bundle.yaml 307 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.8.0
  6. creationTimestamp: null
  7. name: clusterexternalsecrets.external-secrets.io
  8. spec:
  9. group: external-secrets.io
  10. names:
  11. categories:
  12. - externalsecrets
  13. kind: ClusterExternalSecret
  14. listKind: ClusterExternalSecretList
  15. plural: clusterexternalsecrets
  16. shortNames:
  17. - ces
  18. singular: clusterexternalsecret
  19. scope: Cluster
  20. versions:
  21. - name: v1beta1
  22. schema:
  23. openAPIV3Schema:
  24. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  25. properties:
  26. apiVersion:
  27. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  28. type: string
  29. kind:
  30. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  31. type: string
  32. metadata:
  33. type: object
  34. spec:
  35. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  36. properties:
  37. externalSecretName:
  38. description: The name of the external secrets to be created defaults to the name of the ClusterExternalSecret
  39. type: string
  40. externalSecretSpec:
  41. description: The spec for the ExternalSecrets to be created
  42. properties:
  43. data:
  44. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  45. items:
  46. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  47. properties:
  48. remoteRef:
  49. description: ExternalSecretDataRemoteRef defines Provider data location.
  50. properties:
  51. conversionStrategy:
  52. default: Default
  53. description: Used to define a conversion Strategy
  54. type: string
  55. key:
  56. description: Key is the key used in the Provider, mandatory
  57. type: string
  58. property:
  59. description: Used to select a specific property of the Provider value (if a map), if supported
  60. type: string
  61. version:
  62. description: Used to select a specific version of the Provider value, if supported
  63. type: string
  64. required:
  65. - key
  66. type: object
  67. secretKey:
  68. type: string
  69. required:
  70. - remoteRef
  71. - secretKey
  72. type: object
  73. type: array
  74. dataFrom:
  75. description: DataFrom is used to fetch all properties from a specific Provider data If multiple entries are specified, the Secret keys are merged in the specified order
  76. items:
  77. maxProperties: 1
  78. minProperties: 1
  79. properties:
  80. extract:
  81. description: Used to extract multiple key/value pairs from one secret
  82. properties:
  83. conversionStrategy:
  84. default: Default
  85. description: Used to define a conversion Strategy
  86. type: string
  87. key:
  88. description: Key is the key used in the Provider, mandatory
  89. type: string
  90. property:
  91. description: Used to select a specific property of the Provider value (if a map), if supported
  92. type: string
  93. version:
  94. description: Used to select a specific version of the Provider value, if supported
  95. type: string
  96. required:
  97. - key
  98. type: object
  99. find:
  100. description: Used to find secrets based on tags or regular expressions
  101. properties:
  102. conversionStrategy:
  103. default: Default
  104. description: Used to define a conversion Strategy
  105. type: string
  106. name:
  107. description: Finds secrets based on the name.
  108. properties:
  109. regexp:
  110. description: Finds secrets base
  111. type: string
  112. type: object
  113. path:
  114. description: A root path to start the find operations.
  115. type: string
  116. tags:
  117. additionalProperties:
  118. type: string
  119. description: Find secrets based on tags.
  120. type: object
  121. type: object
  122. type: object
  123. type: array
  124. refreshInterval:
  125. default: 1h
  126. description: RefreshInterval is the amount of time before the values are read again from the SecretStore provider Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h" May be set to zero to fetch and create it once. Defaults to 1h.
  127. type: string
  128. secretStoreRef:
  129. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  130. properties:
  131. kind:
  132. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  133. type: string
  134. name:
  135. description: Name of the SecretStore resource
  136. type: string
  137. required:
  138. - name
  139. type: object
  140. target:
  141. description: ExternalSecretTarget defines the Kubernetes Secret to be created There can be only one target per ExternalSecret.
  142. properties:
  143. creationPolicy:
  144. default: Owner
  145. description: CreationPolicy defines rules on how to create the resulting Secret Defaults to 'Owner'
  146. enum:
  147. - Owner
  148. - Orphan
  149. - Merge
  150. - None
  151. type: string
  152. deletionPolicy:
  153. default: Retain
  154. description: DeletionPolicy defines rules on how to delete the resulting Secret Defaults to 'Retain'
  155. enum:
  156. - Delete
  157. - Merge
  158. - Retain
  159. type: string
  160. immutable:
  161. description: Immutable defines if the final secret will be immutable
  162. type: boolean
  163. name:
  164. description: Name defines the name of the Secret resource to be managed This field is immutable Defaults to the .metadata.name of the ExternalSecret resource
  165. type: string
  166. template:
  167. description: Template defines a blueprint for the created Secret resource.
  168. properties:
  169. data:
  170. additionalProperties:
  171. type: string
  172. type: object
  173. engineVersion:
  174. default: v2
  175. type: string
  176. metadata:
  177. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  178. properties:
  179. annotations:
  180. additionalProperties:
  181. type: string
  182. type: object
  183. labels:
  184. additionalProperties:
  185. type: string
  186. type: object
  187. type: object
  188. templateFrom:
  189. items:
  190. maxProperties: 1
  191. minProperties: 1
  192. properties:
  193. configMap:
  194. properties:
  195. items:
  196. items:
  197. properties:
  198. key:
  199. type: string
  200. required:
  201. - key
  202. type: object
  203. type: array
  204. name:
  205. type: string
  206. required:
  207. - items
  208. - name
  209. type: object
  210. secret:
  211. properties:
  212. items:
  213. items:
  214. properties:
  215. key:
  216. type: string
  217. required:
  218. - key
  219. type: object
  220. type: array
  221. name:
  222. type: string
  223. required:
  224. - items
  225. - name
  226. type: object
  227. type: object
  228. type: array
  229. type:
  230. type: string
  231. type: object
  232. type: object
  233. required:
  234. - secretStoreRef
  235. type: object
  236. namespaceSelector:
  237. description: The labels to select by to find the Namespaces to create the ExternalSecrets in.
  238. properties:
  239. matchExpressions:
  240. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  241. items:
  242. description: A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
  243. properties:
  244. key:
  245. description: key is the label key that the selector applies to.
  246. type: string
  247. operator:
  248. description: operator represents a key's relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
  249. type: string
  250. values:
  251. description: values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.
  252. items:
  253. type: string
  254. type: array
  255. required:
  256. - key
  257. - operator
  258. type: object
  259. type: array
  260. matchLabels:
  261. additionalProperties:
  262. type: string
  263. description: matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.
  264. type: object
  265. type: object
  266. refreshTime:
  267. description: The time in which the controller should reconcile it's objects and recheck namespaces for labels.
  268. type: string
  269. required:
  270. - externalSecretSpec
  271. - namespaceSelector
  272. type: object
  273. status:
  274. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  275. properties:
  276. conditions:
  277. items:
  278. properties:
  279. message:
  280. type: string
  281. status:
  282. type: string
  283. type:
  284. type: string
  285. required:
  286. - status
  287. - type
  288. type: object
  289. type: array
  290. failedNamespaces:
  291. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  292. items:
  293. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  294. properties:
  295. namespace:
  296. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  297. type: string
  298. reason:
  299. description: Reason is why the ExternalSecret failed to apply to the namespace
  300. type: string
  301. required:
  302. - namespace
  303. type: object
  304. type: array
  305. provisionedNamespaces:
  306. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  307. items:
  308. type: string
  309. type: array
  310. type: object
  311. type: object
  312. served: true
  313. storage: true
  314. subresources:
  315. status: {}
  316. conversion:
  317. strategy: Webhook
  318. webhook:
  319. conversionReviewVersions:
  320. - v1
  321. clientConfig:
  322. service:
  323. name: kubernetes
  324. namespace: default
  325. path: /convert
  326. status:
  327. acceptedNames:
  328. kind: ""
  329. plural: ""
  330. conditions: []
  331. storedVersions: []
  332. ---
  333. apiVersion: apiextensions.k8s.io/v1
  334. kind: CustomResourceDefinition
  335. metadata:
  336. annotations:
  337. controller-gen.kubebuilder.io/version: v0.8.0
  338. creationTimestamp: null
  339. name: clustersecretstores.external-secrets.io
  340. spec:
  341. group: external-secrets.io
  342. names:
  343. categories:
  344. - externalsecrets
  345. kind: ClusterSecretStore
  346. listKind: ClusterSecretStoreList
  347. plural: clustersecretstores
  348. shortNames:
  349. - css
  350. singular: clustersecretstore
  351. scope: Cluster
  352. versions:
  353. - additionalPrinterColumns:
  354. - jsonPath: .metadata.creationTimestamp
  355. name: AGE
  356. type: date
  357. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  358. name: Status
  359. type: string
  360. deprecated: true
  361. name: v1alpha1
  362. schema:
  363. openAPIV3Schema:
  364. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  365. properties:
  366. apiVersion:
  367. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  368. type: string
  369. kind:
  370. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  371. type: string
  372. metadata:
  373. type: object
  374. spec:
  375. description: SecretStoreSpec defines the desired state of SecretStore.
  376. properties:
  377. controller:
  378. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  379. type: string
  380. provider:
  381. description: Used to configure the provider. Only one provider may be set
  382. maxProperties: 1
  383. minProperties: 1
  384. properties:
  385. akeyless:
  386. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  387. properties:
  388. akeylessGWApiURL:
  389. description: Akeyless GW API Url from which the secrets to be fetched from.
  390. type: string
  391. authSecretRef:
  392. description: Auth configures how the operator authenticates with Akeyless.
  393. properties:
  394. secretRef:
  395. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  396. properties:
  397. accessID:
  398. description: The SecretAccessID is used for authentication
  399. properties:
  400. key:
  401. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  402. type: string
  403. name:
  404. description: The name of the Secret resource being referred to.
  405. type: string
  406. namespace:
  407. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  408. type: string
  409. type: object
  410. accessType:
  411. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  412. properties:
  413. key:
  414. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  415. type: string
  416. name:
  417. description: The name of the Secret resource being referred to.
  418. type: string
  419. namespace:
  420. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  421. type: string
  422. type: object
  423. accessTypeParam:
  424. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  425. properties:
  426. key:
  427. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  428. type: string
  429. name:
  430. description: The name of the Secret resource being referred to.
  431. type: string
  432. namespace:
  433. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  434. type: string
  435. type: object
  436. type: object
  437. required:
  438. - secretRef
  439. type: object
  440. required:
  441. - akeylessGWApiURL
  442. - authSecretRef
  443. type: object
  444. alibaba:
  445. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  446. properties:
  447. auth:
  448. description: AlibabaAuth contains a secretRef for credentials.
  449. properties:
  450. secretRef:
  451. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  452. properties:
  453. accessKeyIDSecretRef:
  454. description: The AccessKeyID is used for authentication
  455. properties:
  456. key:
  457. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  458. type: string
  459. name:
  460. description: The name of the Secret resource being referred to.
  461. type: string
  462. namespace:
  463. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  464. type: string
  465. type: object
  466. accessKeySecretSecretRef:
  467. description: The AccessKeySecret is used for authentication
  468. properties:
  469. key:
  470. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  471. type: string
  472. name:
  473. description: The name of the Secret resource being referred to.
  474. type: string
  475. namespace:
  476. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  477. type: string
  478. type: object
  479. required:
  480. - accessKeyIDSecretRef
  481. - accessKeySecretSecretRef
  482. type: object
  483. required:
  484. - secretRef
  485. type: object
  486. endpoint:
  487. type: string
  488. regionID:
  489. description: Alibaba Region to be used for the provider
  490. type: string
  491. required:
  492. - auth
  493. - regionID
  494. type: object
  495. aws:
  496. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  497. properties:
  498. auth:
  499. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  500. properties:
  501. jwt:
  502. description: Authenticate against AWS using service account tokens.
  503. properties:
  504. serviceAccountRef:
  505. description: A reference to a ServiceAccount resource.
  506. properties:
  507. name:
  508. description: The name of the ServiceAccount resource being referred to.
  509. type: string
  510. namespace:
  511. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  512. type: string
  513. required:
  514. - name
  515. type: object
  516. type: object
  517. secretRef:
  518. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  519. properties:
  520. accessKeyIDSecretRef:
  521. description: The AccessKeyID is used for authentication
  522. properties:
  523. key:
  524. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  525. type: string
  526. name:
  527. description: The name of the Secret resource being referred to.
  528. type: string
  529. namespace:
  530. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  531. type: string
  532. type: object
  533. secretAccessKeySecretRef:
  534. description: The SecretAccessKey is used for authentication
  535. properties:
  536. key:
  537. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  538. type: string
  539. name:
  540. description: The name of the Secret resource being referred to.
  541. type: string
  542. namespace:
  543. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  544. type: string
  545. type: object
  546. type: object
  547. type: object
  548. region:
  549. description: AWS Region to be used for the provider
  550. type: string
  551. role:
  552. description: Role is a Role ARN which the SecretManager provider will assume
  553. type: string
  554. service:
  555. description: Service defines which service should be used to fetch the secrets
  556. enum:
  557. - SecretsManager
  558. - ParameterStore
  559. type: string
  560. required:
  561. - region
  562. - service
  563. type: object
  564. azurekv:
  565. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  566. properties:
  567. authSecretRef:
  568. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  569. properties:
  570. clientId:
  571. description: The Azure clientId of the service principle used for authentication.
  572. properties:
  573. key:
  574. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  575. type: string
  576. name:
  577. description: The name of the Secret resource being referred to.
  578. type: string
  579. namespace:
  580. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  581. type: string
  582. type: object
  583. clientSecret:
  584. description: The Azure ClientSecret of the service principle used for authentication.
  585. properties:
  586. key:
  587. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  588. type: string
  589. name:
  590. description: The name of the Secret resource being referred to.
  591. type: string
  592. namespace:
  593. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  594. type: string
  595. type: object
  596. type: object
  597. authType:
  598. default: ServicePrincipal
  599. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  600. enum:
  601. - ServicePrincipal
  602. - ManagedIdentity
  603. - WorkloadIdentity
  604. type: string
  605. identityId:
  606. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  607. type: string
  608. serviceAccountRef:
  609. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  610. properties:
  611. name:
  612. description: The name of the ServiceAccount resource being referred to.
  613. type: string
  614. namespace:
  615. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  616. type: string
  617. required:
  618. - name
  619. type: object
  620. tenantId:
  621. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  622. type: string
  623. vaultUrl:
  624. description: Vault Url from which the secrets to be fetched from.
  625. type: string
  626. required:
  627. - vaultUrl
  628. type: object
  629. fake:
  630. description: Fake configures a store with static key/value pairs
  631. properties:
  632. data:
  633. items:
  634. properties:
  635. key:
  636. type: string
  637. value:
  638. type: string
  639. valueMap:
  640. additionalProperties:
  641. type: string
  642. type: object
  643. version:
  644. type: string
  645. required:
  646. - key
  647. type: object
  648. type: array
  649. required:
  650. - data
  651. type: object
  652. gcpsm:
  653. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  654. properties:
  655. auth:
  656. description: Auth defines the information necessary to authenticate against GCP
  657. properties:
  658. secretRef:
  659. properties:
  660. secretAccessKeySecretRef:
  661. description: The SecretAccessKey is used for authentication
  662. properties:
  663. key:
  664. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  665. type: string
  666. name:
  667. description: The name of the Secret resource being referred to.
  668. type: string
  669. namespace:
  670. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  671. type: string
  672. type: object
  673. type: object
  674. workloadIdentity:
  675. properties:
  676. clusterLocation:
  677. type: string
  678. clusterName:
  679. type: string
  680. clusterProjectID:
  681. type: string
  682. serviceAccountRef:
  683. description: A reference to a ServiceAccount resource.
  684. properties:
  685. name:
  686. description: The name of the ServiceAccount resource being referred to.
