221. description: ValidationResult is defined type for the number of validation results.
  17222. type: integer
  17223. required:
  17224. - data
  17225. type: object
  17226. fortanix:
  17227. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17228. properties:
  17229. apiKey:
  17230. description: APIKey is the API token to access SDKMS Applications.
  17231. properties:
  17232. secretRef:
  17233. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17234. properties:
  17235. key:
  17236. description: |-
  17237. A key in the referenced Secret.
  17238. Some instances of this field may be defaulted, in others it may be required.
  17239. maxLength: 253
  17240. minLength: 1
  17241. pattern: ^[-._a-zA-Z0-9]+$
  17242. type: string
  17243. name:
  17244. description: The name of the Secret resource being referred to.
  17245. maxLength: 253
  17246. minLength: 1
  17247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17248. type: string
  17249. namespace:
  17250. description: |-
  17251. The namespace of the Secret resource being referred to.
  17252. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17253. maxLength: 63
  17254. minLength: 1
  17255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17256. type: string
  17257. type: object
  17258. type: object
  17259. apiUrl:
  17260. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17261. type: string
  17262. type: object
  17263. gcpsm:
  17264. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17265. properties:
  17266. auth:
  17267. description: Auth defines the information necessary to authenticate against GCP
  17268. properties:
  17269. secretRef:
  17270. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17271. properties:
  17272. secretAccessKeySecretRef:
  17273. description: The SecretAccessKey is used for authentication
  17274. properties:
  17275. key:
  17276. description: |-
  17277. A key in the referenced Secret.
  17278. Some instances of this field may be defaulted, in others it may be required.
  17279. maxLength: 253
  17280. minLength: 1
  17281. pattern: ^[-._a-zA-Z0-9]+$
  17282. type: string
  17283. name:
  17284. description: The name of the Secret resource being referred to.
  17285. maxLength: 253
  17286. minLength: 1
  17287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17288. type: string
  17289. namespace:
  17290. description: |-
  17291. The namespace of the Secret resource being referred to.
  17292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17293. maxLength: 63
  17294. minLength: 1
  17295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17296. type: string
  17297. type: object
  17298. type: object
  17299. workloadIdentity:
  17300. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17301. properties:
  17302. clusterLocation:
  17303. description: |-
  17304. ClusterLocation is the location of the cluster
  17305. If not specified, it fetches information from the metadata server
  17306. type: string
  17307. clusterName:
  17308. description: |-
  17309. ClusterName is the name of the cluster
  17310. If not specified, it fetches information from the metadata server
  17311. type: string
  17312. clusterProjectID:
  17313. description: |-
  17314. ClusterProjectID is the project ID of the cluster
  17315. If not specified, it fetches information from the metadata server
  17316. type: string
  17317. serviceAccountRef:
  17318. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17319. properties:
  17320. audiences:
  17321. description: |-
  17322. Audience specifies the `aud` claim for the service account token
  17323. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17324. then this audiences will be appended to the list
  17325. items:
  17326. type: string
  17327. type: array
  17328. name:
  17329. description: The name of the ServiceAccount resource being referred to.
  17330. maxLength: 253
  17331. minLength: 1
  17332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17333. type: string
  17334. namespace:
  17335. description: |-
  17336. Namespace of the resource being referred to.
  17337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17338. maxLength: 63
  17339. minLength: 1
  17340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17341. type: string
  17342. required:
  17343. - name
  17344. type: object
  17345. required:
  17346. - serviceAccountRef
  17347. type: object
  17348. workloadIdentityFederation:
  17349. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17350. properties:
  17351. audience:
  17352. description: |-
  17353. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17354. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17355. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17356. type: string
  17357. awsSecurityCredentials:
  17358. description: |-
  17359. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  17360. when using the AWS metadata server is not an option.
  17361. properties:
  17362. awsCredentialsSecretRef:
  17363. description: |-
  17364. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  17365. Secret should be created with below names for keys
  17366. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  17367. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  17368. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  17369. properties:
  17370. name:
  17371. description: name of the secret.
  17372. maxLength: 253
  17373. minLength: 1
  17374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17375. type: string
  17376. namespace:
  17377. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  17378. maxLength: 63
  17379. minLength: 1
  17380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17381. type: string
  17382. required:
  17383. - name
  17384. type: object
  17385. region:
  17386. description: region is for configuring the AWS region to be used.
  17387. example: ap-south-1
  17388. maxLength: 50
  17389. minLength: 1
  17390. pattern: ^[a-z0-9-]+$
  17391. type: string
  17392. required:
  17393. - awsCredentialsSecretRef
  17394. - region
  17395. type: object
  17396. credConfig:
  17397. description: |-
  17398. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  17399. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  17400. serviceAccountRef must be used by providing operators service account details.
  17401. properties:
  17402. key:
  17403. description: key name holding the external account credential config.
  17404. maxLength: 253
  17405. minLength: 1
  17406. pattern: ^[-._a-zA-Z0-9]+$
  17407. type: string
  17408. name:
  17409. description: name of the configmap.
  17410. maxLength: 253
  17411. minLength: 1
  17412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17413. type: string
  17414. namespace:
  17415. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  17416. maxLength: 63
  17417. minLength: 1
  17418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17419. type: string
  17420. required:
  17421. - key
  17422. - name
  17423. type: object
  17424. externalTokenEndpoint:
  17425. description: |-
  17426. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  17427. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  17428. URL is having the expected value.
  17429. type: string
  17430. gcpServiceAccountEmail:
  17431. description: |-
  17432. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  17433. after Workload Identity Federation. Use this to grant access through the service account's
  17434. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  17435. service_account_impersonation_url in the external account JSON from credConfig;
  17436. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  17437. on that ServiceAccount.
  17438. example: my-gsa@my-project.iam.gserviceaccount.com
  17439. minLength: 1
  17440. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  17441. type: string
  17442. serviceAccountRef:
  17443. description: |-
  17444. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  17445. when Kubernetes is configured as provider in workload identity pool.
  17446. properties:
  17447. audiences:
  17448. description: |-
  17449. Audience specifies the `aud` claim for the service account token
  17450. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17451. then this audiences will be appended to the list
  17452. items:
  17453. type: string
  17454. type: array
  17455. name:
  17456. description: The name of the ServiceAccount resource being referred to.
  17457. maxLength: 253
  17458. minLength: 1
  17459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17460. type: string
  17461. namespace:
  17462. description: |-
  17463. Namespace of the resource being referred to.
  17464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17465. maxLength: 63
  17466. minLength: 1
  17467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17468. type: string
  17469. required:
  17470. - name
  17471. type: object
  17472. type: object
  17473. type: object
  17474. location:
  17475. description: Location optionally defines a location for a secret
  17476. type: string
  17477. projectID:
  17478. description: ProjectID project where secret is located
  17479. type: string
  17480. secretVersionSelectionPolicy:
  17481. default: LatestOrFail
  17482. description: |-
  17483. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  17484. when "latest" is disabled or destroyed.
  17485. Possible values are:
  17486. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  17487. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  17488. type: string
  17489. type: object
  17490. github:
  17491. description: |-
  17492. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  17493. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  17494. properties:
  17495. appID:
  17496. description: appID specifies the Github APP that will be used to authenticate the client
  17497. format: int64
  17498. type: integer
  17499. auth:
  17500. description: auth configures how secret-manager authenticates with a Github instance.
  17501. properties:
  17502. privateKey:
  17503. description: |-
  17504. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17505. In some instances, `key` is a required field.
  17506. properties:
  17507. key:
  17508. description: |-
  17509. A key in the referenced Secret.
  17510. Some instances of this field may be defaulted, in others it may be required.
  17511. maxLength: 253
  17512. minLength: 1
  17513. pattern: ^[-._a-zA-Z0-9]+$
  17514. type: string
  17515. name:
  17516. description: The name of the Secret resource being referred to.
  17517. maxLength: 253
  17518. minLength: 1
  17519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17520. type: string
  17521. namespace:
  17522. description: |-
  17523. The namespace of the Secret resource being referred to.
  17524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17525. maxLength: 63
  17526. minLength: 1
  17527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17528. type: string
  17529. type: object
  17530. required:
  17531. - privateKey
  17532. type: object
  17533. environment:
  17534. description: environment will be used to fetch secrets from a particular environment within a github repository
  17535. type: string
  17536. installationID:
  17537. description: installationID specifies the Github APP installation that will be used to authenticate the client
  17538. format: int64
  17539. type: integer
  17540. orgSecretVisibility:
  17541. description: |-
  17542. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  17543. Valid values are "all" or "private".
  17544. When unset, new secrets are created with visibility "all" and existing secrets preserve
  17545. whatever visibility they already have in GitHub.
  17546. enum:
  17547. - all
  17548. - private
  17549. type: string
  17550. organization:
  17551. description: organization will be used to fetch secrets from the Github organization
  17552. type: string
  17553. repository:
  17554. description: repository will be used to fetch secrets from the Github repository within an organization
  17555. type: string
  17556. uploadURL:
  17557. description: Upload URL for enterprise instances. Default to URL.
  17558. type: string
  17559. url:
  17560. default: https://github.com/
  17561. description: URL configures the Github instance URL. Defaults to https://github.com/.
  17562. type: string
  17563. required:
  17564. - appID
  17565. - auth
  17566. - installationID
  17567. - organization
  17568. type: object
  17569. gitlab:
  17570. description: GitLab configures this store to sync secrets using GitLab Variables provider
  17571. properties:
  17572. auth:
  17573. description: Auth configures how secret-manager authenticates with a GitLab instance.
  17574. properties:
  17575. SecretRef:
  17576. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  17577. properties:
  17578. accessToken:
  17579. description: AccessToken is used for authentication.
  17580. properties:
  17581. key:
  17582. description: |-
  17583. A key in the referenced Secret.
  17584. Some instances of this field may be defaulted, in others it may be required.
  17585. maxLength: 253
  17586. minLength: 1
  17587. pattern: ^[-._a-zA-Z0-9]+$
  17588. type: string
  17589. name:
  17590. description: The name of the Secret resource being referred to.
  17591. maxLength: 253
  17592. minLength: 1
  17593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17594. type: string
  17595. namespace:
  17596. description: |-
  17597. The namespace of the Secret resource being referred to.
  17598. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17599. maxLength: 63
  17600. minLength: 1
  17601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17602. type: string
  17603. type: object
  17604. type: object
  17605. required:
  17606. - SecretRef
  17607. type: object
  17608. caBundle:
  17609. description: |-
  17610. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  17611. can be performed.
  17612. format: byte
  17613. type: string
  17614. caProvider:
  17615. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17616. properties:
  17617. key:
  17618. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17619. maxLength: 253
  17620. minLength: 1
  17621. pattern: ^[-._a-zA-Z0-9]+$
  17622. type: string
  17623. name:
  17624. description: The name of the object located at the provider type.
  17625. maxLength: 253
  17626. minLength: 1
  17627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17628. type: string
  17629. namespace:
  17630. description: |-
  17631. The namespace the Provider type is in.
  17632. Can only be defined when used in a ClusterSecretStore.
  17633. maxLength: 63
  17634. minLength: 1
  17635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17636. type: string
  17637. type:
  17638. description: The type of provider to use such as "Secret", or "ConfigMap".
  17639. enum:
  17640. - Secret
  17641. - ConfigMap
  17642. type: string
  17643. required:
  17644. - name
  17645. - type
  17646. type: object
  17647. environment:
  17648. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  17649. type: string
  17650. groupIDs:
  17651. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  17652. items:
  17653. type: string
  17654. type: array
  17655. inheritFromGroups:
  17656. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  17657. type: boolean
  17658. projectID:
  17659. description: ProjectID specifies a project where secrets are located.
  17660. type: string
  17661. url:
  17662. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  17663. type: string
  17664. required:
  17665. - auth
  17666. type: object
  17667. ibm:
  17668. description: IBM configures this store to sync secrets using IBM Cloud provider
  17669. properties:
  17670. auth:
  17671. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  17672. maxProperties: 1
  17673. minProperties: 1
  17674. properties:
  17675. containerAuth:
  17676. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  17677. properties:
  17678. iamEndpoint:
  17679. type: string
  17680. profile:
  17681. description: the IBM Trusted Profile
  17682. type: string
  17683. tokenLocation:
  17684. description: Location the token is mounted on the pod
  17685. type: string
  17686. required:
  17687. - profile
  17688. type: object
  17689. secretRef:
  17690. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  17691. properties:
  17692. iamEndpoint:
  17693. description: The IAM endpoint used to obain a token
  17694. type: string
  17695. secretApiKeySecretRef:
  17696. description: The SecretAccessKey is used for authentication
  17697. properties:
  17698. key:
  17699. description: |-
  17700. A key in the referenced Secret.
  17701. Some instances of this field may be defaulted, in others it may be required.
  17702. maxLength: 253
  17703. minLength: 1
  17704. pattern: ^[-._a-zA-Z0-9]+$
  17705. type: string
  17706. name:
  17707. description: The name of the Secret resource being referred to.
  17708. maxLength: 253
  17709. minLength: 1
  17710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17711. type: string
  17712. namespace:
  17713. description: |-
  17714. The namespace of the Secret resource being referred to.
  17715. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17716. maxLength: 63
  17717. minLength: 1
  17718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17719. type: string
  17720. type: object
  17721. type: object
  17722. type: object
  17723. serviceUrl:
  17724. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  17725. type: string
  17726. required:
  17727. - auth
  17728. type: object
  17729. infisical:
  17730. description: Infisical configures this store to sync secrets using the Infisical provider
  17731. properties:
  17732. auth:
  17733. description: Auth configures how the Operator authenticates with the Infisical API
  17734. properties:
  17735. awsAuthCredentials:
  17736. description: AwsAuthCredentials represents the credentials for AWS authentication.
  17737. properties:
  17738. identityId:
  17739. description: |-
  17740. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17741. In some instances, `key` is a required field.
  17742. properties:
  17743. key:
  17744. description: |-
  17745. A key in the referenced Secret.
  17746. Some instances of this field may be defaulted, in others it may be required.
  17747. maxLength: 253
  17748. minLength: 1
  17749. pattern: ^[-._a-zA-Z0-9]+$
  17750. type: string
  17751. name:
  17752. description: The name of the Secret resource being referred to.
  17753. maxLength: 253
  17754. minLength: 1
  17755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17756. type: string
  17757. namespace:
  17758. description: |-
  17759. The namespace of the Secret resource being referred to.
  17760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17761. maxLength: 63
  17762. minLength: 1
  17763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17764. type: string
  17765. type: object
  17766. required:
  17767. - identityId
  17768. type: object
  17769. azureAuthCredentials:
  17770. description: AzureAuthCredentials represents the credentials for Azure authentication.
  17771. properties:
  17772. identityId:
  17773. description: |-
  17774. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17775. In some instances, `key` is a required field.
  17776. properties:
  17777. key:
  17778. description: |-
  17779. A key in the referenced Secret.
  17780. Some instances of this field may be defaulted, in others it may be required.
  17781. maxLength: 253
  17782. minLength: 1
  17783. pattern: ^[-._a-zA-Z0-9]+$
  17784. type: string
  17785. name:
  17786. description: The name of the Secret resource being referred to.
  17787. maxLength: 253
  17788. minLength: 1
  17789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17790. type: string
  17791. namespace:
  17792. description: |-
  17793. The namespace of the Secret resource being referred to.
  17794. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17795. maxLength: 63
  17796. minLength: 1
  17797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17798. type: string
  17799. type: object
  17800. resource:
  17801. description: |-
  17802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17803. In some instances, `key` is a required field.
  17804. properties:
  17805. key:
  17806. description: |-
  17807. A key in the referenced Secret.
  17808. Some instances of this field may be defaulted, in others it may be required.
  17809. maxLength: 253
  17810. minLength: 1
  17811. pattern: ^[-._a-zA-Z0-9]+$
  17812. type: string
  17813. name:
  17814. description: The name of the Secret resource being referred to.
  17815. maxLength: 253
  17816. minLength: 1
  17817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17818. type: string
  17819. namespace:
  17820. description: |-
  17821. The namespace of the Secret resource being referred to.
  17822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17823. maxLength: 63
  17824. minLength: 1
  17825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17826. type: string
  17827. type: object
  17828. required:
  17829. - identityId
  17830. type: object
  17831. gcpIamAuthCredentials:
  17832. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  17833. properties:
  17834. identityId:
  17835. description: |-
  17836. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17837. In some instances, `key` is a required field.
  17838. properties:
  17839. key:
  17840. description: |-
  17841. A key in the referenced Secret.
  17842. Some instances of this field may be defaulted, in others it may be required.
  17843. maxLength: 253
  17844. minLength: 1
  17845. pattern: ^[-._a-zA-Z0-9]+$
  17846. type: string
  17847. name:
  17848. description: The name of the Secret resource being referred to.
  17849. maxLength: 253
  17850. minLength: 1
  17851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17852. type: string
  17853. namespace:
  17854. description: |-
  17855. The namespace of the Secret resource being referred to.
  17856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17857. maxLength: 63
  17858. minLength: 1
  17859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17860. type: string
  17861. type: object
  17862. serviceAccountKeyFilePath:
  17863. description: |-
  17864. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17865. In some instances, `key` is a required field.
  17866. properties:
  17867. key:
  17868. description: |-
  17869. A key in the referenced Secret.
  17870. Some instances of this field may be defaulted, in others it may be required.
  17871. maxLength: 253
  17872. minLength: 1
  17873. pattern: ^[-._a-zA-Z0-9]+$
  17874. type: string
  17875. name:
  17876. description: The name of the Secret resource being referred to.
  17877. maxLength: 253
  17878. minLength: 1
  17879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17880. type: string
  17881. namespace:
  17882. description: |-
  17883. The namespace of the Secret resource being referred to.
  17884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17885. maxLength: 63
  17886. minLength: 1
  17887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17888. type: string
  17889. type: object
  17890. required:
  17891. - identityId
  17892. - serviceAccountKeyFilePath
  17893. type: object
  17894. gcpIdTokenAuthCredentials:
  17895. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  17896. properties:
  17897. identityId:
  17898. description: |-
  17899. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17900. In some instances, `key` is a required field.
  17901. properties:
  17902. key:
  17903. description: |-
  17904. A key in the referenced Secret.
  17905. Some instances of this field may be defaulted, in others it may be required.
  17906. maxLength: 253
  17907. minLength: 1
  17908. pattern: ^[-._a-zA-Z0-9]+$
  17909. type: string
  17910. name:
  17911. description: The name of the Secret resource being referred to.
  17912. maxLength: 253
  17913. minLength: 1
  17914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17915. type: string
  17916. namespace:
  17917. description: |-
  17918. The namespace of the Secret resource being referred to.
  17919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17920. maxLength: 63
  17921. minLength: 1
  17922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17923. type: string
  17924. type: object
  17925. required:
  17926. - identityId
  17927. type: object
  17928. jwtAuthCredentials:
  17929. description: JwtAuthCredentials represents the credentials for JWT authentication.
  17930. properties:
  17931. identityId:
  17932. description: |-
  17933. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17934. In some instances, `key` is a required field.
  17935. properties:
  17936. key:
  17937. description: |-
  17938. A key in the referenced Secret.
  17939. Some instances of this field may be defaulted, in others it may be required.
  17940. maxLength: 253
  17941. minLength: 1
  17942. pattern: ^[-._a-zA-Z0-9]+$
  17943. type: string
  17944. name:
  17945. description: The name of the Secret resource being referred to.
  17946. maxLength: 253
  17947. minLength: 1
  17948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17949. type: string
  17950. namespace:
  17951. description: |-
  17952. The namespace of the Secret resource being referred to.
  17953. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17954. maxLength: 63
  17955. minLength: 1
  17956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17957. type: string
  17958. type: object
  17959. jwt:
  17960. description: |-
  17961. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17962. In some instances, `key` is a required field.
  17963. properties:
  17964. key:
  17965. description: |-
  17966. A key in the referenced Secret.
  17967. Some instances of this field may be defaulted, in others it may be required.
  17968. maxLength: 253
  17969. minLength: 1
  17970. pattern: ^[-._a-zA-Z0-9]+$
  17971. type: string
  17972. name:
  17973. description: The name of the Secret resource being referred to.
  17974. maxLength: 253
  17975. minLength: 1
  17976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17977. type: string
  17978. namespace:
  17979. description: |-
  17980. The namespace of the Secret resource being referred to.
  17981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17982. maxLength: 63
  17983. minLength: 1
  17984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17985. type: string
  17986. type: object
  17987. required:
  17988. - identityId
  17989. - jwt
  17990. type: object
  17991. kubernetesAuthCredentials:
  17992. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  17993. properties:
  17994. identityId:
  17995. description: |-
  17996. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17997. In some instances, `key` is a required field.
  17998. properties:
  17999. key:
  18000. description: |-
  18001. A key in the referenced Secret.
  18002. Some instances of this field may be defaulted, in others it may be required.
  18003. maxLength: 253
  18004. minLength: 1
  18005. pattern: ^[-._a-zA-Z0-9]+$
  18006. type: string
  18007. name:
  18008. description: The name of the Secret resource being referred to.
  18009. maxLength: 253
  18010. minLength: 1
  18011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18012. type: string
  18013. namespace:
  18014. description: |-
  18015. The namespace of the Secret resource being referred to.
  18016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18017. maxLength: 63
  18018. minLength: 1
  18019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18020. type: string
  18021. type: object
  18022. serviceAccountTokenPath:
  18023. description: |-
  18024. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18025. In some instances, `key` is a required field.
  18026. properties:
  18027. key:
  18028. description: |-
  18029. A key in the referenced Secret.
  18030. Some instances of this field may be defaulted, in others it may be required.
  18031. maxLength: 253
  18032. minLength: 1
  18033. pattern: ^[-._a-zA-Z0-9]+$
  18034. type: string
  18035. name:
  18036. description: The name of the Secret resource being referred to.
  18037. maxLength: 253
  18038. minLength: 1
  18039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18040. type: string
  18041. namespace:
  18042. description: |-
  18043. The namespace of the Secret resource being referred to.
  18044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18045. maxLength: 63
  18046. minLength: 1
  18047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18048. type: string
  18049. type: object
  18050. required:
  18051. - identityId
  18052. type: object
  18053. ldapAuthCredentials:
  18054. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18055. properties:
  18056. identityId:
  18057. description: |-
  18058. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18059. In some instances, `key` is a required field.
  18060. properties:
  18061. key:
  18062. description: |-
  18063. A key in the referenced Secret.
  18064. Some instances of this field may be defaulted, in others it may be required.
  18065. maxLength: 253
  18066. minLength: 1
  18067. pattern: ^[-._a-zA-Z0-9]+$
  18068. type: string
  18069. name:
  18070. description: The name of the Secret resource being referred to.
  18071. maxLength: 253
  18072. minLength: 1
  18073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18074. type: string
  18075. namespace:
  18076. description: |-
  18077. The namespace of the Secret resource being referred to.
  18078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18079. maxLength: 63
  18080. minLength: 1
  18081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18082. type: string
  18083. type: object
  18084. ldapPassword:
  18085. description: |-
  18086. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18087. In some instances, `key` is a required field.
  18088. properties:
  18089. key:
  18090. description: |-
  18091. A key in the referenced Secret.
  18092. Some instances of this field may be defaulted, in others it may be required.
  18093. maxLength: 253
  18094. minLength: 1
  18095. pattern: ^[-._a-zA-Z0-9]+$
  18096. type: string
  18097. name:
  18098. description: The name of the Secret resource being referred to.
  18099. maxLength: 253
  18100. minLength: 1
  18101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18102. type: string
  18103. namespace:
  18104. description: |-
  18105. The namespace of the Secret resource being referred to.
  18106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18107. maxLength: 63
  18108. minLength: 1
  18109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18110. type: string
  18111. type: object
  18112. ldapUsername:
  18113. description: |-
  18114. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18115. In some instances, `key` is a required field.
  18116. properties:
  18117. key:
  18118. description: |-
  18119. A key in the referenced Secret.
  18120. Some instances of this field may be defaulted, in others it may be required.
  18121. maxLength: 253
  18122. minLength: 1
  18123. pattern: ^[-._a-zA-Z0-9]+$
  18124. type: string
  18125. name:
  18126. description: The name of the Secret resource being referred to.
  18127. maxLength: 253
  18128. minLength: 1
  18129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18130. type: string
  18131. namespace:
  18132. description: |-
  18133. The namespace of the Secret resource being referred to.
  18134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18135. maxLength: 63
  18136. minLength: 1
  18137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18138. type: string
  18139. type: object
  18140. required:
  18141. - identityId
  18142. - ldapPassword
  18143. - ldapUsername
  18144. type: object
  18145. ociAuthCredentials:
  18146. description: OciAuthCredentials represents the credentials for OCI authentication.
  18147. properties:
  18148. fingerprint:
  18149. description: |-
  18150. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18151. In some instances, `key` is a required field.
  18152. properties:
  18153. key:
  18154. description: |-
  18155. A key in the referenced Secret.
  18156. Some instances of this field may be defaulted, in others it may be required.
  18157. maxLength: 253
  18158. minLength: 1
  18159. pattern: ^[-._a-zA-Z0-9]+$
  18160. type: string
  18161. name:
  18162. description: The name of the Secret resource being referred to.
  18163. maxLength: 253
  18164. minLength: 1
  18165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18166. type: string
  18167. namespace:
  18168. description: |-
  18169. The namespace of the Secret resource being referred to.
  18170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18171. maxLength: 63
  18172. minLength: 1
  18173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18174. type: string
  18175. type: object
  18176. identityId:
  18177. description: |-
  18178. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18179. In some instances, `key` is a required field.
  18180. properties:
  18181. key:
  18182. description: |-
  18183. A key in the referenced Secret.
  18184. Some instances of this field may be defaulted, in others it may be required.
  18185. maxLength: 253
  18186. minLength: 1
  18187. pattern: ^[-._a-zA-Z0-9]+$
  18188. type: string
  18189. name:
  18190. description: The name of the Secret resource being referred to.
  18191. maxLength: 253
  18192. minLength: 1
  18193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18194. type: string
  18195. namespace:
  18196. description: |-
  18197. The namespace of the Secret resource being referred to.
  18198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18199. maxLength: 63
  18200. minLength: 1
  18201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18202. type: string
  18203. type: object
  18204. privateKey:
  18205. description: |-
  18206. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18207. In some instances, `key` is a required field.
  18208. properties:
  18209. key:
  18210. description: |-
  18211. A key in the referenced Secret.
  18212. Some instances of this field may be defaulted, in others it may be required.
  18213. maxLength: 253
  18214. minLength: 1
  18215. pattern: ^[-._a-zA-Z0-9]+$
  18216. type: string
  18217. name:
  18218. description: The name of the Secret resource being referred to.
  18219. maxLength: 253
  18220. minLength: 1
  18221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18222. type: string
  18223. namespace:
  18224. description: |-
  18225. The namespace of the Secret resource being referred to.
  18226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18227. maxLength: 63
  18228. minLength: 1
  18229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18230. type: string
  18231. type: object
  18232. privateKeyPassphrase:
  18233. description: |-
  18234. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18235. In some instances, `key` is a required field.
  18236. properties:
  18237. key:
  18238. description: |-
  18239. A key in the referenced Secret.
  18240. Some instances of this field may be defaulted, in others it may be required.
  18241. maxLength: 253
  18242. minLength: 1
  18243. pattern: ^[-._a-zA-Z0-9]+$
  18244. type: string
  18245. name:
  18246. description: The name of the Secret resource being referred to.
  18247. maxLength: 253
  18248. minLength: 1
  18249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18250. type: string
  18251. namespace:
  18252. description: |-
  18253. The namespace of the Secret resource being referred to.
  18254. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18255. maxLength: 63
  18256. minLength: 1
  18257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18258. type: string
  18259. type: object
  18260. region:
  18261. description: |-
  18262. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18263. In some instances, `key` is a required field.
  18264. properties:
  18265. key:
  18266. description: |-
  18267. A key in the referenced Secret.
  18268. Some instances of this field may be defaulted, in others it may be required.
  18269. maxLength: 253
  18270. minLength: 1
  18271. pattern: ^[-._a-zA-Z0-9]+$
  18272. type: string
  18273. name:
  18274. description: The name of the Secret resource being referred to.
  18275. maxLength: 253
  18276. minLength: 1
  18277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18278. type: string
  18279. namespace:
  18280. description: |-
  18281. The namespace of the Secret resource being referred to.
  18282. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18283. maxLength: 63
  18284. minLength: 1
  18285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18286. type: string
  18287. type: object
  18288. tenancyId:
  18289. description: |-
  18290. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18291. In some instances, `key` is a required field.
  18292. properties:
  18293. key:
  18294. description: |-
  18295. A key in the referenced Secret.
  18296. Some instances of this field may be defaulted, in others it may be required.
  18297. maxLength: 253
  18298. minLength: 1
  18299. pattern: ^[-._a-zA-Z0-9]+$
  18300. type: string
  18301. name:
  18302. description: The name of the Secret resource being referred to.
  18303. maxLength: 253
  18304. minLength: 1
  18305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18306. type: string
  18307. namespace:
  18308. description: |-
  18309. The namespace of the Secret resource being referred to.
  18310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18311. maxLength: 63
  18312. minLength: 1
  18313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18314. type: string
  18315. type: object
  18316. userId:
  18317. description: |-
  18318. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18319. In some instances, `key` is a required field.
  18320. properties:
  18321. key:
  18322. description: |-
  18323. A key in the referenced Secret.
  18324. Some instances of this field may be defaulted, in others it may be required.
  18325. maxLength: 253
  18326. minLength: 1
  18327. pattern: ^[-._a-zA-Z0-9]+$
  18328. type: string
  18329. name:
  18330. description: The name of the Secret resource being referred to.
  18331. maxLength: 253
  18332. minLength: 1
  18333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18334. type: string
  18335. namespace:
  18336. description: |-
  18337. The namespace of the Secret resource being referred to.
  18338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18339. maxLength: 63
  18340. minLength: 1
  18341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18342. type: string
  18343. type: object
  18344. required:
  18345. - fingerprint
  18346. - identityId
  18347. - privateKey
  18348. - region
  18349. - tenancyId
  18350. - userId
  18351. type: object
  18352. tokenAuthCredentials:
  18353. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18354. properties:
  18355. accessToken:
  18356. description: |-
  18357. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18358. In some instances, `key` is a required field.
  18359. properties:
  18360. key:
  18361. description: |-
  18362. A key in the referenced Secret.
  18363. Some instances of this field may be defaulted, in others it may be required.
  18364. maxLength: 253
  18365. minLength: 1
  18366. pattern: ^[-._a-zA-Z0-9]+$
  18367. type: string
  18368. name:
  18369. description: The name of the Secret resource being referred to.
  18370. maxLength: 253
  18371. minLength: 1
  18372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18373. type: string
  18374. namespace:
  18375. description: |-
  18376. The namespace of the Secret resource being referred to.
  18377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18378. maxLength: 63
  18379. minLength: 1
  18380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18381. type: string
  18382. type: object
  18383. required:
  18384. - accessToken
  18385. type: object
  18386. universalAuthCredentials:
  18387. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  18388. properties:
  18389. clientId:
  18390. description: |-
  18391. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18392. In some instances, `key` is a required field.
  18393. properties:
  18394. key:
  18395. description: |-
  18396. A key in the referenced Secret.
  18397. Some instances of this field may be defaulted, in others it may be required.
  18398. maxLength: 253
  18399. minLength: 1
  18400. pattern: ^[-._a-zA-Z0-9]+$
  18401. type: string
  18402. name:
  18403. description: The name of the Secret resource being referred to.
  18404. maxLength: 253
  18405. minLength: 1
  18406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18407. type: string
  18408. namespace:
  18409. description: |-
  18410. The namespace of the Secret resource being referred to.
  18411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18412. maxLength: 63
  18413. minLength: 1
  18414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18415. type: string
  18416. type: object
  18417. clientSecret:
  18418. description: |-
  18419. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18420. In some instances, `key` is a required field.
  18421. properties:
  18422. key:
  18423. description: |-
  18424. A key in the referenced Secret.
  18425. Some instances of this field may be defaulted, in others it may be required.
  18426. maxLength: 253
  18427. minLength: 1
  18428. pattern: ^[-._a-zA-Z0-9]+$
  18429. type: string
  18430. name:
  18431. description: The name of the Secret resource being referred to.
  18432. maxLength: 253
  18433. minLength: 1
  18434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18435. type: string
  18436. namespace:
  18437. description: |-
  18438. The namespace of the Secret resource being referred to.
  18439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18440. maxLength: 63
  18441. minLength: 1
  18442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18443. type: string
  18444. type: object
  18445. required:
  18446. - clientId
  18447. - clientSecret
  18448. type: object
  18449. type: object
  18450. caBundle:
  18451. description: |-
  18452. CABundle is a PEM-encoded CA certificate bundle used to validate
  18453. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  18454. format: byte
  18455. type: string
  18456. caProvider:
  18457. description: |-
  18458. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  18459. The certificate is used to validate the Infisical server's TLS certificate.
  18460. Mutually exclusive with CABundle.
  18461. properties:
  18462. key:
  18463. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18464. maxLength: 253
  18465. minLength: 1
  18466. pattern: ^[-._a-zA-Z0-9]+$
  18467. type: string
  18468. name:
  18469. description: The name of the object located at the provider type.
  18470. maxLength: 253
  18471. minLength: 1
  18472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18473. type: string
  18474. namespace:
  18475. description: |-
  18476. The namespace the Provider type is in.
  18477. Can only be defined when used in a ClusterSecretStore.
  18478. maxLength: 63
  18479. minLength: 1
  18480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18481. type: string
  18482. type:
  18483. description: The type of provider to use such as "Secret", or "ConfigMap".
  18484. enum:
  18485. - Secret
  18486. - ConfigMap
  18487. type: string
  18488. required:
  18489. - name
  18490. - type
  18491. type: object
  18492. hostAPI:
  18493. default: https://app.infisical.com/api
  18494. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  18495. type: string
  18496. secretsScope:
  18497. description: SecretsScope defines the scope of the secrets within the workspace
  18498. properties:
  18499. environmentSlug:
  18500. description: EnvironmentSlug is the required slug identifier for the environment.
  18501. type: string
  18502. expandSecretReferences:
  18503. default: true
  18504. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  18505. type: boolean
  18506. organizationSlug:
  18507. description: |-
  18508. OrganizationSlug is the optional slug that identifies the organization that will be used
  18509. during authentication. Useful for sub-organization setups
  18510. type: string
  18511. projectSlug:
  18512. description: ProjectSlug is the required slug identifier for the project.
  18513. type: string
  18514. recursive:
  18515. default: false
  18516. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  18517. type: boolean
  18518. secretsPath:
  18519. default: /
  18520. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  18521. type: string
  18522. required:
  18523. - environmentSlug
  18524. - projectSlug
  18525. type: object
  18526. required:
  18527. - auth
  18528. - secretsScope
  18529. type: object
  18530. keepersecurity:
  18531. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  18532. properties:
  18533. authRef:
  18534. description: |-
  18535. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18536. In some instances, `key` is a required field.
  18537. properties:
  18538. key:
  18539. description: |-
  18540. A key in the referenced Secret.
  18541. Some instances of this field may be defaulted, in others it may be required.
  18542. maxLength: 253
  18543. minLength: 1
  18544. pattern: ^[-._a-zA-Z0-9]+$
  18545. type: string
  18546. name:
  18547. description: The name of the Secret resource being referred to.
  18548. maxLength: 253
  18549. minLength: 1
  18550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18551. type: string
  18552. namespace:
  18553. description: |-
  18554. The namespace of the Secret resource being referred to.
  18555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18556. maxLength: 63
  18557. minLength: 1
  18558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18559. type: string
  18560. type: object
  18561. folderID:
  18562. type: string
  18563. getByTitleFallback:
  18564. type: boolean
  18565. required:
  18566. - authRef
  18567. - folderID
  18568. type: object
  18569. kubernetes:
  18570. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  18571. properties:
  18572. auth:
  18573. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  18574. maxProperties: 1
  18575. minProperties: 1
  18576. properties:
  18577. cert:
  18578. description: has both clientCert and clientKey as secretKeySelector
  18579. properties:
  18580. clientCert:
  18581. description: |-
  18582. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18583. In some instances, `key` is a required field.
  18584. properties:
  18585. key:
  18586. description: |-
  18587. A key in the referenced Secret.
  18588. Some instances of this field may be defaulted, in others it may be required.
  18589. maxLength: 253
  18590. minLength: 1
  18591. pattern: ^[-._a-zA-Z0-9]+$
  18592. type: string
  18593. name:
  18594. description: The name of the Secret resource being referred to.
  18595. maxLength: 253
  18596. minLength: 1
  18597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18598. type: string
  18599. namespace:
  18600. description: |-
  18601. The namespace of the Secret resource being referred to.
  18602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18603. maxLength: 63
  18604. minLength: 1
  18605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18606. type: string
  18607. type: object
  18608. clientKey:
  18609. description: |-
  18610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18611. In some instances, `key` is a required field.
  18612. properties:
  18613. key:
  18614. description: |-
  18615. A key in the referenced Secret.
  18616. Some instances of this field may be defaulted, in others it may be required.
  18617. maxLength: 253
  18618. minLength: 1
  18619. pattern: ^[-._a-zA-Z0-9]+$
  18620. type: string
  18621. name:
  18622. description: The name of the Secret resource being referred to.
  18623. maxLength: 253
  18624. minLength: 1
  18625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18626. type: string
  18627. namespace:
  18628. description: |-
  18629. The namespace of the Secret resource being referred to.
  18630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18631. maxLength: 63
  18632. minLength: 1
  18633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18634. type: string
  18635. type: object
  18636. type: object
  18637. serviceAccount:
  18638. description: points to a service account that should be used for authentication
  18639. properties:
  18640. audiences:
  18641. description: |-
  18642. Audience specifies the `aud` claim for the service account token
  18643. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18644. then this audiences will be appended to the list
  18645. items:
  18646. type: string
  18647. type: array
  18648. name:
  18649. description: The name of the ServiceAccount resource being referred to.
  18650. maxLength: 253
  18651. minLength: 1
  18652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18653. type: string
  18654. namespace:
  18655. description: |-
  18656. Namespace of the resource being referred to.
  18657. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18658. maxLength: 63
  18659. minLength: 1
  18660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18661. type: string
  18662. required:
  18663. - name
  18664. type: object
  18665. token:
  18666. description: use static token to authenticate with
  18667. properties:
  18668. bearerToken:
  18669. description: |-
  18670. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18671. In some instances, `key` is a required field.
  18672. properties:
  18673. key:
  18674. description: |-
  18675. A key in the referenced Secret.
  18676. Some instances of this field may be defaulted, in others it may be required.
  18677. maxLength: 253
  18678. minLength: 1
  18679. pattern: ^[-._a-zA-Z0-9]+$
  18680. type: string
  18681. name:
  18682. description: The name of the Secret resource being referred to.
  18683. maxLength: 253
  18684. minLength: 1
  18685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18686. type: string
  18687. namespace:
  18688. description: |-
  18689. The namespace of the Secret resource being referred to.
  18690. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18691. maxLength: 63
  18692. minLength: 1
  18693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18694. type: string
  18695. type: object
  18696. type: object
  18697. type: object
  18698. authRef:
  18699. description: A reference to a secret that contains the auth information.
  18700. properties:
  18701. key:
  18702. description: |-
  18703. A key in the referenced Secret.
  18704. Some instances of this field may be defaulted, in others it may be required.
  18705. maxLength: 253
  18706. minLength: 1
  18707. pattern: ^[-._a-zA-Z0-9]+$
  18708. type: string
  18709. name:
  18710. description: The name of the Secret resource being referred to.
  18711. maxLength: 253
  18712. minLength: 1
  18713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18714. type: string
  18715. namespace:
  18716. description: |-
  18717. The namespace of the Secret resource being referred to.
  18718. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18719. maxLength: 63
  18720. minLength: 1
  18721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18722. type: string
  18723. type: object
  18724. remoteNamespace:
  18725. default: default
  18726. description: Remote namespace to fetch the secrets from
  18727. maxLength: 63
  18728. minLength: 1
  18729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18730. type: string
  18731. server:
  18732. description: configures the Kubernetes server Address.
  18733. properties:
  18734. caBundle:
  18735. description: CABundle is a base64-encoded CA certificate
  18736. format: byte
  18737. type: string
  18738. caProvider:
  18739. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  18740. properties:
  18741. key:
  18742. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18743. maxLength: 253
  18744. minLength: 1
  18745. pattern: ^[-._a-zA-Z0-9]+$
  18746. type: string
  18747. name:
  18748. description: The name of the object located at the provider type.
  18749. maxLength: 253
  18750. minLength: 1
  18751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18752. type: string
  18753. namespace:
  18754. description: |-
  18755. The namespace the Provider type is in.
  18756. Can only be defined when used in a ClusterSecretStore.
  18757. maxLength: 63
  18758. minLength: 1
  18759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18760. type: string
  18761. type:
  18762. description: The type of provider to use such as "Secret", or "ConfigMap".
  18763. enum:
  18764. - Secret
  18765. - ConfigMap
  18766. type: string
  18767. required:
  18768. - name
  18769. - type
  18770. type: object
  18771. url:
  18772. default: kubernetes.default
  18773. description: configures the Kubernetes server Address.
  18774. type: string
  18775. type: object
  18776. type: object
  18777. nebiusmysterybox:
  18778. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  18779. properties:
  18780. apiDomain:
  18781. description: NebiusMysterybox API endpoint
  18782. type: string
  18783. auth:
  18784. description: Auth defines parameters to authenticate in MysteryBox
  18785. properties:
  18786. serviceAccountCredsSecretRef:
  18787. description: |-
  18788. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  18789. document with service account credentials used to get an IAM token.
  18790. Expected JSON structure:
  18791. {
  18792. "subject-credentials": {
  18793. "alg": "RS256",
  18794. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  18795. "kid": "<public-key-id>",
  18796. "iss": "<issuer-service-account-id>",
  18797. "sub": "<subject-service-account-id>"
  18798. }
  18799. }
  18800. properties:
  18801. key:
  18802. description: |-
  18803. A key in the referenced Secret.
  18804. Some instances of this field may be defaulted, in others it may be required.
  18805. maxLength: 253
  18806. minLength: 1
  18807. pattern: ^[-._a-zA-Z0-9]+$
  18808. type: string
  18809. name:
  18810. description: The name of the Secret resource being referred to.
  18811. maxLength: 253
  18812. minLength: 1
  18813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18814. type: string
  18815. namespace:
  18816. description: |-
  18817. The namespace of the Secret resource being referred to.
  18818. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18819. maxLength: 63
  18820. minLength: 1
  18821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18822. type: string
  18823. type: object
  18824. tokenSecretRef:
  18825. description: Token authenticates with Nebius Mysterybox by presenting a token.
  18826. properties:
  18827. key:
  18828. description: |-
  18829. A key in the referenced Secret.
  18830. Some instances of this field may be defaulted, in others it may be required.
  18831. maxLength: 253
  18832. minLength: 1
  18833. pattern: ^[-._a-zA-Z0-9]+$
  18834. type: string
  18835. name:
  18836. description: The name of the Secret resource being referred to.
  18837. maxLength: 253
  18838. minLength: 1
  18839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18840. type: string
  18841. namespace:
  18842. description: |-
  18843. The namespace of the Secret resource being referred to.
  18844. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18845. maxLength: 63
  18846. minLength: 1
  18847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18848. type: string
  18849. type: object
  18850. type: object
  18851. x-kubernetes-validations:
  18852. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  18853. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  18854. caProvider:
  18855. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  18856. properties:
  18857. certSecretRef:
  18858. description: |-
  18859. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18860. In some instances, `key` is a required field.
  18861. properties:
  18862. key:
  18863. description: |-
  18864. A key in the referenced Secret.
  18865. Some instances of this field may be defaulted, in others it may be required.
  18866. maxLength: 253
  18867. minLength: 1
  18868. pattern: ^[-._a-zA-Z0-9]+$
  18869. type: string
  18870. name:
  18871. description: The name of the Secret resource being referred to.
  18872. maxLength: 253
  18873. minLength: 1
  18874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18875. type: string
  18876. namespace:
  18877. description: |-
  18878. The namespace of the Secret resource being referred to.
  18879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18880. maxLength: 63
  18881. minLength: 1
  18882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18883. type: string
  18884. type: object
  18885. type: object
  18886. required:
  18887. - apiDomain
  18888. - auth
  18889. type: object
  18890. ngrok:
  18891. description: Ngrok configures this store to sync secrets using the ngrok provider.
  18892. properties:
  18893. apiUrl:
  18894. default: https://api.ngrok.com
  18895. description: APIURL is the URL of the ngrok API.
  18896. type: string
  18897. auth:
  18898. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  18899. maxProperties: 1
  18900. minProperties: 1
  18901. properties:
  18902. apiKey:
  18903. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  18904. properties:
  18905. secretRef:
  18906. description: SecretRef is a reference to a secret containing the ngrok API key.
  18907. properties:
  18908. key:
  18909. description: |-
  18910. A key in the referenced Secret.
  18911. Some instances of this field may be defaulted, in others it may be required.
  18912. maxLength: 253
  18913. minLength: 1
  18914. pattern: ^[-._a-zA-Z0-9]+$
  18915. type: string
  18916. name:
  18917. description: The name of the Secret resource being referred to.
  18918. maxLength: 253
  18919. minLength: 1
  18920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18921. type: string
  18922. namespace:
  18923. description: |-
  18924. The namespace of the Secret resource being referred to.
  18925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18926. maxLength: 63
  18927. minLength: 1
  18928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18929. type: string
  18930. type: object
  18931. type: object
  18932. type: object
  18933. vault:
  18934. description: Vault configures the ngrok vault to sync secrets with.
  18935. properties:
  18936. name:
  18937. description: Name is the name of the ngrok vault to sync secrets with.
  18938. type: string
  18939. required:
  18940. - name
  18941. type: object
  18942. required:
  18943. - auth
  18944. - vault
  18945. type: object
  18946. onboardbase:
  18947. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  18948. properties:
  18949. apiHost:
  18950. default: https://public.onboardbase.com/api/v1/
  18951. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  18952. type: string
  18953. auth:
  18954. description: Auth configures how the Operator authenticates with the Onboardbase API
  18955. properties:
  18956. apiKeyRef:
  18957. description: |-
  18958. OnboardbaseAPIKey is the APIKey generated by an admin account.
  18959. It is used to recognize and authorize access to a project and environment within onboardbase
  18960. properties:
  18961. key:
  18962. description: |-
  18963. A key in the referenced Secret.
  18964. Some instances of this field may be defaulted, in others it may be required.
  18965. maxLength: 253
  18966. minLength: 1
  18967. pattern: ^[-._a-zA-Z0-9]+$
  18968. type: string
  18969. name:
  18970. description: The name of the Secret resource being referred to.
  18971. maxLength: 253
  18972. minLength: 1
  18973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18974. type: string
  18975. namespace:
  18976. description: |-
  18977. The namespace of the Secret resource being referred to.
  18978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18979. maxLength: 63
  18980. minLength: 1
  18981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18982. type: string
  18983. type: object
  18984. passcodeRef:
  18985. description: OnboardbasePasscode is the passcode attached to the API Key
  18986. properties:
  18987. key:
  18988. description: |-
  18989. A key in the referenced Secret.
  18990. Some instances of this field may be defaulted, in others it may be required.
  18991. maxLength: 253
  18992. minLength: 1
  18993. pattern: ^[-._a-zA-Z0-9]+$
  18994. type: string
  18995. name:
  18996. description: The name of the Secret resource being referred to.
  18997. maxLength: 253
  18998. minLength: 1
  18999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19000. type: string
  19001. namespace:
  19002. description: |-
  19003. The namespace of the Secret resource being referred to.
  19004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19005. maxLength: 63
  19006. minLength: 1
  19007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19008. type: string
  19009. type: object
  19010. required:
  19011. - apiKeyRef
  19012. - passcodeRef
  19013. type: object
  19014. environment:
  19015. default: development
  19016. description: Environment is the name of an environmnent within a project to pull the secrets from
  19017. type: string
  19018. project:
  19019. default: development
  19020. description: Project is an onboardbase project that the secrets should be pulled from
  19021. type: string
  19022. required:
  19023. - apiHost
  19024. - auth
  19025. - environment
  19026. - project
  19027. type: object
  19028. onepassword:
  19029. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19030. properties:
  19031. auth:
  19032. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19033. properties:
  19034. secretRef:
  19035. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19036. properties:
  19037. connectTokenSecretRef:
  19038. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19039. properties:
  19040. key:
  19041. description: |-
  19042. A key in the referenced Secret.
  19043. Some instances of this field may be defaulted, in others it may be required.
  19044. maxLength: 253
  19045. minLength: 1
  19046. pattern: ^[-._a-zA-Z0-9]+$
  19047. type: string
  19048. name:
  19049. description: The name of the Secret resource being referred to.
  19050. maxLength: 253
  19051. minLength: 1
  19052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19053. type: string
  19054. namespace:
  19055. description: |-
  19056. The namespace of the Secret resource being referred to.
  19057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19058. maxLength: 63
  19059. minLength: 1
  19060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19061. type: string
  19062. type: object
  19063. required:
  19064. - connectTokenSecretRef
  19065. type: object
  19066. required:
  19067. - secretRef
  19068. type: object
  19069. connectHost:
  19070. description: ConnectHost defines the OnePassword Connect Server to connect to
  19071. type: string
  19072. vaults:
  19073. additionalProperties:
  19074. type: integer
  19075. description: Vaults defines which OnePassword vaults to search in which order
  19076. type: object
  19077. required:
  19078. - auth
  19079. - connectHost
  19080. - vaults
  19081. type: object
  19082. onepasswordSDK:
  19083. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19084. properties:
  19085. auth:
  19086. description: Auth defines the information necessary to authenticate against OnePassword API.
  19087. properties:
  19088. serviceAccountSecretRef:
  19089. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19090. properties:
  19091. key:
  19092. description: |-
  19093. A key in the referenced Secret.
  19094. Some instances of this field may be defaulted, in others it may be required.
  19095. maxLength: 253
  19096. minLength: 1
  19097. pattern: ^[-._a-zA-Z0-9]+$
  19098. type: string
  19099. name:
  19100. description: The name of the Secret resource being referred to.
