bundle.yaml 1.9 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. - CreateOrMerge
  561. type: string
  562. deletionPolicy:
  563. default: Retain
  564. description: |-
  565. DeletionPolicy defines rules on how to delete the resulting Secret.
  566. Defaults to "Retain"
  567. enum:
  568. - Delete
  569. - Merge
  570. - Retain
  571. type: string
  572. immutable:
  573. description: Immutable defines if the final secret will be immutable
  574. type: boolean
  575. manifest:
  576. description: |-
  577. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  578. When specified, ExternalSecret will create the resource type defined here
  579. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  580. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  581. properties:
  582. apiVersion:
  583. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  584. minLength: 1
  585. type: string
  586. kind:
  587. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  588. minLength: 1
  589. type: string
  590. required:
  591. - apiVersion
  592. - kind
  593. type: object
  594. name:
  595. description: |-
  596. The name of the Secret resource to be managed.
  597. Defaults to the .metadata.name of the ExternalSecret resource
  598. maxLength: 253
  599. minLength: 1
  600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  601. type: string
  602. template:
  603. description: Template defines a blueprint for the created Secret resource.
  604. properties:
  605. data:
  606. additionalProperties:
  607. type: string
  608. type: object
  609. engineVersion:
  610. default: v2
  611. description: |-
  612. EngineVersion specifies the template engine version
  613. that should be used to compile/execute the
  614. template specified in .data and .templateFrom[].
  615. enum:
  616. - v2
  617. type: string
  618. mergePolicy:
  619. default: Replace
  620. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  621. enum:
  622. - Replace
  623. - Merge
  624. type: string
  625. metadata:
  626. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  627. properties:
  628. annotations:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. finalizers:
  633. items:
  634. type: string
  635. type: array
  636. labels:
  637. additionalProperties:
  638. type: string
  639. type: object
  640. type: object
  641. templateFrom:
  642. items:
  643. description: |-
  644. TemplateFrom specifies a source for templates.
  645. Each item in the list can either reference a ConfigMap or a Secret resource.
  646. properties:
  647. configMap:
  648. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  649. properties:
  650. items:
  651. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  652. items:
  653. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  654. properties:
  655. key:
  656. description: A key in the ConfigMap/Secret
  657. maxLength: 253
  658. minLength: 1
  659. pattern: ^[-._a-zA-Z0-9]+$
  660. type: string
  661. templateAs:
  662. default: Values
  663. description: TemplateScope specifies how the template keys should be interpreted.
  664. enum:
  665. - Values
  666. - KeysAndValues
  667. type: string
  668. required:
  669. - key
  670. type: object
  671. type: array
  672. name:
  673. description: The name of the ConfigMap/Secret resource
  674. maxLength: 253
  675. minLength: 1
  676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  677. type: string
  678. required:
  679. - items
  680. - name
  681. type: object
  682. literal:
  683. type: string
  684. secret:
  685. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  686. properties:
  687. items:
  688. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  689. items:
  690. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  691. properties:
  692. key:
  693. description: A key in the ConfigMap/Secret
  694. maxLength: 253
  695. minLength: 1
  696. pattern: ^[-._a-zA-Z0-9]+$
  697. type: string
  698. templateAs:
  699. default: Values
  700. description: TemplateScope specifies how the template keys should be interpreted.
  701. enum:
  702. - Values
  703. - KeysAndValues
  704. type: string
  705. required:
  706. - key
  707. type: object
  708. type: array
  709. name:
  710. description: The name of the ConfigMap/Secret resource
  711. maxLength: 253
  712. minLength: 1
  713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  714. type: string
  715. required:
  716. - items
  717. - name
  718. type: object
  719. target:
  720. default: Data
  721. description: |-
  722. Target specifies where to place the template result.
  723. For Secret resources, common values are: "Data", "Annotations", "Labels".
  724. For custom resources (when spec.target.manifest is set), this supports
  725. nested paths like "spec.database.config" or "data".
  726. type: string
  727. valuesDecodingStrategy:
  728. default: None
  729. description: Used to define a decoding Strategy for the rendered template values.
  730. enum:
  731. - Auto
  732. - Base64
  733. - Base64URL
  734. - None
  735. type: string
  736. type: object
  737. type: array
  738. type:
  739. type: string
  740. type: object
  741. type: object
  742. type: object
  743. namespaceSelector:
  744. description: |-
  745. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  746. Deprecated: Use NamespaceSelectors instead.
  747. properties:
  748. matchExpressions:
  749. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  750. items:
  751. description: |-
  752. A label selector requirement is a selector that contains values, a key, and an operator that
  753. relates the key and values.
  754. properties:
  755. key:
  756. description: key is the label key that the selector applies to.
  757. type: string
  758. operator:
  759. description: |-
  760. operator represents a key's relationship to a set of values.
  761. Valid operators are In, NotIn, Exists and DoesNotExist.
  762. type: string
  763. values:
  764. description: |-
  765. values is an array of string values. If the operator is In or NotIn,
  766. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  767. the values array must be empty. This array is replaced during a strategic
  768. merge patch.
  769. items:
  770. type: string
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. required:
  774. - key
  775. - operator
  776. type: object
  777. type: array
  778. x-kubernetes-list-type: atomic
  779. matchLabels:
  780. additionalProperties:
  781. type: string
  782. description: |-
  783. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  784. map is equivalent to an element of matchExpressions, whose key field is "key", the
  785. operator is "In", and the values array contains only "value". The requirements are ANDed.
  786. type: object
  787. type: object
  788. x-kubernetes-map-type: atomic
  789. namespaceSelectors:
  790. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  791. items:
  792. description: |-
  793. A label selector is a label query over a set of resources. The result of matchLabels and
  794. matchExpressions are ANDed. An empty label selector matches all objects. A null
  795. label selector matches no objects.
  796. properties:
  797. matchExpressions:
  798. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  799. items:
  800. description: |-
  801. A label selector requirement is a selector that contains values, a key, and an operator that
  802. relates the key and values.
  803. properties:
  804. key:
  805. description: key is the label key that the selector applies to.
  806. type: string
  807. operator:
  808. description: |-
  809. operator represents a key's relationship to a set of values.
  810. Valid operators are In, NotIn, Exists and DoesNotExist.
  811. type: string
  812. values:
  813. description: |-
  814. values is an array of string values. If the operator is In or NotIn,
  815. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  816. the values array must be empty. This array is replaced during a strategic
  817. merge patch.
  818. items:
  819. type: string
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. required:
  823. - key
  824. - operator
  825. type: object
  826. type: array
  827. x-kubernetes-list-type: atomic
  828. matchLabels:
  829. additionalProperties:
  830. type: string
  831. description: |-
  832. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  833. map is equivalent to an element of matchExpressions, whose key field is "key", the
  834. operator is "In", and the values array contains only "value". The requirements are ANDed.
  835. type: object
  836. type: object
  837. x-kubernetes-map-type: atomic
  838. type: array
  839. namespaces:
  840. description: |-
  841. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  842. Deprecated: Use NamespaceSelectors instead.
  843. items:
  844. maxLength: 63
  845. minLength: 1
  846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  847. type: string
  848. type: array
  849. refreshTime:
  850. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  851. type: string
  852. required:
  853. - externalSecretSpec
  854. type: object
  855. status:
  856. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  857. properties:
  858. conditions:
  859. items:
  860. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  861. properties:
  862. message:
  863. type: string
  864. status:
  865. type: string
  866. type:
  867. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  868. type: string
  869. required:
  870. - status
  871. - type
  872. type: object
  873. type: array
  874. externalSecretName:
  875. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  876. type: string
  877. failedNamespaces:
  878. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  879. items:
  880. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  881. properties:
  882. namespace:
  883. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  884. type: string
  885. reason:
  886. description: Reason is why the ExternalSecret failed to apply to the namespace
  887. type: string
  888. required:
  889. - namespace
  890. type: object
  891. type: array
  892. provisionedNamespaces:
  893. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  894. items:
  895. type: string
  896. type: array
  897. type: object
  898. type: object
  899. served: true
  900. storage: true
  901. subresources:
  902. status: {}
  903. - additionalPrinterColumns:
  904. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  905. name: Store
  906. type: string
  907. - jsonPath: .spec.refreshTime
  908. name: Refresh Interval
  909. type: string
  910. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  911. name: Ready
  912. type: string
  913. deprecated: true
  914. name: v1beta1
  915. schema:
  916. openAPIV3Schema:
  917. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  918. properties:
  919. apiVersion:
  920. description: |-
  921. APIVersion defines the versioned schema of this representation of an object.
  922. Servers should convert recognized schemas to the latest internal value, and
  923. may reject unrecognized values.
  924. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  925. type: string
  926. kind:
  927. description: |-
  928. Kind is a string value representing the REST resource this object represents.
  929. Servers may infer this from the endpoint the client submits requests to.
  930. Cannot be updated.
  931. In CamelCase.
  932. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  933. type: string
  934. metadata:
  935. type: object
  936. spec:
  937. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  938. properties:
  939. externalSecretMetadata:
  940. description: The metadata of the external secrets to be created
  941. properties:
  942. annotations:
  943. additionalProperties:
  944. type: string
  945. type: object
  946. labels:
  947. additionalProperties:
  948. type: string
  949. type: object
  950. type: object
  951. externalSecretName:
  952. description: |-
  953. The name of the external secrets to be created.
  954. Defaults to the name of the ClusterExternalSecret
  955. maxLength: 253
  956. minLength: 1
  957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  958. type: string
  959. externalSecretSpec:
  960. description: The spec for the ExternalSecrets to be created
  961. properties:
  962. data:
  963. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  964. items:
  965. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  966. properties:
  967. remoteRef:
  968. description: |-
  969. RemoteRef points to the remote secret and defines
  970. which secret (version/property/..) to fetch.
  971. properties:
  972. conversionStrategy:
  973. default: Default
  974. description: Used to define a conversion Strategy
  975. enum:
  976. - Default
  977. - Unicode
  978. type: string
  979. decodingStrategy:
  980. default: None
  981. description: Used to define a decoding Strategy
  982. enum:
  983. - Auto
  984. - Base64
  985. - Base64URL
  986. - None
  987. type: string
  988. key:
  989. description: Key is the key used in the Provider, mandatory
  990. type: string
  991. metadataPolicy:
  992. default: None
  993. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  994. enum:
  995. - None
  996. - Fetch
  997. type: string
  998. property:
  999. description: Used to select a specific property of the Provider value (if a map), if supported
  1000. type: string
  1001. version:
  1002. description: Used to select a specific version of the Provider value, if supported
  1003. type: string
  1004. required:
  1005. - key
  1006. type: object
  1007. secretKey:
  1008. description: The key in the Kubernetes Secret to store the value.
  1009. maxLength: 253
  1010. minLength: 1
  1011. pattern: ^[-._a-zA-Z0-9]+$
  1012. type: string
  1013. sourceRef:
  1014. description: |-
  1015. SourceRef allows you to override the source
  1016. from which the value will be pulled.
  1017. maxProperties: 1
  1018. minProperties: 1
  1019. properties:
  1020. generatorRef:
  1021. description: |-
  1022. GeneratorRef points to a generator custom resource.
  1023. Deprecated: The generatorRef is not implemented in .data[].
  1024. this will be removed with v1.
  1025. properties:
  1026. apiVersion:
  1027. default: generators.external-secrets.io/v1alpha1
  1028. description: Specify the apiVersion of the generator resource
  1029. type: string
  1030. kind:
  1031. description: Specify the Kind of the generator resource
  1032. enum:
  1033. - ACRAccessToken
  1034. - ClusterGenerator
  1035. - ECRAuthorizationToken
  1036. - Fake
  1037. - GCRAccessToken
  1038. - GithubAccessToken
  1039. - QuayAccessToken
  1040. - Password
  1041. - SSHKey
  1042. - STSSessionToken
  1043. - UUID
  1044. - VaultDynamicSecret
  1045. - Webhook
  1046. - Grafana
  1047. type: string
  1048. name:
  1049. description: Specify the name of the generator resource
  1050. maxLength: 253
  1051. minLength: 1
  1052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1053. type: string
  1054. required:
  1055. - kind
  1056. - name
  1057. type: object
  1058. storeRef:
  1059. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1060. properties:
  1061. kind:
  1062. description: |-
  1063. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1064. Defaults to `SecretStore`
  1065. enum:
  1066. - SecretStore
  1067. - ClusterSecretStore
  1068. type: string
  1069. name:
  1070. description: Name of the SecretStore resource
  1071. maxLength: 253
  1072. minLength: 1
  1073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1074. type: string
  1075. type: object
  1076. type: object
  1077. required:
  1078. - remoteRef
  1079. - secretKey
  1080. type: object
  1081. type: array
  1082. dataFrom:
  1083. description: |-
  1084. DataFrom is used to fetch all properties from a specific Provider data
  1085. If multiple entries are specified, the Secret keys are merged in the specified order
  1086. items:
  1087. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1088. properties:
  1089. extract:
  1090. description: |-
  1091. Used to extract multiple key/value pairs from one secret
  1092. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1093. properties:
  1094. conversionStrategy:
  1095. default: Default
  1096. description: Used to define a conversion Strategy
  1097. enum:
  1098. - Default
  1099. - Unicode
  1100. type: string
  1101. decodingStrategy:
  1102. default: None
  1103. description: Used to define a decoding Strategy
  1104. enum:
  1105. - Auto
  1106. - Base64
  1107. - Base64URL
  1108. - None
  1109. type: string
  1110. key:
  1111. description: Key is the key used in the Provider, mandatory
  1112. type: string
  1113. metadataPolicy:
  1114. default: None
  1115. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1116. enum:
  1117. - None
  1118. - Fetch
  1119. type: string
  1120. property:
  1121. description: Used to select a specific property of the Provider value (if a map), if supported
  1122. type: string
  1123. version:
  1124. description: Used to select a specific version of the Provider value, if supported
  1125. type: string
  1126. required:
  1127. - key
  1128. type: object
  1129. find:
  1130. description: |-
  1131. Used to find secrets based on tags or regular expressions
  1132. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1133. properties:
  1134. conversionStrategy:
  1135. default: Default
  1136. description: Used to define a conversion Strategy
  1137. enum:
  1138. - Default
  1139. - Unicode
  1140. type: string
  1141. decodingStrategy:
  1142. default: None
  1143. description: Used to define a decoding Strategy
  1144. enum:
  1145. - Auto
  1146. - Base64
  1147. - Base64URL
  1148. - None
  1149. type: string
  1150. name:
  1151. description: Finds secrets based on the name.
  1152. properties:
  1153. regexp:
  1154. description: Finds secrets base
  1155. type: string
  1156. type: object
  1157. path:
  1158. description: A root path to start the find operations.
  1159. type: string
  1160. tags:
  1161. additionalProperties:
  1162. type: string
  1163. description: Find secrets based on tags.
  1164. type: object
  1165. type: object
  1166. rewrite:
  1167. description: |-
  1168. Used to rewrite secret Keys after getting them from the secret Provider
  1169. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1170. items:
  1171. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1172. maxProperties: 1
  1173. minProperties: 1
  1174. properties:
  1175. regexp:
  1176. description: |-
  1177. Used to rewrite with regular expressions.
  1178. The resulting key will be the output of a regexp.ReplaceAll operation.
  1179. properties:
  1180. source:
  1181. description: Used to define the regular expression of a re.Compiler.
  1182. type: string
  1183. target:
  1184. description: Used to define the target pattern of a ReplaceAll operation.
  1185. type: string
  1186. required:
  1187. - source
  1188. - target
  1189. type: object
  1190. transform:
  1191. description: |-
  1192. Used to apply string transformation on the secrets.
  1193. The resulting key will be the output of the template applied by the operation.
  1194. properties:
  1195. template:
  1196. description: |-
  1197. Used to define the template to apply on the secret name.
  1198. `.value ` will specify the secret name in the template.
  1199. type: string
  1200. required:
  1201. - template
  1202. type: object
  1203. type: object
  1204. type: array
  1205. sourceRef:
  1206. description: |-
  1207. SourceRef points to a store or generator
  1208. which contains secret values ready to use.
  1209. Use this in combination with Extract or Find pull values out of
  1210. a specific SecretStore.
  1211. When sourceRef points to a generator Extract or Find is not supported.
  1212. The generator returns a static map of values
  1213. maxProperties: 1
  1214. minProperties: 1
  1215. properties:
  1216. generatorRef:
  1217. description: GeneratorRef points to a generator custom resource.
  1218. properties:
  1219. apiVersion:
  1220. default: generators.external-secrets.io/v1alpha1
  1221. description: Specify the apiVersion of the generator resource
  1222. type: string
  1223. kind:
  1224. description: Specify the Kind of the generator resource
  1225. enum:
  1226. - ACRAccessToken
  1227. - ClusterGenerator
  1228. - ECRAuthorizationToken
  1229. - Fake
  1230. - GCRAccessToken
  1231. - GithubAccessToken
  1232. - QuayAccessToken
  1233. - Password
  1234. - SSHKey
  1235. - STSSessionToken
  1236. - UUID
  1237. - VaultDynamicSecret
  1238. - Webhook
  1239. - Grafana
  1240. type: string
  1241. name:
  1242. description: Specify the name of the generator resource
  1243. maxLength: 253
  1244. minLength: 1
  1245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1246. type: string
  1247. required:
  1248. - kind
  1249. - name
  1250. type: object
  1251. storeRef:
  1252. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1253. properties:
  1254. kind:
  1255. description: |-
  1256. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1257. Defaults to `SecretStore`
  1258. enum:
  1259. - SecretStore
  1260. - ClusterSecretStore
  1261. type: string
  1262. name:
  1263. description: Name of the SecretStore resource
  1264. maxLength: 253
  1265. minLength: 1
  1266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1267. type: string
  1268. type: object
  1269. type: object
  1270. type: object
  1271. type: array
  1272. refreshInterval:
  1273. default: 1h0m0s
  1274. description: |-
  1275. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1276. specified as Golang Duration strings.
  1277. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1278. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1279. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1280. type: string
  1281. refreshPolicy:
  1282. description: |-
  1283. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1284. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1285. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1286. No periodic updates occur if refreshInterval is 0.
  1287. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1288. enum:
  1289. - CreatedOnce
  1290. - Periodic
  1291. - OnChange
  1292. type: string
  1293. secretStoreRef:
  1294. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1295. properties:
  1296. kind:
  1297. description: |-
  1298. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1299. Defaults to `SecretStore`
  1300. enum:
  1301. - SecretStore
  1302. - ClusterSecretStore
  1303. type: string
  1304. name:
  1305. description: Name of the SecretStore resource
  1306. maxLength: 253
  1307. minLength: 1
  1308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1309. type: string
  1310. type: object
  1311. target:
  1312. default:
  1313. creationPolicy: Owner
  1314. deletionPolicy: Retain
  1315. description: |-
  1316. ExternalSecretTarget defines the Kubernetes Secret to be created
  1317. There can be only one target per ExternalSecret.
  1318. properties:
  1319. creationPolicy:
  1320. default: Owner
  1321. description: |-
  1322. CreationPolicy defines rules on how to create the resulting Secret.
  1323. Defaults to "Owner"
  1324. enum:
  1325. - Owner
  1326. - Orphan
  1327. - Merge
  1328. - None
  1329. type: string
  1330. deletionPolicy:
  1331. default: Retain
  1332. description: |-
  1333. DeletionPolicy defines rules on how to delete the resulting Secret.
  1334. Defaults to "Retain"
  1335. enum:
  1336. - Delete
  1337. - Merge
  1338. - Retain
  1339. type: string
  1340. immutable:
  1341. description: Immutable defines if the final secret will be immutable
  1342. type: boolean
  1343. name:
  1344. description: |-
  1345. The name of the Secret resource to be managed.
  1346. Defaults to the .metadata.name of the ExternalSecret resource
  1347. maxLength: 253
  1348. minLength: 1
  1349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1350. type: string
  1351. template:
  1352. description: Template defines a blueprint for the created Secret resource.
  1353. properties:
  1354. data:
  1355. additionalProperties:
  1356. type: string
  1357. type: object
  1358. engineVersion:
  1359. default: v2
  1360. description: |-
  1361. EngineVersion specifies the template engine version
  1362. that should be used to compile/execute the
  1363. template specified in .data and .templateFrom[].
  1364. enum:
  1365. - v2
  1366. type: string
  1367. mergePolicy:
  1368. default: Replace
  1369. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1370. enum:
  1371. - Replace
  1372. - Merge
  1373. type: string
  1374. metadata:
  1375. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1376. properties:
  1377. annotations:
  1378. additionalProperties:
  1379. type: string
  1380. type: object
  1381. labels:
  1382. additionalProperties:
  1383. type: string
  1384. type: object
  1385. type: object
  1386. templateFrom:
  1387. items:
  1388. description: TemplateFrom defines a source for template data.
  1389. properties:
  1390. configMap:
  1391. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1392. properties:
  1393. items:
  1394. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1395. items:
  1396. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1397. properties:
  1398. key:
  1399. description: A key in the ConfigMap/Secret
  1400. maxLength: 253
  1401. minLength: 1
  1402. pattern: ^[-._a-zA-Z0-9]+$
  1403. type: string
  1404. templateAs:
  1405. default: Values
  1406. description: TemplateScope defines the scope of the template when processing template data.
  1407. enum:
  1408. - Values
  1409. - KeysAndValues
  1410. type: string
  1411. required:
  1412. - key
  1413. type: object
  1414. type: array
  1415. name:
  1416. description: The name of the ConfigMap/Secret resource
  1417. maxLength: 253
  1418. minLength: 1
  1419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1420. type: string
  1421. required:
  1422. - items
  1423. - name
  1424. type: object
  1425. literal:
  1426. type: string
  1427. secret:
  1428. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1429. properties:
  1430. items:
  1431. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1432. items:
  1433. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1434. properties:
  1435. key:
  1436. description: A key in the ConfigMap/Secret
  1437. maxLength: 253
  1438. minLength: 1
  1439. pattern: ^[-._a-zA-Z0-9]+$
  1440. type: string
  1441. templateAs:
  1442. default: Values
  1443. description: TemplateScope defines the scope of the template when processing template data.
  1444. enum:
  1445. - Values
  1446. - KeysAndValues
  1447. type: string
  1448. required:
  1449. - key
  1450. type: object
  1451. type: array
  1452. name:
  1453. description: The name of the ConfigMap/Secret resource
  1454. maxLength: 253
  1455. minLength: 1
  1456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1457. type: string
  1458. required:
  1459. - items
  1460. - name
  1461. type: object
  1462. target:
  1463. default: Data
  1464. description: TemplateTarget defines the target field where the template result will be stored.
  1465. enum:
  1466. - Data
  1467. - Annotations
  1468. - Labels
  1469. type: string
  1470. type: object
  1471. type: array
  1472. type:
  1473. type: string
  1474. type: object
  1475. type: object
  1476. type: object
  1477. namespaceSelector:
  1478. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1479. properties:
  1480. matchExpressions:
  1481. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1482. items:
  1483. description: |-
  1484. A label selector requirement is a selector that contains values, a key, and an operator that
  1485. relates the key and values.
  1486. properties:
  1487. key:
  1488. description: key is the label key that the selector applies to.
  1489. type: string
  1490. operator:
  1491. description: |-
  1492. operator represents a key's relationship to a set of values.
  1493. Valid operators are In, NotIn, Exists and DoesNotExist.
  1494. type: string
  1495. values:
  1496. description: |-
  1497. values is an array of string values. If the operator is In or NotIn,
  1498. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1499. the values array must be empty. This array is replaced during a strategic
  1500. merge patch.
  1501. items:
  1502. type: string
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. required:
  1506. - key
  1507. - operator
  1508. type: object
  1509. type: array
  1510. x-kubernetes-list-type: atomic
  1511. matchLabels:
  1512. additionalProperties:
  1513. type: string
  1514. description: |-
  1515. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1516. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1517. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1518. type: object
  1519. type: object
  1520. x-kubernetes-map-type: atomic
  1521. namespaceSelectors:
  1522. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1523. items:
  1524. description: |-
  1525. A label selector is a label query over a set of resources. The result of matchLabels and
  1526. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1527. label selector matches no objects.
  1528. properties:
  1529. matchExpressions:
  1530. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1531. items:
  1532. description: |-
  1533. A label selector requirement is a selector that contains values, a key, and an operator that
  1534. relates the key and values.
  1535. properties:
  1536. key:
  1537. description: key is the label key that the selector applies to.
  1538. type: string
  1539. operator:
  1540. description: |-
  1541. operator represents a key's relationship to a set of values.
  1542. Valid operators are In, NotIn, Exists and DoesNotExist.
  1543. type: string
  1544. values:
  1545. description: |-
  1546. values is an array of string values. If the operator is In or NotIn,
  1547. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1548. the values array must be empty. This array is replaced during a strategic
  1549. merge patch.
  1550. items:
  1551. type: string
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. required:
  1555. - key
  1556. - operator
  1557. type: object
  1558. type: array
  1559. x-kubernetes-list-type: atomic
  1560. matchLabels:
  1561. additionalProperties:
  1562. type: string
  1563. description: |-
  1564. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1565. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1566. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1567. type: object
  1568. type: object
  1569. x-kubernetes-map-type: atomic
  1570. type: array
  1571. namespaces:
  1572. description: |-
  1573. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1574. Deprecated: Use NamespaceSelectors instead.
  1575. items:
  1576. maxLength: 63
  1577. minLength: 1
  1578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1579. type: string
  1580. type: array
  1581. refreshTime:
  1582. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1583. type: string
  1584. required:
  1585. - externalSecretSpec
  1586. type: object
  1587. status:
  1588. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1589. properties:
  1590. conditions:
  1591. items:
  1592. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1593. properties:
  1594. message:
  1595. type: string
  1596. status:
  1597. type: string
  1598. type:
  1599. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1600. type: string
  1601. required:
  1602. - status
  1603. - type
  1604. type: object
  1605. type: array
  1606. externalSecretName:
  1607. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1608. type: string
  1609. failedNamespaces:
  1610. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1611. items:
  1612. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1613. properties:
  1614. namespace:
  1615. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1616. type: string
  1617. reason:
  1618. description: Reason is why the ExternalSecret failed to apply to the namespace
  1619. type: string
  1620. required:
  1621. - namespace
  1622. type: object
  1623. type: array
  1624. provisionedNamespaces:
  1625. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1626. items:
  1627. type: string
  1628. type: array
  1629. type: object
  1630. type: object
  1631. served: false
  1632. storage: false
  1633. subresources:
  1634. status: {}
  1635. ---
  1636. apiVersion: apiextensions.k8s.io/v1
  1637. kind: CustomResourceDefinition
  1638. metadata:
  1639. annotations:
  1640. controller-gen.kubebuilder.io/version: v0.19.0
  1641. labels:
  1642. external-secrets.io/component: controller
  1643. name: clusterpushsecrets.external-secrets.io
  1644. spec:
  1645. group: external-secrets.io
  1646. names:
  1647. categories:
  1648. - external-secrets
  1649. kind: ClusterPushSecret
  1650. listKind: ClusterPushSecretList
  1651. plural: clusterpushsecrets
  1652. singular: clusterpushsecret
  1653. scope: Cluster
  1654. versions:
  1655. - additionalPrinterColumns:
  1656. - jsonPath: .metadata.creationTimestamp
  1657. name: AGE
  1658. type: date
  1659. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1660. name: Status
  1661. type: string
  1662. name: v1alpha1
  1663. schema:
  1664. openAPIV3Schema:
  1665. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1666. properties:
  1667. apiVersion:
  1668. description: |-
  1669. APIVersion defines the versioned schema of this representation of an object.
  1670. Servers should convert recognized schemas to the latest internal value, and
  1671. may reject unrecognized values.
  1672. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1673. type: string
  1674. kind:
  1675. description: |-
  1676. Kind is a string value representing the REST resource this object represents.
  1677. Servers may infer this from the endpoint the client submits requests to.
  1678. Cannot be updated.
  1679. In CamelCase.
  1680. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1681. type: string
  1682. metadata:
  1683. type: object
  1684. spec:
  1685. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1686. properties:
  1687. namespaceSelectors:
  1688. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1689. items:
  1690. description: |-
  1691. A label selector is a label query over a set of resources. The result of matchLabels and
  1692. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1693. label selector matches no objects.
  1694. properties:
  1695. matchExpressions:
  1696. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1697. items:
  1698. description: |-
  1699. A label selector requirement is a selector that contains values, a key, and an operator that
  1700. relates the key and values.
  1701. properties:
  1702. key:
  1703. description: key is the label key that the selector applies to.
  1704. type: string
  1705. operator:
  1706. description: |-
  1707. operator represents a key's relationship to a set of values.
  1708. Valid operators are In, NotIn, Exists and DoesNotExist.
  1709. type: string
  1710. values:
  1711. description: |-
  1712. values is an array of string values. If the operator is In or NotIn,
  1713. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1714. the values array must be empty. This array is replaced during a strategic
  1715. merge patch.
  1716. items:
  1717. type: string
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. required:
  1721. - key
  1722. - operator
  1723. type: object
  1724. type: array
  1725. x-kubernetes-list-type: atomic
  1726. matchLabels:
  1727. additionalProperties:
  1728. type: string
  1729. description: |-
  1730. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1731. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1732. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1733. type: object
  1734. type: object
  1735. x-kubernetes-map-type: atomic
  1736. type: array
  1737. pushSecretMetadata:
  1738. description: The metadata of the external secrets to be created
  1739. properties:
  1740. annotations:
  1741. additionalProperties:
  1742. type: string
  1743. type: object
  1744. labels:
  1745. additionalProperties:
  1746. type: string
  1747. type: object
  1748. type: object
  1749. pushSecretName:
  1750. description: |-
  1751. The name of the push secrets to be created.
  1752. Defaults to the name of the ClusterPushSecret
  1753. maxLength: 253
  1754. minLength: 1
  1755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1756. type: string
  1757. pushSecretSpec:
  1758. description: PushSecretSpec defines what to do with the secrets.
  1759. properties:
  1760. data:
  1761. description: Secret Data that should be pushed to providers
  1762. items:
  1763. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1764. properties:
  1765. conversionStrategy:
  1766. default: None
  1767. description: Used to define a conversion Strategy for the secret keys
  1768. enum:
  1769. - None
  1770. - ReverseUnicode
  1771. type: string
  1772. match:
  1773. description: Match a given Secret Key to be pushed to the provider.
  1774. properties:
  1775. remoteRef:
  1776. description: Remote Refs to push to providers.
  1777. properties:
  1778. property:
  1779. description: Name of the property in the resulting secret
  1780. type: string
  1781. remoteKey:
  1782. description: Name of the resulting provider secret.
  1783. type: string
  1784. required:
  1785. - remoteKey
  1786. type: object
  1787. secretKey:
  1788. description: Secret Key to be pushed
  1789. type: string
  1790. required:
  1791. - remoteRef
  1792. type: object
  1793. metadata:
  1794. description: |-
  1795. Metadata is metadata attached to the secret.
  1796. The structure of metadata is provider specific, please look it up in the provider documentation.
  1797. x-kubernetes-preserve-unknown-fields: true
  1798. required:
  1799. - match
  1800. type: object
  1801. type: array
  1802. dataTo:
  1803. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1804. items:
  1805. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1806. properties:
  1807. conversionStrategy:
  1808. default: None
  1809. description: Used to define a conversion Strategy for the secret keys
  1810. enum:
  1811. - None
  1812. - ReverseUnicode
  1813. type: string
  1814. match:
  1815. description: |-
  1816. Match pattern for selecting keys from the source Secret.
  1817. If not specified, all keys are selected.
  1818. properties:
  1819. regexp:
  1820. description: |-
  1821. Regexp matches keys by regular expression.
  1822. If not specified, all keys are matched.
  1823. type: string
  1824. type: object
  1825. metadata:
  1826. description: |-
  1827. Metadata is metadata attached to the secret.
  1828. The structure of metadata is provider specific, please look it up in the provider documentation.
  1829. x-kubernetes-preserve-unknown-fields: true
  1830. remoteKey:
  1831. description: |-
  1832. RemoteKey is the name of the single provider secret that will receive ALL
  1833. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1834. When set, per-key expansion is skipped and a single push is performed.
  1835. The provider's store prefix (if any) is still prepended to this value.
  1836. When not set, each matched key is pushed as its own individual provider secret.
  1837. type: string
  1838. rewrite:
  1839. description: |-
  1840. Rewrite operations to transform keys before pushing to the provider.
  1841. Operations are applied sequentially.
  1842. items:
  1843. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1844. properties:
  1845. regexp:
  1846. description: Used to rewrite with regular expressions.
  1847. properties:
  1848. source:
  1849. description: Used to define the regular expression of a re.Compiler.
  1850. type: string
  1851. target:
  1852. description: Used to define the target pattern of a ReplaceAll operation.
  1853. type: string
  1854. required:
  1855. - source
  1856. - target
  1857. type: object
  1858. transform:
  1859. description: Used to apply string transformation on the secrets.
  1860. properties:
  1861. template:
  1862. description: |-
  1863. Used to define the template to apply on the secret name.
  1864. `.value ` will specify the secret name in the template.
  1865. type: string
  1866. required:
  1867. - template
  1868. type: object
  1869. type: object
  1870. x-kubernetes-validations:
  1871. - message: exactly one of regexp or transform must be set
  1872. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1873. type: array
  1874. storeRef:
  1875. description: StoreRef specifies which SecretStore to push to. Required.
  1876. properties:
  1877. kind:
  1878. default: SecretStore
  1879. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1880. enum:
  1881. - SecretStore
  1882. - ClusterSecretStore
  1883. type: string
  1884. labelSelector:
  1885. description: Optionally, sync to secret stores with label selector
  1886. properties:
  1887. matchExpressions:
  1888. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1889. items:
  1890. description: |-
  1891. A label selector requirement is a selector that contains values, a key, and an operator that
  1892. relates the key and values.
  1893. properties:
  1894. key:
  1895. description: key is the label key that the selector applies to.
  1896. type: string
  1897. operator:
  1898. description: |-
  1899. operator represents a key's relationship to a set of values.
  1900. Valid operators are In, NotIn, Exists and DoesNotExist.
  1901. type: string
  1902. values:
  1903. description: |-
  1904. values is an array of string values. If the operator is In or NotIn,
  1905. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1906. the values array must be empty. This array is replaced during a strategic
  1907. merge patch.
  1908. items:
  1909. type: string
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. required:
  1913. - key
  1914. - operator
  1915. type: object
  1916. type: array
  1917. x-kubernetes-list-type: atomic
  1918. matchLabels:
  1919. additionalProperties:
  1920. type: string
  1921. description: |-
  1922. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1923. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1924. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1925. type: object
  1926. type: object
  1927. x-kubernetes-map-type: atomic
  1928. name:
  1929. description: Optionally, sync to the SecretStore of the given name
  1930. maxLength: 253
  1931. minLength: 1
  1932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1933. type: string
  1934. type: object
  1935. type: object
  1936. x-kubernetes-validations:
  1937. - message: storeRef must specify either name or labelSelector
  1938. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1939. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1940. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1941. type: array
  1942. deletionPolicy:
  1943. default: None
  1944. description: Deletion Policy to handle Secrets in the provider.
  1945. enum:
  1946. - Delete
  1947. - None
  1948. type: string
  1949. refreshInterval:
  1950. default: 1h0m0s
  1951. description: The Interval to which External Secrets will try to push a secret definition
  1952. type: string
  1953. secretStoreRefs:
  1954. items:
  1955. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1956. properties:
  1957. kind:
  1958. default: SecretStore
  1959. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1960. enum:
  1961. - SecretStore
  1962. - ClusterSecretStore
  1963. type: string
  1964. labelSelector:
  1965. description: Optionally, sync to secret stores with label selector
  1966. properties:
  1967. matchExpressions:
  1968. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1969. items:
  1970. description: |-
  1971. A label selector requirement is a selector that contains values, a key, and an operator that
  1972. relates the key and values.
  1973. properties:
  1974. key:
  1975. description: key is the label key that the selector applies to.
  1976. type: string
  1977. operator:
  1978. description: |-
  1979. operator represents a key's relationship to a set of values.
  1980. Valid operators are In, NotIn, Exists and DoesNotExist.
  1981. type: string
  1982. values:
  1983. description: |-
  1984. values is an array of string values. If the operator is In or NotIn,
  1985. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1986. the values array must be empty. This array is replaced during a strategic
  1987. merge patch.
  1988. items:
  1989. type: string
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. required:
  1993. - key
  1994. - operator
  1995. type: object
  1996. type: array
  1997. x-kubernetes-list-type: atomic
  1998. matchLabels:
  1999. additionalProperties:
  2000. type: string
  2001. description: |-
  2002. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2003. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2004. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2005. type: object
  2006. type: object
  2007. x-kubernetes-map-type: atomic
  2008. name:
  2009. description: Optionally, sync to the SecretStore of the given name
  2010. maxLength: 253
  2011. minLength: 1
  2012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2013. type: string
  2014. type: object
  2015. type: array
  2016. selector:
  2017. description: The Secret Selector (k8s source) for the Push Secret
  2018. maxProperties: 1
  2019. minProperties: 1
  2020. properties:
  2021. generatorRef:
  2022. description: Point to a generator to create a Secret.
  2023. properties:
  2024. apiVersion:
  2025. default: generators.external-secrets.io/v1alpha1
  2026. description: Specify the apiVersion of the generator resource
  2027. type: string
  2028. kind:
  2029. description: Specify the Kind of the generator resource
  2030. enum:
  2031. - ACRAccessToken
  2032. - BeyondtrustWorkloadCredentialsDynamicSecret
  2033. - ClusterGenerator
  2034. - CloudsmithAccessToken
  2035. - ECRAuthorizationToken
  2036. - Fake
  2037. - GCRAccessToken
  2038. - GithubAccessToken
  2039. - GitlabDeployToken
  2040. - QuayAccessToken
  2041. - Password
  2042. - SSHKey
  2043. - STSSessionToken
  2044. - UUID
  2045. - VaultDynamicSecret
  2046. - Webhook
  2047. - Grafana
  2048. - MFA
  2049. type: string
  2050. name:
  2051. description: Specify the name of the generator resource
  2052. maxLength: 253
  2053. minLength: 1
  2054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2055. type: string
  2056. required:
  2057. - kind
  2058. - name
  2059. type: object
  2060. secret:
  2061. description: Select a Secret to Push.
  2062. properties:
  2063. name:
  2064. description: |-
  2065. Name of the Secret.
  2066. The Secret must exist in the same namespace as the PushSecret manifest.
  2067. maxLength: 253
  2068. minLength: 1
  2069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2070. type: string
  2071. selector:
  2072. description: Selector chooses secrets using a labelSelector.
  2073. properties:
  2074. matchExpressions:
  2075. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2076. items:
  2077. description: |-
  2078. A label selector requirement is a selector that contains values, a key, and an operator that
  2079. relates the key and values.
  2080. properties:
  2081. key:
  2082. description: key is the label key that the selector applies to.
  2083. type: string
  2084. operator:
  2085. description: |-
  2086. operator represents a key's relationship to a set of values.
  2087. Valid operators are In, NotIn, Exists and DoesNotExist.
  2088. type: string
  2089. values:
  2090. description: |-
  2091. values is an array of string values. If the operator is In or NotIn,
  2092. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2093. the values array must be empty. This array is replaced during a strategic
  2094. merge patch.
  2095. items:
  2096. type: string
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. required:
  2100. - key
  2101. - operator
  2102. type: object
  2103. type: array
  2104. x-kubernetes-list-type: atomic
  2105. matchLabels:
  2106. additionalProperties:
  2107. type: string
  2108. description: |-
  2109. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2110. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2111. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2112. type: object
  2113. type: object
  2114. x-kubernetes-map-type: atomic
  2115. type: object
  2116. type: object
  2117. template:
  2118. description: Template defines a blueprint for the created Secret resource.
  2119. properties:
  2120. data:
  2121. additionalProperties:
  2122. type: string
  2123. type: object
  2124. engineVersion:
  2125. default: v2
  2126. description: |-
  2127. EngineVersion specifies the template engine version
  2128. that should be used to compile/execute the
  2129. template specified in .data and .templateFrom[].
  2130. enum:
  2131. - v2
  2132. type: string
  2133. mergePolicy:
  2134. default: Replace
  2135. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2136. enum:
  2137. - Replace
  2138. - Merge
  2139. type: string
  2140. metadata:
  2141. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2142. properties:
  2143. annotations:
  2144. additionalProperties:
  2145. type: string
  2146. type: object
  2147. finalizers:
  2148. items:
  2149. type: string
  2150. type: array
  2151. labels:
  2152. additionalProperties:
  2153. type: string
  2154. type: object
  2155. type: object
  2156. templateFrom:
  2157. items:
  2158. description: |-
  2159. TemplateFrom specifies a source for templates.
  2160. Each item in the list can either reference a ConfigMap or a Secret resource.
  2161. properties:
  2162. configMap:
  2163. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2164. properties:
  2165. items:
  2166. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2167. items:
  2168. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2169. properties:
  2170. key:
  2171. description: A key in the ConfigMap/Secret
  2172. maxLength: 253
  2173. minLength: 1
  2174. pattern: ^[-._a-zA-Z0-9]+$
  2175. type: string
  2176. templateAs:
  2177. default: Values
  2178. description: TemplateScope specifies how the template keys should be interpreted.
  2179. enum:
  2180. - Values
  2181. - KeysAndValues
  2182. type: string
  2183. required:
  2184. - key
  2185. type: object
  2186. type: array
  2187. name:
  2188. description: The name of the ConfigMap/Secret resource
  2189. maxLength: 253
  2190. minLength: 1
  2191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2192. type: string
  2193. required:
  2194. - items
  2195. - name
  2196. type: object
  2197. literal:
  2198. type: string
  2199. secret:
  2200. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2201. properties:
  2202. items:
  2203. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2204. items:
  2205. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2206. properties:
  2207. key:
  2208. description: A key in the ConfigMap/Secret
  2209. maxLength: 253
  2210. minLength: 1
  2211. pattern: ^[-._a-zA-Z0-9]+$
  2212. type: string
  2213. templateAs:
  2214. default: Values
  2215. description: TemplateScope specifies how the template keys should be interpreted.
  2216. enum:
  2217. - Values
  2218. - KeysAndValues
  2219. type: string
  2220. required:
  2221. - key
  2222. type: object
  2223. type: array
  2224. name:
  2225. description: The name of the ConfigMap/Secret resource
  2226. maxLength: 253
  2227. minLength: 1
  2228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2229. type: string
  2230. required:
  2231. - items
  2232. - name
  2233. type: object
  2234. target:
  2235. default: Data
  2236. description: |-
  2237. Target specifies where to place the template result.
  2238. For Secret resources, common values are: "Data", "Annotations", "Labels".
  2239. For custom resources (when spec.target.manifest is set), this supports
  2240. nested paths like "spec.database.config" or "data".
  2241. type: string
  2242. valuesDecodingStrategy:
  2243. default: None
  2244. description: Used to define a decoding Strategy for the rendered template values.
  2245. enum:
  2246. - Auto
  2247. - Base64
  2248. - Base64URL
  2249. - None
  2250. type: string
  2251. type: object
  2252. type: array
  2253. type:
  2254. type: string
  2255. type: object
  2256. updatePolicy:
  2257. default: Replace
  2258. description: UpdatePolicy to handle Secrets in the provider.
  2259. enum:
  2260. - Replace
  2261. - IfNotExists
  2262. type: string
  2263. required:
  2264. - secretStoreRefs
  2265. - selector
  2266. type: object
  2267. refreshTime:
  2268. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2269. type: string
  2270. required:
  2271. - pushSecretSpec
  2272. type: object
  2273. status:
  2274. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2275. properties:
  2276. conditions:
  2277. items:
  2278. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2279. properties:
  2280. lastTransitionTime:
  2281. format: date-time
  2282. type: string
  2283. message:
  2284. type: string
  2285. reason:
  2286. type: string
  2287. status:
  2288. type: string
  2289. type:
  2290. description: PushSecretConditionType indicates the condition of the PushSecret.
  2291. type: string
  2292. required:
  2293. - status
  2294. - type
  2295. type: object
  2296. type: array
  2297. failedNamespaces:
  2298. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2299. items:
  2300. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2301. properties:
  2302. namespace:
  2303. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2304. type: string
  2305. reason:
  2306. description: Reason is why the PushSecret failed to apply to the namespace
  2307. type: string
  2308. required:
  2309. - namespace
  2310. type: object
  2311. type: array
  2312. provisionedNamespaces:
  2313. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2314. items:
  2315. type: string
  2316. type: array
  2317. pushSecretName:
  2318. type: string
  2319. type: object
  2320. type: object
  2321. served: true
  2322. storage: true
  2323. subresources:
  2324. status: {}
  2325. ---
  2326. apiVersion: apiextensions.k8s.io/v1
  2327. kind: CustomResourceDefinition
  2328. metadata:
  2329. annotations:
  2330. controller-gen.kubebuilder.io/version: v0.19.0
  2331. labels:
  2332. external-secrets.io/component: controller
  2333. name: clustersecretstores.external-secrets.io
  2334. spec:
  2335. group: external-secrets.io
  2336. names:
  2337. categories:
  2338. - external-secrets
  2339. kind: ClusterSecretStore
  2340. listKind: ClusterSecretStoreList
  2341. plural: clustersecretstores
  2342. shortNames:
  2343. - css
  2344. singular: clustersecretstore
  2345. scope: Cluster
  2346. versions:
  2347. - additionalPrinterColumns:
  2348. - jsonPath: .metadata.creationTimestamp
  2349. name: AGE
  2350. type: date
  2351. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2352. name: Status
  2353. type: string
  2354. - jsonPath: .status.capabilities
  2355. name: Capabilities
  2356. type: string
  2357. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2358. name: Ready
  2359. type: string
  2360. name: v1
  2361. schema:
  2362. openAPIV3Schema:
  2363. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2364. properties:
  2365. apiVersion:
  2366. description: |-
  2367. APIVersion defines the versioned schema of this representation of an object.
  2368. Servers should convert recognized schemas to the latest internal value, and
  2369. may reject unrecognized values.
  2370. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2371. type: string
  2372. kind:
  2373. description: |-
  2374. Kind is a string value representing the REST resource this object represents.
  2375. Servers may infer this from the endpoint the client submits requests to.
  2376. Cannot be updated.
  2377. In CamelCase.
  2378. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2379. type: string
  2380. metadata:
  2381. type: object
  2382. spec:
  2383. description: SecretStoreSpec defines the desired state of SecretStore.
  2384. properties:
  2385. conditions:
  2386. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2387. items:
  2388. description: |-
  2389. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2390. for a ClusterSecretStore instance.
  2391. properties:
  2392. namespaceRegexes:
  2393. description: Choose namespaces by using regex matching
  2394. items:
  2395. type: string
  2396. type: array
  2397. namespaceSelector:
  2398. description: Choose namespace using a labelSelector
  2399. properties:
  2400. matchExpressions:
  2401. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2402. items:
  2403. description: |-
  2404. A label selector requirement is a selector that contains values, a key, and an operator that
  2405. relates the key and values.
  2406. properties:
  2407. key:
  2408. description: key is the label key that the selector applies to.
  2409. type: string
  2410. operator:
  2411. description: |-
  2412. operator represents a key's relationship to a set of values.
  2413. Valid operators are In, NotIn, Exists and DoesNotExist.
  2414. type: string
  2415. values:
  2416. description: |-
  2417. values is an array of string values. If the operator is In or NotIn,
  2418. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2419. the values array must be empty. This array is replaced during a strategic
  2420. merge patch.
  2421. items:
  2422. type: string
  2423. type: array
  2424. x-kubernetes-list-type: atomic
  2425. required:
  2426. - key
  2427. - operator
  2428. type: object
  2429. type: array
  2430. x-kubernetes-list-type: atomic
  2431. matchLabels:
  2432. additionalProperties:
  2433. type: string
  2434. description: |-
  2435. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2436. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2437. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2438. type: object
  2439. type: object
  2440. x-kubernetes-map-type: atomic
  2441. namespaces:
  2442. description: Choose namespaces by name
  2443. items:
  2444. maxLength: 63
  2445. minLength: 1
  2446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2447. type: string
  2448. type: array
  2449. type: object
  2450. type: array
  2451. controller:
  2452. description: |-
  2453. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2454. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2455. type: string
  2456. provider:
  2457. description: Used to configure the provider. Only one provider may be set
  2458. maxProperties: 1
  2459. minProperties: 1
  2460. properties:
  2461. akeyless:
  2462. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2463. properties:
  2464. akeylessGWApiURL:
  2465. description: Akeyless GW API Url from which the secrets to be fetched from.
  2466. type: string
  2467. authSecretRef:
  2468. description: Auth configures how the operator authenticates with Akeyless.
  2469. properties:
  2470. kubernetesAuth:
  2471. description: |-
  2472. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2473. token stored in the named Secret resource.
  2474. properties:
  2475. accessID:
  2476. description: the Akeyless Kubernetes auth-method access-id
  2477. type: string
  2478. k8sConfName:
  2479. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2480. type: string
  2481. secretRef:
  2482. description: |-
  2483. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2484. for authenticating with Akeyless. If a name is specified without a key,
  2485. `token` is the default. If one is not specified, the one bound to
  2486. the controller will be used.
  2487. properties:
  2488. key:
  2489. description: |-
  2490. A key in the referenced Secret.
  2491. Some instances of this field may be defaulted, in others it may be required.
  2492. maxLength: 253
  2493. minLength: 1
  2494. pattern: ^[-._a-zA-Z0-9]+$
  2495. type: string
  2496. name:
  2497. description: The name of the Secret resource being referred to.
  2498. maxLength: 253
  2499. minLength: 1
  2500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2501. type: string
  2502. namespace:
  2503. description: |-
  2504. The namespace of the Secret resource being referred to.
  2505. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2506. maxLength: 63
  2507. minLength: 1
  2508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2509. type: string
  2510. type: object
  2511. serviceAccountRef:
  2512. description: |-
  2513. Optional service account field containing the name of a kubernetes ServiceAccount.
  2514. If the service account is specified, the service account secret token JWT will be used
  2515. for authenticating with Akeyless. If the service account selector is not supplied,
  2516. the secretRef will be used instead.
  2517. properties:
  2518. audiences:
  2519. description: |-
  2520. Audience specifies the `aud` claim for the service account token
  2521. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2522. then this audiences will be appended to the list
  2523. items:
  2524. type: string
  2525. type: array
  2526. name:
  2527. description: The name of the ServiceAccount resource being referred to.
  2528. maxLength: 253
  2529. minLength: 1
  2530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2531. type: string
  2532. namespace:
  2533. description: |-
  2534. Namespace of the resource being referred to.
  2535. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2536. maxLength: 63
  2537. minLength: 1
  2538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2539. type: string
  2540. required:
  2541. - name
  2542. type: object
  2543. required:
  2544. - accessID
  2545. - k8sConfName
  2546. type: object
  2547. secretRef:
  2548. description: |-
  2549. Reference to a Secret that contains the details
  2550. to authenticate with Akeyless.
  2551. properties:
  2552. accessID:
  2553. description: The SecretAccessID is used for authentication
  2554. properties:
  2555. key:
  2556. description: |-
  2557. A key in the referenced Secret.
  2558. Some instances of this field may be defaulted, in others it may be required.
  2559. maxLength: 253
  2560. minLength: 1
  2561. pattern: ^[-._a-zA-Z0-9]+$
  2562. type: string
  2563. name:
  2564. description: The name of the Secret resource being referred to.
  2565. maxLength: 253
  2566. minLength: 1
  2567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2568. type: string
  2569. namespace:
  2570. description: |-
  2571. The namespace of the Secret resource being referred to.
  2572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2573. maxLength: 63
  2574. minLength: 1
  2575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2576. type: string
  2577. type: object
  2578. accessType:
  2579. description: |-
  2580. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2581. In some instances, `key` is a required field.
  2582. properties:
  2583. key:
  2584. description: |-
  2585. A key in the referenced Secret.
  2586. Some instances of this field may be defaulted, in others it may be required.
  2587. maxLength: 253
  2588. minLength: 1
  2589. pattern: ^[-._a-zA-Z0-9]+$
  2590. type: string
  2591. name:
  2592. description: The name of the Secret resource being referred to.
  2593. maxLength: 253
  2594. minLength: 1
  2595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2596. type: string
  2597. namespace:
  2598. description: |-
  2599. The namespace of the Secret resource being referred to.
  2600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2601. maxLength: 63
  2602. minLength: 1
  2603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2604. type: string
  2605. type: object
  2606. accessTypeParam:
  2607. description: |-
  2608. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2609. In some instances, `key` is a required field.
  2610. properties:
  2611. key:
  2612. description: |-
  2613. A key in the referenced Secret.
  2614. Some instances of this field may be defaulted, in others it may be required.
  2615. maxLength: 253
  2616. minLength: 1
  2617. pattern: ^[-._a-zA-Z0-9]+$
  2618. type: string
  2619. name:
  2620. description: The name of the Secret resource being referred to.
  2621. maxLength: 253
  2622. minLength: 1
  2623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2624. type: string
  2625. namespace:
  2626. description: |-
  2627. The namespace of the Secret resource being referred to.
  2628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2629. maxLength: 63
  2630. minLength: 1
  2631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2632. type: string
  2633. type: object
  2634. type: object
  2635. serviceAccountRef:
  2636. description: |-
  2637. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2638. authentication on AKS Workload Identity. The operator obtains a federated
  2639. identity token from this ServiceAccount via the TokenRequest API instead
  2640. of using the ESO controller pod identity. Ignored for other access types.
  2641. properties:
  2642. audiences:
  2643. description: |-
  2644. Audience specifies the `aud` claim for the service account token
  2645. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2646. then this audiences will be appended to the list
  2647. items:
  2648. type: string
  2649. type: array
  2650. name:
  2651. description: The name of the ServiceAccount resource being referred to.
  2652. maxLength: 253
  2653. minLength: 1
  2654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2655. type: string
  2656. namespace:
  2657. description: |-
  2658. Namespace of the resource being referred to.
  2659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2660. maxLength: 63
  2661. minLength: 1
  2662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2663. type: string
  2664. required:
  2665. - name
  2666. type: object
  2667. type: object
  2668. caBundle:
  2669. description: |-
  2670. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2671. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2672. are used to validate the TLS connection.
  2673. format: byte
  2674. type: string
  2675. caProvider:
  2676. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2677. properties:
  2678. key:
  2679. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2680. maxLength: 253
  2681. minLength: 1
  2682. pattern: ^[-._a-zA-Z0-9]+$
  2683. type: string
  2684. name:
  2685. description: The name of the object located at the provider type.
  2686. maxLength: 253
  2687. minLength: 1
  2688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2689. type: string
  2690. namespace:
  2691. description: |-
  2692. The namespace the Provider type is in.
  2693. Can only be defined when used in a ClusterSecretStore.
  2694. maxLength: 63
  2695. minLength: 1
  2696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2697. type: string
  2698. type:
  2699. description: The type of provider to use such as "Secret", or "ConfigMap".
  2700. enum:
  2701. - Secret
  2702. - ConfigMap
  2703. type: string
  2704. required:
  2705. - name
  2706. - type
  2707. type: object
  2708. ignoreCache:
  2709. description: |-
  2710. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2711. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2712. type: boolean
  2713. required:
  2714. - akeylessGWApiURL
  2715. - authSecretRef
  2716. type: object
  2717. aws:
  2718. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2719. properties:
  2720. additionalRoles:
  2721. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2722. items:
  2723. type: string
  2724. type: array
  2725. auth:
  2726. description: |-
  2727. Auth defines the information necessary to authenticate against AWS
  2728. if not set aws sdk will infer credentials from your environment
  2729. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2730. properties:
  2731. jwt:
  2732. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2733. properties:
  2734. serviceAccountRef:
  2735. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2736. properties:
  2737. audiences:
  2738. description: |-
  2739. Audience specifies the `aud` claim for the service account token
  2740. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2741. then this audiences will be appended to the list
  2742. items:
  2743. type: string
  2744. type: array
  2745. name:
  2746. description: The name of the ServiceAccount resource being referred to.
  2747. maxLength: 253
  2748. minLength: 1
  2749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2750. type: string
  2751. namespace:
  2752. description: |-
  2753. Namespace of the resource being referred to.
  2754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2755. maxLength: 63
  2756. minLength: 1
  2757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2758. type: string
  2759. required:
  2760. - name
  2761. type: object
  2762. type: object
  2763. secretRef:
  2764. description: |-
  2765. AWSAuthSecretRef holds secret references for AWS credentials
  2766. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2767. properties:
  2768. accessKeyIDSecretRef:
  2769. description: The AccessKeyID is used for authentication
  2770. properties:
  2771. key:
  2772. description: |-
  2773. A key in the referenced Secret.
  2774. Some instances of this field may be defaulted, in others it may be required.
  2775. maxLength: 253
  2776. minLength: 1
  2777. pattern: ^[-._a-zA-Z0-9]+$
  2778. type: string
  2779. name:
  2780. description: The name of the Secret resource being referred to.
  2781. maxLength: 253
  2782. minLength: 1
  2783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2784. type: string
  2785. namespace:
  2786. description: |-
  2787. The namespace of the Secret resource being referred to.
  2788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2789. maxLength: 63
  2790. minLength: 1
  2791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2792. type: string
  2793. type: object
  2794. secretAccessKeySecretRef:
  2795. description: The SecretAccessKey is used for authentication
  2796. properties:
  2797. key:
  2798. description: |-
  2799. A key in the referenced Secret.
  2800. Some instances of this field may be defaulted, in others it may be required.
  2801. maxLength: 253
  2802. minLength: 1
  2803. pattern: ^[-._a-zA-Z0-9]+$
  2804. type: string
  2805. name:
  2806. description: The name of the Secret resource being referred to.
  2807. maxLength: 253
  2808. minLength: 1
  2809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2810. type: string
  2811. namespace:
  2812. description: |-
  2813. The namespace of the Secret resource being referred to.
  2814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2815. maxLength: 63
  2816. minLength: 1
  2817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2818. type: string
  2819. type: object
  2820. sessionTokenSecretRef:
  2821. description: |-
  2822. The SessionToken used for authentication
  2823. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2824. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2825. properties:
  2826. key:
  2827. description: |-
  2828. A key in the referenced Secret.
  2829. Some instances of this field may be defaulted, in others it may be required.
  2830. maxLength: 253
  2831. minLength: 1
  2832. pattern: ^[-._a-zA-Z0-9]+$
  2833. type: string
  2834. name:
  2835. description: The name of the Secret resource being referred to.
  2836. maxLength: 253
  2837. minLength: 1
  2838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2839. type: string
  2840. namespace:
  2841. description: |-
  2842. The namespace of the Secret resource being referred to.
  2843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2844. maxLength: 63
  2845. minLength: 1
  2846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2847. type: string
  2848. type: object
  2849. type: object
  2850. type: object
  2851. customSessionTags:
  2852. additionalProperties:
  2853. type: string
  2854. description: |-
  2855. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2856. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2857. type: object
  2858. x-kubernetes-validations:
  2859. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2860. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2861. externalID:
  2862. description: AWS External ID set on assumed IAM roles
  2863. type: string
  2864. prefix:
  2865. description: Prefix adds a prefix to all retrieved values.
  2866. type: string
  2867. region:
  2868. description: AWS Region to be used for the provider
  2869. type: string
  2870. role:
  2871. description: Role is a Role ARN which the provider will assume
  2872. type: string
  2873. secretsManager:
  2874. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2875. properties:
  2876. forceDeleteWithoutRecovery:
  2877. description: |-
  2878. Specifies whether to delete the secret without any recovery window. You
  2879. can't use both this parameter and RecoveryWindowInDays in the same call.
  2880. If you don't use either, then by default Secrets Manager uses a 30 day
  2881. recovery window.
  2882. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2883. type: boolean
  2884. recoveryWindowInDays:
  2885. description: |-
  2886. The number of days from 7 to 30 that Secrets Manager waits before
  2887. permanently deleting the secret. You can't use both this parameter and
  2888. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2889. then by default Secrets Manager uses a 30-day recovery window.
  2890. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2891. format: int64
  2892. type: integer
  2893. type: object
  2894. service:
  2895. description: Service defines which service should be used to fetch the secrets
  2896. enum:
  2897. - SecretsManager
  2898. - ParameterStore
  2899. - CertificateManager
  2900. type: string
  2901. sessionTags:
  2902. description: AWS STS assume role session tags
  2903. items:
  2904. description: |-
  2905. Tag is a key-value pair that can be attached to an AWS resource.
  2906. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2907. properties:
  2908. key:
  2909. type: string
  2910. value:
  2911. type: string
  2912. required:
  2913. - key
  2914. - value
  2915. type: object
  2916. type: array
  2917. sessionTagsPolicy:
  2918. default: None
  2919. description: |-
  2920. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2921. None (default): no tags are added.
  2922. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2923. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2924. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2925. enum:
  2926. - None
  2927. - Simple
  2928. - Custom
  2929. type: string
  2930. transitiveTagKeys:
  2931. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2932. items:
  2933. type: string
  2934. type: array
  2935. required:
  2936. - region
  2937. - service
  2938. type: object
  2939. azurekv:
  2940. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2941. properties:
  2942. authSecretRef:
  2943. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2944. properties:
  2945. clientCertificate:
  2946. description: The Azure ClientCertificate of the service principle used for authentication.
  2947. properties:
  2948. key:
  2949. description: |-
  2950. A key in the referenced Secret.
  2951. Some instances of this field may be defaulted, in others it may be required.
  2952. maxLength: 253
  2953. minLength: 1
  2954. pattern: ^[-._a-zA-Z0-9]+$
  2955. type: string
  2956. name:
  2957. description: The name of the Secret resource being referred to.
  2958. maxLength: 253
  2959. minLength: 1
  2960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2961. type: string
  2962. namespace:
  2963. description: |-
  2964. The namespace of the Secret resource being referred to.
  2965. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2966. maxLength: 63
  2967. minLength: 1
  2968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2969. type: string
  2970. type: object
  2971. clientId:
  2972. description: The Azure clientId of the service principle or managed identity used for authentication.
  2973. properties:
  2974. key:
  2975. description: |-
  2976. A key in the referenced Secret.
  2977. Some instances of this field may be defaulted, in others it may be required.
  2978. maxLength: 253
  2979. minLength: 1
  2980. pattern: ^[-._a-zA-Z0-9]+$
  2981. type: string
  2982. name:
  2983. description: The name of the Secret resource being referred to.
  2984. maxLength: 253
  2985. minLength: 1
  2986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2987. type: string
  2988. namespace:
  2989. description: |-
  2990. The namespace of the Secret resource being referred to.
  2991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2992. maxLength: 63
  2993. minLength: 1
  2994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2995. type: string
  2996. type: object
  2997. clientSecret:
  2998. description: The Azure ClientSecret of the service principle used for authentication.
  2999. properties:
  3000. key:
  3001. description: |-
  3002. A key in the referenced Secret.
  3003. Some instances of this field may be defaulted, in others it may be required.
  3004. maxLength: 253
  3005. minLength: 1
  3006. pattern: ^[-._a-zA-Z0-9]+$
  3007. type: string
  3008. name:
  3009. description: The name of the Secret resource being referred to.
  3010. maxLength: 253
  3011. minLength: 1
  3012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3013. type: string
  3014. namespace:
  3015. description: |-
  3016. The namespace of the Secret resource being referred to.
  3017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3018. maxLength: 63
  3019. minLength: 1
  3020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3021. type: string
  3022. type: object
  3023. tenantId:
  3024. description: The Azure tenantId of the managed identity used for authentication.
  3025. properties:
  3026. key:
  3027. description: |-
  3028. A key in the referenced Secret.
  3029. Some instances of this field may be defaulted, in others it may be required.
  3030. maxLength: 253
  3031. minLength: 1
  3032. pattern: ^[-._a-zA-Z0-9]+$
  3033. type: string
  3034. name:
  3035. description: The name of the Secret resource being referred to.
  3036. maxLength: 253
  3037. minLength: 1
  3038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3039. type: string
  3040. namespace:
  3041. description: |-
  3042. The namespace of the Secret resource being referred to.
  3043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3044. maxLength: 63
  3045. minLength: 1
  3046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3047. type: string
  3048. type: object
  3049. type: object
  3050. authType:
  3051. default: ServicePrincipal
  3052. description: |-
  3053. Auth type defines how to authenticate to the keyvault service.
  3054. Valid values are:
  3055. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3056. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3057. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3058. enum:
  3059. - ServicePrincipal
  3060. - ManagedIdentity
  3061. - WorkloadIdentity
  3062. type: string
  3063. customCloudConfig:
  3064. description: |-
  3065. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3066. Required when EnvironmentType is AzureStackCloud.
  3067. Optional for other environment types - useful for Azure China when using Workload Identity
  3068. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3069. standard China Cloud endpoint (login.chinacloudapi.cn).
  3070. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3071. configuration is not supported with the legacy go-autorest SDK.
  3072. properties:
  3073. activeDirectoryEndpoint:
  3074. description: |-
  3075. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3076. Required when using custom cloud configuration
  3077. type: string
  3078. keyVaultDNSSuffix:
  3079. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3080. type: string
  3081. keyVaultEndpoint:
  3082. description: KeyVaultEndpoint is the Key Vault service endpoint
  3083. type: string
  3084. resourceManagerEndpoint:
  3085. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3086. type: string
  3087. required:
  3088. - activeDirectoryEndpoint
  3089. type: object
  3090. environmentType:
  3091. default: PublicCloud
  3092. description: |-
  3093. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3094. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3095. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3096. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3097. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3098. enum:
  3099. - PublicCloud
  3100. - USGovernmentCloud
  3101. - ChinaCloud
  3102. - GermanCloud
  3103. - AzureStackCloud
  3104. type: string
  3105. identityId:
  3106. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3107. type: string
  3108. serviceAccountRef:
  3109. description: |-
  3110. ServiceAccountRef specified the service account
  3111. that should be used when authenticating with WorkloadIdentity.
  3112. properties:
  3113. audiences:
  3114. description: |-
  3115. Audience specifies the `aud` claim for the service account token
  3116. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3117. then this audiences will be appended to the list
  3118. items:
  3119. type: string
  3120. type: array
  3121. name:
  3122. description: The name of the ServiceAccount resource being referred to.
  3123. maxLength: 253
  3124. minLength: 1
  3125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3126. type: string
  3127. namespace:
  3128. description: |-
  3129. Namespace of the resource being referred to.
  3130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3131. maxLength: 63
  3132. minLength: 1
  3133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3134. type: string
  3135. required:
  3136. - name
  3137. type: object
  3138. tenantId:
  3139. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3140. type: string
  3141. useAzureSDK:
  3142. default: false
  3143. description: |-
  3144. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3145. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3146. type: boolean
  3147. vaultUrl:
  3148. description: Vault Url from which the secrets to be fetched from.
  3149. type: string
  3150. required:
  3151. - vaultUrl
  3152. type: object
  3153. barbican:
  3154. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3155. properties:
  3156. auth:
  3157. description: BarbicanAuth contains the authentication information for Barbican.
  3158. properties:
  3159. password:
  3160. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3161. properties:
  3162. secretRef:
  3163. description: |-
  3164. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3165. In some instances, `key` is a required field.
  3166. properties:
  3167. key:
  3168. description: |-
  3169. A key in the referenced Secret.
  3170. Some instances of this field may be defaulted, in others it may be required.
  3171. maxLength: 253
  3172. minLength: 1
  3173. pattern: ^[-._a-zA-Z0-9]+$
  3174. type: string
  3175. name:
  3176. description: The name of the Secret resource being referred to.
  3177. maxLength: 253
  3178. minLength: 1
  3179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3180. type: string
  3181. namespace:
  3182. description: |-
  3183. The namespace of the Secret resource being referred to.
  3184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3185. maxLength: 63
  3186. minLength: 1
  3187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3188. type: string
  3189. type: object
  3190. required:
  3191. - secretRef
  3192. type: object
  3193. username:
  3194. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3195. maxProperties: 1
  3196. minProperties: 1
  3197. properties:
  3198. secretRef:
  3199. description: |-
  3200. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3201. In some instances, `key` is a required field.
  3202. properties:
  3203. key:
  3204. description: |-
  3205. A key in the referenced Secret.
  3206. Some instances of this field may be defaulted, in others it may be required.
  3207. maxLength: 253
  3208. minLength: 1
  3209. pattern: ^[-._a-zA-Z0-9]+$
  3210. type: string
  3211. name:
  3212. description: The name of the Secret resource being referred to.
  3213. maxLength: 253
  3214. minLength: 1
  3215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3216. type: string
  3217. namespace:
  3218. description: |-
  3219. The namespace of the Secret resource being referred to.
  3220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3221. maxLength: 63
  3222. minLength: 1
  3223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3224. type: string
  3225. type: object
  3226. value:
  3227. type: string
  3228. type: object
  3229. required:
  3230. - password
  3231. - username
  3232. type: object
  3233. authURL:
  3234. type: string
  3235. domainName:
  3236. type: string
  3237. region:
  3238. type: string
  3239. tenantName:
  3240. type: string
  3241. required:
  3242. - auth
  3243. type: object
  3244. beyondtrust:
  3245. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3246. properties:
  3247. auth:
  3248. description: Auth configures how the operator authenticates with Beyondtrust.
  3249. properties:
  3250. apiKey:
  3251. description: APIKey If not provided then ClientID/ClientSecret become required.
  3252. properties:
  3253. secretRef:
  3254. description: SecretRef references a key in a secret that will be used as value.
  3255. properties:
  3256. key:
  3257. description: |-
  3258. A key in the referenced Secret.
  3259. Some instances of this field may be defaulted, in others it may be required.
  3260. maxLength: 253
  3261. minLength: 1
  3262. pattern: ^[-._a-zA-Z0-9]+$
  3263. type: string
  3264. name:
  3265. description: The name of the Secret resource being referred to.
  3266. maxLength: 253
  3267. minLength: 1
  3268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3269. type: string
  3270. namespace:
  3271. description: |-
  3272. The namespace of the Secret resource being referred to.
  3273. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3274. maxLength: 63
  3275. minLength: 1
  3276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3277. type: string
  3278. type: object
  3279. value:
  3280. description: Value can be specified directly to set a value without using a secret.
  3281. type: string
  3282. type: object
  3283. certificate:
  3284. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3285. properties:
  3286. secretRef:
  3287. description: SecretRef references a key in a secret that will be used as value.
  3288. properties:
  3289. key:
  3290. description: |-
  3291. A key in the referenced Secret.
  3292. Some instances of this field may be defaulted, in others it may be required.
  3293. maxLength: 253
  3294. minLength: 1
  3295. pattern: ^[-._a-zA-Z0-9]+$
  3296. type: string
  3297. name:
  3298. description: The name of the Secret resource being referred to.
  3299. maxLength: 253
  3300. minLength: 1
  3301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3302. type: string
  3303. namespace:
  3304. description: |-
  3305. The namespace of the Secret resource being referred to.
  3306. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3307. maxLength: 63
  3308. minLength: 1
  3309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3310. type: string
  3311. type: object
  3312. value:
  3313. description: Value can be specified directly to set a value without using a secret.
  3314. type: string
  3315. type: object
  3316. certificateKey:
  3317. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3318. properties:
  3319. secretRef:
  3320. description: SecretRef references a key in a secret that will be used as value.
  3321. properties:
  3322. key:
  3323. description: |-
  3324. A key in the referenced Secret.
  3325. Some instances of this field may be defaulted, in others it may be required.
  3326. maxLength: 253
  3327. minLength: 1
  3328. pattern: ^[-._a-zA-Z0-9]+$
  3329. type: string
  3330. name:
  3331. description: The name of the Secret resource being referred to.
  3332. maxLength: 253
  3333. minLength: 1
  3334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3335. type: string
  3336. namespace:
  3337. description: |-
  3338. The namespace of the Secret resource being referred to.
  3339. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3340. maxLength: 63
  3341. minLength: 1
  3342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3343. type: string
  3344. type: object
  3345. value:
  3346. description: Value can be specified directly to set a value without using a secret.
  3347. type: string
  3348. type: object
  3349. clientId:
  3350. description: ClientID is the API OAuth Client ID.
  3351. properties:
  3352. secretRef:
  3353. description: SecretRef references a key in a secret that will be used as value.
  3354. properties:
  3355. key:
  3356. description: |-
  3357. A key in the referenced Secret.
  3358. Some instances of this field may be defaulted, in others it may be required.
  3359. maxLength: 253
  3360. minLength: 1
  3361. pattern: ^[-._a-zA-Z0-9]+$
  3362. type: string
  3363. name:
  3364. description: The name of the Secret resource being referred to.
  3365. maxLength: 253
  3366. minLength: 1
  3367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3368. type: string
  3369. namespace:
  3370. description: |-
  3371. The namespace of the Secret resource being referred to.
  3372. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3373. maxLength: 63
  3374. minLength: 1
  3375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3376. type: string
  3377. type: object
  3378. value:
  3379. description: Value can be specified directly to set a value without using a secret.
  3380. type: string
  3381. type: object
  3382. clientSecret:
  3383. description: ClientSecret is the API OAuth Client Secret.
  3384. properties:
  3385. secretRef:
  3386. description: SecretRef references a key in a secret that will be used as value.
  3387. properties:
  3388. key:
  3389. description: |-
  3390. A key in the referenced Secret.
  3391. Some instances of this field may be defaulted, in others it may be required.
  3392. maxLength: 253
  3393. minLength: 1
  3394. pattern: ^[-._a-zA-Z0-9]+$
  3395. type: string
  3396. name:
  3397. description: The name of the Secret resource being referred to.
  3398. maxLength: 253
  3399. minLength: 1
  3400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3401. type: string
  3402. namespace:
  3403. description: |-
  3404. The namespace of the Secret resource being referred to.
  3405. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3406. maxLength: 63
  3407. minLength: 1
  3408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3409. type: string
  3410. type: object
  3411. value:
  3412. description: Value can be specified directly to set a value without using a secret.
  3413. type: string
  3414. type: object
  3415. type: object
  3416. server:
  3417. description: Auth configures how API server works.
  3418. properties:
  3419. apiUrl:
  3420. type: string
  3421. apiVersion:
  3422. type: string
  3423. clientTimeOutSeconds:
  3424. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3425. type: integer
  3426. decrypt:
  3427. default: true
  3428. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3429. type: boolean
  3430. retrievalType:
  3431. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3432. type: string
  3433. separator:
  3434. description: A character that separates the folder names.
  3435. type: string
  3436. verifyCA:
  3437. type: boolean
  3438. required:
  3439. - apiUrl
  3440. - verifyCA
  3441. type: object
  3442. required:
  3443. - auth
  3444. - server
  3445. type: object
  3446. beyondtrustworkloadcredentials:
  3447. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3448. properties:
  3449. auth:
  3450. description: |-
  3451. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3452. Currently supports API key authentication via Kubernetes secret reference.
  3453. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3454. properties:
  3455. apikey:
  3456. description: |-
  3457. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3458. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3459. properties:
  3460. token:
  3461. description: |-
  3462. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3463. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3464. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3465. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3466. properties:
  3467. key:
  3468. description: |-
  3469. A key in the referenced Secret.
  3470. Some instances of this field may be defaulted, in others it may be required.
  3471. maxLength: 253
  3472. minLength: 1
  3473. pattern: ^[-._a-zA-Z0-9]+$
  3474. type: string
  3475. name:
  3476. description: The name of the Secret resource being referred to.
  3477. maxLength: 253
  3478. minLength: 1
  3479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3480. type: string
  3481. namespace:
  3482. description: |-
  3483. The namespace of the Secret resource being referred to.
  3484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3485. maxLength: 63
  3486. minLength: 1
  3487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3488. type: string
  3489. type: object
  3490. required:
  3491. - token
  3492. type: object
  3493. required:
  3494. - apikey
  3495. type: object
  3496. caBundle:
  3497. description: |-
  3498. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3499. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3500. If not set, the system's trusted root certificates are used.
  3501. format: byte
  3502. type: string
  3503. caProvider:
  3504. description: |-
  3505. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3506. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3507. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3508. properties:
  3509. key:
  3510. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3511. maxLength: 253
  3512. minLength: 1
  3513. pattern: ^[-._a-zA-Z0-9]+$
  3514. type: string
  3515. name:
  3516. description: The name of the object located at the provider type.
  3517. maxLength: 253
  3518. minLength: 1
  3519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3520. type: string
  3521. namespace:
  3522. description: |-
  3523. The namespace the Provider type is in.
  3524. Can only be defined when used in a ClusterSecretStore.
  3525. maxLength: 63
  3526. minLength: 1
  3527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3528. type: string
  3529. type:
  3530. description: The type of provider to use such as "Secret", or "ConfigMap".
  3531. enum:
  3532. - Secret
  3533. - ConfigMap
  3534. type: string
  3535. required:
  3536. - name
  3537. - type
  3538. type: object
  3539. folderPath:
  3540. description: |-
  3541. FolderPath specifies the default folder path for secret retrieval.
  3542. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3543. Example: "production/database" or "dev/api-keys"
  3544. Leave empty to retrieve secrets from the root folder.
  3545. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3546. type: string
  3547. server:
  3548. description: |-
  3549. Server configures the BeyondTrust Workload Credentials server connection details.
  3550. Includes the API URL and Site ID for your BeyondTrust instance.
  3551. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3552. properties:
  3553. apiUrl:
  3554. description: |-
  3555. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3556. This should be the full URL to your BeyondTrust instance.
  3557. Example: https://api.beyondtrust.io/siie
  3558. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3559. type: string
  3560. siteId:
  3561. description: |-
  3562. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3563. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3564. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3565. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3566. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3567. type: string
  3568. required:
  3569. - apiUrl
  3570. - siteId
  3571. type: object
  3572. required:
  3573. - auth
  3574. - server
  3575. type: object
  3576. bitwardensecretsmanager:
  3577. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3578. properties:
  3579. apiURL:
  3580. type: string
  3581. auth:
  3582. description: |-
  3583. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3584. Make sure that the token being used has permissions on the given secret.
  3585. properties:
  3586. secretRef:
  3587. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3588. properties:
  3589. credentials:
  3590. description: AccessToken used for the bitwarden instance.
  3591. properties:
  3592. key:
  3593. description: |-
  3594. A key in the referenced Secret.
  3595. Some instances of this field may be defaulted, in others it may be required.
  3596. maxLength: 253
  3597. minLength: 1
  3598. pattern: ^[-._a-zA-Z0-9]+$
  3599. type: string
  3600. name:
  3601. description: The name of the Secret resource being referred to.
  3602. maxLength: 253
  3603. minLength: 1
  3604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3605. type: string
  3606. namespace:
  3607. description: |-
  3608. The namespace of the Secret resource being referred to.
  3609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3610. maxLength: 63
  3611. minLength: 1
  3612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3613. type: string
  3614. type: object
  3615. required:
  3616. - credentials
  3617. type: object
  3618. required:
  3619. - secretRef
  3620. type: object
  3621. bitwardenServerSDKURL:
  3622. type: string
  3623. caBundle:
  3624. description: |-
  3625. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3626. can be performed.
  3627. type: string
  3628. caProvider:
  3629. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3630. properties:
  3631. key:
  3632. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3633. maxLength: 253
  3634. minLength: 1
  3635. pattern: ^[-._a-zA-Z0-9]+$
  3636. type: string
  3637. name:
  3638. description: The name of the object located at the provider type.
  3639. maxLength: 253
  3640. minLength: 1
  3641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3642. type: string
  3643. namespace:
  3644. description: |-
  3645. The namespace the Provider type is in.
  3646. Can only be defined when used in a ClusterSecretStore.
  3647. maxLength: 63
  3648. minLength: 1
  3649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3650. type: string
  3651. type:
  3652. description: The type of provider to use such as "Secret", or "ConfigMap".
  3653. enum:
  3654. - Secret
  3655. - ConfigMap
  3656. type: string
  3657. required:
  3658. - name
  3659. - type
  3660. type: object
  3661. identityURL:
  3662. type: string
  3663. organizationID:
  3664. description: OrganizationID determines which organization this secret store manages.
  3665. type: string
  3666. projectID:
  3667. description: ProjectID determines which project this secret store manages.
  3668. type: string
  3669. required:
  3670. - auth
  3671. - organizationID
  3672. - projectID
  3673. type: object
  3674. chef:
  3675. description: Chef configures this store to sync secrets with chef server
  3676. properties:
  3677. auth:
  3678. description: Auth defines the information necessary to authenticate against chef Server
  3679. properties:
  3680. secretRef:
  3681. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3682. properties:
  3683. privateKeySecretRef:
  3684. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3685. properties:
  3686. key:
  3687. description: |-
  3688. A key in the referenced Secret.
  3689. Some instances of this field may be defaulted, in others it may be required.
  3690. maxLength: 253
  3691. minLength: 1
  3692. pattern: ^[-._a-zA-Z0-9]+$
  3693. type: string
  3694. name:
  3695. description: The name of the Secret resource being referred to.
  3696. maxLength: 253
  3697. minLength: 1
  3698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3699. type: string
  3700. namespace:
  3701. description: |-
  3702. The namespace of the Secret resource being referred to.
  3703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3704. maxLength: 63
  3705. minLength: 1
  3706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3707. type: string
  3708. type: object
  3709. required:
  3710. - privateKeySecretRef
  3711. type: object
  3712. required:
  3713. - secretRef
  3714. type: object
  3715. serverUrl:
  3716. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3717. type: string
  3718. username:
  3719. description: UserName should be the user ID on the chef server
  3720. type: string
  3721. required:
  3722. - auth
  3723. - serverUrl
  3724. - username
  3725. type: object
  3726. cloudrusm:
  3727. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3728. properties:
  3729. auth:
  3730. description: CSMAuth contains a secretRef for credentials.
  3731. properties:
  3732. secretRef:
  3733. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3734. properties:
  3735. accessKeyIDSecretRef:
  3736. description: The AccessKeyID is used for authentication
  3737. properties:
  3738. key:
  3739. description: |-
  3740. A key in the referenced Secret.
  3741. Some instances of this field may be defaulted, in others it may be required.
  3742. maxLength: 253
  3743. minLength: 1
  3744. pattern: ^[-._a-zA-Z0-9]+$
  3745. type: string
  3746. name:
  3747. description: The name of the Secret resource being referred to.
  3748. maxLength: 253
  3749. minLength: 1
  3750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3751. type: string
  3752. namespace:
  3753. description: |-
  3754. The namespace of the Secret resource being referred to.
  3755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3756. maxLength: 63
  3757. minLength: 1
  3758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3759. type: string
  3760. type: object
  3761. accessKeySecretSecretRef:
  3762. description: The AccessKeySecret is used for authentication
  3763. properties:
  3764. key:
  3765. description: |-
  3766. A key in the referenced Secret.
  3767. Some instances of this field may be defaulted, in others it may be required.
  3768. maxLength: 253
  3769. minLength: 1
  3770. pattern: ^[-._a-zA-Z0-9]+$
  3771. type: string
  3772. name:
  3773. description: The name of the Secret resource being referred to.
  3774. maxLength: 253
  3775. minLength: 1
  3776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3777. type: string
  3778. namespace:
  3779. description: |-
  3780. The namespace of the Secret resource being referred to.
  3781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3782. maxLength: 63
  3783. minLength: 1
  3784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3785. type: string
  3786. type: object
  3787. required:
  3788. - accessKeyIDSecretRef
  3789. - accessKeySecretSecretRef
  3790. type: object
  3791. type: object
  3792. projectID:
  3793. description: ProjectID is the project, which the secrets are stored in.
  3794. type: string
  3795. required:
  3796. - auth
  3797. type: object
  3798. conjur:
  3799. description: Conjur configures this store to sync secrets using conjur provider
  3800. properties:
  3801. auth:
  3802. description: Defines authentication settings for connecting to Conjur.
  3803. maxProperties: 1
  3804. minProperties: 1
  3805. properties:
  3806. apikey:
  3807. description: Authenticates with Conjur using an API key.
  3808. properties:
  3809. account:
  3810. description: Account is the Conjur organization account name.
  3811. type: string
  3812. apiKeyRef:
  3813. description: |-
  3814. A reference to a specific 'key' containing the Conjur API key
  3815. within a Secret resource. In some instances, `key` is a required field.
  3816. properties:
  3817. key:
  3818. description: |-
  3819. A key in the referenced Secret.
  3820. Some instances of this field may be defaulted, in others it may be required.
  3821. maxLength: 253
  3822. minLength: 1
  3823. pattern: ^[-._a-zA-Z0-9]+$
  3824. type: string
  3825. name:
  3826. description: The name of the Secret resource being referred to.
  3827. maxLength: 253
  3828. minLength: 1
  3829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3830. type: string
  3831. namespace:
  3832. description: |-
  3833. The namespace of the Secret resource being referred to.
  3834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3835. maxLength: 63
  3836. minLength: 1
  3837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3838. type: string
  3839. type: object
  3840. userRef:
  3841. description: |-
  3842. A reference to a specific 'key' containing the Conjur username
  3843. within a Secret resource. In some instances, `key` is a required field.
  3844. properties:
  3845. key:
  3846. description: |-
  3847. A key in the referenced Secret.
  3848. Some instances of this field may be defaulted, in others it may be required.
  3849. maxLength: 253
  3850. minLength: 1
  3851. pattern: ^[-._a-zA-Z0-9]+$
  3852. type: string
  3853. name:
  3854. description: The name of the Secret resource being referred to.
  3855. maxLength: 253
  3856. minLength: 1
  3857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3858. type: string
  3859. namespace:
  3860. description: |-
  3861. The namespace of the Secret resource being referred to.
  3862. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3863. maxLength: 63
  3864. minLength: 1
  3865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3866. type: string
  3867. type: object
  3868. required:
  3869. - account
  3870. - apiKeyRef
  3871. - userRef
  3872. type: object
  3873. cert:
  3874. description: Cert enables certificate-based authentication using a client certificate and key.
  3875. properties:
  3876. account:
  3877. description: Account is the Conjur organization account name.
  3878. type: string
  3879. clientCertRef:
  3880. description: |-
  3881. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3882. within a Secret resource. The certificate must be PEM-encoded.
  3883. properties:
  3884. key:
  3885. description: |-
  3886. A key in the referenced Secret.
  3887. Some instances of this field may be defaulted, in others it may be required.
  3888. maxLength: 253
  3889. minLength: 1
  3890. pattern: ^[-._a-zA-Z0-9]+$
  3891. type: string
  3892. name:
  3893. description: The name of the Secret resource being referred to.
  3894. maxLength: 253
  3895. minLength: 1
  3896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3897. type: string
  3898. namespace:
  3899. description: |-
  3900. The namespace of the Secret resource being referred to.
  3901. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3902. maxLength: 63
  3903. minLength: 1
  3904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3905. type: string
  3906. type: object
  3907. clientKeyRef:
  3908. description: |-
  3909. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3910. within a Secret resource. The key must be PEM-encoded.
  3911. properties:
  3912. key:
  3913. description: |-
  3914. A key in the referenced Secret.
  3915. Some instances of this field may be defaulted, in others it may be required.
  3916. maxLength: 253
  3917. minLength: 1
  3918. pattern: ^[-._a-zA-Z0-9]+$
  3919. type: string
  3920. name:
  3921. description: The name of the Secret resource being referred to.
  3922. maxLength: 253
  3923. minLength: 1
  3924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3925. type: string
  3926. namespace:
  3927. description: |-
  3928. The namespace of the Secret resource being referred to.
  3929. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3930. maxLength: 63
  3931. minLength: 1
  3932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3933. type: string
  3934. type: object
  3935. hostId:
  3936. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3937. type: string
  3938. serviceID:
  3939. description: The conjur authn cert webservice id
  3940. type: string
  3941. required:
  3942. - account
  3943. - clientCertRef
  3944. - clientKeyRef
  3945. - serviceID
  3946. type: object
  3947. jwt:
  3948. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3949. properties:
  3950. account:
  3951. description: Account is the Conjur organization account name.
  3952. type: string
  3953. hostId:
  3954. description: |-
  3955. Optional HostID for JWT authentication. This may be used depending
  3956. on how the Conjur JWT authenticator policy is configured.
  3957. type: string
  3958. secretRef:
  3959. description: |-
  3960. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3961. authenticate with Conjur using the JWT authentication method.
  3962. properties:
  3963. key:
  3964. description: |-
  3965. A key in the referenced Secret.
  3966. Some instances of this field may be defaulted, in others it may be required.
  3967. maxLength: 253
  3968. minLength: 1
  3969. pattern: ^[-._a-zA-Z0-9]+$
  3970. type: string
  3971. name:
  3972. description: The name of the Secret resource being referred to.
  3973. maxLength: 253
  3974. minLength: 1
  3975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3976. type: string
  3977. namespace:
  3978. description: |-
  3979. The namespace of the Secret resource being referred to.
  3980. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3981. maxLength: 63
  3982. minLength: 1
  3983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3984. type: string
  3985. type: object
  3986. serviceAccountRef:
  3987. description: |-
  3988. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3989. a token for with the `TokenRequest` API.
  3990. properties:
  3991. audiences:
  3992. description: |-
  3993. Audience specifies the `aud` claim for the service account token
  3994. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3995. then this audiences will be appended to the list
  3996. items:
  3997. type: string
  3998. type: array
  3999. name:
  4000. description: The name of the ServiceAccount resource being referred to.
  4001. maxLength: 253
  4002. minLength: 1
  4003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4004. type: string
  4005. namespace:
  4006. description: |-
  4007. Namespace of the resource being referred to.
  4008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4009. maxLength: 63
  4010. minLength: 1
  4011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4012. type: string
  4013. required:
  4014. - name
  4015. type: object
  4016. serviceID:
  4017. description: The conjur authn jwt webservice id
  4018. type: string
  4019. required:
  4020. - account
  4021. - serviceID
  4022. type: object
  4023. type: object
  4024. caBundle:
  4025. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4026. type: string
  4027. caProvider:
  4028. description: |-
  4029. Used to provide custom certificate authority (CA) certificates
  4030. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4031. that contains a PEM-encoded certificate.
  4032. properties:
  4033. key:
  4034. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4035. maxLength: 253
  4036. minLength: 1
  4037. pattern: ^[-._a-zA-Z0-9]+$
  4038. type: string
  4039. name:
  4040. description: The name of the object located at the provider type.
  4041. maxLength: 253
  4042. minLength: 1
  4043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4044. type: string
  4045. namespace:
  4046. description: |-
  4047. The namespace the Provider type is in.
  4048. Can only be defined when used in a ClusterSecretStore.
  4049. maxLength: 63
  4050. minLength: 1
  4051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4052. type: string
  4053. type:
  4054. description: The type of provider to use such as "Secret", or "ConfigMap".
  4055. enum:
  4056. - Secret
  4057. - ConfigMap
  4058. type: string
  4059. required:
  4060. - name
  4061. - type
  4062. type: object
  4063. url:
  4064. description: URL is the endpoint of the Conjur instance.
  4065. type: string
  4066. required:
  4067. - auth
  4068. - url
  4069. type: object
  4070. crd:
  4071. description: |-
  4072. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4073. including both custom resources (CRDs) and core API resources. Resources are
  4074. selected by API group, version and kind, where group can be "" (empty string)
  4075. for core resources such as ConfigMap. Reading the core v1 Secret is
  4076. intentionally blocked — use the Kubernetes provider for that.
  4077. properties:
  4078. auth:
  4079. description: |-
  4080. Auth configures authentication to the Kubernetes API, same as the
  4081. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4082. maxProperties: 1
  4083. minProperties: 1
  4084. properties:
  4085. cert:
  4086. description: has both clientCert and clientKey as secretKeySelector
  4087. properties:
  4088. clientCert:
  4089. description: |-
  4090. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4091. In some instances, `key` is a required field.
  4092. properties:
  4093. key:
  4094. description: |-
  4095. A key in the referenced Secret.
  4096. Some instances of this field may be defaulted, in others it may be required.
  4097. maxLength: 253
  4098. minLength: 1
  4099. pattern: ^[-._a-zA-Z0-9]+$
  4100. type: string
  4101. name:
  4102. description: The name of the Secret resource being referred to.
  4103. maxLength: 253
  4104. minLength: 1
  4105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4106. type: string
  4107. namespace:
  4108. description: |-
  4109. The namespace of the Secret resource being referred to.
  4110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4111. maxLength: 63
  4112. minLength: 1
  4113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4114. type: string
  4115. type: object
  4116. clientKey:
  4117. description: |-
  4118. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4119. In some instances, `key` is a required field.
  4120. properties:
  4121. key:
  4122. description: |-
  4123. A key in the referenced Secret.
  4124. Some instances of this field may be defaulted, in others it may be required.
  4125. maxLength: 253
  4126. minLength: 1
  4127. pattern: ^[-._a-zA-Z0-9]+$
  4128. type: string
  4129. name:
  4130. description: The name of the Secret resource being referred to.
  4131. maxLength: 253
  4132. minLength: 1
  4133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4134. type: string
  4135. namespace:
  4136. description: |-
  4137. The namespace of the Secret resource being referred to.
  4138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4139. maxLength: 63
  4140. minLength: 1
  4141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4142. type: string
  4143. type: object
  4144. required:
  4145. - clientCert
  4146. - clientKey
  4147. type: object
  4148. serviceAccount:
  4149. description: points to a service account that should be used for authentication
  4150. properties:
  4151. audiences:
  4152. description: |-
  4153. Audience specifies the `aud` claim for the service account token
  4154. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4155. then this audiences will be appended to the list
  4156. items:
  4157. type: string
  4158. type: array
  4159. name:
  4160. description: The name of the ServiceAccount resource being referred to.
  4161. maxLength: 253
  4162. minLength: 1
  4163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4164. type: string
  4165. namespace:
  4166. description: |-
  4167. Namespace of the resource being referred to.
  4168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4169. maxLength: 63
  4170. minLength: 1
  4171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4172. type: string
  4173. required:
  4174. - name
  4175. type: object
  4176. token:
  4177. description: use static token to authenticate with
  4178. properties:
  4179. bearerToken:
  4180. description: |-
  4181. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4182. In some instances, `key` is a required field.
  4183. properties:
  4184. key:
  4185. description: |-
  4186. A key in the referenced Secret.
  4187. Some instances of this field may be defaulted, in others it may be required.
  4188. maxLength: 253
  4189. minLength: 1
  4190. pattern: ^[-._a-zA-Z0-9]+$
  4191. type: string
  4192. name:
  4193. description: The name of the Secret resource being referred to.
  4194. maxLength: 253
  4195. minLength: 1
  4196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4197. type: string
  4198. namespace:
  4199. description: |-
  4200. The namespace of the Secret resource being referred to.
  4201. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4202. maxLength: 63
  4203. minLength: 1
  4204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4205. type: string
  4206. type: object
  4207. required:
  4208. - bearerToken
  4209. type: object
  4210. type: object
  4211. authRef:
  4212. description: |-
  4213. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4214. Kubernetes provider.
  4215. properties:
  4216. key:
  4217. description: |-
  4218. A key in the referenced Secret.
  4219. Some instances of this field may be defaulted, in others it may be required.
  4220. maxLength: 253
  4221. minLength: 1
  4222. pattern: ^[-._a-zA-Z0-9]+$
  4223. type: string
  4224. name:
  4225. description: The name of the Secret resource being referred to.
  4226. maxLength: 253
  4227. minLength: 1
  4228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4229. type: string
  4230. namespace:
  4231. description: |-
  4232. The namespace of the Secret resource being referred to.
  4233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4234. maxLength: 63
  4235. minLength: 1
  4236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4237. type: string
  4238. type: object
  4239. resource:
  4240. description: Resource identifies the CRD by its API group, version and kind.
  4241. properties:
  4242. group:
  4243. description: |-
  4244. Group is the API group of the resource. Use "" (empty string) for core
  4245. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4246. for a CRD. The field is required to be present in the manifest — write
  4247. `group: ""` explicitly for core resources so typos fail at admission
  4248. time rather than later at discovery.
  4249. type: string
  4250. kind:
  4251. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4252. minLength: 1
  4253. type: string
  4254. version:
  4255. description: Version is the API version of the resource (e.g. "v1alpha1").
  4256. minLength: 1
  4257. type: string
  4258. required:
  4259. - group
  4260. - kind
  4261. - version
  4262. type: object
  4263. server:
  4264. description: |-
  4265. Server configures the Kubernetes API address and TLS trust, same as the
  4266. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4267. properties:
  4268. caBundle:
  4269. description: CABundle is a base64-encoded CA certificate
  4270. format: byte
  4271. type: string
  4272. caProvider:
  4273. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4274. properties:
  4275. key:
  4276. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4277. maxLength: 253
  4278. minLength: 1
  4279. pattern: ^[-._a-zA-Z0-9]+$
  4280. type: string
  4281. name:
  4282. description: The name of the object located at the provider type.
  4283. maxLength: 253
  4284. minLength: 1
  4285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4286. type: string
  4287. namespace:
  4288. description: |-
  4289. The namespace the Provider type is in.
  4290. Can only be defined when used in a ClusterSecretStore.
  4291. maxLength: 63
  4292. minLength: 1
  4293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4294. type: string
  4295. type:
  4296. description: The type of provider to use such as "Secret", or "ConfigMap".
  4297. enum:
  4298. - Secret
  4299. - ConfigMap
  4300. type: string
  4301. required:
  4302. - name
  4303. - type
  4304. type: object
  4305. url:
  4306. default: kubernetes.default
  4307. description: configures the Kubernetes server Address.
  4308. type: string
  4309. type: object
  4310. whitelist:
  4311. description: |-
  4312. Whitelist optionally restricts which object names and requested properties
  4313. are allowed to be read.
  4314. properties:
  4315. rules:
  4316. description: |-
  4317. Rules is a list of allow rules. If rules are set, at least one rule must
  4318. match for a request to be allowed.
  4319. items:
  4320. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4321. properties:
  4322. name:
  4323. description: |-
  4324. Name is an optional regular expression matched against the bare object name.
  4325. For both SecretStore and ClusterSecretStore this is always the object name
  4326. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4327. type: string
  4328. namespace:
  4329. description: |-
  4330. Namespace is an optional regular expression matched against the namespace of
  4331. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4332. for SecretStore (where the namespace is fixed to the store namespace).
  4333. type: string
  4334. properties:
  4335. description: |-
  4336. Properties is an optional list of regular expressions matched against
  4337. requested property keys (for example: "spec.secretValue").
  4338. items:
  4339. type: string
  4340. type: array
  4341. type: object
  4342. type: array
  4343. type: object
  4344. required:
  4345. - resource
  4346. type: object
  4347. x-kubernetes-validations:
  4348. - message: one of auth or authRef is required
  4349. rule: has(self.auth) || has(self.authRef)
  4350. - message: at most one of the fields in [auth authRef] may be set
  4351. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4352. delinea:
  4353. description: |-
  4354. Delinea DevOps Secrets Vault
  4355. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4356. properties:
  4357. clientId:
  4358. description: ClientID is the non-secret part of the credential.
  4359. properties:
  4360. secretRef:
  4361. description: SecretRef references a key in a secret that will be used as value.
  4362. properties:
  4363. key:
  4364. description: |-
  4365. A key in the referenced Secret.
  4366. Some instances of this field may be defaulted, in others it may be required.
  4367. maxLength: 253
  4368. minLength: 1
  4369. pattern: ^[-._a-zA-Z0-9]+$
  4370. type: string
  4371. name:
  4372. description: The name of the Secret resource being referred to.
  4373. maxLength: 253
  4374. minLength: 1
  4375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4376. type: string
  4377. namespace:
  4378. description: |-
  4379. The namespace of the Secret resource being referred to.
  4380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4381. maxLength: 63
  4382. minLength: 1
  4383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4384. type: string
  4385. type: object
  4386. value:
  4387. description: Value can be specified directly to set a value without using a secret.
  4388. type: string
  4389. type: object
  4390. clientSecret:
  4391. description: ClientSecret is the secret part of the credential.
  4392. properties:
  4393. secretRef:
  4394. description: SecretRef references a key in a secret that will be used as value.
  4395. properties:
  4396. key:
  4397. description: |-
  4398. A key in the referenced Secret.
  4399. Some instances of this field may be defaulted, in others it may be required.
  4400. maxLength: 253
  4401. minLength: 1
  4402. pattern: ^[-._a-zA-Z0-9]+$
  4403. type: string
  4404. name:
  4405. description: The name of the Secret resource being referred to.
  4406. maxLength: 253
  4407. minLength: 1
  4408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4409. type: string
  4410. namespace:
  4411. description: |-
  4412. The namespace of the Secret resource being referred to.
  4413. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4414. maxLength: 63
  4415. minLength: 1
  4416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4417. type: string
  4418. type: object
  4419. value:
  4420. description: Value can be specified directly to set a value without using a secret.
  4421. type: string
  4422. type: object
  4423. tenant:
  4424. description: Tenant is the chosen hostname / site name.
  4425. type: string
  4426. tld:
  4427. description: |-
  4428. TLD is based on the server location that was chosen during provisioning.
  4429. If unset, defaults to "com".
  4430. type: string
  4431. urlTemplate:
  4432. description: |-
  4433. URLTemplate
  4434. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4435. type: string
  4436. required:
  4437. - clientId
  4438. - clientSecret
  4439. - tenant
  4440. type: object
  4441. doppler:
  4442. description: Doppler configures this store to sync secrets using the Doppler provider
  4443. properties:
  4444. auth:
  4445. description: Auth configures how the Operator authenticates with the Doppler API
  4446. properties:
  4447. oidcConfig:
  4448. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4449. properties:
  4450. expirationSeconds:
  4451. default: 600
  4452. description: |-
  4453. ExpirationSeconds sets the ServiceAccount token validity duration.
  4454. Defaults to 10 minutes.
  4455. format: int64
  4456. type: integer
  4457. identity:
  4458. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4459. type: string
  4460. serviceAccountRef:
  4461. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4462. properties:
  4463. audiences:
  4464. description: |-
  4465. Audience specifies the `aud` claim for the service account token
  4466. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4467. then this audiences will be appended to the list
  4468. items:
  4469. type: string
  4470. type: array
  4471. name:
  4472. description: The name of the ServiceAccount resource being referred to.
  4473. maxLength: 253
  4474. minLength: 1
  4475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4476. type: string
  4477. namespace:
  4478. description: |-
  4479. Namespace of the resource being referred to.
  4480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4481. maxLength: 63
  4482. minLength: 1
  4483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4484. type: string
  4485. required:
  4486. - name
  4487. type: object
  4488. required:
  4489. - identity
  4490. - serviceAccountRef
  4491. type: object
  4492. secretRef:
  4493. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4494. properties:
  4495. dopplerToken:
  4496. description: |-
  4497. The DopplerToken is used for authentication.
  4498. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4499. The Key attribute defaults to dopplerToken if not specified.
  4500. properties:
  4501. key:
  4502. description: |-
  4503. A key in the referenced Secret.
  4504. Some instances of this field may be defaulted, in others it may be required.
  4505. maxLength: 253
  4506. minLength: 1
  4507. pattern: ^[-._a-zA-Z0-9]+$
  4508. type: string
  4509. name:
  4510. description: The name of the Secret resource being referred to.
  4511. maxLength: 253
  4512. minLength: 1
  4513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4514. type: string
  4515. namespace:
  4516. description: |-
  4517. The namespace of the Secret resource being referred to.
  4518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4519. maxLength: 63
  4520. minLength: 1
  4521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4522. type: string
  4523. type: object
  4524. required:
  4525. - dopplerToken
  4526. type: object
  4527. type: object
  4528. x-kubernetes-validations:
  4529. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4530. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4531. config:
  4532. description: Doppler config (required if not using a Service Token)
  4533. type: string
  4534. format:
  4535. description: Format enables the downloading of secrets as a file (string)
  4536. enum:
  4537. - json
  4538. - dotnet-json
  4539. - env
  4540. - yaml
  4541. - docker
  4542. type: string
  4543. nameTransformer:
  4544. description: Environment variable compatible name transforms that change secret names to a different format
  4545. enum:
  4546. - upper-camel
  4547. - camel
  4548. - lower-snake
  4549. - tf-var
  4550. - dotnet-env
  4551. - lower-kebab
  4552. type: string
  4553. project:
  4554. description: Doppler project (required if not using a Service Token)
  4555. type: string
  4556. required:
  4557. - auth
  4558. type: object
  4559. dvls:
  4560. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4561. properties:
  4562. auth:
  4563. description: Auth defines the authentication method to use.
  4564. properties:
  4565. secretRef:
  4566. description: SecretRef contains the Application ID and Application Secret for authentication.
  4567. properties:
  4568. appId:
  4569. description: AppID is the reference to the secret containing the Application ID.
  4570. properties:
  4571. key:
  4572. description: |-
  4573. A key in the referenced Secret.
  4574. Some instances of this field may be defaulted, in others it may be required.
  4575. maxLength: 253
  4576. minLength: 1
  4577. pattern: ^[-._a-zA-Z0-9]+$
  4578. type: string
  4579. name:
  4580. description: The name of the Secret resource being referred to.
  4581. maxLength: 253
  4582. minLength: 1
  4583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4584. type: string
  4585. namespace:
  4586. description: |-
  4587. The namespace of the Secret resource being referred to.
  4588. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4589. maxLength: 63
  4590. minLength: 1
  4591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4592. type: string
  4593. type: object
  4594. appSecret:
  4595. description: AppSecret is the reference to the secret containing the Application Secret.
  4596. properties:
  4597. key:
  4598. description: |-
  4599. A key in the referenced Secret.
  4600. Some instances of this field may be defaulted, in others it may be required.
  4601. maxLength: 253
  4602. minLength: 1
  4603. pattern: ^[-._a-zA-Z0-9]+$
  4604. type: string
  4605. name:
  4606. description: The name of the Secret resource being referred to.
  4607. maxLength: 253
  4608. minLength: 1
  4609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4610. type: string
  4611. namespace:
  4612. description: |-
  4613. The namespace of the Secret resource being referred to.
  4614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4615. maxLength: 63
  4616. minLength: 1
  4617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4618. type: string
  4619. type: object
  4620. required:
  4621. - appId
  4622. - appSecret
  4623. type: object
  4624. required:
  4625. - secretRef
  4626. type: object
  4627. insecure:
  4628. description: |-
  4629. Insecure allows connecting to DVLS over plain HTTP.
  4630. This is NOT RECOMMENDED for production use.
  4631. Set to true only if you understand the security implications.
  4632. type: boolean
  4633. serverUrl:
  4634. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4635. type: string
  4636. vault:
  4637. description: |-
  4638. Vault is the name or UUID of the vault to fetch secrets from.
  4639. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4640. type: string
  4641. required:
  4642. - auth
  4643. - serverUrl
  4644. type: object
  4645. fake:
  4646. description: Fake configures a store with static key/value pairs
  4647. properties:
  4648. data:
  4649. items:
  4650. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4651. properties:
  4652. key:
  4653. type: string
  4654. value:
  4655. type: string
  4656. version:
  4657. type: string
  4658. required:
  4659. - key
  4660. - value
  4661. type: object
  4662. type: array
  4663. validationResult:
  4664. description: ValidationResult is defined type for the number of validation results.
