azkv-workload-identity-secretref.yaml 687 B

12345678910111213141516171819202122232425262728
  1. apiVersion: v1
  2. kind: ServiceAccount
  3. metadata:
  4. # this service account was created by azwi
  5. name: workload-identity-sa
  6. annotations: {}
  7. ---
  8. apiVersion: external-secrets.io/v1beta1
  9. kind: SecretStore
  10. metadata:
  11. name: azure-store
  12. spec:
  13. provider:
  14. azurekv:
  15. # tenantId spec option #1
  16. tenantId: "5a02a20e-xxxx-xxxx-xxxx-0ad5b634c5d8"
  17. authType: WorkloadIdentity
  18. vaultUrl: "https://xx-xxxx-xx.vault.azure.net"
  19. serviceAccountRef:
  20. name: workload-identity-sa
  21. authSecretRef:
  22. clientId:
  23. name: umi-secret
  24. key: clientId
  25. # tenantId spec option #2
  26. tenantId:
  27. name: umi-secret
  28. key: tenantId