  687. type: string
  688. namespace:
  689. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  690. type: string
  691. required:
  692. - name
  693. type: object
  694. required:
  695. - clusterLocation
  696. - clusterName
  697. - serviceAccountRef
  698. type: object
  699. type: object
  700. projectID:
  701. description: ProjectID project where secret is located
  702. type: string
  703. type: object
  704. gitlab:
  705. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  706. properties:
  707. auth:
  708. description: Auth configures how secret-manager authenticates with a GitLab instance.
  709. properties:
  710. SecretRef:
  711. properties:
  712. accessToken:
  713. description: AccessToken is used for authentication.
  714. properties:
  715. key:
  716. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  717. type: string
  718. name:
  719. description: The name of the Secret resource being referred to.
  720. type: string
  721. namespace:
  722. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  723. type: string
  724. type: object
  725. type: object
  726. required:
  727. - SecretRef
  728. type: object
  729. projectID:
  730. description: ProjectID specifies a project where secrets are located.
  731. type: string
  732. url:
  733. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  734. type: string
  735. required:
  736. - auth
  737. type: object
  738. ibm:
  739. description: IBM configures this store to sync secrets using IBM Cloud provider
  740. properties:
  741. auth:
  742. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  743. properties:
  744. secretRef:
  745. properties:
  746. secretApiKeySecretRef:
  747. description: The SecretAccessKey is used for authentication
  748. properties:
  749. key:
  750. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  751. type: string
  752. name:
  753. description: The name of the Secret resource being referred to.
  754. type: string
  755. namespace:
  756. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  757. type: string
  758. type: object
  759. type: object
  760. required:
  761. - secretRef
  762. type: object
  763. serviceUrl:
  764. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  765. type: string
  766. required:
  767. - auth
  768. type: object
  769. kubernetes:
  770. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  771. properties:
  772. auth:
  773. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  774. maxProperties: 1
  775. minProperties: 1
  776. properties:
  777. cert:
  778. description: has both clientCert and clientKey as secretKeySelector
  779. properties:
  780. clientCert:
  781. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  782. properties:
  783. key:
  784. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  785. type: string
  786. name:
  787. description: The name of the Secret resource being referred to.
  788. type: string
  789. namespace:
  790. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  791. type: string
  792. type: object
  793. clientKey:
  794. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  795. properties:
  796. key:
  797. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  798. type: string
  799. name:
  800. description: The name of the Secret resource being referred to.
  801. type: string
  802. namespace:
  803. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  804. type: string
  805. type: object
  806. type: object
  807. serviceAccount:
  808. description: points to a service account that should be used for authentication
  809. properties:
  810. serviceAccount:
  811. description: A reference to a ServiceAccount resource.
  812. properties:
  813. name:
  814. description: The name of the ServiceAccount resource being referred to.
  815. type: string
  816. namespace:
  817. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  818. type: string
  819. required:
  820. - name
  821. type: object
  822. type: object
  823. token:
  824. description: use static token to authenticate with
  825. properties:
  826. bearerToken:
  827. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  828. properties:
  829. key:
  830. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  831. type: string
  832. name:
  833. description: The name of the Secret resource being referred to.
  834. type: string
  835. namespace:
  836. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  837. type: string
  838. type: object
  839. type: object
  840. type: object
  841. remoteNamespace:
  842. default: default
  843. description: Remote namespace to fetch the secrets from
  844. type: string
  845. server:
  846. description: configures the Kubernetes server Address.
  847. properties:
  848. caBundle:
  849. description: CABundle is a base64-encoded CA certificate
  850. format: byte
  851. type: string
  852. caProvider:
  853. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  854. properties:
  855. key:
  856. description: The key the value inside of the provider type to use, only used with "Secret" type
  857. type: string
  858. name:
  859. description: The name of the object located at the provider type.
  860. type: string
  861. namespace:
  862. description: The namespace the Provider type is in.
  863. type: string
  864. type:
  865. description: The type of provider to use such as "Secret", or "ConfigMap".
  866. enum:
  867. - Secret
  868. - ConfigMap
  869. type: string
  870. required:
  871. - name
  872. - type
  873. type: object
  874. url:
  875. default: kubernetes.default
  876. description: configures the Kubernetes server Address.
  877. type: string
  878. type: object
  879. required:
  880. - auth
  881. type: object
  882. oracle:
  883. description: Oracle configures this store to sync secrets using Oracle Vault provider
  884. properties:
  885. auth:
  886. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  887. properties:
  888. secretRef:
  889. description: SecretRef to pass through sensitive information.
  890. properties:
  891. fingerprint:
  892. description: Fingerprint is the fingerprint of the API private key.
  893. properties:
  894. key:
  895. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  896. type: string
  897. name:
  898. description: The name of the Secret resource being referred to.
  899. type: string
  900. namespace:
  901. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  902. type: string
  903. type: object
  904. privatekey:
  905. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  906. properties:
  907. key:
  908. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  909. type: string
  910. name:
  911. description: The name of the Secret resource being referred to.
  912. type: string
  913. namespace:
  914. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  915. type: string
  916. type: object
  917. required:
  918. - fingerprint
  919. - privatekey
  920. type: object
  921. tenancy:
  922. description: Tenancy is the tenancy OCID where user is located.
  923. type: string
  924. user:
  925. description: User is an access OCID specific to the account.
  926. type: string
  927. required:
  928. - secretRef
  929. - tenancy
  930. - user
  931. type: object
  932. region:
  933. description: Region is the region where vault is located.
  934. type: string
  935. vault:
  936. description: Vault is the vault's OCID of the specific vault where secret is located.
  937. type: string
  938. required:
  939. - region
  940. - vault
  941. type: object
  942. vault:
  943. description: Vault configures this store to sync secrets using Hashi provider
  944. properties:
  945. auth:
  946. description: Auth configures how secret-manager authenticates with the Vault server.
  947. properties:
  948. appRole:
  949. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  950. properties:
  951. path:
  952. default: approle
  953. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  954. type: string
  955. roleId:
  956. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  957. type: string
  958. secretRef:
  959. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  960. properties:
  961. key:
  962. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  963. type: string
  964. name:
  965. description: The name of the Secret resource being referred to.
  966. type: string
  967. namespace:
  968. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  969. type: string
  970. type: object
  971. required:
  972. - path
  973. - roleId
  974. - secretRef
  975. type: object
  976. cert:
  977. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  978. properties:
  979. clientCert:
  980. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  981. properties:
  982. key:
  983. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  984. type: string
  985. name:
  986. description: The name of the Secret resource being referred to.
  987. type: string
  988. namespace:
  989. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  990. type: string
  991. type: object
  992. secretRef:
  993. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  994. properties:
  995. key:
  996. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  997. type: string
  998. name:
  999. description: The name of the Secret resource being referred to.
  1000. type: string
  1001. namespace:
  1002. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1003. type: string
  1004. type: object
  1005. type: object
  1006. jwt:
  1007. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  1008. properties:
  1009. kubernetesServiceAccountToken:
  1010. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  1011. properties:
  1012. audiences:
  1013. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  1014. items:
  1015. type: string
  1016. type: array
  1017. expirationSeconds:
  1018. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  1019. format: int64
  1020. type: integer
  1021. serviceAccountRef:
  1022. description: Service account field containing the name of a kubernetes ServiceAccount.
  1023. properties:
  1024. name:
  1025. description: The name of the ServiceAccount resource being referred to.
  1026. type: string
  1027. namespace:
  1028. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1029. type: string
  1030. required:
  1031. - name
  1032. type: object
  1033. required:
  1034. - serviceAccountRef
  1035. type: object
  1036. path:
  1037. default: jwt
  1038. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  1039. type: string
  1040. role:
  1041. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  1042. type: string
  1043. secretRef:
  1044. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  1045. properties:
  1046. key:
  1047. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1048. type: string
  1049. name:
  1050. description: The name of the Secret resource being referred to.
  1051. type: string
  1052. namespace:
  1053. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1054. type: string
  1055. type: object
  1056. required:
  1057. - path
  1058. type: object
  1059. kubernetes:
  1060. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  1061. properties:
  1062. mountPath:
  1063. default: kubernetes
  1064. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  1065. type: string
  1066. role:
  1067. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  1068. type: string
  1069. secretRef:
  1070. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  1071. properties:
  1072. key:
  1073. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1074. type: string
  1075. name:
  1076. description: The name of the Secret resource being referred to.
  1077. type: string
  1078. namespace:
  1079. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1080. type: string
  1081. type: object
  1082. serviceAccountRef:
  1083. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  1084. properties:
  1085. name:
  1086. description: The name of the ServiceAccount resource being referred to.
  1087. type: string
  1088. namespace:
  1089. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1090. type: string
  1091. required:
  1092. - name
  1093. type: object
  1094. required:
  1095. - mountPath
  1096. - role
  1097. type: object
  1098. ldap:
  1099. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  1100. properties:
  1101. path:
  1102. default: ldap
  1103. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  1104. type: string
  1105. secretRef:
  1106. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  1107. properties:
  1108. key:
  1109. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1110. type: string
  1111. name:
  1112. description: The name of the Secret resource being referred to.
  1113. type: string
  1114. namespace:
  1115. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1116. type: string
  1117. type: object
  1118. username:
  1119. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  1120. type: string
  1121. required:
  1122. - path
  1123. - username
  1124. type: object
  1125. tokenSecretRef:
  1126. description: TokenSecretRef authenticates with Vault by presenting a token.
  1127. properties:
  1128. key:
  1129. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1130. type: string
  1131. name:
  1132. description: The name of the Secret resource being referred to.
  1133. type: string
  1134. namespace:
  1135. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1136. type: string
  1137. type: object
  1138. type: object
  1139. caBundle:
  1140. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  1141. format: byte
  1142. type: string
  1143. caProvider:
  1144. description: The provider for the CA bundle to use to validate Vault server certificate.
  1145. properties:
  1146. key:
  1147. description: The key the value inside of the provider type to use, only used with "Secret" type
  1148. type: string
  1149. name:
  1150. description: The name of the object located at the provider type.
  1151. type: string
  1152. namespace:
  1153. description: The namespace the Provider type is in.
  1154. type: string
  1155. type:
  1156. description: The type of provider to use such as "Secret", or "ConfigMap".
  1157. enum:
  1158. - Secret
  1159. - ConfigMap
  1160. type: string
  1161. required:
  1162. - name
  1163. - type
  1164. type: object
  1165. forwardInconsistent:
  1166. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  1167. type: boolean
  1168. namespace:
  1169. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  1170. type: string
  1171. path:
  1172. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  1173. type: string
  1174. readYourWrites:
  1175. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  1176. type: boolean
  1177. server:
  1178. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  1179. type: string
  1180. version:
  1181. default: v2
  1182. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  1183. enum:
  1184. - v1
  1185. - v2
  1186. type: string
  1187. required:
  1188. - auth
  1189. - server
  1190. type: object
  1191. webhook:
  1192. description: Webhook configures this store to sync secrets using a generic templated webhook
  1193. properties:
  1194. body:
  1195. description: Body
  1196. type: string
  1197. caBundle:
  1198. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  1199. format: byte
  1200. type: string
  1201. caProvider:
  1202. description: The provider for the CA bundle to use to validate webhook server certificate.
  1203. properties:
  1204. key:
  1205. description: The key the value inside of the provider type to use, only used with "Secret" type
  1206. type: string
  1207. name:
  1208. description: The name of the object located at the provider type.
  1209. type: string
  1210. namespace:
  1211. description: The namespace the Provider type is in.
  1212. type: string
  1213. type:
  1214. description: The type of provider to use such as "Secret", or "ConfigMap".
  1215. enum:
  1216. - Secret
  1217. - ConfigMap
  1218. type: string
  1219. required:
  1220. - name
  1221. - type
  1222. type: object
  1223. headers:
  1224. additionalProperties:
  1225. type: string
  1226. description: Headers
  1227. type: object
  1228. method:
  1229. description: Webhook Method
  1230. type: string
  1231. result:
  1232. description: Result formatting
  1233. properties:
  1234. jsonPath:
  1235. description: Json path of return value
  1236. type: string
  1237. type: object
  1238. secrets:
  1239. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  1240. items:
  1241. properties:
  1242. name:
  1243. description: Name of this secret in templates
  1244. type: string
  1245. secretRef:
  1246. description: Secret ref to fill in credentials
  1247. properties:
  1248. key:
  1249. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1250. type: string
  1251. name:
  1252. description: The name of the Secret resource being referred to.
  1253. type: string
  1254. namespace:
  1255. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1256. type: string
  1257. type: object
  1258. required:
  1259. - name
  1260. - secretRef
  1261. type: object
  1262. type: array
  1263. timeout:
  1264. description: Timeout
  1265. type: string
  1266. url:
  1267. description: Webhook url to call
  1268. type: string
  1269. required:
  1270. - result
  1271. - url
  1272. type: object
  1273. yandexlockbox:
  1274. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  1275. properties:
  1276. apiEndpoint:
  1277. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  1278. type: string
  1279. auth:
  1280. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  1281. properties:
  1282. authorizedKeySecretRef:
  1283. description: The authorized key used for authentication
  1284. properties:
  1285. key:
  1286. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1287. type: string
  1288. name:
  1289. description: The name of the Secret resource being referred to.
  1290. type: string
  1291. namespace:
  1292. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1293. type: string
  1294. type: object
  1295. type: object
  1296. caProvider:
  1297. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  1298. properties:
  1299. certSecretRef:
  1300. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1301. properties:
  1302. key:
  1303. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1304. type: string
  1305. name:
  1306. description: The name of the Secret resource being referred to.
  1307. type: string
  1308. namespace:
  1309. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1310. type: string
  1311. type: object
  1312. type: object
  1313. required:
  1314. - auth
  1315. type: object
  1316. type: object
  1317. retrySettings:
  1318. description: Used to configure http retries if failed
  1319. properties:
  1320. maxRetries:
  1321. format: int32
  1322. type: integer
  1323. retryInterval:
  1324. type: string
  1325. type: object
  1326. required:
  1327. - provider
  1328. type: object
  1329. status:
  1330. description: SecretStoreStatus defines the observed state of the SecretStore.
  1331. properties:
  1332. conditions:
  1333. items:
  1334. properties:
  1335. lastTransitionTime:
  1336. format: date-time
  1337. type: string
  1338. message:
  1339. type: string
  1340. reason:
  1341. type: string
  1342. status:
  1343. type: string
  1344. type:
  1345. type: string
  1346. required:
  1347. - status
  1348. - type
  1349. type: object
  1350. type: array
  1351. type: object
  1352. type: object
  1353. served: true
  1354. storage: false
  1355. subresources:
  1356. status: {}
  1357. - additionalPrinterColumns:
  1358. - jsonPath: .metadata.creationTimestamp
  1359. name: AGE
  1360. type: date
  1361. name: v1beta1
  1362. schema:
  1363. openAPIV3Schema:
  1364. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  1365. properties:
  1366. apiVersion:
  1367. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  1368. type: string
  1369. kind:
  1370. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  1371. type: string
  1372. metadata:
  1373. type: object
  1374. spec:
  1375. description: SecretStoreSpec defines the desired state of SecretStore.
  1376. properties:
  1377. controller:
  1378. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  1379. type: string
  1380. provider:
  1381. description: Used to configure the provider. Only one provider may be set
  1382. maxProperties: 1
  1383. minProperties: 1
  1384. properties:
  1385. akeyless:
  1386. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  1387. properties:
  1388. akeylessGWApiURL:
  1389. description: Akeyless GW API Url from which the secrets to be fetched from.
  1390. type: string
  1391. authSecretRef:
  1392. description: Auth configures how the operator authenticates with Akeyless.