  4665. type: integer
  4666. required:
  4667. - data
  4668. type: object
  4669. fortanix:
  4670. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4671. properties:
  4672. apiKey:
  4673. description: APIKey is the API token to access SDKMS Applications.
  4674. properties:
  4675. secretRef:
  4676. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4677. properties:
  4678. key:
  4679. description: |-
  4680. A key in the referenced Secret.
  4681. Some instances of this field may be defaulted, in others it may be required.
  4682. maxLength: 253
  4683. minLength: 1
  4684. pattern: ^[-._a-zA-Z0-9]+$
  4685. type: string
  4686. name:
  4687. description: The name of the Secret resource being referred to.
  4688. maxLength: 253
  4689. minLength: 1
  4690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4691. type: string
  4692. namespace:
  4693. description: |-
  4694. The namespace of the Secret resource being referred to.
  4695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4696. maxLength: 63
  4697. minLength: 1
  4698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4699. type: string
  4700. type: object
  4701. type: object
  4702. apiUrl:
  4703. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4704. type: string
  4705. type: object
  4706. gcpsm:
  4707. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4708. properties:
  4709. auth:
  4710. description: Auth defines the information necessary to authenticate against GCP
  4711. properties:
  4712. secretRef:
  4713. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4714. properties:
  4715. secretAccessKeySecretRef:
  4716. description: The SecretAccessKey is used for authentication
  4717. properties:
  4718. key:
  4719. description: |-
  4720. A key in the referenced Secret.
  4721. Some instances of this field may be defaulted, in others it may be required.
  4722. maxLength: 253
  4723. minLength: 1
  4724. pattern: ^[-._a-zA-Z0-9]+$
  4725. type: string
  4726. name:
  4727. description: The name of the Secret resource being referred to.
  4728. maxLength: 253
  4729. minLength: 1
  4730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4731. type: string
  4732. namespace:
  4733. description: |-
  4734. The namespace of the Secret resource being referred to.
  4735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4736. maxLength: 63
  4737. minLength: 1
  4738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4739. type: string
  4740. type: object
  4741. type: object
  4742. workloadIdentity:
  4743. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4744. properties:
  4745. clusterLocation:
  4746. description: |-
  4747. ClusterLocation is the location of the cluster
  4748. If not specified, it fetches information from the metadata server
  4749. type: string
  4750. clusterName:
  4751. description: |-
  4752. ClusterName is the name of the cluster
  4753. If not specified, it fetches information from the metadata server
  4754. type: string
  4755. clusterProjectID:
  4756. description: |-
  4757. ClusterProjectID is the project ID of the cluster
  4758. If not specified, it fetches information from the metadata server
  4759. type: string
  4760. serviceAccountRef:
  4761. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4762. properties:
  4763. audiences:
  4764. description: |-
  4765. Audience specifies the `aud` claim for the service account token
  4766. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4767. then this audiences will be appended to the list
  4768. items:
  4769. type: string
  4770. type: array
  4771. name:
  4772. description: The name of the ServiceAccount resource being referred to.
  4773. maxLength: 253
  4774. minLength: 1
  4775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4776. type: string
  4777. namespace:
  4778. description: |-
  4779. Namespace of the resource being referred to.
  4780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4781. maxLength: 63
  4782. minLength: 1
  4783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4784. type: string
  4785. required:
  4786. - name
  4787. type: object
  4788. required:
  4789. - serviceAccountRef
  4790. type: object
  4791. workloadIdentityFederation:
  4792. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4793. properties:
  4794. audience:
  4795. description: |-
  4796. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4797. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4798. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4799. type: string
  4800. awsSecurityCredentials:
  4801. description: |-
  4802. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4803. when using the AWS metadata server is not an option.
  4804. properties:
  4805. awsCredentialsSecretRef:
  4806. description: |-
  4807. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4808. Secret should be created with below names for keys
  4809. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4810. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4811. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4812. properties:
  4813. name:
  4814. description: name of the secret.
  4815. maxLength: 253
  4816. minLength: 1
  4817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4818. type: string
  4819. namespace:
  4820. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4821. maxLength: 63
  4822. minLength: 1
  4823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4824. type: string
  4825. required:
  4826. - name
  4827. type: object
  4828. region:
  4829. description: region is for configuring the AWS region to be used.
  4830. example: ap-south-1
  4831. maxLength: 50
  4832. minLength: 1
  4833. pattern: ^[a-z0-9-]+$
  4834. type: string
  4835. required:
  4836. - awsCredentialsSecretRef
  4837. - region
  4838. type: object
  4839. credConfig:
  4840. description: |-
  4841. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4842. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4843. serviceAccountRef must be used by providing operators service account details.
  4844. properties:
  4845. key:
  4846. description: key name holding the external account credential config.
  4847. maxLength: 253
  4848. minLength: 1
  4849. pattern: ^[-._a-zA-Z0-9]+$
  4850. type: string
  4851. name:
  4852. description: name of the configmap.
  4853. maxLength: 253
  4854. minLength: 1
  4855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4856. type: string
  4857. namespace:
  4858. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4859. maxLength: 63
  4860. minLength: 1
  4861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4862. type: string
  4863. required:
  4864. - key
  4865. - name
  4866. type: object
  4867. externalTokenEndpoint:
  4868. description: |-
  4869. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4870. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4871. URL is having the expected value.
  4872. type: string
  4873. gcpServiceAccountEmail:
  4874. description: |-
  4875. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4876. after Workload Identity Federation. Use this to grant access through the service account's
  4877. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4878. service_account_impersonation_url in the external account JSON from credConfig;
  4879. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4880. on that ServiceAccount.
  4881. example: my-gsa@my-project.iam.gserviceaccount.com
  4882. minLength: 1
  4883. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4884. type: string
  4885. serviceAccountRef:
  4886. description: |-
  4887. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4888. when Kubernetes is configured as provider in workload identity pool.
  4889. properties:
  4890. audiences:
  4891. description: |-
  4892. Audience specifies the `aud` claim for the service account token
  4893. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4894. then this audiences will be appended to the list
  4895. items:
  4896. type: string
  4897. type: array
  4898. name:
  4899. description: The name of the ServiceAccount resource being referred to.
  4900. maxLength: 253
  4901. minLength: 1
  4902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4903. type: string
  4904. namespace:
  4905. description: |-
  4906. Namespace of the resource being referred to.
  4907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4908. maxLength: 63
  4909. minLength: 1
  4910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4911. type: string
  4912. required:
  4913. - name
  4914. type: object
  4915. type: object
  4916. type: object
  4917. location:
  4918. description: Location optionally defines a location for a secret
  4919. type: string
  4920. projectID:
  4921. description: ProjectID project where secret is located
  4922. type: string
  4923. secretVersionSelectionPolicy:
  4924. default: LatestOrFail
  4925. description: |-
  4926. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4927. when "latest" is disabled or destroyed.
  4928. Possible values are:
  4929. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4930. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4931. type: string
  4932. type: object
  4933. github:
  4934. description: |-
  4935. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4936. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4937. properties:
  4938. appID:
  4939. description: appID specifies the Github APP that will be used to authenticate the client
  4940. format: int64
  4941. type: integer
  4942. auth:
  4943. description: auth configures how secret-manager authenticates with a Github instance.
  4944. properties:
  4945. privateKey:
  4946. description: |-
  4947. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4948. In some instances, `key` is a required field.
  4949. properties:
  4950. key:
  4951. description: |-
  4952. A key in the referenced Secret.
  4953. Some instances of this field may be defaulted, in others it may be required.
  4954. maxLength: 253
  4955. minLength: 1
  4956. pattern: ^[-._a-zA-Z0-9]+$
  4957. type: string
  4958. name:
  4959. description: The name of the Secret resource being referred to.
  4960. maxLength: 253
  4961. minLength: 1
  4962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4963. type: string
  4964. namespace:
  4965. description: |-
  4966. The namespace of the Secret resource being referred to.
  4967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4968. maxLength: 63
  4969. minLength: 1
  4970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4971. type: string
  4972. type: object
  4973. required:
  4974. - privateKey
  4975. type: object
  4976. environment:
  4977. description: environment will be used to fetch secrets from a particular environment within a github repository
  4978. type: string
  4979. installationID:
  4980. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4981. format: int64
  4982. type: integer
  4983. orgSecretVisibility:
  4984. description: |-
  4985. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4986. Valid values are "all" or "private".
  4987. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4988. whatever visibility they already have in GitHub.
  4989. enum:
  4990. - all
  4991. - private
  4992. type: string
  4993. organization:
  4994. description: organization will be used to fetch secrets from the Github organization
  4995. type: string
  4996. repository:
  4997. description: repository will be used to fetch secrets from the Github repository within an organization
  4998. type: string
  4999. uploadURL:
  5000. description: Upload URL for enterprise instances. Default to URL.
  5001. type: string
  5002. url:
  5003. default: https://github.com/
  5004. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5005. type: string
  5006. required:
  5007. - appID
  5008. - auth
  5009. - installationID
  5010. - organization
  5011. type: object
  5012. gitlab:
  5013. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5014. properties:
  5015. auth:
  5016. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5017. properties:
  5018. SecretRef:
  5019. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5020. properties:
  5021. accessToken:
  5022. description: AccessToken is used for authentication.
  5023. properties:
  5024. key:
  5025. description: |-
  5026. A key in the referenced Secret.
  5027. Some instances of this field may be defaulted, in others it may be required.
  5028. maxLength: 253
  5029. minLength: 1
  5030. pattern: ^[-._a-zA-Z0-9]+$
  5031. type: string
  5032. name:
  5033. description: The name of the Secret resource being referred to.
  5034. maxLength: 253
  5035. minLength: 1
  5036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5037. type: string
  5038. namespace:
  5039. description: |-
  5040. The namespace of the Secret resource being referred to.
  5041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5042. maxLength: 63
  5043. minLength: 1
  5044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5045. type: string
  5046. type: object
  5047. type: object
  5048. required:
  5049. - SecretRef
  5050. type: object
  5051. caBundle:
  5052. description: |-
  5053. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5054. can be performed.
  5055. format: byte
  5056. type: string
  5057. caProvider:
  5058. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5059. properties:
  5060. key:
  5061. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5062. maxLength: 253
  5063. minLength: 1
  5064. pattern: ^[-._a-zA-Z0-9]+$
  5065. type: string
  5066. name:
  5067. description: The name of the object located at the provider type.
  5068. maxLength: 253
  5069. minLength: 1
  5070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5071. type: string
  5072. namespace:
  5073. description: |-
  5074. The namespace the Provider type is in.
  5075. Can only be defined when used in a ClusterSecretStore.
  5076. maxLength: 63
  5077. minLength: 1
  5078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5079. type: string
  5080. type:
  5081. description: The type of provider to use such as "Secret", or "ConfigMap".
  5082. enum:
  5083. - Secret
  5084. - ConfigMap
  5085. type: string
  5086. required:
  5087. - name
  5088. - type
  5089. type: object
  5090. environment:
  5091. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5092. type: string
  5093. groupIDs:
  5094. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5095. items:
  5096. type: string
  5097. type: array
  5098. inheritFromGroups:
  5099. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5100. type: boolean
  5101. projectID:
  5102. description: ProjectID specifies a project where secrets are located.
  5103. type: string
  5104. url:
  5105. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5106. type: string
  5107. required:
  5108. - auth
  5109. type: object
  5110. ibm:
  5111. description: IBM configures this store to sync secrets using IBM Cloud provider
  5112. properties:
  5113. auth:
  5114. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5115. maxProperties: 1
  5116. minProperties: 1
  5117. properties:
  5118. containerAuth:
  5119. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5120. properties:
  5121. iamEndpoint:
  5122. type: string
  5123. profile:
  5124. description: the IBM Trusted Profile
  5125. type: string
  5126. tokenLocation:
  5127. description: Location the token is mounted on the pod
  5128. type: string
  5129. required:
  5130. - profile
  5131. type: object
  5132. secretRef:
  5133. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5134. properties:
  5135. iamEndpoint:
  5136. description: The IAM endpoint used to obain a token
  5137. type: string
  5138. secretApiKeySecretRef:
  5139. description: The SecretAccessKey is used for authentication
  5140. properties:
  5141. key:
  5142. description: |-
  5143. A key in the referenced Secret.
  5144. Some instances of this field may be defaulted, in others it may be required.
  5145. maxLength: 253
  5146. minLength: 1
  5147. pattern: ^[-._a-zA-Z0-9]+$
  5148. type: string
  5149. name:
  5150. description: The name of the Secret resource being referred to.
  5151. maxLength: 253
  5152. minLength: 1
  5153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5154. type: string
  5155. namespace:
  5156. description: |-
  5157. The namespace of the Secret resource being referred to.
  5158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5159. maxLength: 63
  5160. minLength: 1
  5161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5162. type: string
  5163. type: object
  5164. type: object
  5165. type: object
  5166. serviceUrl:
  5167. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5168. type: string
  5169. required:
  5170. - auth
  5171. type: object
  5172. infisical:
  5173. description: Infisical configures this store to sync secrets using the Infisical provider
  5174. properties:
  5175. auth:
  5176. description: Auth configures how the Operator authenticates with the Infisical API
  5177. properties:
  5178. awsAuthCredentials:
  5179. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5180. properties:
  5181. identityId:
  5182. description: |-
  5183. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5184. In some instances, `key` is a required field.
  5185. properties:
  5186. key:
  5187. description: |-
  5188. A key in the referenced Secret.
  5189. Some instances of this field may be defaulted, in others it may be required.
  5190. maxLength: 253
  5191. minLength: 1
  5192. pattern: ^[-._a-zA-Z0-9]+$
  5193. type: string
  5194. name:
  5195. description: The name of the Secret resource being referred to.
  5196. maxLength: 253
  5197. minLength: 1
  5198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5199. type: string
  5200. namespace:
  5201. description: |-
  5202. The namespace of the Secret resource being referred to.
  5203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5204. maxLength: 63
  5205. minLength: 1
  5206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5207. type: string
  5208. type: object
  5209. required:
  5210. - identityId
  5211. type: object
  5212. azureAuthCredentials:
  5213. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5214. properties:
  5215. identityId:
  5216. description: |-
  5217. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5218. In some instances, `key` is a required field.
  5219. properties:
  5220. key:
  5221. description: |-
  5222. A key in the referenced Secret.
  5223. Some instances of this field may be defaulted, in others it may be required.
  5224. maxLength: 253
  5225. minLength: 1
  5226. pattern: ^[-._a-zA-Z0-9]+$
  5227. type: string
  5228. name:
  5229. description: The name of the Secret resource being referred to.
  5230. maxLength: 253
  5231. minLength: 1
  5232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5233. type: string
  5234. namespace:
  5235. description: |-
  5236. The namespace of the Secret resource being referred to.
  5237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5238. maxLength: 63
  5239. minLength: 1
  5240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5241. type: string
  5242. type: object
  5243. resource:
  5244. description: |-
  5245. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5246. In some instances, `key` is a required field.
  5247. properties:
  5248. key:
  5249. description: |-
  5250. A key in the referenced Secret.
  5251. Some instances of this field may be defaulted, in others it may be required.
  5252. maxLength: 253
  5253. minLength: 1
  5254. pattern: ^[-._a-zA-Z0-9]+$
  5255. type: string
  5256. name:
  5257. description: The name of the Secret resource being referred to.
  5258. maxLength: 253
  5259. minLength: 1
  5260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5261. type: string
  5262. namespace:
  5263. description: |-
  5264. The namespace of the Secret resource being referred to.
  5265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5266. maxLength: 63
  5267. minLength: 1
  5268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5269. type: string
  5270. type: object
  5271. required:
  5272. - identityId
  5273. type: object
  5274. gcpIamAuthCredentials:
  5275. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5276. properties:
  5277. identityId:
  5278. description: |-
  5279. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5280. In some instances, `key` is a required field.
  5281. properties:
  5282. key:
  5283. description: |-
  5284. A key in the referenced Secret.
  5285. Some instances of this field may be defaulted, in others it may be required.
  5286. maxLength: 253
  5287. minLength: 1
  5288. pattern: ^[-._a-zA-Z0-9]+$
  5289. type: string
  5290. name:
  5291. description: The name of the Secret resource being referred to.
  5292. maxLength: 253
  5293. minLength: 1
  5294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5295. type: string
  5296. namespace:
  5297. description: |-
  5298. The namespace of the Secret resource being referred to.
  5299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5300. maxLength: 63
  5301. minLength: 1
  5302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5303. type: string
  5304. type: object
  5305. serviceAccountKeyFilePath:
  5306. description: |-
  5307. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5308. In some instances, `key` is a required field.
  5309. properties:
  5310. key:
  5311. description: |-
  5312. A key in the referenced Secret.
  5313. Some instances of this field may be defaulted, in others it may be required.
  5314. maxLength: 253
  5315. minLength: 1
  5316. pattern: ^[-._a-zA-Z0-9]+$
  5317. type: string
  5318. name:
  5319. description: The name of the Secret resource being referred to.
  5320. maxLength: 253
  5321. minLength: 1
  5322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5323. type: string
  5324. namespace:
  5325. description: |-
  5326. The namespace of the Secret resource being referred to.
  5327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5328. maxLength: 63
  5329. minLength: 1
  5330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5331. type: string
  5332. type: object
  5333. required:
  5334. - identityId
  5335. - serviceAccountKeyFilePath
  5336. type: object
  5337. gcpIdTokenAuthCredentials:
  5338. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5339. properties:
  5340. identityId:
  5341. description: |-
  5342. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5343. In some instances, `key` is a required field.
  5344. properties:
  5345. key:
  5346. description: |-
  5347. A key in the referenced Secret.
  5348. Some instances of this field may be defaulted, in others it may be required.
  5349. maxLength: 253
  5350. minLength: 1
  5351. pattern: ^[-._a-zA-Z0-9]+$
  5352. type: string
  5353. name:
  5354. description: The name of the Secret resource being referred to.
  5355. maxLength: 253
  5356. minLength: 1
  5357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5358. type: string
  5359. namespace:
  5360. description: |-
  5361. The namespace of the Secret resource being referred to.
  5362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5363. maxLength: 63
  5364. minLength: 1
  5365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5366. type: string
  5367. type: object
  5368. required:
  5369. - identityId
  5370. type: object
  5371. jwtAuthCredentials:
  5372. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5373. properties:
  5374. identityId:
  5375. description: |-
  5376. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5377. In some instances, `key` is a required field.
  5378. properties:
  5379. key:
  5380. description: |-
  5381. A key in the referenced Secret.
  5382. Some instances of this field may be defaulted, in others it may be required.
  5383. maxLength: 253
  5384. minLength: 1
  5385. pattern: ^[-._a-zA-Z0-9]+$
  5386. type: string
  5387. name:
  5388. description: The name of the Secret resource being referred to.
  5389. maxLength: 253
  5390. minLength: 1
  5391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5392. type: string
  5393. namespace:
  5394. description: |-
  5395. The namespace of the Secret resource being referred to.
  5396. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5397. maxLength: 63
  5398. minLength: 1
  5399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5400. type: string
  5401. type: object
  5402. jwt:
  5403. description: |-
  5404. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5405. In some instances, `key` is a required field.
  5406. properties:
  5407. key:
  5408. description: |-
  5409. A key in the referenced Secret.
  5410. Some instances of this field may be defaulted, in others it may be required.
  5411. maxLength: 253
  5412. minLength: 1
  5413. pattern: ^[-._a-zA-Z0-9]+$
  5414. type: string
  5415. name:
  5416. description: The name of the Secret resource being referred to.
  5417. maxLength: 253
  5418. minLength: 1
  5419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5420. type: string
  5421. namespace:
  5422. description: |-
  5423. The namespace of the Secret resource being referred to.
  5424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5425. maxLength: 63
  5426. minLength: 1
  5427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5428. type: string
  5429. type: object
  5430. required:
  5431. - identityId
  5432. - jwt
  5433. type: object
  5434. kubernetesAuthCredentials:
  5435. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5436. properties:
  5437. identityId:
  5438. description: |-
  5439. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5440. In some instances, `key` is a required field.
  5441. properties:
  5442. key:
  5443. description: |-
  5444. A key in the referenced Secret.
  5445. Some instances of this field may be defaulted, in others it may be required.
  5446. maxLength: 253
  5447. minLength: 1
  5448. pattern: ^[-._a-zA-Z0-9]+$
  5449. type: string
  5450. name:
  5451. description: The name of the Secret resource being referred to.
  5452. maxLength: 253
  5453. minLength: 1
  5454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5455. type: string
  5456. namespace:
  5457. description: |-
  5458. The namespace of the Secret resource being referred to.
  5459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5460. maxLength: 63
  5461. minLength: 1
  5462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5463. type: string
  5464. type: object
  5465. serviceAccountTokenPath:
  5466. description: |-
  5467. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5468. In some instances, `key` is a required field.
  5469. properties:
  5470. key:
  5471. description: |-
  5472. A key in the referenced Secret.
  5473. Some instances of this field may be defaulted, in others it may be required.
  5474. maxLength: 253
  5475. minLength: 1
  5476. pattern: ^[-._a-zA-Z0-9]+$
  5477. type: string
  5478. name:
  5479. description: The name of the Secret resource being referred to.
  5480. maxLength: 253
  5481. minLength: 1
  5482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5483. type: string
  5484. namespace:
  5485. description: |-
  5486. The namespace of the Secret resource being referred to.
  5487. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5488. maxLength: 63
  5489. minLength: 1
  5490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5491. type: string
  5492. type: object
  5493. required:
  5494. - identityId
  5495. type: object
  5496. ldapAuthCredentials:
  5497. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5498. properties:
  5499. identityId:
  5500. description: |-
  5501. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5502. In some instances, `key` is a required field.
  5503. properties:
  5504. key:
  5505. description: |-
  5506. A key in the referenced Secret.
  5507. Some instances of this field may be defaulted, in others it may be required.
  5508. maxLength: 253
  5509. minLength: 1
  5510. pattern: ^[-._a-zA-Z0-9]+$
  5511. type: string
  5512. name:
  5513. description: The name of the Secret resource being referred to.
  5514. maxLength: 253
  5515. minLength: 1
  5516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5517. type: string
  5518. namespace:
  5519. description: |-
  5520. The namespace of the Secret resource being referred to.
  5521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5522. maxLength: 63
  5523. minLength: 1
  5524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5525. type: string
  5526. type: object
  5527. ldapPassword:
  5528. description: |-
  5529. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5530. In some instances, `key` is a required field.
  5531. properties:
  5532. key:
  5533. description: |-
  5534. A key in the referenced Secret.
  5535. Some instances of this field may be defaulted, in others it may be required.
  5536. maxLength: 253
  5537. minLength: 1
  5538. pattern: ^[-._a-zA-Z0-9]+$
  5539. type: string
  5540. name:
  5541. description: The name of the Secret resource being referred to.
  5542. maxLength: 253
  5543. minLength: 1
  5544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5545. type: string
  5546. namespace:
  5547. description: |-
  5548. The namespace of the Secret resource being referred to.
  5549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5550. maxLength: 63
  5551. minLength: 1
  5552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5553. type: string
  5554. type: object
  5555. ldapUsername:
  5556. description: |-
  5557. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5558. In some instances, `key` is a required field.
  5559. properties:
  5560. key:
  5561. description: |-
  5562. A key in the referenced Secret.
  5563. Some instances of this field may be defaulted, in others it may be required.
  5564. maxLength: 253
  5565. minLength: 1
  5566. pattern: ^[-._a-zA-Z0-9]+$
  5567. type: string
  5568. name:
  5569. description: The name of the Secret resource being referred to.
  5570. maxLength: 253
  5571. minLength: 1
  5572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5573. type: string
  5574. namespace:
  5575. description: |-
  5576. The namespace of the Secret resource being referred to.
  5577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5578. maxLength: 63
  5579. minLength: 1
  5580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5581. type: string
  5582. type: object
  5583. required:
  5584. - identityId
  5585. - ldapPassword
  5586. - ldapUsername
  5587. type: object
  5588. ociAuthCredentials:
  5589. description: OciAuthCredentials represents the credentials for OCI authentication.
  5590. properties:
  5591. fingerprint:
  5592. description: |-
  5593. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5594. In some instances, `key` is a required field.
  5595. properties:
  5596. key:
  5597. description: |-
  5598. A key in the referenced Secret.
  5599. Some instances of this field may be defaulted, in others it may be required.
  5600. maxLength: 253
  5601. minLength: 1
  5602. pattern: ^[-._a-zA-Z0-9]+$
  5603. type: string
  5604. name:
  5605. description: The name of the Secret resource being referred to.
  5606. maxLength: 253
  5607. minLength: 1
  5608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5609. type: string
  5610. namespace:
  5611. description: |-
  5612. The namespace of the Secret resource being referred to.
  5613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5614. maxLength: 63
  5615. minLength: 1
  5616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5617. type: string
  5618. type: object
  5619. identityId:
  5620. description: |-
  5621. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5622. In some instances, `key` is a required field.
  5623. properties:
  5624. key:
  5625. description: |-
  5626. A key in the referenced Secret.
  5627. Some instances of this field may be defaulted, in others it may be required.
  5628. maxLength: 253
  5629. minLength: 1
  5630. pattern: ^[-._a-zA-Z0-9]+$
  5631. type: string
  5632. name:
  5633. description: The name of the Secret resource being referred to.
  5634. maxLength: 253
  5635. minLength: 1
  5636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5637. type: string
  5638. namespace:
  5639. description: |-
  5640. The namespace of the Secret resource being referred to.
  5641. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5642. maxLength: 63
  5643. minLength: 1
  5644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5645. type: string
  5646. type: object
  5647. privateKey:
  5648. description: |-
  5649. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5650. In some instances, `key` is a required field.
  5651. properties:
  5652. key:
  5653. description: |-
  5654. A key in the referenced Secret.
  5655. Some instances of this field may be defaulted, in others it may be required.
  5656. maxLength: 253
  5657. minLength: 1
  5658. pattern: ^[-._a-zA-Z0-9]+$
  5659. type: string
  5660. name:
  5661. description: The name of the Secret resource being referred to.
  5662. maxLength: 253
  5663. minLength: 1
  5664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5665. type: string
  5666. namespace:
  5667. description: |-
  5668. The namespace of the Secret resource being referred to.
  5669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5670. maxLength: 63
  5671. minLength: 1
  5672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5673. type: string
  5674. type: object
  5675. privateKeyPassphrase:
  5676. description: |-
  5677. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5678. In some instances, `key` is a required field.
  5679. properties:
  5680. key:
  5681. description: |-
  5682. A key in the referenced Secret.
  5683. Some instances of this field may be defaulted, in others it may be required.
  5684. maxLength: 253
  5685. minLength: 1
  5686. pattern: ^[-._a-zA-Z0-9]+$
  5687. type: string
  5688. name:
  5689. description: The name of the Secret resource being referred to.
  5690. maxLength: 253
  5691. minLength: 1
  5692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5693. type: string
  5694. namespace:
  5695. description: |-
  5696. The namespace of the Secret resource being referred to.
  5697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5698. maxLength: 63
  5699. minLength: 1
  5700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5701. type: string
  5702. type: object
  5703. region:
  5704. description: |-
  5705. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5706. In some instances, `key` is a required field.
  5707. properties:
  5708. key:
  5709. description: |-
  5710. A key in the referenced Secret.
  5711. Some instances of this field may be defaulted, in others it may be required.
  5712. maxLength: 253
  5713. minLength: 1
  5714. pattern: ^[-._a-zA-Z0-9]+$
  5715. type: string
  5716. name:
  5717. description: The name of the Secret resource being referred to.
  5718. maxLength: 253
  5719. minLength: 1
  5720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5721. type: string
  5722. namespace:
  5723. description: |-
  5724. The namespace of the Secret resource being referred to.
  5725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5726. maxLength: 63
  5727. minLength: 1
  5728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5729. type: string
  5730. type: object
  5731. tenancyId:
  5732. description: |-
  5733. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5734. In some instances, `key` is a required field.
  5735. properties:
  5736. key:
  5737. description: |-
  5738. A key in the referenced Secret.
  5739. Some instances of this field may be defaulted, in others it may be required.
  5740. maxLength: 253
  5741. minLength: 1
  5742. pattern: ^[-._a-zA-Z0-9]+$
  5743. type: string
  5744. name:
  5745. description: The name of the Secret resource being referred to.
  5746. maxLength: 253
  5747. minLength: 1
  5748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5749. type: string
  5750. namespace:
  5751. description: |-
  5752. The namespace of the Secret resource being referred to.
  5753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5754. maxLength: 63
  5755. minLength: 1
  5756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5757. type: string
  5758. type: object
  5759. userId:
  5760. description: |-
  5761. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5762. In some instances, `key` is a required field.
  5763. properties:
  5764. key:
  5765. description: |-
  5766. A key in the referenced Secret.
  5767. Some instances of this field may be defaulted, in others it may be required.
  5768. maxLength: 253
  5769. minLength: 1
  5770. pattern: ^[-._a-zA-Z0-9]+$
  5771. type: string
  5772. name:
  5773. description: The name of the Secret resource being referred to.
  5774. maxLength: 253
  5775. minLength: 1
  5776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5777. type: string
  5778. namespace:
  5779. description: |-
  5780. The namespace of the Secret resource being referred to.
  5781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5782. maxLength: 63
  5783. minLength: 1
  5784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5785. type: string
  5786. type: object
  5787. required:
  5788. - fingerprint
  5789. - identityId
  5790. - privateKey
  5791. - region
  5792. - tenancyId
  5793. - userId
  5794. type: object
  5795. tokenAuthCredentials:
  5796. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5797. properties:
  5798. accessToken:
  5799. description: |-
  5800. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5801. In some instances, `key` is a required field.
  5802. properties:
  5803. key:
  5804. description: |-
  5805. A key in the referenced Secret.
  5806. Some instances of this field may be defaulted, in others it may be required.
  5807. maxLength: 253
  5808. minLength: 1
  5809. pattern: ^[-._a-zA-Z0-9]+$
  5810. type: string
  5811. name:
  5812. description: The name of the Secret resource being referred to.
  5813. maxLength: 253
  5814. minLength: 1
  5815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5816. type: string
  5817. namespace:
  5818. description: |-
  5819. The namespace of the Secret resource being referred to.
  5820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5821. maxLength: 63
  5822. minLength: 1
  5823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5824. type: string
  5825. type: object
  5826. required:
  5827. - accessToken
  5828. type: object
  5829. universalAuthCredentials:
  5830. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5831. properties:
  5832. clientId:
  5833. description: |-
  5834. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5835. In some instances, `key` is a required field.
  5836. properties:
  5837. key:
  5838. description: |-
  5839. A key in the referenced Secret.
  5840. Some instances of this field may be defaulted, in others it may be required.
  5841. maxLength: 253
  5842. minLength: 1
  5843. pattern: ^[-._a-zA-Z0-9]+$
  5844. type: string
  5845. name:
  5846. description: The name of the Secret resource being referred to.
  5847. maxLength: 253
  5848. minLength: 1
  5849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5850. type: string
  5851. namespace:
  5852. description: |-
  5853. The namespace of the Secret resource being referred to.
  5854. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5855. maxLength: 63
  5856. minLength: 1
  5857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5858. type: string
  5859. type: object
  5860. clientSecret:
  5861. description: |-
  5862. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5863. In some instances, `key` is a required field.
  5864. properties:
  5865. key:
  5866. description: |-
  5867. A key in the referenced Secret.
  5868. Some instances of this field may be defaulted, in others it may be required.
  5869. maxLength: 253
  5870. minLength: 1
  5871. pattern: ^[-._a-zA-Z0-9]+$
  5872. type: string
  5873. name:
  5874. description: The name of the Secret resource being referred to.
  5875. maxLength: 253
  5876. minLength: 1
  5877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5878. type: string
  5879. namespace:
  5880. description: |-
  5881. The namespace of the Secret resource being referred to.
  5882. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5883. maxLength: 63
  5884. minLength: 1
  5885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5886. type: string
  5887. type: object
  5888. required:
  5889. - clientId
  5890. - clientSecret
  5891. type: object
  5892. type: object
  5893. caBundle:
  5894. description: |-
  5895. CABundle is a PEM-encoded CA certificate bundle used to validate
  5896. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5897. format: byte
  5898. type: string
  5899. caProvider:
  5900. description: |-
  5901. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5902. The certificate is used to validate the Infisical server's TLS certificate.
  5903. Mutually exclusive with CABundle.
  5904. properties:
  5905. key:
  5906. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5907. maxLength: 253
  5908. minLength: 1
  5909. pattern: ^[-._a-zA-Z0-9]+$
  5910. type: string
  5911. name:
  5912. description: The name of the object located at the provider type.
  5913. maxLength: 253
  5914. minLength: 1
  5915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5916. type: string
  5917. namespace:
  5918. description: |-
  5919. The namespace the Provider type is in.
  5920. Can only be defined when used in a ClusterSecretStore.
  5921. maxLength: 63
  5922. minLength: 1
  5923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5924. type: string
  5925. type:
  5926. description: The type of provider to use such as "Secret", or "ConfigMap".
  5927. enum:
  5928. - Secret
  5929. - ConfigMap
  5930. type: string
  5931. required:
  5932. - name
  5933. - type
  5934. type: object
  5935. hostAPI:
  5936. default: https://app.infisical.com/api
  5937. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5938. type: string
  5939. secretsScope:
  5940. description: SecretsScope defines the scope of the secrets within the workspace
  5941. properties:
  5942. environmentSlug:
  5943. description: EnvironmentSlug is the required slug identifier for the environment.
  5944. type: string
  5945. expandSecretReferences:
  5946. default: true
  5947. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5948. type: boolean
  5949. organizationSlug:
  5950. description: |-
  5951. OrganizationSlug is the optional slug that identifies the organization that will be used
  5952. during authentication. Useful for sub-organization setups
  5953. type: string
  5954. projectSlug:
  5955. description: ProjectSlug is the required slug identifier for the project.
  5956. type: string
  5957. recursive:
  5958. default: false
  5959. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5960. type: boolean
  5961. secretsPath:
  5962. default: /
  5963. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5964. type: string
  5965. required:
  5966. - environmentSlug
  5967. - projectSlug
  5968. type: object
  5969. required:
  5970. - auth
  5971. - secretsScope
  5972. type: object
  5973. keepersecurity:
  5974. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5975. properties:
  5976. authRef:
  5977. description: |-
  5978. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5979. In some instances, `key` is a required field.
  5980. properties:
  5981. key:
  5982. description: |-
  5983. A key in the referenced Secret.
  5984. Some instances of this field may be defaulted, in others it may be required.
  5985. maxLength: 253
  5986. minLength: 1
  5987. pattern: ^[-._a-zA-Z0-9]+$
  5988. type: string
  5989. name:
  5990. description: The name of the Secret resource being referred to.
  5991. maxLength: 253
  5992. minLength: 1
  5993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5994. type: string
  5995. namespace:
  5996. description: |-
  5997. The namespace of the Secret resource being referred to.
  5998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5999. maxLength: 63
  6000. minLength: 1
  6001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6002. type: string
  6003. type: object
  6004. folderID:
  6005. type: string
  6006. getByTitleFallback:
  6007. type: boolean
  6008. required:
  6009. - authRef
  6010. - folderID
  6011. type: object
  6012. kubernetes:
  6013. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6014. properties:
  6015. auth:
  6016. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6017. maxProperties: 1
  6018. minProperties: 1
  6019. properties:
  6020. cert:
  6021. description: has both clientCert and clientKey as secretKeySelector
  6022. properties:
  6023. clientCert:
  6024. description: |-
  6025. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6026. In some instances, `key` is a required field.
  6027. properties:
  6028. key:
  6029. description: |-
  6030. A key in the referenced Secret.
  6031. Some instances of this field may be defaulted, in others it may be required.
  6032. maxLength: 253
  6033. minLength: 1
  6034. pattern: ^[-._a-zA-Z0-9]+$
  6035. type: string
  6036. name:
  6037. description: The name of the Secret resource being referred to.
  6038. maxLength: 253
  6039. minLength: 1
  6040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6041. type: string
  6042. namespace:
  6043. description: |-
  6044. The namespace of the Secret resource being referred to.
  6045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6046. maxLength: 63
  6047. minLength: 1
  6048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6049. type: string
  6050. type: object
  6051. clientKey:
  6052. description: |-
  6053. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6054. In some instances, `key` is a required field.
  6055. properties:
  6056. key:
  6057. description: |-
  6058. A key in the referenced Secret.
  6059. Some instances of this field may be defaulted, in others it may be required.
  6060. maxLength: 253
  6061. minLength: 1
  6062. pattern: ^[-._a-zA-Z0-9]+$
  6063. type: string
  6064. name:
  6065. description: The name of the Secret resource being referred to.
  6066. maxLength: 253
  6067. minLength: 1
  6068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6069. type: string
  6070. namespace:
  6071. description: |-
  6072. The namespace of the Secret resource being referred to.
  6073. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6074. maxLength: 63
  6075. minLength: 1
  6076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6077. type: string
  6078. type: object
  6079. required:
  6080. - clientCert
  6081. - clientKey
  6082. type: object
  6083. serviceAccount:
  6084. description: points to a service account that should be used for authentication
  6085. properties:
  6086. audiences:
  6087. description: |-
  6088. Audience specifies the `aud` claim for the service account token
  6089. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6090. then this audiences will be appended to the list
  6091. items:
  6092. type: string
  6093. type: array
  6094. name:
  6095. description: The name of the ServiceAccount resource being referred to.
  6096. maxLength: 253
  6097. minLength: 1
  6098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6099. type: string
  6100. namespace:
  6101. description: |-
  6102. Namespace of the resource being referred to.
  6103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6104. maxLength: 63
  6105. minLength: 1
  6106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6107. type: string
  6108. required:
  6109. - name
  6110. type: object
  6111. token:
  6112. description: use static token to authenticate with
  6113. properties:
  6114. bearerToken:
  6115. description: |-
  6116. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6117. In some instances, `key` is a required field.
  6118. properties:
  6119. key:
  6120. description: |-
  6121. A key in the referenced Secret.
  6122. Some instances of this field may be defaulted, in others it may be required.
  6123. maxLength: 253
  6124. minLength: 1
  6125. pattern: ^[-._a-zA-Z0-9]+$
  6126. type: string
  6127. name:
  6128. description: The name of the Secret resource being referred to.
  6129. maxLength: 253
  6130. minLength: 1
  6131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6132. type: string
  6133. namespace:
  6134. description: |-
  6135. The namespace of the Secret resource being referred to.
  6136. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6137. maxLength: 63
  6138. minLength: 1
  6139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6140. type: string
  6141. type: object
  6142. required:
  6143. - bearerToken
  6144. type: object
  6145. type: object
  6146. authRef:
  6147. description: A reference to a secret that contains the auth information.
  6148. properties:
  6149. key:
  6150. description: |-
  6151. A key in the referenced Secret.
  6152. Some instances of this field may be defaulted, in others it may be required.
  6153. maxLength: 253
  6154. minLength: 1
  6155. pattern: ^[-._a-zA-Z0-9]+$
  6156. type: string
  6157. name:
  6158. description: The name of the Secret resource being referred to.
  6159. maxLength: 253
  6160. minLength: 1
  6161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6162. type: string
  6163. namespace:
  6164. description: |-
  6165. The namespace of the Secret resource being referred to.
  6166. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6167. maxLength: 63
  6168. minLength: 1
  6169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6170. type: string
  6171. type: object
  6172. remoteNamespace:
  6173. default: default
  6174. description: Remote namespace to fetch the secrets from
  6175. maxLength: 63
  6176. minLength: 1
  6177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6178. type: string
  6179. server:
  6180. description: configures the Kubernetes server Address.
  6181. properties:
  6182. caBundle:
  6183. description: CABundle is a base64-encoded CA certificate
  6184. format: byte
  6185. type: string
  6186. caProvider:
  6187. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6188. properties:
  6189. key:
  6190. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6191. maxLength: 253
  6192. minLength: 1
  6193. pattern: ^[-._a-zA-Z0-9]+$
  6194. type: string
  6195. name:
  6196. description: The name of the object located at the provider type.
  6197. maxLength: 253
  6198. minLength: 1
  6199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6200. type: string
  6201. namespace:
  6202. description: |-
  6203. The namespace the Provider type is in.
  6204. Can only be defined when used in a ClusterSecretStore.
  6205. maxLength: 63
  6206. minLength: 1
  6207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6208. type: string
  6209. type:
  6210. description: The type of provider to use such as "Secret", or "ConfigMap".
  6211. enum:
  6212. - Secret
  6213. - ConfigMap
  6214. type: string
  6215. required:
  6216. - name
  6217. - type
  6218. type: object
  6219. url:
  6220. default: kubernetes.default
  6221. description: configures the Kubernetes server Address.
  6222. type: string
  6223. type: object
  6224. type: object
  6225. nebiusmysterybox:
  6226. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6227. properties:
  6228. apiDomain:
  6229. description: NebiusMysterybox API endpoint
  6230. type: string
  6231. auth:
  6232. description: Auth defines parameters to authenticate in MysteryBox
  6233. properties:
  6234. serviceAccountCredsSecretRef:
  6235. description: |-
  6236. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6237. document with service account credentials used to get an IAM token.
  6238. Expected JSON structure:
  6239. {
  6240. "subject-credentials": {
  6241. "alg": "RS256",
  6242. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6243. "kid": "<public-key-id>",
  6244. "iss": "<issuer-service-account-id>",
  6245. "sub": "<subject-service-account-id>"
  6246. }
  6247. }
  6248. properties:
  6249. key:
  6250. description: |-
  6251. A key in the referenced Secret.
  6252. Some instances of this field may be defaulted, in others it may be required.
  6253. maxLength: 253
  6254. minLength: 1
  6255. pattern: ^[-._a-zA-Z0-9]+$
  6256. type: string
  6257. name:
  6258. description: The name of the Secret resource being referred to.
  6259. maxLength: 253
  6260. minLength: 1
  6261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6262. type: string
  6263. namespace:
  6264. description: |-
  6265. The namespace of the Secret resource being referred to.
  6266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6267. maxLength: 63
  6268. minLength: 1
  6269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6270. type: string
  6271. type: object
  6272. tokenSecretRef:
  6273. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6274. properties:
  6275. key:
  6276. description: |-
  6277. A key in the referenced Secret.
  6278. Some instances of this field may be defaulted, in others it may be required.
  6279. maxLength: 253
  6280. minLength: 1
  6281. pattern: ^[-._a-zA-Z0-9]+$
  6282. type: string
  6283. name:
  6284. description: The name of the Secret resource being referred to.
  6285. maxLength: 253
  6286. minLength: 1
  6287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6288. type: string
  6289. namespace:
  6290. description: |-
  6291. The namespace of the Secret resource being referred to.
  6292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6293. maxLength: 63
  6294. minLength: 1
  6295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6296. type: string
  6297. type: object
  6298. type: object
  6299. x-kubernetes-validations:
  6300. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6301. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6302. caProvider:
  6303. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6304. properties:
  6305. certSecretRef:
  6306. description: |-
  6307. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6308. In some instances, `key` is a required field.
  6309. properties:
  6310. key:
  6311. description: |-
  6312. A key in the referenced Secret.
  6313. Some instances of this field may be defaulted, in others it may be required.
  6314. maxLength: 253
  6315. minLength: 1
  6316. pattern: ^[-._a-zA-Z0-9]+$
  6317. type: string
  6318. name:
  6319. description: The name of the Secret resource being referred to.
  6320. maxLength: 253
  6321. minLength: 1
  6322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6323. type: string
  6324. namespace:
  6325. description: |-
  6326. The namespace of the Secret resource being referred to.
  6327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6328. maxLength: 63
  6329. minLength: 1
  6330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6331. type: string
  6332. type: object
  6333. type: object
  6334. required:
  6335. - apiDomain
  6336. - auth
  6337. type: object
  6338. ngrok:
  6339. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6340. properties:
  6341. apiUrl:
  6342. default: https://api.ngrok.com
  6343. description: APIURL is the URL of the ngrok API.
  6344. type: string
  6345. auth:
  6346. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6347. maxProperties: 1
  6348. minProperties: 1
  6349. properties:
  6350. apiKey:
  6351. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6352. properties:
  6353. secretRef:
  6354. description: SecretRef is a reference to a secret containing the ngrok API key.
  6355. properties:
  6356. key:
  6357. description: |-
  6358. A key in the referenced Secret.
  6359. Some instances of this field may be defaulted, in others it may be required.
  6360. maxLength: 253
  6361. minLength: 1
  6362. pattern: ^[-._a-zA-Z0-9]+$
  6363. type: string
  6364. name:
  6365. description: The name of the Secret resource being referred to.
  6366. maxLength: 253
  6367. minLength: 1
  6368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6369. type: string
  6370. namespace:
  6371. description: |-
  6372. The namespace of the Secret resource being referred to.
  6373. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6374. maxLength: 63
  6375. minLength: 1
  6376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6377. type: string
  6378. type: object
  6379. type: object
  6380. type: object
  6381. vault:
  6382. description: Vault configures the ngrok vault to sync secrets with.
  6383. properties:
  6384. name:
  6385. description: Name is the name of the ngrok vault to sync secrets with.
  6386. type: string
  6387. required:
  6388. - name
  6389. type: object
  6390. required:
  6391. - auth
  6392. - vault
  6393. type: object
  6394. onboardbase:
  6395. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6396. properties:
  6397. apiHost:
  6398. default: https://public.onboardbase.com/api/v1/
  6399. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6400. type: string
  6401. auth:
  6402. description: Auth configures how the Operator authenticates with the Onboardbase API
  6403. properties:
  6404. apiKeyRef:
  6405. description: |-
  6406. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6407. It is used to recognize and authorize access to a project and environment within onboardbase
  6408. properties:
  6409. key:
  6410. description: |-
  6411. A key in the referenced Secret.
  6412. Some instances of this field may be defaulted, in others it may be required.
  6413. maxLength: 253
  6414. minLength: 1
  6415. pattern: ^[-._a-zA-Z0-9]+$
  6416. type: string
  6417. name:
  6418. description: The name of the Secret resource being referred to.
  6419. maxLength: 253
  6420. minLength: 1
  6421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6422. type: string
  6423. namespace:
  6424. description: |-
  6425. The namespace of the Secret resource being referred to.
  6426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6427. maxLength: 63
  6428. minLength: 1
  6429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6430. type: string
  6431. type: object
  6432. passcodeRef:
  6433. description: OnboardbasePasscode is the passcode attached to the API Key
  6434. properties:
  6435. key:
  6436. description: |-
  6437. A key in the referenced Secret.
  6438. Some instances of this field may be defaulted, in others it may be required.
  6439. maxLength: 253
  6440. minLength: 1
  6441. pattern: ^[-._a-zA-Z0-9]+$
  6442. type: string
  6443. name:
  6444. description: The name of the Secret resource being referred to.
  6445. maxLength: 253
  6446. minLength: 1
  6447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6448. type: string
  6449. namespace:
  6450. description: |-
  6451. The namespace of the Secret resource being referred to.
  6452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6453. maxLength: 63
  6454. minLength: 1
  6455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6456. type: string
  6457. type: object
  6458. required:
  6459. - apiKeyRef
  6460. - passcodeRef
  6461. type: object
  6462. environment:
  6463. default: development
  6464. description: Environment is the name of an environmnent within a project to pull the secrets from
  6465. type: string
  6466. project:
  6467. default: development
  6468. description: Project is an onboardbase project that the secrets should be pulled from
  6469. type: string
  6470. required:
  6471. - apiHost
  6472. - auth
  6473. - environment
  6474. - project
  6475. type: object
  6476. onepassword:
  6477. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6478. properties:
  6479. auth:
  6480. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6481. properties:
  6482. secretRef:
  6483. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6484. properties:
  6485. connectTokenSecretRef:
  6486. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6487. properties:
  6488. key:
  6489. description: |-
  6490. A key in the referenced Secret.
  6491. Some instances of this field may be defaulted, in others it may be required.
  6492. maxLength: 253
  6493. minLength: 1
  6494. pattern: ^[-._a-zA-Z0-9]+$
  6495. type: string
  6496. name:
  6497. description: The name of the Secret resource being referred to.
  6498. maxLength: 253
  6499. minLength: 1
  6500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6501. type: string
  6502. namespace:
  6503. description: |-
  6504. The namespace of the Secret resource being referred to.
  6505. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6506. maxLength: 63
  6507. minLength: 1
  6508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6509. type: string
  6510. type: object
  6511. required:
  6512. - connectTokenSecretRef
  6513. type: object
  6514. required:
  6515. - secretRef
  6516. type: object
  6517. connectHost:
  6518. description: ConnectHost defines the OnePassword Connect Server to connect to
  6519. type: string
  6520. vaults:
  6521. additionalProperties:
  6522. type: integer
  6523. description: Vaults defines which OnePassword vaults to search in which order
  6524. type: object
  6525. required:
  6526. - auth
  6527. - connectHost
  6528. - vaults
  6529. type: object
  6530. onepasswordSDK:
  6531. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6532. properties:
  6533. auth:
  6534. description: Auth defines the information necessary to authenticate against OnePassword API.
  6535. properties:
  6536. serviceAccountSecretRef:
  6537. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6538. properties:
  6539. key:
  6540. description: |-
  6541. A key in the referenced Secret.
  6542. Some instances of this field may be defaulted, in others it may be required.
  6543. maxLength: 253
  6544. minLength: 1
  6545. pattern: ^[-._a-zA-Z0-9]+$
  6546. type: string
  6547. name:
  6548. description: The name of the Secret resource being referred to.
  6549. maxLength: 253
  6550. minLength: 1
  6551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6552. type: string
  6553. namespace:
  6554. description: |-
  6555. The namespace of the Secret resource being referred to.
  6556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6557. maxLength: 63
  6558. minLength: 1
  6559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6560. type: string
  6561. type: object
  6562. required:
  6563. - serviceAccountSecretRef
  6564. type: object
  6565. cache:
  6566. description: |-
  6567. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6568. When enabled, secrets are cached with the specified TTL.
  6569. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6570. If omitted, caching is disabled (default).
  6571. cache: {} is a valid option to set.
  6572. properties:
  6573. maxSize:
  6574. default: 100
  6575. description: |-
  6576. MaxSize is the maximum number of secrets to cache.
  6577. When the cache is full, least-recently-used entries are evicted.
  6578. minimum: 1
  6579. type: integer
  6580. ttl:
  6581. default: 5m
  6582. description: |-
  6583. TTL is the time-to-live for cached secrets.
  6584. Format: duration string (e.g., "5m", "1h", "30s")
  6585. type: string
  6586. type: object
  6587. integrationInfo:
  6588. description: |-
  6589. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6590. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6591. properties:
  6592. name:
  6593. default: 1Password SDK
  6594. description: Name defaults to "1Password SDK".
  6595. type: string
  6596. version:
  6597. default: v1.0.0
  6598. description: Version defaults to "v1.0.0".
  6599. type: string
  6600. type: object
  6601. vault:
  6602. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6603. type: string
  6604. required:
  6605. - auth
  6606. - vault
  6607. type: object
  6608. openBao:
  6609. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6610. properties:
  6611. auth:
  6612. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6613. properties:
  6614. appRole:
  6615. description: |-
  6616. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6617. with the role and secret stored in a Kubernetes Secret resource.
  6618. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6619. properties:
  6620. path:
  6621. default: approle
  6622. description: |-
  6623. Path where the App Role authentication backend is mounted
  6624. in OpenBao, e.g: "approle"
  6625. type: string
  6626. roleId:
  6627. description: |-
  6628. RoleID configured in the App Role authentication backend when setting
  6629. up the authentication backend in OpenBao.
  6630. minLength: 1
  6631. type: string
  6632. roleRef:
  6633. description: |-
  6634. Reference to a key in a Secret that contains the App Role ID used
  6635. to authenticate with OpenBao.
  6636. The `key` field must be specified and denotes which entry within the Secret
  6637. resource is used as the app role id.
  6638. properties:
  6639. key:
  6640. description: |-
  6641. A key in the referenced Secret.
  6642. Some instances of this field may be defaulted, in others it may be required.
  6643. maxLength: 253
  6644. minLength: 1
  6645. pattern: ^[-._a-zA-Z0-9]+$
  6646. type: string
  6647. name:
  6648. description: The name of the Secret resource being referred to.
  6649. maxLength: 253
  6650. minLength: 1
  6651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6652. type: string
  6653. namespace:
  6654. description: |-
  6655. The namespace of the Secret resource being referred to.
  6656. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6657. maxLength: 63
  6658. minLength: 1
  6659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6660. type: string
  6661. type: object
  6662. secretRef:
  6663. description: |-
  6664. Reference to a key in a Secret that contains the App Role secret used
  6665. to authenticate with OpenBao.
  6666. The `key` field must be specified and denotes which entry within the Secret
  6667. resource is used as the app role secret.
  6668. properties:
  6669. key:
  6670. description: |-
  6671. A key in the referenced Secret.
  6672. Some instances of this field may be defaulted, in others it may be required.
  6673. maxLength: 253
  6674. minLength: 1
  6675. pattern: ^[-._a-zA-Z0-9]+$
  6676. type: string
  6677. name:
  6678. description: The name of the Secret resource being referred to.
  6679. maxLength: 253
  6680. minLength: 1
  6681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6682. type: string
  6683. namespace:
  6684. description: |-
  6685. The namespace of the Secret resource being referred to.
  6686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6687. maxLength: 63
  6688. minLength: 1
  6689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6690. type: string
  6691. type: object
  6692. required:
  6693. - path
  6694. - secretRef
  6695. type: object
  6696. x-kubernetes-validations:
  6697. - message: exactly one of the fields in [roleId roleRef] must be set
  6698. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6699. namespace:
  6700. description: |-
  6701. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6702. than the namespace your secret is in. Namespaces is a set of features
  6703. within OpenBao that allows OpenBao environments to support secure
  6704. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6705. if set, or empty otherwise
  6706. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6707. type: string
  6708. tokenSecretRef:
  6709. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6710. properties:
  6711. key:
  6712. description: |-
  6713. A key in the referenced Secret.
  6714. Some instances of this field may be defaulted, in others it may be required.
  6715. maxLength: 253
  6716. minLength: 1
  6717. pattern: ^[-._a-zA-Z0-9]+$
  6718. type: string
  6719. name:
  6720. description: The name of the Secret resource being referred to.
  6721. maxLength: 253
  6722. minLength: 1
  6723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6724. type: string
  6725. namespace:
  6726. description: |-
  6727. The namespace of the Secret resource being referred to.
  6728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6729. maxLength: 63
  6730. minLength: 1
  6731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6732. type: string
  6733. type: object
  6734. userPass:
  6735. description: UserPass authenticates with OpenBao by passing a username/password pair
  6736. properties:
  6737. path:
  6738. default: userpass
  6739. description: |-
  6740. Path where the UserPassword authentication backend is mounted
  6741. in OpenBao, e.g: "userpass"
  6742. type: string
  6743. secretRef:
  6744. description: |-
  6745. SecretRef to a key in a Secret resource containing password for the user
  6746. used to authenticate with OpenBao using the [UserPass authentication
  6747. method]
  6748. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6749. properties:
  6750. key:
  6751. description: |-
  6752. A key in the referenced Secret.
  6753. Some instances of this field may be defaulted, in others it may be required.
  6754. maxLength: 253
  6755. minLength: 1
  6756. pattern: ^[-._a-zA-Z0-9]+$
  6757. type: string
  6758. name:
  6759. description: The name of the Secret resource being referred to.
  6760. maxLength: 253
  6761. minLength: 1
  6762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6763. type: string
  6764. namespace:
  6765. description: |-
  6766. The namespace of the Secret resource being referred to.
  6767. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6768. maxLength: 63
  6769. minLength: 1
  6770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6771. type: string
  6772. type: object
  6773. username:
  6774. description: |-
  6775. Username is a username used to authenticate using the [UserPass
  6776. authentication method]
  6777. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6778. type: string
  6779. required:
  6780. - path
  6781. - username
  6782. type: object
  6783. type: object
  6784. x-kubernetes-validations:
  6785. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6786. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6787. caBundle:
  6788. description: |-
  6789. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6790. this and `caProvider` are not set the system root certificates are used
  6791. to validate the TLS connection.
  6792. format: byte
  6793. type: string
  6794. caProvider:
  6795. description: |-
  6796. The provider for the CA bundle to use to validate OpenBao server
  6797. certificate. If this and `caBundle` are not set the system root
  6798. certificates are used to validate the TLS connection.
  6799. properties:
  6800. key:
  6801. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6802. maxLength: 253
  6803. minLength: 1
  6804. pattern: ^[-._a-zA-Z0-9]+$
  6805. type: string
  6806. name:
  6807. description: The name of the object located at the provider type.
  6808. maxLength: 253
  6809. minLength: 1
  6810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6811. type: string
  6812. namespace:
  6813. description: |-
  6814. The namespace the Provider type is in.
  6815. Can only be defined when used in a ClusterSecretStore.
  6816. maxLength: 63
  6817. minLength: 1
  6818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6819. type: string
  6820. type:
  6821. description: The type of provider to use such as "Secret", or "ConfigMap".
  6822. enum:
  6823. - Secret
  6824. - ConfigMap
  6825. type: string
  6826. required:
  6827. - name
  6828. - type
  6829. type: object
  6830. namespace:
  6831. description: |-
  6832. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6833. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6834. e.g: "ns1".
  6835. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6836. type: string
  6837. path:
  6838. description: |-
  6839. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6840. "secret". The v2 KV secret engine version specific "/data" path suffix
  6841. for fetching secrets from OpenBao is optional and will be appended
  6842. if not present in specified path.
  6843. type: string
  6844. server:
  6845. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6846. type: string
  6847. version:
  6848. default: v2
  6849. description: |-
  6850. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6851. "v2". Version defaults to "v2".
  6852. enum:
  6853. - v1
  6854. - v2
  6855. type: string
  6856. required:
  6857. - server
  6858. type: object
  6859. x-kubernetes-validations:
  6860. - message: at most one of the fields in [caBundle caProvider] may be set
  6861. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6862. oracle:
  6863. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6864. properties:
  6865. auth:
  6866. description: |-
  6867. Auth configures how secret-manager authenticates with the Oracle Vault.
  6868. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6869. properties:
  6870. secretRef:
  6871. description: SecretRef to pass through sensitive information.
  6872. properties:
  6873. fingerprint:
  6874. description: Fingerprint is the fingerprint of the API private key.
  6875. properties:
  6876. key:
  6877. description: |-
  6878. A key in the referenced Secret.
  6879. Some instances of this field may be defaulted, in others it may be required.
  6880. maxLength: 253
  6881. minLength: 1
  6882. pattern: ^[-._a-zA-Z0-9]+$
  6883. type: string
  6884. name:
  6885. description: The name of the Secret resource being referred to.
  6886. maxLength: 253
  6887. minLength: 1
  6888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6889. type: string
  6890. namespace:
  6891. description: |-
  6892. The namespace of the Secret resource being referred to.
  6893. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6894. maxLength: 63
  6895. minLength: 1
  6896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6897. type: string
  6898. type: object
  6899. privatekey:
  6900. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6901. properties:
  6902. key:
  6903. description: |-
  6904. A key in the referenced Secret.
  6905. Some instances of this field may be defaulted, in others it may be required.
  6906. maxLength: 253
  6907. minLength: 1
  6908. pattern: ^[-._a-zA-Z0-9]+$
  6909. type: string
  6910. name:
  6911. description: The name of the Secret resource being referred to.
  6912. maxLength: 253
  6913. minLength: 1
  6914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6915. type: string
  6916. namespace:
  6917. description: |-
  6918. The namespace of the Secret resource being referred to.
  6919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6920. maxLength: 63
  6921. minLength: 1
  6922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6923. type: string
  6924. type: object
  6925. required:
  6926. - fingerprint
  6927. - privatekey
  6928. type: object
  6929. tenancy:
  6930. description: Tenancy is the tenancy OCID where user is located.
  6931. type: string
  6932. user:
  6933. description: User is an access OCID specific to the account.
  6934. type: string
  6935. required:
  6936. - secretRef
  6937. - tenancy
  6938. - user
  6939. type: object
  6940. compartment:
  6941. description: |-
  6942. Compartment is the vault compartment OCID.
  6943. Required for PushSecret
  6944. type: string
  6945. encryptionKey:
  6946. description: |-
  6947. EncryptionKey is the OCID of the encryption key within the vault.
  6948. Required for PushSecret
  6949. type: string
  6950. principalType:
  6951. description: |-
  6952. The type of principal to use for authentication. If left blank, the Auth struct will
  6953. determine the principal type. This optional field must be specified if using
  6954. workload identity.
  6955. enum:
  6956. - ""
  6957. - UserPrincipal
  6958. - InstancePrincipal
  6959. - Workload
  6960. type: string
  6961. region:
  6962. description: Region is the region where vault is located.
  6963. type: string
  6964. serviceAccountRef:
  6965. description: |-
  6966. ServiceAccountRef specified the service account
  6967. that should be used when authenticating with WorkloadIdentity.
  6968. properties:
  6969. audiences:
  6970. description: |-
  6971. Audience specifies the `aud` claim for the service account token
  6972. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6973. then this audiences will be appended to the list
  6974. items:
  6975. type: string
  6976. type: array
  6977. name:
  6978. description: The name of the ServiceAccount resource being referred to.
  6979. maxLength: 253
  6980. minLength: 1
  6981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6982. type: string
  6983. namespace:
  6984. description: |-
  6985. Namespace of the resource being referred to.
  6986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6987. maxLength: 63
  6988. minLength: 1
  6989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6990. type: string
  6991. required:
  6992. - name
  6993. type: object
  6994. vault:
  6995. description: Vault is the vault's OCID of the specific vault where secret is located.
  6996. type: string
  6997. required:
  6998. - region
  6999. - vault
  7000. type: object
  7001. ovh:
  7002. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7003. properties:
  7004. auth:
  7005. description: Authentication method (mtls or token).
  7006. properties:
  7007. mtls:
  7008. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7009. properties:
  7010. caBundle:
  7011. format: byte
  7012. type: string
  7013. caProvider:
  7014. description: |-
  7015. CAProvider provides a custom certificate authority for accessing the provider's store.
  7016. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7017. properties:
  7018. key:
  7019. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7020. maxLength: 253
  7021. minLength: 1
  7022. pattern: ^[-._a-zA-Z0-9]+$
  7023. type: string
  7024. name:
  7025. description: The name of the object located at the provider type.
  7026. maxLength: 253
  7027. minLength: 1
  7028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7029. type: string
  7030. namespace:
  7031. description: |-
  7032. The namespace the Provider type is in.
  7033. Can only be defined when used in a ClusterSecretStore.
  7034. maxLength: 63
  7035. minLength: 1
  7036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7037. type: string
  7038. type:
  7039. description: The type of provider to use such as "Secret", or "ConfigMap".
  7040. enum:
  7041. - Secret
  7042. - ConfigMap
  7043. type: string
  7044. required:
  7045. - name
  7046. - type
  7047. type: object
  7048. certSecretRef:
  7049. description: |-
  7050. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7051. In some instances, `key` is a required field.
  7052. properties:
  7053. key:
  7054. description: |-
  7055. A key in the referenced Secret.
  7056. Some instances of this field may be defaulted, in others it may be required.
  7057. maxLength: 253
  7058. minLength: 1
  7059. pattern: ^[-._a-zA-Z0-9]+$
  7060. type: string
  7061. name:
  7062. description: The name of the Secret resource being referred to.
  7063. maxLength: 253
  7064. minLength: 1
  7065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7066. type: string
  7067. namespace:
  7068. description: |-
  7069. The namespace of the Secret resource being referred to.
  7070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7071. maxLength: 63
  7072. minLength: 1
  7073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7074. type: string
  7075. type: object
  7076. keySecretRef:
  7077. description: |-
  7078. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7079. In some instances, `key` is a required field.
  7080. properties:
  7081. key:
  7082. description: |-
  7083. A key in the referenced Secret.
  7084. Some instances of this field may be defaulted, in others it may be required.
  7085. maxLength: 253
  7086. minLength: 1
  7087. pattern: ^[-._a-zA-Z0-9]+$
  7088. type: string
  7089. name:
  7090. description: The name of the Secret resource being referred to.
  7091. maxLength: 253
  7092. minLength: 1
  7093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7094. type: string
  7095. namespace:
  7096. description: |-
  7097. The namespace of the Secret resource being referred to.
  7098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7099. maxLength: 63
  7100. minLength: 1
  7101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7102. type: string
  7103. type: object
  7104. required:
  7105. - certSecretRef
  7106. - keySecretRef
  7107. type: object
  7108. token:
  7109. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7110. properties:
  7111. tokenSecretRef:
  7112. description: |-
  7113. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7114. In some instances, `key` is a required field.
  7115. properties:
  7116. key:
  7117. description: |-
  7118. A key in the referenced Secret.
  7119. Some instances of this field may be defaulted, in others it may be required.
  7120. maxLength: 253
  7121. minLength: 1
  7122. pattern: ^[-._a-zA-Z0-9]+$
  7123. type: string
  7124. name:
  7125. description: The name of the Secret resource being referred to.
  7126. maxLength: 253
  7127. minLength: 1
  7128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7129. type: string
  7130. namespace:
  7131. description: |-
  7132. The namespace of the Secret resource being referred to.
  7133. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7134. maxLength: 63
  7135. minLength: 1
  7136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7137. type: string
  7138. type: object
  7139. required:
  7140. - tokenSecretRef
  7141. type: object
  7142. type: object
  7143. casRequired:
  7144. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7145. type: boolean
  7146. okmsTimeout:
  7147. default: 30
  7148. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7149. format: int32
  7150. minimum: 1
  7151. type: integer
  7152. okmsid:
  7153. description: specifies the OKMS ID.
  7154. type: string
  7155. server:
  7156. description: specifies the OKMS server endpoint.
  7157. type: string
  7158. required:
  7159. - auth
  7160. - okmsid
  7161. - server
  7162. type: object
  7163. passbolt:
  7164. description: |-
  7165. PassboltProvider provides access to Passbolt secrets manager.
  7166. See: https://www.passbolt.com.
  7167. properties:
  7168. auth:
  7169. description: Auth defines the information necessary to authenticate against Passbolt Server
  7170. properties:
  7171. passwordSecretRef:
  7172. description: |-
  7173. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7174. In some instances, `key` is a required field.
  7175. properties:
  7176. key:
  7177. description: |-
  7178. A key in the referenced Secret.
  7179. Some instances of this field may be defaulted, in others it may be required.
  7180. maxLength: 253
  7181. minLength: 1
  7182. pattern: ^[-._a-zA-Z0-9]+$
  7183. type: string
  7184. name:
  7185. description: The name of the Secret resource being referred to.
  7186. maxLength: 253
  7187. minLength: 1
  7188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7189. type: string
  7190. namespace:
  7191. description: |-
  7192. The namespace of the Secret resource being referred to.
  7193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7194. maxLength: 63
  7195. minLength: 1
  7196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7197. type: string
  7198. type: object
  7199. privateKeySecretRef:
  7200. description: |-
  7201. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7202. In some instances, `key` is a required field.
  7203. properties:
  7204. key:
  7205. description: |-
  7206. A key in the referenced Secret.
  7207. Some instances of this field may be defaulted, in others it may be required.
  7208. maxLength: 253
  7209. minLength: 1
  7210. pattern: ^[-._a-zA-Z0-9]+$
  7211. type: string
  7212. name:
  7213. description: The name of the Secret resource being referred to.
  7214. maxLength: 253
  7215. minLength: 1
  7216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7217. type: string
  7218. namespace:
  7219. description: |-
  7220. The namespace of the Secret resource being referred to.
  7221. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7222. maxLength: 63
  7223. minLength: 1
  7224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7225. type: string
  7226. type: object
  7227. required:
  7228. - passwordSecretRef
  7229. - privateKeySecretRef
  7230. type: object
  7231. caBundle:
  7232. description: |-
  7233. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7234. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7235. are used to validate the TLS connection.
  7236. format: byte
  7237. type: string
  7238. caProvider:
  7239. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7240. properties:
  7241. key:
  7242. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7243. maxLength: 253
  7244. minLength: 1
  7245. pattern: ^[-._a-zA-Z0-9]+$
  7246. type: string
  7247. name:
  7248. description: The name of the object located at the provider type.
  7249. maxLength: 253
  7250. minLength: 1
  7251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7252. type: string
  7253. namespace:
  7254. description: |-
  7255. The namespace the Provider type is in.
  7256. Can only be defined when used in a ClusterSecretStore.
  7257. maxLength: 63
  7258. minLength: 1
  7259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7260. type: string
  7261. type:
  7262. description: The type of provider to use such as "Secret", or "ConfigMap".
  7263. enum:
  7264. - Secret
  7265. - ConfigMap
  7266. type: string
  7267. required:
  7268. - name
  7269. - type
  7270. type: object
  7271. host:
  7272. description: Host defines the Passbolt Server to connect to
  7273. type: string
  7274. required:
  7275. - auth
  7276. - host
  7277. type: object
  7278. passworddepot:
  7279. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7280. properties:
  7281. auth:
  7282. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7283. properties:
  7284. secretRef:
  7285. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7286. properties:
  7287. credentials:
  7288. description: Username / Password is used for authentication.
  7289. properties:
  7290. key:
  7291. description: |-
  7292. A key in the referenced Secret.
  7293. Some instances of this field may be defaulted, in others it may be required.
  7294. maxLength: 253
  7295. minLength: 1
  7296. pattern: ^[-._a-zA-Z0-9]+$
  7297. type: string
  7298. name:
  7299. description: The name of the Secret resource being referred to.
  7300. maxLength: 253
  7301. minLength: 1
  7302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7303. type: string
  7304. namespace:
  7305. description: |-
  7306. The namespace of the Secret resource being referred to.
  7307. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7308. maxLength: 63
  7309. minLength: 1
  7310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7311. type: string
  7312. type: object
  7313. type: object
  7314. required:
  7315. - secretRef
  7316. type: object
  7317. database:
  7318. description: Database to use as source
  7319. type: string
  7320. host:
  7321. description: URL configures the Password Depot instance URL.
  7322. type: string
  7323. required:
  7324. - auth
  7325. - database
  7326. - host
  7327. type: object
  7328. previder:
  7329. description: Previder configures this store to sync secrets using the Previder provider
  7330. properties:
  7331. auth:
  7332. description: PreviderAuth contains a secretRef for credentials.
  7333. properties:
  7334. secretRef:
  7335. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7336. properties:
  7337. accessToken:
  7338. description: The AccessToken is used for authentication
  7339. properties:
  7340. key:
  7341. description: |-
  7342. A key in the referenced Secret.
  7343. Some instances of this field may be defaulted, in others it may be required.
  7344. maxLength: 253
  7345. minLength: 1
  7346. pattern: ^[-._a-zA-Z0-9]+$
  7347. type: string
  7348. name:
  7349. description: The name of the Secret resource being referred to.
  7350. maxLength: 253
  7351. minLength: 1
  7352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7353. type: string
  7354. namespace:
  7355. description: |-
  7356. The namespace of the Secret resource being referred to.
  7357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7358. maxLength: 63
  7359. minLength: 1
  7360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7361. type: string
  7362. type: object
  7363. required:
  7364. - accessToken
  7365. type: object
  7366. type: object
  7367. baseUri:
  7368. type: string
  7369. required:
  7370. - auth
  7371. type: object
  7372. pulumi:
  7373. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7374. properties:
  7375. accessToken:
  7376. description: |-
  7377. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7378. Deprecated: Use auth.accessToken instead.
  7379. properties:
  7380. secretRef:
  7381. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7382. properties:
  7383. key:
  7384. description: |-
  7385. A key in the referenced Secret.
  7386. Some instances of this field may be defaulted, in others it may be required.
  7387. maxLength: 253
  7388. minLength: 1
  7389. pattern: ^[-._a-zA-Z0-9]+$
  7390. type: string
  7391. name:
  7392. description: The name of the Secret resource being referred to.
  7393. maxLength: 253
  7394. minLength: 1
  7395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7396. type: string
  7397. namespace:
  7398. description: |-
  7399. The namespace of the Secret resource being referred to.
  7400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7401. maxLength: 63
  7402. minLength: 1
  7403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7404. type: string
  7405. type: object
  7406. type: object
  7407. apiUrl:
  7408. default: https://api.pulumi.com/api/esc
  7409. description: APIURL is the URL of the Pulumi API.
  7410. type: string
  7411. auth:
  7412. description: |-
  7413. Auth configures how the Operator authenticates with the Pulumi API.
  7414. Either auth or the deprecated accessToken field must be specified.
  7415. properties:
  7416. accessToken:
  7417. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7418. properties:
  7419. secretRef:
  7420. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7421. properties:
  7422. key:
  7423. description: |-
  7424. A key in the referenced Secret.
  7425. Some instances of this field may be defaulted, in others it may be required.
  7426. maxLength: 253
  7427. minLength: 1
  7428. pattern: ^[-._a-zA-Z0-9]+$
  7429. type: string
  7430. name:
  7431. description: The name of the Secret resource being referred to.
  7432. maxLength: 253
  7433. minLength: 1
  7434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7435. type: string
  7436. namespace:
  7437. description: |-
  7438. The namespace of the Secret resource being referred to.
  7439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7440. maxLength: 63
  7441. minLength: 1
  7442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7443. type: string
  7444. type: object
  7445. type: object
  7446. oidcConfig:
  7447. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7448. properties:
  7449. expirationSeconds:
  7450. default: 600
  7451. description: |-
  7452. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7453. Defaults to 10 minutes.
  7454. format: int64
  7455. minimum: 600
  7456. type: integer
  7457. organization:
  7458. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7459. type: string
  7460. serviceAccountRef:
  7461. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7462. properties:
  7463. audiences:
  7464. description: |-
  7465. Audience specifies the `aud` claim for the service account token
  7466. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7467. then this audiences will be appended to the list
  7468. items:
  7469. type: string
  7470. type: array
  7471. name:
  7472. description: The name of the ServiceAccount resource being referred to.
  7473. maxLength: 253
  7474. minLength: 1
  7475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7476. type: string
  7477. namespace:
  7478. description: |-
  7479. Namespace of the resource being referred to.
  7480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7481. maxLength: 63
  7482. minLength: 1
  7483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7484. type: string
  7485. required:
  7486. - name
  7487. type: object
  7488. required:
  7489. - organization
  7490. - serviceAccountRef
  7491. type: object
  7492. type: object
  7493. x-kubernetes-validations:
  7494. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7495. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7496. environment:
  7497. description: |-
  7498. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7499. dynamically retrieved values from supported providers including all major clouds,
  7500. and other Pulumi ESC environments.
  7501. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7502. type: string
  7503. organization:
  7504. description: |-
  7505. Organization are a space to collaborate on shared projects and stacks.
  7506. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7507. type: string
  7508. project:
  7509. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7510. type: string
  7511. required:
  7512. - environment
  7513. - organization
  7514. - project
  7515. type: object
  7516. x-kubernetes-validations:
  7517. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7518. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7519. scaleway:
  7520. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7521. properties:
  7522. accessKey:
  7523. description: AccessKey is the non-secret part of the api key.
  7524. properties:
  7525. secretRef:
  7526. description: SecretRef references a key in a secret that will be used as value.
  7527. properties:
  7528. key:
  7529. description: |-
  7530. A key in the referenced Secret.
  7531. Some instances of this field may be defaulted, in others it may be required.
  7532. maxLength: 253
  7533. minLength: 1
  7534. pattern: ^[-._a-zA-Z0-9]+$
  7535. type: string
  7536. name:
  7537. description: The name of the Secret resource being referred to.
  7538. maxLength: 253
  7539. minLength: 1
  7540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7541. type: string
  7542. namespace:
  7543. description: |-
  7544. The namespace of the Secret resource being referred to.
  7545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7546. maxLength: 63
  7547. minLength: 1
  7548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7549. type: string
  7550. type: object
  7551. value:
  7552. description: Value can be specified directly to set a value without using a secret.
  7553. type: string
  7554. type: object
  7555. apiUrl:
  7556. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7557. type: string
  7558. projectId:
  7559. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7560. type: string
  7561. region:
  7562. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7563. type: string
  7564. secretKey:
  7565. description: SecretKey is the non-secret part of the api key.
  7566. properties:
  7567. secretRef:
  7568. description: SecretRef references a key in a secret that will be used as value.
  7569. properties:
  7570. key:
  7571. description: |-
  7572. A key in the referenced Secret.
  7573. Some instances of this field may be defaulted, in others it may be required.
  7574. maxLength: 253
  7575. minLength: 1
  7576. pattern: ^[-._a-zA-Z0-9]+$
  7577. type: string
  7578. name:
  7579. description: The name of the Secret resource being referred to.
  7580. maxLength: 253
  7581. minLength: 1
  7582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7583. type: string
  7584. namespace:
  7585. description: |-
  7586. The namespace of the Secret resource being referred to.
  7587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7588. maxLength: 63
  7589. minLength: 1
  7590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7591. type: string
  7592. type: object
  7593. value:
  7594. description: Value can be specified directly to set a value without using a secret.
  7595. type: string
  7596. type: object
  7597. required:
  7598. - accessKey
  7599. - projectId
  7600. - region
  7601. - secretKey
  7602. type: object
  7603. secretserver:
  7604. description: |-
  7605. SecretServer configures this store to sync secrets using SecretServer provider
  7606. https://docs.delinea.com/online-help/secret-server/start.htm
  7607. properties:
  7608. caBundle:
  7609. description: |-
  7610. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7611. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7612. are used to validate the TLS connection.
  7613. format: byte
  7614. type: string
  7615. caProvider:
  7616. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7617. properties:
  7618. key:
  7619. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7620. maxLength: 253
  7621. minLength: 1
  7622. pattern: ^[-._a-zA-Z0-9]+$
  7623. type: string
  7624. name:
  7625. description: The name of the object located at the provider type.
  7626. maxLength: 253
  7627. minLength: 1
  7628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7629. type: string
  7630. namespace:
  7631. description: |-
  7632. The namespace the Provider type is in.
  7633. Can only be defined when used in a ClusterSecretStore.
  7634. maxLength: 63
  7635. minLength: 1
  7636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7637. type: string
  7638. type:
  7639. description: The type of provider to use such as "Secret", or "ConfigMap".
  7640. enum:
  7641. - Secret
  7642. - ConfigMap
  7643. type: string
  7644. required:
  7645. - name
  7646. - type
  7647. type: object
  7648. domain:
  7649. description: Domain is the secret server domain.
  7650. type: string
  7651. password:
  7652. description: |-
  7653. Password is the secret server account password.
  7654. Required unless Token is set.
  7655. properties:
  7656. secretRef:
  7657. description: SecretRef references a key in a secret that will be used as value.
  7658. properties:
  7659. key:
  7660. description: |-
  7661. A key in the referenced Secret.
  7662. Some instances of this field may be defaulted, in others it may be required.
  7663. maxLength: 253
  7664. minLength: 1
  7665. pattern: ^[-._a-zA-Z0-9]+$
  7666. type: string
  7667. name:
  7668. description: The name of the Secret resource being referred to.
  7669. maxLength: 253
  7670. minLength: 1
  7671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7672. type: string
  7673. namespace:
  7674. description: |-
  7675. The namespace of the Secret resource being referred to.
  7676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7677. maxLength: 63
  7678. minLength: 1
  7679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7680. type: string
  7681. type: object
  7682. value:
  7683. description: Value can be specified directly to set a value without using a secret.
  7684. minLength: 1
  7685. type: string
  7686. type: object
  7687. x-kubernetes-validations:
  7688. - message: exactly one of value or secretRef must be set
  7689. rule: has(self.value) != has(self.secretRef)
  7690. serverURL:
  7691. description: |-
  7692. ServerURL
  7693. URL to your secret server installation
  7694. type: string
  7695. token:
  7696. description: |-
  7697. Token is an access token used to authenticate to the secret server,
  7698. as an alternative to Username and Password. When set, Username and
  7699. Password are not required and are ignored.
  7700. properties:
  7701. secretRef:
  7702. description: SecretRef references a key in a secret that will be used as value.
  7703. properties:
  7704. key:
  7705. description: |-
  7706. A key in the referenced Secret.
  7707. Some instances of this field may be defaulted, in others it may be required.
  7708. maxLength: 253
  7709. minLength: 1
  7710. pattern: ^[-._a-zA-Z0-9]+$
  7711. type: string
  7712. name:
  7713. description: The name of the Secret resource being referred to.
  7714. maxLength: 253
  7715. minLength: 1
  7716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7717. type: string
  7718. namespace:
  7719. description: |-
  7720. The namespace of the Secret resource being referred to.
  7721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7722. maxLength: 63
  7723. minLength: 1
  7724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7725. type: string
  7726. type: object
  7727. value:
  7728. description: Value can be specified directly to set a value without using a secret.
  7729. minLength: 1
  7730. type: string
  7731. type: object
  7732. x-kubernetes-validations:
  7733. - message: exactly one of value or secretRef must be set
  7734. rule: has(self.value) != has(self.secretRef)
  7735. username:
  7736. description: |-
  7737. Username is the secret server account username.
  7738. Required unless Token is set.
  7739. properties:
  7740. secretRef:
  7741. description: SecretRef references a key in a secret that will be used as value.
  7742. properties:
  7743. key:
  7744. description: |-
  7745. A key in the referenced Secret.
  7746. Some instances of this field may be defaulted, in others it may be required.
  7747. maxLength: 253
  7748. minLength: 1
  7749. pattern: ^[-._a-zA-Z0-9]+$
  7750. type: string
  7751. name:
  7752. description: The name of the Secret resource being referred to.
  7753. maxLength: 253
  7754. minLength: 1
  7755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7756. type: string
  7757. namespace:
  7758. description: |-
  7759. The namespace of the Secret resource being referred to.
  7760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7761. maxLength: 63
  7762. minLength: 1
  7763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7764. type: string
  7765. type: object
  7766. value:
  7767. description: Value can be specified directly to set a value without using a secret.
  7768. minLength: 1
  7769. type: string
  7770. type: object
  7771. x-kubernetes-validations:
  7772. - message: exactly one of value or secretRef must be set
  7773. rule: has(self.value) != has(self.secretRef)
  7774. required:
  7775. - serverURL
  7776. type: object
  7777. x-kubernetes-validations:
  7778. - message: either token, or both username and password, must be set
  7779. rule: has(self.token) || (has(self.username) && has(self.password))
  7780. senhasegura:
  7781. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7782. properties:
  7783. auth:
  7784. description: Auth defines parameters to authenticate in senhasegura
  7785. properties:
  7786. clientId:
  7787. type: string
  7788. clientSecretSecretRef:
  7789. description: |-
  7790. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7791. In some instances, `key` is a required field.
  7792. properties:
  7793. key:
  7794. description: |-
  7795. A key in the referenced Secret.
  7796. Some instances of this field may be defaulted, in others it may be required.
  7797. maxLength: 253
  7798. minLength: 1
  7799. pattern: ^[-._a-zA-Z0-9]+$
  7800. type: string
  7801. name:
  7802. description: The name of the Secret resource being referred to.
  7803. maxLength: 253
  7804. minLength: 1
  7805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7806. type: string
  7807. namespace:
  7808. description: |-
  7809. The namespace of the Secret resource being referred to.
  7810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7811. maxLength: 63
  7812. minLength: 1
  7813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7814. type: string
  7815. type: object
  7816. required:
  7817. - clientId
  7818. - clientSecretSecretRef
  7819. type: object
  7820. ignoreSslCertificate:
  7821. default: false
  7822. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7823. type: boolean
  7824. module:
  7825. description: Module defines which senhasegura module should be used to get secrets
  7826. type: string
  7827. url:
  7828. description: URL of senhasegura
  7829. type: string
  7830. required:
  7831. - auth
  7832. - module
  7833. - url
  7834. type: object
  7835. vault:
  7836. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7837. properties:
  7838. auth:
  7839. description: Auth configures how secret-manager authenticates with the Vault server.
  7840. properties:
  7841. appRole:
  7842. description: |-
  7843. AppRole authenticates with Vault using the App Role auth mechanism,
  7844. with the role and secret stored in a Kubernetes Secret resource.
  7845. properties:
  7846. path:
  7847. default: approle
  7848. description: |-
  7849. Path where the App Role authentication backend is mounted
  7850. in Vault, e.g: "approle"
  7851. type: string
  7852. roleId:
  7853. description: |-
  7854. RoleID configured in the App Role authentication backend when setting
  7855. up the authentication backend in Vault.
  7856. type: string
  7857. roleRef:
  7858. description: |-
  7859. Reference to a key in a Secret that contains the App Role ID used
  7860. to authenticate with Vault.
  7861. The `key` field must be specified and denotes which entry within the Secret
  7862. resource is used as the app role id.
  7863. properties:
  7864. key:
  7865. description: |-
  7866. A key in the referenced Secret.
  7867. Some instances of this field may be defaulted, in others it may be required.
  7868. maxLength: 253
  7869. minLength: 1
  7870. pattern: ^[-._a-zA-Z0-9]+$
  7871. type: string
  7872. name:
  7873. description: The name of the Secret resource being referred to.
  7874. maxLength: 253
  7875. minLength: 1
  7876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7877. type: string
  7878. namespace:
  7879. description: |-
  7880. The namespace of the Secret resource being referred to.
  7881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7882. maxLength: 63
  7883. minLength: 1
  7884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7885. type: string
  7886. type: object
  7887. secretRef:
  7888. description: |-
  7889. Reference to a key in a Secret that contains the App Role secret used
  7890. to authenticate with Vault.
  7891. The `key` field must be specified and denotes which entry within the Secret
  7892. resource is used as the app role secret.
  7893. properties:
  7894. key:
  7895. description: |-
  7896. A key in the referenced Secret.
  7897. Some instances of this field may be defaulted, in others it may be required.
  7898. maxLength: 253
  7899. minLength: 1
  7900. pattern: ^[-._a-zA-Z0-9]+$
  7901. type: string
  7902. name:
  7903. description: The name of the Secret resource being referred to.
  7904. maxLength: 253
  7905. minLength: 1
  7906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7907. type: string
  7908. namespace:
  7909. description: |-
  7910. The namespace of the Secret resource being referred to.
  7911. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7912. maxLength: 63
  7913. minLength: 1
  7914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7915. type: string
  7916. type: object
  7917. required:
  7918. - path
  7919. - secretRef
  7920. type: object
  7921. cert:
  7922. description: |-
  7923. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7924. Cert authentication method
  7925. properties:
  7926. clientCert:
  7927. description: |-
  7928. ClientCert is a certificate to authenticate using the Cert Vault
  7929. authentication method
  7930. properties:
  7931. key:
  7932. description: |-
  7933. A key in the referenced Secret.
  7934. Some instances of this field may be defaulted, in others it may be required.
  7935. maxLength: 253
  7936. minLength: 1
  7937. pattern: ^[-._a-zA-Z0-9]+$
  7938. type: string
  7939. name:
  7940. description: The name of the Secret resource being referred to.
  7941. maxLength: 253
  7942. minLength: 1
  7943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7944. type: string
  7945. namespace:
  7946. description: |-
  7947. The namespace of the Secret resource being referred to.
  7948. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7949. maxLength: 63
  7950. minLength: 1
  7951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7952. type: string
  7953. type: object
  7954. path:
  7955. default: cert
  7956. description: |-
  7957. Path where the Certificate authentication backend is mounted
  7958. in Vault, e.g: "cert"
  7959. type: string
  7960. secretRef:
  7961. description: |-
  7962. SecretRef to a key in a Secret resource containing client private key to
  7963. authenticate with Vault using the Cert authentication method
  7964. properties:
  7965. key:
  7966. description: |-
  7967. A key in the referenced Secret.
  7968. Some instances of this field may be defaulted, in others it may be required.
  7969. maxLength: 253
  7970. minLength: 1
  7971. pattern: ^[-._a-zA-Z0-9]+$
  7972. type: string
  7973. name:
  7974. description: The name of the Secret resource being referred to.
  7975. maxLength: 253
  7976. minLength: 1
  7977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7978. type: string
  7979. namespace:
  7980. description: |-
  7981. The namespace of the Secret resource being referred to.
  7982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7983. maxLength: 63
  7984. minLength: 1
  7985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7986. type: string
  7987. type: object
  7988. vaultRole:
  7989. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7990. type: string
  7991. type: object
  7992. gcp:
  7993. description: |-
  7994. Gcp authenticates with Vault using Google Cloud Platform authentication method
  7995. GCP authentication method
  7996. properties:
  7997. location:
  7998. description: Location optionally defines a location/region for the secret
  7999. type: string
  8000. path:
  8001. default: gcp
  8002. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8003. type: string
  8004. projectID:
  8005. description: Project ID of the Google Cloud Platform project
  8006. type: string
  8007. role:
  8008. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8009. type: string
  8010. secretRef:
  8011. description: Specify credentials in a Secret object
  8012. properties:
  8013. secretAccessKeySecretRef:
  8014. description: The SecretAccessKey is used for authentication
  8015. properties:
  8016. key:
  8017. description: |-
  8018. A key in the referenced Secret.
  8019. Some instances of this field may be defaulted, in others it may be required.
  8020. maxLength: 253
  8021. minLength: 1
  8022. pattern: ^[-._a-zA-Z0-9]+$
  8023. type: string
  8024. name:
  8025. description: The name of the Secret resource being referred to.
  8026. maxLength: 253
  8027. minLength: 1
  8028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8029. type: string
  8030. namespace:
  8031. description: |-
  8032. The namespace of the Secret resource being referred to.
  8033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8034. maxLength: 63
  8035. minLength: 1
  8036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8037. type: string
  8038. type: object
  8039. type: object
  8040. serviceAccountRef:
  8041. description: ServiceAccountRef to a service account for impersonation
  8042. properties:
  8043. audiences:
  8044. description: |-
  8045. Audience specifies the `aud` claim for the service account token
  8046. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8047. then this audiences will be appended to the list
  8048. items:
  8049. type: string
  8050. type: array
  8051. name:
  8052. description: The name of the ServiceAccount resource being referred to.
  8053. maxLength: 253
  8054. minLength: 1
  8055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8056. type: string
  8057. namespace:
  8058. description: |-
  8059. Namespace of the resource being referred to.
  8060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8061. maxLength: 63
  8062. minLength: 1
  8063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8064. type: string
  8065. required:
  8066. - name
  8067. type: object
  8068. workloadIdentity:
  8069. description: Specify a service account with Workload Identity
  8070. properties:
  8071. clusterLocation:
  8072. description: |-
  8073. ClusterLocation is the location of the cluster
  8074. If not specified, it fetches information from the metadata server
  8075. type: string
  8076. clusterName:
  8077. description: |-
  8078. ClusterName is the name of the cluster
  8079. If not specified, it fetches information from the metadata server
  8080. type: string
  8081. clusterProjectID:
  8082. description: |-
  8083. ClusterProjectID is the project ID of the cluster
  8084. If not specified, it fetches information from the metadata server
  8085. type: string
  8086. serviceAccountRef:
  8087. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8088. properties:
  8089. audiences:
  8090. description: |-
  8091. Audience specifies the `aud` claim for the service account token
  8092. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8093. then this audiences will be appended to the list
  8094. items:
  8095. type: string
  8096. type: array
  8097. name:
  8098. description: The name of the ServiceAccount resource being referred to.
  8099. maxLength: 253
  8100. minLength: 1
  8101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8102. type: string
  8103. namespace:
  8104. description: |-
  8105. Namespace of the resource being referred to.
  8106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8107. maxLength: 63
  8108. minLength: 1
  8109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8110. type: string
  8111. required:
  8112. - name
  8113. type: object
  8114. required:
  8115. - serviceAccountRef
  8116. type: object
  8117. required:
  8118. - role
  8119. type: object
  8120. iam:
  8121. description: |-
  8122. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8123. AWS IAM authentication method
  8124. properties:
  8125. externalID:
  8126. description: AWS External ID set on assumed IAM roles
  8127. type: string
  8128. jwt:
  8129. description: Specify a service account with IRSA enabled
  8130. properties:
  8131. serviceAccountRef:
  8132. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8133. properties:
  8134. audiences:
  8135. description: |-
  8136. Audience specifies the `aud` claim for the service account token
  8137. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8138. then this audiences will be appended to the list
  8139. items:
  8140. type: string
  8141. type: array
  8142. name:
  8143. description: The name of the ServiceAccount resource being referred to.
  8144. maxLength: 253
  8145. minLength: 1
  8146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8147. type: string
  8148. namespace:
  8149. description: |-
  8150. Namespace of the resource being referred to.
  8151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8152. maxLength: 63
  8153. minLength: 1
  8154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8155. type: string
  8156. required:
  8157. - name
  8158. type: object
  8159. type: object
  8160. path:
  8161. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8162. type: string
  8163. region:
  8164. description: AWS region
  8165. type: string
  8166. role:
  8167. description: This is the AWS role to be assumed before talking to vault
  8168. type: string
  8169. secretRef:
  8170. description: Specify credentials in a Secret object
  8171. properties:
  8172. accessKeyIDSecretRef:
  8173. description: The AccessKeyID is used for authentication
  8174. properties:
  8175. key:
  8176. description: |-
  8177. A key in the referenced Secret.
  8178. Some instances of this field may be defaulted, in others it may be required.
  8179. maxLength: 253
  8180. minLength: 1
  8181. pattern: ^[-._a-zA-Z0-9]+$
  8182. type: string
  8183. name:
  8184. description: The name of the Secret resource being referred to.
  8185. maxLength: 253
  8186. minLength: 1
  8187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8188. type: string
  8189. namespace:
  8190. description: |-
  8191. The namespace of the Secret resource being referred to.
  8192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8193. maxLength: 63
  8194. minLength: 1
  8195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8196. type: string
  8197. type: object
  8198. secretAccessKeySecretRef:
  8199. description: The SecretAccessKey is used for authentication
  8200. properties:
  8201. key:
  8202. description: |-
  8203. A key in the referenced Secret.
  8204. Some instances of this field may be defaulted, in others it may be required.
  8205. maxLength: 253
  8206. minLength: 1
  8207. pattern: ^[-._a-zA-Z0-9]+$
  8208. type: string
  8209. name:
  8210. description: The name of the Secret resource being referred to.
  8211. maxLength: 253
  8212. minLength: 1
  8213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8214. type: string
  8215. namespace:
  8216. description: |-
  8217. The namespace of the Secret resource being referred to.
  8218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8219. maxLength: 63
  8220. minLength: 1
  8221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8222. type: string
  8223. type: object
  8224. sessionTokenSecretRef:
  8225. description: |-
  8226. The SessionToken used for authentication
  8227. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8228. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8229. properties:
  8230. key:
  8231. description: |-
  8232. A key in the referenced Secret.
  8233. Some instances of this field may be defaulted, in others it may be required.
  8234. maxLength: 253
  8235. minLength: 1
  8236. pattern: ^[-._a-zA-Z0-9]+$
  8237. type: string
  8238. name:
  8239. description: The name of the Secret resource being referred to.
  8240. maxLength: 253
  8241. minLength: 1
  8242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8243. type: string
  8244. namespace:
  8245. description: |-
  8246. The namespace of the Secret resource being referred to.
  8247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8248. maxLength: 63
  8249. minLength: 1
  8250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8251. type: string
  8252. type: object
  8253. type: object
  8254. vaultAwsIamServerID:
  8255. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8256. type: string
  8257. vaultRole:
  8258. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8259. type: string
  8260. required:
  8261. - vaultRole
  8262. type: object
  8263. jwt:
  8264. description: |-
  8265. Jwt authenticates with Vault by passing role and JWT token using the
  8266. JWT/OIDC authentication method
  8267. properties:
  8268. kubernetesServiceAccountToken:
  8269. description: |-
  8270. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8271. a token for with the `TokenRequest` API.
  8272. properties:
  8273. audiences:
  8274. description: |-
  8275. Optional audiences field that will be used to request a temporary Kubernetes service
  8276. account token for the service account referenced by `serviceAccountRef`.
  8277. Defaults to a single audience `vault` it not specified.
  8278. Deprecated: use serviceAccountRef.Audiences instead
  8279. items:
  8280. type: string
  8281. type: array
  8282. expirationSeconds:
  8283. description: |-
  8284. Optional expiration time in seconds that will be used to request a temporary
  8285. Kubernetes service account token for the service account referenced by
  8286. `serviceAccountRef`.
  8287. Deprecated: this will be removed in the future.
  8288. Defaults to 10 minutes.
  8289. format: int64
  8290. type: integer
  8291. serviceAccountRef:
  8292. description: Service account field containing the name of a kubernetes ServiceAccount.
  8293. properties:
  8294. audiences:
  8295. description: |-
  8296. Audience specifies the `aud` claim for the service account token
  8297. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8298. then this audiences will be appended to the list
  8299. items:
  8300. type: string
  8301. type: array
  8302. name:
  8303. description: The name of the ServiceAccount resource being referred to.
  8304. maxLength: 253
  8305. minLength: 1
  8306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8307. type: string
  8308. namespace:
  8309. description: |-
  8310. Namespace of the resource being referred to.
  8311. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8312. maxLength: 63
  8313. minLength: 1
  8314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8315. type: string
  8316. required:
  8317. - name
  8318. type: object
  8319. required:
  8320. - serviceAccountRef
  8321. type: object
  8322. path:
  8323. default: jwt
  8324. description: |-
  8325. Path where the JWT authentication backend is mounted
  8326. in Vault, e.g: "jwt"
  8327. type: string
  8328. role:
  8329. description: |-
  8330. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8331. authentication method
  8332. type: string
  8333. secretRef:
  8334. description: |-
  8335. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8336. authenticate with Vault using the JWT/OIDC authentication method.
  8337. properties:
  8338. key:
  8339. description: |-
  8340. A key in the referenced Secret.
  8341. Some instances of this field may be defaulted, in others it may be required.
  8342. maxLength: 253
  8343. minLength: 1
  8344. pattern: ^[-._a-zA-Z0-9]+$
  8345. type: string
  8346. name:
  8347. description: The name of the Secret resource being referred to.
  8348. maxLength: 253
  8349. minLength: 1
  8350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8351. type: string
  8352. namespace:
  8353. description: |-
  8354. The namespace of the Secret resource being referred to.
  8355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8356. maxLength: 63
  8357. minLength: 1
  8358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8359. type: string
  8360. type: object
  8361. required:
  8362. - path
  8363. type: object
  8364. kubernetes:
  8365. description: |-
  8366. Kubernetes authenticates with Vault by passing the ServiceAccount
  8367. token stored in the named Secret resource to the Vault server.
  8368. properties:
  8369. mountPath:
  8370. default: kubernetes
  8371. description: |-
  8372. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8373. "kubernetes"
  8374. type: string
  8375. role:
  8376. description: |-
  8377. A required field containing the Vault Role to assume. A Role binds a
  8378. Kubernetes ServiceAccount with a set of Vault policies.
  8379. type: string
  8380. secretRef:
  8381. description: |-
  8382. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8383. for authenticating with Vault. If a name is specified without a key,
  8384. `token` is the default. If one is not specified, the one bound to
  8385. the controller will be used.
  8386. properties:
  8387. key:
  8388. description: |-
  8389. A key in the referenced Secret.
  8390. Some instances of this field may be defaulted, in others it may be required.
  8391. maxLength: 253
  8392. minLength: 1
  8393. pattern: ^[-._a-zA-Z0-9]+$
  8394. type: string
  8395. name:
  8396. description: The name of the Secret resource being referred to.
  8397. maxLength: 253
  8398. minLength: 1
  8399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8400. type: string
  8401. namespace:
  8402. description: |-
  8403. The namespace of the Secret resource being referred to.
  8404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8405. maxLength: 63
  8406. minLength: 1
  8407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8408. type: string
  8409. type: object
  8410. serviceAccountRef:
  8411. description: |-
  8412. Optional service account field containing the name of a kubernetes ServiceAccount.
  8413. If the service account is specified, the service account secret token JWT will be used
  8414. for authenticating with Vault. If the service account selector is not supplied,
  8415. the secretRef will be used instead.
  8416. properties:
  8417. audiences:
  8418. description: |-
  8419. Audience specifies the `aud` claim for the service account token
  8420. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8421. then this audiences will be appended to the list
  8422. items:
  8423. type: string
  8424. type: array
  8425. name:
  8426. description: The name of the ServiceAccount resource being referred to.
  8427. maxLength: 253
  8428. minLength: 1
  8429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8430. type: string
  8431. namespace:
  8432. description: |-
  8433. Namespace of the resource being referred to.
  8434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8435. maxLength: 63
  8436. minLength: 1
  8437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8438. type: string
  8439. required:
  8440. - name
  8441. type: object
  8442. required:
  8443. - mountPath
  8444. - role
  8445. type: object
  8446. ldap:
  8447. description: |-
  8448. Ldap authenticates with Vault by passing username/password pair using
  8449. the LDAP authentication method
  8450. properties:
  8451. path:
  8452. default: ldap
  8453. description: |-
  8454. Path where the LDAP authentication backend is mounted
  8455. in Vault, e.g: "ldap"
  8456. type: string
  8457. secretRef:
  8458. description: |-
  8459. SecretRef to a key in a Secret resource containing password for the LDAP
  8460. user used to authenticate with Vault using the LDAP authentication
  8461. method
  8462. properties:
  8463. key:
  8464. description: |-
  8465. A key in the referenced Secret.
  8466. Some instances of this field may be defaulted, in others it may be required.
  8467. maxLength: 253
  8468. minLength: 1
  8469. pattern: ^[-._a-zA-Z0-9]+$
  8470. type: string
  8471. name:
  8472. description: The name of the Secret resource being referred to.
  8473. maxLength: 253
  8474. minLength: 1
  8475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8476. type: string
  8477. namespace:
  8478. description: |-
  8479. The namespace of the Secret resource being referred to.
  8480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8481. maxLength: 63
  8482. minLength: 1
  8483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8484. type: string
  8485. type: object
  8486. username:
  8487. description: |-
  8488. Username is an LDAP username used to authenticate using the LDAP Vault
  8489. authentication method
  8490. type: string
  8491. required:
  8492. - path
  8493. - username
  8494. type: object
  8495. namespace:
  8496. description: |-
  8497. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8498. Namespaces is a set of features within Vault Enterprise that allows
  8499. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8500. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8501. This will default to Vault.Namespace field if set, or empty otherwise
  8502. type: string
  8503. tokenSecretRef:
  8504. description: TokenSecretRef authenticates with Vault by presenting a token.
  8505. properties:
  8506. key:
  8507. description: |-
  8508. A key in the referenced Secret.
  8509. Some instances of this field may be defaulted, in others it may be required.
  8510. maxLength: 253
  8511. minLength: 1
  8512. pattern: ^[-._a-zA-Z0-9]+$
  8513. type: string
  8514. name:
  8515. description: The name of the Secret resource being referred to.
  8516. maxLength: 253
  8517. minLength: 1
  8518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8519. type: string
  8520. namespace:
  8521. description: |-
  8522. The namespace of the Secret resource being referred to.
  8523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8524. maxLength: 63
  8525. minLength: 1
  8526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8527. type: string
  8528. type: object
  8529. userPass:
  8530. description: UserPass authenticates with Vault by passing username/password pair
  8531. properties:
  8532. path:
  8533. default: userpass
  8534. description: |-
  8535. Path where the UserPassword authentication backend is mounted
  8536. in Vault, e.g: "userpass"
  8537. type: string
  8538. secretRef:
  8539. description: |-
  8540. SecretRef to a key in a Secret resource containing password for the
  8541. user used to authenticate with Vault using the UserPass authentication
  8542. method
  8543. properties:
  8544. key:
  8545. description: |-
  8546. A key in the referenced Secret.
  8547. Some instances of this field may be defaulted, in others it may be required.
  8548. maxLength: 253
  8549. minLength: 1
  8550. pattern: ^[-._a-zA-Z0-9]+$
  8551. type: string
  8552. name:
  8553. description: The name of the Secret resource being referred to.
  8554. maxLength: 253
  8555. minLength: 1
  8556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8557. type: string
  8558. namespace:
  8559. description: |-
  8560. The namespace of the Secret resource being referred to.
  8561. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8562. maxLength: 63
  8563. minLength: 1
  8564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8565. type: string
  8566. type: object
  8567. username:
  8568. description: |-
  8569. Username is a username used to authenticate using the UserPass Vault
  8570. authentication method
  8571. type: string
  8572. required:
  8573. - path
  8574. - username
  8575. type: object
  8576. type: object
  8577. caBundle:
  8578. description: |-
  8579. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8580. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8581. plain HTTP protocol connection. If not set the system root certificates
  8582. are used to validate the TLS connection.
  8583. format: byte
  8584. type: string
  8585. caProvider:
  8586. description: The provider for the CA bundle to use to validate Vault server certificate.
  8587. properties:
  8588. key:
  8589. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8590. maxLength: 253
  8591. minLength: 1
  8592. pattern: ^[-._a-zA-Z0-9]+$
  8593. type: string
  8594. name:
  8595. description: The name of the object located at the provider type.
  8596. maxLength: 253
  8597. minLength: 1
  8598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8599. type: string
  8600. namespace:
  8601. description: |-
  8602. The namespace the Provider type is in.
  8603. Can only be defined when used in a ClusterSecretStore.
  8604. maxLength: 63
  8605. minLength: 1
  8606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8607. type: string
  8608. type:
  8609. description: The type of provider to use such as "Secret", or "ConfigMap".
  8610. enum:
  8611. - Secret
  8612. - ConfigMap
  8613. type: string
  8614. required:
  8615. - name
  8616. - type
  8617. type: object
  8618. checkAndSet:
  8619. description: |-
  8620. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8621. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8622. the current version of the secret to prevent unintentional overwrites.
  8623. properties:
  8624. required:
  8625. description: |-
  8626. Required when true, all write operations must include a check-and-set parameter.
  8627. This helps prevent unintentional overwrites of secrets.
  8628. type: boolean
  8629. type: object
  8630. forwardInconsistent:
  8631. description: |-
  8632. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8633. leader instead of simply retrying within a loop. This can increase performance if
  8634. the option is enabled serverside.
  8635. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8636. type: boolean
  8637. headers:
  8638. additionalProperties:
  8639. type: string
  8640. description: Headers to be added in Vault request
  8641. type: object
  8642. namespace:
  8643. description: |-
  8644. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8645. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8646. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8647. type: string
  8648. path:
  8649. description: |-
  8650. Path is the mount path of the Vault KV backend endpoint, e.g:
  8651. "secret". The v2 KV secret engine version specific "/data" path suffix
  8652. for fetching secrets from Vault is optional and will be appended
  8653. if not present in specified path.
  8654. type: string
  8655. readYourWrites:
  8656. description: |-
  8657. ReadYourWrites ensures isolated read-after-write semantics by
  8658. providing discovered cluster replication states in each request.
  8659. More information about eventual consistency in Vault can be found here
  8660. https://www.vaultproject.io/docs/enterprise/consistency
  8661. type: boolean
  8662. server:
  8663. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8664. type: string
  8665. tls:
  8666. description: |-
  8667. The configuration used for client side related TLS communication, when the Vault server
  8668. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8669. This parameter is ignored for plain HTTP protocol connection.