  19101. maxLength: 253
  19102. minLength: 1
  19103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19104. type: string
  19105. namespace:
  19106. description: |-
  19107. The namespace of the Secret resource being referred to.
  19108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19109. maxLength: 63
  19110. minLength: 1
  19111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19112. type: string
  19113. type: object
  19114. required:
  19115. - serviceAccountSecretRef
  19116. type: object
  19117. cache:
  19118. description: |-
  19119. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19120. When enabled, secrets are cached with the specified TTL.
  19121. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19122. If omitted, caching is disabled (default).
  19123. cache: {} is a valid option to set.
  19124. properties:
  19125. maxSize:
  19126. default: 100
  19127. description: |-
  19128. MaxSize is the maximum number of secrets to cache.
  19129. When the cache is full, least-recently-used entries are evicted.
  19130. minimum: 1
  19131. type: integer
  19132. ttl:
  19133. default: 5m
  19134. description: |-
  19135. TTL is the time-to-live for cached secrets.
  19136. Format: duration string (e.g., "5m", "1h", "30s")
  19137. type: string
  19138. type: object
  19139. integrationInfo:
  19140. description: |-
  19141. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19142. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19143. properties:
  19144. name:
  19145. default: 1Password SDK
  19146. description: Name defaults to "1Password SDK".
  19147. type: string
  19148. version:
  19149. default: v1.0.0
  19150. description: Version defaults to "v1.0.0".
  19151. type: string
  19152. type: object
  19153. vault:
  19154. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19155. type: string
  19156. required:
  19157. - auth
  19158. - vault
  19159. type: object
  19160. openBao:
  19161. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19162. properties:
  19163. auth:
  19164. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19165. properties:
  19166. appRole:
  19167. description: |-
  19168. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19169. with the role and secret stored in a Kubernetes Secret resource.
  19170. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19171. properties:
  19172. path:
  19173. default: approle
  19174. description: |-
  19175. Path where the App Role authentication backend is mounted
  19176. in OpenBao, e.g: "approle"
  19177. type: string
  19178. roleId:
  19179. description: |-
  19180. RoleID configured in the App Role authentication backend when setting
  19181. up the authentication backend in OpenBao.
  19182. minLength: 1
  19183. type: string
  19184. roleRef:
  19185. description: |-
  19186. Reference to a key in a Secret that contains the App Role ID used
  19187. to authenticate with OpenBao.
  19188. The `key` field must be specified and denotes which entry within the Secret
  19189. resource is used as the app role id.
  19190. properties:
  19191. key:
  19192. description: |-
  19193. A key in the referenced Secret.
  19194. Some instances of this field may be defaulted, in others it may be required.
  19195. maxLength: 253
  19196. minLength: 1
  19197. pattern: ^[-._a-zA-Z0-9]+$
  19198. type: string
  19199. name:
  19200. description: The name of the Secret resource being referred to.
  19201. maxLength: 253
  19202. minLength: 1
  19203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19204. type: string
  19205. namespace:
  19206. description: |-
  19207. The namespace of the Secret resource being referred to.
  19208. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19209. maxLength: 63
  19210. minLength: 1
  19211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19212. type: string
  19213. type: object
  19214. secretRef:
  19215. description: |-
  19216. Reference to a key in a Secret that contains the App Role secret used
  19217. to authenticate with OpenBao.
  19218. The `key` field must be specified and denotes which entry within the Secret
  19219. resource is used as the app role secret.
  19220. properties:
  19221. key:
  19222. description: |-
  19223. A key in the referenced Secret.
  19224. Some instances of this field may be defaulted, in others it may be required.
  19225. maxLength: 253
  19226. minLength: 1
  19227. pattern: ^[-._a-zA-Z0-9]+$
  19228. type: string
  19229. name:
  19230. description: The name of the Secret resource being referred to.
  19231. maxLength: 253
  19232. minLength: 1
  19233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19234. type: string
  19235. namespace:
  19236. description: |-
  19237. The namespace of the Secret resource being referred to.
  19238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19239. maxLength: 63
  19240. minLength: 1
  19241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19242. type: string
  19243. type: object
  19244. required:
  19245. - path
  19246. - secretRef
  19247. type: object
  19248. x-kubernetes-validations:
  19249. - message: exactly one of the fields in [roleId roleRef] must be set
  19250. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19251. namespace:
  19252. description: |-
  19253. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19254. than the namespace your secret is in. Namespaces is a set of features
  19255. within OpenBao that allows OpenBao environments to support secure
  19256. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19257. if set, or empty otherwise
  19258. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19259. type: string
  19260. tokenSecretRef:
  19261. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19262. properties:
  19263. key:
  19264. description: |-
  19265. A key in the referenced Secret.
  19266. Some instances of this field may be defaulted, in others it may be required.
  19267. maxLength: 253
  19268. minLength: 1
  19269. pattern: ^[-._a-zA-Z0-9]+$
  19270. type: string
  19271. name:
  19272. description: The name of the Secret resource being referred to.
  19273. maxLength: 253
  19274. minLength: 1
  19275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19276. type: string
  19277. namespace:
  19278. description: |-
  19279. The namespace of the Secret resource being referred to.
  19280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19281. maxLength: 63
  19282. minLength: 1
  19283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19284. type: string
  19285. type: object
  19286. userPass:
  19287. description: UserPass authenticates with OpenBao by passing a username/password pair
  19288. properties:
  19289. path:
  19290. default: userpass
  19291. description: |-
  19292. Path where the UserPassword authentication backend is mounted
  19293. in OpenBao, e.g: "userpass"
  19294. type: string
  19295. secretRef:
  19296. description: |-
  19297. SecretRef to a key in a Secret resource containing password for the user
  19298. used to authenticate with OpenBao using the [UserPass authentication
  19299. method]
  19300. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19301. properties:
  19302. key:
  19303. description: |-
  19304. A key in the referenced Secret.
  19305. Some instances of this field may be defaulted, in others it may be required.
  19306. maxLength: 253
  19307. minLength: 1
  19308. pattern: ^[-._a-zA-Z0-9]+$
  19309. type: string
  19310. name:
  19311. description: The name of the Secret resource being referred to.
  19312. maxLength: 253
  19313. minLength: 1
  19314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19315. type: string
  19316. namespace:
  19317. description: |-
  19318. The namespace of the Secret resource being referred to.
  19319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19320. maxLength: 63
  19321. minLength: 1
  19322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19323. type: string
  19324. type: object
  19325. username:
  19326. description: |-
  19327. Username is a username used to authenticate using the [UserPass
  19328. authentication method]
  19329. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19330. type: string
  19331. required:
  19332. - path
  19333. - username
  19334. type: object
  19335. type: object
  19336. x-kubernetes-validations:
  19337. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19338. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19339. caBundle:
  19340. description: |-
  19341. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19342. this and `caProvider` are not set the system root certificates are used
  19343. to validate the TLS connection.
  19344. format: byte
  19345. type: string
  19346. caProvider:
  19347. description: |-
  19348. The provider for the CA bundle to use to validate OpenBao server
  19349. certificate. If this and `caBundle` are not set the system root
  19350. certificates are used to validate the TLS connection.
  19351. properties:
  19352. key:
  19353. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19354. maxLength: 253
  19355. minLength: 1
  19356. pattern: ^[-._a-zA-Z0-9]+$
  19357. type: string
  19358. name:
  19359. description: The name of the object located at the provider type.
  19360. maxLength: 253
  19361. minLength: 1
  19362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19363. type: string
  19364. namespace:
  19365. description: |-
  19366. The namespace the Provider type is in.
  19367. Can only be defined when used in a ClusterSecretStore.
  19368. maxLength: 63
  19369. minLength: 1
  19370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19371. type: string
  19372. type:
  19373. description: The type of provider to use such as "Secret", or "ConfigMap".
  19374. enum:
  19375. - Secret
  19376. - ConfigMap
  19377. type: string
  19378. required:
  19379. - name
  19380. - type
  19381. type: object
  19382. namespace:
  19383. description: |-
  19384. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  19385. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  19386. e.g: "ns1".
  19387. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19388. type: string
  19389. path:
  19390. description: |-
  19391. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  19392. "secret". The v2 KV secret engine version specific "/data" path suffix
  19393. for fetching secrets from OpenBao is optional and will be appended
  19394. if not present in specified path.
  19395. type: string
  19396. server:
  19397. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  19398. type: string
  19399. version:
  19400. default: v2
  19401. description: |-
  19402. Version is the OpenBao KV secret engine version. This can be either "v1" or
  19403. "v2". Version defaults to "v2".
  19404. enum:
  19405. - v1
  19406. - v2
  19407. type: string
  19408. required:
  19409. - server
  19410. type: object
  19411. x-kubernetes-validations:
  19412. - message: at most one of the fields in [caBundle caProvider] may be set
  19413. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  19414. oracle:
  19415. description: Oracle configures this store to sync secrets using Oracle Vault provider
  19416. properties:
  19417. auth:
  19418. description: |-
  19419. Auth configures how secret-manager authenticates with the Oracle Vault.
  19420. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  19421. properties:
  19422. secretRef:
  19423. description: SecretRef to pass through sensitive information.
  19424. properties:
  19425. fingerprint:
  19426. description: Fingerprint is the fingerprint of the API private key.
  19427. properties:
  19428. key:
  19429. description: |-
  19430. A key in the referenced Secret.
  19431. Some instances of this field may be defaulted, in others it may be required.
  19432. maxLength: 253
  19433. minLength: 1
  19434. pattern: ^[-._a-zA-Z0-9]+$
  19435. type: string
  19436. name:
  19437. description: The name of the Secret resource being referred to.
  19438. maxLength: 253
  19439. minLength: 1
  19440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19441. type: string
  19442. namespace:
  19443. description: |-
  19444. The namespace of the Secret resource being referred to.
  19445. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19446. maxLength: 63
  19447. minLength: 1
  19448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19449. type: string
  19450. type: object
  19451. privatekey:
  19452. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  19453. properties:
  19454. key:
  19455. description: |-
  19456. A key in the referenced Secret.
  19457. Some instances of this field may be defaulted, in others it may be required.
  19458. maxLength: 253
  19459. minLength: 1
  19460. pattern: ^[-._a-zA-Z0-9]+$
  19461. type: string
  19462. name:
  19463. description: The name of the Secret resource being referred to.
  19464. maxLength: 253
  19465. minLength: 1
  19466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19467. type: string
  19468. namespace:
  19469. description: |-
  19470. The namespace of the Secret resource being referred to.
  19471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19472. maxLength: 63
  19473. minLength: 1
  19474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19475. type: string
  19476. type: object
  19477. required:
  19478. - fingerprint
  19479. - privatekey
  19480. type: object
  19481. tenancy:
  19482. description: Tenancy is the tenancy OCID where user is located.
  19483. type: string
  19484. user:
  19485. description: User is an access OCID specific to the account.
  19486. type: string
  19487. required:
  19488. - secretRef
  19489. - tenancy
  19490. - user
  19491. type: object
  19492. compartment:
  19493. description: |-
  19494. Compartment is the vault compartment OCID.
  19495. Required for PushSecret
  19496. type: string
  19497. encryptionKey:
  19498. description: |-
  19499. EncryptionKey is the OCID of the encryption key within the vault.
  19500. Required for PushSecret
  19501. type: string
  19502. principalType:
  19503. description: |-
  19504. The type of principal to use for authentication. If left blank, the Auth struct will
  19505. determine the principal type. This optional field must be specified if using
  19506. workload identity.
  19507. enum:
  19508. - ""
  19509. - UserPrincipal
  19510. - InstancePrincipal
  19511. - Workload
  19512. type: string
  19513. region:
  19514. description: Region is the region where vault is located.
  19515. type: string
  19516. serviceAccountRef:
  19517. description: |-
  19518. ServiceAccountRef specified the service account
  19519. that should be used when authenticating with WorkloadIdentity.
  19520. properties:
  19521. audiences:
  19522. description: |-
  19523. Audience specifies the `aud` claim for the service account token
  19524. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19525. then this audiences will be appended to the list
  19526. items:
  19527. type: string
  19528. type: array
  19529. name:
  19530. description: The name of the ServiceAccount resource being referred to.
  19531. maxLength: 253
  19532. minLength: 1
  19533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19534. type: string
  19535. namespace:
  19536. description: |-
  19537. Namespace of the resource being referred to.
  19538. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19539. maxLength: 63
  19540. minLength: 1
  19541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19542. type: string
  19543. required:
  19544. - name
  19545. type: object
  19546. vault:
  19547. description: Vault is the vault's OCID of the specific vault where secret is located.
  19548. type: string
  19549. required:
  19550. - region
  19551. - vault
  19552. type: object
  19553. ovh:
  19554. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  19555. properties:
  19556. auth:
  19557. description: Authentication method (mtls or token).
  19558. properties:
  19559. mtls:
  19560. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  19561. properties:
  19562. caBundle:
  19563. format: byte
  19564. type: string
  19565. caProvider:
  19566. description: |-
  19567. CAProvider provides a custom certificate authority for accessing the provider's store.
  19568. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  19569. properties:
  19570. key:
  19571. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19572. maxLength: 253
  19573. minLength: 1
  19574. pattern: ^[-._a-zA-Z0-9]+$
  19575. type: string
  19576. name:
  19577. description: The name of the object located at the provider type.
  19578. maxLength: 253
  19579. minLength: 1
  19580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19581. type: string
  19582. namespace:
  19583. description: |-
  19584. The namespace the Provider type is in.
  19585. Can only be defined when used in a ClusterSecretStore.
  19586. maxLength: 63
  19587. minLength: 1
  19588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19589. type: string
  19590. type:
  19591. description: The type of provider to use such as "Secret", or "ConfigMap".
  19592. enum:
  19593. - Secret
  19594. - ConfigMap
  19595. type: string
  19596. required:
  19597. - name
  19598. - type
  19599. type: object
  19600. certSecretRef:
  19601. description: |-
  19602. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19603. In some instances, `key` is a required field.
  19604. properties:
  19605. key:
  19606. description: |-
  19607. A key in the referenced Secret.
  19608. Some instances of this field may be defaulted, in others it may be required.
  19609. maxLength: 253
  19610. minLength: 1
  19611. pattern: ^[-._a-zA-Z0-9]+$
  19612. type: string
  19613. name:
  19614. description: The name of the Secret resource being referred to.
  19615. maxLength: 253
  19616. minLength: 1
  19617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19618. type: string
  19619. namespace:
  19620. description: |-
  19621. The namespace of the Secret resource being referred to.
  19622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19623. maxLength: 63
  19624. minLength: 1
  19625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19626. type: string
  19627. type: object
  19628. keySecretRef:
  19629. description: |-
  19630. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19631. In some instances, `key` is a required field.
  19632. properties:
  19633. key:
  19634. description: |-
  19635. A key in the referenced Secret.
  19636. Some instances of this field may be defaulted, in others it may be required.
  19637. maxLength: 253
  19638. minLength: 1
  19639. pattern: ^[-._a-zA-Z0-9]+$
  19640. type: string
  19641. name:
  19642. description: The name of the Secret resource being referred to.
  19643. maxLength: 253
  19644. minLength: 1
  19645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19646. type: string
  19647. namespace:
  19648. description: |-
  19649. The namespace of the Secret resource being referred to.
  19650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19651. maxLength: 63
  19652. minLength: 1
  19653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19654. type: string
  19655. type: object
  19656. required:
  19657. - certSecretRef
  19658. - keySecretRef
  19659. type: object
  19660. token:
  19661. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  19662. properties:
  19663. tokenSecretRef:
  19664. description: |-
  19665. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19666. In some instances, `key` is a required field.
  19667. properties:
  19668. key:
  19669. description: |-
  19670. A key in the referenced Secret.
  19671. Some instances of this field may be defaulted, in others it may be required.
  19672. maxLength: 253
  19673. minLength: 1
  19674. pattern: ^[-._a-zA-Z0-9]+$
  19675. type: string
  19676. name:
  19677. description: The name of the Secret resource being referred to.
  19678. maxLength: 253
  19679. minLength: 1
  19680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19681. type: string
  19682. namespace:
  19683. description: |-
  19684. The namespace of the Secret resource being referred to.
  19685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19686. maxLength: 63
  19687. minLength: 1
  19688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19689. type: string
  19690. type: object
  19691. required:
  19692. - tokenSecretRef
  19693. type: object
  19694. type: object
  19695. casRequired:
  19696. description: 'Enables or disables check-and-set (CAS) (default: false).'
  19697. type: boolean
  19698. okmsTimeout:
  19699. default: 30
  19700. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  19701. format: int32
  19702. minimum: 1
  19703. type: integer
  19704. okmsid:
  19705. description: specifies the OKMS ID.
  19706. type: string
  19707. server:
  19708. description: specifies the OKMS server endpoint.
  19709. type: string
  19710. required:
  19711. - auth
  19712. - okmsid
  19713. - server
  19714. type: object
  19715. passbolt:
  19716. description: |-
  19717. PassboltProvider provides access to Passbolt secrets manager.
  19718. See: https://www.passbolt.com.
  19719. properties:
  19720. auth:
  19721. description: Auth defines the information necessary to authenticate against Passbolt Server
  19722. properties:
  19723. passwordSecretRef:
  19724. description: |-
  19725. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19726. In some instances, `key` is a required field.
  19727. properties:
  19728. key:
  19729. description: |-
  19730. A key in the referenced Secret.
  19731. Some instances of this field may be defaulted, in others it may be required.
  19732. maxLength: 253
  19733. minLength: 1
  19734. pattern: ^[-._a-zA-Z0-9]+$
  19735. type: string
  19736. name:
  19737. description: The name of the Secret resource being referred to.
  19738. maxLength: 253
  19739. minLength: 1
  19740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19741. type: string
  19742. namespace:
  19743. description: |-
  19744. The namespace of the Secret resource being referred to.
  19745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19746. maxLength: 63
  19747. minLength: 1
  19748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19749. type: string
  19750. type: object
  19751. privateKeySecretRef:
  19752. description: |-
  19753. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19754. In some instances, `key` is a required field.
  19755. properties:
  19756. key:
  19757. description: |-
  19758. A key in the referenced Secret.
  19759. Some instances of this field may be defaulted, in others it may be required.
  19760. maxLength: 253
  19761. minLength: 1
  19762. pattern: ^[-._a-zA-Z0-9]+$
  19763. type: string
  19764. name:
  19765. description: The name of the Secret resource being referred to.
  19766. maxLength: 253
  19767. minLength: 1
  19768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19769. type: string
  19770. namespace:
  19771. description: |-
  19772. The namespace of the Secret resource being referred to.
  19773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19774. maxLength: 63
  19775. minLength: 1
  19776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19777. type: string
  19778. type: object
  19779. required:
  19780. - passwordSecretRef
  19781. - privateKeySecretRef
  19782. type: object
  19783. caBundle:
  19784. description: |-
  19785. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  19786. if the Host URL is using HTTPS protocol. If not set the system root certificates
  19787. are used to validate the TLS connection.
  19788. format: byte
  19789. type: string
  19790. caProvider:
  19791. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  19792. properties:
  19793. key:
  19794. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19795. maxLength: 253
  19796. minLength: 1
  19797. pattern: ^[-._a-zA-Z0-9]+$
  19798. type: string
  19799. name:
  19800. description: The name of the object located at the provider type.
  19801. maxLength: 253
  19802. minLength: 1
  19803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19804. type: string
  19805. namespace:
  19806. description: |-
  19807. The namespace the Provider type is in.
  19808. Can only be defined when used in a ClusterSecretStore.
  19809. maxLength: 63
  19810. minLength: 1
  19811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19812. type: string
  19813. type:
  19814. description: The type of provider to use such as "Secret", or "ConfigMap".
  19815. enum:
  19816. - Secret
  19817. - ConfigMap
  19818. type: string
  19819. required:
  19820. - name
  19821. - type
  19822. type: object
  19823. host:
  19824. description: Host defines the Passbolt Server to connect to
  19825. type: string
  19826. required:
  19827. - auth
  19828. - host
  19829. type: object
  19830. passworddepot:
  19831. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  19832. properties:
  19833. auth:
  19834. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  19835. properties:
  19836. secretRef:
  19837. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  19838. properties:
  19839. credentials:
  19840. description: Username / Password is used for authentication.
  19841. properties:
  19842. key:
  19843. description: |-
  19844. A key in the referenced Secret.
  19845. Some instances of this field may be defaulted, in others it may be required.
  19846. maxLength: 253
  19847. minLength: 1
  19848. pattern: ^[-._a-zA-Z0-9]+$
  19849. type: string
  19850. name:
  19851. description: The name of the Secret resource being referred to.
  19852. maxLength: 253
  19853. minLength: 1
  19854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19855. type: string
  19856. namespace:
  19857. description: |-
  19858. The namespace of the Secret resource being referred to.
  19859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19860. maxLength: 63
  19861. minLength: 1
  19862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19863. type: string
  19864. type: object
  19865. type: object
  19866. required:
  19867. - secretRef
  19868. type: object
  19869. database:
  19870. description: Database to use as source
  19871. type: string
  19872. host:
  19873. description: URL configures the Password Depot instance URL.
  19874. type: string
  19875. required:
  19876. - auth
  19877. - database
  19878. - host
  19879. type: object
  19880. previder:
  19881. description: Previder configures this store to sync secrets using the Previder provider
  19882. properties:
  19883. auth:
  19884. description: PreviderAuth contains a secretRef for credentials.
  19885. properties:
  19886. secretRef:
  19887. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  19888. properties:
  19889. accessToken:
  19890. description: The AccessToken is used for authentication
  19891. properties:
  19892. key:
  19893. description: |-
  19894. A key in the referenced Secret.
  19895. Some instances of this field may be defaulted, in others it may be required.
  19896. maxLength: 253
  19897. minLength: 1
  19898. pattern: ^[-._a-zA-Z0-9]+$
  19899. type: string
  19900. name:
  19901. description: The name of the Secret resource being referred to.
  19902. maxLength: 253
  19903. minLength: 1
  19904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19905. type: string
  19906. namespace:
  19907. description: |-
  19908. The namespace of the Secret resource being referred to.
  19909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19910. maxLength: 63
  19911. minLength: 1
  19912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19913. type: string
  19914. type: object
  19915. required:
  19916. - accessToken
  19917. type: object
  19918. type: object
  19919. baseUri:
  19920. type: string
  19921. required:
  19922. - auth
  19923. type: object
  19924. pulumi:
  19925. description: Pulumi configures this store to sync secrets using the Pulumi provider
  19926. properties:
  19927. accessToken:
  19928. description: |-
  19929. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  19930. Deprecated: Use auth.accessToken instead.
  19931. properties:
  19932. secretRef:
  19933. description: SecretRef is a reference to a secret containing the Pulumi API token.
  19934. properties:
  19935. key:
  19936. description: |-
  19937. A key in the referenced Secret.
  19938. Some instances of this field may be defaulted, in others it may be required.
  19939. maxLength: 253
  19940. minLength: 1
  19941. pattern: ^[-._a-zA-Z0-9]+$
  19942. type: string
  19943. name:
  19944. description: The name of the Secret resource being referred to.
  19945. maxLength: 253
  19946. minLength: 1
  19947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19948. type: string
  19949. namespace:
  19950. description: |-
  19951. The namespace of the Secret resource being referred to.
  19952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19953. maxLength: 63
  19954. minLength: 1
  19955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19956. type: string
  19957. type: object
  19958. type: object
  19959. apiUrl:
  19960. default: https://api.pulumi.com/api/esc
  19961. description: APIURL is the URL of the Pulumi API.
  19962. type: string
  19963. auth:
  19964. description: |-
  19965. Auth configures how the Operator authenticates with the Pulumi API.
  19966. Either auth or the deprecated accessToken field must be specified.
  19967. properties:
  19968. accessToken:
  19969. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  19970. properties:
  19971. secretRef:
  19972. description: SecretRef is a reference to a secret containing the Pulumi API token.
  19973. properties:
  19974. key:
  19975. description: |-
  19976. A key in the referenced Secret.
  19977. Some instances of this field may be defaulted, in others it may be required.
  19978. maxLength: 253
  19979. minLength: 1
  19980. pattern: ^[-._a-zA-Z0-9]+$
  19981. type: string
  19982. name:
  19983. description: The name of the Secret resource being referred to.
  19984. maxLength: 253
  19985. minLength: 1
  19986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19987. type: string
  19988. namespace:
  19989. description: |-
  19990. The namespace of the Secret resource being referred to.
  19991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19992. maxLength: 63
  19993. minLength: 1
  19994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19995. type: string
  19996. type: object
  19997. type: object
  19998. oidcConfig:
  19999. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20000. properties:
  20001. expirationSeconds:
  20002. default: 600
  20003. description: |-
  20004. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20005. Defaults to 10 minutes.
  20006. format: int64
  20007. minimum: 600
  20008. type: integer
  20009. organization:
  20010. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20011. type: string
  20012. serviceAccountRef:
  20013. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20014. properties:
  20015. audiences:
  20016. description: |-
  20017. Audience specifies the `aud` claim for the service account token
  20018. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20019. then this audiences will be appended to the list
  20020. items:
  20021. type: string
  20022. type: array
  20023. name:
  20024. description: The name of the ServiceAccount resource being referred to.
  20025. maxLength: 253
  20026. minLength: 1
  20027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20028. type: string
  20029. namespace:
  20030. description: |-
  20031. Namespace of the resource being referred to.
  20032. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20033. maxLength: 63
  20034. minLength: 1
  20035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20036. type: string
  20037. required:
  20038. - name
  20039. type: object
  20040. required:
  20041. - organization
  20042. - serviceAccountRef
  20043. type: object
  20044. type: object
  20045. x-kubernetes-validations:
  20046. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20047. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20048. environment:
  20049. description: |-
  20050. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20051. dynamically retrieved values from supported providers including all major clouds,
  20052. and other Pulumi ESC environments.
  20053. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20054. type: string
  20055. organization:
  20056. description: |-
  20057. Organization are a space to collaborate on shared projects and stacks.
  20058. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20059. type: string
  20060. project:
  20061. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20062. type: string
  20063. required:
  20064. - environment
  20065. - organization
  20066. - project
  20067. type: object
  20068. x-kubernetes-validations:
  20069. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20070. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20071. scaleway:
  20072. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20073. properties:
  20074. accessKey:
  20075. description: AccessKey is the non-secret part of the api key.
  20076. properties:
  20077. secretRef:
  20078. description: SecretRef references a key in a secret that will be used as value.
  20079. properties:
  20080. key:
  20081. description: |-
  20082. A key in the referenced Secret.
  20083. Some instances of this field may be defaulted, in others it may be required.
  20084. maxLength: 253
  20085. minLength: 1
  20086. pattern: ^[-._a-zA-Z0-9]+$
  20087. type: string
  20088. name:
  20089. description: The name of the Secret resource being referred to.
  20090. maxLength: 253
  20091. minLength: 1
  20092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20093. type: string
  20094. namespace:
  20095. description: |-
  20096. The namespace of the Secret resource being referred to.
  20097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20098. maxLength: 63
  20099. minLength: 1
  20100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20101. type: string
  20102. type: object
  20103. value:
  20104. description: Value can be specified directly to set a value without using a secret.
  20105. type: string
  20106. type: object
  20107. apiUrl:
  20108. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20109. type: string
  20110. projectId:
  20111. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20112. type: string
  20113. region:
  20114. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20115. type: string
  20116. secretKey:
  20117. description: SecretKey is the non-secret part of the api key.
  20118. properties:
  20119. secretRef:
  20120. description: SecretRef references a key in a secret that will be used as value.
  20121. properties:
  20122. key:
  20123. description: |-
  20124. A key in the referenced Secret.
  20125. Some instances of this field may be defaulted, in others it may be required.
  20126. maxLength: 253
  20127. minLength: 1
  20128. pattern: ^[-._a-zA-Z0-9]+$
  20129. type: string
  20130. name:
  20131. description: The name of the Secret resource being referred to.
  20132. maxLength: 253
  20133. minLength: 1
  20134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20135. type: string
  20136. namespace:
  20137. description: |-
  20138. The namespace of the Secret resource being referred to.
  20139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20140. maxLength: 63
  20141. minLength: 1
  20142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20143. type: string
  20144. type: object
  20145. value:
  20146. description: Value can be specified directly to set a value without using a secret.
  20147. type: string
  20148. type: object
  20149. required:
  20150. - accessKey
  20151. - projectId
  20152. - region
  20153. - secretKey
  20154. type: object
  20155. secretserver:
  20156. description: |-
  20157. SecretServer configures this store to sync secrets using SecretServer provider
  20158. https://docs.delinea.com/online-help/secret-server/start.htm
  20159. properties:
  20160. caBundle:
  20161. description: |-
  20162. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20163. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20164. are used to validate the TLS connection.
  20165. format: byte
  20166. type: string
  20167. caProvider:
  20168. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20169. properties:
  20170. key:
  20171. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20172. maxLength: 253
  20173. minLength: 1
  20174. pattern: ^[-._a-zA-Z0-9]+$
  20175. type: string
  20176. name:
  20177. description: The name of the object located at the provider type.
  20178. maxLength: 253
  20179. minLength: 1
  20180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20181. type: string
  20182. namespace:
  20183. description: |-
  20184. The namespace the Provider type is in.
  20185. Can only be defined when used in a ClusterSecretStore.
  20186. maxLength: 63
  20187. minLength: 1
  20188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20189. type: string
  20190. type:
  20191. description: The type of provider to use such as "Secret", or "ConfigMap".
  20192. enum:
  20193. - Secret
  20194. - ConfigMap
  20195. type: string
  20196. required:
  20197. - name
  20198. - type
  20199. type: object
  20200. domain:
  20201. description: Domain is the secret server domain.
  20202. type: string
  20203. password:
  20204. description: Password is the secret server account password.
  20205. properties:
  20206. secretRef:
  20207. description: SecretRef references a key in a secret that will be used as value.
  20208. properties:
  20209. key:
  20210. description: |-
  20211. A key in the referenced Secret.
  20212. Some instances of this field may be defaulted, in others it may be required.
  20213. maxLength: 253
  20214. minLength: 1
  20215. pattern: ^[-._a-zA-Z0-9]+$
  20216. type: string
  20217. name:
  20218. description: The name of the Secret resource being referred to.
  20219. maxLength: 253
  20220. minLength: 1
  20221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20222. type: string
  20223. namespace:
  20224. description: |-
  20225. The namespace of the Secret resource being referred to.
  20226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20227. maxLength: 63
  20228. minLength: 1
  20229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20230. type: string
  20231. type: object
  20232. value:
  20233. description: Value can be specified directly to set a value without using a secret.
  20234. type: string
  20235. type: object
  20236. serverURL:
  20237. description: |-
  20238. ServerURL
  20239. URL to your secret server installation
  20240. type: string
  20241. username:
  20242. description: Username is the secret server account username.
  20243. properties:
  20244. secretRef:
  20245. description: SecretRef references a key in a secret that will be used as value.
  20246. properties:
  20247. key:
  20248. description: |-
  20249. A key in the referenced Secret.
  20250. Some instances of this field may be defaulted, in others it may be required.
  20251. maxLength: 253
  20252. minLength: 1
  20253. pattern: ^[-._a-zA-Z0-9]+$
  20254. type: string
  20255. name:
  20256. description: The name of the Secret resource being referred to.
  20257. maxLength: 253
  20258. minLength: 1
  20259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20260. type: string
  20261. namespace:
  20262. description: |-
  20263. The namespace of the Secret resource being referred to.
  20264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20265. maxLength: 63
  20266. minLength: 1
  20267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20268. type: string
  20269. type: object
  20270. value:
  20271. description: Value can be specified directly to set a value without using a secret.
  20272. type: string
  20273. type: object
  20274. required:
  20275. - password
  20276. - serverURL
  20277. - username
  20278. type: object
  20279. senhasegura:
  20280. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20281. properties:
  20282. auth:
  20283. description: Auth defines parameters to authenticate in senhasegura
  20284. properties:
  20285. clientId:
  20286. type: string
  20287. clientSecretSecretRef:
  20288. description: |-
  20289. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20290. In some instances, `key` is a required field.
  20291. properties:
  20292. key:
  20293. description: |-
  20294. A key in the referenced Secret.
  20295. Some instances of this field may be defaulted, in others it may be required.
  20296. maxLength: 253
  20297. minLength: 1
  20298. pattern: ^[-._a-zA-Z0-9]+$
  20299. type: string
  20300. name:
  20301. description: The name of the Secret resource being referred to.
  20302. maxLength: 253
  20303. minLength: 1
  20304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20305. type: string
  20306. namespace:
  20307. description: |-
  20308. The namespace of the Secret resource being referred to.
  20309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20310. maxLength: 63
  20311. minLength: 1
  20312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20313. type: string
  20314. type: object
  20315. required:
  20316. - clientId
  20317. - clientSecretSecretRef
  20318. type: object
  20319. ignoreSslCertificate:
  20320. default: false
  20321. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  20322. type: boolean
  20323. module:
  20324. description: Module defines which senhasegura module should be used to get secrets
  20325. type: string
  20326. url:
  20327. description: URL of senhasegura
  20328. type: string
  20329. required:
  20330. - auth
  20331. - module
  20332. - url
  20333. type: object
  20334. vault:
  20335. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  20336. properties:
  20337. auth:
  20338. description: Auth configures how secret-manager authenticates with the Vault server.
  20339. properties:
  20340. appRole:
  20341. description: |-
  20342. AppRole authenticates with Vault using the App Role auth mechanism,
  20343. with the role and secret stored in a Kubernetes Secret resource.
  20344. properties:
  20345. path:
  20346. default: approle
  20347. description: |-
  20348. Path where the App Role authentication backend is mounted
  20349. in Vault, e.g: "approle"
  20350. type: string
  20351. roleId:
  20352. description: |-
  20353. RoleID configured in the App Role authentication backend when setting
  20354. up the authentication backend in Vault.
  20355. type: string
  20356. roleRef:
  20357. description: |-
  20358. Reference to a key in a Secret that contains the App Role ID used
  20359. to authenticate with Vault.
  20360. The `key` field must be specified and denotes which entry within the Secret
  20361. resource is used as the app role id.
  20362. properties:
  20363. key:
  20364. description: |-
  20365. A key in the referenced Secret.
  20366. Some instances of this field may be defaulted, in others it may be required.
  20367. maxLength: 253
  20368. minLength: 1
  20369. pattern: ^[-._a-zA-Z0-9]+$
  20370. type: string
  20371. name:
  20372. description: The name of the Secret resource being referred to.
  20373. maxLength: 253
  20374. minLength: 1
  20375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20376. type: string
  20377. namespace:
  20378. description: |-
  20379. The namespace of the Secret resource being referred to.
  20380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20381. maxLength: 63
  20382. minLength: 1
  20383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20384. type: string
  20385. type: object
  20386. secretRef:
  20387. description: |-
  20388. Reference to a key in a Secret that contains the App Role secret used
  20389. to authenticate with Vault.
  20390. The `key` field must be specified and denotes which entry within the Secret
  20391. resource is used as the app role secret.
  20392. properties:
  20393. key:
  20394. description: |-
  20395. A key in the referenced Secret.
  20396. Some instances of this field may be defaulted, in others it may be required.
  20397. maxLength: 253
  20398. minLength: 1
  20399. pattern: ^[-._a-zA-Z0-9]+$
  20400. type: string
  20401. name:
  20402. description: The name of the Secret resource being referred to.
  20403. maxLength: 253
  20404. minLength: 1
  20405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20406. type: string
  20407. namespace:
  20408. description: |-
  20409. The namespace of the Secret resource being referred to.
  20410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20411. maxLength: 63
  20412. minLength: 1
  20413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20414. type: string
  20415. type: object
  20416. required:
  20417. - path
  20418. - secretRef
  20419. type: object
  20420. cert:
  20421. description: |-
  20422. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  20423. Cert authentication method
  20424. properties:
  20425. clientCert:
  20426. description: |-
  20427. ClientCert is a certificate to authenticate using the Cert Vault
  20428. authentication method
  20429. properties:
  20430. key:
  20431. description: |-
  20432. A key in the referenced Secret.
  20433. Some instances of this field may be defaulted, in others it may be required.
  20434. maxLength: 253
  20435. minLength: 1
  20436. pattern: ^[-._a-zA-Z0-9]+$
  20437. type: string
  20438. name:
  20439. description: The name of the Secret resource being referred to.
  20440. maxLength: 253
  20441. minLength: 1
  20442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20443. type: string
  20444. namespace:
  20445. description: |-
  20446. The namespace of the Secret resource being referred to.
  20447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20448. maxLength: 63
  20449. minLength: 1
  20450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20451. type: string
  20452. type: object
  20453. path:
  20454. default: cert
  20455. description: |-
  20456. Path where the Certificate authentication backend is mounted
  20457. in Vault, e.g: "cert"
  20458. type: string
  20459. secretRef:
  20460. description: |-
  20461. SecretRef to a key in a Secret resource containing client private key to
  20462. authenticate with Vault using the Cert authentication method
  20463. properties:
  20464. key:
  20465. description: |-
  20466. A key in the referenced Secret.
  20467. Some instances of this field may be defaulted, in others it may be required.
  20468. maxLength: 253
  20469. minLength: 1
  20470. pattern: ^[-._a-zA-Z0-9]+$
  20471. type: string
  20472. name:
  20473. description: The name of the Secret resource being referred to.
  20474. maxLength: 253
  20475. minLength: 1
  20476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20477. type: string
  20478. namespace:
  20479. description: |-
  20480. The namespace of the Secret resource being referred to.
  20481. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20482. maxLength: 63
  20483. minLength: 1
  20484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20485. type: string
  20486. type: object
  20487. vaultRole:
  20488. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  20489. type: string
  20490. type: object
  20491. gcp:
  20492. description: |-
  20493. Gcp authenticates with Vault using Google Cloud Platform authentication method
  20494. GCP authentication method
  20495. properties:
  20496. location:
  20497. description: Location optionally defines a location/region for the secret
  20498. type: string
  20499. path:
  20500. default: gcp
  20501. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  20502. type: string
  20503. projectID:
  20504. description: Project ID of the Google Cloud Platform project
  20505. type: string
  20506. role:
  20507. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  20508. type: string
  20509. secretRef:
  20510. description: Specify credentials in a Secret object
  20511. properties:
  20512. secretAccessKeySecretRef:
  20513. description: The SecretAccessKey is used for authentication
  20514. properties:
  20515. key:
  20516. description: |-
  20517. A key in the referenced Secret.
  20518. Some instances of this field may be defaulted, in others it may be required.
  20519. maxLength: 253
  20520. minLength: 1
  20521. pattern: ^[-._a-zA-Z0-9]+$
  20522. type: string
  20523. name:
  20524. description: The name of the Secret resource being referred to.
  20525. maxLength: 253
  20526. minLength: 1
  20527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20528. type: string
  20529. namespace:
  20530. description: |-
  20531. The namespace of the Secret resource being referred to.
  20532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20533. maxLength: 63
  20534. minLength: 1
  20535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20536. type: string
  20537. type: object
  20538. type: object
  20539. serviceAccountRef:
  20540. description: ServiceAccountRef to a service account for impersonation
  20541. properties:
  20542. audiences:
  20543. description: |-
  20544. Audience specifies the `aud` claim for the service account token
  20545. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20546. then this audiences will be appended to the list
  20547. items:
  20548. type: string
  20549. type: array
  20550. name:
  20551. description: The name of the ServiceAccount resource being referred to.
  20552. maxLength: 253
  20553. minLength: 1
  20554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20555. type: string
  20556. namespace:
  20557. description: |-
  20558. Namespace of the resource being referred to.
  20559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20560. maxLength: 63
  20561. minLength: 1
  20562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20563. type: string
  20564. required:
  20565. - name
  20566. type: object
  20567. workloadIdentity:
  20568. description: Specify a service account with Workload Identity
  20569. properties:
  20570. clusterLocation:
  20571. description: |-
  20572. ClusterLocation is the location of the cluster
  20573. If not specified, it fetches information from the metadata server
  20574. type: string
  20575. clusterName:
  20576. description: |-
  20577. ClusterName is the name of the cluster
  20578. If not specified, it fetches information from the metadata server
  20579. type: string
  20580. clusterProjectID:
  20581. description: |-
  20582. ClusterProjectID is the project ID of the cluster
  20583. If not specified, it fetches information from the metadata server
  20584. type: string
  20585. serviceAccountRef:
  20586. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  20587. properties:
  20588. audiences:
  20589. description: |-
  20590. Audience specifies the `aud` claim for the service account token
  20591. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20592. then this audiences will be appended to the list
  20593. items:
  20594. type: string
  20595. type: array
  20596. name:
  20597. description: The name of the ServiceAccount resource being referred to.
  20598. maxLength: 253
  20599. minLength: 1
  20600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20601. type: string
  20602. namespace:
  20603. description: |-
  20604. Namespace of the resource being referred to.
  20605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20606. maxLength: 63
  20607. minLength: 1
  20608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20609. type: string
  20610. required:
  20611. - name
  20612. type: object
  20613. required:
  20614. - serviceAccountRef
  20615. type: object
  20616. required:
  20617. - role
  20618. type: object
  20619. iam:
  20620. description: |-
  20621. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  20622. AWS IAM authentication method
  20623. properties:
  20624. externalID:
  20625. description: AWS External ID set on assumed IAM roles
  20626. type: string
  20627. jwt:
  20628. description: Specify a service account with IRSA enabled
  20629. properties:
  20630. serviceAccountRef:
  20631. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  20632. properties:
  20633. audiences:
  20634. description: |-
  20635. Audience specifies the `aud` claim for the service account token
  20636. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20637. then this audiences will be appended to the list
  20638. items:
  20639. type: string
  20640. type: array
  20641. name:
  20642. description: The name of the ServiceAccount resource being referred to.
  20643. maxLength: 253
  20644. minLength: 1
  20645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20646. type: string
  20647. namespace:
  20648. description: |-
  20649. Namespace of the resource being referred to.
  20650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20651. maxLength: 63
  20652. minLength: 1
  20653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20654. type: string
  20655. required:
  20656. - name
  20657. type: object
  20658. type: object
  20659. path:
  20660. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  20661. type: string
  20662. region:
  20663. description: AWS region
  20664. type: string
  20665. role:
  20666. description: This is the AWS role to be assumed before talking to vault
  20667. type: string
  20668. secretRef:
  20669. description: Specify credentials in a Secret object
  20670. properties:
  20671. accessKeyIDSecretRef:
  20672. description: The AccessKeyID is used for authentication
  20673. properties:
  20674. key:
  20675. description: |-
  20676. A key in the referenced Secret.
  20677. Some instances of this field may be defaulted, in others it may be required.
  20678. maxLength: 253
  20679. minLength: 1
  20680. pattern: ^[-._a-zA-Z0-9]+$
  20681. type: string
  20682. name:
  20683. description: The name of the Secret resource being referred to.
  20684. maxLength: 253
  20685. minLength: 1
  20686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20687. type: string
  20688. namespace:
  20689. description: |-
  20690. The namespace of the Secret resource being referred to.
  20691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20692. maxLength: 63
  20693. minLength: 1
  20694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20695. type: string
  20696. type: object
  20697. secretAccessKeySecretRef:
  20698. description: The SecretAccessKey is used for authentication
  20699. properties:
  20700. key:
  20701. description: |-
  20702. A key in the referenced Secret.
  20703. Some instances of this field may be defaulted, in others it may be required.
  20704. maxLength: 253
  20705. minLength: 1
  20706. pattern: ^[-._a-zA-Z0-9]+$
  20707. type: string
  20708. name:
  20709. description: The name of the Secret resource being referred to.
  20710. maxLength: 253
  20711. minLength: 1
  20712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20713. type: string
  20714. namespace:
  20715. description: |-
  20716. The namespace of the Secret resource being referred to.
  20717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20718. maxLength: 63
  20719. minLength: 1
  20720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20721. type: string
  20722. type: object
  20723. sessionTokenSecretRef:
  20724. description: |-
  20725. The SessionToken used for authentication
  20726. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  20727. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  20728. properties:
  20729. key:
  20730. description: |-
  20731. A key in the referenced Secret.
  20732. Some instances of this field may be defaulted, in others it may be required.
  20733. maxLength: 253
  20734. minLength: 1
  20735. pattern: ^[-._a-zA-Z0-9]+$
  20736. type: string
  20737. name:
  20738. description: The name of the Secret resource being referred to.
  20739. maxLength: 253
  20740. minLength: 1
  20741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20742. type: string
  20743. namespace:
  20744. description: |-
  20745. The namespace of the Secret resource being referred to.
  20746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20747. maxLength: 63
  20748. minLength: 1
  20749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20750. type: string
  20751. type: object
  20752. type: object
  20753. vaultAwsIamServerID:
  20754. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  20755. type: string
  20756. vaultRole:
  20757. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  20758. type: string
  20759. required:
  20760. - vaultRole
  20761. type: object
  20762. jwt:
  20763. description: |-
  20764. Jwt authenticates with Vault by passing role and JWT token using the
  20765. JWT/OIDC authentication method
  20766. properties:
  20767. kubernetesServiceAccountToken:
  20768. description: |-
  20769. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  20770. a token for with the `TokenRequest` API.
  20771. properties:
  20772. audiences:
  20773. description: |-
  20774. Optional audiences field that will be used to request a temporary Kubernetes service
  20775. account token for the service account referenced by `serviceAccountRef`.
  20776. Defaults to a single audience `vault` it not specified.
  20777. Deprecated: use serviceAccountRef.Audiences instead
  20778. items:
  20779. type: string
  20780. type: array
  20781. expirationSeconds:
  20782. description: |-
  20783. Optional expiration time in seconds that will be used to request a temporary
  20784. Kubernetes service account token for the service account referenced by
  20785. `serviceAccountRef`.
  20786. Deprecated: this will be removed in the future.
  20787. Defaults to 10 minutes.
  20788. format: int64
  20789. type: integer
  20790. serviceAccountRef:
  20791. description: Service account field containing the name of a kubernetes ServiceAccount.
  20792. properties:
  20793. audiences:
  20794. description: |-
  20795. Audience specifies the `aud` claim for the service account token
  20796. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20797. then this audiences will be appended to the list
  20798. items:
  20799. type: string
  20800. type: array
  20801. name:
  20802. description: The name of the ServiceAccount resource being referred to.
  20803. maxLength: 253
  20804. minLength: 1
  20805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20806. type: string
  20807. namespace:
  20808. description: |-
  20809. Namespace of the resource being referred to.
  20810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20811. maxLength: 63
  20812. minLength: 1
  20813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20814. type: string
  20815. required:
  20816. - name
  20817. type: object
  20818. required:
  20819. - serviceAccountRef
  20820. type: object
  20821. path:
  20822. default: jwt
  20823. description: |-
  20824. Path where the JWT authentication backend is mounted
  20825. in Vault, e.g: "jwt"
  20826. type: string
  20827. role:
  20828. description: |-
  20829. Role is a JWT role to authenticate using the JWT/OIDC Vault
  20830. authentication method
  20831. type: string
  20832. secretRef:
  20833. description: |-
  20834. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  20835. authenticate with Vault using the JWT/OIDC authentication method.
  20836. properties:
  20837. key:
  20838. description: |-
  20839. A key in the referenced Secret.
  20840. Some instances of this field may be defaulted, in others it may be required.
  20841. maxLength: 253
  20842. minLength: 1
  20843. pattern: ^[-._a-zA-Z0-9]+$
  20844. type: string
  20845. name:
  20846. description: The name of the Secret resource being referred to.
  20847. maxLength: 253
  20848. minLength: 1
  20849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20850. type: string
  20851. namespace:
  20852. description: |-
  20853. The namespace of the Secret resource being referred to.
  20854. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20855. maxLength: 63
  20856. minLength: 1
  20857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20858. type: string
  20859. type: object
  20860. required:
  20861. - path
  20862. type: object
  20863. kubernetes:
  20864. description: |-
  20865. Kubernetes authenticates with Vault by passing the ServiceAccount
  20866. token stored in the named Secret resource to the Vault server.
  20867. properties:
  20868. mountPath:
  20869. default: kubernetes
  20870. description: |-
  20871. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  20872. "kubernetes"
  20873. type: string
  20874. role:
  20875. description: |-
  20876. A required field containing the Vault Role to assume. A Role binds a
  20877. Kubernetes ServiceAccount with a set of Vault policies.
  20878. type: string
  20879. secretRef:
  20880. description: |-
  20881. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20882. for authenticating with Vault. If a name is specified without a key,
  20883. `token` is the default. If one is not specified, the one bound to
  20884. the controller will be used.
  20885. properties:
  20886. key:
  20887. description: |-
  20888. A key in the referenced Secret.
  20889. Some instances of this field may be defaulted, in others it may be required.
  20890. maxLength: 253
  20891. minLength: 1
  20892. pattern: ^[-._a-zA-Z0-9]+$
  20893. type: string
  20894. name:
  20895. description: The name of the Secret resource being referred to.
  20896. maxLength: 253
  20897. minLength: 1
  20898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20899. type: string
  20900. namespace:
  20901. description: |-
  20902. The namespace of the Secret resource being referred to.
  20903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20904. maxLength: 63
  20905. minLength: 1
  20906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20907. type: string
  20908. type: object
  20909. serviceAccountRef:
  20910. description: |-
  20911. Optional service account field containing the name of a kubernetes ServiceAccount.
  20912. If the service account is specified, the service account secret token JWT will be used
  20913. for authenticating with Vault. If the service account selector is not supplied,
  20914. the secretRef will be used instead.
  20915. properties:
  20916. audiences:
  20917. description: |-
  20918. Audience specifies the `aud` claim for the service account token
  20919. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20920. then this audiences will be appended to the list
  20921. items:
  20922. type: string
  20923. type: array
  20924. name:
  20925. description: The name of the ServiceAccount resource being referred to.