  1393. properties:
  1394. secretRef:
  1395. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  1396. properties:
  1397. accessID:
  1398. description: The SecretAccessID is used for authentication
  1399. properties:
  1400. key:
  1401. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1402. type: string
  1403. name:
  1404. description: The name of the Secret resource being referred to.
  1405. type: string
  1406. namespace:
  1407. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1408. type: string
  1409. type: object
  1410. accessType:
  1411. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1412. properties:
  1413. key:
  1414. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1415. type: string
  1416. name:
  1417. description: The name of the Secret resource being referred to.
  1418. type: string
  1419. namespace:
  1420. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1421. type: string
  1422. type: object
  1423. accessTypeParam:
  1424. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1425. properties:
  1426. key:
  1427. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1428. type: string
  1429. name:
  1430. description: The name of the Secret resource being referred to.
  1431. type: string
  1432. namespace:
  1433. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1434. type: string
  1435. type: object
  1436. type: object
  1437. required:
  1438. - secretRef
  1439. type: object
  1440. required:
  1441. - akeylessGWApiURL
  1442. - authSecretRef
  1443. type: object
  1444. alibaba:
  1445. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  1446. properties:
  1447. auth:
  1448. description: AlibabaAuth contains a secretRef for credentials.
  1449. properties:
  1450. secretRef:
  1451. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  1452. properties:
  1453. accessKeyIDSecretRef:
  1454. description: The AccessKeyID is used for authentication
  1455. properties:
  1456. key:
  1457. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1458. type: string
  1459. name:
  1460. description: The name of the Secret resource being referred to.
  1461. type: string
  1462. namespace:
  1463. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1464. type: string
  1465. type: object
  1466. accessKeySecretSecretRef:
  1467. description: The AccessKeySecret is used for authentication
  1468. properties:
  1469. key:
  1470. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1471. type: string
  1472. name:
  1473. description: The name of the Secret resource being referred to.
  1474. type: string
  1475. namespace:
  1476. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1477. type: string
  1478. type: object
  1479. required:
  1480. - accessKeyIDSecretRef
  1481. - accessKeySecretSecretRef
  1482. type: object
  1483. required:
  1484. - secretRef
  1485. type: object
  1486. endpoint:
  1487. type: string
  1488. regionID:
  1489. description: Alibaba Region to be used for the provider
  1490. type: string
  1491. required:
  1492. - auth
  1493. - regionID
  1494. type: object
  1495. aws:
  1496. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  1497. properties:
  1498. auth:
  1499. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  1500. properties:
  1501. jwt:
  1502. description: Authenticate against AWS using service account tokens.
  1503. properties:
  1504. serviceAccountRef:
  1505. description: A reference to a ServiceAccount resource.
  1506. properties:
  1507. name:
  1508. description: The name of the ServiceAccount resource being referred to.
  1509. type: string
  1510. namespace:
  1511. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1512. type: string
  1513. required:
  1514. - name
  1515. type: object
  1516. type: object
  1517. secretRef:
  1518. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  1519. properties:
  1520. accessKeyIDSecretRef:
  1521. description: The AccessKeyID is used for authentication
  1522. properties:
  1523. key:
  1524. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1525. type: string
  1526. name:
  1527. description: The name of the Secret resource being referred to.
  1528. type: string
  1529. namespace:
  1530. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1531. type: string
  1532. type: object
  1533. secretAccessKeySecretRef:
  1534. description: The SecretAccessKey is used for authentication
  1535. properties:
  1536. key:
  1537. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1538. type: string
  1539. name:
  1540. description: The name of the Secret resource being referred to.
  1541. type: string
  1542. namespace:
  1543. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1544. type: string
  1545. type: object
  1546. type: object
  1547. type: object
  1548. region:
  1549. description: AWS Region to be used for the provider
  1550. type: string
  1551. role:
  1552. description: Role is a Role ARN which the SecretManager provider will assume
  1553. type: string
  1554. service:
  1555. description: Service defines which service should be used to fetch the secrets
  1556. enum:
  1557. - SecretsManager
  1558. - ParameterStore
  1559. type: string
  1560. required:
  1561. - region
  1562. - service
  1563. type: object
  1564. azurekv:
  1565. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  1566. properties:
  1567. authSecretRef:
  1568. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  1569. properties:
  1570. clientId:
  1571. description: The Azure clientId of the service principle used for authentication.
  1572. properties:
  1573. key:
  1574. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1575. type: string
  1576. name:
  1577. description: The name of the Secret resource being referred to.
  1578. type: string
  1579. namespace:
  1580. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1581. type: string
  1582. type: object
  1583. clientSecret:
  1584. description: The Azure ClientSecret of the service principle used for authentication.
  1585. properties:
  1586. key:
  1587. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1588. type: string
  1589. name:
  1590. description: The name of the Secret resource being referred to.
  1591. type: string
  1592. namespace:
  1593. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1594. type: string
  1595. type: object
  1596. type: object
  1597. authType:
  1598. default: ServicePrincipal
  1599. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  1600. enum:
  1601. - ServicePrincipal
  1602. - ManagedIdentity
  1603. - WorkloadIdentity
  1604. type: string
  1605. identityId:
  1606. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  1607. type: string
  1608. serviceAccountRef:
  1609. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  1610. properties:
  1611. name:
  1612. description: The name of the ServiceAccount resource being referred to.
  1613. type: string
  1614. namespace:
  1615. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1616. type: string
  1617. required:
  1618. - name
  1619. type: object
  1620. tenantId:
  1621. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  1622. type: string
  1623. vaultUrl:
  1624. description: Vault Url from which the secrets to be fetched from.
  1625. type: string
  1626. required:
  1627. - vaultUrl
  1628. type: object
  1629. fake:
  1630. description: Fake configures a store with static key/value pairs
  1631. properties:
  1632. data:
  1633. items:
  1634. properties:
  1635. key:
  1636. type: string
  1637. value:
  1638. type: string
  1639. valueMap:
  1640. additionalProperties:
  1641. type: string
  1642. type: object
  1643. version:
  1644. type: string
  1645. required:
  1646. - key
  1647. type: object
  1648. type: array
  1649. required:
  1650. - data
  1651. type: object
  1652. gcpsm:
  1653. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  1654. properties:
  1655. auth:
  1656. description: Auth defines the information necessary to authenticate against GCP
  1657. properties:
  1658. secretRef:
  1659. properties:
  1660. secretAccessKeySecretRef:
  1661. description: The SecretAccessKey is used for authentication
  1662. properties:
  1663. key:
  1664. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1665. type: string
  1666. name:
  1667. description: The name of the Secret resource being referred to.
  1668. type: string
  1669. namespace:
  1670. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1671. type: string
  1672. type: object
  1673. type: object
  1674. workloadIdentity:
  1675. properties:
  1676. clusterLocation:
  1677. type: string
  1678. clusterName:
  1679. type: string
  1680. clusterProjectID:
  1681. type: string
  1682. serviceAccountRef:
  1683. description: A reference to a ServiceAccount resource.
  1684. properties:
  1685. name:
  1686. description: The name of the ServiceAccount resource being referred to.
  1687. type: string
  1688. namespace:
  1689. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1690. type: string
  1691. required:
  1692. - name
  1693. type: object
  1694. required:
  1695. - clusterLocation
  1696. - clusterName
  1697. - serviceAccountRef
  1698. type: object
  1699. type: object
  1700. projectID:
  1701. description: ProjectID project where secret is located
  1702. type: string
  1703. type: object
  1704. gitlab:
  1705. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  1706. properties:
  1707. auth:
  1708. description: Auth configures how secret-manager authenticates with a GitLab instance.
  1709. properties:
  1710. SecretRef:
  1711. properties:
  1712. accessToken:
  1713. description: AccessToken is used for authentication.
  1714. properties:
  1715. key:
  1716. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1717. type: string
  1718. name:
  1719. description: The name of the Secret resource being referred to.
  1720. type: string
  1721. namespace:
  1722. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1723. type: string
  1724. type: object
  1725. type: object
  1726. required:
  1727. - SecretRef
  1728. type: object
  1729. projectID:
  1730. description: ProjectID specifies a project where secrets are located.
  1731. type: string
  1732. url:
  1733. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  1734. type: string
  1735. required:
  1736. - auth
  1737. type: object
  1738. ibm:
  1739. description: IBM configures this store to sync secrets using IBM Cloud provider
  1740. properties:
  1741. auth:
  1742. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  1743. properties:
  1744. secretRef:
  1745. properties:
  1746. secretApiKeySecretRef:
  1747. description: The SecretAccessKey is used for authentication
  1748. properties:
  1749. key:
  1750. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1751. type: string
  1752. name:
  1753. description: The name of the Secret resource being referred to.
  1754. type: string
  1755. namespace:
  1756. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1757. type: string
  1758. type: object
  1759. type: object
  1760. required:
  1761. - secretRef
  1762. type: object
  1763. serviceUrl:
  1764. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  1765. type: string
  1766. required:
  1767. - auth
  1768. type: object
  1769. kubernetes:
  1770. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  1771. properties:
  1772. auth:
  1773. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  1774. maxProperties: 1
  1775. minProperties: 1
  1776. properties:
  1777. cert:
  1778. description: has both clientCert and clientKey as secretKeySelector
  1779. properties:
  1780. clientCert:
  1781. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1782. properties:
  1783. key:
  1784. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1785. type: string
  1786. name:
  1787. description: The name of the Secret resource being referred to.
  1788. type: string
  1789. namespace:
  1790. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1791. type: string
  1792. type: object
  1793. clientKey:
  1794. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1795. properties:
  1796. key:
  1797. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1798. type: string
  1799. name:
  1800. description: The name of the Secret resource being referred to.
  1801. type: string
  1802. namespace:
  1803. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1804. type: string
  1805. type: object
  1806. type: object
  1807. serviceAccount:
  1808. description: points to a service account that should be used for authentication
  1809. properties:
  1810. serviceAccount:
  1811. description: A reference to a ServiceAccount resource.
  1812. properties:
  1813. name:
  1814. description: The name of the ServiceAccount resource being referred to.
  1815. type: string
  1816. namespace:
  1817. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1818. type: string
  1819. required:
  1820. - name
  1821. type: object
  1822. type: object
  1823. token:
  1824. description: use static token to authenticate with
  1825. properties:
  1826. bearerToken:
  1827. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1828. properties:
  1829. key:
  1830. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1831. type: string
  1832. name:
  1833. description: The name of the Secret resource being referred to.
  1834. type: string
  1835. namespace:
  1836. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1837. type: string
  1838. type: object
  1839. type: object
  1840. type: object
  1841. remoteNamespace:
  1842. default: default
  1843. description: Remote namespace to fetch the secrets from
  1844. type: string
  1845. server:
  1846. description: configures the Kubernetes server Address.
  1847. properties:
  1848. caBundle:
  1849. description: CABundle is a base64-encoded CA certificate
  1850. format: byte
  1851. type: string
  1852. caProvider:
  1853. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  1854. properties:
  1855. key:
  1856. description: The key the value inside of the provider type to use, only used with "Secret" type
  1857. type: string
  1858. name:
  1859. description: The name of the object located at the provider type.
  1860. type: string
  1861. namespace:
  1862. description: The namespace the Provider type is in.
  1863. type: string
  1864. type:
  1865. description: The type of provider to use such as "Secret", or "ConfigMap".
  1866. enum:
  1867. - Secret
  1868. - ConfigMap
  1869. type: string
  1870. required:
  1871. - name
  1872. - type
  1873. type: object
  1874. url:
  1875. default: kubernetes.default
  1876. description: configures the Kubernetes server Address.
  1877. type: string
  1878. type: object
  1879. required:
  1880. - auth
  1881. type: object
  1882. oracle:
  1883. description: Oracle configures this store to sync secrets using Oracle Vault provider
  1884. properties:
  1885. auth:
  1886. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  1887. properties:
  1888. secretRef:
  1889. description: SecretRef to pass through sensitive information.
  1890. properties:
  1891. fingerprint:
  1892. description: Fingerprint is the fingerprint of the API private key.
  1893. properties:
  1894. key:
  1895. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1896. type: string
  1897. name:
  1898. description: The name of the Secret resource being referred to.
  1899. type: string
  1900. namespace:
  1901. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1902. type: string
  1903. type: object
  1904. privatekey:
  1905. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  1906. properties:
  1907. key:
  1908. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1909. type: string
  1910. name:
  1911. description: The name of the Secret resource being referred to.
  1912. type: string
  1913. namespace:
  1914. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1915. type: string
  1916. type: object
  1917. required:
  1918. - fingerprint
  1919. - privatekey
  1920. type: object
  1921. tenancy:
  1922. description: Tenancy is the tenancy OCID where user is located.
  1923. type: string
  1924. user:
  1925. description: User is an access OCID specific to the account.
  1926. type: string
  1927. required:
  1928. - secretRef
  1929. - tenancy
  1930. - user
  1931. type: object
  1932. region:
  1933. description: Region is the region where vault is located.
  1934. type: string
  1935. vault:
  1936. description: Vault is the vault's OCID of the specific vault where secret is located.
  1937. type: string
  1938. required:
  1939. - region
  1940. - vault
  1941. type: object
  1942. senhasegura:
  1943. description: Senhasegura configures this store to sync secrets using senhasegura provider
  1944. properties:
  1945. auth:
  1946. description: Auth defines parameters to authenticate in senhasegura
  1947. properties:
  1948. clientId:
  1949. type: string
  1950. clientSecretSecretRef:
  1951. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  1952. properties:
  1953. key:
  1954. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  1955. type: string
  1956. name:
  1957. description: The name of the Secret resource being referred to.
  1958. type: string
  1959. namespace:
  1960. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  1961. type: string
  1962. type: object
  1963. required:
  1964. - clientId
  1965. - clientSecretSecretRef
  1966. type: object
  1967. ignoreSslCertificate:
  1968. default: false
  1969. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  1970. type: boolean
  1971. module:
  1972. description: Module defines which senhasegura module should be used to get secrets
  1973. type: string
  1974. url:
  1975. description: URL of senhasegura
  1976. type: string
  1977. required:
  1978. - auth
  1979. - module
  1980. - url
  1981. type: object
  1982. vault:
  1983. description: Vault configures this store to sync secrets using Hashi provider
  1984. properties:
  1985. auth:
  1986. description: Auth configures how secret-manager authenticates with the Vault server.
  1987. properties:
  1988. appRole:
  1989. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  1990. properties:
  1991. path:
  1992. default: approle
  1993. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  1994. type: string
  1995. roleId:
  1996. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  1997. type: string
  1998. secretRef:
  1999. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  2000. properties:
  2001. key:
  2002. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2003. type: string
  2004. name:
  2005. description: The name of the Secret resource being referred to.
  2006. type: string
  2007. namespace:
  2008. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2009. type: string
  2010. type: object
  2011. required:
  2012. - path
  2013. - roleId
  2014. - secretRef
  2015. type: object
  2016. cert:
  2017. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  2018. properties:
  2019. clientCert:
  2020. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  2021. properties:
  2022. key:
  2023. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2024. type: string
  2025. name:
  2026. description: The name of the Secret resource being referred to.
  2027. type: string
  2028. namespace:
  2029. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2030. type: string
  2031. type: object
  2032. secretRef:
  2033. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  2034. properties:
  2035. key:
  2036. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2037. type: string
  2038. name:
  2039. description: The name of the Secret resource being referred to.
  2040. type: string
  2041. namespace:
  2042. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2043. type: string
  2044. type: object
  2045. type: object
  2046. jwt:
  2047. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  2048. properties:
  2049. kubernetesServiceAccountToken:
  2050. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  2051. properties:
  2052. audiences:
  2053. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  2054. items:
  2055. type: string
  2056. type: array
  2057. expirationSeconds:
  2058. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  2059. format: int64
  2060. type: integer
  2061. serviceAccountRef:
  2062. description: Service account field containing the name of a kubernetes ServiceAccount.