  8670. It's worth noting this configuration is different from the "TLS certificates auth method",
  8671. which is available under the `auth.cert` section.
  8672. properties:
  8673. certSecretRef:
  8674. description: |-
  8675. CertSecretRef is a certificate added to the transport layer
  8676. when communicating with the Vault server.
  8677. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8678. properties:
  8679. key:
  8680. description: |-
  8681. A key in the referenced Secret.
  8682. Some instances of this field may be defaulted, in others it may be required.
  8683. maxLength: 253
  8684. minLength: 1
  8685. pattern: ^[-._a-zA-Z0-9]+$
  8686. type: string
  8687. name:
  8688. description: The name of the Secret resource being referred to.
  8689. maxLength: 253
  8690. minLength: 1
  8691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8692. type: string
  8693. namespace:
  8694. description: |-
  8695. The namespace of the Secret resource being referred to.
  8696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8697. maxLength: 63
  8698. minLength: 1
  8699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8700. type: string
  8701. type: object
  8702. keySecretRef:
  8703. description: |-
  8704. KeySecretRef to a key in a Secret resource containing client private key
  8705. added to the transport layer when communicating with the Vault server.
  8706. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8707. properties:
  8708. key:
  8709. description: |-
  8710. A key in the referenced Secret.
  8711. Some instances of this field may be defaulted, in others it may be required.
  8712. maxLength: 253
  8713. minLength: 1
  8714. pattern: ^[-._a-zA-Z0-9]+$
  8715. type: string
  8716. name:
  8717. description: The name of the Secret resource being referred to.
  8718. maxLength: 253
  8719. minLength: 1
  8720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8721. type: string
  8722. namespace:
  8723. description: |-
  8724. The namespace of the Secret resource being referred to.
  8725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8726. maxLength: 63
  8727. minLength: 1
  8728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8729. type: string
  8730. type: object
  8731. type: object
  8732. version:
  8733. default: v2
  8734. description: |-
  8735. Version is the Vault KV secret engine version. This can be either "v1" or
  8736. "v2". Version defaults to "v2".
  8737. enum:
  8738. - v1
  8739. - v2
  8740. type: string
  8741. required:
  8742. - server
  8743. type: object
  8744. volcengine:
  8745. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8746. properties:
  8747. auth:
  8748. description: |-
  8749. Auth defines the authentication method to use.
  8750. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8751. properties:
  8752. secretRef:
  8753. description: |-
  8754. SecretRef defines the static credentials to use for authentication.
  8755. If not set, IRSA is used.
  8756. properties:
  8757. accessKeyID:
  8758. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8759. properties:
  8760. key:
  8761. description: |-
  8762. A key in the referenced Secret.
  8763. Some instances of this field may be defaulted, in others it may be required.
  8764. maxLength: 253
  8765. minLength: 1
  8766. pattern: ^[-._a-zA-Z0-9]+$
  8767. type: string
  8768. name:
  8769. description: The name of the Secret resource being referred to.
  8770. maxLength: 253
  8771. minLength: 1
  8772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8773. type: string
  8774. namespace:
  8775. description: |-
  8776. The namespace of the Secret resource being referred to.
  8777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8778. maxLength: 63
  8779. minLength: 1
  8780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8781. type: string
  8782. type: object
  8783. secretAccessKey:
  8784. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8785. properties:
  8786. key:
  8787. description: |-
  8788. A key in the referenced Secret.
  8789. Some instances of this field may be defaulted, in others it may be required.
  8790. maxLength: 253
  8791. minLength: 1
  8792. pattern: ^[-._a-zA-Z0-9]+$
  8793. type: string
  8794. name:
  8795. description: The name of the Secret resource being referred to.
  8796. maxLength: 253
  8797. minLength: 1
  8798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8799. type: string
  8800. namespace:
  8801. description: |-
  8802. The namespace of the Secret resource being referred to.
  8803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8804. maxLength: 63
  8805. minLength: 1
  8806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8807. type: string
  8808. type: object
  8809. token:
  8810. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8811. properties:
  8812. key:
  8813. description: |-
  8814. A key in the referenced Secret.
  8815. Some instances of this field may be defaulted, in others it may be required.
  8816. maxLength: 253
  8817. minLength: 1
  8818. pattern: ^[-._a-zA-Z0-9]+$
  8819. type: string
  8820. name:
  8821. description: The name of the Secret resource being referred to.
  8822. maxLength: 253
  8823. minLength: 1
  8824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8825. type: string
  8826. namespace:
  8827. description: |-
  8828. The namespace of the Secret resource being referred to.
  8829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8830. maxLength: 63
  8831. minLength: 1
  8832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8833. type: string
  8834. type: object
  8835. required:
  8836. - accessKeyID
  8837. - secretAccessKey
  8838. type: object
  8839. type: object
  8840. region:
  8841. description: Region specifies the Volcengine region to connect to.
  8842. type: string
  8843. required:
  8844. - region
  8845. type: object
  8846. webhook:
  8847. description: Webhook configures this store to sync secrets using a generic templated webhook
  8848. properties:
  8849. auth:
  8850. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8851. maxProperties: 1
  8852. minProperties: 1
  8853. properties:
  8854. ntlm:
  8855. description: NTLMProtocol configures the store to use NTLM for auth
  8856. properties:
  8857. passwordSecret:
  8858. description: |-
  8859. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8860. In some instances, `key` is a required field.
  8861. properties:
  8862. key:
  8863. description: |-
  8864. A key in the referenced Secret.
  8865. Some instances of this field may be defaulted, in others it may be required.
  8866. maxLength: 253
  8867. minLength: 1
  8868. pattern: ^[-._a-zA-Z0-9]+$
  8869. type: string
  8870. name:
  8871. description: The name of the Secret resource being referred to.
  8872. maxLength: 253
  8873. minLength: 1
  8874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8875. type: string
  8876. namespace:
  8877. description: |-
  8878. The namespace of the Secret resource being referred to.
  8879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8880. maxLength: 63
  8881. minLength: 1
  8882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8883. type: string
  8884. type: object
  8885. usernameSecret:
  8886. description: |-
  8887. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8888. In some instances, `key` is a required field.
  8889. properties:
  8890. key:
  8891. description: |-
  8892. A key in the referenced Secret.
  8893. Some instances of this field may be defaulted, in others it may be required.
  8894. maxLength: 253
  8895. minLength: 1
  8896. pattern: ^[-._a-zA-Z0-9]+$
  8897. type: string
  8898. name:
  8899. description: The name of the Secret resource being referred to.
  8900. maxLength: 253
  8901. minLength: 1
  8902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8903. type: string
  8904. namespace:
  8905. description: |-
  8906. The namespace of the Secret resource being referred to.
  8907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8908. maxLength: 63
  8909. minLength: 1
  8910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8911. type: string
  8912. type: object
  8913. required:
  8914. - passwordSecret
  8915. - usernameSecret
  8916. type: object
  8917. type: object
  8918. body:
  8919. description: Body
  8920. type: string
  8921. caBundle:
  8922. description: |-
  8923. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8924. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8925. plain HTTP protocol connection. If not set the system root certificates
  8926. are used to validate the TLS connection.
  8927. format: byte
  8928. type: string
  8929. caProvider:
  8930. description: The provider for the CA bundle to use to validate webhook server certificate.
  8931. properties:
  8932. key:
  8933. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8934. maxLength: 253
  8935. minLength: 1
  8936. pattern: ^[-._a-zA-Z0-9]+$
  8937. type: string
  8938. name:
  8939. description: The name of the object located at the provider type.
  8940. maxLength: 253
  8941. minLength: 1
  8942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8943. type: string
  8944. namespace:
  8945. description: The namespace the Provider type is in.
  8946. maxLength: 63
  8947. minLength: 1
  8948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8949. type: string
  8950. type:
  8951. description: The type of provider to use such as "Secret", or "ConfigMap".
  8952. enum:
  8953. - Secret
  8954. - ConfigMap
  8955. type: string
  8956. required:
  8957. - name
  8958. - type
  8959. type: object
  8960. headers:
  8961. additionalProperties:
  8962. type: string
  8963. description: Headers
  8964. type: object
  8965. method:
  8966. description: Webhook Method
  8967. type: string
  8968. result:
  8969. description: Result formatting
  8970. properties:
  8971. jsonPath:
  8972. description: Json path of return value
  8973. type: string
  8974. type: object
  8975. secrets:
  8976. description: |-
  8977. Secrets to fill in templates
  8978. These secrets will be passed to the templating function as key value pairs under the given name
  8979. items:
  8980. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8981. properties:
  8982. name:
  8983. description: Name of this secret in templates
  8984. type: string
  8985. secretRef:
  8986. description: Secret ref to fill in credentials
  8987. properties:
  8988. key:
  8989. description: |-
  8990. A key in the referenced Secret.
  8991. Some instances of this field may be defaulted, in others it may be required.
  8992. maxLength: 253
  8993. minLength: 1
  8994. pattern: ^[-._a-zA-Z0-9]+$
  8995. type: string
  8996. name:
  8997. description: The name of the Secret resource being referred to.
  8998. maxLength: 253
  8999. minLength: 1
  9000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9001. type: string
  9002. namespace:
  9003. description: |-
  9004. The namespace of the Secret resource being referred to.
  9005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9006. maxLength: 63
  9007. minLength: 1
  9008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9009. type: string
  9010. type: object
  9011. required:
  9012. - name
  9013. - secretRef
  9014. type: object
  9015. type: array
  9016. timeout:
  9017. description: Timeout
  9018. type: string
  9019. url:
  9020. description: Webhook url to call
  9021. type: string
  9022. required:
  9023. - url
  9024. type: object
  9025. yandexcertificatemanager:
  9026. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9027. properties:
  9028. apiEndpoint:
  9029. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9030. type: string
  9031. auth:
  9032. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9033. properties:
  9034. authorizedKeySecretRef:
  9035. description: The authorized key used for authentication
  9036. properties:
  9037. key:
  9038. description: |-
  9039. A key in the referenced Secret.
  9040. Some instances of this field may be defaulted, in others it may be required.
  9041. maxLength: 253
  9042. minLength: 1
  9043. pattern: ^[-._a-zA-Z0-9]+$
  9044. type: string
  9045. name:
  9046. description: The name of the Secret resource being referred to.
  9047. maxLength: 253
  9048. minLength: 1
  9049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9050. type: string
  9051. namespace:
  9052. description: |-
  9053. The namespace of the Secret resource being referred to.
  9054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9055. maxLength: 63
  9056. minLength: 1
  9057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9058. type: string
  9059. type: object
  9060. type: object
  9061. caProvider:
  9062. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9063. properties:
  9064. certSecretRef:
  9065. description: |-
  9066. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9067. In some instances, `key` is a required field.
  9068. properties:
  9069. key:
  9070. description: |-
  9071. A key in the referenced Secret.
  9072. Some instances of this field may be defaulted, in others it may be required.
  9073. maxLength: 253
  9074. minLength: 1
  9075. pattern: ^[-._a-zA-Z0-9]+$
  9076. type: string
  9077. name:
  9078. description: The name of the Secret resource being referred to.
  9079. maxLength: 253
  9080. minLength: 1
  9081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9082. type: string
  9083. namespace:
  9084. description: |-
  9085. The namespace of the Secret resource being referred to.
  9086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9087. maxLength: 63
  9088. minLength: 1
  9089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9090. type: string
  9091. type: object
  9092. type: object
  9093. fetching:
  9094. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9095. maxProperties: 1
  9096. minProperties: 1
  9097. properties:
  9098. byID:
  9099. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9100. type: object
  9101. byName:
  9102. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9103. properties:
  9104. folderID:
  9105. description: The folder to fetch secrets from
  9106. type: string
  9107. required:
  9108. - folderID
  9109. type: object
  9110. type: object
  9111. required:
  9112. - auth
  9113. type: object
  9114. yandexlockbox:
  9115. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9116. properties:
  9117. apiEndpoint:
  9118. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9119. type: string
  9120. auth:
  9121. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9122. properties:
  9123. authorizedKeySecretRef:
  9124. description: The authorized key used for authentication
  9125. properties:
  9126. key:
  9127. description: |-
  9128. A key in the referenced Secret.
  9129. Some instances of this field may be defaulted, in others it may be required.
  9130. maxLength: 253
  9131. minLength: 1
  9132. pattern: ^[-._a-zA-Z0-9]+$
  9133. type: string
  9134. name:
  9135. description: The name of the Secret resource being referred to.
  9136. maxLength: 253
  9137. minLength: 1
  9138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9139. type: string
  9140. namespace:
  9141. description: |-
  9142. The namespace of the Secret resource being referred to.
  9143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9144. maxLength: 63
  9145. minLength: 1
  9146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9147. type: string
  9148. type: object
  9149. type: object
  9150. caProvider:
  9151. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9152. properties:
  9153. certSecretRef:
  9154. description: |-
  9155. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9156. In some instances, `key` is a required field.
  9157. properties:
  9158. key:
  9159. description: |-
  9160. A key in the referenced Secret.
  9161. Some instances of this field may be defaulted, in others it may be required.
  9162. maxLength: 253
  9163. minLength: 1
  9164. pattern: ^[-._a-zA-Z0-9]+$
  9165. type: string
  9166. name:
  9167. description: The name of the Secret resource being referred to.
  9168. maxLength: 253
  9169. minLength: 1
  9170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9171. type: string
  9172. namespace:
  9173. description: |-
  9174. The namespace of the Secret resource being referred to.
  9175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9176. maxLength: 63
  9177. minLength: 1
  9178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9179. type: string
  9180. type: object
  9181. type: object
  9182. fetching:
  9183. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9184. maxProperties: 1
  9185. minProperties: 1
  9186. properties:
  9187. byID:
  9188. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9189. type: object
  9190. byName:
  9191. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9192. properties:
  9193. folderID:
  9194. description: The folder to fetch secrets from
  9195. type: string
  9196. required:
  9197. - folderID
  9198. type: object
  9199. type: object
  9200. required:
  9201. - auth
  9202. type: object
  9203. type: object
  9204. refreshInterval:
  9205. anyOf:
  9206. - type: integer
  9207. - type: string
  9208. description: |-
  9209. Used to configure store refresh interval. Accepts either an integer number
  9210. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9211. 0 will default to the controller config.
  9212. x-kubernetes-int-or-string: true
  9213. retrySettings:
  9214. description: Used to configure HTTP retries on failures.
  9215. properties:
  9216. maxRetries:
  9217. format: int32
  9218. type: integer
  9219. retryInterval:
  9220. type: string
  9221. type: object
  9222. required:
  9223. - provider
  9224. type: object
  9225. status:
  9226. description: SecretStoreStatus defines the observed state of the SecretStore.
  9227. properties:
  9228. capabilities:
  9229. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9230. type: string
  9231. conditions:
  9232. items:
  9233. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9234. properties:
  9235. lastTransitionTime:
  9236. format: date-time
  9237. type: string
  9238. message:
  9239. type: string
  9240. reason:
  9241. type: string
  9242. status:
  9243. type: string
  9244. type:
  9245. description: SecretStoreConditionType represents the condition of the SecretStore.
  9246. type: string
  9247. required:
  9248. - status
  9249. - type
  9250. type: object
  9251. type: array
  9252. type: object
  9253. type: object
  9254. served: true
  9255. storage: true
  9256. subresources:
  9257. status: {}
  9258. - additionalPrinterColumns:
  9259. - jsonPath: .metadata.creationTimestamp
  9260. name: AGE
  9261. type: date
  9262. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9263. name: Status
  9264. type: string
  9265. - jsonPath: .status.capabilities
  9266. name: Capabilities
  9267. type: string
  9268. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9269. name: Ready
  9270. type: string
  9271. deprecated: true
  9272. name: v1beta1
  9273. schema:
  9274. openAPIV3Schema:
  9275. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9276. properties:
  9277. apiVersion:
  9278. description: |-
  9279. APIVersion defines the versioned schema of this representation of an object.
  9280. Servers should convert recognized schemas to the latest internal value, and
  9281. may reject unrecognized values.
  9282. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9283. type: string
  9284. kind:
  9285. description: |-
  9286. Kind is a string value representing the REST resource this object represents.
  9287. Servers may infer this from the endpoint the client submits requests to.
  9288. Cannot be updated.
  9289. In CamelCase.
  9290. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9291. type: string
  9292. metadata:
  9293. type: object
  9294. spec:
  9295. description: SecretStoreSpec defines the desired state of SecretStore.
  9296. properties:
  9297. conditions:
  9298. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9299. items:
  9300. description: |-
  9301. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9302. for a ClusterSecretStore instance.
  9303. properties:
  9304. namespaceRegexes:
  9305. description: Choose namespaces by using regex matching
  9306. items:
  9307. type: string
  9308. type: array
  9309. namespaceSelector:
  9310. description: Choose namespace using a labelSelector
  9311. properties:
  9312. matchExpressions:
  9313. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9314. items:
  9315. description: |-
  9316. A label selector requirement is a selector that contains values, a key, and an operator that
  9317. relates the key and values.
  9318. properties:
  9319. key:
  9320. description: key is the label key that the selector applies to.
  9321. type: string
  9322. operator:
  9323. description: |-
  9324. operator represents a key's relationship to a set of values.
  9325. Valid operators are In, NotIn, Exists and DoesNotExist.
  9326. type: string
  9327. values:
  9328. description: |-
  9329. values is an array of string values. If the operator is In or NotIn,
  9330. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9331. the values array must be empty. This array is replaced during a strategic
  9332. merge patch.
  9333. items:
  9334. type: string
  9335. type: array
  9336. x-kubernetes-list-type: atomic
  9337. required:
  9338. - key
  9339. - operator
  9340. type: object
  9341. type: array
  9342. x-kubernetes-list-type: atomic
  9343. matchLabels:
  9344. additionalProperties:
  9345. type: string
  9346. description: |-
  9347. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9348. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9349. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9350. type: object
  9351. type: object
  9352. x-kubernetes-map-type: atomic
  9353. namespaces:
  9354. description: Choose namespaces by name
  9355. items:
  9356. maxLength: 63
  9357. minLength: 1
  9358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9359. type: string
  9360. type: array
  9361. type: object
  9362. type: array
  9363. controller:
  9364. description: |-
  9365. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9366. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9367. type: string
  9368. provider:
  9369. description: Used to configure the provider. Only one provider may be set
  9370. maxProperties: 1
  9371. minProperties: 1
  9372. properties:
  9373. akeyless:
  9374. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9375. properties:
  9376. akeylessGWApiURL:
  9377. description: Akeyless GW API Url from which the secrets to be fetched from.
  9378. type: string
  9379. authSecretRef:
  9380. description: Auth configures how the operator authenticates with Akeyless.
  9381. properties:
  9382. kubernetesAuth:
  9383. description: |-
  9384. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9385. token stored in the named Secret resource.
  9386. properties:
  9387. accessID:
  9388. description: the Akeyless Kubernetes auth-method access-id
  9389. type: string
  9390. k8sConfName:
  9391. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9392. type: string
  9393. secretRef:
  9394. description: |-
  9395. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9396. for authenticating with Akeyless. If a name is specified without a key,
  9397. `token` is the default. If one is not specified, the one bound to
  9398. the controller will be used.
  9399. properties:
  9400. key:
  9401. description: |-
  9402. A key in the referenced Secret.
  9403. Some instances of this field may be defaulted, in others it may be required.
  9404. maxLength: 253
  9405. minLength: 1
  9406. pattern: ^[-._a-zA-Z0-9]+$
  9407. type: string
  9408. name:
  9409. description: The name of the Secret resource being referred to.
  9410. maxLength: 253
  9411. minLength: 1
  9412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9413. type: string
  9414. namespace:
  9415. description: |-
  9416. The namespace of the Secret resource being referred to.
  9417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9418. maxLength: 63
  9419. minLength: 1
  9420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9421. type: string
  9422. type: object
  9423. serviceAccountRef:
  9424. description: |-
  9425. Optional service account field containing the name of a kubernetes ServiceAccount.
  9426. If the service account is specified, the service account secret token JWT will be used
  9427. for authenticating with Akeyless. If the service account selector is not supplied,
  9428. the secretRef will be used instead.
  9429. properties:
  9430. audiences:
  9431. description: |-
  9432. Audience specifies the `aud` claim for the service account token
  9433. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9434. then this audiences will be appended to the list
  9435. items:
  9436. type: string
  9437. type: array
  9438. name:
  9439. description: The name of the ServiceAccount resource being referred to.
  9440. maxLength: 253
  9441. minLength: 1
  9442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9443. type: string
  9444. namespace:
  9445. description: |-
  9446. Namespace of the resource being referred to.
  9447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9448. maxLength: 63
  9449. minLength: 1
  9450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9451. type: string
  9452. required:
  9453. - name
  9454. type: object
  9455. required:
  9456. - accessID
  9457. - k8sConfName
  9458. type: object
  9459. secretRef:
  9460. description: |-
  9461. Reference to a Secret that contains the details
  9462. to authenticate with Akeyless.
  9463. properties:
  9464. accessID:
  9465. description: The SecretAccessID is used for authentication
  9466. properties:
  9467. key:
  9468. description: |-
  9469. A key in the referenced Secret.
  9470. Some instances of this field may be defaulted, in others it may be required.
  9471. maxLength: 253
  9472. minLength: 1
  9473. pattern: ^[-._a-zA-Z0-9]+$
  9474. type: string
  9475. name:
  9476. description: The name of the Secret resource being referred to.
  9477. maxLength: 253
  9478. minLength: 1
  9479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9480. type: string
  9481. namespace:
  9482. description: |-
  9483. The namespace of the Secret resource being referred to.
  9484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9485. maxLength: 63
  9486. minLength: 1
  9487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9488. type: string
  9489. type: object
  9490. accessType:
  9491. description: |-
  9492. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9493. In some instances, `key` is a required field.
  9494. properties:
  9495. key:
  9496. description: |-
  9497. A key in the referenced Secret.
  9498. Some instances of this field may be defaulted, in others it may be required.
  9499. maxLength: 253
  9500. minLength: 1
  9501. pattern: ^[-._a-zA-Z0-9]+$
  9502. type: string
  9503. name:
  9504. description: The name of the Secret resource being referred to.
  9505. maxLength: 253
  9506. minLength: 1
  9507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9508. type: string
  9509. namespace:
  9510. description: |-
  9511. The namespace of the Secret resource being referred to.
  9512. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9513. maxLength: 63
  9514. minLength: 1
  9515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9516. type: string
  9517. type: object
  9518. accessTypeParam:
  9519. description: |-
  9520. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9521. In some instances, `key` is a required field.
  9522. properties:
  9523. key:
  9524. description: |-
  9525. A key in the referenced Secret.
  9526. Some instances of this field may be defaulted, in others it may be required.
  9527. maxLength: 253
  9528. minLength: 1
  9529. pattern: ^[-._a-zA-Z0-9]+$
  9530. type: string
  9531. name:
  9532. description: The name of the Secret resource being referred to.
  9533. maxLength: 253
  9534. minLength: 1
  9535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9536. type: string
  9537. namespace:
  9538. description: |-
  9539. The namespace of the Secret resource being referred to.
  9540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9541. maxLength: 63
  9542. minLength: 1
  9543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9544. type: string
  9545. type: object
  9546. type: object
  9547. type: object
  9548. caBundle:
  9549. description: |-
  9550. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9551. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9552. are used to validate the TLS connection.
  9553. format: byte
  9554. type: string
  9555. caProvider:
  9556. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9557. properties:
  9558. key:
  9559. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9560. maxLength: 253
  9561. minLength: 1
  9562. pattern: ^[-._a-zA-Z0-9]+$
  9563. type: string
  9564. name:
  9565. description: The name of the object located at the provider type.
  9566. maxLength: 253
  9567. minLength: 1
  9568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9569. type: string
  9570. namespace:
  9571. description: |-
  9572. The namespace the Provider type is in.
  9573. Can only be defined when used in a ClusterSecretStore.
  9574. maxLength: 63
  9575. minLength: 1
  9576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9577. type: string
  9578. type:
  9579. description: The type of provider to use such as "Secret", or "ConfigMap".
  9580. enum:
  9581. - Secret
  9582. - ConfigMap
  9583. type: string
  9584. required:
  9585. - name
  9586. - type
  9587. type: object
  9588. required:
  9589. - akeylessGWApiURL
  9590. - authSecretRef
  9591. type: object
  9592. alibaba:
  9593. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9594. properties:
  9595. auth:
  9596. description: AlibabaAuth contains a secretRef for credentials.
  9597. properties:
  9598. rrsa:
  9599. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9600. properties:
  9601. oidcProviderArn:
  9602. type: string
  9603. oidcTokenFilePath:
  9604. type: string
  9605. roleArn:
  9606. type: string
  9607. sessionName:
  9608. type: string
  9609. required:
  9610. - oidcProviderArn
  9611. - oidcTokenFilePath
  9612. - roleArn
  9613. - sessionName
  9614. type: object
  9615. secretRef:
  9616. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9617. properties:
  9618. accessKeyIDSecretRef:
  9619. description: The AccessKeyID is used for authentication
  9620. properties:
  9621. key:
  9622. description: |-
  9623. A key in the referenced Secret.
  9624. Some instances of this field may be defaulted, in others it may be required.
  9625. maxLength: 253
  9626. minLength: 1
  9627. pattern: ^[-._a-zA-Z0-9]+$
  9628. type: string
  9629. name:
  9630. description: The name of the Secret resource being referred to.
  9631. maxLength: 253
  9632. minLength: 1
  9633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9634. type: string
  9635. namespace:
  9636. description: |-
  9637. The namespace of the Secret resource being referred to.
  9638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9639. maxLength: 63
  9640. minLength: 1
  9641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9642. type: string
  9643. type: object
  9644. accessKeySecretSecretRef:
  9645. description: The AccessKeySecret is used for authentication
  9646. properties:
  9647. key:
  9648. description: |-
  9649. A key in the referenced Secret.
  9650. Some instances of this field may be defaulted, in others it may be required.
  9651. maxLength: 253
  9652. minLength: 1
  9653. pattern: ^[-._a-zA-Z0-9]+$
  9654. type: string
  9655. name:
  9656. description: The name of the Secret resource being referred to.
  9657. maxLength: 253
  9658. minLength: 1
  9659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9660. type: string
  9661. namespace:
  9662. description: |-
  9663. The namespace of the Secret resource being referred to.
  9664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9665. maxLength: 63
  9666. minLength: 1
  9667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9668. type: string
  9669. type: object
  9670. required:
  9671. - accessKeyIDSecretRef
  9672. - accessKeySecretSecretRef
  9673. type: object
  9674. type: object
  9675. regionID:
  9676. description: Alibaba Region to be used for the provider
  9677. type: string
  9678. required:
  9679. - auth
  9680. - regionID
  9681. type: object
  9682. aws:
  9683. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9684. properties:
  9685. additionalRoles:
  9686. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9687. items:
  9688. type: string
  9689. type: array
  9690. auth:
  9691. description: |-
  9692. Auth defines the information necessary to authenticate against AWS
  9693. if not set aws sdk will infer credentials from your environment
  9694. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9695. properties:
  9696. jwt:
  9697. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9698. properties:
  9699. serviceAccountRef:
  9700. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9701. properties:
  9702. audiences:
  9703. description: |-
  9704. Audience specifies the `aud` claim for the service account token
  9705. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9706. then this audiences will be appended to the list
  9707. items:
  9708. type: string
  9709. type: array
  9710. name:
  9711. description: The name of the ServiceAccount resource being referred to.
  9712. maxLength: 253
  9713. minLength: 1
  9714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9715. type: string
  9716. namespace:
  9717. description: |-
  9718. Namespace of the resource being referred to.
  9719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9720. maxLength: 63
  9721. minLength: 1
  9722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9723. type: string
  9724. required:
  9725. - name
  9726. type: object
  9727. type: object
  9728. secretRef:
  9729. description: |-
  9730. AWSAuthSecretRef holds secret references for AWS credentials
  9731. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9732. properties:
  9733. accessKeyIDSecretRef:
  9734. description: The AccessKeyID is used for authentication
  9735. properties:
  9736. key:
  9737. description: |-
  9738. A key in the referenced Secret.
  9739. Some instances of this field may be defaulted, in others it may be required.
  9740. maxLength: 253
  9741. minLength: 1
  9742. pattern: ^[-._a-zA-Z0-9]+$
  9743. type: string
  9744. name:
  9745. description: The name of the Secret resource being referred to.
  9746. maxLength: 253
  9747. minLength: 1
  9748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9749. type: string
  9750. namespace:
  9751. description: |-
  9752. The namespace of the Secret resource being referred to.
  9753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9754. maxLength: 63
  9755. minLength: 1
  9756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9757. type: string
  9758. type: object
  9759. secretAccessKeySecretRef:
  9760. description: The SecretAccessKey is used for authentication
  9761. properties:
  9762. key:
  9763. description: |-
  9764. A key in the referenced Secret.
  9765. Some instances of this field may be defaulted, in others it may be required.
  9766. maxLength: 253
  9767. minLength: 1
  9768. pattern: ^[-._a-zA-Z0-9]+$
  9769. type: string
  9770. name:
  9771. description: The name of the Secret resource being referred to.
  9772. maxLength: 253
  9773. minLength: 1
  9774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9775. type: string
  9776. namespace:
  9777. description: |-
  9778. The namespace of the Secret resource being referred to.
  9779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9780. maxLength: 63
  9781. minLength: 1
  9782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9783. type: string
  9784. type: object
  9785. sessionTokenSecretRef:
  9786. description: |-
  9787. The SessionToken used for authentication
  9788. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9789. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9790. properties:
  9791. key:
  9792. description: |-
  9793. A key in the referenced Secret.
  9794. Some instances of this field may be defaulted, in others it may be required.
  9795. maxLength: 253
  9796. minLength: 1
  9797. pattern: ^[-._a-zA-Z0-9]+$
  9798. type: string
  9799. name:
  9800. description: The name of the Secret resource being referred to.
  9801. maxLength: 253
  9802. minLength: 1
  9803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9804. type: string
  9805. namespace:
  9806. description: |-
  9807. The namespace of the Secret resource being referred to.
  9808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9809. maxLength: 63
  9810. minLength: 1
  9811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9812. type: string
  9813. type: object
  9814. type: object
  9815. type: object
  9816. externalID:
  9817. description: AWS External ID set on assumed IAM roles
  9818. type: string
  9819. prefix:
  9820. description: Prefix adds a prefix to all retrieved values.
  9821. type: string
  9822. region:
  9823. description: AWS Region to be used for the provider
  9824. type: string
  9825. role:
  9826. description: Role is a Role ARN which the provider will assume
  9827. type: string
  9828. secretsManager:
  9829. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9830. properties:
  9831. forceDeleteWithoutRecovery:
  9832. description: |-
  9833. Specifies whether to delete the secret without any recovery window. You
  9834. can't use both this parameter and RecoveryWindowInDays in the same call.
  9835. If you don't use either, then by default Secrets Manager uses a 30 day
  9836. recovery window.
  9837. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9838. type: boolean
  9839. recoveryWindowInDays:
  9840. description: |-
  9841. The number of days from 7 to 30 that Secrets Manager waits before
  9842. permanently deleting the secret. You can't use both this parameter and
  9843. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9844. then by default Secrets Manager uses a 30 day recovery window.
  9845. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9846. format: int64
  9847. type: integer
  9848. type: object
  9849. service:
  9850. description: Service defines which service should be used to fetch the secrets
  9851. enum:
  9852. - SecretsManager
  9853. - ParameterStore
  9854. type: string
  9855. sessionTags:
  9856. description: AWS STS assume role session tags
  9857. items:
  9858. description: Tag defines a tag key and value for AWS resources.
  9859. properties:
  9860. key:
  9861. type: string
  9862. value:
  9863. type: string
  9864. required:
  9865. - key
  9866. - value
  9867. type: object
  9868. type: array
  9869. transitiveTagKeys:
  9870. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9871. items:
  9872. type: string
  9873. type: array
  9874. required:
  9875. - region
  9876. - service
  9877. type: object
  9878. azurekv:
  9879. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9880. properties:
  9881. authSecretRef:
  9882. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9883. properties:
  9884. clientCertificate:
  9885. description: The Azure ClientCertificate of the service principle used for authentication.
  9886. properties:
  9887. key:
  9888. description: |-
  9889. A key in the referenced Secret.
  9890. Some instances of this field may be defaulted, in others it may be required.
  9891. maxLength: 253
  9892. minLength: 1
  9893. pattern: ^[-._a-zA-Z0-9]+$
  9894. type: string
  9895. name:
  9896. description: The name of the Secret resource being referred to.
  9897. maxLength: 253
  9898. minLength: 1
  9899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9900. type: string
  9901. namespace:
  9902. description: |-
  9903. The namespace of the Secret resource being referred to.
  9904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9905. maxLength: 63
  9906. minLength: 1
  9907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9908. type: string
  9909. type: object
  9910. clientId:
  9911. description: The Azure clientId of the service principle or managed identity used for authentication.
  9912. properties:
  9913. key:
  9914. description: |-
  9915. A key in the referenced Secret.
  9916. Some instances of this field may be defaulted, in others it may be required.
  9917. maxLength: 253
  9918. minLength: 1
  9919. pattern: ^[-._a-zA-Z0-9]+$
  9920. type: string
  9921. name:
  9922. description: The name of the Secret resource being referred to.
  9923. maxLength: 253
  9924. minLength: 1
  9925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9926. type: string
  9927. namespace:
  9928. description: |-
  9929. The namespace of the Secret resource being referred to.
  9930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9931. maxLength: 63
  9932. minLength: 1
  9933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9934. type: string
  9935. type: object
  9936. clientSecret:
  9937. description: The Azure ClientSecret of the service principle used for authentication.
  9938. properties:
  9939. key:
  9940. description: |-
  9941. A key in the referenced Secret.
  9942. Some instances of this field may be defaulted, in others it may be required.
  9943. maxLength: 253
  9944. minLength: 1
  9945. pattern: ^[-._a-zA-Z0-9]+$
  9946. type: string
  9947. name:
  9948. description: The name of the Secret resource being referred to.
  9949. maxLength: 253
  9950. minLength: 1
  9951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9952. type: string
  9953. namespace:
  9954. description: |-
  9955. The namespace of the Secret resource being referred to.
  9956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9957. maxLength: 63
  9958. minLength: 1
  9959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9960. type: string
  9961. type: object
  9962. tenantId:
  9963. description: The Azure tenantId of the managed identity used for authentication.
  9964. properties:
  9965. key:
  9966. description: |-
  9967. A key in the referenced Secret.
  9968. Some instances of this field may be defaulted, in others it may be required.
  9969. maxLength: 253
  9970. minLength: 1
  9971. pattern: ^[-._a-zA-Z0-9]+$
  9972. type: string
  9973. name:
  9974. description: The name of the Secret resource being referred to.
  9975. maxLength: 253
  9976. minLength: 1
  9977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9978. type: string
  9979. namespace:
  9980. description: |-
  9981. The namespace of the Secret resource being referred to.
  9982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9983. maxLength: 63
  9984. minLength: 1
  9985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9986. type: string
  9987. type: object
  9988. type: object
  9989. authType:
  9990. default: ServicePrincipal
  9991. description: |-
  9992. Auth type defines how to authenticate to the keyvault service.
  9993. Valid values are:
  9994. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  9995. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  9996. enum:
  9997. - ServicePrincipal
  9998. - ManagedIdentity
  9999. - WorkloadIdentity
  10000. type: string
  10001. environmentType:
  10002. default: PublicCloud
  10003. description: |-
  10004. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10005. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10006. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10007. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10008. enum:
  10009. - PublicCloud
  10010. - USGovernmentCloud
  10011. - ChinaCloud
  10012. - GermanCloud
  10013. type: string
  10014. identityId:
  10015. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10016. type: string
  10017. serviceAccountRef:
  10018. description: |-
  10019. ServiceAccountRef specified the service account
  10020. that should be used when authenticating with WorkloadIdentity.
  10021. properties:
  10022. audiences:
  10023. description: |-
  10024. Audience specifies the `aud` claim for the service account token
  10025. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10026. then this audiences will be appended to the list
  10027. items:
  10028. type: string
  10029. type: array
  10030. name:
  10031. description: The name of the ServiceAccount resource being referred to.
  10032. maxLength: 253
  10033. minLength: 1
  10034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10035. type: string
  10036. namespace:
  10037. description: |-
  10038. Namespace of the resource being referred to.
  10039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10040. maxLength: 63
  10041. minLength: 1
  10042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10043. type: string
  10044. required:
  10045. - name
  10046. type: object
  10047. tenantId:
  10048. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10049. type: string
  10050. vaultUrl:
  10051. description: Vault Url from which the secrets to be fetched from.
  10052. type: string
  10053. required:
  10054. - vaultUrl
  10055. type: object
  10056. beyondtrust:
  10057. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10058. properties:
  10059. auth:
  10060. description: Auth configures how the operator authenticates with Beyondtrust.
  10061. properties:
  10062. apiKey:
  10063. description: APIKey If not provided then ClientID/ClientSecret become required.
  10064. properties:
  10065. secretRef:
  10066. description: SecretRef references a key in a secret that will be used as value.
  10067. properties:
  10068. key:
  10069. description: |-
  10070. A key in the referenced Secret.
  10071. Some instances of this field may be defaulted, in others it may be required.
  10072. maxLength: 253
  10073. minLength: 1
  10074. pattern: ^[-._a-zA-Z0-9]+$
  10075. type: string
  10076. name:
  10077. description: The name of the Secret resource being referred to.
  10078. maxLength: 253
  10079. minLength: 1
  10080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10081. type: string
  10082. namespace:
  10083. description: |-
  10084. The namespace of the Secret resource being referred to.
  10085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10086. maxLength: 63
  10087. minLength: 1
  10088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10089. type: string
  10090. type: object
  10091. value:
  10092. description: Value can be specified directly to set a value without using a secret.
  10093. type: string
  10094. type: object
  10095. certificate:
  10096. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10097. properties:
  10098. secretRef:
  10099. description: SecretRef references a key in a secret that will be used as value.
  10100. properties:
  10101. key:
  10102. description: |-
  10103. A key in the referenced Secret.
  10104. Some instances of this field may be defaulted, in others it may be required.
  10105. maxLength: 253
  10106. minLength: 1
  10107. pattern: ^[-._a-zA-Z0-9]+$
  10108. type: string
  10109. name:
  10110. description: The name of the Secret resource being referred to.
  10111. maxLength: 253
  10112. minLength: 1
  10113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10114. type: string
  10115. namespace:
  10116. description: |-
  10117. The namespace of the Secret resource being referred to.
  10118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10119. maxLength: 63
  10120. minLength: 1
  10121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10122. type: string
  10123. type: object
  10124. value:
  10125. description: Value can be specified directly to set a value without using a secret.
  10126. type: string
  10127. type: object
  10128. certificateKey:
  10129. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10130. properties:
  10131. secretRef:
  10132. description: SecretRef references a key in a secret that will be used as value.
  10133. properties:
  10134. key:
  10135. description: |-
  10136. A key in the referenced Secret.
  10137. Some instances of this field may be defaulted, in others it may be required.
  10138. maxLength: 253
  10139. minLength: 1
  10140. pattern: ^[-._a-zA-Z0-9]+$
  10141. type: string
  10142. name:
  10143. description: The name of the Secret resource being referred to.
  10144. maxLength: 253
  10145. minLength: 1
  10146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10147. type: string
  10148. namespace:
  10149. description: |-
  10150. The namespace of the Secret resource being referred to.
  10151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10152. maxLength: 63
  10153. minLength: 1
  10154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10155. type: string
  10156. type: object
  10157. value:
  10158. description: Value can be specified directly to set a value without using a secret.
  10159. type: string
  10160. type: object
  10161. clientId:
  10162. description: ClientID is the API OAuth Client ID.
  10163. properties:
  10164. secretRef:
  10165. description: SecretRef references a key in a secret that will be used as value.
  10166. properties:
  10167. key:
  10168. description: |-
  10169. A key in the referenced Secret.
  10170. Some instances of this field may be defaulted, in others it may be required.
  10171. maxLength: 253
  10172. minLength: 1
  10173. pattern: ^[-._a-zA-Z0-9]+$
  10174. type: string
  10175. name:
  10176. description: The name of the Secret resource being referred to.
  10177. maxLength: 253
  10178. minLength: 1
  10179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10180. type: string
  10181. namespace:
  10182. description: |-
  10183. The namespace of the Secret resource being referred to.
  10184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10185. maxLength: 63
  10186. minLength: 1
  10187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10188. type: string
  10189. type: object
  10190. value:
  10191. description: Value can be specified directly to set a value without using a secret.
  10192. type: string
  10193. type: object
  10194. clientSecret:
  10195. description: ClientSecret is the API OAuth Client Secret.
  10196. properties:
  10197. secretRef:
  10198. description: SecretRef references a key in a secret that will be used as value.
  10199. properties:
  10200. key:
  10201. description: |-
  10202. A key in the referenced Secret.
  10203. Some instances of this field may be defaulted, in others it may be required.
  10204. maxLength: 253
  10205. minLength: 1
  10206. pattern: ^[-._a-zA-Z0-9]+$
  10207. type: string
  10208. name:
  10209. description: The name of the Secret resource being referred to.
  10210. maxLength: 253
  10211. minLength: 1
  10212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10213. type: string
  10214. namespace:
  10215. description: |-
  10216. The namespace of the Secret resource being referred to.
  10217. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10218. maxLength: 63
  10219. minLength: 1
  10220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10221. type: string
  10222. type: object
  10223. value:
  10224. description: Value can be specified directly to set a value without using a secret.
  10225. type: string
  10226. type: object
  10227. type: object
  10228. server:
  10229. description: Auth configures how API server works.
  10230. properties:
  10231. apiUrl:
  10232. type: string
  10233. apiVersion:
  10234. type: string
  10235. clientTimeOutSeconds:
  10236. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10237. type: integer
  10238. decrypt:
  10239. default: true
  10240. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10241. type: boolean
  10242. retrievalType:
  10243. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10244. type: string
  10245. separator:
  10246. description: A character that separates the folder names.
  10247. type: string
  10248. verifyCA:
  10249. type: boolean
  10250. required:
  10251. - apiUrl
  10252. - verifyCA
  10253. type: object
  10254. required:
  10255. - auth
  10256. - server
  10257. type: object
  10258. bitwardensecretsmanager:
  10259. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10260. properties:
  10261. apiURL:
  10262. type: string
  10263. auth:
  10264. description: |-
  10265. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10266. Make sure that the token being used has permissions on the given secret.
  10267. properties:
  10268. secretRef:
  10269. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10270. properties:
  10271. credentials:
  10272. description: AccessToken used for the bitwarden instance.
  10273. properties:
  10274. key:
  10275. description: |-
  10276. A key in the referenced Secret.
  10277. Some instances of this field may be defaulted, in others it may be required.
  10278. maxLength: 253
  10279. minLength: 1
  10280. pattern: ^[-._a-zA-Z0-9]+$
  10281. type: string
  10282. name:
  10283. description: The name of the Secret resource being referred to.
  10284. maxLength: 253
  10285. minLength: 1
  10286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10287. type: string
  10288. namespace:
  10289. description: |-
  10290. The namespace of the Secret resource being referred to.
  10291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10292. maxLength: 63
  10293. minLength: 1
  10294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10295. type: string
  10296. type: object
  10297. required:
  10298. - credentials
  10299. type: object
  10300. required:
  10301. - secretRef
  10302. type: object
  10303. bitwardenServerSDKURL:
  10304. type: string
  10305. caBundle:
  10306. description: |-
  10307. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10308. can be performed.
  10309. type: string
  10310. caProvider:
  10311. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10312. properties:
  10313. key:
  10314. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10315. maxLength: 253
  10316. minLength: 1
  10317. pattern: ^[-._a-zA-Z0-9]+$
  10318. type: string
  10319. name:
  10320. description: The name of the object located at the provider type.
  10321. maxLength: 253
  10322. minLength: 1
  10323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10324. type: string
  10325. namespace:
  10326. description: |-
  10327. The namespace the Provider type is in.
  10328. Can only be defined when used in a ClusterSecretStore.
  10329. maxLength: 63
  10330. minLength: 1
  10331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10332. type: string
  10333. type:
  10334. description: The type of provider to use such as "Secret", or "ConfigMap".
  10335. enum:
  10336. - Secret
  10337. - ConfigMap
  10338. type: string
  10339. required:
  10340. - name
  10341. - type
  10342. type: object
  10343. identityURL:
  10344. type: string
  10345. organizationID:
  10346. description: OrganizationID determines which organization this secret store manages.
  10347. type: string
  10348. projectID:
  10349. description: ProjectID determines which project this secret store manages.
  10350. type: string
  10351. required:
  10352. - auth
  10353. - organizationID
  10354. - projectID
  10355. type: object
  10356. chef:
  10357. description: Chef configures this store to sync secrets with chef server
  10358. properties:
  10359. auth:
  10360. description: Auth defines the information necessary to authenticate against chef Server
  10361. properties:
  10362. secretRef:
  10363. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10364. properties:
  10365. privateKeySecretRef:
  10366. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10367. properties:
  10368. key:
  10369. description: |-
  10370. A key in the referenced Secret.
  10371. Some instances of this field may be defaulted, in others it may be required.
  10372. maxLength: 253
  10373. minLength: 1
  10374. pattern: ^[-._a-zA-Z0-9]+$
  10375. type: string
  10376. name:
  10377. description: The name of the Secret resource being referred to.
  10378. maxLength: 253
  10379. minLength: 1
  10380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10381. type: string
  10382. namespace:
  10383. description: |-
  10384. The namespace of the Secret resource being referred to.
  10385. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10386. maxLength: 63
  10387. minLength: 1
  10388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10389. type: string
  10390. type: object
  10391. required:
  10392. - privateKeySecretRef
  10393. type: object
  10394. required:
  10395. - secretRef
  10396. type: object
  10397. serverUrl:
  10398. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10399. type: string
  10400. username:
  10401. description: UserName should be the user ID on the chef server
  10402. type: string
  10403. required:
  10404. - auth
  10405. - serverUrl
  10406. - username
  10407. type: object
  10408. cloudrusm:
  10409. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10410. properties:
  10411. auth:
  10412. description: CSMAuth contains a secretRef for credentials.
  10413. properties:
  10414. secretRef:
  10415. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10416. properties:
  10417. accessKeyIDSecretRef:
  10418. description: The AccessKeyID is used for authentication
  10419. properties:
  10420. key:
  10421. description: |-
  10422. A key in the referenced Secret.
  10423. Some instances of this field may be defaulted, in others it may be required.
  10424. maxLength: 253
  10425. minLength: 1
  10426. pattern: ^[-._a-zA-Z0-9]+$
  10427. type: string
  10428. name:
  10429. description: The name of the Secret resource being referred to.
  10430. maxLength: 253
  10431. minLength: 1
  10432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10433. type: string
  10434. namespace:
  10435. description: |-
  10436. The namespace of the Secret resource being referred to.
  10437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10438. maxLength: 63
  10439. minLength: 1
  10440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10441. type: string
  10442. type: object
  10443. accessKeySecretSecretRef:
  10444. description: The AccessKeySecret is used for authentication
  10445. properties:
  10446. key:
  10447. description: |-
  10448. A key in the referenced Secret.
  10449. Some instances of this field may be defaulted, in others it may be required.
  10450. maxLength: 253
  10451. minLength: 1
  10452. pattern: ^[-._a-zA-Z0-9]+$
  10453. type: string
  10454. name:
  10455. description: The name of the Secret resource being referred to.
  10456. maxLength: 253
  10457. minLength: 1
  10458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10459. type: string
  10460. namespace:
  10461. description: |-
  10462. The namespace of the Secret resource being referred to.
  10463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10464. maxLength: 63
  10465. minLength: 1
  10466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10467. type: string
  10468. type: object
  10469. required:
  10470. - accessKeyIDSecretRef
  10471. - accessKeySecretSecretRef
  10472. type: object
  10473. type: object
  10474. projectID:
  10475. description: ProjectID is the project, which the secrets are stored in.
  10476. type: string
  10477. required:
  10478. - auth
  10479. type: object
  10480. conjur:
  10481. description: Conjur configures this store to sync secrets using conjur provider
  10482. properties:
  10483. auth:
  10484. description: Defines authentication settings for connecting to Conjur.
  10485. properties:
  10486. apikey:
  10487. description: Authenticates with Conjur using an API key.
  10488. properties:
  10489. account:
  10490. description: Account is the Conjur organization account name.
  10491. type: string
  10492. apiKeyRef:
  10493. description: |-
  10494. A reference to a specific 'key' containing the Conjur API key
  10495. within a Secret resource. In some instances, `key` is a required field.
  10496. properties:
  10497. key:
  10498. description: |-
  10499. A key in the referenced Secret.
  10500. Some instances of this field may be defaulted, in others it may be required.
  10501. maxLength: 253
  10502. minLength: 1
  10503. pattern: ^[-._a-zA-Z0-9]+$
  10504. type: string
  10505. name:
  10506. description: The name of the Secret resource being referred to.
  10507. maxLength: 253
  10508. minLength: 1
  10509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10510. type: string
  10511. namespace:
  10512. description: |-
  10513. The namespace of the Secret resource being referred to.
  10514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10515. maxLength: 63
  10516. minLength: 1
  10517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10518. type: string
  10519. type: object
  10520. userRef:
  10521. description: |-
  10522. A reference to a specific 'key' containing the Conjur username
  10523. within a Secret resource. In some instances, `key` is a required field.
  10524. properties:
  10525. key:
  10526. description: |-
  10527. A key in the referenced Secret.
  10528. Some instances of this field may be defaulted, in others it may be required.
  10529. maxLength: 253
  10530. minLength: 1
  10531. pattern: ^[-._a-zA-Z0-9]+$
  10532. type: string
  10533. name:
  10534. description: The name of the Secret resource being referred to.
  10535. maxLength: 253
  10536. minLength: 1
  10537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10538. type: string
  10539. namespace:
  10540. description: |-
  10541. The namespace of the Secret resource being referred to.
  10542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10543. maxLength: 63
  10544. minLength: 1
  10545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10546. type: string
  10547. type: object
  10548. required:
  10549. - account
  10550. - apiKeyRef
  10551. - userRef
  10552. type: object
  10553. jwt:
  10554. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10555. properties:
  10556. account:
  10557. description: Account is the Conjur organization account name.
  10558. type: string
  10559. hostId:
  10560. description: |-
  10561. Optional HostID for JWT authentication. This may be used depending
  10562. on how the Conjur JWT authenticator policy is configured.
  10563. type: string
  10564. secretRef:
  10565. description: |-
  10566. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10567. authenticate with Conjur using the JWT authentication method.
  10568. properties:
  10569. key:
  10570. description: |-
  10571. A key in the referenced Secret.
  10572. Some instances of this field may be defaulted, in others it may be required.
  10573. maxLength: 253
  10574. minLength: 1
  10575. pattern: ^[-._a-zA-Z0-9]+$
  10576. type: string
  10577. name:
  10578. description: The name of the Secret resource being referred to.
  10579. maxLength: 253
  10580. minLength: 1
  10581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10582. type: string
  10583. namespace:
  10584. description: |-
  10585. The namespace of the Secret resource being referred to.
  10586. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10587. maxLength: 63
  10588. minLength: 1
  10589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10590. type: string
  10591. type: object
  10592. serviceAccountRef:
  10593. description: |-
  10594. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10595. a token for with the `TokenRequest` API.
  10596. properties:
  10597. audiences:
  10598. description: |-
  10599. Audience specifies the `aud` claim for the service account token
  10600. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10601. then this audiences will be appended to the list
  10602. items:
  10603. type: string
  10604. type: array
  10605. name:
  10606. description: The name of the ServiceAccount resource being referred to.
  10607. maxLength: 253
  10608. minLength: 1
  10609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10610. type: string
  10611. namespace:
  10612. description: |-
  10613. Namespace of the resource being referred to.
  10614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10615. maxLength: 63
  10616. minLength: 1
  10617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10618. type: string
  10619. required:
  10620. - name
  10621. type: object
  10622. serviceID:
  10623. description: The conjur authn jwt webservice id
  10624. type: string
  10625. required:
  10626. - account
  10627. - serviceID
  10628. type: object
  10629. type: object
  10630. caBundle:
  10631. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10632. type: string
  10633. caProvider:
  10634. description: |-
  10635. Used to provide custom certificate authority (CA) certificates
  10636. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10637. that contains a PEM-encoded certificate.
  10638. properties:
  10639. key:
  10640. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10641. maxLength: 253
  10642. minLength: 1
  10643. pattern: ^[-._a-zA-Z0-9]+$
  10644. type: string
  10645. name:
  10646. description: The name of the object located at the provider type.
  10647. maxLength: 253
  10648. minLength: 1
  10649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10650. type: string
  10651. namespace:
  10652. description: |-
  10653. The namespace the Provider type is in.
  10654. Can only be defined when used in a ClusterSecretStore.
  10655. maxLength: 63
  10656. minLength: 1
  10657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10658. type: string
  10659. type:
  10660. description: The type of provider to use such as "Secret", or "ConfigMap".
  10661. enum:
  10662. - Secret
  10663. - ConfigMap
  10664. type: string
  10665. required:
  10666. - name
  10667. - type
  10668. type: object
  10669. url:
  10670. description: URL is the endpoint of the Conjur instance.
  10671. type: string
  10672. required:
  10673. - auth
  10674. - url
  10675. type: object
  10676. delinea:
  10677. description: |-
  10678. Delinea DevOps Secrets Vault
  10679. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10680. properties:
  10681. clientId:
  10682. description: ClientID is the non-secret part of the credential.
  10683. properties:
  10684. secretRef:
  10685. description: SecretRef references a key in a secret that will be used as value.
  10686. properties:
  10687. key:
  10688. description: |-
  10689. A key in the referenced Secret.
  10690. Some instances of this field may be defaulted, in others it may be required.
  10691. maxLength: 253
  10692. minLength: 1
  10693. pattern: ^[-._a-zA-Z0-9]+$
  10694. type: string
  10695. name:
  10696. description: The name of the Secret resource being referred to.
  10697. maxLength: 253
  10698. minLength: 1
  10699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10700. type: string
  10701. namespace:
  10702. description: |-
  10703. The namespace of the Secret resource being referred to.
  10704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10705. maxLength: 63
  10706. minLength: 1
  10707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10708. type: string
  10709. type: object
  10710. value:
  10711. description: Value can be specified directly to set a value without using a secret.
  10712. type: string
  10713. type: object
  10714. clientSecret:
  10715. description: ClientSecret is the secret part of the credential.
  10716. properties:
  10717. secretRef:
  10718. description: SecretRef references a key in a secret that will be used as value.
  10719. properties:
  10720. key:
  10721. description: |-
  10722. A key in the referenced Secret.
  10723. Some instances of this field may be defaulted, in others it may be required.
  10724. maxLength: 253
  10725. minLength: 1
  10726. pattern: ^[-._a-zA-Z0-9]+$
  10727. type: string
  10728. name:
  10729. description: The name of the Secret resource being referred to.
  10730. maxLength: 253
  10731. minLength: 1
  10732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10733. type: string
  10734. namespace:
  10735. description: |-
  10736. The namespace of the Secret resource being referred to.
  10737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10738. maxLength: 63
  10739. minLength: 1
  10740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10741. type: string
  10742. type: object
  10743. value:
  10744. description: Value can be specified directly to set a value without using a secret.
  10745. type: string
  10746. type: object
  10747. tenant:
  10748. description: Tenant is the chosen hostname / site name.
  10749. type: string
  10750. tld:
  10751. description: |-
  10752. TLD is based on the server location that was chosen during provisioning.
  10753. If unset, defaults to "com".
  10754. type: string
  10755. urlTemplate:
  10756. description: |-
  10757. URLTemplate
  10758. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10759. type: string
  10760. required:
  10761. - clientId
  10762. - clientSecret
  10763. - tenant
  10764. type: object
  10765. device42:
  10766. description: Device42 configures this store to sync secrets using the Device42 provider
  10767. properties:
  10768. auth:
  10769. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10770. properties:
  10771. secretRef:
  10772. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10773. properties:
  10774. credentials:
  10775. description: Username / Password is used for authentication.
  10776. properties:
  10777. key:
  10778. description: |-
  10779. A key in the referenced Secret.
  10780. Some instances of this field may be defaulted, in others it may be required.
  10781. maxLength: 253
  10782. minLength: 1
  10783. pattern: ^[-._a-zA-Z0-9]+$
  10784. type: string
  10785. name:
  10786. description: The name of the Secret resource being referred to.
  10787. maxLength: 253
  10788. minLength: 1
  10789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10790. type: string
  10791. namespace:
  10792. description: |-
  10793. The namespace of the Secret resource being referred to.
  10794. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10795. maxLength: 63
  10796. minLength: 1
  10797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10798. type: string
  10799. type: object
  10800. type: object
  10801. required:
  10802. - secretRef
  10803. type: object
  10804. host:
  10805. description: URL configures the Device42 instance URL.
  10806. type: string
  10807. required:
  10808. - auth
  10809. - host
  10810. type: object
  10811. doppler:
  10812. description: Doppler configures this store to sync secrets using the Doppler provider
  10813. properties:
  10814. auth:
  10815. description: Auth configures how the Operator authenticates with the Doppler API
  10816. properties:
  10817. secretRef:
  10818. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10819. properties:
  10820. dopplerToken:
  10821. description: |-
  10822. The DopplerToken is used for authentication.
  10823. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10824. The Key attribute defaults to dopplerToken if not specified.
  10825. properties:
  10826. key:
  10827. description: |-
  10828. A key in the referenced Secret.
  10829. Some instances of this field may be defaulted, in others it may be required.
  10830. maxLength: 253
  10831. minLength: 1
  10832. pattern: ^[-._a-zA-Z0-9]+$
  10833. type: string
  10834. name:
  10835. description: The name of the Secret resource being referred to.
  10836. maxLength: 253
  10837. minLength: 1
  10838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10839. type: string
  10840. namespace:
  10841. description: |-
  10842. The namespace of the Secret resource being referred to.
  10843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10844. maxLength: 63
  10845. minLength: 1
  10846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10847. type: string
  10848. type: object
  10849. required:
  10850. - dopplerToken
  10851. type: object
  10852. required:
  10853. - secretRef
  10854. type: object
  10855. config:
  10856. description: Doppler config (required if not using a Service Token)
  10857. type: string
  10858. format:
  10859. description: Format enables the downloading of secrets as a file (string)
  10860. enum:
  10861. - json
  10862. - dotnet-json
  10863. - env
  10864. - yaml
  10865. - docker
  10866. type: string
  10867. nameTransformer:
  10868. description: Environment variable compatible name transforms that change secret names to a different format
  10869. enum:
  10870. - upper-camel
  10871. - camel
  10872. - lower-snake
  10873. - tf-var
  10874. - dotnet-env
  10875. - lower-kebab
  10876. type: string
  10877. project:
  10878. description: Doppler project (required if not using a Service Token)
  10879. type: string
  10880. required:
  10881. - auth
  10882. type: object
  10883. fake:
  10884. description: Fake configures a store with static key/value pairs
  10885. properties:
  10886. data:
  10887. items:
  10888. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10889. properties:
  10890. key:
  10891. type: string
  10892. value:
  10893. type: string
  10894. version:
  10895. type: string
  10896. required:
  10897. - key
  10898. - value
  10899. type: object
  10900. type: array
  10901. required:
  10902. - data
  10903. type: object
  10904. fortanix:
  10905. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10906. properties:
  10907. apiKey:
  10908. description: APIKey is the API token to access SDKMS Applications.
  10909. properties:
  10910. secretRef:
  10911. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10912. properties:
  10913. key:
  10914. description: |-
  10915. A key in the referenced Secret.
  10916. Some instances of this field may be defaulted, in others it may be required.
  10917. maxLength: 253
  10918. minLength: 1
  10919. pattern: ^[-._a-zA-Z0-9]+$
  10920. type: string
  10921. name:
  10922. description: The name of the Secret resource being referred to.
  10923. maxLength: 253
  10924. minLength: 1
  10925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10926. type: string
  10927. namespace:
  10928. description: |-
  10929. The namespace of the Secret resource being referred to.
  10930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10931. maxLength: 63
  10932. minLength: 1
  10933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10934. type: string
  10935. type: object
  10936. type: object
  10937. apiUrl:
  10938. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10939. type: string
  10940. type: object
  10941. gcpsm:
  10942. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10943. properties:
  10944. auth:
  10945. description: Auth defines the information necessary to authenticate against GCP
  10946. properties:
  10947. secretRef:
  10948. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10949. properties:
  10950. secretAccessKeySecretRef:
  10951. description: The SecretAccessKey is used for authentication
  10952. properties:
  10953. key:
  10954. description: |-
  10955. A key in the referenced Secret.
  10956. Some instances of this field may be defaulted, in others it may be required.
  10957. maxLength: 253
  10958. minLength: 1
  10959. pattern: ^[-._a-zA-Z0-9]+$
  10960. type: string
  10961. name:
  10962. description: The name of the Secret resource being referred to.
  10963. maxLength: 253
  10964. minLength: 1
  10965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10966. type: string
  10967. namespace:
  10968. description: |-
  10969. The namespace of the Secret resource being referred to.
  10970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10971. maxLength: 63
  10972. minLength: 1
  10973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10974. type: string
  10975. type: object
  10976. type: object
  10977. workloadIdentity:
  10978. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10979. properties:
  10980. clusterLocation:
  10981. description: |-
  10982. ClusterLocation is the location of the cluster
  10983. If not specified, it fetches information from the metadata server
  10984. type: string
  10985. clusterName:
  10986. description: |-
  10987. ClusterName is the name of the cluster
  10988. If not specified, it fetches information from the metadata server
  10989. type: string
  10990. clusterProjectID:
  10991. description: |-
  10992. ClusterProjectID is the project ID of the cluster
  10993. If not specified, it fetches information from the metadata server
  10994. type: string
  10995. serviceAccountRef:
  10996. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  10997. properties:
  10998. audiences:
  10999. description: |-
  11000. Audience specifies the `aud` claim for the service account token
  11001. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11002. then this audiences will be appended to the list
  11003. items:
  11004. type: string
  11005. type: array
  11006. name:
  11007. description: The name of the ServiceAccount resource being referred to.
  11008. maxLength: 253
  11009. minLength: 1
  11010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11011. type: string
  11012. namespace:
  11013. description: |-
  11014. Namespace of the resource being referred to.
  11015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11016. maxLength: 63
  11017. minLength: 1
  11018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11019. type: string
  11020. required:
  11021. - name
  11022. type: object
  11023. required:
  11024. - serviceAccountRef
  11025. type: object
  11026. type: object
  11027. location:
  11028. description: Location optionally defines a location for a secret
  11029. type: string
  11030. projectID:
  11031. description: ProjectID project where secret is located
  11032. type: string
  11033. type: object
  11034. github:
  11035. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11036. properties:
  11037. appID:
  11038. description: appID specifies the Github APP that will be used to authenticate the client
  11039. format: int64
  11040. type: integer
  11041. auth:
  11042. description: auth configures how secret-manager authenticates with a Github instance.
  11043. properties:
  11044. privateKey:
  11045. description: |-
  11046. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11047. In some instances, `key` is a required field.
  11048. properties:
  11049. key:
  11050. description: |-
  11051. A key in the referenced Secret.
  11052. Some instances of this field may be defaulted, in others it may be required.
  11053. maxLength: 253
  11054. minLength: 1
  11055. pattern: ^[-._a-zA-Z0-9]+$
  11056. type: string
  11057. name:
  11058. description: The name of the Secret resource being referred to.
  11059. maxLength: 253
  11060. minLength: 1
  11061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11062. type: string
  11063. namespace:
  11064. description: |-
  11065. The namespace of the Secret resource being referred to.
  11066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11067. maxLength: 63
  11068. minLength: 1
  11069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11070. type: string
  11071. type: object
  11072. required:
  11073. - privateKey
  11074. type: object
  11075. environment:
  11076. description: environment will be used to fetch secrets from a particular environment within a github repository
  11077. type: string
  11078. installationID:
  11079. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11080. format: int64
  11081. type: integer
  11082. organization:
  11083. description: organization will be used to fetch secrets from the Github organization
  11084. type: string
  11085. repository:
  11086. description: repository will be used to fetch secrets from the Github repository within an organization
  11087. type: string
  11088. uploadURL:
  11089. description: Upload URL for enterprise instances. Default to URL.
  11090. type: string
  11091. url:
  11092. default: https://github.com/
  11093. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11094. type: string
  11095. required:
  11096. - appID
  11097. - auth
  11098. - installationID
  11099. - organization
  11100. type: object
  11101. gitlab:
  11102. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11103. properties:
  11104. auth:
  11105. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11106. properties:
  11107. SecretRef:
  11108. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11109. properties:
  11110. accessToken:
  11111. description: AccessToken is used for authentication.
  11112. properties:
  11113. key:
  11114. description: |-
  11115. A key in the referenced Secret.
  11116. Some instances of this field may be defaulted, in others it may be required.
  11117. maxLength: 253
  11118. minLength: 1
  11119. pattern: ^[-._a-zA-Z0-9]+$
  11120. type: string
  11121. name:
  11122. description: The name of the Secret resource being referred to.
  11123. maxLength: 253
  11124. minLength: 1
  11125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11126. type: string
  11127. namespace:
  11128. description: |-
  11129. The namespace of the Secret resource being referred to.
  11130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11131. maxLength: 63
  11132. minLength: 1
  11133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11134. type: string
  11135. type: object
  11136. type: object
  11137. required:
  11138. - SecretRef
  11139. type: object
  11140. caBundle:
  11141. description: |-
  11142. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11143. can be performed.
  11144. format: byte
  11145. type: string
  11146. caProvider:
  11147. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11148. properties:
  11149. key:
  11150. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11151. maxLength: 253
  11152. minLength: 1
  11153. pattern: ^[-._a-zA-Z0-9]+$
  11154. type: string
  11155. name:
  11156. description: The name of the object located at the provider type.
  11157. maxLength: 253
  11158. minLength: 1
  11159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11160. type: string
  11161. namespace:
  11162. description: |-
  11163. The namespace the Provider type is in.
  11164. Can only be defined when used in a ClusterSecretStore.
  11165. maxLength: 63
  11166. minLength: 1
  11167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11168. type: string
  11169. type:
  11170. description: The type of provider to use such as "Secret", or "ConfigMap".
  11171. enum:
  11172. - Secret
  11173. - ConfigMap
  11174. type: string
  11175. required:
  11176. - name
  11177. - type
  11178. type: object
  11179. environment:
  11180. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11181. type: string
  11182. groupIDs:
  11183. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11184. items:
  11185. type: string
  11186. type: array
  11187. inheritFromGroups:
  11188. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11189. type: boolean
  11190. projectID:
  11191. description: ProjectID specifies a project where secrets are located.
  11192. type: string
  11193. url:
  11194. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11195. type: string
  11196. required:
  11197. - auth
  11198. type: object
  11199. ibm:
  11200. description: IBM configures this store to sync secrets using IBM Cloud provider
  11201. properties:
  11202. auth:
  11203. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11204. maxProperties: 1
  11205. minProperties: 1
  11206. properties:
  11207. containerAuth:
  11208. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11209. properties:
  11210. iamEndpoint:
  11211. type: string
  11212. profile:
  11213. description: the IBM Trusted Profile
  11214. type: string
  11215. tokenLocation:
  11216. description: Location the token is mounted on the pod
  11217. type: string
  11218. required:
  11219. - profile
  11220. type: object
  11221. secretRef:
  11222. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11223. properties:
  11224. secretApiKeySecretRef:
  11225. description: The SecretAccessKey is used for authentication
  11226. properties:
  11227. key:
  11228. description: |-
  11229. A key in the referenced Secret.
  11230. Some instances of this field may be defaulted, in others it may be required.
  11231. maxLength: 253
  11232. minLength: 1
  11233. pattern: ^[-._a-zA-Z0-9]+$
  11234. type: string
  11235. name:
  11236. description: The name of the Secret resource being referred to.
  11237. maxLength: 253
  11238. minLength: 1
  11239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11240. type: string
  11241. namespace:
  11242. description: |-
  11243. The namespace of the Secret resource being referred to.
  11244. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11245. maxLength: 63
  11246. minLength: 1
  11247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11248. type: string
  11249. type: object
  11250. type: object
  11251. type: object
  11252. serviceUrl:
  11253. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11254. type: string
  11255. required:
  11256. - auth
  11257. type: object
  11258. infisical:
  11259. description: Infisical configures this store to sync secrets using the Infisical provider
  11260. properties:
  11261. auth:
  11262. description: Auth configures how the Operator authenticates with the Infisical API
  11263. properties:
  11264. universalAuthCredentials:
  11265. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11266. properties:
  11267. clientId:
  11268. description: |-
  11269. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11270. In some instances, `key` is a required field.
  11271. properties:
  11272. key:
  11273. description: |-
  11274. A key in the referenced Secret.
  11275. Some instances of this field may be defaulted, in others it may be required.
  11276. maxLength: 253
  11277. minLength: 1
  11278. pattern: ^[-._a-zA-Z0-9]+$
  11279. type: string
  11280. name:
  11281. description: The name of the Secret resource being referred to.
  11282. maxLength: 253
  11283. minLength: 1
  11284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11285. type: string
  11286. namespace:
  11287. description: |-
  11288. The namespace of the Secret resource being referred to.
  11289. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11290. maxLength: 63
  11291. minLength: 1
  11292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11293. type: string
  11294. type: object
  11295. clientSecret:
  11296. description: |-
  11297. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11298. In some instances, `key` is a required field.
  11299. properties:
  11300. key:
  11301. description: |-
  11302. A key in the referenced Secret.
  11303. Some instances of this field may be defaulted, in others it may be required.
  11304. maxLength: 253
  11305. minLength: 1
  11306. pattern: ^[-._a-zA-Z0-9]+$
  11307. type: string
  11308. name:
  11309. description: The name of the Secret resource being referred to.
  11310. maxLength: 253
  11311. minLength: 1
  11312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11313. type: string
  11314. namespace:
  11315. description: |-
  11316. The namespace of the Secret resource being referred to.
  11317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11318. maxLength: 63
  11319. minLength: 1
  11320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11321. type: string
  11322. type: object
  11323. required:
  11324. - clientId
  11325. - clientSecret
  11326. type: object
  11327. type: object
  11328. hostAPI:
  11329. default: https://app.infisical.com/api
  11330. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11331. type: string
  11332. secretsScope:
  11333. description: SecretsScope defines the scope of the secrets within the workspace
  11334. properties:
  11335. environmentSlug:
  11336. description: EnvironmentSlug is the required slug identifier for the environment.
  11337. type: string
  11338. expandSecretReferences:
  11339. default: true
  11340. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11341. type: boolean
  11342. projectSlug:
  11343. description: ProjectSlug is the required slug identifier for the project.
  11344. type: string
  11345. recursive:
  11346. default: false
  11347. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11348. type: boolean
  11349. secretsPath:
  11350. default: /
  11351. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11352. type: string
  11353. required:
  11354. - environmentSlug
  11355. - projectSlug
  11356. type: object
  11357. required:
  11358. - auth
  11359. - secretsScope
  11360. type: object
  11361. keepersecurity:
  11362. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11363. properties:
  11364. authRef:
  11365. description: |-
  11366. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11367. In some instances, `key` is a required field.
  11368. properties:
  11369. key:
  11370. description: |-
  11371. A key in the referenced Secret.
  11372. Some instances of this field may be defaulted, in others it may be required.
  11373. maxLength: 253
  11374. minLength: 1
  11375. pattern: ^[-._a-zA-Z0-9]+$
  11376. type: string
  11377. name:
  11378. description: The name of the Secret resource being referred to.
  11379. maxLength: 253
  11380. minLength: 1
  11381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11382. type: string
  11383. namespace:
  11384. description: |-
  11385. The namespace of the Secret resource being referred to.
  11386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11387. maxLength: 63
  11388. minLength: 1
  11389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11390. type: string
  11391. type: object
  11392. folderID:
  11393. type: string
  11394. required:
  11395. - authRef
  11396. - folderID
  11397. type: object
  11398. kubernetes:
  11399. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11400. properties:
  11401. auth:
  11402. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11403. maxProperties: 1
  11404. minProperties: 1
  11405. properties:
  11406. cert:
  11407. description: has both clientCert and clientKey as secretKeySelector
  11408. properties:
  11409. clientCert:
  11410. description: |-
  11411. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11412. In some instances, `key` is a required field.
  11413. properties:
  11414. key:
  11415. description: |-
  11416. A key in the referenced Secret.
  11417. Some instances of this field may be defaulted, in others it may be required.
  11418. maxLength: 253
  11419. minLength: 1
  11420. pattern: ^[-._a-zA-Z0-9]+$
  11421. type: string
  11422. name:
  11423. description: The name of the Secret resource being referred to.
  11424. maxLength: 253
  11425. minLength: 1
  11426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11427. type: string
  11428. namespace:
  11429. description: |-
  11430. The namespace of the Secret resource being referred to.
  11431. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11432. maxLength: 63
  11433. minLength: 1
  11434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11435. type: string
  11436. type: object
  11437. clientKey:
  11438. description: |-
  11439. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11440. In some instances, `key` is a required field.
  11441. properties:
  11442. key:
  11443. description: |-
  11444. A key in the referenced Secret.
  11445. Some instances of this field may be defaulted, in others it may be required.
  11446. maxLength: 253
  11447. minLength: 1
  11448. pattern: ^[-._a-zA-Z0-9]+$
  11449. type: string
  11450. name:
  11451. description: The name of the Secret resource being referred to.
  11452. maxLength: 253
  11453. minLength: 1
  11454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11455. type: string
  11456. namespace:
  11457. description: |-
  11458. The namespace of the Secret resource being referred to.
  11459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11460. maxLength: 63
  11461. minLength: 1
  11462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11463. type: string
  11464. type: object
  11465. type: object
  11466. serviceAccount:
  11467. description: points to a service account that should be used for authentication
  11468. properties:
  11469. audiences:
  11470. description: |-
  11471. Audience specifies the `aud` claim for the service account token
  11472. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11473. then this audiences will be appended to the list
  11474. items:
  11475. type: string
  11476. type: array
  11477. name:
  11478. description: The name of the ServiceAccount resource being referred to.
  11479. maxLength: 253
  11480. minLength: 1
  11481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11482. type: string
  11483. namespace:
  11484. description: |-
  11485. Namespace of the resource being referred to.
  11486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11487. maxLength: 63
  11488. minLength: 1
  11489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11490. type: string
  11491. required:
  11492. - name
  11493. type: object
  11494. token:
  11495. description: use static token to authenticate with
  11496. properties:
  11497. bearerToken:
  11498. description: |-
  11499. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11500. In some instances, `key` is a required field.
  11501. properties:
  11502. key:
  11503. description: |-
  11504. A key in the referenced Secret.
  11505. Some instances of this field may be defaulted, in others it may be required.
  11506. maxLength: 253
  11507. minLength: 1
  11508. pattern: ^[-._a-zA-Z0-9]+$
  11509. type: string
  11510. name:
  11511. description: The name of the Secret resource being referred to.
  11512. maxLength: 253
  11513. minLength: 1
  11514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11515. type: string
  11516. namespace:
  11517. description: |-
  11518. The namespace of the Secret resource being referred to.
  11519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11520. maxLength: 63
  11521. minLength: 1
  11522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11523. type: string
  11524. type: object
  11525. type: object
  11526. type: object
  11527. authRef:
  11528. description: A reference to a secret that contains the auth information.
  11529. properties:
  11530. key:
  11531. description: |-
  11532. A key in the referenced Secret.
  11533. Some instances of this field may be defaulted, in others it may be required.
  11534. maxLength: 253
  11535. minLength: 1
  11536. pattern: ^[-._a-zA-Z0-9]+$
  11537. type: string
  11538. name:
  11539. description: The name of the Secret resource being referred to.
  11540. maxLength: 253
  11541. minLength: 1
  11542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11543. type: string
  11544. namespace:
  11545. description: |-
  11546. The namespace of the Secret resource being referred to.
  11547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11548. maxLength: 63
  11549. minLength: 1
  11550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11551. type: string
  11552. type: object
  11553. remoteNamespace:
  11554. default: default
  11555. description: Remote namespace to fetch the secrets from
  11556. maxLength: 63
  11557. minLength: 1
  11558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11559. type: string
  11560. server:
  11561. description: configures the Kubernetes server Address.
  11562. properties:
  11563. caBundle:
  11564. description: CABundle is a base64-encoded CA certificate
  11565. format: byte
  11566. type: string
  11567. caProvider:
  11568. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11569. properties:
  11570. key:
  11571. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11572. maxLength: 253
  11573. minLength: 1
  11574. pattern: ^[-._a-zA-Z0-9]+$
  11575. type: string
  11576. name:
  11577. description: The name of the object located at the provider type.
  11578. maxLength: 253
  11579. minLength: 1
  11580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11581. type: string
  11582. namespace:
  11583. description: |-
  11584. The namespace the Provider type is in.
  11585. Can only be defined when used in a ClusterSecretStore.
  11586. maxLength: 63
  11587. minLength: 1
  11588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11589. type: string
  11590. type:
  11591. description: The type of provider to use such as "Secret", or "ConfigMap".
  11592. enum:
  11593. - Secret
  11594. - ConfigMap
  11595. type: string
  11596. required:
  11597. - name
  11598. - type
  11599. type: object
  11600. url:
  11601. default: kubernetes.default
  11602. description: configures the Kubernetes server Address.
  11603. type: string
  11604. type: object
  11605. type: object
  11606. onboardbase:
  11607. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11608. properties:
  11609. apiHost:
  11610. default: https://public.onboardbase.com/api/v1/
  11611. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11612. type: string
  11613. auth:
  11614. description: Auth configures how the Operator authenticates with the Onboardbase API
  11615. properties:
  11616. apiKeyRef:
  11617. description: |-
  11618. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11619. It is used to recognize and authorize access to a project and environment within onboardbase
  11620. properties:
  11621. key:
  11622. description: |-
  11623. A key in the referenced Secret.
  11624. Some instances of this field may be defaulted, in others it may be required.
  11625. maxLength: 253
  11626. minLength: 1
  11627. pattern: ^[-._a-zA-Z0-9]+$
  11628. type: string
  11629. name:
  11630. description: The name of the Secret resource being referred to.
  11631. maxLength: 253
  11632. minLength: 1
  11633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11634. type: string
  11635. namespace:
  11636. description: |-
  11637. The namespace of the Secret resource being referred to.
  11638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11639. maxLength: 63
  11640. minLength: 1
  11641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11642. type: string
  11643. type: object
  11644. passcodeRef:
  11645. description: OnboardbasePasscode is the passcode attached to the API Key
  11646. properties:
  11647. key:
  11648. description: |-
  11649. A key in the referenced Secret.
  11650. Some instances of this field may be defaulted, in others it may be required.
  11651. maxLength: 253
  11652. minLength: 1
  11653. pattern: ^[-._a-zA-Z0-9]+$
  11654. type: string
  11655. name:
  11656. description: The name of the Secret resource being referred to.
  11657. maxLength: 253
  11658. minLength: 1
  11659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11660. type: string
  11661. namespace:
  11662. description: |-
  11663. The namespace of the Secret resource being referred to.
  11664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11665. maxLength: 63
  11666. minLength: 1
  11667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11668. type: string
  11669. type: object
  11670. required:
  11671. - apiKeyRef
  11672. - passcodeRef
  11673. type: object
  11674. environment:
  11675. default: development
  11676. description: Environment is the name of an environmnent within a project to pull the secrets from
  11677. type: string
  11678. project:
  11679. default: development
  11680. description: Project is an onboardbase project that the secrets should be pulled from
  11681. type: string
  11682. required:
  11683. - apiHost
  11684. - auth
  11685. - environment
  11686. - project
  11687. type: object
  11688. onepassword:
  11689. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11690. properties:
  11691. auth:
  11692. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11693. properties:
  11694. secretRef:
  11695. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11696. properties:
  11697. connectTokenSecretRef:
  11698. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11699. properties:
  11700. key:
  11701. description: |-
  11702. A key in the referenced Secret.
  11703. Some instances of this field may be defaulted, in others it may be required.
  11704. maxLength: 253
  11705. minLength: 1
  11706. pattern: ^[-._a-zA-Z0-9]+$
  11707. type: string
  11708. name:
  11709. description: The name of the Secret resource being referred to.
  11710. maxLength: 253
  11711. minLength: 1
  11712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11713. type: string
  11714. namespace:
  11715. description: |-
  11716. The namespace of the Secret resource being referred to.
  11717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11718. maxLength: 63
  11719. minLength: 1
  11720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11721. type: string
  11722. type: object
  11723. required:
  11724. - connectTokenSecretRef
  11725. type: object
  11726. required:
  11727. - secretRef
  11728. type: object
  11729. connectHost:
  11730. description: ConnectHost defines the OnePassword Connect Server to connect to
  11731. type: string
  11732. vaults:
  11733. additionalProperties:
  11734. type: integer
  11735. description: Vaults defines which OnePassword vaults to search in which order
  11736. type: object
  11737. required:
  11738. - auth
  11739. - connectHost
  11740. - vaults
  11741. type: object
  11742. oracle:
  11743. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11744. properties:
  11745. auth:
  11746. description: |-
  11747. Auth configures how secret-manager authenticates with the Oracle Vault.
  11748. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11749. properties:
  11750. secretRef:
  11751. description: SecretRef to pass through sensitive information.
  11752. properties:
  11753. fingerprint:
  11754. description: Fingerprint is the fingerprint of the API private key.
  11755. properties:
  11756. key:
  11757. description: |-
  11758. A key in the referenced Secret.
  11759. Some instances of this field may be defaulted, in others it may be required.
  11760. maxLength: 253
  11761. minLength: 1
  11762. pattern: ^[-._a-zA-Z0-9]+$
  11763. type: string
  11764. name:
  11765. description: The name of the Secret resource being referred to.
  11766. maxLength: 253
  11767. minLength: 1
  11768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11769. type: string
  11770. namespace:
  11771. description: |-
  11772. The namespace of the Secret resource being referred to.
  11773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11774. maxLength: 63
  11775. minLength: 1
  11776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11777. type: string
  11778. type: object
  11779. privatekey:
  11780. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11781. properties:
  11782. key:
  11783. description: |-
  11784. A key in the referenced Secret.
  11785. Some instances of this field may be defaulted, in others it may be required.
  11786. maxLength: 253
  11787. minLength: 1
  11788. pattern: ^[-._a-zA-Z0-9]+$
  11789. type: string
  11790. name:
  11791. description: The name of the Secret resource being referred to.
  11792. maxLength: 253
  11793. minLength: 1
  11794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11795. type: string
  11796. namespace:
  11797. description: |-
  11798. The namespace of the Secret resource being referred to.
  11799. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11800. maxLength: 63
  11801. minLength: 1
  11802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11803. type: string
  11804. type: object
  11805. required:
  11806. - fingerprint
  11807. - privatekey
  11808. type: object
  11809. tenancy:
  11810. description: Tenancy is the tenancy OCID where user is located.
  11811. type: string
  11812. user:
  11813. description: User is an access OCID specific to the account.
  11814. type: string
  11815. required:
  11816. - secretRef
  11817. - tenancy
  11818. - user
  11819. type: object
  11820. compartment:
  11821. description: |-
  11822. Compartment is the vault compartment OCID.
  11823. Required for PushSecret
  11824. type: string
  11825. encryptionKey:
  11826. description: |-
  11827. EncryptionKey is the OCID of the encryption key within the vault.
  11828. Required for PushSecret
  11829. type: string
  11830. principalType:
  11831. description: |-
  11832. The type of principal to use for authentication. If left blank, the Auth struct will
  11833. determine the principal type. This optional field must be specified if using
  11834. workload identity.
  11835. enum:
  11836. - ""
  11837. - UserPrincipal
  11838. - InstancePrincipal
  11839. - Workload
  11840. type: string
  11841. region:
  11842. description: Region is the region where vault is located.
  11843. type: string
  11844. serviceAccountRef:
  11845. description: |-
  11846. ServiceAccountRef specified the service account
  11847. that should be used when authenticating with WorkloadIdentity.
  11848. properties:
  11849. audiences:
  11850. description: |-
  11851. Audience specifies the `aud` claim for the service account token
  11852. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11853. then this audiences will be appended to the list
  11854. items:
  11855. type: string
  11856. type: array
  11857. name:
  11858. description: The name of the ServiceAccount resource being referred to.
  11859. maxLength: 253
  11860. minLength: 1
  11861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11862. type: string
  11863. namespace:
  11864. description: |-
  11865. Namespace of the resource being referred to.
  11866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11867. maxLength: 63
  11868. minLength: 1
  11869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11870. type: string
  11871. required:
  11872. - name
  11873. type: object
  11874. vault:
  11875. description: Vault is the vault's OCID of the specific vault where secret is located.
  11876. type: string
  11877. required:
  11878. - region
  11879. - vault
  11880. type: object
  11881. passbolt:
  11882. description: PassboltProvider defines configuration for the Passbolt provider.
  11883. properties:
  11884. auth:
  11885. description: Auth defines the information necessary to authenticate against Passbolt Server
  11886. properties:
  11887. passwordSecretRef:
  11888. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11889. properties:
  11890. key:
  11891. description: |-
  11892. A key in the referenced Secret.
  11893. Some instances of this field may be defaulted, in others it may be required.
  11894. maxLength: 253
  11895. minLength: 1
  11896. pattern: ^[-._a-zA-Z0-9]+$
  11897. type: string
  11898. name:
  11899. description: The name of the Secret resource being referred to.
  11900. maxLength: 253
  11901. minLength: 1
  11902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11903. type: string
  11904. namespace:
  11905. description: |-
  11906. The namespace of the Secret resource being referred to.
  11907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11908. maxLength: 63
  11909. minLength: 1
  11910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11911. type: string
  11912. type: object
  11913. privateKeySecretRef:
  11914. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11915. properties:
  11916. key:
  11917. description: |-
  11918. A key in the referenced Secret.
  11919. Some instances of this field may be defaulted, in others it may be required.
  11920. maxLength: 253
  11921. minLength: 1
  11922. pattern: ^[-._a-zA-Z0-9]+$
  11923. type: string
  11924. name:
  11925. description: The name of the Secret resource being referred to.
  11926. maxLength: 253
  11927. minLength: 1
  11928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11929. type: string
  11930. namespace:
  11931. description: |-
  11932. The namespace of the Secret resource being referred to.
  11933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11934. maxLength: 63
  11935. minLength: 1
  11936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11937. type: string
  11938. type: object
  11939. required:
  11940. - passwordSecretRef
  11941. - privateKeySecretRef
  11942. type: object
  11943. host:
  11944. description: Host defines the Passbolt Server to connect to
  11945. type: string
  11946. required:
  11947. - auth
  11948. - host
  11949. type: object
  11950. passworddepot:
  11951. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11952. properties:
  11953. auth:
  11954. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11955. properties:
  11956. secretRef:
  11957. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11958. properties:
  11959. credentials:
  11960. description: Username / Password is used for authentication.
  11961. properties:
  11962. key:
  11963. description: |-
  11964. A key in the referenced Secret.
  11965. Some instances of this field may be defaulted, in others it may be required.
  11966. maxLength: 253
  11967. minLength: 1
  11968. pattern: ^[-._a-zA-Z0-9]+$
  11969. type: string
  11970. name:
  11971. description: The name of the Secret resource being referred to.
  11972. maxLength: 253
  11973. minLength: 1
  11974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11975. type: string
  11976. namespace:
  11977. description: |-
  11978. The namespace of the Secret resource being referred to.
  11979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11980. maxLength: 63
  11981. minLength: 1
  11982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11983. type: string
  11984. type: object
  11985. type: object
  11986. required:
  11987. - secretRef
  11988. type: object
  11989. database:
  11990. description: Database to use as source
  11991. type: string
  11992. host:
  11993. description: URL configures the Password Depot instance URL.
  11994. type: string
  11995. required:
  11996. - auth
  11997. - database
  11998. - host
  11999. type: object
  12000. previder:
  12001. description: Previder configures this store to sync secrets using the Previder provider
  12002. properties:
  12003. auth:
  12004. description: PreviderAuth contains a secretRef for credentials.
  12005. properties:
  12006. secretRef:
  12007. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12008. properties:
  12009. accessToken:
  12010. description: The AccessToken is used for authentication
  12011. properties:
  12012. key:
  12013. description: |-
  12014. A key in the referenced Secret.
  12015. Some instances of this field may be defaulted, in others it may be required.
  12016. maxLength: 253
  12017. minLength: 1
  12018. pattern: ^[-._a-zA-Z0-9]+$
  12019. type: string
  12020. name:
  12021. description: The name of the Secret resource being referred to.
  12022. maxLength: 253
  12023. minLength: 1
  12024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12025. type: string
  12026. namespace:
  12027. description: |-
  12028. The namespace of the Secret resource being referred to.
  12029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12030. maxLength: 63
  12031. minLength: 1
  12032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12033. type: string
  12034. type: object
  12035. required:
  12036. - accessToken
  12037. type: object
  12038. type: object
  12039. baseUri:
  12040. type: string
  12041. required:
  12042. - auth
  12043. type: object
  12044. pulumi:
  12045. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12046. properties:
  12047. accessToken:
  12048. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12049. properties:
  12050. secretRef:
  12051. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12052. properties:
  12053. key:
  12054. description: |-
  12055. A key in the referenced Secret.
  12056. Some instances of this field may be defaulted, in others it may be required.
  12057. maxLength: 253
  12058. minLength: 1
  12059. pattern: ^[-._a-zA-Z0-9]+$
  12060. type: string
  12061. name:
  12062. description: The name of the Secret resource being referred to.
  12063. maxLength: 253
  12064. minLength: 1
  12065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12066. type: string
  12067. namespace:
  12068. description: |-
  12069. The namespace of the Secret resource being referred to.
  12070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12071. maxLength: 63
  12072. minLength: 1
  12073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12074. type: string
  12075. type: object
  12076. type: object
  12077. apiUrl:
  12078. default: https://api.pulumi.com/api/esc
  12079. description: APIURL is the URL of the Pulumi API.
  12080. type: string
  12081. environment:
  12082. description: |-
  12083. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12084. dynamically retrieved values from supported providers including all major clouds,
  12085. and other Pulumi ESC environments.
  12086. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12087. type: string
  12088. organization:
  12089. description: |-
  12090. Organization are a space to collaborate on shared projects and stacks.
  12091. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12092. type: string
  12093. project:
  12094. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12095. type: string
  12096. required:
  12097. - accessToken
  12098. - environment
  12099. - organization
  12100. - project
  12101. type: object
  12102. scaleway:
  12103. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12104. properties:
  12105. accessKey:
  12106. description: AccessKey is the non-secret part of the api key.
  12107. properties:
  12108. secretRef:
  12109. description: SecretRef references a key in a secret that will be used as value.
  12110. properties:
  12111. key:
  12112. description: |-
  12113. A key in the referenced Secret.
  12114. Some instances of this field may be defaulted, in others it may be required.
  12115. maxLength: 253
  12116. minLength: 1
  12117. pattern: ^[-._a-zA-Z0-9]+$
  12118. type: string
  12119. name:
  12120. description: The name of the Secret resource being referred to.
  12121. maxLength: 253
  12122. minLength: 1
  12123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12124. type: string
  12125. namespace:
  12126. description: |-
  12127. The namespace of the Secret resource being referred to.
  12128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12129. maxLength: 63
  12130. minLength: 1
  12131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12132. type: string
  12133. type: object
  12134. value:
  12135. description: Value can be specified directly to set a value without using a secret.
  12136. type: string
  12137. type: object
  12138. apiUrl:
  12139. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12140. type: string
  12141. projectId:
  12142. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12143. type: string
  12144. region:
  12145. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12146. type: string
  12147. secretKey:
  12148. description: SecretKey is the non-secret part of the api key.
  12149. properties:
  12150. secretRef:
  12151. description: SecretRef references a key in a secret that will be used as value.
  12152. properties:
  12153. key:
  12154. description: |-
  12155. A key in the referenced Secret.
  12156. Some instances of this field may be defaulted, in others it may be required.
  12157. maxLength: 253
  12158. minLength: 1
  12159. pattern: ^[-._a-zA-Z0-9]+$
  12160. type: string
  12161. name:
  12162. description: The name of the Secret resource being referred to.
  12163. maxLength: 253
  12164. minLength: 1
  12165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12166. type: string
  12167. namespace:
  12168. description: |-
  12169. The namespace of the Secret resource being referred to.
  12170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12171. maxLength: 63
  12172. minLength: 1
  12173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12174. type: string
  12175. type: object
  12176. value:
  12177. description: Value can be specified directly to set a value without using a secret.
  12178. type: string
  12179. type: object
  12180. required:
  12181. - accessKey
  12182. - projectId
  12183. - region
  12184. - secretKey
  12185. type: object
  12186. secretserver:
  12187. description: |-
  12188. SecretServer configures this store to sync secrets using SecretServer provider
  12189. https://docs.delinea.com/online-help/secret-server/start.htm
  12190. properties:
  12191. password:
  12192. description: Password is the secret server account password.
  12193. properties:
  12194. secretRef:
  12195. description: SecretRef references a key in a secret that will be used as value.
  12196. properties:
  12197. key:
  12198. description: |-
  12199. A key in the referenced Secret.
  12200. Some instances of this field may be defaulted, in others it may be required.
  12201. maxLength: 253
  12202. minLength: 1
  12203. pattern: ^[-._a-zA-Z0-9]+$
  12204. type: string
  12205. name:
  12206. description: The name of the Secret resource being referred to.
  12207. maxLength: 253
  12208. minLength: 1
  12209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12210. type: string
  12211. namespace:
  12212. description: |-
  12213. The namespace of the Secret resource being referred to.
  12214. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12215. maxLength: 63
  12216. minLength: 1
  12217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12218. type: string
  12219. type: object
  12220. value:
  12221. description: Value can be specified directly to set a value without using a secret.
  12222. type: string
  12223. type: object
  12224. serverURL:
  12225. description: |-
  12226. ServerURL
  12227. URL to your secret server installation
  12228. type: string
  12229. username:
  12230. description: Username is the secret server account username.
  12231. properties:
  12232. secretRef:
  12233. description: SecretRef references a key in a secret that will be used as value.
  12234. properties:
  12235. key:
  12236. description: |-
  12237. A key in the referenced Secret.
  12238. Some instances of this field may be defaulted, in others it may be required.
  12239. maxLength: 253
  12240. minLength: 1
  12241. pattern: ^[-._a-zA-Z0-9]+$
  12242. type: string
  12243. name:
  12244. description: The name of the Secret resource being referred to.
  12245. maxLength: 253
  12246. minLength: 1
  12247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12248. type: string
  12249. namespace:
  12250. description: |-
  12251. The namespace of the Secret resource being referred to.
  12252. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12253. maxLength: 63
  12254. minLength: 1
  12255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12256. type: string
  12257. type: object
  12258. value:
  12259. description: Value can be specified directly to set a value without using a secret.
  12260. type: string
  12261. type: object
  12262. required:
  12263. - password
  12264. - serverURL
  12265. - username
  12266. type: object
  12267. senhasegura:
  12268. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12269. properties:
  12270. auth:
  12271. description: Auth defines parameters to authenticate in senhasegura
  12272. properties:
  12273. clientId:
  12274. type: string
  12275. clientSecretSecretRef:
  12276. description: |-
  12277. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12278. In some instances, `key` is a required field.
  12279. properties:
  12280. key:
  12281. description: |-
  12282. A key in the referenced Secret.
  12283. Some instances of this field may be defaulted, in others it may be required.
  12284. maxLength: 253
  12285. minLength: 1
  12286. pattern: ^[-._a-zA-Z0-9]+$
  12287. type: string
  12288. name:
  12289. description: The name of the Secret resource being referred to.
  12290. maxLength: 253
  12291. minLength: 1
  12292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12293. type: string
  12294. namespace:
  12295. description: |-
  12296. The namespace of the Secret resource being referred to.
  12297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12298. maxLength: 63
  12299. minLength: 1
  12300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12301. type: string
  12302. type: object
  12303. required:
  12304. - clientId
  12305. - clientSecretSecretRef
  12306. type: object
  12307. ignoreSslCertificate:
  12308. default: false
  12309. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12310. type: boolean
  12311. module:
  12312. description: Module defines which senhasegura module should be used to get secrets
  12313. type: string
  12314. url:
  12315. description: URL of senhasegura
  12316. type: string
  12317. required:
  12318. - auth
  12319. - module
  12320. - url
  12321. type: object
  12322. vault:
  12323. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12324. properties:
  12325. auth:
  12326. description: Auth configures how secret-manager authenticates with the Vault server.
  12327. properties:
  12328. appRole:
  12329. description: |-
  12330. AppRole authenticates with Vault using the App Role auth mechanism,
  12331. with the role and secret stored in a Kubernetes Secret resource.
  12332. properties:
  12333. path:
  12334. default: approle
  12335. description: |-
  12336. Path where the App Role authentication backend is mounted
  12337. in Vault, e.g: "approle"
  12338. type: string
  12339. roleId:
  12340. description: |-
  12341. RoleID configured in the App Role authentication backend when setting
  12342. up the authentication backend in Vault.
  12343. type: string
  12344. roleRef:
  12345. description: |-
  12346. Reference to a key in a Secret that contains the App Role ID used
  12347. to authenticate with Vault.
  12348. The `key` field must be specified and denotes which entry within the Secret
  12349. resource is used as the app role id.
  12350. properties:
  12351. key:
  12352. description: |-
  12353. A key in the referenced Secret.
  12354. Some instances of this field may be defaulted, in others it may be required.
  12355. maxLength: 253
  12356. minLength: 1
  12357. pattern: ^[-._a-zA-Z0-9]+$
  12358. type: string
  12359. name:
  12360. description: The name of the Secret resource being referred to.
  12361. maxLength: 253
  12362. minLength: 1
  12363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12364. type: string
  12365. namespace:
  12366. description: |-
  12367. The namespace of the Secret resource being referred to.
  12368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12369. maxLength: 63
  12370. minLength: 1
  12371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12372. type: string
  12373. type: object
  12374. secretRef:
  12375. description: |-
  12376. Reference to a key in a Secret that contains the App Role secret used
  12377. to authenticate with Vault.
  12378. The `key` field must be specified and denotes which entry within the Secret
  12379. resource is used as the app role secret.
  12380. properties:
  12381. key:
  12382. description: |-
  12383. A key in the referenced Secret.
  12384. Some instances of this field may be defaulted, in others it may be required.
  12385. maxLength: 253
  12386. minLength: 1
  12387. pattern: ^[-._a-zA-Z0-9]+$
  12388. type: string
  12389. name:
  12390. description: The name of the Secret resource being referred to.
  12391. maxLength: 253
  12392. minLength: 1
  12393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12394. type: string
  12395. namespace:
  12396. description: |-
  12397. The namespace of the Secret resource being referred to.
  12398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12399. maxLength: 63
  12400. minLength: 1
  12401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12402. type: string
  12403. type: object
  12404. required:
  12405. - path
  12406. - secretRef
  12407. type: object
  12408. cert:
  12409. description: |-
  12410. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12411. Cert authentication method
  12412. properties:
  12413. clientCert:
  12414. description: |-
  12415. ClientCert is a certificate to authenticate using the Cert Vault
  12416. authentication method
  12417. properties:
  12418. key:
  12419. description: |-
  12420. A key in the referenced Secret.
  12421. Some instances of this field may be defaulted, in others it may be required.
  12422. maxLength: 253
  12423. minLength: 1
  12424. pattern: ^[-._a-zA-Z0-9]+$
  12425. type: string
  12426. name:
  12427. description: The name of the Secret resource being referred to.
  12428. maxLength: 253
  12429. minLength: 1
  12430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12431. type: string
  12432. namespace:
  12433. description: |-
  12434. The namespace of the Secret resource being referred to.
  12435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12436. maxLength: 63
  12437. minLength: 1
  12438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12439. type: string
  12440. type: object
  12441. secretRef:
  12442. description: |-
  12443. SecretRef to a key in a Secret resource containing client private key to
  12444. authenticate with Vault using the Cert authentication method
  12445. properties:
  12446. key:
  12447. description: |-
  12448. A key in the referenced Secret.
  12449. Some instances of this field may be defaulted, in others it may be required.
  12450. maxLength: 253
  12451. minLength: 1
  12452. pattern: ^[-._a-zA-Z0-9]+$
  12453. type: string
  12454. name:
  12455. description: The name of the Secret resource being referred to.
  12456. maxLength: 253
  12457. minLength: 1
  12458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12459. type: string
  12460. namespace:
  12461. description: |-
  12462. The namespace of the Secret resource being referred to.
  12463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12464. maxLength: 63
  12465. minLength: 1
  12466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12467. type: string
  12468. type: object
  12469. type: object
  12470. iam:
  12471. description: |-
  12472. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12473. AWS IAM authentication method
  12474. properties:
  12475. externalID:
  12476. description: AWS External ID set on assumed IAM roles
  12477. type: string
  12478. jwt:
  12479. description: Specify a service account with IRSA enabled
  12480. properties:
  12481. serviceAccountRef:
  12482. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12483. properties:
  12484. audiences:
  12485. description: |-
  12486. Audience specifies the `aud` claim for the service account token
  12487. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12488. then this audiences will be appended to the list
  12489. items:
  12490. type: string
  12491. type: array
  12492. name:
  12493. description: The name of the ServiceAccount resource being referred to.
  12494. maxLength: 253
  12495. minLength: 1
  12496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12497. type: string
  12498. namespace:
  12499. description: |-
  12500. Namespace of the resource being referred to.
  12501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12502. maxLength: 63
  12503. minLength: 1
  12504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12505. type: string
  12506. required:
  12507. - name
  12508. type: object
  12509. type: object
  12510. path:
  12511. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12512. type: string
  12513. region:
  12514. description: AWS region
  12515. type: string
  12516. role:
  12517. description: This is the AWS role to be assumed before talking to vault
  12518. type: string
  12519. secretRef:
  12520. description: Specify credentials in a Secret object
  12521. properties:
  12522. accessKeyIDSecretRef:
  12523. description: The AccessKeyID is used for authentication
  12524. properties:
  12525. key:
  12526. description: |-
  12527. A key in the referenced Secret.
  12528. Some instances of this field may be defaulted, in others it may be required.
  12529. maxLength: 253
  12530. minLength: 1
  12531. pattern: ^[-._a-zA-Z0-9]+$
  12532. type: string
  12533. name:
  12534. description: The name of the Secret resource being referred to.
  12535. maxLength: 253
  12536. minLength: 1
  12537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12538. type: string
  12539. namespace:
  12540. description: |-
  12541. The namespace of the Secret resource being referred to.
  12542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12543. maxLength: 63
  12544. minLength: 1
  12545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12546. type: string
  12547. type: object
  12548. secretAccessKeySecretRef:
  12549. description: The SecretAccessKey is used for authentication
  12550. properties:
  12551. key:
  12552. description: |-
  12553. A key in the referenced Secret.
  12554. Some instances of this field may be defaulted, in others it may be required.
  12555. maxLength: 253
  12556. minLength: 1
  12557. pattern: ^[-._a-zA-Z0-9]+$
  12558. type: string
  12559. name:
  12560. description: The name of the Secret resource being referred to.
  12561. maxLength: 253
  12562. minLength: 1
  12563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12564. type: string
  12565. namespace:
  12566. description: |-
  12567. The namespace of the Secret resource being referred to.
  12568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12569. maxLength: 63
  12570. minLength: 1
  12571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12572. type: string
  12573. type: object
  12574. sessionTokenSecretRef:
  12575. description: |-
  12576. The SessionToken used for authentication
  12577. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12578. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12579. properties:
  12580. key:
  12581. description: |-
  12582. A key in the referenced Secret.
  12583. Some instances of this field may be defaulted, in others it may be required.
  12584. maxLength: 253
  12585. minLength: 1
  12586. pattern: ^[-._a-zA-Z0-9]+$
  12587. type: string
  12588. name:
  12589. description: The name of the Secret resource being referred to.
  12590. maxLength: 253
  12591. minLength: 1
  12592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12593. type: string
  12594. namespace:
  12595. description: |-
  12596. The namespace of the Secret resource being referred to.
  12597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12598. maxLength: 63
  12599. minLength: 1
  12600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12601. type: string
  12602. type: object
  12603. type: object
  12604. vaultAwsIamServerID:
  12605. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12606. type: string
  12607. vaultRole:
  12608. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12609. type: string
  12610. required:
  12611. - vaultRole
  12612. type: object
  12613. jwt:
  12614. description: |-
  12615. Jwt authenticates with Vault by passing role and JWT token using the
  12616. JWT/OIDC authentication method
  12617. properties:
  12618. kubernetesServiceAccountToken:
  12619. description: |-
  12620. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12621. a token for with the `TokenRequest` API.
  12622. properties:
  12623. audiences:
  12624. description: |-
  12625. Optional audiences field that will be used to request a temporary Kubernetes service
  12626. account token for the service account referenced by `serviceAccountRef`.
  12627. Defaults to a single audience `vault` it not specified.
  12628. Deprecated: use serviceAccountRef.Audiences instead
  12629. items:
  12630. type: string
  12631. type: array
  12632. expirationSeconds:
  12633. description: |-
  12634. Optional expiration time in seconds that will be used to request a temporary
  12635. Kubernetes service account token for the service account referenced by
  12636. `serviceAccountRef`.
  12637. Deprecated: this will be removed in the future.
  12638. Defaults to 10 minutes.
  12639. format: int64
  12640. type: integer
  12641. serviceAccountRef:
  12642. description: Service account field containing the name of a kubernetes ServiceAccount.
  12643. properties:
  12644. audiences:
  12645. description: |-
  12646. Audience specifies the `aud` claim for the service account token
  12647. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12648. then this audiences will be appended to the list
  12649. items:
  12650. type: string
  12651. type: array
  12652. name:
  12653. description: The name of the ServiceAccount resource being referred to.
  12654. maxLength: 253
  12655. minLength: 1
  12656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12657. type: string
  12658. namespace:
  12659. description: |-
  12660. Namespace of the resource being referred to.
  12661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12662. maxLength: 63
  12663. minLength: 1
  12664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12665. type: string
  12666. required:
  12667. - name
  12668. type: object
  12669. required:
  12670. - serviceAccountRef
  12671. type: object
  12672. path:
  12673. default: jwt
  12674. description: |-
  12675. Path where the JWT authentication backend is mounted
  12676. in Vault, e.g: "jwt"
  12677. type: string
  12678. role:
  12679. description: |-
  12680. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12681. authentication method
  12682. type: string
  12683. secretRef:
  12684. description: |-
  12685. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12686. authenticate with Vault using the JWT/OIDC authentication method.
  12687. properties:
  12688. key:
  12689. description: |-
  12690. A key in the referenced Secret.
  12691. Some instances of this field may be defaulted, in others it may be required.
  12692. maxLength: 253
  12693. minLength: 1
  12694. pattern: ^[-._a-zA-Z0-9]+$
  12695. type: string
  12696. name:
  12697. description: The name of the Secret resource being referred to.