  20926. maxLength: 253
  20927. minLength: 1
  20928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20929. type: string
  20930. namespace:
  20931. description: |-
  20932. Namespace of the resource being referred to.
  20933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20934. maxLength: 63
  20935. minLength: 1
  20936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20937. type: string
  20938. required:
  20939. - name
  20940. type: object
  20941. required:
  20942. - mountPath
  20943. - role
  20944. type: object
  20945. ldap:
  20946. description: |-
  20947. Ldap authenticates with Vault by passing username/password pair using
  20948. the LDAP authentication method
  20949. properties:
  20950. path:
  20951. default: ldap
  20952. description: |-
  20953. Path where the LDAP authentication backend is mounted
  20954. in Vault, e.g: "ldap"
  20955. type: string
  20956. secretRef:
  20957. description: |-
  20958. SecretRef to a key in a Secret resource containing password for the LDAP
  20959. user used to authenticate with Vault using the LDAP authentication
  20960. method
  20961. properties:
  20962. key:
  20963. description: |-
  20964. A key in the referenced Secret.
  20965. Some instances of this field may be defaulted, in others it may be required.
  20966. maxLength: 253
  20967. minLength: 1
  20968. pattern: ^[-._a-zA-Z0-9]+$
  20969. type: string
  20970. name:
  20971. description: The name of the Secret resource being referred to.
  20972. maxLength: 253
  20973. minLength: 1
  20974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20975. type: string
  20976. namespace:
  20977. description: |-
  20978. The namespace of the Secret resource being referred to.
  20979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20980. maxLength: 63
  20981. minLength: 1
  20982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20983. type: string
  20984. type: object
  20985. username:
  20986. description: |-
  20987. Username is an LDAP username used to authenticate using the LDAP Vault
  20988. authentication method
  20989. type: string
  20990. required:
  20991. - path
  20992. - username
  20993. type: object
  20994. namespace:
  20995. description: |-
  20996. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  20997. Namespaces is a set of features within Vault Enterprise that allows
  20998. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  20999. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21000. This will default to Vault.Namespace field if set, or empty otherwise
  21001. type: string
  21002. tokenSecretRef:
  21003. description: TokenSecretRef authenticates with Vault by presenting a token.
  21004. properties:
  21005. key:
  21006. description: |-
  21007. A key in the referenced Secret.
  21008. Some instances of this field may be defaulted, in others it may be required.
  21009. maxLength: 253
  21010. minLength: 1
  21011. pattern: ^[-._a-zA-Z0-9]+$
  21012. type: string
  21013. name:
  21014. description: The name of the Secret resource being referred to.
  21015. maxLength: 253
  21016. minLength: 1
  21017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21018. type: string
  21019. namespace:
  21020. description: |-
  21021. The namespace of the Secret resource being referred to.
  21022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21023. maxLength: 63
  21024. minLength: 1
  21025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21026. type: string
  21027. type: object
  21028. userPass:
  21029. description: UserPass authenticates with Vault by passing username/password pair
  21030. properties:
  21031. path:
  21032. default: userpass
  21033. description: |-
  21034. Path where the UserPassword authentication backend is mounted
  21035. in Vault, e.g: "userpass"
  21036. type: string
  21037. secretRef:
  21038. description: |-
  21039. SecretRef to a key in a Secret resource containing password for the
  21040. user used to authenticate with Vault using the UserPass authentication
  21041. method
  21042. properties:
  21043. key:
  21044. description: |-
  21045. A key in the referenced Secret.
  21046. Some instances of this field may be defaulted, in others it may be required.
  21047. maxLength: 253
  21048. minLength: 1
  21049. pattern: ^[-._a-zA-Z0-9]+$
  21050. type: string
  21051. name:
  21052. description: The name of the Secret resource being referred to.
  21053. maxLength: 253
  21054. minLength: 1
  21055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21056. type: string
  21057. namespace:
  21058. description: |-
  21059. The namespace of the Secret resource being referred to.
  21060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21061. maxLength: 63
  21062. minLength: 1
  21063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21064. type: string
  21065. type: object
  21066. username:
  21067. description: |-
  21068. Username is a username used to authenticate using the UserPass Vault
  21069. authentication method
  21070. type: string
  21071. required:
  21072. - path
  21073. - username
  21074. type: object
  21075. type: object
  21076. caBundle:
  21077. description: |-
  21078. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21079. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21080. plain HTTP protocol connection. If not set the system root certificates
  21081. are used to validate the TLS connection.
  21082. format: byte
  21083. type: string
  21084. caProvider:
  21085. description: The provider for the CA bundle to use to validate Vault server certificate.
  21086. properties:
  21087. key:
  21088. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21089. maxLength: 253
  21090. minLength: 1
  21091. pattern: ^[-._a-zA-Z0-9]+$
  21092. type: string
  21093. name:
  21094. description: The name of the object located at the provider type.
  21095. maxLength: 253
  21096. minLength: 1
  21097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21098. type: string
  21099. namespace:
  21100. description: |-
  21101. The namespace the Provider type is in.
  21102. Can only be defined when used in a ClusterSecretStore.
  21103. maxLength: 63
  21104. minLength: 1
  21105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21106. type: string
  21107. type:
  21108. description: The type of provider to use such as "Secret", or "ConfigMap".
  21109. enum:
  21110. - Secret
  21111. - ConfigMap
  21112. type: string
  21113. required:
  21114. - name
  21115. - type
  21116. type: object
  21117. checkAndSet:
  21118. description: |-
  21119. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21120. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21121. the current version of the secret to prevent unintentional overwrites.
  21122. properties:
  21123. required:
  21124. description: |-
  21125. Required when true, all write operations must include a check-and-set parameter.
  21126. This helps prevent unintentional overwrites of secrets.
  21127. type: boolean
  21128. type: object
  21129. forwardInconsistent:
  21130. description: |-
  21131. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21132. leader instead of simply retrying within a loop. This can increase performance if
  21133. the option is enabled serverside.
  21134. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21135. type: boolean
  21136. headers:
  21137. additionalProperties:
  21138. type: string
  21139. description: Headers to be added in Vault request
  21140. type: object
  21141. namespace:
  21142. description: |-
  21143. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21144. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21145. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21146. type: string
  21147. path:
  21148. description: |-
  21149. Path is the mount path of the Vault KV backend endpoint, e.g:
  21150. "secret". The v2 KV secret engine version specific "/data" path suffix
  21151. for fetching secrets from Vault is optional and will be appended
  21152. if not present in specified path.
  21153. type: string
  21154. readYourWrites:
  21155. description: |-
  21156. ReadYourWrites ensures isolated read-after-write semantics by
  21157. providing discovered cluster replication states in each request.
  21158. More information about eventual consistency in Vault can be found here
  21159. https://www.vaultproject.io/docs/enterprise/consistency
  21160. type: boolean
  21161. server:
  21162. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21163. type: string
  21164. tls:
  21165. description: |-
  21166. The configuration used for client side related TLS communication, when the Vault server
  21167. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21168. This parameter is ignored for plain HTTP protocol connection.
  21169. It's worth noting this configuration is different from the "TLS certificates auth method",
  21170. which is available under the `auth.cert` section.
  21171. properties:
  21172. certSecretRef:
  21173. description: |-
  21174. CertSecretRef is a certificate added to the transport layer
  21175. when communicating with the Vault server.
  21176. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21177. properties:
  21178. key:
  21179. description: |-
  21180. A key in the referenced Secret.
  21181. Some instances of this field may be defaulted, in others it may be required.
  21182. maxLength: 253
  21183. minLength: 1
  21184. pattern: ^[-._a-zA-Z0-9]+$
  21185. type: string
  21186. name:
  21187. description: The name of the Secret resource being referred to.
  21188. maxLength: 253
  21189. minLength: 1
  21190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21191. type: string
  21192. namespace:
  21193. description: |-
  21194. The namespace of the Secret resource being referred to.
  21195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21196. maxLength: 63
  21197. minLength: 1
  21198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21199. type: string
  21200. type: object
  21201. keySecretRef:
  21202. description: |-
  21203. KeySecretRef to a key in a Secret resource containing client private key
  21204. added to the transport layer when communicating with the Vault server.
  21205. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21206. properties:
  21207. key:
  21208. description: |-
  21209. A key in the referenced Secret.
  21210. Some instances of this field may be defaulted, in others it may be required.
  21211. maxLength: 253
  21212. minLength: 1
  21213. pattern: ^[-._a-zA-Z0-9]+$
  21214. type: string
  21215. name:
  21216. description: The name of the Secret resource being referred to.
  21217. maxLength: 253
  21218. minLength: 1
  21219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21220. type: string
  21221. namespace:
  21222. description: |-
  21223. The namespace of the Secret resource being referred to.
  21224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21225. maxLength: 63
  21226. minLength: 1
  21227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21228. type: string
  21229. type: object
  21230. type: object
  21231. version:
  21232. default: v2
  21233. description: |-
  21234. Version is the Vault KV secret engine version. This can be either "v1" or
  21235. "v2". Version defaults to "v2".
  21236. enum:
  21237. - v1
  21238. - v2
  21239. type: string
  21240. required:
  21241. - server
  21242. type: object
  21243. volcengine:
  21244. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21245. properties:
  21246. auth:
  21247. description: |-
  21248. Auth defines the authentication method to use.
  21249. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21250. properties:
  21251. secretRef:
  21252. description: |-
  21253. SecretRef defines the static credentials to use for authentication.
  21254. If not set, IRSA is used.
  21255. properties:
  21256. accessKeyID:
  21257. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21258. properties:
  21259. key:
  21260. description: |-
  21261. A key in the referenced Secret.
  21262. Some instances of this field may be defaulted, in others it may be required.
  21263. maxLength: 253
  21264. minLength: 1
  21265. pattern: ^[-._a-zA-Z0-9]+$
  21266. type: string
  21267. name:
  21268. description: The name of the Secret resource being referred to.
  21269. maxLength: 253
  21270. minLength: 1
  21271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21272. type: string
  21273. namespace:
  21274. description: |-
  21275. The namespace of the Secret resource being referred to.
  21276. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21277. maxLength: 63
  21278. minLength: 1
  21279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21280. type: string
  21281. type: object
  21282. secretAccessKey:
  21283. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21284. properties:
  21285. key:
  21286. description: |-
  21287. A key in the referenced Secret.
  21288. Some instances of this field may be defaulted, in others it may be required.
  21289. maxLength: 253
  21290. minLength: 1
  21291. pattern: ^[-._a-zA-Z0-9]+$
  21292. type: string
  21293. name:
  21294. description: The name of the Secret resource being referred to.
  21295. maxLength: 253
  21296. minLength: 1
  21297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21298. type: string
  21299. namespace:
  21300. description: |-
  21301. The namespace of the Secret resource being referred to.
  21302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21303. maxLength: 63
  21304. minLength: 1
  21305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21306. type: string
  21307. type: object
  21308. token:
  21309. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  21310. properties:
  21311. key:
  21312. description: |-
  21313. A key in the referenced Secret.
  21314. Some instances of this field may be defaulted, in others it may be required.
  21315. maxLength: 253
  21316. minLength: 1
  21317. pattern: ^[-._a-zA-Z0-9]+$
  21318. type: string
  21319. name:
  21320. description: The name of the Secret resource being referred to.
  21321. maxLength: 253
  21322. minLength: 1
  21323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21324. type: string
  21325. namespace:
  21326. description: |-
  21327. The namespace of the Secret resource being referred to.
  21328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21329. maxLength: 63
  21330. minLength: 1
  21331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21332. type: string
  21333. type: object
  21334. required:
  21335. - accessKeyID
  21336. - secretAccessKey
  21337. type: object
  21338. type: object
  21339. region:
  21340. description: Region specifies the Volcengine region to connect to.
  21341. type: string
  21342. required:
  21343. - region
  21344. type: object
  21345. webhook:
  21346. description: Webhook configures this store to sync secrets using a generic templated webhook
  21347. properties:
  21348. auth:
  21349. description: Auth specifies a authorization protocol. Only one protocol may be set.
  21350. maxProperties: 1
  21351. minProperties: 1
  21352. properties:
  21353. ntlm:
  21354. description: NTLMProtocol configures the store to use NTLM for auth
  21355. properties:
  21356. passwordSecret:
  21357. description: |-
  21358. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21359. In some instances, `key` is a required field.
  21360. properties:
  21361. key:
  21362. description: |-
  21363. A key in the referenced Secret.
  21364. Some instances of this field may be defaulted, in others it may be required.
  21365. maxLength: 253
  21366. minLength: 1
  21367. pattern: ^[-._a-zA-Z0-9]+$
  21368. type: string
  21369. name:
  21370. description: The name of the Secret resource being referred to.
  21371. maxLength: 253
  21372. minLength: 1
  21373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21374. type: string
  21375. namespace:
  21376. description: |-
  21377. The namespace of the Secret resource being referred to.
  21378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21379. maxLength: 63
  21380. minLength: 1
  21381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21382. type: string
  21383. type: object
  21384. usernameSecret:
  21385. description: |-
  21386. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21387. In some instances, `key` is a required field.
  21388. properties:
  21389. key:
  21390. description: |-
  21391. A key in the referenced Secret.
  21392. Some instances of this field may be defaulted, in others it may be required.
  21393. maxLength: 253
  21394. minLength: 1
  21395. pattern: ^[-._a-zA-Z0-9]+$
  21396. type: string
  21397. name:
  21398. description: The name of the Secret resource being referred to.
  21399. maxLength: 253
  21400. minLength: 1
  21401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21402. type: string
  21403. namespace:
  21404. description: |-
  21405. The namespace of the Secret resource being referred to.
  21406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21407. maxLength: 63
  21408. minLength: 1
  21409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21410. type: string
  21411. type: object
  21412. required:
  21413. - passwordSecret
  21414. - usernameSecret
  21415. type: object
  21416. type: object
  21417. body:
  21418. description: Body
  21419. type: string
  21420. caBundle:
  21421. description: |-
  21422. PEM encoded CA bundle used to validate webhook server certificate. Only used
  21423. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21424. plain HTTP protocol connection. If not set the system root certificates
  21425. are used to validate the TLS connection.
  21426. format: byte
  21427. type: string
  21428. caProvider:
  21429. description: The provider for the CA bundle to use to validate webhook server certificate.
  21430. properties:
  21431. key:
  21432. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21433. maxLength: 253
  21434. minLength: 1
  21435. pattern: ^[-._a-zA-Z0-9]+$
  21436. type: string
  21437. name:
  21438. description: The name of the object located at the provider type.
  21439. maxLength: 253
  21440. minLength: 1
  21441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21442. type: string
  21443. namespace:
  21444. description: The namespace the Provider type is in.
  21445. maxLength: 63
  21446. minLength: 1
  21447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21448. type: string
  21449. type:
  21450. description: The type of provider to use such as "Secret", or "ConfigMap".
  21451. enum:
  21452. - Secret
  21453. - ConfigMap
  21454. type: string
  21455. required:
  21456. - name
  21457. - type
  21458. type: object
  21459. headers:
  21460. additionalProperties:
  21461. type: string
  21462. description: Headers
  21463. type: object
  21464. method:
  21465. description: Webhook Method
  21466. type: string
  21467. result:
  21468. description: Result formatting
  21469. properties:
  21470. jsonPath:
  21471. description: Json path of return value
  21472. type: string
  21473. type: object
  21474. secrets:
  21475. description: |-
  21476. Secrets to fill in templates
  21477. These secrets will be passed to the templating function as key value pairs under the given name
  21478. items:
  21479. description: WebhookSecret defines a secret that will be passed to the webhook request.
  21480. properties:
  21481. name:
  21482. description: Name of this secret in templates
  21483. type: string
  21484. secretRef:
  21485. description: Secret ref to fill in credentials
  21486. properties:
  21487. key:
  21488. description: |-
  21489. A key in the referenced Secret.
  21490. Some instances of this field may be defaulted, in others it may be required.
  21491. maxLength: 253
  21492. minLength: 1
  21493. pattern: ^[-._a-zA-Z0-9]+$
  21494. type: string
  21495. name:
  21496. description: The name of the Secret resource being referred to.
  21497. maxLength: 253
  21498. minLength: 1
  21499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21500. type: string
  21501. namespace:
  21502. description: |-
  21503. The namespace of the Secret resource being referred to.
  21504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21505. maxLength: 63
  21506. minLength: 1
  21507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21508. type: string
  21509. type: object
  21510. required:
  21511. - name
  21512. - secretRef
  21513. type: object
  21514. type: array
  21515. timeout:
  21516. description: Timeout
  21517. type: string
  21518. url:
  21519. description: Webhook url to call
  21520. type: string
  21521. required:
  21522. - url
  21523. type: object
  21524. yandexcertificatemanager:
  21525. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  21526. properties:
  21527. apiEndpoint:
  21528. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  21529. type: string
  21530. auth:
  21531. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  21532. properties:
  21533. authorizedKeySecretRef:
  21534. description: The authorized key used for authentication
  21535. properties:
  21536. key:
  21537. description: |-
  21538. A key in the referenced Secret.
  21539. Some instances of this field may be defaulted, in others it may be required.
  21540. maxLength: 253
  21541. minLength: 1
  21542. pattern: ^[-._a-zA-Z0-9]+$
  21543. type: string
  21544. name:
  21545. description: The name of the Secret resource being referred to.
  21546. maxLength: 253
  21547. minLength: 1
  21548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21549. type: string
  21550. namespace:
  21551. description: |-
  21552. The namespace of the Secret resource being referred to.
  21553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21554. maxLength: 63
  21555. minLength: 1
  21556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21557. type: string
  21558. type: object
  21559. type: object
  21560. caProvider:
  21561. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  21562. properties:
  21563. certSecretRef:
  21564. description: |-
  21565. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21566. In some instances, `key` is a required field.
  21567. properties:
  21568. key:
  21569. description: |-
  21570. A key in the referenced Secret.
  21571. Some instances of this field may be defaulted, in others it may be required.
  21572. maxLength: 253
  21573. minLength: 1
  21574. pattern: ^[-._a-zA-Z0-9]+$
  21575. type: string
  21576. name:
  21577. description: The name of the Secret resource being referred to.
  21578. maxLength: 253
  21579. minLength: 1
  21580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21581. type: string
  21582. namespace:
  21583. description: |-
  21584. The namespace of the Secret resource being referred to.
  21585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21586. maxLength: 63
  21587. minLength: 1
  21588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21589. type: string
  21590. type: object
  21591. type: object
  21592. fetching:
  21593. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  21594. maxProperties: 1
  21595. minProperties: 1
  21596. properties:
  21597. byID:
  21598. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  21599. type: object
  21600. byName:
  21601. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  21602. properties:
  21603. folderID:
  21604. description: The folder to fetch secrets from
  21605. type: string
  21606. required:
  21607. - folderID
  21608. type: object
  21609. type: object
  21610. required:
  21611. - auth
  21612. type: object
  21613. yandexlockbox:
  21614. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  21615. properties:
  21616. apiEndpoint:
  21617. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  21618. type: string
  21619. auth:
  21620. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  21621. properties:
  21622. authorizedKeySecretRef:
  21623. description: The authorized key used for authentication
  21624. properties:
  21625. key:
  21626. description: |-
  21627. A key in the referenced Secret.
  21628. Some instances of this field may be defaulted, in others it may be required.
  21629. maxLength: 253
  21630. minLength: 1
  21631. pattern: ^[-._a-zA-Z0-9]+$
  21632. type: string
  21633. name:
  21634. description: The name of the Secret resource being referred to.
  21635. maxLength: 253
  21636. minLength: 1
  21637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21638. type: string
  21639. namespace:
  21640. description: |-
  21641. The namespace of the Secret resource being referred to.
  21642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21643. maxLength: 63
  21644. minLength: 1
  21645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21646. type: string
  21647. type: object
  21648. type: object
  21649. caProvider:
  21650. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  21651. properties:
  21652. certSecretRef:
  21653. description: |-
  21654. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21655. In some instances, `key` is a required field.
  21656. properties:
  21657. key:
  21658. description: |-
  21659. A key in the referenced Secret.
  21660. Some instances of this field may be defaulted, in others it may be required.
  21661. maxLength: 253
  21662. minLength: 1
  21663. pattern: ^[-._a-zA-Z0-9]+$
  21664. type: string
  21665. name:
  21666. description: The name of the Secret resource being referred to.
  21667. maxLength: 253
  21668. minLength: 1
  21669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21670. type: string
  21671. namespace:
  21672. description: |-
  21673. The namespace of the Secret resource being referred to.
  21674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21675. maxLength: 63
  21676. minLength: 1
  21677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21678. type: string
  21679. type: object
  21680. type: object
  21681. fetching:
  21682. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  21683. maxProperties: 1
  21684. minProperties: 1
  21685. properties:
  21686. byID:
  21687. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  21688. type: object
  21689. byName:
  21690. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  21691. properties:
  21692. folderID:
  21693. description: The folder to fetch secrets from
  21694. type: string
  21695. required:
  21696. - folderID
  21697. type: object
  21698. type: object
  21699. required:
  21700. - auth
  21701. type: object
  21702. type: object
  21703. refreshInterval:
  21704. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  21705. type: integer
  21706. retrySettings:
  21707. description: Used to configure HTTP retries on failures.
  21708. properties:
  21709. maxRetries:
  21710. format: int32
  21711. type: integer
  21712. retryInterval:
  21713. type: string
  21714. type: object
  21715. required:
  21716. - provider
  21717. type: object
  21718. status:
  21719. description: SecretStoreStatus defines the observed state of the SecretStore.
  21720. properties:
  21721. capabilities:
  21722. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  21723. type: string
  21724. conditions:
  21725. items:
  21726. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  21727. properties:
  21728. lastTransitionTime:
  21729. format: date-time
  21730. type: string
  21731. message:
  21732. type: string
  21733. reason:
  21734. type: string
  21735. status:
  21736. type: string
  21737. type:
  21738. description: SecretStoreConditionType represents the condition of the SecretStore.
  21739. type: string
  21740. required:
  21741. - status
  21742. - type
  21743. type: object
  21744. type: array
  21745. type: object
  21746. type: object
  21747. served: true
  21748. storage: true
  21749. subresources:
  21750. status: {}
  21751. - additionalPrinterColumns:
  21752. - jsonPath: .metadata.creationTimestamp
  21753. name: AGE
  21754. type: date
  21755. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  21756. name: Status
  21757. type: string
  21758. - jsonPath: .status.capabilities
  21759. name: Capabilities
  21760. type: string
  21761. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  21762. name: Ready
  21763. type: string
  21764. deprecated: true
  21765. name: v1beta1
  21766. schema:
  21767. openAPIV3Schema:
  21768. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  21769. properties:
  21770. apiVersion:
  21771. description: |-
  21772. APIVersion defines the versioned schema of this representation of an object.
  21773. Servers should convert recognized schemas to the latest internal value, and
  21774. may reject unrecognized values.
  21775. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  21776. type: string
  21777. kind:
  21778. description: |-
  21779. Kind is a string value representing the REST resource this object represents.
  21780. Servers may infer this from the endpoint the client submits requests to.
  21781. Cannot be updated.
  21782. In CamelCase.
  21783. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  21784. type: string
  21785. metadata:
  21786. type: object
  21787. spec:
  21788. description: SecretStoreSpec defines the desired state of SecretStore.
  21789. properties:
  21790. conditions:
  21791. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  21792. items:
  21793. description: |-
  21794. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  21795. for a ClusterSecretStore instance.
  21796. properties:
  21797. namespaceRegexes:
  21798. description: Choose namespaces by using regex matching
  21799. items:
  21800. type: string
  21801. type: array
  21802. namespaceSelector:
  21803. description: Choose namespace using a labelSelector
  21804. properties:
  21805. matchExpressions:
  21806. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  21807. items:
  21808. description: |-
  21809. A label selector requirement is a selector that contains values, a key, and an operator that
  21810. relates the key and values.
  21811. properties:
  21812. key:
  21813. description: key is the label key that the selector applies to.
  21814. type: string
  21815. operator:
  21816. description: |-
  21817. operator represents a key's relationship to a set of values.
  21818. Valid operators are In, NotIn, Exists and DoesNotExist.
  21819. type: string
  21820. values:
  21821. description: |-
  21822. values is an array of string values. If the operator is In or NotIn,
  21823. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  21824. the values array must be empty. This array is replaced during a strategic
  21825. merge patch.
  21826. items:
  21827. type: string
  21828. type: array
  21829. x-kubernetes-list-type: atomic
  21830. required:
  21831. - key
  21832. - operator
  21833. type: object
  21834. type: array
  21835. x-kubernetes-list-type: atomic
  21836. matchLabels:
  21837. additionalProperties:
  21838. type: string
  21839. description: |-
  21840. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  21841. map is equivalent to an element of matchExpressions, whose key field is "key", the
  21842. operator is "In", and the values array contains only "value". The requirements are ANDed.
  21843. type: object
  21844. type: object
  21845. x-kubernetes-map-type: atomic
  21846. namespaces:
  21847. description: Choose namespaces by name
  21848. items:
  21849. maxLength: 63
  21850. minLength: 1
  21851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21852. type: string
  21853. type: array
  21854. type: object
  21855. type: array
  21856. controller:
  21857. description: |-
  21858. Used to select the correct ESO controller (think: ingress.ingressClassName)
  21859. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  21860. type: string
  21861. provider:
  21862. description: Used to configure the provider. Only one provider may be set
  21863. maxProperties: 1
  21864. minProperties: 1
  21865. properties:
  21866. akeyless:
  21867. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  21868. properties:
  21869. akeylessGWApiURL:
  21870. description: Akeyless GW API Url from which the secrets to be fetched from.
  21871. type: string
  21872. authSecretRef:
  21873. description: Auth configures how the operator authenticates with Akeyless.
  21874. properties:
  21875. kubernetesAuth:
  21876. description: |-
  21877. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  21878. token stored in the named Secret resource.
  21879. properties:
  21880. accessID:
  21881. description: the Akeyless Kubernetes auth-method access-id
  21882. type: string
  21883. k8sConfName:
  21884. description: Kubernetes-auth configuration name in Akeyless-Gateway
  21885. type: string
  21886. secretRef:
  21887. description: |-
  21888. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21889. for authenticating with Akeyless. If a name is specified without a key,
  21890. `token` is the default. If one is not specified, the one bound to
  21891. the controller will be used.
  21892. properties:
  21893. key:
  21894. description: |-
  21895. A key in the referenced Secret.
  21896. Some instances of this field may be defaulted, in others it may be required.
  21897. maxLength: 253
  21898. minLength: 1
  21899. pattern: ^[-._a-zA-Z0-9]+$
  21900. type: string
  21901. name:
  21902. description: The name of the Secret resource being referred to.
  21903. maxLength: 253
  21904. minLength: 1
  21905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21906. type: string
  21907. namespace:
  21908. description: |-
  21909. The namespace of the Secret resource being referred to.
  21910. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21911. maxLength: 63
  21912. minLength: 1
  21913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21914. type: string
  21915. type: object
  21916. serviceAccountRef:
  21917. description: |-
  21918. Optional service account field containing the name of a kubernetes ServiceAccount.
  21919. If the service account is specified, the service account secret token JWT will be used
  21920. for authenticating with Akeyless. If the service account selector is not supplied,
  21921. the secretRef will be used instead.
  21922. properties:
  21923. audiences:
  21924. description: |-
  21925. Audience specifies the `aud` claim for the service account token
  21926. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21927. then this audiences will be appended to the list
  21928. items:
  21929. type: string
  21930. type: array
  21931. name:
  21932. description: The name of the ServiceAccount resource being referred to.
  21933. maxLength: 253
  21934. minLength: 1
  21935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21936. type: string
  21937. namespace:
  21938. description: |-
  21939. Namespace of the resource being referred to.
  21940. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21941. maxLength: 63
  21942. minLength: 1
  21943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21944. type: string
  21945. required:
  21946. - name
  21947. type: object
  21948. required:
  21949. - accessID
  21950. - k8sConfName
  21951. type: object
  21952. secretRef:
  21953. description: |-
  21954. Reference to a Secret that contains the details
  21955. to authenticate with Akeyless.
  21956. properties:
  21957. accessID:
  21958. description: The SecretAccessID is used for authentication
  21959. properties:
  21960. key:
  21961. description: |-
  21962. A key in the referenced Secret.
  21963. Some instances of this field may be defaulted, in others it may be required.
  21964. maxLength: 253
  21965. minLength: 1
  21966. pattern: ^[-._a-zA-Z0-9]+$
  21967. type: string
  21968. name:
  21969. description: The name of the Secret resource being referred to.
  21970. maxLength: 253
  21971. minLength: 1
  21972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21973. type: string
  21974. namespace:
  21975. description: |-
  21976. The namespace of the Secret resource being referred to.
  21977. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21978. maxLength: 63
  21979. minLength: 1
  21980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21981. type: string
  21982. type: object
  21983. accessType:
  21984. description: |-
  21985. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21986. In some instances, `key` is a required field.
  21987. properties:
  21988. key:
  21989. description: |-
  21990. A key in the referenced Secret.
  21991. Some instances of this field may be defaulted, in others it may be required.
  21992. maxLength: 253
  21993. minLength: 1
  21994. pattern: ^[-._a-zA-Z0-9]+$
  21995. type: string
  21996. name:
  21997. description: The name of the Secret resource being referred to.
  21998. maxLength: 253
  21999. minLength: 1
  22000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22001. type: string
  22002. namespace:
  22003. description: |-
  22004. The namespace of the Secret resource being referred to.
  22005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22006. maxLength: 63
  22007. minLength: 1
  22008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22009. type: string
  22010. type: object
  22011. accessTypeParam:
  22012. description: |-
  22013. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22014. In some instances, `key` is a required field.
  22015. properties:
  22016. key:
  22017. description: |-
  22018. A key in the referenced Secret.
  22019. Some instances of this field may be defaulted, in others it may be required.
  22020. maxLength: 253
  22021. minLength: 1
  22022. pattern: ^[-._a-zA-Z0-9]+$
  22023. type: string
  22024. name:
  22025. description: The name of the Secret resource being referred to.
  22026. maxLength: 253
  22027. minLength: 1
  22028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22029. type: string
  22030. namespace:
  22031. description: |-
  22032. The namespace of the Secret resource being referred to.
  22033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22034. maxLength: 63
  22035. minLength: 1
  22036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22037. type: string
  22038. type: object
  22039. type: object
  22040. type: object
  22041. caBundle:
  22042. description: |-
  22043. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22044. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22045. are used to validate the TLS connection.
  22046. format: byte
  22047. type: string
  22048. caProvider:
  22049. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22050. properties:
  22051. key:
  22052. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22053. maxLength: 253
  22054. minLength: 1
  22055. pattern: ^[-._a-zA-Z0-9]+$
  22056. type: string
  22057. name:
  22058. description: The name of the object located at the provider type.
  22059. maxLength: 253
  22060. minLength: 1
  22061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22062. type: string
  22063. namespace:
  22064. description: |-
  22065. The namespace the Provider type is in.
  22066. Can only be defined when used in a ClusterSecretStore.
  22067. maxLength: 63
  22068. minLength: 1
  22069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22070. type: string
  22071. type:
  22072. description: The type of provider to use such as "Secret", or "ConfigMap".
  22073. enum:
  22074. - Secret
  22075. - ConfigMap
  22076. type: string
  22077. required:
  22078. - name
  22079. - type
  22080. type: object
  22081. required:
  22082. - akeylessGWApiURL
  22083. - authSecretRef
  22084. type: object
  22085. alibaba:
  22086. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22087. properties:
  22088. auth:
  22089. description: AlibabaAuth contains a secretRef for credentials.
  22090. properties:
  22091. rrsa:
  22092. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22093. properties:
  22094. oidcProviderArn:
  22095. type: string
  22096. oidcTokenFilePath:
  22097. type: string
  22098. roleArn:
  22099. type: string
  22100. sessionName:
  22101. type: string
  22102. required:
  22103. - oidcProviderArn
  22104. - oidcTokenFilePath
  22105. - roleArn
  22106. - sessionName
  22107. type: object
  22108. secretRef:
  22109. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22110. properties:
  22111. accessKeyIDSecretRef:
  22112. description: The AccessKeyID is used for authentication
  22113. properties:
  22114. key:
  22115. description: |-
  22116. A key in the referenced Secret.
  22117. Some instances of this field may be defaulted, in others it may be required.
  22118. maxLength: 253
  22119. minLength: 1
  22120. pattern: ^[-._a-zA-Z0-9]+$
  22121. type: string
  22122. name:
  22123. description: The name of the Secret resource being referred to.
  22124. maxLength: 253
  22125. minLength: 1
  22126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22127. type: string
  22128. namespace:
  22129. description: |-
  22130. The namespace of the Secret resource being referred to.
  22131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22132. maxLength: 63
  22133. minLength: 1
  22134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22135. type: string
  22136. type: object
  22137. accessKeySecretSecretRef:
  22138. description: The AccessKeySecret is used for authentication
  22139. properties:
  22140. key:
  22141. description: |-
  22142. A key in the referenced Secret.
  22143. Some instances of this field may be defaulted, in others it may be required.
  22144. maxLength: 253
  22145. minLength: 1
  22146. pattern: ^[-._a-zA-Z0-9]+$
  22147. type: string
  22148. name:
  22149. description: The name of the Secret resource being referred to.
  22150. maxLength: 253
  22151. minLength: 1
  22152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22153. type: string
  22154. namespace:
  22155. description: |-
  22156. The namespace of the Secret resource being referred to.
  22157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22158. maxLength: 63
  22159. minLength: 1
  22160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22161. type: string
  22162. type: object
  22163. required:
  22164. - accessKeyIDSecretRef
  22165. - accessKeySecretSecretRef
  22166. type: object
  22167. type: object
  22168. regionID:
  22169. description: Alibaba Region to be used for the provider
  22170. type: string
  22171. required:
  22172. - auth
  22173. - regionID
  22174. type: object
  22175. aws:
  22176. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22177. properties:
  22178. additionalRoles:
  22179. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22180. items:
  22181. type: string
  22182. type: array
  22183. auth:
  22184. description: |-
  22185. Auth defines the information necessary to authenticate against AWS
  22186. if not set aws sdk will infer credentials from your environment
  22187. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22188. properties:
  22189. jwt:
  22190. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22191. properties:
  22192. serviceAccountRef:
  22193. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22194. properties:
  22195. audiences:
  22196. description: |-
  22197. Audience specifies the `aud` claim for the service account token
  22198. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22199. then this audiences will be appended to the list
  22200. items:
  22201. type: string
  22202. type: array
  22203. name:
  22204. description: The name of the ServiceAccount resource being referred to.
  22205. maxLength: 253
  22206. minLength: 1
  22207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22208. type: string
  22209. namespace:
  22210. description: |-
  22211. Namespace of the resource being referred to.
  22212. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22213. maxLength: 63
  22214. minLength: 1
  22215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22216. type: string
  22217. required:
  22218. - name
  22219. type: object
  22220. type: object
  22221. secretRef:
  22222. description: |-
  22223. AWSAuthSecretRef holds secret references for AWS credentials
  22224. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22225. properties:
  22226. accessKeyIDSecretRef:
  22227. description: The AccessKeyID is used for authentication
  22228. properties:
  22229. key:
  22230. description: |-
  22231. A key in the referenced Secret.
  22232. Some instances of this field may be defaulted, in others it may be required.
  22233. maxLength: 253
  22234. minLength: 1
  22235. pattern: ^[-._a-zA-Z0-9]+$
  22236. type: string
  22237. name:
  22238. description: The name of the Secret resource being referred to.
  22239. maxLength: 253
  22240. minLength: 1
  22241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22242. type: string
  22243. namespace:
  22244. description: |-
  22245. The namespace of the Secret resource being referred to.
  22246. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22247. maxLength: 63
  22248. minLength: 1
  22249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22250. type: string
  22251. type: object
  22252. secretAccessKeySecretRef:
  22253. description: The SecretAccessKey is used for authentication
  22254. properties:
  22255. key:
  22256. description: |-
  22257. A key in the referenced Secret.
  22258. Some instances of this field may be defaulted, in others it may be required.
  22259. maxLength: 253
  22260. minLength: 1
  22261. pattern: ^[-._a-zA-Z0-9]+$
  22262. type: string
  22263. name:
  22264. description: The name of the Secret resource being referred to.
  22265. maxLength: 253
  22266. minLength: 1
  22267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22268. type: string
  22269. namespace:
  22270. description: |-
  22271. The namespace of the Secret resource being referred to.
  22272. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22273. maxLength: 63
  22274. minLength: 1
  22275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22276. type: string
  22277. type: object
  22278. sessionTokenSecretRef:
  22279. description: |-
  22280. The SessionToken used for authentication
  22281. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22282. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22283. properties:
  22284. key:
  22285. description: |-
  22286. A key in the referenced Secret.
  22287. Some instances of this field may be defaulted, in others it may be required.
  22288. maxLength: 253
  22289. minLength: 1
  22290. pattern: ^[-._a-zA-Z0-9]+$
  22291. type: string
  22292. name:
  22293. description: The name of the Secret resource being referred to.
  22294. maxLength: 253
  22295. minLength: 1
  22296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22297. type: string
  22298. namespace:
  22299. description: |-
  22300. The namespace of the Secret resource being referred to.
  22301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22302. maxLength: 63
  22303. minLength: 1
  22304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22305. type: string
  22306. type: object
  22307. type: object
  22308. type: object
  22309. externalID:
  22310. description: AWS External ID set on assumed IAM roles
  22311. type: string
  22312. prefix:
  22313. description: Prefix adds a prefix to all retrieved values.
  22314. type: string
  22315. region:
  22316. description: AWS Region to be used for the provider
  22317. type: string
  22318. role:
  22319. description: Role is a Role ARN which the provider will assume
  22320. type: string
  22321. secretsManager:
  22322. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  22323. properties:
  22324. forceDeleteWithoutRecovery:
  22325. description: |-
  22326. Specifies whether to delete the secret without any recovery window. You
  22327. can't use both this parameter and RecoveryWindowInDays in the same call.
  22328. If you don't use either, then by default Secrets Manager uses a 30 day
  22329. recovery window.
  22330. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  22331. type: boolean
  22332. recoveryWindowInDays:
  22333. description: |-
  22334. The number of days from 7 to 30 that Secrets Manager waits before
  22335. permanently deleting the secret. You can't use both this parameter and
  22336. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  22337. then by default Secrets Manager uses a 30 day recovery window.
  22338. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  22339. format: int64
  22340. type: integer
  22341. type: object
  22342. service:
  22343. description: Service defines which service should be used to fetch the secrets
  22344. enum:
  22345. - SecretsManager
  22346. - ParameterStore
  22347. type: string
  22348. sessionTags:
  22349. description: AWS STS assume role session tags
  22350. items:
  22351. description: Tag defines a tag key and value for AWS resources.
  22352. properties:
  22353. key:
  22354. type: string
  22355. value:
  22356. type: string
  22357. required:
  22358. - key
  22359. - value
  22360. type: object
  22361. type: array
  22362. transitiveTagKeys:
  22363. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  22364. items:
  22365. type: string
  22366. type: array
  22367. required:
  22368. - region
  22369. - service
  22370. type: object
  22371. azurekv:
  22372. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  22373. properties:
  22374. authSecretRef:
  22375. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  22376. properties:
  22377. clientCertificate:
  22378. description: The Azure ClientCertificate of the service principle used for authentication.
  22379. properties:
  22380. key:
  22381. description: |-
  22382. A key in the referenced Secret.
  22383. Some instances of this field may be defaulted, in others it may be required.
  22384. maxLength: 253
  22385. minLength: 1
  22386. pattern: ^[-._a-zA-Z0-9]+$
  22387. type: string
  22388. name:
  22389. description: The name of the Secret resource being referred to.
  22390. maxLength: 253
  22391. minLength: 1
  22392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22393. type: string
  22394. namespace:
  22395. description: |-
  22396. The namespace of the Secret resource being referred to.
  22397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22398. maxLength: 63
  22399. minLength: 1
  22400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22401. type: string
  22402. type: object
  22403. clientId:
  22404. description: The Azure clientId of the service principle or managed identity used for authentication.
  22405. properties:
  22406. key:
  22407. description: |-
  22408. A key in the referenced Secret.
  22409. Some instances of this field may be defaulted, in others it may be required.
  22410. maxLength: 253
  22411. minLength: 1
  22412. pattern: ^[-._a-zA-Z0-9]+$
  22413. type: string
  22414. name:
  22415. description: The name of the Secret resource being referred to.
  22416. maxLength: 253
  22417. minLength: 1
  22418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22419. type: string
  22420. namespace:
  22421. description: |-
  22422. The namespace of the Secret resource being referred to.
  22423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22424. maxLength: 63
  22425. minLength: 1
  22426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22427. type: string
  22428. type: object
  22429. clientSecret:
  22430. description: The Azure ClientSecret of the service principle used for authentication.
  22431. properties:
  22432. key:
  22433. description: |-
  22434. A key in the referenced Secret.
  22435. Some instances of this field may be defaulted, in others it may be required.
  22436. maxLength: 253
  22437. minLength: 1
  22438. pattern: ^[-._a-zA-Z0-9]+$
  22439. type: string
  22440. name:
  22441. description: The name of the Secret resource being referred to.
  22442. maxLength: 253
  22443. minLength: 1
  22444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22445. type: string
  22446. namespace:
  22447. description: |-
  22448. The namespace of the Secret resource being referred to.
  22449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22450. maxLength: 63
  22451. minLength: 1
  22452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22453. type: string
  22454. type: object
  22455. tenantId:
  22456. description: The Azure tenantId of the managed identity used for authentication.
  22457. properties:
  22458. key:
  22459. description: |-
  22460. A key in the referenced Secret.
  22461. Some instances of this field may be defaulted, in others it may be required.
  22462. maxLength: 253
  22463. minLength: 1
  22464. pattern: ^[-._a-zA-Z0-9]+$
  22465. type: string
  22466. name:
  22467. description: The name of the Secret resource being referred to.
  22468. maxLength: 253
  22469. minLength: 1
  22470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22471. type: string
  22472. namespace:
  22473. description: |-
  22474. The namespace of the Secret resource being referred to.
  22475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22476. maxLength: 63
  22477. minLength: 1
  22478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22479. type: string
  22480. type: object
  22481. type: object
  22482. authType:
  22483. default: ServicePrincipal
  22484. description: |-
  22485. Auth type defines how to authenticate to the keyvault service.
  22486. Valid values are:
  22487. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  22488. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  22489. enum:
  22490. - ServicePrincipal
  22491. - ManagedIdentity
  22492. - WorkloadIdentity
  22493. type: string
  22494. environmentType:
  22495. default: PublicCloud
  22496. description: |-
  22497. EnvironmentType specifies the Azure cloud environment endpoints to use for
  22498. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  22499. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  22500. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  22501. enum:
  22502. - PublicCloud
  22503. - USGovernmentCloud
  22504. - ChinaCloud
  22505. - GermanCloud
  22506. type: string
  22507. identityId:
  22508. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  22509. type: string
  22510. serviceAccountRef:
  22511. description: |-
  22512. ServiceAccountRef specified the service account
  22513. that should be used when authenticating with WorkloadIdentity.
  22514. properties:
  22515. audiences:
  22516. description: |-
  22517. Audience specifies the `aud` claim for the service account token
  22518. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22519. then this audiences will be appended to the list
  22520. items:
  22521. type: string
  22522. type: array
  22523. name:
  22524. description: The name of the ServiceAccount resource being referred to.
  22525. maxLength: 253
  22526. minLength: 1
  22527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22528. type: string
  22529. namespace:
  22530. description: |-
  22531. Namespace of the resource being referred to.
  22532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22533. maxLength: 63
  22534. minLength: 1
  22535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22536. type: string
  22537. required:
  22538. - name
  22539. type: object
  22540. tenantId:
  22541. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  22542. type: string
  22543. vaultUrl:
  22544. description: Vault Url from which the secrets to be fetched from.
  22545. type: string
  22546. required:
  22547. - vaultUrl
  22548. type: object
  22549. beyondtrust:
  22550. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  22551. properties:
  22552. auth:
  22553. description: Auth configures how the operator authenticates with Beyondtrust.
  22554. properties:
  22555. apiKey:
  22556. description: APIKey If not provided then ClientID/ClientSecret become required.
  22557. properties:
  22558. secretRef:
  22559. description: SecretRef references a key in a secret that will be used as value.
  22560. properties:
  22561. key:
  22562. description: |-
  22563. A key in the referenced Secret.
  22564. Some instances of this field may be defaulted, in others it may be required.
  22565. maxLength: 253
  22566. minLength: 1
  22567. pattern: ^[-._a-zA-Z0-9]+$
  22568. type: string
  22569. name:
  22570. description: The name of the Secret resource being referred to.
  22571. maxLength: 253
  22572. minLength: 1
  22573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22574. type: string
  22575. namespace:
  22576. description: |-
  22577. The namespace of the Secret resource being referred to.
  22578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22579. maxLength: 63
  22580. minLength: 1
  22581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22582. type: string
  22583. type: object
  22584. value:
  22585. description: Value can be specified directly to set a value without using a secret.
  22586. type: string
  22587. type: object
  22588. certificate:
  22589. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  22590. properties:
  22591. secretRef:
  22592. description: SecretRef references a key in a secret that will be used as value.
  22593. properties:
  22594. key:
  22595. description: |-
  22596. A key in the referenced Secret.
  22597. Some instances of this field may be defaulted, in others it may be required.
  22598. maxLength: 253
  22599. minLength: 1
  22600. pattern: ^[-._a-zA-Z0-9]+$
  22601. type: string
  22602. name:
  22603. description: The name of the Secret resource being referred to.
  22604. maxLength: 253
  22605. minLength: 1
  22606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22607. type: string
  22608. namespace:
  22609. description: |-
  22610. The namespace of the Secret resource being referred to.
  22611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22612. maxLength: 63
  22613. minLength: 1
  22614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22615. type: string
  22616. type: object
  22617. value:
  22618. description: Value can be specified directly to set a value without using a secret.
  22619. type: string
  22620. type: object
  22621. certificateKey:
  22622. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  22623. properties:
  22624. secretRef:
  22625. description: SecretRef references a key in a secret that will be used as value.
  22626. properties:
  22627. key:
  22628. description: |-
  22629. A key in the referenced Secret.
  22630. Some instances of this field may be defaulted, in others it may be required.
  22631. maxLength: 253
  22632. minLength: 1
  22633. pattern: ^[-._a-zA-Z0-9]+$
  22634. type: string
  22635. name:
  22636. description: The name of the Secret resource being referred to.
  22637. maxLength: 253
  22638. minLength: 1
  22639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22640. type: string
  22641. namespace:
  22642. description: |-
  22643. The namespace of the Secret resource being referred to.
  22644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22645. maxLength: 63
  22646. minLength: 1
  22647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22648. type: string
  22649. type: object
  22650. value:
  22651. description: Value can be specified directly to set a value without using a secret.
  22652. type: string
  22653. type: object
  22654. clientId:
  22655. description: ClientID is the API OAuth Client ID.
  22656. properties:
  22657. secretRef:
  22658. description: SecretRef references a key in a secret that will be used as value.
  22659. properties:
  22660. key:
  22661. description: |-
  22662. A key in the referenced Secret.
  22663. Some instances of this field may be defaulted, in others it may be required.
  22664. maxLength: 253
  22665. minLength: 1
  22666. pattern: ^[-._a-zA-Z0-9]+$
  22667. type: string
  22668. name:
  22669. description: The name of the Secret resource being referred to.
  22670. maxLength: 253
  22671. minLength: 1
  22672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22673. type: string
  22674. namespace:
  22675. description: |-
  22676. The namespace of the Secret resource being referred to.
  22677. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22678. maxLength: 63
  22679. minLength: 1
  22680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22681. type: string
  22682. type: object
  22683. value:
  22684. description: Value can be specified directly to set a value without using a secret.
  22685. type: string
  22686. type: object
  22687. clientSecret:
  22688. description: ClientSecret is the API OAuth Client Secret.
  22689. properties:
  22690. secretRef:
  22691. description: SecretRef references a key in a secret that will be used as value.
  22692. properties:
  22693. key:
  22694. description: |-
  22695. A key in the referenced Secret.
  22696. Some instances of this field may be defaulted, in others it may be required.
  22697. maxLength: 253
  22698. minLength: 1
  22699. pattern: ^[-._a-zA-Z0-9]+$
  22700. type: string
  22701. name:
  22702. description: The name of the Secret resource being referred to.
  22703. maxLength: 253
  22704. minLength: 1
  22705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22706. type: string
  22707. namespace:
  22708. description: |-
  22709. The namespace of the Secret resource being referred to.
  22710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22711. maxLength: 63
  22712. minLength: 1
  22713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22714. type: string
  22715. type: object
  22716. value:
  22717. description: Value can be specified directly to set a value without using a secret.
  22718. type: string
  22719. type: object
  22720. type: object
  22721. server:
  22722. description: Auth configures how API server works.
  22723. properties:
  22724. apiUrl:
  22725. type: string
  22726. apiVersion:
  22727. type: string
  22728. clientTimeOutSeconds:
  22729. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  22730. type: integer
  22731. decrypt:
  22732. default: true
  22733. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  22734. type: boolean
  22735. retrievalType:
  22736. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  22737. type: string
  22738. separator:
  22739. description: A character that separates the folder names.
  22740. type: string
  22741. verifyCA:
  22742. type: boolean
  22743. required:
  22744. - apiUrl
  22745. - verifyCA
  22746. type: object
  22747. required:
  22748. - auth
  22749. - server
  22750. type: object
  22751. bitwardensecretsmanager:
  22752. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  22753. properties:
  22754. apiURL:
  22755. type: string
  22756. auth:
  22757. description: |-
  22758. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  22759. Make sure that the token being used has permissions on the given secret.
  22760. properties:
  22761. secretRef:
  22762. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  22763. properties:
  22764. credentials:
  22765. description: AccessToken used for the bitwarden instance.
  22766. properties:
  22767. key:
  22768. description: |-
  22769. A key in the referenced Secret.
  22770. Some instances of this field may be defaulted, in others it may be required.
  22771. maxLength: 253
  22772. minLength: 1
  22773. pattern: ^[-._a-zA-Z0-9]+$
  22774. type: string
  22775. name:
  22776. description: The name of the Secret resource being referred to.
  22777. maxLength: 253
  22778. minLength: 1
  22779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22780. type: string
  22781. namespace:
  22782. description: |-
  22783. The namespace of the Secret resource being referred to.
  22784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22785. maxLength: 63
  22786. minLength: 1
  22787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22788. type: string
  22789. type: object
  22790. required:
  22791. - credentials
  22792. type: object
  22793. required:
  22794. - secretRef
  22795. type: object
  22796. bitwardenServerSDKURL:
  22797. type: string
  22798. caBundle:
  22799. description: |-
  22800. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  22801. can be performed.