  2063. properties:
  2064. name:
  2065. description: The name of the ServiceAccount resource being referred to.
  2066. type: string
  2067. namespace:
  2068. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2069. type: string
  2070. required:
  2071. - name
  2072. type: object
  2073. required:
  2074. - serviceAccountRef
  2075. type: object
  2076. path:
  2077. default: jwt
  2078. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  2079. type: string
  2080. role:
  2081. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  2082. type: string
  2083. secretRef:
  2084. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  2085. properties:
  2086. key:
  2087. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2088. type: string
  2089. name:
  2090. description: The name of the Secret resource being referred to.
  2091. type: string
  2092. namespace:
  2093. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2094. type: string
  2095. type: object
  2096. required:
  2097. - path
  2098. type: object
  2099. kubernetes:
  2100. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  2101. properties:
  2102. mountPath:
  2103. default: kubernetes
  2104. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  2105. type: string
  2106. role:
  2107. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  2108. type: string
  2109. secretRef:
  2110. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  2111. properties:
  2112. key:
  2113. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2114. type: string
  2115. name:
  2116. description: The name of the Secret resource being referred to.
  2117. type: string
  2118. namespace:
  2119. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2120. type: string
  2121. type: object
  2122. serviceAccountRef:
  2123. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  2124. properties:
  2125. name:
  2126. description: The name of the ServiceAccount resource being referred to.
  2127. type: string
  2128. namespace:
  2129. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2130. type: string
  2131. required:
  2132. - name
  2133. type: object
  2134. required:
  2135. - mountPath
  2136. - role
  2137. type: object
  2138. ldap:
  2139. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  2140. properties:
  2141. path:
  2142. default: ldap
  2143. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  2144. type: string
  2145. secretRef:
  2146. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  2147. properties:
  2148. key:
  2149. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2150. type: string
  2151. name:
  2152. description: The name of the Secret resource being referred to.
  2153. type: string
  2154. namespace:
  2155. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2156. type: string
  2157. type: object
  2158. username:
  2159. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  2160. type: string
  2161. required:
  2162. - path
  2163. - username
  2164. type: object
  2165. tokenSecretRef:
  2166. description: TokenSecretRef authenticates with Vault by presenting a token.
  2167. properties:
  2168. key:
  2169. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2170. type: string
  2171. name:
  2172. description: The name of the Secret resource being referred to.
  2173. type: string
  2174. namespace:
  2175. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2176. type: string
  2177. type: object
  2178. type: object
  2179. caBundle:
  2180. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  2181. format: byte
  2182. type: string
  2183. caProvider:
  2184. description: The provider for the CA bundle to use to validate Vault server certificate.
  2185. properties:
  2186. key:
  2187. description: The key the value inside of the provider type to use, only used with "Secret" type
  2188. type: string
  2189. name:
  2190. description: The name of the object located at the provider type.
  2191. type: string
  2192. namespace:
  2193. description: The namespace the Provider type is in.
  2194. type: string
  2195. type:
  2196. description: The type of provider to use such as "Secret", or "ConfigMap".
  2197. enum:
  2198. - Secret
  2199. - ConfigMap
  2200. type: string
  2201. required:
  2202. - name
  2203. - type
  2204. type: object
  2205. forwardInconsistent:
  2206. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  2207. type: boolean
  2208. namespace:
  2209. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  2210. type: string
  2211. path:
  2212. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  2213. type: string
  2214. readYourWrites:
  2215. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  2216. type: boolean
  2217. server:
  2218. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  2219. type: string
  2220. version:
  2221. default: v2
  2222. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  2223. enum:
  2224. - v1
  2225. - v2
  2226. type: string
  2227. required:
  2228. - auth
  2229. - server
  2230. type: object
  2231. webhook:
  2232. description: Webhook configures this store to sync secrets using a generic templated webhook
  2233. properties:
  2234. body:
  2235. description: Body
  2236. type: string
  2237. caBundle:
  2238. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  2239. format: byte
  2240. type: string
  2241. caProvider:
  2242. description: The provider for the CA bundle to use to validate webhook server certificate.
  2243. properties:
  2244. key:
  2245. description: The key the value inside of the provider type to use, only used with "Secret" type
  2246. type: string
  2247. name:
  2248. description: The name of the object located at the provider type.
  2249. type: string
  2250. namespace:
  2251. description: The namespace the Provider type is in.
  2252. type: string
  2253. type:
  2254. description: The type of provider to use such as "Secret", or "ConfigMap".
  2255. enum:
  2256. - Secret
  2257. - ConfigMap
  2258. type: string
  2259. required:
  2260. - name
  2261. - type
  2262. type: object
  2263. headers:
  2264. additionalProperties:
  2265. type: string
  2266. description: Headers
  2267. type: object
  2268. method:
  2269. description: Webhook Method
  2270. type: string
  2271. result:
  2272. description: Result formatting
  2273. properties:
  2274. jsonPath:
  2275. description: Json path of return value
  2276. type: string
  2277. type: object
  2278. secrets:
  2279. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  2280. items:
  2281. properties:
  2282. name:
  2283. description: Name of this secret in templates
  2284. type: string
  2285. secretRef:
  2286. description: Secret ref to fill in credentials
  2287. properties:
  2288. key:
  2289. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2290. type: string
  2291. name:
  2292. description: The name of the Secret resource being referred to.
  2293. type: string
  2294. namespace:
  2295. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2296. type: string
  2297. type: object
  2298. required:
  2299. - name
  2300. - secretRef
  2301. type: object
  2302. type: array
  2303. timeout:
  2304. description: Timeout
  2305. type: string
  2306. url:
  2307. description: Webhook url to call
  2308. type: string
  2309. required:
  2310. - result
  2311. - url
  2312. type: object
  2313. yandexlockbox:
  2314. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  2315. properties:
  2316. apiEndpoint:
  2317. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  2318. type: string
  2319. auth:
  2320. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  2321. properties:
  2322. authorizedKeySecretRef:
  2323. description: The authorized key used for authentication
  2324. properties:
  2325. key:
  2326. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2327. type: string
  2328. name:
  2329. description: The name of the Secret resource being referred to.
  2330. type: string
  2331. namespace:
  2332. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2333. type: string
  2334. type: object
  2335. type: object
  2336. caProvider:
  2337. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  2338. properties:
  2339. certSecretRef:
  2340. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  2341. properties:
  2342. key:
  2343. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  2344. type: string
  2345. name:
  2346. description: The name of the Secret resource being referred to.
  2347. type: string
  2348. namespace:
  2349. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  2350. type: string
  2351. type: object
  2352. type: object
  2353. required:
  2354. - auth
  2355. type: object
  2356. type: object
  2357. refreshInterval:
  2358. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  2359. type: integer
  2360. retrySettings:
  2361. description: Used to configure http retries if failed
  2362. properties:
  2363. maxRetries:
  2364. format: int32
  2365. type: integer
  2366. retryInterval:
  2367. type: string
  2368. type: object
  2369. required:
  2370. - provider
  2371. type: object
  2372. status:
  2373. description: SecretStoreStatus defines the observed state of the SecretStore.
  2374. properties:
  2375. conditions:
  2376. items:
  2377. properties:
  2378. lastTransitionTime:
  2379. format: date-time
  2380. type: string
  2381. message:
  2382. type: string
  2383. reason:
  2384. type: string
  2385. status:
  2386. type: string
  2387. type:
  2388. type: string
  2389. required:
  2390. - status
  2391. - type
  2392. type: object
  2393. type: array
  2394. type: object
  2395. type: object
  2396. served: true
  2397. storage: true
  2398. subresources:
  2399. status: {}
  2400. conversion:
  2401. strategy: Webhook
  2402. webhook:
  2403. conversionReviewVersions:
  2404. - v1
  2405. clientConfig:
  2406. service:
  2407. name: kubernetes
  2408. namespace: default
  2409. path: /convert
  2410. status:
  2411. acceptedNames:
  2412. kind: ""
  2413. plural: ""
  2414. conditions: []
  2415. storedVersions: []
  2416. ---
  2417. apiVersion: apiextensions.k8s.io/v1
  2418. kind: CustomResourceDefinition
  2419. metadata:
  2420. annotations:
  2421. controller-gen.kubebuilder.io/version: v0.8.0
  2422. creationTimestamp: null
  2423. name: externalsecrets.external-secrets.io
  2424. spec:
  2425. group: external-secrets.io
  2426. names:
  2427. categories:
  2428. - externalsecrets
  2429. kind: ExternalSecret
  2430. listKind: ExternalSecretList
  2431. plural: externalsecrets
  2432. shortNames:
  2433. - es
  2434. singular: externalsecret
  2435. scope: Namespaced
  2436. versions:
  2437. - additionalPrinterColumns:
  2438. - jsonPath: .spec.secretStoreRef.name
  2439. name: Store
  2440. type: string
  2441. - jsonPath: .spec.refreshInterval
  2442. name: Refresh Interval
  2443. type: string
  2444. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2445. name: Status
  2446. type: string
  2447. deprecated: true
  2448. name: v1alpha1
  2449. schema:
  2450. openAPIV3Schema:
  2451. description: ExternalSecret is the Schema for the external-secrets API.
  2452. properties:
  2453. apiVersion:
  2454. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  2455. type: string
  2456. kind:
  2457. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  2458. type: string
  2459. metadata:
  2460. type: object
  2461. spec:
  2462. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  2463. properties:
  2464. data:
  2465. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  2466. items:
  2467. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  2468. properties:
  2469. remoteRef:
  2470. description: ExternalSecretDataRemoteRef defines Provider data location.
  2471. properties:
  2472. conversionStrategy:
  2473. default: Default
  2474. description: Used to define a conversion Strategy
  2475. type: string
  2476. key:
  2477. description: Key is the key used in the Provider, mandatory
  2478. type: string
  2479. property:
  2480. description: Used to select a specific property of the Provider value (if a map), if supported
  2481. type: string
  2482. version:
  2483. description: Used to select a specific version of the Provider value, if supported
  2484. type: string
  2485. required:
  2486. - key
  2487. type: object
  2488. secretKey:
  2489. type: string
  2490. required:
  2491. - remoteRef
  2492. - secretKey
  2493. type: object
  2494. type: array
  2495. dataFrom:
  2496. description: DataFrom is used to fetch all properties from a specific Provider data If multiple entries are specified, the Secret keys are merged in the specified order
  2497. items:
  2498. description: ExternalSecretDataRemoteRef defines Provider data location.
  2499. properties:
  2500. conversionStrategy:
  2501. default: Default
  2502. description: Used to define a conversion Strategy
  2503. type: string
  2504. key:
  2505. description: Key is the key used in the Provider, mandatory
  2506. type: string
  2507. property:
  2508. description: Used to select a specific property of the Provider value (if a map), if supported
  2509. type: string
  2510. version:
  2511. description: Used to select a specific version of the Provider value, if supported
  2512. type: string
  2513. required:
  2514. - key
  2515. type: object
  2516. type: array
  2517. refreshInterval:
  2518. default: 1h
  2519. description: RefreshInterval is the amount of time before the values are read again from the SecretStore provider Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h" May be set to zero to fetch and create it once. Defaults to 1h.
  2520. type: string
  2521. secretStoreRef:
  2522. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  2523. properties:
  2524. kind:
  2525. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  2526. type: string
  2527. name:
  2528. description: Name of the SecretStore resource
  2529. type: string
  2530. required:
  2531. - name
  2532. type: object
  2533. target:
  2534. description: ExternalSecretTarget defines the Kubernetes Secret to be created There can be only one target per ExternalSecret.
  2535. properties:
  2536. creationPolicy:
  2537. default: Owner
  2538. description: CreationPolicy defines rules on how to create the resulting Secret Defaults to 'Owner'
  2539. type: string
  2540. immutable:
  2541. description: Immutable defines if the final secret will be immutable
  2542. type: boolean
  2543. name:
  2544. description: Name defines the name of the Secret resource to be managed This field is immutable Defaults to the .metadata.name of the ExternalSecret resource
  2545. type: string
  2546. template:
  2547. description: Template defines a blueprint for the created Secret resource.
  2548. properties:
  2549. data:
  2550. additionalProperties:
  2551. type: string
  2552. type: object
  2553. engineVersion:
  2554. default: v1
  2555. description: EngineVersion specifies the template engine version that should be used to compile/execute the template specified in .data and .templateFrom[].
  2556. type: string
  2557. metadata:
  2558. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2559. properties:
  2560. annotations:
  2561. additionalProperties:
  2562. type: string
  2563. type: object
  2564. labels:
  2565. additionalProperties:
  2566. type: string
  2567. type: object
  2568. type: object
  2569. templateFrom:
  2570. items:
  2571. maxProperties: 1
  2572. minProperties: 1
  2573. properties:
  2574. configMap:
  2575. properties:
  2576. items:
  2577. items:
  2578. properties:
  2579. key:
  2580. type: string
  2581. required:
  2582. - key
  2583. type: object
  2584. type: array
  2585. name:
  2586. type: string
  2587. required:
  2588. - items
  2589. - name
  2590. type: object
  2591. secret:
  2592. properties:
  2593. items:
  2594. items:
  2595. properties:
  2596. key:
  2597. type: string
  2598. required:
  2599. - key
  2600. type: object
  2601. type: array
  2602. name:
  2603. type: string
  2604. required:
  2605. - items
  2606. - name
  2607. type: object
  2608. type: object
  2609. type: array
  2610. type:
  2611. type: string
  2612. type: object
  2613. type: object
  2614. required:
  2615. - secretStoreRef
  2616. - target
  2617. type: object
  2618. status:
  2619. properties:
  2620. conditions:
  2621. items:
  2622. properties:
  2623. lastTransitionTime:
  2624. format: date-time
  2625. type: string
  2626. message:
  2627. type: string
  2628. reason:
  2629. type: string
  2630. status:
  2631. type: string
  2632. type:
  2633. type: string
  2634. required:
  2635. - status
  2636. - type
  2637. type: object
  2638. type: array
  2639. refreshTime:
  2640. description: refreshTime is the time and date the external secret was fetched and the target secret updated
  2641. format: date-time
  2642. nullable: true
  2643. type: string
  2644. syncedResourceVersion:
  2645. description: SyncedResourceVersion keeps track of the last synced version
  2646. type: string
  2647. type: object
  2648. type: object
  2649. served: true
  2650. storage: false
  2651. subresources:
  2652. status: {}
  2653. - additionalPrinterColumns:
  2654. - jsonPath: .spec.secretStoreRef.name
  2655. name: Store
  2656. type: string
  2657. - jsonPath: .spec.refreshInterval
  2658. name: Refresh Interval
  2659. type: string
  2660. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2661. name: Status
  2662. type: string
  2663. name: v1beta1
  2664. schema:
  2665. openAPIV3Schema:
  2666. description: ExternalSecret is the Schema for the external-secrets API.
  2667. properties:
  2668. apiVersion:
  2669. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  2670. type: string
  2671. kind:
  2672. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  2673. type: string
  2674. metadata:
  2675. type: object
  2676. spec:
  2677. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  2678. properties:
  2679. data:
  2680. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  2681. items:
  2682. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  2683. properties:
  2684. remoteRef:
  2685. description: ExternalSecretDataRemoteRef defines Provider data location.