  12698. maxLength: 253
  12699. minLength: 1
  12700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12701. type: string
  12702. namespace:
  12703. description: |-
  12704. The namespace of the Secret resource being referred to.
  12705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12706. maxLength: 63
  12707. minLength: 1
  12708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12709. type: string
  12710. type: object
  12711. required:
  12712. - path
  12713. type: object
  12714. kubernetes:
  12715. description: |-
  12716. Kubernetes authenticates with Vault by passing the ServiceAccount
  12717. token stored in the named Secret resource to the Vault server.
  12718. properties:
  12719. mountPath:
  12720. default: kubernetes
  12721. description: |-
  12722. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12723. "kubernetes"
  12724. type: string
  12725. role:
  12726. description: |-
  12727. A required field containing the Vault Role to assume. A Role binds a
  12728. Kubernetes ServiceAccount with a set of Vault policies.
  12729. type: string
  12730. secretRef:
  12731. description: |-
  12732. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12733. for authenticating with Vault. If a name is specified without a key,
  12734. `token` is the default. If one is not specified, the one bound to
  12735. the controller will be used.
  12736. properties:
  12737. key:
  12738. description: |-
  12739. A key in the referenced Secret.
  12740. Some instances of this field may be defaulted, in others it may be required.
  12741. maxLength: 253
  12742. minLength: 1
  12743. pattern: ^[-._a-zA-Z0-9]+$
  12744. type: string
  12745. name:
  12746. description: The name of the Secret resource being referred to.
  12747. maxLength: 253
  12748. minLength: 1
  12749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12750. type: string
  12751. namespace:
  12752. description: |-
  12753. The namespace of the Secret resource being referred to.
  12754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12755. maxLength: 63
  12756. minLength: 1
  12757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12758. type: string
  12759. type: object
  12760. serviceAccountRef:
  12761. description: |-
  12762. Optional service account field containing the name of a kubernetes ServiceAccount.
  12763. If the service account is specified, the service account secret token JWT will be used
  12764. for authenticating with Vault. If the service account selector is not supplied,
  12765. the secretRef will be used instead.
  12766. properties:
  12767. audiences:
  12768. description: |-
  12769. Audience specifies the `aud` claim for the service account token
  12770. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12771. then this audiences will be appended to the list
  12772. items:
  12773. type: string
  12774. type: array
  12775. name:
  12776. description: The name of the ServiceAccount resource being referred to.
  12777. maxLength: 253
  12778. minLength: 1
  12779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12780. type: string
  12781. namespace:
  12782. description: |-
  12783. Namespace of the resource being referred to.
  12784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12785. maxLength: 63
  12786. minLength: 1
  12787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12788. type: string
  12789. required:
  12790. - name
  12791. type: object
  12792. required:
  12793. - mountPath
  12794. - role
  12795. type: object
  12796. ldap:
  12797. description: |-
  12798. Ldap authenticates with Vault by passing username/password pair using
  12799. the LDAP authentication method
  12800. properties:
  12801. path:
  12802. default: ldap
  12803. description: |-
  12804. Path where the LDAP authentication backend is mounted
  12805. in Vault, e.g: "ldap"
  12806. type: string
  12807. secretRef:
  12808. description: |-
  12809. SecretRef to a key in a Secret resource containing password for the LDAP
  12810. user used to authenticate with Vault using the LDAP authentication
  12811. method
  12812. properties:
  12813. key:
  12814. description: |-
  12815. A key in the referenced Secret.
  12816. Some instances of this field may be defaulted, in others it may be required.
  12817. maxLength: 253
  12818. minLength: 1
  12819. pattern: ^[-._a-zA-Z0-9]+$
  12820. type: string
  12821. name:
  12822. description: The name of the Secret resource being referred to.
  12823. maxLength: 253
  12824. minLength: 1
  12825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12826. type: string
  12827. namespace:
  12828. description: |-
  12829. The namespace of the Secret resource being referred to.
  12830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12831. maxLength: 63
  12832. minLength: 1
  12833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12834. type: string
  12835. type: object
  12836. username:
  12837. description: |-
  12838. Username is an LDAP username used to authenticate using the LDAP Vault
  12839. authentication method
  12840. type: string
  12841. required:
  12842. - path
  12843. - username
  12844. type: object
  12845. namespace:
  12846. description: |-
  12847. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12848. Namespaces is a set of features within Vault Enterprise that allows
  12849. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12850. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12851. This will default to Vault.Namespace field if set, or empty otherwise
  12852. type: string
  12853. tokenSecretRef:
  12854. description: TokenSecretRef authenticates with Vault by presenting a token.
  12855. properties:
  12856. key:
  12857. description: |-
  12858. A key in the referenced Secret.
  12859. Some instances of this field may be defaulted, in others it may be required.
  12860. maxLength: 253
  12861. minLength: 1
  12862. pattern: ^[-._a-zA-Z0-9]+$
  12863. type: string
  12864. name:
  12865. description: The name of the Secret resource being referred to.
  12866. maxLength: 253
  12867. minLength: 1
  12868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12869. type: string
  12870. namespace:
  12871. description: |-
  12872. The namespace of the Secret resource being referred to.
  12873. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12874. maxLength: 63
  12875. minLength: 1
  12876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12877. type: string
  12878. type: object
  12879. userPass:
  12880. description: UserPass authenticates with Vault by passing username/password pair
  12881. properties:
  12882. path:
  12883. default: userpass
  12884. description: |-
  12885. Path where the UserPassword authentication backend is mounted
  12886. in Vault, e.g: "userpass"
  12887. type: string
  12888. secretRef:
  12889. description: |-
  12890. SecretRef to a key in a Secret resource containing password for the
  12891. user used to authenticate with Vault using the UserPass authentication
  12892. method
  12893. properties:
  12894. key:
  12895. description: |-
  12896. A key in the referenced Secret.
  12897. Some instances of this field may be defaulted, in others it may be required.
  12898. maxLength: 253
  12899. minLength: 1
  12900. pattern: ^[-._a-zA-Z0-9]+$
  12901. type: string
  12902. name:
  12903. description: The name of the Secret resource being referred to.
  12904. maxLength: 253
  12905. minLength: 1
  12906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12907. type: string
  12908. namespace:
  12909. description: |-
  12910. The namespace of the Secret resource being referred to.
  12911. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12912. maxLength: 63
  12913. minLength: 1
  12914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12915. type: string
  12916. type: object
  12917. username:
  12918. description: |-
  12919. Username is a username used to authenticate using the UserPass Vault
  12920. authentication method
  12921. type: string
  12922. required:
  12923. - path
  12924. - username
  12925. type: object
  12926. type: object
  12927. caBundle:
  12928. description: |-
  12929. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12930. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12931. plain HTTP protocol connection. If not set the system root certificates
  12932. are used to validate the TLS connection.
  12933. format: byte
  12934. type: string
  12935. caProvider:
  12936. description: The provider for the CA bundle to use to validate Vault server certificate.
  12937. properties:
  12938. key:
  12939. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12940. maxLength: 253
  12941. minLength: 1
  12942. pattern: ^[-._a-zA-Z0-9]+$
  12943. type: string
  12944. name:
  12945. description: The name of the object located at the provider type.
  12946. maxLength: 253
  12947. minLength: 1
  12948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12949. type: string
  12950. namespace:
  12951. description: |-
  12952. The namespace the Provider type is in.
  12953. Can only be defined when used in a ClusterSecretStore.
  12954. maxLength: 63
  12955. minLength: 1
  12956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12957. type: string
  12958. type:
  12959. description: The type of provider to use such as "Secret", or "ConfigMap".
  12960. enum:
  12961. - Secret
  12962. - ConfigMap
  12963. type: string
  12964. required:
  12965. - name
  12966. - type
  12967. type: object
  12968. forwardInconsistent:
  12969. description: |-
  12970. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12971. leader instead of simply retrying within a loop. This can increase performance if
  12972. the option is enabled serverside.
  12973. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12974. type: boolean
  12975. headers:
  12976. additionalProperties:
  12977. type: string
  12978. description: Headers to be added in Vault request
  12979. type: object
  12980. namespace:
  12981. description: |-
  12982. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12983. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12984. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12985. type: string
  12986. path:
  12987. description: |-
  12988. Path is the mount path of the Vault KV backend endpoint, e.g:
  12989. "secret". The v2 KV secret engine version specific "/data" path suffix
  12990. for fetching secrets from Vault is optional and will be appended
  12991. if not present in specified path.
  12992. type: string
  12993. readYourWrites:
  12994. description: |-
  12995. ReadYourWrites ensures isolated read-after-write semantics by
  12996. providing discovered cluster replication states in each request.
  12997. More information about eventual consistency in Vault can be found here
  12998. https://www.vaultproject.io/docs/enterprise/consistency
  12999. type: boolean
  13000. server:
  13001. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13002. type: string
  13003. tls:
  13004. description: |-
  13005. The configuration used for client side related TLS communication, when the Vault server
  13006. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13007. This parameter is ignored for plain HTTP protocol connection.
  13008. It's worth noting this configuration is different from the "TLS certificates auth method",
  13009. which is available under the `auth.cert` section.
  13010. properties:
  13011. certSecretRef:
  13012. description: |-
  13013. CertSecretRef is a certificate added to the transport layer
  13014. when communicating with the Vault server.
  13015. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13016. properties:
  13017. key:
  13018. description: |-
  13019. A key in the referenced Secret.
  13020. Some instances of this field may be defaulted, in others it may be required.
  13021. maxLength: 253
  13022. minLength: 1
  13023. pattern: ^[-._a-zA-Z0-9]+$
  13024. type: string
  13025. name:
  13026. description: The name of the Secret resource being referred to.
  13027. maxLength: 253
  13028. minLength: 1
  13029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13030. type: string
  13031. namespace:
  13032. description: |-
  13033. The namespace of the Secret resource being referred to.
  13034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13035. maxLength: 63
  13036. minLength: 1
  13037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13038. type: string
  13039. type: object
  13040. keySecretRef:
  13041. description: |-
  13042. KeySecretRef to a key in a Secret resource containing client private key
  13043. added to the transport layer when communicating with the Vault server.
  13044. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13045. properties:
  13046. key:
  13047. description: |-
  13048. A key in the referenced Secret.
  13049. Some instances of this field may be defaulted, in others it may be required.
  13050. maxLength: 253
  13051. minLength: 1
  13052. pattern: ^[-._a-zA-Z0-9]+$
  13053. type: string
  13054. name:
  13055. description: The name of the Secret resource being referred to.
  13056. maxLength: 253
  13057. minLength: 1
  13058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13059. type: string
  13060. namespace:
  13061. description: |-
  13062. The namespace of the Secret resource being referred to.
  13063. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13064. maxLength: 63
  13065. minLength: 1
  13066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13067. type: string
  13068. type: object
  13069. type: object
  13070. version:
  13071. default: v2
  13072. description: |-
  13073. Version is the Vault KV secret engine version. This can be either "v1" or
  13074. "v2". Version defaults to "v2".
  13075. enum:
  13076. - v1
  13077. - v2
  13078. type: string
  13079. required:
  13080. - server
  13081. type: object
  13082. webhook:
  13083. description: Webhook configures this store to sync secrets using a generic templated webhook
  13084. properties:
  13085. auth:
  13086. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13087. maxProperties: 1
  13088. minProperties: 1
  13089. properties:
  13090. ntlm:
  13091. description: NTLMProtocol configures the store to use NTLM for auth
  13092. properties:
  13093. passwordSecret:
  13094. description: |-
  13095. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13096. In some instances, `key` is a required field.
  13097. properties:
  13098. key:
  13099. description: |-
  13100. A key in the referenced Secret.
  13101. Some instances of this field may be defaulted, in others it may be required.
  13102. maxLength: 253
  13103. minLength: 1
  13104. pattern: ^[-._a-zA-Z0-9]+$
  13105. type: string
  13106. name:
  13107. description: The name of the Secret resource being referred to.
  13108. maxLength: 253
  13109. minLength: 1
  13110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13111. type: string
  13112. namespace:
  13113. description: |-
  13114. The namespace of the Secret resource being referred to.
  13115. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13116. maxLength: 63
  13117. minLength: 1
  13118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13119. type: string
  13120. type: object
  13121. usernameSecret:
  13122. description: |-
  13123. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13124. In some instances, `key` is a required field.
  13125. properties:
  13126. key:
  13127. description: |-
  13128. A key in the referenced Secret.
  13129. Some instances of this field may be defaulted, in others it may be required.
  13130. maxLength: 253
  13131. minLength: 1
  13132. pattern: ^[-._a-zA-Z0-9]+$
  13133. type: string
  13134. name:
  13135. description: The name of the Secret resource being referred to.
  13136. maxLength: 253
  13137. minLength: 1
  13138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13139. type: string
  13140. namespace:
  13141. description: |-
  13142. The namespace of the Secret resource being referred to.
  13143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13144. maxLength: 63
  13145. minLength: 1
  13146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13147. type: string
  13148. type: object
  13149. required:
  13150. - passwordSecret
  13151. - usernameSecret
  13152. type: object
  13153. type: object
  13154. body:
  13155. description: Body
  13156. type: string
  13157. caBundle:
  13158. description: |-
  13159. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13160. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13161. plain HTTP protocol connection. If not set the system root certificates
  13162. are used to validate the TLS connection.
  13163. format: byte
  13164. type: string
  13165. caProvider:
  13166. description: The provider for the CA bundle to use to validate webhook server certificate.
  13167. properties:
  13168. key:
  13169. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13170. maxLength: 253
  13171. minLength: 1
  13172. pattern: ^[-._a-zA-Z0-9]+$
  13173. type: string
  13174. name:
  13175. description: The name of the object located at the provider type.
  13176. maxLength: 253
  13177. minLength: 1
  13178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13179. type: string
  13180. namespace:
  13181. description: The namespace the Provider type is in.
  13182. maxLength: 63
  13183. minLength: 1
  13184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13185. type: string
  13186. type:
  13187. description: The type of provider to use such as "Secret", or "ConfigMap".
  13188. enum:
  13189. - Secret
  13190. - ConfigMap
  13191. type: string
  13192. required:
  13193. - name
  13194. - type
  13195. type: object
  13196. headers:
  13197. additionalProperties:
  13198. type: string
  13199. description: Headers
  13200. type: object
  13201. method:
  13202. description: Webhook Method
  13203. type: string
  13204. result:
  13205. description: Result formatting
  13206. properties:
  13207. jsonPath:
  13208. description: Json path of return value
  13209. type: string
  13210. type: object
  13211. secrets:
  13212. description: |-
  13213. Secrets to fill in templates
  13214. These secrets will be passed to the templating function as key value pairs under the given name
  13215. items:
  13216. description: WebhookSecret defines a secret to be used in webhook templates.
  13217. properties:
  13218. name:
  13219. description: Name of this secret in templates
  13220. type: string
  13221. secretRef:
  13222. description: Secret ref to fill in credentials
  13223. properties:
  13224. key:
  13225. description: |-
  13226. A key in the referenced Secret.
  13227. Some instances of this field may be defaulted, in others it may be required.
  13228. maxLength: 253
  13229. minLength: 1
  13230. pattern: ^[-._a-zA-Z0-9]+$
  13231. type: string
  13232. name:
  13233. description: The name of the Secret resource being referred to.
  13234. maxLength: 253
  13235. minLength: 1
  13236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13237. type: string
  13238. namespace:
  13239. description: |-
  13240. The namespace of the Secret resource being referred to.
  13241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13242. maxLength: 63
  13243. minLength: 1
  13244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13245. type: string
  13246. type: object
  13247. required:
  13248. - name
  13249. - secretRef
  13250. type: object
  13251. type: array
  13252. timeout:
  13253. description: Timeout
  13254. type: string
  13255. url:
  13256. description: Webhook url to call
  13257. type: string
  13258. required:
  13259. - result
  13260. - url
  13261. type: object
  13262. yandexcertificatemanager:
  13263. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13264. properties:
  13265. apiEndpoint:
  13266. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13267. type: string
  13268. auth:
  13269. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13270. properties:
  13271. authorizedKeySecretRef:
  13272. description: The authorized key used for authentication
  13273. properties:
  13274. key:
  13275. description: |-
  13276. A key in the referenced Secret.
  13277. Some instances of this field may be defaulted, in others it may be required.
  13278. maxLength: 253
  13279. minLength: 1
  13280. pattern: ^[-._a-zA-Z0-9]+$
  13281. type: string
  13282. name:
  13283. description: The name of the Secret resource being referred to.
  13284. maxLength: 253
  13285. minLength: 1
  13286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13287. type: string
  13288. namespace:
  13289. description: |-
  13290. The namespace of the Secret resource being referred to.
  13291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13292. maxLength: 63
  13293. minLength: 1
  13294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13295. type: string
  13296. type: object
  13297. type: object
  13298. caProvider:
  13299. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13300. properties:
  13301. certSecretRef:
  13302. description: |-
  13303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13304. In some instances, `key` is a required field.
  13305. properties:
  13306. key:
  13307. description: |-
  13308. A key in the referenced Secret.
  13309. Some instances of this field may be defaulted, in others it may be required.
  13310. maxLength: 253
  13311. minLength: 1
  13312. pattern: ^[-._a-zA-Z0-9]+$
  13313. type: string
  13314. name:
  13315. description: The name of the Secret resource being referred to.
  13316. maxLength: 253
  13317. minLength: 1
  13318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13319. type: string
  13320. namespace:
  13321. description: |-
  13322. The namespace of the Secret resource being referred to.
  13323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13324. maxLength: 63
  13325. minLength: 1
  13326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13327. type: string
  13328. type: object
  13329. type: object
  13330. required:
  13331. - auth
  13332. type: object
  13333. yandexlockbox:
  13334. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13335. properties:
  13336. apiEndpoint:
  13337. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13338. type: string
  13339. auth:
  13340. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13341. properties:
  13342. authorizedKeySecretRef:
  13343. description: The authorized key used for authentication
  13344. properties:
  13345. key:
  13346. description: |-
  13347. A key in the referenced Secret.
  13348. Some instances of this field may be defaulted, in others it may be required.
  13349. maxLength: 253
  13350. minLength: 1
  13351. pattern: ^[-._a-zA-Z0-9]+$
  13352. type: string
  13353. name:
  13354. description: The name of the Secret resource being referred to.
  13355. maxLength: 253
  13356. minLength: 1
  13357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13358. type: string
  13359. namespace:
  13360. description: |-
  13361. The namespace of the Secret resource being referred to.
  13362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13363. maxLength: 63
  13364. minLength: 1
  13365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13366. type: string
  13367. type: object
  13368. type: object
  13369. caProvider:
  13370. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13371. properties:
  13372. certSecretRef:
  13373. description: |-
  13374. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13375. In some instances, `key` is a required field.
  13376. properties:
  13377. key:
  13378. description: |-
  13379. A key in the referenced Secret.
  13380. Some instances of this field may be defaulted, in others it may be required.
  13381. maxLength: 253
  13382. minLength: 1
  13383. pattern: ^[-._a-zA-Z0-9]+$
  13384. type: string
  13385. name:
  13386. description: The name of the Secret resource being referred to.
  13387. maxLength: 253
  13388. minLength: 1
  13389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13390. type: string
  13391. namespace:
  13392. description: |-
  13393. The namespace of the Secret resource being referred to.
  13394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13395. maxLength: 63
  13396. minLength: 1
  13397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13398. type: string
  13399. type: object
  13400. type: object
  13401. required:
  13402. - auth
  13403. type: object
  13404. type: object
  13405. refreshInterval:
  13406. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13407. type: integer
  13408. retrySettings:
  13409. description: Used to configure HTTP retries on failures.
  13410. properties:
  13411. maxRetries:
  13412. description: MaxRetries is the maximum number of retry attempts.
  13413. format: int32
  13414. type: integer
  13415. retryInterval:
  13416. description: RetryInterval is the interval between retry attempts.
  13417. type: string
  13418. type: object
  13419. required:
  13420. - provider
  13421. type: object
  13422. status:
  13423. description: SecretStoreStatus defines the observed state of the SecretStore.
  13424. properties:
  13425. capabilities:
  13426. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13427. type: string
  13428. conditions:
  13429. items:
  13430. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13431. properties:
  13432. lastTransitionTime:
  13433. format: date-time
  13434. type: string
  13435. message:
  13436. type: string
  13437. reason:
  13438. type: string
  13439. status:
  13440. type: string
  13441. type:
  13442. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13443. type: string
  13444. required:
  13445. - status
  13446. - type
  13447. type: object
  13448. type: array
  13449. type: object
  13450. type: object
  13451. served: false
  13452. storage: false
  13453. subresources:
  13454. status: {}
  13455. ---
  13456. apiVersion: apiextensions.k8s.io/v1
  13457. kind: CustomResourceDefinition
  13458. metadata:
  13459. annotations:
  13460. controller-gen.kubebuilder.io/version: v0.19.0
  13461. labels:
  13462. external-secrets.io/component: controller
  13463. name: externalsecrets.external-secrets.io
  13464. spec:
  13465. group: external-secrets.io
  13466. names:
  13467. categories:
  13468. - external-secrets
  13469. kind: ExternalSecret
  13470. listKind: ExternalSecretList
  13471. plural: externalsecrets
  13472. shortNames:
  13473. - es
  13474. singular: externalsecret
  13475. scope: Namespaced
  13476. versions:
  13477. - additionalPrinterColumns:
  13478. - jsonPath: .spec.secretStoreRef.kind
  13479. name: StoreType
  13480. type: string
  13481. - jsonPath: .spec.secretStoreRef.name
  13482. name: Store
  13483. type: string
  13484. - jsonPath: .spec.refreshInterval
  13485. name: Refresh Interval
  13486. type: string
  13487. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13488. name: Status
  13489. type: string
  13490. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13491. name: Ready
  13492. type: string
  13493. - jsonPath: .status.refreshTime
  13494. name: Last Sync
  13495. type: date
  13496. name: v1
  13497. schema:
  13498. openAPIV3Schema:
  13499. description: |-
  13500. ExternalSecret is the Schema for the external-secrets API.
  13501. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13502. properties:
  13503. apiVersion:
  13504. description: |-
  13505. APIVersion defines the versioned schema of this representation of an object.
  13506. Servers should convert recognized schemas to the latest internal value, and
  13507. may reject unrecognized values.
  13508. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13509. type: string
  13510. kind:
  13511. description: |-
  13512. Kind is a string value representing the REST resource this object represents.
  13513. Servers may infer this from the endpoint the client submits requests to.
  13514. Cannot be updated.
  13515. In CamelCase.
  13516. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13517. type: string
  13518. metadata:
  13519. type: object
  13520. spec:
  13521. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13522. properties:
  13523. data:
  13524. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13525. items:
  13526. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13527. properties:
  13528. remoteRef:
  13529. description: |-
  13530. RemoteRef points to the remote secret and defines
  13531. which secret (version/property/..) to fetch.
  13532. properties:
  13533. conversionStrategy:
  13534. default: Default
  13535. description: Used to define a conversion Strategy
  13536. enum:
  13537. - Default
  13538. - Unicode
  13539. type: string
  13540. decodingStrategy:
  13541. default: None
  13542. description: Used to define a decoding Strategy
  13543. enum:
  13544. - Auto
  13545. - Base64
  13546. - Base64URL
  13547. - None
  13548. type: string
  13549. key:
  13550. description: Key is the key used in the Provider, mandatory
  13551. type: string
  13552. metadataPolicy:
  13553. default: None
  13554. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13555. enum:
  13556. - None
  13557. - Fetch
  13558. type: string
  13559. nullBytePolicy:
  13560. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13561. enum:
  13562. - Ignore
  13563. - Fail
  13564. type: string
  13565. property:
  13566. description: Used to select a specific property of the Provider value (if a map), if supported
  13567. type: string
  13568. version:
  13569. description: Used to select a specific version of the Provider value, if supported
  13570. type: string
  13571. required:
  13572. - key
  13573. type: object
  13574. secretKey:
  13575. description: The key in the Kubernetes Secret to store the value.
  13576. maxLength: 253
  13577. minLength: 1
  13578. pattern: ^[-._a-zA-Z0-9]+$
  13579. type: string
  13580. sourceRef:
  13581. description: |-
  13582. SourceRef allows you to override the source
  13583. from which the value will be pulled.
  13584. maxProperties: 1
  13585. minProperties: 1
  13586. properties:
  13587. generatorRef:
  13588. description: |-
  13589. GeneratorRef points to a generator custom resource.
  13590. Deprecated: The generatorRef is not implemented in .data[].
  13591. this will be removed with v1.
  13592. properties:
  13593. apiVersion:
  13594. default: generators.external-secrets.io/v1alpha1
  13595. description: Specify the apiVersion of the generator resource
  13596. type: string
  13597. kind:
  13598. description: Specify the Kind of the generator resource
  13599. enum:
  13600. - ACRAccessToken
  13601. - BeyondtrustWorkloadCredentialsDynamicSecret
  13602. - ClusterGenerator
  13603. - CloudsmithAccessToken
  13604. - ECRAuthorizationToken
  13605. - Fake
  13606. - GCRAccessToken
  13607. - GithubAccessToken
  13608. - GitlabDeployToken
  13609. - QuayAccessToken
  13610. - Password
  13611. - SSHKey
  13612. - STSSessionToken
  13613. - UUID
  13614. - VaultDynamicSecret
  13615. - Webhook
  13616. - Grafana
  13617. - MFA
  13618. type: string
  13619. name:
  13620. description: Specify the name of the generator resource
  13621. maxLength: 253
  13622. minLength: 1
  13623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13624. type: string
  13625. required:
  13626. - kind
  13627. - name
  13628. type: object
  13629. storeRef:
  13630. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13631. properties:
  13632. kind:
  13633. description: |-
  13634. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13635. Defaults to `SecretStore`
  13636. enum:
  13637. - SecretStore
  13638. - ClusterSecretStore
  13639. type: string
  13640. name:
  13641. description: Name of the SecretStore resource
  13642. maxLength: 253
  13643. minLength: 1
  13644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13645. type: string
  13646. type: object
  13647. type: object
  13648. required:
  13649. - remoteRef
  13650. - secretKey
  13651. type: object
  13652. type: array
  13653. dataFrom:
  13654. description: |-
  13655. DataFrom is used to fetch all properties from a specific Provider data
  13656. If multiple entries are specified, the Secret keys are merged in the specified order
  13657. items:
  13658. description: |-
  13659. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13660. when using DataFrom to fetch multiple values from a Provider.
  13661. properties:
  13662. extract:
  13663. description: |-
  13664. Used to extract multiple key/value pairs from one secret
  13665. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13666. properties:
  13667. conversionStrategy:
  13668. default: Default
  13669. description: Used to define a conversion Strategy
  13670. enum:
  13671. - Default
  13672. - Unicode
  13673. type: string
  13674. decodingStrategy:
  13675. default: None
  13676. description: Used to define a decoding Strategy
  13677. enum:
  13678. - Auto
  13679. - Base64
  13680. - Base64URL
  13681. - None
  13682. type: string
  13683. key:
  13684. description: Key is the key used in the Provider, mandatory
  13685. type: string
  13686. metadataPolicy:
  13687. default: None
  13688. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13689. enum:
  13690. - None
  13691. - Fetch
  13692. type: string
  13693. nullBytePolicy:
  13694. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13695. enum:
  13696. - Ignore
  13697. - Fail
  13698. type: string
  13699. property:
  13700. description: Used to select a specific property of the Provider value (if a map), if supported
  13701. type: string
  13702. version:
  13703. description: Used to select a specific version of the Provider value, if supported
  13704. type: string
  13705. required:
  13706. - key
  13707. type: object
  13708. find:
  13709. description: |-
  13710. Used to find secrets based on tags or regular expressions
  13711. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13712. properties:
  13713. conversionStrategy:
  13714. default: Default
  13715. description: Used to define a conversion Strategy
  13716. enum:
  13717. - Default
  13718. - Unicode
  13719. type: string
  13720. decodingStrategy:
  13721. default: None
  13722. description: Used to define a decoding Strategy
  13723. enum:
  13724. - Auto
  13725. - Base64
  13726. - Base64URL
  13727. - None
  13728. type: string
  13729. name:
  13730. description: Finds secrets based on the name.
  13731. properties:
  13732. regexp:
  13733. description: Finds secrets base
  13734. type: string
  13735. type: object
  13736. nullBytePolicy:
  13737. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13738. enum:
  13739. - Ignore
  13740. - Fail
  13741. type: string
  13742. path:
  13743. description: A root path to start the find operations.
  13744. type: string
  13745. tags:
  13746. additionalProperties:
  13747. type: string
  13748. description: Find secrets based on tags.
  13749. type: object
  13750. type: object
  13751. rewrite:
  13752. description: |-
  13753. Used to rewrite secret Keys after getting them from the secret Provider
  13754. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13755. items:
  13756. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13757. maxProperties: 1
  13758. minProperties: 1
  13759. properties:
  13760. merge:
  13761. description: |-
  13762. Used to merge key/values in one single Secret
  13763. The resulting key will contain all values from the specified secrets
  13764. properties:
  13765. conflictPolicy:
  13766. default: Error
  13767. description: Used to define the policy to use in conflict resolution.
  13768. enum:
  13769. - Ignore
  13770. - Error
  13771. type: string
  13772. into:
  13773. default: ""
  13774. description: |-
  13775. Used to define the target key of the merge operation.
  13776. Required if strategy is JSON. Ignored otherwise.
  13777. type: string
  13778. priority:
  13779. description: Used to define key priority in conflict resolution.
  13780. items:
  13781. type: string
  13782. type: array
  13783. priorityPolicy:
  13784. default: Strict
  13785. description: Used to define the policy when a key in the priority list does not exist in the input.
  13786. enum:
  13787. - IgnoreNotFound
  13788. - Strict
  13789. type: string
  13790. strategy:
  13791. default: Extract
  13792. description: Used to define the strategy to use in the merge operation.
  13793. enum:
  13794. - Extract
  13795. - JSON
  13796. type: string
  13797. type: object
  13798. regexp:
  13799. description: |-
  13800. Used to rewrite with regular expressions.
  13801. The resulting key will be the output of a regexp.ReplaceAll operation.
  13802. properties:
  13803. source:
  13804. description: Used to define the regular expression of a re.Compiler.
  13805. type: string
  13806. target:
  13807. description: Used to define the target pattern of a ReplaceAll operation.
  13808. type: string
  13809. required:
  13810. - source
  13811. - target
  13812. type: object
  13813. transform:
  13814. description: |-
  13815. Used to apply string transformation on the secrets.
  13816. The resulting key will be the output of the template applied by the operation.
  13817. properties:
  13818. template:
  13819. description: |-
  13820. Used to define the template to apply on the secret name.
  13821. `.value ` will specify the secret name in the template.
  13822. type: string
  13823. required:
  13824. - template
  13825. type: object
  13826. type: object
  13827. type: array
  13828. sourceRef:
  13829. description: |-
  13830. SourceRef points to a store or generator
  13831. which contains secret values ready to use.
  13832. Use this in combination with Extract or Find pull values out of
  13833. a specific SecretStore.
  13834. When sourceRef points to a generator Extract or Find is not supported.
  13835. The generator returns a static map of values
  13836. maxProperties: 1
  13837. minProperties: 1
  13838. properties:
  13839. generatorRef:
  13840. description: GeneratorRef points to a generator custom resource.
  13841. properties:
  13842. apiVersion:
  13843. default: generators.external-secrets.io/v1alpha1
  13844. description: Specify the apiVersion of the generator resource
  13845. type: string
  13846. kind:
  13847. description: Specify the Kind of the generator resource
  13848. enum:
  13849. - ACRAccessToken
  13850. - BeyondtrustWorkloadCredentialsDynamicSecret
  13851. - ClusterGenerator
  13852. - CloudsmithAccessToken
  13853. - ECRAuthorizationToken
  13854. - Fake
  13855. - GCRAccessToken
  13856. - GithubAccessToken
  13857. - GitlabDeployToken
  13858. - QuayAccessToken
  13859. - Password
  13860. - SSHKey
  13861. - STSSessionToken
  13862. - UUID
  13863. - VaultDynamicSecret
  13864. - Webhook
  13865. - Grafana
  13866. - MFA
  13867. type: string
  13868. name:
  13869. description: Specify the name of the generator resource
  13870. maxLength: 253
  13871. minLength: 1
  13872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13873. type: string
  13874. required:
  13875. - kind
  13876. - name
  13877. type: object
  13878. storeRef:
  13879. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13880. properties:
  13881. kind:
  13882. description: |-
  13883. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13884. Defaults to `SecretStore`
  13885. enum:
  13886. - SecretStore
  13887. - ClusterSecretStore
  13888. type: string
  13889. name:
  13890. description: Name of the SecretStore resource
  13891. maxLength: 253
  13892. minLength: 1
  13893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13894. type: string
  13895. type: object
  13896. type: object
  13897. type: object
  13898. type: array
  13899. refreshInterval:
  13900. default: 1h0m0s
  13901. description: |-
  13902. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13903. specified as Golang Duration strings.
  13904. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13905. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13906. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13907. type: string
  13908. refreshPolicy:
  13909. description: |-
  13910. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13911. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13912. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13913. No periodic updates occur if refreshInterval is 0.
  13914. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13915. enum:
  13916. - CreatedOnce
  13917. - Periodic
  13918. - OnChange
  13919. type: string
  13920. secretStoreRef:
  13921. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13922. properties:
  13923. kind:
  13924. description: |-
  13925. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13926. Defaults to `SecretStore`
  13927. enum:
  13928. - SecretStore
  13929. - ClusterSecretStore
  13930. type: string
  13931. name:
  13932. description: Name of the SecretStore resource
  13933. maxLength: 253
  13934. minLength: 1
  13935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13936. type: string
  13937. type: object
  13938. syncWindows:
  13939. description: |-
  13940. SyncWindows optionally restricts when periodic refreshes may occur.
  13941. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13942. properties:
  13943. kind:
  13944. description: |-
  13945. Kind applies to every window in the list.
  13946. "allow" -- syncs are permitted only while at least one window is active;
  13947. all other times are blocked.
  13948. "deny" -- syncs are blocked while any window is active;
  13949. all other times are permitted.
  13950. enum:
  13951. - allow
  13952. - deny
  13953. type: string
  13954. windows:
  13955. description: Windows is the list of schedule+duration pairs.
  13956. items:
  13957. description: |-
  13958. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13959. within a SyncWindows block.
  13960. properties:
  13961. duration:
  13962. description: |-
  13963. Duration specifies how long the window stays open after each Schedule
  13964. firing. Example: "8h".
  13965. type: string
  13966. schedule:
  13967. description: |-
  13968. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13969. named shorthand such as @daily or @every 1h. It marks the start time of
  13970. each window occurrence.
  13971. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13972. minLength: 1
  13973. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13974. type: string
  13975. required:
  13976. - duration
  13977. - schedule
  13978. type: object
  13979. minItems: 1
  13980. type: array
  13981. required:
  13982. - kind
  13983. - windows
  13984. type: object
  13985. target:
  13986. default:
  13987. creationPolicy: Owner
  13988. deletionPolicy: Retain
  13989. description: |-
  13990. ExternalSecretTarget defines the Kubernetes Secret to be created,
  13991. there can be only one target per ExternalSecret.
  13992. properties:
  13993. creationPolicy:
  13994. default: Owner
  13995. description: |-
  13996. CreationPolicy defines rules on how to create the resulting Secret.
  13997. Defaults to "Owner"
  13998. enum:
  13999. - Owner
  14000. - Orphan
  14001. - Merge
  14002. - None
  14003. - CreateOrMerge
  14004. type: string
  14005. deletionPolicy:
  14006. default: Retain
  14007. description: |-
  14008. DeletionPolicy defines rules on how to delete the resulting Secret.
  14009. Defaults to "Retain"
  14010. enum:
  14011. - Delete
  14012. - Merge
  14013. - Retain
  14014. type: string
  14015. immutable:
  14016. description: Immutable defines if the final secret will be immutable
  14017. type: boolean
  14018. manifest:
  14019. description: |-
  14020. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14021. When specified, ExternalSecret will create the resource type defined here
  14022. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14023. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14024. properties:
  14025. apiVersion:
  14026. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14027. minLength: 1
  14028. type: string
  14029. kind:
  14030. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14031. minLength: 1
  14032. type: string
  14033. required:
  14034. - apiVersion
  14035. - kind
  14036. type: object
  14037. name:
  14038. description: |-
  14039. The name of the Secret resource to be managed.
  14040. Defaults to the .metadata.name of the ExternalSecret resource
  14041. maxLength: 253
  14042. minLength: 1
  14043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14044. type: string
  14045. template:
  14046. description: Template defines a blueprint for the created Secret resource.
  14047. properties:
  14048. data:
  14049. additionalProperties:
  14050. type: string
  14051. type: object
  14052. engineVersion:
  14053. default: v2
  14054. description: |-
  14055. EngineVersion specifies the template engine version
  14056. that should be used to compile/execute the
  14057. template specified in .data and .templateFrom[].
  14058. enum:
  14059. - v2
  14060. type: string
  14061. mergePolicy:
  14062. default: Replace
  14063. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14064. enum:
  14065. - Replace
  14066. - Merge
  14067. type: string
  14068. metadata:
  14069. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14070. properties:
  14071. annotations:
  14072. additionalProperties:
  14073. type: string
  14074. type: object
  14075. finalizers:
  14076. items:
  14077. type: string
  14078. type: array
  14079. labels:
  14080. additionalProperties:
  14081. type: string
  14082. type: object
  14083. type: object
  14084. templateFrom:
  14085. items:
  14086. description: |-
  14087. TemplateFrom specifies a source for templates.
  14088. Each item in the list can either reference a ConfigMap or a Secret resource.
  14089. properties:
  14090. configMap:
  14091. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14092. properties:
  14093. items:
  14094. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14095. items:
  14096. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14097. properties:
  14098. key:
  14099. description: A key in the ConfigMap/Secret
  14100. maxLength: 253
  14101. minLength: 1
  14102. pattern: ^[-._a-zA-Z0-9]+$
  14103. type: string
  14104. templateAs:
  14105. default: Values
  14106. description: TemplateScope specifies how the template keys should be interpreted.
  14107. enum:
  14108. - Values
  14109. - KeysAndValues
  14110. type: string
  14111. required:
  14112. - key
  14113. type: object
  14114. type: array
  14115. name:
  14116. description: The name of the ConfigMap/Secret resource
  14117. maxLength: 253
  14118. minLength: 1
  14119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14120. type: string
  14121. required:
  14122. - items
  14123. - name
  14124. type: object
  14125. literal:
  14126. type: string
  14127. secret:
  14128. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14129. properties:
  14130. items:
  14131. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14132. items:
  14133. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14134. properties:
  14135. key:
  14136. description: A key in the ConfigMap/Secret
  14137. maxLength: 253
  14138. minLength: 1
  14139. pattern: ^[-._a-zA-Z0-9]+$
  14140. type: string
  14141. templateAs:
  14142. default: Values
  14143. description: TemplateScope specifies how the template keys should be interpreted.
  14144. enum:
  14145. - Values
  14146. - KeysAndValues
  14147. type: string
  14148. required:
  14149. - key
  14150. type: object
  14151. type: array
  14152. name:
  14153. description: The name of the ConfigMap/Secret resource
  14154. maxLength: 253
  14155. minLength: 1
  14156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14157. type: string
  14158. required:
  14159. - items
  14160. - name
  14161. type: object
  14162. target:
  14163. default: Data
  14164. description: |-
  14165. Target specifies where to place the template result.
  14166. For Secret resources, common values are: "Data", "Annotations", "Labels".
  14167. For custom resources (when spec.target.manifest is set), this supports
  14168. nested paths like "spec.database.config" or "data".
  14169. type: string
  14170. valuesDecodingStrategy:
  14171. default: None
  14172. description: Used to define a decoding Strategy for the rendered template values.
  14173. enum:
  14174. - Auto
  14175. - Base64
  14176. - Base64URL
  14177. - None
  14178. type: string
  14179. type: object
  14180. type: array
  14181. type:
  14182. type: string
  14183. type: object
  14184. type: object
  14185. type: object
  14186. status:
  14187. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14188. properties:
  14189. binding:
  14190. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14191. properties:
  14192. name:
  14193. default: ""
  14194. description: |-
  14195. Name of the referent.
  14196. This field is effectively required, but due to backwards compatibility is
  14197. allowed to be empty. Instances of this type with an empty value here are
  14198. almost certainly wrong.
  14199. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14200. type: string
  14201. type: object
  14202. x-kubernetes-map-type: atomic
  14203. conditions:
  14204. items:
  14205. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14206. properties:
  14207. lastTransitionTime:
  14208. format: date-time
  14209. type: string
  14210. message:
  14211. type: string
  14212. reason:
  14213. type: string
  14214. status:
  14215. type: string
  14216. type:
  14217. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14218. enum:
  14219. - Ready
  14220. - Deleted
  14221. type: string
  14222. required:
  14223. - status
  14224. - type
  14225. type: object
  14226. type: array
  14227. refreshTime:
  14228. description: |-
  14229. refreshTime is the time and date the external secret was fetched and
  14230. the target secret updated
  14231. format: date-time
  14232. nullable: true
  14233. type: string
  14234. syncedResourceVersion:
  14235. description: SyncedResourceVersion keeps track of the last synced version
  14236. type: string
  14237. type: object
  14238. type: object
  14239. selectableFields:
  14240. - jsonPath: .spec.secretStoreRef.name
  14241. - jsonPath: .spec.secretStoreRef.kind
  14242. - jsonPath: .spec.target.name
  14243. - jsonPath: .spec.refreshInterval
  14244. served: true
  14245. storage: true
  14246. subresources:
  14247. status: {}
  14248. - additionalPrinterColumns:
  14249. - jsonPath: .spec.secretStoreRef.kind
  14250. name: StoreType
  14251. type: string
  14252. - jsonPath: .spec.secretStoreRef.name
  14253. name: Store
  14254. type: string
  14255. - jsonPath: .spec.refreshInterval
  14256. name: Refresh Interval
  14257. type: string
  14258. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14259. name: Status
  14260. type: string
  14261. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14262. name: Ready
  14263. type: string
  14264. - jsonPath: .status.refreshTime
  14265. name: Last Sync
  14266. type: date
  14267. deprecated: true
  14268. name: v1beta1
  14269. schema:
  14270. openAPIV3Schema:
  14271. description: ExternalSecret is the schema for the external-secrets API.
  14272. properties:
  14273. apiVersion:
  14274. description: |-
  14275. APIVersion defines the versioned schema of this representation of an object.
  14276. Servers should convert recognized schemas to the latest internal value, and
  14277. may reject unrecognized values.
  14278. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14279. type: string
  14280. kind:
  14281. description: |-
  14282. Kind is a string value representing the REST resource this object represents.
  14283. Servers may infer this from the endpoint the client submits requests to.
  14284. Cannot be updated.
  14285. In CamelCase.
  14286. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14287. type: string
  14288. metadata:
  14289. type: object
  14290. spec:
  14291. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14292. properties:
  14293. data:
  14294. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14295. items:
  14296. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14297. properties:
  14298. remoteRef:
  14299. description: |-
  14300. RemoteRef points to the remote secret and defines
  14301. which secret (version/property/..) to fetch.
  14302. properties:
  14303. conversionStrategy:
  14304. default: Default
  14305. description: Used to define a conversion Strategy
  14306. enum:
  14307. - Default
  14308. - Unicode
  14309. type: string
  14310. decodingStrategy:
  14311. default: None
  14312. description: Used to define a decoding Strategy
  14313. enum:
  14314. - Auto
  14315. - Base64
  14316. - Base64URL
  14317. - None
  14318. type: string
  14319. key:
  14320. description: Key is the key used in the Provider, mandatory
  14321. type: string
  14322. metadataPolicy:
  14323. default: None
  14324. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14325. enum:
  14326. - None
  14327. - Fetch
  14328. type: string
  14329. property:
  14330. description: Used to select a specific property of the Provider value (if a map), if supported
  14331. type: string
  14332. version:
  14333. description: Used to select a specific version of the Provider value, if supported
  14334. type: string
  14335. required:
  14336. - key
  14337. type: object
  14338. secretKey:
  14339. description: The key in the Kubernetes Secret to store the value.
  14340. maxLength: 253
  14341. minLength: 1
  14342. pattern: ^[-._a-zA-Z0-9]+$
  14343. type: string
  14344. sourceRef:
  14345. description: |-
  14346. SourceRef allows you to override the source
  14347. from which the value will be pulled.
  14348. maxProperties: 1
  14349. minProperties: 1
  14350. properties:
  14351. generatorRef:
  14352. description: |-
  14353. GeneratorRef points to a generator custom resource.
  14354. Deprecated: The generatorRef is not implemented in .data[].
  14355. this will be removed with v1.
  14356. properties:
  14357. apiVersion:
  14358. default: generators.external-secrets.io/v1alpha1
  14359. description: Specify the apiVersion of the generator resource
  14360. type: string
  14361. kind:
  14362. description: Specify the Kind of the generator resource
  14363. enum:
  14364. - ACRAccessToken
  14365. - ClusterGenerator
  14366. - ECRAuthorizationToken
  14367. - Fake
  14368. - GCRAccessToken
  14369. - GithubAccessToken
  14370. - QuayAccessToken
  14371. - Password
  14372. - SSHKey
  14373. - STSSessionToken
  14374. - UUID
  14375. - VaultDynamicSecret
  14376. - Webhook
  14377. - Grafana
  14378. type: string
  14379. name:
  14380. description: Specify the name of the generator resource
  14381. maxLength: 253
  14382. minLength: 1
  14383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14384. type: string
  14385. required:
  14386. - kind
  14387. - name
  14388. type: object
  14389. storeRef:
  14390. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14391. properties:
  14392. kind:
  14393. description: |-
  14394. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14395. Defaults to `SecretStore`
  14396. enum:
  14397. - SecretStore
  14398. - ClusterSecretStore
  14399. type: string
  14400. name:
  14401. description: Name of the SecretStore resource
  14402. maxLength: 253
  14403. minLength: 1
  14404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14405. type: string
  14406. type: object
  14407. type: object
  14408. required:
  14409. - remoteRef
  14410. - secretKey
  14411. type: object
  14412. type: array
  14413. dataFrom:
  14414. description: |-
  14415. DataFrom is used to fetch all properties from a specific Provider data
  14416. If multiple entries are specified, the Secret keys are merged in the specified order
  14417. items:
  14418. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14419. properties:
  14420. extract:
  14421. description: |-
  14422. Used to extract multiple key/value pairs from one secret
  14423. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14424. properties:
  14425. conversionStrategy:
  14426. default: Default
  14427. description: Used to define a conversion Strategy
  14428. enum:
  14429. - Default
  14430. - Unicode
  14431. type: string
  14432. decodingStrategy:
  14433. default: None
  14434. description: Used to define a decoding Strategy
  14435. enum:
  14436. - Auto
  14437. - Base64
  14438. - Base64URL
  14439. - None
  14440. type: string
  14441. key:
  14442. description: Key is the key used in the Provider, mandatory
  14443. type: string
  14444. metadataPolicy:
  14445. default: None
  14446. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14447. enum:
  14448. - None
  14449. - Fetch
  14450. type: string
  14451. property:
  14452. description: Used to select a specific property of the Provider value (if a map), if supported
  14453. type: string
  14454. version:
  14455. description: Used to select a specific version of the Provider value, if supported
  14456. type: string
  14457. required:
  14458. - key
  14459. type: object
  14460. find:
  14461. description: |-
  14462. Used to find secrets based on tags or regular expressions
  14463. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14464. properties:
  14465. conversionStrategy:
  14466. default: Default
  14467. description: Used to define a conversion Strategy
  14468. enum:
  14469. - Default
  14470. - Unicode
  14471. type: string
  14472. decodingStrategy:
  14473. default: None
  14474. description: Used to define a decoding Strategy
  14475. enum:
  14476. - Auto
  14477. - Base64
  14478. - Base64URL
  14479. - None
  14480. type: string
  14481. name:
  14482. description: Finds secrets based on the name.
  14483. properties:
  14484. regexp:
  14485. description: Finds secrets base
  14486. type: string
  14487. type: object
  14488. path:
  14489. description: A root path to start the find operations.
  14490. type: string
  14491. tags:
  14492. additionalProperties:
  14493. type: string
  14494. description: Find secrets based on tags.
  14495. type: object
  14496. type: object
  14497. rewrite:
  14498. description: |-
  14499. Used to rewrite secret Keys after getting them from the secret Provider
  14500. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14501. items:
  14502. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14503. maxProperties: 1
  14504. minProperties: 1
  14505. properties:
  14506. regexp:
  14507. description: |-
  14508. Used to rewrite with regular expressions.
  14509. The resulting key will be the output of a regexp.ReplaceAll operation.
  14510. properties:
  14511. source:
  14512. description: Used to define the regular expression of a re.Compiler.
  14513. type: string
  14514. target:
  14515. description: Used to define the target pattern of a ReplaceAll operation.
  14516. type: string
  14517. required:
  14518. - source
  14519. - target
  14520. type: object
  14521. transform:
  14522. description: |-
  14523. Used to apply string transformation on the secrets.
  14524. The resulting key will be the output of the template applied by the operation.
  14525. properties:
  14526. template:
  14527. description: |-
  14528. Used to define the template to apply on the secret name.
  14529. `.value ` will specify the secret name in the template.
  14530. type: string
  14531. required:
  14532. - template
  14533. type: object
  14534. type: object
  14535. type: array
  14536. sourceRef:
  14537. description: |-
  14538. SourceRef points to a store or generator
  14539. which contains secret values ready to use.
  14540. Use this in combination with Extract or Find pull values out of
  14541. a specific SecretStore.
  14542. When sourceRef points to a generator Extract or Find is not supported.
  14543. The generator returns a static map of values
  14544. maxProperties: 1
  14545. minProperties: 1
  14546. properties:
  14547. generatorRef:
  14548. description: GeneratorRef points to a generator custom resource.
  14549. properties:
  14550. apiVersion:
  14551. default: generators.external-secrets.io/v1alpha1
  14552. description: Specify the apiVersion of the generator resource
  14553. type: string
  14554. kind:
  14555. description: Specify the Kind of the generator resource
  14556. enum:
  14557. - ACRAccessToken
  14558. - ClusterGenerator
  14559. - ECRAuthorizationToken
  14560. - Fake
  14561. - GCRAccessToken
  14562. - GithubAccessToken
  14563. - QuayAccessToken
  14564. - Password
  14565. - SSHKey
  14566. - STSSessionToken
  14567. - UUID
  14568. - VaultDynamicSecret
  14569. - Webhook
  14570. - Grafana
  14571. type: string
  14572. name:
  14573. description: Specify the name of the generator resource
  14574. maxLength: 253
  14575. minLength: 1
  14576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14577. type: string
  14578. required:
  14579. - kind
  14580. - name
  14581. type: object
  14582. storeRef:
  14583. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14584. properties:
  14585. kind:
  14586. description: |-
  14587. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14588. Defaults to `SecretStore`
  14589. enum:
  14590. - SecretStore
  14591. - ClusterSecretStore
  14592. type: string
  14593. name:
  14594. description: Name of the SecretStore resource
  14595. maxLength: 253
  14596. minLength: 1
  14597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14598. type: string
  14599. type: object
  14600. type: object
  14601. type: object
  14602. type: array
  14603. refreshInterval:
  14604. default: 1h0m0s
  14605. description: |-
  14606. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14607. specified as Golang Duration strings.
  14608. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14609. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14610. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14611. type: string
  14612. refreshPolicy:
  14613. description: |-
  14614. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14615. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14616. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14617. No periodic updates occur if refreshInterval is 0.
  14618. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14619. enum:
  14620. - CreatedOnce
  14621. - Periodic
  14622. - OnChange
  14623. type: string
  14624. secretStoreRef:
  14625. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14626. properties:
  14627. kind:
  14628. description: |-
  14629. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14630. Defaults to `SecretStore`
  14631. enum:
  14632. - SecretStore
  14633. - ClusterSecretStore
  14634. type: string
  14635. name:
  14636. description: Name of the SecretStore resource
  14637. maxLength: 253
  14638. minLength: 1
  14639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14640. type: string
  14641. type: object
  14642. target:
  14643. default:
  14644. creationPolicy: Owner
  14645. deletionPolicy: Retain
  14646. description: |-
  14647. ExternalSecretTarget defines the Kubernetes Secret to be created
  14648. There can be only one target per ExternalSecret.
  14649. properties:
  14650. creationPolicy:
  14651. default: Owner
  14652. description: |-
  14653. CreationPolicy defines rules on how to create the resulting Secret.
  14654. Defaults to "Owner"
  14655. enum:
  14656. - Owner
  14657. - Orphan
  14658. - Merge
  14659. - None
  14660. type: string
  14661. deletionPolicy:
  14662. default: Retain
  14663. description: |-
  14664. DeletionPolicy defines rules on how to delete the resulting Secret.
  14665. Defaults to "Retain"
  14666. enum:
  14667. - Delete
  14668. - Merge
  14669. - Retain
  14670. type: string
  14671. immutable:
  14672. description: Immutable defines if the final secret will be immutable
  14673. type: boolean
  14674. name:
  14675. description: |-
  14676. The name of the Secret resource to be managed.
  14677. Defaults to the .metadata.name of the ExternalSecret resource
  14678. maxLength: 253
  14679. minLength: 1
  14680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14681. type: string
  14682. template:
  14683. description: Template defines a blueprint for the created Secret resource.
  14684. properties:
  14685. data:
  14686. additionalProperties:
  14687. type: string
  14688. type: object
  14689. engineVersion:
  14690. default: v2
  14691. description: |-
  14692. EngineVersion specifies the template engine version
  14693. that should be used to compile/execute the
  14694. template specified in .data and .templateFrom[].
  14695. enum:
  14696. - v2
  14697. type: string
  14698. mergePolicy:
  14699. default: Replace
  14700. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14701. enum:
  14702. - Replace
  14703. - Merge
  14704. type: string
  14705. metadata:
  14706. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14707. properties:
  14708. annotations:
  14709. additionalProperties:
  14710. type: string
  14711. type: object
  14712. labels:
  14713. additionalProperties:
  14714. type: string
  14715. type: object
  14716. type: object
  14717. templateFrom:
  14718. items:
  14719. description: TemplateFrom defines a source for template data.
  14720. properties:
  14721. configMap:
  14722. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14723. properties:
  14724. items:
  14725. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14726. items:
  14727. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14728. properties:
  14729. key:
  14730. description: A key in the ConfigMap/Secret
  14731. maxLength: 253
  14732. minLength: 1
  14733. pattern: ^[-._a-zA-Z0-9]+$
  14734. type: string
  14735. templateAs:
  14736. default: Values
  14737. description: TemplateScope defines the scope of the template when processing template data.
  14738. enum:
  14739. - Values
  14740. - KeysAndValues
  14741. type: string
  14742. required:
  14743. - key
  14744. type: object
  14745. type: array
  14746. name:
  14747. description: The name of the ConfigMap/Secret resource
  14748. maxLength: 253
  14749. minLength: 1
  14750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14751. type: string
  14752. required:
  14753. - items
  14754. - name
  14755. type: object
  14756. literal:
  14757. type: string
  14758. secret:
  14759. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14760. properties:
  14761. items:
  14762. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14763. items:
  14764. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14765. properties:
  14766. key:
  14767. description: A key in the ConfigMap/Secret
  14768. maxLength: 253
  14769. minLength: 1
  14770. pattern: ^[-._a-zA-Z0-9]+$
  14771. type: string
  14772. templateAs:
  14773. default: Values
  14774. description: TemplateScope defines the scope of the template when processing template data.
  14775. enum:
  14776. - Values
  14777. - KeysAndValues
  14778. type: string
  14779. required:
  14780. - key
  14781. type: object
  14782. type: array
  14783. name:
  14784. description: The name of the ConfigMap/Secret resource
  14785. maxLength: 253
  14786. minLength: 1
  14787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14788. type: string
  14789. required:
  14790. - items
  14791. - name
  14792. type: object
  14793. target:
  14794. default: Data
  14795. description: TemplateTarget defines the target field where the template result will be stored.
  14796. enum:
  14797. - Data
  14798. - Annotations
  14799. - Labels
  14800. type: string
  14801. type: object
  14802. type: array
  14803. type:
  14804. type: string
  14805. type: object
  14806. type: object
  14807. type: object
  14808. status:
  14809. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14810. properties:
  14811. binding:
  14812. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14813. properties:
  14814. name:
  14815. default: ""
  14816. description: |-
  14817. Name of the referent.
  14818. This field is effectively required, but due to backwards compatibility is
  14819. allowed to be empty. Instances of this type with an empty value here are
  14820. almost certainly wrong.
  14821. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14822. type: string
  14823. type: object
  14824. x-kubernetes-map-type: atomic
  14825. conditions:
  14826. items:
  14827. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14828. properties:
  14829. lastTransitionTime:
  14830. format: date-time
  14831. type: string
  14832. message:
  14833. type: string
  14834. reason:
  14835. type: string
  14836. status:
  14837. type: string
  14838. type:
  14839. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14840. type: string
  14841. required:
  14842. - status
  14843. - type
  14844. type: object
  14845. type: array
  14846. refreshTime:
  14847. description: |-
  14848. refreshTime is the time and date the external secret was fetched and
  14849. the target secret updated
  14850. format: date-time
  14851. nullable: true
  14852. type: string
  14853. syncedResourceVersion:
  14854. description: SyncedResourceVersion keeps track of the last synced version
  14855. type: string
  14856. type: object
  14857. type: object
  14858. served: false
  14859. storage: false
  14860. subresources:
  14861. status: {}
  14862. ---
  14863. apiVersion: apiextensions.k8s.io/v1
  14864. kind: CustomResourceDefinition
  14865. metadata:
  14866. annotations:
  14867. controller-gen.kubebuilder.io/version: v0.19.0
  14868. labels:
  14869. external-secrets.io/component: controller
  14870. name: pushsecrets.external-secrets.io
  14871. spec:
  14872. group: external-secrets.io
  14873. names:
  14874. categories:
  14875. - external-secrets
  14876. kind: PushSecret
  14877. listKind: PushSecretList
  14878. plural: pushsecrets
  14879. shortNames:
  14880. - ps
  14881. singular: pushsecret
  14882. scope: Namespaced
  14883. versions:
  14884. - additionalPrinterColumns:
  14885. - jsonPath: .metadata.creationTimestamp
  14886. name: AGE
  14887. type: date
  14888. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14889. name: Status
  14890. type: string
  14891. - jsonPath: .status.refreshTime
  14892. name: Last Sync
  14893. type: date
  14894. name: v1alpha1
  14895. schema:
  14896. openAPIV3Schema:
  14897. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14898. properties:
  14899. apiVersion:
  14900. description: |-
  14901. APIVersion defines the versioned schema of this representation of an object.
  14902. Servers should convert recognized schemas to the latest internal value, and
  14903. may reject unrecognized values.
  14904. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14905. type: string
  14906. kind:
  14907. description: |-
  14908. Kind is a string value representing the REST resource this object represents.
  14909. Servers may infer this from the endpoint the client submits requests to.
  14910. Cannot be updated.
  14911. In CamelCase.
  14912. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14913. type: string
  14914. metadata:
  14915. type: object
  14916. spec:
  14917. description: PushSecretSpec configures the behavior of the PushSecret.
  14918. properties:
  14919. data:
  14920. description: Secret Data that should be pushed to providers
  14921. items:
  14922. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14923. properties:
  14924. conversionStrategy:
  14925. default: None
  14926. description: Used to define a conversion Strategy for the secret keys
  14927. enum:
  14928. - None
  14929. - ReverseUnicode
  14930. type: string
  14931. match:
  14932. description: Match a given Secret Key to be pushed to the provider.
  14933. properties:
  14934. remoteRef:
  14935. description: Remote Refs to push to providers.
  14936. properties:
  14937. property:
  14938. description: Name of the property in the resulting secret
  14939. type: string
  14940. remoteKey:
  14941. description: Name of the resulting provider secret.
  14942. type: string
  14943. required:
  14944. - remoteKey
  14945. type: object
  14946. secretKey:
  14947. description: Secret Key to be pushed
  14948. type: string
  14949. required:
  14950. - remoteRef
  14951. type: object
  14952. metadata:
  14953. description: |-
  14954. Metadata is metadata attached to the secret.
  14955. The structure of metadata is provider specific, please look it up in the provider documentation.
  14956. x-kubernetes-preserve-unknown-fields: true
  14957. required:
  14958. - match
  14959. type: object
  14960. type: array
  14961. dataTo:
  14962. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14963. items:
  14964. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14965. properties:
  14966. conversionStrategy:
  14967. default: None
  14968. description: Used to define a conversion Strategy for the secret keys
  14969. enum:
  14970. - None
  14971. - ReverseUnicode
  14972. type: string
  14973. match:
  14974. description: |-
  14975. Match pattern for selecting keys from the source Secret.
  14976. If not specified, all keys are selected.
  14977. properties:
  14978. regexp:
  14979. description: |-
  14980. Regexp matches keys by regular expression.
  14981. If not specified, all keys are matched.
  14982. type: string
  14983. type: object
  14984. metadata:
  14985. description: |-
  14986. Metadata is metadata attached to the secret.
  14987. The structure of metadata is provider specific, please look it up in the provider documentation.
  14988. x-kubernetes-preserve-unknown-fields: true
  14989. remoteKey:
  14990. description: |-
  14991. RemoteKey is the name of the single provider secret that will receive ALL
  14992. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  14993. When set, per-key expansion is skipped and a single push is performed.
  14994. The provider's store prefix (if any) is still prepended to this value.
  14995. When not set, each matched key is pushed as its own individual provider secret.
  14996. type: string
  14997. rewrite:
  14998. description: |-
  14999. Rewrite operations to transform keys before pushing to the provider.
  15000. Operations are applied sequentially.
  15001. items:
  15002. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15003. properties:
  15004. regexp:
  15005. description: Used to rewrite with regular expressions.
  15006. properties:
  15007. source:
  15008. description: Used to define the regular expression of a re.Compiler.
  15009. type: string
  15010. target:
  15011. description: Used to define the target pattern of a ReplaceAll operation.
  15012. type: string
  15013. required:
  15014. - source
  15015. - target
  15016. type: object
  15017. transform:
  15018. description: Used to apply string transformation on the secrets.
  15019. properties:
  15020. template:
  15021. description: |-
  15022. Used to define the template to apply on the secret name.
  15023. `.value ` will specify the secret name in the template.
  15024. type: string
  15025. required:
  15026. - template
  15027. type: object
  15028. type: object
  15029. x-kubernetes-validations:
  15030. - message: exactly one of regexp or transform must be set
  15031. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15032. type: array
  15033. storeRef:
  15034. description: StoreRef specifies which SecretStore to push to. Required.
  15035. properties:
  15036. kind:
  15037. default: SecretStore
  15038. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15039. enum:
  15040. - SecretStore
  15041. - ClusterSecretStore
  15042. type: string
  15043. labelSelector:
  15044. description: Optionally, sync to secret stores with label selector
  15045. properties:
  15046. matchExpressions:
  15047. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15048. items:
  15049. description: |-
  15050. A label selector requirement is a selector that contains values, a key, and an operator that
  15051. relates the key and values.
  15052. properties:
  15053. key:
  15054. description: key is the label key that the selector applies to.
  15055. type: string
  15056. operator:
  15057. description: |-
  15058. operator represents a key's relationship to a set of values.
  15059. Valid operators are In, NotIn, Exists and DoesNotExist.
  15060. type: string
  15061. values:
  15062. description: |-
  15063. values is an array of string values. If the operator is In or NotIn,
  15064. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15065. the values array must be empty. This array is replaced during a strategic
  15066. merge patch.
  15067. items:
  15068. type: string
  15069. type: array
  15070. x-kubernetes-list-type: atomic
  15071. required:
  15072. - key
  15073. - operator
  15074. type: object
  15075. type: array
  15076. x-kubernetes-list-type: atomic
  15077. matchLabels:
  15078. additionalProperties:
  15079. type: string
  15080. description: |-
  15081. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15082. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15083. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15084. type: object
  15085. type: object
  15086. x-kubernetes-map-type: atomic
  15087. name:
  15088. description: Optionally, sync to the SecretStore of the given name
  15089. maxLength: 253
  15090. minLength: 1
  15091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15092. type: string
  15093. type: object
  15094. type: object
  15095. x-kubernetes-validations:
  15096. - message: storeRef must specify either name or labelSelector
  15097. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15098. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15099. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15100. type: array
  15101. deletionPolicy:
  15102. default: None
  15103. description: Deletion Policy to handle Secrets in the provider.
  15104. enum:
  15105. - Delete
  15106. - None
  15107. type: string
  15108. refreshInterval:
  15109. default: 1h0m0s
  15110. description: The Interval to which External Secrets will try to push a secret definition
  15111. type: string
  15112. secretStoreRefs:
  15113. items:
  15114. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15115. properties:
  15116. kind:
  15117. default: SecretStore
  15118. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15119. enum:
  15120. - SecretStore
  15121. - ClusterSecretStore
  15122. type: string
  15123. labelSelector:
  15124. description: Optionally, sync to secret stores with label selector
  15125. properties:
  15126. matchExpressions:
  15127. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15128. items:
  15129. description: |-
  15130. A label selector requirement is a selector that contains values, a key, and an operator that
  15131. relates the key and values.
  15132. properties:
  15133. key:
  15134. description: key is the label key that the selector applies to.
  15135. type: string
  15136. operator:
  15137. description: |-
  15138. operator represents a key's relationship to a set of values.
  15139. Valid operators are In, NotIn, Exists and DoesNotExist.
  15140. type: string
  15141. values:
  15142. description: |-
  15143. values is an array of string values. If the operator is In or NotIn,
  15144. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15145. the values array must be empty. This array is replaced during a strategic
  15146. merge patch.
  15147. items:
  15148. type: string
  15149. type: array
  15150. x-kubernetes-list-type: atomic
  15151. required:
  15152. - key
  15153. - operator
  15154. type: object
  15155. type: array
  15156. x-kubernetes-list-type: atomic
  15157. matchLabels:
  15158. additionalProperties:
  15159. type: string
  15160. description: |-
  15161. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15162. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15163. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15164. type: object
  15165. type: object
  15166. x-kubernetes-map-type: atomic
  15167. name:
  15168. description: Optionally, sync to the SecretStore of the given name
  15169. maxLength: 253
  15170. minLength: 1
  15171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15172. type: string
  15173. type: object
  15174. type: array
  15175. selector:
  15176. description: The Secret Selector (k8s source) for the Push Secret
  15177. maxProperties: 1
  15178. minProperties: 1
  15179. properties:
  15180. generatorRef:
  15181. description: Point to a generator to create a Secret.
  15182. properties:
  15183. apiVersion:
  15184. default: generators.external-secrets.io/v1alpha1
  15185. description: Specify the apiVersion of the generator resource
  15186. type: string
  15187. kind:
  15188. description: Specify the Kind of the generator resource
  15189. enum:
  15190. - ACRAccessToken
  15191. - BeyondtrustWorkloadCredentialsDynamicSecret
  15192. - ClusterGenerator
  15193. - CloudsmithAccessToken
  15194. - ECRAuthorizationToken
  15195. - Fake
  15196. - GCRAccessToken
  15197. - GithubAccessToken
  15198. - GitlabDeployToken
  15199. - QuayAccessToken
  15200. - Password
  15201. - SSHKey
  15202. - STSSessionToken
  15203. - UUID
  15204. - VaultDynamicSecret
  15205. - Webhook
  15206. - Grafana
  15207. - MFA
  15208. type: string
  15209. name:
  15210. description: Specify the name of the generator resource
  15211. maxLength: 253
  15212. minLength: 1
  15213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15214. type: string
  15215. required:
  15216. - kind
  15217. - name
  15218. type: object
  15219. secret:
  15220. description: Select a Secret to Push.
  15221. properties:
  15222. name:
  15223. description: |-
  15224. Name of the Secret.
  15225. The Secret must exist in the same namespace as the PushSecret manifest.
  15226. maxLength: 253
  15227. minLength: 1
  15228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15229. type: string
  15230. selector:
  15231. description: Selector chooses secrets using a labelSelector.
  15232. properties:
  15233. matchExpressions:
  15234. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15235. items:
  15236. description: |-
  15237. A label selector requirement is a selector that contains values, a key, and an operator that
  15238. relates the key and values.
  15239. properties:
  15240. key:
  15241. description: key is the label key that the selector applies to.
  15242. type: string
  15243. operator:
  15244. description: |-
  15245. operator represents a key's relationship to a set of values.
  15246. Valid operators are In, NotIn, Exists and DoesNotExist.
  15247. type: string
  15248. values:
  15249. description: |-
  15250. values is an array of string values. If the operator is In or NotIn,
  15251. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15252. the values array must be empty. This array is replaced during a strategic
  15253. merge patch.
  15254. items:
  15255. type: string
  15256. type: array
  15257. x-kubernetes-list-type: atomic
  15258. required:
  15259. - key
  15260. - operator
  15261. type: object
  15262. type: array
  15263. x-kubernetes-list-type: atomic
  15264. matchLabels:
  15265. additionalProperties:
  15266. type: string
  15267. description: |-
  15268. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15269. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15270. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15271. type: object
  15272. type: object
  15273. x-kubernetes-map-type: atomic
  15274. type: object
  15275. type: object
  15276. template:
  15277. description: Template defines a blueprint for the created Secret resource.
  15278. properties:
  15279. data:
  15280. additionalProperties:
  15281. type: string
  15282. type: object
  15283. engineVersion:
  15284. default: v2
  15285. description: |-
  15286. EngineVersion specifies the template engine version
  15287. that should be used to compile/execute the
  15288. template specified in .data and .templateFrom[].
  15289. enum:
  15290. - v2
  15291. type: string
  15292. mergePolicy:
  15293. default: Replace
  15294. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15295. enum:
  15296. - Replace
  15297. - Merge
  15298. type: string
  15299. metadata:
  15300. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15301. properties:
  15302. annotations:
  15303. additionalProperties:
  15304. type: string
  15305. type: object
  15306. finalizers:
  15307. items:
  15308. type: string
  15309. type: array
  15310. labels:
  15311. additionalProperties:
  15312. type: string
  15313. type: object
  15314. type: object
  15315. templateFrom:
  15316. items:
  15317. description: |-
  15318. TemplateFrom specifies a source for templates.
  15319. Each item in the list can either reference a ConfigMap or a Secret resource.
  15320. properties:
  15321. configMap:
  15322. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15323. properties:
  15324. items:
  15325. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15326. items:
  15327. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15328. properties:
  15329. key:
  15330. description: A key in the ConfigMap/Secret
  15331. maxLength: 253
  15332. minLength: 1
  15333. pattern: ^[-._a-zA-Z0-9]+$
  15334. type: string
  15335. templateAs:
  15336. default: Values
  15337. description: TemplateScope specifies how the template keys should be interpreted.
  15338. enum:
  15339. - Values
  15340. - KeysAndValues
  15341. type: string
  15342. required:
  15343. - key
  15344. type: object
  15345. type: array
  15346. name:
  15347. description: The name of the ConfigMap/Secret resource
  15348. maxLength: 253
  15349. minLength: 1
  15350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15351. type: string
  15352. required:
  15353. - items
  15354. - name
  15355. type: object
  15356. literal:
  15357. type: string
  15358. secret:
  15359. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15360. properties:
  15361. items:
  15362. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15363. items:
  15364. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15365. properties:
  15366. key:
  15367. description: A key in the ConfigMap/Secret
  15368. maxLength: 253
  15369. minLength: 1
  15370. pattern: ^[-._a-zA-Z0-9]+$
  15371. type: string
  15372. templateAs:
  15373. default: Values
  15374. description: TemplateScope specifies how the template keys should be interpreted.
  15375. enum:
  15376. - Values
  15377. - KeysAndValues
  15378. type: string
  15379. required:
  15380. - key
  15381. type: object
  15382. type: array
  15383. name:
  15384. description: The name of the ConfigMap/Secret resource
  15385. maxLength: 253
  15386. minLength: 1
  15387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15388. type: string
  15389. required:
  15390. - items
  15391. - name
  15392. type: object
  15393. target:
  15394. default: Data
  15395. description: |-
  15396. Target specifies where to place the template result.
  15397. For Secret resources, common values are: "Data", "Annotations", "Labels".
  15398. For custom resources (when spec.target.manifest is set), this supports
  15399. nested paths like "spec.database.config" or "data".
  15400. type: string
  15401. valuesDecodingStrategy:
  15402. default: None
  15403. description: Used to define a decoding Strategy for the rendered template values.
  15404. enum:
  15405. - Auto
  15406. - Base64
  15407. - Base64URL
  15408. - None
  15409. type: string
  15410. type: object
  15411. type: array
  15412. type:
  15413. type: string
  15414. type: object
  15415. updatePolicy:
  15416. default: Replace
  15417. description: UpdatePolicy to handle Secrets in the provider.
  15418. enum:
  15419. - Replace
  15420. - IfNotExists
  15421. type: string
  15422. required:
  15423. - secretStoreRefs
  15424. - selector
  15425. type: object
  15426. status:
  15427. description: PushSecretStatus indicates the history of the status of PushSecret.
  15428. properties:
  15429. conditions:
  15430. items:
  15431. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15432. properties:
  15433. lastTransitionTime:
  15434. format: date-time
  15435. type: string
  15436. message:
  15437. type: string
  15438. reason:
  15439. type: string
  15440. status:
  15441. type: string
  15442. type:
  15443. description: PushSecretConditionType indicates the condition of the PushSecret.
  15444. type: string
  15445. required:
  15446. - status
  15447. - type
  15448. type: object
  15449. type: array
  15450. refreshTime:
  15451. description: |-
  15452. refreshTime is the time and date the external secret was fetched and
  15453. the target secret updated
  15454. format: date-time
  15455. nullable: true
  15456. type: string
  15457. syncedPushSecrets:
  15458. additionalProperties:
  15459. additionalProperties:
  15460. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15461. properties:
  15462. conversionStrategy:
  15463. default: None
  15464. description: Used to define a conversion Strategy for the secret keys
  15465. enum:
  15466. - None
  15467. - ReverseUnicode
  15468. type: string
  15469. match:
  15470. description: Match a given Secret Key to be pushed to the provider.
  15471. properties:
  15472. remoteRef:
  15473. description: Remote Refs to push to providers.
  15474. properties:
  15475. property:
  15476. description: Name of the property in the resulting secret
  15477. type: string
  15478. remoteKey:
  15479. description: Name of the resulting provider secret.
  15480. type: string
  15481. required:
  15482. - remoteKey
  15483. type: object
  15484. secretKey:
  15485. description: Secret Key to be pushed
  15486. type: string
  15487. required:
  15488. - remoteRef
  15489. type: object
  15490. metadata:
  15491. description: |-
  15492. Metadata is metadata attached to the secret.
  15493. The structure of metadata is provider specific, please look it up in the provider documentation.
  15494. x-kubernetes-preserve-unknown-fields: true
  15495. required:
  15496. - match
  15497. type: object
  15498. type: object
  15499. description: |-
  15500. Synced PushSecrets, including secrets that already exist in provider.
  15501. Matches secret stores to PushSecretData that was stored to that secret store.
  15502. type: object
  15503. syncedResourceVersion:
  15504. description: SyncedResourceVersion keeps track of the last synced version.
  15505. type: string
  15506. type: object
  15507. type: object
  15508. served: true
  15509. storage: true
  15510. subresources:
  15511. status: {}
  15512. ---
  15513. apiVersion: apiextensions.k8s.io/v1
  15514. kind: CustomResourceDefinition
  15515. metadata:
  15516. annotations:
  15517. controller-gen.kubebuilder.io/version: v0.19.0
  15518. labels:
  15519. external-secrets.io/component: controller
  15520. name: secretstores.external-secrets.io
  15521. spec:
  15522. group: external-secrets.io
  15523. names:
  15524. categories:
  15525. - external-secrets
  15526. kind: SecretStore
  15527. listKind: SecretStoreList
  15528. plural: secretstores
  15529. shortNames:
  15530. - ss
  15531. singular: secretstore
  15532. scope: Namespaced
  15533. versions:
  15534. - additionalPrinterColumns:
  15535. - jsonPath: .metadata.creationTimestamp
  15536. name: AGE
  15537. type: date
  15538. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15539. name: Status
  15540. type: string
  15541. - jsonPath: .status.capabilities
  15542. name: Capabilities
  15543. type: string
  15544. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15545. name: Ready
  15546. type: string
  15547. name: v1
  15548. schema:
  15549. openAPIV3Schema:
  15550. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15551. properties:
  15552. apiVersion:
  15553. description: |-
  15554. APIVersion defines the versioned schema of this representation of an object.
  15555. Servers should convert recognized schemas to the latest internal value, and
  15556. may reject unrecognized values.
  15557. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15558. type: string
  15559. kind:
  15560. description: |-
  15561. Kind is a string value representing the REST resource this object represents.
  15562. Servers may infer this from the endpoint the client submits requests to.
  15563. Cannot be updated.
  15564. In CamelCase.
  15565. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15566. type: string
  15567. metadata:
  15568. type: object
  15569. spec:
  15570. description: SecretStoreSpec defines the desired state of SecretStore.
  15571. properties:
  15572. conditions:
  15573. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15574. items:
  15575. description: |-
  15576. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15577. for a ClusterSecretStore instance.
  15578. properties:
  15579. namespaceRegexes:
  15580. description: Choose namespaces by using regex matching
  15581. items:
  15582. type: string
  15583. type: array
  15584. namespaceSelector:
  15585. description: Choose namespace using a labelSelector
  15586. properties:
  15587. matchExpressions:
  15588. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15589. items:
  15590. description: |-
  15591. A label selector requirement is a selector that contains values, a key, and an operator that
  15592. relates the key and values.
  15593. properties:
  15594. key:
  15595. description: key is the label key that the selector applies to.
  15596. type: string
  15597. operator:
  15598. description: |-
  15599. operator represents a key's relationship to a set of values.
  15600. Valid operators are In, NotIn, Exists and DoesNotExist.
  15601. type: string
  15602. values:
  15603. description: |-
  15604. values is an array of string values. If the operator is In or NotIn,
  15605. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15606. the values array must be empty. This array is replaced during a strategic
  15607. merge patch.
  15608. items:
  15609. type: string
  15610. type: array
  15611. x-kubernetes-list-type: atomic
  15612. required:
  15613. - key
  15614. - operator
  15615. type: object
  15616. type: array
  15617. x-kubernetes-list-type: atomic
  15618. matchLabels:
  15619. additionalProperties:
  15620. type: string
  15621. description: |-
  15622. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15623. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15624. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15625. type: object
  15626. type: object
  15627. x-kubernetes-map-type: atomic
  15628. namespaces:
  15629. description: Choose namespaces by name
  15630. items:
  15631. maxLength: 63
  15632. minLength: 1
  15633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15634. type: string
  15635. type: array
  15636. type: object
  15637. type: array
  15638. controller:
  15639. description: |-
  15640. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15641. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15642. type: string
  15643. provider:
  15644. description: Used to configure the provider. Only one provider may be set
  15645. maxProperties: 1
  15646. minProperties: 1
  15647. properties:
  15648. akeyless:
  15649. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15650. properties:
  15651. akeylessGWApiURL:
  15652. description: Akeyless GW API Url from which the secrets to be fetched from.
  15653. type: string
  15654. authSecretRef:
  15655. description: Auth configures how the operator authenticates with Akeyless.
  15656. properties:
  15657. kubernetesAuth:
  15658. description: |-
  15659. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15660. token stored in the named Secret resource.
  15661. properties:
  15662. accessID:
  15663. description: the Akeyless Kubernetes auth-method access-id
  15664. type: string
  15665. k8sConfName:
  15666. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15667. type: string
  15668. secretRef:
  15669. description: |-
  15670. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15671. for authenticating with Akeyless. If a name is specified without a key,
  15672. `token` is the default. If one is not specified, the one bound to
  15673. the controller will be used.
  15674. properties:
  15675. key:
  15676. description: |-
  15677. A key in the referenced Secret.
  15678. Some instances of this field may be defaulted, in others it may be required.
  15679. maxLength: 253
  15680. minLength: 1
  15681. pattern: ^[-._a-zA-Z0-9]+$
  15682. type: string
  15683. name:
  15684. description: The name of the Secret resource being referred to.
  15685. maxLength: 253
  15686. minLength: 1
  15687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15688. type: string
  15689. namespace:
  15690. description: |-
  15691. The namespace of the Secret resource being referred to.
  15692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15693. maxLength: 63
  15694. minLength: 1
  15695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15696. type: string
  15697. type: object
  15698. serviceAccountRef:
  15699. description: |-
  15700. Optional service account field containing the name of a kubernetes ServiceAccount.
  15701. If the service account is specified, the service account secret token JWT will be used
  15702. for authenticating with Akeyless. If the service account selector is not supplied,
  15703. the secretRef will be used instead.
  15704. properties:
  15705. audiences:
  15706. description: |-
  15707. Audience specifies the `aud` claim for the service account token
  15708. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15709. then this audiences will be appended to the list
  15710. items:
  15711. type: string
  15712. type: array
  15713. name:
  15714. description: The name of the ServiceAccount resource being referred to.
  15715. maxLength: 253
  15716. minLength: 1
  15717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15718. type: string
  15719. namespace:
  15720. description: |-
  15721. Namespace of the resource being referred to.
  15722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15723. maxLength: 63
  15724. minLength: 1
  15725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15726. type: string
  15727. required:
  15728. - name
  15729. type: object
  15730. required:
  15731. - accessID
  15732. - k8sConfName
  15733. type: object
  15734. secretRef:
  15735. description: |-
  15736. Reference to a Secret that contains the details
  15737. to authenticate with Akeyless.
  15738. properties:
  15739. accessID:
  15740. description: The SecretAccessID is used for authentication
  15741. properties:
  15742. key:
  15743. description: |-
  15744. A key in the referenced Secret.
  15745. Some instances of this field may be defaulted, in others it may be required.
  15746. maxLength: 253
  15747. minLength: 1
  15748. pattern: ^[-._a-zA-Z0-9]+$
  15749. type: string
  15750. name:
  15751. description: The name of the Secret resource being referred to.
  15752. maxLength: 253
  15753. minLength: 1
  15754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15755. type: string
  15756. namespace:
  15757. description: |-
  15758. The namespace of the Secret resource being referred to.
  15759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15760. maxLength: 63
  15761. minLength: 1
  15762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15763. type: string
  15764. type: object
  15765. accessType:
  15766. description: |-
  15767. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15768. In some instances, `key` is a required field.
  15769. properties:
  15770. key:
  15771. description: |-
  15772. A key in the referenced Secret.
  15773. Some instances of this field may be defaulted, in others it may be required.
  15774. maxLength: 253
  15775. minLength: 1
  15776. pattern: ^[-._a-zA-Z0-9]+$
  15777. type: string
  15778. name:
  15779. description: The name of the Secret resource being referred to.
  15780. maxLength: 253
  15781. minLength: 1
  15782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15783. type: string
  15784. namespace:
  15785. description: |-
  15786. The namespace of the Secret resource being referred to.
  15787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15788. maxLength: 63
  15789. minLength: 1
  15790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15791. type: string
  15792. type: object
  15793. accessTypeParam:
  15794. description: |-
  15795. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15796. In some instances, `key` is a required field.
  15797. properties:
  15798. key:
  15799. description: |-
  15800. A key in the referenced Secret.
  15801. Some instances of this field may be defaulted, in others it may be required.
  15802. maxLength: 253
  15803. minLength: 1
  15804. pattern: ^[-._a-zA-Z0-9]+$
  15805. type: string
  15806. name:
  15807. description: The name of the Secret resource being referred to.
  15808. maxLength: 253
  15809. minLength: 1
  15810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15811. type: string
  15812. namespace:
  15813. description: |-
  15814. The namespace of the Secret resource being referred to.
  15815. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15816. maxLength: 63
  15817. minLength: 1
  15818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15819. type: string
  15820. type: object
  15821. type: object
  15822. serviceAccountRef:
  15823. description: |-
  15824. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15825. authentication on AKS Workload Identity. The operator obtains a federated
  15826. identity token from this ServiceAccount via the TokenRequest API instead
  15827. of using the ESO controller pod identity. Ignored for other access types.
  15828. properties:
  15829. audiences:
  15830. description: |-
  15831. Audience specifies the `aud` claim for the service account token
  15832. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15833. then this audiences will be appended to the list
  15834. items:
  15835. type: string
  15836. type: array
  15837. name:
  15838. description: The name of the ServiceAccount resource being referred to.
  15839. maxLength: 253
  15840. minLength: 1
  15841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15842. type: string
  15843. namespace:
  15844. description: |-
  15845. Namespace of the resource being referred to.
  15846. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15847. maxLength: 63
  15848. minLength: 1
  15849. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15850. type: string
  15851. required:
  15852. - name
  15853. type: object
  15854. type: object
  15855. caBundle:
  15856. description: |-
  15857. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15858. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15859. are used to validate the TLS connection.
  15860. format: byte
  15861. type: string
  15862. caProvider:
  15863. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15864. properties:
  15865. key:
  15866. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15867. maxLength: 253
  15868. minLength: 1
  15869. pattern: ^[-._a-zA-Z0-9]+$
  15870. type: string
  15871. name:
  15872. description: The name of the object located at the provider type.
  15873. maxLength: 253
  15874. minLength: 1
  15875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15876. type: string
  15877. namespace:
  15878. description: |-
  15879. The namespace the Provider type is in.
  15880. Can only be defined when used in a ClusterSecretStore.
  15881. maxLength: 63
  15882. minLength: 1
  15883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15884. type: string
  15885. type:
  15886. description: The type of provider to use such as "Secret", or "ConfigMap".
  15887. enum:
  15888. - Secret
  15889. - ConfigMap
  15890. type: string
  15891. required:
  15892. - name
  15893. - type
  15894. type: object
  15895. ignoreCache:
  15896. description: |-
  15897. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15898. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15899. type: boolean
  15900. required:
  15901. - akeylessGWApiURL
  15902. - authSecretRef
  15903. type: object
  15904. aws:
  15905. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15906. properties:
  15907. additionalRoles:
  15908. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15909. items:
  15910. type: string
  15911. type: array
  15912. auth:
  15913. description: |-
  15914. Auth defines the information necessary to authenticate against AWS
  15915. if not set aws sdk will infer credentials from your environment
  15916. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15917. properties:
  15918. jwt:
  15919. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15920. properties:
  15921. serviceAccountRef:
  15922. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15923. properties:
  15924. audiences:
  15925. description: |-
  15926. Audience specifies the `aud` claim for the service account token
  15927. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15928. then this audiences will be appended to the list
  15929. items:
  15930. type: string
  15931. type: array
  15932. name:
  15933. description: The name of the ServiceAccount resource being referred to.
  15934. maxLength: 253
  15935. minLength: 1
  15936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15937. type: string
  15938. namespace:
  15939. description: |-
  15940. Namespace of the resource being referred to.
  15941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15942. maxLength: 63
  15943. minLength: 1
  15944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15945. type: string
  15946. required:
  15947. - name
  15948. type: object
  15949. type: object
  15950. secretRef:
  15951. description: |-
  15952. AWSAuthSecretRef holds secret references for AWS credentials
  15953. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15954. properties:
  15955. accessKeyIDSecretRef:
  15956. description: The AccessKeyID is used for authentication
  15957. properties:
  15958. key:
  15959. description: |-
  15960. A key in the referenced Secret.
  15961. Some instances of this field may be defaulted, in others it may be required.
  15962. maxLength: 253
  15963. minLength: 1
  15964. pattern: ^[-._a-zA-Z0-9]+$
  15965. type: string
  15966. name:
  15967. description: The name of the Secret resource being referred to.
  15968. maxLength: 253
  15969. minLength: 1
  15970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15971. type: string
  15972. namespace:
  15973. description: |-
  15974. The namespace of the Secret resource being referred to.
  15975. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15976. maxLength: 63
  15977. minLength: 1
  15978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15979. type: string
  15980. type: object
  15981. secretAccessKeySecretRef:
  15982. description: The SecretAccessKey is used for authentication
  15983. properties:
  15984. key:
  15985. description: |-
  15986. A key in the referenced Secret.
  15987. Some instances of this field may be defaulted, in others it may be required.
  15988. maxLength: 253
  15989. minLength: 1
  15990. pattern: ^[-._a-zA-Z0-9]+$
  15991. type: string
  15992. name:
  15993. description: The name of the Secret resource being referred to.
  15994. maxLength: 253
  15995. minLength: 1
  15996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15997. type: string
  15998. namespace:
  15999. description: |-
  16000. The namespace of the Secret resource being referred to.
  16001. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16002. maxLength: 63
  16003. minLength: 1
  16004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16005. type: string
  16006. type: object
  16007. sessionTokenSecretRef:
  16008. description: |-
  16009. The SessionToken used for authentication
  16010. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16011. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16012. properties:
  16013. key:
  16014. description: |-
  16015. A key in the referenced Secret.
  16016. Some instances of this field may be defaulted, in others it may be required.
  16017. maxLength: 253
  16018. minLength: 1
  16019. pattern: ^[-._a-zA-Z0-9]+$
  16020. type: string
  16021. name:
  16022. description: The name of the Secret resource being referred to.
  16023. maxLength: 253
  16024. minLength: 1
  16025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16026. type: string
  16027. namespace:
  16028. description: |-
  16029. The namespace of the Secret resource being referred to.
  16030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16031. maxLength: 63
  16032. minLength: 1
  16033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16034. type: string
  16035. type: object
  16036. type: object
  16037. type: object
  16038. customSessionTags:
  16039. additionalProperties:
  16040. type: string
  16041. description: |-
  16042. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16043. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16044. type: object
  16045. x-kubernetes-validations:
  16046. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16047. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16048. externalID:
  16049. description: AWS External ID set on assumed IAM roles
  16050. type: string
  16051. prefix:
  16052. description: Prefix adds a prefix to all retrieved values.
  16053. type: string
  16054. region:
  16055. description: AWS Region to be used for the provider
  16056. type: string
  16057. role:
  16058. description: Role is a Role ARN which the provider will assume
  16059. type: string
  16060. secretsManager:
  16061. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16062. properties:
  16063. forceDeleteWithoutRecovery:
  16064. description: |-
  16065. Specifies whether to delete the secret without any recovery window. You
  16066. can't use both this parameter and RecoveryWindowInDays in the same call.
  16067. If you don't use either, then by default Secrets Manager uses a 30 day
  16068. recovery window.
  16069. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16070. type: boolean
  16071. recoveryWindowInDays:
  16072. description: |-
  16073. The number of days from 7 to 30 that Secrets Manager waits before
  16074. permanently deleting the secret. You can't use both this parameter and
  16075. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16076. then by default Secrets Manager uses a 30-day recovery window.
  16077. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16078. format: int64
  16079. type: integer
  16080. type: object
  16081. service:
  16082. description: Service defines which service should be used to fetch the secrets
  16083. enum:
  16084. - SecretsManager
  16085. - ParameterStore
  16086. - CertificateManager
  16087. type: string
  16088. sessionTags:
  16089. description: AWS STS assume role session tags
  16090. items:
  16091. description: |-
  16092. Tag is a key-value pair that can be attached to an AWS resource.
  16093. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16094. properties:
  16095. key:
  16096. type: string
  16097. value:
  16098. type: string
  16099. required:
  16100. - key
  16101. - value
  16102. type: object
  16103. type: array
  16104. sessionTagsPolicy:
  16105. default: None
  16106. description: |-
  16107. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16108. None (default): no tags are added.
  16109. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16110. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16111. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16112. enum:
  16113. - None
  16114. - Simple
  16115. - Custom
  16116. type: string
  16117. transitiveTagKeys:
  16118. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16119. items:
  16120. type: string
  16121. type: array
  16122. required:
  16123. - region
  16124. - service
  16125. type: object
  16126. azurekv:
  16127. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16128. properties:
  16129. authSecretRef:
  16130. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16131. properties:
  16132. clientCertificate:
  16133. description: The Azure ClientCertificate of the service principle used for authentication.
  16134. properties:
  16135. key:
  16136. description: |-
  16137. A key in the referenced Secret.
  16138. Some instances of this field may be defaulted, in others it may be required.
  16139. maxLength: 253
  16140. minLength: 1
  16141. pattern: ^[-._a-zA-Z0-9]+$
  16142. type: string
  16143. name:
  16144. description: The name of the Secret resource being referred to.
  16145. maxLength: 253
  16146. minLength: 1
  16147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16148. type: string
  16149. namespace:
  16150. description: |-
  16151. The namespace of the Secret resource being referred to.
  16152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16153. maxLength: 63
  16154. minLength: 1
  16155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16156. type: string
  16157. type: object
  16158. clientId:
  16159. description: The Azure clientId of the service principle or managed identity used for authentication.
  16160. properties:
  16161. key:
  16162. description: |-
  16163. A key in the referenced Secret.
  16164. Some instances of this field may be defaulted, in others it may be required.
  16165. maxLength: 253
  16166. minLength: 1
  16167. pattern: ^[-._a-zA-Z0-9]+$
  16168. type: string
  16169. name:
  16170. description: The name of the Secret resource being referred to.
  16171. maxLength: 253
  16172. minLength: 1
  16173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16174. type: string
  16175. namespace:
  16176. description: |-
  16177. The namespace of the Secret resource being referred to.
  16178. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16179. maxLength: 63
  16180. minLength: 1
  16181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16182. type: string
  16183. type: object
  16184. clientSecret:
  16185. description: The Azure ClientSecret of the service principle used for authentication.
  16186. properties:
  16187. key:
  16188. description: |-
  16189. A key in the referenced Secret.
  16190. Some instances of this field may be defaulted, in others it may be required.
  16191. maxLength: 253
  16192. minLength: 1
  16193. pattern: ^[-._a-zA-Z0-9]+$
  16194. type: string
  16195. name:
  16196. description: The name of the Secret resource being referred to.
  16197. maxLength: 253
  16198. minLength: 1
  16199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16200. type: string
  16201. namespace:
  16202. description: |-
  16203. The namespace of the Secret resource being referred to.
  16204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16205. maxLength: 63
  16206. minLength: 1
  16207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16208. type: string
  16209. type: object
  16210. tenantId:
  16211. description: The Azure tenantId of the managed identity used for authentication.
  16212. properties:
  16213. key:
  16214. description: |-
  16215. A key in the referenced Secret.
  16216. Some instances of this field may be defaulted, in others it may be required.
  16217. maxLength: 253
  16218. minLength: 1
  16219. pattern: ^[-._a-zA-Z0-9]+$
  16220. type: string
  16221. name:
  16222. description: The name of the Secret resource being referred to.
  16223. maxLength: 253
  16224. minLength: 1
  16225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16226. type: string
  16227. namespace:
  16228. description: |-
  16229. The namespace of the Secret resource being referred to.
  16230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16231. maxLength: 63
  16232. minLength: 1
  16233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16234. type: string
  16235. type: object
  16236. type: object
  16237. authType:
  16238. default: ServicePrincipal
  16239. description: |-
  16240. Auth type defines how to authenticate to the keyvault service.
  16241. Valid values are:
  16242. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16243. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16244. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16245. enum:
  16246. - ServicePrincipal
  16247. - ManagedIdentity
  16248. - WorkloadIdentity
  16249. type: string
  16250. customCloudConfig:
  16251. description: |-
  16252. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16253. Required when EnvironmentType is AzureStackCloud.
  16254. Optional for other environment types - useful for Azure China when using Workload Identity
  16255. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16256. standard China Cloud endpoint (login.chinacloudapi.cn).
  16257. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16258. configuration is not supported with the legacy go-autorest SDK.
  16259. properties:
  16260. activeDirectoryEndpoint:
  16261. description: |-
  16262. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16263. Required when using custom cloud configuration
  16264. type: string
  16265. keyVaultDNSSuffix:
  16266. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16267. type: string
  16268. keyVaultEndpoint:
  16269. description: KeyVaultEndpoint is the Key Vault service endpoint
  16270. type: string
  16271. resourceManagerEndpoint:
  16272. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16273. type: string
  16274. required:
  16275. - activeDirectoryEndpoint
  16276. type: object
  16277. environmentType:
  16278. default: PublicCloud
  16279. description: |-
  16280. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16281. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16282. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16283. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16284. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16285. enum:
  16286. - PublicCloud
  16287. - USGovernmentCloud
  16288. - ChinaCloud
  16289. - GermanCloud
  16290. - AzureStackCloud
  16291. type: string
  16292. identityId:
  16293. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16294. type: string
  16295. serviceAccountRef:
  16296. description: |-
  16297. ServiceAccountRef specified the service account
  16298. that should be used when authenticating with WorkloadIdentity.
  16299. properties:
  16300. audiences:
  16301. description: |-
  16302. Audience specifies the `aud` claim for the service account token
  16303. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16304. then this audiences will be appended to the list
  16305. items:
  16306. type: string
  16307. type: array
  16308. name:
  16309. description: The name of the ServiceAccount resource being referred to.
  16310. maxLength: 253
  16311. minLength: 1
  16312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16313. type: string
  16314. namespace:
  16315. description: |-
  16316. Namespace of the resource being referred to.
  16317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16318. maxLength: 63
  16319. minLength: 1
  16320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16321. type: string
  16322. required:
  16323. - name
  16324. type: object
  16325. tenantId:
  16326. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16327. type: string
  16328. useAzureSDK:
  16329. default: false
  16330. description: |-
  16331. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16332. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16333. type: boolean
  16334. vaultUrl:
  16335. description: Vault Url from which the secrets to be fetched from.
  16336. type: string
  16337. required:
  16338. - vaultUrl
  16339. type: object
  16340. barbican:
  16341. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16342. properties:
  16343. auth:
  16344. description: BarbicanAuth contains the authentication information for Barbican.
  16345. properties:
  16346. password:
  16347. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16348. properties:
  16349. secretRef:
  16350. description: |-
  16351. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16352. In some instances, `key` is a required field.
  16353. properties:
  16354. key:
  16355. description: |-
  16356. A key in the referenced Secret.
  16357. Some instances of this field may be defaulted, in others it may be required.
  16358. maxLength: 253
  16359. minLength: 1
  16360. pattern: ^[-._a-zA-Z0-9]+$
  16361. type: string
  16362. name:
  16363. description: The name of the Secret resource being referred to.
  16364. maxLength: 253
  16365. minLength: 1
  16366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16367. type: string
  16368. namespace:
  16369. description: |-
  16370. The namespace of the Secret resource being referred to.
  16371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16372. maxLength: 63
  16373. minLength: 1
  16374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16375. type: string
  16376. type: object
  16377. required:
  16378. - secretRef
  16379. type: object
  16380. username:
  16381. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16382. maxProperties: 1
  16383. minProperties: 1
  16384. properties:
  16385. secretRef:
  16386. description: |-
  16387. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16388. In some instances, `key` is a required field.
  16389. properties:
  16390. key:
  16391. description: |-
  16392. A key in the referenced Secret.
  16393. Some instances of this field may be defaulted, in others it may be required.
  16394. maxLength: 253
  16395. minLength: 1
  16396. pattern: ^[-._a-zA-Z0-9]+$
  16397. type: string
  16398. name:
  16399. description: The name of the Secret resource being referred to.
  16400. maxLength: 253
  16401. minLength: 1
  16402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16403. type: string
  16404. namespace:
  16405. description: |-
  16406. The namespace of the Secret resource being referred to.
  16407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16408. maxLength: 63
  16409. minLength: 1
  16410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16411. type: string
  16412. type: object
  16413. value:
  16414. type: string
  16415. type: object
  16416. required:
  16417. - password
  16418. - username
  16419. type: object
  16420. authURL:
  16421. type: string
  16422. domainName:
  16423. type: string
  16424. region:
  16425. type: string
  16426. tenantName:
  16427. type: string
  16428. required:
  16429. - auth
  16430. type: object
  16431. beyondtrust:
  16432. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16433. properties:
  16434. auth:
  16435. description: Auth configures how the operator authenticates with Beyondtrust.
  16436. properties:
  16437. apiKey:
  16438. description: APIKey If not provided then ClientID/ClientSecret become required.
  16439. properties:
  16440. secretRef:
  16441. description: SecretRef references a key in a secret that will be used as value.
  16442. properties:
  16443. key:
  16444. description: |-
  16445. A key in the referenced Secret.
  16446. Some instances of this field may be defaulted, in others it may be required.
  16447. maxLength: 253
  16448. minLength: 1
  16449. pattern: ^[-._a-zA-Z0-9]+$
  16450. type: string
  16451. name:
  16452. description: The name of the Secret resource being referred to.
  16453. maxLength: 253
  16454. minLength: 1
  16455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16456. type: string
  16457. namespace:
  16458. description: |-
  16459. The namespace of the Secret resource being referred to.
  16460. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16461. maxLength: 63
  16462. minLength: 1
  16463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16464. type: string
  16465. type: object
  16466. value:
  16467. description: Value can be specified directly to set a value without using a secret.
  16468. type: string
  16469. type: object
  16470. certificate:
  16471. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16472. properties:
  16473. secretRef:
  16474. description: SecretRef references a key in a secret that will be used as value.
  16475. properties:
  16476. key:
  16477. description: |-
  16478. A key in the referenced Secret.
  16479. Some instances of this field may be defaulted, in others it may be required.
  16480. maxLength: 253
  16481. minLength: 1
  16482. pattern: ^[-._a-zA-Z0-9]+$
  16483. type: string
  16484. name:
  16485. description: The name of the Secret resource being referred to.
  16486. maxLength: 253
  16487. minLength: 1
  16488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16489. type: string
  16490. namespace:
  16491. description: |-
  16492. The namespace of the Secret resource being referred to.
  16493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16494. maxLength: 63
  16495. minLength: 1
  16496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16497. type: string
  16498. type: object
  16499. value:
  16500. description: Value can be specified directly to set a value without using a secret.
  16501. type: string
  16502. type: object
  16503. certificateKey:
  16504. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16505. properties:
  16506. secretRef:
  16507. description: SecretRef references a key in a secret that will be used as value.
  16508. properties:
  16509. key:
  16510. description: |-
  16511. A key in the referenced Secret.
  16512. Some instances of this field may be defaulted, in others it may be required.
  16513. maxLength: 253
  16514. minLength: 1
  16515. pattern: ^[-._a-zA-Z0-9]+$
  16516. type: string
  16517. name:
  16518. description: The name of the Secret resource being referred to.
  16519. maxLength: 253
  16520. minLength: 1
  16521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16522. type: string
  16523. namespace:
  16524. description: |-
  16525. The namespace of the Secret resource being referred to.
  16526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16527. maxLength: 63
  16528. minLength: 1
  16529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16530. type: string
  16531. type: object
  16532. value:
  16533. description: Value can be specified directly to set a value without using a secret.
  16534. type: string
  16535. type: object
  16536. clientId:
  16537. description: ClientID is the API OAuth Client ID.
  16538. properties:
  16539. secretRef:
  16540. description: SecretRef references a key in a secret that will be used as value.
  16541. properties:
  16542. key:
  16543. description: |-
  16544. A key in the referenced Secret.
  16545. Some instances of this field may be defaulted, in others it may be required.
  16546. maxLength: 253
  16547. minLength: 1
  16548. pattern: ^[-._a-zA-Z0-9]+$
  16549. type: string
  16550. name:
  16551. description: The name of the Secret resource being referred to.
  16552. maxLength: 253
  16553. minLength: 1
  16554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16555. type: string
  16556. namespace:
  16557. description: |-
  16558. The namespace of the Secret resource being referred to.
  16559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16560. maxLength: 63
  16561. minLength: 1
  16562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16563. type: string
  16564. type: object
  16565. value:
  16566. description: Value can be specified directly to set a value without using a secret.
  16567. type: string
  16568. type: object
  16569. clientSecret:
  16570. description: ClientSecret is the API OAuth Client Secret.
  16571. properties:
  16572. secretRef:
  16573. description: SecretRef references a key in a secret that will be used as value.
  16574. properties:
  16575. key:
  16576. description: |-
  16577. A key in the referenced Secret.
  16578. Some instances of this field may be defaulted, in others it may be required.
  16579. maxLength: 253
  16580. minLength: 1
  16581. pattern: ^[-._a-zA-Z0-9]+$
  16582. type: string
  16583. name:
  16584. description: The name of the Secret resource being referred to.
  16585. maxLength: 253
  16586. minLength: 1
  16587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16588. type: string
  16589. namespace:
  16590. description: |-
  16591. The namespace of the Secret resource being referred to.
  16592. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16593. maxLength: 63
  16594. minLength: 1
  16595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16596. type: string
  16597. type: object
  16598. value:
  16599. description: Value can be specified directly to set a value without using a secret.
  16600. type: string
  16601. type: object
  16602. type: object
  16603. server:
  16604. description: Auth configures how API server works.
  16605. properties:
  16606. apiUrl:
  16607. type: string
  16608. apiVersion:
  16609. type: string
  16610. clientTimeOutSeconds:
  16611. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16612. type: integer
  16613. decrypt:
  16614. default: true
  16615. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16616. type: boolean
  16617. retrievalType:
  16618. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16619. type: string
  16620. separator:
  16621. description: A character that separates the folder names.
  16622. type: string
  16623. verifyCA:
  16624. type: boolean
  16625. required:
  16626. - apiUrl
  16627. - verifyCA
  16628. type: object
  16629. required:
  16630. - auth
  16631. - server
  16632. type: object
  16633. beyondtrustworkloadcredentials:
  16634. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16635. properties:
  16636. auth:
  16637. description: |-
  16638. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16639. Currently supports API key authentication via Kubernetes secret reference.
  16640. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16641. properties:
  16642. apikey:
  16643. description: |-
  16644. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16645. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16646. properties:
  16647. token:
  16648. description: |-
  16649. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16650. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16651. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16652. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16653. properties:
  16654. key:
  16655. description: |-
  16656. A key in the referenced Secret.
  16657. Some instances of this field may be defaulted, in others it may be required.
  16658. maxLength: 253
  16659. minLength: 1
  16660. pattern: ^[-._a-zA-Z0-9]+$
  16661. type: string
  16662. name:
  16663. description: The name of the Secret resource being referred to.
  16664. maxLength: 253
  16665. minLength: 1
  16666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16667. type: string
  16668. namespace:
  16669. description: |-
  16670. The namespace of the Secret resource being referred to.
  16671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16672. maxLength: 63
  16673. minLength: 1
  16674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16675. type: string
  16676. type: object
  16677. required:
  16678. - token
  16679. type: object
  16680. required:
  16681. - apikey
  16682. type: object
  16683. caBundle:
  16684. description: |-
  16685. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16686. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16687. If not set, the system's trusted root certificates are used.
  16688. format: byte
  16689. type: string
  16690. caProvider:
  16691. description: |-
  16692. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16693. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16694. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16695. properties:
  16696. key:
  16697. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16698. maxLength: 253
  16699. minLength: 1
  16700. pattern: ^[-._a-zA-Z0-9]+$
  16701. type: string
  16702. name:
  16703. description: The name of the object located at the provider type.