  22802. type: string
  22803. caProvider:
  22804. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  22805. properties:
  22806. key:
  22807. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22808. maxLength: 253
  22809. minLength: 1
  22810. pattern: ^[-._a-zA-Z0-9]+$
  22811. type: string
  22812. name:
  22813. description: The name of the object located at the provider type.
  22814. maxLength: 253
  22815. minLength: 1
  22816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22817. type: string
  22818. namespace:
  22819. description: |-
  22820. The namespace the Provider type is in.
  22821. Can only be defined when used in a ClusterSecretStore.
  22822. maxLength: 63
  22823. minLength: 1
  22824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22825. type: string
  22826. type:
  22827. description: The type of provider to use such as "Secret", or "ConfigMap".
  22828. enum:
  22829. - Secret
  22830. - ConfigMap
  22831. type: string
  22832. required:
  22833. - name
  22834. - type
  22835. type: object
  22836. identityURL:
  22837. type: string
  22838. organizationID:
  22839. description: OrganizationID determines which organization this secret store manages.
  22840. type: string
  22841. projectID:
  22842. description: ProjectID determines which project this secret store manages.
  22843. type: string
  22844. required:
  22845. - auth
  22846. - organizationID
  22847. - projectID
  22848. type: object
  22849. chef:
  22850. description: Chef configures this store to sync secrets with chef server
  22851. properties:
  22852. auth:
  22853. description: Auth defines the information necessary to authenticate against chef Server
  22854. properties:
  22855. secretRef:
  22856. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  22857. properties:
  22858. privateKeySecretRef:
  22859. description: SecretKey is the Signing Key in PEM format, used for authentication.
  22860. properties:
  22861. key:
  22862. description: |-
  22863. A key in the referenced Secret.
  22864. Some instances of this field may be defaulted, in others it may be required.
  22865. maxLength: 253
  22866. minLength: 1
  22867. pattern: ^[-._a-zA-Z0-9]+$
  22868. type: string
  22869. name:
  22870. description: The name of the Secret resource being referred to.
  22871. maxLength: 253
  22872. minLength: 1
  22873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22874. type: string
  22875. namespace:
  22876. description: |-
  22877. The namespace of the Secret resource being referred to.
  22878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22879. maxLength: 63
  22880. minLength: 1
  22881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22882. type: string
  22883. type: object
  22884. required:
  22885. - privateKeySecretRef
  22886. type: object
  22887. required:
  22888. - secretRef
  22889. type: object
  22890. serverUrl:
  22891. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  22892. type: string
  22893. username:
  22894. description: UserName should be the user ID on the chef server
  22895. type: string
  22896. required:
  22897. - auth
  22898. - serverUrl
  22899. - username
  22900. type: object
  22901. cloudrusm:
  22902. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  22903. properties:
  22904. auth:
  22905. description: CSMAuth contains a secretRef for credentials.
  22906. properties:
  22907. secretRef:
  22908. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  22909. properties:
  22910. accessKeyIDSecretRef:
  22911. description: The AccessKeyID is used for authentication
  22912. properties:
  22913. key:
  22914. description: |-
  22915. A key in the referenced Secret.
  22916. Some instances of this field may be defaulted, in others it may be required.
  22917. maxLength: 253
  22918. minLength: 1
  22919. pattern: ^[-._a-zA-Z0-9]+$
  22920. type: string
  22921. name:
  22922. description: The name of the Secret resource being referred to.
  22923. maxLength: 253
  22924. minLength: 1
  22925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22926. type: string
  22927. namespace:
  22928. description: |-
  22929. The namespace of the Secret resource being referred to.
  22930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22931. maxLength: 63
  22932. minLength: 1
  22933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22934. type: string
  22935. type: object
  22936. accessKeySecretSecretRef:
  22937. description: The AccessKeySecret is used for authentication
  22938. properties:
  22939. key:
  22940. description: |-
  22941. A key in the referenced Secret.
  22942. Some instances of this field may be defaulted, in others it may be required.
  22943. maxLength: 253
  22944. minLength: 1
  22945. pattern: ^[-._a-zA-Z0-9]+$
  22946. type: string
  22947. name:
  22948. description: The name of the Secret resource being referred to.
  22949. maxLength: 253
  22950. minLength: 1
  22951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22952. type: string
  22953. namespace:
  22954. description: |-
  22955. The namespace of the Secret resource being referred to.
  22956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22957. maxLength: 63
  22958. minLength: 1
  22959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22960. type: string
  22961. type: object
  22962. required:
  22963. - accessKeyIDSecretRef
  22964. - accessKeySecretSecretRef
  22965. type: object
  22966. type: object
  22967. projectID:
  22968. description: ProjectID is the project, which the secrets are stored in.
  22969. type: string
  22970. required:
  22971. - auth
  22972. type: object
  22973. conjur:
  22974. description: Conjur configures this store to sync secrets using conjur provider
  22975. properties:
  22976. auth:
  22977. description: Defines authentication settings for connecting to Conjur.
  22978. properties:
  22979. apikey:
  22980. description: Authenticates with Conjur using an API key.
  22981. properties:
  22982. account:
  22983. description: Account is the Conjur organization account name.
  22984. type: string
  22985. apiKeyRef:
  22986. description: |-
  22987. A reference to a specific 'key' containing the Conjur API key
  22988. within a Secret resource. In some instances, `key` is a required field.
  22989. properties:
  22990. key:
  22991. description: |-
  22992. A key in the referenced Secret.
  22993. Some instances of this field may be defaulted, in others it may be required.
  22994. maxLength: 253
  22995. minLength: 1
  22996. pattern: ^[-._a-zA-Z0-9]+$
  22997. type: string
  22998. name:
  22999. description: The name of the Secret resource being referred to.
  23000. maxLength: 253
  23001. minLength: 1
  23002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23003. type: string
  23004. namespace:
  23005. description: |-
  23006. The namespace of the Secret resource being referred to.
  23007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23008. maxLength: 63
  23009. minLength: 1
  23010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23011. type: string
  23012. type: object
  23013. userRef:
  23014. description: |-
  23015. A reference to a specific 'key' containing the Conjur username
  23016. within a Secret resource. In some instances, `key` is a required field.
  23017. properties:
  23018. key:
  23019. description: |-
  23020. A key in the referenced Secret.
  23021. Some instances of this field may be defaulted, in others it may be required.
  23022. maxLength: 253
  23023. minLength: 1
  23024. pattern: ^[-._a-zA-Z0-9]+$
  23025. type: string
  23026. name:
  23027. description: The name of the Secret resource being referred to.
  23028. maxLength: 253
  23029. minLength: 1
  23030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23031. type: string
  23032. namespace:
  23033. description: |-
  23034. The namespace of the Secret resource being referred to.
  23035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23036. maxLength: 63
  23037. minLength: 1
  23038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23039. type: string
  23040. type: object
  23041. required:
  23042. - account
  23043. - apiKeyRef
  23044. - userRef
  23045. type: object
  23046. jwt:
  23047. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23048. properties:
  23049. account:
  23050. description: Account is the Conjur organization account name.
  23051. type: string
  23052. hostId:
  23053. description: |-
  23054. Optional HostID for JWT authentication. This may be used depending
  23055. on how the Conjur JWT authenticator policy is configured.
  23056. type: string
  23057. secretRef:
  23058. description: |-
  23059. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23060. authenticate with Conjur using the JWT authentication method.
  23061. properties:
  23062. key:
  23063. description: |-
  23064. A key in the referenced Secret.
  23065. Some instances of this field may be defaulted, in others it may be required.
  23066. maxLength: 253
  23067. minLength: 1
  23068. pattern: ^[-._a-zA-Z0-9]+$
  23069. type: string
  23070. name:
  23071. description: The name of the Secret resource being referred to.
  23072. maxLength: 253
  23073. minLength: 1
  23074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23075. type: string
  23076. namespace:
  23077. description: |-
  23078. The namespace of the Secret resource being referred to.
  23079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23080. maxLength: 63
  23081. minLength: 1
  23082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23083. type: string
  23084. type: object
  23085. serviceAccountRef:
  23086. description: |-
  23087. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23088. a token for with the `TokenRequest` API.
  23089. properties:
  23090. audiences:
  23091. description: |-
  23092. Audience specifies the `aud` claim for the service account token
  23093. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23094. then this audiences will be appended to the list
  23095. items:
  23096. type: string
  23097. type: array
  23098. name:
  23099. description: The name of the ServiceAccount resource being referred to.
  23100. maxLength: 253
  23101. minLength: 1
  23102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23103. type: string
  23104. namespace:
  23105. description: |-
  23106. Namespace of the resource being referred to.
  23107. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23108. maxLength: 63
  23109. minLength: 1
  23110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23111. type: string
  23112. required:
  23113. - name
  23114. type: object
  23115. serviceID:
  23116. description: The conjur authn jwt webservice id
  23117. type: string
  23118. required:
  23119. - account
  23120. - serviceID
  23121. type: object
  23122. type: object
  23123. caBundle:
  23124. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23125. type: string
  23126. caProvider:
  23127. description: |-
  23128. Used to provide custom certificate authority (CA) certificates
  23129. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23130. that contains a PEM-encoded certificate.
  23131. properties:
  23132. key:
  23133. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23134. maxLength: 253
  23135. minLength: 1
  23136. pattern: ^[-._a-zA-Z0-9]+$
  23137. type: string
  23138. name:
  23139. description: The name of the object located at the provider type.
  23140. maxLength: 253
  23141. minLength: 1
  23142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23143. type: string
  23144. namespace:
  23145. description: |-
  23146. The namespace the Provider type is in.
  23147. Can only be defined when used in a ClusterSecretStore.
  23148. maxLength: 63
  23149. minLength: 1
  23150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23151. type: string
  23152. type:
  23153. description: The type of provider to use such as "Secret", or "ConfigMap".
  23154. enum:
  23155. - Secret
  23156. - ConfigMap
  23157. type: string
  23158. required:
  23159. - name
  23160. - type
  23161. type: object
  23162. url:
  23163. description: URL is the endpoint of the Conjur instance.
  23164. type: string
  23165. required:
  23166. - auth
  23167. - url
  23168. type: object
  23169. delinea:
  23170. description: |-
  23171. Delinea DevOps Secrets Vault
  23172. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23173. properties:
  23174. clientId:
  23175. description: ClientID is the non-secret part of the credential.
  23176. properties:
  23177. secretRef:
  23178. description: SecretRef references a key in a secret that will be used as value.
  23179. properties:
  23180. key:
  23181. description: |-
  23182. A key in the referenced Secret.
  23183. Some instances of this field may be defaulted, in others it may be required.
  23184. maxLength: 253
  23185. minLength: 1
  23186. pattern: ^[-._a-zA-Z0-9]+$
  23187. type: string
  23188. name:
  23189. description: The name of the Secret resource being referred to.
  23190. maxLength: 253
  23191. minLength: 1
  23192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23193. type: string
  23194. namespace:
  23195. description: |-
  23196. The namespace of the Secret resource being referred to.
  23197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23198. maxLength: 63
  23199. minLength: 1
  23200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23201. type: string
  23202. type: object
  23203. value:
  23204. description: Value can be specified directly to set a value without using a secret.
  23205. type: string
  23206. type: object
  23207. clientSecret:
  23208. description: ClientSecret is the secret part of the credential.
  23209. properties:
  23210. secretRef:
  23211. description: SecretRef references a key in a secret that will be used as value.
  23212. properties:
  23213. key:
  23214. description: |-
  23215. A key in the referenced Secret.
  23216. Some instances of this field may be defaulted, in others it may be required.
  23217. maxLength: 253
  23218. minLength: 1
  23219. pattern: ^[-._a-zA-Z0-9]+$
  23220. type: string
  23221. name:
  23222. description: The name of the Secret resource being referred to.
  23223. maxLength: 253
  23224. minLength: 1
  23225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23226. type: string
  23227. namespace:
  23228. description: |-
  23229. The namespace of the Secret resource being referred to.
  23230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23231. maxLength: 63
  23232. minLength: 1
  23233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23234. type: string
  23235. type: object
  23236. value:
  23237. description: Value can be specified directly to set a value without using a secret.
  23238. type: string
  23239. type: object
  23240. tenant:
  23241. description: Tenant is the chosen hostname / site name.
  23242. type: string
  23243. tld:
  23244. description: |-
  23245. TLD is based on the server location that was chosen during provisioning.
  23246. If unset, defaults to "com".
  23247. type: string
  23248. urlTemplate:
  23249. description: |-
  23250. URLTemplate
  23251. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23252. type: string
  23253. required:
  23254. - clientId
  23255. - clientSecret
  23256. - tenant
  23257. type: object
  23258. device42:
  23259. description: Device42 configures this store to sync secrets using the Device42 provider
  23260. properties:
  23261. auth:
  23262. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23263. properties:
  23264. secretRef:
  23265. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23266. properties:
  23267. credentials:
  23268. description: Username / Password is used for authentication.
  23269. properties:
  23270. key:
  23271. description: |-
  23272. A key in the referenced Secret.
  23273. Some instances of this field may be defaulted, in others it may be required.
  23274. maxLength: 253
  23275. minLength: 1
  23276. pattern: ^[-._a-zA-Z0-9]+$
  23277. type: string
  23278. name:
  23279. description: The name of the Secret resource being referred to.
  23280. maxLength: 253
  23281. minLength: 1
  23282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23283. type: string
  23284. namespace:
  23285. description: |-
  23286. The namespace of the Secret resource being referred to.
  23287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23288. maxLength: 63
  23289. minLength: 1
  23290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23291. type: string
  23292. type: object
  23293. type: object
  23294. required:
  23295. - secretRef
  23296. type: object
  23297. host:
  23298. description: URL configures the Device42 instance URL.
  23299. type: string
  23300. required:
  23301. - auth
  23302. - host
  23303. type: object
  23304. doppler:
  23305. description: Doppler configures this store to sync secrets using the Doppler provider
  23306. properties:
  23307. auth:
  23308. description: Auth configures how the Operator authenticates with the Doppler API
  23309. properties:
  23310. secretRef:
  23311. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  23312. properties:
  23313. dopplerToken:
  23314. description: |-
  23315. The DopplerToken is used for authentication.
  23316. See https://docs.doppler.com/reference/api#authentication for auth token types.
  23317. The Key attribute defaults to dopplerToken if not specified.
  23318. properties:
  23319. key:
  23320. description: |-
  23321. A key in the referenced Secret.
  23322. Some instances of this field may be defaulted, in others it may be required.
  23323. maxLength: 253
  23324. minLength: 1
  23325. pattern: ^[-._a-zA-Z0-9]+$
  23326. type: string
  23327. name:
  23328. description: The name of the Secret resource being referred to.
  23329. maxLength: 253
  23330. minLength: 1
  23331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23332. type: string
  23333. namespace:
  23334. description: |-
  23335. The namespace of the Secret resource being referred to.
  23336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23337. maxLength: 63
  23338. minLength: 1
  23339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23340. type: string
  23341. type: object
  23342. required:
  23343. - dopplerToken
  23344. type: object
  23345. required:
  23346. - secretRef
  23347. type: object
  23348. config:
  23349. description: Doppler config (required if not using a Service Token)
  23350. type: string
  23351. format:
  23352. description: Format enables the downloading of secrets as a file (string)
  23353. enum:
  23354. - json
  23355. - dotnet-json
  23356. - env
  23357. - yaml
  23358. - docker
  23359. type: string
  23360. nameTransformer:
  23361. description: Environment variable compatible name transforms that change secret names to a different format
  23362. enum:
  23363. - upper-camel
  23364. - camel
  23365. - lower-snake
  23366. - tf-var
  23367. - dotnet-env
  23368. - lower-kebab
  23369. type: string
  23370. project:
  23371. description: Doppler project (required if not using a Service Token)
  23372. type: string
  23373. required:
  23374. - auth
  23375. type: object
  23376. fake:
  23377. description: Fake configures a store with static key/value pairs
  23378. properties:
  23379. data:
  23380. items:
  23381. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  23382. properties:
  23383. key:
  23384. type: string
  23385. value:
  23386. type: string
  23387. version:
  23388. type: string
  23389. required:
  23390. - key
  23391. - value
  23392. type: object
  23393. type: array
  23394. required:
  23395. - data
  23396. type: object
  23397. fortanix:
  23398. description: Fortanix configures this store to sync secrets using the Fortanix provider
  23399. properties:
  23400. apiKey:
  23401. description: APIKey is the API token to access SDKMS Applications.
  23402. properties:
  23403. secretRef:
  23404. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  23405. properties:
  23406. key:
  23407. description: |-
  23408. A key in the referenced Secret.
  23409. Some instances of this field may be defaulted, in others it may be required.
  23410. maxLength: 253
  23411. minLength: 1
  23412. pattern: ^[-._a-zA-Z0-9]+$
  23413. type: string
  23414. name:
  23415. description: The name of the Secret resource being referred to.
  23416. maxLength: 253
  23417. minLength: 1
  23418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23419. type: string
  23420. namespace:
  23421. description: |-
  23422. The namespace of the Secret resource being referred to.
  23423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23424. maxLength: 63
  23425. minLength: 1
  23426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23427. type: string
  23428. type: object
  23429. type: object
  23430. apiUrl:
  23431. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  23432. type: string
  23433. type: object
  23434. gcpsm:
  23435. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  23436. properties:
  23437. auth:
  23438. description: Auth defines the information necessary to authenticate against GCP
  23439. properties:
  23440. secretRef:
  23441. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  23442. properties:
  23443. secretAccessKeySecretRef:
  23444. description: The SecretAccessKey is used for authentication
  23445. properties:
  23446. key:
  23447. description: |-
  23448. A key in the referenced Secret.
  23449. Some instances of this field may be defaulted, in others it may be required.
  23450. maxLength: 253
  23451. minLength: 1
  23452. pattern: ^[-._a-zA-Z0-9]+$
  23453. type: string
  23454. name:
  23455. description: The name of the Secret resource being referred to.
  23456. maxLength: 253
  23457. minLength: 1
  23458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23459. type: string
  23460. namespace:
  23461. description: |-
  23462. The namespace of the Secret resource being referred to.
  23463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23464. maxLength: 63
  23465. minLength: 1
  23466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23467. type: string
  23468. type: object
  23469. type: object
  23470. workloadIdentity:
  23471. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  23472. properties:
  23473. clusterLocation:
  23474. description: |-
  23475. ClusterLocation is the location of the cluster
  23476. If not specified, it fetches information from the metadata server
  23477. type: string
  23478. clusterName:
  23479. description: |-
  23480. ClusterName is the name of the cluster
  23481. If not specified, it fetches information from the metadata server
  23482. type: string
  23483. clusterProjectID:
  23484. description: |-
  23485. ClusterProjectID is the project ID of the cluster
  23486. If not specified, it fetches information from the metadata server
  23487. type: string
  23488. serviceAccountRef:
  23489. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23490. properties:
  23491. audiences:
  23492. description: |-
  23493. Audience specifies the `aud` claim for the service account token
  23494. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23495. then this audiences will be appended to the list
  23496. items:
  23497. type: string
  23498. type: array
  23499. name:
  23500. description: The name of the ServiceAccount resource being referred to.
  23501. maxLength: 253
  23502. minLength: 1
  23503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23504. type: string
  23505. namespace:
  23506. description: |-
  23507. Namespace of the resource being referred to.
  23508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23509. maxLength: 63
  23510. minLength: 1
  23511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23512. type: string
  23513. required:
  23514. - name
  23515. type: object
  23516. required:
  23517. - serviceAccountRef
  23518. type: object
  23519. type: object
  23520. location:
  23521. description: Location optionally defines a location for a secret
  23522. type: string
  23523. projectID:
  23524. description: ProjectID project where secret is located
  23525. type: string
  23526. type: object
  23527. github:
  23528. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  23529. properties:
  23530. appID:
  23531. description: appID specifies the Github APP that will be used to authenticate the client
  23532. format: int64
  23533. type: integer
  23534. auth:
  23535. description: auth configures how secret-manager authenticates with a Github instance.
  23536. properties:
  23537. privateKey:
  23538. description: |-
  23539. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23540. In some instances, `key` is a required field.
  23541. properties:
  23542. key:
  23543. description: |-
  23544. A key in the referenced Secret.
  23545. Some instances of this field may be defaulted, in others it may be required.
  23546. maxLength: 253
  23547. minLength: 1
  23548. pattern: ^[-._a-zA-Z0-9]+$
  23549. type: string
  23550. name:
  23551. description: The name of the Secret resource being referred to.
  23552. maxLength: 253
  23553. minLength: 1
  23554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23555. type: string
  23556. namespace:
  23557. description: |-
  23558. The namespace of the Secret resource being referred to.
  23559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23560. maxLength: 63
  23561. minLength: 1
  23562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23563. type: string
  23564. type: object
  23565. required:
  23566. - privateKey
  23567. type: object
  23568. environment:
  23569. description: environment will be used to fetch secrets from a particular environment within a github repository
  23570. type: string
  23571. installationID:
  23572. description: installationID specifies the Github APP installation that will be used to authenticate the client
  23573. format: int64
  23574. type: integer
  23575. organization:
  23576. description: organization will be used to fetch secrets from the Github organization
  23577. type: string
  23578. repository:
  23579. description: repository will be used to fetch secrets from the Github repository within an organization
  23580. type: string
  23581. uploadURL:
  23582. description: Upload URL for enterprise instances. Default to URL.
  23583. type: string
  23584. url:
  23585. default: https://github.com/
  23586. description: URL configures the Github instance URL. Defaults to https://github.com/.
  23587. type: string
  23588. required:
  23589. - appID
  23590. - auth
  23591. - installationID
  23592. - organization
  23593. type: object
  23594. gitlab:
  23595. description: GitLab configures this store to sync secrets using GitLab Variables provider
  23596. properties:
  23597. auth:
  23598. description: Auth configures how secret-manager authenticates with a GitLab instance.
  23599. properties:
  23600. SecretRef:
  23601. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  23602. properties:
  23603. accessToken:
  23604. description: AccessToken is used for authentication.
  23605. properties:
  23606. key:
  23607. description: |-
  23608. A key in the referenced Secret.
  23609. Some instances of this field may be defaulted, in others it may be required.
  23610. maxLength: 253
  23611. minLength: 1
  23612. pattern: ^[-._a-zA-Z0-9]+$
  23613. type: string
  23614. name:
  23615. description: The name of the Secret resource being referred to.
  23616. maxLength: 253
  23617. minLength: 1
  23618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23619. type: string
  23620. namespace:
  23621. description: |-
  23622. The namespace of the Secret resource being referred to.
  23623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23624. maxLength: 63
  23625. minLength: 1
  23626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23627. type: string
  23628. type: object
  23629. type: object
  23630. required:
  23631. - SecretRef
  23632. type: object
  23633. caBundle:
  23634. description: |-
  23635. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23636. can be performed.
  23637. format: byte
  23638. type: string
  23639. caProvider:
  23640. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23641. properties:
  23642. key:
  23643. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23644. maxLength: 253
  23645. minLength: 1
  23646. pattern: ^[-._a-zA-Z0-9]+$
  23647. type: string
  23648. name:
  23649. description: The name of the object located at the provider type.
  23650. maxLength: 253
  23651. minLength: 1
  23652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23653. type: string
  23654. namespace:
  23655. description: |-
  23656. The namespace the Provider type is in.
  23657. Can only be defined when used in a ClusterSecretStore.
  23658. maxLength: 63
  23659. minLength: 1
  23660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23661. type: string
  23662. type:
  23663. description: The type of provider to use such as "Secret", or "ConfigMap".
  23664. enum:
  23665. - Secret
  23666. - ConfigMap
  23667. type: string
  23668. required:
  23669. - name
  23670. - type
  23671. type: object
  23672. environment:
  23673. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  23674. type: string
  23675. groupIDs:
  23676. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  23677. items:
  23678. type: string
  23679. type: array
  23680. inheritFromGroups:
  23681. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  23682. type: boolean
  23683. projectID:
  23684. description: ProjectID specifies a project where secrets are located.
  23685. type: string
  23686. url:
  23687. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  23688. type: string
  23689. required:
  23690. - auth
  23691. type: object
  23692. ibm:
  23693. description: IBM configures this store to sync secrets using IBM Cloud provider
  23694. properties:
  23695. auth:
  23696. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  23697. maxProperties: 1
  23698. minProperties: 1
  23699. properties:
  23700. containerAuth:
  23701. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  23702. properties:
  23703. iamEndpoint:
  23704. type: string
  23705. profile:
  23706. description: the IBM Trusted Profile
  23707. type: string
  23708. tokenLocation:
  23709. description: Location the token is mounted on the pod
  23710. type: string
  23711. required:
  23712. - profile
  23713. type: object
  23714. secretRef:
  23715. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  23716. properties:
  23717. secretApiKeySecretRef:
  23718. description: The SecretAccessKey is used for authentication
  23719. properties:
  23720. key:
  23721. description: |-
  23722. A key in the referenced Secret.
  23723. Some instances of this field may be defaulted, in others it may be required.
  23724. maxLength: 253
  23725. minLength: 1
  23726. pattern: ^[-._a-zA-Z0-9]+$
  23727. type: string
  23728. name:
  23729. description: The name of the Secret resource being referred to.
  23730. maxLength: 253
  23731. minLength: 1
  23732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23733. type: string
  23734. namespace:
  23735. description: |-
  23736. The namespace of the Secret resource being referred to.
  23737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23738. maxLength: 63
  23739. minLength: 1
  23740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23741. type: string
  23742. type: object
  23743. type: object
  23744. type: object
  23745. serviceUrl:
  23746. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  23747. type: string
  23748. required:
  23749. - auth
  23750. type: object
  23751. infisical:
  23752. description: Infisical configures this store to sync secrets using the Infisical provider
  23753. properties:
  23754. auth:
  23755. description: Auth configures how the Operator authenticates with the Infisical API
  23756. properties:
  23757. universalAuthCredentials:
  23758. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  23759. properties:
  23760. clientId:
  23761. description: |-
  23762. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23763. In some instances, `key` is a required field.
  23764. properties:
  23765. key:
  23766. description: |-
  23767. A key in the referenced Secret.
  23768. Some instances of this field may be defaulted, in others it may be required.
  23769. maxLength: 253
  23770. minLength: 1
  23771. pattern: ^[-._a-zA-Z0-9]+$
  23772. type: string
  23773. name:
  23774. description: The name of the Secret resource being referred to.
  23775. maxLength: 253
  23776. minLength: 1
  23777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23778. type: string
  23779. namespace:
  23780. description: |-
  23781. The namespace of the Secret resource being referred to.
  23782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23783. maxLength: 63
  23784. minLength: 1
  23785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23786. type: string
  23787. type: object
  23788. clientSecret:
  23789. description: |-
  23790. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23791. In some instances, `key` is a required field.
  23792. properties:
  23793. key:
  23794. description: |-
  23795. A key in the referenced Secret.
  23796. Some instances of this field may be defaulted, in others it may be required.
  23797. maxLength: 253
  23798. minLength: 1
  23799. pattern: ^[-._a-zA-Z0-9]+$
  23800. type: string
  23801. name:
  23802. description: The name of the Secret resource being referred to.
  23803. maxLength: 253
  23804. minLength: 1
  23805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23806. type: string
  23807. namespace:
  23808. description: |-
  23809. The namespace of the Secret resource being referred to.
  23810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23811. maxLength: 63
  23812. minLength: 1
  23813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23814. type: string
  23815. type: object
  23816. required:
  23817. - clientId
  23818. - clientSecret
  23819. type: object
  23820. type: object
  23821. hostAPI:
  23822. default: https://app.infisical.com/api
  23823. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  23824. type: string
  23825. secretsScope:
  23826. description: SecretsScope defines the scope of the secrets within the workspace
  23827. properties:
  23828. environmentSlug:
  23829. description: EnvironmentSlug is the required slug identifier for the environment.
  23830. type: string
  23831. expandSecretReferences:
  23832. default: true
  23833. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  23834. type: boolean
  23835. projectSlug:
  23836. description: ProjectSlug is the required slug identifier for the project.
  23837. type: string
  23838. recursive:
  23839. default: false
  23840. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  23841. type: boolean
  23842. secretsPath:
  23843. default: /
  23844. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  23845. type: string
  23846. required:
  23847. - environmentSlug
  23848. - projectSlug
  23849. type: object
  23850. required:
  23851. - auth
  23852. - secretsScope
  23853. type: object
  23854. keepersecurity:
  23855. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  23856. properties:
  23857. authRef:
  23858. description: |-
  23859. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23860. In some instances, `key` is a required field.
  23861. properties:
  23862. key:
  23863. description: |-
  23864. A key in the referenced Secret.
  23865. Some instances of this field may be defaulted, in others it may be required.
  23866. maxLength: 253
  23867. minLength: 1
  23868. pattern: ^[-._a-zA-Z0-9]+$
  23869. type: string
  23870. name:
  23871. description: The name of the Secret resource being referred to.
  23872. maxLength: 253
  23873. minLength: 1
  23874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23875. type: string
  23876. namespace:
  23877. description: |-
  23878. The namespace of the Secret resource being referred to.
  23879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23880. maxLength: 63
  23881. minLength: 1
  23882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23883. type: string
  23884. type: object
  23885. folderID:
  23886. type: string
  23887. required:
  23888. - authRef
  23889. - folderID
  23890. type: object
  23891. kubernetes:
  23892. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  23893. properties:
  23894. auth:
  23895. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  23896. maxProperties: 1
  23897. minProperties: 1
  23898. properties:
  23899. cert:
  23900. description: has both clientCert and clientKey as secretKeySelector
  23901. properties:
  23902. clientCert:
  23903. description: |-
  23904. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23905. In some instances, `key` is a required field.
  23906. properties:
  23907. key:
  23908. description: |-
  23909. A key in the referenced Secret.
  23910. Some instances of this field may be defaulted, in others it may be required.
  23911. maxLength: 253
  23912. minLength: 1
  23913. pattern: ^[-._a-zA-Z0-9]+$
  23914. type: string
  23915. name:
  23916. description: The name of the Secret resource being referred to.
  23917. maxLength: 253
  23918. minLength: 1
  23919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23920. type: string
  23921. namespace:
  23922. description: |-
  23923. The namespace of the Secret resource being referred to.
  23924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23925. maxLength: 63
  23926. minLength: 1
  23927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23928. type: string
  23929. type: object
  23930. clientKey:
  23931. description: |-
  23932. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23933. In some instances, `key` is a required field.
  23934. properties:
  23935. key:
  23936. description: |-
  23937. A key in the referenced Secret.
  23938. Some instances of this field may be defaulted, in others it may be required.
  23939. maxLength: 253
  23940. minLength: 1
  23941. pattern: ^[-._a-zA-Z0-9]+$
  23942. type: string
  23943. name:
  23944. description: The name of the Secret resource being referred to.
  23945. maxLength: 253
  23946. minLength: 1
  23947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23948. type: string
  23949. namespace:
  23950. description: |-
  23951. The namespace of the Secret resource being referred to.
  23952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23953. maxLength: 63
  23954. minLength: 1
  23955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23956. type: string
  23957. type: object
  23958. type: object
  23959. serviceAccount:
  23960. description: points to a service account that should be used for authentication
  23961. properties:
  23962. audiences:
  23963. description: |-
  23964. Audience specifies the `aud` claim for the service account token
  23965. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23966. then this audiences will be appended to the list
  23967. items:
  23968. type: string
  23969. type: array
  23970. name:
  23971. description: The name of the ServiceAccount resource being referred to.
  23972. maxLength: 253
  23973. minLength: 1
  23974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23975. type: string
  23976. namespace:
  23977. description: |-
  23978. Namespace of the resource being referred to.
  23979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23980. maxLength: 63
  23981. minLength: 1
  23982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23983. type: string
  23984. required:
  23985. - name
  23986. type: object
  23987. token:
  23988. description: use static token to authenticate with
  23989. properties:
  23990. bearerToken:
  23991. description: |-
  23992. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23993. In some instances, `key` is a required field.
  23994. properties:
  23995. key:
  23996. description: |-
  23997. A key in the referenced Secret.
  23998. Some instances of this field may be defaulted, in others it may be required.
  23999. maxLength: 253
  24000. minLength: 1
  24001. pattern: ^[-._a-zA-Z0-9]+$
  24002. type: string
  24003. name:
  24004. description: The name of the Secret resource being referred to.
  24005. maxLength: 253
  24006. minLength: 1
  24007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24008. type: string
  24009. namespace:
  24010. description: |-
  24011. The namespace of the Secret resource being referred to.
  24012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24013. maxLength: 63
  24014. minLength: 1
  24015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24016. type: string
  24017. type: object
  24018. type: object
  24019. type: object
  24020. authRef:
  24021. description: A reference to a secret that contains the auth information.
  24022. properties:
  24023. key:
  24024. description: |-
  24025. A key in the referenced Secret.
  24026. Some instances of this field may be defaulted, in others it may be required.
  24027. maxLength: 253
  24028. minLength: 1
  24029. pattern: ^[-._a-zA-Z0-9]+$
  24030. type: string
  24031. name:
  24032. description: The name of the Secret resource being referred to.
  24033. maxLength: 253
  24034. minLength: 1
  24035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24036. type: string
  24037. namespace:
  24038. description: |-
  24039. The namespace of the Secret resource being referred to.
  24040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24041. maxLength: 63
  24042. minLength: 1
  24043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24044. type: string
  24045. type: object
  24046. remoteNamespace:
  24047. default: default
  24048. description: Remote namespace to fetch the secrets from
  24049. maxLength: 63
  24050. minLength: 1
  24051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24052. type: string
  24053. server:
  24054. description: configures the Kubernetes server Address.
  24055. properties:
  24056. caBundle:
  24057. description: CABundle is a base64-encoded CA certificate
  24058. format: byte
  24059. type: string
  24060. caProvider:
  24061. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24062. properties:
  24063. key:
  24064. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24065. maxLength: 253
  24066. minLength: 1
  24067. pattern: ^[-._a-zA-Z0-9]+$
  24068. type: string
  24069. name:
  24070. description: The name of the object located at the provider type.
  24071. maxLength: 253
  24072. minLength: 1
  24073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24074. type: string
  24075. namespace:
  24076. description: |-
  24077. The namespace the Provider type is in.
  24078. Can only be defined when used in a ClusterSecretStore.
  24079. maxLength: 63
  24080. minLength: 1
  24081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24082. type: string
  24083. type:
  24084. description: The type of provider to use such as "Secret", or "ConfigMap".
  24085. enum:
  24086. - Secret
  24087. - ConfigMap
  24088. type: string
  24089. required:
  24090. - name
  24091. - type
  24092. type: object
  24093. url:
  24094. default: kubernetes.default
  24095. description: configures the Kubernetes server Address.
  24096. type: string
  24097. type: object
  24098. type: object
  24099. onboardbase:
  24100. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24101. properties:
  24102. apiHost:
  24103. default: https://public.onboardbase.com/api/v1/
  24104. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24105. type: string
  24106. auth:
  24107. description: Auth configures how the Operator authenticates with the Onboardbase API
  24108. properties:
  24109. apiKeyRef:
  24110. description: |-
  24111. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24112. It is used to recognize and authorize access to a project and environment within onboardbase
  24113. properties:
  24114. key:
  24115. description: |-
  24116. A key in the referenced Secret.
  24117. Some instances of this field may be defaulted, in others it may be required.
  24118. maxLength: 253
  24119. minLength: 1
  24120. pattern: ^[-._a-zA-Z0-9]+$
  24121. type: string
  24122. name:
  24123. description: The name of the Secret resource being referred to.
  24124. maxLength: 253
  24125. minLength: 1
  24126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24127. type: string
  24128. namespace:
  24129. description: |-
  24130. The namespace of the Secret resource being referred to.
  24131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24132. maxLength: 63
  24133. minLength: 1
  24134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24135. type: string
  24136. type: object
  24137. passcodeRef:
  24138. description: OnboardbasePasscode is the passcode attached to the API Key
  24139. properties:
  24140. key:
  24141. description: |-
  24142. A key in the referenced Secret.
  24143. Some instances of this field may be defaulted, in others it may be required.
  24144. maxLength: 253
  24145. minLength: 1
  24146. pattern: ^[-._a-zA-Z0-9]+$
  24147. type: string
  24148. name:
  24149. description: The name of the Secret resource being referred to.
  24150. maxLength: 253
  24151. minLength: 1
  24152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24153. type: string
  24154. namespace:
  24155. description: |-
  24156. The namespace of the Secret resource being referred to.
  24157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24158. maxLength: 63
  24159. minLength: 1
  24160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24161. type: string
  24162. type: object
  24163. required:
  24164. - apiKeyRef
  24165. - passcodeRef
  24166. type: object
  24167. environment:
  24168. default: development
  24169. description: Environment is the name of an environmnent within a project to pull the secrets from
  24170. type: string
  24171. project:
  24172. default: development
  24173. description: Project is an onboardbase project that the secrets should be pulled from
  24174. type: string
  24175. required:
  24176. - apiHost
  24177. - auth
  24178. - environment
  24179. - project
  24180. type: object
  24181. onepassword:
  24182. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24183. properties:
  24184. auth:
  24185. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24186. properties:
  24187. secretRef:
  24188. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24189. properties:
  24190. connectTokenSecretRef:
  24191. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24192. properties:
  24193. key:
  24194. description: |-
  24195. A key in the referenced Secret.
  24196. Some instances of this field may be defaulted, in others it may be required.
  24197. maxLength: 253
  24198. minLength: 1
  24199. pattern: ^[-._a-zA-Z0-9]+$
  24200. type: string
  24201. name:
  24202. description: The name of the Secret resource being referred to.
  24203. maxLength: 253
  24204. minLength: 1
  24205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24206. type: string
  24207. namespace:
  24208. description: |-
  24209. The namespace of the Secret resource being referred to.
  24210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24211. maxLength: 63
  24212. minLength: 1
  24213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24214. type: string
  24215. type: object
  24216. required:
  24217. - connectTokenSecretRef
  24218. type: object
  24219. required:
  24220. - secretRef
  24221. type: object
  24222. connectHost:
  24223. description: ConnectHost defines the OnePassword Connect Server to connect to
  24224. type: string
  24225. vaults:
  24226. additionalProperties:
  24227. type: integer
  24228. description: Vaults defines which OnePassword vaults to search in which order
  24229. type: object
  24230. required:
  24231. - auth
  24232. - connectHost
  24233. - vaults
  24234. type: object
  24235. oracle:
  24236. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24237. properties:
  24238. auth:
  24239. description: |-
  24240. Auth configures how secret-manager authenticates with the Oracle Vault.
  24241. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24242. properties:
  24243. secretRef:
  24244. description: SecretRef to pass through sensitive information.
  24245. properties:
  24246. fingerprint:
  24247. description: Fingerprint is the fingerprint of the API private key.
  24248. properties:
  24249. key:
  24250. description: |-
  24251. A key in the referenced Secret.
  24252. Some instances of this field may be defaulted, in others it may be required.
  24253. maxLength: 253
  24254. minLength: 1
  24255. pattern: ^[-._a-zA-Z0-9]+$
  24256. type: string
  24257. name:
  24258. description: The name of the Secret resource being referred to.
  24259. maxLength: 253
  24260. minLength: 1
  24261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24262. type: string
  24263. namespace:
  24264. description: |-
  24265. The namespace of the Secret resource being referred to.
  24266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24267. maxLength: 63
  24268. minLength: 1
  24269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24270. type: string
  24271. type: object
  24272. privatekey:
  24273. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24274. properties:
  24275. key:
  24276. description: |-
  24277. A key in the referenced Secret.
  24278. Some instances of this field may be defaulted, in others it may be required.
  24279. maxLength: 253
  24280. minLength: 1
  24281. pattern: ^[-._a-zA-Z0-9]+$
  24282. type: string
  24283. name:
  24284. description: The name of the Secret resource being referred to.
  24285. maxLength: 253
  24286. minLength: 1
  24287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24288. type: string
  24289. namespace:
  24290. description: |-
  24291. The namespace of the Secret resource being referred to.
  24292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24293. maxLength: 63
  24294. minLength: 1
  24295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24296. type: string
  24297. type: object
  24298. required:
  24299. - fingerprint
  24300. - privatekey
  24301. type: object
  24302. tenancy:
  24303. description: Tenancy is the tenancy OCID where user is located.
  24304. type: string
  24305. user:
  24306. description: User is an access OCID specific to the account.
  24307. type: string
  24308. required:
  24309. - secretRef
  24310. - tenancy
  24311. - user
  24312. type: object
  24313. compartment:
  24314. description: |-
  24315. Compartment is the vault compartment OCID.
  24316. Required for PushSecret
  24317. type: string
  24318. encryptionKey:
  24319. description: |-
  24320. EncryptionKey is the OCID of the encryption key within the vault.
  24321. Required for PushSecret
  24322. type: string
  24323. principalType:
  24324. description: |-
  24325. The type of principal to use for authentication. If left blank, the Auth struct will
  24326. determine the principal type. This optional field must be specified if using
  24327. workload identity.
  24328. enum:
  24329. - ""
  24330. - UserPrincipal
  24331. - InstancePrincipal
  24332. - Workload
  24333. type: string
  24334. region:
  24335. description: Region is the region where vault is located.
  24336. type: string
  24337. serviceAccountRef:
  24338. description: |-
  24339. ServiceAccountRef specified the service account
  24340. that should be used when authenticating with WorkloadIdentity.
  24341. properties:
  24342. audiences:
  24343. description: |-
  24344. Audience specifies the `aud` claim for the service account token
  24345. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24346. then this audiences will be appended to the list
  24347. items:
  24348. type: string
  24349. type: array
  24350. name:
  24351. description: The name of the ServiceAccount resource being referred to.
  24352. maxLength: 253
  24353. minLength: 1
  24354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24355. type: string
  24356. namespace:
  24357. description: |-
  24358. Namespace of the resource being referred to.
  24359. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24360. maxLength: 63
  24361. minLength: 1
  24362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24363. type: string
  24364. required:
  24365. - name
  24366. type: object
  24367. vault:
  24368. description: Vault is the vault's OCID of the specific vault where secret is located.
  24369. type: string
  24370. required:
  24371. - region
  24372. - vault
  24373. type: object
  24374. passbolt:
  24375. description: PassboltProvider defines configuration for the Passbolt provider.
  24376. properties:
  24377. auth:
  24378. description: Auth defines the information necessary to authenticate against Passbolt Server
  24379. properties:
  24380. passwordSecretRef:
  24381. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  24382. properties:
  24383. key:
  24384. description: |-
  24385. A key in the referenced Secret.
  24386. Some instances of this field may be defaulted, in others it may be required.
  24387. maxLength: 253
  24388. minLength: 1
  24389. pattern: ^[-._a-zA-Z0-9]+$
  24390. type: string
  24391. name:
  24392. description: The name of the Secret resource being referred to.
  24393. maxLength: 253
  24394. minLength: 1
  24395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24396. type: string
  24397. namespace:
  24398. description: |-
  24399. The namespace of the Secret resource being referred to.
  24400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24401. maxLength: 63
  24402. minLength: 1
  24403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24404. type: string
  24405. type: object
  24406. privateKeySecretRef:
  24407. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  24408. properties:
  24409. key:
  24410. description: |-
  24411. A key in the referenced Secret.
  24412. Some instances of this field may be defaulted, in others it may be required.
  24413. maxLength: 253
  24414. minLength: 1
  24415. pattern: ^[-._a-zA-Z0-9]+$
  24416. type: string
  24417. name:
  24418. description: The name of the Secret resource being referred to.
  24419. maxLength: 253
  24420. minLength: 1
  24421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24422. type: string
  24423. namespace:
  24424. description: |-
  24425. The namespace of the Secret resource being referred to.
  24426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24427. maxLength: 63
  24428. minLength: 1
  24429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24430. type: string
  24431. type: object
  24432. required:
  24433. - passwordSecretRef
  24434. - privateKeySecretRef
  24435. type: object
  24436. host:
  24437. description: Host defines the Passbolt Server to connect to
  24438. type: string
  24439. required:
  24440. - auth
  24441. - host
  24442. type: object
  24443. passworddepot:
  24444. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  24445. properties:
  24446. auth:
  24447. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  24448. properties:
  24449. secretRef:
  24450. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  24451. properties:
  24452. credentials:
  24453. description: Username / Password is used for authentication.
  24454. properties:
  24455. key:
  24456. description: |-
  24457. A key in the referenced Secret.
  24458. Some instances of this field may be defaulted, in others it may be required.
  24459. maxLength: 253
  24460. minLength: 1
  24461. pattern: ^[-._a-zA-Z0-9]+$
  24462. type: string
  24463. name:
  24464. description: The name of the Secret resource being referred to.
  24465. maxLength: 253
  24466. minLength: 1
  24467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24468. type: string
  24469. namespace:
  24470. description: |-
  24471. The namespace of the Secret resource being referred to.
  24472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24473. maxLength: 63
  24474. minLength: 1
  24475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24476. type: string
  24477. type: object
  24478. type: object
  24479. required:
  24480. - secretRef
  24481. type: object
  24482. database:
  24483. description: Database to use as source
  24484. type: string
  24485. host:
  24486. description: URL configures the Password Depot instance URL.
  24487. type: string
  24488. required:
  24489. - auth
  24490. - database
  24491. - host
  24492. type: object
  24493. previder:
  24494. description: Previder configures this store to sync secrets using the Previder provider
  24495. properties:
  24496. auth:
  24497. description: PreviderAuth contains a secretRef for credentials.
  24498. properties:
  24499. secretRef:
  24500. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  24501. properties:
  24502. accessToken:
  24503. description: The AccessToken is used for authentication
  24504. properties:
  24505. key:
  24506. description: |-
  24507. A key in the referenced Secret.
  24508. Some instances of this field may be defaulted, in others it may be required.
  24509. maxLength: 253
  24510. minLength: 1
  24511. pattern: ^[-._a-zA-Z0-9]+$
  24512. type: string
  24513. name:
  24514. description: The name of the Secret resource being referred to.
  24515. maxLength: 253
  24516. minLength: 1
  24517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24518. type: string
  24519. namespace:
  24520. description: |-
  24521. The namespace of the Secret resource being referred to.
  24522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24523. maxLength: 63
  24524. minLength: 1
  24525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24526. type: string
  24527. type: object
  24528. required:
  24529. - accessToken
  24530. type: object
  24531. type: object
  24532. baseUri:
  24533. type: string
  24534. required:
  24535. - auth
  24536. type: object
  24537. pulumi:
  24538. description: Pulumi configures this store to sync secrets using the Pulumi provider
  24539. properties:
  24540. accessToken:
  24541. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  24542. properties:
  24543. secretRef:
  24544. description: SecretRef is a reference to a secret containing the Pulumi API token.
  24545. properties:
  24546. key:
  24547. description: |-
  24548. A key in the referenced Secret.
  24549. Some instances of this field may be defaulted, in others it may be required.
  24550. maxLength: 253
  24551. minLength: 1
  24552. pattern: ^[-._a-zA-Z0-9]+$
  24553. type: string
  24554. name:
  24555. description: The name of the Secret resource being referred to.
  24556. maxLength: 253
  24557. minLength: 1
  24558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24559. type: string
  24560. namespace:
  24561. description: |-
  24562. The namespace of the Secret resource being referred to.
  24563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24564. maxLength: 63
  24565. minLength: 1
  24566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24567. type: string
  24568. type: object
  24569. type: object
  24570. apiUrl:
  24571. default: https://api.pulumi.com/api/esc
  24572. description: APIURL is the URL of the Pulumi API.
  24573. type: string
  24574. environment:
  24575. description: |-
  24576. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  24577. dynamically retrieved values from supported providers including all major clouds,
  24578. and other Pulumi ESC environments.
  24579. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  24580. type: string
  24581. organization:
  24582. description: |-
  24583. Organization are a space to collaborate on shared projects and stacks.
  24584. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  24585. type: string
  24586. project:
  24587. description: Project is the name of the Pulumi ESC project the environment belongs to.
  24588. type: string
  24589. required:
  24590. - accessToken
  24591. - environment
  24592. - organization
  24593. - project
  24594. type: object
  24595. scaleway:
  24596. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  24597. properties:
  24598. accessKey:
  24599. description: AccessKey is the non-secret part of the api key.
  24600. properties:
  24601. secretRef:
  24602. description: SecretRef references a key in a secret that will be used as value.
  24603. properties:
  24604. key:
  24605. description: |-
  24606. A key in the referenced Secret.
  24607. Some instances of this field may be defaulted, in others it may be required.
  24608. maxLength: 253
  24609. minLength: 1
  24610. pattern: ^[-._a-zA-Z0-9]+$
  24611. type: string
  24612. name:
  24613. description: The name of the Secret resource being referred to.
  24614. maxLength: 253
  24615. minLength: 1
  24616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24617. type: string
  24618. namespace:
  24619. description: |-
  24620. The namespace of the Secret resource being referred to.
  24621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24622. maxLength: 63
  24623. minLength: 1
  24624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24625. type: string
  24626. type: object
  24627. value:
  24628. description: Value can be specified directly to set a value without using a secret.
  24629. type: string
  24630. type: object
  24631. apiUrl:
  24632. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  24633. type: string
  24634. projectId:
  24635. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  24636. type: string
  24637. region:
  24638. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  24639. type: string
  24640. secretKey:
  24641. description: SecretKey is the non-secret part of the api key.
  24642. properties:
  24643. secretRef:
  24644. description: SecretRef references a key in a secret that will be used as value.
  24645. properties:
  24646. key:
  24647. description: |-
  24648. A key in the referenced Secret.
  24649. Some instances of this field may be defaulted, in others it may be required.
  24650. maxLength: 253
  24651. minLength: 1
  24652. pattern: ^[-._a-zA-Z0-9]+$
  24653. type: string
  24654. name:
  24655. description: The name of the Secret resource being referred to.
  24656. maxLength: 253
  24657. minLength: 1
  24658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24659. type: string
  24660. namespace:
  24661. description: |-
  24662. The namespace of the Secret resource being referred to.
  24663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24664. maxLength: 63
  24665. minLength: 1
  24666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24667. type: string
  24668. type: object
  24669. value:
  24670. description: Value can be specified directly to set a value without using a secret.