  2686. properties:
  2687. conversionStrategy:
  2688. default: Default
  2689. description: Used to define a conversion Strategy
  2690. type: string
  2691. key:
  2692. description: Key is the key used in the Provider, mandatory
  2693. type: string
  2694. property:
  2695. description: Used to select a specific property of the Provider value (if a map), if supported
  2696. type: string
  2697. version:
  2698. description: Used to select a specific version of the Provider value, if supported
  2699. type: string
  2700. required:
  2701. - key
  2702. type: object
  2703. secretKey:
  2704. type: string
  2705. required:
  2706. - remoteRef
  2707. - secretKey
  2708. type: object
  2709. type: array
  2710. dataFrom:
  2711. description: DataFrom is used to fetch all properties from a specific Provider data If multiple entries are specified, the Secret keys are merged in the specified order
  2712. items:
  2713. maxProperties: 1
  2714. minProperties: 1
  2715. properties:
  2716. extract:
  2717. description: Used to extract multiple key/value pairs from one secret
  2718. properties:
  2719. conversionStrategy:
  2720. default: Default
  2721. description: Used to define a conversion Strategy
  2722. type: string
  2723. key:
  2724. description: Key is the key used in the Provider, mandatory
  2725. type: string
  2726. property:
  2727. description: Used to select a specific property of the Provider value (if a map), if supported
  2728. type: string
  2729. version:
  2730. description: Used to select a specific version of the Provider value, if supported
  2731. type: string
  2732. required:
  2733. - key
  2734. type: object
  2735. find:
  2736. description: Used to find secrets based on tags or regular expressions
  2737. properties:
  2738. conversionStrategy:
  2739. default: Default
  2740. description: Used to define a conversion Strategy
  2741. type: string
  2742. name:
  2743. description: Finds secrets based on the name.
  2744. properties:
  2745. regexp:
  2746. description: Finds secrets base
  2747. type: string
  2748. type: object
  2749. path:
  2750. description: A root path to start the find operations.
  2751. type: string
  2752. tags:
  2753. additionalProperties:
  2754. type: string
  2755. description: Find secrets based on tags.
  2756. type: object
  2757. type: object
  2758. type: object
  2759. type: array
  2760. refreshInterval:
  2761. default: 1h
  2762. description: RefreshInterval is the amount of time before the values are read again from the SecretStore provider Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h" May be set to zero to fetch and create it once. Defaults to 1h.
  2763. type: string
  2764. secretStoreRef:
  2765. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  2766. properties:
  2767. kind:
  2768. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  2769. type: string
  2770. name:
  2771. description: Name of the SecretStore resource
  2772. type: string
  2773. required:
  2774. - name
  2775. type: object
  2776. target:
  2777. description: ExternalSecretTarget defines the Kubernetes Secret to be created There can be only one target per ExternalSecret.
  2778. properties:
  2779. creationPolicy:
  2780. default: Owner
  2781. description: CreationPolicy defines rules on how to create the resulting Secret Defaults to 'Owner'
  2782. enum:
  2783. - Owner
  2784. - Orphan
  2785. - Merge
  2786. - None
  2787. type: string
  2788. deletionPolicy:
  2789. default: Retain
  2790. description: DeletionPolicy defines rules on how to delete the resulting Secret Defaults to 'Retain'
  2791. enum:
  2792. - Delete
  2793. - Merge
  2794. - Retain
  2795. type: string
  2796. immutable:
  2797. description: Immutable defines if the final secret will be immutable
  2798. type: boolean
  2799. name:
  2800. description: Name defines the name of the Secret resource to be managed This field is immutable Defaults to the .metadata.name of the ExternalSecret resource
  2801. type: string
  2802. template:
  2803. description: Template defines a blueprint for the created Secret resource.
  2804. properties:
  2805. data:
  2806. additionalProperties:
  2807. type: string
  2808. type: object
  2809. engineVersion:
  2810. default: v2
  2811. type: string
  2812. metadata:
  2813. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2814. properties:
  2815. annotations:
  2816. additionalProperties:
  2817. type: string
  2818. type: object
  2819. labels:
  2820. additionalProperties:
  2821. type: string
  2822. type: object
  2823. type: object
  2824. templateFrom:
  2825. items:
  2826. maxProperties: 1
  2827. minProperties: 1
  2828. properties:
  2829. configMap:
  2830. properties:
  2831. items:
  2832. items:
  2833. properties:
  2834. key:
  2835. type: string
  2836. required:
  2837. - key
  2838. type: object
  2839. type: array
  2840. name:
  2841. type: string
  2842. required:
  2843. - items
  2844. - name
  2845. type: object
  2846. secret:
  2847. properties:
  2848. items:
  2849. items:
  2850. properties:
  2851. key:
  2852. type: string
  2853. required:
  2854. - key
  2855. type: object
  2856. type: array
  2857. name:
  2858. type: string
  2859. required:
  2860. - items
  2861. - name
  2862. type: object
  2863. type: object
  2864. type: array
  2865. type:
  2866. type: string
  2867. type: object
  2868. type: object
  2869. required:
  2870. - secretStoreRef
  2871. type: object
  2872. status:
  2873. properties:
  2874. conditions:
  2875. items:
  2876. properties:
  2877. lastTransitionTime:
  2878. format: date-time
  2879. type: string
  2880. message:
  2881. type: string
  2882. reason:
  2883. type: string
  2884. status:
  2885. type: string
  2886. type:
  2887. type: string
  2888. required:
  2889. - status
  2890. - type
  2891. type: object
  2892. type: array
  2893. refreshTime:
  2894. description: refreshTime is the time and date the external secret was fetched and the target secret updated
  2895. format: date-time
  2896. nullable: true
  2897. type: string
  2898. syncedResourceVersion:
  2899. description: SyncedResourceVersion keeps track of the last synced version
  2900. type: string
  2901. type: object
  2902. type: object
  2903. served: true
  2904. storage: true
  2905. subresources:
  2906. status: {}
  2907. conversion:
  2908. strategy: Webhook
  2909. webhook:
  2910. conversionReviewVersions:
  2911. - v1
  2912. clientConfig:
  2913. service:
  2914. name: kubernetes
  2915. namespace: default
  2916. path: /convert
  2917. status:
  2918. acceptedNames:
  2919. kind: ""
  2920. plural: ""
  2921. conditions: []
  2922. storedVersions: []
  2923. ---
  2924. apiVersion: apiextensions.k8s.io/v1
  2925. kind: CustomResourceDefinition
  2926. metadata:
  2927. annotations:
  2928. controller-gen.kubebuilder.io/version: v0.8.0
  2929. creationTimestamp: null
  2930. name: secretsinks.external-secrets.io
  2931. spec:
  2932. group: external-secrets.io
  2933. names:
  2934. categories:
  2935. - secretsinks
  2936. kind: SecretSink
  2937. listKind: SecretSinkList
  2938. plural: secretsinks
  2939. singular: secretsink
  2940. scope: Namespaced
  2941. versions:
  2942. - name: v1alpha1
  2943. schema:
  2944. openAPIV3Schema:
  2945. properties:
  2946. apiVersion:
  2947. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  2948. type: string
  2949. kind:
  2950. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  2951. type: string
  2952. metadata:
  2953. type: object
  2954. spec:
  2955. description: SecretSinkSpec configures the behavior of the SecretSink.
  2956. properties:
  2957. data:
  2958. items:
  2959. properties:
  2960. match:
  2961. items:
  2962. properties:
  2963. remoteRefs:
  2964. items:
  2965. properties:
  2966. remoteKey:
  2967. type: string
  2968. required:
  2969. - remoteKey
  2970. type: object
  2971. type: array
  2972. secretKey:
  2973. type: string
  2974. required:
  2975. - remoteRefs
  2976. - secretKey
  2977. type: object
  2978. type: array
  2979. required:
  2980. - match
  2981. type: object
  2982. type: array
  2983. secretStoreRefs:
  2984. items:
  2985. properties:
  2986. kind:
  2987. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore) Defaults to `SecretStore`
  2988. type: string
  2989. name:
  2990. description: Name of the SecretStore resource
  2991. type: string
  2992. required:
  2993. - name
  2994. type: object
  2995. type: array
  2996. selector:
  2997. properties:
  2998. secret:
  2999. properties:
  3000. name:
  3001. type: string
  3002. required:
  3003. - name
  3004. type: object
  3005. required:
  3006. - secret
  3007. type: object
  3008. required:
  3009. - secretStoreRefs
  3010. - selector
  3011. type: object
  3012. status:
  3013. description: SecretSinkStatus indicates the history of the status of SecretSink.
  3014. properties:
  3015. conditions:
  3016. items:
  3017. description: SecretSinkStatusCondition indicates the status of the SecretSink.
  3018. properties:
  3019. lastTransitionTime:
  3020. format: date-time
  3021. type: string
  3022. message:
  3023. type: string
  3024. reason:
  3025. type: string
  3026. status:
  3027. type: string
  3028. type:
  3029. description: SecretSinkConditionType indicates the condition of the SecretSink.
  3030. type: string
  3031. required:
  3032. - status
  3033. - type
  3034. type: object
  3035. type: array
  3036. refreshTime:
  3037. description: refreshTime is the time and date the external secret was fetched and the target secret updated
  3038. format: date-time
  3039. nullable: true
  3040. type: string
  3041. syncedResourceVersion:
  3042. description: SyncedResourceVersion keeps track of the last synced version.
  3043. type: string
  3044. type: object
  3045. type: object
  3046. served: true
  3047. storage: true
  3048. subresources:
  3049. status: {}
  3050. conversion:
  3051. strategy: Webhook
  3052. webhook:
  3053. conversionReviewVersions:
  3054. - v1
  3055. clientConfig:
  3056. service:
  3057. name: kubernetes
  3058. namespace: default
  3059. path: /convert
  3060. status:
  3061. acceptedNames:
  3062. kind: ""
  3063. plural: ""
  3064. conditions: []
  3065. storedVersions: []
  3066. ---
  3067. apiVersion: apiextensions.k8s.io/v1
  3068. kind: CustomResourceDefinition
  3069. metadata:
  3070. annotations:
  3071. controller-gen.kubebuilder.io/version: v0.8.0
  3072. creationTimestamp: null
  3073. name: secretstores.external-secrets.io
  3074. spec:
  3075. group: external-secrets.io
  3076. names:
  3077. categories:
  3078. - externalsecrets
  3079. kind: SecretStore
  3080. listKind: SecretStoreList
  3081. plural: secretstores
  3082. shortNames:
  3083. - ss
  3084. singular: secretstore
  3085. scope: Namespaced
  3086. versions:
  3087. - additionalPrinterColumns:
  3088. - jsonPath: .metadata.creationTimestamp
  3089. name: AGE
  3090. type: date
  3091. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  3092. name: Status
  3093. type: string
  3094. deprecated: true
  3095. name: v1alpha1
  3096. schema:
  3097. openAPIV3Schema:
  3098. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  3099. properties:
  3100. apiVersion:
  3101. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  3102. type: string
  3103. kind:
  3104. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  3105. type: string
  3106. metadata:
  3107. type: object
  3108. spec:
  3109. description: SecretStoreSpec defines the desired state of SecretStore.
  3110. properties:
  3111. controller:
  3112. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  3113. type: string
  3114. provider:
  3115. description: Used to configure the provider. Only one provider may be set
  3116. maxProperties: 1
  3117. minProperties: 1
  3118. properties:
  3119. akeyless:
  3120. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  3121. properties:
  3122. akeylessGWApiURL:
  3123. description: Akeyless GW API Url from which the secrets to be fetched from.
  3124. type: string
  3125. authSecretRef:
  3126. description: Auth configures how the operator authenticates with Akeyless.
  3127. properties:
  3128. secretRef:
  3129. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  3130. properties:
  3131. accessID:
  3132. description: The SecretAccessID is used for authentication
  3133. properties:
  3134. key:
  3135. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3136. type: string
  3137. name:
  3138. description: The name of the Secret resource being referred to.
  3139. type: string
  3140. namespace:
  3141. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3142. type: string
  3143. type: object
  3144. accessType:
  3145. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3146. properties:
  3147. key:
  3148. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3149. type: string
  3150. name:
  3151. description: The name of the Secret resource being referred to.
  3152. type: string
  3153. namespace:
  3154. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3155. type: string
  3156. type: object
  3157. accessTypeParam:
  3158. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3159. properties:
  3160. key:
  3161. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3162. type: string
  3163. name:
  3164. description: The name of the Secret resource being referred to.
  3165. type: string
  3166. namespace:
  3167. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3168. type: string
  3169. type: object
  3170. type: object
  3171. required:
  3172. - secretRef
  3173. type: object
  3174. required:
  3175. - akeylessGWApiURL
  3176. - authSecretRef
  3177. type: object
  3178. alibaba:
  3179. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  3180. properties:
  3181. auth:
  3182. description: AlibabaAuth contains a secretRef for credentials.
  3183. properties:
  3184. secretRef:
  3185. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  3186. properties:
  3187. accessKeyIDSecretRef:
  3188. description: The AccessKeyID is used for authentication
  3189. properties:
  3190. key:
  3191. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3192. type: string
  3193. name:
  3194. description: The name of the Secret resource being referred to.
  3195. type: string
  3196. namespace:
  3197. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3198. type: string
  3199. type: object
  3200. accessKeySecretSecretRef:
  3201. description: The AccessKeySecret is used for authentication
  3202. properties:
  3203. key:
  3204. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3205. type: string
  3206. name:
  3207. description: The name of the Secret resource being referred to.
  3208. type: string
  3209. namespace:
  3210. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3211. type: string
  3212. type: object
  3213. required:
  3214. - accessKeyIDSecretRef
  3215. - accessKeySecretSecretRef
  3216. type: object
  3217. required:
  3218. - secretRef
  3219. type: object
  3220. endpoint:
  3221. type: string
  3222. regionID:
  3223. description: Alibaba Region to be used for the provider
  3224. type: string
  3225. required:
  3226. - auth
  3227. - regionID
  3228. type: object
  3229. aws:
  3230. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  3231. properties:
  3232. auth:
  3233. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  3234. properties:
  3235. jwt:
  3236. description: Authenticate against AWS using service account tokens.
  3237. properties:
  3238. serviceAccountRef:
  3239. description: A reference to a ServiceAccount resource.
  3240. properties:
  3241. name:
  3242. description: The name of the ServiceAccount resource being referred to.
  3243. type: string
  3244. namespace:
  3245. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3246. type: string
  3247. required:
  3248. - name
  3249. type: object
  3250. type: object
  3251. secretRef:
  3252. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  3253. properties:
  3254. accessKeyIDSecretRef:
  3255. description: The AccessKeyID is used for authentication
  3256. properties:
  3257. key:
  3258. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3259. type: string
  3260. name:
  3261. description: The name of the Secret resource being referred to.
  3262. type: string
  3263. namespace:
  3264. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3265. type: string
  3266. type: object
  3267. secretAccessKeySecretRef:
  3268. description: The SecretAccessKey is used for authentication
  3269. properties:
  3270. key:
  3271. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3272. type: string
  3273. name:
  3274. description: The name of the Secret resource being referred to.
  3275. type: string
  3276. namespace:
  3277. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3278. type: string
  3279. type: object
  3280. type: object
  3281. type: object
  3282. region:
  3283. description: AWS Region to be used for the provider
  3284. type: string
  3285. role:
  3286. description: Role is a Role ARN which the SecretManager provider will assume
  3287. type: string
  3288. service:
  3289. description: Service defines which service should be used to fetch the secrets
  3290. enum:
  3291. - SecretsManager
  3292. - ParameterStore
  3293. type: string
  3294. required:
  3295. - region
  3296. - service
  3297. type: object
  3298. azurekv:
  3299. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  3300. properties:
  3301. authSecretRef:
  3302. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  3303. properties:
  3304. clientId:
  3305. description: The Azure clientId of the service principle used for authentication.
  3306. properties:
  3307. key:
  3308. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3309. type: string
  3310. name:
  3311. description: The name of the Secret resource being referred to.
  3312. type: string
  3313. namespace:
  3314. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3315. type: string
  3316. type: object
  3317. clientSecret:
  3318. description: The Azure ClientSecret of the service principle used for authentication.