  16704. maxLength: 253
  16705. minLength: 1
  16706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16707. type: string
  16708. namespace:
  16709. description: |-
  16710. The namespace the Provider type is in.
  16711. Can only be defined when used in a ClusterSecretStore.
  16712. maxLength: 63
  16713. minLength: 1
  16714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16715. type: string
  16716. type:
  16717. description: The type of provider to use such as "Secret", or "ConfigMap".
  16718. enum:
  16719. - Secret
  16720. - ConfigMap
  16721. type: string
  16722. required:
  16723. - name
  16724. - type
  16725. type: object
  16726. folderPath:
  16727. description: |-
  16728. FolderPath specifies the default folder path for secret retrieval.
  16729. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16730. Example: "production/database" or "dev/api-keys"
  16731. Leave empty to retrieve secrets from the root folder.
  16732. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16733. type: string
  16734. server:
  16735. description: |-
  16736. Server configures the BeyondTrust Workload Credentials server connection details.
  16737. Includes the API URL and Site ID for your BeyondTrust instance.
  16738. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16739. properties:
  16740. apiUrl:
  16741. description: |-
  16742. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16743. This should be the full URL to your BeyondTrust instance.
  16744. Example: https://api.beyondtrust.io/siie
  16745. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16746. type: string
  16747. siteId:
  16748. description: |-
  16749. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16750. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16751. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16752. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16753. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16754. type: string
  16755. required:
  16756. - apiUrl
  16757. - siteId
  16758. type: object
  16759. required:
  16760. - auth
  16761. - server
  16762. type: object
  16763. bitwardensecretsmanager:
  16764. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16765. properties:
  16766. apiURL:
  16767. type: string
  16768. auth:
  16769. description: |-
  16770. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16771. Make sure that the token being used has permissions on the given secret.
  16772. properties:
  16773. secretRef:
  16774. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16775. properties:
  16776. credentials:
  16777. description: AccessToken used for the bitwarden instance.
  16778. properties:
  16779. key:
  16780. description: |-
  16781. A key in the referenced Secret.
  16782. Some instances of this field may be defaulted, in others it may be required.
  16783. maxLength: 253
  16784. minLength: 1
  16785. pattern: ^[-._a-zA-Z0-9]+$
  16786. type: string
  16787. name:
  16788. description: The name of the Secret resource being referred to.
  16789. maxLength: 253
  16790. minLength: 1
  16791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16792. type: string
  16793. namespace:
  16794. description: |-
  16795. The namespace of the Secret resource being referred to.
  16796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16797. maxLength: 63
  16798. minLength: 1
  16799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16800. type: string
  16801. type: object
  16802. required:
  16803. - credentials
  16804. type: object
  16805. required:
  16806. - secretRef
  16807. type: object
  16808. bitwardenServerSDKURL:
  16809. type: string
  16810. caBundle:
  16811. description: |-
  16812. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16813. can be performed.
  16814. type: string
  16815. caProvider:
  16816. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16817. properties:
  16818. key:
  16819. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16820. maxLength: 253
  16821. minLength: 1
  16822. pattern: ^[-._a-zA-Z0-9]+$
  16823. type: string
  16824. name:
  16825. description: The name of the object located at the provider type.
  16826. maxLength: 253
  16827. minLength: 1
  16828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16829. type: string
  16830. namespace:
  16831. description: |-
  16832. The namespace the Provider type is in.
  16833. Can only be defined when used in a ClusterSecretStore.
  16834. maxLength: 63
  16835. minLength: 1
  16836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16837. type: string
  16838. type:
  16839. description: The type of provider to use such as "Secret", or "ConfigMap".
  16840. enum:
  16841. - Secret
  16842. - ConfigMap
  16843. type: string
  16844. required:
  16845. - name
  16846. - type
  16847. type: object
  16848. identityURL:
  16849. type: string
  16850. organizationID:
  16851. description: OrganizationID determines which organization this secret store manages.
  16852. type: string
  16853. projectID:
  16854. description: ProjectID determines which project this secret store manages.
  16855. type: string
  16856. required:
  16857. - auth
  16858. - organizationID
  16859. - projectID
  16860. type: object
  16861. chef:
  16862. description: Chef configures this store to sync secrets with chef server
  16863. properties:
  16864. auth:
  16865. description: Auth defines the information necessary to authenticate against chef Server
  16866. properties:
  16867. secretRef:
  16868. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16869. properties:
  16870. privateKeySecretRef:
  16871. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16872. properties:
  16873. key:
  16874. description: |-
  16875. A key in the referenced Secret.
  16876. Some instances of this field may be defaulted, in others it may be required.
  16877. maxLength: 253
  16878. minLength: 1
  16879. pattern: ^[-._a-zA-Z0-9]+$
  16880. type: string
  16881. name:
  16882. description: The name of the Secret resource being referred to.
  16883. maxLength: 253
  16884. minLength: 1
  16885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16886. type: string
  16887. namespace:
  16888. description: |-
  16889. The namespace of the Secret resource being referred to.
  16890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16891. maxLength: 63
  16892. minLength: 1
  16893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16894. type: string
  16895. type: object
  16896. required:
  16897. - privateKeySecretRef
  16898. type: object
  16899. required:
  16900. - secretRef
  16901. type: object
  16902. serverUrl:
  16903. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16904. type: string
  16905. username:
  16906. description: UserName should be the user ID on the chef server
  16907. type: string
  16908. required:
  16909. - auth
  16910. - serverUrl
  16911. - username
  16912. type: object
  16913. cloudrusm:
  16914. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16915. properties:
  16916. auth:
  16917. description: CSMAuth contains a secretRef for credentials.
  16918. properties:
  16919. secretRef:
  16920. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16921. properties:
  16922. accessKeyIDSecretRef:
  16923. description: The AccessKeyID is used for authentication
  16924. properties:
  16925. key:
  16926. description: |-
  16927. A key in the referenced Secret.
  16928. Some instances of this field may be defaulted, in others it may be required.
  16929. maxLength: 253
  16930. minLength: 1
  16931. pattern: ^[-._a-zA-Z0-9]+$
  16932. type: string
  16933. name:
  16934. description: The name of the Secret resource being referred to.
  16935. maxLength: 253
  16936. minLength: 1
  16937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16938. type: string
  16939. namespace:
  16940. description: |-
  16941. The namespace of the Secret resource being referred to.
  16942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16943. maxLength: 63
  16944. minLength: 1
  16945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16946. type: string
  16947. type: object
  16948. accessKeySecretSecretRef:
  16949. description: The AccessKeySecret is used for authentication
  16950. properties:
  16951. key:
  16952. description: |-
  16953. A key in the referenced Secret.
  16954. Some instances of this field may be defaulted, in others it may be required.
  16955. maxLength: 253
  16956. minLength: 1
  16957. pattern: ^[-._a-zA-Z0-9]+$
  16958. type: string
  16959. name:
  16960. description: The name of the Secret resource being referred to.
  16961. maxLength: 253
  16962. minLength: 1
  16963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16964. type: string
  16965. namespace:
  16966. description: |-
  16967. The namespace of the Secret resource being referred to.
  16968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16969. maxLength: 63
  16970. minLength: 1
  16971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16972. type: string
  16973. type: object
  16974. required:
  16975. - accessKeyIDSecretRef
  16976. - accessKeySecretSecretRef
  16977. type: object
  16978. type: object
  16979. projectID:
  16980. description: ProjectID is the project, which the secrets are stored in.
  16981. type: string
  16982. required:
  16983. - auth
  16984. type: object
  16985. conjur:
  16986. description: Conjur configures this store to sync secrets using conjur provider
  16987. properties:
  16988. auth:
  16989. description: Defines authentication settings for connecting to Conjur.
  16990. maxProperties: 1
  16991. minProperties: 1
  16992. properties:
  16993. apikey:
  16994. description: Authenticates with Conjur using an API key.
  16995. properties:
  16996. account:
  16997. description: Account is the Conjur organization account name.
  16998. type: string
  16999. apiKeyRef:
  17000. description: |-
  17001. A reference to a specific 'key' containing the Conjur API key
  17002. within a Secret resource. In some instances, `key` is a required field.
  17003. properties:
  17004. key:
  17005. description: |-
  17006. A key in the referenced Secret.
  17007. Some instances of this field may be defaulted, in others it may be required.
  17008. maxLength: 253
  17009. minLength: 1
  17010. pattern: ^[-._a-zA-Z0-9]+$
  17011. type: string
  17012. name:
  17013. description: The name of the Secret resource being referred to.
  17014. maxLength: 253
  17015. minLength: 1
  17016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17017. type: string
  17018. namespace:
  17019. description: |-
  17020. The namespace of the Secret resource being referred to.
  17021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17022. maxLength: 63
  17023. minLength: 1
  17024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17025. type: string
  17026. type: object
  17027. userRef:
  17028. description: |-
  17029. A reference to a specific 'key' containing the Conjur username
  17030. within a Secret resource. In some instances, `key` is a required field.
  17031. properties:
  17032. key:
  17033. description: |-
  17034. A key in the referenced Secret.
  17035. Some instances of this field may be defaulted, in others it may be required.
  17036. maxLength: 253
  17037. minLength: 1
  17038. pattern: ^[-._a-zA-Z0-9]+$
  17039. type: string
  17040. name:
  17041. description: The name of the Secret resource being referred to.
  17042. maxLength: 253
  17043. minLength: 1
  17044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17045. type: string
  17046. namespace:
  17047. description: |-
  17048. The namespace of the Secret resource being referred to.
  17049. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17050. maxLength: 63
  17051. minLength: 1
  17052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17053. type: string
  17054. type: object
  17055. required:
  17056. - account
  17057. - apiKeyRef
  17058. - userRef
  17059. type: object
  17060. cert:
  17061. description: Cert enables certificate-based authentication using a client certificate and key.
  17062. properties:
  17063. account:
  17064. description: Account is the Conjur organization account name.
  17065. type: string
  17066. clientCertRef:
  17067. description: |-
  17068. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17069. within a Secret resource. The certificate must be PEM-encoded.
  17070. properties:
  17071. key:
  17072. description: |-
  17073. A key in the referenced Secret.
  17074. Some instances of this field may be defaulted, in others it may be required.
  17075. maxLength: 253
  17076. minLength: 1
  17077. pattern: ^[-._a-zA-Z0-9]+$
  17078. type: string
  17079. name:
  17080. description: The name of the Secret resource being referred to.
  17081. maxLength: 253
  17082. minLength: 1
  17083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17084. type: string
  17085. namespace:
  17086. description: |-
  17087. The namespace of the Secret resource being referred to.
  17088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17089. maxLength: 63
  17090. minLength: 1
  17091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17092. type: string
  17093. type: object
  17094. clientKeyRef:
  17095. description: |-
  17096. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17097. within a Secret resource. The key must be PEM-encoded.
  17098. properties:
  17099. key:
  17100. description: |-
  17101. A key in the referenced Secret.
  17102. Some instances of this field may be defaulted, in others it may be required.
  17103. maxLength: 253
  17104. minLength: 1
  17105. pattern: ^[-._a-zA-Z0-9]+$
  17106. type: string
  17107. name:
  17108. description: The name of the Secret resource being referred to.
  17109. maxLength: 253
  17110. minLength: 1
  17111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17112. type: string
  17113. namespace:
  17114. description: |-
  17115. The namespace of the Secret resource being referred to.
  17116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17117. maxLength: 63
  17118. minLength: 1
  17119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17120. type: string
  17121. type: object
  17122. hostId:
  17123. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17124. type: string
  17125. serviceID:
  17126. description: The conjur authn cert webservice id
  17127. type: string
  17128. required:
  17129. - account
  17130. - clientCertRef
  17131. - clientKeyRef
  17132. - serviceID
  17133. type: object
  17134. jwt:
  17135. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17136. properties:
  17137. account:
  17138. description: Account is the Conjur organization account name.
  17139. type: string
  17140. hostId:
  17141. description: |-
  17142. Optional HostID for JWT authentication. This may be used depending
  17143. on how the Conjur JWT authenticator policy is configured.
  17144. type: string
  17145. secretRef:
  17146. description: |-
  17147. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17148. authenticate with Conjur using the JWT authentication method.
  17149. properties:
  17150. key:
  17151. description: |-
  17152. A key in the referenced Secret.
  17153. Some instances of this field may be defaulted, in others it may be required.
  17154. maxLength: 253
  17155. minLength: 1
  17156. pattern: ^[-._a-zA-Z0-9]+$
  17157. type: string
  17158. name:
  17159. description: The name of the Secret resource being referred to.
  17160. maxLength: 253
  17161. minLength: 1
  17162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17163. type: string
  17164. namespace:
  17165. description: |-
  17166. The namespace of the Secret resource being referred to.
  17167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17168. maxLength: 63
  17169. minLength: 1
  17170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17171. type: string
  17172. type: object
  17173. serviceAccountRef:
  17174. description: |-
  17175. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17176. a token for with the `TokenRequest` API.
  17177. properties:
  17178. audiences:
  17179. description: |-
  17180. Audience specifies the `aud` claim for the service account token
  17181. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17182. then this audiences will be appended to the list
  17183. items:
  17184. type: string
  17185. type: array
  17186. name:
  17187. description: The name of the ServiceAccount resource being referred to.
  17188. maxLength: 253
  17189. minLength: 1
  17190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17191. type: string
  17192. namespace:
  17193. description: |-
  17194. Namespace of the resource being referred to.
  17195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17196. maxLength: 63
  17197. minLength: 1
  17198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17199. type: string
  17200. required:
  17201. - name
  17202. type: object
  17203. serviceID:
  17204. description: The conjur authn jwt webservice id
  17205. type: string
  17206. required:
  17207. - account
  17208. - serviceID
  17209. type: object
  17210. type: object
  17211. caBundle:
  17212. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17213. type: string
  17214. caProvider:
  17215. description: |-
  17216. Used to provide custom certificate authority (CA) certificates
  17217. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17218. that contains a PEM-encoded certificate.
  17219. properties:
  17220. key:
  17221. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17222. maxLength: 253
  17223. minLength: 1
  17224. pattern: ^[-._a-zA-Z0-9]+$
  17225. type: string
  17226. name:
  17227. description: The name of the object located at the provider type.
  17228. maxLength: 253
  17229. minLength: 1
  17230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17231. type: string
  17232. namespace:
  17233. description: |-
  17234. The namespace the Provider type is in.
  17235. Can only be defined when used in a ClusterSecretStore.
  17236. maxLength: 63
  17237. minLength: 1
  17238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17239. type: string
  17240. type:
  17241. description: The type of provider to use such as "Secret", or "ConfigMap".
  17242. enum:
  17243. - Secret
  17244. - ConfigMap
  17245. type: string
  17246. required:
  17247. - name
  17248. - type
  17249. type: object
  17250. url:
  17251. description: URL is the endpoint of the Conjur instance.
  17252. type: string
  17253. required:
  17254. - auth
  17255. - url
  17256. type: object
  17257. crd:
  17258. description: |-
  17259. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17260. including both custom resources (CRDs) and core API resources. Resources are
  17261. selected by API group, version and kind, where group can be "" (empty string)
  17262. for core resources such as ConfigMap. Reading the core v1 Secret is
  17263. intentionally blocked — use the Kubernetes provider for that.
  17264. properties:
  17265. auth:
  17266. description: |-
  17267. Auth configures authentication to the Kubernetes API, same as the
  17268. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17269. maxProperties: 1
  17270. minProperties: 1
  17271. properties:
  17272. cert:
  17273. description: has both clientCert and clientKey as secretKeySelector
  17274. properties:
  17275. clientCert:
  17276. description: |-
  17277. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17278. In some instances, `key` is a required field.
  17279. properties:
  17280. key:
  17281. description: |-
  17282. A key in the referenced Secret.
  17283. Some instances of this field may be defaulted, in others it may be required.
  17284. maxLength: 253
  17285. minLength: 1
  17286. pattern: ^[-._a-zA-Z0-9]+$
  17287. type: string
  17288. name:
  17289. description: The name of the Secret resource being referred to.
  17290. maxLength: 253
  17291. minLength: 1
  17292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17293. type: string
  17294. namespace:
  17295. description: |-
  17296. The namespace of the Secret resource being referred to.
  17297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17298. maxLength: 63
  17299. minLength: 1
  17300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17301. type: string
  17302. type: object
  17303. clientKey:
  17304. description: |-
  17305. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17306. In some instances, `key` is a required field.
  17307. properties:
  17308. key:
  17309. description: |-
  17310. A key in the referenced Secret.
  17311. Some instances of this field may be defaulted, in others it may be required.
  17312. maxLength: 253
  17313. minLength: 1
  17314. pattern: ^[-._a-zA-Z0-9]+$
  17315. type: string
  17316. name:
  17317. description: The name of the Secret resource being referred to.
  17318. maxLength: 253
  17319. minLength: 1
  17320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17321. type: string
  17322. namespace:
  17323. description: |-
  17324. The namespace of the Secret resource being referred to.
  17325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17326. maxLength: 63
  17327. minLength: 1
  17328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17329. type: string
  17330. type: object
  17331. required:
  17332. - clientCert
  17333. - clientKey
  17334. type: object
  17335. serviceAccount:
  17336. description: points to a service account that should be used for authentication
  17337. properties:
  17338. audiences:
  17339. description: |-
  17340. Audience specifies the `aud` claim for the service account token
  17341. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17342. then this audiences will be appended to the list
  17343. items:
  17344. type: string
  17345. type: array
  17346. name:
  17347. description: The name of the ServiceAccount resource being referred to.
  17348. maxLength: 253
  17349. minLength: 1
  17350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17351. type: string
  17352. namespace:
  17353. description: |-
  17354. Namespace of the resource being referred to.
  17355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17356. maxLength: 63
  17357. minLength: 1
  17358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17359. type: string
  17360. required:
  17361. - name
  17362. type: object
  17363. token:
  17364. description: use static token to authenticate with
  17365. properties:
  17366. bearerToken:
  17367. description: |-
  17368. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17369. In some instances, `key` is a required field.
  17370. properties:
  17371. key:
  17372. description: |-
  17373. A key in the referenced Secret.
  17374. Some instances of this field may be defaulted, in others it may be required.
  17375. maxLength: 253
  17376. minLength: 1
  17377. pattern: ^[-._a-zA-Z0-9]+$
  17378. type: string
  17379. name:
  17380. description: The name of the Secret resource being referred to.
  17381. maxLength: 253
  17382. minLength: 1
  17383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17384. type: string
  17385. namespace:
  17386. description: |-
  17387. The namespace of the Secret resource being referred to.
  17388. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17389. maxLength: 63
  17390. minLength: 1
  17391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17392. type: string
  17393. type: object
  17394. required:
  17395. - bearerToken
  17396. type: object
  17397. type: object
  17398. authRef:
  17399. description: |-
  17400. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17401. Kubernetes provider.
  17402. properties:
  17403. key:
  17404. description: |-
  17405. A key in the referenced Secret.
  17406. Some instances of this field may be defaulted, in others it may be required.
  17407. maxLength: 253
  17408. minLength: 1
  17409. pattern: ^[-._a-zA-Z0-9]+$
  17410. type: string
  17411. name:
  17412. description: The name of the Secret resource being referred to.
  17413. maxLength: 253
  17414. minLength: 1
  17415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17416. type: string
  17417. namespace:
  17418. description: |-
  17419. The namespace of the Secret resource being referred to.
  17420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17421. maxLength: 63
  17422. minLength: 1
  17423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17424. type: string
  17425. type: object
  17426. resource:
  17427. description: Resource identifies the CRD by its API group, version and kind.
  17428. properties:
  17429. group:
  17430. description: |-
  17431. Group is the API group of the resource. Use "" (empty string) for core
  17432. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17433. for a CRD. The field is required to be present in the manifest — write
  17434. `group: ""` explicitly for core resources so typos fail at admission
  17435. time rather than later at discovery.
  17436. type: string
  17437. kind:
  17438. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17439. minLength: 1
  17440. type: string
  17441. version:
  17442. description: Version is the API version of the resource (e.g. "v1alpha1").
  17443. minLength: 1
  17444. type: string
  17445. required:
  17446. - group
  17447. - kind
  17448. - version
  17449. type: object
  17450. server:
  17451. description: |-
  17452. Server configures the Kubernetes API address and TLS trust, same as the
  17453. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17454. properties:
  17455. caBundle:
  17456. description: CABundle is a base64-encoded CA certificate
  17457. format: byte
  17458. type: string
  17459. caProvider:
  17460. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17461. properties:
  17462. key:
  17463. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17464. maxLength: 253
  17465. minLength: 1
  17466. pattern: ^[-._a-zA-Z0-9]+$
  17467. type: string
  17468. name:
  17469. description: The name of the object located at the provider type.
  17470. maxLength: 253
  17471. minLength: 1
  17472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17473. type: string
  17474. namespace:
  17475. description: |-
  17476. The namespace the Provider type is in.
  17477. Can only be defined when used in a ClusterSecretStore.
  17478. maxLength: 63
  17479. minLength: 1
  17480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17481. type: string
  17482. type:
  17483. description: The type of provider to use such as "Secret", or "ConfigMap".
  17484. enum:
  17485. - Secret
  17486. - ConfigMap
  17487. type: string
  17488. required:
  17489. - name
  17490. - type
  17491. type: object
  17492. url:
  17493. default: kubernetes.default
  17494. description: configures the Kubernetes server Address.
  17495. type: string
  17496. type: object
  17497. whitelist:
  17498. description: |-
  17499. Whitelist optionally restricts which object names and requested properties
  17500. are allowed to be read.
  17501. properties:
  17502. rules:
  17503. description: |-
  17504. Rules is a list of allow rules. If rules are set, at least one rule must
  17505. match for a request to be allowed.
  17506. items:
  17507. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17508. properties:
  17509. name:
  17510. description: |-
  17511. Name is an optional regular expression matched against the bare object name.
  17512. For both SecretStore and ClusterSecretStore this is always the object name
  17513. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17514. type: string
  17515. namespace:
  17516. description: |-
  17517. Namespace is an optional regular expression matched against the namespace of
  17518. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17519. for SecretStore (where the namespace is fixed to the store namespace).
  17520. type: string
  17521. properties:
  17522. description: |-
  17523. Properties is an optional list of regular expressions matched against
  17524. requested property keys (for example: "spec.secretValue").
  17525. items:
  17526. type: string
  17527. type: array
  17528. type: object
  17529. type: array
  17530. type: object
  17531. required:
  17532. - resource
  17533. type: object
  17534. x-kubernetes-validations:
  17535. - message: one of auth or authRef is required
  17536. rule: has(self.auth) || has(self.authRef)
  17537. - message: at most one of the fields in [auth authRef] may be set
  17538. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17539. delinea:
  17540. description: |-
  17541. Delinea DevOps Secrets Vault
  17542. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17543. properties:
  17544. clientId:
  17545. description: ClientID is the non-secret part of the credential.
  17546. properties:
  17547. secretRef:
  17548. description: SecretRef references a key in a secret that will be used as value.
  17549. properties:
  17550. key:
  17551. description: |-
  17552. A key in the referenced Secret.
  17553. Some instances of this field may be defaulted, in others it may be required.
  17554. maxLength: 253
  17555. minLength: 1
  17556. pattern: ^[-._a-zA-Z0-9]+$
  17557. type: string
  17558. name:
  17559. description: The name of the Secret resource being referred to.
  17560. maxLength: 253
  17561. minLength: 1
  17562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17563. type: string
  17564. namespace:
  17565. description: |-
  17566. The namespace of the Secret resource being referred to.
  17567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17568. maxLength: 63
  17569. minLength: 1
  17570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17571. type: string
  17572. type: object
  17573. value:
  17574. description: Value can be specified directly to set a value without using a secret.
  17575. type: string
  17576. type: object
  17577. clientSecret:
  17578. description: ClientSecret is the secret part of the credential.
  17579. properties:
  17580. secretRef:
  17581. description: SecretRef references a key in a secret that will be used as value.
  17582. properties:
  17583. key:
  17584. description: |-
  17585. A key in the referenced Secret.
  17586. Some instances of this field may be defaulted, in others it may be required.
  17587. maxLength: 253
  17588. minLength: 1
  17589. pattern: ^[-._a-zA-Z0-9]+$
  17590. type: string
  17591. name:
  17592. description: The name of the Secret resource being referred to.
  17593. maxLength: 253
  17594. minLength: 1
  17595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17596. type: string
  17597. namespace:
  17598. description: |-
  17599. The namespace of the Secret resource being referred to.
  17600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17601. maxLength: 63
  17602. minLength: 1
  17603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17604. type: string
  17605. type: object
  17606. value:
  17607. description: Value can be specified directly to set a value without using a secret.
  17608. type: string
  17609. type: object
  17610. tenant:
  17611. description: Tenant is the chosen hostname / site name.
  17612. type: string
  17613. tld:
  17614. description: |-
  17615. TLD is based on the server location that was chosen during provisioning.
  17616. If unset, defaults to "com".
  17617. type: string
  17618. urlTemplate:
  17619. description: |-
  17620. URLTemplate
  17621. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17622. type: string
  17623. required:
  17624. - clientId
  17625. - clientSecret
  17626. - tenant
  17627. type: object
  17628. doppler:
  17629. description: Doppler configures this store to sync secrets using the Doppler provider
  17630. properties:
  17631. auth:
  17632. description: Auth configures how the Operator authenticates with the Doppler API
  17633. properties:
  17634. oidcConfig:
  17635. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17636. properties:
  17637. expirationSeconds:
  17638. default: 600
  17639. description: |-
  17640. ExpirationSeconds sets the ServiceAccount token validity duration.
  17641. Defaults to 10 minutes.
  17642. format: int64
  17643. type: integer
  17644. identity:
  17645. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17646. type: string
  17647. serviceAccountRef:
  17648. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17649. properties:
  17650. audiences:
  17651. description: |-
  17652. Audience specifies the `aud` claim for the service account token
  17653. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17654. then this audiences will be appended to the list
  17655. items:
  17656. type: string
  17657. type: array
  17658. name:
  17659. description: The name of the ServiceAccount resource being referred to.
  17660. maxLength: 253
  17661. minLength: 1
  17662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17663. type: string
  17664. namespace:
  17665. description: |-
  17666. Namespace of the resource being referred to.
  17667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17668. maxLength: 63
  17669. minLength: 1
  17670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17671. type: string
  17672. required:
  17673. - name
  17674. type: object
  17675. required:
  17676. - identity
  17677. - serviceAccountRef
  17678. type: object
  17679. secretRef:
  17680. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17681. properties:
  17682. dopplerToken:
  17683. description: |-
  17684. The DopplerToken is used for authentication.
  17685. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17686. The Key attribute defaults to dopplerToken if not specified.
  17687. properties:
  17688. key:
  17689. description: |-
  17690. A key in the referenced Secret.
  17691. Some instances of this field may be defaulted, in others it may be required.
  17692. maxLength: 253
  17693. minLength: 1
  17694. pattern: ^[-._a-zA-Z0-9]+$
  17695. type: string
  17696. name:
  17697. description: The name of the Secret resource being referred to.
  17698. maxLength: 253
  17699. minLength: 1
  17700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17701. type: string
  17702. namespace:
  17703. description: |-
  17704. The namespace of the Secret resource being referred to.
  17705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17706. maxLength: 63
  17707. minLength: 1
  17708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17709. type: string
  17710. type: object
  17711. required:
  17712. - dopplerToken
  17713. type: object
  17714. type: object
  17715. x-kubernetes-validations:
  17716. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17717. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17718. config:
  17719. description: Doppler config (required if not using a Service Token)
  17720. type: string
  17721. format:
  17722. description: Format enables the downloading of secrets as a file (string)
  17723. enum:
  17724. - json
  17725. - dotnet-json
  17726. - env
  17727. - yaml
  17728. - docker
  17729. type: string
  17730. nameTransformer:
  17731. description: Environment variable compatible name transforms that change secret names to a different format
  17732. enum:
  17733. - upper-camel
  17734. - camel
  17735. - lower-snake
  17736. - tf-var
  17737. - dotnet-env
  17738. - lower-kebab
  17739. type: string
  17740. project:
  17741. description: Doppler project (required if not using a Service Token)
  17742. type: string
  17743. required:
  17744. - auth
  17745. type: object
  17746. dvls:
  17747. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17748. properties:
  17749. auth:
  17750. description: Auth defines the authentication method to use.
  17751. properties:
  17752. secretRef:
  17753. description: SecretRef contains the Application ID and Application Secret for authentication.
  17754. properties:
  17755. appId:
  17756. description: AppID is the reference to the secret containing the Application ID.
  17757. properties:
  17758. key:
  17759. description: |-
  17760. A key in the referenced Secret.
  17761. Some instances of this field may be defaulted, in others it may be required.
  17762. maxLength: 253
  17763. minLength: 1
  17764. pattern: ^[-._a-zA-Z0-9]+$
  17765. type: string
  17766. name:
  17767. description: The name of the Secret resource being referred to.
  17768. maxLength: 253
  17769. minLength: 1
  17770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17771. type: string
  17772. namespace:
  17773. description: |-
  17774. The namespace of the Secret resource being referred to.
  17775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17776. maxLength: 63
  17777. minLength: 1
  17778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17779. type: string
  17780. type: object
  17781. appSecret:
  17782. description: AppSecret is the reference to the secret containing the Application Secret.
  17783. properties:
  17784. key:
  17785. description: |-
  17786. A key in the referenced Secret.
  17787. Some instances of this field may be defaulted, in others it may be required.
  17788. maxLength: 253
  17789. minLength: 1
  17790. pattern: ^[-._a-zA-Z0-9]+$
  17791. type: string
  17792. name:
  17793. description: The name of the Secret resource being referred to.
  17794. maxLength: 253
  17795. minLength: 1
  17796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17797. type: string
  17798. namespace:
  17799. description: |-
  17800. The namespace of the Secret resource being referred to.
  17801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17802. maxLength: 63
  17803. minLength: 1
  17804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17805. type: string
  17806. type: object
  17807. required:
  17808. - appId
  17809. - appSecret
  17810. type: object
  17811. required:
  17812. - secretRef
  17813. type: object
  17814. insecure:
  17815. description: |-
  17816. Insecure allows connecting to DVLS over plain HTTP.
  17817. This is NOT RECOMMENDED for production use.
  17818. Set to true only if you understand the security implications.
  17819. type: boolean
  17820. serverUrl:
  17821. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17822. type: string
  17823. vault:
  17824. description: |-
  17825. Vault is the name or UUID of the vault to fetch secrets from.
  17826. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17827. type: string
  17828. required:
  17829. - auth
  17830. - serverUrl
  17831. type: object
  17832. fake:
  17833. description: Fake configures a store with static key/value pairs
  17834. properties:
  17835. data:
  17836. items:
  17837. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17838. properties:
  17839. key:
  17840. type: string
  17841. value:
  17842. type: string
  17843. version:
  17844. type: string
  17845. required:
  17846. - key
  17847. - value
  17848. type: object
  17849. type: array
  17850. validationResult:
  17851. description: ValidationResult is defined type for the number of validation results.
  17852. type: integer
  17853. required:
  17854. - data
  17855. type: object
  17856. fortanix:
  17857. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17858. properties:
  17859. apiKey:
  17860. description: APIKey is the API token to access SDKMS Applications.
  17861. properties:
  17862. secretRef:
  17863. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17864. properties:
  17865. key:
  17866. description: |-
  17867. A key in the referenced Secret.
  17868. Some instances of this field may be defaulted, in others it may be required.
  17869. maxLength: 253
  17870. minLength: 1
  17871. pattern: ^[-._a-zA-Z0-9]+$
  17872. type: string
  17873. name:
  17874. description: The name of the Secret resource being referred to.
  17875. maxLength: 253
  17876. minLength: 1
  17877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17878. type: string
  17879. namespace:
  17880. description: |-
  17881. The namespace of the Secret resource being referred to.
  17882. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17883. maxLength: 63
  17884. minLength: 1
  17885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17886. type: string
  17887. type: object
  17888. type: object
  17889. apiUrl:
  17890. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17891. type: string
  17892. type: object
  17893. gcpsm:
  17894. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17895. properties:
  17896. auth:
  17897. description: Auth defines the information necessary to authenticate against GCP
  17898. properties:
  17899. secretRef:
  17900. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17901. properties:
  17902. secretAccessKeySecretRef:
  17903. description: The SecretAccessKey is used for authentication
  17904. properties:
  17905. key:
  17906. description: |-
  17907. A key in the referenced Secret.
  17908. Some instances of this field may be defaulted, in others it may be required.
  17909. maxLength: 253
  17910. minLength: 1
  17911. pattern: ^[-._a-zA-Z0-9]+$
  17912. type: string
  17913. name:
  17914. description: The name of the Secret resource being referred to.
  17915. maxLength: 253
  17916. minLength: 1
  17917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17918. type: string
  17919. namespace:
  17920. description: |-
  17921. The namespace of the Secret resource being referred to.
  17922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17923. maxLength: 63
  17924. minLength: 1
  17925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17926. type: string
  17927. type: object
  17928. type: object
  17929. workloadIdentity:
  17930. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17931. properties:
  17932. clusterLocation:
  17933. description: |-
  17934. ClusterLocation is the location of the cluster
  17935. If not specified, it fetches information from the metadata server
  17936. type: string
  17937. clusterName:
  17938. description: |-
  17939. ClusterName is the name of the cluster
  17940. If not specified, it fetches information from the metadata server
  17941. type: string
  17942. clusterProjectID:
  17943. description: |-
  17944. ClusterProjectID is the project ID of the cluster
  17945. If not specified, it fetches information from the metadata server
  17946. type: string
  17947. serviceAccountRef:
  17948. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17949. properties:
  17950. audiences:
  17951. description: |-
  17952. Audience specifies the `aud` claim for the service account token
  17953. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17954. then this audiences will be appended to the list
  17955. items:
  17956. type: string
  17957. type: array
  17958. name:
  17959. description: The name of the ServiceAccount resource being referred to.
  17960. maxLength: 253
  17961. minLength: 1
  17962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17963. type: string
  17964. namespace:
  17965. description: |-
  17966. Namespace of the resource being referred to.
  17967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17968. maxLength: 63
  17969. minLength: 1
  17970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17971. type: string
  17972. required:
  17973. - name
  17974. type: object
  17975. required:
  17976. - serviceAccountRef
  17977. type: object
  17978. workloadIdentityFederation:
  17979. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17980. properties:
  17981. audience:
  17982. description: |-
  17983. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17984. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17985. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17986. type: string
  17987. awsSecurityCredentials:
  17988. description: |-
  17989. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  17990. when using the AWS metadata server is not an option.
  17991. properties:
  17992. awsCredentialsSecretRef:
  17993. description: |-
  17994. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  17995. Secret should be created with below names for keys
  17996. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  17997. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  17998. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  17999. properties:
  18000. name:
  18001. description: name of the secret.
  18002. maxLength: 253
  18003. minLength: 1
  18004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18005. type: string
  18006. namespace:
  18007. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18008. maxLength: 63
  18009. minLength: 1
  18010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18011. type: string
  18012. required:
  18013. - name
  18014. type: object
  18015. region:
  18016. description: region is for configuring the AWS region to be used.
  18017. example: ap-south-1
  18018. maxLength: 50
  18019. minLength: 1
  18020. pattern: ^[a-z0-9-]+$
  18021. type: string
  18022. required:
  18023. - awsCredentialsSecretRef
  18024. - region
  18025. type: object
  18026. credConfig:
  18027. description: |-
  18028. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18029. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18030. serviceAccountRef must be used by providing operators service account details.
  18031. properties:
  18032. key:
  18033. description: key name holding the external account credential config.
  18034. maxLength: 253
  18035. minLength: 1
  18036. pattern: ^[-._a-zA-Z0-9]+$
  18037. type: string
  18038. name:
  18039. description: name of the configmap.
  18040. maxLength: 253
  18041. minLength: 1
  18042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18043. type: string
  18044. namespace:
  18045. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18046. maxLength: 63
  18047. minLength: 1
  18048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18049. type: string
  18050. required:
  18051. - key
  18052. - name
  18053. type: object
  18054. externalTokenEndpoint:
  18055. description: |-
  18056. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18057. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18058. URL is having the expected value.
  18059. type: string
  18060. gcpServiceAccountEmail:
  18061. description: |-
  18062. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18063. after Workload Identity Federation. Use this to grant access through the service account's
  18064. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18065. service_account_impersonation_url in the external account JSON from credConfig;
  18066. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18067. on that ServiceAccount.
  18068. example: my-gsa@my-project.iam.gserviceaccount.com
  18069. minLength: 1
  18070. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18071. type: string
  18072. serviceAccountRef:
  18073. description: |-
  18074. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18075. when Kubernetes is configured as provider in workload identity pool.
  18076. properties:
  18077. audiences:
  18078. description: |-
  18079. Audience specifies the `aud` claim for the service account token
  18080. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18081. then this audiences will be appended to the list
  18082. items:
  18083. type: string
  18084. type: array
  18085. name:
  18086. description: The name of the ServiceAccount resource being referred to.
  18087. maxLength: 253
  18088. minLength: 1
  18089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18090. type: string
  18091. namespace:
  18092. description: |-
  18093. Namespace of the resource being referred to.
  18094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18095. maxLength: 63
  18096. minLength: 1
  18097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18098. type: string
  18099. required:
  18100. - name
  18101. type: object
  18102. type: object
  18103. type: object
  18104. location:
  18105. description: Location optionally defines a location for a secret
  18106. type: string
  18107. projectID:
  18108. description: ProjectID project where secret is located
  18109. type: string
  18110. secretVersionSelectionPolicy:
  18111. default: LatestOrFail
  18112. description: |-
  18113. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18114. when "latest" is disabled or destroyed.
  18115. Possible values are:
  18116. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18117. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18118. type: string
  18119. type: object
  18120. github:
  18121. description: |-
  18122. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18123. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18124. properties:
  18125. appID:
  18126. description: appID specifies the Github APP that will be used to authenticate the client
  18127. format: int64
  18128. type: integer
  18129. auth:
  18130. description: auth configures how secret-manager authenticates with a Github instance.
  18131. properties:
  18132. privateKey:
  18133. description: |-
  18134. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18135. In some instances, `key` is a required field.
  18136. properties:
  18137. key:
  18138. description: |-
  18139. A key in the referenced Secret.
  18140. Some instances of this field may be defaulted, in others it may be required.
  18141. maxLength: 253
  18142. minLength: 1
  18143. pattern: ^[-._a-zA-Z0-9]+$
  18144. type: string
  18145. name:
  18146. description: The name of the Secret resource being referred to.
  18147. maxLength: 253
  18148. minLength: 1
  18149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18150. type: string
  18151. namespace:
  18152. description: |-
  18153. The namespace of the Secret resource being referred to.
  18154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18155. maxLength: 63
  18156. minLength: 1
  18157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18158. type: string
  18159. type: object
  18160. required:
  18161. - privateKey
  18162. type: object
  18163. environment:
  18164. description: environment will be used to fetch secrets from a particular environment within a github repository
  18165. type: string
  18166. installationID:
  18167. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18168. format: int64
  18169. type: integer
  18170. orgSecretVisibility:
  18171. description: |-
  18172. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18173. Valid values are "all" or "private".
  18174. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18175. whatever visibility they already have in GitHub.
  18176. enum:
  18177. - all
  18178. - private
  18179. type: string
  18180. organization:
  18181. description: organization will be used to fetch secrets from the Github organization
  18182. type: string
  18183. repository:
  18184. description: repository will be used to fetch secrets from the Github repository within an organization
  18185. type: string
  18186. uploadURL:
  18187. description: Upload URL for enterprise instances. Default to URL.
  18188. type: string
  18189. url:
  18190. default: https://github.com/
  18191. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18192. type: string
  18193. required:
  18194. - appID
  18195. - auth
  18196. - installationID
  18197. - organization
  18198. type: object
  18199. gitlab:
  18200. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18201. properties:
  18202. auth:
  18203. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18204. properties:
  18205. SecretRef:
  18206. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18207. properties:
  18208. accessToken:
  18209. description: AccessToken is used for authentication.
  18210. properties:
  18211. key:
  18212. description: |-
  18213. A key in the referenced Secret.
  18214. Some instances of this field may be defaulted, in others it may be required.
  18215. maxLength: 253
  18216. minLength: 1
  18217. pattern: ^[-._a-zA-Z0-9]+$
  18218. type: string
  18219. name:
  18220. description: The name of the Secret resource being referred to.
  18221. maxLength: 253
  18222. minLength: 1
  18223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18224. type: string
  18225. namespace:
  18226. description: |-
  18227. The namespace of the Secret resource being referred to.
  18228. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18229. maxLength: 63
  18230. minLength: 1
  18231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18232. type: string
  18233. type: object
  18234. type: object
  18235. required:
  18236. - SecretRef
  18237. type: object
  18238. caBundle:
  18239. description: |-
  18240. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18241. can be performed.
  18242. format: byte
  18243. type: string
  18244. caProvider:
  18245. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18246. properties:
  18247. key:
  18248. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18249. maxLength: 253
  18250. minLength: 1
  18251. pattern: ^[-._a-zA-Z0-9]+$
  18252. type: string
  18253. name:
  18254. description: The name of the object located at the provider type.
  18255. maxLength: 253
  18256. minLength: 1
  18257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18258. type: string
  18259. namespace:
  18260. description: |-
  18261. The namespace the Provider type is in.
  18262. Can only be defined when used in a ClusterSecretStore.
  18263. maxLength: 63
  18264. minLength: 1
  18265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18266. type: string
  18267. type:
  18268. description: The type of provider to use such as "Secret", or "ConfigMap".
  18269. enum:
  18270. - Secret
  18271. - ConfigMap
  18272. type: string
  18273. required:
  18274. - name
  18275. - type
  18276. type: object
  18277. environment:
  18278. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18279. type: string
  18280. groupIDs:
  18281. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18282. items:
  18283. type: string
  18284. type: array
  18285. inheritFromGroups:
  18286. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18287. type: boolean
  18288. projectID:
  18289. description: ProjectID specifies a project where secrets are located.
  18290. type: string
  18291. url:
  18292. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18293. type: string
  18294. required:
  18295. - auth
  18296. type: object
  18297. ibm:
  18298. description: IBM configures this store to sync secrets using IBM Cloud provider
  18299. properties:
  18300. auth:
  18301. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18302. maxProperties: 1
  18303. minProperties: 1
  18304. properties:
  18305. containerAuth:
  18306. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18307. properties:
  18308. iamEndpoint:
  18309. type: string
  18310. profile:
  18311. description: the IBM Trusted Profile
  18312. type: string
  18313. tokenLocation:
  18314. description: Location the token is mounted on the pod
  18315. type: string
  18316. required:
  18317. - profile
  18318. type: object
  18319. secretRef:
  18320. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18321. properties:
  18322. iamEndpoint:
  18323. description: The IAM endpoint used to obain a token
  18324. type: string
  18325. secretApiKeySecretRef:
  18326. description: The SecretAccessKey is used for authentication
  18327. properties:
  18328. key:
  18329. description: |-
  18330. A key in the referenced Secret.
  18331. Some instances of this field may be defaulted, in others it may be required.
  18332. maxLength: 253
  18333. minLength: 1
  18334. pattern: ^[-._a-zA-Z0-9]+$
  18335. type: string
  18336. name:
  18337. description: The name of the Secret resource being referred to.
  18338. maxLength: 253
  18339. minLength: 1
  18340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18341. type: string
  18342. namespace:
  18343. description: |-
  18344. The namespace of the Secret resource being referred to.
  18345. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18346. maxLength: 63
  18347. minLength: 1
  18348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18349. type: string
  18350. type: object
  18351. type: object
  18352. type: object
  18353. serviceUrl:
  18354. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18355. type: string
  18356. required:
  18357. - auth
  18358. type: object
  18359. infisical:
  18360. description: Infisical configures this store to sync secrets using the Infisical provider
  18361. properties:
  18362. auth:
  18363. description: Auth configures how the Operator authenticates with the Infisical API
  18364. properties:
  18365. awsAuthCredentials:
  18366. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18367. properties:
  18368. identityId:
  18369. description: |-
  18370. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18371. In some instances, `key` is a required field.
  18372. properties:
  18373. key:
  18374. description: |-
  18375. A key in the referenced Secret.
  18376. Some instances of this field may be defaulted, in others it may be required.
  18377. maxLength: 253
  18378. minLength: 1
  18379. pattern: ^[-._a-zA-Z0-9]+$
  18380. type: string
  18381. name:
  18382. description: The name of the Secret resource being referred to.
  18383. maxLength: 253
  18384. minLength: 1
  18385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18386. type: string
  18387. namespace:
  18388. description: |-
  18389. The namespace of the Secret resource being referred to.
  18390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18391. maxLength: 63
  18392. minLength: 1
  18393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18394. type: string
  18395. type: object
  18396. required:
  18397. - identityId
  18398. type: object
  18399. azureAuthCredentials:
  18400. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18401. properties:
  18402. identityId:
  18403. description: |-
  18404. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18405. In some instances, `key` is a required field.
  18406. properties:
  18407. key:
  18408. description: |-
  18409. A key in the referenced Secret.
  18410. Some instances of this field may be defaulted, in others it may be required.
  18411. maxLength: 253
  18412. minLength: 1
  18413. pattern: ^[-._a-zA-Z0-9]+$
  18414. type: string
  18415. name:
  18416. description: The name of the Secret resource being referred to.
  18417. maxLength: 253
  18418. minLength: 1
  18419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18420. type: string
  18421. namespace:
  18422. description: |-
  18423. The namespace of the Secret resource being referred to.
  18424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18425. maxLength: 63
  18426. minLength: 1
  18427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18428. type: string
  18429. type: object
  18430. resource:
  18431. description: |-
  18432. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18433. In some instances, `key` is a required field.
  18434. properties:
  18435. key:
  18436. description: |-
  18437. A key in the referenced Secret.
  18438. Some instances of this field may be defaulted, in others it may be required.
  18439. maxLength: 253
  18440. minLength: 1
  18441. pattern: ^[-._a-zA-Z0-9]+$
  18442. type: string
  18443. name:
  18444. description: The name of the Secret resource being referred to.
  18445. maxLength: 253
  18446. minLength: 1
  18447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18448. type: string
  18449. namespace:
  18450. description: |-
  18451. The namespace of the Secret resource being referred to.
  18452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18453. maxLength: 63
  18454. minLength: 1
  18455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18456. type: string
  18457. type: object
  18458. required:
  18459. - identityId
  18460. type: object
  18461. gcpIamAuthCredentials:
  18462. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18463. properties:
  18464. identityId:
  18465. description: |-
  18466. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18467. In some instances, `key` is a required field.
  18468. properties:
  18469. key:
  18470. description: |-
  18471. A key in the referenced Secret.
  18472. Some instances of this field may be defaulted, in others it may be required.
  18473. maxLength: 253
  18474. minLength: 1
  18475. pattern: ^[-._a-zA-Z0-9]+$
  18476. type: string
  18477. name:
  18478. description: The name of the Secret resource being referred to.
  18479. maxLength: 253
  18480. minLength: 1
  18481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18482. type: string
  18483. namespace:
  18484. description: |-
  18485. The namespace of the Secret resource being referred to.
  18486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18487. maxLength: 63
  18488. minLength: 1
  18489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18490. type: string
  18491. type: object
  18492. serviceAccountKeyFilePath:
  18493. description: |-
  18494. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18495. In some instances, `key` is a required field.
  18496. properties:
  18497. key:
  18498. description: |-
  18499. A key in the referenced Secret.
  18500. Some instances of this field may be defaulted, in others it may be required.
  18501. maxLength: 253
  18502. minLength: 1
  18503. pattern: ^[-._a-zA-Z0-9]+$
  18504. type: string
  18505. name:
  18506. description: The name of the Secret resource being referred to.
  18507. maxLength: 253
  18508. minLength: 1
  18509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18510. type: string
  18511. namespace:
  18512. description: |-
  18513. The namespace of the Secret resource being referred to.
  18514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18515. maxLength: 63
  18516. minLength: 1
  18517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18518. type: string
  18519. type: object
  18520. required:
  18521. - identityId
  18522. - serviceAccountKeyFilePath
  18523. type: object
  18524. gcpIdTokenAuthCredentials:
  18525. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18526. properties:
  18527. identityId:
  18528. description: |-
  18529. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18530. In some instances, `key` is a required field.
  18531. properties:
  18532. key:
  18533. description: |-
  18534. A key in the referenced Secret.
  18535. Some instances of this field may be defaulted, in others it may be required.
  18536. maxLength: 253
  18537. minLength: 1
  18538. pattern: ^[-._a-zA-Z0-9]+$
  18539. type: string
  18540. name:
  18541. description: The name of the Secret resource being referred to.
  18542. maxLength: 253
  18543. minLength: 1
  18544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18545. type: string
  18546. namespace:
  18547. description: |-
  18548. The namespace of the Secret resource being referred to.
  18549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18550. maxLength: 63
  18551. minLength: 1
  18552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18553. type: string
  18554. type: object
  18555. required:
  18556. - identityId
  18557. type: object
  18558. jwtAuthCredentials:
  18559. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18560. properties:
  18561. identityId:
  18562. description: |-
  18563. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18564. In some instances, `key` is a required field.
  18565. properties:
  18566. key:
  18567. description: |-
  18568. A key in the referenced Secret.
  18569. Some instances of this field may be defaulted, in others it may be required.
  18570. maxLength: 253
  18571. minLength: 1
  18572. pattern: ^[-._a-zA-Z0-9]+$
  18573. type: string
  18574. name:
  18575. description: The name of the Secret resource being referred to.
  18576. maxLength: 253
  18577. minLength: 1
  18578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18579. type: string
  18580. namespace:
  18581. description: |-
  18582. The namespace of the Secret resource being referred to.
  18583. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18584. maxLength: 63
  18585. minLength: 1
  18586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18587. type: string
  18588. type: object
  18589. jwt:
  18590. description: |-
  18591. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18592. In some instances, `key` is a required field.
  18593. properties:
  18594. key:
  18595. description: |-
  18596. A key in the referenced Secret.
  18597. Some instances of this field may be defaulted, in others it may be required.
  18598. maxLength: 253
  18599. minLength: 1
  18600. pattern: ^[-._a-zA-Z0-9]+$
  18601. type: string
  18602. name:
  18603. description: The name of the Secret resource being referred to.
  18604. maxLength: 253
  18605. minLength: 1
  18606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18607. type: string
  18608. namespace:
  18609. description: |-
  18610. The namespace of the Secret resource being referred to.
  18611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18612. maxLength: 63
  18613. minLength: 1
  18614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18615. type: string
  18616. type: object
  18617. required:
  18618. - identityId
  18619. - jwt
  18620. type: object
  18621. kubernetesAuthCredentials:
  18622. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18623. properties:
  18624. identityId:
  18625. description: |-
  18626. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18627. In some instances, `key` is a required field.
  18628. properties:
  18629. key:
  18630. description: |-
  18631. A key in the referenced Secret.
  18632. Some instances of this field may be defaulted, in others it may be required.
  18633. maxLength: 253
  18634. minLength: 1
  18635. pattern: ^[-._a-zA-Z0-9]+$
  18636. type: string
  18637. name:
  18638. description: The name of the Secret resource being referred to.
  18639. maxLength: 253
  18640. minLength: 1
  18641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18642. type: string
  18643. namespace:
  18644. description: |-
  18645. The namespace of the Secret resource being referred to.
  18646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18647. maxLength: 63
  18648. minLength: 1
  18649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18650. type: string
  18651. type: object
  18652. serviceAccountTokenPath:
  18653. description: |-
  18654. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18655. In some instances, `key` is a required field.
  18656. properties:
  18657. key:
  18658. description: |-
  18659. A key in the referenced Secret.
  18660. Some instances of this field may be defaulted, in others it may be required.
  18661. maxLength: 253
  18662. minLength: 1
  18663. pattern: ^[-._a-zA-Z0-9]+$
  18664. type: string
  18665. name:
  18666. description: The name of the Secret resource being referred to.
  18667. maxLength: 253
  18668. minLength: 1
  18669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18670. type: string
  18671. namespace:
  18672. description: |-
  18673. The namespace of the Secret resource being referred to.
  18674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18675. maxLength: 63
  18676. minLength: 1
  18677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18678. type: string
  18679. type: object
  18680. required:
  18681. - identityId
  18682. type: object
  18683. ldapAuthCredentials:
  18684. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18685. properties:
  18686. identityId:
  18687. description: |-
  18688. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18689. In some instances, `key` is a required field.
  18690. properties:
  18691. key:
  18692. description: |-
  18693. A key in the referenced Secret.
  18694. Some instances of this field may be defaulted, in others it may be required.
  18695. maxLength: 253
  18696. minLength: 1
  18697. pattern: ^[-._a-zA-Z0-9]+$
  18698. type: string
  18699. name:
  18700. description: The name of the Secret resource being referred to.
  18701. maxLength: 253
  18702. minLength: 1
  18703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18704. type: string
  18705. namespace:
  18706. description: |-
  18707. The namespace of the Secret resource being referred to.
  18708. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18709. maxLength: 63
  18710. minLength: 1
  18711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18712. type: string
  18713. type: object
  18714. ldapPassword:
  18715. description: |-
  18716. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18717. In some instances, `key` is a required field.
  18718. properties:
  18719. key:
  18720. description: |-
  18721. A key in the referenced Secret.
  18722. Some instances of this field may be defaulted, in others it may be required.
  18723. maxLength: 253
  18724. minLength: 1
  18725. pattern: ^[-._a-zA-Z0-9]+$
  18726. type: string
  18727. name:
  18728. description: The name of the Secret resource being referred to.
  18729. maxLength: 253
  18730. minLength: 1
  18731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18732. type: string
  18733. namespace:
  18734. description: |-
  18735. The namespace of the Secret resource being referred to.
  18736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18737. maxLength: 63
  18738. minLength: 1
  18739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18740. type: string
  18741. type: object
  18742. ldapUsername:
  18743. description: |-
  18744. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18745. In some instances, `key` is a required field.
  18746. properties:
  18747. key:
  18748. description: |-
  18749. A key in the referenced Secret.
  18750. Some instances of this field may be defaulted, in others it may be required.
  18751. maxLength: 253
  18752. minLength: 1
  18753. pattern: ^[-._a-zA-Z0-9]+$
  18754. type: string
  18755. name:
  18756. description: The name of the Secret resource being referred to.
  18757. maxLength: 253
  18758. minLength: 1
  18759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18760. type: string
  18761. namespace:
  18762. description: |-
  18763. The namespace of the Secret resource being referred to.
  18764. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18765. maxLength: 63
  18766. minLength: 1
  18767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18768. type: string
  18769. type: object
  18770. required:
  18771. - identityId
  18772. - ldapPassword
  18773. - ldapUsername
  18774. type: object
  18775. ociAuthCredentials:
  18776. description: OciAuthCredentials represents the credentials for OCI authentication.
  18777. properties:
  18778. fingerprint:
  18779. description: |-
  18780. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18781. In some instances, `key` is a required field.
  18782. properties:
  18783. key:
  18784. description: |-
  18785. A key in the referenced Secret.
  18786. Some instances of this field may be defaulted, in others it may be required.
  18787. maxLength: 253
  18788. minLength: 1
  18789. pattern: ^[-._a-zA-Z0-9]+$
  18790. type: string
  18791. name:
  18792. description: The name of the Secret resource being referred to.
  18793. maxLength: 253
  18794. minLength: 1
  18795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18796. type: string
  18797. namespace:
  18798. description: |-
  18799. The namespace of the Secret resource being referred to.
  18800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18801. maxLength: 63
  18802. minLength: 1
  18803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18804. type: string
  18805. type: object
  18806. identityId:
  18807. description: |-
  18808. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18809. In some instances, `key` is a required field.
  18810. properties:
  18811. key:
  18812. description: |-
  18813. A key in the referenced Secret.
  18814. Some instances of this field may be defaulted, in others it may be required.
  18815. maxLength: 253
  18816. minLength: 1
  18817. pattern: ^[-._a-zA-Z0-9]+$
  18818. type: string
  18819. name:
  18820. description: The name of the Secret resource being referred to.
  18821. maxLength: 253
  18822. minLength: 1
  18823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18824. type: string
  18825. namespace:
  18826. description: |-
  18827. The namespace of the Secret resource being referred to.
  18828. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18829. maxLength: 63
  18830. minLength: 1
  18831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18832. type: string
  18833. type: object
  18834. privateKey:
  18835. description: |-
  18836. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18837. In some instances, `key` is a required field.
  18838. properties:
  18839. key:
  18840. description: |-
  18841. A key in the referenced Secret.
  18842. Some instances of this field may be defaulted, in others it may be required.
  18843. maxLength: 253
  18844. minLength: 1
  18845. pattern: ^[-._a-zA-Z0-9]+$
  18846. type: string
  18847. name:
  18848. description: The name of the Secret resource being referred to.
  18849. maxLength: 253
  18850. minLength: 1
  18851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18852. type: string
  18853. namespace:
  18854. description: |-
  18855. The namespace of the Secret resource being referred to.
  18856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18857. maxLength: 63
  18858. minLength: 1
  18859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18860. type: string
  18861. type: object
  18862. privateKeyPassphrase:
  18863. description: |-
  18864. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18865. In some instances, `key` is a required field.
  18866. properties:
  18867. key:
  18868. description: |-
  18869. A key in the referenced Secret.
  18870. Some instances of this field may be defaulted, in others it may be required.
  18871. maxLength: 253
  18872. minLength: 1
  18873. pattern: ^[-._a-zA-Z0-9]+$
  18874. type: string
  18875. name:
  18876. description: The name of the Secret resource being referred to.
  18877. maxLength: 253
  18878. minLength: 1
  18879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18880. type: string
  18881. namespace:
  18882. description: |-
  18883. The namespace of the Secret resource being referred to.
  18884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18885. maxLength: 63
  18886. minLength: 1
  18887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18888. type: string
  18889. type: object
  18890. region:
  18891. description: |-
  18892. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18893. In some instances, `key` is a required field.
  18894. properties:
  18895. key:
  18896. description: |-
  18897. A key in the referenced Secret.
  18898. Some instances of this field may be defaulted, in others it may be required.
  18899. maxLength: 253
  18900. minLength: 1
  18901. pattern: ^[-._a-zA-Z0-9]+$
  18902. type: string
  18903. name:
  18904. description: The name of the Secret resource being referred to.
  18905. maxLength: 253
  18906. minLength: 1
  18907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18908. type: string
  18909. namespace:
  18910. description: |-
  18911. The namespace of the Secret resource being referred to.
  18912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18913. maxLength: 63
  18914. minLength: 1
  18915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18916. type: string
  18917. type: object
  18918. tenancyId:
  18919. description: |-
  18920. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18921. In some instances, `key` is a required field.
  18922. properties:
  18923. key:
  18924. description: |-
  18925. A key in the referenced Secret.
  18926. Some instances of this field may be defaulted, in others it may be required.
  18927. maxLength: 253
  18928. minLength: 1
  18929. pattern: ^[-._a-zA-Z0-9]+$
  18930. type: string
  18931. name:
  18932. description: The name of the Secret resource being referred to.
  18933. maxLength: 253
  18934. minLength: 1
  18935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18936. type: string
  18937. namespace:
  18938. description: |-
  18939. The namespace of the Secret resource being referred to.
  18940. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18941. maxLength: 63
  18942. minLength: 1
  18943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18944. type: string
  18945. type: object
  18946. userId:
  18947. description: |-
  18948. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18949. In some instances, `key` is a required field.
  18950. properties:
  18951. key:
  18952. description: |-
  18953. A key in the referenced Secret.
  18954. Some instances of this field may be defaulted, in others it may be required.
  18955. maxLength: 253
  18956. minLength: 1
  18957. pattern: ^[-._a-zA-Z0-9]+$
  18958. type: string
  18959. name:
  18960. description: The name of the Secret resource being referred to.
  18961. maxLength: 253
  18962. minLength: 1
  18963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18964. type: string
  18965. namespace:
  18966. description: |-
  18967. The namespace of the Secret resource being referred to.
  18968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18969. maxLength: 63
  18970. minLength: 1
  18971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18972. type: string
  18973. type: object
  18974. required:
  18975. - fingerprint
  18976. - identityId
  18977. - privateKey
  18978. - region
  18979. - tenancyId
  18980. - userId
  18981. type: object
  18982. tokenAuthCredentials:
  18983. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18984. properties:
  18985. accessToken:
  18986. description: |-
  18987. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18988. In some instances, `key` is a required field.
  18989. properties:
  18990. key:
  18991. description: |-
  18992. A key in the referenced Secret.
  18993. Some instances of this field may be defaulted, in others it may be required.
  18994. maxLength: 253
  18995. minLength: 1
  18996. pattern: ^[-._a-zA-Z0-9]+$
  18997. type: string
  18998. name:
  18999. description: The name of the Secret resource being referred to.
  19000. maxLength: 253
  19001. minLength: 1
  19002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19003. type: string
  19004. namespace:
  19005. description: |-
  19006. The namespace of the Secret resource being referred to.
  19007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19008. maxLength: 63
  19009. minLength: 1
  19010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19011. type: string
  19012. type: object
  19013. required:
  19014. - accessToken
  19015. type: object
  19016. universalAuthCredentials:
  19017. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19018. properties:
  19019. clientId:
  19020. description: |-
  19021. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19022. In some instances, `key` is a required field.
  19023. properties:
  19024. key:
  19025. description: |-
  19026. A key in the referenced Secret.
  19027. Some instances of this field may be defaulted, in others it may be required.
  19028. maxLength: 253
  19029. minLength: 1
  19030. pattern: ^[-._a-zA-Z0-9]+$
  19031. type: string
  19032. name:
  19033. description: The name of the Secret resource being referred to.
  19034. maxLength: 253
  19035. minLength: 1
  19036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19037. type: string
  19038. namespace:
  19039. description: |-
  19040. The namespace of the Secret resource being referred to.
  19041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19042. maxLength: 63
  19043. minLength: 1
  19044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19045. type: string
  19046. type: object
  19047. clientSecret:
  19048. description: |-
  19049. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19050. In some instances, `key` is a required field.
  19051. properties:
  19052. key:
  19053. description: |-
  19054. A key in the referenced Secret.
  19055. Some instances of this field may be defaulted, in others it may be required.
  19056. maxLength: 253
  19057. minLength: 1
  19058. pattern: ^[-._a-zA-Z0-9]+$
  19059. type: string
  19060. name:
  19061. description: The name of the Secret resource being referred to.
  19062. maxLength: 253
  19063. minLength: 1
  19064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19065. type: string
  19066. namespace:
  19067. description: |-
  19068. The namespace of the Secret resource being referred to.
  19069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19070. maxLength: 63
  19071. minLength: 1
  19072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19073. type: string
  19074. type: object
  19075. required:
  19076. - clientId
  19077. - clientSecret
  19078. type: object
  19079. type: object
  19080. caBundle:
  19081. description: |-
  19082. CABundle is a PEM-encoded CA certificate bundle used to validate
  19083. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19084. format: byte
  19085. type: string
  19086. caProvider:
  19087. description: |-
  19088. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19089. The certificate is used to validate the Infisical server's TLS certificate.
  19090. Mutually exclusive with CABundle.
  19091. properties:
  19092. key:
  19093. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19094. maxLength: 253
  19095. minLength: 1
  19096. pattern: ^[-._a-zA-Z0-9]+$
  19097. type: string
  19098. name:
  19099. description: The name of the object located at the provider type.
  19100. maxLength: 253
  19101. minLength: 1
  19102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19103. type: string
  19104. namespace:
  19105. description: |-
  19106. The namespace the Provider type is in.
  19107. Can only be defined when used in a ClusterSecretStore.
  19108. maxLength: 63
  19109. minLength: 1
  19110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19111. type: string
  19112. type:
  19113. description: The type of provider to use such as "Secret", or "ConfigMap".
  19114. enum:
  19115. - Secret
  19116. - ConfigMap
  19117. type: string
  19118. required:
  19119. - name
  19120. - type
  19121. type: object
  19122. hostAPI:
  19123. default: https://app.infisical.com/api
  19124. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19125. type: string
  19126. secretsScope:
  19127. description: SecretsScope defines the scope of the secrets within the workspace
  19128. properties:
  19129. environmentSlug:
  19130. description: EnvironmentSlug is the required slug identifier for the environment.
  19131. type: string
  19132. expandSecretReferences:
  19133. default: true
  19134. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19135. type: boolean
  19136. organizationSlug:
  19137. description: |-
  19138. OrganizationSlug is the optional slug that identifies the organization that will be used
  19139. during authentication. Useful for sub-organization setups
  19140. type: string
  19141. projectSlug:
  19142. description: ProjectSlug is the required slug identifier for the project.
  19143. type: string
  19144. recursive:
  19145. default: false
  19146. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19147. type: boolean
  19148. secretsPath:
  19149. default: /
  19150. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19151. type: string
  19152. required:
  19153. - environmentSlug
  19154. - projectSlug
  19155. type: object
  19156. required:
  19157. - auth
  19158. - secretsScope
  19159. type: object
  19160. keepersecurity:
  19161. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19162. properties:
  19163. authRef:
  19164. description: |-
  19165. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19166. In some instances, `key` is a required field.
  19167. properties:
  19168. key:
  19169. description: |-
  19170. A key in the referenced Secret.
  19171. Some instances of this field may be defaulted, in others it may be required.
  19172. maxLength: 253
  19173. minLength: 1
  19174. pattern: ^[-._a-zA-Z0-9]+$
  19175. type: string
  19176. name:
  19177. description: The name of the Secret resource being referred to.
  19178. maxLength: 253
  19179. minLength: 1
  19180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19181. type: string
  19182. namespace:
  19183. description: |-
  19184. The namespace of the Secret resource being referred to.
  19185. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19186. maxLength: 63
  19187. minLength: 1
  19188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19189. type: string
  19190. type: object
  19191. folderID:
  19192. type: string
  19193. getByTitleFallback:
  19194. type: boolean
  19195. required:
  19196. - authRef
  19197. - folderID
  19198. type: object
  19199. kubernetes:
  19200. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19201. properties:
  19202. auth:
  19203. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19204. maxProperties: 1
  19205. minProperties: 1
  19206. properties:
  19207. cert:
  19208. description: has both clientCert and clientKey as secretKeySelector
  19209. properties:
  19210. clientCert:
  19211. description: |-
  19212. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19213. In some instances, `key` is a required field.
  19214. properties:
  19215. key:
  19216. description: |-
  19217. A key in the referenced Secret.
  19218. Some instances of this field may be defaulted, in others it may be required.
  19219. maxLength: 253
  19220. minLength: 1
  19221. pattern: ^[-._a-zA-Z0-9]+$
  19222. type: string
  19223. name:
  19224. description: The name of the Secret resource being referred to.
  19225. maxLength: 253
  19226. minLength: 1
  19227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19228. type: string
  19229. namespace:
  19230. description: |-
  19231. The namespace of the Secret resource being referred to.
  19232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19233. maxLength: 63
  19234. minLength: 1
  19235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19236. type: string
  19237. type: object
  19238. clientKey:
  19239. description: |-
  19240. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19241. In some instances, `key` is a required field.
  19242. properties:
  19243. key:
  19244. description: |-
  19245. A key in the referenced Secret.
  19246. Some instances of this field may be defaulted, in others it may be required.
  19247. maxLength: 253
  19248. minLength: 1
  19249. pattern: ^[-._a-zA-Z0-9]+$
  19250. type: string
  19251. name:
  19252. description: The name of the Secret resource being referred to.
  19253. maxLength: 253
  19254. minLength: 1
  19255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19256. type: string
  19257. namespace:
  19258. description: |-
  19259. The namespace of the Secret resource being referred to.
  19260. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19261. maxLength: 63
  19262. minLength: 1
  19263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19264. type: string
  19265. type: object
  19266. required:
  19267. - clientCert
  19268. - clientKey
  19269. type: object
  19270. serviceAccount:
  19271. description: points to a service account that should be used for authentication
  19272. properties:
  19273. audiences:
  19274. description: |-
  19275. Audience specifies the `aud` claim for the service account token
  19276. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19277. then this audiences will be appended to the list
  19278. items:
  19279. type: string
  19280. type: array
  19281. name:
  19282. description: The name of the ServiceAccount resource being referred to.
  19283. maxLength: 253
  19284. minLength: 1
  19285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19286. type: string
  19287. namespace:
  19288. description: |-
  19289. Namespace of the resource being referred to.
  19290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19291. maxLength: 63
  19292. minLength: 1
  19293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19294. type: string
  19295. required:
  19296. - name
  19297. type: object
  19298. token:
  19299. description: use static token to authenticate with
  19300. properties:
  19301. bearerToken:
  19302. description: |-
  19303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19304. In some instances, `key` is a required field.
  19305. properties:
  19306. key:
  19307. description: |-
  19308. A key in the referenced Secret.
  19309. Some instances of this field may be defaulted, in others it may be required.
  19310. maxLength: 253
  19311. minLength: 1
  19312. pattern: ^[-._a-zA-Z0-9]+$
  19313. type: string
  19314. name:
  19315. description: The name of the Secret resource being referred to.
  19316. maxLength: 253
  19317. minLength: 1
  19318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19319. type: string
  19320. namespace:
  19321. description: |-
  19322. The namespace of the Secret resource being referred to.
  19323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19324. maxLength: 63
  19325. minLength: 1
  19326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19327. type: string
  19328. type: object
  19329. required:
  19330. - bearerToken
  19331. type: object
  19332. type: object
  19333. authRef:
  19334. description: A reference to a secret that contains the auth information.
  19335. properties:
  19336. key:
  19337. description: |-
  19338. A key in the referenced Secret.
  19339. Some instances of this field may be defaulted, in others it may be required.
  19340. maxLength: 253
  19341. minLength: 1
  19342. pattern: ^[-._a-zA-Z0-9]+$
  19343. type: string
  19344. name:
  19345. description: The name of the Secret resource being referred to.
  19346. maxLength: 253
  19347. minLength: 1
  19348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19349. type: string
  19350. namespace:
  19351. description: |-
  19352. The namespace of the Secret resource being referred to.
  19353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19354. maxLength: 63
  19355. minLength: 1
  19356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19357. type: string
  19358. type: object
  19359. remoteNamespace:
  19360. default: default
  19361. description: Remote namespace to fetch the secrets from
  19362. maxLength: 63
  19363. minLength: 1
  19364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19365. type: string
  19366. server:
  19367. description: configures the Kubernetes server Address.
  19368. properties:
  19369. caBundle:
  19370. description: CABundle is a base64-encoded CA certificate
  19371. format: byte
  19372. type: string
  19373. caProvider:
  19374. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19375. properties:
  19376. key:
  19377. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19378. maxLength: 253
  19379. minLength: 1
  19380. pattern: ^[-._a-zA-Z0-9]+$
  19381. type: string
  19382. name:
  19383. description: The name of the object located at the provider type.
  19384. maxLength: 253
  19385. minLength: 1
  19386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19387. type: string
  19388. namespace:
  19389. description: |-
  19390. The namespace the Provider type is in.
  19391. Can only be defined when used in a ClusterSecretStore.
  19392. maxLength: 63
  19393. minLength: 1
  19394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19395. type: string
  19396. type:
  19397. description: The type of provider to use such as "Secret", or "ConfigMap".
  19398. enum:
  19399. - Secret
  19400. - ConfigMap
  19401. type: string
  19402. required:
  19403. - name
  19404. - type
  19405. type: object
  19406. url:
  19407. default: kubernetes.default
  19408. description: configures the Kubernetes server Address.
  19409. type: string
  19410. type: object
  19411. type: object
  19412. nebiusmysterybox:
  19413. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19414. properties:
  19415. apiDomain:
  19416. description: NebiusMysterybox API endpoint
  19417. type: string
  19418. auth:
  19419. description: Auth defines parameters to authenticate in MysteryBox
  19420. properties:
  19421. serviceAccountCredsSecretRef:
  19422. description: |-
  19423. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19424. document with service account credentials used to get an IAM token.
  19425. Expected JSON structure:
  19426. {
  19427. "subject-credentials": {
  19428. "alg": "RS256",
  19429. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19430. "kid": "<public-key-id>",
  19431. "iss": "<issuer-service-account-id>",
  19432. "sub": "<subject-service-account-id>"
  19433. }
  19434. }
  19435. properties:
  19436. key:
  19437. description: |-
  19438. A key in the referenced Secret.
  19439. Some instances of this field may be defaulted, in others it may be required.
  19440. maxLength: 253
  19441. minLength: 1
  19442. pattern: ^[-._a-zA-Z0-9]+$
  19443. type: string
  19444. name:
  19445. description: The name of the Secret resource being referred to.
  19446. maxLength: 253
  19447. minLength: 1
  19448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19449. type: string
  19450. namespace:
  19451. description: |-
  19452. The namespace of the Secret resource being referred to.
  19453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19454. maxLength: 63
  19455. minLength: 1
  19456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19457. type: string
  19458. type: object
  19459. tokenSecretRef:
  19460. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19461. properties:
  19462. key:
  19463. description: |-
  19464. A key in the referenced Secret.
  19465. Some instances of this field may be defaulted, in others it may be required.
  19466. maxLength: 253
  19467. minLength: 1
  19468. pattern: ^[-._a-zA-Z0-9]+$
  19469. type: string
  19470. name:
  19471. description: The name of the Secret resource being referred to.
  19472. maxLength: 253
  19473. minLength: 1
  19474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19475. type: string
  19476. namespace:
  19477. description: |-
  19478. The namespace of the Secret resource being referred to.
  19479. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19480. maxLength: 63
  19481. minLength: 1
  19482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19483. type: string
  19484. type: object
  19485. type: object
  19486. x-kubernetes-validations:
  19487. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  19488. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  19489. caProvider:
  19490. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19491. properties:
  19492. certSecretRef:
  19493. description: |-
  19494. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19495. In some instances, `key` is a required field.
  19496. properties:
  19497. key:
  19498. description: |-
  19499. A key in the referenced Secret.
  19500. Some instances of this field may be defaulted, in others it may be required.
  19501. maxLength: 253
  19502. minLength: 1
  19503. pattern: ^[-._a-zA-Z0-9]+$
  19504. type: string
  19505. name:
  19506. description: The name of the Secret resource being referred to.
  19507. maxLength: 253
  19508. minLength: 1
  19509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19510. type: string
  19511. namespace:
  19512. description: |-
  19513. The namespace of the Secret resource being referred to.
  19514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19515. maxLength: 63
  19516. minLength: 1
  19517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19518. type: string
  19519. type: object
  19520. type: object
  19521. required:
  19522. - apiDomain
  19523. - auth
  19524. type: object
  19525. ngrok:
  19526. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19527. properties:
  19528. apiUrl:
  19529. default: https://api.ngrok.com
  19530. description: APIURL is the URL of the ngrok API.
  19531. type: string
  19532. auth:
  19533. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19534. maxProperties: 1
  19535. minProperties: 1
  19536. properties:
  19537. apiKey:
  19538. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19539. properties:
  19540. secretRef:
  19541. description: SecretRef is a reference to a secret containing the ngrok API key.
  19542. properties:
  19543. key:
  19544. description: |-
  19545. A key in the referenced Secret.
  19546. Some instances of this field may be defaulted, in others it may be required.
  19547. maxLength: 253
  19548. minLength: 1
  19549. pattern: ^[-._a-zA-Z0-9]+$
  19550. type: string
  19551. name:
  19552. description: The name of the Secret resource being referred to.
  19553. maxLength: 253
  19554. minLength: 1
  19555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19556. type: string
  19557. namespace:
  19558. description: |-
  19559. The namespace of the Secret resource being referred to.
  19560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19561. maxLength: 63
  19562. minLength: 1
  19563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19564. type: string
  19565. type: object
  19566. type: object
  19567. type: object
  19568. vault:
  19569. description: Vault configures the ngrok vault to sync secrets with.
  19570. properties:
  19571. name:
  19572. description: Name is the name of the ngrok vault to sync secrets with.
  19573. type: string
  19574. required:
  19575. - name
  19576. type: object
  19577. required:
  19578. - auth
  19579. - vault
  19580. type: object
  19581. onboardbase:
  19582. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19583. properties:
  19584. apiHost:
  19585. default: https://public.onboardbase.com/api/v1/
  19586. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19587. type: string
  19588. auth:
  19589. description: Auth configures how the Operator authenticates with the Onboardbase API
  19590. properties:
  19591. apiKeyRef:
  19592. description: |-
  19593. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19594. It is used to recognize and authorize access to a project and environment within onboardbase
  19595. properties:
  19596. key:
  19597. description: |-
  19598. A key in the referenced Secret.
  19599. Some instances of this field may be defaulted, in others it may be required.
  19600. maxLength: 253
  19601. minLength: 1
  19602. pattern: ^[-._a-zA-Z0-9]+$
  19603. type: string
  19604. name:
  19605. description: The name of the Secret resource being referred to.
  19606. maxLength: 253
  19607. minLength: 1
  19608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19609. type: string
  19610. namespace:
  19611. description: |-
  19612. The namespace of the Secret resource being referred to.
  19613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19614. maxLength: 63
  19615. minLength: 1
  19616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19617. type: string
  19618. type: object
  19619. passcodeRef:
  19620. description: OnboardbasePasscode is the passcode attached to the API Key
  19621. properties:
  19622. key:
  19623. description: |-
  19624. A key in the referenced Secret.
  19625. Some instances of this field may be defaulted, in others it may be required.
  19626. maxLength: 253
  19627. minLength: 1
  19628. pattern: ^[-._a-zA-Z0-9]+$
  19629. type: string
  19630. name:
  19631. description: The name of the Secret resource being referred to.
  19632. maxLength: 253
  19633. minLength: 1
  19634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19635. type: string
  19636. namespace:
  19637. description: |-
  19638. The namespace of the Secret resource being referred to.
  19639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19640. maxLength: 63
  19641. minLength: 1
  19642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19643. type: string
  19644. type: object
  19645. required:
  19646. - apiKeyRef
  19647. - passcodeRef
  19648. type: object
  19649. environment:
  19650. default: development
  19651. description: Environment is the name of an environmnent within a project to pull the secrets from
  19652. type: string
  19653. project:
  19654. default: development
  19655. description: Project is an onboardbase project that the secrets should be pulled from
  19656. type: string
  19657. required:
  19658. - apiHost
  19659. - auth
  19660. - environment
  19661. - project
  19662. type: object
  19663. onepassword:
  19664. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19665. properties:
  19666. auth:
  19667. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19668. properties:
  19669. secretRef:
  19670. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19671. properties:
  19672. connectTokenSecretRef:
  19673. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19674. properties:
  19675. key:
  19676. description: |-
  19677. A key in the referenced Secret.
  19678. Some instances of this field may be defaulted, in others it may be required.
  19679. maxLength: 253
  19680. minLength: 1
  19681. pattern: ^[-._a-zA-Z0-9]+$
  19682. type: string
  19683. name:
  19684. description: The name of the Secret resource being referred to.
  19685. maxLength: 253
  19686. minLength: 1
  19687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19688. type: string
  19689. namespace:
  19690. description: |-
  19691. The namespace of the Secret resource being referred to.
  19692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19693. maxLength: 63
  19694. minLength: 1
  19695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19696. type: string
  19697. type: object
  19698. required:
  19699. - connectTokenSecretRef
  19700. type: object
  19701. required:
  19702. - secretRef
  19703. type: object
  19704. connectHost:
  19705. description: ConnectHost defines the OnePassword Connect Server to connect to
  19706. type: string
  19707. vaults:
  19708. additionalProperties:
  19709. type: integer
  19710. description: Vaults defines which OnePassword vaults to search in which order
  19711. type: object
  19712. required:
  19713. - auth
  19714. - connectHost
  19715. - vaults
  19716. type: object
  19717. onepasswordSDK:
  19718. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19719. properties:
  19720. auth:
  19721. description: Auth defines the information necessary to authenticate against OnePassword API.
  19722. properties:
  19723. serviceAccountSecretRef:
  19724. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19725. properties:
  19726. key:
  19727. description: |-
  19728. A key in the referenced Secret.
  19729. Some instances of this field may be defaulted, in others it may be required.
  19730. maxLength: 253
  19731. minLength: 1
  19732. pattern: ^[-._a-zA-Z0-9]+$
  19733. type: string
  19734. name:
  19735. description: The name of the Secret resource being referred to.
  19736. maxLength: 253
  19737. minLength: 1
  19738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19739. type: string
  19740. namespace:
  19741. description: |-
  19742. The namespace of the Secret resource being referred to.
  19743. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19744. maxLength: 63
  19745. minLength: 1
  19746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19747. type: string
  19748. type: object
  19749. required:
  19750. - serviceAccountSecretRef
  19751. type: object
  19752. cache:
  19753. description: |-
  19754. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19755. When enabled, secrets are cached with the specified TTL.
  19756. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19757. If omitted, caching is disabled (default).
  19758. cache: {} is a valid option to set.
  19759. properties:
  19760. maxSize:
  19761. default: 100
  19762. description: |-
  19763. MaxSize is the maximum number of secrets to cache.
  19764. When the cache is full, least-recently-used entries are evicted.
  19765. minimum: 1
  19766. type: integer
  19767. ttl:
  19768. default: 5m
  19769. description: |-
  19770. TTL is the time-to-live for cached secrets.
  19771. Format: duration string (e.g., "5m", "1h", "30s")
  19772. type: string
  19773. type: object
  19774. integrationInfo:
  19775. description: |-
  19776. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19777. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19778. properties:
  19779. name:
  19780. default: 1Password SDK
  19781. description: Name defaults to "1Password SDK".
  19782. type: string
  19783. version:
  19784. default: v1.0.0
  19785. description: Version defaults to "v1.0.0".
  19786. type: string
  19787. type: object
  19788. vault:
  19789. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19790. type: string
  19791. required:
  19792. - auth
  19793. - vault
  19794. type: object
  19795. openBao:
  19796. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19797. properties:
  19798. auth:
  19799. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19800. properties:
  19801. appRole:
  19802. description: |-
  19803. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19804. with the role and secret stored in a Kubernetes Secret resource.
  19805. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19806. properties:
  19807. path:
  19808. default: approle
  19809. description: |-
  19810. Path where the App Role authentication backend is mounted
  19811. in OpenBao, e.g: "approle"
  19812. type: string
  19813. roleId:
  19814. description: |-
  19815. RoleID configured in the App Role authentication backend when setting
  19816. up the authentication backend in OpenBao.
  19817. minLength: 1
  19818. type: string
  19819. roleRef:
  19820. description: |-
  19821. Reference to a key in a Secret that contains the App Role ID used
  19822. to authenticate with OpenBao.
  19823. The `key` field must be specified and denotes which entry within the Secret
  19824. resource is used as the app role id.
  19825. properties:
  19826. key:
  19827. description: |-
  19828. A key in the referenced Secret.
  19829. Some instances of this field may be defaulted, in others it may be required.
  19830. maxLength: 253
  19831. minLength: 1
  19832. pattern: ^[-._a-zA-Z0-9]+$
  19833. type: string
  19834. name:
  19835. description: The name of the Secret resource being referred to.
  19836. maxLength: 253
  19837. minLength: 1
  19838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19839. type: string
  19840. namespace:
  19841. description: |-
  19842. The namespace of the Secret resource being referred to.
  19843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19844. maxLength: 63
  19845. minLength: 1
  19846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19847. type: string
  19848. type: object
  19849. secretRef:
  19850. description: |-
  19851. Reference to a key in a Secret that contains the App Role secret used
  19852. to authenticate with OpenBao.
  19853. The `key` field must be specified and denotes which entry within the Secret
  19854. resource is used as the app role secret.
  19855. properties:
  19856. key:
  19857. description: |-
  19858. A key in the referenced Secret.
  19859. Some instances of this field may be defaulted, in others it may be required.
  19860. maxLength: 253
  19861. minLength: 1
  19862. pattern: ^[-._a-zA-Z0-9]+$
  19863. type: string
  19864. name:
  19865. description: The name of the Secret resource being referred to.
  19866. maxLength: 253
  19867. minLength: 1
  19868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19869. type: string
  19870. namespace:
  19871. description: |-
  19872. The namespace of the Secret resource being referred to.
  19873. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19874. maxLength: 63
  19875. minLength: 1
  19876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19877. type: string
  19878. type: object
  19879. required:
  19880. - path
  19881. - secretRef
  19882. type: object
  19883. x-kubernetes-validations:
  19884. - message: exactly one of the fields in [roleId roleRef] must be set
  19885. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19886. namespace:
  19887. description: |-
  19888. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19889. than the namespace your secret is in. Namespaces is a set of features
  19890. within OpenBao that allows OpenBao environments to support secure
  19891. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19892. if set, or empty otherwise
  19893. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19894. type: string
  19895. tokenSecretRef:
  19896. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19897. properties:
  19898. key:
  19899. description: |-
  19900. A key in the referenced Secret.
  19901. Some instances of this field may be defaulted, in others it may be required.
  19902. maxLength: 253
  19903. minLength: 1
  19904. pattern: ^[-._a-zA-Z0-9]+$
  19905. type: string
  19906. name:
  19907. description: The name of the Secret resource being referred to.
  19908. maxLength: 253
  19909. minLength: 1
  19910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19911. type: string
  19912. namespace:
  19913. description: |-
  19914. The namespace of the Secret resource being referred to.
  19915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19916. maxLength: 63
  19917. minLength: 1
  19918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19919. type: string
  19920. type: object
  19921. userPass:
  19922. description: UserPass authenticates with OpenBao by passing a username/password pair
  19923. properties:
  19924. path:
  19925. default: userpass
  19926. description: |-
  19927. Path where the UserPassword authentication backend is mounted
  19928. in OpenBao, e.g: "userpass"
  19929. type: string
  19930. secretRef:
  19931. description: |-
  19932. SecretRef to a key in a Secret resource containing password for the user
  19933. used to authenticate with OpenBao using the [UserPass authentication
  19934. method]
  19935. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19936. properties:
  19937. key:
  19938. description: |-
  19939. A key in the referenced Secret.
  19940. Some instances of this field may be defaulted, in others it may be required.
  19941. maxLength: 253
  19942. minLength: 1
  19943. pattern: ^[-._a-zA-Z0-9]+$
  19944. type: string
  19945. name:
  19946. description: The name of the Secret resource being referred to.
  19947. maxLength: 253
  19948. minLength: 1
  19949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19950. type: string
  19951. namespace:
  19952. description: |-
  19953. The namespace of the Secret resource being referred to.
  19954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19955. maxLength: 63
  19956. minLength: 1
  19957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19958. type: string
  19959. type: object
  19960. username:
  19961. description: |-
  19962. Username is a username used to authenticate using the [UserPass
  19963. authentication method]
  19964. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19965. type: string
  19966. required:
  19967. - path
  19968. - username
  19969. type: object
  19970. type: object
  19971. x-kubernetes-validations:
  19972. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19973. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19974. caBundle:
  19975. description: |-
  19976. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19977. this and `caProvider` are not set the system root certificates are used
  19978. to validate the TLS connection.
  19979. format: byte
  19980. type: string
  19981. caProvider:
  19982. description: |-
  19983. The provider for the CA bundle to use to validate OpenBao server
  19984. certificate. If this and `caBundle` are not set the system root
  19985. certificates are used to validate the TLS connection.
  19986. properties:
  19987. key:
  19988. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19989. maxLength: 253
  19990. minLength: 1
  19991. pattern: ^[-._a-zA-Z0-9]+$
  19992. type: string
  19993. name:
  19994. description: The name of the object located at the provider type.
  19995. maxLength: 253
  19996. minLength: 1
  19997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19998. type: string
  19999. namespace:
  20000. description: |-
  20001. The namespace the Provider type is in.
  20002. Can only be defined when used in a ClusterSecretStore.
  20003. maxLength: 63
  20004. minLength: 1
  20005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20006. type: string
  20007. type:
  20008. description: The type of provider to use such as "Secret", or "ConfigMap".
  20009. enum:
  20010. - Secret
  20011. - ConfigMap
  20012. type: string
  20013. required:
  20014. - name
  20015. - type
  20016. type: object
  20017. namespace:
  20018. description: |-
  20019. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20020. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20021. e.g: "ns1".
  20022. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20023. type: string
  20024. path:
  20025. description: |-
  20026. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20027. "secret". The v2 KV secret engine version specific "/data" path suffix
  20028. for fetching secrets from OpenBao is optional and will be appended
  20029. if not present in specified path.
  20030. type: string
  20031. server:
  20032. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20033. type: string
  20034. version:
  20035. default: v2
  20036. description: |-
  20037. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20038. "v2". Version defaults to "v2".
  20039. enum:
  20040. - v1
  20041. - v2
  20042. type: string
  20043. required:
  20044. - server
  20045. type: object
  20046. x-kubernetes-validations:
  20047. - message: at most one of the fields in [caBundle caProvider] may be set
  20048. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20049. oracle:
  20050. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20051. properties:
  20052. auth:
  20053. description: |-
  20054. Auth configures how secret-manager authenticates with the Oracle Vault.
  20055. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20056. properties:
  20057. secretRef:
  20058. description: SecretRef to pass through sensitive information.
  20059. properties:
  20060. fingerprint:
  20061. description: Fingerprint is the fingerprint of the API private key.
  20062. properties:
  20063. key:
  20064. description: |-
  20065. A key in the referenced Secret.
  20066. Some instances of this field may be defaulted, in others it may be required.
  20067. maxLength: 253
  20068. minLength: 1
  20069. pattern: ^[-._a-zA-Z0-9]+$
  20070. type: string
  20071. name:
  20072. description: The name of the Secret resource being referred to.
  20073. maxLength: 253
  20074. minLength: 1
  20075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20076. type: string
  20077. namespace:
  20078. description: |-
  20079. The namespace of the Secret resource being referred to.
  20080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20081. maxLength: 63
  20082. minLength: 1
  20083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20084. type: string
  20085. type: object
  20086. privatekey:
  20087. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20088. properties:
  20089. key:
  20090. description: |-
  20091. A key in the referenced Secret.
  20092. Some instances of this field may be defaulted, in others it may be required.
  20093. maxLength: 253
  20094. minLength: 1
  20095. pattern: ^[-._a-zA-Z0-9]+$
  20096. type: string
  20097. name:
  20098. description: The name of the Secret resource being referred to.
  20099. maxLength: 253
  20100. minLength: 1
  20101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20102. type: string
  20103. namespace:
  20104. description: |-
  20105. The namespace of the Secret resource being referred to.
  20106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20107. maxLength: 63
  20108. minLength: 1
  20109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20110. type: string
  20111. type: object
  20112. required:
  20113. - fingerprint
  20114. - privatekey
  20115. type: object
  20116. tenancy:
  20117. description: Tenancy is the tenancy OCID where user is located.
  20118. type: string
  20119. user:
  20120. description: User is an access OCID specific to the account.
  20121. type: string
  20122. required:
  20123. - secretRef
  20124. - tenancy
  20125. - user
  20126. type: object
  20127. compartment:
  20128. description: |-
  20129. Compartment is the vault compartment OCID.
  20130. Required for PushSecret
  20131. type: string
  20132. encryptionKey:
  20133. description: |-
  20134. EncryptionKey is the OCID of the encryption key within the vault.
  20135. Required for PushSecret
  20136. type: string
  20137. principalType:
  20138. description: |-
  20139. The type of principal to use for authentication. If left blank, the Auth struct will
  20140. determine the principal type. This optional field must be specified if using
  20141. workload identity.
  20142. enum:
  20143. - ""
  20144. - UserPrincipal
  20145. - InstancePrincipal
  20146. - Workload
  20147. type: string
  20148. region:
  20149. description: Region is the region where vault is located.
  20150. type: string
  20151. serviceAccountRef:
  20152. description: |-
  20153. ServiceAccountRef specified the service account
  20154. that should be used when authenticating with WorkloadIdentity.
  20155. properties:
  20156. audiences:
  20157. description: |-
  20158. Audience specifies the `aud` claim for the service account token
  20159. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20160. then this audiences will be appended to the list
  20161. items:
  20162. type: string
  20163. type: array
  20164. name:
  20165. description: The name of the ServiceAccount resource being referred to.
  20166. maxLength: 253
  20167. minLength: 1
  20168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20169. type: string
  20170. namespace:
  20171. description: |-
  20172. Namespace of the resource being referred to.
  20173. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20174. maxLength: 63
  20175. minLength: 1
  20176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20177. type: string
  20178. required:
  20179. - name
  20180. type: object
  20181. vault:
  20182. description: Vault is the vault's OCID of the specific vault where secret is located.
  20183. type: string
  20184. required:
  20185. - region
  20186. - vault
  20187. type: object
  20188. ovh:
  20189. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20190. properties:
  20191. auth:
  20192. description: Authentication method (mtls or token).
  20193. properties:
  20194. mtls:
  20195. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20196. properties:
  20197. caBundle:
  20198. format: byte
  20199. type: string
  20200. caProvider:
  20201. description: |-
  20202. CAProvider provides a custom certificate authority for accessing the provider's store.
  20203. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20204. properties:
  20205. key:
  20206. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20207. maxLength: 253
  20208. minLength: 1
  20209. pattern: ^[-._a-zA-Z0-9]+$
  20210. type: string
  20211. name:
  20212. description: The name of the object located at the provider type.
  20213. maxLength: 253
  20214. minLength: 1
  20215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20216. type: string
  20217. namespace:
  20218. description: |-
  20219. The namespace the Provider type is in.
  20220. Can only be defined when used in a ClusterSecretStore.
  20221. maxLength: 63
  20222. minLength: 1
  20223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20224. type: string
  20225. type:
  20226. description: The type of provider to use such as "Secret", or "ConfigMap".
  20227. enum:
  20228. - Secret
  20229. - ConfigMap
  20230. type: string
  20231. required:
  20232. - name
  20233. - type
  20234. type: object
  20235. certSecretRef:
  20236. description: |-
  20237. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20238. In some instances, `key` is a required field.
  20239. properties:
  20240. key:
  20241. description: |-
  20242. A key in the referenced Secret.
  20243. Some instances of this field may be defaulted, in others it may be required.
  20244. maxLength: 253
  20245. minLength: 1
  20246. pattern: ^[-._a-zA-Z0-9]+$
  20247. type: string
  20248. name:
  20249. description: The name of the Secret resource being referred to.
  20250. maxLength: 253
  20251. minLength: 1
  20252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20253. type: string
  20254. namespace:
  20255. description: |-
  20256. The namespace of the Secret resource being referred to.
  20257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20258. maxLength: 63
  20259. minLength: 1
  20260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20261. type: string
  20262. type: object
  20263. keySecretRef:
  20264. description: |-
  20265. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20266. In some instances, `key` is a required field.
  20267. properties:
  20268. key:
  20269. description: |-
  20270. A key in the referenced Secret.
  20271. Some instances of this field may be defaulted, in others it may be required.
  20272. maxLength: 253
  20273. minLength: 1
  20274. pattern: ^[-._a-zA-Z0-9]+$
  20275. type: string
  20276. name:
  20277. description: The name of the Secret resource being referred to.
  20278. maxLength: 253
  20279. minLength: 1
  20280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20281. type: string
  20282. namespace:
  20283. description: |-
  20284. The namespace of the Secret resource being referred to.
  20285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20286. maxLength: 63
  20287. minLength: 1
  20288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20289. type: string
  20290. type: object
  20291. required:
  20292. - certSecretRef
  20293. - keySecretRef
  20294. type: object
  20295. token:
  20296. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20297. properties:
  20298. tokenSecretRef:
  20299. description: |-
  20300. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20301. In some instances, `key` is a required field.
  20302. properties:
  20303. key:
  20304. description: |-
  20305. A key in the referenced Secret.
  20306. Some instances of this field may be defaulted, in others it may be required.
  20307. maxLength: 253
  20308. minLength: 1
  20309. pattern: ^[-._a-zA-Z0-9]+$
  20310. type: string
  20311. name:
  20312. description: The name of the Secret resource being referred to.
  20313. maxLength: 253
  20314. minLength: 1
  20315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20316. type: string
  20317. namespace:
  20318. description: |-
  20319. The namespace of the Secret resource being referred to.
  20320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20321. maxLength: 63
  20322. minLength: 1
  20323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20324. type: string
  20325. type: object
  20326. required:
  20327. - tokenSecretRef
  20328. type: object
  20329. type: object
  20330. casRequired:
  20331. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20332. type: boolean
  20333. okmsTimeout:
  20334. default: 30
  20335. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20336. format: int32
  20337. minimum: 1
  20338. type: integer
  20339. okmsid:
  20340. description: specifies the OKMS ID.
  20341. type: string
  20342. server:
  20343. description: specifies the OKMS server endpoint.
  20344. type: string
  20345. required:
  20346. - auth
  20347. - okmsid
  20348. - server
  20349. type: object
  20350. passbolt:
  20351. description: |-
  20352. PassboltProvider provides access to Passbolt secrets manager.
  20353. See: https://www.passbolt.com.
  20354. properties:
  20355. auth:
  20356. description: Auth defines the information necessary to authenticate against Passbolt Server
  20357. properties:
  20358. passwordSecretRef:
  20359. description: |-
  20360. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20361. In some instances, `key` is a required field.
  20362. properties:
  20363. key:
  20364. description: |-
  20365. A key in the referenced Secret.
  20366. Some instances of this field may be defaulted, in others it may be required.
  20367. maxLength: 253
  20368. minLength: 1
  20369. pattern: ^[-._a-zA-Z0-9]+$
  20370. type: string
  20371. name:
  20372. description: The name of the Secret resource being referred to.
  20373. maxLength: 253
  20374. minLength: 1
  20375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20376. type: string
  20377. namespace:
  20378. description: |-
  20379. The namespace of the Secret resource being referred to.
  20380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20381. maxLength: 63
  20382. minLength: 1
  20383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20384. type: string
  20385. type: object
  20386. privateKeySecretRef:
  20387. description: |-
  20388. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20389. In some instances, `key` is a required field.
  20390. properties:
  20391. key:
  20392. description: |-
  20393. A key in the referenced Secret.
  20394. Some instances of this field may be defaulted, in others it may be required.
  20395. maxLength: 253
  20396. minLength: 1
  20397. pattern: ^[-._a-zA-Z0-9]+$
  20398. type: string
  20399. name:
  20400. description: The name of the Secret resource being referred to.
  20401. maxLength: 253
  20402. minLength: 1
  20403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20404. type: string
  20405. namespace:
  20406. description: |-
  20407. The namespace of the Secret resource being referred to.
  20408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20409. maxLength: 63
  20410. minLength: 1
  20411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20412. type: string
  20413. type: object
  20414. required:
  20415. - passwordSecretRef
  20416. - privateKeySecretRef
  20417. type: object
  20418. caBundle:
  20419. description: |-
  20420. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20421. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20422. are used to validate the TLS connection.
  20423. format: byte
  20424. type: string
  20425. caProvider:
  20426. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20427. properties:
  20428. key:
  20429. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20430. maxLength: 253
  20431. minLength: 1
  20432. pattern: ^[-._a-zA-Z0-9]+$
  20433. type: string
  20434. name:
  20435. description: The name of the object located at the provider type.
  20436. maxLength: 253
  20437. minLength: 1
  20438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20439. type: string
  20440. namespace:
  20441. description: |-
  20442. The namespace the Provider type is in.
  20443. Can only be defined when used in a ClusterSecretStore.
  20444. maxLength: 63
  20445. minLength: 1
  20446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20447. type: string
  20448. type:
  20449. description: The type of provider to use such as "Secret", or "ConfigMap".
  20450. enum:
  20451. - Secret
  20452. - ConfigMap
  20453. type: string
  20454. required:
  20455. - name
  20456. - type
  20457. type: object
  20458. host:
  20459. description: Host defines the Passbolt Server to connect to
  20460. type: string
  20461. required:
  20462. - auth
  20463. - host
  20464. type: object
  20465. passworddepot:
  20466. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20467. properties:
  20468. auth:
  20469. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20470. properties:
  20471. secretRef:
  20472. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20473. properties:
  20474. credentials:
  20475. description: Username / Password is used for authentication.
  20476. properties:
  20477. key:
  20478. description: |-
  20479. A key in the referenced Secret.
  20480. Some instances of this field may be defaulted, in others it may be required.
  20481. maxLength: 253
  20482. minLength: 1
  20483. pattern: ^[-._a-zA-Z0-9]+$
  20484. type: string
  20485. name:
  20486. description: The name of the Secret resource being referred to.
  20487. maxLength: 253
  20488. minLength: 1
  20489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20490. type: string
  20491. namespace:
  20492. description: |-
  20493. The namespace of the Secret resource being referred to.
  20494. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20495. maxLength: 63
  20496. minLength: 1
  20497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20498. type: string
  20499. type: object
  20500. type: object
  20501. required:
  20502. - secretRef
  20503. type: object
  20504. database:
  20505. description: Database to use as source
  20506. type: string
  20507. host:
  20508. description: URL configures the Password Depot instance URL.
  20509. type: string
  20510. required:
  20511. - auth
  20512. - database
  20513. - host
  20514. type: object
  20515. previder:
  20516. description: Previder configures this store to sync secrets using the Previder provider
  20517. properties:
  20518. auth:
  20519. description: PreviderAuth contains a secretRef for credentials.
  20520. properties:
  20521. secretRef:
  20522. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20523. properties:
  20524. accessToken:
  20525. description: The AccessToken is used for authentication
  20526. properties:
  20527. key:
  20528. description: |-
  20529. A key in the referenced Secret.
  20530. Some instances of this field may be defaulted, in others it may be required.
  20531. maxLength: 253
  20532. minLength: 1
  20533. pattern: ^[-._a-zA-Z0-9]+$
  20534. type: string
  20535. name:
  20536. description: The name of the Secret resource being referred to.
  20537. maxLength: 253
  20538. minLength: 1
  20539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20540. type: string
  20541. namespace:
  20542. description: |-
  20543. The namespace of the Secret resource being referred to.
  20544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20545. maxLength: 63
  20546. minLength: 1
  20547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20548. type: string
  20549. type: object
  20550. required:
  20551. - accessToken
  20552. type: object
  20553. type: object
  20554. baseUri:
  20555. type: string
  20556. required:
  20557. - auth
  20558. type: object
  20559. pulumi:
  20560. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20561. properties:
  20562. accessToken:
  20563. description: |-
  20564. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20565. Deprecated: Use auth.accessToken instead.
  20566. properties:
  20567. secretRef:
  20568. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20569. properties:
  20570. key:
  20571. description: |-
  20572. A key in the referenced Secret.
  20573. Some instances of this field may be defaulted, in others it may be required.
  20574. maxLength: 253
  20575. minLength: 1
  20576. pattern: ^[-._a-zA-Z0-9]+$
  20577. type: string
  20578. name:
  20579. description: The name of the Secret resource being referred to.
  20580. maxLength: 253
  20581. minLength: 1
  20582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20583. type: string
  20584. namespace:
  20585. description: |-
  20586. The namespace of the Secret resource being referred to.
  20587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20588. maxLength: 63
  20589. minLength: 1
  20590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20591. type: string
  20592. type: object
  20593. type: object
  20594. apiUrl:
  20595. default: https://api.pulumi.com/api/esc
  20596. description: APIURL is the URL of the Pulumi API.
  20597. type: string
  20598. auth:
  20599. description: |-
  20600. Auth configures how the Operator authenticates with the Pulumi API.
  20601. Either auth or the deprecated accessToken field must be specified.
  20602. properties:
  20603. accessToken:
  20604. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20605. properties:
  20606. secretRef:
  20607. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20608. properties:
  20609. key:
  20610. description: |-
  20611. A key in the referenced Secret.
  20612. Some instances of this field may be defaulted, in others it may be required.
  20613. maxLength: 253
  20614. minLength: 1
  20615. pattern: ^[-._a-zA-Z0-9]+$
  20616. type: string
  20617. name:
  20618. description: The name of the Secret resource being referred to.
  20619. maxLength: 253
  20620. minLength: 1
  20621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20622. type: string
  20623. namespace:
  20624. description: |-
  20625. The namespace of the Secret resource being referred to.
  20626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20627. maxLength: 63
  20628. minLength: 1
  20629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20630. type: string
  20631. type: object
  20632. type: object
  20633. oidcConfig:
  20634. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20635. properties:
  20636. expirationSeconds:
  20637. default: 600
  20638. description: |-
  20639. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20640. Defaults to 10 minutes.
  20641. format: int64
  20642. minimum: 600
  20643. type: integer
  20644. organization:
  20645. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20646. type: string
  20647. serviceAccountRef:
  20648. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20649. properties:
  20650. audiences:
  20651. description: |-
  20652. Audience specifies the `aud` claim for the service account token
  20653. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20654. then this audiences will be appended to the list
  20655. items:
  20656. type: string
  20657. type: array
  20658. name:
  20659. description: The name of the ServiceAccount resource being referred to.
  20660. maxLength: 253
  20661. minLength: 1
  20662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20663. type: string
  20664. namespace:
  20665. description: |-
  20666. Namespace of the resource being referred to.
  20667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20668. maxLength: 63
  20669. minLength: 1
  20670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20671. type: string
  20672. required:
  20673. - name
  20674. type: object
  20675. required:
  20676. - organization
  20677. - serviceAccountRef
  20678. type: object
  20679. type: object
  20680. x-kubernetes-validations:
  20681. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20682. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20683. environment:
  20684. description: |-
  20685. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20686. dynamically retrieved values from supported providers including all major clouds,
  20687. and other Pulumi ESC environments.
  20688. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20689. type: string
  20690. organization:
  20691. description: |-
  20692. Organization are a space to collaborate on shared projects and stacks.
  20693. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20694. type: string
  20695. project:
  20696. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20697. type: string
  20698. required:
  20699. - environment
  20700. - organization
  20701. - project
  20702. type: object
  20703. x-kubernetes-validations:
  20704. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20705. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20706. scaleway:
  20707. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20708. properties:
  20709. accessKey:
  20710. description: AccessKey is the non-secret part of the api key.
  20711. properties:
  20712. secretRef:
  20713. description: SecretRef references a key in a secret that will be used as value.
  20714. properties:
  20715. key:
  20716. description: |-
  20717. A key in the referenced Secret.
  20718. Some instances of this field may be defaulted, in others it may be required.
  20719. maxLength: 253
  20720. minLength: 1
  20721. pattern: ^[-._a-zA-Z0-9]+$
  20722. type: string
  20723. name:
  20724. description: The name of the Secret resource being referred to.
  20725. maxLength: 253
  20726. minLength: 1
  20727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20728. type: string
  20729. namespace:
  20730. description: |-
  20731. The namespace of the Secret resource being referred to.
  20732. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20733. maxLength: 63
  20734. minLength: 1
  20735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20736. type: string
  20737. type: object
  20738. value:
  20739. description: Value can be specified directly to set a value without using a secret.
  20740. type: string
  20741. type: object
  20742. apiUrl:
  20743. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20744. type: string
  20745. projectId:
  20746. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20747. type: string
  20748. region:
  20749. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20750. type: string
  20751. secretKey:
  20752. description: SecretKey is the non-secret part of the api key.
  20753. properties:
  20754. secretRef:
  20755. description: SecretRef references a key in a secret that will be used as value.