  24671. type: string
  24672. type: object
  24673. required:
  24674. - accessKey
  24675. - projectId
  24676. - region
  24677. - secretKey
  24678. type: object
  24679. secretserver:
  24680. description: |-
  24681. SecretServer configures this store to sync secrets using SecretServer provider
  24682. https://docs.delinea.com/online-help/secret-server/start.htm
  24683. properties:
  24684. password:
  24685. description: Password is the secret server account password.
  24686. properties:
  24687. secretRef:
  24688. description: SecretRef references a key in a secret that will be used as value.
  24689. properties:
  24690. key:
  24691. description: |-
  24692. A key in the referenced Secret.
  24693. Some instances of this field may be defaulted, in others it may be required.
  24694. maxLength: 253
  24695. minLength: 1
  24696. pattern: ^[-._a-zA-Z0-9]+$
  24697. type: string
  24698. name:
  24699. description: The name of the Secret resource being referred to.
  24700. maxLength: 253
  24701. minLength: 1
  24702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24703. type: string
  24704. namespace:
  24705. description: |-
  24706. The namespace of the Secret resource being referred to.
  24707. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24708. maxLength: 63
  24709. minLength: 1
  24710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24711. type: string
  24712. type: object
  24713. value:
  24714. description: Value can be specified directly to set a value without using a secret.
  24715. type: string
  24716. type: object
  24717. serverURL:
  24718. description: |-
  24719. ServerURL
  24720. URL to your secret server installation
  24721. type: string
  24722. username:
  24723. description: Username is the secret server account username.
  24724. properties:
  24725. secretRef:
  24726. description: SecretRef references a key in a secret that will be used as value.
  24727. properties:
  24728. key:
  24729. description: |-
  24730. A key in the referenced Secret.
  24731. Some instances of this field may be defaulted, in others it may be required.
  24732. maxLength: 253
  24733. minLength: 1
  24734. pattern: ^[-._a-zA-Z0-9]+$
  24735. type: string
  24736. name:
  24737. description: The name of the Secret resource being referred to.
  24738. maxLength: 253
  24739. minLength: 1
  24740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24741. type: string
  24742. namespace:
  24743. description: |-
  24744. The namespace of the Secret resource being referred to.
  24745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24746. maxLength: 63
  24747. minLength: 1
  24748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24749. type: string
  24750. type: object
  24751. value:
  24752. description: Value can be specified directly to set a value without using a secret.
  24753. type: string
  24754. type: object
  24755. required:
  24756. - password
  24757. - serverURL
  24758. - username
  24759. type: object
  24760. senhasegura:
  24761. description: Senhasegura configures this store to sync secrets using senhasegura provider
  24762. properties:
  24763. auth:
  24764. description: Auth defines parameters to authenticate in senhasegura
  24765. properties:
  24766. clientId:
  24767. type: string
  24768. clientSecretSecretRef:
  24769. description: |-
  24770. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24771. In some instances, `key` is a required field.
  24772. properties:
  24773. key:
  24774. description: |-
  24775. A key in the referenced Secret.
  24776. Some instances of this field may be defaulted, in others it may be required.
  24777. maxLength: 253
  24778. minLength: 1
  24779. pattern: ^[-._a-zA-Z0-9]+$
  24780. type: string
  24781. name:
  24782. description: The name of the Secret resource being referred to.
  24783. maxLength: 253
  24784. minLength: 1
  24785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24786. type: string
  24787. namespace:
  24788. description: |-
  24789. The namespace of the Secret resource being referred to.
  24790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24791. maxLength: 63
  24792. minLength: 1
  24793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24794. type: string
  24795. type: object
  24796. required:
  24797. - clientId
  24798. - clientSecretSecretRef
  24799. type: object
  24800. ignoreSslCertificate:
  24801. default: false
  24802. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  24803. type: boolean
  24804. module:
  24805. description: Module defines which senhasegura module should be used to get secrets
  24806. type: string
  24807. url:
  24808. description: URL of senhasegura
  24809. type: string
  24810. required:
  24811. - auth
  24812. - module
  24813. - url
  24814. type: object
  24815. vault:
  24816. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  24817. properties:
  24818. auth:
  24819. description: Auth configures how secret-manager authenticates with the Vault server.
  24820. properties:
  24821. appRole:
  24822. description: |-
  24823. AppRole authenticates with Vault using the App Role auth mechanism,
  24824. with the role and secret stored in a Kubernetes Secret resource.
  24825. properties:
  24826. path:
  24827. default: approle
  24828. description: |-
  24829. Path where the App Role authentication backend is mounted
  24830. in Vault, e.g: "approle"
  24831. type: string
  24832. roleId:
  24833. description: |-
  24834. RoleID configured in the App Role authentication backend when setting
  24835. up the authentication backend in Vault.
  24836. type: string
  24837. roleRef:
  24838. description: |-
  24839. Reference to a key in a Secret that contains the App Role ID used
  24840. to authenticate with Vault.
  24841. The `key` field must be specified and denotes which entry within the Secret
  24842. resource is used as the app role id.
  24843. properties:
  24844. key:
  24845. description: |-
  24846. A key in the referenced Secret.
  24847. Some instances of this field may be defaulted, in others it may be required.
  24848. maxLength: 253
  24849. minLength: 1
  24850. pattern: ^[-._a-zA-Z0-9]+$
  24851. type: string
  24852. name:
  24853. description: The name of the Secret resource being referred to.
  24854. maxLength: 253
  24855. minLength: 1
  24856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24857. type: string
  24858. namespace:
  24859. description: |-
  24860. The namespace of the Secret resource being referred to.
  24861. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24862. maxLength: 63
  24863. minLength: 1
  24864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24865. type: string
  24866. type: object
  24867. secretRef:
  24868. description: |-
  24869. Reference to a key in a Secret that contains the App Role secret used
  24870. to authenticate with Vault.
  24871. The `key` field must be specified and denotes which entry within the Secret
  24872. resource is used as the app role secret.
  24873. properties:
  24874. key:
  24875. description: |-
  24876. A key in the referenced Secret.
  24877. Some instances of this field may be defaulted, in others it may be required.
  24878. maxLength: 253
  24879. minLength: 1
  24880. pattern: ^[-._a-zA-Z0-9]+$
  24881. type: string
  24882. name:
  24883. description: The name of the Secret resource being referred to.
  24884. maxLength: 253
  24885. minLength: 1
  24886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24887. type: string
  24888. namespace:
  24889. description: |-
  24890. The namespace of the Secret resource being referred to.
  24891. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24892. maxLength: 63
  24893. minLength: 1
  24894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24895. type: string
  24896. type: object
  24897. required:
  24898. - path
  24899. - secretRef
  24900. type: object
  24901. cert:
  24902. description: |-
  24903. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  24904. Cert authentication method
  24905. properties:
  24906. clientCert:
  24907. description: |-
  24908. ClientCert is a certificate to authenticate using the Cert Vault
  24909. authentication method
  24910. properties:
  24911. key:
  24912. description: |-
  24913. A key in the referenced Secret.
  24914. Some instances of this field may be defaulted, in others it may be required.
  24915. maxLength: 253
  24916. minLength: 1
  24917. pattern: ^[-._a-zA-Z0-9]+$
  24918. type: string
  24919. name:
  24920. description: The name of the Secret resource being referred to.
  24921. maxLength: 253
  24922. minLength: 1
  24923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24924. type: string
  24925. namespace:
  24926. description: |-
  24927. The namespace of the Secret resource being referred to.
  24928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24929. maxLength: 63
  24930. minLength: 1
  24931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24932. type: string
  24933. type: object
  24934. secretRef:
  24935. description: |-
  24936. SecretRef to a key in a Secret resource containing client private key to
  24937. authenticate with Vault using the Cert authentication method
  24938. properties:
  24939. key:
  24940. description: |-
  24941. A key in the referenced Secret.
  24942. Some instances of this field may be defaulted, in others it may be required.
  24943. maxLength: 253
  24944. minLength: 1
  24945. pattern: ^[-._a-zA-Z0-9]+$
  24946. type: string
  24947. name:
  24948. description: The name of the Secret resource being referred to.
  24949. maxLength: 253
  24950. minLength: 1
  24951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24952. type: string
  24953. namespace:
  24954. description: |-
  24955. The namespace of the Secret resource being referred to.
  24956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24957. maxLength: 63
  24958. minLength: 1
  24959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24960. type: string
  24961. type: object
  24962. type: object
  24963. iam:
  24964. description: |-
  24965. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  24966. AWS IAM authentication method
  24967. properties:
  24968. externalID:
  24969. description: AWS External ID set on assumed IAM roles
  24970. type: string
  24971. jwt:
  24972. description: Specify a service account with IRSA enabled
  24973. properties:
  24974. serviceAccountRef:
  24975. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24976. properties:
  24977. audiences:
  24978. description: |-
  24979. Audience specifies the `aud` claim for the service account token
  24980. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24981. then this audiences will be appended to the list
  24982. items:
  24983. type: string
  24984. type: array
  24985. name:
  24986. description: The name of the ServiceAccount resource being referred to.
  24987. maxLength: 253
  24988. minLength: 1
  24989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24990. type: string
  24991. namespace:
  24992. description: |-
  24993. Namespace of the resource being referred to.
  24994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24995. maxLength: 63
  24996. minLength: 1
  24997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24998. type: string
  24999. required:
  25000. - name
  25001. type: object
  25002. type: object
  25003. path:
  25004. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25005. type: string
  25006. region:
  25007. description: AWS region
  25008. type: string
  25009. role:
  25010. description: This is the AWS role to be assumed before talking to vault
  25011. type: string
  25012. secretRef:
  25013. description: Specify credentials in a Secret object
  25014. properties:
  25015. accessKeyIDSecretRef:
  25016. description: The AccessKeyID is used for authentication
  25017. properties:
  25018. key:
  25019. description: |-
  25020. A key in the referenced Secret.
  25021. Some instances of this field may be defaulted, in others it may be required.
  25022. maxLength: 253
  25023. minLength: 1
  25024. pattern: ^[-._a-zA-Z0-9]+$
  25025. type: string
  25026. name:
  25027. description: The name of the Secret resource being referred to.
  25028. maxLength: 253
  25029. minLength: 1
  25030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25031. type: string
  25032. namespace:
  25033. description: |-
  25034. The namespace of the Secret resource being referred to.
  25035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25036. maxLength: 63
  25037. minLength: 1
  25038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25039. type: string
  25040. type: object
  25041. secretAccessKeySecretRef:
  25042. description: The SecretAccessKey is used for authentication
  25043. properties:
  25044. key:
  25045. description: |-
  25046. A key in the referenced Secret.
  25047. Some instances of this field may be defaulted, in others it may be required.
  25048. maxLength: 253
  25049. minLength: 1
  25050. pattern: ^[-._a-zA-Z0-9]+$
  25051. type: string
  25052. name:
  25053. description: The name of the Secret resource being referred to.
  25054. maxLength: 253
  25055. minLength: 1
  25056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25057. type: string
  25058. namespace:
  25059. description: |-
  25060. The namespace of the Secret resource being referred to.
  25061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25062. maxLength: 63
  25063. minLength: 1
  25064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25065. type: string
  25066. type: object
  25067. sessionTokenSecretRef:
  25068. description: |-
  25069. The SessionToken used for authentication
  25070. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25071. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25072. properties:
  25073. key:
  25074. description: |-
  25075. A key in the referenced Secret.
  25076. Some instances of this field may be defaulted, in others it may be required.
  25077. maxLength: 253
  25078. minLength: 1
  25079. pattern: ^[-._a-zA-Z0-9]+$
  25080. type: string
  25081. name:
  25082. description: The name of the Secret resource being referred to.
  25083. maxLength: 253
  25084. minLength: 1
  25085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25086. type: string
  25087. namespace:
  25088. description: |-
  25089. The namespace of the Secret resource being referred to.
  25090. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25091. maxLength: 63
  25092. minLength: 1
  25093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25094. type: string
  25095. type: object
  25096. type: object
  25097. vaultAwsIamServerID:
  25098. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25099. type: string
  25100. vaultRole:
  25101. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25102. type: string
  25103. required:
  25104. - vaultRole
  25105. type: object
  25106. jwt:
  25107. description: |-
  25108. Jwt authenticates with Vault by passing role and JWT token using the
  25109. JWT/OIDC authentication method
  25110. properties:
  25111. kubernetesServiceAccountToken:
  25112. description: |-
  25113. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25114. a token for with the `TokenRequest` API.
  25115. properties:
  25116. audiences:
  25117. description: |-
  25118. Optional audiences field that will be used to request a temporary Kubernetes service
  25119. account token for the service account referenced by `serviceAccountRef`.
  25120. Defaults to a single audience `vault` it not specified.
  25121. Deprecated: use serviceAccountRef.Audiences instead
  25122. items:
  25123. type: string
  25124. type: array
  25125. expirationSeconds:
  25126. description: |-
  25127. Optional expiration time in seconds that will be used to request a temporary
  25128. Kubernetes service account token for the service account referenced by
  25129. `serviceAccountRef`.
  25130. Deprecated: this will be removed in the future.
  25131. Defaults to 10 minutes.
  25132. format: int64
  25133. type: integer
  25134. serviceAccountRef:
  25135. description: Service account field containing the name of a kubernetes ServiceAccount.
  25136. properties:
  25137. audiences:
  25138. description: |-
  25139. Audience specifies the `aud` claim for the service account token
  25140. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25141. then this audiences will be appended to the list
  25142. items:
  25143. type: string
  25144. type: array
  25145. name:
  25146. description: The name of the ServiceAccount resource being referred to.
  25147. maxLength: 253
  25148. minLength: 1
  25149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25150. type: string
  25151. namespace:
  25152. description: |-
  25153. Namespace of the resource being referred to.
  25154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25155. maxLength: 63
  25156. minLength: 1
  25157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25158. type: string
  25159. required:
  25160. - name
  25161. type: object
  25162. required:
  25163. - serviceAccountRef
  25164. type: object
  25165. path:
  25166. default: jwt
  25167. description: |-
  25168. Path where the JWT authentication backend is mounted
  25169. in Vault, e.g: "jwt"
  25170. type: string
  25171. role:
  25172. description: |-
  25173. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25174. authentication method
  25175. type: string
  25176. secretRef:
  25177. description: |-
  25178. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25179. authenticate with Vault using the JWT/OIDC authentication method.
  25180. properties:
  25181. key:
  25182. description: |-
  25183. A key in the referenced Secret.
  25184. Some instances of this field may be defaulted, in others it may be required.
  25185. maxLength: 253
  25186. minLength: 1
  25187. pattern: ^[-._a-zA-Z0-9]+$
  25188. type: string
  25189. name:
  25190. description: The name of the Secret resource being referred to.
  25191. maxLength: 253
  25192. minLength: 1
  25193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25194. type: string
  25195. namespace:
  25196. description: |-
  25197. The namespace of the Secret resource being referred to.
  25198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25199. maxLength: 63
  25200. minLength: 1
  25201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25202. type: string
  25203. type: object
  25204. required:
  25205. - path
  25206. type: object
  25207. kubernetes:
  25208. description: |-
  25209. Kubernetes authenticates with Vault by passing the ServiceAccount
  25210. token stored in the named Secret resource to the Vault server.
  25211. properties:
  25212. mountPath:
  25213. default: kubernetes
  25214. description: |-
  25215. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25216. "kubernetes"
  25217. type: string
  25218. role:
  25219. description: |-
  25220. A required field containing the Vault Role to assume. A Role binds a
  25221. Kubernetes ServiceAccount with a set of Vault policies.
  25222. type: string
  25223. secretRef:
  25224. description: |-
  25225. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25226. for authenticating with Vault. If a name is specified without a key,
  25227. `token` is the default. If one is not specified, the one bound to
  25228. the controller will be used.
  25229. properties:
  25230. key:
  25231. description: |-
  25232. A key in the referenced Secret.
  25233. Some instances of this field may be defaulted, in others it may be required.
  25234. maxLength: 253
  25235. minLength: 1
  25236. pattern: ^[-._a-zA-Z0-9]+$
  25237. type: string
  25238. name:
  25239. description: The name of the Secret resource being referred to.
  25240. maxLength: 253
  25241. minLength: 1
  25242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25243. type: string
  25244. namespace:
  25245. description: |-
  25246. The namespace of the Secret resource being referred to.
  25247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25248. maxLength: 63
  25249. minLength: 1
  25250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25251. type: string
  25252. type: object
  25253. serviceAccountRef:
  25254. description: |-
  25255. Optional service account field containing the name of a kubernetes ServiceAccount.
  25256. If the service account is specified, the service account secret token JWT will be used
  25257. for authenticating with Vault. If the service account selector is not supplied,
  25258. the secretRef will be used instead.
  25259. properties:
  25260. audiences:
  25261. description: |-
  25262. Audience specifies the `aud` claim for the service account token
  25263. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25264. then this audiences will be appended to the list
  25265. items:
  25266. type: string
  25267. type: array
  25268. name:
  25269. description: The name of the ServiceAccount resource being referred to.
  25270. maxLength: 253
  25271. minLength: 1
  25272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25273. type: string
  25274. namespace:
  25275. description: |-
  25276. Namespace of the resource being referred to.
  25277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25278. maxLength: 63
  25279. minLength: 1
  25280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25281. type: string
  25282. required:
  25283. - name
  25284. type: object
  25285. required:
  25286. - mountPath
  25287. - role
  25288. type: object
  25289. ldap:
  25290. description: |-
  25291. Ldap authenticates with Vault by passing username/password pair using
  25292. the LDAP authentication method
  25293. properties:
  25294. path:
  25295. default: ldap
  25296. description: |-
  25297. Path where the LDAP authentication backend is mounted
  25298. in Vault, e.g: "ldap"
  25299. type: string
  25300. secretRef:
  25301. description: |-
  25302. SecretRef to a key in a Secret resource containing password for the LDAP
  25303. user used to authenticate with Vault using the LDAP authentication
  25304. method
  25305. properties:
  25306. key:
  25307. description: |-
  25308. A key in the referenced Secret.
  25309. Some instances of this field may be defaulted, in others it may be required.
  25310. maxLength: 253
  25311. minLength: 1
  25312. pattern: ^[-._a-zA-Z0-9]+$
  25313. type: string
  25314. name:
  25315. description: The name of the Secret resource being referred to.
  25316. maxLength: 253
  25317. minLength: 1
  25318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25319. type: string
  25320. namespace:
  25321. description: |-
  25322. The namespace of the Secret resource being referred to.
  25323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25324. maxLength: 63
  25325. minLength: 1
  25326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25327. type: string
  25328. type: object
  25329. username:
  25330. description: |-
  25331. Username is an LDAP username used to authenticate using the LDAP Vault
  25332. authentication method
  25333. type: string
  25334. required:
  25335. - path
  25336. - username
  25337. type: object
  25338. namespace:
  25339. description: |-
  25340. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  25341. Namespaces is a set of features within Vault Enterprise that allows
  25342. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  25343. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  25344. This will default to Vault.Namespace field if set, or empty otherwise
  25345. type: string
  25346. tokenSecretRef:
  25347. description: TokenSecretRef authenticates with Vault by presenting a token.
  25348. properties:
  25349. key:
  25350. description: |-
  25351. A key in the referenced Secret.
  25352. Some instances of this field may be defaulted, in others it may be required.
  25353. maxLength: 253
  25354. minLength: 1
  25355. pattern: ^[-._a-zA-Z0-9]+$
  25356. type: string
  25357. name:
  25358. description: The name of the Secret resource being referred to.
  25359. maxLength: 253
  25360. minLength: 1
  25361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25362. type: string
  25363. namespace:
  25364. description: |-
  25365. The namespace of the Secret resource being referred to.
  25366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25367. maxLength: 63
  25368. minLength: 1
  25369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25370. type: string
  25371. type: object
  25372. userPass:
  25373. description: UserPass authenticates with Vault by passing username/password pair
  25374. properties:
  25375. path:
  25376. default: userpass
  25377. description: |-
  25378. Path where the UserPassword authentication backend is mounted
  25379. in Vault, e.g: "userpass"
  25380. type: string
  25381. secretRef:
  25382. description: |-
  25383. SecretRef to a key in a Secret resource containing password for the
  25384. user used to authenticate with Vault using the UserPass authentication
  25385. method
  25386. properties:
  25387. key:
  25388. description: |-
  25389. A key in the referenced Secret.
  25390. Some instances of this field may be defaulted, in others it may be required.
  25391. maxLength: 253
  25392. minLength: 1
  25393. pattern: ^[-._a-zA-Z0-9]+$
  25394. type: string
  25395. name:
  25396. description: The name of the Secret resource being referred to.
  25397. maxLength: 253
  25398. minLength: 1
  25399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25400. type: string
  25401. namespace:
  25402. description: |-
  25403. The namespace of the Secret resource being referred to.
  25404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25405. maxLength: 63
  25406. minLength: 1
  25407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25408. type: string
  25409. type: object
  25410. username:
  25411. description: |-
  25412. Username is a username used to authenticate using the UserPass Vault
  25413. authentication method
  25414. type: string
  25415. required:
  25416. - path
  25417. - username
  25418. type: object
  25419. type: object
  25420. caBundle:
  25421. description: |-
  25422. PEM encoded CA bundle used to validate Vault server certificate. Only used
  25423. if the Server URL is using HTTPS protocol. This parameter is ignored for
  25424. plain HTTP protocol connection. If not set the system root certificates
  25425. are used to validate the TLS connection.
  25426. format: byte
  25427. type: string
  25428. caProvider:
  25429. description: The provider for the CA bundle to use to validate Vault server certificate.
  25430. properties:
  25431. key:
  25432. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25433. maxLength: 253
  25434. minLength: 1
  25435. pattern: ^[-._a-zA-Z0-9]+$
  25436. type: string
  25437. name:
  25438. description: The name of the object located at the provider type.
  25439. maxLength: 253
  25440. minLength: 1
  25441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25442. type: string
  25443. namespace:
  25444. description: |-
  25445. The namespace the Provider type is in.
  25446. Can only be defined when used in a ClusterSecretStore.
  25447. maxLength: 63
  25448. minLength: 1
  25449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25450. type: string
  25451. type:
  25452. description: The type of provider to use such as "Secret", or "ConfigMap".
  25453. enum:
  25454. - Secret
  25455. - ConfigMap
  25456. type: string
  25457. required:
  25458. - name
  25459. - type
  25460. type: object
  25461. forwardInconsistent:
  25462. description: |-
  25463. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  25464. leader instead of simply retrying within a loop. This can increase performance if
  25465. the option is enabled serverside.
  25466. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  25467. type: boolean
  25468. headers:
  25469. additionalProperties:
  25470. type: string
  25471. description: Headers to be added in Vault request
  25472. type: object
  25473. namespace:
  25474. description: |-
  25475. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  25476. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  25477. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  25478. type: string
  25479. path:
  25480. description: |-
  25481. Path is the mount path of the Vault KV backend endpoint, e.g:
  25482. "secret". The v2 KV secret engine version specific "/data" path suffix
  25483. for fetching secrets from Vault is optional and will be appended
  25484. if not present in specified path.
  25485. type: string
  25486. readYourWrites:
  25487. description: |-
  25488. ReadYourWrites ensures isolated read-after-write semantics by
  25489. providing discovered cluster replication states in each request.
  25490. More information about eventual consistency in Vault can be found here
  25491. https://www.vaultproject.io/docs/enterprise/consistency
  25492. type: boolean
  25493. server:
  25494. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  25495. type: string
  25496. tls:
  25497. description: |-
  25498. The configuration used for client side related TLS communication, when the Vault server
  25499. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  25500. This parameter is ignored for plain HTTP protocol connection.
  25501. It's worth noting this configuration is different from the "TLS certificates auth method",
  25502. which is available under the `auth.cert` section.
  25503. properties:
  25504. certSecretRef:
  25505. description: |-
  25506. CertSecretRef is a certificate added to the transport layer
  25507. when communicating with the Vault server.
  25508. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  25509. properties:
  25510. key:
  25511. description: |-
  25512. A key in the referenced Secret.
  25513. Some instances of this field may be defaulted, in others it may be required.
  25514. maxLength: 253
  25515. minLength: 1
  25516. pattern: ^[-._a-zA-Z0-9]+$
  25517. type: string
  25518. name:
  25519. description: The name of the Secret resource being referred to.
  25520. maxLength: 253
  25521. minLength: 1
  25522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25523. type: string
  25524. namespace:
  25525. description: |-
  25526. The namespace of the Secret resource being referred to.
  25527. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25528. maxLength: 63
  25529. minLength: 1
  25530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25531. type: string
  25532. type: object
  25533. keySecretRef:
  25534. description: |-
  25535. KeySecretRef to a key in a Secret resource containing client private key
  25536. added to the transport layer when communicating with the Vault server.
  25537. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  25538. properties:
  25539. key:
  25540. description: |-
  25541. A key in the referenced Secret.
  25542. Some instances of this field may be defaulted, in others it may be required.
  25543. maxLength: 253
  25544. minLength: 1
  25545. pattern: ^[-._a-zA-Z0-9]+$
  25546. type: string
  25547. name:
  25548. description: The name of the Secret resource being referred to.
  25549. maxLength: 253
  25550. minLength: 1
  25551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25552. type: string
  25553. namespace:
  25554. description: |-
  25555. The namespace of the Secret resource being referred to.
  25556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25557. maxLength: 63
  25558. minLength: 1
  25559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25560. type: string
  25561. type: object
  25562. type: object
  25563. version:
  25564. default: v2
  25565. description: |-
  25566. Version is the Vault KV secret engine version. This can be either "v1" or
  25567. "v2". Version defaults to "v2".
  25568. enum:
  25569. - v1
  25570. - v2
  25571. type: string
  25572. required:
  25573. - server
  25574. type: object
  25575. webhook:
  25576. description: Webhook configures this store to sync secrets using a generic templated webhook
  25577. properties:
  25578. auth:
  25579. description: Auth specifies a authorization protocol. Only one protocol may be set.
  25580. maxProperties: 1
  25581. minProperties: 1
  25582. properties:
  25583. ntlm:
  25584. description: NTLMProtocol configures the store to use NTLM for auth
  25585. properties:
  25586. passwordSecret:
  25587. description: |-
  25588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25589. In some instances, `key` is a required field.
  25590. properties:
  25591. key:
  25592. description: |-
  25593. A key in the referenced Secret.
  25594. Some instances of this field may be defaulted, in others it may be required.
  25595. maxLength: 253
  25596. minLength: 1
  25597. pattern: ^[-._a-zA-Z0-9]+$
  25598. type: string
  25599. name:
  25600. description: The name of the Secret resource being referred to.
  25601. maxLength: 253
  25602. minLength: 1
  25603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25604. type: string
  25605. namespace:
  25606. description: |-
  25607. The namespace of the Secret resource being referred to.
  25608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25609. maxLength: 63
  25610. minLength: 1
  25611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25612. type: string
  25613. type: object
  25614. usernameSecret:
  25615. description: |-
  25616. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25617. In some instances, `key` is a required field.
  25618. properties:
  25619. key:
  25620. description: |-
  25621. A key in the referenced Secret.
  25622. Some instances of this field may be defaulted, in others it may be required.
  25623. maxLength: 253
  25624. minLength: 1
  25625. pattern: ^[-._a-zA-Z0-9]+$
  25626. type: string
  25627. name:
  25628. description: The name of the Secret resource being referred to.
  25629. maxLength: 253
  25630. minLength: 1
  25631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25632. type: string
  25633. namespace:
  25634. description: |-
  25635. The namespace of the Secret resource being referred to.
  25636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25637. maxLength: 63
  25638. minLength: 1
  25639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25640. type: string
  25641. type: object
  25642. required:
  25643. - passwordSecret
  25644. - usernameSecret
  25645. type: object
  25646. type: object
  25647. body:
  25648. description: Body
  25649. type: string
  25650. caBundle:
  25651. description: |-
  25652. PEM encoded CA bundle used to validate webhook server certificate. Only used
  25653. if the Server URL is using HTTPS protocol. This parameter is ignored for
  25654. plain HTTP protocol connection. If not set the system root certificates
  25655. are used to validate the TLS connection.
  25656. format: byte
  25657. type: string
  25658. caProvider:
  25659. description: The provider for the CA bundle to use to validate webhook server certificate.
  25660. properties:
  25661. key:
  25662. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25663. maxLength: 253
  25664. minLength: 1
  25665. pattern: ^[-._a-zA-Z0-9]+$
  25666. type: string
  25667. name:
  25668. description: The name of the object located at the provider type.
  25669. maxLength: 253
  25670. minLength: 1
  25671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25672. type: string
  25673. namespace:
  25674. description: The namespace the Provider type is in.
  25675. maxLength: 63
  25676. minLength: 1
  25677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25678. type: string
  25679. type:
  25680. description: The type of provider to use such as "Secret", or "ConfigMap".
  25681. enum:
  25682. - Secret
  25683. - ConfigMap
  25684. type: string
  25685. required:
  25686. - name
  25687. - type
  25688. type: object
  25689. headers:
  25690. additionalProperties:
  25691. type: string
  25692. description: Headers
  25693. type: object
  25694. method:
  25695. description: Webhook Method
  25696. type: string
  25697. result:
  25698. description: Result formatting
  25699. properties:
  25700. jsonPath:
  25701. description: Json path of return value
  25702. type: string
  25703. type: object
  25704. secrets:
  25705. description: |-
  25706. Secrets to fill in templates
  25707. These secrets will be passed to the templating function as key value pairs under the given name
  25708. items:
  25709. description: WebhookSecret defines a secret to be used in webhook templates.
  25710. properties:
  25711. name:
  25712. description: Name of this secret in templates
  25713. type: string
  25714. secretRef:
  25715. description: Secret ref to fill in credentials
  25716. properties:
  25717. key:
  25718. description: |-
  25719. A key in the referenced Secret.
  25720. Some instances of this field may be defaulted, in others it may be required.
  25721. maxLength: 253
  25722. minLength: 1
  25723. pattern: ^[-._a-zA-Z0-9]+$
  25724. type: string
  25725. name:
  25726. description: The name of the Secret resource being referred to.
  25727. maxLength: 253
  25728. minLength: 1
  25729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25730. type: string
  25731. namespace:
  25732. description: |-
  25733. The namespace of the Secret resource being referred to.
  25734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25735. maxLength: 63
  25736. minLength: 1
  25737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25738. type: string
  25739. type: object
  25740. required:
  25741. - name
  25742. - secretRef
  25743. type: object
  25744. type: array
  25745. timeout:
  25746. description: Timeout
  25747. type: string
  25748. url:
  25749. description: Webhook url to call
  25750. type: string
  25751. required:
  25752. - result
  25753. - url
  25754. type: object
  25755. yandexcertificatemanager:
  25756. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  25757. properties:
  25758. apiEndpoint:
  25759. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  25760. type: string
  25761. auth:
  25762. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  25763. properties:
  25764. authorizedKeySecretRef:
  25765. description: The authorized key used for authentication
  25766. properties:
  25767. key:
  25768. description: |-
  25769. A key in the referenced Secret.
  25770. Some instances of this field may be defaulted, in others it may be required.
  25771. maxLength: 253
  25772. minLength: 1
  25773. pattern: ^[-._a-zA-Z0-9]+$
  25774. type: string
  25775. name:
  25776. description: The name of the Secret resource being referred to.
  25777. maxLength: 253
  25778. minLength: 1
  25779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25780. type: string
  25781. namespace:
  25782. description: |-
  25783. The namespace of the Secret resource being referred to.
  25784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25785. maxLength: 63
  25786. minLength: 1
  25787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25788. type: string
  25789. type: object
  25790. type: object
  25791. caProvider:
  25792. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  25793. properties:
  25794. certSecretRef:
  25795. description: |-
  25796. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25797. In some instances, `key` is a required field.
  25798. properties:
  25799. key:
  25800. description: |-
  25801. A key in the referenced Secret.
  25802. Some instances of this field may be defaulted, in others it may be required.
  25803. maxLength: 253
  25804. minLength: 1
  25805. pattern: ^[-._a-zA-Z0-9]+$
  25806. type: string
  25807. name:
  25808. description: The name of the Secret resource being referred to.
  25809. maxLength: 253
  25810. minLength: 1
  25811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25812. type: string
  25813. namespace:
  25814. description: |-
  25815. The namespace of the Secret resource being referred to.
  25816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25817. maxLength: 63
  25818. minLength: 1
  25819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25820. type: string
  25821. type: object
  25822. type: object
  25823. required:
  25824. - auth
  25825. type: object
  25826. yandexlockbox:
  25827. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  25828. properties:
  25829. apiEndpoint:
  25830. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  25831. type: string
  25832. auth:
  25833. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  25834. properties:
  25835. authorizedKeySecretRef:
  25836. description: The authorized key used for authentication
  25837. properties:
  25838. key:
  25839. description: |-
  25840. A key in the referenced Secret.
  25841. Some instances of this field may be defaulted, in others it may be required.
  25842. maxLength: 253
  25843. minLength: 1
  25844. pattern: ^[-._a-zA-Z0-9]+$
  25845. type: string
  25846. name:
  25847. description: The name of the Secret resource being referred to.
  25848. maxLength: 253
  25849. minLength: 1
  25850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25851. type: string
  25852. namespace:
  25853. description: |-
  25854. The namespace of the Secret resource being referred to.
  25855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25856. maxLength: 63
  25857. minLength: 1
  25858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25859. type: string
  25860. type: object
  25861. type: object
  25862. caProvider:
  25863. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  25864. properties:
  25865. certSecretRef:
  25866. description: |-
  25867. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25868. In some instances, `key` is a required field.
  25869. properties:
  25870. key:
  25871. description: |-
  25872. A key in the referenced Secret.
  25873. Some instances of this field may be defaulted, in others it may be required.
  25874. maxLength: 253
  25875. minLength: 1
  25876. pattern: ^[-._a-zA-Z0-9]+$
  25877. type: string
  25878. name:
  25879. description: The name of the Secret resource being referred to.
  25880. maxLength: 253
  25881. minLength: 1
  25882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25883. type: string
  25884. namespace:
  25885. description: |-
  25886. The namespace of the Secret resource being referred to.
  25887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25888. maxLength: 63
  25889. minLength: 1
  25890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25891. type: string
  25892. type: object
  25893. type: object
  25894. required:
  25895. - auth
  25896. type: object
  25897. type: object
  25898. refreshInterval:
  25899. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  25900. type: integer
  25901. retrySettings:
  25902. description: Used to configure HTTP retries on failures.
  25903. properties:
  25904. maxRetries:
  25905. description: MaxRetries is the maximum number of retry attempts.
  25906. format: int32
  25907. type: integer
  25908. retryInterval:
  25909. description: RetryInterval is the interval between retry attempts.
  25910. type: string
  25911. type: object
  25912. required:
  25913. - provider
  25914. type: object
  25915. status:
  25916. description: SecretStoreStatus defines the observed state of the SecretStore.
  25917. properties:
  25918. capabilities:
  25919. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  25920. type: string
  25921. conditions:
  25922. items:
  25923. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  25924. properties:
  25925. lastTransitionTime:
  25926. format: date-time
  25927. type: string
  25928. message:
  25929. type: string
  25930. reason:
  25931. type: string
  25932. status:
  25933. type: string
  25934. type:
  25935. description: SecretStoreConditionType represents the condition type of the SecretStore.
  25936. type: string
  25937. required:
  25938. - status
  25939. - type
  25940. type: object
  25941. type: array
  25942. type: object
  25943. type: object
  25944. served: false
  25945. storage: false
  25946. subresources:
  25947. status: {}
  25948. ---
  25949. apiVersion: apiextensions.k8s.io/v1
  25950. kind: CustomResourceDefinition
  25951. metadata:
  25952. annotations:
  25953. controller-gen.kubebuilder.io/version: v0.19.0
  25954. labels:
  25955. external-secrets.io/component: controller
  25956. name: acraccesstokens.generators.external-secrets.io
  25957. spec:
  25958. group: generators.external-secrets.io
  25959. names:
  25960. categories:
  25961. - external-secrets
  25962. - external-secrets-generators
  25963. kind: ACRAccessToken
  25964. listKind: ACRAccessTokenList
  25965. plural: acraccesstokens
  25966. singular: acraccesstoken
  25967. scope: Namespaced
  25968. versions:
  25969. - name: v1alpha1
  25970. schema:
  25971. openAPIV3Schema:
  25972. description: |-
  25973. ACRAccessToken returns an Azure Container Registry token
  25974. that can be used for pushing/pulling images.
  25975. Note: by default it will return an ACR Refresh Token with full access
  25976. (depending on the identity).
  25977. This can be scoped down to the repository level using .spec.scope.
  25978. In case scope is defined it will return an ACR Access Token.
  25979. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  25980. properties:
  25981. apiVersion:
  25982. description: |-
  25983. APIVersion defines the versioned schema of this representation of an object.
  25984. Servers should convert recognized schemas to the latest internal value, and
  25985. may reject unrecognized values.
  25986. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  25987. type: string
  25988. kind:
  25989. description: |-
  25990. Kind is a string value representing the REST resource this object represents.
  25991. Servers may infer this from the endpoint the client submits requests to.
  25992. Cannot be updated.
  25993. In CamelCase.
  25994. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  25995. type: string
  25996. metadata:
  25997. type: object
  25998. spec:
  25999. description: |-
  26000. ACRAccessTokenSpec defines how to generate the access token
  26001. e.g. how to authenticate and which registry to use.
  26002. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26003. properties:
  26004. auth:
  26005. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26006. properties:
  26007. managedIdentity:
  26008. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26009. properties:
  26010. identityId:
  26011. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26012. type: string
  26013. type: object
  26014. servicePrincipal:
  26015. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26016. properties:
  26017. secretRef:
  26018. description: |-
  26019. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26020. It uses static credentials stored in a Kind=Secret.
  26021. properties:
  26022. clientId:
  26023. description: The Azure clientId of the service principle used for authentication.
  26024. properties:
  26025. key:
  26026. description: |-
  26027. A key in the referenced Secret.
  26028. Some instances of this field may be defaulted, in others it may be required.
  26029. maxLength: 253
  26030. minLength: 1
  26031. pattern: ^[-._a-zA-Z0-9]+$
  26032. type: string
  26033. name:
  26034. description: The name of the Secret resource being referred to.
  26035. maxLength: 253
  26036. minLength: 1
  26037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26038. type: string
  26039. namespace:
  26040. description: |-
  26041. The namespace of the Secret resource being referred to.
  26042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26043. maxLength: 63
  26044. minLength: 1
  26045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26046. type: string
  26047. type: object
  26048. clientSecret:
  26049. description: The Azure ClientSecret of the service principle used for authentication.
  26050. properties:
  26051. key:
  26052. description: |-
  26053. A key in the referenced Secret.
  26054. Some instances of this field may be defaulted, in others it may be required.
  26055. maxLength: 253
  26056. minLength: 1
  26057. pattern: ^[-._a-zA-Z0-9]+$
  26058. type: string
  26059. name:
  26060. description: The name of the Secret resource being referred to.
  26061. maxLength: 253
  26062. minLength: 1
  26063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26064. type: string
  26065. namespace:
  26066. description: |-
  26067. The namespace of the Secret resource being referred to.
  26068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26069. maxLength: 63
  26070. minLength: 1
  26071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26072. type: string
  26073. type: object
  26074. type: object
  26075. required:
  26076. - secretRef
  26077. type: object
  26078. workloadIdentity:
  26079. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26080. properties:
  26081. serviceAccountRef:
  26082. description: |-
  26083. ServiceAccountRef specified the service account
  26084. that should be used when authenticating with WorkloadIdentity.
  26085. properties:
  26086. audiences:
  26087. description: |-
  26088. Audience specifies the `aud` claim for the service account token
  26089. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26090. then this audiences will be appended to the list
  26091. items:
  26092. type: string
  26093. type: array
  26094. name:
  26095. description: The name of the ServiceAccount resource being referred to.
  26096. maxLength: 253
  26097. minLength: 1
  26098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26099. type: string
  26100. namespace:
  26101. description: |-
  26102. Namespace of the resource being referred to.
  26103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26104. maxLength: 63
  26105. minLength: 1
  26106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26107. type: string
  26108. required:
  26109. - name
  26110. type: object
  26111. type: object
  26112. type: object
  26113. environmentType:
  26114. default: PublicCloud
  26115. description: |-
  26116. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26117. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26118. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26119. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26120. enum:
  26121. - PublicCloud
  26122. - USGovernmentCloud
  26123. - ChinaCloud
  26124. - GermanCloud
  26125. - AzureStackCloud
  26126. type: string
  26127. registry:
  26128. description: |-
  26129. the domain name of the ACR registry
  26130. e.g. foobarexample.azurecr.io
  26131. type: string
  26132. scope:
  26133. description: |-
  26134. Define the scope for the access token, e.g. pull/push access for a repository.
  26135. if not provided it will return a refresh token that has full scope.
  26136. Note: you need to pin it down to the repository level, there is no wildcard available.
  26137. examples:
  26138. repository:my-repository:pull,push
  26139. repository:my-repository:pull
  26140. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26141. type: string
  26142. tenantId:
  26143. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26144. type: string
  26145. required:
  26146. - auth
  26147. - registry
  26148. type: object
  26149. type: object
  26150. served: true
  26151. storage: true
  26152. subresources:
  26153. status: {}
  26154. ---
  26155. apiVersion: apiextensions.k8s.io/v1
  26156. kind: CustomResourceDefinition
  26157. metadata:
  26158. annotations:
  26159. controller-gen.kubebuilder.io/version: v0.19.0
  26160. labels:
  26161. external-secrets.io/component: controller
  26162. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26163. spec:
  26164. group: generators.external-secrets.io
  26165. names:
  26166. categories:
  26167. - external-secrets
  26168. - external-secrets-generators
  26169. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26170. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26171. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26172. singular: beyondtrustworkloadcredentialsdynamicsecret
  26173. scope: Namespaced
  26174. versions:
  26175. - name: v1alpha1
  26176. schema:
  26177. openAPIV3Schema:
  26178. description: |-
  26179. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26180. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26181. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26182. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26183. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26184. properties:
  26185. apiVersion:
  26186. description: |-
  26187. APIVersion defines the versioned schema of this representation of an object.
  26188. Servers should convert recognized schemas to the latest internal value, and
  26189. may reject unrecognized values.
  26190. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26191. type: string
  26192. kind:
  26193. description: |-
  26194. Kind is a string value representing the REST resource this object represents.
  26195. Servers may infer this from the endpoint the client submits requests to.
  26196. Cannot be updated.
  26197. In CamelCase.
  26198. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26199. type: string
  26200. metadata:
  26201. type: object
  26202. spec:
  26203. description: |-
  26204. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26205. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26206. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26207. properties:
  26208. controller:
  26209. description: |-
  26210. Controller selects the controller that should handle this generator.
  26211. Leave empty to use the default controller.
  26212. type: string
  26213. provider:
  26214. description: |-
  26215. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26216. server connection details, and the folder path to the dynamic secret definition.
  26217. The folderPath should point to a dynamic secret definition that has been created in
  26218. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26219. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26220. properties:
  26221. auth:
  26222. description: |-
  26223. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26224. Currently supports API key authentication via Kubernetes secret reference.
  26225. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26226. properties:
  26227. apikey:
  26228. description: |-
  26229. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26230. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26231. properties:
  26232. token:
  26233. description: |-
  26234. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26235. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26236. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26237. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26238. properties:
  26239. key:
  26240. description: |-
  26241. A key in the referenced Secret.
  26242. Some instances of this field may be defaulted, in others it may be required.
  26243. maxLength: 253
  26244. minLength: 1
  26245. pattern: ^[-._a-zA-Z0-9]+$
  26246. type: string
  26247. name:
  26248. description: The name of the Secret resource being referred to.
  26249. maxLength: 253
  26250. minLength: 1
  26251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26252. type: string
  26253. namespace:
  26254. description: |-
  26255. The namespace of the Secret resource being referred to.
  26256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26257. maxLength: 63
  26258. minLength: 1
  26259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26260. type: string
  26261. type: object
  26262. required:
  26263. - token
  26264. type: object
  26265. required:
  26266. - apikey
  26267. type: object
  26268. caBundle:
  26269. description: |-
  26270. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26271. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26272. If not set, the system's trusted root certificates are used.
  26273. format: byte
  26274. type: string
  26275. caProvider:
  26276. description: |-
  26277. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26278. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26279. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26280. properties:
  26281. key:
  26282. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26283. maxLength: 253
  26284. minLength: 1
  26285. pattern: ^[-._a-zA-Z0-9]+$
  26286. type: string
  26287. name:
  26288. description: The name of the object located at the provider type.
  26289. maxLength: 253
  26290. minLength: 1
  26291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26292. type: string
  26293. namespace:
  26294. description: |-
  26295. The namespace the Provider type is in.
  26296. Can only be defined when used in a ClusterSecretStore.
  26297. maxLength: 63
  26298. minLength: 1
  26299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26300. type: string
  26301. type:
  26302. description: The type of provider to use such as "Secret", or "ConfigMap".
  26303. enum:
  26304. - Secret
  26305. - ConfigMap
  26306. type: string
  26307. required:
  26308. - name
  26309. - type
  26310. type: object
  26311. folderPath:
  26312. description: |-
  26313. FolderPath specifies the default folder path for secret retrieval.
  26314. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  26315. Example: "production/database" or "dev/api-keys"
  26316. Leave empty to retrieve secrets from the root folder.
  26317. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  26318. type: string
  26319. server:
  26320. description: |-
  26321. Server configures the BeyondTrust Workload Credentials server connection details.
  26322. Includes the API URL and Site ID for your BeyondTrust instance.
  26323. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26324. properties:
  26325. apiUrl:
  26326. description: |-
  26327. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  26328. This should be the full URL to your BeyondTrust instance.
  26329. Example: https://api.beyondtrust.io/siie
  26330. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  26331. type: string
  26332. siteId:
  26333. description: |-
  26334. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  26335. This identifier is unique to your BeyondTrust Workload Credentials instance.
  26336. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  26337. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  26338. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26339. type: string
  26340. required:
  26341. - apiUrl
  26342. - siteId
  26343. type: object
  26344. required:
  26345. - auth
  26346. - server
  26347. type: object
  26348. retrySettings:
  26349. description: |-
  26350. RetrySettings configures exponential backoff for failed API requests.
  26351. If not specified, uses the default retry settings.
  26352. properties:
  26353. maxRetries:
  26354. format: int32
  26355. type: integer
  26356. retryInterval:
  26357. type: string
  26358. type: object
  26359. required:
  26360. - provider
  26361. type: object
  26362. type: object
  26363. served: true
  26364. storage: true
  26365. subresources:
  26366. status: {}
  26367. ---
  26368. apiVersion: apiextensions.k8s.io/v1
  26369. kind: CustomResourceDefinition
  26370. metadata:
  26371. annotations:
  26372. controller-gen.kubebuilder.io/version: v0.19.0
  26373. labels:
  26374. external-secrets.io/component: controller
  26375. name: cloudsmithaccesstokens.generators.external-secrets.io
  26376. spec:
  26377. group: generators.external-secrets.io
  26378. names:
  26379. categories:
  26380. - external-secrets
  26381. - external-secrets-generators
  26382. kind: CloudsmithAccessToken
  26383. listKind: CloudsmithAccessTokenList
  26384. plural: cloudsmithaccesstokens
  26385. singular: cloudsmithaccesstoken
  26386. scope: Namespaced
  26387. versions:
  26388. - name: v1alpha1
  26389. schema:
  26390. openAPIV3Schema:
  26391. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  26392. properties:
  26393. apiVersion:
  26394. description: |-
  26395. APIVersion defines the versioned schema of this representation of an object.
  26396. Servers should convert recognized schemas to the latest internal value, and
  26397. may reject unrecognized values.
  26398. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26399. type: string
  26400. kind:
  26401. description: |-
  26402. Kind is a string value representing the REST resource this object represents.
  26403. Servers may infer this from the endpoint the client submits requests to.
  26404. Cannot be updated.
  26405. In CamelCase.
  26406. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26407. type: string
  26408. metadata:
  26409. type: object
  26410. spec:
  26411. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  26412. properties:
  26413. apiUrl:
  26414. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  26415. type: string
  26416. orgSlug:
  26417. description: OrgSlug is the organization slug in Cloudsmith
  26418. type: string
  26419. serviceAccountRef:
  26420. description: Name of the service account you are federating with
  26421. properties:
  26422. audiences:
  26423. description: |-
  26424. Audience specifies the `aud` claim for the service account token
  26425. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26426. then this audiences will be appended to the list
  26427. items:
  26428. type: string
  26429. type: array
  26430. name:
  26431. description: The name of the ServiceAccount resource being referred to.
  26432. maxLength: 253
  26433. minLength: 1
  26434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26435. type: string
  26436. namespace:
  26437. description: |-
  26438. Namespace of the resource being referred to.
  26439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26440. maxLength: 63
  26441. minLength: 1
  26442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26443. type: string
  26444. required:
  26445. - name
  26446. type: object
  26447. serviceSlug:
  26448. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  26449. type: string
  26450. required:
  26451. - orgSlug
  26452. - serviceAccountRef
  26453. - serviceSlug
  26454. type: object
  26455. type: object
  26456. served: true
  26457. storage: true
  26458. subresources:
  26459. status: {}
  26460. ---
  26461. apiVersion: apiextensions.k8s.io/v1
  26462. kind: CustomResourceDefinition
  26463. metadata:
  26464. annotations:
  26465. controller-gen.kubebuilder.io/version: v0.19.0
  26466. labels:
  26467. external-secrets.io/component: controller
  26468. name: clustergenerators.generators.external-secrets.io
  26469. spec:
  26470. group: generators.external-secrets.io
  26471. names:
  26472. categories:
  26473. - external-secrets
  26474. - external-secrets-generators
  26475. kind: ClusterGenerator
  26476. listKind: ClusterGeneratorList
  26477. plural: clustergenerators
  26478. singular: clustergenerator
  26479. scope: Cluster
  26480. versions:
  26481. - name: v1alpha1
  26482. schema:
  26483. openAPIV3Schema:
  26484. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  26485. properties:
  26486. apiVersion:
  26487. description: |-
  26488. APIVersion defines the versioned schema of this representation of an object.
  26489. Servers should convert recognized schemas to the latest internal value, and
  26490. may reject unrecognized values.