  3319. properties:
  3320. key:
  3321. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3322. type: string
  3323. name:
  3324. description: The name of the Secret resource being referred to.
  3325. type: string
  3326. namespace:
  3327. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3328. type: string
  3329. type: object
  3330. type: object
  3331. authType:
  3332. default: ServicePrincipal
  3333. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  3334. enum:
  3335. - ServicePrincipal
  3336. - ManagedIdentity
  3337. - WorkloadIdentity
  3338. type: string
  3339. identityId:
  3340. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3341. type: string
  3342. serviceAccountRef:
  3343. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  3344. properties:
  3345. name:
  3346. description: The name of the ServiceAccount resource being referred to.
  3347. type: string
  3348. namespace:
  3349. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3350. type: string
  3351. required:
  3352. - name
  3353. type: object
  3354. tenantId:
  3355. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  3356. type: string
  3357. vaultUrl:
  3358. description: Vault Url from which the secrets to be fetched from.
  3359. type: string
  3360. required:
  3361. - vaultUrl
  3362. type: object
  3363. fake:
  3364. description: Fake configures a store with static key/value pairs
  3365. properties:
  3366. data:
  3367. items:
  3368. properties:
  3369. key:
  3370. type: string
  3371. value:
  3372. type: string
  3373. valueMap:
  3374. additionalProperties:
  3375. type: string
  3376. type: object
  3377. version:
  3378. type: string
  3379. required:
  3380. - key
  3381. type: object
  3382. type: array
  3383. required:
  3384. - data
  3385. type: object
  3386. gcpsm:
  3387. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  3388. properties:
  3389. auth:
  3390. description: Auth defines the information necessary to authenticate against GCP
  3391. properties:
  3392. secretRef:
  3393. properties:
  3394. secretAccessKeySecretRef:
  3395. description: The SecretAccessKey is used for authentication
  3396. properties:
  3397. key:
  3398. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3399. type: string
  3400. name:
  3401. description: The name of the Secret resource being referred to.
  3402. type: string
  3403. namespace:
  3404. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3405. type: string
  3406. type: object
  3407. type: object
  3408. workloadIdentity:
  3409. properties:
  3410. clusterLocation:
  3411. type: string
  3412. clusterName:
  3413. type: string
  3414. clusterProjectID:
  3415. type: string
  3416. serviceAccountRef:
  3417. description: A reference to a ServiceAccount resource.
  3418. properties:
  3419. name:
  3420. description: The name of the ServiceAccount resource being referred to.
  3421. type: string
  3422. namespace:
  3423. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3424. type: string
  3425. required:
  3426. - name
  3427. type: object
  3428. required:
  3429. - clusterLocation
  3430. - clusterName
  3431. - serviceAccountRef
  3432. type: object
  3433. type: object
  3434. projectID:
  3435. description: ProjectID project where secret is located
  3436. type: string
  3437. type: object
  3438. gitlab:
  3439. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  3440. properties:
  3441. auth:
  3442. description: Auth configures how secret-manager authenticates with a GitLab instance.
  3443. properties:
  3444. SecretRef:
  3445. properties:
  3446. accessToken:
  3447. description: AccessToken is used for authentication.
  3448. properties:
  3449. key:
  3450. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3451. type: string
  3452. name:
  3453. description: The name of the Secret resource being referred to.
  3454. type: string
  3455. namespace:
  3456. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3457. type: string
  3458. type: object
  3459. type: object
  3460. required:
  3461. - SecretRef
  3462. type: object
  3463. projectID:
  3464. description: ProjectID specifies a project where secrets are located.
  3465. type: string
  3466. url:
  3467. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  3468. type: string
  3469. required:
  3470. - auth
  3471. type: object
  3472. ibm:
  3473. description: IBM configures this store to sync secrets using IBM Cloud provider
  3474. properties:
  3475. auth:
  3476. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  3477. properties:
  3478. secretRef:
  3479. properties:
  3480. secretApiKeySecretRef:
  3481. description: The SecretAccessKey is used for authentication
  3482. properties:
  3483. key:
  3484. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3485. type: string
  3486. name:
  3487. description: The name of the Secret resource being referred to.
  3488. type: string
  3489. namespace:
  3490. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3491. type: string
  3492. type: object
  3493. type: object
  3494. required:
  3495. - secretRef
  3496. type: object
  3497. serviceUrl:
  3498. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  3499. type: string
  3500. required:
  3501. - auth
  3502. type: object
  3503. kubernetes:
  3504. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  3505. properties:
  3506. auth:
  3507. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  3508. maxProperties: 1
  3509. minProperties: 1
  3510. properties:
  3511. cert:
  3512. description: has both clientCert and clientKey as secretKeySelector
  3513. properties:
  3514. clientCert:
  3515. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3516. properties:
  3517. key:
  3518. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3519. type: string
  3520. name:
  3521. description: The name of the Secret resource being referred to.
  3522. type: string
  3523. namespace:
  3524. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3525. type: string
  3526. type: object
  3527. clientKey:
  3528. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3529. properties:
  3530. key:
  3531. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3532. type: string
  3533. name:
  3534. description: The name of the Secret resource being referred to.
  3535. type: string
  3536. namespace:
  3537. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3538. type: string
  3539. type: object
  3540. type: object
  3541. serviceAccount:
  3542. description: points to a service account that should be used for authentication
  3543. properties:
  3544. serviceAccount:
  3545. description: A reference to a ServiceAccount resource.
  3546. properties:
  3547. name:
  3548. description: The name of the ServiceAccount resource being referred to.
  3549. type: string
  3550. namespace:
  3551. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3552. type: string
  3553. required:
  3554. - name
  3555. type: object
  3556. type: object
  3557. token:
  3558. description: use static token to authenticate with
  3559. properties:
  3560. bearerToken:
  3561. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  3562. properties:
  3563. key:
  3564. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3565. type: string
  3566. name:
  3567. description: The name of the Secret resource being referred to.
  3568. type: string
  3569. namespace:
  3570. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3571. type: string
  3572. type: object
  3573. type: object
  3574. type: object
  3575. remoteNamespace:
  3576. default: default
  3577. description: Remote namespace to fetch the secrets from
  3578. type: string
  3579. server:
  3580. description: configures the Kubernetes server Address.
  3581. properties:
  3582. caBundle:
  3583. description: CABundle is a base64-encoded CA certificate
  3584. format: byte
  3585. type: string
  3586. caProvider:
  3587. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  3588. properties:
  3589. key:
  3590. description: The key the value inside of the provider type to use, only used with "Secret" type
  3591. type: string
  3592. name:
  3593. description: The name of the object located at the provider type.
  3594. type: string
  3595. namespace:
  3596. description: The namespace the Provider type is in.
  3597. type: string
  3598. type:
  3599. description: The type of provider to use such as "Secret", or "ConfigMap".
  3600. enum:
  3601. - Secret
  3602. - ConfigMap
  3603. type: string
  3604. required:
  3605. - name
  3606. - type
  3607. type: object
  3608. url:
  3609. default: kubernetes.default
  3610. description: configures the Kubernetes server Address.
  3611. type: string
  3612. type: object
  3613. required:
  3614. - auth
  3615. type: object
  3616. oracle:
  3617. description: Oracle configures this store to sync secrets using Oracle Vault provider
  3618. properties:
  3619. auth:
  3620. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  3621. properties:
  3622. secretRef:
  3623. description: SecretRef to pass through sensitive information.
  3624. properties:
  3625. fingerprint:
  3626. description: Fingerprint is the fingerprint of the API private key.
  3627. properties:
  3628. key:
  3629. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3630. type: string
  3631. name:
  3632. description: The name of the Secret resource being referred to.
  3633. type: string
  3634. namespace:
  3635. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3636. type: string
  3637. type: object
  3638. privatekey:
  3639. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  3640. properties:
  3641. key:
  3642. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3643. type: string
  3644. name:
  3645. description: The name of the Secret resource being referred to.
  3646. type: string
  3647. namespace:
  3648. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3649. type: string
  3650. type: object
  3651. required:
  3652. - fingerprint
  3653. - privatekey
  3654. type: object
  3655. tenancy:
  3656. description: Tenancy is the tenancy OCID where user is located.
  3657. type: string
  3658. user:
  3659. description: User is an access OCID specific to the account.
  3660. type: string
  3661. required:
  3662. - secretRef
  3663. - tenancy
  3664. - user
  3665. type: object
  3666. region:
  3667. description: Region is the region where vault is located.
  3668. type: string
  3669. vault:
  3670. description: Vault is the vault's OCID of the specific vault where secret is located.
  3671. type: string
  3672. required:
  3673. - region
  3674. - vault
  3675. type: object
  3676. vault:
  3677. description: Vault configures this store to sync secrets using Hashi provider
  3678. properties:
  3679. auth:
  3680. description: Auth configures how secret-manager authenticates with the Vault server.
  3681. properties:
  3682. appRole:
  3683. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  3684. properties:
  3685. path:
  3686. default: approle
  3687. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  3688. type: string
  3689. roleId:
  3690. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  3691. type: string
  3692. secretRef:
  3693. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  3694. properties:
  3695. key:
  3696. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3697. type: string
  3698. name:
  3699. description: The name of the Secret resource being referred to.
  3700. type: string
  3701. namespace:
  3702. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3703. type: string
  3704. type: object
  3705. required:
  3706. - path
  3707. - roleId
  3708. - secretRef
  3709. type: object
  3710. cert:
  3711. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  3712. properties:
  3713. clientCert:
  3714. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  3715. properties:
  3716. key:
  3717. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3718. type: string
  3719. name:
  3720. description: The name of the Secret resource being referred to.
  3721. type: string
  3722. namespace:
  3723. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3724. type: string
  3725. type: object
  3726. secretRef:
  3727. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  3728. properties:
  3729. key:
  3730. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3731. type: string
  3732. name:
  3733. description: The name of the Secret resource being referred to.
  3734. type: string
  3735. namespace:
  3736. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3737. type: string
  3738. type: object
  3739. type: object
  3740. jwt:
  3741. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  3742. properties:
  3743. kubernetesServiceAccountToken:
  3744. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  3745. properties:
  3746. audiences:
  3747. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  3748. items:
  3749. type: string
  3750. type: array
  3751. expirationSeconds:
  3752. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  3753. format: int64
  3754. type: integer
  3755. serviceAccountRef:
  3756. description: Service account field containing the name of a kubernetes ServiceAccount.
  3757. properties:
  3758. name:
  3759. description: The name of the ServiceAccount resource being referred to.
  3760. type: string
  3761. namespace:
  3762. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3763. type: string
  3764. required:
  3765. - name
  3766. type: object
  3767. required:
  3768. - serviceAccountRef
  3769. type: object
  3770. path:
  3771. default: jwt
  3772. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  3773. type: string
  3774. role:
  3775. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  3776. type: string
  3777. secretRef:
  3778. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  3779. properties:
  3780. key:
  3781. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3782. type: string
  3783. name:
  3784. description: The name of the Secret resource being referred to.
  3785. type: string
  3786. namespace:
  3787. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3788. type: string
  3789. type: object
  3790. required:
  3791. - path
  3792. type: object
  3793. kubernetes:
  3794. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  3795. properties:
  3796. mountPath:
  3797. default: kubernetes
  3798. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  3799. type: string
  3800. role:
  3801. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  3802. type: string
  3803. secretRef:
  3804. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  3805. properties:
  3806. key:
  3807. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3808. type: string
  3809. name:
  3810. description: The name of the Secret resource being referred to.
  3811. type: string
  3812. namespace:
  3813. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3814. type: string
  3815. type: object
  3816. serviceAccountRef:
  3817. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  3818. properties:
  3819. name:
  3820. description: The name of the ServiceAccount resource being referred to.
  3821. type: string
  3822. namespace:
  3823. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3824. type: string
  3825. required:
  3826. - name
  3827. type: object
  3828. required:
  3829. - mountPath
  3830. - role
  3831. type: object
  3832. ldap:
  3833. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  3834. properties:
  3835. path:
  3836. default: ldap
  3837. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  3838. type: string
  3839. secretRef:
  3840. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  3841. properties:
  3842. key:
  3843. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3844. type: string
  3845. name:
  3846. description: The name of the Secret resource being referred to.
  3847. type: string
  3848. namespace:
  3849. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3850. type: string
  3851. type: object
  3852. username:
  3853. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  3854. type: string
  3855. required:
  3856. - path
  3857. - username
  3858. type: object
  3859. tokenSecretRef:
  3860. description: TokenSecretRef authenticates with Vault by presenting a token.
  3861. properties:
  3862. key:
  3863. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3864. type: string
  3865. name:
  3866. description: The name of the Secret resource being referred to.
  3867. type: string
  3868. namespace:
  3869. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3870. type: string
  3871. type: object
  3872. type: object
  3873. caBundle:
  3874. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  3875. format: byte
  3876. type: string
  3877. caProvider:
  3878. description: The provider for the CA bundle to use to validate Vault server certificate.
  3879. properties:
  3880. key:
  3881. description: The key the value inside of the provider type to use, only used with "Secret" type
  3882. type: string
  3883. name:
  3884. description: The name of the object located at the provider type.
  3885. type: string
  3886. namespace:
  3887. description: The namespace the Provider type is in.
  3888. type: string
  3889. type:
  3890. description: The type of provider to use such as "Secret", or "ConfigMap".
  3891. enum:
  3892. - Secret
  3893. - ConfigMap
  3894. type: string
  3895. required:
  3896. - name
  3897. - type
  3898. type: object
  3899. forwardInconsistent:
  3900. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  3901. type: boolean
  3902. namespace:
  3903. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  3904. type: string
  3905. path:
  3906. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  3907. type: string
  3908. readYourWrites:
  3909. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  3910. type: boolean
  3911. server:
  3912. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  3913. type: string
  3914. version:
  3915. default: v2
  3916. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  3917. enum:
  3918. - v1
  3919. - v2
  3920. type: string
  3921. required:
  3922. - auth
  3923. - server
  3924. type: object
  3925. webhook:
  3926. description: Webhook configures this store to sync secrets using a generic templated webhook
  3927. properties:
  3928. body:
  3929. description: Body
  3930. type: string
  3931. caBundle:
  3932. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  3933. format: byte
  3934. type: string
  3935. caProvider:
  3936. description: The provider for the CA bundle to use to validate webhook server certificate.
  3937. properties:
  3938. key:
  3939. description: The key the value inside of the provider type to use, only used with "Secret" type
  3940. type: string
  3941. name:
  3942. description: The name of the object located at the provider type.
  3943. type: string
  3944. namespace:
  3945. description: The namespace the Provider type is in.
  3946. type: string
  3947. type:
  3948. description: The type of provider to use such as "Secret", or "ConfigMap".
  3949. enum:
  3950. - Secret
  3951. - ConfigMap
  3952. type: string
  3953. required:
  3954. - name
  3955. - type
  3956. type: object
  3957. headers:
  3958. additionalProperties:
  3959. type: string
  3960. description: Headers
  3961. type: object
  3962. method:
  3963. description: Webhook Method
  3964. type: string
  3965. result:
  3966. description: Result formatting
  3967. properties:
  3968. jsonPath:
  3969. description: Json path of return value
  3970. type: string
  3971. type: object
  3972. secrets:
  3973. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  3974. items:
  3975. properties:
  3976. name:
  3977. description: Name of this secret in templates
  3978. type: string
  3979. secretRef:
  3980. description: Secret ref to fill in credentials
  3981. properties:
  3982. key:
  3983. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  3984. type: string
  3985. name:
  3986. description: The name of the Secret resource being referred to.