  20756. properties:
  20757. key:
  20758. description: |-
  20759. A key in the referenced Secret.
  20760. Some instances of this field may be defaulted, in others it may be required.
  20761. maxLength: 253
  20762. minLength: 1
  20763. pattern: ^[-._a-zA-Z0-9]+$
  20764. type: string
  20765. name:
  20766. description: The name of the Secret resource being referred to.
  20767. maxLength: 253
  20768. minLength: 1
  20769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20770. type: string
  20771. namespace:
  20772. description: |-
  20773. The namespace of the Secret resource being referred to.
  20774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20775. maxLength: 63
  20776. minLength: 1
  20777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20778. type: string
  20779. type: object
  20780. value:
  20781. description: Value can be specified directly to set a value without using a secret.
  20782. type: string
  20783. type: object
  20784. required:
  20785. - accessKey
  20786. - projectId
  20787. - region
  20788. - secretKey
  20789. type: object
  20790. secretserver:
  20791. description: |-
  20792. SecretServer configures this store to sync secrets using SecretServer provider
  20793. https://docs.delinea.com/online-help/secret-server/start.htm
  20794. properties:
  20795. caBundle:
  20796. description: |-
  20797. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20798. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20799. are used to validate the TLS connection.
  20800. format: byte
  20801. type: string
  20802. caProvider:
  20803. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20804. properties:
  20805. key:
  20806. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20807. maxLength: 253
  20808. minLength: 1
  20809. pattern: ^[-._a-zA-Z0-9]+$
  20810. type: string
  20811. name:
  20812. description: The name of the object located at the provider type.
  20813. maxLength: 253
  20814. minLength: 1
  20815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20816. type: string
  20817. namespace:
  20818. description: |-
  20819. The namespace the Provider type is in.
  20820. Can only be defined when used in a ClusterSecretStore.
  20821. maxLength: 63
  20822. minLength: 1
  20823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20824. type: string
  20825. type:
  20826. description: The type of provider to use such as "Secret", or "ConfigMap".
  20827. enum:
  20828. - Secret
  20829. - ConfigMap
  20830. type: string
  20831. required:
  20832. - name
  20833. - type
  20834. type: object
  20835. domain:
  20836. description: Domain is the secret server domain.
  20837. type: string
  20838. password:
  20839. description: |-
  20840. Password is the secret server account password.
  20841. Required unless Token is set.
  20842. properties:
  20843. secretRef:
  20844. description: SecretRef references a key in a secret that will be used as value.
  20845. properties:
  20846. key:
  20847. description: |-
  20848. A key in the referenced Secret.
  20849. Some instances of this field may be defaulted, in others it may be required.
  20850. maxLength: 253
  20851. minLength: 1
  20852. pattern: ^[-._a-zA-Z0-9]+$
  20853. type: string
  20854. name:
  20855. description: The name of the Secret resource being referred to.
  20856. maxLength: 253
  20857. minLength: 1
  20858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20859. type: string
  20860. namespace:
  20861. description: |-
  20862. The namespace of the Secret resource being referred to.
  20863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20864. maxLength: 63
  20865. minLength: 1
  20866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20867. type: string
  20868. type: object
  20869. value:
  20870. description: Value can be specified directly to set a value without using a secret.
  20871. minLength: 1
  20872. type: string
  20873. type: object
  20874. x-kubernetes-validations:
  20875. - message: exactly one of value or secretRef must be set
  20876. rule: has(self.value) != has(self.secretRef)
  20877. serverURL:
  20878. description: |-
  20879. ServerURL
  20880. URL to your secret server installation
  20881. type: string
  20882. token:
  20883. description: |-
  20884. Token is an access token used to authenticate to the secret server,
  20885. as an alternative to Username and Password. When set, Username and
  20886. Password are not required and are ignored.
  20887. properties:
  20888. secretRef:
  20889. description: SecretRef references a key in a secret that will be used as value.
  20890. properties:
  20891. key:
  20892. description: |-
  20893. A key in the referenced Secret.
  20894. Some instances of this field may be defaulted, in others it may be required.
  20895. maxLength: 253
  20896. minLength: 1
  20897. pattern: ^[-._a-zA-Z0-9]+$
  20898. type: string
  20899. name:
  20900. description: The name of the Secret resource being referred to.
  20901. maxLength: 253
  20902. minLength: 1
  20903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20904. type: string
  20905. namespace:
  20906. description: |-
  20907. The namespace of the Secret resource being referred to.
  20908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20909. maxLength: 63
  20910. minLength: 1
  20911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20912. type: string
  20913. type: object
  20914. value:
  20915. description: Value can be specified directly to set a value without using a secret.
  20916. minLength: 1
  20917. type: string
  20918. type: object
  20919. x-kubernetes-validations:
  20920. - message: exactly one of value or secretRef must be set
  20921. rule: has(self.value) != has(self.secretRef)
  20922. username:
  20923. description: |-
  20924. Username is the secret server account username.
  20925. Required unless Token is set.
  20926. properties:
  20927. secretRef:
  20928. description: SecretRef references a key in a secret that will be used as value.
  20929. properties:
  20930. key:
  20931. description: |-
  20932. A key in the referenced Secret.
  20933. Some instances of this field may be defaulted, in others it may be required.
  20934. maxLength: 253
  20935. minLength: 1
  20936. pattern: ^[-._a-zA-Z0-9]+$
  20937. type: string
  20938. name:
  20939. description: The name of the Secret resource being referred to.
  20940. maxLength: 253
  20941. minLength: 1
  20942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20943. type: string
  20944. namespace:
  20945. description: |-
  20946. The namespace of the Secret resource being referred to.
  20947. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20948. maxLength: 63
  20949. minLength: 1
  20950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20951. type: string
  20952. type: object
  20953. value:
  20954. description: Value can be specified directly to set a value without using a secret.
  20955. minLength: 1
  20956. type: string
  20957. type: object
  20958. x-kubernetes-validations:
  20959. - message: exactly one of value or secretRef must be set
  20960. rule: has(self.value) != has(self.secretRef)
  20961. required:
  20962. - serverURL
  20963. type: object
  20964. x-kubernetes-validations:
  20965. - message: either token, or both username and password, must be set
  20966. rule: has(self.token) || (has(self.username) && has(self.password))
  20967. senhasegura:
  20968. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20969. properties:
  20970. auth:
  20971. description: Auth defines parameters to authenticate in senhasegura
  20972. properties:
  20973. clientId:
  20974. type: string
  20975. clientSecretSecretRef:
  20976. description: |-
  20977. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20978. In some instances, `key` is a required field.
  20979. properties:
  20980. key:
  20981. description: |-
  20982. A key in the referenced Secret.
  20983. Some instances of this field may be defaulted, in others it may be required.
  20984. maxLength: 253
  20985. minLength: 1
  20986. pattern: ^[-._a-zA-Z0-9]+$
  20987. type: string
  20988. name:
  20989. description: The name of the Secret resource being referred to.
  20990. maxLength: 253
  20991. minLength: 1
  20992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20993. type: string
  20994. namespace:
  20995. description: |-
  20996. The namespace of the Secret resource being referred to.
  20997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20998. maxLength: 63
  20999. minLength: 1
  21000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21001. type: string
  21002. type: object
  21003. required:
  21004. - clientId
  21005. - clientSecretSecretRef
  21006. type: object
  21007. ignoreSslCertificate:
  21008. default: false
  21009. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21010. type: boolean
  21011. module:
  21012. description: Module defines which senhasegura module should be used to get secrets
  21013. type: string
  21014. url:
  21015. description: URL of senhasegura
  21016. type: string
  21017. required:
  21018. - auth
  21019. - module
  21020. - url
  21021. type: object
  21022. vault:
  21023. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21024. properties:
  21025. auth:
  21026. description: Auth configures how secret-manager authenticates with the Vault server.
  21027. properties:
  21028. appRole:
  21029. description: |-
  21030. AppRole authenticates with Vault using the App Role auth mechanism,
  21031. with the role and secret stored in a Kubernetes Secret resource.
  21032. properties:
  21033. path:
  21034. default: approle
  21035. description: |-
  21036. Path where the App Role authentication backend is mounted
  21037. in Vault, e.g: "approle"
  21038. type: string
  21039. roleId:
  21040. description: |-
  21041. RoleID configured in the App Role authentication backend when setting
  21042. up the authentication backend in Vault.
  21043. type: string
  21044. roleRef:
  21045. description: |-
  21046. Reference to a key in a Secret that contains the App Role ID used
  21047. to authenticate with Vault.
  21048. The `key` field must be specified and denotes which entry within the Secret
  21049. resource is used as the app role id.
  21050. properties:
  21051. key:
  21052. description: |-
  21053. A key in the referenced Secret.
  21054. Some instances of this field may be defaulted, in others it may be required.
  21055. maxLength: 253
  21056. minLength: 1
  21057. pattern: ^[-._a-zA-Z0-9]+$
  21058. type: string
  21059. name:
  21060. description: The name of the Secret resource being referred to.
  21061. maxLength: 253
  21062. minLength: 1
  21063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21064. type: string
  21065. namespace:
  21066. description: |-
  21067. The namespace of the Secret resource being referred to.
  21068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21069. maxLength: 63
  21070. minLength: 1
  21071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21072. type: string
  21073. type: object
  21074. secretRef:
  21075. description: |-
  21076. Reference to a key in a Secret that contains the App Role secret used
  21077. to authenticate with Vault.
  21078. The `key` field must be specified and denotes which entry within the Secret
  21079. resource is used as the app role secret.
  21080. properties:
  21081. key:
  21082. description: |-
  21083. A key in the referenced Secret.
  21084. Some instances of this field may be defaulted, in others it may be required.
  21085. maxLength: 253
  21086. minLength: 1
  21087. pattern: ^[-._a-zA-Z0-9]+$
  21088. type: string
  21089. name:
  21090. description: The name of the Secret resource being referred to.
  21091. maxLength: 253
  21092. minLength: 1
  21093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21094. type: string
  21095. namespace:
  21096. description: |-
  21097. The namespace of the Secret resource being referred to.
  21098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21099. maxLength: 63
  21100. minLength: 1
  21101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21102. type: string
  21103. type: object
  21104. required:
  21105. - path
  21106. - secretRef
  21107. type: object
  21108. cert:
  21109. description: |-
  21110. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21111. Cert authentication method
  21112. properties:
  21113. clientCert:
  21114. description: |-
  21115. ClientCert is a certificate to authenticate using the Cert Vault
  21116. authentication method
  21117. properties:
  21118. key:
  21119. description: |-
  21120. A key in the referenced Secret.
  21121. Some instances of this field may be defaulted, in others it may be required.
  21122. maxLength: 253
  21123. minLength: 1
  21124. pattern: ^[-._a-zA-Z0-9]+$
  21125. type: string
  21126. name:
  21127. description: The name of the Secret resource being referred to.
  21128. maxLength: 253
  21129. minLength: 1
  21130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21131. type: string
  21132. namespace:
  21133. description: |-
  21134. The namespace of the Secret resource being referred to.
  21135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21136. maxLength: 63
  21137. minLength: 1
  21138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21139. type: string
  21140. type: object
  21141. path:
  21142. default: cert
  21143. description: |-
  21144. Path where the Certificate authentication backend is mounted
  21145. in Vault, e.g: "cert"
  21146. type: string
  21147. secretRef:
  21148. description: |-
  21149. SecretRef to a key in a Secret resource containing client private key to
  21150. authenticate with Vault using the Cert authentication method
  21151. properties:
  21152. key:
  21153. description: |-
  21154. A key in the referenced Secret.
  21155. Some instances of this field may be defaulted, in others it may be required.
  21156. maxLength: 253
  21157. minLength: 1
  21158. pattern: ^[-._a-zA-Z0-9]+$
  21159. type: string
  21160. name:
  21161. description: The name of the Secret resource being referred to.
  21162. maxLength: 253
  21163. minLength: 1
  21164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21165. type: string
  21166. namespace:
  21167. description: |-
  21168. The namespace of the Secret resource being referred to.
  21169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21170. maxLength: 63
  21171. minLength: 1
  21172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21173. type: string
  21174. type: object
  21175. vaultRole:
  21176. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21177. type: string
  21178. type: object
  21179. gcp:
  21180. description: |-
  21181. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21182. GCP authentication method
  21183. properties:
  21184. location:
  21185. description: Location optionally defines a location/region for the secret
  21186. type: string
  21187. path:
  21188. default: gcp
  21189. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21190. type: string
  21191. projectID:
  21192. description: Project ID of the Google Cloud Platform project
  21193. type: string
  21194. role:
  21195. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21196. type: string
  21197. secretRef:
  21198. description: Specify credentials in a Secret object
  21199. properties:
  21200. secretAccessKeySecretRef:
  21201. description: The SecretAccessKey is used for authentication
  21202. properties:
  21203. key:
  21204. description: |-
  21205. A key in the referenced Secret.
  21206. Some instances of this field may be defaulted, in others it may be required.
  21207. maxLength: 253
  21208. minLength: 1
  21209. pattern: ^[-._a-zA-Z0-9]+$
  21210. type: string
  21211. name:
  21212. description: The name of the Secret resource being referred to.
  21213. maxLength: 253
  21214. minLength: 1
  21215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21216. type: string
  21217. namespace:
  21218. description: |-
  21219. The namespace of the Secret resource being referred to.
  21220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21221. maxLength: 63
  21222. minLength: 1
  21223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21224. type: string
  21225. type: object
  21226. type: object
  21227. serviceAccountRef:
  21228. description: ServiceAccountRef to a service account for impersonation
  21229. properties:
  21230. audiences:
  21231. description: |-
  21232. Audience specifies the `aud` claim for the service account token
  21233. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21234. then this audiences will be appended to the list
  21235. items:
  21236. type: string
  21237. type: array
  21238. name:
  21239. description: The name of the ServiceAccount resource being referred to.
  21240. maxLength: 253
  21241. minLength: 1
  21242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21243. type: string
  21244. namespace:
  21245. description: |-
  21246. Namespace of the resource being referred to.
  21247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21248. maxLength: 63
  21249. minLength: 1
  21250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21251. type: string
  21252. required:
  21253. - name
  21254. type: object
  21255. workloadIdentity:
  21256. description: Specify a service account with Workload Identity
  21257. properties:
  21258. clusterLocation:
  21259. description: |-
  21260. ClusterLocation is the location of the cluster
  21261. If not specified, it fetches information from the metadata server
  21262. type: string
  21263. clusterName:
  21264. description: |-
  21265. ClusterName is the name of the cluster
  21266. If not specified, it fetches information from the metadata server
  21267. type: string
  21268. clusterProjectID:
  21269. description: |-
  21270. ClusterProjectID is the project ID of the cluster
  21271. If not specified, it fetches information from the metadata server
  21272. type: string
  21273. serviceAccountRef:
  21274. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21275. properties:
  21276. audiences:
  21277. description: |-
  21278. Audience specifies the `aud` claim for the service account token
  21279. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21280. then this audiences will be appended to the list
  21281. items:
  21282. type: string
  21283. type: array
  21284. name:
  21285. description: The name of the ServiceAccount resource being referred to.
  21286. maxLength: 253
  21287. minLength: 1
  21288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21289. type: string
  21290. namespace:
  21291. description: |-
  21292. Namespace of the resource being referred to.
  21293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21294. maxLength: 63
  21295. minLength: 1
  21296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21297. type: string
  21298. required:
  21299. - name
  21300. type: object
  21301. required:
  21302. - serviceAccountRef
  21303. type: object
  21304. required:
  21305. - role
  21306. type: object
  21307. iam:
  21308. description: |-
  21309. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21310. AWS IAM authentication method
  21311. properties:
  21312. externalID:
  21313. description: AWS External ID set on assumed IAM roles
  21314. type: string
  21315. jwt:
  21316. description: Specify a service account with IRSA enabled
  21317. properties:
  21318. serviceAccountRef:
  21319. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21320. properties:
  21321. audiences:
  21322. description: |-
  21323. Audience specifies the `aud` claim for the service account token
  21324. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21325. then this audiences will be appended to the list
  21326. items:
  21327. type: string
  21328. type: array
  21329. name:
  21330. description: The name of the ServiceAccount resource being referred to.
  21331. maxLength: 253
  21332. minLength: 1
  21333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21334. type: string
  21335. namespace:
  21336. description: |-
  21337. Namespace of the resource being referred to.
  21338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21339. maxLength: 63
  21340. minLength: 1
  21341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21342. type: string
  21343. required:
  21344. - name
  21345. type: object
  21346. type: object
  21347. path:
  21348. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21349. type: string
  21350. region:
  21351. description: AWS region
  21352. type: string
  21353. role:
  21354. description: This is the AWS role to be assumed before talking to vault
  21355. type: string
  21356. secretRef:
  21357. description: Specify credentials in a Secret object
  21358. properties:
  21359. accessKeyIDSecretRef:
  21360. description: The AccessKeyID is used for authentication
  21361. properties:
  21362. key:
  21363. description: |-
  21364. A key in the referenced Secret.
  21365. Some instances of this field may be defaulted, in others it may be required.
  21366. maxLength: 253
  21367. minLength: 1
  21368. pattern: ^[-._a-zA-Z0-9]+$
  21369. type: string
  21370. name:
  21371. description: The name of the Secret resource being referred to.
  21372. maxLength: 253
  21373. minLength: 1
  21374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21375. type: string
  21376. namespace:
  21377. description: |-
  21378. The namespace of the Secret resource being referred to.
  21379. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21380. maxLength: 63
  21381. minLength: 1
  21382. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21383. type: string
  21384. type: object
  21385. secretAccessKeySecretRef:
  21386. description: The SecretAccessKey is used for authentication
  21387. properties:
  21388. key:
  21389. description: |-
  21390. A key in the referenced Secret.
  21391. Some instances of this field may be defaulted, in others it may be required.
  21392. maxLength: 253
  21393. minLength: 1
  21394. pattern: ^[-._a-zA-Z0-9]+$
  21395. type: string
  21396. name:
  21397. description: The name of the Secret resource being referred to.
  21398. maxLength: 253
  21399. minLength: 1
  21400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21401. type: string
  21402. namespace:
  21403. description: |-
  21404. The namespace of the Secret resource being referred to.
  21405. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21406. maxLength: 63
  21407. minLength: 1
  21408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21409. type: string
  21410. type: object
  21411. sessionTokenSecretRef:
  21412. description: |-
  21413. The SessionToken used for authentication
  21414. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21415. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21416. properties:
  21417. key:
  21418. description: |-
  21419. A key in the referenced Secret.
  21420. Some instances of this field may be defaulted, in others it may be required.
  21421. maxLength: 253
  21422. minLength: 1
  21423. pattern: ^[-._a-zA-Z0-9]+$
  21424. type: string
  21425. name:
  21426. description: The name of the Secret resource being referred to.
  21427. maxLength: 253
  21428. minLength: 1
  21429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21430. type: string
  21431. namespace:
  21432. description: |-
  21433. The namespace of the Secret resource being referred to.
  21434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21435. maxLength: 63
  21436. minLength: 1
  21437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21438. type: string
  21439. type: object
  21440. type: object
  21441. vaultAwsIamServerID:
  21442. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21443. type: string
  21444. vaultRole:
  21445. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21446. type: string
  21447. required:
  21448. - vaultRole
  21449. type: object
  21450. jwt:
  21451. description: |-
  21452. Jwt authenticates with Vault by passing role and JWT token using the
  21453. JWT/OIDC authentication method
  21454. properties:
  21455. kubernetesServiceAccountToken:
  21456. description: |-
  21457. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21458. a token for with the `TokenRequest` API.
  21459. properties:
  21460. audiences:
  21461. description: |-
  21462. Optional audiences field that will be used to request a temporary Kubernetes service
  21463. account token for the service account referenced by `serviceAccountRef`.
  21464. Defaults to a single audience `vault` it not specified.
  21465. Deprecated: use serviceAccountRef.Audiences instead
  21466. items:
  21467. type: string
  21468. type: array
  21469. expirationSeconds:
  21470. description: |-
  21471. Optional expiration time in seconds that will be used to request a temporary
  21472. Kubernetes service account token for the service account referenced by
  21473. `serviceAccountRef`.
  21474. Deprecated: this will be removed in the future.
  21475. Defaults to 10 minutes.
  21476. format: int64
  21477. type: integer
  21478. serviceAccountRef:
  21479. description: Service account field containing the name of a kubernetes ServiceAccount.
  21480. properties:
  21481. audiences:
  21482. description: |-
  21483. Audience specifies the `aud` claim for the service account token
  21484. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21485. then this audiences will be appended to the list
  21486. items:
  21487. type: string
  21488. type: array
  21489. name:
  21490. description: The name of the ServiceAccount resource being referred to.
  21491. maxLength: 253
  21492. minLength: 1
  21493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21494. type: string
  21495. namespace:
  21496. description: |-
  21497. Namespace of the resource being referred to.
  21498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21499. maxLength: 63
  21500. minLength: 1
  21501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21502. type: string
  21503. required:
  21504. - name
  21505. type: object
  21506. required:
  21507. - serviceAccountRef
  21508. type: object
  21509. path:
  21510. default: jwt
  21511. description: |-
  21512. Path where the JWT authentication backend is mounted
  21513. in Vault, e.g: "jwt"
  21514. type: string
  21515. role:
  21516. description: |-
  21517. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21518. authentication method
  21519. type: string
  21520. secretRef:
  21521. description: |-
  21522. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21523. authenticate with Vault using the JWT/OIDC authentication method.
  21524. properties:
  21525. key:
  21526. description: |-
  21527. A key in the referenced Secret.
  21528. Some instances of this field may be defaulted, in others it may be required.
  21529. maxLength: 253
  21530. minLength: 1
  21531. pattern: ^[-._a-zA-Z0-9]+$
  21532. type: string
  21533. name:
  21534. description: The name of the Secret resource being referred to.
  21535. maxLength: 253
  21536. minLength: 1
  21537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21538. type: string
  21539. namespace:
  21540. description: |-
  21541. The namespace of the Secret resource being referred to.
  21542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21543. maxLength: 63
  21544. minLength: 1
  21545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21546. type: string
  21547. type: object
  21548. required:
  21549. - path
  21550. type: object
  21551. kubernetes:
  21552. description: |-
  21553. Kubernetes authenticates with Vault by passing the ServiceAccount
  21554. token stored in the named Secret resource to the Vault server.
  21555. properties:
  21556. mountPath:
  21557. default: kubernetes
  21558. description: |-
  21559. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21560. "kubernetes"
  21561. type: string
  21562. role:
  21563. description: |-
  21564. A required field containing the Vault Role to assume. A Role binds a
  21565. Kubernetes ServiceAccount with a set of Vault policies.
  21566. type: string
  21567. secretRef:
  21568. description: |-
  21569. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21570. for authenticating with Vault. If a name is specified without a key,
  21571. `token` is the default. If one is not specified, the one bound to
  21572. the controller will be used.
  21573. properties:
  21574. key:
  21575. description: |-
  21576. A key in the referenced Secret.
  21577. Some instances of this field may be defaulted, in others it may be required.
  21578. maxLength: 253
  21579. minLength: 1
  21580. pattern: ^[-._a-zA-Z0-9]+$
  21581. type: string
  21582. name:
  21583. description: The name of the Secret resource being referred to.
  21584. maxLength: 253
  21585. minLength: 1
  21586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21587. type: string
  21588. namespace:
  21589. description: |-
  21590. The namespace of the Secret resource being referred to.
  21591. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21592. maxLength: 63
  21593. minLength: 1
  21594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21595. type: string
  21596. type: object
  21597. serviceAccountRef:
  21598. description: |-
  21599. Optional service account field containing the name of a kubernetes ServiceAccount.
  21600. If the service account is specified, the service account secret token JWT will be used
  21601. for authenticating with Vault. If the service account selector is not supplied,
  21602. the secretRef will be used instead.
  21603. properties:
  21604. audiences:
  21605. description: |-
  21606. Audience specifies the `aud` claim for the service account token
  21607. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21608. then this audiences will be appended to the list
  21609. items:
  21610. type: string
  21611. type: array
  21612. name:
  21613. description: The name of the ServiceAccount resource being referred to.
  21614. maxLength: 253
  21615. minLength: 1
  21616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21617. type: string
  21618. namespace:
  21619. description: |-
  21620. Namespace of the resource being referred to.
  21621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21622. maxLength: 63
  21623. minLength: 1
  21624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21625. type: string
  21626. required:
  21627. - name
  21628. type: object
  21629. required:
  21630. - mountPath
  21631. - role
  21632. type: object
  21633. ldap:
  21634. description: |-
  21635. Ldap authenticates with Vault by passing username/password pair using
  21636. the LDAP authentication method
  21637. properties:
  21638. path:
  21639. default: ldap
  21640. description: |-
  21641. Path where the LDAP authentication backend is mounted
  21642. in Vault, e.g: "ldap"
  21643. type: string
  21644. secretRef:
  21645. description: |-
  21646. SecretRef to a key in a Secret resource containing password for the LDAP
  21647. user used to authenticate with Vault using the LDAP authentication
  21648. method
  21649. properties:
  21650. key:
  21651. description: |-
  21652. A key in the referenced Secret.
  21653. Some instances of this field may be defaulted, in others it may be required.
  21654. maxLength: 253
  21655. minLength: 1
  21656. pattern: ^[-._a-zA-Z0-9]+$
  21657. type: string
  21658. name:
  21659. description: The name of the Secret resource being referred to.
  21660. maxLength: 253
  21661. minLength: 1
  21662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21663. type: string
  21664. namespace:
  21665. description: |-
  21666. The namespace of the Secret resource being referred to.
  21667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21668. maxLength: 63
  21669. minLength: 1
  21670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21671. type: string
  21672. type: object
  21673. username:
  21674. description: |-
  21675. Username is an LDAP username used to authenticate using the LDAP Vault
  21676. authentication method
  21677. type: string
  21678. required:
  21679. - path
  21680. - username
  21681. type: object
  21682. namespace:
  21683. description: |-
  21684. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21685. Namespaces is a set of features within Vault Enterprise that allows
  21686. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21687. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21688. This will default to Vault.Namespace field if set, or empty otherwise
  21689. type: string
  21690. tokenSecretRef:
  21691. description: TokenSecretRef authenticates with Vault by presenting a token.
  21692. properties:
  21693. key:
  21694. description: |-
  21695. A key in the referenced Secret.
  21696. Some instances of this field may be defaulted, in others it may be required.
  21697. maxLength: 253
  21698. minLength: 1
  21699. pattern: ^[-._a-zA-Z0-9]+$
  21700. type: string
  21701. name:
  21702. description: The name of the Secret resource being referred to.
  21703. maxLength: 253
  21704. minLength: 1
  21705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21706. type: string
  21707. namespace:
  21708. description: |-
  21709. The namespace of the Secret resource being referred to.
  21710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21711. maxLength: 63
  21712. minLength: 1
  21713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21714. type: string
  21715. type: object
  21716. userPass:
  21717. description: UserPass authenticates with Vault by passing username/password pair
  21718. properties:
  21719. path:
  21720. default: userpass
  21721. description: |-
  21722. Path where the UserPassword authentication backend is mounted
  21723. in Vault, e.g: "userpass"
  21724. type: string
  21725. secretRef:
  21726. description: |-
  21727. SecretRef to a key in a Secret resource containing password for the
  21728. user used to authenticate with Vault using the UserPass authentication
  21729. method
  21730. properties:
  21731. key:
  21732. description: |-
  21733. A key in the referenced Secret.
  21734. Some instances of this field may be defaulted, in others it may be required.
  21735. maxLength: 253
  21736. minLength: 1
  21737. pattern: ^[-._a-zA-Z0-9]+$
  21738. type: string
  21739. name:
  21740. description: The name of the Secret resource being referred to.
  21741. maxLength: 253
  21742. minLength: 1
  21743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21744. type: string
  21745. namespace:
  21746. description: |-
  21747. The namespace of the Secret resource being referred to.
  21748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21749. maxLength: 63
  21750. minLength: 1
  21751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21752. type: string
  21753. type: object
  21754. username:
  21755. description: |-
  21756. Username is a username used to authenticate using the UserPass Vault
  21757. authentication method
  21758. type: string
  21759. required:
  21760. - path
  21761. - username
  21762. type: object
  21763. type: object
  21764. caBundle:
  21765. description: |-
  21766. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21767. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21768. plain HTTP protocol connection. If not set the system root certificates
  21769. are used to validate the TLS connection.
  21770. format: byte
  21771. type: string
  21772. caProvider:
  21773. description: The provider for the CA bundle to use to validate Vault server certificate.
  21774. properties:
  21775. key:
  21776. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21777. maxLength: 253
  21778. minLength: 1
  21779. pattern: ^[-._a-zA-Z0-9]+$
  21780. type: string
  21781. name:
  21782. description: The name of the object located at the provider type.
  21783. maxLength: 253
  21784. minLength: 1
  21785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21786. type: string
  21787. namespace:
  21788. description: |-
  21789. The namespace the Provider type is in.
  21790. Can only be defined when used in a ClusterSecretStore.
  21791. maxLength: 63
  21792. minLength: 1
  21793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21794. type: string
  21795. type:
  21796. description: The type of provider to use such as "Secret", or "ConfigMap".
  21797. enum:
  21798. - Secret
  21799. - ConfigMap
  21800. type: string
  21801. required:
  21802. - name
  21803. - type
  21804. type: object
  21805. checkAndSet:
  21806. description: |-
  21807. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21808. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21809. the current version of the secret to prevent unintentional overwrites.
  21810. properties:
  21811. required:
  21812. description: |-
  21813. Required when true, all write operations must include a check-and-set parameter.
  21814. This helps prevent unintentional overwrites of secrets.
  21815. type: boolean
  21816. type: object
  21817. forwardInconsistent:
  21818. description: |-
  21819. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21820. leader instead of simply retrying within a loop. This can increase performance if
  21821. the option is enabled serverside.
  21822. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21823. type: boolean
  21824. headers:
  21825. additionalProperties:
  21826. type: string
  21827. description: Headers to be added in Vault request
  21828. type: object
  21829. namespace:
  21830. description: |-
  21831. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21832. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21833. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21834. type: string
  21835. path:
  21836. description: |-
  21837. Path is the mount path of the Vault KV backend endpoint, e.g:
  21838. "secret". The v2 KV secret engine version specific "/data" path suffix
  21839. for fetching secrets from Vault is optional and will be appended
  21840. if not present in specified path.
  21841. type: string
  21842. readYourWrites:
  21843. description: |-
  21844. ReadYourWrites ensures isolated read-after-write semantics by
  21845. providing discovered cluster replication states in each request.
  21846. More information about eventual consistency in Vault can be found here
  21847. https://www.vaultproject.io/docs/enterprise/consistency
  21848. type: boolean
  21849. server:
  21850. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21851. type: string
  21852. tls:
  21853. description: |-
  21854. The configuration used for client side related TLS communication, when the Vault server
  21855. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21856. This parameter is ignored for plain HTTP protocol connection.
  21857. It's worth noting this configuration is different from the "TLS certificates auth method",
  21858. which is available under the `auth.cert` section.
  21859. properties:
  21860. certSecretRef:
  21861. description: |-
  21862. CertSecretRef is a certificate added to the transport layer
  21863. when communicating with the Vault server.
  21864. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21865. properties:
  21866. key:
  21867. description: |-
  21868. A key in the referenced Secret.
  21869. Some instances of this field may be defaulted, in others it may be required.
  21870. maxLength: 253
  21871. minLength: 1
  21872. pattern: ^[-._a-zA-Z0-9]+$
  21873. type: string
  21874. name:
  21875. description: The name of the Secret resource being referred to.
  21876. maxLength: 253
  21877. minLength: 1
  21878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21879. type: string
  21880. namespace:
  21881. description: |-
  21882. The namespace of the Secret resource being referred to.
  21883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21884. maxLength: 63
  21885. minLength: 1
  21886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21887. type: string
  21888. type: object
  21889. keySecretRef:
  21890. description: |-
  21891. KeySecretRef to a key in a Secret resource containing client private key
  21892. added to the transport layer when communicating with the Vault server.
  21893. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21894. properties:
  21895. key:
  21896. description: |-
  21897. A key in the referenced Secret.
  21898. Some instances of this field may be defaulted, in others it may be required.
  21899. maxLength: 253
  21900. minLength: 1
  21901. pattern: ^[-._a-zA-Z0-9]+$
  21902. type: string
  21903. name:
  21904. description: The name of the Secret resource being referred to.
  21905. maxLength: 253
  21906. minLength: 1
  21907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21908. type: string
  21909. namespace:
  21910. description: |-
  21911. The namespace of the Secret resource being referred to.
  21912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21913. maxLength: 63
  21914. minLength: 1
  21915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21916. type: string
  21917. type: object
  21918. type: object
  21919. version:
  21920. default: v2
  21921. description: |-
  21922. Version is the Vault KV secret engine version. This can be either "v1" or
  21923. "v2". Version defaults to "v2".
  21924. enum:
  21925. - v1
  21926. - v2
  21927. type: string
  21928. required:
  21929. - server
  21930. type: object
  21931. volcengine:
  21932. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21933. properties:
  21934. auth:
  21935. description: |-
  21936. Auth defines the authentication method to use.
  21937. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21938. properties:
  21939. secretRef:
  21940. description: |-
  21941. SecretRef defines the static credentials to use for authentication.
  21942. If not set, IRSA is used.
  21943. properties:
  21944. accessKeyID:
  21945. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21946. properties:
  21947. key:
  21948. description: |-
  21949. A key in the referenced Secret.
  21950. Some instances of this field may be defaulted, in others it may be required.
  21951. maxLength: 253
  21952. minLength: 1
  21953. pattern: ^[-._a-zA-Z0-9]+$
  21954. type: string
  21955. name:
  21956. description: The name of the Secret resource being referred to.
  21957. maxLength: 253
  21958. minLength: 1
  21959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21960. type: string
  21961. namespace:
  21962. description: |-
  21963. The namespace of the Secret resource being referred to.
  21964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21965. maxLength: 63
  21966. minLength: 1
  21967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21968. type: string
  21969. type: object
  21970. secretAccessKey:
  21971. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21972. properties:
  21973. key:
  21974. description: |-
  21975. A key in the referenced Secret.
  21976. Some instances of this field may be defaulted, in others it may be required.
  21977. maxLength: 253
  21978. minLength: 1
  21979. pattern: ^[-._a-zA-Z0-9]+$
  21980. type: string
  21981. name:
  21982. description: The name of the Secret resource being referred to.
  21983. maxLength: 253
  21984. minLength: 1
  21985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21986. type: string
  21987. namespace:
  21988. description: |-
  21989. The namespace of the Secret resource being referred to.
  21990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21991. maxLength: 63
  21992. minLength: 1
  21993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21994. type: string
  21995. type: object
  21996. token:
  21997. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  21998. properties:
  21999. key:
  22000. description: |-
  22001. A key in the referenced Secret.
  22002. Some instances of this field may be defaulted, in others it may be required.
  22003. maxLength: 253
  22004. minLength: 1
  22005. pattern: ^[-._a-zA-Z0-9]+$
  22006. type: string
  22007. name:
  22008. description: The name of the Secret resource being referred to.
  22009. maxLength: 253
  22010. minLength: 1
  22011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22012. type: string
  22013. namespace:
  22014. description: |-
  22015. The namespace of the Secret resource being referred to.
  22016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22017. maxLength: 63
  22018. minLength: 1
  22019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22020. type: string
  22021. type: object
  22022. required:
  22023. - accessKeyID
  22024. - secretAccessKey
  22025. type: object
  22026. type: object
  22027. region:
  22028. description: Region specifies the Volcengine region to connect to.
  22029. type: string
  22030. required:
  22031. - region
  22032. type: object
  22033. webhook:
  22034. description: Webhook configures this store to sync secrets using a generic templated webhook
  22035. properties:
  22036. auth:
  22037. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22038. maxProperties: 1
  22039. minProperties: 1
  22040. properties:
  22041. ntlm:
  22042. description: NTLMProtocol configures the store to use NTLM for auth
  22043. properties:
  22044. passwordSecret:
  22045. description: |-
  22046. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22047. In some instances, `key` is a required field.
  22048. properties:
  22049. key:
  22050. description: |-
  22051. A key in the referenced Secret.
  22052. Some instances of this field may be defaulted, in others it may be required.
  22053. maxLength: 253
  22054. minLength: 1
  22055. pattern: ^[-._a-zA-Z0-9]+$
  22056. type: string
  22057. name:
  22058. description: The name of the Secret resource being referred to.
  22059. maxLength: 253
  22060. minLength: 1
  22061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22062. type: string
  22063. namespace:
  22064. description: |-
  22065. The namespace of the Secret resource being referred to.
  22066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22067. maxLength: 63
  22068. minLength: 1
  22069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22070. type: string
  22071. type: object
  22072. usernameSecret:
  22073. description: |-
  22074. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22075. In some instances, `key` is a required field.
  22076. properties:
  22077. key:
  22078. description: |-
  22079. A key in the referenced Secret.
  22080. Some instances of this field may be defaulted, in others it may be required.
  22081. maxLength: 253
  22082. minLength: 1
  22083. pattern: ^[-._a-zA-Z0-9]+$
  22084. type: string
  22085. name:
  22086. description: The name of the Secret resource being referred to.
  22087. maxLength: 253
  22088. minLength: 1
  22089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22090. type: string
  22091. namespace:
  22092. description: |-
  22093. The namespace of the Secret resource being referred to.
  22094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22095. maxLength: 63
  22096. minLength: 1
  22097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22098. type: string
  22099. type: object
  22100. required:
  22101. - passwordSecret
  22102. - usernameSecret
  22103. type: object
  22104. type: object
  22105. body:
  22106. description: Body
  22107. type: string
  22108. caBundle:
  22109. description: |-
  22110. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22111. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22112. plain HTTP protocol connection. If not set the system root certificates
  22113. are used to validate the TLS connection.
  22114. format: byte
  22115. type: string
  22116. caProvider:
  22117. description: The provider for the CA bundle to use to validate webhook server certificate.
  22118. properties:
  22119. key:
  22120. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22121. maxLength: 253
  22122. minLength: 1
  22123. pattern: ^[-._a-zA-Z0-9]+$
  22124. type: string
  22125. name:
  22126. description: The name of the object located at the provider type.
  22127. maxLength: 253
  22128. minLength: 1
  22129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22130. type: string
  22131. namespace:
  22132. description: The namespace the Provider type is in.
  22133. maxLength: 63
  22134. minLength: 1
  22135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22136. type: string
  22137. type:
  22138. description: The type of provider to use such as "Secret", or "ConfigMap".
  22139. enum:
  22140. - Secret
  22141. - ConfigMap
  22142. type: string
  22143. required:
  22144. - name
  22145. - type
  22146. type: object
  22147. headers:
  22148. additionalProperties:
  22149. type: string
  22150. description: Headers
  22151. type: object
  22152. method:
  22153. description: Webhook Method
  22154. type: string
  22155. result:
  22156. description: Result formatting
  22157. properties:
  22158. jsonPath:
  22159. description: Json path of return value
  22160. type: string
  22161. type: object
  22162. secrets:
  22163. description: |-
  22164. Secrets to fill in templates
  22165. These secrets will be passed to the templating function as key value pairs under the given name
  22166. items:
  22167. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22168. properties:
  22169. name:
  22170. description: Name of this secret in templates
  22171. type: string
  22172. secretRef:
  22173. description: Secret ref to fill in credentials
  22174. properties:
  22175. key:
  22176. description: |-
  22177. A key in the referenced Secret.
  22178. Some instances of this field may be defaulted, in others it may be required.
  22179. maxLength: 253
  22180. minLength: 1
  22181. pattern: ^[-._a-zA-Z0-9]+$
  22182. type: string
  22183. name:
  22184. description: The name of the Secret resource being referred to.
  22185. maxLength: 253
  22186. minLength: 1
  22187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22188. type: string
  22189. namespace:
  22190. description: |-
  22191. The namespace of the Secret resource being referred to.
  22192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22193. maxLength: 63
  22194. minLength: 1
  22195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22196. type: string
  22197. type: object
  22198. required:
  22199. - name
  22200. - secretRef
  22201. type: object
  22202. type: array
  22203. timeout:
  22204. description: Timeout
  22205. type: string
  22206. url:
  22207. description: Webhook url to call
  22208. type: string
  22209. required:
  22210. - url
  22211. type: object
  22212. yandexcertificatemanager:
  22213. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22214. properties:
  22215. apiEndpoint:
  22216. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22217. type: string
  22218. auth:
  22219. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22220. properties:
  22221. authorizedKeySecretRef:
  22222. description: The authorized key used for authentication
  22223. properties:
  22224. key:
  22225. description: |-
  22226. A key in the referenced Secret.
  22227. Some instances of this field may be defaulted, in others it may be required.
  22228. maxLength: 253
  22229. minLength: 1
  22230. pattern: ^[-._a-zA-Z0-9]+$
  22231. type: string
  22232. name:
  22233. description: The name of the Secret resource being referred to.
  22234. maxLength: 253
  22235. minLength: 1
  22236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22237. type: string
  22238. namespace:
  22239. description: |-
  22240. The namespace of the Secret resource being referred to.
  22241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22242. maxLength: 63
  22243. minLength: 1
  22244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22245. type: string
  22246. type: object
  22247. type: object
  22248. caProvider:
  22249. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22250. properties:
  22251. certSecretRef:
  22252. description: |-
  22253. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22254. In some instances, `key` is a required field.
  22255. properties:
  22256. key:
  22257. description: |-
  22258. A key in the referenced Secret.
  22259. Some instances of this field may be defaulted, in others it may be required.
  22260. maxLength: 253
  22261. minLength: 1
  22262. pattern: ^[-._a-zA-Z0-9]+$
  22263. type: string
  22264. name:
  22265. description: The name of the Secret resource being referred to.
  22266. maxLength: 253
  22267. minLength: 1
  22268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22269. type: string
  22270. namespace:
  22271. description: |-
  22272. The namespace of the Secret resource being referred to.
  22273. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22274. maxLength: 63
  22275. minLength: 1
  22276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22277. type: string
  22278. type: object
  22279. type: object
  22280. fetching:
  22281. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22282. maxProperties: 1
  22283. minProperties: 1
  22284. properties:
  22285. byID:
  22286. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22287. type: object
  22288. byName:
  22289. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22290. properties:
  22291. folderID:
  22292. description: The folder to fetch secrets from
  22293. type: string
  22294. required:
  22295. - folderID
  22296. type: object
  22297. type: object
  22298. required:
  22299. - auth
  22300. type: object
  22301. yandexlockbox:
  22302. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22303. properties:
  22304. apiEndpoint:
  22305. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22306. type: string
  22307. auth:
  22308. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22309. properties:
  22310. authorizedKeySecretRef:
  22311. description: The authorized key used for authentication
  22312. properties:
  22313. key:
  22314. description: |-
  22315. A key in the referenced Secret.
  22316. Some instances of this field may be defaulted, in others it may be required.
  22317. maxLength: 253
  22318. minLength: 1
  22319. pattern: ^[-._a-zA-Z0-9]+$
  22320. type: string
  22321. name:
  22322. description: The name of the Secret resource being referred to.
  22323. maxLength: 253
  22324. minLength: 1
  22325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22326. type: string
  22327. namespace:
  22328. description: |-
  22329. The namespace of the Secret resource being referred to.
  22330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22331. maxLength: 63
  22332. minLength: 1
  22333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22334. type: string
  22335. type: object
  22336. type: object
  22337. caProvider:
  22338. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22339. properties:
  22340. certSecretRef:
  22341. description: |-
  22342. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22343. In some instances, `key` is a required field.
  22344. properties:
  22345. key:
  22346. description: |-
  22347. A key in the referenced Secret.
  22348. Some instances of this field may be defaulted, in others it may be required.
  22349. maxLength: 253
  22350. minLength: 1
  22351. pattern: ^[-._a-zA-Z0-9]+$
  22352. type: string
  22353. name:
  22354. description: The name of the Secret resource being referred to.
  22355. maxLength: 253
  22356. minLength: 1
  22357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22358. type: string
  22359. namespace:
  22360. description: |-
  22361. The namespace of the Secret resource being referred to.
  22362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22363. maxLength: 63
  22364. minLength: 1
  22365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22366. type: string
  22367. type: object
  22368. type: object
  22369. fetching:
  22370. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22371. maxProperties: 1
  22372. minProperties: 1
  22373. properties:
  22374. byID:
  22375. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22376. type: object
  22377. byName:
  22378. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22379. properties:
  22380. folderID:
  22381. description: The folder to fetch secrets from
  22382. type: string
  22383. required:
  22384. - folderID
  22385. type: object
  22386. type: object
  22387. required:
  22388. - auth
  22389. type: object
  22390. type: object
  22391. refreshInterval:
  22392. anyOf:
  22393. - type: integer
  22394. - type: string
  22395. description: |-
  22396. Used to configure store refresh interval. Accepts either an integer number
  22397. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22398. 0 will default to the controller config.
  22399. x-kubernetes-int-or-string: true
  22400. retrySettings:
  22401. description: Used to configure HTTP retries on failures.
  22402. properties:
  22403. maxRetries:
  22404. format: int32
  22405. type: integer
  22406. retryInterval:
  22407. type: string
  22408. type: object
  22409. required:
  22410. - provider
  22411. type: object
  22412. status:
  22413. description: SecretStoreStatus defines the observed state of the SecretStore.
  22414. properties:
  22415. capabilities:
  22416. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22417. type: string
  22418. conditions:
  22419. items:
  22420. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22421. properties:
  22422. lastTransitionTime:
  22423. format: date-time
  22424. type: string
  22425. message:
  22426. type: string
  22427. reason:
  22428. type: string
  22429. status:
  22430. type: string
  22431. type:
  22432. description: SecretStoreConditionType represents the condition of the SecretStore.
  22433. type: string
  22434. required:
  22435. - status
  22436. - type
  22437. type: object
  22438. type: array
  22439. type: object
  22440. type: object
  22441. served: true
  22442. storage: true
  22443. subresources:
  22444. status: {}
  22445. - additionalPrinterColumns:
  22446. - jsonPath: .metadata.creationTimestamp
  22447. name: AGE
  22448. type: date
  22449. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22450. name: Status
  22451. type: string
  22452. - jsonPath: .status.capabilities
  22453. name: Capabilities
  22454. type: string
  22455. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22456. name: Ready
  22457. type: string
  22458. deprecated: true
  22459. name: v1beta1
  22460. schema:
  22461. openAPIV3Schema:
  22462. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22463. properties:
  22464. apiVersion:
  22465. description: |-
  22466. APIVersion defines the versioned schema of this representation of an object.
  22467. Servers should convert recognized schemas to the latest internal value, and
  22468. may reject unrecognized values.
  22469. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22470. type: string
  22471. kind:
  22472. description: |-
  22473. Kind is a string value representing the REST resource this object represents.
  22474. Servers may infer this from the endpoint the client submits requests to.
  22475. Cannot be updated.
  22476. In CamelCase.
  22477. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22478. type: string
  22479. metadata:
  22480. type: object
  22481. spec:
  22482. description: SecretStoreSpec defines the desired state of SecretStore.
  22483. properties:
  22484. conditions:
  22485. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22486. items:
  22487. description: |-
  22488. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22489. for a ClusterSecretStore instance.
  22490. properties:
  22491. namespaceRegexes:
  22492. description: Choose namespaces by using regex matching
  22493. items:
  22494. type: string
  22495. type: array
  22496. namespaceSelector:
  22497. description: Choose namespace using a labelSelector
  22498. properties:
  22499. matchExpressions:
  22500. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22501. items:
  22502. description: |-
  22503. A label selector requirement is a selector that contains values, a key, and an operator that
  22504. relates the key and values.
  22505. properties:
  22506. key:
  22507. description: key is the label key that the selector applies to.
  22508. type: string
  22509. operator:
  22510. description: |-
  22511. operator represents a key's relationship to a set of values.
  22512. Valid operators are In, NotIn, Exists and DoesNotExist.
  22513. type: string
  22514. values:
  22515. description: |-
  22516. values is an array of string values. If the operator is In or NotIn,
  22517. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22518. the values array must be empty. This array is replaced during a strategic
  22519. merge patch.
  22520. items:
  22521. type: string
  22522. type: array
  22523. x-kubernetes-list-type: atomic
  22524. required:
  22525. - key
  22526. - operator
  22527. type: object
  22528. type: array
  22529. x-kubernetes-list-type: atomic
  22530. matchLabels:
  22531. additionalProperties:
  22532. type: string
  22533. description: |-
  22534. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22535. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22536. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22537. type: object
  22538. type: object
  22539. x-kubernetes-map-type: atomic
  22540. namespaces:
  22541. description: Choose namespaces by name
  22542. items:
  22543. maxLength: 63
  22544. minLength: 1
  22545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22546. type: string
  22547. type: array
  22548. type: object
  22549. type: array
  22550. controller:
  22551. description: |-
  22552. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22553. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22554. type: string
  22555. provider:
  22556. description: Used to configure the provider. Only one provider may be set
  22557. maxProperties: 1
  22558. minProperties: 1
  22559. properties:
  22560. akeyless:
  22561. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22562. properties:
  22563. akeylessGWApiURL:
  22564. description: Akeyless GW API Url from which the secrets to be fetched from.
  22565. type: string
  22566. authSecretRef:
  22567. description: Auth configures how the operator authenticates with Akeyless.
  22568. properties:
  22569. kubernetesAuth:
  22570. description: |-
  22571. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22572. token stored in the named Secret resource.
  22573. properties:
  22574. accessID:
  22575. description: the Akeyless Kubernetes auth-method access-id
  22576. type: string
  22577. k8sConfName:
  22578. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22579. type: string
  22580. secretRef:
  22581. description: |-
  22582. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22583. for authenticating with Akeyless. If a name is specified without a key,
  22584. `token` is the default. If one is not specified, the one bound to
  22585. the controller will be used.
  22586. properties:
  22587. key:
  22588. description: |-
  22589. A key in the referenced Secret.
  22590. Some instances of this field may be defaulted, in others it may be required.
  22591. maxLength: 253
  22592. minLength: 1
  22593. pattern: ^[-._a-zA-Z0-9]+$
  22594. type: string
  22595. name:
  22596. description: The name of the Secret resource being referred to.
  22597. maxLength: 253
  22598. minLength: 1
  22599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22600. type: string
  22601. namespace:
  22602. description: |-
  22603. The namespace of the Secret resource being referred to.
  22604. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22605. maxLength: 63
  22606. minLength: 1
  22607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22608. type: string
  22609. type: object
  22610. serviceAccountRef:
  22611. description: |-
  22612. Optional service account field containing the name of a kubernetes ServiceAccount.
  22613. If the service account is specified, the service account secret token JWT will be used
  22614. for authenticating with Akeyless. If the service account selector is not supplied,
  22615. the secretRef will be used instead.
  22616. properties:
  22617. audiences:
  22618. description: |-
  22619. Audience specifies the `aud` claim for the service account token
  22620. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22621. then this audiences will be appended to the list
  22622. items:
  22623. type: string
  22624. type: array
  22625. name:
  22626. description: The name of the ServiceAccount resource being referred to.
  22627. maxLength: 253
  22628. minLength: 1
  22629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22630. type: string
  22631. namespace:
  22632. description: |-
  22633. Namespace of the resource being referred to.
  22634. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22635. maxLength: 63
  22636. minLength: 1
  22637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22638. type: string
  22639. required:
  22640. - name
  22641. type: object
  22642. required:
  22643. - accessID
  22644. - k8sConfName
  22645. type: object
  22646. secretRef:
  22647. description: |-
  22648. Reference to a Secret that contains the details
  22649. to authenticate with Akeyless.
  22650. properties:
  22651. accessID:
  22652. description: The SecretAccessID is used for authentication
  22653. properties:
  22654. key:
  22655. description: |-
  22656. A key in the referenced Secret.
  22657. Some instances of this field may be defaulted, in others it may be required.
  22658. maxLength: 253
  22659. minLength: 1
  22660. pattern: ^[-._a-zA-Z0-9]+$
  22661. type: string
  22662. name:
  22663. description: The name of the Secret resource being referred to.
  22664. maxLength: 253
  22665. minLength: 1
  22666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22667. type: string
  22668. namespace:
  22669. description: |-
  22670. The namespace of the Secret resource being referred to.
  22671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22672. maxLength: 63
  22673. minLength: 1
  22674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22675. type: string
  22676. type: object
  22677. accessType:
  22678. description: |-
  22679. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22680. In some instances, `key` is a required field.
  22681. properties:
  22682. key:
  22683. description: |-
  22684. A key in the referenced Secret.
  22685. Some instances of this field may be defaulted, in others it may be required.
  22686. maxLength: 253
  22687. minLength: 1
  22688. pattern: ^[-._a-zA-Z0-9]+$
  22689. type: string
  22690. name:
  22691. description: The name of the Secret resource being referred to.
  22692. maxLength: 253
  22693. minLength: 1
  22694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22695. type: string
  22696. namespace:
  22697. description: |-
  22698. The namespace of the Secret resource being referred to.
  22699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22700. maxLength: 63
  22701. minLength: 1
  22702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22703. type: string
  22704. type: object
  22705. accessTypeParam:
  22706. description: |-
  22707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22708. In some instances, `key` is a required field.
  22709. properties:
  22710. key:
  22711. description: |-
  22712. A key in the referenced Secret.
  22713. Some instances of this field may be defaulted, in others it may be required.
  22714. maxLength: 253
  22715. minLength: 1
  22716. pattern: ^[-._a-zA-Z0-9]+$
  22717. type: string
  22718. name:
  22719. description: The name of the Secret resource being referred to.
  22720. maxLength: 253
  22721. minLength: 1
  22722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22723. type: string
  22724. namespace:
  22725. description: |-
  22726. The namespace of the Secret resource being referred to.
  22727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22728. maxLength: 63
  22729. minLength: 1
  22730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22731. type: string
  22732. type: object
  22733. type: object
  22734. type: object
  22735. caBundle:
  22736. description: |-
  22737. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22738. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22739. are used to validate the TLS connection.
  22740. format: byte
  22741. type: string
  22742. caProvider:
  22743. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22744. properties:
  22745. key:
  22746. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22747. maxLength: 253
  22748. minLength: 1
  22749. pattern: ^[-._a-zA-Z0-9]+$
  22750. type: string
  22751. name:
  22752. description: The name of the object located at the provider type.
  22753. maxLength: 253
  22754. minLength: 1
  22755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22756. type: string
  22757. namespace:
  22758. description: |-
  22759. The namespace the Provider type is in.
  22760. Can only be defined when used in a ClusterSecretStore.
  22761. maxLength: 63
  22762. minLength: 1
  22763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22764. type: string
  22765. type:
  22766. description: The type of provider to use such as "Secret", or "ConfigMap".
  22767. enum:
  22768. - Secret
  22769. - ConfigMap
  22770. type: string
  22771. required:
  22772. - name
  22773. - type
  22774. type: object
  22775. required:
  22776. - akeylessGWApiURL
  22777. - authSecretRef
  22778. type: object
  22779. alibaba:
  22780. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22781. properties:
  22782. auth:
  22783. description: AlibabaAuth contains a secretRef for credentials.
  22784. properties:
  22785. rrsa:
  22786. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22787. properties:
  22788. oidcProviderArn:
  22789. type: string
  22790. oidcTokenFilePath:
  22791. type: string
  22792. roleArn:
  22793. type: string
  22794. sessionName:
  22795. type: string
  22796. required:
  22797. - oidcProviderArn
  22798. - oidcTokenFilePath
  22799. - roleArn
  22800. - sessionName
  22801. type: object
  22802. secretRef:
  22803. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22804. properties:
  22805. accessKeyIDSecretRef:
  22806. description: The AccessKeyID is used for authentication
  22807. properties:
  22808. key:
  22809. description: |-
  22810. A key in the referenced Secret.
  22811. Some instances of this field may be defaulted, in others it may be required.
  22812. maxLength: 253
  22813. minLength: 1
  22814. pattern: ^[-._a-zA-Z0-9]+$
  22815. type: string
  22816. name:
  22817. description: The name of the Secret resource being referred to.
  22818. maxLength: 253
  22819. minLength: 1
  22820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22821. type: string
  22822. namespace:
  22823. description: |-
  22824. The namespace of the Secret resource being referred to.
  22825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22826. maxLength: 63
  22827. minLength: 1
  22828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22829. type: string
  22830. type: object
  22831. accessKeySecretSecretRef:
  22832. description: The AccessKeySecret is used for authentication
  22833. properties:
  22834. key:
  22835. description: |-
  22836. A key in the referenced Secret.
  22837. Some instances of this field may be defaulted, in others it may be required.
  22838. maxLength: 253
  22839. minLength: 1
  22840. pattern: ^[-._a-zA-Z0-9]+$
  22841. type: string
  22842. name:
  22843. description: The name of the Secret resource being referred to.
  22844. maxLength: 253
  22845. minLength: 1
  22846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22847. type: string
  22848. namespace:
  22849. description: |-
  22850. The namespace of the Secret resource being referred to.
  22851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22852. maxLength: 63
  22853. minLength: 1
  22854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22855. type: string
  22856. type: object
  22857. required:
  22858. - accessKeyIDSecretRef
  22859. - accessKeySecretSecretRef
  22860. type: object
  22861. type: object
  22862. regionID:
  22863. description: Alibaba Region to be used for the provider
  22864. type: string
  22865. required:
  22866. - auth
  22867. - regionID
  22868. type: object
  22869. aws:
  22870. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22871. properties:
  22872. additionalRoles:
  22873. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22874. items:
  22875. type: string
  22876. type: array
  22877. auth:
  22878. description: |-
  22879. Auth defines the information necessary to authenticate against AWS
  22880. if not set aws sdk will infer credentials from your environment
  22881. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22882. properties:
  22883. jwt:
  22884. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22885. properties:
  22886. serviceAccountRef:
  22887. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22888. properties:
  22889. audiences:
  22890. description: |-
  22891. Audience specifies the `aud` claim for the service account token
  22892. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22893. then this audiences will be appended to the list
  22894. items:
  22895. type: string
  22896. type: array
  22897. name:
  22898. description: The name of the ServiceAccount resource being referred to.
  22899. maxLength: 253
  22900. minLength: 1
  22901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22902. type: string
  22903. namespace:
  22904. description: |-
  22905. Namespace of the resource being referred to.
  22906. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22907. maxLength: 63
  22908. minLength: 1
  22909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22910. type: string
  22911. required:
  22912. - name
  22913. type: object
  22914. type: object
  22915. secretRef:
  22916. description: |-
  22917. AWSAuthSecretRef holds secret references for AWS credentials
  22918. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22919. properties:
  22920. accessKeyIDSecretRef:
  22921. description: The AccessKeyID is used for authentication
  22922. properties:
  22923. key:
  22924. description: |-
  22925. A key in the referenced Secret.
  22926. Some instances of this field may be defaulted, in others it may be required.
  22927. maxLength: 253
  22928. minLength: 1
  22929. pattern: ^[-._a-zA-Z0-9]+$
  22930. type: string
  22931. name:
  22932. description: The name of the Secret resource being referred to.
  22933. maxLength: 253
  22934. minLength: 1
  22935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22936. type: string
  22937. namespace:
  22938. description: |-
  22939. The namespace of the Secret resource being referred to.
  22940. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22941. maxLength: 63
  22942. minLength: 1
  22943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22944. type: string
  22945. type: object
  22946. secretAccessKeySecretRef:
  22947. description: The SecretAccessKey is used for authentication
  22948. properties:
  22949. key:
  22950. description: |-
  22951. A key in the referenced Secret.
  22952. Some instances of this field may be defaulted, in others it may be required.
  22953. maxLength: 253
  22954. minLength: 1
  22955. pattern: ^[-._a-zA-Z0-9]+$
  22956. type: string
  22957. name:
  22958. description: The name of the Secret resource being referred to.
  22959. maxLength: 253
  22960. minLength: 1
  22961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22962. type: string
  22963. namespace:
  22964. description: |-
  22965. The namespace of the Secret resource being referred to.
  22966. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22967. maxLength: 63
  22968. minLength: 1
  22969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22970. type: string
  22971. type: object
  22972. sessionTokenSecretRef:
  22973. description: |-
  22974. The SessionToken used for authentication
  22975. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22976. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22977. properties:
  22978. key:
  22979. description: |-
  22980. A key in the referenced Secret.
  22981. Some instances of this field may be defaulted, in others it may be required.
  22982. maxLength: 253
  22983. minLength: 1
  22984. pattern: ^[-._a-zA-Z0-9]+$
  22985. type: string
  22986. name:
  22987. description: The name of the Secret resource being referred to.
  22988. maxLength: 253
  22989. minLength: 1
  22990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22991. type: string
  22992. namespace:
  22993. description: |-
  22994. The namespace of the Secret resource being referred to.
  22995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22996. maxLength: 63
  22997. minLength: 1
  22998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22999. type: string
  23000. type: object
  23001. type: object
  23002. type: object
  23003. externalID:
  23004. description: AWS External ID set on assumed IAM roles
  23005. type: string
  23006. prefix:
  23007. description: Prefix adds a prefix to all retrieved values.
  23008. type: string
  23009. region:
  23010. description: AWS Region to be used for the provider
  23011. type: string
  23012. role:
  23013. description: Role is a Role ARN which the provider will assume
  23014. type: string
  23015. secretsManager:
  23016. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23017. properties:
  23018. forceDeleteWithoutRecovery:
  23019. description: |-
  23020. Specifies whether to delete the secret without any recovery window. You
  23021. can't use both this parameter and RecoveryWindowInDays in the same call.
  23022. If you don't use either, then by default Secrets Manager uses a 30 day
  23023. recovery window.
  23024. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23025. type: boolean
  23026. recoveryWindowInDays:
  23027. description: |-
  23028. The number of days from 7 to 30 that Secrets Manager waits before
  23029. permanently deleting the secret. You can't use both this parameter and
  23030. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23031. then by default Secrets Manager uses a 30 day recovery window.
  23032. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23033. format: int64
  23034. type: integer
  23035. type: object
  23036. service:
  23037. description: Service defines which service should be used to fetch the secrets
  23038. enum:
  23039. - SecretsManager
  23040. - ParameterStore
  23041. type: string
  23042. sessionTags:
  23043. description: AWS STS assume role session tags
  23044. items:
  23045. description: Tag defines a tag key and value for AWS resources.
  23046. properties:
  23047. key:
  23048. type: string
  23049. value:
  23050. type: string
  23051. required:
  23052. - key
  23053. - value
  23054. type: object
  23055. type: array
  23056. transitiveTagKeys:
  23057. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23058. items:
  23059. type: string
  23060. type: array
  23061. required:
  23062. - region
  23063. - service
  23064. type: object
  23065. azurekv:
  23066. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23067. properties:
  23068. authSecretRef:
  23069. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23070. properties:
  23071. clientCertificate:
  23072. description: The Azure ClientCertificate of the service principle used for authentication.
  23073. properties:
  23074. key:
  23075. description: |-
  23076. A key in the referenced Secret.
  23077. Some instances of this field may be defaulted, in others it may be required.
  23078. maxLength: 253
  23079. minLength: 1
  23080. pattern: ^[-._a-zA-Z0-9]+$
  23081. type: string
  23082. name:
  23083. description: The name of the Secret resource being referred to.
  23084. maxLength: 253
  23085. minLength: 1
  23086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23087. type: string
  23088. namespace:
  23089. description: |-
  23090. The namespace of the Secret resource being referred to.
  23091. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23092. maxLength: 63
  23093. minLength: 1
  23094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23095. type: string
  23096. type: object
  23097. clientId:
  23098. description: The Azure clientId of the service principle or managed identity used for authentication.
  23099. properties:
  23100. key:
  23101. description: |-
  23102. A key in the referenced Secret.
  23103. Some instances of this field may be defaulted, in others it may be required.
  23104. maxLength: 253
  23105. minLength: 1
  23106. pattern: ^[-._a-zA-Z0-9]+$
  23107. type: string
  23108. name:
  23109. description: The name of the Secret resource being referred to.
  23110. maxLength: 253
  23111. minLength: 1
  23112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23113. type: string
  23114. namespace:
  23115. description: |-
  23116. The namespace of the Secret resource being referred to.
  23117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23118. maxLength: 63
  23119. minLength: 1
  23120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23121. type: string
  23122. type: object
  23123. clientSecret:
  23124. description: The Azure ClientSecret of the service principle used for authentication.
  23125. properties:
  23126. key:
  23127. description: |-
  23128. A key in the referenced Secret.
  23129. Some instances of this field may be defaulted, in others it may be required.
  23130. maxLength: 253
  23131. minLength: 1
  23132. pattern: ^[-._a-zA-Z0-9]+$
  23133. type: string
  23134. name:
  23135. description: The name of the Secret resource being referred to.
  23136. maxLength: 253
  23137. minLength: 1
  23138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23139. type: string
  23140. namespace:
  23141. description: |-
  23142. The namespace of the Secret resource being referred to.
  23143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23144. maxLength: 63
  23145. minLength: 1
  23146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23147. type: string
  23148. type: object
  23149. tenantId:
  23150. description: The Azure tenantId of the managed identity used for authentication.
  23151. properties:
  23152. key:
  23153. description: |-
  23154. A key in the referenced Secret.
  23155. Some instances of this field may be defaulted, in others it may be required.
  23156. maxLength: 253
  23157. minLength: 1
  23158. pattern: ^[-._a-zA-Z0-9]+$
  23159. type: string
  23160. name:
  23161. description: The name of the Secret resource being referred to.
  23162. maxLength: 253
  23163. minLength: 1
  23164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23165. type: string
  23166. namespace:
  23167. description: |-
  23168. The namespace of the Secret resource being referred to.
  23169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23170. maxLength: 63
  23171. minLength: 1
  23172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23173. type: string
  23174. type: object
  23175. type: object
  23176. authType:
  23177. default: ServicePrincipal
  23178. description: |-
  23179. Auth type defines how to authenticate to the keyvault service.
  23180. Valid values are:
  23181. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23182. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23183. enum:
  23184. - ServicePrincipal
  23185. - ManagedIdentity
  23186. - WorkloadIdentity
  23187. type: string
  23188. environmentType:
  23189. default: PublicCloud
  23190. description: |-
  23191. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23192. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23193. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23194. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23195. enum:
  23196. - PublicCloud
  23197. - USGovernmentCloud
  23198. - ChinaCloud
  23199. - GermanCloud
  23200. type: string
  23201. identityId:
  23202. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23203. type: string
  23204. serviceAccountRef:
  23205. description: |-
  23206. ServiceAccountRef specified the service account
  23207. that should be used when authenticating with WorkloadIdentity.
  23208. properties:
  23209. audiences:
  23210. description: |-
  23211. Audience specifies the `aud` claim for the service account token
  23212. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23213. then this audiences will be appended to the list
  23214. items:
  23215. type: string
  23216. type: array
  23217. name:
  23218. description: The name of the ServiceAccount resource being referred to.
  23219. maxLength: 253
  23220. minLength: 1
  23221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23222. type: string
  23223. namespace:
  23224. description: |-
  23225. Namespace of the resource being referred to.
  23226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23227. maxLength: 63
  23228. minLength: 1
  23229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23230. type: string
  23231. required:
  23232. - name
  23233. type: object
  23234. tenantId:
  23235. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23236. type: string
  23237. vaultUrl:
  23238. description: Vault Url from which the secrets to be fetched from.
  23239. type: string
  23240. required:
  23241. - vaultUrl
  23242. type: object
  23243. beyondtrust:
  23244. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23245. properties:
  23246. auth:
  23247. description: Auth configures how the operator authenticates with Beyondtrust.
  23248. properties:
  23249. apiKey:
  23250. description: APIKey If not provided then ClientID/ClientSecret become required.
  23251. properties:
  23252. secretRef:
  23253. description: SecretRef references a key in a secret that will be used as value.
  23254. properties:
  23255. key:
  23256. description: |-
  23257. A key in the referenced Secret.
  23258. Some instances of this field may be defaulted, in others it may be required.
  23259. maxLength: 253
  23260. minLength: 1
  23261. pattern: ^[-._a-zA-Z0-9]+$
  23262. type: string
  23263. name:
  23264. description: The name of the Secret resource being referred to.
  23265. maxLength: 253
  23266. minLength: 1
  23267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23268. type: string
  23269. namespace:
  23270. description: |-
  23271. The namespace of the Secret resource being referred to.
  23272. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23273. maxLength: 63
  23274. minLength: 1
  23275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23276. type: string
  23277. type: object
  23278. value:
  23279. description: Value can be specified directly to set a value without using a secret.
  23280. type: string
  23281. type: object
  23282. certificate:
  23283. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23284. properties:
  23285. secretRef:
  23286. description: SecretRef references a key in a secret that will be used as value.
  23287. properties:
  23288. key:
  23289. description: |-
  23290. A key in the referenced Secret.
  23291. Some instances of this field may be defaulted, in others it may be required.
  23292. maxLength: 253
  23293. minLength: 1
  23294. pattern: ^[-._a-zA-Z0-9]+$
  23295. type: string
  23296. name:
  23297. description: The name of the Secret resource being referred to.
  23298. maxLength: 253
  23299. minLength: 1
  23300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23301. type: string
  23302. namespace:
  23303. description: |-
  23304. The namespace of the Secret resource being referred to.
  23305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23306. maxLength: 63
  23307. minLength: 1
  23308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23309. type: string
  23310. type: object
  23311. value:
  23312. description: Value can be specified directly to set a value without using a secret.
  23313. type: string
  23314. type: object
  23315. certificateKey:
  23316. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23317. properties:
  23318. secretRef:
  23319. description: SecretRef references a key in a secret that will be used as value.
  23320. properties:
  23321. key:
  23322. description: |-
  23323. A key in the referenced Secret.
  23324. Some instances of this field may be defaulted, in others it may be required.
  23325. maxLength: 253
  23326. minLength: 1
  23327. pattern: ^[-._a-zA-Z0-9]+$
  23328. type: string
  23329. name:
  23330. description: The name of the Secret resource being referred to.
  23331. maxLength: 253
  23332. minLength: 1
  23333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23334. type: string
  23335. namespace:
  23336. description: |-
  23337. The namespace of the Secret resource being referred to.
  23338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23339. maxLength: 63
  23340. minLength: 1
  23341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23342. type: string
  23343. type: object
  23344. value:
  23345. description: Value can be specified directly to set a value without using a secret.
  23346. type: string
  23347. type: object
  23348. clientId:
  23349. description: ClientID is the API OAuth Client ID.
  23350. properties:
  23351. secretRef:
  23352. description: SecretRef references a key in a secret that will be used as value.
  23353. properties:
  23354. key:
  23355. description: |-
  23356. A key in the referenced Secret.
  23357. Some instances of this field may be defaulted, in others it may be required.
  23358. maxLength: 253
  23359. minLength: 1
  23360. pattern: ^[-._a-zA-Z0-9]+$
  23361. type: string
  23362. name:
  23363. description: The name of the Secret resource being referred to.
  23364. maxLength: 253
  23365. minLength: 1
  23366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23367. type: string
  23368. namespace:
  23369. description: |-
  23370. The namespace of the Secret resource being referred to.
  23371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23372. maxLength: 63
  23373. minLength: 1
  23374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23375. type: string
  23376. type: object
  23377. value:
  23378. description: Value can be specified directly to set a value without using a secret.
  23379. type: string
  23380. type: object
  23381. clientSecret:
  23382. description: ClientSecret is the API OAuth Client Secret.
  23383. properties:
  23384. secretRef:
  23385. description: SecretRef references a key in a secret that will be used as value.
  23386. properties:
  23387. key:
  23388. description: |-
  23389. A key in the referenced Secret.
  23390. Some instances of this field may be defaulted, in others it may be required.
  23391. maxLength: 253
  23392. minLength: 1
  23393. pattern: ^[-._a-zA-Z0-9]+$
  23394. type: string
  23395. name:
  23396. description: The name of the Secret resource being referred to.
  23397. maxLength: 253
  23398. minLength: 1
  23399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23400. type: string
  23401. namespace:
  23402. description: |-
  23403. The namespace of the Secret resource being referred to.
  23404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23405. maxLength: 63
  23406. minLength: 1
  23407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23408. type: string
  23409. type: object
  23410. value:
  23411. description: Value can be specified directly to set a value without using a secret.
  23412. type: string
  23413. type: object
  23414. type: object
  23415. server:
  23416. description: Auth configures how API server works.
  23417. properties:
  23418. apiUrl:
  23419. type: string
  23420. apiVersion:
  23421. type: string
  23422. clientTimeOutSeconds:
  23423. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23424. type: integer
  23425. decrypt:
  23426. default: true
  23427. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23428. type: boolean
  23429. retrievalType:
  23430. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23431. type: string
  23432. separator:
  23433. description: A character that separates the folder names.
  23434. type: string
  23435. verifyCA:
  23436. type: boolean
  23437. required:
  23438. - apiUrl
  23439. - verifyCA
  23440. type: object
  23441. required:
  23442. - auth
  23443. - server
  23444. type: object
  23445. bitwardensecretsmanager:
  23446. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23447. properties:
  23448. apiURL:
  23449. type: string
  23450. auth:
  23451. description: |-
  23452. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23453. Make sure that the token being used has permissions on the given secret.
  23454. properties:
  23455. secretRef:
  23456. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23457. properties:
  23458. credentials:
  23459. description: AccessToken used for the bitwarden instance.
  23460. properties:
  23461. key:
  23462. description: |-
  23463. A key in the referenced Secret.
  23464. Some instances of this field may be defaulted, in others it may be required.
  23465. maxLength: 253
  23466. minLength: 1
  23467. pattern: ^[-._a-zA-Z0-9]+$
  23468. type: string
  23469. name:
  23470. description: The name of the Secret resource being referred to.
  23471. maxLength: 253
  23472. minLength: 1
  23473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23474. type: string
  23475. namespace:
  23476. description: |-
  23477. The namespace of the Secret resource being referred to.
  23478. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23479. maxLength: 63
  23480. minLength: 1
  23481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23482. type: string
  23483. type: object
  23484. required:
  23485. - credentials
  23486. type: object
  23487. required:
  23488. - secretRef
  23489. type: object
  23490. bitwardenServerSDKURL:
  23491. type: string
  23492. caBundle:
  23493. description: |-
  23494. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23495. can be performed.
  23496. type: string
  23497. caProvider:
  23498. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23499. properties:
  23500. key:
  23501. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23502. maxLength: 253
  23503. minLength: 1
  23504. pattern: ^[-._a-zA-Z0-9]+$
  23505. type: string
  23506. name:
  23507. description: The name of the object located at the provider type.
  23508. maxLength: 253
  23509. minLength: 1
  23510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23511. type: string
  23512. namespace:
  23513. description: |-
  23514. The namespace the Provider type is in.
  23515. Can only be defined when used in a ClusterSecretStore.
  23516. maxLength: 63
  23517. minLength: 1
  23518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23519. type: string
  23520. type:
  23521. description: The type of provider to use such as "Secret", or "ConfigMap".
  23522. enum:
  23523. - Secret
  23524. - ConfigMap
  23525. type: string
  23526. required:
  23527. - name
  23528. - type
  23529. type: object
  23530. identityURL:
  23531. type: string
  23532. organizationID:
  23533. description: OrganizationID determines which organization this secret store manages.
  23534. type: string
  23535. projectID:
  23536. description: ProjectID determines which project this secret store manages.
  23537. type: string
  23538. required:
  23539. - auth
  23540. - organizationID
  23541. - projectID
  23542. type: object
  23543. chef:
  23544. description: Chef configures this store to sync secrets with chef server
  23545. properties:
  23546. auth:
  23547. description: Auth defines the information necessary to authenticate against chef Server
  23548. properties:
  23549. secretRef:
  23550. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23551. properties:
  23552. privateKeySecretRef:
  23553. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23554. properties:
  23555. key:
  23556. description: |-
  23557. A key in the referenced Secret.
  23558. Some instances of this field may be defaulted, in others it may be required.
  23559. maxLength: 253
  23560. minLength: 1
  23561. pattern: ^[-._a-zA-Z0-9]+$
  23562. type: string
  23563. name:
  23564. description: The name of the Secret resource being referred to.
  23565. maxLength: 253
  23566. minLength: 1
  23567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23568. type: string
  23569. namespace:
  23570. description: |-
  23571. The namespace of the Secret resource being referred to.
  23572. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23573. maxLength: 63
  23574. minLength: 1
  23575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23576. type: string
  23577. type: object
  23578. required:
  23579. - privateKeySecretRef
  23580. type: object
  23581. required:
  23582. - secretRef
  23583. type: object
  23584. serverUrl:
  23585. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23586. type: string
  23587. username:
  23588. description: UserName should be the user ID on the chef server
  23589. type: string
  23590. required:
  23591. - auth
  23592. - serverUrl
  23593. - username
  23594. type: object
  23595. cloudrusm:
  23596. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23597. properties:
  23598. auth:
  23599. description: CSMAuth contains a secretRef for credentials.
  23600. properties:
  23601. secretRef:
  23602. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23603. properties:
  23604. accessKeyIDSecretRef:
  23605. description: The AccessKeyID is used for authentication
  23606. properties:
  23607. key:
  23608. description: |-
  23609. A key in the referenced Secret.
  23610. Some instances of this field may be defaulted, in others it may be required.
  23611. maxLength: 253
  23612. minLength: 1
  23613. pattern: ^[-._a-zA-Z0-9]+$
  23614. type: string
  23615. name:
  23616. description: The name of the Secret resource being referred to.
  23617. maxLength: 253
  23618. minLength: 1
  23619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23620. type: string
  23621. namespace:
  23622. description: |-
  23623. The namespace of the Secret resource being referred to.
  23624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23625. maxLength: 63
  23626. minLength: 1
  23627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23628. type: string
  23629. type: object
  23630. accessKeySecretSecretRef:
  23631. description: The AccessKeySecret is used for authentication
  23632. properties:
  23633. key:
  23634. description: |-
  23635. A key in the referenced Secret.
  23636. Some instances of this field may be defaulted, in others it may be required.
  23637. maxLength: 253
  23638. minLength: 1
  23639. pattern: ^[-._a-zA-Z0-9]+$
  23640. type: string
  23641. name:
  23642. description: The name of the Secret resource being referred to.
  23643. maxLength: 253
  23644. minLength: 1
  23645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23646. type: string
  23647. namespace:
  23648. description: |-
  23649. The namespace of the Secret resource being referred to.
  23650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23651. maxLength: 63
  23652. minLength: 1
  23653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23654. type: string
  23655. type: object
  23656. required:
  23657. - accessKeyIDSecretRef
  23658. - accessKeySecretSecretRef
  23659. type: object
  23660. type: object
  23661. projectID:
  23662. description: ProjectID is the project, which the secrets are stored in.
  23663. type: string
  23664. required:
  23665. - auth
  23666. type: object
  23667. conjur:
  23668. description: Conjur configures this store to sync secrets using conjur provider
  23669. properties:
  23670. auth:
  23671. description: Defines authentication settings for connecting to Conjur.
  23672. properties:
  23673. apikey:
  23674. description: Authenticates with Conjur using an API key.
  23675. properties:
  23676. account:
  23677. description: Account is the Conjur organization account name.
  23678. type: string
  23679. apiKeyRef:
  23680. description: |-
  23681. A reference to a specific 'key' containing the Conjur API key
  23682. within a Secret resource. In some instances, `key` is a required field.
  23683. properties:
  23684. key:
  23685. description: |-
  23686. A key in the referenced Secret.
  23687. Some instances of this field may be defaulted, in others it may be required.
  23688. maxLength: 253
  23689. minLength: 1
  23690. pattern: ^[-._a-zA-Z0-9]+$
  23691. type: string
  23692. name:
  23693. description: The name of the Secret resource being referred to.
  23694. maxLength: 253
  23695. minLength: 1
  23696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23697. type: string
  23698. namespace:
  23699. description: |-
  23700. The namespace of the Secret resource being referred to.
  23701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23702. maxLength: 63
  23703. minLength: 1
  23704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23705. type: string
  23706. type: object
  23707. userRef:
  23708. description: |-
  23709. A reference to a specific 'key' containing the Conjur username
  23710. within a Secret resource. In some instances, `key` is a required field.
  23711. properties:
  23712. key:
  23713. description: |-
  23714. A key in the referenced Secret.
  23715. Some instances of this field may be defaulted, in others it may be required.
  23716. maxLength: 253
  23717. minLength: 1
  23718. pattern: ^[-._a-zA-Z0-9]+$
  23719. type: string
  23720. name:
  23721. description: The name of the Secret resource being referred to.
  23722. maxLength: 253
  23723. minLength: 1
  23724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23725. type: string
  23726. namespace:
  23727. description: |-
  23728. The namespace of the Secret resource being referred to.
  23729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23730. maxLength: 63
  23731. minLength: 1
  23732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23733. type: string
  23734. type: object
  23735. required:
  23736. - account
  23737. - apiKeyRef
  23738. - userRef
  23739. type: object
  23740. jwt:
  23741. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23742. properties:
  23743. account:
  23744. description: Account is the Conjur organization account name.
  23745. type: string
  23746. hostId:
  23747. description: |-
  23748. Optional HostID for JWT authentication. This may be used depending
  23749. on how the Conjur JWT authenticator policy is configured.
  23750. type: string
  23751. secretRef:
  23752. description: |-
  23753. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23754. authenticate with Conjur using the JWT authentication method.
  23755. properties:
  23756. key:
  23757. description: |-
  23758. A key in the referenced Secret.
  23759. Some instances of this field may be defaulted, in others it may be required.
  23760. maxLength: 253
  23761. minLength: 1
  23762. pattern: ^[-._a-zA-Z0-9]+$
  23763. type: string
  23764. name:
  23765. description: The name of the Secret resource being referred to.
  23766. maxLength: 253
  23767. minLength: 1
  23768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23769. type: string
  23770. namespace:
  23771. description: |-
  23772. The namespace of the Secret resource being referred to.
  23773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23774. maxLength: 63
  23775. minLength: 1
  23776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23777. type: string
  23778. type: object
  23779. serviceAccountRef:
  23780. description: |-
  23781. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23782. a token for with the `TokenRequest` API.
  23783. properties:
  23784. audiences:
  23785. description: |-
  23786. Audience specifies the `aud` claim for the service account token
  23787. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23788. then this audiences will be appended to the list
  23789. items:
  23790. type: string
  23791. type: array
  23792. name:
  23793. description: The name of the ServiceAccount resource being referred to.
  23794. maxLength: 253
  23795. minLength: 1
  23796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23797. type: string
  23798. namespace:
  23799. description: |-
  23800. Namespace of the resource being referred to.
  23801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23802. maxLength: 63
  23803. minLength: 1
  23804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23805. type: string
  23806. required:
  23807. - name
  23808. type: object
  23809. serviceID:
  23810. description: The conjur authn jwt webservice id
  23811. type: string
  23812. required:
  23813. - account
  23814. - serviceID
  23815. type: object
  23816. type: object
  23817. caBundle:
  23818. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23819. type: string
  23820. caProvider:
  23821. description: |-
  23822. Used to provide custom certificate authority (CA) certificates
  23823. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23824. that contains a PEM-encoded certificate.
  23825. properties:
  23826. key:
  23827. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23828. maxLength: 253
  23829. minLength: 1
  23830. pattern: ^[-._a-zA-Z0-9]+$
  23831. type: string
  23832. name:
  23833. description: The name of the object located at the provider type.
  23834. maxLength: 253
  23835. minLength: 1
  23836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23837. type: string
  23838. namespace:
  23839. description: |-
  23840. The namespace the Provider type is in.
  23841. Can only be defined when used in a ClusterSecretStore.
  23842. maxLength: 63
  23843. minLength: 1
  23844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23845. type: string
  23846. type:
  23847. description: The type of provider to use such as "Secret", or "ConfigMap".
  23848. enum:
  23849. - Secret
  23850. - ConfigMap
  23851. type: string
  23852. required:
  23853. - name
  23854. - type
  23855. type: object
  23856. url:
  23857. description: URL is the endpoint of the Conjur instance.
  23858. type: string
  23859. required:
  23860. - auth
  23861. - url
  23862. type: object
  23863. delinea:
  23864. description: |-
  23865. Delinea DevOps Secrets Vault
  23866. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23867. properties:
  23868. clientId:
  23869. description: ClientID is the non-secret part of the credential.
  23870. properties:
  23871. secretRef:
  23872. description: SecretRef references a key in a secret that will be used as value.
  23873. properties:
  23874. key:
  23875. description: |-
  23876. A key in the referenced Secret.
  23877. Some instances of this field may be defaulted, in others it may be required.
  23878. maxLength: 253
  23879. minLength: 1
  23880. pattern: ^[-._a-zA-Z0-9]+$
  23881. type: string
  23882. name:
  23883. description: The name of the Secret resource being referred to.
  23884. maxLength: 253
  23885. minLength: 1
  23886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23887. type: string
  23888. namespace:
  23889. description: |-
  23890. The namespace of the Secret resource being referred to.
  23891. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23892. maxLength: 63
  23893. minLength: 1
  23894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23895. type: string
  23896. type: object
  23897. value:
  23898. description: Value can be specified directly to set a value without using a secret.
  23899. type: string
  23900. type: object
  23901. clientSecret:
  23902. description: ClientSecret is the secret part of the credential.
  23903. properties:
  23904. secretRef:
  23905. description: SecretRef references a key in a secret that will be used as value.
  23906. properties:
  23907. key:
  23908. description: |-
  23909. A key in the referenced Secret.
  23910. Some instances of this field may be defaulted, in others it may be required.
  23911. maxLength: 253
  23912. minLength: 1
  23913. pattern: ^[-._a-zA-Z0-9]+$
  23914. type: string
  23915. name:
  23916. description: The name of the Secret resource being referred to.
  23917. maxLength: 253
  23918. minLength: 1
  23919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23920. type: string
  23921. namespace:
  23922. description: |-
  23923. The namespace of the Secret resource being referred to.
  23924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23925. maxLength: 63
  23926. minLength: 1
  23927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23928. type: string
  23929. type: object
  23930. value:
  23931. description: Value can be specified directly to set a value without using a secret.
  23932. type: string
  23933. type: object
  23934. tenant:
  23935. description: Tenant is the chosen hostname / site name.
  23936. type: string
  23937. tld:
  23938. description: |-
  23939. TLD is based on the server location that was chosen during provisioning.
  23940. If unset, defaults to "com".
  23941. type: string
  23942. urlTemplate:
  23943. description: |-
  23944. URLTemplate
  23945. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23946. type: string
  23947. required:
  23948. - clientId
  23949. - clientSecret
  23950. - tenant
  23951. type: object
  23952. device42:
  23953. description: Device42 configures this store to sync secrets using the Device42 provider
  23954. properties:
  23955. auth:
  23956. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23957. properties:
  23958. secretRef:
  23959. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23960. properties:
  23961. credentials:
  23962. description: Username / Password is used for authentication.
  23963. properties:
  23964. key:
  23965. description: |-
  23966. A key in the referenced Secret.
  23967. Some instances of this field may be defaulted, in others it may be required.
  23968. maxLength: 253
  23969. minLength: 1
  23970. pattern: ^[-._a-zA-Z0-9]+$
  23971. type: string
  23972. name:
  23973. description: The name of the Secret resource being referred to.
  23974. maxLength: 253
  23975. minLength: 1
  23976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23977. type: string
  23978. namespace:
  23979. description: |-
  23980. The namespace of the Secret resource being referred to.
  23981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23982. maxLength: 63
  23983. minLength: 1
  23984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23985. type: string
  23986. type: object
  23987. type: object
  23988. required:
  23989. - secretRef
  23990. type: object
  23991. host:
  23992. description: URL configures the Device42 instance URL.
  23993. type: string
  23994. required:
  23995. - auth
  23996. - host
  23997. type: object
  23998. doppler:
  23999. description: Doppler configures this store to sync secrets using the Doppler provider
  24000. properties:
  24001. auth:
  24002. description: Auth configures how the Operator authenticates with the Doppler API
  24003. properties:
  24004. secretRef:
  24005. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24006. properties:
  24007. dopplerToken:
  24008. description: |-
  24009. The DopplerToken is used for authentication.
  24010. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24011. The Key attribute defaults to dopplerToken if not specified.
  24012. properties:
  24013. key:
  24014. description: |-
  24015. A key in the referenced Secret.
  24016. Some instances of this field may be defaulted, in others it may be required.
  24017. maxLength: 253
  24018. minLength: 1
  24019. pattern: ^[-._a-zA-Z0-9]+$
  24020. type: string
  24021. name:
  24022. description: The name of the Secret resource being referred to.
  24023. maxLength: 253
  24024. minLength: 1
  24025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24026. type: string
  24027. namespace:
  24028. description: |-
  24029. The namespace of the Secret resource being referred to.
  24030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24031. maxLength: 63
  24032. minLength: 1
  24033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24034. type: string
  24035. type: object
  24036. required:
  24037. - dopplerToken
  24038. type: object
  24039. required:
  24040. - secretRef
  24041. type: object
  24042. config:
  24043. description: Doppler config (required if not using a Service Token)
  24044. type: string
  24045. format:
  24046. description: Format enables the downloading of secrets as a file (string)
  24047. enum:
  24048. - json
  24049. - dotnet-json
  24050. - env
  24051. - yaml
  24052. - docker
  24053. type: string
  24054. nameTransformer:
  24055. description: Environment variable compatible name transforms that change secret names to a different format
  24056. enum:
  24057. - upper-camel
  24058. - camel
  24059. - lower-snake
  24060. - tf-var
  24061. - dotnet-env
  24062. - lower-kebab
  24063. type: string
  24064. project:
  24065. description: Doppler project (required if not using a Service Token)
  24066. type: string
  24067. required:
  24068. - auth
  24069. type: object
  24070. fake:
  24071. description: Fake configures a store with static key/value pairs
  24072. properties:
  24073. data:
  24074. items:
  24075. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24076. properties:
  24077. key:
  24078. type: string
  24079. value:
  24080. type: string
  24081. version:
  24082. type: string
  24083. required:
  24084. - key
  24085. - value
  24086. type: object
  24087. type: array
  24088. required:
  24089. - data
  24090. type: object
  24091. fortanix:
  24092. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24093. properties:
  24094. apiKey:
  24095. description: APIKey is the API token to access SDKMS Applications.
  24096. properties:
  24097. secretRef:
  24098. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24099. properties:
  24100. key:
  24101. description: |-
  24102. A key in the referenced Secret.
  24103. Some instances of this field may be defaulted, in others it may be required.
  24104. maxLength: 253
  24105. minLength: 1
  24106. pattern: ^[-._a-zA-Z0-9]+$
  24107. type: string
  24108. name:
  24109. description: The name of the Secret resource being referred to.
  24110. maxLength: 253
  24111. minLength: 1
  24112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24113. type: string
  24114. namespace:
  24115. description: |-
  24116. The namespace of the Secret resource being referred to.
  24117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24118. maxLength: 63
  24119. minLength: 1
  24120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24121. type: string
  24122. type: object
  24123. type: object
  24124. apiUrl:
  24125. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24126. type: string
  24127. type: object
  24128. gcpsm:
  24129. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24130. properties:
  24131. auth:
  24132. description: Auth defines the information necessary to authenticate against GCP
  24133. properties:
  24134. secretRef:
  24135. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24136. properties:
  24137. secretAccessKeySecretRef:
  24138. description: The SecretAccessKey is used for authentication
  24139. properties:
  24140. key:
  24141. description: |-
  24142. A key in the referenced Secret.
  24143. Some instances of this field may be defaulted, in others it may be required.
  24144. maxLength: 253
  24145. minLength: 1
  24146. pattern: ^[-._a-zA-Z0-9]+$
  24147. type: string
  24148. name:
  24149. description: The name of the Secret resource being referred to.
  24150. maxLength: 253
  24151. minLength: 1
  24152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24153. type: string
  24154. namespace:
  24155. description: |-
  24156. The namespace of the Secret resource being referred to.
  24157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24158. maxLength: 63
  24159. minLength: 1
  24160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24161. type: string
  24162. type: object
  24163. type: object
  24164. workloadIdentity:
  24165. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24166. properties:
  24167. clusterLocation:
  24168. description: |-
  24169. ClusterLocation is the location of the cluster
  24170. If not specified, it fetches information from the metadata server
  24171. type: string
  24172. clusterName:
  24173. description: |-
  24174. ClusterName is the name of the cluster
  24175. If not specified, it fetches information from the metadata server
  24176. type: string
  24177. clusterProjectID:
  24178. description: |-
  24179. ClusterProjectID is the project ID of the cluster
  24180. If not specified, it fetches information from the metadata server
  24181. type: string
  24182. serviceAccountRef:
  24183. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24184. properties:
  24185. audiences:
  24186. description: |-
  24187. Audience specifies the `aud` claim for the service account token
  24188. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24189. then this audiences will be appended to the list
  24190. items:
  24191. type: string
  24192. type: array
  24193. name:
  24194. description: The name of the ServiceAccount resource being referred to.
  24195. maxLength: 253
  24196. minLength: 1
  24197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24198. type: string
  24199. namespace:
  24200. description: |-
  24201. Namespace of the resource being referred to.
  24202. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24203. maxLength: 63
  24204. minLength: 1
  24205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24206. type: string
  24207. required:
  24208. - name
  24209. type: object
  24210. required:
  24211. - serviceAccountRef
  24212. type: object
  24213. type: object
  24214. location:
  24215. description: Location optionally defines a location for a secret
  24216. type: string
  24217. projectID:
  24218. description: ProjectID project where secret is located
  24219. type: string
  24220. type: object
  24221. github:
  24222. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24223. properties:
  24224. appID:
  24225. description: appID specifies the Github APP that will be used to authenticate the client
  24226. format: int64
  24227. type: integer
  24228. auth:
  24229. description: auth configures how secret-manager authenticates with a Github instance.
  24230. properties:
  24231. privateKey:
  24232. description: |-
  24233. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24234. In some instances, `key` is a required field.
  24235. properties:
  24236. key:
  24237. description: |-
  24238. A key in the referenced Secret.
  24239. Some instances of this field may be defaulted, in others it may be required.
  24240. maxLength: 253
  24241. minLength: 1
  24242. pattern: ^[-._a-zA-Z0-9]+$
  24243. type: string
  24244. name:
  24245. description: The name of the Secret resource being referred to.
  24246. maxLength: 253
  24247. minLength: 1
  24248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24249. type: string
  24250. namespace:
  24251. description: |-
  24252. The namespace of the Secret resource being referred to.
  24253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24254. maxLength: 63
  24255. minLength: 1
  24256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24257. type: string
  24258. type: object
  24259. required:
  24260. - privateKey
  24261. type: object
  24262. environment:
  24263. description: environment will be used to fetch secrets from a particular environment within a github repository
  24264. type: string
  24265. installationID:
  24266. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24267. format: int64
  24268. type: integer
  24269. organization:
  24270. description: organization will be used to fetch secrets from the Github organization
  24271. type: string
  24272. repository:
  24273. description: repository will be used to fetch secrets from the Github repository within an organization
  24274. type: string
  24275. uploadURL:
  24276. description: Upload URL for enterprise instances. Default to URL.
  24277. type: string
  24278. url:
  24279. default: https://github.com/
  24280. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24281. type: string
  24282. required:
  24283. - appID
  24284. - auth
  24285. - installationID
  24286. - organization
  24287. type: object
  24288. gitlab:
  24289. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24290. properties:
  24291. auth:
  24292. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24293. properties:
  24294. SecretRef:
  24295. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24296. properties:
  24297. accessToken:
  24298. description: AccessToken is used for authentication.
  24299. properties:
  24300. key:
  24301. description: |-
  24302. A key in the referenced Secret.
  24303. Some instances of this field may be defaulted, in others it may be required.
  24304. maxLength: 253
  24305. minLength: 1
  24306. pattern: ^[-._a-zA-Z0-9]+$
  24307. type: string
  24308. name:
  24309. description: The name of the Secret resource being referred to.
  24310. maxLength: 253
  24311. minLength: 1
  24312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24313. type: string
  24314. namespace:
  24315. description: |-
  24316. The namespace of the Secret resource being referred to.
  24317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24318. maxLength: 63
  24319. minLength: 1
  24320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24321. type: string
  24322. type: object
  24323. type: object
  24324. required:
  24325. - SecretRef
  24326. type: object
  24327. caBundle:
  24328. description: |-
  24329. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24330. can be performed.
  24331. format: byte
  24332. type: string
  24333. caProvider:
  24334. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24335. properties:
  24336. key:
  24337. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24338. maxLength: 253
  24339. minLength: 1
  24340. pattern: ^[-._a-zA-Z0-9]+$
  24341. type: string
  24342. name:
  24343. description: The name of the object located at the provider type.
  24344. maxLength: 253
  24345. minLength: 1
  24346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24347. type: string
  24348. namespace:
  24349. description: |-
  24350. The namespace the Provider type is in.
  24351. Can only be defined when used in a ClusterSecretStore.
  24352. maxLength: 63
  24353. minLength: 1
  24354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24355. type: string
  24356. type:
  24357. description: The type of provider to use such as "Secret", or "ConfigMap".
  24358. enum:
  24359. - Secret
  24360. - ConfigMap
  24361. type: string
  24362. required:
  24363. - name
  24364. - type
  24365. type: object
  24366. environment:
  24367. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24368. type: string
  24369. groupIDs:
  24370. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24371. items:
  24372. type: string
  24373. type: array
  24374. inheritFromGroups:
  24375. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24376. type: boolean
  24377. projectID:
  24378. description: ProjectID specifies a project where secrets are located.
  24379. type: string
  24380. url:
  24381. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24382. type: string
  24383. required:
  24384. - auth
  24385. type: object
  24386. ibm:
  24387. description: IBM configures this store to sync secrets using IBM Cloud provider
  24388. properties:
  24389. auth:
  24390. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24391. maxProperties: 1
  24392. minProperties: 1
  24393. properties:
  24394. containerAuth:
  24395. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24396. properties:
  24397. iamEndpoint:
  24398. type: string
  24399. profile:
  24400. description: the IBM Trusted Profile
  24401. type: string
  24402. tokenLocation:
  24403. description: Location the token is mounted on the pod
  24404. type: string
  24405. required:
  24406. - profile
  24407. type: object
  24408. secretRef:
  24409. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24410. properties:
  24411. secretApiKeySecretRef:
  24412. description: The SecretAccessKey is used for authentication
  24413. properties:
  24414. key:
  24415. description: |-
  24416. A key in the referenced Secret.
  24417. Some instances of this field may be defaulted, in others it may be required.
  24418. maxLength: 253
  24419. minLength: 1
  24420. pattern: ^[-._a-zA-Z0-9]+$
  24421. type: string
  24422. name:
  24423. description: The name of the Secret resource being referred to.
  24424. maxLength: 253
  24425. minLength: 1
  24426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24427. type: string
  24428. namespace:
  24429. description: |-
  24430. The namespace of the Secret resource being referred to.
  24431. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24432. maxLength: 63
  24433. minLength: 1
  24434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24435. type: string
  24436. type: object
  24437. type: object
  24438. type: object
  24439. serviceUrl:
  24440. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24441. type: string
  24442. required:
  24443. - auth
  24444. type: object
  24445. infisical:
  24446. description: Infisical configures this store to sync secrets using the Infisical provider
  24447. properties:
  24448. auth:
  24449. description: Auth configures how the Operator authenticates with the Infisical API
  24450. properties:
  24451. universalAuthCredentials:
  24452. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24453. properties:
  24454. clientId:
  24455. description: |-
  24456. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24457. In some instances, `key` is a required field.
  24458. properties:
  24459. key:
  24460. description: |-
  24461. A key in the referenced Secret.
  24462. Some instances of this field may be defaulted, in others it may be required.
  24463. maxLength: 253
  24464. minLength: 1
  24465. pattern: ^[-._a-zA-Z0-9]+$
  24466. type: string
  24467. name:
  24468. description: The name of the Secret resource being referred to.
  24469. maxLength: 253
  24470. minLength: 1
  24471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24472. type: string
  24473. namespace:
  24474. description: |-
  24475. The namespace of the Secret resource being referred to.
  24476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24477. maxLength: 63
  24478. minLength: 1
  24479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24480. type: string
  24481. type: object
  24482. clientSecret:
  24483. description: |-
  24484. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24485. In some instances, `key` is a required field.
  24486. properties:
  24487. key:
  24488. description: |-
  24489. A key in the referenced Secret.
  24490. Some instances of this field may be defaulted, in others it may be required.
  24491. maxLength: 253
  24492. minLength: 1
  24493. pattern: ^[-._a-zA-Z0-9]+$
  24494. type: string
  24495. name:
  24496. description: The name of the Secret resource being referred to.
  24497. maxLength: 253
  24498. minLength: 1
  24499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24500. type: string
  24501. namespace:
  24502. description: |-
  24503. The namespace of the Secret resource being referred to.
  24504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24505. maxLength: 63
  24506. minLength: 1
  24507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24508. type: string
  24509. type: object
  24510. required:
  24511. - clientId
  24512. - clientSecret
  24513. type: object
  24514. type: object
  24515. hostAPI:
  24516. default: https://app.infisical.com/api
  24517. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24518. type: string
  24519. secretsScope:
  24520. description: SecretsScope defines the scope of the secrets within the workspace
  24521. properties:
  24522. environmentSlug:
  24523. description: EnvironmentSlug is the required slug identifier for the environment.
  24524. type: string
  24525. expandSecretReferences:
  24526. default: true
  24527. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24528. type: boolean
  24529. projectSlug:
  24530. description: ProjectSlug is the required slug identifier for the project.
  24531. type: string
  24532. recursive:
  24533. default: false
  24534. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24535. type: boolean
  24536. secretsPath:
  24537. default: /
  24538. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24539. type: string
  24540. required:
  24541. - environmentSlug
  24542. - projectSlug
  24543. type: object
  24544. required:
  24545. - auth
  24546. - secretsScope
  24547. type: object
  24548. keepersecurity:
  24549. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24550. properties:
  24551. authRef:
  24552. description: |-
  24553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24554. In some instances, `key` is a required field.
  24555. properties:
  24556. key:
  24557. description: |-
  24558. A key in the referenced Secret.
  24559. Some instances of this field may be defaulted, in others it may be required.
  24560. maxLength: 253
  24561. minLength: 1
  24562. pattern: ^[-._a-zA-Z0-9]+$
  24563. type: string
  24564. name:
  24565. description: The name of the Secret resource being referred to.
  24566. maxLength: 253
  24567. minLength: 1
  24568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24569. type: string
  24570. namespace:
  24571. description: |-
  24572. The namespace of the Secret resource being referred to.
  24573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24574. maxLength: 63
  24575. minLength: 1
  24576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24577. type: string
  24578. type: object
  24579. folderID:
  24580. type: string
  24581. required:
  24582. - authRef
  24583. - folderID
  24584. type: object
  24585. kubernetes:
  24586. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24587. properties:
  24588. auth:
  24589. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24590. maxProperties: 1
  24591. minProperties: 1
  24592. properties:
  24593. cert:
  24594. description: has both clientCert and clientKey as secretKeySelector
  24595. properties:
  24596. clientCert:
  24597. description: |-
  24598. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24599. In some instances, `key` is a required field.
  24600. properties:
  24601. key:
  24602. description: |-
  24603. A key in the referenced Secret.
  24604. Some instances of this field may be defaulted, in others it may be required.
  24605. maxLength: 253
  24606. minLength: 1
  24607. pattern: ^[-._a-zA-Z0-9]+$
  24608. type: string
  24609. name:
  24610. description: The name of the Secret resource being referred to.
  24611. maxLength: 253
  24612. minLength: 1
  24613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24614. type: string
  24615. namespace:
  24616. description: |-
  24617. The namespace of the Secret resource being referred to.
  24618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24619. maxLength: 63
  24620. minLength: 1
  24621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24622. type: string
  24623. type: object
  24624. clientKey:
  24625. description: |-
  24626. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24627. In some instances, `key` is a required field.
  24628. properties:
  24629. key:
  24630. description: |-
  24631. A key in the referenced Secret.
  24632. Some instances of this field may be defaulted, in others it may be required.
  24633. maxLength: 253
  24634. minLength: 1
  24635. pattern: ^[-._a-zA-Z0-9]+$
  24636. type: string
  24637. name:
  24638. description: The name of the Secret resource being referred to.
  24639. maxLength: 253
  24640. minLength: 1
  24641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24642. type: string
  24643. namespace:
  24644. description: |-
  24645. The namespace of the Secret resource being referred to.
  24646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24647. maxLength: 63
  24648. minLength: 1
  24649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24650. type: string
  24651. type: object
  24652. type: object
  24653. serviceAccount:
  24654. description: points to a service account that should be used for authentication
  24655. properties:
  24656. audiences:
  24657. description: |-
  24658. Audience specifies the `aud` claim for the service account token
  24659. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24660. then this audiences will be appended to the list
  24661. items:
  24662. type: string
  24663. type: array
  24664. name:
  24665. description: The name of the ServiceAccount resource being referred to.
  24666. maxLength: 253
  24667. minLength: 1
  24668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24669. type: string
  24670. namespace:
  24671. description: |-
  24672. Namespace of the resource being referred to.
  24673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24674. maxLength: 63
  24675. minLength: 1
  24676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24677. type: string
  24678. required:
  24679. - name
  24680. type: object
  24681. token:
  24682. description: use static token to authenticate with
  24683. properties:
  24684. bearerToken:
  24685. description: |-
  24686. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24687. In some instances, `key` is a required field.
  24688. properties:
  24689. key:
  24690. description: |-
  24691. A key in the referenced Secret.
  24692. Some instances of this field may be defaulted, in others it may be required.
  24693. maxLength: 253
  24694. minLength: 1
  24695. pattern: ^[-._a-zA-Z0-9]+$
  24696. type: string
  24697. name:
  24698. description: The name of the Secret resource being referred to.
  24699. maxLength: 253
  24700. minLength: 1
  24701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24702. type: string
  24703. namespace:
  24704. description: |-
  24705. The namespace of the Secret resource being referred to.
  24706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24707. maxLength: 63
  24708. minLength: 1
  24709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24710. type: string
  24711. type: object
  24712. type: object
  24713. type: object
  24714. authRef:
  24715. description: A reference to a secret that contains the auth information.
  24716. properties:
  24717. key:
  24718. description: |-
  24719. A key in the referenced Secret.
  24720. Some instances of this field may be defaulted, in others it may be required.
  24721. maxLength: 253
  24722. minLength: 1
  24723. pattern: ^[-._a-zA-Z0-9]+$
  24724. type: string
  24725. name:
  24726. description: The name of the Secret resource being referred to.
  24727. maxLength: 253
  24728. minLength: 1
  24729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24730. type: string
  24731. namespace:
  24732. description: |-
  24733. The namespace of the Secret resource being referred to.
  24734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24735. maxLength: 63
  24736. minLength: 1
  24737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24738. type: string
  24739. type: object
  24740. remoteNamespace:
  24741. default: default
  24742. description: Remote namespace to fetch the secrets from
  24743. maxLength: 63
  24744. minLength: 1
  24745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24746. type: string
  24747. server:
  24748. description: configures the Kubernetes server Address.