  26491. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26492. type: string
  26493. kind:
  26494. description: |-
  26495. Kind is a string value representing the REST resource this object represents.
  26496. Servers may infer this from the endpoint the client submits requests to.
  26497. Cannot be updated.
  26498. In CamelCase.
  26499. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26500. type: string
  26501. metadata:
  26502. type: object
  26503. spec:
  26504. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  26505. properties:
  26506. generator:
  26507. description: Generator the spec for this generator, must match the kind.
  26508. maxProperties: 1
  26509. minProperties: 1
  26510. properties:
  26511. acrAccessTokenSpec:
  26512. description: |-
  26513. ACRAccessTokenSpec defines how to generate the access token
  26514. e.g. how to authenticate and which registry to use.
  26515. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26516. properties:
  26517. auth:
  26518. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26519. properties:
  26520. managedIdentity:
  26521. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26522. properties:
  26523. identityId:
  26524. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26525. type: string
  26526. type: object
  26527. servicePrincipal:
  26528. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26529. properties:
  26530. secretRef:
  26531. description: |-
  26532. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26533. It uses static credentials stored in a Kind=Secret.
  26534. properties:
  26535. clientId:
  26536. description: The Azure clientId of the service principle used for authentication.
  26537. properties:
  26538. key:
  26539. description: |-
  26540. A key in the referenced Secret.
  26541. Some instances of this field may be defaulted, in others it may be required.
  26542. maxLength: 253
  26543. minLength: 1
  26544. pattern: ^[-._a-zA-Z0-9]+$
  26545. type: string
  26546. name:
  26547. description: The name of the Secret resource being referred to.
  26548. maxLength: 253
  26549. minLength: 1
  26550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26551. type: string
  26552. namespace:
  26553. description: |-
  26554. The namespace of the Secret resource being referred to.
  26555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26556. maxLength: 63
  26557. minLength: 1
  26558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26559. type: string
  26560. type: object
  26561. clientSecret:
  26562. description: The Azure ClientSecret of the service principle used for authentication.
  26563. properties:
  26564. key:
  26565. description: |-
  26566. A key in the referenced Secret.
  26567. Some instances of this field may be defaulted, in others it may be required.
  26568. maxLength: 253
  26569. minLength: 1
  26570. pattern: ^[-._a-zA-Z0-9]+$
  26571. type: string
  26572. name:
  26573. description: The name of the Secret resource being referred to.
  26574. maxLength: 253
  26575. minLength: 1
  26576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26577. type: string
  26578. namespace:
  26579. description: |-
  26580. The namespace of the Secret resource being referred to.
  26581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26582. maxLength: 63
  26583. minLength: 1
  26584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26585. type: string
  26586. type: object
  26587. type: object
  26588. required:
  26589. - secretRef
  26590. type: object
  26591. workloadIdentity:
  26592. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26593. properties:
  26594. serviceAccountRef:
  26595. description: |-
  26596. ServiceAccountRef specified the service account
  26597. that should be used when authenticating with WorkloadIdentity.
  26598. properties:
  26599. audiences:
  26600. description: |-
  26601. Audience specifies the `aud` claim for the service account token
  26602. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26603. then this audiences will be appended to the list
  26604. items:
  26605. type: string
  26606. type: array
  26607. name:
  26608. description: The name of the ServiceAccount resource being referred to.
  26609. maxLength: 253
  26610. minLength: 1
  26611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26612. type: string
  26613. namespace:
  26614. description: |-
  26615. Namespace of the resource being referred to.
  26616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26617. maxLength: 63
  26618. minLength: 1
  26619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26620. type: string
  26621. required:
  26622. - name
  26623. type: object
  26624. type: object
  26625. type: object
  26626. environmentType:
  26627. default: PublicCloud
  26628. description: |-
  26629. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26630. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26631. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26632. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26633. enum:
  26634. - PublicCloud
  26635. - USGovernmentCloud
  26636. - ChinaCloud
  26637. - GermanCloud
  26638. - AzureStackCloud
  26639. type: string
  26640. registry:
  26641. description: |-
  26642. the domain name of the ACR registry
  26643. e.g. foobarexample.azurecr.io
  26644. type: string
  26645. scope:
  26646. description: |-
  26647. Define the scope for the access token, e.g. pull/push access for a repository.
  26648. if not provided it will return a refresh token that has full scope.
  26649. Note: you need to pin it down to the repository level, there is no wildcard available.
  26650. examples:
  26651. repository:my-repository:pull,push
  26652. repository:my-repository:pull
  26653. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26654. type: string
  26655. tenantId:
  26656. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26657. type: string
  26658. required:
  26659. - auth
  26660. - registry
  26661. type: object
  26662. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  26663. description: |-
  26664. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26665. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26666. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26667. properties:
  26668. controller:
  26669. description: |-
  26670. Controller selects the controller that should handle this generator.
  26671. Leave empty to use the default controller.
  26672. type: string
  26673. provider:
  26674. description: |-
  26675. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26676. server connection details, and the folder path to the dynamic secret definition.
  26677. The folderPath should point to a dynamic secret definition that has been created in
  26678. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26679. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26680. properties:
  26681. auth:
  26682. description: |-
  26683. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26684. Currently supports API key authentication via Kubernetes secret reference.
  26685. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26686. properties:
  26687. apikey:
  26688. description: |-
  26689. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26690. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26691. properties:
  26692. token:
  26693. description: |-
  26694. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26695. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26696. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26697. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26698. properties:
  26699. key:
  26700. description: |-
  26701. A key in the referenced Secret.
  26702. Some instances of this field may be defaulted, in others it may be required.
  26703. maxLength: 253
  26704. minLength: 1
  26705. pattern: ^[-._a-zA-Z0-9]+$
  26706. type: string
  26707. name:
  26708. description: The name of the Secret resource being referred to.
  26709. maxLength: 253
  26710. minLength: 1
  26711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26712. type: string
  26713. namespace:
  26714. description: |-
  26715. The namespace of the Secret resource being referred to.
  26716. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26717. maxLength: 63
  26718. minLength: 1
  26719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26720. type: string
  26721. type: object
  26722. required:
  26723. - token
  26724. type: object
  26725. required:
  26726. - apikey
  26727. type: object
  26728. caBundle:
  26729. description: |-
  26730. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26731. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26732. If not set, the system's trusted root certificates are used.
  26733. format: byte
  26734. type: string
  26735. caProvider:
  26736. description: |-
  26737. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26738. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26739. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26740. properties:
  26741. key:
  26742. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26743. maxLength: 253
  26744. minLength: 1
  26745. pattern: ^[-._a-zA-Z0-9]+$
  26746. type: string
  26747. name:
  26748. description: The name of the object located at the provider type.
  26749. maxLength: 253
  26750. minLength: 1
  26751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26752. type: string
  26753. namespace:
  26754. description: |-
  26755. The namespace the Provider type is in.
  26756. Can only be defined when used in a ClusterSecretStore.
  26757. maxLength: 63
  26758. minLength: 1
  26759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26760. type: string
  26761. type:
  26762. description: The type of provider to use such as "Secret", or "ConfigMap".
  26763. enum:
  26764. - Secret
  26765. - ConfigMap
  26766. type: string
  26767. required:
  26768. - name
  26769. - type
  26770. type: object
  26771. folderPath:
  26772. description: |-
  26773. FolderPath specifies the default folder path for secret retrieval.
  26774. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  26775. Example: "production/database" or "dev/api-keys"
  26776. Leave empty to retrieve secrets from the root folder.
  26777. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  26778. type: string
  26779. server:
  26780. description: |-
  26781. Server configures the BeyondTrust Workload Credentials server connection details.
  26782. Includes the API URL and Site ID for your BeyondTrust instance.
  26783. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26784. properties:
  26785. apiUrl:
  26786. description: |-
  26787. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  26788. This should be the full URL to your BeyondTrust instance.
  26789. Example: https://api.beyondtrust.io/siie
  26790. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  26791. type: string
  26792. siteId:
  26793. description: |-
  26794. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  26795. This identifier is unique to your BeyondTrust Workload Credentials instance.
  26796. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  26797. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  26798. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26799. type: string
  26800. required:
  26801. - apiUrl
  26802. - siteId
  26803. type: object
  26804. required:
  26805. - auth
  26806. - server
  26807. type: object
  26808. retrySettings:
  26809. description: |-
  26810. RetrySettings configures exponential backoff for failed API requests.
  26811. If not specified, uses the default retry settings.
  26812. properties:
  26813. maxRetries:
  26814. format: int32
  26815. type: integer
  26816. retryInterval:
  26817. type: string
  26818. type: object
  26819. required:
  26820. - provider
  26821. type: object
  26822. cloudsmithAccessTokenSpec:
  26823. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  26824. properties:
  26825. apiUrl:
  26826. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  26827. type: string
  26828. orgSlug:
  26829. description: OrgSlug is the organization slug in Cloudsmith
  26830. type: string
  26831. serviceAccountRef:
  26832. description: Name of the service account you are federating with
  26833. properties:
  26834. audiences:
  26835. description: |-
  26836. Audience specifies the `aud` claim for the service account token
  26837. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26838. then this audiences will be appended to the list
  26839. items:
  26840. type: string
  26841. type: array
  26842. name:
  26843. description: The name of the ServiceAccount resource being referred to.
  26844. maxLength: 253
  26845. minLength: 1
  26846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26847. type: string
  26848. namespace:
  26849. description: |-
  26850. Namespace of the resource being referred to.
  26851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26852. maxLength: 63
  26853. minLength: 1
  26854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26855. type: string
  26856. required:
  26857. - name
  26858. type: object
  26859. serviceSlug:
  26860. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  26861. type: string
  26862. required:
  26863. - orgSlug
  26864. - serviceAccountRef
  26865. - serviceSlug
  26866. type: object
  26867. ecrAuthorizationTokenSpec:
  26868. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  26869. properties:
  26870. auth:
  26871. description: Auth defines how to authenticate with AWS
  26872. properties:
  26873. jwt:
  26874. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  26875. properties:
  26876. serviceAccountRef:
  26877. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26878. properties:
  26879. audiences:
  26880. description: |-
  26881. Audience specifies the `aud` claim for the service account token
  26882. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26883. then this audiences will be appended to the list
  26884. items:
  26885. type: string
  26886. type: array
  26887. name:
  26888. description: The name of the ServiceAccount resource being referred to.
  26889. maxLength: 253
  26890. minLength: 1
  26891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26892. type: string
  26893. namespace:
  26894. description: |-
  26895. Namespace of the resource being referred to.
  26896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26897. maxLength: 63
  26898. minLength: 1
  26899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26900. type: string
  26901. required:
  26902. - name
  26903. type: object
  26904. type: object
  26905. secretRef:
  26906. description: |-
  26907. AWSAuthSecretRef holds secret references for AWS credentials
  26908. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  26909. properties:
  26910. accessKeyIDSecretRef:
  26911. description: The AccessKeyID is used for authentication
  26912. properties:
  26913. key:
  26914. description: |-
  26915. A key in the referenced Secret.
  26916. Some instances of this field may be defaulted, in others it may be required.
  26917. maxLength: 253
  26918. minLength: 1
  26919. pattern: ^[-._a-zA-Z0-9]+$
  26920. type: string
  26921. name:
  26922. description: The name of the Secret resource being referred to.
  26923. maxLength: 253
  26924. minLength: 1
  26925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26926. type: string
  26927. namespace:
  26928. description: |-
  26929. The namespace of the Secret resource being referred to.
  26930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26931. maxLength: 63
  26932. minLength: 1
  26933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26934. type: string
  26935. type: object
  26936. secretAccessKeySecretRef:
  26937. description: The SecretAccessKey is used for authentication
  26938. properties:
  26939. key:
  26940. description: |-
  26941. A key in the referenced Secret.
  26942. Some instances of this field may be defaulted, in others it may be required.
  26943. maxLength: 253
  26944. minLength: 1
  26945. pattern: ^[-._a-zA-Z0-9]+$
  26946. type: string
  26947. name:
  26948. description: The name of the Secret resource being referred to.
  26949. maxLength: 253
  26950. minLength: 1
  26951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26952. type: string
  26953. namespace:
  26954. description: |-
  26955. The namespace of the Secret resource being referred to.
  26956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26957. maxLength: 63
  26958. minLength: 1
  26959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26960. type: string
  26961. type: object
  26962. sessionTokenSecretRef:
  26963. description: |-
  26964. The SessionToken used for authentication
  26965. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26966. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26967. properties:
  26968. key:
  26969. description: |-
  26970. A key in the referenced Secret.
  26971. Some instances of this field may be defaulted, in others it may be required.
  26972. maxLength: 253
  26973. minLength: 1
  26974. pattern: ^[-._a-zA-Z0-9]+$
  26975. type: string
  26976. name:
  26977. description: The name of the Secret resource being referred to.
  26978. maxLength: 253
  26979. minLength: 1
  26980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26981. type: string
  26982. namespace:
  26983. description: |-
  26984. The namespace of the Secret resource being referred to.
  26985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26986. maxLength: 63
  26987. minLength: 1
  26988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26989. type: string
  26990. type: object
  26991. type: object
  26992. type: object
  26993. region:
  26994. description: Region specifies the region to operate in.
  26995. type: string
  26996. role:
  26997. description: |-
  26998. You can assume a role before making calls to the
  26999. desired AWS service.
  27000. type: string
  27001. scope:
  27002. description: |-
  27003. Scope specifies the ECR service scope.
  27004. Valid options are private and public.
  27005. type: string
  27006. required:
  27007. - region
  27008. type: object
  27009. fakeSpec:
  27010. description: FakeSpec contains the static data.
  27011. properties:
  27012. controller:
  27013. description: |-
  27014. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27015. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27016. type: string
  27017. data:
  27018. additionalProperties:
  27019. type: string
  27020. description: |-
  27021. Data defines the static data returned
  27022. by this generator.
  27023. type: object
  27024. type: object
  27025. gcrAccessTokenSpec:
  27026. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27027. properties:
  27028. auth:
  27029. description: Auth defines the means for authenticating with GCP
  27030. properties:
  27031. secretRef:
  27032. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27033. properties:
  27034. secretAccessKeySecretRef:
  27035. description: The SecretAccessKey is used for authentication
  27036. properties:
  27037. key:
  27038. description: |-
  27039. A key in the referenced Secret.
  27040. Some instances of this field may be defaulted, in others it may be required.
  27041. maxLength: 253
  27042. minLength: 1
  27043. pattern: ^[-._a-zA-Z0-9]+$
  27044. type: string
  27045. name:
  27046. description: The name of the Secret resource being referred to.
  27047. maxLength: 253
  27048. minLength: 1
  27049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27050. type: string
  27051. namespace:
  27052. description: |-
  27053. The namespace of the Secret resource being referred to.
  27054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27055. maxLength: 63
  27056. minLength: 1
  27057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27058. type: string
  27059. type: object
  27060. type: object
  27061. workloadIdentity:
  27062. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27063. properties:
  27064. clusterLocation:
  27065. type: string
  27066. clusterName:
  27067. type: string
  27068. clusterProjectID:
  27069. type: string
  27070. serviceAccountRef:
  27071. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27072. properties:
  27073. audiences:
  27074. description: |-
  27075. Audience specifies the `aud` claim for the service account token
  27076. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27077. then this audiences will be appended to the list
  27078. items:
  27079. type: string
  27080. type: array
  27081. name:
  27082. description: The name of the ServiceAccount resource being referred to.
  27083. maxLength: 253
  27084. minLength: 1
  27085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27086. type: string
  27087. namespace:
  27088. description: |-
  27089. Namespace of the resource being referred to.
  27090. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27091. maxLength: 63
  27092. minLength: 1
  27093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27094. type: string
  27095. required:
  27096. - name
  27097. type: object
  27098. required:
  27099. - clusterLocation
  27100. - clusterName
  27101. - serviceAccountRef
  27102. type: object
  27103. workloadIdentityFederation:
  27104. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27105. properties:
  27106. audience:
  27107. description: |-
  27108. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27109. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27110. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27111. type: string
  27112. awsSecurityCredentials:
  27113. description: |-
  27114. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27115. when using the AWS metadata server is not an option.
  27116. properties:
  27117. awsCredentialsSecretRef:
  27118. description: |-
  27119. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27120. Secret should be created with below names for keys
  27121. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27122. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27123. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27124. properties:
  27125. name:
  27126. description: name of the secret.
  27127. maxLength: 253
  27128. minLength: 1
  27129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27130. type: string
  27131. namespace:
  27132. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27133. maxLength: 63
  27134. minLength: 1
  27135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27136. type: string
  27137. required:
  27138. - name
  27139. type: object
  27140. region:
  27141. description: region is for configuring the AWS region to be used.
  27142. example: ap-south-1
  27143. maxLength: 50
  27144. minLength: 1
  27145. pattern: ^[a-z0-9-]+$
  27146. type: string
  27147. required:
  27148. - awsCredentialsSecretRef
  27149. - region
  27150. type: object
  27151. credConfig:
  27152. description: |-
  27153. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27154. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27155. serviceAccountRef must be used by providing operators service account details.
  27156. properties:
  27157. key:
  27158. description: key name holding the external account credential config.
  27159. maxLength: 253
  27160. minLength: 1
  27161. pattern: ^[-._a-zA-Z0-9]+$
  27162. type: string
  27163. name:
  27164. description: name of the configmap.
  27165. maxLength: 253
  27166. minLength: 1
  27167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27168. type: string
  27169. namespace:
  27170. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27171. maxLength: 63
  27172. minLength: 1
  27173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27174. type: string
  27175. required:
  27176. - key
  27177. - name
  27178. type: object
  27179. externalTokenEndpoint:
  27180. description: |-
  27181. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27182. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27183. URL is having the expected value.
  27184. type: string
  27185. gcpServiceAccountEmail:
  27186. description: |-
  27187. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27188. after Workload Identity Federation. Use this to grant access through the service account's
  27189. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27190. service_account_impersonation_url in the external account JSON from credConfig;
  27191. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27192. on that ServiceAccount.
  27193. example: my-gsa@my-project.iam.gserviceaccount.com
  27194. minLength: 1
  27195. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27196. type: string
  27197. serviceAccountRef:
  27198. description: |-
  27199. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27200. when Kubernetes is configured as provider in workload identity pool.
  27201. properties:
  27202. audiences:
  27203. description: |-
  27204. Audience specifies the `aud` claim for the service account token
  27205. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27206. then this audiences will be appended to the list
  27207. items:
  27208. type: string
  27209. type: array
  27210. name:
  27211. description: The name of the ServiceAccount resource being referred to.
  27212. maxLength: 253
  27213. minLength: 1
  27214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27215. type: string
  27216. namespace:
  27217. description: |-
  27218. Namespace of the resource being referred to.
  27219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27220. maxLength: 63
  27221. minLength: 1
  27222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27223. type: string
  27224. required:
  27225. - name
  27226. type: object
  27227. type: object
  27228. type: object
  27229. projectID:
  27230. description: ProjectID defines which project to use to authenticate with
  27231. type: string
  27232. required:
  27233. - auth
  27234. - projectID
  27235. type: object
  27236. githubAccessTokenSpec:
  27237. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27238. properties:
  27239. appID:
  27240. type: string
  27241. auth:
  27242. description: Auth configures how ESO authenticates with a Github instance.
  27243. properties:
  27244. privateKey:
  27245. description: GithubSecretRef references a secret containing GitHub credentials.
  27246. properties:
  27247. secretRef:
  27248. description: |-
  27249. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27250. In some instances, `key` is a required field.
  27251. properties:
  27252. key:
  27253. description: |-
  27254. A key in the referenced Secret.
  27255. Some instances of this field may be defaulted, in others it may be required.
  27256. maxLength: 253
  27257. minLength: 1
  27258. pattern: ^[-._a-zA-Z0-9]+$
  27259. type: string
  27260. name:
  27261. description: The name of the Secret resource being referred to.
  27262. maxLength: 253
  27263. minLength: 1
  27264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27265. type: string
  27266. namespace:
  27267. description: |-
  27268. The namespace of the Secret resource being referred to.
  27269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27270. maxLength: 63
  27271. minLength: 1
  27272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27273. type: string
  27274. type: object
  27275. required:
  27276. - secretRef
  27277. type: object
  27278. required:
  27279. - privateKey
  27280. type: object
  27281. installID:
  27282. type: string
  27283. permissions:
  27284. additionalProperties:
  27285. type: string
  27286. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27287. type: object
  27288. repositories:
  27289. description: |-
  27290. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  27291. is installed to.
  27292. items:
  27293. type: string
  27294. type: array
  27295. url:
  27296. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  27297. type: string
  27298. required:
  27299. - appID
  27300. - auth
  27301. - installID
  27302. type: object
  27303. gitlabDeployTokenSpec:
  27304. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  27305. properties:
  27306. auth:
  27307. description: Auth configures how ESO authenticates with the GitLab API.
  27308. properties:
  27309. token:
  27310. description: |-
  27311. Token references a secret containing a GitLab access token (personal, group, or
  27312. project) with the api scope and at least the Maintainer role on the target.
  27313. properties:
  27314. secretRef:
  27315. description: |-
  27316. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27317. In some instances, `key` is a required field.
  27318. properties:
  27319. key:
  27320. description: |-
  27321. A key in the referenced Secret.
  27322. Some instances of this field may be defaulted, in others it may be required.
  27323. maxLength: 253
  27324. minLength: 1
  27325. pattern: ^[-._a-zA-Z0-9]+$
  27326. type: string
  27327. name:
  27328. description: The name of the Secret resource being referred to.
  27329. maxLength: 253
  27330. minLength: 1
  27331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27332. type: string
  27333. namespace:
  27334. description: |-
  27335. The namespace of the Secret resource being referred to.
  27336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27337. maxLength: 63
  27338. minLength: 1
  27339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27340. type: string
  27341. type: object
  27342. required:
  27343. - secretRef
  27344. type: object
  27345. required:
  27346. - token
  27347. type: object
  27348. expiresAt:
  27349. description: |-
  27350. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  27351. not expire on the GitLab side and is revoked only when the generator state is
  27352. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  27353. format: date-time
  27354. type: string
  27355. groupID:
  27356. description: |-
  27357. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  27358. create the deploy token in. The generator URL-escapes paths before calling the
  27359. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  27360. minLength: 1
  27361. type: string
  27362. name:
  27363. description: Name of the deploy token.
  27364. minLength: 1
  27365. type: string
  27366. projectID:
  27367. description: |-
  27368. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  27369. project to create the deploy token in. The generator URL-escapes paths before
  27370. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  27371. minLength: 1
  27372. type: string
  27373. scopes:
  27374. description: Scopes granted to the deploy token. At least one scope is required.
  27375. items:
  27376. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  27377. enum:
  27378. - read_repository
  27379. - read_registry
  27380. - write_registry
  27381. - read_package_registry
  27382. - write_package_registry
  27383. - read_virtual_registry
  27384. - write_virtual_registry
  27385. type: string
  27386. minItems: 1
  27387. type: array
  27388. url:
  27389. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  27390. type: string
  27391. username:
  27392. description: |-
  27393. Username is an optional username for the deploy token. GitLab defaults it to
  27394. gitlab+deploy-token-{n} when omitted.
  27395. type: string
  27396. required:
  27397. - auth
  27398. - name
  27399. - scopes
  27400. type: object
  27401. x-kubernetes-validations:
  27402. - message: exactly one of projectID or groupID must be set
  27403. rule: has(self.projectID) != has(self.groupID)
  27404. grafanaSpec:
  27405. description: GrafanaSpec controls the behavior of the grafana generator.
  27406. properties:
  27407. auth:
  27408. description: |-
  27409. Auth is the authentication configuration to authenticate
  27410. against the Grafana instance.
  27411. properties:
  27412. basic:
  27413. description: |-
  27414. Basic auth credentials used to authenticate against the Grafana instance.
  27415. Note: you need a token which has elevated permissions to create service accounts.
  27416. See here for the documentation on basic roles offered by Grafana:
  27417. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27418. properties:
  27419. password:
  27420. description: A basic auth password used to authenticate against the Grafana instance.
  27421. properties:
  27422. key:
  27423. description: The key where the token is found.
  27424. maxLength: 253
  27425. minLength: 1
  27426. pattern: ^[-._a-zA-Z0-9]+$
  27427. type: string
  27428. name:
  27429. description: The name of the Secret resource being referred to.
  27430. maxLength: 253
  27431. minLength: 1
  27432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27433. type: string
  27434. type: object
  27435. username:
  27436. description: A basic auth username used to authenticate against the Grafana instance.
  27437. type: string
  27438. required:
  27439. - password
  27440. - username
  27441. type: object
  27442. token:
  27443. description: |-
  27444. A service account token used to authenticate against the Grafana instance.
  27445. Note: you need a token which has elevated permissions to create service accounts.
  27446. See here for the documentation on basic roles offered by Grafana:
  27447. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27448. properties:
  27449. key:
  27450. description: The key where the token is found.
  27451. maxLength: 253
  27452. minLength: 1
  27453. pattern: ^[-._a-zA-Z0-9]+$
  27454. type: string
  27455. name:
  27456. description: The name of the Secret resource being referred to.
  27457. maxLength: 253
  27458. minLength: 1
  27459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27460. type: string
  27461. type: object
  27462. type: object
  27463. serviceAccount:
  27464. description: |-
  27465. ServiceAccount is the configuration for the service account that
  27466. is supposed to be generated by the generator.
  27467. properties:
  27468. name:
  27469. description: Name is the name of the service account that will be created by ESO.
  27470. type: string
  27471. role:
  27472. description: |-
  27473. Role is the role of the service account.
  27474. See here for the documentation on basic roles offered by Grafana:
  27475. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  27476. type: string
  27477. secondsToLive:
  27478. description: |-
  27479. SecondsToLive is the number of seconds before the generated service account token will expire.
  27480. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  27481. format: int64
  27482. minimum: 1
  27483. type: integer
  27484. required:
  27485. - name
  27486. - role
  27487. type: object
  27488. url:
  27489. description: URL is the URL of the Grafana instance.
  27490. type: string
  27491. required:
  27492. - auth
  27493. - serviceAccount
  27494. - url
  27495. type: object
  27496. mfaSpec:
  27497. description: MFASpec controls the behavior of the mfa generator.
  27498. properties:
  27499. algorithm:
  27500. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  27501. type: string
  27502. length:
  27503. description: Length defines the token length. Defaults to 6 characters.
  27504. type: integer
  27505. secret:
  27506. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  27507. properties:
  27508. key:
  27509. description: |-
  27510. A key in the referenced Secret.
  27511. Some instances of this field may be defaulted, in others it may be required.
  27512. maxLength: 253
  27513. minLength: 1
  27514. pattern: ^[-._a-zA-Z0-9]+$
  27515. type: string
  27516. name:
  27517. description: The name of the Secret resource being referred to.
  27518. maxLength: 253
  27519. minLength: 1
  27520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27521. type: string
  27522. namespace:
  27523. description: |-
  27524. The namespace of the Secret resource being referred to.
  27525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27526. maxLength: 63
  27527. minLength: 1
  27528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27529. type: string
  27530. type: object
  27531. timePeriod:
  27532. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  27533. type: integer
  27534. when:
  27535. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  27536. format: date-time
  27537. type: string
  27538. required:
  27539. - secret
  27540. type: object
  27541. passwordSpec:
  27542. description: PasswordSpec controls the behavior of the password generator.
  27543. properties:
  27544. allowRepeat:
  27545. default: false
  27546. description: set AllowRepeat to true to allow repeating characters.
  27547. type: boolean
  27548. digits:
  27549. description: |-
  27550. Digits specifies the number of digits in the generated
  27551. password. If omitted it defaults to 25% of the length of the password
  27552. type: integer
  27553. encoding:
  27554. default: raw
  27555. description: |-
  27556. Encoding specifies the encoding of the generated password.
  27557. Valid values are:
  27558. - "raw" (default): no encoding
  27559. - "base64": standard base64 encoding
  27560. - "base64url": base64url encoding
  27561. - "base32": base32 encoding
  27562. - "hex": hexadecimal encoding
  27563. enum:
  27564. - base64
  27565. - base64url
  27566. - base32
  27567. - hex
  27568. - raw
  27569. type: string
  27570. length:
  27571. default: 24
  27572. description: |-
  27573. Length of the password to be generated.
  27574. Defaults to 24
  27575. type: integer
  27576. noUpper:
  27577. default: false
  27578. description: Set NoUpper to disable uppercase characters
  27579. type: boolean
  27580. secretKeys:
  27581. description: |-
  27582. SecretKeys defines the keys that will be populated with generated passwords.
  27583. Defaults to "password" when not set.
  27584. items:
  27585. type: string
  27586. minItems: 1
  27587. type: array
  27588. symbolCharacters:
  27589. description: |-
  27590. SymbolCharacters specifies the special characters that should be used
  27591. in the generated password.
  27592. type: string
  27593. symbols:
  27594. description: |-
  27595. Symbols specifies the number of symbol characters in the generated
  27596. password. If omitted it defaults to 25% of the length of the password
  27597. type: integer
  27598. required:
  27599. - allowRepeat
  27600. - length
  27601. - noUpper
  27602. type: object
  27603. quayAccessTokenSpec:
  27604. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  27605. properties:
  27606. robotAccount:
  27607. description: Name of the robot account you are federating with
  27608. type: string
  27609. serviceAccountRef:
  27610. description: Name of the service account you are federating with
  27611. properties:
  27612. audiences:
  27613. description: |-
  27614. Audience specifies the `aud` claim for the service account token
  27615. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27616. then this audiences will be appended to the list
  27617. items:
  27618. type: string
  27619. type: array
  27620. name:
  27621. description: The name of the ServiceAccount resource being referred to.
  27622. maxLength: 253
  27623. minLength: 1
  27624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27625. type: string
  27626. namespace:
  27627. description: |-
  27628. Namespace of the resource being referred to.
  27629. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27630. maxLength: 63
  27631. minLength: 1
  27632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27633. type: string
  27634. required:
  27635. - name
  27636. type: object
  27637. url:
  27638. description: URL configures the Quay instance URL. Defaults to quay.io.
  27639. type: string
  27640. required:
  27641. - robotAccount
  27642. - serviceAccountRef
  27643. type: object
  27644. sshKeySpec:
  27645. description: SSHKeySpec controls the behavior of the ssh key generator.
  27646. properties:
  27647. comment:
  27648. description: Comment specifies an optional comment for the SSH key
  27649. type: string
  27650. keySize:
  27651. description: |-
  27652. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  27653. For RSA keys: 2048, 3072, 4096
  27654. For ECDSA keys: 256, 384, 521
  27655. Ignored for ed25519 keys
  27656. maximum: 8192
  27657. minimum: 256
  27658. type: integer
  27659. keyType:
  27660. default: rsa
  27661. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  27662. enum:
  27663. - rsa
  27664. - ecdsa
  27665. - ed25519
  27666. type: string
  27667. type: object
  27668. stsSessionTokenSpec:
  27669. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  27670. properties:
  27671. auth:
  27672. description: Auth defines how to authenticate with AWS
  27673. properties:
  27674. jwt:
  27675. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27676. properties:
  27677. serviceAccountRef:
  27678. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27679. properties:
  27680. audiences:
  27681. description: |-
  27682. Audience specifies the `aud` claim for the service account token
  27683. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27684. then this audiences will be appended to the list
  27685. items:
  27686. type: string
  27687. type: array
  27688. name:
  27689. description: The name of the ServiceAccount resource being referred to.
  27690. maxLength: 253
  27691. minLength: 1
  27692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27693. type: string
  27694. namespace:
  27695. description: |-
  27696. Namespace of the resource being referred to.
  27697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27698. maxLength: 63
  27699. minLength: 1
  27700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27701. type: string
  27702. required:
  27703. - name
  27704. type: object
  27705. type: object
  27706. secretRef:
  27707. description: |-
  27708. AWSAuthSecretRef holds secret references for AWS credentials
  27709. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27710. properties:
  27711. accessKeyIDSecretRef:
  27712. description: The AccessKeyID is used for authentication
  27713. properties:
  27714. key:
  27715. description: |-
  27716. A key in the referenced Secret.
  27717. Some instances of this field may be defaulted, in others it may be required.
  27718. maxLength: 253
  27719. minLength: 1
  27720. pattern: ^[-._a-zA-Z0-9]+$
  27721. type: string
  27722. name:
  27723. description: The name of the Secret resource being referred to.
  27724. maxLength: 253
  27725. minLength: 1
  27726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27727. type: string
  27728. namespace:
  27729. description: |-
  27730. The namespace of the Secret resource being referred to.
  27731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27732. maxLength: 63
  27733. minLength: 1
  27734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27735. type: string
  27736. type: object
  27737. secretAccessKeySecretRef:
  27738. description: The SecretAccessKey is used for authentication
  27739. properties:
  27740. key:
  27741. description: |-
  27742. A key in the referenced Secret.
  27743. Some instances of this field may be defaulted, in others it may be required.
  27744. maxLength: 253
  27745. minLength: 1
  27746. pattern: ^[-._a-zA-Z0-9]+$
  27747. type: string
  27748. name:
  27749. description: The name of the Secret resource being referred to.
  27750. maxLength: 253
  27751. minLength: 1
  27752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27753. type: string
  27754. namespace:
  27755. description: |-
  27756. The namespace of the Secret resource being referred to.
  27757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27758. maxLength: 63
  27759. minLength: 1
  27760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27761. type: string
  27762. type: object
  27763. sessionTokenSecretRef:
  27764. description: |-
  27765. The SessionToken used for authentication
  27766. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27767. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27768. properties:
  27769. key:
  27770. description: |-
  27771. A key in the referenced Secret.
  27772. Some instances of this field may be defaulted, in others it may be required.
  27773. maxLength: 253
  27774. minLength: 1
  27775. pattern: ^[-._a-zA-Z0-9]+$
  27776. type: string
  27777. name:
  27778. description: The name of the Secret resource being referred to.
  27779. maxLength: 253
  27780. minLength: 1
  27781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27782. type: string
  27783. namespace:
  27784. description: |-
  27785. The namespace of the Secret resource being referred to.
  27786. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27787. maxLength: 63
  27788. minLength: 1
  27789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27790. type: string
  27791. type: object
  27792. type: object
  27793. type: object
  27794. region:
  27795. description: Region specifies the region to operate in.
  27796. type: string
  27797. requestParameters:
  27798. description: RequestParameters contains parameters that can be passed to the STS service.
  27799. properties:
  27800. serialNumber:
  27801. description: |-
  27802. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  27803. the GetSessionToken call.
  27804. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  27805. (such as arn:aws:iam::123456789012:mfa/user)
  27806. type: string
  27807. sessionDuration:
  27808. format: int32
  27809. type: integer
  27810. tokenCode:
  27811. description: TokenCode is the value provided by the MFA device, if MFA is required.
  27812. type: string
  27813. type: object
  27814. role:
  27815. description: |-
  27816. You can assume a role before making calls to the
  27817. desired AWS service.
  27818. type: string
  27819. required:
  27820. - region
  27821. type: object
  27822. uuidSpec:
  27823. description: UUIDSpec controls the behavior of the uuid generator.
  27824. type: object
  27825. vaultDynamicSecretSpec:
  27826. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  27827. properties:
  27828. allowEmptyResponse:
  27829. default: false
  27830. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  27831. type: boolean
  27832. controller:
  27833. description: |-
  27834. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27835. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27836. type: string
  27837. getParameters:
  27838. additionalProperties:
  27839. items:
  27840. type: string
  27841. type: array
  27842. description: |-
  27843. GetParameters are query-string parameters passed to Vault on GET calls.
  27844. Each key may map to multiple values, matching HTTP query-string semantics.
  27845. Ignored for non-GET methods; use Parameters for write bodies.
  27846. type: object
  27847. method:
  27848. description: Vault API method to use (GET/POST/other)
  27849. type: string
  27850. parameters:
  27851. description: Parameters to pass to Vault write (for non-GET methods)
  27852. x-kubernetes-preserve-unknown-fields: true
  27853. path:
  27854. description: Vault path to obtain the dynamic secret from
  27855. type: string
  27856. provider:
  27857. description: Vault provider common spec
  27858. properties:
  27859. auth:
  27860. description: Auth configures how secret-manager authenticates with the Vault server.
  27861. properties:
  27862. appRole:
  27863. description: |-
  27864. AppRole authenticates with Vault using the App Role auth mechanism,
  27865. with the role and secret stored in a Kubernetes Secret resource.
  27866. properties:
  27867. path:
  27868. default: approle
  27869. description: |-
  27870. Path where the App Role authentication backend is mounted
  27871. in Vault, e.g: "approle"
  27872. type: string
  27873. roleId:
  27874. description: |-
  27875. RoleID configured in the App Role authentication backend when setting
  27876. up the authentication backend in Vault.
  27877. type: string
  27878. roleRef:
  27879. description: |-
  27880. Reference to a key in a Secret that contains the App Role ID used
  27881. to authenticate with Vault.
  27882. The `key` field must be specified and denotes which entry within the Secret
  27883. resource is used as the app role id.
  27884. properties:
  27885. key:
  27886. description: |-
  27887. A key in the referenced Secret.
  27888. Some instances of this field may be defaulted, in others it may be required.
  27889. maxLength: 253
  27890. minLength: 1
  27891. pattern: ^[-._a-zA-Z0-9]+$
  27892. type: string
  27893. name:
  27894. description: The name of the Secret resource being referred to.
  27895. maxLength: 253
  27896. minLength: 1
  27897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27898. type: string
  27899. namespace:
  27900. description: |-
  27901. The namespace of the Secret resource being referred to.
  27902. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27903. maxLength: 63
  27904. minLength: 1
  27905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27906. type: string
  27907. type: object
  27908. secretRef:
  27909. description: |-
  27910. Reference to a key in a Secret that contains the App Role secret used
  27911. to authenticate with Vault.
  27912. The `key` field must be specified and denotes which entry within the Secret
  27913. resource is used as the app role secret.
  27914. properties:
  27915. key:
  27916. description: |-
  27917. A key in the referenced Secret.
  27918. Some instances of this field may be defaulted, in others it may be required.
  27919. maxLength: 253
  27920. minLength: 1
  27921. pattern: ^[-._a-zA-Z0-9]+$
  27922. type: string
  27923. name:
  27924. description: The name of the Secret resource being referred to.
  27925. maxLength: 253
  27926. minLength: 1
  27927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27928. type: string
  27929. namespace:
  27930. description: |-
  27931. The namespace of the Secret resource being referred to.
  27932. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27933. maxLength: 63
  27934. minLength: 1
  27935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27936. type: string
  27937. type: object
  27938. required:
  27939. - path
  27940. - secretRef
  27941. type: object
  27942. cert:
  27943. description: |-
  27944. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  27945. Cert authentication method
  27946. properties:
  27947. clientCert:
  27948. description: |-
  27949. ClientCert is a certificate to authenticate using the Cert Vault
  27950. authentication method
  27951. properties:
  27952. key:
  27953. description: |-
  27954. A key in the referenced Secret.
  27955. Some instances of this field may be defaulted, in others it may be required.
  27956. maxLength: 253
  27957. minLength: 1
  27958. pattern: ^[-._a-zA-Z0-9]+$
  27959. type: string
  27960. name:
  27961. description: The name of the Secret resource being referred to.
  27962. maxLength: 253
  27963. minLength: 1
  27964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27965. type: string
  27966. namespace:
  27967. description: |-
  27968. The namespace of the Secret resource being referred to.
  27969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27970. maxLength: 63
  27971. minLength: 1
  27972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27973. type: string
  27974. type: object
  27975. path:
  27976. default: cert
  27977. description: |-
  27978. Path where the Certificate authentication backend is mounted
  27979. in Vault, e.g: "cert"
  27980. type: string
  27981. secretRef:
  27982. description: |-
  27983. SecretRef to a key in a Secret resource containing client private key to
  27984. authenticate with Vault using the Cert authentication method
  27985. properties:
  27986. key:
  27987. description: |-
  27988. A key in the referenced Secret.
  27989. Some instances of this field may be defaulted, in others it may be required.
  27990. maxLength: 253
  27991. minLength: 1
  27992. pattern: ^[-._a-zA-Z0-9]+$
  27993. type: string
  27994. name:
  27995. description: The name of the Secret resource being referred to.
  27996. maxLength: 253
  27997. minLength: 1
  27998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27999. type: string
  28000. namespace:
  28001. description: |-
  28002. The namespace of the Secret resource being referred to.
  28003. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28004. maxLength: 63
  28005. minLength: 1
  28006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28007. type: string
  28008. type: object
  28009. vaultRole:
  28010. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28011. type: string
  28012. type: object
  28013. gcp:
  28014. description: |-
  28015. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28016. GCP authentication method
  28017. properties:
  28018. location:
  28019. description: Location optionally defines a location/region for the secret
  28020. type: string
  28021. path:
  28022. default: gcp
  28023. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28024. type: string
  28025. projectID:
  28026. description: Project ID of the Google Cloud Platform project
  28027. type: string
  28028. role:
  28029. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28030. type: string
  28031. secretRef:
  28032. description: Specify credentials in a Secret object
  28033. properties:
  28034. secretAccessKeySecretRef:
  28035. description: The SecretAccessKey is used for authentication
  28036. properties:
  28037. key:
  28038. description: |-
  28039. A key in the referenced Secret.
  28040. Some instances of this field may be defaulted, in others it may be required.
  28041. maxLength: 253
  28042. minLength: 1
  28043. pattern: ^[-._a-zA-Z0-9]+$
  28044. type: string
  28045. name:
  28046. description: The name of the Secret resource being referred to.
  28047. maxLength: 253
  28048. minLength: 1
  28049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28050. type: string
  28051. namespace:
  28052. description: |-
  28053. The namespace of the Secret resource being referred to.
  28054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28055. maxLength: 63
  28056. minLength: 1
  28057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28058. type: string
  28059. type: object
  28060. type: object
  28061. serviceAccountRef:
  28062. description: ServiceAccountRef to a service account for impersonation
  28063. properties:
  28064. audiences:
  28065. description: |-
  28066. Audience specifies the `aud` claim for the service account token
  28067. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28068. then this audiences will be appended to the list
  28069. items:
  28070. type: string
  28071. type: array
  28072. name:
  28073. description: The name of the ServiceAccount resource being referred to.
  28074. maxLength: 253
  28075. minLength: 1
  28076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28077. type: string
  28078. namespace:
  28079. description: |-
  28080. Namespace of the resource being referred to.
  28081. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28082. maxLength: 63
  28083. minLength: 1
  28084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28085. type: string
  28086. required:
  28087. - name
  28088. type: object
  28089. workloadIdentity:
  28090. description: Specify a service account with Workload Identity
  28091. properties:
  28092. clusterLocation:
  28093. description: |-
  28094. ClusterLocation is the location of the cluster
  28095. If not specified, it fetches information from the metadata server
  28096. type: string
  28097. clusterName:
  28098. description: |-
  28099. ClusterName is the name of the cluster
  28100. If not specified, it fetches information from the metadata server
  28101. type: string
  28102. clusterProjectID:
  28103. description: |-
  28104. ClusterProjectID is the project ID of the cluster
  28105. If not specified, it fetches information from the metadata server
  28106. type: string
  28107. serviceAccountRef:
  28108. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28109. properties:
  28110. audiences:
  28111. description: |-
  28112. Audience specifies the `aud` claim for the service account token
  28113. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28114. then this audiences will be appended to the list
  28115. items:
  28116. type: string
  28117. type: array
  28118. name:
  28119. description: The name of the ServiceAccount resource being referred to.
  28120. maxLength: 253
  28121. minLength: 1
  28122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28123. type: string
  28124. namespace:
  28125. description: |-
  28126. Namespace of the resource being referred to.
  28127. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28128. maxLength: 63
  28129. minLength: 1
  28130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28131. type: string
  28132. required:
  28133. - name
  28134. type: object
  28135. required:
  28136. - serviceAccountRef
  28137. type: object
  28138. required:
  28139. - role
  28140. type: object
  28141. iam:
  28142. description: |-
  28143. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28144. AWS IAM authentication method
  28145. properties:
  28146. externalID:
  28147. description: AWS External ID set on assumed IAM roles
  28148. type: string
  28149. jwt:
  28150. description: Specify a service account with IRSA enabled
  28151. properties:
  28152. serviceAccountRef:
  28153. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28154. properties:
  28155. audiences:
  28156. description: |-
  28157. Audience specifies the `aud` claim for the service account token
  28158. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28159. then this audiences will be appended to the list
  28160. items:
  28161. type: string
  28162. type: array
  28163. name:
  28164. description: The name of the ServiceAccount resource being referred to.
  28165. maxLength: 253
  28166. minLength: 1
  28167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28168. type: string
  28169. namespace:
  28170. description: |-
  28171. Namespace of the resource being referred to.
  28172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28173. maxLength: 63
  28174. minLength: 1
  28175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28176. type: string
  28177. required:
  28178. - name
  28179. type: object
  28180. type: object
  28181. path:
  28182. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28183. type: string
  28184. region:
  28185. description: AWS region
  28186. type: string
  28187. role:
  28188. description: This is the AWS role to be assumed before talking to vault
  28189. type: string
  28190. secretRef:
  28191. description: Specify credentials in a Secret object
  28192. properties:
  28193. accessKeyIDSecretRef:
  28194. description: The AccessKeyID is used for authentication
  28195. properties:
  28196. key:
  28197. description: |-
  28198. A key in the referenced Secret.
  28199. Some instances of this field may be defaulted, in others it may be required.
  28200. maxLength: 253
  28201. minLength: 1
  28202. pattern: ^[-._a-zA-Z0-9]+$
  28203. type: string
  28204. name:
  28205. description: The name of the Secret resource being referred to.
  28206. maxLength: 253
  28207. minLength: 1
  28208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28209. type: string
  28210. namespace:
  28211. description: |-
  28212. The namespace of the Secret resource being referred to.
  28213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28214. maxLength: 63
  28215. minLength: 1
  28216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28217. type: string
  28218. type: object
  28219. secretAccessKeySecretRef:
  28220. description: The SecretAccessKey is used for authentication
  28221. properties:
  28222. key:
  28223. description: |-
  28224. A key in the referenced Secret.
  28225. Some instances of this field may be defaulted, in others it may be required.
  28226. maxLength: 253
  28227. minLength: 1
  28228. pattern: ^[-._a-zA-Z0-9]+$
  28229. type: string
  28230. name:
  28231. description: The name of the Secret resource being referred to.
  28232. maxLength: 253
  28233. minLength: 1
  28234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28235. type: string
  28236. namespace:
  28237. description: |-
  28238. The namespace of the Secret resource being referred to.
  28239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28240. maxLength: 63
  28241. minLength: 1
  28242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28243. type: string
  28244. type: object
  28245. sessionTokenSecretRef:
  28246. description: |-
  28247. The SessionToken used for authentication
  28248. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28249. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28250. properties:
  28251. key:
  28252. description: |-
  28253. A key in the referenced Secret.
  28254. Some instances of this field may be defaulted, in others it may be required.
  28255. maxLength: 253
  28256. minLength: 1
  28257. pattern: ^[-._a-zA-Z0-9]+$
  28258. type: string
  28259. name:
  28260. description: The name of the Secret resource being referred to.
  28261. maxLength: 253
  28262. minLength: 1
  28263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28264. type: string
  28265. namespace:
  28266. description: |-
  28267. The namespace of the Secret resource being referred to.
  28268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28269. maxLength: 63
  28270. minLength: 1
  28271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28272. type: string
  28273. type: object
  28274. type: object
  28275. vaultAwsIamServerID:
  28276. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28277. type: string
  28278. vaultRole:
  28279. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28280. type: string
  28281. required:
  28282. - vaultRole
  28283. type: object
  28284. jwt:
  28285. description: |-
  28286. Jwt authenticates with Vault by passing role and JWT token using the
  28287. JWT/OIDC authentication method
  28288. properties:
  28289. kubernetesServiceAccountToken:
  28290. description: |-
  28291. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  28292. a token for with the `TokenRequest` API.
  28293. properties:
  28294. audiences:
  28295. description: |-
  28296. Optional audiences field that will be used to request a temporary Kubernetes service
  28297. account token for the service account referenced by `serviceAccountRef`.
  28298. Defaults to a single audience `vault` it not specified.
  28299. Deprecated: use serviceAccountRef.Audiences instead
  28300. items:
  28301. type: string
  28302. type: array
  28303. expirationSeconds:
  28304. description: |-
  28305. Optional expiration time in seconds that will be used to request a temporary
  28306. Kubernetes service account token for the service account referenced by
  28307. `serviceAccountRef`.
  28308. Deprecated: this will be removed in the future.
  28309. Defaults to 10 minutes.
  28310. format: int64
  28311. type: integer
  28312. serviceAccountRef:
  28313. description: Service account field containing the name of a kubernetes ServiceAccount.
  28314. properties:
  28315. audiences:
  28316. description: |-
  28317. Audience specifies the `aud` claim for the service account token
  28318. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28319. then this audiences will be appended to the list
  28320. items:
  28321. type: string
  28322. type: array
  28323. name:
  28324. description: The name of the ServiceAccount resource being referred to.
  28325. maxLength: 253
  28326. minLength: 1
  28327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28328. type: string
  28329. namespace:
  28330. description: |-
  28331. Namespace of the resource being referred to.
  28332. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28333. maxLength: 63
  28334. minLength: 1
  28335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28336. type: string
  28337. required:
  28338. - name
  28339. type: object
  28340. required:
  28341. - serviceAccountRef
  28342. type: object
  28343. path:
  28344. default: jwt
  28345. description: |-
  28346. Path where the JWT authentication backend is mounted
  28347. in Vault, e.g: "jwt"
  28348. type: string
  28349. role:
  28350. description: |-
  28351. Role is a JWT role to authenticate using the JWT/OIDC Vault
  28352. authentication method
  28353. type: string
  28354. secretRef:
  28355. description: |-
  28356. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  28357. authenticate with Vault using the JWT/OIDC authentication method.