  3987. type: string
  3988. namespace:
  3989. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  3990. type: string
  3991. type: object
  3992. required:
  3993. - name
  3994. - secretRef
  3995. type: object
  3996. type: array
  3997. timeout:
  3998. description: Timeout
  3999. type: string
  4000. url:
  4001. description: Webhook url to call
  4002. type: string
  4003. required:
  4004. - result
  4005. - url
  4006. type: object
  4007. yandexlockbox:
  4008. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  4009. properties:
  4010. apiEndpoint:
  4011. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  4012. type: string
  4013. auth:
  4014. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  4015. properties:
  4016. authorizedKeySecretRef:
  4017. description: The authorized key used for authentication
  4018. properties:
  4019. key:
  4020. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4021. type: string
  4022. name:
  4023. description: The name of the Secret resource being referred to.
  4024. type: string
  4025. namespace:
  4026. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4027. type: string
  4028. type: object
  4029. type: object
  4030. caProvider:
  4031. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  4032. properties:
  4033. certSecretRef:
  4034. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4035. properties:
  4036. key:
  4037. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4038. type: string
  4039. name:
  4040. description: The name of the Secret resource being referred to.
  4041. type: string
  4042. namespace:
  4043. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4044. type: string
  4045. type: object
  4046. type: object
  4047. required:
  4048. - auth
  4049. type: object
  4050. type: object
  4051. retrySettings:
  4052. description: Used to configure http retries if failed
  4053. properties:
  4054. maxRetries:
  4055. format: int32
  4056. type: integer
  4057. retryInterval:
  4058. type: string
  4059. type: object
  4060. required:
  4061. - provider
  4062. type: object
  4063. status:
  4064. description: SecretStoreStatus defines the observed state of the SecretStore.
  4065. properties:
  4066. conditions:
  4067. items:
  4068. properties:
  4069. lastTransitionTime:
  4070. format: date-time
  4071. type: string
  4072. message:
  4073. type: string
  4074. reason:
  4075. type: string
  4076. status:
  4077. type: string
  4078. type:
  4079. type: string
  4080. required:
  4081. - status
  4082. - type
  4083. type: object
  4084. type: array
  4085. type: object
  4086. type: object
  4087. served: true
  4088. storage: false
  4089. subresources:
  4090. status: {}
  4091. - additionalPrinterColumns:
  4092. - jsonPath: .metadata.creationTimestamp
  4093. name: AGE
  4094. type: date
  4095. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  4096. name: Status
  4097. type: string
  4098. name: v1beta1
  4099. schema:
  4100. openAPIV3Schema:
  4101. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  4102. properties:
  4103. apiVersion:
  4104. description: 'APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
  4105. type: string
  4106. kind:
  4107. description: 'Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
  4108. type: string
  4109. metadata:
  4110. type: object
  4111. spec:
  4112. description: SecretStoreSpec defines the desired state of SecretStore.
  4113. properties:
  4114. controller:
  4115. description: 'Used to select the correct KES controller (think: ingress.ingressClassName) The KES controller is instantiated with a specific controller name and filters ES based on this property'
  4116. type: string
  4117. provider:
  4118. description: Used to configure the provider. Only one provider may be set
  4119. maxProperties: 1
  4120. minProperties: 1
  4121. properties:
  4122. akeyless:
  4123. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  4124. properties:
  4125. akeylessGWApiURL:
  4126. description: Akeyless GW API Url from which the secrets to be fetched from.
  4127. type: string
  4128. authSecretRef:
  4129. description: Auth configures how the operator authenticates with Akeyless.
  4130. properties:
  4131. secretRef:
  4132. description: 'AkeylessAuthSecretRef AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.'
  4133. properties:
  4134. accessID:
  4135. description: The SecretAccessID is used for authentication
  4136. properties:
  4137. key:
  4138. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4139. type: string
  4140. name:
  4141. description: The name of the Secret resource being referred to.
  4142. type: string
  4143. namespace:
  4144. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4145. type: string
  4146. type: object
  4147. accessType:
  4148. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4149. properties:
  4150. key:
  4151. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4152. type: string
  4153. name:
  4154. description: The name of the Secret resource being referred to.
  4155. type: string
  4156. namespace:
  4157. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4158. type: string
  4159. type: object
  4160. accessTypeParam:
  4161. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4162. properties:
  4163. key:
  4164. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4165. type: string
  4166. name:
  4167. description: The name of the Secret resource being referred to.
  4168. type: string
  4169. namespace:
  4170. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4171. type: string
  4172. type: object
  4173. type: object
  4174. required:
  4175. - secretRef
  4176. type: object
  4177. required:
  4178. - akeylessGWApiURL
  4179. - authSecretRef
  4180. type: object
  4181. alibaba:
  4182. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  4183. properties:
  4184. auth:
  4185. description: AlibabaAuth contains a secretRef for credentials.
  4186. properties:
  4187. secretRef:
  4188. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  4189. properties:
  4190. accessKeyIDSecretRef:
  4191. description: The AccessKeyID is used for authentication
  4192. properties:
  4193. key:
  4194. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4195. type: string
  4196. name:
  4197. description: The name of the Secret resource being referred to.
  4198. type: string
  4199. namespace:
  4200. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4201. type: string
  4202. type: object
  4203. accessKeySecretSecretRef:
  4204. description: The AccessKeySecret is used for authentication
  4205. properties:
  4206. key:
  4207. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4208. type: string
  4209. name:
  4210. description: The name of the Secret resource being referred to.
  4211. type: string
  4212. namespace:
  4213. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4214. type: string
  4215. type: object
  4216. required:
  4217. - accessKeyIDSecretRef
  4218. - accessKeySecretSecretRef
  4219. type: object
  4220. required:
  4221. - secretRef
  4222. type: object
  4223. endpoint:
  4224. type: string
  4225. regionID:
  4226. description: Alibaba Region to be used for the provider
  4227. type: string
  4228. required:
  4229. - auth
  4230. - regionID
  4231. type: object
  4232. aws:
  4233. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  4234. properties:
  4235. auth:
  4236. description: 'Auth defines the information necessary to authenticate against AWS if not set aws sdk will infer credentials from your environment see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials'
  4237. properties:
  4238. jwt:
  4239. description: Authenticate against AWS using service account tokens.
  4240. properties:
  4241. serviceAccountRef:
  4242. description: A reference to a ServiceAccount resource.
  4243. properties:
  4244. name:
  4245. description: The name of the ServiceAccount resource being referred to.
  4246. type: string
  4247. namespace:
  4248. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4249. type: string
  4250. required:
  4251. - name
  4252. type: object
  4253. type: object
  4254. secretRef:
  4255. description: AWSAuthSecretRef holds secret references for AWS credentials both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  4256. properties:
  4257. accessKeyIDSecretRef:
  4258. description: The AccessKeyID is used for authentication
  4259. properties:
  4260. key:
  4261. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4262. type: string
  4263. name:
  4264. description: The name of the Secret resource being referred to.
  4265. type: string
  4266. namespace:
  4267. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4268. type: string
  4269. type: object
  4270. secretAccessKeySecretRef:
  4271. description: The SecretAccessKey is used for authentication
  4272. properties:
  4273. key:
  4274. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4275. type: string
  4276. name:
  4277. description: The name of the Secret resource being referred to.
  4278. type: string
  4279. namespace:
  4280. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4281. type: string
  4282. type: object
  4283. type: object
  4284. type: object
  4285. region:
  4286. description: AWS Region to be used for the provider
  4287. type: string
  4288. role:
  4289. description: Role is a Role ARN which the SecretManager provider will assume
  4290. type: string
  4291. service:
  4292. description: Service defines which service should be used to fetch the secrets
  4293. enum:
  4294. - SecretsManager
  4295. - ParameterStore
  4296. type: string
  4297. required:
  4298. - region
  4299. - service
  4300. type: object
  4301. azurekv:
  4302. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  4303. properties:
  4304. authSecretRef:
  4305. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  4306. properties:
  4307. clientId:
  4308. description: The Azure clientId of the service principle used for authentication.
  4309. properties:
  4310. key:
  4311. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4312. type: string
  4313. name:
  4314. description: The name of the Secret resource being referred to.
  4315. type: string
  4316. namespace:
  4317. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4318. type: string
  4319. type: object
  4320. clientSecret:
  4321. description: The Azure ClientSecret of the service principle used for authentication.
  4322. properties:
  4323. key:
  4324. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4325. type: string
  4326. name:
  4327. description: The name of the Secret resource being referred to.
  4328. type: string
  4329. namespace:
  4330. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4331. type: string
  4332. type: object
  4333. type: object
  4334. authType:
  4335. default: ServicePrincipal
  4336. description: 'Auth type defines how to authenticate to the keyvault service. Valid values are: - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret) - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)'
  4337. enum:
  4338. - ServicePrincipal
  4339. - ManagedIdentity
  4340. - WorkloadIdentity
  4341. type: string
  4342. identityId:
  4343. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  4344. type: string
  4345. serviceAccountRef:
  4346. description: ServiceAccountRef specified the service account that should be used when authenticating with WorkloadIdentity.
  4347. properties:
  4348. name:
  4349. description: The name of the ServiceAccount resource being referred to.
  4350. type: string
  4351. namespace:
  4352. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4353. type: string
  4354. required:
  4355. - name
  4356. type: object
  4357. tenantId:
  4358. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  4359. type: string
  4360. vaultUrl:
  4361. description: Vault Url from which the secrets to be fetched from.
  4362. type: string
  4363. required:
  4364. - vaultUrl
  4365. type: object
  4366. fake:
  4367. description: Fake configures a store with static key/value pairs
  4368. properties:
  4369. data:
  4370. items:
  4371. properties:
  4372. key:
  4373. type: string
  4374. value:
  4375. type: string
  4376. valueMap:
  4377. additionalProperties:
  4378. type: string
  4379. type: object
  4380. version:
  4381. type: string
  4382. required:
  4383. - key
  4384. type: object
  4385. type: array
  4386. required:
  4387. - data
  4388. type: object
  4389. gcpsm:
  4390. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4391. properties:
  4392. auth:
  4393. description: Auth defines the information necessary to authenticate against GCP
  4394. properties:
  4395. secretRef:
  4396. properties:
  4397. secretAccessKeySecretRef:
  4398. description: The SecretAccessKey is used for authentication
  4399. properties:
  4400. key:
  4401. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4402. type: string
  4403. name:
  4404. description: The name of the Secret resource being referred to.
  4405. type: string
  4406. namespace:
  4407. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4408. type: string
  4409. type: object
  4410. type: object
  4411. workloadIdentity:
  4412. properties:
  4413. clusterLocation:
  4414. type: string
  4415. clusterName:
  4416. type: string
  4417. clusterProjectID:
  4418. type: string
  4419. serviceAccountRef:
  4420. description: A reference to a ServiceAccount resource.
  4421. properties:
  4422. name:
  4423. description: The name of the ServiceAccount resource being referred to.
  4424. type: string
  4425. namespace:
  4426. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4427. type: string
  4428. required:
  4429. - name
  4430. type: object
  4431. required:
  4432. - clusterLocation
  4433. - clusterName
  4434. - serviceAccountRef
  4435. type: object
  4436. type: object
  4437. projectID:
  4438. description: ProjectID project where secret is located
  4439. type: string
  4440. type: object
  4441. gitlab:
  4442. description: Gitlab configures this store to sync secrets using Gitlab Variables provider
  4443. properties:
  4444. auth:
  4445. description: Auth configures how secret-manager authenticates with a GitLab instance.
  4446. properties:
  4447. SecretRef:
  4448. properties:
  4449. accessToken:
  4450. description: AccessToken is used for authentication.
  4451. properties:
  4452. key:
  4453. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4454. type: string
  4455. name:
  4456. description: The name of the Secret resource being referred to.
  4457. type: string
  4458. namespace:
  4459. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4460. type: string
  4461. type: object
  4462. type: object
  4463. required:
  4464. - SecretRef
  4465. type: object
  4466. projectID:
  4467. description: ProjectID specifies a project where secrets are located.
  4468. type: string
  4469. url:
  4470. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  4471. type: string
  4472. required:
  4473. - auth
  4474. type: object
  4475. ibm:
  4476. description: IBM configures this store to sync secrets using IBM Cloud provider
  4477. properties:
  4478. auth:
  4479. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  4480. properties:
  4481. secretRef:
  4482. properties:
  4483. secretApiKeySecretRef:
  4484. description: The SecretAccessKey is used for authentication
  4485. properties:
  4486. key:
  4487. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4488. type: string
  4489. name:
  4490. description: The name of the Secret resource being referred to.
  4491. type: string
  4492. namespace:
  4493. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4494. type: string
  4495. type: object
  4496. type: object
  4497. required:
  4498. - secretRef
  4499. type: object
  4500. serviceUrl:
  4501. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  4502. type: string
  4503. required:
  4504. - auth
  4505. type: object
  4506. kubernetes:
  4507. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  4508. properties:
  4509. auth:
  4510. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  4511. maxProperties: 1
  4512. minProperties: 1
  4513. properties:
  4514. cert:
  4515. description: has both clientCert and clientKey as secretKeySelector
  4516. properties:
  4517. clientCert:
  4518. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4519. properties:
  4520. key:
  4521. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4522. type: string
  4523. name:
  4524. description: The name of the Secret resource being referred to.
  4525. type: string
  4526. namespace:
  4527. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4528. type: string
  4529. type: object
  4530. clientKey:
  4531. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4532. properties:
  4533. key:
  4534. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4535. type: string
  4536. name:
  4537. description: The name of the Secret resource being referred to.
  4538. type: string
  4539. namespace:
  4540. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4541. type: string
  4542. type: object
  4543. type: object
  4544. serviceAccount:
  4545. description: points to a service account that should be used for authentication
  4546. properties:
  4547. serviceAccount:
  4548. description: A reference to a ServiceAccount resource.
  4549. properties:
  4550. name:
  4551. description: The name of the ServiceAccount resource being referred to.
  4552. type: string
  4553. namespace:
  4554. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4555. type: string
  4556. required:
  4557. - name
  4558. type: object
  4559. type: object
  4560. token:
  4561. description: use static token to authenticate with
  4562. properties:
  4563. bearerToken:
  4564. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4565. properties:
  4566. key:
  4567. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4568. type: string
  4569. name:
  4570. description: The name of the Secret resource being referred to.
  4571. type: string
  4572. namespace:
  4573. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4574. type: string
  4575. type: object
  4576. type: object
  4577. type: object
  4578. remoteNamespace:
  4579. default: default
  4580. description: Remote namespace to fetch the secrets from
  4581. type: string
  4582. server:
  4583. description: configures the Kubernetes server Address.
  4584. properties:
  4585. caBundle:
  4586. description: CABundle is a base64-encoded CA certificate
  4587. format: byte
  4588. type: string
  4589. caProvider:
  4590. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  4591. properties:
  4592. key:
  4593. description: The key the value inside of the provider type to use, only used with "Secret" type
  4594. type: string
  4595. name:
  4596. description: The name of the object located at the provider type.
  4597. type: string
  4598. namespace:
  4599. description: The namespace the Provider type is in.
  4600. type: string
  4601. type:
  4602. description: The type of provider to use such as "Secret", or "ConfigMap".
  4603. enum:
  4604. - Secret
  4605. - ConfigMap
  4606. type: string
  4607. required:
  4608. - name
  4609. - type
  4610. type: object
  4611. url:
  4612. default: kubernetes.default
  4613. description: configures the Kubernetes server Address.
  4614. type: string
  4615. type: object
  4616. required:
  4617. - auth
  4618. type: object
  4619. oracle:
  4620. description: Oracle configures this store to sync secrets using Oracle Vault provider
  4621. properties:
  4622. auth:
  4623. description: Auth configures how secret-manager authenticates with the Oracle Vault. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  4624. properties:
  4625. secretRef:
  4626. description: SecretRef to pass through sensitive information.