  24749. properties:
  24750. caBundle:
  24751. description: CABundle is a base64-encoded CA certificate
  24752. format: byte
  24753. type: string
  24754. caProvider:
  24755. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24756. properties:
  24757. key:
  24758. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24759. maxLength: 253
  24760. minLength: 1
  24761. pattern: ^[-._a-zA-Z0-9]+$
  24762. type: string
  24763. name:
  24764. description: The name of the object located at the provider type.
  24765. maxLength: 253
  24766. minLength: 1
  24767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24768. type: string
  24769. namespace:
  24770. description: |-
  24771. The namespace the Provider type is in.
  24772. Can only be defined when used in a ClusterSecretStore.
  24773. maxLength: 63
  24774. minLength: 1
  24775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24776. type: string
  24777. type:
  24778. description: The type of provider to use such as "Secret", or "ConfigMap".
  24779. enum:
  24780. - Secret
  24781. - ConfigMap
  24782. type: string
  24783. required:
  24784. - name
  24785. - type
  24786. type: object
  24787. url:
  24788. default: kubernetes.default
  24789. description: configures the Kubernetes server Address.
  24790. type: string
  24791. type: object
  24792. type: object
  24793. onboardbase:
  24794. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24795. properties:
  24796. apiHost:
  24797. default: https://public.onboardbase.com/api/v1/
  24798. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24799. type: string
  24800. auth:
  24801. description: Auth configures how the Operator authenticates with the Onboardbase API
  24802. properties:
  24803. apiKeyRef:
  24804. description: |-
  24805. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24806. It is used to recognize and authorize access to a project and environment within onboardbase
  24807. properties:
  24808. key:
  24809. description: |-
  24810. A key in the referenced Secret.
  24811. Some instances of this field may be defaulted, in others it may be required.
  24812. maxLength: 253
  24813. minLength: 1
  24814. pattern: ^[-._a-zA-Z0-9]+$
  24815. type: string
  24816. name:
  24817. description: The name of the Secret resource being referred to.
  24818. maxLength: 253
  24819. minLength: 1
  24820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24821. type: string
  24822. namespace:
  24823. description: |-
  24824. The namespace of the Secret resource being referred to.
  24825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24826. maxLength: 63
  24827. minLength: 1
  24828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24829. type: string
  24830. type: object
  24831. passcodeRef:
  24832. description: OnboardbasePasscode is the passcode attached to the API Key
  24833. properties:
  24834. key:
  24835. description: |-
  24836. A key in the referenced Secret.
  24837. Some instances of this field may be defaulted, in others it may be required.
  24838. maxLength: 253
  24839. minLength: 1
  24840. pattern: ^[-._a-zA-Z0-9]+$
  24841. type: string
  24842. name:
  24843. description: The name of the Secret resource being referred to.
  24844. maxLength: 253
  24845. minLength: 1
  24846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24847. type: string
  24848. namespace:
  24849. description: |-
  24850. The namespace of the Secret resource being referred to.
  24851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24852. maxLength: 63
  24853. minLength: 1
  24854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24855. type: string
  24856. type: object
  24857. required:
  24858. - apiKeyRef
  24859. - passcodeRef
  24860. type: object
  24861. environment:
  24862. default: development
  24863. description: Environment is the name of an environmnent within a project to pull the secrets from
  24864. type: string
  24865. project:
  24866. default: development
  24867. description: Project is an onboardbase project that the secrets should be pulled from
  24868. type: string
  24869. required:
  24870. - apiHost
  24871. - auth
  24872. - environment
  24873. - project
  24874. type: object
  24875. onepassword:
  24876. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24877. properties:
  24878. auth:
  24879. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24880. properties:
  24881. secretRef:
  24882. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24883. properties:
  24884. connectTokenSecretRef:
  24885. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24886. properties:
  24887. key:
  24888. description: |-
  24889. A key in the referenced Secret.
  24890. Some instances of this field may be defaulted, in others it may be required.
  24891. maxLength: 253
  24892. minLength: 1
  24893. pattern: ^[-._a-zA-Z0-9]+$
  24894. type: string
  24895. name:
  24896. description: The name of the Secret resource being referred to.
  24897. maxLength: 253
  24898. minLength: 1
  24899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24900. type: string
  24901. namespace:
  24902. description: |-
  24903. The namespace of the Secret resource being referred to.
  24904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24905. maxLength: 63
  24906. minLength: 1
  24907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24908. type: string
  24909. type: object
  24910. required:
  24911. - connectTokenSecretRef
  24912. type: object
  24913. required:
  24914. - secretRef
  24915. type: object
  24916. connectHost:
  24917. description: ConnectHost defines the OnePassword Connect Server to connect to
  24918. type: string
  24919. vaults:
  24920. additionalProperties:
  24921. type: integer
  24922. description: Vaults defines which OnePassword vaults to search in which order
  24923. type: object
  24924. required:
  24925. - auth
  24926. - connectHost
  24927. - vaults
  24928. type: object
  24929. oracle:
  24930. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24931. properties:
  24932. auth:
  24933. description: |-
  24934. Auth configures how secret-manager authenticates with the Oracle Vault.
  24935. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24936. properties:
  24937. secretRef:
  24938. description: SecretRef to pass through sensitive information.
  24939. properties:
  24940. fingerprint:
  24941. description: Fingerprint is the fingerprint of the API private key.
  24942. properties:
  24943. key:
  24944. description: |-
  24945. A key in the referenced Secret.
  24946. Some instances of this field may be defaulted, in others it may be required.
  24947. maxLength: 253
  24948. minLength: 1
  24949. pattern: ^[-._a-zA-Z0-9]+$
  24950. type: string
  24951. name:
  24952. description: The name of the Secret resource being referred to.
  24953. maxLength: 253
  24954. minLength: 1
  24955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24956. type: string
  24957. namespace:
  24958. description: |-
  24959. The namespace of the Secret resource being referred to.
  24960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24961. maxLength: 63
  24962. minLength: 1
  24963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24964. type: string
  24965. type: object
  24966. privatekey:
  24967. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24968. properties:
  24969. key:
  24970. description: |-
  24971. A key in the referenced Secret.
  24972. Some instances of this field may be defaulted, in others it may be required.
  24973. maxLength: 253
  24974. minLength: 1
  24975. pattern: ^[-._a-zA-Z0-9]+$
  24976. type: string
  24977. name:
  24978. description: The name of the Secret resource being referred to.
  24979. maxLength: 253
  24980. minLength: 1
  24981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24982. type: string
  24983. namespace:
  24984. description: |-
  24985. The namespace of the Secret resource being referred to.
  24986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24987. maxLength: 63
  24988. minLength: 1
  24989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24990. type: string
  24991. type: object
  24992. required:
  24993. - fingerprint
  24994. - privatekey
  24995. type: object
  24996. tenancy:
  24997. description: Tenancy is the tenancy OCID where user is located.
  24998. type: string
  24999. user:
  25000. description: User is an access OCID specific to the account.
  25001. type: string
  25002. required:
  25003. - secretRef
  25004. - tenancy
  25005. - user
  25006. type: object
  25007. compartment:
  25008. description: |-
  25009. Compartment is the vault compartment OCID.
  25010. Required for PushSecret
  25011. type: string
  25012. encryptionKey:
  25013. description: |-
  25014. EncryptionKey is the OCID of the encryption key within the vault.
  25015. Required for PushSecret
  25016. type: string
  25017. principalType:
  25018. description: |-
  25019. The type of principal to use for authentication. If left blank, the Auth struct will
  25020. determine the principal type. This optional field must be specified if using
  25021. workload identity.
  25022. enum:
  25023. - ""
  25024. - UserPrincipal
  25025. - InstancePrincipal
  25026. - Workload
  25027. type: string
  25028. region:
  25029. description: Region is the region where vault is located.
  25030. type: string
  25031. serviceAccountRef:
  25032. description: |-
  25033. ServiceAccountRef specified the service account
  25034. that should be used when authenticating with WorkloadIdentity.
  25035. properties:
  25036. audiences:
  25037. description: |-
  25038. Audience specifies the `aud` claim for the service account token
  25039. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25040. then this audiences will be appended to the list
  25041. items:
  25042. type: string
  25043. type: array
  25044. name:
  25045. description: The name of the ServiceAccount resource being referred to.
  25046. maxLength: 253
  25047. minLength: 1
  25048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25049. type: string
  25050. namespace:
  25051. description: |-
  25052. Namespace of the resource being referred to.
  25053. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25054. maxLength: 63
  25055. minLength: 1
  25056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25057. type: string
  25058. required:
  25059. - name
  25060. type: object
  25061. vault:
  25062. description: Vault is the vault's OCID of the specific vault where secret is located.
  25063. type: string
  25064. required:
  25065. - region
  25066. - vault
  25067. type: object
  25068. passbolt:
  25069. description: PassboltProvider defines configuration for the Passbolt provider.
  25070. properties:
  25071. auth:
  25072. description: Auth defines the information necessary to authenticate against Passbolt Server
  25073. properties:
  25074. passwordSecretRef:
  25075. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25076. properties:
  25077. key:
  25078. description: |-
  25079. A key in the referenced Secret.
  25080. Some instances of this field may be defaulted, in others it may be required.
  25081. maxLength: 253
  25082. minLength: 1
  25083. pattern: ^[-._a-zA-Z0-9]+$
  25084. type: string
  25085. name:
  25086. description: The name of the Secret resource being referred to.
  25087. maxLength: 253
  25088. minLength: 1
  25089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25090. type: string
  25091. namespace:
  25092. description: |-
  25093. The namespace of the Secret resource being referred to.
  25094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25095. maxLength: 63
  25096. minLength: 1
  25097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25098. type: string
  25099. type: object
  25100. privateKeySecretRef:
  25101. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25102. properties:
  25103. key:
  25104. description: |-
  25105. A key in the referenced Secret.
  25106. Some instances of this field may be defaulted, in others it may be required.
  25107. maxLength: 253
  25108. minLength: 1
  25109. pattern: ^[-._a-zA-Z0-9]+$
  25110. type: string
  25111. name:
  25112. description: The name of the Secret resource being referred to.
  25113. maxLength: 253
  25114. minLength: 1
  25115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25116. type: string
  25117. namespace:
  25118. description: |-
  25119. The namespace of the Secret resource being referred to.
  25120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25121. maxLength: 63
  25122. minLength: 1
  25123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25124. type: string
  25125. type: object
  25126. required:
  25127. - passwordSecretRef
  25128. - privateKeySecretRef
  25129. type: object
  25130. host:
  25131. description: Host defines the Passbolt Server to connect to
  25132. type: string
  25133. required:
  25134. - auth
  25135. - host
  25136. type: object
  25137. passworddepot:
  25138. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25139. properties:
  25140. auth:
  25141. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25142. properties:
  25143. secretRef:
  25144. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25145. properties:
  25146. credentials:
  25147. description: Username / Password is used for authentication.
  25148. properties:
  25149. key:
  25150. description: |-
  25151. A key in the referenced Secret.
  25152. Some instances of this field may be defaulted, in others it may be required.
  25153. maxLength: 253
  25154. minLength: 1
  25155. pattern: ^[-._a-zA-Z0-9]+$
  25156. type: string
  25157. name:
  25158. description: The name of the Secret resource being referred to.
  25159. maxLength: 253
  25160. minLength: 1
  25161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25162. type: string
  25163. namespace:
  25164. description: |-
  25165. The namespace of the Secret resource being referred to.
  25166. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25167. maxLength: 63
  25168. minLength: 1
  25169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25170. type: string
  25171. type: object
  25172. type: object
  25173. required:
  25174. - secretRef
  25175. type: object
  25176. database:
  25177. description: Database to use as source
  25178. type: string
  25179. host:
  25180. description: URL configures the Password Depot instance URL.
  25181. type: string
  25182. required:
  25183. - auth
  25184. - database
  25185. - host
  25186. type: object
  25187. previder:
  25188. description: Previder configures this store to sync secrets using the Previder provider
  25189. properties:
  25190. auth:
  25191. description: PreviderAuth contains a secretRef for credentials.
  25192. properties:
  25193. secretRef:
  25194. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25195. properties:
  25196. accessToken:
  25197. description: The AccessToken is used for authentication
  25198. properties:
  25199. key:
  25200. description: |-
  25201. A key in the referenced Secret.
  25202. Some instances of this field may be defaulted, in others it may be required.
  25203. maxLength: 253
  25204. minLength: 1
  25205. pattern: ^[-._a-zA-Z0-9]+$
  25206. type: string
  25207. name:
  25208. description: The name of the Secret resource being referred to.
  25209. maxLength: 253
  25210. minLength: 1
  25211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25212. type: string
  25213. namespace:
  25214. description: |-
  25215. The namespace of the Secret resource being referred to.
  25216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25217. maxLength: 63
  25218. minLength: 1
  25219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25220. type: string
  25221. type: object
  25222. required:
  25223. - accessToken
  25224. type: object
  25225. type: object
  25226. baseUri:
  25227. type: string
  25228. required:
  25229. - auth
  25230. type: object
  25231. pulumi:
  25232. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25233. properties:
  25234. accessToken:
  25235. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25236. properties:
  25237. secretRef:
  25238. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25239. properties:
  25240. key:
  25241. description: |-
  25242. A key in the referenced Secret.
  25243. Some instances of this field may be defaulted, in others it may be required.
  25244. maxLength: 253
  25245. minLength: 1
  25246. pattern: ^[-._a-zA-Z0-9]+$
  25247. type: string
  25248. name:
  25249. description: The name of the Secret resource being referred to.
  25250. maxLength: 253
  25251. minLength: 1
  25252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25253. type: string
  25254. namespace:
  25255. description: |-
  25256. The namespace of the Secret resource being referred to.
  25257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25258. maxLength: 63
  25259. minLength: 1
  25260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25261. type: string
  25262. type: object
  25263. type: object
  25264. apiUrl:
  25265. default: https://api.pulumi.com/api/esc
  25266. description: APIURL is the URL of the Pulumi API.
  25267. type: string
  25268. environment:
  25269. description: |-
  25270. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25271. dynamically retrieved values from supported providers including all major clouds,
  25272. and other Pulumi ESC environments.
  25273. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25274. type: string
  25275. organization:
  25276. description: |-
  25277. Organization are a space to collaborate on shared projects and stacks.
  25278. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25279. type: string
  25280. project:
  25281. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25282. type: string
  25283. required:
  25284. - accessToken
  25285. - environment
  25286. - organization
  25287. - project
  25288. type: object
  25289. scaleway:
  25290. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25291. properties:
  25292. accessKey:
  25293. description: AccessKey is the non-secret part of the api key.
  25294. properties:
  25295. secretRef:
  25296. description: SecretRef references a key in a secret that will be used as value.
  25297. properties:
  25298. key:
  25299. description: |-
  25300. A key in the referenced Secret.
  25301. Some instances of this field may be defaulted, in others it may be required.
  25302. maxLength: 253
  25303. minLength: 1
  25304. pattern: ^[-._a-zA-Z0-9]+$
  25305. type: string
  25306. name:
  25307. description: The name of the Secret resource being referred to.
  25308. maxLength: 253
  25309. minLength: 1
  25310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25311. type: string
  25312. namespace:
  25313. description: |-
  25314. The namespace of the Secret resource being referred to.
  25315. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25316. maxLength: 63
  25317. minLength: 1
  25318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25319. type: string
  25320. type: object
  25321. value:
  25322. description: Value can be specified directly to set a value without using a secret.
  25323. type: string
  25324. type: object
  25325. apiUrl:
  25326. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25327. type: string
  25328. projectId:
  25329. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25330. type: string
  25331. region:
  25332. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25333. type: string
  25334. secretKey:
  25335. description: SecretKey is the non-secret part of the api key.
  25336. properties:
  25337. secretRef:
  25338. description: SecretRef references a key in a secret that will be used as value.
  25339. properties:
  25340. key:
  25341. description: |-
  25342. A key in the referenced Secret.
  25343. Some instances of this field may be defaulted, in others it may be required.
  25344. maxLength: 253
  25345. minLength: 1
  25346. pattern: ^[-._a-zA-Z0-9]+$
  25347. type: string
  25348. name:
  25349. description: The name of the Secret resource being referred to.
  25350. maxLength: 253
  25351. minLength: 1
  25352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25353. type: string
  25354. namespace:
  25355. description: |-
  25356. The namespace of the Secret resource being referred to.
  25357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25358. maxLength: 63
  25359. minLength: 1
  25360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25361. type: string
  25362. type: object
  25363. value:
  25364. description: Value can be specified directly to set a value without using a secret.
  25365. type: string
  25366. type: object
  25367. required:
  25368. - accessKey
  25369. - projectId
  25370. - region
  25371. - secretKey
  25372. type: object
  25373. secretserver:
  25374. description: |-
  25375. SecretServer configures this store to sync secrets using SecretServer provider
  25376. https://docs.delinea.com/online-help/secret-server/start.htm
  25377. properties:
  25378. password:
  25379. description: Password is the secret server account password.
  25380. properties:
  25381. secretRef:
  25382. description: SecretRef references a key in a secret that will be used as value.
  25383. properties:
  25384. key:
  25385. description: |-
  25386. A key in the referenced Secret.
  25387. Some instances of this field may be defaulted, in others it may be required.
  25388. maxLength: 253
  25389. minLength: 1
  25390. pattern: ^[-._a-zA-Z0-9]+$
  25391. type: string
  25392. name:
  25393. description: The name of the Secret resource being referred to.
  25394. maxLength: 253
  25395. minLength: 1
  25396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25397. type: string
  25398. namespace:
  25399. description: |-
  25400. The namespace of the Secret resource being referred to.
  25401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25402. maxLength: 63
  25403. minLength: 1
  25404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25405. type: string
  25406. type: object
  25407. value:
  25408. description: Value can be specified directly to set a value without using a secret.
  25409. type: string
  25410. type: object
  25411. serverURL:
  25412. description: |-
  25413. ServerURL
  25414. URL to your secret server installation
  25415. type: string
  25416. username:
  25417. description: Username is the secret server account username.
  25418. properties:
  25419. secretRef:
  25420. description: SecretRef references a key in a secret that will be used as value.
  25421. properties:
  25422. key:
  25423. description: |-
  25424. A key in the referenced Secret.
  25425. Some instances of this field may be defaulted, in others it may be required.
  25426. maxLength: 253
  25427. minLength: 1
  25428. pattern: ^[-._a-zA-Z0-9]+$
  25429. type: string
  25430. name:
  25431. description: The name of the Secret resource being referred to.
  25432. maxLength: 253
  25433. minLength: 1
  25434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25435. type: string
  25436. namespace:
  25437. description: |-
  25438. The namespace of the Secret resource being referred to.
  25439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25440. maxLength: 63
  25441. minLength: 1
  25442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25443. type: string
  25444. type: object
  25445. value:
  25446. description: Value can be specified directly to set a value without using a secret.
  25447. type: string
  25448. type: object
  25449. required:
  25450. - password
  25451. - serverURL
  25452. - username
  25453. type: object
  25454. senhasegura:
  25455. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25456. properties:
  25457. auth:
  25458. description: Auth defines parameters to authenticate in senhasegura
  25459. properties:
  25460. clientId:
  25461. type: string
  25462. clientSecretSecretRef:
  25463. description: |-
  25464. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25465. In some instances, `key` is a required field.
  25466. properties:
  25467. key:
  25468. description: |-
  25469. A key in the referenced Secret.
  25470. Some instances of this field may be defaulted, in others it may be required.
  25471. maxLength: 253
  25472. minLength: 1
  25473. pattern: ^[-._a-zA-Z0-9]+$
  25474. type: string
  25475. name:
  25476. description: The name of the Secret resource being referred to.
  25477. maxLength: 253
  25478. minLength: 1
  25479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25480. type: string
  25481. namespace:
  25482. description: |-
  25483. The namespace of the Secret resource being referred to.
  25484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25485. maxLength: 63
  25486. minLength: 1
  25487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25488. type: string
  25489. type: object
  25490. required:
  25491. - clientId
  25492. - clientSecretSecretRef
  25493. type: object
  25494. ignoreSslCertificate:
  25495. default: false
  25496. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25497. type: boolean
  25498. module:
  25499. description: Module defines which senhasegura module should be used to get secrets
  25500. type: string
  25501. url:
  25502. description: URL of senhasegura
  25503. type: string
  25504. required:
  25505. - auth
  25506. - module
  25507. - url
  25508. type: object
  25509. vault:
  25510. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25511. properties:
  25512. auth:
  25513. description: Auth configures how secret-manager authenticates with the Vault server.
  25514. properties:
  25515. appRole:
  25516. description: |-
  25517. AppRole authenticates with Vault using the App Role auth mechanism,
  25518. with the role and secret stored in a Kubernetes Secret resource.
  25519. properties:
  25520. path:
  25521. default: approle
  25522. description: |-
  25523. Path where the App Role authentication backend is mounted
  25524. in Vault, e.g: "approle"
  25525. type: string
  25526. roleId:
  25527. description: |-
  25528. RoleID configured in the App Role authentication backend when setting
  25529. up the authentication backend in Vault.
  25530. type: string
  25531. roleRef:
  25532. description: |-
  25533. Reference to a key in a Secret that contains the App Role ID used
  25534. to authenticate with Vault.
  25535. The `key` field must be specified and denotes which entry within the Secret
  25536. resource is used as the app role id.
  25537. properties:
  25538. key:
  25539. description: |-
  25540. A key in the referenced Secret.
  25541. Some instances of this field may be defaulted, in others it may be required.
  25542. maxLength: 253
  25543. minLength: 1
  25544. pattern: ^[-._a-zA-Z0-9]+$
  25545. type: string
  25546. name:
  25547. description: The name of the Secret resource being referred to.
  25548. maxLength: 253
  25549. minLength: 1
  25550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25551. type: string
  25552. namespace:
  25553. description: |-
  25554. The namespace of the Secret resource being referred to.
  25555. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25556. maxLength: 63
  25557. minLength: 1
  25558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25559. type: string
  25560. type: object
  25561. secretRef:
  25562. description: |-
  25563. Reference to a key in a Secret that contains the App Role secret used
  25564. to authenticate with Vault.
  25565. The `key` field must be specified and denotes which entry within the Secret
  25566. resource is used as the app role secret.
  25567. properties:
  25568. key:
  25569. description: |-
  25570. A key in the referenced Secret.
  25571. Some instances of this field may be defaulted, in others it may be required.
  25572. maxLength: 253
  25573. minLength: 1
  25574. pattern: ^[-._a-zA-Z0-9]+$
  25575. type: string
  25576. name:
  25577. description: The name of the Secret resource being referred to.
  25578. maxLength: 253
  25579. minLength: 1
  25580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25581. type: string
  25582. namespace:
  25583. description: |-
  25584. The namespace of the Secret resource being referred to.
  25585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25586. maxLength: 63
  25587. minLength: 1
  25588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25589. type: string
  25590. type: object
  25591. required:
  25592. - path
  25593. - secretRef
  25594. type: object
  25595. cert:
  25596. description: |-
  25597. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25598. Cert authentication method
  25599. properties:
  25600. clientCert:
  25601. description: |-
  25602. ClientCert is a certificate to authenticate using the Cert Vault
  25603. authentication method
  25604. properties:
  25605. key:
  25606. description: |-
  25607. A key in the referenced Secret.
  25608. Some instances of this field may be defaulted, in others it may be required.
  25609. maxLength: 253
  25610. minLength: 1
  25611. pattern: ^[-._a-zA-Z0-9]+$
  25612. type: string
  25613. name:
  25614. description: The name of the Secret resource being referred to.
  25615. maxLength: 253
  25616. minLength: 1
  25617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25618. type: string
  25619. namespace:
  25620. description: |-
  25621. The namespace of the Secret resource being referred to.
  25622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25623. maxLength: 63
  25624. minLength: 1
  25625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25626. type: string
  25627. type: object
  25628. secretRef:
  25629. description: |-
  25630. SecretRef to a key in a Secret resource containing client private key to
  25631. authenticate with Vault using the Cert authentication method
  25632. properties:
  25633. key:
  25634. description: |-
  25635. A key in the referenced Secret.
  25636. Some instances of this field may be defaulted, in others it may be required.
  25637. maxLength: 253
  25638. minLength: 1
  25639. pattern: ^[-._a-zA-Z0-9]+$
  25640. type: string
  25641. name:
  25642. description: The name of the Secret resource being referred to.
  25643. maxLength: 253
  25644. minLength: 1
  25645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25646. type: string
  25647. namespace:
  25648. description: |-
  25649. The namespace of the Secret resource being referred to.
  25650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25651. maxLength: 63
  25652. minLength: 1
  25653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25654. type: string
  25655. type: object
  25656. type: object
  25657. iam:
  25658. description: |-
  25659. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25660. AWS IAM authentication method
  25661. properties:
  25662. externalID:
  25663. description: AWS External ID set on assumed IAM roles
  25664. type: string
  25665. jwt:
  25666. description: Specify a service account with IRSA enabled
  25667. properties:
  25668. serviceAccountRef:
  25669. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25670. properties:
  25671. audiences:
  25672. description: |-
  25673. Audience specifies the `aud` claim for the service account token
  25674. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25675. then this audiences will be appended to the list
  25676. items:
  25677. type: string
  25678. type: array
  25679. name:
  25680. description: The name of the ServiceAccount resource being referred to.
  25681. maxLength: 253
  25682. minLength: 1
  25683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25684. type: string
  25685. namespace:
  25686. description: |-
  25687. Namespace of the resource being referred to.
  25688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25689. maxLength: 63
  25690. minLength: 1
  25691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25692. type: string
  25693. required:
  25694. - name
  25695. type: object
  25696. type: object
  25697. path:
  25698. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25699. type: string
  25700. region:
  25701. description: AWS region
  25702. type: string
  25703. role:
  25704. description: This is the AWS role to be assumed before talking to vault
  25705. type: string
  25706. secretRef:
  25707. description: Specify credentials in a Secret object
  25708. properties:
  25709. accessKeyIDSecretRef:
  25710. description: The AccessKeyID is used for authentication
  25711. properties:
  25712. key:
  25713. description: |-
  25714. A key in the referenced Secret.
  25715. Some instances of this field may be defaulted, in others it may be required.
  25716. maxLength: 253
  25717. minLength: 1
  25718. pattern: ^[-._a-zA-Z0-9]+$
  25719. type: string
  25720. name:
  25721. description: The name of the Secret resource being referred to.
  25722. maxLength: 253
  25723. minLength: 1
  25724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25725. type: string
  25726. namespace:
  25727. description: |-
  25728. The namespace of the Secret resource being referred to.
  25729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25730. maxLength: 63
  25731. minLength: 1
  25732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25733. type: string
  25734. type: object
  25735. secretAccessKeySecretRef:
  25736. description: The SecretAccessKey is used for authentication
  25737. properties:
  25738. key:
  25739. description: |-
  25740. A key in the referenced Secret.
  25741. Some instances of this field may be defaulted, in others it may be required.
  25742. maxLength: 253
  25743. minLength: 1
  25744. pattern: ^[-._a-zA-Z0-9]+$
  25745. type: string
  25746. name:
  25747. description: The name of the Secret resource being referred to.
  25748. maxLength: 253
  25749. minLength: 1
  25750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25751. type: string
  25752. namespace:
  25753. description: |-
  25754. The namespace of the Secret resource being referred to.
  25755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25756. maxLength: 63
  25757. minLength: 1
  25758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25759. type: string
  25760. type: object
  25761. sessionTokenSecretRef:
  25762. description: |-
  25763. The SessionToken used for authentication
  25764. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25765. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25766. properties:
  25767. key:
  25768. description: |-
  25769. A key in the referenced Secret.
  25770. Some instances of this field may be defaulted, in others it may be required.
  25771. maxLength: 253
  25772. minLength: 1
  25773. pattern: ^[-._a-zA-Z0-9]+$
  25774. type: string
  25775. name:
  25776. description: The name of the Secret resource being referred to.
  25777. maxLength: 253
  25778. minLength: 1
  25779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25780. type: string
  25781. namespace:
  25782. description: |-
  25783. The namespace of the Secret resource being referred to.
  25784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25785. maxLength: 63
  25786. minLength: 1
  25787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25788. type: string
  25789. type: object
  25790. type: object
  25791. vaultAwsIamServerID:
  25792. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25793. type: string
  25794. vaultRole:
  25795. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25796. type: string
  25797. required:
  25798. - vaultRole
  25799. type: object
  25800. jwt:
  25801. description: |-
  25802. Jwt authenticates with Vault by passing role and JWT token using the
  25803. JWT/OIDC authentication method
  25804. properties:
  25805. kubernetesServiceAccountToken:
  25806. description: |-
  25807. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25808. a token for with the `TokenRequest` API.
  25809. properties:
  25810. audiences:
  25811. description: |-
  25812. Optional audiences field that will be used to request a temporary Kubernetes service
  25813. account token for the service account referenced by `serviceAccountRef`.
  25814. Defaults to a single audience `vault` it not specified.
  25815. Deprecated: use serviceAccountRef.Audiences instead
  25816. items:
  25817. type: string
  25818. type: array
  25819. expirationSeconds:
  25820. description: |-
  25821. Optional expiration time in seconds that will be used to request a temporary
  25822. Kubernetes service account token for the service account referenced by
  25823. `serviceAccountRef`.
  25824. Deprecated: this will be removed in the future.
  25825. Defaults to 10 minutes.
  25826. format: int64
  25827. type: integer
  25828. serviceAccountRef:
  25829. description: Service account field containing the name of a kubernetes ServiceAccount.
  25830. properties:
  25831. audiences:
  25832. description: |-
  25833. Audience specifies the `aud` claim for the service account token
  25834. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25835. then this audiences will be appended to the list
  25836. items:
  25837. type: string
  25838. type: array
  25839. name:
  25840. description: The name of the ServiceAccount resource being referred to.
  25841. maxLength: 253
  25842. minLength: 1
  25843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25844. type: string
  25845. namespace:
  25846. description: |-
  25847. Namespace of the resource being referred to.
  25848. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25849. maxLength: 63
  25850. minLength: 1
  25851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25852. type: string
  25853. required:
  25854. - name
  25855. type: object
  25856. required:
  25857. - serviceAccountRef
  25858. type: object
  25859. path:
  25860. default: jwt
  25861. description: |-
  25862. Path where the JWT authentication backend is mounted
  25863. in Vault, e.g: "jwt"
  25864. type: string
  25865. role:
  25866. description: |-
  25867. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25868. authentication method
  25869. type: string
  25870. secretRef:
  25871. description: |-
  25872. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25873. authenticate with Vault using the JWT/OIDC authentication method.
  25874. properties:
  25875. key:
  25876. description: |-
  25877. A key in the referenced Secret.
  25878. Some instances of this field may be defaulted, in others it may be required.
  25879. maxLength: 253
  25880. minLength: 1
  25881. pattern: ^[-._a-zA-Z0-9]+$
  25882. type: string
  25883. name:
  25884. description: The name of the Secret resource being referred to.
  25885. maxLength: 253
  25886. minLength: 1
  25887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25888. type: string
  25889. namespace:
  25890. description: |-
  25891. The namespace of the Secret resource being referred to.
  25892. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25893. maxLength: 63
  25894. minLength: 1
  25895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25896. type: string
  25897. type: object
  25898. required:
  25899. - path
  25900. type: object
  25901. kubernetes:
  25902. description: |-
  25903. Kubernetes authenticates with Vault by passing the ServiceAccount
  25904. token stored in the named Secret resource to the Vault server.
  25905. properties:
  25906. mountPath:
  25907. default: kubernetes
  25908. description: |-
  25909. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25910. "kubernetes"
  25911. type: string
  25912. role:
  25913. description: |-
  25914. A required field containing the Vault Role to assume. A Role binds a
  25915. Kubernetes ServiceAccount with a set of Vault policies.
  25916. type: string
  25917. secretRef:
  25918. description: |-
  25919. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25920. for authenticating with Vault. If a name is specified without a key,
  25921. `token` is the default. If one is not specified, the one bound to
  25922. the controller will be used.
  25923. properties:
  25924. key:
  25925. description: |-
  25926. A key in the referenced Secret.
  25927. Some instances of this field may be defaulted, in others it may be required.
  25928. maxLength: 253
  25929. minLength: 1
  25930. pattern: ^[-._a-zA-Z0-9]+$
  25931. type: string
  25932. name:
  25933. description: The name of the Secret resource being referred to.
  25934. maxLength: 253
  25935. minLength: 1
  25936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25937. type: string
  25938. namespace:
  25939. description: |-
  25940. The namespace of the Secret resource being referred to.
  25941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25942. maxLength: 63
  25943. minLength: 1
  25944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25945. type: string
  25946. type: object
  25947. serviceAccountRef:
  25948. description: |-
  25949. Optional service account field containing the name of a kubernetes ServiceAccount.
  25950. If the service account is specified, the service account secret token JWT will be used
  25951. for authenticating with Vault. If the service account selector is not supplied,
  25952. the secretRef will be used instead.
  25953. properties:
  25954. audiences:
  25955. description: |-
  25956. Audience specifies the `aud` claim for the service account token
  25957. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25958. then this audiences will be appended to the list
  25959. items:
  25960. type: string
  25961. type: array
  25962. name:
  25963. description: The name of the ServiceAccount resource being referred to.
  25964. maxLength: 253
  25965. minLength: 1
  25966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25967. type: string
  25968. namespace:
  25969. description: |-
  25970. Namespace of the resource being referred to.
  25971. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25972. maxLength: 63
  25973. minLength: 1
  25974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25975. type: string
  25976. required:
  25977. - name
  25978. type: object
  25979. required:
  25980. - mountPath
  25981. - role
  25982. type: object
  25983. ldap:
  25984. description: |-
  25985. Ldap authenticates with Vault by passing username/password pair using
  25986. the LDAP authentication method
  25987. properties:
  25988. path:
  25989. default: ldap
  25990. description: |-
  25991. Path where the LDAP authentication backend is mounted
  25992. in Vault, e.g: "ldap"
  25993. type: string
  25994. secretRef:
  25995. description: |-
  25996. SecretRef to a key in a Secret resource containing password for the LDAP
  25997. user used to authenticate with Vault using the LDAP authentication
  25998. method
  25999. properties:
  26000. key:
  26001. description: |-
  26002. A key in the referenced Secret.
  26003. Some instances of this field may be defaulted, in others it may be required.
  26004. maxLength: 253
  26005. minLength: 1
  26006. pattern: ^[-._a-zA-Z0-9]+$
  26007. type: string
  26008. name:
  26009. description: The name of the Secret resource being referred to.
  26010. maxLength: 253
  26011. minLength: 1
  26012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26013. type: string
  26014. namespace:
  26015. description: |-
  26016. The namespace of the Secret resource being referred to.
  26017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26018. maxLength: 63
  26019. minLength: 1
  26020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26021. type: string
  26022. type: object
  26023. username:
  26024. description: |-
  26025. Username is an LDAP username used to authenticate using the LDAP Vault
  26026. authentication method
  26027. type: string
  26028. required:
  26029. - path
  26030. - username
  26031. type: object
  26032. namespace:
  26033. description: |-
  26034. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26035. Namespaces is a set of features within Vault Enterprise that allows
  26036. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26037. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26038. This will default to Vault.Namespace field if set, or empty otherwise
  26039. type: string
  26040. tokenSecretRef:
  26041. description: TokenSecretRef authenticates with Vault by presenting a token.
  26042. properties:
  26043. key:
  26044. description: |-
  26045. A key in the referenced Secret.
  26046. Some instances of this field may be defaulted, in others it may be required.
  26047. maxLength: 253
  26048. minLength: 1
  26049. pattern: ^[-._a-zA-Z0-9]+$
  26050. type: string
  26051. name:
  26052. description: The name of the Secret resource being referred to.
  26053. maxLength: 253
  26054. minLength: 1
  26055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26056. type: string
  26057. namespace:
  26058. description: |-
  26059. The namespace of the Secret resource being referred to.
  26060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26061. maxLength: 63
  26062. minLength: 1
  26063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26064. type: string
  26065. type: object
  26066. userPass:
  26067. description: UserPass authenticates with Vault by passing username/password pair
  26068. properties:
  26069. path:
  26070. default: userpass
  26071. description: |-
  26072. Path where the UserPassword authentication backend is mounted
  26073. in Vault, e.g: "userpass"
  26074. type: string
  26075. secretRef:
  26076. description: |-
  26077. SecretRef to a key in a Secret resource containing password for the
  26078. user used to authenticate with Vault using the UserPass authentication
  26079. method
  26080. properties:
  26081. key:
  26082. description: |-
  26083. A key in the referenced Secret.
  26084. Some instances of this field may be defaulted, in others it may be required.
  26085. maxLength: 253
  26086. minLength: 1
  26087. pattern: ^[-._a-zA-Z0-9]+$
  26088. type: string
  26089. name:
  26090. description: The name of the Secret resource being referred to.
  26091. maxLength: 253
  26092. minLength: 1
  26093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26094. type: string
  26095. namespace:
  26096. description: |-
  26097. The namespace of the Secret resource being referred to.
  26098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26099. maxLength: 63
  26100. minLength: 1
  26101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26102. type: string
  26103. type: object
  26104. username:
  26105. description: |-
  26106. Username is a username used to authenticate using the UserPass Vault
  26107. authentication method
  26108. type: string
  26109. required:
  26110. - path
  26111. - username
  26112. type: object
  26113. type: object
  26114. caBundle:
  26115. description: |-
  26116. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26117. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26118. plain HTTP protocol connection. If not set the system root certificates
  26119. are used to validate the TLS connection.
  26120. format: byte
  26121. type: string
  26122. caProvider:
  26123. description: The provider for the CA bundle to use to validate Vault server certificate.
  26124. properties:
  26125. key:
  26126. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26127. maxLength: 253
  26128. minLength: 1
  26129. pattern: ^[-._a-zA-Z0-9]+$
  26130. type: string
  26131. name:
  26132. description: The name of the object located at the provider type.
  26133. maxLength: 253
  26134. minLength: 1
  26135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26136. type: string
  26137. namespace:
  26138. description: |-
  26139. The namespace the Provider type is in.
  26140. Can only be defined when used in a ClusterSecretStore.
  26141. maxLength: 63
  26142. minLength: 1
  26143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26144. type: string
  26145. type:
  26146. description: The type of provider to use such as "Secret", or "ConfigMap".
  26147. enum:
  26148. - Secret
  26149. - ConfigMap
  26150. type: string
  26151. required:
  26152. - name
  26153. - type
  26154. type: object
  26155. forwardInconsistent:
  26156. description: |-
  26157. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26158. leader instead of simply retrying within a loop. This can increase performance if
  26159. the option is enabled serverside.
  26160. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26161. type: boolean
  26162. headers:
  26163. additionalProperties:
  26164. type: string
  26165. description: Headers to be added in Vault request
  26166. type: object
  26167. namespace:
  26168. description: |-
  26169. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26170. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26171. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26172. type: string
  26173. path:
  26174. description: |-
  26175. Path is the mount path of the Vault KV backend endpoint, e.g:
  26176. "secret". The v2 KV secret engine version specific "/data" path suffix
  26177. for fetching secrets from Vault is optional and will be appended
  26178. if not present in specified path.
  26179. type: string
  26180. readYourWrites:
  26181. description: |-
  26182. ReadYourWrites ensures isolated read-after-write semantics by
  26183. providing discovered cluster replication states in each request.
  26184. More information about eventual consistency in Vault can be found here
  26185. https://www.vaultproject.io/docs/enterprise/consistency
  26186. type: boolean
  26187. server:
  26188. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26189. type: string
  26190. tls:
  26191. description: |-
  26192. The configuration used for client side related TLS communication, when the Vault server
  26193. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26194. This parameter is ignored for plain HTTP protocol connection.
  26195. It's worth noting this configuration is different from the "TLS certificates auth method",
  26196. which is available under the `auth.cert` section.
  26197. properties:
  26198. certSecretRef:
  26199. description: |-
  26200. CertSecretRef is a certificate added to the transport layer
  26201. when communicating with the Vault server.
  26202. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26203. properties:
  26204. key:
  26205. description: |-
  26206. A key in the referenced Secret.
  26207. Some instances of this field may be defaulted, in others it may be required.
  26208. maxLength: 253
  26209. minLength: 1
  26210. pattern: ^[-._a-zA-Z0-9]+$
  26211. type: string
  26212. name:
  26213. description: The name of the Secret resource being referred to.
  26214. maxLength: 253
  26215. minLength: 1
  26216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26217. type: string
  26218. namespace:
  26219. description: |-
  26220. The namespace of the Secret resource being referred to.
  26221. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26222. maxLength: 63
  26223. minLength: 1
  26224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26225. type: string
  26226. type: object
  26227. keySecretRef:
  26228. description: |-
  26229. KeySecretRef to a key in a Secret resource containing client private key
  26230. added to the transport layer when communicating with the Vault server.
  26231. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26232. properties:
  26233. key:
  26234. description: |-
  26235. A key in the referenced Secret.
  26236. Some instances of this field may be defaulted, in others it may be required.
  26237. maxLength: 253
  26238. minLength: 1
  26239. pattern: ^[-._a-zA-Z0-9]+$
  26240. type: string
  26241. name:
  26242. description: The name of the Secret resource being referred to.
  26243. maxLength: 253
  26244. minLength: 1
  26245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26246. type: string
  26247. namespace:
  26248. description: |-
  26249. The namespace of the Secret resource being referred to.
  26250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26251. maxLength: 63
  26252. minLength: 1
  26253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26254. type: string
  26255. type: object
  26256. type: object
  26257. version:
  26258. default: v2
  26259. description: |-
  26260. Version is the Vault KV secret engine version. This can be either "v1" or
  26261. "v2". Version defaults to "v2".
  26262. enum:
  26263. - v1
  26264. - v2
  26265. type: string
  26266. required:
  26267. - server
  26268. type: object
  26269. webhook:
  26270. description: Webhook configures this store to sync secrets using a generic templated webhook
  26271. properties:
  26272. auth:
  26273. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26274. maxProperties: 1
  26275. minProperties: 1
  26276. properties:
  26277. ntlm:
  26278. description: NTLMProtocol configures the store to use NTLM for auth
  26279. properties:
  26280. passwordSecret:
  26281. description: |-
  26282. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26283. In some instances, `key` is a required field.
  26284. properties:
  26285. key:
  26286. description: |-
  26287. A key in the referenced Secret.
  26288. Some instances of this field may be defaulted, in others it may be required.
  26289. maxLength: 253
  26290. minLength: 1
  26291. pattern: ^[-._a-zA-Z0-9]+$
  26292. type: string
  26293. name:
  26294. description: The name of the Secret resource being referred to.
  26295. maxLength: 253
  26296. minLength: 1
  26297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26298. type: string
  26299. namespace:
  26300. description: |-
  26301. The namespace of the Secret resource being referred to.
  26302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26303. maxLength: 63
  26304. minLength: 1
  26305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26306. type: string
  26307. type: object
  26308. usernameSecret:
  26309. description: |-
  26310. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26311. In some instances, `key` is a required field.
  26312. properties:
  26313. key:
  26314. description: |-
  26315. A key in the referenced Secret.
  26316. Some instances of this field may be defaulted, in others it may be required.
  26317. maxLength: 253
  26318. minLength: 1
  26319. pattern: ^[-._a-zA-Z0-9]+$
  26320. type: string
  26321. name:
  26322. description: The name of the Secret resource being referred to.
  26323. maxLength: 253
  26324. minLength: 1
  26325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26326. type: string
  26327. namespace:
  26328. description: |-
  26329. The namespace of the Secret resource being referred to.
  26330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26331. maxLength: 63
  26332. minLength: 1
  26333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26334. type: string
  26335. type: object
  26336. required:
  26337. - passwordSecret
  26338. - usernameSecret
  26339. type: object
  26340. type: object
  26341. body:
  26342. description: Body
  26343. type: string
  26344. caBundle:
  26345. description: |-
  26346. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26347. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26348. plain HTTP protocol connection. If not set the system root certificates
  26349. are used to validate the TLS connection.
  26350. format: byte
  26351. type: string
  26352. caProvider:
  26353. description: The provider for the CA bundle to use to validate webhook server certificate.
  26354. properties:
  26355. key:
  26356. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26357. maxLength: 253
  26358. minLength: 1
  26359. pattern: ^[-._a-zA-Z0-9]+$
  26360. type: string
  26361. name:
  26362. description: The name of the object located at the provider type.
  26363. maxLength: 253
  26364. minLength: 1
  26365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26366. type: string
  26367. namespace:
  26368. description: The namespace the Provider type is in.
  26369. maxLength: 63
  26370. minLength: 1
  26371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26372. type: string
  26373. type:
  26374. description: The type of provider to use such as "Secret", or "ConfigMap".
  26375. enum:
  26376. - Secret
  26377. - ConfigMap
  26378. type: string
  26379. required:
  26380. - name
  26381. - type
  26382. type: object
  26383. headers:
  26384. additionalProperties:
  26385. type: string
  26386. description: Headers
  26387. type: object
  26388. method:
  26389. description: Webhook Method
  26390. type: string
  26391. result:
  26392. description: Result formatting
  26393. properties:
  26394. jsonPath:
  26395. description: Json path of return value
  26396. type: string
  26397. type: object
  26398. secrets:
  26399. description: |-
  26400. Secrets to fill in templates
  26401. These secrets will be passed to the templating function as key value pairs under the given name
  26402. items:
  26403. description: WebhookSecret defines a secret to be used in webhook templates.
  26404. properties:
  26405. name:
  26406. description: Name of this secret in templates
  26407. type: string
  26408. secretRef:
  26409. description: Secret ref to fill in credentials
  26410. properties:
  26411. key:
  26412. description: |-
  26413. A key in the referenced Secret.
  26414. Some instances of this field may be defaulted, in others it may be required.
  26415. maxLength: 253
  26416. minLength: 1
  26417. pattern: ^[-._a-zA-Z0-9]+$
  26418. type: string
  26419. name:
  26420. description: The name of the Secret resource being referred to.
  26421. maxLength: 253
  26422. minLength: 1
  26423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26424. type: string
  26425. namespace:
  26426. description: |-
  26427. The namespace of the Secret resource being referred to.
  26428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26429. maxLength: 63
  26430. minLength: 1
  26431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26432. type: string
  26433. type: object
  26434. required:
  26435. - name
  26436. - secretRef
  26437. type: object
  26438. type: array
  26439. timeout:
  26440. description: Timeout
  26441. type: string
  26442. url:
  26443. description: Webhook url to call
  26444. type: string
  26445. required:
  26446. - result
  26447. - url
  26448. type: object
  26449. yandexcertificatemanager:
  26450. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26451. properties:
  26452. apiEndpoint:
  26453. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26454. type: string
  26455. auth:
  26456. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26457. properties:
  26458. authorizedKeySecretRef:
  26459. description: The authorized key used for authentication
  26460. properties:
  26461. key:
  26462. description: |-
  26463. A key in the referenced Secret.
  26464. Some instances of this field may be defaulted, in others it may be required.
  26465. maxLength: 253
  26466. minLength: 1
  26467. pattern: ^[-._a-zA-Z0-9]+$
  26468. type: string
  26469. name:
  26470. description: The name of the Secret resource being referred to.
  26471. maxLength: 253
  26472. minLength: 1
  26473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26474. type: string
  26475. namespace:
  26476. description: |-
  26477. The namespace of the Secret resource being referred to.
  26478. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26479. maxLength: 63
  26480. minLength: 1
  26481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26482. type: string
  26483. type: object
  26484. type: object
  26485. caProvider:
  26486. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26487. properties:
  26488. certSecretRef:
  26489. description: |-
  26490. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26491. In some instances, `key` is a required field.
  26492. properties:
  26493. key:
  26494. description: |-
  26495. A key in the referenced Secret.
  26496. Some instances of this field may be defaulted, in others it may be required.
  26497. maxLength: 253
  26498. minLength: 1
  26499. pattern: ^[-._a-zA-Z0-9]+$
  26500. type: string
  26501. name:
  26502. description: The name of the Secret resource being referred to.
  26503. maxLength: 253
  26504. minLength: 1
  26505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26506. type: string
  26507. namespace:
  26508. description: |-
  26509. The namespace of the Secret resource being referred to.
  26510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26511. maxLength: 63
  26512. minLength: 1
  26513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26514. type: string
  26515. type: object
  26516. type: object
  26517. required:
  26518. - auth
  26519. type: object
  26520. yandexlockbox:
  26521. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26522. properties:
  26523. apiEndpoint:
  26524. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26525. type: string
  26526. auth:
  26527. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26528. properties:
  26529. authorizedKeySecretRef:
  26530. description: The authorized key used for authentication
  26531. properties:
  26532. key:
  26533. description: |-
  26534. A key in the referenced Secret.
  26535. Some instances of this field may be defaulted, in others it may be required.
  26536. maxLength: 253
  26537. minLength: 1
  26538. pattern: ^[-._a-zA-Z0-9]+$
  26539. type: string
  26540. name:
  26541. description: The name of the Secret resource being referred to.
  26542. maxLength: 253
  26543. minLength: 1
  26544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26545. type: string
  26546. namespace:
  26547. description: |-
  26548. The namespace of the Secret resource being referred to.
  26549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26550. maxLength: 63
  26551. minLength: 1
  26552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26553. type: string
  26554. type: object
  26555. type: object
  26556. caProvider:
  26557. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26558. properties:
  26559. certSecretRef:
  26560. description: |-
  26561. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26562. In some instances, `key` is a required field.
  26563. properties:
  26564. key:
  26565. description: |-
  26566. A key in the referenced Secret.
  26567. Some instances of this field may be defaulted, in others it may be required.
  26568. maxLength: 253
  26569. minLength: 1
  26570. pattern: ^[-._a-zA-Z0-9]+$
  26571. type: string
  26572. name:
  26573. description: The name of the Secret resource being referred to.
  26574. maxLength: 253
  26575. minLength: 1
  26576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26577. type: string
  26578. namespace:
  26579. description: |-
  26580. The namespace of the Secret resource being referred to.
  26581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26582. maxLength: 63
  26583. minLength: 1
  26584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26585. type: string
  26586. type: object
  26587. type: object
  26588. required:
  26589. - auth
  26590. type: object
  26591. type: object
  26592. refreshInterval:
  26593. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26594. type: integer
  26595. retrySettings:
  26596. description: Used to configure HTTP retries on failures.
  26597. properties:
  26598. maxRetries:
  26599. description: MaxRetries is the maximum number of retry attempts.
  26600. format: int32
  26601. type: integer
  26602. retryInterval:
  26603. description: RetryInterval is the interval between retry attempts.
  26604. type: string
  26605. type: object
  26606. required:
  26607. - provider
  26608. type: object
  26609. status:
  26610. description: SecretStoreStatus defines the observed state of the SecretStore.
  26611. properties:
  26612. capabilities:
  26613. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26614. type: string
  26615. conditions:
  26616. items:
  26617. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26618. properties:
  26619. lastTransitionTime:
  26620. format: date-time
  26621. type: string
  26622. message:
  26623. type: string
  26624. reason:
  26625. type: string
  26626. status:
  26627. type: string
  26628. type:
  26629. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26630. type: string
  26631. required:
  26632. - status
  26633. - type
  26634. type: object
  26635. type: array
  26636. type: object
  26637. type: object
  26638. served: false
  26639. storage: false
  26640. subresources:
  26641. status: {}
  26642. ---
  26643. apiVersion: apiextensions.k8s.io/v1
  26644. kind: CustomResourceDefinition
  26645. metadata:
  26646. annotations:
  26647. controller-gen.kubebuilder.io/version: v0.19.0
  26648. labels:
  26649. external-secrets.io/component: controller
  26650. name: acraccesstokens.generators.external-secrets.io
  26651. spec:
  26652. group: generators.external-secrets.io
  26653. names:
  26654. categories:
  26655. - external-secrets
  26656. - external-secrets-generators
  26657. kind: ACRAccessToken
  26658. listKind: ACRAccessTokenList
  26659. plural: acraccesstokens
  26660. singular: acraccesstoken
  26661. scope: Namespaced
  26662. versions:
  26663. - name: v1alpha1
  26664. schema:
  26665. openAPIV3Schema:
  26666. description: |-
  26667. ACRAccessToken returns an Azure Container Registry token
  26668. that can be used for pushing/pulling images.
  26669. Note: by default it will return an ACR Refresh Token with full access
  26670. (depending on the identity).
  26671. This can be scoped down to the repository level using .spec.scope.
  26672. In case scope is defined it will return an ACR Access Token.
  26673. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26674. properties:
  26675. apiVersion:
  26676. description: |-
  26677. APIVersion defines the versioned schema of this representation of an object.
  26678. Servers should convert recognized schemas to the latest internal value, and
  26679. may reject unrecognized values.
  26680. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26681. type: string
  26682. kind:
  26683. description: |-
  26684. Kind is a string value representing the REST resource this object represents.
  26685. Servers may infer this from the endpoint the client submits requests to.
  26686. Cannot be updated.
  26687. In CamelCase.
  26688. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26689. type: string
  26690. metadata:
  26691. type: object
  26692. spec:
  26693. description: |-
  26694. ACRAccessTokenSpec defines how to generate the access token
  26695. e.g. how to authenticate and which registry to use.
  26696. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26697. properties:
  26698. auth:
  26699. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26700. properties:
  26701. managedIdentity:
  26702. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26703. properties:
  26704. identityId:
  26705. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26706. type: string
  26707. type: object
  26708. servicePrincipal:
  26709. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26710. properties:
  26711. secretRef:
  26712. description: |-
  26713. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26714. It uses static credentials stored in a Kind=Secret.
  26715. properties:
  26716. clientId:
  26717. description: The Azure clientId of the service principle used for authentication.
  26718. properties:
  26719. key:
  26720. description: |-
  26721. A key in the referenced Secret.
  26722. Some instances of this field may be defaulted, in others it may be required.
  26723. maxLength: 253
  26724. minLength: 1
  26725. pattern: ^[-._a-zA-Z0-9]+$
  26726. type: string
  26727. name:
  26728. description: The name of the Secret resource being referred to.
  26729. maxLength: 253
  26730. minLength: 1
  26731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26732. type: string
  26733. namespace:
  26734. description: |-
  26735. The namespace of the Secret resource being referred to.
  26736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26737. maxLength: 63
  26738. minLength: 1
  26739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26740. type: string
  26741. type: object
  26742. clientSecret:
  26743. description: The Azure ClientSecret of the service principle used for authentication.
  26744. properties:
  26745. key:
  26746. description: |-
  26747. A key in the referenced Secret.
  26748. Some instances of this field may be defaulted, in others it may be required.
  26749. maxLength: 253
  26750. minLength: 1
  26751. pattern: ^[-._a-zA-Z0-9]+$
  26752. type: string
  26753. name:
  26754. description: The name of the Secret resource being referred to.
  26755. maxLength: 253
  26756. minLength: 1
  26757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26758. type: string
  26759. namespace:
  26760. description: |-
  26761. The namespace of the Secret resource being referred to.
  26762. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26763. maxLength: 63
  26764. minLength: 1
  26765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26766. type: string
  26767. type: object
  26768. type: object
  26769. required:
  26770. - secretRef
  26771. type: object
  26772. workloadIdentity:
  26773. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26774. properties:
  26775. serviceAccountRef:
  26776. description: |-
  26777. ServiceAccountRef specified the service account
  26778. that should be used when authenticating with WorkloadIdentity.
  26779. properties:
  26780. audiences:
  26781. description: |-
  26782. Audience specifies the `aud` claim for the service account token
  26783. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26784. then this audiences will be appended to the list
  26785. items:
  26786. type: string
  26787. type: array
  26788. name:
  26789. description: The name of the ServiceAccount resource being referred to.
  26790. maxLength: 253
  26791. minLength: 1
  26792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26793. type: string
  26794. namespace:
  26795. description: |-
  26796. Namespace of the resource being referred to.
  26797. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26798. maxLength: 63
  26799. minLength: 1
  26800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26801. type: string
  26802. required:
  26803. - name
  26804. type: object
  26805. type: object
  26806. type: object
  26807. environmentType:
  26808. default: PublicCloud
  26809. description: |-
  26810. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26811. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26812. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26813. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26814. enum:
  26815. - PublicCloud
  26816. - USGovernmentCloud
  26817. - ChinaCloud
  26818. - GermanCloud
  26819. - AzureStackCloud
  26820. type: string
  26821. registry:
  26822. description: |-
  26823. the domain name of the ACR registry
  26824. e.g. foobarexample.azurecr.io
  26825. type: string
  26826. scope:
  26827. description: |-
  26828. Define the scope for the access token, e.g. pull/push access for a repository.
  26829. if not provided it will return a refresh token that has full scope.
  26830. Note: you need to pin it down to the repository level, there is no wildcard available.
  26831. examples:
  26832. repository:my-repository:pull,push
  26833. repository:my-repository:pull
  26834. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26835. type: string
  26836. tenantId:
  26837. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26838. type: string
  26839. required:
  26840. - auth
  26841. - registry
  26842. type: object
  26843. type: object
  26844. served: true
  26845. storage: true
  26846. subresources:
  26847. status: {}
  26848. ---
  26849. apiVersion: apiextensions.k8s.io/v1
  26850. kind: CustomResourceDefinition
  26851. metadata:
  26852. annotations:
  26853. controller-gen.kubebuilder.io/version: v0.19.0
  26854. labels:
  26855. external-secrets.io/component: controller
  26856. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26857. spec:
  26858. group: generators.external-secrets.io
  26859. names:
  26860. categories:
  26861. - external-secrets
  26862. - external-secrets-generators
  26863. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26864. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26865. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26866. singular: beyondtrustworkloadcredentialsdynamicsecret
  26867. scope: Namespaced
  26868. versions:
  26869. - name: v1alpha1
  26870. schema:
  26871. openAPIV3Schema:
  26872. description: |-
  26873. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26874. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26875. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26876. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26877. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26878. properties:
  26879. apiVersion:
  26880. description: |-
  26881. APIVersion defines the versioned schema of this representation of an object.
  26882. Servers should convert recognized schemas to the latest internal value, and
  26883. may reject unrecognized values.
  26884. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26885. type: string
  26886. kind:
  26887. description: |-
  26888. Kind is a string value representing the REST resource this object represents.
  26889. Servers may infer this from the endpoint the client submits requests to.
  26890. Cannot be updated.
  26891. In CamelCase.
  26892. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26893. type: string
  26894. metadata:
  26895. type: object
  26896. spec:
  26897. description: |-
  26898. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26899. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26900. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26901. properties:
  26902. controller:
  26903. description: |-
  26904. Controller selects the controller that should handle this generator.
  26905. Leave empty to use the default controller.
  26906. type: string
  26907. provider:
  26908. description: |-
  26909. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26910. server connection details, and the folder path to the dynamic secret definition.
  26911. The folderPath should point to a dynamic secret definition that has been created in
  26912. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26913. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26914. properties:
  26915. auth:
  26916. description: |-
  26917. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26918. Currently supports API key authentication via Kubernetes secret reference.
  26919. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26920. properties:
  26921. apikey:
  26922. description: |-
  26923. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26924. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26925. properties:
  26926. token:
  26927. description: |-
  26928. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26929. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26930. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26931. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26932. properties:
  26933. key:
  26934. description: |-
  26935. A key in the referenced Secret.
  26936. Some instances of this field may be defaulted, in others it may be required.
  26937. maxLength: 253
  26938. minLength: 1
  26939. pattern: ^[-._a-zA-Z0-9]+$
  26940. type: string
  26941. name:
  26942. description: The name of the Secret resource being referred to.
  26943. maxLength: 253
  26944. minLength: 1
  26945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26946. type: string
  26947. namespace:
  26948. description: |-
  26949. The namespace of the Secret resource being referred to.
  26950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26951. maxLength: 63
  26952. minLength: 1
  26953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26954. type: string
  26955. type: object
  26956. required:
  26957. - token
  26958. type: object
  26959. required:
  26960. - apikey
  26961. type: object
  26962. caBundle:
  26963. description: |-
  26964. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26965. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26966. If not set, the system's trusted root certificates are used.
  26967. format: byte
  26968. type: string
  26969. caProvider:
  26970. description: |-
  26971. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26972. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26973. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26974. properties:
  26975. key:
  26976. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26977. maxLength: 253
  26978. minLength: 1
  26979. pattern: ^[-._a-zA-Z0-9]+$
  26980. type: string
  26981. name:
  26982. description: The name of the object located at the provider type.
  26983. maxLength: 253
  26984. minLength: 1
  26985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26986. type: string
  26987. namespace:
  26988. description: |-
  26989. The namespace the Provider type is in.
  26990. Can only be defined when used in a ClusterSecretStore.
  26991. maxLength: 63
  26992. minLength: 1
  26993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26994. type: string
  26995. type:
  26996. description: The type of provider to use such as "Secret", or "ConfigMap".
  26997. enum:
  26998. - Secret
  26999. - ConfigMap
  27000. type: string
  27001. required:
  27002. - name
  27003. - type
  27004. type: object
  27005. folderPath:
  27006. description: |-
  27007. FolderPath specifies the default folder path for secret retrieval.
  27008. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27009. Example: "production/database" or "dev/api-keys"
  27010. Leave empty to retrieve secrets from the root folder.
  27011. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27012. type: string
  27013. server:
  27014. description: |-
  27015. Server configures the BeyondTrust Workload Credentials server connection details.
  27016. Includes the API URL and Site ID for your BeyondTrust instance.
  27017. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27018. properties:
  27019. apiUrl:
  27020. description: |-
  27021. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27022. This should be the full URL to your BeyondTrust instance.
  27023. Example: https://api.beyondtrust.io/siie
  27024. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27025. type: string
  27026. siteId:
  27027. description: |-
  27028. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27029. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27030. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27031. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27032. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27033. type: string
  27034. required:
  27035. - apiUrl
  27036. - siteId
  27037. type: object
  27038. required:
  27039. - auth
  27040. - server
  27041. type: object
  27042. retrySettings:
  27043. description: |-
  27044. RetrySettings configures exponential backoff for failed API requests.
  27045. If not specified, uses the default retry settings.
  27046. properties:
  27047. maxRetries:
  27048. format: int32
  27049. type: integer
  27050. retryInterval:
  27051. type: string
  27052. type: object
  27053. required:
  27054. - provider
  27055. type: object
  27056. type: object
  27057. served: true
  27058. storage: true
  27059. subresources:
  27060. status: {}
  27061. ---
  27062. apiVersion: apiextensions.k8s.io/v1
  27063. kind: CustomResourceDefinition
  27064. metadata:
  27065. annotations:
  27066. controller-gen.kubebuilder.io/version: v0.19.0
  27067. labels:
  27068. external-secrets.io/component: controller
  27069. name: cloudsmithaccesstokens.generators.external-secrets.io
  27070. spec:
  27071. group: generators.external-secrets.io
  27072. names:
  27073. categories:
  27074. - external-secrets
  27075. - external-secrets-generators
  27076. kind: CloudsmithAccessToken
  27077. listKind: CloudsmithAccessTokenList
  27078. plural: cloudsmithaccesstokens
  27079. singular: cloudsmithaccesstoken
  27080. scope: Namespaced
  27081. versions:
  27082. - name: v1alpha1
  27083. schema:
  27084. openAPIV3Schema:
  27085. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27086. properties:
  27087. apiVersion:
  27088. description: |-
  27089. APIVersion defines the versioned schema of this representation of an object.
  27090. Servers should convert recognized schemas to the latest internal value, and
  27091. may reject unrecognized values.
  27092. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27093. type: string
  27094. kind:
  27095. description: |-
  27096. Kind is a string value representing the REST resource this object represents.
  27097. Servers may infer this from the endpoint the client submits requests to.
  27098. Cannot be updated.
  27099. In CamelCase.
  27100. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27101. type: string
  27102. metadata:
  27103. type: object
  27104. spec:
  27105. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27106. properties:
  27107. apiUrl:
  27108. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27109. type: string
  27110. orgSlug:
  27111. description: OrgSlug is the organization slug in Cloudsmith
  27112. type: string
  27113. serviceAccountRef:
  27114. description: Name of the service account you are federating with
  27115. properties:
  27116. audiences:
  27117. description: |-
  27118. Audience specifies the `aud` claim for the service account token
  27119. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27120. then this audiences will be appended to the list
  27121. items:
  27122. type: string
  27123. type: array
  27124. name:
  27125. description: The name of the ServiceAccount resource being referred to.
  27126. maxLength: 253
  27127. minLength: 1
  27128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27129. type: string
  27130. namespace:
  27131. description: |-
  27132. Namespace of the resource being referred to.
  27133. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27134. maxLength: 63
  27135. minLength: 1
  27136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27137. type: string
  27138. required:
  27139. - name
  27140. type: object
  27141. serviceSlug:
  27142. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27143. type: string
  27144. required:
  27145. - orgSlug
  27146. - serviceAccountRef
  27147. - serviceSlug
  27148. type: object
  27149. type: object
  27150. served: true
  27151. storage: true
  27152. subresources:
  27153. status: {}
  27154. ---
  27155. apiVersion: apiextensions.k8s.io/v1
  27156. kind: CustomResourceDefinition
  27157. metadata:
  27158. annotations:
  27159. controller-gen.kubebuilder.io/version: v0.19.0
  27160. labels:
  27161. external-secrets.io/component: controller
  27162. name: clustergenerators.generators.external-secrets.io
  27163. spec:
  27164. group: generators.external-secrets.io
  27165. names:
  27166. categories:
  27167. - external-secrets
  27168. - external-secrets-generators
  27169. kind: ClusterGenerator
  27170. listKind: ClusterGeneratorList
  27171. plural: clustergenerators
  27172. singular: clustergenerator
  27173. scope: Cluster
  27174. versions:
  27175. - name: v1alpha1
  27176. schema:
  27177. openAPIV3Schema:
  27178. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27179. properties:
  27180. apiVersion:
  27181. description: |-
  27182. APIVersion defines the versioned schema of this representation of an object.
  27183. Servers should convert recognized schemas to the latest internal value, and
  27184. may reject unrecognized values.
  27185. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27186. type: string
  27187. kind:
  27188. description: |-
  27189. Kind is a string value representing the REST resource this object represents.
  27190. Servers may infer this from the endpoint the client submits requests to.
  27191. Cannot be updated.
  27192. In CamelCase.
  27193. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27194. type: string
  27195. metadata:
  27196. type: object
  27197. spec:
  27198. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27199. properties:
  27200. generator:
  27201. description: Generator the spec for this generator, must match the kind.
  27202. maxProperties: 1
  27203. minProperties: 1
  27204. properties:
  27205. acrAccessTokenSpec:
  27206. description: |-
  27207. ACRAccessTokenSpec defines how to generate the access token
  27208. e.g. how to authenticate and which registry to use.
  27209. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27210. properties:
  27211. auth:
  27212. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27213. properties:
  27214. managedIdentity:
  27215. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27216. properties:
  27217. identityId:
  27218. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27219. type: string
  27220. type: object
  27221. servicePrincipal:
  27222. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27223. properties:
  27224. secretRef:
  27225. description: |-
  27226. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27227. It uses static credentials stored in a Kind=Secret.
  27228. properties:
  27229. clientId:
  27230. description: The Azure clientId of the service principle used for authentication.
  27231. properties:
  27232. key:
  27233. description: |-
  27234. A key in the referenced Secret.
  27235. Some instances of this field may be defaulted, in others it may be required.
  27236. maxLength: 253
  27237. minLength: 1
  27238. pattern: ^[-._a-zA-Z0-9]+$
  27239. type: string
  27240. name:
  27241. description: The name of the Secret resource being referred to.
  27242. maxLength: 253
  27243. minLength: 1
  27244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27245. type: string
  27246. namespace:
  27247. description: |-
  27248. The namespace of the Secret resource being referred to.
  27249. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27250. maxLength: 63
  27251. minLength: 1
  27252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27253. type: string
  27254. type: object
  27255. clientSecret:
  27256. description: The Azure ClientSecret of the service principle used for authentication.
  27257. properties:
  27258. key:
  27259. description: |-
  27260. A key in the referenced Secret.
  27261. Some instances of this field may be defaulted, in others it may be required.
  27262. maxLength: 253
  27263. minLength: 1
  27264. pattern: ^[-._a-zA-Z0-9]+$
  27265. type: string
  27266. name:
  27267. description: The name of the Secret resource being referred to.
  27268. maxLength: 253
  27269. minLength: 1
  27270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27271. type: string
  27272. namespace:
  27273. description: |-
  27274. The namespace of the Secret resource being referred to.
  27275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27276. maxLength: 63
  27277. minLength: 1
  27278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27279. type: string
  27280. type: object
  27281. type: object
  27282. required:
  27283. - secretRef
  27284. type: object
  27285. workloadIdentity:
  27286. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27287. properties:
  27288. serviceAccountRef:
  27289. description: |-
  27290. ServiceAccountRef specified the service account
  27291. that should be used when authenticating with WorkloadIdentity.
  27292. properties:
  27293. audiences:
  27294. description: |-
  27295. Audience specifies the `aud` claim for the service account token
  27296. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27297. then this audiences will be appended to the list
  27298. items:
  27299. type: string
  27300. type: array
  27301. name:
  27302. description: The name of the ServiceAccount resource being referred to.
  27303. maxLength: 253
  27304. minLength: 1
  27305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27306. type: string
  27307. namespace:
  27308. description: |-
  27309. Namespace of the resource being referred to.
  27310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27311. maxLength: 63
  27312. minLength: 1
  27313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27314. type: string
  27315. required:
  27316. - name
  27317. type: object
  27318. type: object
  27319. type: object
  27320. environmentType:
  27321. default: PublicCloud
  27322. description: |-
  27323. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27324. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27325. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27326. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27327. enum:
  27328. - PublicCloud
  27329. - USGovernmentCloud
  27330. - ChinaCloud
  27331. - GermanCloud
  27332. - AzureStackCloud
  27333. type: string
  27334. registry:
  27335. description: |-
  27336. the domain name of the ACR registry
  27337. e.g. foobarexample.azurecr.io
  27338. type: string
  27339. scope:
  27340. description: |-
  27341. Define the scope for the access token, e.g. pull/push access for a repository.
  27342. if not provided it will return a refresh token that has full scope.
  27343. Note: you need to pin it down to the repository level, there is no wildcard available.
  27344. examples:
  27345. repository:my-repository:pull,push
  27346. repository:my-repository:pull
  27347. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27348. type: string
  27349. tenantId:
  27350. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27351. type: string
  27352. required:
  27353. - auth
  27354. - registry
  27355. type: object
  27356. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27357. description: |-
  27358. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27359. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27360. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27361. properties:
  27362. controller:
  27363. description: |-
  27364. Controller selects the controller that should handle this generator.
  27365. Leave empty to use the default controller.
  27366. type: string
  27367. provider:
  27368. description: |-
  27369. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27370. server connection details, and the folder path to the dynamic secret definition.
  27371. The folderPath should point to a dynamic secret definition that has been created in
  27372. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27373. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27374. properties:
  27375. auth:
  27376. description: |-
  27377. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27378. Currently supports API key authentication via Kubernetes secret reference.
  27379. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27380. properties:
  27381. apikey:
  27382. description: |-
  27383. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27384. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27385. properties:
  27386. token:
  27387. description: |-
  27388. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27389. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27390. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27391. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27392. properties:
  27393. key:
  27394. description: |-
  27395. A key in the referenced Secret.
  27396. Some instances of this field may be defaulted, in others it may be required.
  27397. maxLength: 253
  27398. minLength: 1
  27399. pattern: ^[-._a-zA-Z0-9]+$
  27400. type: string
  27401. name:
  27402. description: The name of the Secret resource being referred to.
  27403. maxLength: 253
  27404. minLength: 1
  27405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27406. type: string
  27407. namespace:
  27408. description: |-
  27409. The namespace of the Secret resource being referred to.
  27410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27411. maxLength: 63
  27412. minLength: 1
  27413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27414. type: string
  27415. type: object
  27416. required:
  27417. - token
  27418. type: object
  27419. required:
  27420. - apikey
  27421. type: object
  27422. caBundle:
  27423. description: |-
  27424. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27425. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27426. If not set, the system's trusted root certificates are used.
  27427. format: byte
  27428. type: string
  27429. caProvider:
  27430. description: |-
  27431. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27432. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27433. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27434. properties:
  27435. key:
  27436. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27437. maxLength: 253
  27438. minLength: 1
  27439. pattern: ^[-._a-zA-Z0-9]+$
  27440. type: string
  27441. name:
  27442. description: The name of the object located at the provider type.
  27443. maxLength: 253
  27444. minLength: 1
  27445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27446. type: string
  27447. namespace:
  27448. description: |-
  27449. The namespace the Provider type is in.
  27450. Can only be defined when used in a ClusterSecretStore.
  27451. maxLength: 63
  27452. minLength: 1
  27453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27454. type: string
  27455. type:
  27456. description: The type of provider to use such as "Secret", or "ConfigMap".
  27457. enum:
  27458. - Secret
  27459. - ConfigMap
  27460. type: string
  27461. required:
  27462. - name
  27463. - type
  27464. type: object
  27465. folderPath:
  27466. description: |-
  27467. FolderPath specifies the default folder path for secret retrieval.
  27468. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27469. Example: "production/database" or "dev/api-keys"
  27470. Leave empty to retrieve secrets from the root folder.
  27471. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27472. type: string
  27473. server:
  27474. description: |-
  27475. Server configures the BeyondTrust Workload Credentials server connection details.
  27476. Includes the API URL and Site ID for your BeyondTrust instance.
  27477. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27478. properties:
  27479. apiUrl:
  27480. description: |-
  27481. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27482. This should be the full URL to your BeyondTrust instance.
  27483. Example: https://api.beyondtrust.io/siie
  27484. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27485. type: string
  27486. siteId:
  27487. description: |-
  27488. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27489. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27490. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27491. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27492. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27493. type: string
  27494. required:
  27495. - apiUrl
  27496. - siteId
  27497. type: object
  27498. required:
  27499. - auth
  27500. - server
  27501. type: object
  27502. retrySettings:
  27503. description: |-
  27504. RetrySettings configures exponential backoff for failed API requests.
  27505. If not specified, uses the default retry settings.
  27506. properties:
  27507. maxRetries:
  27508. format: int32
  27509. type: integer
  27510. retryInterval:
  27511. type: string
  27512. type: object
  27513. required:
  27514. - provider
  27515. type: object
  27516. cloudsmithAccessTokenSpec:
  27517. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27518. properties:
  27519. apiUrl:
  27520. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27521. type: string
  27522. orgSlug:
  27523. description: OrgSlug is the organization slug in Cloudsmith
  27524. type: string
  27525. serviceAccountRef:
  27526. description: Name of the service account you are federating with
  27527. properties:
  27528. audiences:
  27529. description: |-
  27530. Audience specifies the `aud` claim for the service account token
  27531. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27532. then this audiences will be appended to the list
  27533. items:
  27534. type: string
  27535. type: array
  27536. name:
  27537. description: The name of the ServiceAccount resource being referred to.
  27538. maxLength: 253
  27539. minLength: 1
  27540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27541. type: string
  27542. namespace:
  27543. description: |-
  27544. Namespace of the resource being referred to.
  27545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27546. maxLength: 63
  27547. minLength: 1
  27548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27549. type: string
  27550. required:
  27551. - name
  27552. type: object
  27553. serviceSlug:
  27554. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27555. type: string
  27556. required:
  27557. - orgSlug
  27558. - serviceAccountRef
  27559. - serviceSlug
  27560. type: object
  27561. ecrAuthorizationTokenSpec:
  27562. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27563. properties:
  27564. auth:
  27565. description: Auth defines how to authenticate with AWS
  27566. properties:
  27567. jwt:
  27568. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27569. properties:
  27570. serviceAccountRef:
  27571. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27572. properties:
  27573. audiences:
  27574. description: |-
  27575. Audience specifies the `aud` claim for the service account token
  27576. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27577. then this audiences will be appended to the list
  27578. items:
  27579. type: string
  27580. type: array
  27581. name:
  27582. description: The name of the ServiceAccount resource being referred to.
  27583. maxLength: 253
  27584. minLength: 1
  27585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27586. type: string
  27587. namespace:
  27588. description: |-
  27589. Namespace of the resource being referred to.
  27590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27591. maxLength: 63
  27592. minLength: 1
  27593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27594. type: string
  27595. required:
  27596. - name
  27597. type: object
  27598. type: object
  27599. secretRef:
  27600. description: |-
  27601. AWSAuthSecretRef holds secret references for AWS credentials
  27602. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27603. properties:
  27604. accessKeyIDSecretRef:
  27605. description: The AccessKeyID is used for authentication
  27606. properties:
  27607. key:
  27608. description: |-
  27609. A key in the referenced Secret.
  27610. Some instances of this field may be defaulted, in others it may be required.
  27611. maxLength: 253
  27612. minLength: 1
  27613. pattern: ^[-._a-zA-Z0-9]+$
  27614. type: string
  27615. name:
  27616. description: The name of the Secret resource being referred to.
  27617. maxLength: 253
  27618. minLength: 1
  27619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27620. type: string
  27621. namespace:
  27622. description: |-
  27623. The namespace of the Secret resource being referred to.
  27624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27625. maxLength: 63
  27626. minLength: 1
  27627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27628. type: string
  27629. type: object
  27630. secretAccessKeySecretRef:
  27631. description: The SecretAccessKey is used for authentication
  27632. properties:
  27633. key:
  27634. description: |-
  27635. A key in the referenced Secret.
  27636. Some instances of this field may be defaulted, in others it may be required.
  27637. maxLength: 253
  27638. minLength: 1
  27639. pattern: ^[-._a-zA-Z0-9]+$
  27640. type: string
  27641. name:
  27642. description: The name of the Secret resource being referred to.
  27643. maxLength: 253
  27644. minLength: 1
  27645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27646. type: string
  27647. namespace:
  27648. description: |-
  27649. The namespace of the Secret resource being referred to.
  27650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27651. maxLength: 63
  27652. minLength: 1
  27653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27654. type: string
  27655. type: object
  27656. sessionTokenSecretRef:
  27657. description: |-
  27658. The SessionToken used for authentication
  27659. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27660. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27661. properties:
  27662. key:
  27663. description: |-
  27664. A key in the referenced Secret.
  27665. Some instances of this field may be defaulted, in others it may be required.
  27666. maxLength: 253
  27667. minLength: 1
  27668. pattern: ^[-._a-zA-Z0-9]+$
  27669. type: string
  27670. name:
  27671. description: The name of the Secret resource being referred to.
  27672. maxLength: 253
  27673. minLength: 1
  27674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27675. type: string
  27676. namespace:
  27677. description: |-
  27678. The namespace of the Secret resource being referred to.
  27679. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27680. maxLength: 63
  27681. minLength: 1
  27682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27683. type: string
  27684. type: object
  27685. type: object
  27686. type: object
  27687. region:
  27688. description: Region specifies the region to operate in.
  27689. type: string
  27690. role:
  27691. description: |-
  27692. You can assume a role before making calls to the
  27693. desired AWS service.
  27694. type: string
  27695. scope:
  27696. description: |-
  27697. Scope specifies the ECR service scope.
  27698. Valid options are private and public.
  27699. type: string
  27700. required:
  27701. - region
  27702. type: object
  27703. fakeSpec:
  27704. description: FakeSpec contains the static data.
  27705. properties:
  27706. controller:
  27707. description: |-
  27708. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27709. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27710. type: string
  27711. data:
  27712. additionalProperties:
  27713. type: string
  27714. description: |-
  27715. Data defines the static data returned
  27716. by this generator.
  27717. type: object
  27718. type: object
  27719. gcrAccessTokenSpec:
  27720. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27721. properties:
  27722. auth:
  27723. description: Auth defines the means for authenticating with GCP
  27724. properties:
  27725. secretRef:
  27726. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27727. properties:
  27728. secretAccessKeySecretRef:
  27729. description: The SecretAccessKey is used for authentication
  27730. properties:
  27731. key:
  27732. description: |-
  27733. A key in the referenced Secret.
  27734. Some instances of this field may be defaulted, in others it may be required.
  27735. maxLength: 253
  27736. minLength: 1
  27737. pattern: ^[-._a-zA-Z0-9]+$
  27738. type: string
  27739. name:
  27740. description: The name of the Secret resource being referred to.
  27741. maxLength: 253
  27742. minLength: 1
  27743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27744. type: string
  27745. namespace:
  27746. description: |-
  27747. The namespace of the Secret resource being referred to.
  27748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27749. maxLength: 63
  27750. minLength: 1
  27751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27752. type: string
  27753. type: object
  27754. type: object
  27755. workloadIdentity:
  27756. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27757. properties:
  27758. clusterLocation:
  27759. type: string
  27760. clusterName:
  27761. type: string
  27762. clusterProjectID:
  27763. type: string
  27764. serviceAccountRef:
  27765. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27766. properties:
  27767. audiences:
  27768. description: |-
  27769. Audience specifies the `aud` claim for the service account token
  27770. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27771. then this audiences will be appended to the list
  27772. items:
  27773. type: string
  27774. type: array
  27775. name:
  27776. description: The name of the ServiceAccount resource being referred to.
  27777. maxLength: 253
  27778. minLength: 1
  27779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27780. type: string
  27781. namespace:
  27782. description: |-
  27783. Namespace of the resource being referred to.
  27784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27785. maxLength: 63
  27786. minLength: 1
  27787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27788. type: string
  27789. required:
  27790. - name
  27791. type: object
  27792. required:
  27793. - clusterLocation
  27794. - clusterName
  27795. - serviceAccountRef
  27796. type: object
  27797. workloadIdentityFederation:
  27798. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27799. properties:
  27800. audience:
  27801. description: |-
  27802. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27803. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27804. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27805. type: string
  27806. awsSecurityCredentials:
  27807. description: |-
  27808. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27809. when using the AWS metadata server is not an option.
  27810. properties:
  27811. awsCredentialsSecretRef:
  27812. description: |-
  27813. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27814. Secret should be created with below names for keys
  27815. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27816. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27817. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27818. properties:
  27819. name:
  27820. description: name of the secret.
  27821. maxLength: 253
  27822. minLength: 1
  27823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27824. type: string
  27825. namespace:
  27826. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27827. maxLength: 63
  27828. minLength: 1
  27829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27830. type: string
  27831. required:
  27832. - name
  27833. type: object
  27834. region:
  27835. description: region is for configuring the AWS region to be used.
  27836. example: ap-south-1
  27837. maxLength: 50
  27838. minLength: 1
  27839. pattern: ^[a-z0-9-]+$
  27840. type: string
  27841. required:
  27842. - awsCredentialsSecretRef
  27843. - region
  27844. type: object
  27845. credConfig:
  27846. description: |-
  27847. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27848. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27849. serviceAccountRef must be used by providing operators service account details.
  27850. properties:
  27851. key:
  27852. description: key name holding the external account credential config.
  27853. maxLength: 253
  27854. minLength: 1
  27855. pattern: ^[-._a-zA-Z0-9]+$
  27856. type: string
  27857. name:
  27858. description: name of the configmap.
  27859. maxLength: 253
  27860. minLength: 1
  27861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27862. type: string
  27863. namespace:
  27864. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27865. maxLength: 63
  27866. minLength: 1
  27867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27868. type: string
  27869. required:
  27870. - key
  27871. - name
  27872. type: object
  27873. externalTokenEndpoint:
  27874. description: |-
  27875. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27876. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27877. URL is having the expected value.
  27878. type: string
  27879. gcpServiceAccountEmail:
  27880. description: |-
  27881. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27882. after Workload Identity Federation. Use this to grant access through the service account's
  27883. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27884. service_account_impersonation_url in the external account JSON from credConfig;
  27885. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27886. on that ServiceAccount.
  27887. example: my-gsa@my-project.iam.gserviceaccount.com
  27888. minLength: 1
  27889. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27890. type: string
  27891. serviceAccountRef:
  27892. description: |-
  27893. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27894. when Kubernetes is configured as provider in workload identity pool.
  27895. properties:
  27896. audiences:
  27897. description: |-
  27898. Audience specifies the `aud` claim for the service account token
  27899. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27900. then this audiences will be appended to the list
  27901. items:
  27902. type: string
  27903. type: array
  27904. name:
  27905. description: The name of the ServiceAccount resource being referred to.
  27906. maxLength: 253
  27907. minLength: 1
  27908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27909. type: string
  27910. namespace:
  27911. description: |-
  27912. Namespace of the resource being referred to.
  27913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27914. maxLength: 63
  27915. minLength: 1
  27916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27917. type: string
  27918. required:
  27919. - name
  27920. type: object
  27921. type: object
  27922. type: object
  27923. projectID:
  27924. description: ProjectID defines which project to use to authenticate with
  27925. type: string
  27926. required:
  27927. - auth
  27928. - projectID
  27929. type: object
  27930. githubAccessTokenSpec:
  27931. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27932. properties:
  27933. appID:
  27934. type: string
  27935. auth:
  27936. description: Auth configures how ESO authenticates with a Github instance.
  27937. properties:
  27938. privateKey:
  27939. description: GithubSecretRef references a secret containing GitHub credentials.
  27940. properties:
  27941. secretRef:
  27942. description: |-
  27943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27944. In some instances, `key` is a required field.
  27945. properties:
  27946. key:
  27947. description: |-
  27948. A key in the referenced Secret.
  27949. Some instances of this field may be defaulted, in others it may be required.
  27950. maxLength: 253
  27951. minLength: 1
  27952. pattern: ^[-._a-zA-Z0-9]+$
  27953. type: string
  27954. name:
  27955. description: The name of the Secret resource being referred to.
  27956. maxLength: 253
  27957. minLength: 1
  27958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27959. type: string
  27960. namespace:
  27961. description: |-
  27962. The namespace of the Secret resource being referred to.
  27963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27964. maxLength: 63
  27965. minLength: 1
  27966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27967. type: string
  27968. type: object
  27969. required:
  27970. - secretRef
  27971. type: object
  27972. required:
  27973. - privateKey
  27974. type: object
  27975. installID:
  27976. type: string
  27977. permissions:
  27978. additionalProperties:
  27979. type: string
  27980. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27981. type: object
  27982. repositories:
  27983. description: |-
  27984. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  27985. is installed to.
  27986. items:
  27987. type: string
  27988. type: array
  27989. url:
  27990. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  27991. type: string
  27992. required:
  27993. - appID
  27994. - auth
  27995. - installID
  27996. type: object
  27997. gitlabDeployTokenSpec:
  27998. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  27999. properties:
  28000. auth:
  28001. description: Auth configures how ESO authenticates with the GitLab API.
  28002. properties:
  28003. token:
  28004. description: |-
  28005. Token references a secret containing a GitLab access token (personal, group, or
  28006. project) with the api scope and at least the Maintainer role on the target.
  28007. properties:
  28008. secretRef:
  28009. description: |-
  28010. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28011. In some instances, `key` is a required field.
  28012. properties:
  28013. key:
  28014. description: |-
  28015. A key in the referenced Secret.
  28016. Some instances of this field may be defaulted, in others it may be required.
  28017. maxLength: 253
  28018. minLength: 1
  28019. pattern: ^[-._a-zA-Z0-9]+$
  28020. type: string
  28021. name:
  28022. description: The name of the Secret resource being referred to.
  28023. maxLength: 253
  28024. minLength: 1
  28025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28026. type: string
  28027. namespace:
  28028. description: |-
  28029. The namespace of the Secret resource being referred to.
  28030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28031. maxLength: 63
  28032. minLength: 1
  28033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28034. type: string
  28035. type: object
  28036. required:
  28037. - secretRef
  28038. type: object
  28039. required:
  28040. - token
  28041. type: object
  28042. expiresAt:
  28043. description: |-
  28044. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28045. not expire on the GitLab side and is revoked only when the generator state is
  28046. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28047. format: date-time
  28048. type: string
  28049. groupID:
  28050. description: |-
  28051. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28052. create the deploy token in. The generator URL-escapes paths before calling the
  28053. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28054. minLength: 1
  28055. type: string
  28056. name:
  28057. description: Name of the deploy token.
  28058. minLength: 1
  28059. type: string
  28060. projectID:
  28061. description: |-
  28062. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28063. project to create the deploy token in. The generator URL-escapes paths before
  28064. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28065. minLength: 1
  28066. type: string
  28067. scopes:
  28068. description: Scopes granted to the deploy token. At least one scope is required.
  28069. items:
  28070. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28071. enum:
  28072. - read_repository
  28073. - read_registry
  28074. - write_registry
  28075. - read_package_registry
  28076. - write_package_registry
  28077. - read_virtual_registry
  28078. - write_virtual_registry
  28079. type: string
  28080. minItems: 1
  28081. type: array
  28082. url:
  28083. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28084. type: string
  28085. username:
  28086. description: |-
  28087. Username is an optional username for the deploy token. GitLab defaults it to
  28088. gitlab+deploy-token-{n} when omitted.
  28089. type: string
  28090. required:
  28091. - auth
  28092. - name
  28093. - scopes
  28094. type: object
  28095. x-kubernetes-validations:
  28096. - message: exactly one of projectID or groupID must be set
  28097. rule: has(self.projectID) != has(self.groupID)
  28098. grafanaSpec:
  28099. description: GrafanaSpec controls the behavior of the grafana generator.
  28100. properties:
  28101. auth:
  28102. description: |-
  28103. Auth is the authentication configuration to authenticate
  28104. against the Grafana instance.
  28105. properties:
  28106. basic:
  28107. description: |-
  28108. Basic auth credentials used to authenticate against the Grafana instance.
  28109. Note: you need a token which has elevated permissions to create service accounts.
  28110. See here for the documentation on basic roles offered by Grafana:
  28111. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28112. properties:
  28113. password:
  28114. description: A basic auth password used to authenticate against the Grafana instance.
  28115. properties:
  28116. key:
  28117. description: The key where the token is found.
  28118. maxLength: 253
  28119. minLength: 1
  28120. pattern: ^[-._a-zA-Z0-9]+$
  28121. type: string
  28122. name:
  28123. description: The name of the Secret resource being referred to.
  28124. maxLength: 253
  28125. minLength: 1
  28126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28127. type: string
  28128. type: object
  28129. username:
  28130. description: A basic auth username used to authenticate against the Grafana instance.
  28131. type: string
  28132. required:
  28133. - password
  28134. - username
  28135. type: object
  28136. token:
  28137. description: |-
  28138. A service account token used to authenticate against the Grafana instance.
  28139. Note: you need a token which has elevated permissions to create service accounts.
  28140. See here for the documentation on basic roles offered by Grafana:
  28141. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28142. properties:
  28143. key:
  28144. description: The key where the token is found.
  28145. maxLength: 253
  28146. minLength: 1
  28147. pattern: ^[-._a-zA-Z0-9]+$
  28148. type: string
  28149. name:
  28150. description: The name of the Secret resource being referred to.
  28151. maxLength: 253
  28152. minLength: 1
  28153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28154. type: string
  28155. type: object
  28156. type: object
  28157. serviceAccount:
  28158. description: |-
  28159. ServiceAccount is the configuration for the service account that
  28160. is supposed to be generated by the generator.
  28161. properties:
  28162. name:
  28163. description: Name is the name of the service account that will be created by ESO.
  28164. type: string
  28165. role:
  28166. description: |-
  28167. Role is the role of the service account.
  28168. See here for the documentation on basic roles offered by Grafana:
  28169. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28170. type: string
  28171. secondsToLive:
  28172. description: |-
  28173. SecondsToLive is the number of seconds before the generated service account token will expire.
  28174. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28175. format: int64
  28176. minimum: 1
  28177. type: integer
  28178. required:
  28179. - name
  28180. - role
  28181. type: object
  28182. url:
  28183. description: URL is the URL of the Grafana instance.
  28184. type: string
  28185. required:
  28186. - auth
  28187. - serviceAccount
  28188. - url
  28189. type: object
  28190. mfaSpec:
  28191. description: MFASpec controls the behavior of the mfa generator.
  28192. properties:
  28193. algorithm:
  28194. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28195. type: string
  28196. length:
  28197. description: Length defines the token length. Defaults to 6 characters.
  28198. type: integer
  28199. secret:
  28200. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28201. properties:
  28202. key:
  28203. description: |-
  28204. A key in the referenced Secret.
  28205. Some instances of this field may be defaulted, in others it may be required.
  28206. maxLength: 253
  28207. minLength: 1
  28208. pattern: ^[-._a-zA-Z0-9]+$
  28209. type: string
  28210. name:
  28211. description: The name of the Secret resource being referred to.
  28212. maxLength: 253
  28213. minLength: 1
  28214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28215. type: string
  28216. namespace:
  28217. description: |-
  28218. The namespace of the Secret resource being referred to.
  28219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28220. maxLength: 63
  28221. minLength: 1
  28222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28223. type: string
  28224. type: object
  28225. timePeriod:
  28226. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28227. type: integer
  28228. when:
  28229. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28230. format: date-time
  28231. type: string
  28232. required:
  28233. - secret
  28234. type: object
  28235. passwordSpec:
  28236. description: PasswordSpec controls the behavior of the password generator.
  28237. properties:
  28238. allowRepeat:
  28239. default: false
  28240. description: set AllowRepeat to true to allow repeating characters.
  28241. type: boolean
  28242. digits:
  28243. description: |-
  28244. Digits specifies the number of digits in the generated
  28245. password. If omitted it defaults to 25% of the length of the password
  28246. type: integer
  28247. encoding:
  28248. default: raw
  28249. description: |-
  28250. Encoding specifies the encoding of the generated password.
  28251. Valid values are:
  28252. - "raw" (default): no encoding
  28253. - "base64": standard base64 encoding
  28254. - "base64url": base64url encoding
  28255. - "base32": base32 encoding
  28256. - "hex": hexadecimal encoding
  28257. enum:
  28258. - base64
  28259. - base64url
  28260. - base32
  28261. - hex
  28262. - raw
  28263. type: string
  28264. length:
  28265. default: 24
  28266. description: |-
  28267. Length of the password to be generated.
  28268. Defaults to 24
  28269. type: integer
  28270. noUpper:
  28271. default: false
  28272. description: Set NoUpper to disable uppercase characters
  28273. type: boolean
  28274. secretKeys:
  28275. description: |-
  28276. SecretKeys defines the keys that will be populated with generated passwords.
  28277. Defaults to "password" when not set.
  28278. items:
  28279. type: string
  28280. minItems: 1
  28281. type: array
  28282. symbolCharacters:
  28283. description: |-
  28284. SymbolCharacters specifies the special characters that should be used
  28285. in the generated password.
  28286. type: string
  28287. symbols:
  28288. description: |-
  28289. Symbols specifies the number of symbol characters in the generated
  28290. password. If omitted it defaults to 25% of the length of the password
  28291. type: integer
  28292. required:
  28293. - allowRepeat
  28294. - length
  28295. - noUpper
  28296. type: object
  28297. quayAccessTokenSpec:
  28298. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28299. properties:
  28300. robotAccount:
  28301. description: Name of the robot account you are federating with
  28302. type: string
  28303. serviceAccountRef:
  28304. description: Name of the service account you are federating with
  28305. properties:
  28306. audiences:
  28307. description: |-
  28308. Audience specifies the `aud` claim for the service account token
  28309. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28310. then this audiences will be appended to the list
  28311. items:
  28312. type: string
  28313. type: array
  28314. name:
  28315. description: The name of the ServiceAccount resource being referred to.
  28316. maxLength: 253
  28317. minLength: 1
  28318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28319. type: string
  28320. namespace:
  28321. description: |-
  28322. Namespace of the resource being referred to.
  28323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28324. maxLength: 63
  28325. minLength: 1
  28326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28327. type: string
  28328. required:
  28329. - name
  28330. type: object
  28331. url:
  28332. description: URL configures the Quay instance URL. Defaults to quay.io.
  28333. type: string
  28334. required:
  28335. - robotAccount
  28336. - serviceAccountRef
  28337. type: object
  28338. sshKeySpec:
  28339. description: SSHKeySpec controls the behavior of the ssh key generator.
  28340. properties:
  28341. comment:
  28342. description: Comment specifies an optional comment for the SSH key
  28343. type: string
  28344. keySize:
  28345. description: |-
  28346. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28347. For RSA keys: 2048, 3072, 4096
  28348. For ECDSA keys: 256, 384, 521
  28349. Ignored for ed25519 keys
  28350. maximum: 8192
  28351. minimum: 256
  28352. type: integer
  28353. keyType:
  28354. default: rsa
  28355. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28356. enum:
  28357. - rsa
  28358. - ecdsa
  28359. - ed25519
  28360. type: string
  28361. type: object
  28362. stsSessionTokenSpec:
  28363. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28364. properties:
  28365. auth:
  28366. description: Auth defines how to authenticate with AWS
  28367. properties:
  28368. jwt:
  28369. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28370. properties:
  28371. serviceAccountRef:
  28372. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28373. properties:
  28374. audiences:
  28375. description: |-
  28376. Audience specifies the `aud` claim for the service account token
  28377. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28378. then this audiences will be appended to the list
  28379. items:
  28380. type: string
  28381. type: array
  28382. name:
  28383. description: The name of the ServiceAccount resource being referred to.
  28384. maxLength: 253
  28385. minLength: 1
  28386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28387. type: string
  28388. namespace:
  28389. description: |-
  28390. Namespace of the resource being referred to.
  28391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28392. maxLength: 63
  28393. minLength: 1
  28394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28395. type: string
  28396. required:
  28397. - name
  28398. type: object
  28399. type: object
  28400. secretRef:
  28401. description: |-
  28402. AWSAuthSecretRef holds secret references for AWS credentials
  28403. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28404. properties:
  28405. accessKeyIDSecretRef:
  28406. description: The AccessKeyID is used for authentication
  28407. properties:
  28408. key:
  28409. description: |-
  28410. A key in the referenced Secret.
  28411. Some instances of this field may be defaulted, in others it may be required.
  28412. maxLength: 253
  28413. minLength: 1
  28414. pattern: ^[-._a-zA-Z0-9]+$
  28415. type: string
  28416. name:
  28417. description: The name of the Secret resource being referred to.
  28418. maxLength: 253
  28419. minLength: 1
  28420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28421. type: string
  28422. namespace:
  28423. description: |-
  28424. The namespace of the Secret resource being referred to.
  28425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28426. maxLength: 63
  28427. minLength: 1
  28428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28429. type: string
  28430. type: object
  28431. secretAccessKeySecretRef:
  28432. description: The SecretAccessKey is used for authentication
  28433. properties:
  28434. key:
  28435. description: |-
  28436. A key in the referenced Secret.
  28437. Some instances of this field may be defaulted, in others it may be required.
  28438. maxLength: 253
  28439. minLength: 1
  28440. pattern: ^[-._a-zA-Z0-9]+$
  28441. type: string
  28442. name:
  28443. description: The name of the Secret resource being referred to.
  28444. maxLength: 253
  28445. minLength: 1
  28446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28447. type: string
  28448. namespace:
  28449. description: |-
  28450. The namespace of the Secret resource being referred to.
  28451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28452. maxLength: 63
  28453. minLength: 1
  28454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28455. type: string
  28456. type: object
  28457. sessionTokenSecretRef:
  28458. description: |-
  28459. The SessionToken used for authentication
  28460. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28461. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28462. properties:
  28463. key:
  28464. description: |-
  28465. A key in the referenced Secret.
  28466. Some instances of this field may be defaulted, in others it may be required.
  28467. maxLength: 253
  28468. minLength: 1
  28469. pattern: ^[-._a-zA-Z0-9]+$
  28470. type: string
  28471. name:
  28472. description: The name of the Secret resource being referred to.
  28473. maxLength: 253
  28474. minLength: 1
  28475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28476. type: string
  28477. namespace:
  28478. description: |-
  28479. The namespace of the Secret resource being referred to.
  28480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28481. maxLength: 63
  28482. minLength: 1
  28483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28484. type: string
  28485. type: object
  28486. type: object
  28487. type: object
  28488. region:
  28489. description: Region specifies the region to operate in.
  28490. type: string
  28491. requestParameters:
  28492. description: RequestParameters contains parameters that can be passed to the STS service.
  28493. properties:
  28494. serialNumber:
  28495. description: |-
  28496. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28497. the GetSessionToken call.
  28498. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28499. (such as arn:aws:iam::123456789012:mfa/user)
  28500. type: string
  28501. sessionDuration:
  28502. format: int32
  28503. type: integer
  28504. tokenCode:
  28505. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28506. type: string
  28507. type: object
  28508. role:
  28509. description: |-
  28510. You can assume a role before making calls to the
  28511. desired AWS service.
  28512. type: string
  28513. required:
  28514. - region
  28515. type: object
  28516. uuidSpec:
  28517. description: UUIDSpec controls the behavior of the uuid generator.
  28518. type: object
  28519. vaultDynamicSecretSpec:
  28520. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28521. properties:
  28522. allowEmptyResponse:
  28523. default: false
  28524. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28525. type: boolean
  28526. controller:
  28527. description: |-
  28528. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28529. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28530. type: string
  28531. getParameters:
  28532. additionalProperties:
  28533. items:
  28534. type: string
  28535. type: array
  28536. description: |-
  28537. GetParameters are query-string parameters passed to Vault on GET calls.
  28538. Each key may map to multiple values, matching HTTP query-string semantics.
  28539. Ignored for non-GET methods; use Parameters for write bodies.
  28540. type: object
  28541. method:
  28542. description: Vault API method to use (GET/POST/other)
  28543. type: string
  28544. parameters:
  28545. description: Parameters to pass to Vault write (for non-GET methods)
  28546. x-kubernetes-preserve-unknown-fields: true
  28547. path:
  28548. description: Vault path to obtain the dynamic secret from
  28549. type: string
  28550. provider:
  28551. description: Vault provider common spec
  28552. properties:
  28553. auth:
  28554. description: Auth configures how secret-manager authenticates with the Vault server.
  28555. properties:
  28556. appRole:
  28557. description: |-
  28558. AppRole authenticates with Vault using the App Role auth mechanism,
  28559. with the role and secret stored in a Kubernetes Secret resource.
  28560. properties:
  28561. path:
  28562. default: approle
  28563. description: |-
  28564. Path where the App Role authentication backend is mounted
  28565. in Vault, e.g: "approle"
  28566. type: string
  28567. roleId:
  28568. description: |-
  28569. RoleID configured in the App Role authentication backend when setting
  28570. up the authentication backend in Vault.
  28571. type: string
  28572. roleRef:
  28573. description: |-
  28574. Reference to a key in a Secret that contains the App Role ID used
  28575. to authenticate with Vault.
  28576. The `key` field must be specified and denotes which entry within the Secret
  28577. resource is used as the app role id.
  28578. properties:
  28579. key:
  28580. description: |-
  28581. A key in the referenced Secret.
  28582. Some instances of this field may be defaulted, in others it may be required.
  28583. maxLength: 253
  28584. minLength: 1
  28585. pattern: ^[-._a-zA-Z0-9]+$
  28586. type: string
  28587. name:
  28588. description: The name of the Secret resource being referred to.
  28589. maxLength: 253
  28590. minLength: 1
  28591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28592. type: string
  28593. namespace:
  28594. description: |-
  28595. The namespace of the Secret resource being referred to.
  28596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28597. maxLength: 63
  28598. minLength: 1
  28599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28600. type: string
  28601. type: object
  28602. secretRef:
  28603. description: |-
  28604. Reference to a key in a Secret that contains the App Role secret used
  28605. to authenticate with Vault.
  28606. The `key` field must be specified and denotes which entry within the Secret
  28607. resource is used as the app role secret.
  28608. properties:
  28609. key:
  28610. description: |-
  28611. A key in the referenced Secret.
  28612. Some instances of this field may be defaulted, in others it may be required.
  28613. maxLength: 253
  28614. minLength: 1
  28615. pattern: ^[-._a-zA-Z0-9]+$
  28616. type: string
  28617. name:
  28618. description: The name of the Secret resource being referred to.
  28619. maxLength: 253
  28620. minLength: 1
  28621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28622. type: string
  28623. namespace:
  28624. description: |-
  28625. The namespace of the Secret resource being referred to.
  28626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28627. maxLength: 63
  28628. minLength: 1
  28629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28630. type: string
  28631. type: object
  28632. required:
  28633. - path
  28634. - secretRef
  28635. type: object
  28636. cert:
  28637. description: |-
  28638. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28639. Cert authentication method
  28640. properties:
  28641. clientCert:
  28642. description: |-
  28643. ClientCert is a certificate to authenticate using the Cert Vault
  28644. authentication method
  28645. properties:
  28646. key:
  28647. description: |-
  28648. A key in the referenced Secret.
  28649. Some instances of this field may be defaulted, in others it may be required.
  28650. maxLength: 253
  28651. minLength: 1
  28652. pattern: ^[-._a-zA-Z0-9]+$
  28653. type: string
  28654. name:
  28655. description: The name of the Secret resource being referred to.
  28656. maxLength: 253
  28657. minLength: 1
  28658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28659. type: string
  28660. namespace:
  28661. description: |-
  28662. The namespace of the Secret resource being referred to.
  28663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28664. maxLength: 63
  28665. minLength: 1
  28666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28667. type: string
  28668. type: object
  28669. path:
  28670. default: cert
  28671. description: |-
  28672. Path where the Certificate authentication backend is mounted
  28673. in Vault, e.g: "cert"
  28674. type: string
  28675. secretRef:
  28676. description: |-
  28677. SecretRef to a key in a Secret resource containing client private key to
  28678. authenticate with Vault using the Cert authentication method
  28679. properties:
  28680. key:
  28681. description: |-
  28682. A key in the referenced Secret.
  28683. Some instances of this field may be defaulted, in others it may be required.
  28684. maxLength: 253
  28685. minLength: 1
  28686. pattern: ^[-._a-zA-Z0-9]+$
  28687. type: string
  28688. name:
  28689. description: The name of the Secret resource being referred to.
  28690. maxLength: 253
  28691. minLength: 1
  28692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28693. type: string
  28694. namespace:
  28695. description: |-
  28696. The namespace of the Secret resource being referred to.
  28697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28698. maxLength: 63
  28699. minLength: 1
  28700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28701. type: string
  28702. type: object
  28703. vaultRole:
  28704. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28705. type: string
  28706. type: object
  28707. gcp:
  28708. description: |-
  28709. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28710. GCP authentication method
  28711. properties:
  28712. location:
  28713. description: Location optionally defines a location/region for the secret
  28714. type: string
  28715. path:
  28716. default: gcp
  28717. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28718. type: string
  28719. projectID:
  28720. description: Project ID of the Google Cloud Platform project
  28721. type: string
  28722. role:
  28723. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28724. type: string
  28725. secretRef:
  28726. description: Specify credentials in a Secret object
  28727. properties:
  28728. secretAccessKeySecretRef:
  28729. description: The SecretAccessKey is used for authentication
  28730. properties:
  28731. key:
  28732. description: |-
  28733. A key in the referenced Secret.
  28734. Some instances of this field may be defaulted, in others it may be required.
  28735. maxLength: 253
  28736. minLength: 1
  28737. pattern: ^[-._a-zA-Z0-9]+$
  28738. type: string
  28739. name:
  28740. description: The name of the Secret resource being referred to.