  28358. properties:
  28359. key:
  28360. description: |-
  28361. A key in the referenced Secret.
  28362. Some instances of this field may be defaulted, in others it may be required.
  28363. maxLength: 253
  28364. minLength: 1
  28365. pattern: ^[-._a-zA-Z0-9]+$
  28366. type: string
  28367. name:
  28368. description: The name of the Secret resource being referred to.
  28369. maxLength: 253
  28370. minLength: 1
  28371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28372. type: string
  28373. namespace:
  28374. description: |-
  28375. The namespace of the Secret resource being referred to.
  28376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28377. maxLength: 63
  28378. minLength: 1
  28379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28380. type: string
  28381. type: object
  28382. required:
  28383. - path
  28384. type: object
  28385. kubernetes:
  28386. description: |-
  28387. Kubernetes authenticates with Vault by passing the ServiceAccount
  28388. token stored in the named Secret resource to the Vault server.
  28389. properties:
  28390. mountPath:
  28391. default: kubernetes
  28392. description: |-
  28393. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  28394. "kubernetes"
  28395. type: string
  28396. role:
  28397. description: |-
  28398. A required field containing the Vault Role to assume. A Role binds a
  28399. Kubernetes ServiceAccount with a set of Vault policies.
  28400. type: string
  28401. secretRef:
  28402. description: |-
  28403. Optional secret field containing a Kubernetes ServiceAccount JWT used
  28404. for authenticating with Vault. If a name is specified without a key,
  28405. `token` is the default. If one is not specified, the one bound to
  28406. the controller will be used.
  28407. properties:
  28408. key:
  28409. description: |-
  28410. A key in the referenced Secret.
  28411. Some instances of this field may be defaulted, in others it may be required.
  28412. maxLength: 253
  28413. minLength: 1
  28414. pattern: ^[-._a-zA-Z0-9]+$
  28415. type: string
  28416. name:
  28417. description: The name of the Secret resource being referred to.
  28418. maxLength: 253
  28419. minLength: 1
  28420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28421. type: string
  28422. namespace:
  28423. description: |-
  28424. The namespace of the Secret resource being referred to.
  28425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28426. maxLength: 63
  28427. minLength: 1
  28428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28429. type: string
  28430. type: object
  28431. serviceAccountRef:
  28432. description: |-
  28433. Optional service account field containing the name of a kubernetes ServiceAccount.
  28434. If the service account is specified, the service account secret token JWT will be used
  28435. for authenticating with Vault. If the service account selector is not supplied,
  28436. the secretRef will be used instead.
  28437. properties:
  28438. audiences:
  28439. description: |-
  28440. Audience specifies the `aud` claim for the service account token
  28441. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28442. then this audiences will be appended to the list
  28443. items:
  28444. type: string
  28445. type: array
  28446. name:
  28447. description: The name of the ServiceAccount resource being referred to.
  28448. maxLength: 253
  28449. minLength: 1
  28450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28451. type: string
  28452. namespace:
  28453. description: |-
  28454. Namespace of the resource being referred to.
  28455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28456. maxLength: 63
  28457. minLength: 1
  28458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28459. type: string
  28460. required:
  28461. - name
  28462. type: object
  28463. required:
  28464. - mountPath
  28465. - role
  28466. type: object
  28467. ldap:
  28468. description: |-
  28469. Ldap authenticates with Vault by passing username/password pair using
  28470. the LDAP authentication method
  28471. properties:
  28472. path:
  28473. default: ldap
  28474. description: |-
  28475. Path where the LDAP authentication backend is mounted
  28476. in Vault, e.g: "ldap"
  28477. type: string
  28478. secretRef:
  28479. description: |-
  28480. SecretRef to a key in a Secret resource containing password for the LDAP
  28481. user used to authenticate with Vault using the LDAP authentication
  28482. method
  28483. properties:
  28484. key:
  28485. description: |-
  28486. A key in the referenced Secret.
  28487. Some instances of this field may be defaulted, in others it may be required.
  28488. maxLength: 253
  28489. minLength: 1
  28490. pattern: ^[-._a-zA-Z0-9]+$
  28491. type: string
  28492. name:
  28493. description: The name of the Secret resource being referred to.
  28494. maxLength: 253
  28495. minLength: 1
  28496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28497. type: string
  28498. namespace:
  28499. description: |-
  28500. The namespace of the Secret resource being referred to.
  28501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28502. maxLength: 63
  28503. minLength: 1
  28504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28505. type: string
  28506. type: object
  28507. username:
  28508. description: |-
  28509. Username is an LDAP username used to authenticate using the LDAP Vault
  28510. authentication method
  28511. type: string
  28512. required:
  28513. - path
  28514. - username
  28515. type: object
  28516. namespace:
  28517. description: |-
  28518. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  28519. Namespaces is a set of features within Vault Enterprise that allows
  28520. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  28521. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  28522. This will default to Vault.Namespace field if set, or empty otherwise
  28523. type: string
  28524. tokenSecretRef:
  28525. description: TokenSecretRef authenticates with Vault by presenting a token.
  28526. properties:
  28527. key:
  28528. description: |-
  28529. A key in the referenced Secret.
  28530. Some instances of this field may be defaulted, in others it may be required.
  28531. maxLength: 253
  28532. minLength: 1
  28533. pattern: ^[-._a-zA-Z0-9]+$
  28534. type: string
  28535. name:
  28536. description: The name of the Secret resource being referred to.
  28537. maxLength: 253
  28538. minLength: 1
  28539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28540. type: string
  28541. namespace:
  28542. description: |-
  28543. The namespace of the Secret resource being referred to.
  28544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28545. maxLength: 63
  28546. minLength: 1
  28547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28548. type: string
  28549. type: object
  28550. userPass:
  28551. description: UserPass authenticates with Vault by passing username/password pair
  28552. properties:
  28553. path:
  28554. default: userpass
  28555. description: |-
  28556. Path where the UserPassword authentication backend is mounted
  28557. in Vault, e.g: "userpass"
  28558. type: string
  28559. secretRef:
  28560. description: |-
  28561. SecretRef to a key in a Secret resource containing password for the
  28562. user used to authenticate with Vault using the UserPass authentication
  28563. method
  28564. properties:
  28565. key:
  28566. description: |-
  28567. A key in the referenced Secret.
  28568. Some instances of this field may be defaulted, in others it may be required.
  28569. maxLength: 253
  28570. minLength: 1
  28571. pattern: ^[-._a-zA-Z0-9]+$
  28572. type: string
  28573. name:
  28574. description: The name of the Secret resource being referred to.
  28575. maxLength: 253
  28576. minLength: 1
  28577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28578. type: string
  28579. namespace:
  28580. description: |-
  28581. The namespace of the Secret resource being referred to.
  28582. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28583. maxLength: 63
  28584. minLength: 1
  28585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28586. type: string
  28587. type: object
  28588. username:
  28589. description: |-
  28590. Username is a username used to authenticate using the UserPass Vault
  28591. authentication method
  28592. type: string
  28593. required:
  28594. - path
  28595. - username
  28596. type: object
  28597. type: object
  28598. caBundle:
  28599. description: |-
  28600. PEM encoded CA bundle used to validate Vault server certificate. Only used
  28601. if the Server URL is using HTTPS protocol. This parameter is ignored for
  28602. plain HTTP protocol connection. If not set the system root certificates
  28603. are used to validate the TLS connection.
  28604. format: byte
  28605. type: string
  28606. caProvider:
  28607. description: The provider for the CA bundle to use to validate Vault server certificate.
  28608. properties:
  28609. key:
  28610. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  28611. maxLength: 253
  28612. minLength: 1
  28613. pattern: ^[-._a-zA-Z0-9]+$
  28614. type: string
  28615. name:
  28616. description: The name of the object located at the provider type.
  28617. maxLength: 253
  28618. minLength: 1
  28619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28620. type: string
  28621. namespace:
  28622. description: |-
  28623. The namespace the Provider type is in.
  28624. Can only be defined when used in a ClusterSecretStore.
  28625. maxLength: 63
  28626. minLength: 1
  28627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28628. type: string
  28629. type:
  28630. description: The type of provider to use such as "Secret", or "ConfigMap".
  28631. enum:
  28632. - Secret
  28633. - ConfigMap
  28634. type: string
  28635. required:
  28636. - name
  28637. - type
  28638. type: object
  28639. checkAndSet:
  28640. description: |-
  28641. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  28642. Only applies to Vault KV v2 stores. When enabled, write operations must include
  28643. the current version of the secret to prevent unintentional overwrites.
  28644. properties:
  28645. required:
  28646. description: |-
  28647. Required when true, all write operations must include a check-and-set parameter.
  28648. This helps prevent unintentional overwrites of secrets.
  28649. type: boolean
  28650. type: object
  28651. forwardInconsistent:
  28652. description: |-
  28653. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  28654. leader instead of simply retrying within a loop. This can increase performance if
  28655. the option is enabled serverside.
  28656. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  28657. type: boolean
  28658. headers:
  28659. additionalProperties:
  28660. type: string
  28661. description: Headers to be added in Vault request
  28662. type: object
  28663. namespace:
  28664. description: |-
  28665. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  28666. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  28667. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  28668. type: string
  28669. path:
  28670. description: |-
  28671. Path is the mount path of the Vault KV backend endpoint, e.g:
  28672. "secret". The v2 KV secret engine version specific "/data" path suffix
  28673. for fetching secrets from Vault is optional and will be appended
  28674. if not present in specified path.
  28675. type: string
  28676. readYourWrites:
  28677. description: |-
  28678. ReadYourWrites ensures isolated read-after-write semantics by
  28679. providing discovered cluster replication states in each request.
  28680. More information about eventual consistency in Vault can be found here
  28681. https://www.vaultproject.io/docs/enterprise/consistency
  28682. type: boolean
  28683. server:
  28684. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  28685. type: string
  28686. tls:
  28687. description: |-
  28688. The configuration used for client side related TLS communication, when the Vault server
  28689. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  28690. This parameter is ignored for plain HTTP protocol connection.
  28691. It's worth noting this configuration is different from the "TLS certificates auth method",
  28692. which is available under the `auth.cert` section.
  28693. properties:
  28694. certSecretRef:
  28695. description: |-
  28696. CertSecretRef is a certificate added to the transport layer
  28697. when communicating with the Vault server.
  28698. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  28699. properties:
  28700. key:
  28701. description: |-
  28702. A key in the referenced Secret.
  28703. Some instances of this field may be defaulted, in others it may be required.
  28704. maxLength: 253
  28705. minLength: 1
  28706. pattern: ^[-._a-zA-Z0-9]+$
  28707. type: string
  28708. name:
  28709. description: The name of the Secret resource being referred to.
  28710. maxLength: 253
  28711. minLength: 1
  28712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28713. type: string
  28714. namespace:
  28715. description: |-
  28716. The namespace of the Secret resource being referred to.
  28717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28718. maxLength: 63
  28719. minLength: 1
  28720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28721. type: string
  28722. type: object
  28723. keySecretRef:
  28724. description: |-
  28725. KeySecretRef to a key in a Secret resource containing client private key
  28726. added to the transport layer when communicating with the Vault server.
  28727. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  28728. properties:
  28729. key:
  28730. description: |-
  28731. A key in the referenced Secret.
  28732. Some instances of this field may be defaulted, in others it may be required.
  28733. maxLength: 253
  28734. minLength: 1
  28735. pattern: ^[-._a-zA-Z0-9]+$
  28736. type: string
  28737. name:
  28738. description: The name of the Secret resource being referred to.
  28739. maxLength: 253
  28740. minLength: 1
  28741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28742. type: string
  28743. namespace:
  28744. description: |-
  28745. The namespace of the Secret resource being referred to.
  28746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28747. maxLength: 63
  28748. minLength: 1
  28749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28750. type: string
  28751. type: object
  28752. type: object
  28753. version:
  28754. default: v2
  28755. description: |-
  28756. Version is the Vault KV secret engine version. This can be either "v1" or
  28757. "v2". Version defaults to "v2".
  28758. enum:
  28759. - v1
  28760. - v2
  28761. type: string
  28762. required:
  28763. - server
  28764. type: object
  28765. resultType:
  28766. default: Data
  28767. description: |-
  28768. Result type defines which data is returned from the generator.
  28769. By default, it is the "data" section of the Vault API response.
  28770. When using e.g. /auth/token/create the "data" section is empty but
  28771. the "auth" section contains the generated token.
  28772. Please refer to the vault docs regarding the result data structure.
  28773. Additionally, accessing the raw response is possibly by using "Raw" result type.
  28774. enum:
  28775. - Data
  28776. - Auth
  28777. - Raw
  28778. type: string
  28779. retrySettings:
  28780. description: Used to configure http retries if failed
  28781. properties:
  28782. maxRetries:
  28783. format: int32
  28784. type: integer
  28785. retryInterval:
  28786. type: string
  28787. type: object
  28788. required:
  28789. - path
  28790. - provider
  28791. type: object
  28792. webhookSpec:
  28793. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  28794. properties:
  28795. auth:
  28796. description: Auth specifies a authorization protocol. Only one protocol may be set.
  28797. maxProperties: 1
  28798. minProperties: 1
  28799. properties:
  28800. ntlm:
  28801. description: NTLMProtocol configures the store to use NTLM for auth
  28802. properties:
  28803. passwordSecret:
  28804. description: |-
  28805. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28806. In some instances, `key` is a required field.
  28807. properties:
  28808. key:
  28809. description: |-
  28810. A key in the referenced Secret.
  28811. Some instances of this field may be defaulted, in others it may be required.
  28812. maxLength: 253
  28813. minLength: 1
  28814. pattern: ^[-._a-zA-Z0-9]+$
  28815. type: string
  28816. name:
  28817. description: The name of the Secret resource being referred to.
  28818. maxLength: 253
  28819. minLength: 1
  28820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28821. type: string
  28822. namespace:
  28823. description: |-
  28824. The namespace of the Secret resource being referred to.
  28825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28826. maxLength: 63
  28827. minLength: 1
  28828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28829. type: string
  28830. type: object
  28831. usernameSecret:
  28832. description: |-
  28833. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28834. In some instances, `key` is a required field.
  28835. properties:
  28836. key:
  28837. description: |-
  28838. A key in the referenced Secret.
  28839. Some instances of this field may be defaulted, in others it may be required.
  28840. maxLength: 253
  28841. minLength: 1
  28842. pattern: ^[-._a-zA-Z0-9]+$
  28843. type: string
  28844. name:
  28845. description: The name of the Secret resource being referred to.
  28846. maxLength: 253
  28847. minLength: 1
  28848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28849. type: string
  28850. namespace:
  28851. description: |-
  28852. The namespace of the Secret resource being referred to.
  28853. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28854. maxLength: 63
  28855. minLength: 1
  28856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28857. type: string
  28858. type: object
  28859. required:
  28860. - passwordSecret
  28861. - usernameSecret
  28862. type: object
  28863. type: object
  28864. body:
  28865. description: Body
  28866. type: string
  28867. caBundle:
  28868. description: |-
  28869. PEM encoded CA bundle used to validate webhook server certificate. Only used
  28870. if the Server URL is using HTTPS protocol. This parameter is ignored for
  28871. plain HTTP protocol connection. If not set the system root certificates
  28872. are used to validate the TLS connection.
  28873. format: byte
  28874. type: string
  28875. caProvider:
  28876. description: The provider for the CA bundle to use to validate webhook server certificate.
  28877. properties:
  28878. key:
  28879. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  28880. maxLength: 253
  28881. minLength: 1
  28882. pattern: ^[-._a-zA-Z0-9]+$
  28883. type: string
  28884. name:
  28885. description: The name of the object located at the provider type.
  28886. maxLength: 253
  28887. minLength: 1
  28888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28889. type: string
  28890. namespace:
  28891. description: The namespace the Provider type is in.
  28892. maxLength: 63
  28893. minLength: 1
  28894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28895. type: string
  28896. type:
  28897. description: The type of provider to use such as "Secret", or "ConfigMap".
  28898. enum:
  28899. - Secret
  28900. - ConfigMap
  28901. type: string
  28902. required:
  28903. - name
  28904. - type
  28905. type: object
  28906. headers:
  28907. additionalProperties:
  28908. type: string
  28909. description: Headers
  28910. type: object
  28911. method:
  28912. description: Webhook Method
  28913. type: string
  28914. result:
  28915. description: Result formatting
  28916. properties:
  28917. jsonPath:
  28918. description: Json path of return value
  28919. type: string
  28920. type: object
  28921. secrets:
  28922. description: |-
  28923. Secrets to fill in templates
  28924. These secrets will be passed to the templating function as key value pairs under the given name
  28925. items:
  28926. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  28927. properties:
  28928. name:
  28929. description: Name of this secret in templates
  28930. type: string
  28931. secretRef:
  28932. description: Secret ref to fill in credentials
  28933. properties:
  28934. key:
  28935. description: The key where the token is found.
  28936. maxLength: 253
  28937. minLength: 1
  28938. pattern: ^[-._a-zA-Z0-9]+$
  28939. type: string
  28940. name:
  28941. description: The name of the Secret resource being referred to.
  28942. maxLength: 253
  28943. minLength: 1
  28944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28945. type: string
  28946. type: object
  28947. required:
  28948. - name
  28949. - secretRef
  28950. type: object
  28951. type: array
  28952. timeout:
  28953. description: Timeout
  28954. type: string
  28955. url:
  28956. description: Webhook url to call
  28957. type: string
  28958. required:
  28959. - result
  28960. - url
  28961. type: object
  28962. type: object
  28963. kind:
  28964. description: Kind the kind of this generator.
  28965. enum:
  28966. - ACRAccessToken
  28967. - BeyondtrustWorkloadCredentialsDynamicSecret
  28968. - CloudsmithAccessToken
  28969. - ECRAuthorizationToken
  28970. - Fake
  28971. - GCRAccessToken
  28972. - GithubAccessToken
  28973. - GitlabDeployToken
  28974. - QuayAccessToken
  28975. - Password
  28976. - SSHKey
  28977. - STSSessionToken
  28978. - UUID
  28979. - VaultDynamicSecret
  28980. - Webhook
  28981. - Grafana
  28982. - MFA
  28983. type: string
  28984. required:
  28985. - generator
  28986. - kind
  28987. type: object
  28988. type: object
  28989. served: true
  28990. storage: true
  28991. subresources:
  28992. status: {}
  28993. ---
  28994. apiVersion: apiextensions.k8s.io/v1
  28995. kind: CustomResourceDefinition
  28996. metadata:
  28997. annotations:
  28998. controller-gen.kubebuilder.io/version: v0.19.0
  28999. labels:
  29000. external-secrets.io/component: controller
  29001. name: ecrauthorizationtokens.generators.external-secrets.io
  29002. spec:
  29003. group: generators.external-secrets.io
  29004. names:
  29005. categories:
  29006. - external-secrets
  29007. - external-secrets-generators
  29008. kind: ECRAuthorizationToken
  29009. listKind: ECRAuthorizationTokenList
  29010. plural: ecrauthorizationtokens
  29011. singular: ecrauthorizationtoken
  29012. scope: Namespaced
  29013. versions:
  29014. - name: v1alpha1
  29015. schema:
  29016. openAPIV3Schema:
  29017. description: |-
  29018. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29019. The authorization token is valid for 12 hours.
  29020. The authorizationToken returned is a base64 encoded string that can be decoded
  29021. and used in a docker login command to authenticate to a registry.
  29022. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29023. properties:
  29024. apiVersion:
  29025. description: |-
  29026. APIVersion defines the versioned schema of this representation of an object.
  29027. Servers should convert recognized schemas to the latest internal value, and
  29028. may reject unrecognized values.
  29029. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29030. type: string
  29031. kind:
  29032. description: |-
  29033. Kind is a string value representing the REST resource this object represents.
  29034. Servers may infer this from the endpoint the client submits requests to.
  29035. Cannot be updated.
  29036. In CamelCase.
  29037. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29038. type: string
  29039. metadata:
  29040. type: object
  29041. spec:
  29042. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29043. properties:
  29044. auth:
  29045. description: Auth defines how to authenticate with AWS
  29046. properties:
  29047. jwt:
  29048. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29049. properties:
  29050. serviceAccountRef:
  29051. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29052. properties:
  29053. audiences:
  29054. description: |-
  29055. Audience specifies the `aud` claim for the service account token
  29056. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29057. then this audiences will be appended to the list
  29058. items:
  29059. type: string
  29060. type: array
  29061. name:
  29062. description: The name of the ServiceAccount resource being referred to.
  29063. maxLength: 253
  29064. minLength: 1
  29065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29066. type: string
  29067. namespace:
  29068. description: |-
  29069. Namespace of the resource being referred to.
  29070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29071. maxLength: 63
  29072. minLength: 1
  29073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29074. type: string
  29075. required:
  29076. - name
  29077. type: object
  29078. type: object
  29079. secretRef:
  29080. description: |-
  29081. AWSAuthSecretRef holds secret references for AWS credentials
  29082. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29083. properties:
  29084. accessKeyIDSecretRef:
  29085. description: The AccessKeyID is used for authentication
  29086. properties:
  29087. key:
  29088. description: |-
  29089. A key in the referenced Secret.
  29090. Some instances of this field may be defaulted, in others it may be required.
  29091. maxLength: 253
  29092. minLength: 1
  29093. pattern: ^[-._a-zA-Z0-9]+$
  29094. type: string
  29095. name:
  29096. description: The name of the Secret resource being referred to.
  29097. maxLength: 253
  29098. minLength: 1
  29099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29100. type: string
  29101. namespace:
  29102. description: |-
  29103. The namespace of the Secret resource being referred to.
  29104. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29105. maxLength: 63
  29106. minLength: 1
  29107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29108. type: string
  29109. type: object
  29110. secretAccessKeySecretRef:
  29111. description: The SecretAccessKey is used for authentication
  29112. properties:
  29113. key:
  29114. description: |-
  29115. A key in the referenced Secret.
  29116. Some instances of this field may be defaulted, in others it may be required.
  29117. maxLength: 253
  29118. minLength: 1
  29119. pattern: ^[-._a-zA-Z0-9]+$
  29120. type: string
  29121. name:
  29122. description: The name of the Secret resource being referred to.
  29123. maxLength: 253
  29124. minLength: 1
  29125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29126. type: string
  29127. namespace:
  29128. description: |-
  29129. The namespace of the Secret resource being referred to.
  29130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29131. maxLength: 63
  29132. minLength: 1
  29133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29134. type: string
  29135. type: object
  29136. sessionTokenSecretRef:
  29137. description: |-
  29138. The SessionToken used for authentication
  29139. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29140. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29141. properties:
  29142. key:
  29143. description: |-
  29144. A key in the referenced Secret.
  29145. Some instances of this field may be defaulted, in others it may be required.
  29146. maxLength: 253
  29147. minLength: 1
  29148. pattern: ^[-._a-zA-Z0-9]+$
  29149. type: string
  29150. name:
  29151. description: The name of the Secret resource being referred to.
  29152. maxLength: 253
  29153. minLength: 1
  29154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29155. type: string
  29156. namespace:
  29157. description: |-
  29158. The namespace of the Secret resource being referred to.
  29159. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29160. maxLength: 63
  29161. minLength: 1
  29162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29163. type: string
  29164. type: object
  29165. type: object
  29166. type: object
  29167. region:
  29168. description: Region specifies the region to operate in.
  29169. type: string
  29170. role:
  29171. description: |-
  29172. You can assume a role before making calls to the
  29173. desired AWS service.
  29174. type: string
  29175. scope:
  29176. description: |-
  29177. Scope specifies the ECR service scope.
  29178. Valid options are private and public.
  29179. type: string
  29180. required:
  29181. - region
  29182. type: object
  29183. type: object
  29184. served: true
  29185. storage: true
  29186. subresources:
  29187. status: {}
  29188. ---
  29189. apiVersion: apiextensions.k8s.io/v1
  29190. kind: CustomResourceDefinition
  29191. metadata:
  29192. annotations:
  29193. controller-gen.kubebuilder.io/version: v0.19.0
  29194. labels:
  29195. external-secrets.io/component: controller
  29196. name: fakes.generators.external-secrets.io
  29197. spec:
  29198. group: generators.external-secrets.io
  29199. names:
  29200. categories:
  29201. - external-secrets
  29202. - external-secrets-generators
  29203. kind: Fake
  29204. listKind: FakeList
  29205. plural: fakes
  29206. singular: fake
  29207. scope: Namespaced
  29208. versions:
  29209. - name: v1alpha1
  29210. schema:
  29211. openAPIV3Schema:
  29212. description: |-
  29213. Fake generator is used for testing. It lets you define
  29214. a static set of credentials that is always returned.
  29215. properties:
  29216. apiVersion:
  29217. description: |-
  29218. APIVersion defines the versioned schema of this representation of an object.
  29219. Servers should convert recognized schemas to the latest internal value, and
  29220. may reject unrecognized values.
  29221. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29222. type: string
  29223. kind:
  29224. description: |-
  29225. Kind is a string value representing the REST resource this object represents.
  29226. Servers may infer this from the endpoint the client submits requests to.
  29227. Cannot be updated.
  29228. In CamelCase.
  29229. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29230. type: string
  29231. metadata:
  29232. type: object
  29233. spec:
  29234. description: FakeSpec contains the static data.
  29235. properties:
  29236. controller:
  29237. description: |-
  29238. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29239. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29240. type: string
  29241. data:
  29242. additionalProperties:
  29243. type: string
  29244. description: |-
  29245. Data defines the static data returned
  29246. by this generator.
  29247. type: object
  29248. type: object
  29249. type: object
  29250. served: true
  29251. storage: true
  29252. subresources:
  29253. status: {}
  29254. ---
  29255. apiVersion: apiextensions.k8s.io/v1
  29256. kind: CustomResourceDefinition
  29257. metadata:
  29258. annotations:
  29259. controller-gen.kubebuilder.io/version: v0.19.0
  29260. labels:
  29261. external-secrets.io/component: controller
  29262. name: gcraccesstokens.generators.external-secrets.io
  29263. spec:
  29264. group: generators.external-secrets.io
  29265. names:
  29266. categories:
  29267. - external-secrets
  29268. - external-secrets-generators
  29269. kind: GCRAccessToken
  29270. listKind: GCRAccessTokenList
  29271. plural: gcraccesstokens
  29272. singular: gcraccesstoken
  29273. scope: Namespaced
  29274. versions:
  29275. - name: v1alpha1
  29276. schema:
  29277. openAPIV3Schema:
  29278. description: |-
  29279. GCRAccessToken generates an GCP access token
  29280. that can be used to authenticate with GCR.
  29281. properties:
  29282. apiVersion:
  29283. description: |-
  29284. APIVersion defines the versioned schema of this representation of an object.
  29285. Servers should convert recognized schemas to the latest internal value, and
  29286. may reject unrecognized values.
  29287. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29288. type: string
  29289. kind:
  29290. description: |-
  29291. Kind is a string value representing the REST resource this object represents.
  29292. Servers may infer this from the endpoint the client submits requests to.
  29293. Cannot be updated.
  29294. In CamelCase.
  29295. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29296. type: string
  29297. metadata:
  29298. type: object
  29299. spec:
  29300. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  29301. properties:
  29302. auth:
  29303. description: Auth defines the means for authenticating with GCP
  29304. properties:
  29305. secretRef:
  29306. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  29307. properties:
  29308. secretAccessKeySecretRef:
  29309. description: The SecretAccessKey is used for authentication
  29310. properties:
  29311. key:
  29312. description: |-
  29313. A key in the referenced Secret.
  29314. Some instances of this field may be defaulted, in others it may be required.
  29315. maxLength: 253
  29316. minLength: 1
  29317. pattern: ^[-._a-zA-Z0-9]+$
  29318. type: string
  29319. name:
  29320. description: The name of the Secret resource being referred to.
  29321. maxLength: 253
  29322. minLength: 1
  29323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29324. type: string
  29325. namespace:
  29326. description: |-
  29327. The namespace of the Secret resource being referred to.
  29328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29329. maxLength: 63
  29330. minLength: 1
  29331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29332. type: string
  29333. type: object
  29334. type: object
  29335. workloadIdentity:
  29336. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  29337. properties:
  29338. clusterLocation:
  29339. type: string
  29340. clusterName:
  29341. type: string
  29342. clusterProjectID:
  29343. type: string
  29344. serviceAccountRef:
  29345. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29346. properties:
  29347. audiences:
  29348. description: |-
  29349. Audience specifies the `aud` claim for the service account token
  29350. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29351. then this audiences will be appended to the list
  29352. items:
  29353. type: string
  29354. type: array
  29355. name:
  29356. description: The name of the ServiceAccount resource being referred to.
  29357. maxLength: 253
  29358. minLength: 1
  29359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29360. type: string
  29361. namespace:
  29362. description: |-
  29363. Namespace of the resource being referred to.
  29364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29365. maxLength: 63
  29366. minLength: 1
  29367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29368. type: string
  29369. required:
  29370. - name
  29371. type: object
  29372. required:
  29373. - clusterLocation
  29374. - clusterName
  29375. - serviceAccountRef
  29376. type: object
  29377. workloadIdentityFederation:
  29378. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  29379. properties:
  29380. audience:
  29381. description: |-
  29382. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  29383. If specified, Audience found in the external account credential config will be overridden with the configured value.
  29384. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  29385. type: string
  29386. awsSecurityCredentials:
  29387. description: |-
  29388. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  29389. when using the AWS metadata server is not an option.
  29390. properties:
  29391. awsCredentialsSecretRef:
  29392. description: |-
  29393. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  29394. Secret should be created with below names for keys
  29395. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  29396. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  29397. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  29398. properties:
  29399. name:
  29400. description: name of the secret.
  29401. maxLength: 253
  29402. minLength: 1
  29403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29404. type: string
  29405. namespace:
  29406. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  29407. maxLength: 63
  29408. minLength: 1
  29409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29410. type: string
  29411. required:
  29412. - name
  29413. type: object
  29414. region:
  29415. description: region is for configuring the AWS region to be used.
  29416. example: ap-south-1
  29417. maxLength: 50
  29418. minLength: 1
  29419. pattern: ^[a-z0-9-]+$
  29420. type: string
  29421. required:
  29422. - awsCredentialsSecretRef
  29423. - region
  29424. type: object
  29425. credConfig:
  29426. description: |-
  29427. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  29428. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  29429. serviceAccountRef must be used by providing operators service account details.
  29430. properties:
  29431. key:
  29432. description: key name holding the external account credential config.
  29433. maxLength: 253
  29434. minLength: 1
  29435. pattern: ^[-._a-zA-Z0-9]+$
  29436. type: string
  29437. name:
  29438. description: name of the configmap.
  29439. maxLength: 253
  29440. minLength: 1
  29441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29442. type: string
  29443. namespace:
  29444. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  29445. maxLength: 63
  29446. minLength: 1
  29447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29448. type: string
  29449. required:
  29450. - key
  29451. - name
  29452. type: object
  29453. externalTokenEndpoint:
  29454. description: |-
  29455. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  29456. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  29457. URL is having the expected value.
  29458. type: string
  29459. gcpServiceAccountEmail:
  29460. description: |-
  29461. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  29462. after Workload Identity Federation. Use this to grant access through the service account's
  29463. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  29464. service_account_impersonation_url in the external account JSON from credConfig;
  29465. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  29466. on that ServiceAccount.
  29467. example: my-gsa@my-project.iam.gserviceaccount.com
  29468. minLength: 1
  29469. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  29470. type: string
  29471. serviceAccountRef:
  29472. description: |-
  29473. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  29474. when Kubernetes is configured as provider in workload identity pool.
  29475. properties:
  29476. audiences:
  29477. description: |-
  29478. Audience specifies the `aud` claim for the service account token
  29479. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29480. then this audiences will be appended to the list
  29481. items:
  29482. type: string
  29483. type: array
  29484. name:
  29485. description: The name of the ServiceAccount resource being referred to.
  29486. maxLength: 253
  29487. minLength: 1
  29488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29489. type: string
  29490. namespace:
  29491. description: |-
  29492. Namespace of the resource being referred to.
  29493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29494. maxLength: 63
  29495. minLength: 1
  29496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29497. type: string
  29498. required:
  29499. - name
  29500. type: object
  29501. type: object
  29502. type: object
  29503. projectID:
  29504. description: ProjectID defines which project to use to authenticate with
  29505. type: string
  29506. required:
  29507. - auth
  29508. - projectID
  29509. type: object
  29510. type: object
  29511. served: true
  29512. storage: true
  29513. subresources:
  29514. status: {}
  29515. ---
  29516. apiVersion: apiextensions.k8s.io/v1
  29517. kind: CustomResourceDefinition
  29518. metadata:
  29519. annotations:
  29520. controller-gen.kubebuilder.io/version: v0.19.0
  29521. labels:
  29522. external-secrets.io/component: controller
  29523. name: generatorstates.generators.external-secrets.io
  29524. spec:
  29525. group: generators.external-secrets.io
  29526. names:
  29527. categories:
  29528. - external-secrets
  29529. - external-secrets-generators
  29530. kind: GeneratorState
  29531. listKind: GeneratorStateList
  29532. plural: generatorstates
  29533. shortNames:
  29534. - gs
  29535. singular: generatorstate
  29536. scope: Namespaced
  29537. versions:
  29538. - additionalPrinterColumns:
  29539. - jsonPath: .spec.garbageCollectionDeadline
  29540. name: GC Deadline
  29541. type: string
  29542. - jsonPath: .metadata.creationTimestamp
  29543. name: Age
  29544. type: date
  29545. name: v1alpha1
  29546. schema:
  29547. openAPIV3Schema:
  29548. description: GeneratorState represents the state created and managed by a generator resource.
  29549. properties:
  29550. apiVersion:
  29551. description: |-
  29552. APIVersion defines the versioned schema of this representation of an object.
  29553. Servers should convert recognized schemas to the latest internal value, and
  29554. may reject unrecognized values.
  29555. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29556. type: string
  29557. kind:
  29558. description: |-
  29559. Kind is a string value representing the REST resource this object represents.
  29560. Servers may infer this from the endpoint the client submits requests to.
  29561. Cannot be updated.
  29562. In CamelCase.
  29563. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29564. type: string
  29565. metadata:
  29566. type: object
  29567. spec:
  29568. description: GeneratorStateSpec defines the desired state of a generator state resource.
  29569. properties:
  29570. garbageCollectionDeadline:
  29571. description: |-
  29572. GarbageCollectionDeadline is the time after which the generator state
  29573. will be deleted.
  29574. It is set by the controller which creates the generator state and
  29575. can be set configured by the user.
  29576. If the garbage collection deadline is not set the generator state will not be deleted.
  29577. format: date-time
  29578. type: string
  29579. resource:
  29580. description: |-
  29581. Resource is the generator manifest that produced the state.
  29582. It is a snapshot of the generator manifest at the time the state was produced.
  29583. This manifest will be used to delete the resource. Any configuration that is referenced
  29584. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  29585. be blocked by a finalizer.
  29586. x-kubernetes-preserve-unknown-fields: true
  29587. state:
  29588. description: State is the state that was produced by the generator implementation.
  29589. x-kubernetes-preserve-unknown-fields: true
  29590. required:
  29591. - resource
  29592. - state
  29593. type: object
  29594. status:
  29595. description: GeneratorStateStatus defines the observed state of a generator state resource.
  29596. properties:
  29597. conditions:
  29598. items:
  29599. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  29600. properties:
  29601. lastTransitionTime:
  29602. format: date-time
  29603. type: string
  29604. message:
  29605. type: string
  29606. reason:
  29607. type: string
  29608. status:
  29609. type: string
  29610. type:
  29611. description: GeneratorStateConditionType represents the type of condition for a generator state.
  29612. type: string
  29613. required:
  29614. - status
  29615. - type
  29616. type: object
  29617. type: array
  29618. type: object
  29619. type: object
  29620. served: true
  29621. storage: true
  29622. subresources: {}
  29623. ---
  29624. apiVersion: apiextensions.k8s.io/v1
  29625. kind: CustomResourceDefinition
  29626. metadata:
  29627. annotations:
  29628. controller-gen.kubebuilder.io/version: v0.19.0
  29629. labels:
  29630. external-secrets.io/component: controller
  29631. name: githubaccesstokens.generators.external-secrets.io
  29632. spec:
  29633. group: generators.external-secrets.io
  29634. names:
  29635. categories:
  29636. - external-secrets
  29637. - external-secrets-generators
  29638. kind: GithubAccessToken
  29639. listKind: GithubAccessTokenList
  29640. plural: githubaccesstokens
  29641. singular: githubaccesstoken
  29642. scope: Namespaced
  29643. versions:
  29644. - name: v1alpha1
  29645. schema:
  29646. openAPIV3Schema:
  29647. description: GithubAccessToken generates ghs_ accessToken
  29648. properties:
  29649. apiVersion:
  29650. description: |-
  29651. APIVersion defines the versioned schema of this representation of an object.
  29652. Servers should convert recognized schemas to the latest internal value, and
  29653. may reject unrecognized values.
  29654. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29655. type: string
  29656. kind:
  29657. description: |-
  29658. Kind is a string value representing the REST resource this object represents.
  29659. Servers may infer this from the endpoint the client submits requests to.
  29660. Cannot be updated.
  29661. In CamelCase.
  29662. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29663. type: string
  29664. metadata:
  29665. type: object
  29666. spec:
  29667. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  29668. properties:
  29669. appID:
  29670. type: string
  29671. auth:
  29672. description: Auth configures how ESO authenticates with a Github instance.
  29673. properties:
  29674. privateKey:
  29675. description: GithubSecretRef references a secret containing GitHub credentials.
  29676. properties:
  29677. secretRef:
  29678. description: |-
  29679. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29680. In some instances, `key` is a required field.
  29681. properties:
  29682. key:
  29683. description: |-
  29684. A key in the referenced Secret.
  29685. Some instances of this field may be defaulted, in others it may be required.
  29686. maxLength: 253
  29687. minLength: 1
  29688. pattern: ^[-._a-zA-Z0-9]+$
  29689. type: string
  29690. name:
  29691. description: The name of the Secret resource being referred to.
  29692. maxLength: 253
  29693. minLength: 1
  29694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29695. type: string
  29696. namespace:
  29697. description: |-
  29698. The namespace of the Secret resource being referred to.
  29699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29700. maxLength: 63
  29701. minLength: 1
  29702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29703. type: string
  29704. type: object
  29705. required:
  29706. - secretRef
  29707. type: object
  29708. required:
  29709. - privateKey
  29710. type: object
  29711. installID:
  29712. type: string
  29713. permissions:
  29714. additionalProperties:
  29715. type: string
  29716. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  29717. type: object
  29718. repositories:
  29719. description: |-
  29720. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  29721. is installed to.
  29722. items:
  29723. type: string
  29724. type: array
  29725. url:
  29726. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  29727. type: string
  29728. required:
  29729. - appID
  29730. - auth
  29731. - installID
  29732. type: object
  29733. type: object
  29734. served: true
  29735. storage: true
  29736. subresources:
  29737. status: {}
  29738. ---
  29739. apiVersion: apiextensions.k8s.io/v1
  29740. kind: CustomResourceDefinition
  29741. metadata:
  29742. annotations:
  29743. controller-gen.kubebuilder.io/version: v0.19.0
  29744. labels:
  29745. external-secrets.io/component: controller
  29746. name: gitlabdeploytokens.generators.external-secrets.io
  29747. spec:
  29748. group: generators.external-secrets.io
  29749. names:
  29750. categories:
  29751. - external-secrets
  29752. - external-secrets-generators
  29753. kind: GitlabDeployToken
  29754. listKind: GitlabDeployTokenList
  29755. plural: gitlabdeploytokens
  29756. singular: gitlabdeploytoken
  29757. scope: Namespaced
  29758. versions:
  29759. - name: v1alpha1
  29760. schema:
  29761. openAPIV3Schema:
  29762. description: GitlabDeployToken generates a GitLab deploy token.
  29763. properties:
  29764. apiVersion:
  29765. description: |-
  29766. APIVersion defines the versioned schema of this representation of an object.
  29767. Servers should convert recognized schemas to the latest internal value, and
  29768. may reject unrecognized values.
  29769. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29770. type: string
  29771. kind:
  29772. description: |-
  29773. Kind is a string value representing the REST resource this object represents.
  29774. Servers may infer this from the endpoint the client submits requests to.
  29775. Cannot be updated.
  29776. In CamelCase.
  29777. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29778. type: string
  29779. metadata:
  29780. type: object
  29781. spec:
  29782. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  29783. properties:
  29784. auth:
  29785. description: Auth configures how ESO authenticates with the GitLab API.
  29786. properties:
  29787. token:
  29788. description: |-
  29789. Token references a secret containing a GitLab access token (personal, group, or
  29790. project) with the api scope and at least the Maintainer role on the target.
  29791. properties:
  29792. secretRef:
  29793. description: |-
  29794. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29795. In some instances, `key` is a required field.
  29796. properties:
  29797. key:
  29798. description: |-
  29799. A key in the referenced Secret.
  29800. Some instances of this field may be defaulted, in others it may be required.
  29801. maxLength: 253
  29802. minLength: 1
  29803. pattern: ^[-._a-zA-Z0-9]+$
  29804. type: string
  29805. name:
  29806. description: The name of the Secret resource being referred to.
  29807. maxLength: 253
  29808. minLength: 1
  29809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29810. type: string
  29811. namespace:
  29812. description: |-
  29813. The namespace of the Secret resource being referred to.
  29814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29815. maxLength: 63
  29816. minLength: 1
  29817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29818. type: string
  29819. type: object
  29820. required:
  29821. - secretRef
  29822. type: object
  29823. required:
  29824. - token
  29825. type: object
  29826. expiresAt:
  29827. description: |-
  29828. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  29829. not expire on the GitLab side and is revoked only when the generator state is
  29830. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  29831. format: date-time
  29832. type: string
  29833. groupID:
  29834. description: |-
  29835. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  29836. create the deploy token in. The generator URL-escapes paths before calling the
  29837. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  29838. minLength: 1
  29839. type: string
  29840. name:
  29841. description: Name of the deploy token.
  29842. minLength: 1
  29843. type: string
  29844. projectID:
  29845. description: |-
  29846. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  29847. project to create the deploy token in. The generator URL-escapes paths before
  29848. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  29849. minLength: 1
  29850. type: string
  29851. scopes:
  29852. description: Scopes granted to the deploy token. At least one scope is required.
  29853. items:
  29854. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  29855. enum:
  29856. - read_repository
  29857. - read_registry
  29858. - write_registry
  29859. - read_package_registry
  29860. - write_package_registry
  29861. - read_virtual_registry
  29862. - write_virtual_registry
  29863. type: string
  29864. minItems: 1
  29865. type: array
  29866. url:
  29867. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  29868. type: string
  29869. username:
  29870. description: |-
  29871. Username is an optional username for the deploy token. GitLab defaults it to
  29872. gitlab+deploy-token-{n} when omitted.
  29873. type: string
  29874. required:
  29875. - auth
  29876. - name
  29877. - scopes
  29878. type: object
  29879. x-kubernetes-validations:
  29880. - message: exactly one of projectID or groupID must be set
  29881. rule: has(self.projectID) != has(self.groupID)
  29882. type: object
  29883. served: true
  29884. storage: true
  29885. subresources:
  29886. status: {}
  29887. ---
  29888. apiVersion: apiextensions.k8s.io/v1
  29889. kind: CustomResourceDefinition
  29890. metadata:
  29891. annotations:
  29892. controller-gen.kubebuilder.io/version: v0.19.0
  29893. labels:
  29894. external-secrets.io/component: controller
  29895. name: grafanas.generators.external-secrets.io
  29896. spec:
  29897. group: generators.external-secrets.io
  29898. names:
  29899. categories:
  29900. - external-secrets
  29901. - external-secrets-generators
  29902. kind: Grafana
  29903. listKind: GrafanaList
  29904. plural: grafanas
  29905. singular: grafana
  29906. scope: Namespaced
  29907. versions:
  29908. - name: v1alpha1
  29909. schema:
  29910. openAPIV3Schema:
  29911. description: Grafana represents a generator for Grafana service account tokens.
  29912. properties:
  29913. apiVersion:
  29914. description: |-
  29915. APIVersion defines the versioned schema of this representation of an object.
  29916. Servers should convert recognized schemas to the latest internal value, and
  29917. may reject unrecognized values.
  29918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29919. type: string
  29920. kind:
  29921. description: |-
  29922. Kind is a string value representing the REST resource this object represents.
  29923. Servers may infer this from the endpoint the client submits requests to.
  29924. Cannot be updated.
  29925. In CamelCase.
  29926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29927. type: string
  29928. metadata:
  29929. type: object
  29930. spec:
  29931. description: GrafanaSpec controls the behavior of the grafana generator.
  29932. properties:
  29933. auth:
  29934. description: |-
  29935. Auth is the authentication configuration to authenticate
  29936. against the Grafana instance.
  29937. properties:
  29938. basic:
  29939. description: |-
  29940. Basic auth credentials used to authenticate against the Grafana instance.
  29941. Note: you need a token which has elevated permissions to create service accounts.
  29942. See here for the documentation on basic roles offered by Grafana:
  29943. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  29944. properties:
  29945. password:
  29946. description: A basic auth password used to authenticate against the Grafana instance.
  29947. properties:
  29948. key:
  29949. description: The key where the token is found.
  29950. maxLength: 253
  29951. minLength: 1
  29952. pattern: ^[-._a-zA-Z0-9]+$
  29953. type: string
  29954. name:
  29955. description: The name of the Secret resource being referred to.
  29956. maxLength: 253
  29957. minLength: 1
  29958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29959. type: string
  29960. type: object
  29961. username:
  29962. description: A basic auth username used to authenticate against the Grafana instance.
  29963. type: string
  29964. required:
  29965. - password
  29966. - username
  29967. type: object
  29968. token:
  29969. description: |-
  29970. A service account token used to authenticate against the Grafana instance.
  29971. Note: you need a token which has elevated permissions to create service accounts.
  29972. See here for the documentation on basic roles offered by Grafana:
  29973. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  29974. properties:
  29975. key:
  29976. description: The key where the token is found.
  29977. maxLength: 253
  29978. minLength: 1
  29979. pattern: ^[-._a-zA-Z0-9]+$
  29980. type: string
  29981. name:
  29982. description: The name of the Secret resource being referred to.
  29983. maxLength: 253
  29984. minLength: 1
  29985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29986. type: string
  29987. type: object
  29988. type: object
  29989. serviceAccount:
  29990. description: |-
  29991. ServiceAccount is the configuration for the service account that
  29992. is supposed to be generated by the generator.
  29993. properties:
  29994. name:
  29995. description: Name is the name of the service account that will be created by ESO.
  29996. type: string
  29997. role:
  29998. description: |-
  29999. Role is the role of the service account.
  30000. See here for the documentation on basic roles offered by Grafana:
  30001. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30002. type: string
  30003. secondsToLive:
  30004. description: |-
  30005. SecondsToLive is the number of seconds before the generated service account token will expire.
  30006. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30007. format: int64
  30008. minimum: 1
  30009. type: integer
  30010. required:
  30011. - name
  30012. - role
  30013. type: object
  30014. url:
  30015. description: URL is the URL of the Grafana instance.
  30016. type: string
  30017. required:
  30018. - auth
  30019. - serviceAccount
  30020. - url
  30021. type: object
  30022. type: object
  30023. served: true
  30024. storage: true
  30025. subresources:
  30026. status: {}
  30027. ---
  30028. apiVersion: apiextensions.k8s.io/v1
  30029. kind: CustomResourceDefinition
  30030. metadata:
  30031. annotations:
  30032. controller-gen.kubebuilder.io/version: v0.19.0
  30033. labels:
  30034. external-secrets.io/component: controller
  30035. name: mfas.generators.external-secrets.io
  30036. spec:
  30037. group: generators.external-secrets.io
  30038. names:
  30039. categories:
  30040. - external-secrets
  30041. - external-secrets-generators
  30042. kind: MFA
  30043. listKind: MFAList
  30044. plural: mfas
  30045. singular: mfa
  30046. scope: Namespaced
  30047. versions:
  30048. - name: v1alpha1
  30049. schema:
  30050. openAPIV3Schema:
  30051. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30052. properties:
  30053. apiVersion:
  30054. description: |-
  30055. APIVersion defines the versioned schema of this representation of an object.
  30056. Servers should convert recognized schemas to the latest internal value, and
  30057. may reject unrecognized values.
  30058. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30059. type: string
  30060. kind:
  30061. description: |-
  30062. Kind is a string value representing the REST resource this object represents.
  30063. Servers may infer this from the endpoint the client submits requests to.
  30064. Cannot be updated.
  30065. In CamelCase.
  30066. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30067. type: string
  30068. metadata:
  30069. type: object
  30070. spec:
  30071. description: MFASpec controls the behavior of the mfa generator.
  30072. properties:
  30073. algorithm:
  30074. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30075. type: string
  30076. length:
  30077. description: Length defines the token length. Defaults to 6 characters.
  30078. type: integer
  30079. secret:
  30080. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30081. properties:
  30082. key:
  30083. description: |-
  30084. A key in the referenced Secret.
  30085. Some instances of this field may be defaulted, in others it may be required.
  30086. maxLength: 253
  30087. minLength: 1
  30088. pattern: ^[-._a-zA-Z0-9]+$
  30089. type: string
  30090. name:
  30091. description: The name of the Secret resource being referred to.
  30092. maxLength: 253
  30093. minLength: 1
  30094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30095. type: string
  30096. namespace:
  30097. description: |-
  30098. The namespace of the Secret resource being referred to.
  30099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30100. maxLength: 63
  30101. minLength: 1
  30102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30103. type: string
  30104. type: object
  30105. timePeriod:
  30106. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30107. type: integer
  30108. when:
  30109. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30110. format: date-time
  30111. type: string
  30112. required:
  30113. - secret
  30114. type: object
  30115. type: object
  30116. served: true
  30117. storage: true
  30118. subresources:
  30119. status: {}
  30120. ---
  30121. apiVersion: apiextensions.k8s.io/v1
  30122. kind: CustomResourceDefinition
  30123. metadata:
  30124. annotations:
  30125. controller-gen.kubebuilder.io/version: v0.19.0
  30126. labels:
  30127. external-secrets.io/component: controller
  30128. name: passwords.generators.external-secrets.io
  30129. spec:
  30130. group: generators.external-secrets.io
  30131. names:
  30132. categories:
  30133. - external-secrets
  30134. - external-secrets-generators
  30135. kind: Password
  30136. listKind: PasswordList
  30137. plural: passwords
  30138. singular: password
  30139. scope: Namespaced
  30140. versions:
  30141. - name: v1alpha1
  30142. schema:
  30143. openAPIV3Schema:
  30144. description: |-
  30145. Password generates a random password based on the
  30146. configuration parameters in spec.