  4627. properties:
  4628. fingerprint:
  4629. description: Fingerprint is the fingerprint of the API private key.
  4630. properties:
  4631. key:
  4632. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4633. type: string
  4634. name:
  4635. description: The name of the Secret resource being referred to.
  4636. type: string
  4637. namespace:
  4638. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4639. type: string
  4640. type: object
  4641. privatekey:
  4642. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  4643. properties:
  4644. key:
  4645. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4646. type: string
  4647. name:
  4648. description: The name of the Secret resource being referred to.
  4649. type: string
  4650. namespace:
  4651. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4652. type: string
  4653. type: object
  4654. required:
  4655. - fingerprint
  4656. - privatekey
  4657. type: object
  4658. tenancy:
  4659. description: Tenancy is the tenancy OCID where user is located.
  4660. type: string
  4661. user:
  4662. description: User is an access OCID specific to the account.
  4663. type: string
  4664. required:
  4665. - secretRef
  4666. - tenancy
  4667. - user
  4668. type: object
  4669. region:
  4670. description: Region is the region where vault is located.
  4671. type: string
  4672. vault:
  4673. description: Vault is the vault's OCID of the specific vault where secret is located.
  4674. type: string
  4675. required:
  4676. - region
  4677. - vault
  4678. type: object
  4679. senhasegura:
  4680. description: Senhasegura configures this store to sync secrets using senhasegura provider
  4681. properties:
  4682. auth:
  4683. description: Auth defines parameters to authenticate in senhasegura
  4684. properties:
  4685. clientId:
  4686. type: string
  4687. clientSecretSecretRef:
  4688. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  4689. properties:
  4690. key:
  4691. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4692. type: string
  4693. name:
  4694. description: The name of the Secret resource being referred to.
  4695. type: string
  4696. namespace:
  4697. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4698. type: string
  4699. type: object
  4700. required:
  4701. - clientId
  4702. - clientSecretSecretRef
  4703. type: object
  4704. ignoreSslCertificate:
  4705. default: false
  4706. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  4707. type: boolean
  4708. module:
  4709. description: Module defines which senhasegura module should be used to get secrets
  4710. type: string
  4711. url:
  4712. description: URL of senhasegura
  4713. type: string
  4714. required:
  4715. - auth
  4716. - module
  4717. - url
  4718. type: object
  4719. vault:
  4720. description: Vault configures this store to sync secrets using Hashi provider
  4721. properties:
  4722. auth:
  4723. description: Auth configures how secret-manager authenticates with the Vault server.
  4724. properties:
  4725. appRole:
  4726. description: AppRole authenticates with Vault using the App Role auth mechanism, with the role and secret stored in a Kubernetes Secret resource.
  4727. properties:
  4728. path:
  4729. default: approle
  4730. description: 'Path where the App Role authentication backend is mounted in Vault, e.g: "approle"'
  4731. type: string
  4732. roleId:
  4733. description: RoleID configured in the App Role authentication backend when setting up the authentication backend in Vault.
  4734. type: string
  4735. secretRef:
  4736. description: Reference to a key in a Secret that contains the App Role secret used to authenticate with Vault. The `key` field must be specified and denotes which entry within the Secret resource is used as the app role secret.
  4737. properties:
  4738. key:
  4739. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4740. type: string
  4741. name:
  4742. description: The name of the Secret resource being referred to.
  4743. type: string
  4744. namespace:
  4745. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4746. type: string
  4747. type: object
  4748. required:
  4749. - path
  4750. - roleId
  4751. - secretRef
  4752. type: object
  4753. cert:
  4754. description: Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate Cert authentication method
  4755. properties:
  4756. clientCert:
  4757. description: ClientCert is a certificate to authenticate using the Cert Vault authentication method
  4758. properties:
  4759. key:
  4760. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4761. type: string
  4762. name:
  4763. description: The name of the Secret resource being referred to.
  4764. type: string
  4765. namespace:
  4766. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4767. type: string
  4768. type: object
  4769. secretRef:
  4770. description: SecretRef to a key in a Secret resource containing client private key to authenticate with Vault using the Cert authentication method
  4771. properties:
  4772. key:
  4773. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4774. type: string
  4775. name:
  4776. description: The name of the Secret resource being referred to.
  4777. type: string
  4778. namespace:
  4779. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4780. type: string
  4781. type: object
  4782. type: object
  4783. jwt:
  4784. description: Jwt authenticates with Vault by passing role and JWT token using the JWT/OIDC authentication method
  4785. properties:
  4786. kubernetesServiceAccountToken:
  4787. description: Optional ServiceAccountToken specifies the Kubernetes service account for which to request a token for with the `TokenRequest` API.
  4788. properties:
  4789. audiences:
  4790. description: Optional audiences field that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to a single audience `vault` it not specified.
  4791. items:
  4792. type: string
  4793. type: array
  4794. expirationSeconds:
  4795. description: Optional expiration time in seconds that will be used to request a temporary Kubernetes service account token for the service account referenced by `serviceAccountRef`. Defaults to 10 minutes.
  4796. format: int64
  4797. type: integer
  4798. serviceAccountRef:
  4799. description: Service account field containing the name of a kubernetes ServiceAccount.
  4800. properties:
  4801. name:
  4802. description: The name of the ServiceAccount resource being referred to.
  4803. type: string
  4804. namespace:
  4805. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4806. type: string
  4807. required:
  4808. - name
  4809. type: object
  4810. required:
  4811. - serviceAccountRef
  4812. type: object
  4813. path:
  4814. default: jwt
  4815. description: 'Path where the JWT authentication backend is mounted in Vault, e.g: "jwt"'
  4816. type: string
  4817. role:
  4818. description: Role is a JWT role to authenticate using the JWT/OIDC Vault authentication method
  4819. type: string
  4820. secretRef:
  4821. description: Optional SecretRef that refers to a key in a Secret resource containing JWT token to authenticate with Vault using the JWT/OIDC authentication method.
  4822. properties:
  4823. key:
  4824. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4825. type: string
  4826. name:
  4827. description: The name of the Secret resource being referred to.
  4828. type: string
  4829. namespace:
  4830. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4831. type: string
  4832. type: object
  4833. required:
  4834. - path
  4835. type: object
  4836. kubernetes:
  4837. description: Kubernetes authenticates with Vault by passing the ServiceAccount token stored in the named Secret resource to the Vault server.
  4838. properties:
  4839. mountPath:
  4840. default: kubernetes
  4841. description: 'Path where the Kubernetes authentication backend is mounted in Vault, e.g: "kubernetes"'
  4842. type: string
  4843. role:
  4844. description: A required field containing the Vault Role to assume. A Role binds a Kubernetes ServiceAccount with a set of Vault policies.
  4845. type: string
  4846. secretRef:
  4847. description: Optional secret field containing a Kubernetes ServiceAccount JWT used for authenticating with Vault. If a name is specified without a key, `token` is the default. If one is not specified, the one bound to the controller will be used.
  4848. properties:
  4849. key:
  4850. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4851. type: string
  4852. name:
  4853. description: The name of the Secret resource being referred to.
  4854. type: string
  4855. namespace:
  4856. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4857. type: string
  4858. type: object
  4859. serviceAccountRef:
  4860. description: Optional service account field containing the name of a kubernetes ServiceAccount. If the service account is specified, the service account secret token JWT will be used for authenticating with Vault. If the service account selector is not supplied, the secretRef will be used instead.
  4861. properties:
  4862. name:
  4863. description: The name of the ServiceAccount resource being referred to.
  4864. type: string
  4865. namespace:
  4866. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4867. type: string
  4868. required:
  4869. - name
  4870. type: object
  4871. required:
  4872. - mountPath
  4873. - role
  4874. type: object
  4875. ldap:
  4876. description: Ldap authenticates with Vault by passing username/password pair using the LDAP authentication method
  4877. properties:
  4878. path:
  4879. default: ldap
  4880. description: 'Path where the LDAP authentication backend is mounted in Vault, e.g: "ldap"'
  4881. type: string
  4882. secretRef:
  4883. description: SecretRef to a key in a Secret resource containing password for the LDAP user used to authenticate with Vault using the LDAP authentication method
  4884. properties:
  4885. key:
  4886. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4887. type: string
  4888. name:
  4889. description: The name of the Secret resource being referred to.
  4890. type: string
  4891. namespace:
  4892. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4893. type: string
  4894. type: object
  4895. username:
  4896. description: Username is a LDAP user name used to authenticate using the LDAP Vault authentication method
  4897. type: string
  4898. required:
  4899. - path
  4900. - username
  4901. type: object
  4902. tokenSecretRef:
  4903. description: TokenSecretRef authenticates with Vault by presenting a token.
  4904. properties:
  4905. key:
  4906. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  4907. type: string
  4908. name:
  4909. description: The name of the Secret resource being referred to.
  4910. type: string
  4911. namespace:
  4912. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  4913. type: string
  4914. type: object
  4915. type: object
  4916. caBundle:
  4917. description: PEM encoded CA bundle used to validate Vault server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  4918. format: byte
  4919. type: string
  4920. caProvider:
  4921. description: The provider for the CA bundle to use to validate Vault server certificate.
  4922. properties:
  4923. key:
  4924. description: The key the value inside of the provider type to use, only used with "Secret" type
  4925. type: string
  4926. name:
  4927. description: The name of the object located at the provider type.
  4928. type: string
  4929. namespace:
  4930. description: The namespace the Provider type is in.
  4931. type: string
  4932. type:
  4933. description: The type of provider to use such as "Secret", or "ConfigMap".
  4934. enum:
  4935. - Secret
  4936. - ConfigMap
  4937. type: string
  4938. required:
  4939. - name
  4940. - type
  4941. type: object
  4942. forwardInconsistent:
  4943. description: ForwardInconsistent tells Vault to forward read-after-write requests to the Vault leader instead of simply retrying within a loop. This can increase performance if the option is enabled serverside. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  4944. type: boolean
  4945. namespace:
  4946. description: 'Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows Vault environments to support Secure Multi-tenancy. e.g: "ns1". More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces'
  4947. type: string
  4948. path:
  4949. description: 'Path is the mount path of the Vault KV backend endpoint, e.g: "secret". The v2 KV secret engine version specific "/data" path suffix for fetching secrets from Vault is optional and will be appended if not present in specified path.'
  4950. type: string
  4951. readYourWrites:
  4952. description: ReadYourWrites ensures isolated read-after-write semantics by providing discovered cluster replication states in each request. More information about eventual consistency in Vault can be found here https://www.vaultproject.io/docs/enterprise/consistency
  4953. type: boolean
  4954. server:
  4955. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  4956. type: string
  4957. version:
  4958. default: v2
  4959. description: Version is the Vault KV secret engine version. This can be either "v1" or "v2". Version defaults to "v2".
  4960. enum:
  4961. - v1
  4962. - v2
  4963. type: string
  4964. required:
  4965. - auth
  4966. - server
  4967. type: object
  4968. webhook:
  4969. description: Webhook configures this store to sync secrets using a generic templated webhook
  4970. properties:
  4971. body:
  4972. description: Body
  4973. type: string
  4974. caBundle:
  4975. description: PEM encoded CA bundle used to validate webhook server certificate. Only used if the Server URL is using HTTPS protocol. This parameter is ignored for plain HTTP protocol connection. If not set the system root certificates are used to validate the TLS connection.
  4976. format: byte
  4977. type: string
  4978. caProvider:
  4979. description: The provider for the CA bundle to use to validate webhook server certificate.
  4980. properties:
  4981. key:
  4982. description: The key the value inside of the provider type to use, only used with "Secret" type
  4983. type: string
  4984. name:
  4985. description: The name of the object located at the provider type.
  4986. type: string
  4987. namespace:
  4988. description: The namespace the Provider type is in.
  4989. type: string
  4990. type:
  4991. description: The type of provider to use such as "Secret", or "ConfigMap".
  4992. enum:
  4993. - Secret
  4994. - ConfigMap
  4995. type: string
  4996. required:
  4997. - name
  4998. - type
  4999. type: object
  5000. headers:
  5001. additionalProperties:
  5002. type: string
  5003. description: Headers
  5004. type: object
  5005. method:
  5006. description: Webhook Method
  5007. type: string
  5008. result:
  5009. description: Result formatting
  5010. properties:
  5011. jsonPath:
  5012. description: Json path of return value
  5013. type: string
  5014. type: object
  5015. secrets:
  5016. description: Secrets to fill in templates These secrets will be passed to the templating function as key value pairs under the given name
  5017. items:
  5018. properties:
  5019. name:
  5020. description: Name of this secret in templates
  5021. type: string
  5022. secretRef:
  5023. description: Secret ref to fill in credentials
  5024. properties:
  5025. key:
  5026. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  5027. type: string
  5028. name:
  5029. description: The name of the Secret resource being referred to.
  5030. type: string
  5031. namespace:
  5032. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  5033. type: string
  5034. type: object
  5035. required:
  5036. - name
  5037. - secretRef
  5038. type: object
  5039. type: array
  5040. timeout:
  5041. description: Timeout
  5042. type: string
  5043. url:
  5044. description: Webhook url to call
  5045. type: string
  5046. required:
  5047. - result
  5048. - url
  5049. type: object
  5050. yandexlockbox:
  5051. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  5052. properties:
  5053. apiEndpoint:
  5054. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  5055. type: string
  5056. auth:
  5057. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  5058. properties:
  5059. authorizedKeySecretRef:
  5060. description: The authorized key used for authentication
  5061. properties:
  5062. key:
  5063. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  5064. type: string
  5065. name:
  5066. description: The name of the Secret resource being referred to.
  5067. type: string
  5068. namespace:
  5069. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  5070. type: string
  5071. type: object
  5072. type: object
  5073. caProvider:
  5074. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  5075. properties:
  5076. certSecretRef:
  5077. description: A reference to a specific 'key' within a Secret resource, In some instances, `key` is a required field.
  5078. properties:
  5079. key:
  5080. description: The key of the entry in the Secret resource's `data` field to be used. Some instances of this field may be defaulted, in others it may be required.
  5081. type: string
  5082. name:
  5083. description: The name of the Secret resource being referred to.
  5084. type: string
  5085. namespace:
  5086. description: Namespace of the resource being referred to. Ignored if referent is not cluster-scoped. cluster-scoped defaults to the namespace of the referent.
  5087. type: string
  5088. type: object
  5089. type: object
  5090. required:
  5091. - auth
  5092. type: object
  5093. type: object
  5094. refreshInterval:
  5095. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  5096. type: integer
  5097. retrySettings:
  5098. description: Used to configure http retries if failed
  5099. properties:
  5100. maxRetries:
  5101. format: int32
  5102. type: integer
  5103. retryInterval:
  5104. type: string
  5105. type: object
  5106. required:
  5107. - provider
  5108. type: object
  5109. status:
  5110. description: SecretStoreStatus defines the observed state of the SecretStore.
  5111. properties:
  5112. conditions:
  5113. items:
  5114. properties:
  5115. lastTransitionTime:
  5116. format: date-time
  5117. type: string
  5118. message:
  5119. type: string
  5120. reason:
  5121. type: string
  5122. status:
  5123. type: string
  5124. type:
  5125. type: string
  5126. required:
  5127. - status
  5128. - type
  5129. type: object
  5130. type: array
  5131. type: object
  5132. type: object
  5133. served: true
  5134. storage: true
  5135. subresources:
  5136. status: {}
  5137. conversion:
  5138. strategy: Webhook
  5139. webhook:
  5140. conversionReviewVersions:
  5141. - v1
  5142. clientConfig:
  5143. service:
  5144. name: kubernetes
  5145. namespace: default
  5146. path: /convert
  5147. status:
  5148. acceptedNames:
  5149. kind: ""
  5150. plural: ""
  5151. conditions: []
  5152. storedVersions: []