gcpsm-wif-non-native-iam-secret-store.yaml 529 B

1234567891011121314151617
  1. apiVersion: external-secrets.io/v1
  2. kind: SecretStore
  3. metadata:
  4. name: demo-store
  5. namespace: demo
  6. spec:
  7. provider:
  8. gcpsm:
  9. projectID: [PROJECT_ID]
  10. auth:
  11. workloadIdentityFederation:
  12. audience: //iam.googleapis.com/projects/[PROJECT_ID]/locations/[CLUSTER_LOCATION]/workloadIdentityPools/[WORKLOAD_IDENTITY_POOL]/providers/[WORKLOAD_IDENTITY_PROVIDER]
  13. serviceAccountRef:
  14. name: demo-secrets-sa
  15. namespace: demo
  16. audiences:
  17. - demo-audience