  28741. maxLength: 253
  28742. minLength: 1
  28743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28744. type: string
  28745. namespace:
  28746. description: |-
  28747. The namespace of the Secret resource being referred to.
  28748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28749. maxLength: 63
  28750. minLength: 1
  28751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28752. type: string
  28753. type: object
  28754. type: object
  28755. serviceAccountRef:
  28756. description: ServiceAccountRef to a service account for impersonation
  28757. properties:
  28758. audiences:
  28759. description: |-
  28760. Audience specifies the `aud` claim for the service account token
  28761. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28762. then this audiences will be appended to the list
  28763. items:
  28764. type: string
  28765. type: array
  28766. name:
  28767. description: The name of the ServiceAccount resource being referred to.
  28768. maxLength: 253
  28769. minLength: 1
  28770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28771. type: string
  28772. namespace:
  28773. description: |-
  28774. Namespace of the resource being referred to.
  28775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28776. maxLength: 63
  28777. minLength: 1
  28778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28779. type: string
  28780. required:
  28781. - name
  28782. type: object
  28783. workloadIdentity:
  28784. description: Specify a service account with Workload Identity
  28785. properties:
  28786. clusterLocation:
  28787. description: |-
  28788. ClusterLocation is the location of the cluster
  28789. If not specified, it fetches information from the metadata server
  28790. type: string
  28791. clusterName:
  28792. description: |-
  28793. ClusterName is the name of the cluster
  28794. If not specified, it fetches information from the metadata server
  28795. type: string
  28796. clusterProjectID:
  28797. description: |-
  28798. ClusterProjectID is the project ID of the cluster
  28799. If not specified, it fetches information from the metadata server
  28800. type: string
  28801. serviceAccountRef:
  28802. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28803. properties:
  28804. audiences:
  28805. description: |-
  28806. Audience specifies the `aud` claim for the service account token
  28807. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28808. then this audiences will be appended to the list
  28809. items:
  28810. type: string
  28811. type: array
  28812. name:
  28813. description: The name of the ServiceAccount resource being referred to.
  28814. maxLength: 253
  28815. minLength: 1
  28816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28817. type: string
  28818. namespace:
  28819. description: |-
  28820. Namespace of the resource being referred to.
  28821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28822. maxLength: 63
  28823. minLength: 1
  28824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28825. type: string
  28826. required:
  28827. - name
  28828. type: object
  28829. required:
  28830. - serviceAccountRef
  28831. type: object
  28832. required:
  28833. - role
  28834. type: object
  28835. iam:
  28836. description: |-
  28837. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28838. AWS IAM authentication method
  28839. properties:
  28840. externalID:
  28841. description: AWS External ID set on assumed IAM roles
  28842. type: string
  28843. jwt:
  28844. description: Specify a service account with IRSA enabled
  28845. properties:
  28846. serviceAccountRef:
  28847. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28848. properties:
  28849. audiences:
  28850. description: |-
  28851. Audience specifies the `aud` claim for the service account token
  28852. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28853. then this audiences will be appended to the list
  28854. items:
  28855. type: string
  28856. type: array
  28857. name:
  28858. description: The name of the ServiceAccount resource being referred to.
  28859. maxLength: 253
  28860. minLength: 1
  28861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28862. type: string
  28863. namespace:
  28864. description: |-
  28865. Namespace of the resource being referred to.
  28866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28867. maxLength: 63
  28868. minLength: 1
  28869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28870. type: string
  28871. required:
  28872. - name
  28873. type: object
  28874. type: object
  28875. path:
  28876. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28877. type: string
  28878. region:
  28879. description: AWS region
  28880. type: string
  28881. role:
  28882. description: This is the AWS role to be assumed before talking to vault
  28883. type: string
  28884. secretRef:
  28885. description: Specify credentials in a Secret object
  28886. properties:
  28887. accessKeyIDSecretRef:
  28888. description: The AccessKeyID is used for authentication
  28889. properties:
  28890. key:
  28891. description: |-
  28892. A key in the referenced Secret.
  28893. Some instances of this field may be defaulted, in others it may be required.
  28894. maxLength: 253
  28895. minLength: 1
  28896. pattern: ^[-._a-zA-Z0-9]+$
  28897. type: string
  28898. name:
  28899. description: The name of the Secret resource being referred to.
  28900. maxLength: 253
  28901. minLength: 1
  28902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28903. type: string
  28904. namespace:
  28905. description: |-
  28906. The namespace of the Secret resource being referred to.
  28907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28908. maxLength: 63
  28909. minLength: 1
  28910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28911. type: string
  28912. type: object
  28913. secretAccessKeySecretRef:
  28914. description: The SecretAccessKey is used for authentication
  28915. properties:
  28916. key:
  28917. description: |-
  28918. A key in the referenced Secret.
  28919. Some instances of this field may be defaulted, in others it may be required.
  28920. maxLength: 253
  28921. minLength: 1
  28922. pattern: ^[-._a-zA-Z0-9]+$
  28923. type: string
  28924. name:
  28925. description: The name of the Secret resource being referred to.
  28926. maxLength: 253
  28927. minLength: 1
  28928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28929. type: string
  28930. namespace:
  28931. description: |-
  28932. The namespace of the Secret resource being referred to.
  28933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28934. maxLength: 63
  28935. minLength: 1
  28936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28937. type: string
  28938. type: object
  28939. sessionTokenSecretRef:
  28940. description: |-
  28941. The SessionToken used for authentication
  28942. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28943. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28944. properties:
  28945. key:
  28946. description: |-
  28947. A key in the referenced Secret.
  28948. Some instances of this field may be defaulted, in others it may be required.
  28949. maxLength: 253
  28950. minLength: 1
  28951. pattern: ^[-._a-zA-Z0-9]+$
  28952. type: string
  28953. name:
  28954. description: The name of the Secret resource being referred to.
  28955. maxLength: 253
  28956. minLength: 1
  28957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28958. type: string
  28959. namespace:
  28960. description: |-
  28961. The namespace of the Secret resource being referred to.
  28962. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28963. maxLength: 63
  28964. minLength: 1
  28965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28966. type: string
  28967. type: object
  28968. type: object
  28969. vaultAwsIamServerID:
  28970. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28971. type: string
  28972. vaultRole:
  28973. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28974. type: string
  28975. required:
  28976. - vaultRole
  28977. type: object
  28978. jwt:
  28979. description: |-
  28980. Jwt authenticates with Vault by passing role and JWT token using the
  28981. JWT/OIDC authentication method
  28982. properties:
  28983. kubernetesServiceAccountToken:
  28984. description: |-
  28985. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  28986. a token for with the `TokenRequest` API.
  28987. properties:
  28988. audiences:
  28989. description: |-
  28990. Optional audiences field that will be used to request a temporary Kubernetes service
  28991. account token for the service account referenced by `serviceAccountRef`.
  28992. Defaults to a single audience `vault` it not specified.
  28993. Deprecated: use serviceAccountRef.Audiences instead
  28994. items:
  28995. type: string
  28996. type: array
  28997. expirationSeconds:
  28998. description: |-
  28999. Optional expiration time in seconds that will be used to request a temporary
  29000. Kubernetes service account token for the service account referenced by
  29001. `serviceAccountRef`.
  29002. Deprecated: this will be removed in the future.
  29003. Defaults to 10 minutes.
  29004. format: int64
  29005. type: integer
  29006. serviceAccountRef:
  29007. description: Service account field containing the name of a kubernetes ServiceAccount.
  29008. properties:
  29009. audiences:
  29010. description: |-
  29011. Audience specifies the `aud` claim for the service account token
  29012. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29013. then this audiences will be appended to the list
  29014. items:
  29015. type: string
  29016. type: array
  29017. name:
  29018. description: The name of the ServiceAccount resource being referred to.
  29019. maxLength: 253
  29020. minLength: 1
  29021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29022. type: string
  29023. namespace:
  29024. description: |-
  29025. Namespace of the resource being referred to.
  29026. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29027. maxLength: 63
  29028. minLength: 1
  29029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29030. type: string
  29031. required:
  29032. - name
  29033. type: object
  29034. required:
  29035. - serviceAccountRef
  29036. type: object
  29037. path:
  29038. default: jwt
  29039. description: |-
  29040. Path where the JWT authentication backend is mounted
  29041. in Vault, e.g: "jwt"
  29042. type: string
  29043. role:
  29044. description: |-
  29045. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29046. authentication method
  29047. type: string
  29048. secretRef:
  29049. description: |-
  29050. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29051. authenticate with Vault using the JWT/OIDC authentication method.
  29052. properties:
  29053. key:
  29054. description: |-
  29055. A key in the referenced Secret.
  29056. Some instances of this field may be defaulted, in others it may be required.
  29057. maxLength: 253
  29058. minLength: 1
  29059. pattern: ^[-._a-zA-Z0-9]+$
  29060. type: string
  29061. name:
  29062. description: The name of the Secret resource being referred to.
  29063. maxLength: 253
  29064. minLength: 1
  29065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29066. type: string
  29067. namespace:
  29068. description: |-
  29069. The namespace of the Secret resource being referred to.
  29070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29071. maxLength: 63
  29072. minLength: 1
  29073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29074. type: string
  29075. type: object
  29076. required:
  29077. - path
  29078. type: object
  29079. kubernetes:
  29080. description: |-
  29081. Kubernetes authenticates with Vault by passing the ServiceAccount
  29082. token stored in the named Secret resource to the Vault server.
  29083. properties:
  29084. mountPath:
  29085. default: kubernetes
  29086. description: |-
  29087. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29088. "kubernetes"
  29089. type: string
  29090. role:
  29091. description: |-
  29092. A required field containing the Vault Role to assume. A Role binds a
  29093. Kubernetes ServiceAccount with a set of Vault policies.
  29094. type: string
  29095. secretRef:
  29096. description: |-
  29097. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29098. for authenticating with Vault. If a name is specified without a key,
  29099. `token` is the default. If one is not specified, the one bound to
  29100. the controller will be used.
  29101. properties:
  29102. key:
  29103. description: |-
  29104. A key in the referenced Secret.
  29105. Some instances of this field may be defaulted, in others it may be required.
  29106. maxLength: 253
  29107. minLength: 1
  29108. pattern: ^[-._a-zA-Z0-9]+$
  29109. type: string
  29110. name:
  29111. description: The name of the Secret resource being referred to.
  29112. maxLength: 253
  29113. minLength: 1
  29114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29115. type: string
  29116. namespace:
  29117. description: |-
  29118. The namespace of the Secret resource being referred to.
  29119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29120. maxLength: 63
  29121. minLength: 1
  29122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29123. type: string
  29124. type: object
  29125. serviceAccountRef:
  29126. description: |-
  29127. Optional service account field containing the name of a kubernetes ServiceAccount.
  29128. If the service account is specified, the service account secret token JWT will be used
  29129. for authenticating with Vault. If the service account selector is not supplied,
  29130. the secretRef will be used instead.
  29131. properties:
  29132. audiences:
  29133. description: |-
  29134. Audience specifies the `aud` claim for the service account token
  29135. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29136. then this audiences will be appended to the list
  29137. items:
  29138. type: string
  29139. type: array
  29140. name:
  29141. description: The name of the ServiceAccount resource being referred to.
  29142. maxLength: 253
  29143. minLength: 1
  29144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29145. type: string
  29146. namespace:
  29147. description: |-
  29148. Namespace of the resource being referred to.
  29149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29150. maxLength: 63
  29151. minLength: 1
  29152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29153. type: string
  29154. required:
  29155. - name
  29156. type: object
  29157. required:
  29158. - mountPath
  29159. - role
  29160. type: object
  29161. ldap:
  29162. description: |-
  29163. Ldap authenticates with Vault by passing username/password pair using
  29164. the LDAP authentication method
  29165. properties:
  29166. path:
  29167. default: ldap
  29168. description: |-
  29169. Path where the LDAP authentication backend is mounted
  29170. in Vault, e.g: "ldap"
  29171. type: string
  29172. secretRef:
  29173. description: |-
  29174. SecretRef to a key in a Secret resource containing password for the LDAP
  29175. user used to authenticate with Vault using the LDAP authentication
  29176. method
  29177. properties:
  29178. key:
  29179. description: |-
  29180. A key in the referenced Secret.
  29181. Some instances of this field may be defaulted, in others it may be required.
  29182. maxLength: 253
  29183. minLength: 1
  29184. pattern: ^[-._a-zA-Z0-9]+$
  29185. type: string
  29186. name:
  29187. description: The name of the Secret resource being referred to.
  29188. maxLength: 253
  29189. minLength: 1
  29190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29191. type: string
  29192. namespace:
  29193. description: |-
  29194. The namespace of the Secret resource being referred to.
  29195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29196. maxLength: 63
  29197. minLength: 1
  29198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29199. type: string
  29200. type: object
  29201. username:
  29202. description: |-
  29203. Username is an LDAP username used to authenticate using the LDAP Vault
  29204. authentication method
  29205. type: string
  29206. required:
  29207. - path
  29208. - username
  29209. type: object
  29210. namespace:
  29211. description: |-
  29212. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29213. Namespaces is a set of features within Vault Enterprise that allows
  29214. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29215. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29216. This will default to Vault.Namespace field if set, or empty otherwise
  29217. type: string
  29218. tokenSecretRef:
  29219. description: TokenSecretRef authenticates with Vault by presenting a token.
  29220. properties:
  29221. key:
  29222. description: |-
  29223. A key in the referenced Secret.
  29224. Some instances of this field may be defaulted, in others it may be required.
  29225. maxLength: 253
  29226. minLength: 1
  29227. pattern: ^[-._a-zA-Z0-9]+$
  29228. type: string
  29229. name:
  29230. description: The name of the Secret resource being referred to.
  29231. maxLength: 253
  29232. minLength: 1
  29233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29234. type: string
  29235. namespace:
  29236. description: |-
  29237. The namespace of the Secret resource being referred to.
  29238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29239. maxLength: 63
  29240. minLength: 1
  29241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29242. type: string
  29243. type: object
  29244. userPass:
  29245. description: UserPass authenticates with Vault by passing username/password pair
  29246. properties:
  29247. path:
  29248. default: userpass
  29249. description: |-
  29250. Path where the UserPassword authentication backend is mounted
  29251. in Vault, e.g: "userpass"
  29252. type: string
  29253. secretRef:
  29254. description: |-
  29255. SecretRef to a key in a Secret resource containing password for the
  29256. user used to authenticate with Vault using the UserPass authentication
  29257. method
  29258. properties:
  29259. key:
  29260. description: |-
  29261. A key in the referenced Secret.
  29262. Some instances of this field may be defaulted, in others it may be required.
  29263. maxLength: 253
  29264. minLength: 1
  29265. pattern: ^[-._a-zA-Z0-9]+$
  29266. type: string
  29267. name:
  29268. description: The name of the Secret resource being referred to.
  29269. maxLength: 253
  29270. minLength: 1
  29271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29272. type: string
  29273. namespace:
  29274. description: |-
  29275. The namespace of the Secret resource being referred to.
  29276. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29277. maxLength: 63
  29278. minLength: 1
  29279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29280. type: string
  29281. type: object
  29282. username:
  29283. description: |-
  29284. Username is a username used to authenticate using the UserPass Vault
  29285. authentication method
  29286. type: string
  29287. required:
  29288. - path
  29289. - username
  29290. type: object
  29291. type: object
  29292. caBundle:
  29293. description: |-
  29294. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29295. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29296. plain HTTP protocol connection. If not set the system root certificates
  29297. are used to validate the TLS connection.
  29298. format: byte
  29299. type: string
  29300. caProvider:
  29301. description: The provider for the CA bundle to use to validate Vault server certificate.
  29302. properties:
  29303. key:
  29304. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29305. maxLength: 253
  29306. minLength: 1
  29307. pattern: ^[-._a-zA-Z0-9]+$
  29308. type: string
  29309. name:
  29310. description: The name of the object located at the provider type.
  29311. maxLength: 253
  29312. minLength: 1
  29313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29314. type: string
  29315. namespace:
  29316. description: |-
  29317. The namespace the Provider type is in.
  29318. Can only be defined when used in a ClusterSecretStore.
  29319. maxLength: 63
  29320. minLength: 1
  29321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29322. type: string
  29323. type:
  29324. description: The type of provider to use such as "Secret", or "ConfigMap".
  29325. enum:
  29326. - Secret
  29327. - ConfigMap
  29328. type: string
  29329. required:
  29330. - name
  29331. - type
  29332. type: object
  29333. checkAndSet:
  29334. description: |-
  29335. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29336. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29337. the current version of the secret to prevent unintentional overwrites.
  29338. properties:
  29339. required:
  29340. description: |-
  29341. Required when true, all write operations must include a check-and-set parameter.
  29342. This helps prevent unintentional overwrites of secrets.
  29343. type: boolean
  29344. type: object
  29345. forwardInconsistent:
  29346. description: |-
  29347. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29348. leader instead of simply retrying within a loop. This can increase performance if
  29349. the option is enabled serverside.
  29350. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29351. type: boolean
  29352. headers:
  29353. additionalProperties:
  29354. type: string
  29355. description: Headers to be added in Vault request
  29356. type: object
  29357. namespace:
  29358. description: |-
  29359. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29360. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29361. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29362. type: string
  29363. path:
  29364. description: |-
  29365. Path is the mount path of the Vault KV backend endpoint, e.g:
  29366. "secret". The v2 KV secret engine version specific "/data" path suffix
  29367. for fetching secrets from Vault is optional and will be appended
  29368. if not present in specified path.
  29369. type: string
  29370. readYourWrites:
  29371. description: |-
  29372. ReadYourWrites ensures isolated read-after-write semantics by
  29373. providing discovered cluster replication states in each request.
  29374. More information about eventual consistency in Vault can be found here
  29375. https://www.vaultproject.io/docs/enterprise/consistency
  29376. type: boolean
  29377. server:
  29378. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29379. type: string
  29380. tls:
  29381. description: |-
  29382. The configuration used for client side related TLS communication, when the Vault server
  29383. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29384. This parameter is ignored for plain HTTP protocol connection.
  29385. It's worth noting this configuration is different from the "TLS certificates auth method",
  29386. which is available under the `auth.cert` section.
  29387. properties:
  29388. certSecretRef:
  29389. description: |-
  29390. CertSecretRef is a certificate added to the transport layer
  29391. when communicating with the Vault server.
  29392. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29393. properties:
  29394. key:
  29395. description: |-
  29396. A key in the referenced Secret.
  29397. Some instances of this field may be defaulted, in others it may be required.
  29398. maxLength: 253
  29399. minLength: 1
  29400. pattern: ^[-._a-zA-Z0-9]+$
  29401. type: string
  29402. name:
  29403. description: The name of the Secret resource being referred to.
  29404. maxLength: 253
  29405. minLength: 1
  29406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29407. type: string
  29408. namespace:
  29409. description: |-
  29410. The namespace of the Secret resource being referred to.
  29411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29412. maxLength: 63
  29413. minLength: 1
  29414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29415. type: string
  29416. type: object
  29417. keySecretRef:
  29418. description: |-
  29419. KeySecretRef to a key in a Secret resource containing client private key
  29420. added to the transport layer when communicating with the Vault server.
  29421. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29422. properties:
  29423. key:
  29424. description: |-
  29425. A key in the referenced Secret.
  29426. Some instances of this field may be defaulted, in others it may be required.
  29427. maxLength: 253
  29428. minLength: 1
  29429. pattern: ^[-._a-zA-Z0-9]+$
  29430. type: string
  29431. name:
  29432. description: The name of the Secret resource being referred to.
  29433. maxLength: 253
  29434. minLength: 1
  29435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29436. type: string
  29437. namespace:
  29438. description: |-
  29439. The namespace of the Secret resource being referred to.
  29440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29441. maxLength: 63
  29442. minLength: 1
  29443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29444. type: string
  29445. type: object
  29446. type: object
  29447. version:
  29448. default: v2
  29449. description: |-
  29450. Version is the Vault KV secret engine version. This can be either "v1" or
  29451. "v2". Version defaults to "v2".
  29452. enum:
  29453. - v1
  29454. - v2
  29455. type: string
  29456. required:
  29457. - server
  29458. type: object
  29459. resultType:
  29460. default: Data
  29461. description: |-
  29462. Result type defines which data is returned from the generator.
  29463. By default, it is the "data" section of the Vault API response.
  29464. When using e.g. /auth/token/create the "data" section is empty but
  29465. the "auth" section contains the generated token.
  29466. Please refer to the vault docs regarding the result data structure.
  29467. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29468. enum:
  29469. - Data
  29470. - Auth
  29471. - Raw
  29472. type: string
  29473. retrySettings:
  29474. description: Used to configure http retries if failed
  29475. properties:
  29476. maxRetries:
  29477. format: int32
  29478. type: integer
  29479. retryInterval:
  29480. type: string
  29481. type: object
  29482. required:
  29483. - path
  29484. - provider
  29485. type: object
  29486. webhookSpec:
  29487. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29488. properties:
  29489. auth:
  29490. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29491. maxProperties: 1
  29492. minProperties: 1
  29493. properties:
  29494. ntlm:
  29495. description: NTLMProtocol configures the store to use NTLM for auth
  29496. properties:
  29497. passwordSecret:
  29498. description: |-
  29499. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29500. In some instances, `key` is a required field.
  29501. properties:
  29502. key:
  29503. description: |-
  29504. A key in the referenced Secret.
  29505. Some instances of this field may be defaulted, in others it may be required.
  29506. maxLength: 253
  29507. minLength: 1
  29508. pattern: ^[-._a-zA-Z0-9]+$
  29509. type: string
  29510. name:
  29511. description: The name of the Secret resource being referred to.
  29512. maxLength: 253
  29513. minLength: 1
  29514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29515. type: string
  29516. namespace:
  29517. description: |-
  29518. The namespace of the Secret resource being referred to.
  29519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29520. maxLength: 63
  29521. minLength: 1
  29522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29523. type: string
  29524. type: object
  29525. usernameSecret:
  29526. description: |-
  29527. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29528. In some instances, `key` is a required field.
  29529. properties:
  29530. key:
  29531. description: |-
  29532. A key in the referenced Secret.
  29533. Some instances of this field may be defaulted, in others it may be required.
  29534. maxLength: 253
  29535. minLength: 1
  29536. pattern: ^[-._a-zA-Z0-9]+$
  29537. type: string
  29538. name:
  29539. description: The name of the Secret resource being referred to.
  29540. maxLength: 253
  29541. minLength: 1
  29542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29543. type: string
  29544. namespace:
  29545. description: |-
  29546. The namespace of the Secret resource being referred to.
  29547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29548. maxLength: 63
  29549. minLength: 1
  29550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29551. type: string
  29552. type: object
  29553. required:
  29554. - passwordSecret
  29555. - usernameSecret
  29556. type: object
  29557. type: object
  29558. body:
  29559. description: Body
  29560. type: string
  29561. caBundle:
  29562. description: |-
  29563. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29564. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29565. plain HTTP protocol connection. If not set the system root certificates
  29566. are used to validate the TLS connection.
  29567. format: byte
  29568. type: string
  29569. caProvider:
  29570. description: The provider for the CA bundle to use to validate webhook server certificate.
  29571. properties:
  29572. key:
  29573. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29574. maxLength: 253
  29575. minLength: 1
  29576. pattern: ^[-._a-zA-Z0-9]+$
  29577. type: string
  29578. name:
  29579. description: The name of the object located at the provider type.
  29580. maxLength: 253
  29581. minLength: 1
  29582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29583. type: string
  29584. namespace:
  29585. description: The namespace the Provider type is in.
  29586. maxLength: 63
  29587. minLength: 1
  29588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29589. type: string
  29590. type:
  29591. description: The type of provider to use such as "Secret", or "ConfigMap".
  29592. enum:
  29593. - Secret
  29594. - ConfigMap
  29595. type: string
  29596. required:
  29597. - name
  29598. - type
  29599. type: object
  29600. headers:
  29601. additionalProperties:
  29602. type: string
  29603. description: Headers
  29604. type: object
  29605. method:
  29606. description: Webhook Method
  29607. type: string
  29608. result:
  29609. description: Result formatting
  29610. properties:
  29611. jsonPath:
  29612. description: Json path of return value
  29613. type: string
  29614. type: object
  29615. secrets:
  29616. description: |-
  29617. Secrets to fill in templates
  29618. These secrets will be passed to the templating function as key value pairs under the given name
  29619. items:
  29620. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29621. properties:
  29622. name:
  29623. description: Name of this secret in templates
  29624. type: string
  29625. secretRef:
  29626. description: Secret ref to fill in credentials
  29627. properties:
  29628. key:
  29629. description: The key where the token is found.
  29630. maxLength: 253
  29631. minLength: 1
  29632. pattern: ^[-._a-zA-Z0-9]+$
  29633. type: string
  29634. name:
  29635. description: The name of the Secret resource being referred to.
  29636. maxLength: 253
  29637. minLength: 1
  29638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29639. type: string
  29640. type: object
  29641. required:
  29642. - name
  29643. - secretRef
  29644. type: object
  29645. type: array
  29646. timeout:
  29647. description: Timeout
  29648. type: string
  29649. url:
  29650. description: Webhook url to call
  29651. type: string
  29652. required:
  29653. - result
  29654. - url
  29655. type: object
  29656. type: object
  29657. kind:
  29658. description: Kind the kind of this generator.
  29659. enum:
  29660. - ACRAccessToken
  29661. - BeyondtrustWorkloadCredentialsDynamicSecret
  29662. - CloudsmithAccessToken
  29663. - ECRAuthorizationToken
  29664. - Fake
  29665. - GCRAccessToken
  29666. - GithubAccessToken
  29667. - GitlabDeployToken
  29668. - QuayAccessToken
  29669. - Password
  29670. - SSHKey
  29671. - STSSessionToken
  29672. - UUID
  29673. - VaultDynamicSecret
  29674. - Webhook
  29675. - Grafana
  29676. - MFA
  29677. type: string
  29678. required:
  29679. - generator
  29680. - kind
  29681. type: object
  29682. type: object
  29683. served: true
  29684. storage: true
  29685. subresources:
  29686. status: {}
  29687. ---
  29688. apiVersion: apiextensions.k8s.io/v1
  29689. kind: CustomResourceDefinition
  29690. metadata:
  29691. annotations:
  29692. controller-gen.kubebuilder.io/version: v0.19.0
  29693. labels:
  29694. external-secrets.io/component: controller
  29695. name: ecrauthorizationtokens.generators.external-secrets.io
  29696. spec:
  29697. group: generators.external-secrets.io
  29698. names:
  29699. categories:
  29700. - external-secrets
  29701. - external-secrets-generators
  29702. kind: ECRAuthorizationToken
  29703. listKind: ECRAuthorizationTokenList
  29704. plural: ecrauthorizationtokens
  29705. singular: ecrauthorizationtoken
  29706. scope: Namespaced
  29707. versions:
  29708. - name: v1alpha1
  29709. schema:
  29710. openAPIV3Schema:
  29711. description: |-
  29712. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29713. The authorization token is valid for 12 hours.
  29714. The authorizationToken returned is a base64 encoded string that can be decoded
  29715. and used in a docker login command to authenticate to a registry.
  29716. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29717. properties:
  29718. apiVersion:
  29719. description: |-
  29720. APIVersion defines the versioned schema of this representation of an object.
  29721. Servers should convert recognized schemas to the latest internal value, and
  29722. may reject unrecognized values.
  29723. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29724. type: string
  29725. kind:
  29726. description: |-
  29727. Kind is a string value representing the REST resource this object represents.
  29728. Servers may infer this from the endpoint the client submits requests to.
  29729. Cannot be updated.
  29730. In CamelCase.
  29731. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29732. type: string
  29733. metadata:
  29734. type: object
  29735. spec:
  29736. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29737. properties:
  29738. auth:
  29739. description: Auth defines how to authenticate with AWS
  29740. properties:
  29741. jwt:
  29742. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29743. properties:
  29744. serviceAccountRef:
  29745. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29746. properties:
  29747. audiences:
  29748. description: |-
  29749. Audience specifies the `aud` claim for the service account token
  29750. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29751. then this audiences will be appended to the list
  29752. items:
  29753. type: string
  29754. type: array
  29755. name:
  29756. description: The name of the ServiceAccount resource being referred to.
  29757. maxLength: 253
  29758. minLength: 1
  29759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29760. type: string
  29761. namespace:
  29762. description: |-
  29763. Namespace of the resource being referred to.
  29764. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29765. maxLength: 63
  29766. minLength: 1
  29767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29768. type: string
  29769. required:
  29770. - name
  29771. type: object
  29772. type: object
  29773. secretRef:
  29774. description: |-
  29775. AWSAuthSecretRef holds secret references for AWS credentials
  29776. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29777. properties:
  29778. accessKeyIDSecretRef:
  29779. description: The AccessKeyID is used for authentication
  29780. properties:
  29781. key:
  29782. description: |-
  29783. A key in the referenced Secret.
  29784. Some instances of this field may be defaulted, in others it may be required.
  29785. maxLength: 253
  29786. minLength: 1
  29787. pattern: ^[-._a-zA-Z0-9]+$
  29788. type: string
  29789. name:
  29790. description: The name of the Secret resource being referred to.
  29791. maxLength: 253
  29792. minLength: 1
  29793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29794. type: string
  29795. namespace:
  29796. description: |-
  29797. The namespace of the Secret resource being referred to.
  29798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29799. maxLength: 63
  29800. minLength: 1
  29801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29802. type: string
  29803. type: object
  29804. secretAccessKeySecretRef:
  29805. description: The SecretAccessKey is used for authentication
  29806. properties:
  29807. key:
  29808. description: |-
  29809. A key in the referenced Secret.
  29810. Some instances of this field may be defaulted, in others it may be required.
  29811. maxLength: 253
  29812. minLength: 1
  29813. pattern: ^[-._a-zA-Z0-9]+$
  29814. type: string
  29815. name:
  29816. description: The name of the Secret resource being referred to.
  29817. maxLength: 253
  29818. minLength: 1
  29819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29820. type: string
  29821. namespace:
  29822. description: |-
  29823. The namespace of the Secret resource being referred to.
  29824. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29825. maxLength: 63
  29826. minLength: 1
  29827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29828. type: string
  29829. type: object
  29830. sessionTokenSecretRef:
  29831. description: |-
  29832. The SessionToken used for authentication
  29833. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29834. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29835. properties:
  29836. key:
  29837. description: |-
  29838. A key in the referenced Secret.
  29839. Some instances of this field may be defaulted, in others it may be required.
  29840. maxLength: 253
  29841. minLength: 1
  29842. pattern: ^[-._a-zA-Z0-9]+$
  29843. type: string
  29844. name:
  29845. description: The name of the Secret resource being referred to.
  29846. maxLength: 253
  29847. minLength: 1
  29848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29849. type: string
  29850. namespace:
  29851. description: |-
  29852. The namespace of the Secret resource being referred to.
  29853. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29854. maxLength: 63
  29855. minLength: 1
  29856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29857. type: string
  29858. type: object
  29859. type: object
  29860. type: object
  29861. region:
  29862. description: Region specifies the region to operate in.
  29863. type: string
  29864. role:
  29865. description: |-
  29866. You can assume a role before making calls to the
  29867. desired AWS service.
  29868. type: string
  29869. scope:
  29870. description: |-
  29871. Scope specifies the ECR service scope.
  29872. Valid options are private and public.
  29873. type: string
  29874. required:
  29875. - region
  29876. type: object
  29877. type: object
  29878. served: true
  29879. storage: true
  29880. subresources:
  29881. status: {}
  29882. ---
  29883. apiVersion: apiextensions.k8s.io/v1
  29884. kind: CustomResourceDefinition
  29885. metadata:
  29886. annotations:
  29887. controller-gen.kubebuilder.io/version: v0.19.0
  29888. labels:
  29889. external-secrets.io/component: controller
  29890. name: fakes.generators.external-secrets.io
  29891. spec:
  29892. group: generators.external-secrets.io
  29893. names:
  29894. categories:
  29895. - external-secrets
  29896. - external-secrets-generators
  29897. kind: Fake
  29898. listKind: FakeList
  29899. plural: fakes
  29900. singular: fake
  29901. scope: Namespaced
  29902. versions:
  29903. - name: v1alpha1
  29904. schema:
  29905. openAPIV3Schema:
  29906. description: |-
  29907. Fake generator is used for testing. It lets you define
  29908. a static set of credentials that is always returned.
  29909. properties:
  29910. apiVersion:
  29911. description: |-
  29912. APIVersion defines the versioned schema of this representation of an object.
  29913. Servers should convert recognized schemas to the latest internal value, and
  29914. may reject unrecognized values.
  29915. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29916. type: string
  29917. kind:
  29918. description: |-
  29919. Kind is a string value representing the REST resource this object represents.
  29920. Servers may infer this from the endpoint the client submits requests to.
  29921. Cannot be updated.
  29922. In CamelCase.
  29923. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29924. type: string
  29925. metadata:
  29926. type: object
  29927. spec:
  29928. description: FakeSpec contains the static data.
  29929. properties:
  29930. controller:
  29931. description: |-
  29932. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29933. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29934. type: string
  29935. data:
  29936. additionalProperties:
  29937. type: string
  29938. description: |-
  29939. Data defines the static data returned
  29940. by this generator.
  29941. type: object
  29942. type: object
  29943. type: object
  29944. served: true
  29945. storage: true
  29946. subresources:
  29947. status: {}
  29948. ---
  29949. apiVersion: apiextensions.k8s.io/v1
  29950. kind: CustomResourceDefinition
  29951. metadata:
  29952. annotations:
  29953. controller-gen.kubebuilder.io/version: v0.19.0
  29954. labels:
  29955. external-secrets.io/component: controller
  29956. name: gcraccesstokens.generators.external-secrets.io
  29957. spec:
  29958. group: generators.external-secrets.io
  29959. names:
  29960. categories:
  29961. - external-secrets
  29962. - external-secrets-generators
  29963. kind: GCRAccessToken
  29964. listKind: GCRAccessTokenList
  29965. plural: gcraccesstokens
  29966. singular: gcraccesstoken
  29967. scope: Namespaced
  29968. versions:
  29969. - name: v1alpha1
  29970. schema:
  29971. openAPIV3Schema:
  29972. description: |-
  29973. GCRAccessToken generates an GCP access token
  29974. that can be used to authenticate with GCR.
  29975. properties:
  29976. apiVersion:
  29977. description: |-
  29978. APIVersion defines the versioned schema of this representation of an object.
  29979. Servers should convert recognized schemas to the latest internal value, and
  29980. may reject unrecognized values.
  29981. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29982. type: string
  29983. kind:
  29984. description: |-
  29985. Kind is a string value representing the REST resource this object represents.
  29986. Servers may infer this from the endpoint the client submits requests to.
  29987. Cannot be updated.
  29988. In CamelCase.
  29989. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29990. type: string
  29991. metadata:
  29992. type: object
  29993. spec:
  29994. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  29995. properties:
  29996. auth:
  29997. description: Auth defines the means for authenticating with GCP
  29998. properties:
  29999. secretRef:
  30000. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30001. properties:
  30002. secretAccessKeySecretRef:
  30003. description: The SecretAccessKey is used for authentication
  30004. properties:
  30005. key:
  30006. description: |-
  30007. A key in the referenced Secret.
  30008. Some instances of this field may be defaulted, in others it may be required.
  30009. maxLength: 253
  30010. minLength: 1
  30011. pattern: ^[-._a-zA-Z0-9]+$
  30012. type: string
  30013. name:
  30014. description: The name of the Secret resource being referred to.
  30015. maxLength: 253
  30016. minLength: 1
  30017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30018. type: string
  30019. namespace:
  30020. description: |-
  30021. The namespace of the Secret resource being referred to.
  30022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30023. maxLength: 63
  30024. minLength: 1
  30025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30026. type: string
  30027. type: object
  30028. type: object
  30029. workloadIdentity:
  30030. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30031. properties:
  30032. clusterLocation:
  30033. type: string
  30034. clusterName:
  30035. type: string
  30036. clusterProjectID:
  30037. type: string
  30038. serviceAccountRef:
  30039. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30040. properties:
  30041. audiences:
  30042. description: |-
  30043. Audience specifies the `aud` claim for the service account token
  30044. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30045. then this audiences will be appended to the list
  30046. items:
  30047. type: string
  30048. type: array
  30049. name:
  30050. description: The name of the ServiceAccount resource being referred to.
  30051. maxLength: 253
  30052. minLength: 1
  30053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30054. type: string
  30055. namespace:
  30056. description: |-
  30057. Namespace of the resource being referred to.
  30058. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30059. maxLength: 63
  30060. minLength: 1
  30061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30062. type: string
  30063. required:
  30064. - name
  30065. type: object
  30066. required:
  30067. - clusterLocation
  30068. - clusterName
  30069. - serviceAccountRef
  30070. type: object
  30071. workloadIdentityFederation:
  30072. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30073. properties:
  30074. audience:
  30075. description: |-
  30076. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30077. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30078. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30079. type: string
  30080. awsSecurityCredentials:
  30081. description: |-
  30082. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30083. when using the AWS metadata server is not an option.
  30084. properties:
  30085. awsCredentialsSecretRef:
  30086. description: |-
  30087. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30088. Secret should be created with below names for keys
  30089. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30090. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30091. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30092. properties:
  30093. name:
  30094. description: name of the secret.
  30095. maxLength: 253
  30096. minLength: 1
  30097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30098. type: string
  30099. namespace:
  30100. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30101. maxLength: 63
  30102. minLength: 1
  30103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30104. type: string
  30105. required:
  30106. - name
  30107. type: object
  30108. region:
  30109. description: region is for configuring the AWS region to be used.
  30110. example: ap-south-1
  30111. maxLength: 50
  30112. minLength: 1
  30113. pattern: ^[a-z0-9-]+$
  30114. type: string
  30115. required:
  30116. - awsCredentialsSecretRef
  30117. - region
  30118. type: object
  30119. credConfig:
  30120. description: |-
  30121. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30122. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30123. serviceAccountRef must be used by providing operators service account details.
  30124. properties:
  30125. key:
  30126. description: key name holding the external account credential config.
  30127. maxLength: 253
  30128. minLength: 1
  30129. pattern: ^[-._a-zA-Z0-9]+$
  30130. type: string
  30131. name:
  30132. description: name of the configmap.
  30133. maxLength: 253
  30134. minLength: 1
  30135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30136. type: string
  30137. namespace:
  30138. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30139. maxLength: 63
  30140. minLength: 1
  30141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30142. type: string
  30143. required:
  30144. - key
  30145. - name
  30146. type: object
  30147. externalTokenEndpoint:
  30148. description: |-
  30149. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30150. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30151. URL is having the expected value.
  30152. type: string
  30153. gcpServiceAccountEmail:
  30154. description: |-
  30155. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30156. after Workload Identity Federation. Use this to grant access through the service account's
  30157. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30158. service_account_impersonation_url in the external account JSON from credConfig;
  30159. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30160. on that ServiceAccount.
  30161. example: my-gsa@my-project.iam.gserviceaccount.com
  30162. minLength: 1
  30163. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30164. type: string
  30165. serviceAccountRef:
  30166. description: |-
  30167. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30168. when Kubernetes is configured as provider in workload identity pool.
  30169. properties:
  30170. audiences:
  30171. description: |-
  30172. Audience specifies the `aud` claim for the service account token
  30173. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30174. then this audiences will be appended to the list
  30175. items:
  30176. type: string
  30177. type: array
  30178. name:
  30179. description: The name of the ServiceAccount resource being referred to.
  30180. maxLength: 253
  30181. minLength: 1
  30182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30183. type: string
  30184. namespace:
  30185. description: |-
  30186. Namespace of the resource being referred to.
  30187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30188. maxLength: 63
  30189. minLength: 1
  30190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30191. type: string
  30192. required:
  30193. - name
  30194. type: object
  30195. type: object
  30196. type: object
  30197. projectID:
  30198. description: ProjectID defines which project to use to authenticate with
  30199. type: string
  30200. required:
  30201. - auth
  30202. - projectID
  30203. type: object
  30204. type: object
  30205. served: true
  30206. storage: true
  30207. subresources:
  30208. status: {}
  30209. ---
  30210. apiVersion: apiextensions.k8s.io/v1
  30211. kind: CustomResourceDefinition
  30212. metadata:
  30213. annotations:
  30214. controller-gen.kubebuilder.io/version: v0.19.0
  30215. labels:
  30216. external-secrets.io/component: controller
  30217. name: generatorstates.generators.external-secrets.io
  30218. spec:
  30219. group: generators.external-secrets.io
  30220. names:
  30221. categories:
  30222. - external-secrets
  30223. - external-secrets-generators
  30224. kind: GeneratorState
  30225. listKind: GeneratorStateList
  30226. plural: generatorstates
  30227. shortNames:
  30228. - gs
  30229. singular: generatorstate
  30230. scope: Namespaced
  30231. versions:
  30232. - additionalPrinterColumns:
  30233. - jsonPath: .spec.garbageCollectionDeadline
  30234. name: GC Deadline
  30235. type: string
  30236. - jsonPath: .metadata.creationTimestamp
  30237. name: Age
  30238. type: date
  30239. name: v1alpha1
  30240. schema:
  30241. openAPIV3Schema:
  30242. description: GeneratorState represents the state created and managed by a generator resource.
  30243. properties:
  30244. apiVersion:
  30245. description: |-
  30246. APIVersion defines the versioned schema of this representation of an object.
  30247. Servers should convert recognized schemas to the latest internal value, and
  30248. may reject unrecognized values.
  30249. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30250. type: string
  30251. kind:
  30252. description: |-
  30253. Kind is a string value representing the REST resource this object represents.
  30254. Servers may infer this from the endpoint the client submits requests to.
  30255. Cannot be updated.
  30256. In CamelCase.
  30257. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30258. type: string
  30259. metadata:
  30260. type: object
  30261. spec:
  30262. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30263. properties:
  30264. garbageCollectionDeadline:
  30265. description: |-
  30266. GarbageCollectionDeadline is the time after which the generator state
  30267. will be deleted.
  30268. It is set by the controller which creates the generator state and
  30269. can be set configured by the user.
  30270. If the garbage collection deadline is not set the generator state will not be deleted.
  30271. format: date-time
  30272. type: string
  30273. resource:
  30274. description: |-
  30275. Resource is the generator manifest that produced the state.
  30276. It is a snapshot of the generator manifest at the time the state was produced.
  30277. This manifest will be used to delete the resource. Any configuration that is referenced
  30278. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30279. be blocked by a finalizer.
  30280. x-kubernetes-preserve-unknown-fields: true
  30281. state:
  30282. description: State is the state that was produced by the generator implementation.
  30283. x-kubernetes-preserve-unknown-fields: true
  30284. required:
  30285. - resource
  30286. - state
  30287. type: object
  30288. status:
  30289. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30290. properties:
  30291. conditions:
  30292. items:
  30293. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30294. properties:
  30295. lastTransitionTime:
  30296. format: date-time
  30297. type: string
  30298. message:
  30299. type: string
  30300. reason:
  30301. type: string
  30302. status:
  30303. type: string
  30304. type:
  30305. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30306. type: string
  30307. required:
  30308. - status
  30309. - type
  30310. type: object
  30311. type: array
  30312. type: object
  30313. type: object
  30314. served: true
  30315. storage: true
  30316. subresources: {}
  30317. ---
  30318. apiVersion: apiextensions.k8s.io/v1
  30319. kind: CustomResourceDefinition
  30320. metadata:
  30321. annotations:
  30322. controller-gen.kubebuilder.io/version: v0.19.0
  30323. labels:
  30324. external-secrets.io/component: controller
  30325. name: githubaccesstokens.generators.external-secrets.io
  30326. spec:
  30327. group: generators.external-secrets.io
  30328. names:
  30329. categories:
  30330. - external-secrets
  30331. - external-secrets-generators
  30332. kind: GithubAccessToken
  30333. listKind: GithubAccessTokenList
  30334. plural: githubaccesstokens
  30335. singular: githubaccesstoken
  30336. scope: Namespaced
  30337. versions:
  30338. - name: v1alpha1
  30339. schema:
  30340. openAPIV3Schema:
  30341. description: GithubAccessToken generates ghs_ accessToken
  30342. properties:
  30343. apiVersion:
  30344. description: |-
  30345. APIVersion defines the versioned schema of this representation of an object.
  30346. Servers should convert recognized schemas to the latest internal value, and
  30347. may reject unrecognized values.
  30348. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30349. type: string
  30350. kind:
  30351. description: |-
  30352. Kind is a string value representing the REST resource this object represents.
  30353. Servers may infer this from the endpoint the client submits requests to.
  30354. Cannot be updated.
  30355. In CamelCase.
  30356. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30357. type: string
  30358. metadata:
  30359. type: object
  30360. spec:
  30361. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30362. properties:
  30363. appID:
  30364. type: string
  30365. auth:
  30366. description: Auth configures how ESO authenticates with a Github instance.
  30367. properties:
  30368. privateKey:
  30369. description: GithubSecretRef references a secret containing GitHub credentials.
  30370. properties:
  30371. secretRef:
  30372. description: |-
  30373. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30374. In some instances, `key` is a required field.
  30375. properties:
  30376. key:
  30377. description: |-
  30378. A key in the referenced Secret.
  30379. Some instances of this field may be defaulted, in others it may be required.
  30380. maxLength: 253
  30381. minLength: 1
  30382. pattern: ^[-._a-zA-Z0-9]+$
  30383. type: string
  30384. name:
  30385. description: The name of the Secret resource being referred to.
  30386. maxLength: 253
  30387. minLength: 1
  30388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30389. type: string
  30390. namespace:
  30391. description: |-
  30392. The namespace of the Secret resource being referred to.
  30393. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30394. maxLength: 63
  30395. minLength: 1
  30396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30397. type: string
  30398. type: object
  30399. required:
  30400. - secretRef
  30401. type: object
  30402. required:
  30403. - privateKey
  30404. type: object
  30405. installID:
  30406. type: string
  30407. permissions:
  30408. additionalProperties:
  30409. type: string
  30410. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30411. type: object
  30412. repositories:
  30413. description: |-
  30414. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30415. is installed to.
  30416. items:
  30417. type: string
  30418. type: array
  30419. url:
  30420. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30421. type: string
  30422. required:
  30423. - appID
  30424. - auth
  30425. - installID
  30426. type: object
  30427. type: object
  30428. served: true
  30429. storage: true
  30430. subresources:
  30431. status: {}
  30432. ---
  30433. apiVersion: apiextensions.k8s.io/v1
  30434. kind: CustomResourceDefinition
  30435. metadata:
  30436. annotations:
  30437. controller-gen.kubebuilder.io/version: v0.19.0
  30438. labels:
  30439. external-secrets.io/component: controller
  30440. name: gitlabdeploytokens.generators.external-secrets.io
  30441. spec:
  30442. group: generators.external-secrets.io
  30443. names:
  30444. categories:
  30445. - external-secrets
  30446. - external-secrets-generators
  30447. kind: GitlabDeployToken
  30448. listKind: GitlabDeployTokenList
  30449. plural: gitlabdeploytokens
  30450. singular: gitlabdeploytoken
  30451. scope: Namespaced
  30452. versions:
  30453. - name: v1alpha1
  30454. schema:
  30455. openAPIV3Schema:
  30456. description: GitlabDeployToken generates a GitLab deploy token.
  30457. properties:
  30458. apiVersion:
  30459. description: |-
  30460. APIVersion defines the versioned schema of this representation of an object.
  30461. Servers should convert recognized schemas to the latest internal value, and
  30462. may reject unrecognized values.
  30463. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30464. type: string
  30465. kind:
  30466. description: |-
  30467. Kind is a string value representing the REST resource this object represents.
  30468. Servers may infer this from the endpoint the client submits requests to.
  30469. Cannot be updated.
  30470. In CamelCase.
  30471. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30472. type: string
  30473. metadata:
  30474. type: object
  30475. spec:
  30476. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30477. properties:
  30478. auth:
  30479. description: Auth configures how ESO authenticates with the GitLab API.
  30480. properties:
  30481. token:
  30482. description: |-
  30483. Token references a secret containing a GitLab access token (personal, group, or
  30484. project) with the api scope and at least the Maintainer role on the target.
  30485. properties:
  30486. secretRef:
  30487. description: |-
  30488. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30489. In some instances, `key` is a required field.
  30490. properties:
  30491. key:
  30492. description: |-
  30493. A key in the referenced Secret.
  30494. Some instances of this field may be defaulted, in others it may be required.
  30495. maxLength: 253
  30496. minLength: 1
  30497. pattern: ^[-._a-zA-Z0-9]+$
  30498. type: string
  30499. name:
  30500. description: The name of the Secret resource being referred to.
  30501. maxLength: 253
  30502. minLength: 1
  30503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30504. type: string
  30505. namespace:
  30506. description: |-
  30507. The namespace of the Secret resource being referred to.
  30508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30509. maxLength: 63
  30510. minLength: 1
  30511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30512. type: string
  30513. type: object
  30514. required:
  30515. - secretRef
  30516. type: object
  30517. required:
  30518. - token
  30519. type: object
  30520. expiresAt:
  30521. description: |-
  30522. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30523. not expire on the GitLab side and is revoked only when the generator state is
  30524. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30525. format: date-time
  30526. type: string
  30527. groupID:
  30528. description: |-
  30529. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30530. create the deploy token in. The generator URL-escapes paths before calling the
  30531. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30532. minLength: 1
  30533. type: string
  30534. name:
  30535. description: Name of the deploy token.
  30536. minLength: 1
  30537. type: string
  30538. projectID:
  30539. description: |-
  30540. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30541. project to create the deploy token in. The generator URL-escapes paths before
  30542. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30543. minLength: 1
  30544. type: string
  30545. scopes:
  30546. description: Scopes granted to the deploy token. At least one scope is required.
  30547. items:
  30548. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30549. enum:
  30550. - read_repository
  30551. - read_registry
  30552. - write_registry
  30553. - read_package_registry
  30554. - write_package_registry
  30555. - read_virtual_registry
  30556. - write_virtual_registry
  30557. type: string
  30558. minItems: 1
  30559. type: array
  30560. url:
  30561. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30562. type: string
  30563. username:
  30564. description: |-
  30565. Username is an optional username for the deploy token. GitLab defaults it to
  30566. gitlab+deploy-token-{n} when omitted.
  30567. type: string
  30568. required:
  30569. - auth
  30570. - name
  30571. - scopes
  30572. type: object
  30573. x-kubernetes-validations:
  30574. - message: exactly one of projectID or groupID must be set
  30575. rule: has(self.projectID) != has(self.groupID)
  30576. type: object
  30577. served: true
  30578. storage: true
  30579. subresources:
  30580. status: {}
  30581. ---
  30582. apiVersion: apiextensions.k8s.io/v1
  30583. kind: CustomResourceDefinition
  30584. metadata:
  30585. annotations:
  30586. controller-gen.kubebuilder.io/version: v0.19.0
  30587. labels:
  30588. external-secrets.io/component: controller
  30589. name: grafanas.generators.external-secrets.io
  30590. spec:
  30591. group: generators.external-secrets.io
  30592. names:
  30593. categories:
  30594. - external-secrets
  30595. - external-secrets-generators
  30596. kind: Grafana
  30597. listKind: GrafanaList
  30598. plural: grafanas
  30599. singular: grafana
  30600. scope: Namespaced
  30601. versions:
  30602. - name: v1alpha1
  30603. schema:
  30604. openAPIV3Schema:
  30605. description: Grafana represents a generator for Grafana service account tokens.
  30606. properties:
  30607. apiVersion:
  30608. description: |-
  30609. APIVersion defines the versioned schema of this representation of an object.
  30610. Servers should convert recognized schemas to the latest internal value, and
  30611. may reject unrecognized values.
  30612. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30613. type: string
  30614. kind:
  30615. description: |-
  30616. Kind is a string value representing the REST resource this object represents.
  30617. Servers may infer this from the endpoint the client submits requests to.
  30618. Cannot be updated.
  30619. In CamelCase.
  30620. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30621. type: string
  30622. metadata:
  30623. type: object
  30624. spec:
  30625. description: GrafanaSpec controls the behavior of the grafana generator.
  30626. properties:
  30627. auth:
  30628. description: |-
  30629. Auth is the authentication configuration to authenticate
  30630. against the Grafana instance.
  30631. properties:
  30632. basic:
  30633. description: |-
  30634. Basic auth credentials used to authenticate against the Grafana instance.
  30635. Note: you need a token which has elevated permissions to create service accounts.
  30636. See here for the documentation on basic roles offered by Grafana:
  30637. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30638. properties:
  30639. password:
  30640. description: A basic auth password used to authenticate against the Grafana instance.
  30641. properties:
  30642. key:
  30643. description: The key where the token is found.
  30644. maxLength: 253
  30645. minLength: 1
  30646. pattern: ^[-._a-zA-Z0-9]+$
  30647. type: string
  30648. name:
  30649. description: The name of the Secret resource being referred to.
  30650. maxLength: 253
  30651. minLength: 1
  30652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30653. type: string
  30654. type: object
  30655. username:
  30656. description: A basic auth username used to authenticate against the Grafana instance.
  30657. type: string
  30658. required:
  30659. - password
  30660. - username
  30661. type: object
  30662. token:
  30663. description: |-
  30664. A service account token used to authenticate against the Grafana instance.
  30665. Note: you need a token which has elevated permissions to create service accounts.
  30666. See here for the documentation on basic roles offered by Grafana:
  30667. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30668. properties:
  30669. key:
  30670. description: The key where the token is found.
  30671. maxLength: 253
  30672. minLength: 1
  30673. pattern: ^[-._a-zA-Z0-9]+$
  30674. type: string
  30675. name:
  30676. description: The name of the Secret resource being referred to.
  30677. maxLength: 253
  30678. minLength: 1
  30679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30680. type: string
  30681. type: object
  30682. type: object
  30683. serviceAccount:
  30684. description: |-
  30685. ServiceAccount is the configuration for the service account that
  30686. is supposed to be generated by the generator.
  30687. properties:
  30688. name:
  30689. description: Name is the name of the service account that will be created by ESO.
  30690. type: string
  30691. role:
  30692. description: |-
  30693. Role is the role of the service account.
  30694. See here for the documentation on basic roles offered by Grafana:
  30695. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30696. type: string
  30697. secondsToLive:
  30698. description: |-
  30699. SecondsToLive is the number of seconds before the generated service account token will expire.
  30700. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30701. format: int64
  30702. minimum: 1
  30703. type: integer
  30704. required:
  30705. - name
  30706. - role
  30707. type: object
  30708. url:
  30709. description: URL is the URL of the Grafana instance.
  30710. type: string
  30711. required:
  30712. - auth
  30713. - serviceAccount
  30714. - url
  30715. type: object
  30716. type: object
  30717. served: true
  30718. storage: true
  30719. subresources:
  30720. status: {}
  30721. ---
  30722. apiVersion: apiextensions.k8s.io/v1
  30723. kind: CustomResourceDefinition
  30724. metadata:
  30725. annotations:
  30726. controller-gen.kubebuilder.io/version: v0.19.0
  30727. labels:
  30728. external-secrets.io/component: controller
  30729. name: mfas.generators.external-secrets.io
  30730. spec:
  30731. group: generators.external-secrets.io
  30732. names:
  30733. categories:
  30734. - external-secrets
  30735. - external-secrets-generators
  30736. kind: MFA
  30737. listKind: MFAList
  30738. plural: mfas
  30739. singular: mfa
  30740. scope: Namespaced
  30741. versions:
  30742. - name: v1alpha1
  30743. schema:
  30744. openAPIV3Schema:
  30745. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30746. properties:
  30747. apiVersion:
  30748. description: |-
  30749. APIVersion defines the versioned schema of this representation of an object.
  30750. Servers should convert recognized schemas to the latest internal value, and
  30751. may reject unrecognized values.
  30752. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30753. type: string
  30754. kind:
  30755. description: |-
  30756. Kind is a string value representing the REST resource this object represents.
  30757. Servers may infer this from the endpoint the client submits requests to.
  30758. Cannot be updated.
  30759. In CamelCase.
  30760. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30761. type: string
  30762. metadata:
  30763. type: object
  30764. spec:
  30765. description: MFASpec controls the behavior of the mfa generator.
  30766. properties:
  30767. algorithm:
  30768. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30769. type: string
  30770. length:
  30771. description: Length defines the token length. Defaults to 6 characters.
  30772. type: integer
  30773. secret:
  30774. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30775. properties:
  30776. key:
  30777. description: |-
  30778. A key in the referenced Secret.
  30779. Some instances of this field may be defaulted, in others it may be required.
  30780. maxLength: 253
  30781. minLength: 1
  30782. pattern: ^[-._a-zA-Z0-9]+$
  30783. type: string
  30784. name:
  30785. description: The name of the Secret resource being referred to.
  30786. maxLength: 253
  30787. minLength: 1
  30788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30789. type: string
  30790. namespace:
  30791. description: |-
  30792. The namespace of the Secret resource being referred to.
  30793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30794. maxLength: 63
  30795. minLength: 1
  30796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30797. type: string
  30798. type: object
  30799. timePeriod:
  30800. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30801. type: integer
  30802. when:
  30803. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30804. format: date-time
  30805. type: string
  30806. required:
  30807. - secret
  30808. type: object
  30809. type: object
  30810. served: true
  30811. storage: true
  30812. subresources:
  30813. status: {}
  30814. ---
  30815. apiVersion: apiextensions.k8s.io/v1
  30816. kind: CustomResourceDefinition
  30817. metadata:
  30818. annotations:
  30819. controller-gen.kubebuilder.io/version: v0.19.0
  30820. labels:
  30821. external-secrets.io/component: controller
  30822. name: passwords.generators.external-secrets.io
  30823. spec:
  30824. group: generators.external-secrets.io
  30825. names:
  30826. categories:
  30827. - external-secrets
  30828. - external-secrets-generators
  30829. kind: Password
  30830. listKind: PasswordList
  30831. plural: passwords
  30832. singular: password
  30833. scope: Namespaced
  30834. versions:
  30835. - name: v1alpha1
  30836. schema:
  30837. openAPIV3Schema:
  30838. description: |-
  30839. Password generates a random password based on the
  30840. configuration parameters in spec.
  30841. You can specify the length, characterset and other attributes.
  30842. properties:
  30843. apiVersion:
  30844. description: |-
  30845. APIVersion defines the versioned schema of this representation of an object.
  30846. Servers should convert recognized schemas to the latest internal value, and
  30847. may reject unrecognized values.
  30848. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30849. type: string
  30850. kind:
  30851. description: |-
  30852. Kind is a string value representing the REST resource this object represents.
  30853. Servers may infer this from the endpoint the client submits requests to.
  30854. Cannot be updated.
  30855. In CamelCase.
  30856. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30857. type: string
  30858. metadata:
  30859. type: object
  30860. spec:
  30861. description: PasswordSpec controls the behavior of the password generator.
  30862. properties:
  30863. allowRepeat:
  30864. default: false
  30865. description: set AllowRepeat to true to allow repeating characters.
  30866. type: boolean
  30867. digits:
  30868. description: |-
  30869. Digits specifies the number of digits in the generated
  30870. password. If omitted it defaults to 25% of the length of the password
  30871. type: integer
  30872. encoding:
  30873. default: raw
  30874. description: |-
  30875. Encoding specifies the encoding of the generated password.
  30876. Valid values are:
  30877. - "raw" (default): no encoding
  30878. - "base64": standard base64 encoding
  30879. - "base64url": base64url encoding
  30880. - "base32": base32 encoding
  30881. - "hex": hexadecimal encoding
  30882. enum:
  30883. - base64
  30884. - base64url
  30885. - base32
  30886. - hex
  30887. - raw
  30888. type: string
  30889. length:
  30890. default: 24
  30891. description: |-
  30892. Length of the password to be generated.
  30893. Defaults to 24
  30894. type: integer
  30895. noUpper:
  30896. default: false
  30897. description: Set NoUpper to disable uppercase characters
  30898. type: boolean
  30899. secretKeys:
  30900. description: |-
  30901. SecretKeys defines the keys that will be populated with generated passwords.
  30902. Defaults to "password" when not set.
  30903. items:
  30904. type: string
  30905. minItems: 1
  30906. type: array
  30907. symbolCharacters:
  30908. description: |-
  30909. SymbolCharacters specifies the special characters that should be used
  30910. in the generated password.
  30911. type: string
  30912. symbols:
  30913. description: |-
  30914. Symbols specifies the number of symbol characters in the generated
  30915. password. If omitted it defaults to 25% of the length of the password
  30916. type: integer
  30917. required:
  30918. - allowRepeat
  30919. - length
  30920. - noUpper
  30921. type: object
  30922. type: object
  30923. served: true
  30924. storage: true
  30925. subresources:
  30926. status: {}
  30927. ---
  30928. apiVersion: apiextensions.k8s.io/v1
  30929. kind: CustomResourceDefinition
  30930. metadata:
  30931. annotations:
  30932. controller-gen.kubebuilder.io/version: v0.19.0
  30933. labels:
  30934. external-secrets.io/component: controller
  30935. name: quayaccesstokens.generators.external-secrets.io
  30936. spec:
  30937. group: generators.external-secrets.io
  30938. names:
  30939. categories:
  30940. - external-secrets
  30941. - external-secrets-generators
  30942. kind: QuayAccessToken
  30943. listKind: QuayAccessTokenList
  30944. plural: quayaccesstokens
  30945. singular: quayaccesstoken
  30946. scope: Namespaced
  30947. versions:
  30948. - name: v1alpha1
  30949. schema:
  30950. openAPIV3Schema:
  30951. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30952. properties:
  30953. apiVersion:
  30954. description: |-
  30955. APIVersion defines the versioned schema of this representation of an object.
  30956. Servers should convert recognized schemas to the latest internal value, and
  30957. may reject unrecognized values.
  30958. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30959. type: string
  30960. kind:
  30961. description: |-
  30962. Kind is a string value representing the REST resource this object represents.
  30963. Servers may infer this from the endpoint the client submits requests to.
  30964. Cannot be updated.
  30965. In CamelCase.
  30966. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30967. type: string
  30968. metadata:
  30969. type: object
  30970. spec:
  30971. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30972. properties:
  30973. robotAccount:
  30974. description: Name of the robot account you are federating with
  30975. type: string
  30976. serviceAccountRef:
  30977. description: Name of the service account you are federating with
  30978. properties:
  30979. audiences:
  30980. description: |-
  30981. Audience specifies the `aud` claim for the service account token
  30982. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30983. then this audiences will be appended to the list
  30984. items:
  30985. type: string
  30986. type: array
  30987. name:
  30988. description: The name of the ServiceAccount resource being referred to.
  30989. maxLength: 253
  30990. minLength: 1
  30991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30992. type: string
  30993. namespace:
  30994. description: |-
  30995. Namespace of the resource being referred to.
  30996. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30997. maxLength: 63
  30998. minLength: 1
  30999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31000. type: string
  31001. required:
  31002. - name
  31003. type: object
  31004. url:
  31005. description: URL configures the Quay instance URL. Defaults to quay.io.
  31006. type: string
  31007. required:
  31008. - robotAccount
  31009. - serviceAccountRef
  31010. type: object
  31011. type: object
  31012. served: true
  31013. storage: true
  31014. subresources:
  31015. status: {}
  31016. ---
  31017. apiVersion: apiextensions.k8s.io/v1
  31018. kind: CustomResourceDefinition
  31019. metadata:
  31020. annotations:
  31021. controller-gen.kubebuilder.io/version: v0.19.0
  31022. labels:
  31023. external-secrets.io/component: controller
  31024. name: sshkeys.generators.external-secrets.io
  31025. spec:
  31026. group: generators.external-secrets.io
  31027. names:
  31028. categories:
  31029. - external-secrets
  31030. - external-secrets-generators
  31031. kind: SSHKey
  31032. listKind: SSHKeyList
  31033. plural: sshkeys
  31034. singular: sshkey
  31035. scope: Namespaced
  31036. versions:
  31037. - name: v1alpha1
  31038. schema:
  31039. openAPIV3Schema:
  31040. description: SSHKey generates SSH key pairs.
  31041. properties:
  31042. apiVersion:
  31043. description: |-
  31044. APIVersion defines the versioned schema of this representation of an object.
  31045. Servers should convert recognized schemas to the latest internal value, and
  31046. may reject unrecognized values.
  31047. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31048. type: string
  31049. kind:
  31050. description: |-
  31051. Kind is a string value representing the REST resource this object represents.
  31052. Servers may infer this from the endpoint the client submits requests to.
  31053. Cannot be updated.
  31054. In CamelCase.
  31055. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31056. type: string
  31057. metadata:
  31058. type: object
  31059. spec:
  31060. description: SSHKeySpec controls the behavior of the ssh key generator.
  31061. properties:
  31062. comment:
  31063. description: Comment specifies an optional comment for the SSH key
  31064. type: string
  31065. keySize:
  31066. description: |-
  31067. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31068. For RSA keys: 2048, 3072, 4096
  31069. For ECDSA keys: 256, 384, 521
  31070. Ignored for ed25519 keys
  31071. maximum: 8192
  31072. minimum: 256
  31073. type: integer
  31074. keyType:
  31075. default: rsa
  31076. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31077. enum:
  31078. - rsa
  31079. - ecdsa
  31080. - ed25519
  31081. type: string
  31082. type: object
  31083. type: object
  31084. served: true
  31085. storage: true
  31086. subresources:
  31087. status: {}
  31088. ---
  31089. apiVersion: apiextensions.k8s.io/v1
  31090. kind: CustomResourceDefinition
  31091. metadata:
  31092. annotations:
  31093. controller-gen.kubebuilder.io/version: v0.19.0
  31094. labels:
  31095. external-secrets.io/component: controller
  31096. name: stssessiontokens.generators.external-secrets.io
  31097. spec:
  31098. group: generators.external-secrets.io
  31099. names:
  31100. categories:
  31101. - external-secrets
  31102. - external-secrets-generators
  31103. kind: STSSessionToken
  31104. listKind: STSSessionTokenList
  31105. plural: stssessiontokens
  31106. singular: stssessiontoken
  31107. scope: Namespaced
  31108. versions:
  31109. - name: v1alpha1
  31110. schema:
  31111. openAPIV3Schema:
  31112. description: |-
  31113. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31114. The authorization token is valid for 12 hours.
  31115. The authorizationToken returned is a base64 encoded string that can be decoded.
  31116. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31117. properties:
  31118. apiVersion:
  31119. description: |-
  31120. APIVersion defines the versioned schema of this representation of an object.
  31121. Servers should convert recognized schemas to the latest internal value, and
  31122. may reject unrecognized values.
  31123. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31124. type: string
  31125. kind:
  31126. description: |-
  31127. Kind is a string value representing the REST resource this object represents.
  31128. Servers may infer this from the endpoint the client submits requests to.
  31129. Cannot be updated.
  31130. In CamelCase.
  31131. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31132. type: string
  31133. metadata:
  31134. type: object
  31135. spec:
  31136. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31137. properties:
  31138. auth:
  31139. description: Auth defines how to authenticate with AWS
  31140. properties:
  31141. jwt:
  31142. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31143. properties:
  31144. serviceAccountRef:
  31145. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31146. properties:
  31147. audiences:
  31148. description: |-
  31149. Audience specifies the `aud` claim for the service account token
  31150. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31151. then this audiences will be appended to the list
  31152. items:
  31153. type: string
  31154. type: array
  31155. name:
  31156. description: The name of the ServiceAccount resource being referred to.
  31157. maxLength: 253
  31158. minLength: 1
  31159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31160. type: string
  31161. namespace:
  31162. description: |-
  31163. Namespace of the resource being referred to.
  31164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31165. maxLength: 63
  31166. minLength: 1
  31167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31168. type: string
  31169. required:
  31170. - name
  31171. type: object
  31172. type: object
  31173. secretRef:
  31174. description: |-
  31175. AWSAuthSecretRef holds secret references for AWS credentials
  31176. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31177. properties:
  31178. accessKeyIDSecretRef:
  31179. description: The AccessKeyID is used for authentication
  31180. properties:
  31181. key:
  31182. description: |-
  31183. A key in the referenced Secret.
  31184. Some instances of this field may be defaulted, in others it may be required.
  31185. maxLength: 253
  31186. minLength: 1
  31187. pattern: ^[-._a-zA-Z0-9]+$
  31188. type: string
  31189. name:
  31190. description: The name of the Secret resource being referred to.
  31191. maxLength: 253
  31192. minLength: 1
  31193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31194. type: string
  31195. namespace:
  31196. description: |-
  31197. The namespace of the Secret resource being referred to.
  31198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31199. maxLength: 63
  31200. minLength: 1
  31201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31202. type: string
  31203. type: object
  31204. secretAccessKeySecretRef:
  31205. description: The SecretAccessKey is used for authentication
  31206. properties:
  31207. key:
  31208. description: |-
  31209. A key in the referenced Secret.
  31210. Some instances of this field may be defaulted, in others it may be required.
  31211. maxLength: 253
  31212. minLength: 1
  31213. pattern: ^[-._a-zA-Z0-9]+$
  31214. type: string
  31215. name:
  31216. description: The name of the Secret resource being referred to.
  31217. maxLength: 253
  31218. minLength: 1
  31219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31220. type: string
  31221. namespace:
  31222. description: |-
  31223. The namespace of the Secret resource being referred to.
  31224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31225. maxLength: 63
  31226. minLength: 1
  31227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31228. type: string
  31229. type: object
  31230. sessionTokenSecretRef:
  31231. description: |-
  31232. The SessionToken used for authentication
  31233. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31234. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31235. properties:
  31236. key:
  31237. description: |-
  31238. A key in the referenced Secret.
  31239. Some instances of this field may be defaulted, in others it may be required.
  31240. maxLength: 253
  31241. minLength: 1
  31242. pattern: ^[-._a-zA-Z0-9]+$
  31243. type: string
  31244. name:
  31245. description: The name of the Secret resource being referred to.
  31246. maxLength: 253
  31247. minLength: 1
  31248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31249. type: string
  31250. namespace:
  31251. description: |-
  31252. The namespace of the Secret resource being referred to.
  31253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31254. maxLength: 63
  31255. minLength: 1
  31256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31257. type: string
  31258. type: object
  31259. type: object
  31260. type: object
  31261. region:
  31262. description: Region specifies the region to operate in.
  31263. type: string
  31264. requestParameters:
  31265. description: RequestParameters contains parameters that can be passed to the STS service.
  31266. properties:
  31267. serialNumber:
  31268. description: |-
  31269. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31270. the GetSessionToken call.
  31271. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31272. (such as arn:aws:iam::123456789012:mfa/user)
  31273. type: string
  31274. sessionDuration:
  31275. format: int32
  31276. type: integer
  31277. tokenCode:
  31278. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31279. type: string
  31280. type: object
  31281. role:
  31282. description: |-
  31283. You can assume a role before making calls to the
  31284. desired AWS service.
  31285. type: string
  31286. required:
  31287. - region
  31288. type: object
  31289. type: object
  31290. served: true
  31291. storage: true
  31292. subresources:
  31293. status: {}
  31294. ---
  31295. apiVersion: apiextensions.k8s.io/v1
  31296. kind: CustomResourceDefinition
  31297. metadata:
  31298. annotations:
  31299. controller-gen.kubebuilder.io/version: v0.19.0
  31300. labels:
  31301. external-secrets.io/component: controller
  31302. name: uuids.generators.external-secrets.io
  31303. spec:
  31304. group: generators.external-secrets.io
  31305. names:
  31306. categories:
  31307. - external-secrets
  31308. - external-secrets-generators
  31309. kind: UUID
  31310. listKind: UUIDList
  31311. plural: uuids
  31312. singular: uuid
  31313. scope: Namespaced
  31314. versions:
  31315. - name: v1alpha1
  31316. schema:
  31317. openAPIV3Schema:
  31318. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31319. properties:
  31320. apiVersion:
  31321. description: |-
  31322. APIVersion defines the versioned schema of this representation of an object.
  31323. Servers should convert recognized schemas to the latest internal value, and
  31324. may reject unrecognized values.
  31325. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31326. type: string
  31327. kind:
  31328. description: |-
  31329. Kind is a string value representing the REST resource this object represents.
  31330. Servers may infer this from the endpoint the client submits requests to.
  31331. Cannot be updated.
  31332. In CamelCase.
  31333. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31334. type: string
  31335. metadata:
  31336. type: object
  31337. spec:
  31338. description: UUIDSpec controls the behavior of the uuid generator.
  31339. type: object
  31340. type: object
  31341. served: true
  31342. storage: true
  31343. subresources:
  31344. status: {}
  31345. ---
  31346. apiVersion: apiextensions.k8s.io/v1
  31347. kind: CustomResourceDefinition
  31348. metadata:
  31349. annotations:
  31350. controller-gen.kubebuilder.io/version: v0.19.0
  31351. labels:
  31352. external-secrets.io/component: controller
  31353. name: vaultdynamicsecrets.generators.external-secrets.io
  31354. spec:
  31355. group: generators.external-secrets.io
  31356. names:
  31357. categories:
  31358. - external-secrets
  31359. - external-secrets-generators
  31360. kind: VaultDynamicSecret
  31361. listKind: VaultDynamicSecretList
  31362. plural: vaultdynamicsecrets
  31363. singular: vaultdynamicsecret
  31364. scope: Namespaced
  31365. versions:
  31366. - name: v1alpha1
  31367. schema:
  31368. openAPIV3Schema:
  31369. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31370. properties:
  31371. apiVersion:
  31372. description: |-
  31373. APIVersion defines the versioned schema of this representation of an object.
  31374. Servers should convert recognized schemas to the latest internal value, and
  31375. may reject unrecognized values.
  31376. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31377. type: string
  31378. kind:
  31379. description: |-
  31380. Kind is a string value representing the REST resource this object represents.
  31381. Servers may infer this from the endpoint the client submits requests to.
  31382. Cannot be updated.
  31383. In CamelCase.
  31384. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31385. type: string
  31386. metadata:
  31387. type: object
  31388. spec:
  31389. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31390. properties:
  31391. allowEmptyResponse:
  31392. default: false
  31393. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31394. type: boolean
  31395. controller:
  31396. description: |-
  31397. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31398. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31399. type: string
  31400. getParameters:
  31401. additionalProperties:
  31402. items:
  31403. type: string
  31404. type: array
  31405. description: |-
  31406. GetParameters are query-string parameters passed to Vault on GET calls.
  31407. Each key may map to multiple values, matching HTTP query-string semantics.
  31408. Ignored for non-GET methods; use Parameters for write bodies.
  31409. type: object
  31410. method:
  31411. description: Vault API method to use (GET/POST/other)
  31412. type: string
  31413. parameters:
  31414. description: Parameters to pass to Vault write (for non-GET methods)
  31415. x-kubernetes-preserve-unknown-fields: true
  31416. path:
  31417. description: Vault path to obtain the dynamic secret from
  31418. type: string
  31419. provider:
  31420. description: Vault provider common spec
  31421. properties:
  31422. auth:
  31423. description: Auth configures how secret-manager authenticates with the Vault server.
  31424. properties:
  31425. appRole:
  31426. description: |-
  31427. AppRole authenticates with Vault using the App Role auth mechanism,
  31428. with the role and secret stored in a Kubernetes Secret resource.
  31429. properties:
  31430. path:
  31431. default: approle
  31432. description: |-
  31433. Path where the App Role authentication backend is mounted
  31434. in Vault, e.g: "approle"
  31435. type: string
  31436. roleId:
  31437. description: |-
  31438. RoleID configured in the App Role authentication backend when setting
  31439. up the authentication backend in Vault.
  31440. type: string
  31441. roleRef:
  31442. description: |-
  31443. Reference to a key in a Secret that contains the App Role ID used
  31444. to authenticate with Vault.
  31445. The `key` field must be specified and denotes which entry within the Secret
  31446. resource is used as the app role id.
  31447. properties:
  31448. key:
  31449. description: |-
  31450. A key in the referenced Secret.
  31451. Some instances of this field may be defaulted, in others it may be required.
  31452. maxLength: 253
  31453. minLength: 1
  31454. pattern: ^[-._a-zA-Z0-9]+$
  31455. type: string
  31456. name:
  31457. description: The name of the Secret resource being referred to.
  31458. maxLength: 253
  31459. minLength: 1
  31460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31461. type: string
  31462. namespace:
  31463. description: |-
  31464. The namespace of the Secret resource being referred to.
  31465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31466. maxLength: 63
  31467. minLength: 1
  31468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31469. type: string
  31470. type: object
  31471. secretRef:
  31472. description: |-
  31473. Reference to a key in a Secret that contains the App Role secret used
  31474. to authenticate with Vault.
  31475. The `key` field must be specified and denotes which entry within the Secret
  31476. resource is used as the app role secret.
  31477. properties:
  31478. key:
  31479. description: |-
  31480. A key in the referenced Secret.
  31481. Some instances of this field may be defaulted, in others it may be required.
  31482. maxLength: 253
  31483. minLength: 1
  31484. pattern: ^[-._a-zA-Z0-9]+$
  31485. type: string
  31486. name:
  31487. description: The name of the Secret resource being referred to.
  31488. maxLength: 253
  31489. minLength: 1
  31490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31491. type: string
  31492. namespace:
  31493. description: |-
  31494. The namespace of the Secret resource being referred to.
  31495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31496. maxLength: 63
  31497. minLength: 1
  31498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31499. type: string
  31500. type: object
  31501. required:
  31502. - path
  31503. - secretRef
  31504. type: object
  31505. cert:
  31506. description: |-
  31507. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31508. Cert authentication method
  31509. properties:
  31510. clientCert:
  31511. description: |-
  31512. ClientCert is a certificate to authenticate using the Cert Vault
  31513. authentication method
  31514. properties:
  31515. key:
  31516. description: |-
  31517. A key in the referenced Secret.
  31518. Some instances of this field may be defaulted, in others it may be required.
  31519. maxLength: 253
  31520. minLength: 1
  31521. pattern: ^[-._a-zA-Z0-9]+$
  31522. type: string
  31523. name:
  31524. description: The name of the Secret resource being referred to.
  31525. maxLength: 253
  31526. minLength: 1
  31527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31528. type: string
  31529. namespace:
  31530. description: |-
  31531. The namespace of the Secret resource being referred to.
  31532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31533. maxLength: 63
  31534. minLength: 1
  31535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31536. type: string
  31537. type: object
  31538. path:
  31539. default: cert
  31540. description: |-
  31541. Path where the Certificate authentication backend is mounted
  31542. in Vault, e.g: "cert"
  31543. type: string
  31544. secretRef:
  31545. description: |-
  31546. SecretRef to a key in a Secret resource containing client private key to
  31547. authenticate with Vault using the Cert authentication method
  31548. properties:
  31549. key:
  31550. description: |-
  31551. A key in the referenced Secret.
  31552. Some instances of this field may be defaulted, in others it may be required.
  31553. maxLength: 253
  31554. minLength: 1
  31555. pattern: ^[-._a-zA-Z0-9]+$
  31556. type: string
  31557. name:
  31558. description: The name of the Secret resource being referred to.
  31559. maxLength: 253
  31560. minLength: 1
  31561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31562. type: string
  31563. namespace:
  31564. description: |-
  31565. The namespace of the Secret resource being referred to.
  31566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31567. maxLength: 63
  31568. minLength: 1
  31569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31570. type: string
  31571. type: object
  31572. vaultRole:
  31573. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31574. type: string
  31575. type: object
  31576. gcp:
  31577. description: |-
  31578. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31579. GCP authentication method
  31580. properties:
  31581. location:
  31582. description: Location optionally defines a location/region for the secret
  31583. type: string
  31584. path:
  31585. default: gcp
  31586. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31587. type: string
  31588. projectID:
  31589. description: Project ID of the Google Cloud Platform project
  31590. type: string
  31591. role:
  31592. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31593. type: string
  31594. secretRef:
  31595. description: Specify credentials in a Secret object
  31596. properties:
  31597. secretAccessKeySecretRef:
  31598. description: The SecretAccessKey is used for authentication
  31599. properties:
  31600. key:
  31601. description: |-
  31602. A key in the referenced Secret.
  31603. Some instances of this field may be defaulted, in others it may be required.
  31604. maxLength: 253
  31605. minLength: 1
  31606. pattern: ^[-._a-zA-Z0-9]+$
  31607. type: string
  31608. name:
  31609. description: The name of the Secret resource being referred to.
  31610. maxLength: 253
  31611. minLength: 1
  31612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31613. type: string
  31614. namespace:
  31615. description: |-
  31616. The namespace of the Secret resource being referred to.
  31617. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31618. maxLength: 63
  31619. minLength: 1
  31620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31621. type: string
  31622. type: object
  31623. type: object
  31624. serviceAccountRef:
  31625. description: ServiceAccountRef to a service account for impersonation
  31626. properties:
  31627. audiences:
  31628. description: |-
  31629. Audience specifies the `aud` claim for the service account token
  31630. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31631. then this audiences will be appended to the list
  31632. items:
  31633. type: string
  31634. type: array
  31635. name:
  31636. description: The name of the ServiceAccount resource being referred to.
  31637. maxLength: 253
  31638. minLength: 1
  31639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31640. type: string
  31641. namespace:
  31642. description: |-
  31643. Namespace of the resource being referred to.
  31644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31645. maxLength: 63
  31646. minLength: 1
  31647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31648. type: string
  31649. required:
  31650. - name
  31651. type: object
  31652. workloadIdentity:
  31653. description: Specify a service account with Workload Identity
  31654. properties:
  31655. clusterLocation:
  31656. description: |-
  31657. ClusterLocation is the location of the cluster
  31658. If not specified, it fetches information from the metadata server
  31659. type: string
  31660. clusterName:
  31661. description: |-
  31662. ClusterName is the name of the cluster
  31663. If not specified, it fetches information from the metadata server
  31664. type: string
  31665. clusterProjectID:
  31666. description: |-
  31667. ClusterProjectID is the project ID of the cluster
  31668. If not specified, it fetches information from the metadata server
  31669. type: string
  31670. serviceAccountRef:
  31671. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31672. properties:
  31673. audiences:
  31674. description: |-
  31675. Audience specifies the `aud` claim for the service account token
  31676. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31677. then this audiences will be appended to the list
  31678. items:
  31679. type: string
  31680. type: array
  31681. name:
  31682. description: The name of the ServiceAccount resource being referred to.
  31683. maxLength: 253
  31684. minLength: 1
  31685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31686. type: string
  31687. namespace:
  31688. description: |-
  31689. Namespace of the resource being referred to.
  31690. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31691. maxLength: 63
  31692. minLength: 1
  31693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31694. type: string
  31695. required:
  31696. - name
  31697. type: object
  31698. required:
  31699. - serviceAccountRef
  31700. type: object
  31701. required:
  31702. - role
  31703. type: object
  31704. iam:
  31705. description: |-
  31706. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31707. AWS IAM authentication method
  31708. properties:
  31709. externalID:
  31710. description: AWS External ID set on assumed IAM roles
  31711. type: string
  31712. jwt:
  31713. description: Specify a service account with IRSA enabled
  31714. properties:
  31715. serviceAccountRef:
  31716. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31717. properties:
  31718. audiences:
  31719. description: |-
  31720. Audience specifies the `aud` claim for the service account token
  31721. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31722. then this audiences will be appended to the list
  31723. items:
  31724. type: string
  31725. type: array
  31726. name:
  31727. description: The name of the ServiceAccount resource being referred to.
  31728. maxLength: 253
  31729. minLength: 1
  31730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31731. type: string
  31732. namespace:
  31733. description: |-
  31734. Namespace of the resource being referred to.
  31735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31736. maxLength: 63
  31737. minLength: 1
  31738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31739. type: string
  31740. required:
  31741. - name
  31742. type: object
  31743. type: object
  31744. path:
  31745. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31746. type: string
  31747. region:
  31748. description: AWS region
  31749. type: string
  31750. role:
  31751. description: This is the AWS role to be assumed before talking to vault
  31752. type: string
  31753. secretRef:
  31754. description: Specify credentials in a Secret object
  31755. properties:
  31756. accessKeyIDSecretRef:
  31757. description: The AccessKeyID is used for authentication
  31758. properties:
  31759. key:
  31760. description: |-
  31761. A key in the referenced Secret.
  31762. Some instances of this field may be defaulted, in others it may be required.
  31763. maxLength: 253
  31764. minLength: 1
  31765. pattern: ^[-._a-zA-Z0-9]+$
  31766. type: string
  31767. name:
  31768. description: The name of the Secret resource being referred to.
  31769. maxLength: 253
  31770. minLength: 1
  31771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31772. type: string
  31773. namespace:
  31774. description: |-
  31775. The namespace of the Secret resource being referred to.
  31776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31777. maxLength: 63
  31778. minLength: 1
  31779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31780. type: string
  31781. type: object
  31782. secretAccessKeySecretRef:
  31783. description: The SecretAccessKey is used for authentication
  31784. properties:
  31785. key:
  31786. description: |-
  31787. A key in the referenced Secret.
  31788. Some instances of this field may be defaulted, in others it may be required.
  31789. maxLength: 253
  31790. minLength: 1
  31791. pattern: ^[-._a-zA-Z0-9]+$
  31792. type: string
  31793. name:
  31794. description: The name of the Secret resource being referred to.
  31795. maxLength: 253
  31796. minLength: 1
  31797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31798. type: string
  31799. namespace:
  31800. description: |-
  31801. The namespace of the Secret resource being referred to.
  31802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31803. maxLength: 63
  31804. minLength: 1
  31805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31806. type: string
  31807. type: object
  31808. sessionTokenSecretRef:
  31809. description: |-
  31810. The SessionToken used for authentication
  31811. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31812. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31813. properties:
  31814. key:
  31815. description: |-
  31816. A key in the referenced Secret.
  31817. Some instances of this field may be defaulted, in others it may be required.
  31818. maxLength: 253
  31819. minLength: 1
  31820. pattern: ^[-._a-zA-Z0-9]+$
  31821. type: string
  31822. name:
  31823. description: The name of the Secret resource being referred to.
  31824. maxLength: 253
  31825. minLength: 1
  31826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31827. type: string
  31828. namespace:
  31829. description: |-
  31830. The namespace of the Secret resource being referred to.
  31831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31832. maxLength: 63
  31833. minLength: 1
  31834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31835. type: string
  31836. type: object
  31837. type: object
  31838. vaultAwsIamServerID:
  31839. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31840. type: string
  31841. vaultRole:
  31842. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31843. type: string
  31844. required:
  31845. - vaultRole
  31846. type: object
  31847. jwt:
  31848. description: |-
  31849. Jwt authenticates with Vault by passing role and JWT token using the
  31850. JWT/OIDC authentication method
  31851. properties:
  31852. kubernetesServiceAccountToken:
  31853. description: |-
  31854. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31855. a token for with the `TokenRequest` API.
  31856. properties:
  31857. audiences:
  31858. description: |-
  31859. Optional audiences field that will be used to request a temporary Kubernetes service
  31860. account token for the service account referenced by `serviceAccountRef`.
  31861. Defaults to a single audience `vault` it not specified.
  31862. Deprecated: use serviceAccountRef.Audiences instead
  31863. items:
  31864. type: string
  31865. type: array
  31866. expirationSeconds:
  31867. description: |-
  31868. Optional expiration time in seconds that will be used to request a temporary
  31869. Kubernetes service account token for the service account referenced by
  31870. `serviceAccountRef`.
  31871. Deprecated: this will be removed in the future.
  31872. Defaults to 10 minutes.
  31873. format: int64
  31874. type: integer
  31875. serviceAccountRef:
  31876. description: Service account field containing the name of a kubernetes ServiceAccount.
  31877. properties:
  31878. audiences:
  31879. description: |-
  31880. Audience specifies the `aud` claim for the service account token
  31881. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31882. then this audiences will be appended to the list
  31883. items:
  31884. type: string
  31885. type: array
  31886. name:
  31887. description: The name of the ServiceAccount resource being referred to.
  31888. maxLength: 253
  31889. minLength: 1
  31890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31891. type: string
  31892. namespace:
  31893. description: |-
  31894. Namespace of the resource being referred to.
  31895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31896. maxLength: 63
  31897. minLength: 1
  31898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31899. type: string
  31900. required:
  31901. - name
  31902. type: object
  31903. required:
  31904. - serviceAccountRef
  31905. type: object
  31906. path:
  31907. default: jwt
  31908. description: |-
  31909. Path where the JWT authentication backend is mounted
  31910. in Vault, e.g: "jwt"
  31911. type: string
  31912. role:
  31913. description: |-
  31914. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31915. authentication method
  31916. type: string
  31917. secretRef:
  31918. description: |-
  31919. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31920. authenticate with Vault using the JWT/OIDC authentication method.
  31921. properties:
  31922. key:
  31923. description: |-
  31924. A key in the referenced Secret.
  31925. Some instances of this field may be defaulted, in others it may be required.
  31926. maxLength: 253
  31927. minLength: 1
  31928. pattern: ^[-._a-zA-Z0-9]+$
  31929. type: string
  31930. name:
  31931. description: The name of the Secret resource being referred to.
  31932. maxLength: 253
  31933. minLength: 1
  31934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31935. type: string
  31936. namespace:
  31937. description: |-
  31938. The namespace of the Secret resource being referred to.
  31939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31940. maxLength: 63
  31941. minLength: 1
  31942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31943. type: string
  31944. type: object
  31945. required:
  31946. - path
  31947. type: object
  31948. kubernetes:
  31949. description: |-
  31950. Kubernetes authenticates with Vault by passing the ServiceAccount
  31951. token stored in the named Secret resource to the Vault server.
  31952. properties:
  31953. mountPath:
  31954. default: kubernetes
  31955. description: |-
  31956. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31957. "kubernetes"
  31958. type: string
  31959. role:
  31960. description: |-
  31961. A required field containing the Vault Role to assume. A Role binds a
  31962. Kubernetes ServiceAccount with a set of Vault policies.
  31963. type: string
  31964. secretRef:
  31965. description: |-
  31966. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31967. for authenticating with Vault. If a name is specified without a key,
  31968. `token` is the default. If one is not specified, the one bound to
  31969. the controller will be used.
  31970. properties:
  31971. key:
  31972. description: |-
  31973. A key in the referenced Secret.
  31974. Some instances of this field may be defaulted, in others it may be required.
  31975. maxLength: 253
  31976. minLength: 1
  31977. pattern: ^[-._a-zA-Z0-9]+$
  31978. type: string
  31979. name:
  31980. description: The name of the Secret resource being referred to.
  31981. maxLength: 253
  31982. minLength: 1
  31983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31984. type: string
  31985. namespace:
  31986. description: |-
  31987. The namespace of the Secret resource being referred to.
  31988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31989. maxLength: 63
  31990. minLength: 1
  31991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31992. type: string
  31993. type: object
  31994. serviceAccountRef:
  31995. description: |-
  31996. Optional service account field containing the name of a kubernetes ServiceAccount.
  31997. If the service account is specified, the service account secret token JWT will be used
  31998. for authenticating with Vault. If the service account selector is not supplied,
  31999. the secretRef will be used instead.
  32000. properties:
  32001. audiences:
  32002. description: |-
  32003. Audience specifies the `aud` claim for the service account token
  32004. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  32005. then this audiences will be appended to the list
  32006. items:
  32007. type: string
  32008. type: array
  32009. name:
  32010. description: The name of the ServiceAccount resource being referred to.
  32011. maxLength: 253
  32012. minLength: 1
  32013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32014. type: string
  32015. namespace:
  32016. description: |-
  32017. Namespace of the resource being referred to.
  32018. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32019. maxLength: 63
  32020. minLength: 1
  32021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32022. type: string
  32023. required:
  32024. - name
  32025. type: object
  32026. required:
  32027. - mountPath
  32028. - role
  32029. type: object
  32030. ldap:
  32031. description: |-
  32032. Ldap authenticates with Vault by passing username/password pair using
  32033. the LDAP authentication method
  32034. properties:
  32035. path:
  32036. default: ldap
  32037. description: |-
  32038. Path where the LDAP authentication backend is mounted
  32039. in Vault, e.g: "ldap"
  32040. type: string
  32041. secretRef:
  32042. description: |-
  32043. SecretRef to a key in a Secret resource containing password for the LDAP
  32044. user used to authenticate with Vault using the LDAP authentication
  32045. method
  32046. properties:
  32047. key:
  32048. description: |-
  32049. A key in the referenced Secret.
  32050. Some instances of this field may be defaulted, in others it may be required.
  32051. maxLength: 253
  32052. minLength: 1
  32053. pattern: ^[-._a-zA-Z0-9]+$
  32054. type: string
  32055. name:
  32056. description: The name of the Secret resource being referred to.
  32057. maxLength: 253
  32058. minLength: 1
  32059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32060. type: string
  32061. namespace:
  32062. description: |-
  32063. The namespace of the Secret resource being referred to.
  32064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32065. maxLength: 63
  32066. minLength: 1
  32067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32068. type: string
  32069. type: object
  32070. username:
  32071. description: |-
  32072. Username is an LDAP username used to authenticate using the LDAP Vault
  32073. authentication method
  32074. type: string
  32075. required:
  32076. - path
  32077. - username
  32078. type: object
  32079. namespace:
  32080. description: |-
  32081. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32082. Namespaces is a set of features within Vault Enterprise that allows
  32083. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32084. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32085. This will default to Vault.Namespace field if set, or empty otherwise
  32086. type: string
  32087. tokenSecretRef:
  32088. description: TokenSecretRef authenticates with Vault by presenting a token.
  32089. properties:
  32090. key:
  32091. description: |-
  32092. A key in the referenced Secret.
  32093. Some instances of this field may be defaulted, in others it may be required.
  32094. maxLength: 253
  32095. minLength: 1
  32096. pattern: ^[-._a-zA-Z0-9]+$
  32097. type: string
  32098. name:
  32099. description: The name of the Secret resource being referred to.
  32100. maxLength: 253
  32101. minLength: 1
  32102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32103. type: string
  32104. namespace:
  32105. description: |-
  32106. The namespace of the Secret resource being referred to.
  32107. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32108. maxLength: 63
  32109. minLength: 1
  32110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32111. type: string
  32112. type: object
  32113. userPass:
  32114. description: UserPass authenticates with Vault by passing username/password pair
  32115. properties:
  32116. path:
  32117. default: userpass
  32118. description: |-
  32119. Path where the UserPassword authentication backend is mounted
  32120. in Vault, e.g: "userpass"
  32121. type: string
  32122. secretRef:
  32123. description: |-
  32124. SecretRef to a key in a Secret resource containing password for the
  32125. user used to authenticate with Vault using the UserPass authentication
  32126. method
  32127. properties:
  32128. key:
  32129. description: |-
  32130. A key in the referenced Secret.
  32131. Some instances of this field may be defaulted, in others it may be required.
  32132. maxLength: 253
  32133. minLength: 1
  32134. pattern: ^[-._a-zA-Z0-9]+$
  32135. type: string
  32136. name:
  32137. description: The name of the Secret resource being referred to.
  32138. maxLength: 253
  32139. minLength: 1
  32140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32141. type: string
  32142. namespace:
  32143. description: |-
  32144. The namespace of the Secret resource being referred to.
  32145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32146. maxLength: 63
  32147. minLength: 1
  32148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32149. type: string
  32150. type: object
  32151. username:
  32152. description: |-
  32153. Username is a username used to authenticate using the UserPass Vault
  32154. authentication method
  32155. type: string
  32156. required:
  32157. - path
  32158. - username
  32159. type: object
  32160. type: object
  32161. caBundle:
  32162. description: |-
  32163. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32164. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32165. plain HTTP protocol connection. If not set the system root certificates
  32166. are used to validate the TLS connection.
  32167. format: byte
  32168. type: string
  32169. caProvider:
  32170. description: The provider for the CA bundle to use to validate Vault server certificate.
  32171. properties:
  32172. key:
  32173. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32174. maxLength: 253
  32175. minLength: 1
  32176. pattern: ^[-._a-zA-Z0-9]+$
  32177. type: string
  32178. name:
  32179. description: The name of the object located at the provider type.
  32180. maxLength: 253
  32181. minLength: 1
  32182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32183. type: string
  32184. namespace:
  32185. description: |-
  32186. The namespace the Provider type is in.
  32187. Can only be defined when used in a ClusterSecretStore.
  32188. maxLength: 63
  32189. minLength: 1
  32190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32191. type: string
  32192. type:
  32193. description: The type of provider to use such as "Secret", or "ConfigMap".
  32194. enum:
  32195. - Secret
  32196. - ConfigMap
  32197. type: string
  32198. required:
  32199. - name
  32200. - type
  32201. type: object
  32202. checkAndSet:
  32203. description: |-
  32204. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32205. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32206. the current version of the secret to prevent unintentional overwrites.
  32207. properties:
  32208. required:
  32209. description: |-
  32210. Required when true, all write operations must include a check-and-set parameter.
  32211. This helps prevent unintentional overwrites of secrets.
  32212. type: boolean
  32213. type: object
  32214. forwardInconsistent:
  32215. description: |-
  32216. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32217. leader instead of simply retrying within a loop. This can increase performance if
  32218. the option is enabled serverside.
  32219. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32220. type: boolean
  32221. headers:
  32222. additionalProperties:
  32223. type: string
  32224. description: Headers to be added in Vault request
  32225. type: object
  32226. namespace:
  32227. description: |-
  32228. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32229. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32230. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32231. type: string
  32232. path:
  32233. description: |-
  32234. Path is the mount path of the Vault KV backend endpoint, e.g:
  32235. "secret". The v2 KV secret engine version specific "/data" path suffix
  32236. for fetching secrets from Vault is optional and will be appended
  32237. if not present in specified path.
  32238. type: string
  32239. readYourWrites:
  32240. description: |-
  32241. ReadYourWrites ensures isolated read-after-write semantics by
  32242. providing discovered cluster replication states in each request.
  32243. More information about eventual consistency in Vault can be found here
  32244. https://www.vaultproject.io/docs/enterprise/consistency
  32245. type: boolean
  32246. server:
  32247. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32248. type: string
  32249. tls:
  32250. description: |-
  32251. The configuration used for client side related TLS communication, when the Vault server
  32252. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32253. This parameter is ignored for plain HTTP protocol connection.
  32254. It's worth noting this configuration is different from the "TLS certificates auth method",
  32255. which is available under the `auth.cert` section.
  32256. properties:
  32257. certSecretRef:
  32258. description: |-
  32259. CertSecretRef is a certificate added to the transport layer
  32260. when communicating with the Vault server.
  32261. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32262. properties:
  32263. key:
  32264. description: |-
  32265. A key in the referenced Secret.
  32266. Some instances of this field may be defaulted, in others it may be required.
  32267. maxLength: 253
  32268. minLength: 1
  32269. pattern: ^[-._a-zA-Z0-9]+$
  32270. type: string
  32271. name:
  32272. description: The name of the Secret resource being referred to.
  32273. maxLength: 253
  32274. minLength: 1
  32275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32276. type: string
  32277. namespace:
  32278. description: |-
  32279. The namespace of the Secret resource being referred to.
  32280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32281. maxLength: 63
  32282. minLength: 1
  32283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32284. type: string
  32285. type: object
  32286. keySecretRef:
  32287. description: |-
  32288. KeySecretRef to a key in a Secret resource containing client private key
  32289. added to the transport layer when communicating with the Vault server.
  32290. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32291. properties:
  32292. key:
  32293. description: |-
  32294. A key in the referenced Secret.
  32295. Some instances of this field may be defaulted, in others it may be required.
  32296. maxLength: 253
  32297. minLength: 1
  32298. pattern: ^[-._a-zA-Z0-9]+$
  32299. type: string
  32300. name:
  32301. description: The name of the Secret resource being referred to.
  32302. maxLength: 253
  32303. minLength: 1
  32304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32305. type: string
  32306. namespace:
  32307. description: |-
  32308. The namespace of the Secret resource being referred to.
  32309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32310. maxLength: 63
  32311. minLength: 1
  32312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32313. type: string
  32314. type: object
  32315. type: object
  32316. version:
  32317. default: v2
  32318. description: |-
  32319. Version is the Vault KV secret engine version. This can be either "v1" or
  32320. "v2". Version defaults to "v2".
  32321. enum:
  32322. - v1
  32323. - v2
  32324. type: string
  32325. required:
  32326. - server
  32327. type: object
  32328. resultType:
  32329. default: Data
  32330. description: |-
  32331. Result type defines which data is returned from the generator.
  32332. By default, it is the "data" section of the Vault API response.
  32333. When using e.g. /auth/token/create the "data" section is empty but
  32334. the "auth" section contains the generated token.
  32335. Please refer to the vault docs regarding the result data structure.
  32336. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32337. enum:
  32338. - Data
  32339. - Auth
  32340. - Raw
  32341. type: string
  32342. retrySettings:
  32343. description: Used to configure http retries if failed
  32344. properties:
  32345. maxRetries:
  32346. format: int32
  32347. type: integer
  32348. retryInterval:
  32349. type: string
  32350. type: object
  32351. required:
  32352. - path
  32353. - provider
  32354. type: object
  32355. type: object
  32356. served: true
  32357. storage: true
  32358. subresources:
  32359. status: {}
  32360. ---
  32361. apiVersion: apiextensions.k8s.io/v1
  32362. kind: CustomResourceDefinition
  32363. metadata:
  32364. annotations:
  32365. controller-gen.kubebuilder.io/version: v0.19.0
  32366. labels:
  32367. external-secrets.io/component: controller
  32368. name: webhooks.generators.external-secrets.io
  32369. spec:
  32370. group: generators.external-secrets.io
  32371. names:
  32372. categories:
  32373. - external-secrets
  32374. - external-secrets-generators
  32375. kind: Webhook
  32376. listKind: WebhookList
  32377. plural: webhooks
  32378. singular: webhook
  32379. scope: Namespaced
  32380. versions:
  32381. - name: v1alpha1
  32382. schema:
  32383. openAPIV3Schema:
  32384. description: |-
  32385. Webhook connects to a third party API server to handle the secrets generation
  32386. configuration parameters in spec.
  32387. You can specify the server, the token, and additional body parameters.
  32388. See documentation for the full API specification for requests and responses.
  32389. properties:
  32390. apiVersion:
  32391. description: |-
  32392. APIVersion defines the versioned schema of this representation of an object.
  32393. Servers should convert recognized schemas to the latest internal value, and
  32394. may reject unrecognized values.
  32395. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32396. type: string
  32397. kind:
  32398. description: |-
  32399. Kind is a string value representing the REST resource this object represents.
  32400. Servers may infer this from the endpoint the client submits requests to.
  32401. Cannot be updated.
  32402. In CamelCase.
  32403. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32404. type: string
  32405. metadata:
  32406. type: object
  32407. spec:
  32408. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32409. properties:
  32410. auth:
  32411. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32412. maxProperties: 1
  32413. minProperties: 1
  32414. properties:
  32415. ntlm:
  32416. description: NTLMProtocol configures the store to use NTLM for auth
  32417. properties:
  32418. passwordSecret:
  32419. description: |-
  32420. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32421. In some instances, `key` is a required field.
  32422. properties:
  32423. key:
  32424. description: |-
  32425. A key in the referenced Secret.
  32426. Some instances of this field may be defaulted, in others it may be required.
  32427. maxLength: 253
  32428. minLength: 1
  32429. pattern: ^[-._a-zA-Z0-9]+$
  32430. type: string
  32431. name:
  32432. description: The name of the Secret resource being referred to.
  32433. maxLength: 253
  32434. minLength: 1
  32435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32436. type: string
  32437. namespace:
  32438. description: |-
  32439. The namespace of the Secret resource being referred to.
  32440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32441. maxLength: 63
  32442. minLength: 1
  32443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32444. type: string
  32445. type: object
  32446. usernameSecret:
  32447. description: |-
  32448. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32449. In some instances, `key` is a required field.
  32450. properties:
  32451. key:
  32452. description: |-
  32453. A key in the referenced Secret.
  32454. Some instances of this field may be defaulted, in others it may be required.
  32455. maxLength: 253
  32456. minLength: 1
  32457. pattern: ^[-._a-zA-Z0-9]+$
  32458. type: string
  32459. name:
  32460. description: The name of the Secret resource being referred to.
  32461. maxLength: 253
  32462. minLength: 1
  32463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32464. type: string
  32465. namespace:
  32466. description: |-
  32467. The namespace of the Secret resource being referred to.
  32468. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32469. maxLength: 63
  32470. minLength: 1
  32471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32472. type: string
  32473. type: object
  32474. required:
  32475. - passwordSecret
  32476. - usernameSecret
  32477. type: object
  32478. type: object
  32479. body:
  32480. description: Body
  32481. type: string
  32482. caBundle:
  32483. description: |-
  32484. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32485. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32486. plain HTTP protocol connection. If not set the system root certificates
  32487. are used to validate the TLS connection.
  32488. format: byte
  32489. type: string
  32490. caProvider:
  32491. description: The provider for the CA bundle to use to validate webhook server certificate.
  32492. properties:
  32493. key:
  32494. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32495. maxLength: 253
  32496. minLength: 1
  32497. pattern: ^[-._a-zA-Z0-9]+$
  32498. type: string
  32499. name:
  32500. description: The name of the object located at the provider type.
  32501. maxLength: 253
  32502. minLength: 1
  32503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32504. type: string
  32505. namespace:
  32506. description: The namespace the Provider type is in.
  32507. maxLength: 63
  32508. minLength: 1
  32509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32510. type: string
  32511. type:
  32512. description: The type of provider to use such as "Secret", or "ConfigMap".
  32513. enum:
  32514. - Secret
  32515. - ConfigMap
  32516. type: string
  32517. required:
  32518. - name
  32519. - type
  32520. type: object
  32521. headers:
  32522. additionalProperties:
  32523. type: string
  32524. description: Headers
  32525. type: object
  32526. method:
  32527. description: Webhook Method
  32528. type: string
  32529. result:
  32530. description: Result formatting
  32531. properties:
  32532. jsonPath:
  32533. description: Json path of return value
  32534. type: string
  32535. type: object
  32536. secrets:
  32537. description: |-
  32538. Secrets to fill in templates
  32539. These secrets will be passed to the templating function as key value pairs under the given name
  32540. items:
  32541. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32542. properties:
  32543. name:
  32544. description: Name of this secret in templates
  32545. type: string
  32546. secretRef:
  32547. description: Secret ref to fill in credentials
  32548. properties:
  32549. key:
  32550. description: The key where the token is found.
  32551. maxLength: 253
  32552. minLength: 1
  32553. pattern: ^[-._a-zA-Z0-9]+$
  32554. type: string
  32555. name:
  32556. description: The name of the Secret resource being referred to.
  32557. maxLength: 253
  32558. minLength: 1
  32559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32560. type: string
  32561. type: object
  32562. required:
  32563. - name
  32564. - secretRef
  32565. type: object
  32566. type: array
  32567. timeout:
  32568. description: Timeout
  32569. type: string
  32570. url:
  32571. description: Webhook url to call
  32572. type: string
  32573. required:
  32574. - result
  32575. - url
  32576. type: object
  32577. type: object
  32578. served: true
  32579. storage: true
  32580. subresources:
  32581. status: {}