  30147. You can specify the length, characterset and other attributes.
  30148. properties:
  30149. apiVersion:
  30150. description: |-
  30151. APIVersion defines the versioned schema of this representation of an object.
  30152. Servers should convert recognized schemas to the latest internal value, and
  30153. may reject unrecognized values.
  30154. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30155. type: string
  30156. kind:
  30157. description: |-
  30158. Kind is a string value representing the REST resource this object represents.
  30159. Servers may infer this from the endpoint the client submits requests to.
  30160. Cannot be updated.
  30161. In CamelCase.
  30162. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30163. type: string
  30164. metadata:
  30165. type: object
  30166. spec:
  30167. description: PasswordSpec controls the behavior of the password generator.
  30168. properties:
  30169. allowRepeat:
  30170. default: false
  30171. description: set AllowRepeat to true to allow repeating characters.
  30172. type: boolean
  30173. digits:
  30174. description: |-
  30175. Digits specifies the number of digits in the generated
  30176. password. If omitted it defaults to 25% of the length of the password
  30177. type: integer
  30178. encoding:
  30179. default: raw
  30180. description: |-
  30181. Encoding specifies the encoding of the generated password.
  30182. Valid values are:
  30183. - "raw" (default): no encoding
  30184. - "base64": standard base64 encoding
  30185. - "base64url": base64url encoding
  30186. - "base32": base32 encoding
  30187. - "hex": hexadecimal encoding
  30188. enum:
  30189. - base64
  30190. - base64url
  30191. - base32
  30192. - hex
  30193. - raw
  30194. type: string
  30195. length:
  30196. default: 24
  30197. description: |-
  30198. Length of the password to be generated.
  30199. Defaults to 24
  30200. type: integer
  30201. noUpper:
  30202. default: false
  30203. description: Set NoUpper to disable uppercase characters
  30204. type: boolean
  30205. secretKeys:
  30206. description: |-
  30207. SecretKeys defines the keys that will be populated with generated passwords.
  30208. Defaults to "password" when not set.
  30209. items:
  30210. type: string
  30211. minItems: 1
  30212. type: array
  30213. symbolCharacters:
  30214. description: |-
  30215. SymbolCharacters specifies the special characters that should be used
  30216. in the generated password.
  30217. type: string
  30218. symbols:
  30219. description: |-
  30220. Symbols specifies the number of symbol characters in the generated
  30221. password. If omitted it defaults to 25% of the length of the password
  30222. type: integer
  30223. required:
  30224. - allowRepeat
  30225. - length
  30226. - noUpper
  30227. type: object
  30228. type: object
  30229. served: true
  30230. storage: true
  30231. subresources:
  30232. status: {}
  30233. ---
  30234. apiVersion: apiextensions.k8s.io/v1
  30235. kind: CustomResourceDefinition
  30236. metadata:
  30237. annotations:
  30238. controller-gen.kubebuilder.io/version: v0.19.0
  30239. labels:
  30240. external-secrets.io/component: controller
  30241. name: quayaccesstokens.generators.external-secrets.io
  30242. spec:
  30243. group: generators.external-secrets.io
  30244. names:
  30245. categories:
  30246. - external-secrets
  30247. - external-secrets-generators
  30248. kind: QuayAccessToken
  30249. listKind: QuayAccessTokenList
  30250. plural: quayaccesstokens
  30251. singular: quayaccesstoken
  30252. scope: Namespaced
  30253. versions:
  30254. - name: v1alpha1
  30255. schema:
  30256. openAPIV3Schema:
  30257. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30258. properties:
  30259. apiVersion:
  30260. description: |-
  30261. APIVersion defines the versioned schema of this representation of an object.
  30262. Servers should convert recognized schemas to the latest internal value, and
  30263. may reject unrecognized values.
  30264. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30265. type: string
  30266. kind:
  30267. description: |-
  30268. Kind is a string value representing the REST resource this object represents.
  30269. Servers may infer this from the endpoint the client submits requests to.
  30270. Cannot be updated.
  30271. In CamelCase.
  30272. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30273. type: string
  30274. metadata:
  30275. type: object
  30276. spec:
  30277. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30278. properties:
  30279. robotAccount:
  30280. description: Name of the robot account you are federating with
  30281. type: string
  30282. serviceAccountRef:
  30283. description: Name of the service account you are federating with
  30284. properties:
  30285. audiences:
  30286. description: |-
  30287. Audience specifies the `aud` claim for the service account token
  30288. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30289. then this audiences will be appended to the list
  30290. items:
  30291. type: string
  30292. type: array
  30293. name:
  30294. description: The name of the ServiceAccount resource being referred to.
  30295. maxLength: 253
  30296. minLength: 1
  30297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30298. type: string
  30299. namespace:
  30300. description: |-
  30301. Namespace of the resource being referred to.
  30302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30303. maxLength: 63
  30304. minLength: 1
  30305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30306. type: string
  30307. required:
  30308. - name
  30309. type: object
  30310. url:
  30311. description: URL configures the Quay instance URL. Defaults to quay.io.
  30312. type: string
  30313. required:
  30314. - robotAccount
  30315. - serviceAccountRef
  30316. type: object
  30317. type: object
  30318. served: true
  30319. storage: true
  30320. subresources:
  30321. status: {}
  30322. ---
  30323. apiVersion: apiextensions.k8s.io/v1
  30324. kind: CustomResourceDefinition
  30325. metadata:
  30326. annotations:
  30327. controller-gen.kubebuilder.io/version: v0.19.0
  30328. labels:
  30329. external-secrets.io/component: controller
  30330. name: sshkeys.generators.external-secrets.io
  30331. spec:
  30332. group: generators.external-secrets.io
  30333. names:
  30334. categories:
  30335. - external-secrets
  30336. - external-secrets-generators
  30337. kind: SSHKey
  30338. listKind: SSHKeyList
  30339. plural: sshkeys
  30340. singular: sshkey
  30341. scope: Namespaced
  30342. versions:
  30343. - name: v1alpha1
  30344. schema:
  30345. openAPIV3Schema:
  30346. description: SSHKey generates SSH key pairs.
  30347. properties:
  30348. apiVersion:
  30349. description: |-
  30350. APIVersion defines the versioned schema of this representation of an object.
  30351. Servers should convert recognized schemas to the latest internal value, and
  30352. may reject unrecognized values.
  30353. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30354. type: string
  30355. kind:
  30356. description: |-
  30357. Kind is a string value representing the REST resource this object represents.
  30358. Servers may infer this from the endpoint the client submits requests to.
  30359. Cannot be updated.
  30360. In CamelCase.
  30361. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30362. type: string
  30363. metadata:
  30364. type: object
  30365. spec:
  30366. description: SSHKeySpec controls the behavior of the ssh key generator.
  30367. properties:
  30368. comment:
  30369. description: Comment specifies an optional comment for the SSH key
  30370. type: string
  30371. keySize:
  30372. description: |-
  30373. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  30374. For RSA keys: 2048, 3072, 4096
  30375. For ECDSA keys: 256, 384, 521
  30376. Ignored for ed25519 keys
  30377. maximum: 8192
  30378. minimum: 256
  30379. type: integer
  30380. keyType:
  30381. default: rsa
  30382. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  30383. enum:
  30384. - rsa
  30385. - ecdsa
  30386. - ed25519
  30387. type: string
  30388. type: object
  30389. type: object
  30390. served: true
  30391. storage: true
  30392. subresources:
  30393. status: {}
  30394. ---
  30395. apiVersion: apiextensions.k8s.io/v1
  30396. kind: CustomResourceDefinition
  30397. metadata:
  30398. annotations:
  30399. controller-gen.kubebuilder.io/version: v0.19.0
  30400. labels:
  30401. external-secrets.io/component: controller
  30402. name: stssessiontokens.generators.external-secrets.io
  30403. spec:
  30404. group: generators.external-secrets.io
  30405. names:
  30406. categories:
  30407. - external-secrets
  30408. - external-secrets-generators
  30409. kind: STSSessionToken
  30410. listKind: STSSessionTokenList
  30411. plural: stssessiontokens
  30412. singular: stssessiontoken
  30413. scope: Namespaced
  30414. versions:
  30415. - name: v1alpha1
  30416. schema:
  30417. openAPIV3Schema:
  30418. description: |-
  30419. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  30420. The authorization token is valid for 12 hours.
  30421. The authorizationToken returned is a base64 encoded string that can be decoded.
  30422. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  30423. properties:
  30424. apiVersion:
  30425. description: |-
  30426. APIVersion defines the versioned schema of this representation of an object.
  30427. Servers should convert recognized schemas to the latest internal value, and
  30428. may reject unrecognized values.
  30429. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30430. type: string
  30431. kind:
  30432. description: |-
  30433. Kind is a string value representing the REST resource this object represents.
  30434. Servers may infer this from the endpoint the client submits requests to.
  30435. Cannot be updated.
  30436. In CamelCase.
  30437. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30438. type: string
  30439. metadata:
  30440. type: object
  30441. spec:
  30442. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  30443. properties:
  30444. auth:
  30445. description: Auth defines how to authenticate with AWS
  30446. properties:
  30447. jwt:
  30448. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30449. properties:
  30450. serviceAccountRef:
  30451. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30452. properties:
  30453. audiences:
  30454. description: |-
  30455. Audience specifies the `aud` claim for the service account token
  30456. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30457. then this audiences will be appended to the list
  30458. items:
  30459. type: string
  30460. type: array
  30461. name:
  30462. description: The name of the ServiceAccount resource being referred to.
  30463. maxLength: 253
  30464. minLength: 1
  30465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30466. type: string
  30467. namespace:
  30468. description: |-
  30469. Namespace of the resource being referred to.
  30470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30471. maxLength: 63
  30472. minLength: 1
  30473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30474. type: string
  30475. required:
  30476. - name
  30477. type: object
  30478. type: object
  30479. secretRef:
  30480. description: |-
  30481. AWSAuthSecretRef holds secret references for AWS credentials
  30482. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30483. properties:
  30484. accessKeyIDSecretRef:
  30485. description: The AccessKeyID is used for authentication
  30486. properties:
  30487. key:
  30488. description: |-
  30489. A key in the referenced Secret.
  30490. Some instances of this field may be defaulted, in others it may be required.
  30491. maxLength: 253
  30492. minLength: 1
  30493. pattern: ^[-._a-zA-Z0-9]+$
  30494. type: string
  30495. name:
  30496. description: The name of the Secret resource being referred to.
  30497. maxLength: 253
  30498. minLength: 1
  30499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30500. type: string
  30501. namespace:
  30502. description: |-
  30503. The namespace of the Secret resource being referred to.
  30504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30505. maxLength: 63
  30506. minLength: 1
  30507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30508. type: string
  30509. type: object
  30510. secretAccessKeySecretRef:
  30511. description: The SecretAccessKey is used for authentication
  30512. properties:
  30513. key:
  30514. description: |-
  30515. A key in the referenced Secret.
  30516. Some instances of this field may be defaulted, in others it may be required.
  30517. maxLength: 253
  30518. minLength: 1
  30519. pattern: ^[-._a-zA-Z0-9]+$
  30520. type: string
  30521. name:
  30522. description: The name of the Secret resource being referred to.
  30523. maxLength: 253
  30524. minLength: 1
  30525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30526. type: string
  30527. namespace:
  30528. description: |-
  30529. The namespace of the Secret resource being referred to.
  30530. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30531. maxLength: 63
  30532. minLength: 1
  30533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30534. type: string
  30535. type: object
  30536. sessionTokenSecretRef:
  30537. description: |-
  30538. The SessionToken used for authentication
  30539. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30540. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30541. properties:
  30542. key:
  30543. description: |-
  30544. A key in the referenced Secret.
  30545. Some instances of this field may be defaulted, in others it may be required.
  30546. maxLength: 253
  30547. minLength: 1
  30548. pattern: ^[-._a-zA-Z0-9]+$
  30549. type: string
  30550. name:
  30551. description: The name of the Secret resource being referred to.
  30552. maxLength: 253
  30553. minLength: 1
  30554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30555. type: string
  30556. namespace:
  30557. description: |-
  30558. The namespace of the Secret resource being referred to.
  30559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30560. maxLength: 63
  30561. minLength: 1
  30562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30563. type: string
  30564. type: object
  30565. type: object
  30566. type: object
  30567. region:
  30568. description: Region specifies the region to operate in.
  30569. type: string
  30570. requestParameters:
  30571. description: RequestParameters contains parameters that can be passed to the STS service.
  30572. properties:
  30573. serialNumber:
  30574. description: |-
  30575. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  30576. the GetSessionToken call.
  30577. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  30578. (such as arn:aws:iam::123456789012:mfa/user)
  30579. type: string
  30580. sessionDuration:
  30581. format: int32
  30582. type: integer
  30583. tokenCode:
  30584. description: TokenCode is the value provided by the MFA device, if MFA is required.
  30585. type: string
  30586. type: object
  30587. role:
  30588. description: |-
  30589. You can assume a role before making calls to the
  30590. desired AWS service.
  30591. type: string
  30592. required:
  30593. - region
  30594. type: object
  30595. type: object
  30596. served: true
  30597. storage: true
  30598. subresources:
  30599. status: {}
  30600. ---
  30601. apiVersion: apiextensions.k8s.io/v1
  30602. kind: CustomResourceDefinition
  30603. metadata:
  30604. annotations:
  30605. controller-gen.kubebuilder.io/version: v0.19.0
  30606. labels:
  30607. external-secrets.io/component: controller
  30608. name: uuids.generators.external-secrets.io
  30609. spec:
  30610. group: generators.external-secrets.io
  30611. names:
  30612. categories:
  30613. - external-secrets
  30614. - external-secrets-generators
  30615. kind: UUID
  30616. listKind: UUIDList
  30617. plural: uuids
  30618. singular: uuid
  30619. scope: Namespaced
  30620. versions:
  30621. - name: v1alpha1
  30622. schema:
  30623. openAPIV3Schema:
  30624. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  30625. properties:
  30626. apiVersion:
  30627. description: |-
  30628. APIVersion defines the versioned schema of this representation of an object.
  30629. Servers should convert recognized schemas to the latest internal value, and
  30630. may reject unrecognized values.
  30631. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30632. type: string
  30633. kind:
  30634. description: |-
  30635. Kind is a string value representing the REST resource this object represents.
  30636. Servers may infer this from the endpoint the client submits requests to.
  30637. Cannot be updated.
  30638. In CamelCase.
  30639. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30640. type: string
  30641. metadata:
  30642. type: object
  30643. spec:
  30644. description: UUIDSpec controls the behavior of the uuid generator.
  30645. type: object
  30646. type: object
  30647. served: true
  30648. storage: true
  30649. subresources:
  30650. status: {}
  30651. ---
  30652. apiVersion: apiextensions.k8s.io/v1
  30653. kind: CustomResourceDefinition
  30654. metadata:
  30655. annotations:
  30656. controller-gen.kubebuilder.io/version: v0.19.0
  30657. labels:
  30658. external-secrets.io/component: controller
  30659. name: vaultdynamicsecrets.generators.external-secrets.io
  30660. spec:
  30661. group: generators.external-secrets.io
  30662. names:
  30663. categories:
  30664. - external-secrets
  30665. - external-secrets-generators
  30666. kind: VaultDynamicSecret
  30667. listKind: VaultDynamicSecretList
  30668. plural: vaultdynamicsecrets
  30669. singular: vaultdynamicsecret
  30670. scope: Namespaced
  30671. versions:
  30672. - name: v1alpha1
  30673. schema:
  30674. openAPIV3Schema:
  30675. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  30676. properties:
  30677. apiVersion:
  30678. description: |-
  30679. APIVersion defines the versioned schema of this representation of an object.
  30680. Servers should convert recognized schemas to the latest internal value, and
  30681. may reject unrecognized values.
  30682. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30683. type: string
  30684. kind:
  30685. description: |-
  30686. Kind is a string value representing the REST resource this object represents.
  30687. Servers may infer this from the endpoint the client submits requests to.
  30688. Cannot be updated.
  30689. In CamelCase.
  30690. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30691. type: string
  30692. metadata:
  30693. type: object
  30694. spec:
  30695. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  30696. properties:
  30697. allowEmptyResponse:
  30698. default: false
  30699. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  30700. type: boolean
  30701. controller:
  30702. description: |-
  30703. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30704. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30705. type: string
  30706. getParameters:
  30707. additionalProperties:
  30708. items:
  30709. type: string
  30710. type: array
  30711. description: |-
  30712. GetParameters are query-string parameters passed to Vault on GET calls.
  30713. Each key may map to multiple values, matching HTTP query-string semantics.
  30714. Ignored for non-GET methods; use Parameters for write bodies.
  30715. type: object
  30716. method:
  30717. description: Vault API method to use (GET/POST/other)
  30718. type: string
  30719. parameters:
  30720. description: Parameters to pass to Vault write (for non-GET methods)
  30721. x-kubernetes-preserve-unknown-fields: true
  30722. path:
  30723. description: Vault path to obtain the dynamic secret from
  30724. type: string
  30725. provider:
  30726. description: Vault provider common spec
  30727. properties:
  30728. auth:
  30729. description: Auth configures how secret-manager authenticates with the Vault server.
  30730. properties:
  30731. appRole:
  30732. description: |-
  30733. AppRole authenticates with Vault using the App Role auth mechanism,
  30734. with the role and secret stored in a Kubernetes Secret resource.
  30735. properties:
  30736. path:
  30737. default: approle
  30738. description: |-
  30739. Path where the App Role authentication backend is mounted
  30740. in Vault, e.g: "approle"
  30741. type: string
  30742. roleId:
  30743. description: |-
  30744. RoleID configured in the App Role authentication backend when setting
  30745. up the authentication backend in Vault.
  30746. type: string
  30747. roleRef:
  30748. description: |-
  30749. Reference to a key in a Secret that contains the App Role ID used
  30750. to authenticate with Vault.
  30751. The `key` field must be specified and denotes which entry within the Secret
  30752. resource is used as the app role id.
  30753. properties:
  30754. key:
  30755. description: |-
  30756. A key in the referenced Secret.
  30757. Some instances of this field may be defaulted, in others it may be required.
  30758. maxLength: 253
  30759. minLength: 1
  30760. pattern: ^[-._a-zA-Z0-9]+$
  30761. type: string
  30762. name:
  30763. description: The name of the Secret resource being referred to.
  30764. maxLength: 253
  30765. minLength: 1
  30766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30767. type: string
  30768. namespace:
  30769. description: |-
  30770. The namespace of the Secret resource being referred to.
  30771. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30772. maxLength: 63
  30773. minLength: 1
  30774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30775. type: string
  30776. type: object
  30777. secretRef:
  30778. description: |-
  30779. Reference to a key in a Secret that contains the App Role secret used
  30780. to authenticate with Vault.
  30781. The `key` field must be specified and denotes which entry within the Secret
  30782. resource is used as the app role secret.
  30783. properties:
  30784. key:
  30785. description: |-
  30786. A key in the referenced Secret.
  30787. Some instances of this field may be defaulted, in others it may be required.
  30788. maxLength: 253
  30789. minLength: 1
  30790. pattern: ^[-._a-zA-Z0-9]+$
  30791. type: string
  30792. name:
  30793. description: The name of the Secret resource being referred to.
  30794. maxLength: 253
  30795. minLength: 1
  30796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30797. type: string
  30798. namespace:
  30799. description: |-
  30800. The namespace of the Secret resource being referred to.
  30801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30802. maxLength: 63
  30803. minLength: 1
  30804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30805. type: string
  30806. type: object
  30807. required:
  30808. - path
  30809. - secretRef
  30810. type: object
  30811. cert:
  30812. description: |-
  30813. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  30814. Cert authentication method
  30815. properties:
  30816. clientCert:
  30817. description: |-
  30818. ClientCert is a certificate to authenticate using the Cert Vault
  30819. authentication method
  30820. properties:
  30821. key:
  30822. description: |-
  30823. A key in the referenced Secret.
  30824. Some instances of this field may be defaulted, in others it may be required.
  30825. maxLength: 253
  30826. minLength: 1
  30827. pattern: ^[-._a-zA-Z0-9]+$
  30828. type: string
  30829. name:
  30830. description: The name of the Secret resource being referred to.
  30831. maxLength: 253
  30832. minLength: 1
  30833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30834. type: string
  30835. namespace:
  30836. description: |-
  30837. The namespace of the Secret resource being referred to.
  30838. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30839. maxLength: 63
  30840. minLength: 1
  30841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30842. type: string
  30843. type: object
  30844. path:
  30845. default: cert
  30846. description: |-
  30847. Path where the Certificate authentication backend is mounted
  30848. in Vault, e.g: "cert"
  30849. type: string
  30850. secretRef:
  30851. description: |-
  30852. SecretRef to a key in a Secret resource containing client private key to
  30853. authenticate with Vault using the Cert authentication method
  30854. properties:
  30855. key:
  30856. description: |-
  30857. A key in the referenced Secret.
  30858. Some instances of this field may be defaulted, in others it may be required.
  30859. maxLength: 253
  30860. minLength: 1
  30861. pattern: ^[-._a-zA-Z0-9]+$
  30862. type: string
  30863. name:
  30864. description: The name of the Secret resource being referred to.
  30865. maxLength: 253
  30866. minLength: 1
  30867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30868. type: string
  30869. namespace:
  30870. description: |-
  30871. The namespace of the Secret resource being referred to.
  30872. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30873. maxLength: 63
  30874. minLength: 1
  30875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30876. type: string
  30877. type: object
  30878. vaultRole:
  30879. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  30880. type: string
  30881. type: object
  30882. gcp:
  30883. description: |-
  30884. Gcp authenticates with Vault using Google Cloud Platform authentication method
  30885. GCP authentication method
  30886. properties:
  30887. location:
  30888. description: Location optionally defines a location/region for the secret
  30889. type: string
  30890. path:
  30891. default: gcp
  30892. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  30893. type: string
  30894. projectID:
  30895. description: Project ID of the Google Cloud Platform project
  30896. type: string
  30897. role:
  30898. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  30899. type: string
  30900. secretRef:
  30901. description: Specify credentials in a Secret object
  30902. properties:
  30903. secretAccessKeySecretRef:
  30904. description: The SecretAccessKey is used for authentication
  30905. properties:
  30906. key:
  30907. description: |-
  30908. A key in the referenced Secret.
  30909. Some instances of this field may be defaulted, in others it may be required.
  30910. maxLength: 253
  30911. minLength: 1
  30912. pattern: ^[-._a-zA-Z0-9]+$
  30913. type: string
  30914. name:
  30915. description: The name of the Secret resource being referred to.
  30916. maxLength: 253
  30917. minLength: 1
  30918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30919. type: string
  30920. namespace:
  30921. description: |-
  30922. The namespace of the Secret resource being referred to.
  30923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30924. maxLength: 63
  30925. minLength: 1
  30926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30927. type: string
  30928. type: object
  30929. type: object
  30930. serviceAccountRef:
  30931. description: ServiceAccountRef to a service account for impersonation
  30932. properties:
  30933. audiences:
  30934. description: |-
  30935. Audience specifies the `aud` claim for the service account token
  30936. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30937. then this audiences will be appended to the list
  30938. items:
  30939. type: string
  30940. type: array
  30941. name:
  30942. description: The name of the ServiceAccount resource being referred to.
  30943. maxLength: 253
  30944. minLength: 1
  30945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30946. type: string
  30947. namespace:
  30948. description: |-
  30949. Namespace of the resource being referred to.
  30950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30951. maxLength: 63
  30952. minLength: 1
  30953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30954. type: string
  30955. required:
  30956. - name
  30957. type: object
  30958. workloadIdentity:
  30959. description: Specify a service account with Workload Identity
  30960. properties:
  30961. clusterLocation:
  30962. description: |-
  30963. ClusterLocation is the location of the cluster
  30964. If not specified, it fetches information from the metadata server
  30965. type: string
  30966. clusterName:
  30967. description: |-
  30968. ClusterName is the name of the cluster
  30969. If not specified, it fetches information from the metadata server
  30970. type: string
  30971. clusterProjectID:
  30972. description: |-
  30973. ClusterProjectID is the project ID of the cluster
  30974. If not specified, it fetches information from the metadata server
  30975. type: string
  30976. serviceAccountRef:
  30977. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30978. properties:
  30979. audiences:
  30980. description: |-
  30981. Audience specifies the `aud` claim for the service account token
  30982. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30983. then this audiences will be appended to the list
  30984. items:
  30985. type: string
  30986. type: array
  30987. name:
  30988. description: The name of the ServiceAccount resource being referred to.
  30989. maxLength: 253
  30990. minLength: 1
  30991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30992. type: string
  30993. namespace:
  30994. description: |-
  30995. Namespace of the resource being referred to.
  30996. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30997. maxLength: 63
  30998. minLength: 1
  30999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31000. type: string
  31001. required:
  31002. - name
  31003. type: object
  31004. required:
  31005. - serviceAccountRef
  31006. type: object
  31007. required:
  31008. - role
  31009. type: object
  31010. iam:
  31011. description: |-
  31012. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31013. AWS IAM authentication method
  31014. properties:
  31015. externalID:
  31016. description: AWS External ID set on assumed IAM roles
  31017. type: string
  31018. jwt:
  31019. description: Specify a service account with IRSA enabled
  31020. properties:
  31021. serviceAccountRef:
  31022. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31023. properties:
  31024. audiences:
  31025. description: |-
  31026. Audience specifies the `aud` claim for the service account token
  31027. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31028. then this audiences will be appended to the list
  31029. items:
  31030. type: string
  31031. type: array
  31032. name:
  31033. description: The name of the ServiceAccount resource being referred to.
  31034. maxLength: 253
  31035. minLength: 1
  31036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31037. type: string
  31038. namespace:
  31039. description: |-
  31040. Namespace of the resource being referred to.
  31041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31042. maxLength: 63
  31043. minLength: 1
  31044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31045. type: string
  31046. required:
  31047. - name
  31048. type: object
  31049. type: object
  31050. path:
  31051. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31052. type: string
  31053. region:
  31054. description: AWS region
  31055. type: string
  31056. role:
  31057. description: This is the AWS role to be assumed before talking to vault
  31058. type: string
  31059. secretRef:
  31060. description: Specify credentials in a Secret object
  31061. properties:
  31062. accessKeyIDSecretRef:
  31063. description: The AccessKeyID is used for authentication
  31064. properties:
  31065. key:
  31066. description: |-
  31067. A key in the referenced Secret.
  31068. Some instances of this field may be defaulted, in others it may be required.
  31069. maxLength: 253
  31070. minLength: 1
  31071. pattern: ^[-._a-zA-Z0-9]+$
  31072. type: string
  31073. name:
  31074. description: The name of the Secret resource being referred to.
  31075. maxLength: 253
  31076. minLength: 1
  31077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31078. type: string
  31079. namespace:
  31080. description: |-
  31081. The namespace of the Secret resource being referred to.
  31082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31083. maxLength: 63
  31084. minLength: 1
  31085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31086. type: string
  31087. type: object
  31088. secretAccessKeySecretRef:
  31089. description: The SecretAccessKey is used for authentication
  31090. properties:
  31091. key:
  31092. description: |-
  31093. A key in the referenced Secret.
  31094. Some instances of this field may be defaulted, in others it may be required.
  31095. maxLength: 253
  31096. minLength: 1
  31097. pattern: ^[-._a-zA-Z0-9]+$
  31098. type: string
  31099. name:
  31100. description: The name of the Secret resource being referred to.
  31101. maxLength: 253
  31102. minLength: 1
  31103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31104. type: string
  31105. namespace:
  31106. description: |-
  31107. The namespace of the Secret resource being referred to.
  31108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31109. maxLength: 63
  31110. minLength: 1
  31111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31112. type: string
  31113. type: object
  31114. sessionTokenSecretRef:
  31115. description: |-
  31116. The SessionToken used for authentication
  31117. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31118. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31119. properties:
  31120. key:
  31121. description: |-
  31122. A key in the referenced Secret.
  31123. Some instances of this field may be defaulted, in others it may be required.
  31124. maxLength: 253
  31125. minLength: 1
  31126. pattern: ^[-._a-zA-Z0-9]+$
  31127. type: string
  31128. name:
  31129. description: The name of the Secret resource being referred to.
  31130. maxLength: 253
  31131. minLength: 1
  31132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31133. type: string
  31134. namespace:
  31135. description: |-
  31136. The namespace of the Secret resource being referred to.
  31137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31138. maxLength: 63
  31139. minLength: 1
  31140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31141. type: string
  31142. type: object
  31143. type: object
  31144. vaultAwsIamServerID:
  31145. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31146. type: string
  31147. vaultRole:
  31148. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31149. type: string
  31150. required:
  31151. - vaultRole
  31152. type: object
  31153. jwt:
  31154. description: |-
  31155. Jwt authenticates with Vault by passing role and JWT token using the
  31156. JWT/OIDC authentication method
  31157. properties:
  31158. kubernetesServiceAccountToken:
  31159. description: |-
  31160. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31161. a token for with the `TokenRequest` API.
  31162. properties:
  31163. audiences:
  31164. description: |-
  31165. Optional audiences field that will be used to request a temporary Kubernetes service
  31166. account token for the service account referenced by `serviceAccountRef`.
  31167. Defaults to a single audience `vault` it not specified.
  31168. Deprecated: use serviceAccountRef.Audiences instead
  31169. items:
  31170. type: string
  31171. type: array
  31172. expirationSeconds:
  31173. description: |-
  31174. Optional expiration time in seconds that will be used to request a temporary
  31175. Kubernetes service account token for the service account referenced by
  31176. `serviceAccountRef`.
  31177. Deprecated: this will be removed in the future.
  31178. Defaults to 10 minutes.
  31179. format: int64
  31180. type: integer
  31181. serviceAccountRef:
  31182. description: Service account field containing the name of a kubernetes ServiceAccount.
  31183. properties:
  31184. audiences:
  31185. description: |-
  31186. Audience specifies the `aud` claim for the service account token
  31187. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31188. then this audiences will be appended to the list
  31189. items:
  31190. type: string
  31191. type: array
  31192. name:
  31193. description: The name of the ServiceAccount resource being referred to.
  31194. maxLength: 253
  31195. minLength: 1
  31196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31197. type: string
  31198. namespace:
  31199. description: |-
  31200. Namespace of the resource being referred to.
  31201. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31202. maxLength: 63
  31203. minLength: 1
  31204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31205. type: string
  31206. required:
  31207. - name
  31208. type: object
  31209. required:
  31210. - serviceAccountRef
  31211. type: object
  31212. path:
  31213. default: jwt
  31214. description: |-
  31215. Path where the JWT authentication backend is mounted
  31216. in Vault, e.g: "jwt"
  31217. type: string
  31218. role:
  31219. description: |-
  31220. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31221. authentication method
  31222. type: string
  31223. secretRef:
  31224. description: |-
  31225. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31226. authenticate with Vault using the JWT/OIDC authentication method.
  31227. properties:
  31228. key:
  31229. description: |-
  31230. A key in the referenced Secret.
  31231. Some instances of this field may be defaulted, in others it may be required.
  31232. maxLength: 253
  31233. minLength: 1
  31234. pattern: ^[-._a-zA-Z0-9]+$
  31235. type: string
  31236. name:
  31237. description: The name of the Secret resource being referred to.
  31238. maxLength: 253
  31239. minLength: 1
  31240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31241. type: string
  31242. namespace:
  31243. description: |-
  31244. The namespace of the Secret resource being referred to.
  31245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31246. maxLength: 63
  31247. minLength: 1
  31248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31249. type: string
  31250. type: object
  31251. required:
  31252. - path
  31253. type: object
  31254. kubernetes:
  31255. description: |-
  31256. Kubernetes authenticates with Vault by passing the ServiceAccount
  31257. token stored in the named Secret resource to the Vault server.
  31258. properties:
  31259. mountPath:
  31260. default: kubernetes
  31261. description: |-
  31262. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31263. "kubernetes"
  31264. type: string
  31265. role:
  31266. description: |-
  31267. A required field containing the Vault Role to assume. A Role binds a
  31268. Kubernetes ServiceAccount with a set of Vault policies.
  31269. type: string
  31270. secretRef:
  31271. description: |-
  31272. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31273. for authenticating with Vault. If a name is specified without a key,
  31274. `token` is the default. If one is not specified, the one bound to
  31275. the controller will be used.
  31276. properties:
  31277. key:
  31278. description: |-
  31279. A key in the referenced Secret.
  31280. Some instances of this field may be defaulted, in others it may be required.
  31281. maxLength: 253
  31282. minLength: 1
  31283. pattern: ^[-._a-zA-Z0-9]+$
  31284. type: string
  31285. name:
  31286. description: The name of the Secret resource being referred to.
  31287. maxLength: 253
  31288. minLength: 1
  31289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31290. type: string
  31291. namespace:
  31292. description: |-
  31293. The namespace of the Secret resource being referred to.
  31294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31295. maxLength: 63
  31296. minLength: 1
  31297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31298. type: string
  31299. type: object
  31300. serviceAccountRef:
  31301. description: |-
  31302. Optional service account field containing the name of a kubernetes ServiceAccount.
  31303. If the service account is specified, the service account secret token JWT will be used
  31304. for authenticating with Vault. If the service account selector is not supplied,
  31305. the secretRef will be used instead.
  31306. properties:
  31307. audiences:
  31308. description: |-
  31309. Audience specifies the `aud` claim for the service account token
  31310. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31311. then this audiences will be appended to the list
  31312. items:
  31313. type: string
  31314. type: array
  31315. name:
  31316. description: The name of the ServiceAccount resource being referred to.
  31317. maxLength: 253
  31318. minLength: 1
  31319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31320. type: string
  31321. namespace:
  31322. description: |-
  31323. Namespace of the resource being referred to.
  31324. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31325. maxLength: 63
  31326. minLength: 1
  31327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31328. type: string
  31329. required:
  31330. - name
  31331. type: object
  31332. required:
  31333. - mountPath
  31334. - role
  31335. type: object
  31336. ldap:
  31337. description: |-
  31338. Ldap authenticates with Vault by passing username/password pair using
  31339. the LDAP authentication method
  31340. properties:
  31341. path:
  31342. default: ldap
  31343. description: |-
  31344. Path where the LDAP authentication backend is mounted
  31345. in Vault, e.g: "ldap"
  31346. type: string
  31347. secretRef:
  31348. description: |-
  31349. SecretRef to a key in a Secret resource containing password for the LDAP
  31350. user used to authenticate with Vault using the LDAP authentication
  31351. method
  31352. properties:
  31353. key:
  31354. description: |-
  31355. A key in the referenced Secret.
  31356. Some instances of this field may be defaulted, in others it may be required.
  31357. maxLength: 253
  31358. minLength: 1
  31359. pattern: ^[-._a-zA-Z0-9]+$
  31360. type: string
  31361. name:
  31362. description: The name of the Secret resource being referred to.
  31363. maxLength: 253
  31364. minLength: 1
  31365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31366. type: string
  31367. namespace:
  31368. description: |-
  31369. The namespace of the Secret resource being referred to.
  31370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31371. maxLength: 63
  31372. minLength: 1
  31373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31374. type: string
  31375. type: object
  31376. username:
  31377. description: |-
  31378. Username is an LDAP username used to authenticate using the LDAP Vault
  31379. authentication method
  31380. type: string
  31381. required:
  31382. - path
  31383. - username
  31384. type: object
  31385. namespace:
  31386. description: |-
  31387. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  31388. Namespaces is a set of features within Vault Enterprise that allows
  31389. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  31390. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  31391. This will default to Vault.Namespace field if set, or empty otherwise
  31392. type: string
  31393. tokenSecretRef:
  31394. description: TokenSecretRef authenticates with Vault by presenting a token.
  31395. properties:
  31396. key:
  31397. description: |-
  31398. A key in the referenced Secret.
  31399. Some instances of this field may be defaulted, in others it may be required.
  31400. maxLength: 253
  31401. minLength: 1
  31402. pattern: ^[-._a-zA-Z0-9]+$
  31403. type: string
  31404. name:
  31405. description: The name of the Secret resource being referred to.
  31406. maxLength: 253
  31407. minLength: 1
  31408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31409. type: string
  31410. namespace:
  31411. description: |-
  31412. The namespace of the Secret resource being referred to.
  31413. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31414. maxLength: 63
  31415. minLength: 1
  31416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31417. type: string
  31418. type: object
  31419. userPass:
  31420. description: UserPass authenticates with Vault by passing username/password pair
  31421. properties:
  31422. path:
  31423. default: userpass
  31424. description: |-
  31425. Path where the UserPassword authentication backend is mounted
  31426. in Vault, e.g: "userpass"
  31427. type: string
  31428. secretRef:
  31429. description: |-
  31430. SecretRef to a key in a Secret resource containing password for the
  31431. user used to authenticate with Vault using the UserPass authentication
  31432. method
  31433. properties:
  31434. key:
  31435. description: |-
  31436. A key in the referenced Secret.
  31437. Some instances of this field may be defaulted, in others it may be required.
  31438. maxLength: 253
  31439. minLength: 1
  31440. pattern: ^[-._a-zA-Z0-9]+$
  31441. type: string
  31442. name:
  31443. description: The name of the Secret resource being referred to.
  31444. maxLength: 253
  31445. minLength: 1
  31446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31447. type: string
  31448. namespace:
  31449. description: |-
  31450. The namespace of the Secret resource being referred to.
  31451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31452. maxLength: 63
  31453. minLength: 1
  31454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31455. type: string
  31456. type: object
  31457. username:
  31458. description: |-
  31459. Username is a username used to authenticate using the UserPass Vault
  31460. authentication method
  31461. type: string
  31462. required:
  31463. - path
  31464. - username
  31465. type: object
  31466. type: object
  31467. caBundle:
  31468. description: |-
  31469. PEM encoded CA bundle used to validate Vault server certificate. Only used
  31470. if the Server URL is using HTTPS protocol. This parameter is ignored for
  31471. plain HTTP protocol connection. If not set the system root certificates
  31472. are used to validate the TLS connection.
  31473. format: byte
  31474. type: string
  31475. caProvider:
  31476. description: The provider for the CA bundle to use to validate Vault server certificate.
  31477. properties:
  31478. key:
  31479. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  31480. maxLength: 253
  31481. minLength: 1
  31482. pattern: ^[-._a-zA-Z0-9]+$
  31483. type: string
  31484. name:
  31485. description: The name of the object located at the provider type.
  31486. maxLength: 253
  31487. minLength: 1
  31488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31489. type: string
  31490. namespace:
  31491. description: |-
  31492. The namespace the Provider type is in.
  31493. Can only be defined when used in a ClusterSecretStore.
  31494. maxLength: 63
  31495. minLength: 1
  31496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31497. type: string
  31498. type:
  31499. description: The type of provider to use such as "Secret", or "ConfigMap".
  31500. enum:
  31501. - Secret
  31502. - ConfigMap
  31503. type: string
  31504. required:
  31505. - name
  31506. - type
  31507. type: object
  31508. checkAndSet:
  31509. description: |-
  31510. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  31511. Only applies to Vault KV v2 stores. When enabled, write operations must include
  31512. the current version of the secret to prevent unintentional overwrites.
  31513. properties:
  31514. required:
  31515. description: |-
  31516. Required when true, all write operations must include a check-and-set parameter.
  31517. This helps prevent unintentional overwrites of secrets.
  31518. type: boolean
  31519. type: object
  31520. forwardInconsistent:
  31521. description: |-
  31522. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  31523. leader instead of simply retrying within a loop. This can increase performance if
  31524. the option is enabled serverside.
  31525. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  31526. type: boolean
  31527. headers:
  31528. additionalProperties:
  31529. type: string
  31530. description: Headers to be added in Vault request
  31531. type: object
  31532. namespace:
  31533. description: |-
  31534. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  31535. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  31536. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  31537. type: string
  31538. path:
  31539. description: |-
  31540. Path is the mount path of the Vault KV backend endpoint, e.g:
  31541. "secret". The v2 KV secret engine version specific "/data" path suffix
  31542. for fetching secrets from Vault is optional and will be appended
  31543. if not present in specified path.
  31544. type: string
  31545. readYourWrites:
  31546. description: |-
  31547. ReadYourWrites ensures isolated read-after-write semantics by
  31548. providing discovered cluster replication states in each request.
  31549. More information about eventual consistency in Vault can be found here
  31550. https://www.vaultproject.io/docs/enterprise/consistency
  31551. type: boolean
  31552. server:
  31553. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  31554. type: string
  31555. tls:
  31556. description: |-
  31557. The configuration used for client side related TLS communication, when the Vault server
  31558. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  31559. This parameter is ignored for plain HTTP protocol connection.
  31560. It's worth noting this configuration is different from the "TLS certificates auth method",
  31561. which is available under the `auth.cert` section.
  31562. properties:
  31563. certSecretRef:
  31564. description: |-
  31565. CertSecretRef is a certificate added to the transport layer
  31566. when communicating with the Vault server.
  31567. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  31568. properties:
  31569. key:
  31570. description: |-
  31571. A key in the referenced Secret.
  31572. Some instances of this field may be defaulted, in others it may be required.
  31573. maxLength: 253
  31574. minLength: 1
  31575. pattern: ^[-._a-zA-Z0-9]+$
  31576. type: string
  31577. name:
  31578. description: The name of the Secret resource being referred to.
  31579. maxLength: 253
  31580. minLength: 1
  31581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31582. type: string
  31583. namespace:
  31584. description: |-
  31585. The namespace of the Secret resource being referred to.
  31586. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31587. maxLength: 63
  31588. minLength: 1
  31589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31590. type: string
  31591. type: object
  31592. keySecretRef:
  31593. description: |-
  31594. KeySecretRef to a key in a Secret resource containing client private key
  31595. added to the transport layer when communicating with the Vault server.
  31596. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  31597. properties:
  31598. key:
  31599. description: |-
  31600. A key in the referenced Secret.
  31601. Some instances of this field may be defaulted, in others it may be required.
  31602. maxLength: 253
  31603. minLength: 1
  31604. pattern: ^[-._a-zA-Z0-9]+$
  31605. type: string
  31606. name:
  31607. description: The name of the Secret resource being referred to.
  31608. maxLength: 253
  31609. minLength: 1
  31610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31611. type: string
  31612. namespace:
  31613. description: |-
  31614. The namespace of the Secret resource being referred to.
  31615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31616. maxLength: 63
  31617. minLength: 1
  31618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31619. type: string
  31620. type: object
  31621. type: object
  31622. version:
  31623. default: v2
  31624. description: |-
  31625. Version is the Vault KV secret engine version. This can be either "v1" or
  31626. "v2". Version defaults to "v2".
  31627. enum:
  31628. - v1
  31629. - v2
  31630. type: string
  31631. required:
  31632. - server
  31633. type: object
  31634. resultType:
  31635. default: Data
  31636. description: |-
  31637. Result type defines which data is returned from the generator.
  31638. By default, it is the "data" section of the Vault API response.
  31639. When using e.g. /auth/token/create the "data" section is empty but
  31640. the "auth" section contains the generated token.
  31641. Please refer to the vault docs regarding the result data structure.
  31642. Additionally, accessing the raw response is possibly by using "Raw" result type.
  31643. enum:
  31644. - Data
  31645. - Auth
  31646. - Raw
  31647. type: string
  31648. retrySettings:
  31649. description: Used to configure http retries if failed
  31650. properties:
  31651. maxRetries:
  31652. format: int32
  31653. type: integer
  31654. retryInterval:
  31655. type: string
  31656. type: object
  31657. required:
  31658. - path
  31659. - provider
  31660. type: object
  31661. type: object
  31662. served: true
  31663. storage: true
  31664. subresources:
  31665. status: {}
  31666. ---
  31667. apiVersion: apiextensions.k8s.io/v1
  31668. kind: CustomResourceDefinition
  31669. metadata:
  31670. annotations:
  31671. controller-gen.kubebuilder.io/version: v0.19.0
  31672. labels:
  31673. external-secrets.io/component: controller
  31674. name: webhooks.generators.external-secrets.io
  31675. spec:
  31676. group: generators.external-secrets.io
  31677. names:
  31678. categories:
  31679. - external-secrets
  31680. - external-secrets-generators
  31681. kind: Webhook
  31682. listKind: WebhookList
  31683. plural: webhooks
  31684. singular: webhook
  31685. scope: Namespaced
  31686. versions:
  31687. - name: v1alpha1
  31688. schema:
  31689. openAPIV3Schema:
  31690. description: |-
  31691. Webhook connects to a third party API server to handle the secrets generation
  31692. configuration parameters in spec.
  31693. You can specify the server, the token, and additional body parameters.
  31694. See documentation for the full API specification for requests and responses.
  31695. properties:
  31696. apiVersion:
  31697. description: |-
  31698. APIVersion defines the versioned schema of this representation of an object.
  31699. Servers should convert recognized schemas to the latest internal value, and
  31700. may reject unrecognized values.
  31701. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31702. type: string
  31703. kind:
  31704. description: |-
  31705. Kind is a string value representing the REST resource this object represents.
  31706. Servers may infer this from the endpoint the client submits requests to.
  31707. Cannot be updated.
  31708. In CamelCase.
  31709. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31710. type: string
  31711. metadata:
  31712. type: object
  31713. spec:
  31714. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  31715. properties:
  31716. auth:
  31717. description: Auth specifies a authorization protocol. Only one protocol may be set.
  31718. maxProperties: 1
  31719. minProperties: 1
  31720. properties:
  31721. ntlm:
  31722. description: NTLMProtocol configures the store to use NTLM for auth
  31723. properties:
  31724. passwordSecret:
  31725. description: |-
  31726. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31727. In some instances, `key` is a required field.
  31728. properties:
  31729. key:
  31730. description: |-
  31731. A key in the referenced Secret.
  31732. Some instances of this field may be defaulted, in others it may be required.
  31733. maxLength: 253
  31734. minLength: 1
  31735. pattern: ^[-._a-zA-Z0-9]+$
  31736. type: string
  31737. name:
  31738. description: The name of the Secret resource being referred to.
  31739. maxLength: 253
  31740. minLength: 1
  31741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31742. type: string
  31743. namespace:
  31744. description: |-
  31745. The namespace of the Secret resource being referred to.
  31746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31747. maxLength: 63
  31748. minLength: 1
  31749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31750. type: string
  31751. type: object
  31752. usernameSecret:
  31753. description: |-
  31754. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31755. In some instances, `key` is a required field.
  31756. properties:
  31757. key:
  31758. description: |-
  31759. A key in the referenced Secret.
  31760. Some instances of this field may be defaulted, in others it may be required.
  31761. maxLength: 253
  31762. minLength: 1
  31763. pattern: ^[-._a-zA-Z0-9]+$
  31764. type: string
  31765. name:
  31766. description: The name of the Secret resource being referred to.
  31767. maxLength: 253
  31768. minLength: 1
  31769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31770. type: string
  31771. namespace:
  31772. description: |-
  31773. The namespace of the Secret resource being referred to.
  31774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31775. maxLength: 63
  31776. minLength: 1
  31777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31778. type: string
  31779. type: object
  31780. required:
  31781. - passwordSecret
  31782. - usernameSecret
  31783. type: object
  31784. type: object
  31785. body:
  31786. description: Body
  31787. type: string
  31788. caBundle:
  31789. description: |-
  31790. PEM encoded CA bundle used to validate webhook server certificate. Only used
  31791. if the Server URL is using HTTPS protocol. This parameter is ignored for
  31792. plain HTTP protocol connection. If not set the system root certificates
  31793. are used to validate the TLS connection.
  31794. format: byte
  31795. type: string
  31796. caProvider:
  31797. description: The provider for the CA bundle to use to validate webhook server certificate.
  31798. properties:
  31799. key:
  31800. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  31801. maxLength: 253
  31802. minLength: 1
  31803. pattern: ^[-._a-zA-Z0-9]+$
  31804. type: string
  31805. name:
  31806. description: The name of the object located at the provider type.
  31807. maxLength: 253
  31808. minLength: 1
  31809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31810. type: string
  31811. namespace:
  31812. description: The namespace the Provider type is in.
  31813. maxLength: 63
  31814. minLength: 1
  31815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31816. type: string
  31817. type:
  31818. description: The type of provider to use such as "Secret", or "ConfigMap".
  31819. enum:
  31820. - Secret
  31821. - ConfigMap
  31822. type: string
  31823. required:
  31824. - name
  31825. - type
  31826. type: object
  31827. headers:
  31828. additionalProperties:
  31829. type: string
  31830. description: Headers
  31831. type: object
  31832. method:
  31833. description: Webhook Method
  31834. type: string
  31835. result:
  31836. description: Result formatting
  31837. properties:
  31838. jsonPath:
  31839. description: Json path of return value
  31840. type: string
  31841. type: object
  31842. secrets:
  31843. description: |-
  31844. Secrets to fill in templates
  31845. These secrets will be passed to the templating function as key value pairs under the given name
  31846. items:
  31847. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  31848. properties:
  31849. name:
  31850. description: Name of this secret in templates
  31851. type: string
  31852. secretRef:
  31853. description: Secret ref to fill in credentials
  31854. properties:
  31855. key:
  31856. description: The key where the token is found.
  31857. maxLength: 253
  31858. minLength: 1
  31859. pattern: ^[-._a-zA-Z0-9]+$
  31860. type: string
  31861. name:
  31862. description: The name of the Secret resource being referred to.
  31863. maxLength: 253
  31864. minLength: 1
  31865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31866. type: string
  31867. type: object
  31868. required:
  31869. - name
  31870. - secretRef
  31871. type: object
  31872. type: array
  31873. timeout:
  31874. description: Timeout
  31875. type: string
  31876. url:
  31877. description: Webhook url to call
  31878. type: string
  31879. required:
  31880. - result
  31881. - url
  31882. type: object
  31883. type: object
  31884. served: true
  31885. storage: true
  31886. subresources:
  31887. status: {}